UNPKG

@aws-cdk/aws-redshift-alpha

Version:

The CDK Construct Library for AWS::Redshift

552 lines 80.6 kB
"use strict"; var __decorate = (this && this.__decorate) || function (decorators, target, key, desc) { var c = arguments.length, r = c < 3 ? target : desc === null ? desc = Object.getOwnPropertyDescriptor(target, key) : desc, d; if (typeof Reflect === "object" && typeof Reflect.decorate === "function") r = Reflect.decorate(decorators, target, key, desc); else for (var i = decorators.length - 1; i >= 0; i--) if (d = decorators[i]) r = (c < 3 ? d(r) : c > 3 ? d(target, key, r) : d(target, key)) || r; return c > 3 && r && Object.defineProperty(target, key, r), r; }; var _a; Object.defineProperty(exports, "__esModule", { value: true }); exports.Cluster = exports.MaintenanceTrackName = exports.ResourceAction = exports.ClusterType = exports.NodeType = void 0; const jsiiDeprecationWarnings = require("../.warnings.jsii.js"); const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti"); const path = require("path"); const ec2 = require("aws-cdk-lib/aws-ec2"); const iam = require("aws-cdk-lib/aws-iam"); const lambda = require("aws-cdk-lib/aws-lambda"); const secretsmanager = require("aws-cdk-lib/aws-secretsmanager"); const core_1 = require("aws-cdk-lib/core"); const custom_resources_1 = require("aws-cdk-lib/custom-resources"); const database_secret_1 = require("./database-secret"); const endpoint_1 = require("./endpoint"); const parameter_group_1 = require("./parameter-group"); const aws_redshift_1 = require("aws-cdk-lib/aws-redshift"); const subnet_group_1 = require("./subnet-group"); const metadata_resource_1 = require("aws-cdk-lib/core/lib/metadata-resource"); const prop_injectable_1 = require("aws-cdk-lib/core/lib/prop-injectable"); /** * Possible Node Types to use in the cluster * used for defining `ClusterProps.nodeType`. */ var NodeType; (function (NodeType) { /** * ds2.xlarge */ NodeType["DS2_XLARGE"] = "ds2.xlarge"; /** * ds2.8xlarge */ NodeType["DS2_8XLARGE"] = "ds2.8xlarge"; /** * dc1.large */ NodeType["DC1_LARGE"] = "dc1.large"; /** * dc1.8xlarge */ NodeType["DC1_8XLARGE"] = "dc1.8xlarge"; /** * dc2.large */ NodeType["DC2_LARGE"] = "dc2.large"; /** * dc2.8xlarge */ NodeType["DC2_8XLARGE"] = "dc2.8xlarge"; /** * ra3.large */ NodeType["RA3_LARGE"] = "ra3.large"; /** * ra3.xlplus */ NodeType["RA3_XLPLUS"] = "ra3.xlplus"; /** * ra3.4xlarge */ NodeType["RA3_4XLARGE"] = "ra3.4xlarge"; /** * ra3.16xlarge */ NodeType["RA3_16XLARGE"] = "ra3.16xlarge"; })(NodeType || (exports.NodeType = NodeType = {})); /** * What cluster type to use. * Used by `ClusterProps.clusterType` */ var ClusterType; (function (ClusterType) { /** * single-node cluster, the `ClusterProps.numberOfNodes` parameter is not required */ ClusterType["SINGLE_NODE"] = "single-node"; /** * multi-node cluster, set the amount of nodes using `ClusterProps.numberOfNodes` parameter */ ClusterType["MULTI_NODE"] = "multi-node"; })(ClusterType || (exports.ClusterType = ClusterType = {})); /** * The Amazon Redshift operation */ var ResourceAction; (function (ResourceAction) { /** * Pause the cluster */ ResourceAction["PAUSE_CLUSTER"] = "pause-cluster"; /** * Resume the cluster */ ResourceAction["RESUME_CLUSTER"] = "resume-cluster"; /** * Failing over to the other availability zone * * @see https://docs.aws.amazon.com/redshift/latest/mgmt/test-cluster-multi-az.html */ ResourceAction["FAILOVER_PRIMARY_COMPUTE"] = "failover-primary-compute"; })(ResourceAction || (exports.ResourceAction = ResourceAction = {})); /** * The maintenance track for the cluster. * * @see https://docs.aws.amazon.com/redshift/latest/mgmt/managing-cluster-considerations.html#rs-mgmt-maintenance-tracks */ var MaintenanceTrackName; (function (MaintenanceTrackName) { /** * Updated to the most recently certified maintenance release. */ MaintenanceTrackName["CURRENT"] = "current"; /** * Update to the previously certified maintenance release. */ MaintenanceTrackName["TRAILING"] = "trailing"; })(MaintenanceTrackName || (exports.MaintenanceTrackName = MaintenanceTrackName = {})); /** * A new or imported clustered database. */ class ClusterBase extends core_1.Resource { /** * Renders the secret attachment target specifications. */ asSecretAttachmentTarget() { return { targetId: this.clusterName, targetType: secretsmanager.AttachmentTargetType.REDSHIFT_CLUSTER, }; } } /** * Create a Redshift cluster a given number of nodes. * * @resource AWS::Redshift::Cluster */ let Cluster = class Cluster extends ClusterBase { /** * Import an existing DatabaseCluster from properties */ static fromClusterAttributes(scope, id, attrs) { try { jsiiDeprecationWarnings._aws_cdk_aws_redshift_alpha_ClusterAttributes(attrs); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.fromClusterAttributes); } throw error; } class Import extends ClusterBase { constructor() { super(...arguments); this.connections = new ec2.Connections({ securityGroups: attrs.securityGroups, defaultPort: ec2.Port.tcp(attrs.clusterEndpointPort), }); this.clusterName = attrs.clusterName; this.instanceIdentifiers = []; this.clusterEndpoint = new endpoint_1.Endpoint(attrs.clusterEndpointAddress, attrs.clusterEndpointPort); } } return new Import(scope, id); } constructor(scope, id, props) { super(scope, id); try { jsiiDeprecationWarnings._aws_cdk_aws_redshift_alpha_ClusterProps(props); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, Cluster); } throw error; } // Enhanced CDK Analytics Telemetry (0, metadata_resource_1.addConstructMetadata)(this, props); this.vpc = props.vpc; this.vpcSubnets = props.vpcSubnets ?? { subnetType: ec2.SubnetType.PRIVATE_WITH_EGRESS, }; this.parameterGroup = props.parameterGroup; this.roles = props?.roles ? [...props.roles] : []; const removalPolicy = props.removalPolicy ?? core_1.RemovalPolicy.RETAIN; const subnetGroup = props.subnetGroup ?? new subnet_group_1.ClusterSubnetGroup(this, 'Subnets', { description: `Subnets for ${id} Redshift cluster`, vpc: this.vpc, vpcSubnets: this.vpcSubnets, removalPolicy: removalPolicy, }); const securityGroups = props.securityGroups ?? [new ec2.SecurityGroup(this, 'SecurityGroup', { description: 'Redshift security group', vpc: this.vpc, })]; const securityGroupIds = securityGroups.map(sg => sg.securityGroupId); let secret; if (!props.masterUser.masterPassword) { secret = new database_secret_1.DatabaseSecret(this, 'Secret', { username: props.masterUser.masterUsername, encryptionKey: props.masterUser.encryptionKey, excludeCharacters: props.masterUser.excludeCharacters, }); } const clusterType = props.clusterType || ClusterType.MULTI_NODE; const nodeCount = this.validateNodeCount(clusterType, props.numberOfNodes); if (props.encrypted === false && props.encryptionKey !== undefined) { throw new Error('Cannot set property encryptionKey without enabling encryption!'); } this.singleUserRotationApplication = secretsmanager.SecretRotationApplication.REDSHIFT_ROTATION_SINGLE_USER; this.multiUserRotationApplication = secretsmanager.SecretRotationApplication.REDSHIFT_ROTATION_MULTI_USER; let loggingProperties; if (props.loggingProperties) { loggingProperties = { bucketName: props.loggingProperties.loggingBucket.bucketName, s3KeyPrefix: props.loggingProperties.loggingKeyPrefix, }; props.loggingProperties.loggingBucket.addToResourcePolicy(new iam.PolicyStatement({ actions: [ 's3:GetBucketAcl', 's3:PutObject', ], resources: [ props.loggingProperties.loggingBucket.arnForObjects('*'), props.loggingProperties.loggingBucket.bucketArn, ], principals: [ new iam.ServicePrincipal('redshift.amazonaws.com'), ], })); } const nodeType = props.nodeType || NodeType.DC2_LARGE; if (props.multiAz) { if (!nodeType.startsWith('ra3')) { throw new Error(`Multi-AZ cluster is only supported for RA3 node types, got: ${props.nodeType}`); } if (clusterType === ClusterType.SINGLE_NODE) { throw new Error('Multi-AZ cluster is not supported for `clusterType` single-node'); } } if (props.resourceAction === ResourceAction.FAILOVER_PRIMARY_COMPUTE && !props.multiAz) { throw new Error('ResourceAction.FAILOVER_PRIMARY_COMPUTE can only be used with multi-AZ clusters.'); } if (props.availabilityZoneRelocation && !nodeType.startsWith('ra3')) { throw new Error(`Availability zone relocation is supported for only RA3 node types, got: ${props.nodeType}`); } this.cluster = new aws_redshift_1.CfnCluster(this, 'Resource', { // Basic allowVersionUpgrade: true, maintenanceTrackName: props.maintenanceTrackName, automatedSnapshotRetentionPeriod: 1, clusterType, clusterIdentifier: props.clusterName, clusterSubnetGroupName: subnetGroup.clusterSubnetGroupName, vpcSecurityGroupIds: securityGroupIds, port: props.port, clusterParameterGroupName: props.parameterGroup && props.parameterGroup.clusterParameterGroupName, // Admin (unsafeUnwrap here is safe) masterUsername: secret?.secretValueFromJson('username').unsafeUnwrap() ?? props.masterUser.masterUsername, masterUserPassword: secret?.secretValueFromJson('password').unsafeUnwrap() ?? props.masterUser.masterPassword?.unsafeUnwrap() ?? 'default', preferredMaintenanceWindow: props.preferredMaintenanceWindow, nodeType, numberOfNodes: nodeCount, loggingProperties, iamRoles: core_1.Lazy.list({ produce: () => this.roles.map(role => role.roleArn) }, { omitEmpty: true }), dbName: props.defaultDatabaseName || 'default_db', publiclyAccessible: props.publiclyAccessible || false, // Encryption kmsKeyId: props.encryptionKey?.keyId, encrypted: props.encrypted ?? true, classic: props.classicResizing, elasticIp: props.elasticIp, enhancedVpcRouting: props.enhancedVpcRouting, multiAz: props.multiAz, resourceAction: props.resourceAction, availabilityZoneRelocation: props.availabilityZoneRelocation, }); this.cluster.applyRemovalPolicy(removalPolicy, { applyToUpdateReplacePolicy: true, }); this.clusterName = this.cluster.ref; // create a number token that represents the port of the cluster const portAttribute = core_1.Token.asNumber(this.cluster.attrEndpointPort); this.clusterEndpoint = new endpoint_1.Endpoint(this.cluster.attrEndpointAddress, portAttribute); if (secret) { this.secret = secret.attach(this); } const defaultPort = ec2.Port.tcp(this.clusterEndpoint.port); this.connections = new ec2.Connections({ securityGroups, defaultPort }); if (props.rebootForParameterChanges) { this.enableRebootForParameterChanges(); } // Add default role if specified and also available in the roles list if (props.defaultRole) { if (props.roles?.some(x => x === props.defaultRole)) { this.addDefaultIamRole(props.defaultRole); } else { throw new Error('Default role must be included in role list.'); } } } /** * Adds the single user rotation of the master password to this cluster. * * @param [automaticallyAfter=Duration.days(30)] Specifies the number of days after the previous rotation * before Secrets Manager triggers the next automatic rotation. */ addRotationSingleUser(automaticallyAfter) { if (!this.secret) { throw new Error('Cannot add single user rotation for a cluster without secret.'); } const id = 'RotationSingleUser'; const existing = this.node.tryFindChild(id); if (existing) { throw new Error('A single user rotation was already added to this cluster.'); } return new secretsmanager.SecretRotation(this, id, { secret: this.secret, automaticallyAfter, application: this.singleUserRotationApplication, vpc: this.vpc, vpcSubnets: this.vpcSubnets, target: this, }); } /** * Adds the multi user rotation to this cluster. */ addRotationMultiUser(id, options) { try { jsiiDeprecationWarnings._aws_cdk_aws_redshift_alpha_RotationMultiUserOptions(options); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.addRotationMultiUser); } throw error; } if (!this.secret) { throw new Error('Cannot add multi user rotation for a cluster without secret.'); } return new secretsmanager.SecretRotation(this, id, { secret: options.secret, masterSecret: this.secret, automaticallyAfter: options.automaticallyAfter, application: this.multiUserRotationApplication, vpc: this.vpc, vpcSubnets: this.vpcSubnets, target: this, }); } validateNodeCount(clusterType, numberOfNodes) { if (clusterType === ClusterType.SINGLE_NODE) { // This property must not be set for single-node clusters; be generous and treat a value of 1 node as undefined. if (numberOfNodes !== undefined && numberOfNodes !== 1) { throw new Error('Number of nodes must be not be supplied or be 1 for cluster type single-node'); } return undefined; } else { if (core_1.Token.isUnresolved(numberOfNodes)) { return numberOfNodes; } const nodeCount = numberOfNodes ?? 2; if (nodeCount < 2 || nodeCount > 100) { throw new Error('Number of nodes for cluster type multi-node must be at least 2 and no more than 100'); } return nodeCount; } } /** * Adds a parameter to the Clusters' parameter group * * @param name the parameter name * @param value the parameter name */ addToParameterGroup(name, value) { if (!this.parameterGroup) { const param = {}; param[name] = value; this.parameterGroup = new parameter_group_1.ClusterParameterGroup(this, 'ParameterGroup', { description: this.cluster.clusterIdentifier ? `Parameter Group for the ${this.cluster.clusterIdentifier} Redshift cluster` : 'Cluster parameter group for family redshift-1.0', parameters: param, }); this.cluster.clusterParameterGroupName = this.parameterGroup.clusterParameterGroupName; } else if (this.parameterGroup instanceof parameter_group_1.ClusterParameterGroup) { this.parameterGroup.addParameter(name, value); } else { throw new Error('Cannot add a parameter to an imported parameter group.'); } } /** * Enables automatic cluster rebooting when changes to the cluster's parameter group require a restart to apply. */ enableRebootForParameterChanges() { if (this.node.tryFindChild('RedshiftClusterRebooterCustomResource')) { return; } const rebootFunction = new lambda.SingletonFunction(this, 'RedshiftClusterRebooterFunction', { uuid: '511e207f-13df-4b8b-b632-c32b30b65ac2', runtime: lambda.determineLatestNodeRuntime(this), code: lambda.Code.fromAsset(path.join(__dirname, '..', 'custom-resource-handlers', 'dist', 'aws-redshift-alpha', 'cluster-parameter-change-reboot-handler')), handler: 'index.handler', timeout: core_1.Duration.seconds(900), }); rebootFunction.addToRolePolicy(new iam.PolicyStatement({ actions: ['redshift:DescribeClusters'], resources: ['*'], })); rebootFunction.addToRolePolicy(new iam.PolicyStatement({ actions: ['redshift:RebootCluster'], resources: [ core_1.Stack.of(this).formatArn({ service: 'redshift', resource: 'cluster', resourceName: this.clusterName, arnFormat: core_1.ArnFormat.COLON_RESOURCE_NAME, }), ], })); const provider = new custom_resources_1.Provider(this, 'ResourceProvider', { onEventHandler: rebootFunction, }); const customResource = new core_1.CustomResource(this, 'RedshiftClusterRebooterCustomResource', { resourceType: 'Custom::RedshiftClusterRebooter', serviceToken: provider.serviceToken, properties: { ClusterId: this.clusterName, ParameterGroupName: core_1.Lazy.string({ produce: () => { if (!this.parameterGroup) { throw new Error('Cannot enable reboot for parameter changes when there is no associated ClusterParameterGroup.'); } return this.parameterGroup.clusterParameterGroupName; }, }), ParametersString: core_1.Lazy.string({ produce: () => { if (!