Skip to main content

aws_sdk_kms/operation/
create_custom_key_store.rs

1// Code generated by software.amazon.smithy.rust.codegen.smithy-rs. DO NOT EDIT.
2/// Orchestration and serialization glue logic for `CreateCustomKeyStore`.
3#[derive(::std::clone::Clone, ::std::default::Default, ::std::fmt::Debug)]
4#[non_exhaustive]
5pub struct CreateCustomKeyStore;
6impl CreateCustomKeyStore {
7    /// Creates a new `CreateCustomKeyStore`
8    pub fn new() -> Self {
9        Self
10    }
11    pub(crate) async fn orchestrate(
12        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
13        input: crate::operation::create_custom_key_store::CreateCustomKeyStoreInput,
14    ) -> ::std::result::Result<
15        crate::operation::create_custom_key_store::CreateCustomKeyStoreOutput,
16        ::aws_smithy_runtime_api::client::result::SdkError<
17            crate::operation::create_custom_key_store::CreateCustomKeyStoreError,
18            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
19        >,
20    > {
21        let map_err = |err: ::aws_smithy_runtime_api::client::result::SdkError<
22            ::aws_smithy_runtime_api::client::interceptors::context::Error,
23            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
24        >| {
25            err.map_service_error(|err| {
26                err.downcast::<crate::operation::create_custom_key_store::CreateCustomKeyStoreError>()
27                    .expect("correct error type")
28            })
29        };
30        let context = Self::orchestrate_with_stop_point(runtime_plugins, input, ::aws_smithy_runtime::client::orchestrator::StopPoint::None)
31            .await
32            .map_err(map_err)?;
33        let output = context.finalize().map_err(map_err)?;
34        ::std::result::Result::Ok(
35            output
36                .downcast::<crate::operation::create_custom_key_store::CreateCustomKeyStoreOutput>()
37                .expect("correct output type"),
38        )
39    }
40
41    pub(crate) async fn orchestrate_with_stop_point(
42        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
43        input: crate::operation::create_custom_key_store::CreateCustomKeyStoreInput,
44        stop_point: ::aws_smithy_runtime::client::orchestrator::StopPoint,
45    ) -> ::std::result::Result<
46        ::aws_smithy_runtime_api::client::interceptors::context::InterceptorContext,
47        ::aws_smithy_runtime_api::client::result::SdkError<
48            ::aws_smithy_runtime_api::client::interceptors::context::Error,
49            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
50        >,
51    > {
52        let input = ::aws_smithy_runtime_api::client::interceptors::context::Input::erase(input);
53        use ::tracing::Instrument;
54        ::aws_smithy_runtime::client::orchestrator::invoke_with_stop_point("KMS", "CreateCustomKeyStore", input, runtime_plugins, stop_point)
55            // Create a parent span for the entire operation. Includes a random, internal-only,
56            // seven-digit ID for the operation orchestration so that it can be correlated in the logs.
57            .instrument(::tracing::debug_span!(
58                "KMS.CreateCustomKeyStore",
59                "rpc.service" = "KMS",
60                "rpc.method" = "CreateCustomKeyStore",
61                "sdk_invocation_id" = ::fastrand::u32(1_000_000..10_000_000),
62                "rpc.system" = "aws-api",
63            ))
64            .await
65    }
66
67    pub(crate) fn operation_runtime_plugins(
68        client_runtime_plugins: ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
69        client_config: &crate::config::Config,
70        config_override: ::std::option::Option<crate::config::Builder>,
71    ) -> ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins {
72        let mut runtime_plugins = client_runtime_plugins.with_operation_plugin(Self::new());
73
74        if let ::std::option::Option::Some(config_override) = config_override {
75            for plugin in config_override.runtime_plugins.iter().cloned() {
76                runtime_plugins = runtime_plugins.with_operation_plugin(plugin);
77            }
78            runtime_plugins = runtime_plugins.with_operation_plugin(crate::config::ConfigOverrideRuntimePlugin::new(
79                config_override,
80                client_config.config.clone(),
81                &client_config.runtime_components,
82            ));
83        }
84        runtime_plugins
85    }
86}
87impl ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugin for CreateCustomKeyStore {
88    fn config(&self) -> ::std::option::Option<::aws_smithy_types::config_bag::FrozenLayer> {
89        let mut cfg = ::aws_smithy_types::config_bag::Layer::new("CreateCustomKeyStore");
90
91        cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedRequestSerializer::new(
92            CreateCustomKeyStoreRequestSerializer,
93        ));
94        cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedResponseDeserializer::new(
95            CreateCustomKeyStoreResponseDeserializer,
96        ));
97
98        cfg.store_put(::aws_smithy_runtime_api::client::auth::AuthSchemeOptionResolverParams::new(
99            crate::config::auth::Params::builder()
100                .operation_name("CreateCustomKeyStore")
101                .build()
102                .expect("required fields set"),
103        ));
104
105        cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::Metadata::new(
