Redshift.Client.rotate_encryption_key(**kwargs)¶Rotates the encryption keys for a cluster.
See also: AWS API Documentation
Request Syntax
response = client.rotate_encryption_key(
    ClusterIdentifier='string'
)
[REQUIRED]
The unique identifier of the cluster that you want to rotate the encryption keys for.
Constraints: Must be the name of valid cluster that has encryption enabled.
{
    'Cluster': {
        'ClusterIdentifier': 'string',
        'NodeType': 'string',
        'ClusterStatus': 'string',
        'ClusterAvailabilityStatus': 'string',
        'ModifyStatus': 'string',
        'MasterUsername': 'string',
        'DBName': 'string',
        'Endpoint': {
            'Address': 'string',
            'Port': 123,
            'VpcEndpoints': [
                {
                    'VpcEndpointId': 'string',
                    'VpcId': 'string',
                    'NetworkInterfaces': [
                        {
                            'NetworkInterfaceId': 'string',
                            'SubnetId': 'string',
                            'PrivateIpAddress': 'string',
                            'AvailabilityZone': 'string'
                        },
                    ]
                },
            ]
        },
        'ClusterCreateTime': datetime(2015, 1, 1),
        'AutomatedSnapshotRetentionPeriod': 123,
        'ManualSnapshotRetentionPeriod': 123,
        'ClusterSecurityGroups': [
            {
                'ClusterSecurityGroupName': 'string',
                'Status': 'string'
            },
        ],
        'VpcSecurityGroups': [
            {
                'VpcSecurityGroupId': 'string',
                'Status': 'string'
            },
        ],
        'ClusterParameterGroups': [
            {
                'ParameterGroupName': 'string',
                'ParameterApplyStatus': 'string',
                'ClusterParameterStatusList': [
                    {
                        'ParameterName': 'string',
                        'ParameterApplyStatus': 'string',
                        'ParameterApplyErrorDescription': 'string'
                    },
                ]
            },
        ],
        'ClusterSubnetGroupName': 'string',
        'VpcId': 'string',
        'AvailabilityZone': 'string',
        'PreferredMaintenanceWindow': 'string',
        'PendingModifiedValues': {
            'MasterUserPassword': 'string',
            'NodeType': 'string',
            'NumberOfNodes': 123,
            'ClusterType': 'string',
            'ClusterVersion': 'string',
            'AutomatedSnapshotRetentionPeriod': 123,
            'ClusterIdentifier': 'string',
            'PubliclyAccessible': True|False,
            'EnhancedVpcRouting': True|False,
            'MaintenanceTrackName': 'string',
            'EncryptionType': 'string'
        },
        'ClusterVersion': 'string',
        'AllowVersionUpgrade': True|False,
        'NumberOfNodes': 123,
        'PubliclyAccessible': True|False,
        'Encrypted': True|False,
        'RestoreStatus': {
            'Status': 'string',
            'CurrentRestoreRateInMegaBytesPerSecond': 123.0,
            'SnapshotSizeInMegaBytes': 123,
            'ProgressInMegaBytes': 123,
            'ElapsedTimeInSeconds': 123,
            'EstimatedTimeToCompletionInSeconds': 123
        },
        'DataTransferProgress': {
            'Status': 'string',
            'CurrentRateInMegaBytesPerSecond': 123.0,
            'TotalDataInMegaBytes': 123,
            'DataTransferredInMegaBytes': 123,
            'EstimatedTimeToCompletionInSeconds': 123,
            'ElapsedTimeInSeconds': 123
        },
        'HsmStatus': {
            'HsmClientCertificateIdentifier': 'string',
            'HsmConfigurationIdentifier': 'string',
            'Status': 'string'
        },
        'ClusterSnapshotCopyStatus': {
            'DestinationRegion': 'string',
            'RetentionPeriod': 123,
            'ManualSnapshotRetentionPeriod': 123,
            'SnapshotCopyGrantName': 'string'
        },
        'ClusterPublicKey': 'string',
        'ClusterNodes': [
            {
                'NodeRole': 'string',
                'PrivateIPAddress': 'string',
                'PublicIPAddress': 'string'
            },
        ],
        'ElasticIpStatus': {
            'ElasticIp': 'string',
            'Status': 'string'
        },
        'ClusterRevisionNumber': 'string',
        'Tags': [
            {
                'Key': 'string',
