File: //usr/local/aws-cli/v2/current/dist/awscli/botocore/data/ec2/2016-11-15/service-2.json
{
  "version":"2.0",
  "metadata":{
    "apiVersion":"2016-11-15",
    "endpointPrefix":"ec2",
    "protocol":"ec2",
    "serviceAbbreviation":"Amazon EC2",
    "serviceFullName":"Amazon Elastic Compute Cloud",
    "serviceId":"EC2",
    "signatureVersion":"v4",
    "uid":"ec2-2016-11-15",
    "xmlNamespace":"http://ec2.amazonaws.com/doc/2016-11-15"
  },
  "operations":{
    "AcceptAddressTransfer":{
      "name":"AcceptAddressTransfer",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptAddressTransferRequest"},
      "output":{"shape":"AcceptAddressTransferResult"},
      "documentation":"<p>Accepts an Elastic IP address transfer. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-eips.html#using-instance-addressing-eips-transfer-accept\">Accept a transferred Elastic IP address</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AcceptReservedInstancesExchangeQuote":{
      "name":"AcceptReservedInstancesExchangeQuote",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptReservedInstancesExchangeQuoteRequest"},
      "output":{"shape":"AcceptReservedInstancesExchangeQuoteResult"},
      "documentation":"<p>Accepts the Convertible Reserved Instance exchange quote described in the <a>GetReservedInstancesExchangeQuote</a> call.</p>"
    },
    "AcceptTransitGatewayMulticastDomainAssociations":{
      "name":"AcceptTransitGatewayMulticastDomainAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptTransitGatewayMulticastDomainAssociationsRequest"},
      "output":{"shape":"AcceptTransitGatewayMulticastDomainAssociationsResult"},
      "documentation":"<p>Accepts a request to associate subnets with a transit gateway multicast domain.</p>"
    },
    "AcceptTransitGatewayPeeringAttachment":{
      "name":"AcceptTransitGatewayPeeringAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptTransitGatewayPeeringAttachmentRequest"},
      "output":{"shape":"AcceptTransitGatewayPeeringAttachmentResult"},
      "documentation":"<p>Accepts a transit gateway peering attachment request. The peering attachment must be in the <code>pendingAcceptance</code> state.</p>"
    },
    "AcceptTransitGatewayVpcAttachment":{
      "name":"AcceptTransitGatewayVpcAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptTransitGatewayVpcAttachmentRequest"},
      "output":{"shape":"AcceptTransitGatewayVpcAttachmentResult"},
      "documentation":"<p>Accepts a request to attach a VPC to a transit gateway.</p> <p>The VPC attachment must be in the <code>pendingAcceptance</code> state. Use <a>DescribeTransitGatewayVpcAttachments</a> to view your pending VPC attachment requests. Use <a>RejectTransitGatewayVpcAttachment</a> to reject a VPC attachment request.</p>"
    },
    "AcceptVpcEndpointConnections":{
      "name":"AcceptVpcEndpointConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptVpcEndpointConnectionsRequest"},
      "output":{"shape":"AcceptVpcEndpointConnectionsResult"},
      "documentation":"<p>Accepts connection requests to your VPC endpoint service.</p>"
    },
    "AcceptVpcPeeringConnection":{
      "name":"AcceptVpcPeeringConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AcceptVpcPeeringConnectionRequest"},
      "output":{"shape":"AcceptVpcPeeringConnectionResult"},
      "documentation":"<p>Accept a VPC peering connection request. To accept a request, the VPC peering connection must be in the <code>pending-acceptance</code> state, and you must be the owner of the peer VPC. Use <a>DescribeVpcPeeringConnections</a> to view your outstanding VPC peering connection requests.</p> <p>For an inter-Region VPC peering connection request, you must accept the VPC peering connection in the Region of the accepter VPC.</p>"
    },
    "AdvertiseByoipCidr":{
      "name":"AdvertiseByoipCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AdvertiseByoipCidrRequest"},
      "output":{"shape":"AdvertiseByoipCidrResult"},
      "documentation":"<p>Advertises an IPv4 or IPv6 address range that is provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP).</p> <p>You can perform this operation at most once every 10 seconds, even if you specify different address ranges each time.</p> <p>We recommend that you stop advertising the BYOIP CIDR from other locations when you advertise it from Amazon Web Services. To minimize down time, you can configure your Amazon Web Services resources to use an address from a BYOIP CIDR before it is advertised, and then simultaneously stop advertising it from the current location and start advertising it through Amazon Web Services.</p> <p>It can take a few minutes before traffic to the specified addresses starts routing to Amazon Web Services because of BGP propagation delays.</p> <p>To stop advertising the BYOIP CIDR, use <a>WithdrawByoipCidr</a>.</p>"
    },
    "AllocateAddress":{
      "name":"AllocateAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AllocateAddressRequest"},
      "output":{"shape":"AllocateAddressResult"},
      "documentation":"<p>Allocates an Elastic IP address to your Amazon Web Services account. After you allocate the Elastic IP address you can associate it with an instance or network interface. After you release an Elastic IP address, it is released to the IP address pool and can be allocated to a different Amazon Web Services account.</p> <p>You can allocate an Elastic IP address from an address pool owned by Amazon Web Services or from an address pool created from a public IPv4 address range that you have brought to Amazon Web Services for use with your Amazon Web Services resources using bring your own IP addresses (BYOIP). For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-byoip.html\">Bring Your Own IP Addresses (BYOIP)</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>[EC2-VPC] If you release an Elastic IP address, you might be able to recover it. You cannot recover an Elastic IP address that you released after it is allocated to another Amazon Web Services account. You cannot recover an Elastic IP address for EC2-Classic. To attempt to recover an Elastic IP address that you released, specify it in this operation.</p> <p>An Elastic IP address is for use either in the EC2-Classic platform or in a VPC. By default, you can allocate 5 Elastic IP addresses for EC2-Classic per Region and 5 Elastic IP addresses for EC2-VPC per Region.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html\">Elastic IP Addresses</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>You can allocate a carrier IP address which is a public IP address from a telecommunication carrier, to a network interface which resides in a subnet in a Wavelength Zone (for example an EC2 instance). </p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "AllocateHosts":{
      "name":"AllocateHosts",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AllocateHostsRequest"},
      "output":{"shape":"AllocateHostsResult"},
      "documentation":"<p>Allocates a Dedicated Host to your account. At a minimum, specify the supported instance type or instance family, the Availability Zone in which to allocate the host, and the number of hosts to allocate.</p>"
    },
    "AllocateIpamPoolCidr":{
      "name":"AllocateIpamPoolCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AllocateIpamPoolCidrRequest"},
      "output":{"shape":"AllocateIpamPoolCidrResult"},
      "documentation":"<p>Allocate a CIDR from an IPAM pool. In IPAM, an allocation is a CIDR assignment from an IPAM pool to another IPAM pool or to a resource. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/allocate-cidrs-ipam.html\">Allocate CIDRs</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "ApplySecurityGroupsToClientVpnTargetNetwork":{
      "name":"ApplySecurityGroupsToClientVpnTargetNetwork",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ApplySecurityGroupsToClientVpnTargetNetworkRequest"},
      "output":{"shape":"ApplySecurityGroupsToClientVpnTargetNetworkResult"},