106            "CreateCustomKeyStore",
107            "KMS",
108        ));
109        let mut signing_options = ::aws_runtime::auth::SigningOptions::default();
110        signing_options.double_uri_encode = true;
111        signing_options.content_sha256_header = false;
112        signing_options.normalize_uri_path = true;
113        signing_options.payload_override = None;
114
115        cfg.store_put(::aws_runtime::auth::SigV4OperationSigningConfig {
116            signing_options,
117            ..::std::default::Default::default()
118        });
119
120        ::std::option::Option::Some(cfg.freeze())
121    }
122
123    fn runtime_components(
124        &self,
125        _: &::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder,
126    ) -> ::std::borrow::Cow<'_, ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder> {
127        #[allow(unused_mut)]
128        let mut rcb = ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder::new("CreateCustomKeyStore")
129            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
130                CreateCustomKeyStoreTelemetryInputCaptureInterceptor,
131            ))
132            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
133                ::aws_smithy_runtime::client::stalled_stream_protection::StalledStreamProtectionInterceptor::default(),
134            ))
135            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
136                CreateCustomKeyStoreEndpointParamsInterceptor,
137            ))
138            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::TransientErrorClassifier::<
139                crate::operation::create_custom_key_store::CreateCustomKeyStoreError,
140            >::new())
141            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::ModeledAsRetryableClassifier::<
142                crate::operation::create_custom_key_store::CreateCustomKeyStoreError,
143            >::new())
144            .with_retry_classifier(::aws_runtime::retries::classifiers::AwsErrorCodeClassifier::<
145                crate::operation::create_custom_key_store::CreateCustomKeyStoreError,
146            >::new());
147
148        ::std::borrow::Cow::Owned(rcb)
149    }
150}
151
152#[derive(Debug)]
153struct CreateCustomKeyStoreTelemetryInputCaptureInterceptor;
154
155#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
156impl ::aws_smithy_runtime_api::client::interceptors::Intercept for CreateCustomKeyStoreTelemetryInputCaptureInterceptor {
157    fn name(&self) -> &'static str {
158        "CreateCustomKeyStoreTelemetryInputCaptureInterceptor"
159    }
160
161    fn read_before_execution(
162        &self,
163        context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
164            '_,
165            ::aws_smithy_runtime_api::client::interceptors::context::Input,
166            ::aws_smithy_runtime_api::client::interceptors::context::Output,
167            ::aws_smithy_runtime_api::client::interceptors::context::Error,
168        >,
169        cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
170    ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
171        // Nothing to do unless the customer opted in by naming members to record.
172        let ::std::option::Option::Some(requested) = cfg
173            .load::<::aws_smithy_types::telemetry::RequestedTelemetryAttributes>()
174            .filter(|r| !r.is_empty())
175        else {
176            return ::std::result::Result::Ok(());
177        };
178
179        let ::std::option::Option::Some(input) = context.input().downcast_ref::<CreateCustomKeyStoreInput>() else {
180            // A mismatched input is not this interceptor's concern; skip quietly.
181            return ::std::result::Result::Ok(());
182        };
183
184        let mut captured = ::aws_smithy_types::telemetry::CapturedTelemetryAttributes::default();
185        if requested.should_capture("CustomKeyStoreName") {
186            if let ::std::option::Option::Some(value) = input.custom_key_store_name.as_deref() {
187                captured.insert("CustomKeyStoreName", value);
188            }
189        }
190        if requested.should_capture("CloudHsmClusterId") {
191            if let ::std::option::Option::Some(value) = input.cloud_hsm_cluster_id.as_deref() {
192                captured.insert("CloudHsmClusterId", value);
193            }
194        }
195        if requested.should_capture("TrustAnchorCertificate") {
196            if let ::std::option::Option::Some(value) = input.trust_anchor_certificate.as_deref() {
197                captured.insert("TrustAnchorCertificate", value);
198            }
199        }
200        if requested.should_capture("XksProxyUriEndpoint") {
201            if let ::std::option::Option::Some(value) = input.xks_proxy_uri_endpoint.as_deref() {
202                captured.insert("XksProxyUriEndpoint", value);
203            }
204        }
205        if requested.should_capture("XksProxyUriPath") {
206            if let ::std::option::Option::Some(value) = input.xks_proxy_uri_path.as_deref() {
207                captured.insert("XksProxyUriPath", value);
208            }
209        }
210        if requested.should_capture("XksProxyVpcEndpointServiceName") {
211            if let ::std::option::Option::Some(value) = input.xks_proxy_vpc_endpoint_service_name.as_deref() {
212                captured.insert("XksProxyVpcEndpointServiceName", value);
213            }
214        }
215        if requested.should_capture("XksProxyVpcEndpointServiceOwner") {