                'Value': 'string'
            },
        ],
        'KmsKeyId': 'string',
        'EnhancedVpcRouting': True|False,
        'IamRoles': [
            {
                'IamRoleArn': 'string',
                'ApplyStatus': 'string'
            },
        ],
        'PendingActions': [
            'string',
        ],
        'MaintenanceTrackName': 'string',
        'ElasticResizeNumberOfNodeOptions': 'string',
        'DeferredMaintenanceWindows': [
            {
                'DeferMaintenanceIdentifier': 'string',
                'DeferMaintenanceStartTime': datetime(2015, 1, 1),
                'DeferMaintenanceEndTime': datetime(2015, 1, 1)
            },
        ],
        'SnapshotScheduleIdentifier': 'string',
        'SnapshotScheduleState': 'MODIFYING'|'ACTIVE'|'FAILED',
        'ExpectedNextSnapshotScheduleTime': datetime(2015, 1, 1),
        'ExpectedNextSnapshotScheduleTimeStatus': 'string',
        'NextMaintenanceWindowStartTime': datetime(2015, 1, 1),
        'ResizeInfo': {
            'ResizeType': 'string',
            'AllowCancelResize': True|False
        },
        'AvailabilityZoneRelocationStatus': 'string',
        'ClusterNamespaceArn': 'string',
        'TotalStorageCapacityInMegaBytes': 123,
        'AquaConfiguration': {
            'AquaStatus': 'enabled'|'disabled'|'applying',
            'AquaConfigurationStatus': 'enabled'|'disabled'|'auto'
        },
        'DefaultIamRoleArn': 'string',
        'ReservedNodeExchangeStatus': {
            'ReservedNodeExchangeRequestId': 'string',
            'Status': 'REQUESTED'|'PENDING'|'IN_PROGRESS'|'RETRYING'|'SUCCEEDED'|'FAILED',
            'RequestTime': datetime(2015, 1, 1),
            'SourceReservedNodeId': 'string',
            'SourceReservedNodeType': 'string',
            'SourceReservedNodeCount': 123,
            'TargetReservedNodeOfferingId': 'string',
            'TargetReservedNodeType': 'string',
            'TargetReservedNodeCount': 123
        }
    }
}
Response Structure
Describes a cluster.
The unique identifier of the cluster.
The node type for the nodes in the cluster.
The current state of the cluster. Possible values are the following:
availableavailable, prep-for-resizeavailable, resize-cleanupcancelling-resizecreatingdeletingfinal-snapshothardware-failureincompatible-hsmincompatible-networkincompatible-parametersincompatible-restoremodifyingpausedrebootingrenamingresizingrotating-keysstorage-fullupdating-hsmThe availability status of the cluster for queries. Possible values are the following:
The status of a modify operation, if any, initiated for the cluster.
The admin user name for the cluster. This name is used to connect to the database that is specified in the DBName parameter.
The name of the initial database that was created when the cluster was created. This same name is returned for the life of the cluster. If an initial database was not specified, a database named dev dev was created by default.
The connection endpoint.
The DNS address of the Cluster.
The port that the database engine is listening on.
Describes a connection endpoint.
The connection endpoint for connecting to an Amazon Redshift cluster through the proxy.
The connection endpoint ID for connecting an Amazon Redshift cluster through the proxy.
The VPC identifier that the endpoint is associated.
One or more network interfaces of the endpoint. Also known as an interface endpoint.
Describes a network interface.
The network interface identifier.
The subnet identifier.
The IPv4 address of the network interface within the subnet.
The Availability Zone.
The date and time that the cluster was created.
The number of days that automatic cluster snapshots are retained.
The default number of days to retain a manual snapshot. If the value is -1, the snapshot is retained indefinitely. This setting doesn't change the retention period of existing snapshots.
The value must be either -1 or an integer between 1 and 3,653.
A list of cluster security group that are associated with the cluster. Each security group is represented by an element that contains ClusterSecurityGroup.Name and ClusterSecurityGroup.Status subelements.
Cluster security groups are used when the cluster is not created in an Amazon Virtual Private Cloud (VPC). Clusters that are created in a VPC use VPC security groups, which are listed by the VpcSecurityGroups parameter.
Describes a cluster security group.
The name of the cluster security group.
The status of the cluster security group.
