{-# LANGUAGE DeriveGeneric #-}
{-# LANGUAGE DuplicateRecordFields #-}
{-# LANGUAGE NamedFieldPuns #-}
{-# LANGUAGE OverloadedStrings #-}
{-# LANGUAGE RecordWildCards #-}
{-# LANGUAGE StrictData #-}
{-# LANGUAGE NoImplicitPrelude #-}
{-# OPTIONS_GHC -fno-warn-unused-imports #-}
{-# OPTIONS_GHC -fno-warn-unused-matches #-}

-- Derived from AWS service descriptions, licensed under Apache 2.0.

-- |
-- Module      : Amazonka.Forecast.Types.EncryptionConfig
-- Copyright   : (c) 2013-2023 Brendan Hay
-- License     : Mozilla Public License, v. 2.0.
-- Maintainer  : Brendan Hay
-- Stability   : auto-generated
-- Portability : non-portable (GHC extensions)
module Amazonka.Forecast.Types.EncryptionConfig where

import qualified Amazonka.Core as Core
import qualified Amazonka.Core.Lens.Internal as Lens
import qualified Amazonka.Data as Data
import qualified Amazonka.Prelude as Prelude

-- | An AWS Key Management Service (KMS) key and an AWS Identity and Access
-- Management (IAM) role that Amazon Forecast can assume to access the key.
-- You can specify this optional object in the CreateDataset and
-- CreatePredictor requests.
--
-- /See:/ 'newEncryptionConfig' smart constructor.
data EncryptionConfig = EncryptionConfig'
  { -- | The ARN of the IAM role that Amazon Forecast can assume to access the
    -- AWS KMS key.
    --
    -- Passing a role across AWS accounts is not allowed. If you pass a role
    -- that isn\'t in your account, you get an @InvalidInputException@ error.
    EncryptionConfig -> Text
roleArn :: Prelude.Text,
    -- | The Amazon Resource Name (ARN) of the KMS key.
    EncryptionConfig -> Text
kmsKeyArn :: Prelude.Text
  }
  deriving (EncryptionConfig -> EncryptionConfig -> Bool
forall a. (a -> a -> Bool) -> (a -> a -> Bool) -> Eq a
/= :: EncryptionConfig -> EncryptionConfig -> Bool
$c/= :: EncryptionConfig -> EncryptionConfig -> Bool
== :: EncryptionConfig -> EncryptionConfig -> Bool
$c== :: EncryptionConfig -> EncryptionConfig -> Bool
Prelude.Eq, ReadPrec [EncryptionConfig]
ReadPrec EncryptionConfig
Int -> ReadS EncryptionConfig
ReadS [EncryptionConfig]
forall a.
(Int -> ReadS a)
-> ReadS [a] -> ReadPrec a -> ReadPrec [a] -> Read a
readListPrec :: ReadPrec [EncryptionConfig]
$creadListPrec :: ReadPrec [EncryptionConfig]
readPrec :: ReadPrec EncryptionConfig
$creadPrec :: ReadPrec EncryptionConfig
readList :: ReadS [EncryptionConfig]
$creadList :: ReadS [EncryptionConfig]
readsPrec :: Int -> ReadS EncryptionConfig
$creadsPrec :: Int -> ReadS EncryptionConfig
Prelude.Read, Int -> EncryptionConfig -> ShowS
[EncryptionConfig] -> ShowS
EncryptionConfig -> String
forall a.
(Int -> a -> ShowS) -> (a -> String) -> ([a] -> ShowS) -> Show a
showList :: [EncryptionConfig] -> ShowS
$cshowList :: [EncryptionConfig] -> ShowS
show :: EncryptionConfig -> String
$cshow :: EncryptionConfig -> String
showsPrec :: Int -> EncryptionConfig -> ShowS
$cshowsPrec :: Int -> EncryptionConfig -> ShowS
Prelude.Show, forall x. Rep EncryptionConfig x -> EncryptionConfig
forall x. EncryptionConfig -> Rep EncryptionConfig x
forall a.
(forall x. a -> Rep a x) -> (forall x. Rep a x -> a) -> Generic a
$cto :: forall x. Rep EncryptionConfig x -> EncryptionConfig
$cfrom :: forall x. EncryptionConfig -> Rep EncryptionConfig x
Prelude.Generic)

-- |
-- Create a value of 'EncryptionConfig' with all optional fields omitted.
--
-- Use <https://hackage.haskell.org/package/generic-lens generic-lens> or <https://hackage.haskell.org/package/optics optics> to modify other optional fields.
--
-- The following record fields are available, with the corresponding lenses provided
-- for backwards compatibility:
--
-- 'roleArn', 'encryptionConfig_roleArn' - The ARN of the IAM role that Amazon Forecast can assume to access the
-- AWS KMS key.
--
-- Passing a role across AWS accounts is not allowed. If you pass a role
-- that isn\'t in your account, you get an @InvalidInputException@ error.
--
-- 'kmsKeyArn', 'encryptionConfig_kmsKeyArn' - The Amazon Resource Name (ARN) of the KMS key.
newEncryptionConfig ::
  -- | 'roleArn'
  Prelude.Text ->
  -- | 'kmsKeyArn'
  Prelude.Text ->
  EncryptionConfig
newEncryptionConfig :: Text -> Text -> EncryptionConfig
newEncryptionConfig Text
pRoleArn_ Text
pKMSKeyArn_ =
  EncryptionConfig'
    { $sel:roleArn:EncryptionConfig' :: Text
roleArn = Text
pRoleArn_,
      $sel:kmsKeyArn:EncryptionConfig' :: Text
kmsKeyArn = Text
pKMSKeyArn_
    }