216            if let ::std::option::Option::Some(value) = input.xks_proxy_vpc_endpoint_service_owner.as_deref() {
217                captured.insert("XksProxyVpcEndpointServiceOwner", value);
218            }
219        }
220
221        cfg.interceptor_state().store_put(captured);
222        ::std::result::Result::Ok(())
223    }
224}
225#[derive(Debug)]
226struct CreateCustomKeyStoreResponseDeserializer;
227impl ::aws_smithy_runtime_api::client::ser_de::DeserializeResponse for CreateCustomKeyStoreResponseDeserializer {
228    fn deserialize_nonstreaming_with_config(
229        &self,
230        response: &::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
231        _cfg: &::aws_smithy_types::config_bag::ConfigBag,
232    ) -> ::aws_smithy_runtime_api::client::interceptors::context::OutputOrError {
233        let (success, status) = (response.status().is_success(), response.status().as_u16());
234        let headers = response.headers();
235        let body = response.body().bytes().expect("body loaded");
236        #[allow(unused_mut)]
237        let mut force_error = false;
238        ::tracing::debug!(request_id = ?::aws_types::request_id::RequestId::request_id(response));
239        let parse_result = if !success && status != 200 || force_error {
240            crate::protocol_serde::shape_create_custom_key_store::de_create_custom_key_store_http_error(status, headers, body)
241        } else {
242            crate::protocol_serde::shape_create_custom_key_store::de_create_custom_key_store_http_response(status, headers, body)
243        };
244        crate::protocol_serde::type_erase_result(parse_result)
245    }
246}
247#[derive(Debug)]
248struct CreateCustomKeyStoreRequestSerializer;
249impl ::aws_smithy_runtime_api::client::ser_de::SerializeRequest for CreateCustomKeyStoreRequestSerializer {
250    #[allow(unused_mut, clippy::let_and_return, clippy::needless_borrow, clippy::useless_conversion)]
251    fn serialize_input(
252        &self,
253        input: ::aws_smithy_runtime_api::client::interceptors::context::Input,
254        _cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
255    ) -> ::std::result::Result<::aws_smithy_runtime_api::client::orchestrator::HttpRequest, ::aws_smithy_runtime_api::box_error::BoxError> {
256        let input = input
257            .downcast::<crate::operation::create_custom_key_store::CreateCustomKeyStoreInput>()
258            .expect("correct type");
259        let _header_serialization_settings = _cfg
260            .load::<crate::serialization_settings::HeaderSerializationSettings>()
261            .cloned()
262            .unwrap_or_default();
263        let mut request_builder = {
264            #[allow(clippy::uninlined_format_args)]
265            fn uri_base(
266                _input: &crate::operation::create_custom_key_store::CreateCustomKeyStoreInput,
267                output: &mut ::std::string::String,
268            ) -> ::std::result::Result<(), ::aws_smithy_types::error::operation::BuildError> {
269                use ::std::fmt::Write as _;
270                ::std::write!(output, "/").expect("formatting should succeed");
271                ::std::result::Result::Ok(())
272            }
273            #[allow(clippy::unnecessary_wraps)]
274            fn update_http_builder(
275                input: &crate::operation::create_custom_key_store::CreateCustomKeyStoreInput,
276                builder: ::http_1x::request::Builder,
277            ) -> ::std::result::Result<::http_1x::request::Builder, ::aws_smithy_types::error::operation::BuildError> {
278                let mut uri = ::std::string::String::new();
279                uri_base(input, &mut uri)?;
280                ::std::result::Result::Ok(builder.method("POST").uri(uri))
281            }
282            let mut builder = update_http_builder(&input, ::http_1x::request::Builder::new())?;
283            builder = _header_serialization_settings.set_default_header(builder, ::http_1x::header::CONTENT_TYPE, "application/x-amz-json-1.1");
284            builder = _header_serialization_settings.set_default_header(
285                builder,
286                ::http_1x::header::HeaderName::from_static("x-amz-target"),
287                "TrentService.CreateCustomKeyStore",
288            );
289            builder
290        };
291        let body = ::aws_smithy_types::body::SdkBody::from(crate::protocol_serde::shape_create_custom_key_store::ser_create_custom_key_store_input(
292            &input,
293        )?);
294        if let Some(content_length) = body.content_length() {
295            let content_length = content_length.to_string();
296            request_builder = _header_serialization_settings.set_default_header(request_builder, ::http_1x::header::CONTENT_LENGTH, &content_length);
297        }
298        ::std::result::Result::Ok(request_builder.body(body).expect("valid request").try_into().unwrap())
299    }
300}
301#[derive(Debug)]
302struct CreateCustomKeyStoreEndpointParamsInterceptor;
303
304#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
305impl ::aws_smithy_runtime_api::client::interceptors::Intercept for CreateCustomKeyStoreEndpointParamsInterceptor {
306    fn name(&self) -> &'static str {
307        "CreateCustomKeyStoreEndpointParamsInterceptor"
308    }
309
310    fn read_before_execution(
311        &self,
312        context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
313            '_,