A list of Amazon Virtual Private Cloud (Amazon VPC) security groups that are associated with the cluster. This parameter is returned only if the cluster is in a VPC.
Describes the members of a VPC security group.
The identifier of the VPC security group.
The status of the VPC security group.
The list of cluster parameter groups that are associated with this cluster. Each parameter group in the list is returned with its status.
Describes the status of a parameter group.
The name of the cluster parameter group.
The status of parameter updates.
The list of parameter statuses.
For more information about parameters and parameter groups, go to Amazon Redshift Parameter Groups in the Amazon Redshift Cluster Management Guide .
Describes the status of a parameter group.
The name of the parameter.
The status of the parameter that indicates whether the parameter is in sync with the database, waiting for a cluster reboot, or encountered an error when being applied.
The following are possible statuses and descriptions.
in-sync : The parameter value is in sync with the database.pending-reboot : The parameter value will be applied after the cluster reboots.applying : The parameter value is being applied to the database.invalid-parameter : Cannot apply the parameter value because it has an invalid value or syntax.apply-deferred : The parameter contains static property changes. The changes are deferred until the cluster reboots.apply-error : Cannot connect to the cluster. The parameter change will be applied after the cluster reboots.unknown-error : Cannot apply the parameter change right now. The change will be applied after the cluster reboots.The error that prevented the parameter from being applied to the database.
The name of the subnet group that is associated with the cluster. This parameter is valid only when the cluster is in a VPC.
The identifier of the VPC the cluster is in, if the cluster is in a VPC.
The name of the Availability Zone in which the cluster is located.
The weekly time range, in Universal Coordinated Time (UTC), during which system maintenance can occur.
A value that, if present, indicates that changes to the cluster are pending. Specific pending changes are identified by subelements.
The pending or in-progress change of the admin user password for the cluster.
The pending or in-progress change of the cluster's node type.
The pending or in-progress change of the number of nodes in the cluster.
The pending or in-progress change of the cluster type.
The pending or in-progress change of the service version.
The pending or in-progress change of the automated snapshot retention period.
The pending or in-progress change of the new identifier for the cluster.
The pending or in-progress change of the ability to connect to the cluster from the public network.
An option that specifies whether to create the cluster with enhanced VPC routing enabled. To create a cluster that uses enhanced VPC routing, the cluster must be in a VPC. For more information, see Enhanced VPC Routing in the Amazon Redshift Cluster Management Guide.
If this option is true , enhanced VPC routing is enabled.
Default: false
The name of the maintenance track that the cluster will change to during the next maintenance window.
The encryption type for a cluster. Possible values are: KMS and None.
The version ID of the Amazon Redshift engine that is running on the cluster.
A boolean value that, if true , indicates that major version upgrades will be applied automatically to the cluster during the maintenance window.
The number of compute nodes in the cluster.
A boolean value that, if true , indicates that the cluster can be accessed from a public network.
A boolean value that, if true , indicates that data in the cluster is encrypted at rest.
A value that describes the status of a cluster restore action. This parameter returns null if the cluster was not created by restoring a snapshot.
The status of the restore action. Returns starting, restoring, completed, or failed.
The number of megabytes per second being transferred from the backup storage. Returns the average rate for a completed backup. This field is only updated when you restore to DC2 and DS2 node types.
The size of the set of snapshot data used to restore the cluster. This field is only updated when you restore to DC2 and DS2 node types.
The number of megabytes that have been transferred from snapshot storage. This field is only updated when you restore to DC2 and DS2 node types.
The amount of time an in-progress restore has been running, or the amount of time it took a completed restore to finish. This field is only updated when you restore to DC2 and DS2 node types.
The estimate of the time remaining before the restore will complete. Returns 0 for a completed restore. This field is only updated when you restore to DC2 and DS2 node types.
Describes the status of the cluster. While the transfer is in progress the status is transferringdata .
Describes the data transfer rate in MB's per second.
Describes the total amount of data to be transfered in megabytes.
Describes the total amount of data that has been transfered in MB's.
Describes the estimated number of seconds remaining to complete the transfer.
Describes the number of seconds that have elapsed during the data transfer.
A value that reports whether the Amazon Redshift cluster has finished applying any hardware security module (HSM) settings changes specified in a modify cluster command.
Values: active, applying
Specifies the name of the HSM client certificate the Amazon Redshift cluster uses to retrieve the data encryption keys stored in an HSM.
