Skip to main content

aws_sdk_kms/operation/
create_key.rs

1// Code generated by software.amazon.smithy.rust.codegen.smithy-rs. DO NOT EDIT.
2/// Orchestration and serialization glue logic for `CreateKey`.
3#[derive(::std::clone::Clone, ::std::default::Default, ::std::fmt::Debug)]
4#[non_exhaustive]
5pub struct CreateKey;
6impl CreateKey {
7    /// Creates a new `CreateKey`
8    pub fn new() -> Self {
9        Self
10    }
11    pub(crate) async fn orchestrate(
12        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
13        input: crate::operation::create_key::CreateKeyInput,
14    ) -> ::std::result::Result<
15        crate::operation::create_key::CreateKeyOutput,
16        ::aws_smithy_runtime_api::client::result::SdkError<
17            crate::operation::create_key::CreateKeyError,
18            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
19        >,
20    > {
21        let map_err = |err: ::aws_smithy_runtime_api::client::result::SdkError<
22            ::aws_smithy_runtime_api::client::interceptors::context::Error,
23            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
24        >| {
25            err.map_service_error(|err| {
26                err.downcast::<crate::operation::create_key::CreateKeyError>()
27                    .expect("correct error type")
28            })
29        };
30        let context = Self::orchestrate_with_stop_point(runtime_plugins, input, ::aws_smithy_runtime::client::orchestrator::StopPoint::None)
31            .await
32            .map_err(map_err)?;
33        let output = context.finalize().map_err(map_err)?;
34        ::std::result::Result::Ok(
35            output
36                .downcast::<crate::operation::create_key::CreateKeyOutput>()
37                .expect("correct output type"),
38        )
39    }
40
41    pub(crate) async fn orchestrate_with_stop_point(
42        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
43        input: crate::operation::create_key::CreateKeyInput,
44        stop_point: ::aws_smithy_runtime::client::orchestrator::StopPoint,
45    ) -> ::std::result::Result<
46        ::aws_smithy_runtime_api::client::interceptors::context::InterceptorContext,
47        ::aws_smithy_runtime_api::client::result::SdkError<
48            ::aws_smithy_runtime_api::client::interceptors::context::Error,
49            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
50        >,
51    > {
52        let input = ::aws_smithy_runtime_api::client::interceptors::context::Input::erase(input);
53        use ::tracing::Instrument;
54        ::aws_smithy_runtime::client::orchestrator::invoke_with_stop_point("KMS", "CreateKey", input, runtime_plugins, stop_point)
55            // Create a parent span for the entire operation. Includes a random, internal-only,
56            // seven-digit ID for the operation orchestration so that it can be correlated in the logs.
57            .instrument(::tracing::debug_span!(
58                "KMS.CreateKey",
59                "rpc.service" = "KMS",
60                "rpc.method" = "CreateKey",
61                "sdk_invocation_id" = ::fastrand::u32(1_000_000..10_000_000),
62                "rpc.system" = "aws-api",
63            ))
64            .await
65    }
66
67    pub(crate) fn operation_runtime_plugins(
68        client_runtime_plugins: ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
69        client_config: &crate::config::Config,
70        config_override: ::std::option::Option<crate::config::Builder>,
71    ) -> ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins {
72        let mut runtime_plugins = client_runtime_plugins.with_operation_plugin(Self::new());
73
74        if let ::std::option::Option::Some(config_override) = config_override {
75            for plugin in config_override.runtime_plugins.iter().cloned() {
76                runtime_plugins = runtime_plugins.with_operation_plugin(plugin);
77            }
78            runtime_plugins = runtime_plugins.with_operation_plugin(crate::config::ConfigOverrideRuntimePlugin::new(
79                config_override,
80                client_config.config.clone(),
81                &client_config.runtime_components,
82            ));
83        }
84        runtime_plugins
85    }
86}
87impl ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugin for CreateKey {