314            ::aws_smithy_runtime_api::client::interceptors::context::Input,
315            ::aws_smithy_runtime_api::client::interceptors::context::Output,
316            ::aws_smithy_runtime_api::client::interceptors::context::Error,
317        >,
318        cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
319    ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
320        let _input = context
321            .input()
322            .downcast_ref::<CreateCustomKeyStoreInput>()
323            .ok_or("failed to downcast to CreateCustomKeyStoreInput")?;
324
325        let params = crate::config::endpoint::Params::builder()
326            .set_region(cfg.load::<::aws_types::region::Region>().map(|r| r.as_ref().to_owned()))
327            .set_use_dual_stack(cfg.load::<::aws_types::endpoint_config::UseDualStack>().map(|ty| ty.0))
328            .set_use_fips(cfg.load::<::aws_types::endpoint_config::UseFips>().map(|ty| ty.0))
329            .set_endpoint(cfg.load::<::aws_types::endpoint_config::EndpointUrl>().map(|ty| ty.0.clone()))
330            .build()
331            .map_err(|err| {
332                ::aws_smithy_runtime_api::client::interceptors::error::ContextAttachedError::new("endpoint params could not be built", err)
333            })?;
334        cfg.interceptor_state()
335            .store_put(::aws_smithy_runtime_api::client::endpoint::EndpointResolverParams::new(params));
336        ::std::result::Result::Ok(())
337    }
338}
339
340// The get_* functions below are generated from JMESPath expressions in the
341// operationContextParams trait. They target the operation's input shape.
342
343/// Error type for the `CreateCustomKeyStoreError` operation.
344#[non_exhaustive]
345#[derive(::std::fmt::Debug)]
346pub enum CreateCustomKeyStoreError {
347    /// <p>The request was rejected because the specified CloudHSM cluster is already associated with an CloudHSM key store in the account, or it shares a backup history with an CloudHSM key store in the account. Each CloudHSM key store in the account must be associated with a different CloudHSM cluster.</p>
348    /// <p>CloudHSM clusters that share a backup history have the same cluster certificate. To view the cluster certificate of an CloudHSM cluster, use the <a href="https://docs.aws.amazon.com/cloudhsm/latest/APIReference/API_DescribeClusters.html">DescribeClusters</a> operation.</p>
349    CloudHsmClusterInUseException(crate::types::error::CloudHsmClusterInUseException),
350    /// <p>The request was rejected because the associated CloudHSM cluster did not meet the configuration requirements for an CloudHSM key store.</p>
351    /// <ul>
352    /// <li>
353    /// <p>The CloudHSM cluster must be configured with private subnets in at least two different Availability Zones in the Region.</p></li>
354    /// <li>
355    /// <p>The <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/configure-sg.html">security group for the cluster</a> (cloudhsm-cluster-<i><cluster-id></cluster-id></i>-sg) must include inbound rules and outbound rules that allow TCP traffic on ports 2223-2225. The <b>Source</b> in the inbound rules and the <b>Destination</b> in the outbound rules must match the security group ID. These rules are set by default when you create the CloudHSM cluster. Do not delete or change them. To get information about a particular security group, use the <a href="https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroups.html">DescribeSecurityGroups</a> operation.</p></li>
356    /// <li>
357    /// <p>The CloudHSM cluster must contain at least as many HSMs as the operation requires. To add HSMs, use the CloudHSM <a href="https://docs.aws.amazon.com/cloudhsm/latest/APIReference/API_CreateHsm.html">CreateHsm</a> operation.</p>
358    /// <p>For the <code>CreateCustomKeyStore</code>, <code>UpdateCustomKeyStore</code>, and <code>CreateKey</code> operations, the CloudHSM cluster must have at least two active HSMs, each in a different Availability Zone. For the <code>ConnectCustomKeyStore</code> operation, the CloudHSM must contain at least one active HSM.</p></li>
359    /// </ul>
360    /// <p>For information about the requirements for an CloudHSM cluster that is associated with an CloudHSM key store, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/create-keystore.html#before-keystore">Assemble the Prerequisites</a> in the <i>Key Management Service Developer Guide</i>. For information about creating a private subnet for an CloudHSM cluster, see <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/create-subnets.html">Create a Private Subnet</a> in the <i>CloudHSM User Guide</i>. For information about cluster security groups, see <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/configure-sg.html">Configure a Default Security Group</a> in the <i> <i>CloudHSM User Guide</i> </i>.</p>
361    CloudHsmClusterInvalidConfigurationException(crate::types::error::CloudHsmClusterInvalidConfigurationException),
362    /// <p>The request was rejected because the CloudHSM cluster associated with the CloudHSM key store is not active. Initialize and activate the cluster and try the command again. For detailed instructions, see <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/getting-started.html">Getting Started</a> in the <i>CloudHSM User Guide</i>.</p>
363    CloudHsmClusterNotActiveException(crate::types::error::CloudHsmClusterNotActiveException),
364    /// <p>The request was rejected because KMS cannot find the CloudHSM cluster with the specified cluster ID. Retry the request with a different cluster ID.</p>