      "documentation":"<p>Applies a security group to the association between the target network and the Client VPN endpoint. This action replaces the existing security groups with the specified security groups.</p>"
    },
    "AssignIpv6Addresses":{
      "name":"AssignIpv6Addresses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssignIpv6AddressesRequest"},
      "output":{"shape":"AssignIpv6AddressesResult"},
      "documentation":"<p>Assigns one or more IPv6 addresses to the specified network interface. You can specify one or more specific IPv6 addresses, or you can specify the number of IPv6 addresses to be automatically assigned from within the subnet's IPv6 CIDR block range. You can assign as many IPv6 addresses to a network interface as you can assign private IPv4 addresses, and the limit varies per instance type. For information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#AvailableIpPerENI\">IP Addresses Per Network Interface Per Instance Type</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>You must specify either the IPv6 addresses or the IPv6 address count in the request. </p> <p>You can optionally use Prefix Delegation on the network interface. You must specify either the IPV6 Prefix Delegation prefixes, or the IPv6 Prefix Delegation count. For information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-prefix-eni.html\"> Assigning prefixes to Amazon EC2 network interfaces</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "AssignPrivateIpAddresses":{
      "name":"AssignPrivateIpAddresses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssignPrivateIpAddressesRequest"},
      "output":{"shape":"AssignPrivateIpAddressesResult"},
      "documentation":"<p>Assigns one or more secondary private IP addresses to the specified network interface.</p> <p>You can specify one or more specific secondary IP addresses, or you can specify the number of secondary IP addresses to be automatically assigned within the subnet's CIDR block range. The number of secondary IP addresses that you can assign to an instance varies by instance type. For information about instance types, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance Types</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>. For more information about Elastic IP addresses, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html\">Elastic IP Addresses</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>When you move a secondary private IP address to another network interface, any Elastic IP address that is associated with the IP address is also moved.</p> <p>Remapping an IP address is an asynchronous operation. When you move an IP address from one network interface to another, check <code>network/interfaces/macs/mac/local-ipv4s</code> in the instance metadata to confirm that the remapping is complete.</p> <p>You must specify either the IP addresses or the IP address count in the request.</p> <p>You can optionally use Prefix Delegation on the network interface. You must specify either the IPv4 Prefix Delegation prefixes, or the IPv4 Prefix Delegation count. For information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-prefix-eni.html\"> Assigning prefixes to Amazon EC2 network interfaces</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "AssignPrivateNatGatewayAddress":{
      "name":"AssignPrivateNatGatewayAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssignPrivateNatGatewayAddressRequest"},
      "output":{"shape":"AssignPrivateNatGatewayAddressResult"},
      "documentation":"<p>Assigns one or more private IPv4 addresses to a private NAT gateway. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-working-with\">Work with NAT gateways</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AssociateAddress":{
      "name":"AssociateAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateAddressRequest"},
      "output":{"shape":"AssociateAddressResult"},
      "documentation":"<p>Associates an Elastic IP address, or carrier IP address (for instances that are in subnets in Wavelength Zones) with an instance or a network interface. Before you can use an Elastic IP address, you must allocate it to your account.</p> <p>An Elastic IP address is for use in either the EC2-Classic platform or in a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html\">Elastic IP Addresses</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>[EC2-Classic, VPC in an EC2-VPC-only account] If the Elastic IP address is already associated with a different instance, it is disassociated from that instance and associated with the specified instance. If you associate an Elastic IP address with an instance that has an existing Elastic IP address, the existing address is disassociated from the instance, but remains allocated to your account.</p> <p>[VPC in an EC2-Classic account] If you don't specify a private IP address, the Elastic IP address is associated with the primary IP address. If the Elastic IP address is already associated with a different instance or a network interface, you get an error unless you allow reassociation. You cannot associate an Elastic IP address with an instance or network interface that has an existing Elastic IP address.</p> <p>[Subnets in Wavelength Zones] You can associate an IP address from the telecommunication carrier to the instance or network interface. </p> <p>You cannot associate an Elastic IP address with an interface in a different network border group.</p> <important> <p>This is an idempotent operation. If you perform the operation more than once, Amazon EC2 doesn't return an error, and you may be charged for each time the Elastic IP address is remapped to the same instance. For more information, see the <i>Elastic IP Addresses</i> section of <a href=\"http://aws.amazon.com/ec2/pricing/\">Amazon EC2 Pricing</a>.</p> </important> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "AssociateClientVpnTargetNetwork":{
      "name":"AssociateClientVpnTargetNetwork",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateClientVpnTargetNetworkRequest"},
      "output":{"shape":"AssociateClientVpnTargetNetworkResult"},
      "documentation":"<p>Associates a target network with a Client VPN endpoint. A target network is a subnet in a VPC. You can associate multiple subnets from the same VPC with a Client VPN endpoint. You can associate only one subnet in each Availability Zone. We recommend that you associate at least two subnets to provide Availability Zone redundancy.</p> <p>If you specified a VPC when you created the Client VPN endpoint or if you have previous subnet associations, the specified subnet must be in the same VPC. To specify a subnet that's in a different VPC, you must first modify the Client VPN endpoint (<a>ModifyClientVpnEndpoint</a>) and change the VPC that's associated with it.</p>"
    },
    "AssociateDhcpOptions":{
      "name":"AssociateDhcpOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateDhcpOptionsRequest"},
      "documentation":"<p>Associates a set of DHCP options (that you've previously created) with the specified VPC, or associates no DHCP options with the VPC.</p> <p>After you associate the options with the VPC, any existing instances and all new instances that you launch in that VPC use the options. You don't need to restart or relaunch the instances. They automatically pick up the changes within a few hours, depending on how frequently the instance renews its DHCP lease. You can explicitly renew the lease using the operating system on the instance.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_DHCP_Options.html\">DHCP options sets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AssociateEnclaveCertificateIamRole":{
      "name":"AssociateEnclaveCertificateIamRole",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateEnclaveCertificateIamRoleRequest"},
      "output":{"shape":"AssociateEnclaveCertificateIamRoleResult"},