88    fn config(&self) -> ::std::option::Option<::aws_smithy_types::config_bag::FrozenLayer> {
89        let mut cfg = ::aws_smithy_types::config_bag::Layer::new("CreateKey");
90
91        cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedRequestSerializer::new(
92            CreateKeyRequestSerializer,
93        ));
94        cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedResponseDeserializer::new(
95            CreateKeyResponseDeserializer,
96        ));
97
98        cfg.store_put(::aws_smithy_runtime_api::client::auth::AuthSchemeOptionResolverParams::new(
99            crate::config::auth::Params::builder()
100                .operation_name("CreateKey")
101                .build()
102                .expect("required fields set"),
103        ));
104
105        cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::Metadata::new("CreateKey", "KMS"));
106        let mut signing_options = ::aws_runtime::auth::SigningOptions::default();
107        signing_options.double_uri_encode = true;
108        signing_options.content_sha256_header = false;
109        signing_options.normalize_uri_path = true;
110        signing_options.payload_override = None;
111
112        cfg.store_put(::aws_runtime::auth::SigV4OperationSigningConfig {
113            signing_options,
114            ..::std::default::Default::default()
115        });
116
117        ::std::option::Option::Some(cfg.freeze())
118    }
119
120    fn runtime_components(
121        &self,
122        _: &::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder,
123    ) -> ::std::borrow::Cow<'_, ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder> {
124        #[allow(unused_mut)]
125        let mut rcb = ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder::new("CreateKey")
126            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
127                CreateKeyTelemetryInputCaptureInterceptor,
128            ))
129            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
130                ::aws_smithy_runtime::client::stalled_stream_protection::StalledStreamProtectionInterceptor::default(),
131            ))
132            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
133                CreateKeyEndpointParamsInterceptor,
134            ))
135            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::TransientErrorClassifier::<
136                crate::operation::create_key::CreateKeyError,
137            >::new())
138            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::ModeledAsRetryableClassifier::<
139                crate::operation::create_key::CreateKeyError,
140            >::new())
141            .with_retry_classifier(::aws_runtime::retries::classifiers::AwsErrorCodeClassifier::<
142                crate::operation::create_key::CreateKeyError,
143            >::new());
144
145        ::std::borrow::Cow::Owned(rcb)
146    }
147}
148
149#[derive(Debug)]
150struct CreateKeyTelemetryInputCaptureInterceptor;
151
152#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
153impl ::aws_smithy_runtime_api::client::interceptors::Intercept for CreateKeyTelemetryInputCaptureInterceptor {
154    fn name(&self) -> &'static str {
155        "CreateKeyTelemetryInputCaptureInterceptor"
156    }
157
158    fn read_before_execution(
159        &self,
160        context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
161            '_,
162            ::aws_smithy_runtime_api::client::interceptors::context::Input,
163            ::aws_smithy_runtime_api::client::interceptors::context::Output,
164            ::aws_smithy_runtime_api::client::interceptors::context::Error,
165        >,
166        cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
167    ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
168        // Nothing to do unless the customer opted in by naming members to record.
169        let ::std::option::Option::Some(requested) = cfg
170            .load::<::aws_smithy_types::telemetry::RequestedTelemetryAttributes>()
171            .filter(|r| !r.is_empty())
172        else {
173            return ::std::result::Result::Ok(());
174        };
175
176        let ::std::option::Option::Some(input) = context.input().downcast_ref::<CreateKeyInput>() else {
177            // A mismatched input is not this interceptor's concern; skip quietly.
