AwsKinesis(mapping=None, *, ignore_unknown_fields=False, **kwargs)Ingestion settings for Amazon Kinesis Data Streams.
Attributes |
|
|---|---|
| Name | Description |
state
:noindex: |
google.pubsub_v1.types.IngestionDataSourceSettings.AwsKinesis.State
Output only. An output-only field that indicates the state of the Kinesis ingestion source. |
stream_arn
:noindex: |
str
Required. The Kinesis stream ARN to ingest data from. |
consumer_arn
:noindex: |
str
Required. The Kinesis consumer ARN to used for ingestion in Enhanced Fan-Out mode. The consumer must be already created and ready to be used. |
aws_role_arn
:noindex: |
str
Required. AWS role ARN to be used for Federated Identity authentication with Kinesis. Check the Pub/Sub docs for how to set up this role and the required permissions that need to be attached to it. |
gcp_service_account
:noindex: |
str
Required. The GCP service account to be used for Federated Identity authentication with Kinesis (via a AssumeRoleWithWebIdentity call for the provided role).
The aws_role_arn must be set up with
accounts.google.com:sub equals to this service account
number.
|
Classes
State
State(value)Possible states for ingestion from Amazon Kinesis Data Streams.
- The provided `aws_role_arn` does not exist or does not
have the appropriate permissions attached.
- The provided `aws_role_arn` is not set up properly for
Identity Federation using `gcp_service_account`.
- The Pub/Sub SA is not granted the
`iam.serviceAccounts.getOpenIdToken` permission on
`gcp_service_account`.
PUBLISH_PERMISSION_DENIED (3):
Permission denied encountered while publishing to the topic.
This can happen if the Pub/Sub SA has not been granted the
`appropriate publish
permissions <https://cloud.google.com/pubsub/docs/access-control#pubsub.publisher>`__
STREAM_NOT_FOUND (4):
The Kinesis stream does not exist.
CONSUMER_NOT_FOUND (5):
The Kinesis consumer does not exist.
CONFLICTING_REGION_CONSTRAINTS (6):
Indicates an error state where the ingestion
source cannot be processed because the selected
ingestion region is not permitted by the
Regional Access Boundary (RAB) restrictions on
the project's service account.