      "documentation":"<p>Associates an Identity and Access Management (IAM) role with an Certificate Manager (ACM) certificate. This enables the certificate to be used by the ACM for Nitro Enclaves application inside an enclave. For more information, see <a href=\"https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave-refapp.html\">Certificate Manager for Nitro Enclaves</a> in the <i>Amazon Web Services Nitro Enclaves User Guide</i>.</p> <p>When the IAM role is associated with the ACM certificate, the certificate, certificate chain, and encrypted private key are placed in an Amazon S3 location that only the associated IAM role can access. The private key of the certificate is encrypted with an Amazon Web Services managed key that has an attached attestation-based key policy.</p> <p>To enable the IAM role to access the Amazon S3 object, you must grant it permission to call <code>s3:GetObject</code> on the Amazon S3 bucket returned by the command. To enable the IAM role to access the KMS key, you must grant it permission to call <code>kms:Decrypt</code> on the KMS key returned by the command. For more information, see <a href=\"https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave-refapp.html#add-policy\"> Grant the role permission to access the certificate and encryption key</a> in the <i>Amazon Web Services Nitro Enclaves User Guide</i>.</p>"
    },
    "AssociateIamInstanceProfile":{
      "name":"AssociateIamInstanceProfile",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateIamInstanceProfileRequest"},
      "output":{"shape":"AssociateIamInstanceProfileResult"},
      "documentation":"<p>Associates an IAM instance profile with a running or stopped instance. You cannot associate more than one IAM instance profile with an instance.</p>"
    },
    "AssociateInstanceEventWindow":{
      "name":"AssociateInstanceEventWindow",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateInstanceEventWindowRequest"},
      "output":{"shape":"AssociateInstanceEventWindowResult"},
      "documentation":"<p>Associates one or more targets with an event window. Only one type of target (instance IDs, Dedicated Host IDs, or tags) can be specified with an event window.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/event-windows.html\">Define event windows for scheduled events</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "AssociateIpamResourceDiscovery":{
      "name":"AssociateIpamResourceDiscovery",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateIpamResourceDiscoveryRequest"},
      "output":{"shape":"AssociateIpamResourceDiscoveryResult"},
      "documentation":"<p>Associates an IPAM resource discovery with an Amazon VPC IPAM. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "AssociateNatGatewayAddress":{
      "name":"AssociateNatGatewayAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateNatGatewayAddressRequest"},
      "output":{"shape":"AssociateNatGatewayAddressResult"},
      "documentation":"<p>Associates Elastic IP addresses (EIPs) and private IPv4 addresses with a public NAT gateway. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-working-with\">Work with NAT gateways</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>By default, you can associate up to 2 Elastic IP addresses per public NAT gateway. You can increase the limit by requesting a quota adjustment. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html#vpc-limits-eips\">Elastic IP address quotas</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AssociateRouteTable":{
      "name":"AssociateRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateRouteTableRequest"},
      "output":{"shape":"AssociateRouteTableResult"},
      "documentation":"<p>Associates a subnet in your VPC or an internet gateway or virtual private gateway attached to your VPC with a route table in your VPC. This association causes traffic from the subnet or gateway to be routed according to the routes in the route table. The action returns an association ID, which you need in order to disassociate the route table later. A route table can be associated with multiple subnets.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AssociateSubnetCidrBlock":{
      "name":"AssociateSubnetCidrBlock",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateSubnetCidrBlockRequest"},
      "output":{"shape":"AssociateSubnetCidrBlockResult"},
      "documentation":"<p>Associates a CIDR block with your subnet. You can only associate a single IPv6 CIDR block with your subnet. An IPv6 CIDR block must have a prefix length of /64.</p>"
    },
    "AssociateTransitGatewayMulticastDomain":{
      "name":"AssociateTransitGatewayMulticastDomain",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateTransitGatewayMulticastDomainRequest"},
      "output":{"shape":"AssociateTransitGatewayMulticastDomainResult"},
      "documentation":"<p>Associates the specified subnets and transit gateway attachments with the specified transit gateway multicast domain.</p> <p>The transit gateway attachment must be in the available state before you can add a resource. Use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGatewayAttachments.html\">DescribeTransitGatewayAttachments</a> to see the state of the attachment.</p>"
    },
    "AssociateTransitGatewayPolicyTable":{
      "name":"AssociateTransitGatewayPolicyTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateTransitGatewayPolicyTableRequest"},
      "output":{"shape":"AssociateTransitGatewayPolicyTableResult"},
      "documentation":"<p>Associates the specified transit gateway attachment with a transit gateway policy table.</p>"
    },
    "AssociateTransitGatewayRouteTable":{
      "name":"AssociateTransitGatewayRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateTransitGatewayRouteTableRequest"},
      "output":{"shape":"AssociateTransitGatewayRouteTableResult"},
      "documentation":"<p>Associates the specified attachment with the specified transit gateway route table. You can associate only one route table with an attachment.</p>"
    },
    "AssociateTrunkInterface":{
      "name":"AssociateTrunkInterface",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateTrunkInterfaceRequest"},
      "output":{"shape":"AssociateTrunkInterfaceResult"},
      "documentation":"<note> <p>This API action is currently in <b>limited preview only</b>. If you are interested in using this feature, contact your account manager.</p> </note> <p>Associates a branch network interface with a trunk network interface.</p> <p>Before you create the association, run the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateNetworkInterface.html\">create-network-interface</a> command and set <code>--interface-type</code> to <code>trunk</code>. You must also create a network interface for each branch network interface that you want to associate with the trunk network interface.</p>"
    },
    "AssociateVpcCidrBlock":{
      "name":"AssociateVpcCidrBlock",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AssociateVpcCidrBlockRequest"},
      "output":{"shape":"AssociateVpcCidrBlockResult"},
      "documentation":"<p>Associates a CIDR block with your VPC. You can associate a secondary IPv4 CIDR block, an Amazon-provided IPv6 CIDR block, or an IPv6 CIDR block from an IPv6 address pool that you provisioned through bring your own IP addresses (<a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-byoip.html\">BYOIP</a>). The IPv6 CIDR block size is fixed at /56.</p> <p>You must specify one of the following in the request: an IPv4 CIDR block, an IPv6 pool, or an Amazon-provided IPv6 CIDR block.</p> <p>For more information about associating CIDR blocks with your VPC and applicable restrictions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html#VPC_Sizing\">VPC and subnet sizing</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AttachClassicLinkVpc":{
      "name":"AttachClassicLinkVpc",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AttachClassicLinkVpcRequest"},
      "output":{"shape":"AttachClassicLinkVpcResult"},