178            return ::std::result::Result::Ok(());
179        };
180
181        let mut captured = ::aws_smithy_types::telemetry::CapturedTelemetryAttributes::default();
182        if requested.should_capture("Policy") {
183            if let ::std::option::Option::Some(value) = input.policy.as_deref() {
184                captured.insert("Policy", value);
185            }
186        }
187        if requested.should_capture("Description") {
188            if let ::std::option::Option::Some(value) = input.description.as_deref() {
189                captured.insert("Description", value);
190            }
191        }
192        if requested.should_capture("CustomKeyStoreId") {
193            if let ::std::option::Option::Some(value) = input.custom_key_store_id.as_deref() {
194                captured.insert("CustomKeyStoreId", value);
195            }
196        }
197        if requested.should_capture("XksKeyId") {
198            if let ::std::option::Option::Some(value) = input.xks_key_id.as_deref() {
199                captured.insert("XksKeyId", value);
200            }
201        }
202
203        cfg.interceptor_state().store_put(captured);
204        ::std::result::Result::Ok(())
205    }
206}
207#[derive(Debug)]
208struct CreateKeyResponseDeserializer;
209impl ::aws_smithy_runtime_api::client::ser_de::DeserializeResponse for CreateKeyResponseDeserializer {
210    fn deserialize_nonstreaming_with_config(
211        &self,
212        response: &::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
213        _cfg: &::aws_smithy_types::config_bag::ConfigBag,
214    ) -> ::aws_smithy_runtime_api::client::interceptors::context::OutputOrError {
215        let (success, status) = (response.status().is_success(), response.status().as_u16());
216        let headers = response.headers();
217        let body = response.body().bytes().expect("body loaded");
218        #[allow(unused_mut)]
219        let mut force_error = false;
220        ::tracing::debug!(request_id = ?::aws_types::request_id::RequestId::request_id(response));
221        let parse_result = if !success && status != 200 || force_error {
222            crate::protocol_serde::shape_create_key::de_create_key_http_error(status, headers, body)
223        } else {
224            crate::protocol_serde::shape_create_key::de_create_key_http_response(status, headers, body)
225        };
226        crate::protocol_serde::type_erase_result(parse_result)
227    }
228}
229#[derive(Debug)]
230struct CreateKeyRequestSerializer;
231impl ::aws_smithy_runtime_api::client::ser_de::SerializeRequest for CreateKeyRequestSerializer {
232    #[allow(unused_mut, clippy::let_and_return, clippy::needless_borrow, clippy::useless_conversion)]
233    fn serialize_input(
234        &self,
235        input: ::aws_smithy_runtime_api::client::interceptors::context::Input,
236        _cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
237    ) -> ::std::result::Result<::aws_smithy_runtime_api::client::orchestrator::HttpRequest, ::aws_smithy_runtime_api::box_error::BoxError> {
238        let input = input.downcast::<crate::operation::create_key::CreateKeyInput>().expect("correct type");
239        let _header_serialization_settings = _cfg
240            .load::<crate::serialization_settings::HeaderSerializationSettings>()
241            .cloned()
242            .unwrap_or_default();
243        let mut request_builder = {
244            #[allow(clippy::uninlined_format_args)]
245            fn uri_base(
246                _input: &crate::operation::create_key::CreateKeyInput,
247                output: &mut ::std::string::String,
248            ) -> ::std::result::Result<(), ::aws_smithy_types::error::operation::BuildError> {
249                use ::std::fmt::Write as _;
250                ::std::write!(output, "/").expect("formatting should succeed");
251                ::std::result::Result::Ok(())
252            }
253            #[allow(clippy::unnecessary_wraps)]
254            fn update_http_builder(
255                input: &crate::operation::create_key::CreateKeyInput,
256                builder: ::http_1x::request::Builder,
257            ) -> ::std::result::Result<::http_1x::request::Builder, ::aws_smithy_types::error::operation::BuildError> {
258                let mut uri = ::std::string::String::new();
259                uri_base(input, &mut uri)?;
260                ::std::result::Result::Ok(builder.method("POST").uri(uri))
261            }
262            let mut builder = update_http_builder(&input, ::http_1x::request::Builder::new())?;
263            builder = _header_serialization_settings.set_default_header(builder, ::http_1x::header::CONTENT_TYPE, "application/x-amz-json-1.1");