365    CloudHsmClusterNotFoundException(crate::types::error::CloudHsmClusterNotFoundException),
366    /// <p>The request was rejected because the specified custom key store name is already assigned to another custom key store in the account. Try again with a custom key store name that is unique in the account.</p>
367    CustomKeyStoreNameInUseException(crate::types::error::CustomKeyStoreNameInUseException),
368    /// <p>The request was rejected because the trust anchor certificate in the request to create an CloudHSM key store is not the trust anchor certificate for the specified CloudHSM cluster.</p>
369    /// <p>When you <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/initialize-cluster.html#sign-csr">initialize the CloudHSM cluster</a>, you create the trust anchor certificate and save it in the <code>customerCA.crt</code> file.</p>
370    IncorrectTrustAnchorException(crate::types::error::IncorrectTrustAnchorException),
371    /// <p>The request was rejected because an internal exception occurred. The request can be retried.</p>
372    KmsInternalException(crate::types::error::KmsInternalException),
373    /// <p>The request was rejected because a length constraint or quota was exceeded. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/limits.html">Quotas</a> in the <i>Key Management Service Developer Guide</i>.</p>
374    LimitExceededException(crate::types::error::LimitExceededException),
375    /// <p>The request was rejected because the proxy credentials failed to authenticate to the specified external key store proxy. The specified external key store proxy rejected a status request from KMS due to invalid credentials. This can indicate an error in the credentials or in the identification of the external key store proxy.</p>
376    XksProxyIncorrectAuthenticationCredentialException(crate::types::error::XksProxyIncorrectAuthenticationCredentialException),
377    /// <p>The request was rejected because the external key store proxy is not configured correctly. To identify the cause, see the error message that accompanies the exception.</p>
378    XksProxyInvalidConfigurationException(crate::types::error::XksProxyInvalidConfigurationException),
379    /// <p></p>
380    /// <p>KMS cannot interpret the response it received from the external key store proxy. The problem might be a poorly constructed response, but it could also be a transient network issue. If you see this error repeatedly, report it to the proxy vendor.</p>
381    XksProxyInvalidResponseException(crate::types::error::XksProxyInvalidResponseException),
382    /// <p>The request was rejected because the <code>XksProxyUriEndpoint</code> is already associated with another external key store in this Amazon Web Services Region. To identify the cause, see the error message that accompanies the exception.</p>
383    XksProxyUriEndpointInUseException(crate::types::error::XksProxyUriEndpointInUseException),
384    /// <p>The request was rejected because the concatenation of the <code>XksProxyUriEndpoint</code> and <code>XksProxyUriPath</code> is already associated with another external key store in this Amazon Web Services Region. Each external key store in a Region must use a unique external key store proxy API address.</p>
385    XksProxyUriInUseException(crate::types::error::XksProxyUriInUseException),
386    /// <p>KMS was unable to reach the specified <code>XksProxyUriPath</code>. The path must be reachable before you create the external key store or update its settings.</p>
387    /// <p>This exception is also thrown when the external key store proxy response to a <code>GetHealthStatus</code> request indicates that all external key manager instances are unavailable.</p>
388    XksProxyUriUnreachableException(crate::types::error::XksProxyUriUnreachableException),
389    /// <p>The request was rejected because the specified Amazon VPC endpoint service is already associated with another external key store in this Amazon Web Services Region. Each external key store in a Region must use a different Amazon VPC endpoint service.</p>
390    XksProxyVpcEndpointServiceInUseException(crate::types::error::XksProxyVpcEndpointServiceInUseException),
391    /// <p>The request was rejected because the Amazon VPC endpoint service configuration does not fulfill the requirements for an external key store. To identify the cause, see the error message that accompanies the exception and <a href="https://docs.aws.amazon.com/kms/latest/developerguide/vpc-connectivity.html#xks-vpc-requirements">review the requirements</a> for Amazon VPC endpoint service connectivity for an external key store.</p>
392    XksProxyVpcEndpointServiceInvalidConfigurationException(crate::types::error::XksProxyVpcEndpointServiceInvalidConfigurationException),
393    /// <p>The request was rejected because KMS could not find the specified VPC endpoint service. Use <code>DescribeCustomKeyStores</code> to verify the VPC endpoint service name for the external key store. Also, confirm that the <code>Allow principals</code> list for the VPC endpoint service includes the KMS service principal for the Region, such as <code>cks.kms.us-east-1.amazonaws.com</code>.</p>
394    XksProxyVpcEndpointServiceNotFoundException(crate::types::error::XksProxyVpcEndpointServiceNotFoundException),
395    /// An unexpected error occurred (e.g., invalid JSON returned by the service or an unknown error code).