(this.parameterGroup instanceof parameter_group_1.ClusterParameterGroup)) { throw new Error('Cannot enable reboot for parameter changes when using an imported parameter group.'); } return JSON.stringify(this.parameterGroup.parameters); }, }), }, }); core_1.Lazy.any({ produce: () => { if (!this.parameterGroup) { throw new Error('Cannot enable reboot for parameter changes when there is no associated ClusterParameterGroup.'); } customResource.node.addDependency(this, this.parameterGroup); }, }); } /** * Adds default IAM role to cluster. The default IAM role must be already associated to the cluster to be added as the default role. * * @param defaultIamRole the IAM role to be set as the default role */ addDefaultIamRole(defaultIamRole) { // Get list of IAM roles attached to cluster const clusterRoleList = this.roles ?? []; // Check to see if default role is included in list of cluster IAM roles var roleAlreadyOnCluster = false; for (var i = 0; i < clusterRoleList.length; i++) { if (clusterRoleList[i] === defaultIamRole) { roleAlreadyOnCluster = true; break; } } if (!roleAlreadyOnCluster) { throw new Error('Default role must be associated to the Redshift cluster to be set as the default role.'); } // On UPDATE or CREATE define the default IAM role. On DELETE, remove the default IAM role const defaultRoleCustomResource = new custom_resources_1.AwsCustomResource(this, 'default-role', { onUpdate: { service: 'Redshift', action: 'modifyClusterIamRoles', parameters: { ClusterIdentifier: this.cluster.ref, DefaultIamRoleArn: defaultIamRole.roleArn, }, physicalResourceId: custom_resources_1.PhysicalResourceId.of(`${defaultIamRole.roleArn}-${this.cluster.ref}`), }, onDelete: { service: 'Redshift', action: 'modifyClusterIamRoles', parameters: { ClusterIdentifier: this.cluster.ref, DefaultIamRoleArn: '', }, physicalResourceId: custom_resources_1.PhysicalResourceId.of(`${defaultIamRole.roleArn}-${this.cluster.ref}`), }, policy: custom_resources_1.AwsCustomResourcePolicy.fromSdkCalls({ resources: custom_resources_1.AwsCustomResourcePolicy.ANY_RESOURCE, }), installLatestAwsSdk: false, }); defaultIamRole.grantPassRole(defaultRoleCustomResource.grantPrincipal); } /** * Adds a role to the cluster * * @param role the role to add */ addIamRole(role) { const clusterRoleList = this.roles; if (clusterRoleList.includes(role)) { throw new Error(`Role '${role.roleArn}' is already attached to the cluster`); } clusterRoleList.push(role); } }; exports.Cluster = Cluster; _a = JSII_RTTI_SYMBOL_1; Cluster[_a] = { fqn: "@aws-cdk/aws-redshift-alpha.Cluster", version: "2.211.0-alpha.0" }; /** Uniquely identifies this class. */ Cluster.PROPERTY_INJECTION_ID = '@aws-cdk.aws-redshift-alpha.Cluster'; __decorate([ (0, metadata_resource_1.MethodMetadata)() ], Cluster.prototype, "addRotationSingleUser", null); __decorate([ (0, metadata_resource_1.MethodMetadata)() ], Cluster.prototype, "addRotationMultiUser", null); __decorate([ (0, metadata_resource_1.MethodMetadata)() ], Cluster.prototype, "addToParameterGroup", null); __decorate([ (0, metadata_resource_1.MethodMetadata)() ], Cluster.prototype, "enableRebootForParameterChanges", null); __decorate([ (0, metadata_resource_1.MethodMetadata)() ], Cluster.prototype, "addDefaultIamRole", null); __decorate([ (0, metadata_resource_1.MethodMetadata)() ], Cluster.prototype, "addIamRole", null); exports.Cluster = Cluster = __decorate([ prop_injectable_1.propertyInjectable ], Cluster); //# sourceMappingURL=data:application/json;base64,