Specifies the name of the HSM configuration that contains the information the Amazon Redshift cluster can use to retrieve and store keys in an HSM.
Reports whether the Amazon Redshift cluster has finished applying any HSM settings changes specified in a modify cluster command.
Values: active, applying
A value that returns the destination region and retention period that are configured for cross-region snapshot copy.
The destination region that snapshots are automatically copied to when cross-region snapshot copy is enabled.
The number of days that automated snapshots are retained in the destination region after they are copied from a source region.
The number of days that automated snapshots are retained in the destination region after they are copied from a source region. If the value is -1, the manual snapshot is retained indefinitely.
The value must be either -1 or an integer between 1 and 3,653.
The name of the snapshot copy grant.
The public key for the cluster.
The nodes in the cluster.
The identifier of a node in a cluster.
Whether the node is a leader node or a compute node.
The private IP address of a node within a cluster.
The public IP address of a node within a cluster.
The status of the elastic IP (EIP) address.
The elastic IP (EIP) address for the cluster.
The status of the elastic IP (EIP) address.
The specific revision number of the database in the cluster.
The list of tags for the cluster.
A tag consisting of a name/value pair for a resource.
The key, or name, for the resource tag.
The value for the resource tag.
The Key Management Service (KMS) key ID of the encryption key used to encrypt data in the cluster.
An option that specifies whether to create the cluster with enhanced VPC routing enabled. To create a cluster that uses enhanced VPC routing, the cluster must be in a VPC. For more information, see Enhanced VPC Routing in the Amazon Redshift Cluster Management Guide.
If this option is true , enhanced VPC routing is enabled.
Default: false
A list of Identity and Access Management (IAM) roles that can be used by the cluster to access other Amazon Web Services services.
An Identity and Access Management (IAM) role that can be used by the associated Amazon Redshift cluster to access other Amazon Web Services services.
The Amazon Resource Name (ARN) of the IAM role, for example, arn:aws:iam::123456789012:role/RedshiftCopyUnload .
A value that describes the status of the IAM role's association with an Amazon Redshift cluster.
The following are possible statuses and descriptions.
in-sync : The role is available for use by the cluster.adding : The role is in the process of being associated with the cluster.removing : The role is in the process of being disassociated with the cluster.Cluster operations that are waiting to be started.
The name of the maintenance track for the cluster.
The number of nodes that you can resize the cluster to with the elastic resize method.
Describes a group of DeferredMaintenanceWindow objects.
Describes a deferred maintenance window
A unique identifier for the maintenance window.
A timestamp for the beginning of the time period when we defer maintenance.
A timestamp for the end of the time period when we defer maintenance.
A unique identifier for the cluster snapshot schedule.
The current state of the cluster snapshot schedule.
The date and time when the next snapshot is expected to be taken for clusters with a valid snapshot schedule and backups enabled.
The status of next expected snapshot for clusters having a valid snapshot schedule and backups enabled. Possible values are the following:
The date and time in UTC when system maintenance can begin.
Returns the following:
Returns the value ClassicResize .
A boolean value indicating if the resize operation can be cancelled.
Describes the status of the Availability Zone relocation operation.
The namespace Amazon Resource Name (ARN) of the cluster.
The total storage capacity of the cluster in megabytes.
This field is retired. Amazon Redshift automatically determines whether to use AQUA (Advanced Query Accelerator).
This field is retired. Amazon Redshift automatically determines whether to use AQUA (Advanced Query Accelerator).
This field is retired. Amazon Redshift automatically determines whether to use AQUA (Advanced Query Accelerator).
The Amazon Resource Name (ARN) for the IAM role set as default for the cluster.
The status of the reserved-node exchange request. Statuses include in-progress and requested.
The identifier of the reserved-node exchange request.
The status of the reserved-node exchange request. Statuses include in-progress and requested.
A date and time that indicate when the reserved-node exchange was requested.
The identifier of the source reserved node.
The source reserved-node type, for example ds2.xlarge.
The source reserved-node count in the cluster.
The identifier of the target reserved node offering.
The node type of the target reserved node, for example ra3.4xlarge.
The count of target reserved nodes in the cluster.
Exceptions
Redshift.Client.exceptions.ClusterNotFoundFaultRedshift.Client.exceptions.InvalidClusterStateFaultRedshift.Client.exceptions.DependentServiceRequestThrottlingFault