396    #[deprecated(note = "Matching `Unhandled` directly is not forwards compatible. Instead, match using a \
397    variable wildcard pattern and check `.code()`:
398     \
399    &nbsp;&nbsp;&nbsp;`err if err.code() == Some(\"SpecificExceptionCode\") => { /* handle the error */ }`
400     \
401    See [`ProvideErrorMetadata`](#impl-ProvideErrorMetadata-for-CreateCustomKeyStoreError) for what information is available for the error.")]
402    Unhandled(crate::error::sealed_unhandled::Unhandled),
403}
404impl CreateCustomKeyStoreError {
405    /// Creates the `CreateCustomKeyStoreError::Unhandled` variant from any error type.
406    pub fn unhandled(
407        err: impl ::std::convert::Into<::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>>,
408    ) -> Self {
409        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
410            source: err.into(),
411            meta: ::std::default::Default::default(),
412        })
413    }
414
415    /// Creates the `CreateCustomKeyStoreError::Unhandled` variant from an [`ErrorMetadata`](::aws_smithy_types::error::ErrorMetadata).
416    pub fn generic(err: ::aws_smithy_types::error::ErrorMetadata) -> Self {
417        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
418            source: err.clone().into(),
419            meta: err,
420        })
421    }
422    ///
423    /// Returns error metadata, which includes the error code, message,
424    /// request ID, and potentially additional information.
425    ///
426    pub fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
427        match self {
428            Self::CloudHsmClusterInUseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
429            Self::CloudHsmClusterInvalidConfigurationException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
430            Self::CloudHsmClusterNotActiveException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
431            Self::CloudHsmClusterNotFoundException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
432            Self::CustomKeyStoreNameInUseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
433            Self::IncorrectTrustAnchorException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
434            Self::KmsInternalException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
435            Self::LimitExceededException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
436            Self::XksProxyIncorrectAuthenticationCredentialException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
437            Self::XksProxyInvalidConfigurationException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
438            Self::XksProxyInvalidResponseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
439            Self::XksProxyUriEndpointInUseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
440            Self::XksProxyUriInUseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
441            Self::XksProxyUriUnreachableException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
442            Self::XksProxyVpcEndpointServiceInUseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
443            Self::XksProxyVpcEndpointServiceInvalidConfigurationException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
444            Self::XksProxyVpcEndpointServiceNotFoundException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
445            Self::Unhandled(e) => &e.meta,
446        }
447    }
448    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::CloudHsmClusterInUseException`.
449    pub fn is_cloud_hsm_cluster_in_use_exception(&self) -> bool {
450        matches!(self, Self::CloudHsmClusterInUseException(_))
451    }
452    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::CloudHsmClusterInvalidConfigurationException`.
453    pub fn is_cloud_hsm_cluster_invalid_configuration_exception(&self) -> bool {
454        matches!(self, Self::CloudHsmClusterInvalidConfigurationException(_))
455    }
456    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::CloudHsmClusterNotActiveException`.
457    pub fn is_cloud_hsm_cluster_not_active_exception(&self) -> bool {
458        matches!(self, Self::CloudHsmClusterNotActiveException(_))
459    }
460    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::CloudHsmClusterNotFoundException`.
461    pub fn is_cloud_hsm_cluster_not_found_exception(&self) -> bool {
462        matches!(self, Self::CloudHsmClusterNotFoundException(_))
463    }
464    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::CustomKeyStoreNameInUseException`.
465    pub fn is_custom_key_store_name_in_use_exception(&self) -> bool {
466        matches!(self, Self::CustomKeyStoreNameInUseException(_))
467    }
468    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::IncorrectTrustAnchorException`.