264            builder = _header_serialization_settings.set_default_header(
265                builder,
266                ::http_1x::header::HeaderName::from_static("x-amz-target"),
267                "TrentService.CreateKey",
268            );
269            builder
270        };
271        let body = ::aws_smithy_types::body::SdkBody::from(crate::protocol_serde::shape_create_key::ser_create_key_input(&input)?);
272        if let Some(content_length) = body.content_length() {
273            let content_length = content_length.to_string();
274            request_builder = _header_serialization_settings.set_default_header(request_builder, ::http_1x::header::CONTENT_LENGTH, &content_length);
275        }
276        ::std::result::Result::Ok(request_builder.body(body).expect("valid request").try_into().unwrap())
277    }
278}
279#[derive(Debug)]
280struct CreateKeyEndpointParamsInterceptor;
281
282#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
283impl ::aws_smithy_runtime_api::client::interceptors::Intercept for CreateKeyEndpointParamsInterceptor {
284    fn name(&self) -> &'static str {
285        "CreateKeyEndpointParamsInterceptor"
286    }
287
288    fn read_before_execution(
289        &self,
290        context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
291            '_,
292            ::aws_smithy_runtime_api::client::interceptors::context::Input,
293            ::aws_smithy_runtime_api::client::interceptors::context::Output,
294            ::aws_smithy_runtime_api::client::interceptors::context::Error,
295        >,
296        cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
297    ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
298        let _input = context
299            .input()
300            .downcast_ref::<CreateKeyInput>()
301            .ok_or("failed to downcast to CreateKeyInput")?;
302
303        let params = crate::config::endpoint::Params::builder()
304            .set_region(cfg.load::<::aws_types::region::Region>().map(|r| r.as_ref().to_owned()))
305            .set_use_dual_stack(cfg.load::<::aws_types::endpoint_config::UseDualStack>().map(|ty| ty.0))
306            .set_use_fips(cfg.load::<::aws_types::endpoint_config::UseFips>().map(|ty| ty.0))
307            .set_endpoint(cfg.load::<::aws_types::endpoint_config::EndpointUrl>().map(|ty| ty.0.clone()))
308            .build()
309            .map_err(|err| {
310                ::aws_smithy_runtime_api::client::interceptors::error::ContextAttachedError::new("endpoint params could not be built", err)
311            })?;
312        cfg.interceptor_state()
313            .store_put(::aws_smithy_runtime_api::client::endpoint::EndpointResolverParams::new(params));
314        ::std::result::Result::Ok(())
315    }
316}
317
318// The get_* functions below are generated from JMESPath expressions in the
319// operationContextParams trait. They target the operation's input shape.
320
321/// Error type for the `CreateKeyError` operation.
322#[non_exhaustive]
323#[derive(::std::fmt::Debug)]
324pub enum CreateKeyError {
325    /// <p>The request was rejected because the associated CloudHSM cluster did not meet the configuration requirements for an CloudHSM key store.</p>
326    /// <ul>
327    /// <li>
328    /// <p>The CloudHSM cluster must be configured with private subnets in at least two different Availability Zones in the Region.</p></li>
329    /// <li>
330    /// <p>The <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/configure-sg.html">security group for the cluster</a> (cloudhsm-cluster-<i><cluster-id></cluster-id></i>-sg) must include inbound rules and outbound rules that allow TCP traffic on ports 2223-2225. The <b>Source</b> in the inbound rules and the <b>Destination</b> in the outbound rules must match the security group ID. These rules are set by default when you create the CloudHSM cluster. Do not delete or change them. To get information about a particular security group, use the <a href="https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeSecurityGroups.html">DescribeSecurityGroups</a> operation.</p></li>
331    /// <li>
332    /// <p>The CloudHSM cluster must contain at least as many HSMs as the operation requires. To add HSMs, use the CloudHSM <a href="https://docs.aws.amazon.com/cloudhsm/latest/APIReference/API_CreateHsm.html">CreateHsm</a> operation.</p>
333    /// <p>For the <code>CreateCustomKeyStore</code>, <code>UpdateCustomKeyStore</code>, and <code>CreateKey</code> operations, the CloudHSM cluster must have at least two active HSMs, each in a different Availability Zone. For the <code>ConnectCustomKeyStore</code> operation, the CloudHSM must contain at least one active HSM.</p></li>
334    /// </ul>