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Links an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groups. You cannot link an EC2-Classic instance to more than one VPC at a time. You can only link an instance that's in the <code>running</code> state. An instance is automatically unlinked from a VPC when it's stopped - you can link it to the VPC again when you restart it.</p> <p>After you've linked an instance, you cannot change the VPC security groups that are associated with it. To change the security groups, you must first unlink the instance, and then link it again.</p> <p>Linking your instance to a VPC is sometimes referred to as <i>attaching</i> your instance.</p>"
    },
    "AttachInternetGateway":{
      "name":"AttachInternetGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AttachInternetGatewayRequest"},
      "documentation":"<p>Attaches an internet gateway or a virtual private gateway to a VPC, enabling connectivity between the internet and the VPC. For more information about your VPC and internet gateway, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/\">Amazon Virtual Private Cloud User Guide</a>.</p>"
    },
    "AttachNetworkInterface":{
      "name":"AttachNetworkInterface",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AttachNetworkInterfaceRequest"},
      "output":{"shape":"AttachNetworkInterfaceResult"},
      "documentation":"<p>Attaches a network interface to an instance.</p>"
    },
    "AttachVerifiedAccessTrustProvider":{
      "name":"AttachVerifiedAccessTrustProvider",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AttachVerifiedAccessTrustProviderRequest"},
      "output":{"shape":"AttachVerifiedAccessTrustProviderResult"},
      "documentation":"<p>A trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices. One or more trust providers can be attached to an Amazon Web Services Verified Access instance.</p>"
    },
    "AttachVolume":{
      "name":"AttachVolume",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AttachVolumeRequest"},
      "output":{"shape":"VolumeAttachment"},
      "documentation":"<p>Attaches an EBS volume to a running or stopped instance and exposes it to the instance with the specified device name.</p> <p>Encrypted EBS volumes must be attached to instances that support Amazon EBS encryption. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>After you attach an EBS volume, you must make it available. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-using-volumes.html\">Make an EBS volume available for use</a>.</p> <p>If a volume has an Amazon Web Services Marketplace product code:</p> <ul> <li> <p>The volume can be attached only to a stopped instance.</p> </li> <li> <p>Amazon Web Services Marketplace product codes are copied from the volume to the instance.</p> </li> <li> <p>You must be subscribed to the product.</p> </li> <li> <p>The instance type and operating system of the instance must support the product. For example, you can't detach a volume from a Windows instance and attach it to a Linux instance.</p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-attaching-volume.html\">Attach an Amazon EBS volume to an instance</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "AttachVpnGateway":{
      "name":"AttachVpnGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AttachVpnGatewayRequest"},
      "output":{"shape":"AttachVpnGatewayResult"},
      "documentation":"<p>Attaches a virtual private gateway to a VPC. You can attach one virtual private gateway to one VPC at a time.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "AuthorizeClientVpnIngress":{
      "name":"AuthorizeClientVpnIngress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AuthorizeClientVpnIngressRequest"},
      "output":{"shape":"AuthorizeClientVpnIngressResult"},
      "documentation":"<p>Adds an ingress authorization rule to a Client VPN endpoint. Ingress authorization rules act as firewall rules that grant access to networks. You must configure ingress authorization rules to enable clients to access resources in Amazon Web Services or on-premises networks.</p>"
    },
    "AuthorizeSecurityGroupEgress":{
      "name":"AuthorizeSecurityGroupEgress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AuthorizeSecurityGroupEgressRequest"},
      "output":{"shape":"AuthorizeSecurityGroupEgressResult"},
      "documentation":"<p>[VPC only] Adds the specified outbound (egress) rules to a security group for use with a VPC.</p> <p>An outbound rule permits instances to send traffic to the specified IPv4 or IPv6 CIDR address ranges, or to the instances that are associated with the specified source security groups. When specifying an outbound rule for your security group in a VPC, the <code>IpPermissions</code> must include a destination for the traffic.</p> <p>You specify a protocol for each rule (for example, TCP). For the TCP and UDP protocols, you must also specify the destination port or port range. For the ICMP protocol, you must also specify the ICMP type and code. You can use -1 for the type or code to mean all types or all codes.</p> <p>Rule changes are propagated to affected instances as quickly as possible. However, a small delay might occur.</p> <p>For information about VPC security group quotas, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html\">Amazon VPC quotas</a>.</p>"
    },
    "AuthorizeSecurityGroupIngress":{
      "name":"AuthorizeSecurityGroupIngress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"AuthorizeSecurityGroupIngressRequest"},
      "output":{"shape":"AuthorizeSecurityGroupIngressResult"},
      "documentation":"<p>Adds the specified inbound (ingress) rules to a security group.</p> <p>An inbound rule permits instances to receive traffic from the specified IPv4 or IPv6 CIDR address range, or from the instances that are associated with the specified destination security groups. When specifying an inbound rule for your security group in a VPC, the <code>IpPermissions</code> must include a source for the traffic.</p> <p>You specify a protocol for each rule (for example, TCP). For TCP and UDP, you must also specify the destination port or port range. For ICMP/ICMPv6, you must also specify the ICMP/ICMPv6 type and code. You can use -1 to mean all types or all codes.</p> <p>Rule changes are propagated to instances within the security group as quickly as possible. However, a small delay might occur.</p> <p>For more information about VPC security group quotas, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html\">Amazon VPC quotas</a>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "BundleInstance":{
      "name":"BundleInstance",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"BundleInstanceRequest"},
      "output":{"shape":"BundleInstanceResult"},
      "documentation":"<p>Bundles an Amazon instance store-backed Windows instance.</p> <p>During bundling, only the root device volume (C:\\) is bundled. Data on other instance store volumes is not preserved.</p> <note> <p>This action is not applicable for Linux/Unix instances or Windows instances that are backed by Amazon EBS.</p> </note>"
    },
    "CancelBundleTask":{
      "name":"CancelBundleTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelBundleTaskRequest"},
      "output":{"shape":"CancelBundleTaskResult"},
      "documentation":"<p>Cancels a bundling operation for an instance store-backed Windows instance.</p>"
    },
    "CancelCapacityReservation":{
      "name":"CancelCapacityReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelCapacityReservationRequest"},
      "output":{"shape":"CancelCapacityReservationResult"},
      "documentation":"<p>Cancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to <code>cancelled</code>.</p> <p>Instances running in the reserved capacity continue running until you stop them. Stopped instances that target the Capacity Reservation can no longer launch. Modify these instances to either target a different Capacity Reservation, launch On-Demand Instance capacity, or run in any open Capacity Reservation that has matching attributes and sufficient capacity.</p>"
    },
    "CancelCapacityReservationFleets":{
      "name":"CancelCapacityReservationFleets",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelCapacityReservationFleetsRequest"},
      "output":{"shape":"CancelCapacityReservationFleetsResult"},
      "documentation":"<p>Cancels one or more Capacity Reservation Fleets. When you cancel a Capacity Reservation Fleet, the following happens:</p> <ul> <li> <p>The Capacity Reservation Fleet's status changes to <code>cancelled</code>.</p> </li> <li> <p>The individual Capacity Reservations in the Fleet are cancelled. Instances running in the Capacity Reservations at the time of cancelling the Fleet continue to run in shared capacity.</p> </li> <li> <p>The Fleet stops creating new Capacity Reservations.</p> </li> </ul>"
    },
    "CancelConversionTask":{
      "name":"CancelConversionTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelConversionRequest"},
      "documentation":"<p>Cancels an active conversion task. The task can be the import of an instance or volume. The action removes all artifacts of the conversion, including a partially uploaded volume or instance. If the conversion is complete or is in the process of transferring the final disk image, the command fails and returns an exception.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/CommandLineReference/ec2-cli-vmimport-export.html\">Importing a Virtual Machine Using the Amazon EC2 CLI</a>.</p>"
    },
    "CancelExportTask":{
      "name":"CancelExportTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelExportTaskRequest"},
      "documentation":"<p>Cancels an active export task. The request removes all artifacts of the export, including any partially-created Amazon S3 objects. If the export task is complete or is in the process of transferring the final disk image, the command fails and returns an error.</p>"
    },
    "CancelImageLaunchPermission":{
      "name":"CancelImageLaunchPermission",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelImageLaunchPermissionRequest"},
      "output":{"shape":"CancelImageLaunchPermissionResult"},
      "documentation":"<p>Removes your Amazon Web Services account from the launch permissions for the specified AMI. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/cancel-sharing-an-AMI.html\"> Cancel having an AMI shared with your Amazon Web Services account</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CancelImportTask":{
      "name":"CancelImportTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelImportTaskRequest"},
      "output":{"shape":"CancelImportTaskResult"},
      "documentation":"<p>Cancels an in-process import virtual machine or import snapshot task.</p>"
    },
    "CancelReservedInstancesListing":{
      "name":"CancelReservedInstancesListing",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelReservedInstancesListingRequest"},
      "output":{"shape":"CancelReservedInstancesListingResult"},
      "documentation":"<p>Cancels the specified Reserved Instance listing in the Reserved Instance Marketplace.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-market-general.html\">Reserved Instance Marketplace</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CancelSpotFleetRequests":{
      "name":"CancelSpotFleetRequests",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelSpotFleetRequestsRequest"},
      "output":{"shape":"CancelSpotFleetRequestsResponse"},
      "documentation":"<p>Cancels the specified Spot Fleet requests.</p> <p>After you cancel a Spot Fleet request, the Spot Fleet launches no new Spot Instances. You must specify whether the Spot Fleet should also terminate its Spot Instances. If you terminate the instances, the Spot Fleet request enters the <code>cancelled_terminating</code> state. Otherwise, the Spot Fleet request enters the <code>cancelled_running</code> state and the instances continue to run until they are interrupted or you terminate them manually.</p>"
    },
    "CancelSpotInstanceRequests":{
      "name":"CancelSpotInstanceRequests",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CancelSpotInstanceRequestsRequest"},
      "output":{"shape":"CancelSpotInstanceRequestsResult"},
      "documentation":"<p>Cancels one or more Spot Instance requests.</p> <important> <p>Canceling a Spot Instance request does not terminate running Spot Instances associated with the request.</p> </important>"
    },
    "ConfirmProductInstance":{
      "name":"ConfirmProductInstance",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ConfirmProductInstanceRequest"},
      "output":{"shape":"ConfirmProductInstanceResult"},
      "documentation":"<p>Determines whether a product code is associated with an instance. This action can only be used by the owner of the product code. It is useful when a product code owner must verify whether another user's instance is eligible for support.</p>"
    },
    "CopyFpgaImage":{
      "name":"CopyFpgaImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CopyFpgaImageRequest"},
      "output":{"shape":"CopyFpgaImageResult"},
      "documentation":"<p>Copies the specified Amazon FPGA Image (AFI) to the current Region.</p>"
    },
    "CopyImage":{
      "name":"CopyImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CopyImageRequest"},
      "output":{"shape":"CopyImageResult"},
      "documentation":"<p>Initiates the copy of an AMI. You can copy an AMI from one Region to another, or from a Region to an Outpost. You can't copy an AMI from an Outpost to a Region, from one Outpost to another, or within the same Outpost. To copy an AMI to another partition, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateStoreImageTask.html\">CreateStoreImageTask</a>.</p> <p>To copy an AMI from one Region to another, specify the source Region using the <b>SourceRegion</b> parameter, and specify the destination Region using its endpoint. Copies of encrypted backing snapshots for the AMI are encrypted. Copies of unencrypted backing snapshots remain unencrypted, unless you set <code>Encrypted</code> during the copy operation. You cannot create an unencrypted copy of an encrypted backing snapshot.</p> <p>To copy an AMI from a Region to an Outpost, specify the source Region using the <b>SourceRegion</b> parameter, and specify the ARN of the destination Outpost using <b>DestinationOutpostArn</b>. Backing snapshots copied to an Outpost are encrypted by default using the default encryption key for the Region, or a different key that you specify in the request using <b>KmsKeyId</b>. Outposts do not support unencrypted snapshots. For more information, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#ami\"> Amazon EBS local snapshots on Outposts</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For more information about the prerequisites and limits when copying an AMI, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/CopyingAMIs.html\">Copy an AMI</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CopySnapshot":{
      "name":"CopySnapshot",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CopySnapshotRequest"},
      "output":{"shape":"CopySnapshotResult"},
      "documentation":"<p>Copies a point-in-time snapshot of an EBS volume and stores it in Amazon S3. You can copy a snapshot within the same Region, from one Region to another, or from a Region to an Outpost. You can't copy a snapshot from an Outpost to a Region, from one Outpost to another, or within the same Outpost.</p> <p>You can use the snapshot to create EBS volumes or Amazon Machine Images (AMIs).</p> <p>When copying snapshots to a Region, copies of encrypted EBS snapshots remain encrypted. Copies of unencrypted snapshots remain unencrypted, unless you enable encryption for the snapshot copy operation. By default, encrypted snapshot copies use the default Key Management Service (KMS) KMS key; however, you can specify a different KMS key. To copy an encrypted snapshot that has been shared from another account, you must have permissions for the KMS key used to encrypt the snapshot.</p> <p>Snapshots copied to an Outpost are encrypted by default using the default encryption key for the Region, or a different key that you specify in the request using <b>KmsKeyId</b>. Outposts do not support unencrypted snapshots. For more information, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#ami\"> Amazon EBS local snapshots on Outposts</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Snapshots created by copying another snapshot have an arbitrary volume ID that should not be used for any purpose.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-copy-snapshot.html\">Copy an Amazon EBS snapshot</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateCapacityReservation":{