469    pub fn is_incorrect_trust_anchor_exception(&self) -> bool {
470        matches!(self, Self::IncorrectTrustAnchorException(_))
471    }
472    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::KmsInternalException`.
473    pub fn is_kms_internal_exception(&self) -> bool {
474        matches!(self, Self::KmsInternalException(_))
475    }
476    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::LimitExceededException`.
477    pub fn is_limit_exceeded_exception(&self) -> bool {
478        matches!(self, Self::LimitExceededException(_))
479    }
480    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyIncorrectAuthenticationCredentialException`.
481    pub fn is_xks_proxy_incorrect_authentication_credential_exception(&self) -> bool {
482        matches!(self, Self::XksProxyIncorrectAuthenticationCredentialException(_))
483    }
484    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyInvalidConfigurationException`.
485    pub fn is_xks_proxy_invalid_configuration_exception(&self) -> bool {
486        matches!(self, Self::XksProxyInvalidConfigurationException(_))
487    }
488    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyInvalidResponseException`.
489    pub fn is_xks_proxy_invalid_response_exception(&self) -> bool {
490        matches!(self, Self::XksProxyInvalidResponseException(_))
491    }
492    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyUriEndpointInUseException`.
493    pub fn is_xks_proxy_uri_endpoint_in_use_exception(&self) -> bool {
494        matches!(self, Self::XksProxyUriEndpointInUseException(_))
495    }
496    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyUriInUseException`.
497    pub fn is_xks_proxy_uri_in_use_exception(&self) -> bool {
498        matches!(self, Self::XksProxyUriInUseException(_))
499    }
500    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyUriUnreachableException`.
501    pub fn is_xks_proxy_uri_unreachable_exception(&self) -> bool {
502        matches!(self, Self::XksProxyUriUnreachableException(_))
503    }
504    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyVpcEndpointServiceInUseException`.
505    pub fn is_xks_proxy_vpc_endpoint_service_in_use_exception(&self) -> bool {
506        matches!(self, Self::XksProxyVpcEndpointServiceInUseException(_))
507    }
508    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyVpcEndpointServiceInvalidConfigurationException`.
509    pub fn is_xks_proxy_vpc_endpoint_service_invalid_configuration_exception(&self) -> bool {
510        matches!(self, Self::XksProxyVpcEndpointServiceInvalidConfigurationException(_))
511    }
512    /// Returns `true` if the error kind is `CreateCustomKeyStoreError::XksProxyVpcEndpointServiceNotFoundException`.
513    pub fn is_xks_proxy_vpc_endpoint_service_not_found_exception(&self) -> bool {
514        matches!(self, Self::XksProxyVpcEndpointServiceNotFoundException(_))
515    }
516}
517impl ::std::error::Error for CreateCustomKeyStoreError {
518    fn source(&self) -> ::std::option::Option<&(dyn ::std::error::Error + 'static)> {
519        match self {
520            Self::CloudHsmClusterInUseException(_inner) => ::std::option::Option::Some(_inner),
521            Self::CloudHsmClusterInvalidConfigurationException(_inner) => ::std::option::Option::Some(_inner),
522            Self::CloudHsmClusterNotActiveException(_inner) => ::std::option::Option::Some(_inner),
523            Self::CloudHsmClusterNotFoundException(_inner) => ::std::option::Option::Some(_inner),
524            Self::CustomKeyStoreNameInUseException(_inner) => ::std::option::Option::Some(_inner),
525            Self::IncorrectTrustAnchorException(_inner) => ::std::option::Option::Some(_inner),
526            Self::KmsInternalException(_inner) => ::std::option::Option::Some(_inner),
527            Self::LimitExceededException(_inner) => ::std::option::Option::Some(_inner),
528            Self::XksProxyIncorrectAuthenticationCredentialException(_inner) => ::std::option::Option::Some(_inner),
529            Self::XksProxyInvalidConfigurationException(_inner) => ::std::option::Option::Some(_inner),
530            Self::XksProxyInvalidResponseException(_inner) => ::std::option::Option::Some(_inner),
531            Self::XksProxyUriEndpointInUseException(_inner) => ::std::option::Option::Some(_inner),
532            Self::XksProxyUriInUseException(_inner) => ::std::option::Option::Some(_inner),
533            Self::XksProxyUriUnreachableException(_inner) => ::std::option::Option::Some(_inner),
534            Self::XksProxyVpcEndpointServiceInUseException(_inner) => ::std::option::Option::Some(_inner),
535            Self::XksProxyVpcEndpointServiceInvalidConfigurationException(_inner) => ::std::option::Option::Some(_inner),
536            Self::XksProxyVpcEndpointServiceNotFoundException(_inner) => ::std::option::Option::Some(_inner),
537            Self::Unhandled(_inner) => ::std::option::Option::Some(&*_inner.source),
538        }
539    }
540}
541impl ::std::fmt::Display for CreateCustomKeyStoreError {
542    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
543        match self {
544            Self::CloudHsmClusterInUseException(_inner) => _inner.fmt(f),
545            Self::CloudHsmClusterInvalidConfigurationException(_inner) => _inner.fmt(f),