335    /// <p>For information about the requirements for an CloudHSM cluster that is associated with an CloudHSM key store, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/create-keystore.html#before-keystore">Assemble the Prerequisites</a> in the <i>Key Management Service Developer Guide</i>. For information about creating a private subnet for an CloudHSM cluster, see <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/create-subnets.html">Create a Private Subnet</a> in the <i>CloudHSM User Guide</i>. For information about cluster security groups, see <a href="https://docs.aws.amazon.com/cloudhsm/latest/userguide/configure-sg.html">Configure a Default Security Group</a> in the <i> <i>CloudHSM User Guide</i> </i>.</p>
336    CloudHsmClusterInvalidConfigurationException(crate::types::error::CloudHsmClusterInvalidConfigurationException),
337    /// <p>The request was rejected because of the <code>ConnectionState</code> of the custom key store. To get the <code>ConnectionState</code> of a custom key store, use the <code>DescribeCustomKeyStores</code> operation.</p>
338    /// <p>This exception is thrown under the following conditions:</p>
339    /// <ul>
340    /// <li>
341    /// <p>You requested the <code>ConnectCustomKeyStore</code> operation on a custom key store with a <code>ConnectionState</code> of <code>DISCONNECTING</code> or <code>FAILED</code>. This operation is valid for all other <code>ConnectionState</code> values. To reconnect a custom key store in a <code>FAILED</code> state, disconnect it (<code>DisconnectCustomKeyStore</code>), then connect it (<code>ConnectCustomKeyStore</code>).</p></li>
342    /// <li>
343    /// <p>You requested the <code>CreateKey</code> operation in a custom key store that is not connected. This operations is valid only when the custom key store <code>ConnectionState</code> is <code>CONNECTED</code>.</p></li>
344    /// <li>
345    /// <p>You requested the <code>DisconnectCustomKeyStore</code> operation on a custom key store with a <code>ConnectionState</code> of <code>DISCONNECTING</code> or <code>DISCONNECTED</code>. This operation is valid for all other <code>ConnectionState</code> values.</p></li>
346    /// <li>
347    /// <p>You requested the <code>UpdateCustomKeyStore</code> or <code>DeleteCustomKeyStore</code> operation on a custom key store that is not disconnected. <code>UpdateCustomKeyStore</code> can be called on a custom key store in the <code>CONNECTED</code> state only to update <code>NewCustomKeyStoreName</code>. For all other properties, the custom key store <code>ConnectionState</code> must be <code>DISCONNECTED</code>.</p></li>
348    /// <li>
349    /// <p>You requested the <code>GenerateRandom</code> operation in an CloudHSM key store that is not connected. This operation is valid only when the CloudHSM key store <code>ConnectionState</code> is <code>CONNECTED</code>.</p></li>
350    /// </ul>
351    CustomKeyStoreInvalidStateException(crate::types::error::CustomKeyStoreInvalidStateException),
352    /// <p>The request was rejected because KMS cannot find a custom key store with the specified key store name or ID.</p>
353    CustomKeyStoreNotFoundException(crate::types::error::CustomKeyStoreNotFoundException),
354    /// <p>The system timed out while trying to fulfill the request. You can retry the request.</p>
355    DependencyTimeoutException(crate::types::error::DependencyTimeoutException),
356    /// <p>The request was rejected because a specified ARN, or an ARN in a key policy, is not valid.</p>
357    InvalidArnException(crate::types::error::InvalidArnException),
358    /// <p>The request was rejected because an internal exception occurred. The request can be retried.</p>
359    KmsInternalException(crate::types::error::KmsInternalException),
360    /// <p>The request was rejected because a length constraint or quota was exceeded. For more information, see <a href="https://docs.aws.amazon.com/kms/latest/developerguide/limits.html">Quotas</a> in the <i>Key Management Service Developer Guide</i>.</p>
361    LimitExceededException(crate::types::error::LimitExceededException),
362    /// <p>The request was rejected because the specified policy is not syntactically or semantically correct.</p>
363    MalformedPolicyDocumentException(crate::types::error::MalformedPolicyDocumentException),
364    /// <p>The request was rejected because one or more tags are not valid.</p>
365    TagException(crate::types::error::TagException),
366    /// <p>The request was rejected because a specified parameter is not supported or a specified resource is not valid for this operation.</p>
367    UnsupportedOperationException(crate::types::error::UnsupportedOperationException),