-- | The ARN of the IAM role that Amazon Forecast can assume to access the
-- AWS KMS key.
--
-- Passing a role across AWS accounts is not allowed. If you pass a role
-- that isn\'t in your account, you get an @InvalidInputException@ error.
encryptionConfig_roleArn :: Lens.Lens' EncryptionConfig Prelude.Text
encryptionConfig_roleArn :: Lens' EncryptionConfig Text
encryptionConfig_roleArn = forall s a b t. (s -> a) -> (s -> b -> t) -> Lens s t a b
Lens.lens (\EncryptionConfig' {Text
roleArn :: Text
$sel:roleArn:EncryptionConfig' :: EncryptionConfig -> Text
roleArn} -> Text
roleArn) (\s :: EncryptionConfig
s@EncryptionConfig' {} Text
a -> EncryptionConfig
s {$sel:roleArn:EncryptionConfig' :: Text
roleArn = Text
a} :: EncryptionConfig)

-- | The Amazon Resource Name (ARN) of the KMS key.
encryptionConfig_kmsKeyArn :: Lens.Lens' EncryptionConfig Prelude.Text
encryptionConfig_kmsKeyArn :: Lens' EncryptionConfig Text
encryptionConfig_kmsKeyArn = forall s a b t. (s -> a) -> (s -> b -> t) -> Lens s t a b
Lens.lens (\EncryptionConfig' {Text
kmsKeyArn :: Text
$sel:kmsKeyArn:EncryptionConfig' :: EncryptionConfig -> Text
kmsKeyArn} -> Text
kmsKeyArn) (\s :: EncryptionConfig
s@EncryptionConfig' {} Text
a -> EncryptionConfig
s {$sel:kmsKeyArn:EncryptionConfig' :: Text
kmsKeyArn = Text
a} :: EncryptionConfig)

instance Data.FromJSON EncryptionConfig where
  parseJSON :: Value -> Parser EncryptionConfig
parseJSON =
    forall a. String -> (Object -> Parser a) -> Value -> Parser a
Data.withObject
      String
"EncryptionConfig"
      ( \Object
x ->
          Text -> Text -> EncryptionConfig
EncryptionConfig'
            forall (f :: * -> *) a b. Functor f => (a -> b) -> f a -> f b
Prelude.<$> (Object
x forall a. FromJSON a => Object -> Key -> Parser a
Data..: Key
"RoleArn")
            forall (f :: * -> *) a b. Applicative f => f (a -> b) -> f a -> f b
Prelude.<*> (Object
x forall a. FromJSON a => Object -> Key -> Parser a
Data..: Key
"KMSKeyArn")
      )

instance Prelude.Hashable EncryptionConfig where
  hashWithSalt :: Int -> EncryptionConfig -> Int
hashWithSalt Int
_salt EncryptionConfig' {Text
kmsKeyArn :: Text
roleArn :: Text
$sel:kmsKeyArn:EncryptionConfig' :: EncryptionConfig -> Text
$sel:roleArn:EncryptionConfig' :: EncryptionConfig -> Text
..} =
    Int
_salt
      forall a. Hashable a => Int -> a -> Int
`Prelude.hashWithSalt` Text
roleArn
      forall a. Hashable a => Int -> a -> Int
`Prelude.hashWithSalt` Text
kmsKeyArn

instance Prelude.NFData EncryptionConfig where
  rnf :: EncryptionConfig -> ()
rnf EncryptionConfig' {Text
kmsKeyArn :: Text
roleArn :: Text
$sel:kmsKeyArn:EncryptionConfig' :: EncryptionConfig -> Text
$sel:roleArn:EncryptionConfig' :: EncryptionConfig -> Text
..} =
    forall a. NFData a => a -> ()
Prelude.rnf Text
roleArn
      seq :: forall a b. a -> b -> b
`Prelude.seq` forall a. NFData a => a -> ()
Prelude.rnf Text
kmsKeyArn

instance Data.ToJSON EncryptionConfig where
  toJSON :: EncryptionConfig -> Value
toJSON EncryptionConfig' {Text
kmsKeyArn :: Text
roleArn :: Text
$sel:kmsKeyArn:EncryptionConfig' :: EncryptionConfig -> Text
$sel:roleArn:EncryptionConfig' :: EncryptionConfig -> Text
..} =
    [Pair] -> Value
Data.object
      ( forall a. [Maybe a] -> [a]
Prelude.catMaybes
          [ forall a. a -> Maybe a
Prelude.Just (Key
"RoleArn" forall kv v. (KeyValue kv, ToJSON v) => Key -> v -> kv
Data..= Text
roleArn),
            forall a. a -> Maybe a
Prelude.Just (Key
"KMSKeyArn" forall kv v. (KeyValue kv, ToJSON v) => Key -> v -> kv
Data..= Text
kmsKeyArn)
          ]
      )