Skip to content

Modifies the account-level VPC Encryption Control configuration

Description

Modifies the account-level VPC Encryption Control configuration. This sets the encryption control mode and resource exclusions that apply to the VPCs in your account. VPC Encryption Control enables you to enforce encryption for all data in transit within and between VPCs to meet compliance requirements.

For more information, see Enforce VPC encryption in transit in the Amazon VPC User Guide.

Usage

ec2_modify_account_vpc_encryption_control(DryRun, Mode, InternetGateway,
  EgressOnlyInternetGateway, NatGateway, VirtualPrivateGateway,
  VpcPeering, Lambda, VpcLattice, ElasticFileSystem)

Arguments

  • DryRun

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

  • Mode

The encryption mode for the account encryption control configuration.

  • InternetGateway

Specifies whether to exclude internet gateway resource from account-level encryption enforcement.

  • EgressOnlyInternetGateway

Specifies whether to exclude egress-only internet gateway resource from account-level encryption enforcement.

  • NatGateway

Specifies whether to exclude NAT gateway resource from account-level encryption enforcement.

  • VirtualPrivateGateway

Specifies whether to exclude virtual private gateway resource from account-level encryption enforcement.

  • VpcPeering

Specifies whether to exclude VPC peering connection resource from account-level encryption enforcement.

  • Lambda

Specifies whether to exclude Lambda service from account-level encryption enforcement.

  • VpcLattice

Specifies whether to exclude VPC Lattice service from account-level encryption enforcement.

  • ElasticFileSystem

Specifies whether to exclude Elastic File System service from account-level encryption enforcement.

Value

A list with the following syntax:

list(
  AccountVpcEncryptionControl = list(
    State = "default-state"|"transitions-in-progress"|"transitions-partially-successful"|"transitions-successful"|"transitions-failed",
    Mode = "unmanaged"|"attempt-monitor"|"attempt-enforce",
    Exclusions = list(
      InternetGateway = "enabling"|"enabled"|"disabling"|"disabled",
      EgressOnlyInternetGateway = "enabling"|"enabled"|"disabling"|"disabled",
      NatGateway = "enabling"|"enabled"|"disabling"|"disabled",
      VirtualPrivateGateway = "enabling"|"enabled"|"disabling"|"disabled",
      VpcPeering = "enabling"|"enabled"|"disabling"|"disabled",
      Lambda = "enabling"|"enabled"|"disabling"|"disabled",
      VpcLattice = "enabling"|"enabled"|"disabling"|"disabled",
      ElasticFileSystem = "enabling"|"enabled"|"disabling"|"disabled"
    ),
    ManagedBy = "account"|"declarative-policy",
    LastUpdateTimestamp = as.POSIXct(
      "2015-01-01"
    )
  )
)

Request syntax

svc$modify_account_vpc_encryption_control(
  DryRun = TRUE|FALSE,
  Mode = "unmanaged"|"attempt-monitor"|"attempt-enforce",
  InternetGateway = "enable"|"disable",
  EgressOnlyInternetGateway = "enable"|"disable",
  NatGateway = "enable"|"disable",
  VirtualPrivateGateway = "enable"|"disable",
  VpcPeering = "enable"|"disable",
  Lambda = "enable"|"disable",
  VpcLattice = "enable"|"disable",
  ElasticFileSystem = "enable"|"disable"
)