368    /// <p>The request was rejected because the (<code>XksKeyId</code>) is already associated with another KMS key in this external key store. Each KMS key in an external key store must be associated with a different external key.</p>
369    XksKeyAlreadyInUseException(crate::types::error::XksKeyAlreadyInUseException),
370    /// <p>The request was rejected because the external key specified by the <code>XksKeyId</code> parameter did not meet the configuration requirements for an external key store.</p>
371    /// <p>The external key must be an AES-256 symmetric key that is enabled and performs encryption and decryption.</p>
372    XksKeyInvalidConfigurationException(crate::types::error::XksKeyInvalidConfigurationException),
373    /// <p>The request was rejected because the external key store proxy could not find the external key. This exception is thrown when the value of the <code>XksKeyId</code> parameter doesn't identify a key in the external key manager associated with the external key proxy.</p>
374    /// <p>Verify that the <code>XksKeyId</code> represents an existing key in the external key manager. Use the key identifier that the external key store proxy uses to identify the key. For details, see the documentation provided with your external key store proxy or key manager.</p>
375    XksKeyNotFoundException(crate::types::error::XksKeyNotFoundException),
376    /// An unexpected error occurred (e.g., invalid JSON returned by the service or an unknown error code).
377    #[deprecated(note = "Matching `Unhandled` directly is not forwards compatible. Instead, match using a \
378    variable wildcard pattern and check `.code()`:
379     \
380    &nbsp;&nbsp;&nbsp;`err if err.code() == Some(\"SpecificExceptionCode\") => { /* handle the error */ }`
381     \
382    See [`ProvideErrorMetadata`](#impl-ProvideErrorMetadata-for-CreateKeyError) for what information is available for the error.")]
383    Unhandled(crate::error::sealed_unhandled::Unhandled),
384}
385impl CreateKeyError {
386    /// Creates the `CreateKeyError::Unhandled` variant from any error type.
387    pub fn unhandled(
388        err: impl ::std::convert::Into<::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>>,
389    ) -> Self {
390        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
391            source: err.into(),
392            meta: ::std::default::Default::default(),
393        })
394    }
395
396    /// Creates the `CreateKeyError::Unhandled` variant from an [`ErrorMetadata`](::aws_smithy_types::error::ErrorMetadata).
397    pub fn generic(err: ::aws_smithy_types::error::ErrorMetadata) -> Self {
398        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
399            source: err.clone().into(),
400            meta: err,
401        })
402    }
403    ///
404    /// Returns error metadata, which includes the error code, message,
405    /// request ID, and potentially additional information.
406    ///
407    pub fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
408        match self {
409            Self::CloudHsmClusterInvalidConfigurationException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
410            Self::CustomKeyStoreInvalidStateException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
411            Self::CustomKeyStoreNotFoundException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
412            Self::DependencyTimeoutException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
413            Self::InvalidArnException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
414            Self::KmsInternalException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
415            Self::LimitExceededException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
416            Self::MalformedPolicyDocumentException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
417            Self::TagException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
418            Self::UnsupportedOperationException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
419            Self::XksKeyAlreadyInUseException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
420            Self::XksKeyInvalidConfigurationException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
421            Self::XksKeyNotFoundException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
422            Self::Unhandled(e) => &e.meta,
423        }
424    }
425    /// Returns `true` if the error kind is `CreateKeyError::CloudHsmClusterInvalidConfigurationException`.
426    pub fn is_cloud_hsm_cluster_invalid_configuration_exception(&self) -> bool {
427        matches!(self, Self::CloudHsmClusterInvalidConfigurationException(_))
428    }
429    /// Returns `true` if the error kind is `CreateKeyError::CustomKeyStoreInvalidStateException`.