      "name":"CreateCapacityReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateCapacityReservationRequest"},
      "output":{"shape":"CreateCapacityReservationResult"},
      "documentation":"<p>Creates a new Capacity Reservation with the specified attributes.</p> <p>Capacity Reservations enable you to reserve capacity for your Amazon EC2 instances in a specific Availability Zone for any duration. This gives you the flexibility to selectively add capacity reservations and still get the Regional RI discounts for that usage. By creating Capacity Reservations, you ensure that you always have access to Amazon EC2 capacity when you need it, for as long as you need it. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-capacity-reservations.html\">Capacity Reservations</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Your request to create a Capacity Reservation could fail if Amazon EC2 does not have sufficient capacity to fulfill the request. If your request fails due to Amazon EC2 capacity constraints, either try again at a later time, try in a different Availability Zone, or request a smaller capacity reservation. If your application is flexible across instance types and sizes, try to create a Capacity Reservation with different instance attributes.</p> <p>Your request could also fail if the requested quantity exceeds your On-Demand Instance limit for the selected instance type. If your request fails due to limit constraints, increase your On-Demand Instance limit for the required instance type and try again. For more information about increasing your instance limits, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-resource-limits.html\">Amazon EC2 Service Quotas</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreateCapacityReservationFleet":{
      "name":"CreateCapacityReservationFleet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateCapacityReservationFleetRequest"},
      "output":{"shape":"CreateCapacityReservationFleetResult"},
      "documentation":"<p>Creates a Capacity Reservation Fleet. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/work-with-cr-fleets.html#create-crfleet\">Create a Capacity Reservation Fleet</a> in the Amazon EC2 User Guide.</p>"
    },
    "CreateCarrierGateway":{
      "name":"CreateCarrierGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateCarrierGatewayRequest"},
      "output":{"shape":"CreateCarrierGatewayResult"},
      "documentation":"<p>Creates a carrier gateway. For more information about carrier gateways, see <a href=\"https://docs.aws.amazon.com/wavelength/latest/developerguide/how-wavelengths-work.html#wavelength-carrier-gateway\">Carrier gateways</a> in the <i>Amazon Web Services Wavelength Developer Guide</i>.</p>"
    },
    "CreateClientVpnEndpoint":{
      "name":"CreateClientVpnEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateClientVpnEndpointRequest"},
      "output":{"shape":"CreateClientVpnEndpointResult"},
      "documentation":"<p>Creates a Client VPN endpoint. A Client VPN endpoint is the resource you create and configure to enable and manage client VPN sessions. It is the destination endpoint at which all client VPN sessions are terminated.</p>"
    },
    "CreateClientVpnRoute":{
      "name":"CreateClientVpnRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateClientVpnRouteRequest"},
      "output":{"shape":"CreateClientVpnRouteResult"},
      "documentation":"<p>Adds a route to a network to a Client VPN endpoint. Each Client VPN endpoint has a route table that describes the available destination network routes. Each route in the route table specifies the path for traffic to specific resources or networks.</p>"
    },
    "CreateCoipCidr":{
      "name":"CreateCoipCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateCoipCidrRequest"},
      "output":{"shape":"CreateCoipCidrResult"},
      "documentation":"<p> Creates a range of customer-owned IP addresses. </p>"
    },
    "CreateCoipPool":{
      "name":"CreateCoipPool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateCoipPoolRequest"},
      "output":{"shape":"CreateCoipPoolResult"},
      "documentation":"<p> Creates a pool of customer-owned IP (CoIP) addresses. </p>"
    },
    "CreateCustomerGateway":{
      "name":"CreateCustomerGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateCustomerGatewayRequest"},
      "output":{"shape":"CreateCustomerGatewayResult"},
      "documentation":"<p>Provides information to Amazon Web Services about your customer gateway device. The customer gateway device is the appliance at your end of the VPN connection. You must provide the IP address of the customer gateway device’s external interface. The IP address must be static and can be behind a device performing network address translation (NAT).</p> <p>For devices that use Border Gateway Protocol (BGP), you can also provide the device's BGP Autonomous System Number (ASN). You can use an existing ASN assigned to your network. If you don't have an ASN already, you can use a private ASN. For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-options.html\">Customer gateway options for your Site-to-Site VPN connection</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p> <p>To create more than one customer gateway with the same VPN type, IP address, and BGP ASN, specify a unique device name for each customer gateway. An identical request returns information about the existing customer gateway; it doesn't create a new customer gateway.</p>"
    },
    "CreateDefaultSubnet":{
      "name":"CreateDefaultSubnet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateDefaultSubnetRequest"},
      "output":{"shape":"CreateDefaultSubnetResult"},
      "documentation":"<p>Creates a default subnet with a size <code>/20</code> IPv4 CIDR block in the specified Availability Zone in your default VPC. You can have only one default subnet per Availability Zone. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/default-vpc.html#create-default-subnet\">Creating a default subnet</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateDefaultVpc":{
      "name":"CreateDefaultVpc",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateDefaultVpcRequest"},
      "output":{"shape":"CreateDefaultVpcResult"},
      "documentation":"<p>Creates a default VPC with a size <code>/16</code> IPv4 CIDR block and a default subnet in each Availability Zone. For more information about the components of a default VPC, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/default-vpc.html\">Default VPC and default subnets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>. You cannot specify the components of the default VPC yourself.</p> <p>If you deleted your previous default VPC, you can create a default VPC. You cannot have more than one default VPC per Region.</p> <p>If your account supports EC2-Classic, you cannot use this action to create a default VPC in a Region that supports EC2-Classic. If you want a default VPC in a Region that supports EC2-Classic, see \"I really want a default VPC for my existing EC2 account. Is that possible?\" in the <a href=\"http://aws.amazon.com/vpc/faqs/#Default_VPCs\">Default VPCs FAQ</a>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "CreateDhcpOptions":{
      "name":"CreateDhcpOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateDhcpOptionsRequest"},
      "output":{"shape":"CreateDhcpOptionsResult"},