546            Self::CloudHsmClusterNotActiveException(_inner) => _inner.fmt(f),
547            Self::CloudHsmClusterNotFoundException(_inner) => _inner.fmt(f),
548            Self::CustomKeyStoreNameInUseException(_inner) => _inner.fmt(f),
549            Self::IncorrectTrustAnchorException(_inner) => _inner.fmt(f),
550            Self::KmsInternalException(_inner) => _inner.fmt(f),
551            Self::LimitExceededException(_inner) => _inner.fmt(f),
552            Self::XksProxyIncorrectAuthenticationCredentialException(_inner) => _inner.fmt(f),
553            Self::XksProxyInvalidConfigurationException(_inner) => _inner.fmt(f),
554            Self::XksProxyInvalidResponseException(_inner) => _inner.fmt(f),
555            Self::XksProxyUriEndpointInUseException(_inner) => _inner.fmt(f),
556            Self::XksProxyUriInUseException(_inner) => _inner.fmt(f),
557            Self::XksProxyUriUnreachableException(_inner) => _inner.fmt(f),
558            Self::XksProxyVpcEndpointServiceInUseException(_inner) => _inner.fmt(f),
559            Self::XksProxyVpcEndpointServiceInvalidConfigurationException(_inner) => _inner.fmt(f),
560            Self::XksProxyVpcEndpointServiceNotFoundException(_inner) => _inner.fmt(f),
561            Self::Unhandled(_inner) => {
562                if let ::std::option::Option::Some(code) = ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self) {
563                    write!(f, "unhandled error ({code})")
564                } else {
565                    f.write_str("unhandled error")
566                }
567            }
568        }
569    }
570}
571impl ::aws_smithy_types::retry::ProvideErrorKind for CreateCustomKeyStoreError {
572    fn code(&self) -> ::std::option::Option<&str> {
573        ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self)
574    }
575    fn retryable_error_kind(&self) -> ::std::option::Option<::aws_smithy_types::retry::ErrorKind> {
576        ::std::option::Option::None
577    }
578}
579impl ::aws_smithy_types::error::metadata::ProvideErrorMetadata for CreateCustomKeyStoreError {
580    fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
581        match self {
582            Self::CloudHsmClusterInUseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
583            Self::CloudHsmClusterInvalidConfigurationException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
584            Self::CloudHsmClusterNotActiveException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
585            Self::CloudHsmClusterNotFoundException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
586            Self::CustomKeyStoreNameInUseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
587            Self::IncorrectTrustAnchorException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
588            Self::KmsInternalException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
589            Self::LimitExceededException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
590            Self::XksProxyIncorrectAuthenticationCredentialException(_inner) => {
591                ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
592            }
593            Self::XksProxyInvalidConfigurationException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
594            Self::XksProxyInvalidResponseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
595            Self::XksProxyUriEndpointInUseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
596            Self::XksProxyUriInUseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
597            Self::XksProxyUriUnreachableException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
598            Self::XksProxyVpcEndpointServiceInUseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
599            Self::XksProxyVpcEndpointServiceInvalidConfigurationException(_inner) => {
600                ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
601            }
602            Self::XksProxyVpcEndpointServiceNotFoundException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
603            Self::Unhandled(_inner) => &_inner.meta,
604        }
605    }
606}
607impl ::aws_smithy_runtime_api::client::result::CreateUnhandledError for CreateCustomKeyStoreError {
608    fn create_unhandled_error(
609        source: ::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>,
610        meta: ::std::option::Option<::aws_smithy_types::error::ErrorMetadata>,
611    ) -> Self {
612        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
613            source,
614            meta: meta.unwrap_or_default(),
615        })
616    }
617}
618impl ::aws_types::request_id::RequestId for crate::operation::create_custom_key_store::CreateCustomKeyStoreError {
619    fn request_id(&self) -> Option<&str> {
620        self.meta().request_id()
621    }
622}
623
624pub use crate::operation::create_custom_key_store::_create_custom_key_store_input::CreateCustomKeyStoreInput;
625
626pub use crate::operation::create_custom_key_store::_create_custom_key_store_output::CreateCustomKeyStoreOutput;
627
628mod _create_custom_key_store_input;
629
630mod _create_custom_key_store_output;
631
632/// Builders
633pub mod builders;