430    pub fn is_custom_key_store_invalid_state_exception(&self) -> bool {
431        matches!(self, Self::CustomKeyStoreInvalidStateException(_))
432    }
433    /// Returns `true` if the error kind is `CreateKeyError::CustomKeyStoreNotFoundException`.
434    pub fn is_custom_key_store_not_found_exception(&self) -> bool {
435        matches!(self, Self::CustomKeyStoreNotFoundException(_))
436    }
437    /// Returns `true` if the error kind is `CreateKeyError::DependencyTimeoutException`.
438    pub fn is_dependency_timeout_exception(&self) -> bool {
439        matches!(self, Self::DependencyTimeoutException(_))
440    }
441    /// Returns `true` if the error kind is `CreateKeyError::InvalidArnException`.
442    pub fn is_invalid_arn_exception(&self) -> bool {
443        matches!(self, Self::InvalidArnException(_))
444    }
445    /// Returns `true` if the error kind is `CreateKeyError::KmsInternalException`.
446    pub fn is_kms_internal_exception(&self) -> bool {
447        matches!(self, Self::KmsInternalException(_))
448    }
449    /// Returns `true` if the error kind is `CreateKeyError::LimitExceededException`.
450    pub fn is_limit_exceeded_exception(&self) -> bool {
451        matches!(self, Self::LimitExceededException(_))
452    }
453    /// Returns `true` if the error kind is `CreateKeyError::MalformedPolicyDocumentException`.
454    pub fn is_malformed_policy_document_exception(&self) -> bool {
455        matches!(self, Self::MalformedPolicyDocumentException(_))
456    }
457    /// Returns `true` if the error kind is `CreateKeyError::TagException`.
458    pub fn is_tag_exception(&self) -> bool {
459        matches!(self, Self::TagException(_))
460    }
461    /// Returns `true` if the error kind is `CreateKeyError::UnsupportedOperationException`.
462    pub fn is_unsupported_operation_exception(&self) -> bool {
463        matches!(self, Self::UnsupportedOperationException(_))
464    }
465    /// Returns `true` if the error kind is `CreateKeyError::XksKeyAlreadyInUseException`.
466    pub fn is_xks_key_already_in_use_exception(&self) -> bool {
467        matches!(self, Self::XksKeyAlreadyInUseException(_))
468    }
469    /// Returns `true` if the error kind is `CreateKeyError::XksKeyInvalidConfigurationException`.
470    pub fn is_xks_key_invalid_configuration_exception(&self) -> bool {
471        matches!(self, Self::XksKeyInvalidConfigurationException(_))
472    }
473    /// Returns `true` if the error kind is `CreateKeyError::XksKeyNotFoundException`.