      "documentation":"<p>Creates a set of DHCP options for your VPC. After creating the set, you must associate it with the VPC, causing all existing and new instances that you launch in the VPC to use this set of DHCP options. The following are the individual DHCP options you can specify. For more information about the options, see <a href=\"http://www.ietf.org/rfc/rfc2132.txt\">RFC 2132</a>.</p> <ul> <li> <p> <code>domain-name-servers</code> - The IP addresses of up to four domain name servers, or AmazonProvidedDNS. The default DHCP option set specifies AmazonProvidedDNS. If specifying more than one domain name server, specify the IP addresses in a single parameter, separated by commas. To have your instance receive a custom DNS hostname as specified in <code>domain-name</code>, you must set <code>domain-name-servers</code> to a custom DNS server.</p> </li> <li> <p> <code>domain-name</code> - If you're using AmazonProvidedDNS in <code>us-east-1</code>, specify <code>ec2.internal</code>. If you're using AmazonProvidedDNS in another Region, specify <code>region.compute.internal</code> (for example, <code>ap-northeast-1.compute.internal</code>). Otherwise, specify a domain name (for example, <code>ExampleCompany.com</code>). This value is used to complete unqualified DNS hostnames. <b>Important</b>: Some Linux operating systems accept multiple domain names separated by spaces. However, Windows and other Linux operating systems treat the value as a single domain, which results in unexpected behavior. If your DHCP options set is associated with a VPC that has instances with multiple operating systems, specify only one domain name.</p> </li> <li> <p> <code>ntp-servers</code> - The IP addresses of up to four Network Time Protocol (NTP) servers.</p> </li> <li> <p> <code>netbios-name-servers</code> - The IP addresses of up to four NetBIOS name servers.</p> </li> <li> <p> <code>netbios-node-type</code> - The NetBIOS node type (1, 2, 4, or 8). We recommend that you specify 2 (broadcast and multicast are not currently supported). For more information about these node types, see <a href=\"http://www.ietf.org/rfc/rfc2132.txt\">RFC 2132</a>.</p> </li> </ul> <p>Your VPC automatically starts out with a set of DHCP options that includes only a DNS server that we provide (AmazonProvidedDNS). If you create a set of options, and if your VPC has an internet gateway, make sure to set the <code>domain-name-servers</code> option either to <code>AmazonProvidedDNS</code> or to a domain name server of your choice. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_DHCP_Options.html\">DHCP options sets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateEgressOnlyInternetGateway":{
      "name":"CreateEgressOnlyInternetGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateEgressOnlyInternetGatewayRequest"},
      "output":{"shape":"CreateEgressOnlyInternetGatewayResult"},
      "documentation":"<p>[IPv6 only] Creates an egress-only internet gateway for your VPC. An egress-only internet gateway is used to enable outbound communication over IPv6 from instances in your VPC to the internet, and prevents hosts outside of your VPC from initiating an IPv6 connection with your instance.</p>"
    },
    "CreateFleet":{
      "name":"CreateFleet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateFleetRequest"},
      "output":{"shape":"CreateFleetResult"},
      "documentation":"<p>Launches an EC2 Fleet.</p> <p>You can create a single EC2 Fleet that includes multiple launch specifications that vary by instance type, AMI, Availability Zone, or subnet.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet.html\">EC2 Fleet</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreateFlowLogs":{
      "name":"CreateFlowLogs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateFlowLogsRequest"},
      "output":{"shape":"CreateFlowLogsResult"},
      "documentation":"<p>Creates one or more flow logs to capture information about IP traffic for a specific network interface, subnet, or VPC. </p> <p>Flow log data for a monitored network interface is recorded as flow log records, which are log events consisting of fields that describe the traffic flow. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html#flow-log-records\">Flow log records</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>When publishing to CloudWatch Logs, flow log records are published to a log group, and each network interface has a unique log stream in the log group. When publishing to Amazon S3, flow log records for all of the monitored network interfaces are published to a single log file object that is stored in the specified bucket.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html\">VPC Flow Logs</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateFpgaImage":{
      "name":"CreateFpgaImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateFpgaImageRequest"},
      "output":{"shape":"CreateFpgaImageResult"},
      "documentation":"<p>Creates an Amazon FPGA Image (AFI) from the specified design checkpoint (DCP).</p> <p>The create operation is asynchronous. To verify that the AFI is ready for use, check the output logs.</p> <p>An AFI contains the FPGA bitstream that is ready to download to an FPGA. You can securely deploy an AFI on multiple FPGA-accelerated instances. For more information, see the <a href=\"https://github.com/aws/aws-fpga/\">Amazon Web Services FPGA Hardware Development Kit</a>.</p>"
    },
    "CreateImage":{
      "name":"CreateImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateImageRequest"},
      "output":{"shape":"CreateImageResult"},
      "documentation":"<p>Creates an Amazon EBS-backed AMI from an Amazon EBS-backed instance that is either running or stopped.</p> <p>By default, when Amazon EC2 creates the new AMI, it reboots the instance so that it can take snapshots of the attached volumes while data is at rest, in order to ensure a consistent state. You can set the <code>NoReboot</code> parameter to <code>true</code> in the API request, or use the <code>--no-reboot</code> option in the CLI to prevent Amazon EC2 from shutting down and rebooting the instance.</p> <important> <p>If you choose to bypass the shutdown and reboot process by setting the <code>NoReboot</code> parameter to <code>true</code> in the API request, or by using the <code>--no-reboot</code> option in the CLI, we can't guarantee the file system integrity of the created image.</p> </important> <p>If you customized your instance with instance store volumes or Amazon EBS volumes in addition to the root device volume, the new AMI contains block device mapping information for those volumes. When you launch an instance from this new AMI, the instance automatically launches with those additional volumes.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/creating-an-ami-ebs.html\">Create an Amazon EBS-backed Linux AMI</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateInstanceEventWindow":{
      "name":"CreateInstanceEventWindow",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateInstanceEventWindowRequest"},
      "output":{"shape":"CreateInstanceEventWindowResult"},
      "documentation":"<p>Creates an event window in which scheduled events for the associated Amazon EC2 instances can run.</p> <p>You can define either a set of time ranges or a cron expression when creating the event window, but not both. All event window times are in UTC.</p> <p>You can create up to 200 event windows per Amazon Web Services Region.</p> <p>When you create the event window, targets (instance IDs, Dedicated Host IDs, or tags) are not yet associated with it. To ensure that the event window can be used, you must associate one or more targets with it by using the <a>AssociateInstanceEventWindow</a> API.</p> <important> <p>Event windows are applicable only for scheduled events that stop, reboot, or terminate instances.</p> <p>Event windows are <i>not</i> applicable for:</p> <ul> <li> <p>Expedited scheduled events and network maintenance events. </p> </li> <li> <p>Unscheduled maintenance such as AutoRecovery and unplanned reboots.</p> </li> </ul> </important> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/event-windows.html\">Define event windows for scheduled events</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreateInstanceExportTask":{