474    pub fn is_xks_key_not_found_exception(&self) -> bool {
475        matches!(self, Self::XksKeyNotFoundException(_))
476    }
477}
478impl ::std::error::Error for CreateKeyError {
479    fn source(&self) -> ::std::option::Option<&(dyn ::std::error::Error + 'static)> {
480        match self {
481            Self::CloudHsmClusterInvalidConfigurationException(_inner) => ::std::option::Option::Some(_inner),
482            Self::CustomKeyStoreInvalidStateException(_inner) => ::std::option::Option::Some(_inner),
483            Self::CustomKeyStoreNotFoundException(_inner) => ::std::option::Option::Some(_inner),
484            Self::DependencyTimeoutException(_inner) => ::std::option::Option::Some(_inner),
485            Self::InvalidArnException(_inner) => ::std::option::Option::Some(_inner),
486            Self::KmsInternalException(_inner) => ::std::option::Option::Some(_inner),
487            Self::LimitExceededException(_inner) => ::std::option::Option::Some(_inner),
488            Self::MalformedPolicyDocumentException(_inner) => ::std::option::Option::Some(_inner),
489            Self::TagException(_inner) => ::std::option::Option::Some(_inner),
490            Self::UnsupportedOperationException(_inner) => ::std::option::Option::Some(_inner),
491            Self::XksKeyAlreadyInUseException(_inner) => ::std::option::Option::Some(_inner),
492            Self::XksKeyInvalidConfigurationException(_inner) => ::std::option::Option::Some(_inner),
493            Self::XksKeyNotFoundException(_inner) => ::std::option::Option::Some(_inner),
494            Self::Unhandled(_inner) => ::std::option::Option::Some(&*_inner.source),
495        }
496    }
497}
498impl ::std::fmt::Display for CreateKeyError {
499    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
500        match self {
501            Self::CloudHsmClusterInvalidConfigurationException(_inner) => _inner.fmt(f),
502            Self::CustomKeyStoreInvalidStateException(_inner) => _inner.fmt(f),
503            Self::CustomKeyStoreNotFoundException(_inner) => _inner.fmt(f),
504            Self::DependencyTimeoutException(_inner) => _inner.fmt(f),
505            Self::InvalidArnException(_inner) => _inner.fmt(f),
506            Self::KmsInternalException(_inner) => _inner.fmt(f),
507            Self::LimitExceededException(_inner) => _inner.fmt(f),
508            Self::MalformedPolicyDocumentException(_inner) => _inner.fmt(f),
509            Self::TagException(_inner) => _inner.fmt(f),
510            Self::UnsupportedOperationException(_inner) => _inner.fmt(f),
511            Self::XksKeyAlreadyInUseException(_inner) => _inner.fmt(f),
512            Self::XksKeyInvalidConfigurationException(_inner) => _inner.fmt(f),
513            Self::XksKeyNotFoundException(_inner) => _inner.fmt(f),
514            Self::Unhandled(_inner) => {
515                if let ::std::option::Option::Some(code) = ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self) {
516                    write!(f, "unhandled error ({code})")
517                } else {
518                    f.write_str("unhandled error")
519                }
520            }
521        }
522    }
523}
524impl ::aws_smithy_types::retry::ProvideErrorKind for CreateKeyError {
525    fn code(&self) -> ::std::option::Option<&str> {
526        ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self)
527    }
528    fn retryable_error_kind(&self) -> ::std::option::Option<::aws_smithy_types::retry::ErrorKind> {
529        ::std::option::Option::None
530    }
531}
532impl ::aws_smithy_types::error::metadata::ProvideErrorMetadata for CreateKeyError {
533    fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
534        match self {
535            Self::CloudHsmClusterInvalidConfigurationException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
536            Self::CustomKeyStoreInvalidStateException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
537            Self::CustomKeyStoreNotFoundException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
538            Self::DependencyTimeoutException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
539            Self::InvalidArnException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
540            Self::KmsInternalException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
541            Self::LimitExceededException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
542            Self::MalformedPolicyDocumentException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
543            Self::TagException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
544            Self::UnsupportedOperationException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
545            Self::XksKeyAlreadyInUseException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
546            Self::XksKeyInvalidConfigurationException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
547            Self::XksKeyNotFoundException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
548            Self::Unhandled(_inner) => &_inner.meta,
549        }
550    }
551}
552impl ::aws_smithy_runtime_api::client::result::CreateUnhandledError for CreateKeyError {
553    fn create_unhandled_error(
554        source: ::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>,
555        meta: ::std::option::Option<::aws_smithy_types::error::ErrorMetadata>,
556    ) -> Self {
557        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
558            source,
559            meta: meta.unwrap_or_default(),
560        })
561    }
562}
563impl ::aws_types::request_id::RequestId for crate::operation::create_key::CreateKeyError {
564    fn request_id(&self) -> Option<&str> {
565        self.meta().request_id()
566    }
567}
568
569pub use crate::operation::create_key::_create_key_input::CreateKeyInput;
570
571pub use crate::operation::create_key::_create_key_output::CreateKeyOutput;
572
573mod _create_key_input;
574
575mod _create_key_output;
576
577/// Builders
578pub mod builders;