      "name":"CreateInstanceExportTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateInstanceExportTaskRequest"},
      "output":{"shape":"CreateInstanceExportTaskResult"},
      "documentation":"<p>Exports a running or stopped instance to an Amazon S3 bucket.</p> <p>For information about the supported operating systems, image formats, and known limitations for the types of instances you can export, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport.html\">Exporting an instance as a VM Using VM Import/Export</a> in the <i>VM Import/Export User Guide</i>.</p>"
    },
    "CreateInternetGateway":{
      "name":"CreateInternetGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateInternetGatewayRequest"},
      "output":{"shape":"CreateInternetGatewayResult"},
      "documentation":"<p>Creates an internet gateway for use with a VPC. After creating the internet gateway, you attach it to a VPC using <a>AttachInternetGateway</a>.</p> <p>For more information about your VPC and internet gateway, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/\">Amazon Virtual Private Cloud User Guide</a>.</p>"
    },
    "CreateIpam":{
      "name":"CreateIpam",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateIpamRequest"},
      "output":{"shape":"CreateIpamResult"},
      "documentation":"<p>Create an IPAM. Amazon VPC IP Address Manager (IPAM) is a VPC feature that you can use to automate your IP address management workflows including assigning, tracking, troubleshooting, and auditing IP addresses across Amazon Web Services Regions and accounts throughout your Amazon Web Services Organization.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "CreateIpamPool":{
      "name":"CreateIpamPool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateIpamPoolRequest"},
      "output":{"shape":"CreateIpamPoolResult"},
      "documentation":"<p>Create an IP address pool for Amazon VPC IP Address Manager (IPAM). In IPAM, a pool is a collection of contiguous IP addresses CIDRs. Pools enable you to organize your IP addresses according to your routing and security needs. For example, if you have separate routing and security needs for development and production applications, you can create a pool for each.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-top-ipam.html\">Create a top-level pool</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "CreateIpamResourceDiscovery":{
      "name":"CreateIpamResourceDiscovery",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateIpamResourceDiscoveryRequest"},
      "output":{"shape":"CreateIpamResourceDiscoveryResult"},
      "documentation":"<p>Creates an IPAM resource discovery. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "CreateIpamScope":{
      "name":"CreateIpamScope",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateIpamScopeRequest"},
      "output":{"shape":"CreateIpamScopeResult"},
      "documentation":"<p>Create an IPAM scope. In IPAM, a scope is the highest-level container within IPAM. An IPAM contains two default scopes. Each scope represents the IP space for a single network. The private scope is intended for all private IP address space. The public scope is intended for all public IP address space. Scopes enable you to reuse IP addresses across multiple unconnected networks without causing IP address overlap or conflict.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/add-scope-ipam.html\">Add a scope</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "CreateKeyPair":{
      "name":"CreateKeyPair",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateKeyPairRequest"},
      "output":{"shape":"KeyPair"},
      "documentation":"<p>Creates an ED25519 or 2048-bit RSA key pair with the specified name and in the specified PEM or PPK format. Amazon EC2 stores the public key and displays the private key for you to save to a file. The private key is returned as an unencrypted PEM encoded PKCS#1 private key or an unencrypted PPK formatted private key for use with PuTTY. If a key with the specified name already exists, Amazon EC2 returns an error.</p> <p>The key pair returned to you is available only in the Amazon Web Services Region in which you create it. If you prefer, you can create your own key pair using a third-party tool and upload it to any Region using <a>ImportKeyPair</a>.</p> <p>You can have up to 5,000 key pairs per Amazon Web Services Region.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html\">Amazon EC2 key pairs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateLaunchTemplate":{
      "name":"CreateLaunchTemplate",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateLaunchTemplateRequest"},
      "output":{"shape":"CreateLaunchTemplateResult"},
      "documentation":"<p>Creates a launch template.</p> <p>A launch template contains the parameters to launch an instance. When you launch an instance using <a>RunInstances</a>, you can specify a launch template instead of providing the launch parameters in the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html\">Launch an instance from a launch template</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>If you want to clone an existing launch template as the basis for creating a new launch template, you can use the Amazon EC2 console. The API, SDKs, and CLI do not support cloning a template. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#create-launch-template-from-existing-launch-template\">Create a launch template from an existing launch template</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateLaunchTemplateVersion":{
      "name":"CreateLaunchTemplateVersion",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateLaunchTemplateVersionRequest"},
      "output":{"shape":"CreateLaunchTemplateVersionResult"},
      "documentation":"<p>Creates a new version of a launch template. You can specify an existing version of launch template from which to base the new version.</p> <p>Launch template versions are numbered in the order in which they are created. You cannot specify, change, or replace the numbering of launch template versions.</p> <p>Launch templates are immutable; after you create a launch template, you can't modify it. Instead, you can create a new version of the launch template that includes any changes you require.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#manage-launch-template-versions\">Modify a launch template (manage launch template versions)</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateLocalGatewayRoute":{
      "name":"CreateLocalGatewayRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateLocalGatewayRouteRequest"},
      "output":{"shape":"CreateLocalGatewayRouteResult"},
      "documentation":"<p>Creates a static route for the specified local gateway route table. You must specify one of the following targets: </p> <ul> <li> <p> <code>LocalGatewayVirtualInterfaceGroupId</code> </p> </li> <li> <p> <code>NetworkInterfaceId</code> </p> </li> </ul>"
    },
    "CreateLocalGatewayRouteTable":{
      "name":"CreateLocalGatewayRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateLocalGatewayRouteTableRequest"},
      "output":{"shape":"CreateLocalGatewayRouteTableResult"},
      "documentation":"<p> Creates a local gateway route table. </p>"
    },
    "CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation":{
      "name":"CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationRequest"},
      "output":{"shape":"CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationResult"},
      "documentation":"<p> Creates a local gateway route table virtual interface group association. </p>"
    },
    "CreateLocalGatewayRouteTableVpcAssociation":{
      "name":"CreateLocalGatewayRouteTableVpcAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateLocalGatewayRouteTableVpcAssociationRequest"},
      "output":{"shape":"CreateLocalGatewayRouteTableVpcAssociationResult"},
      "documentation":"<p>Associates the specified VPC with the specified local gateway route table.</p>"
    },
    "CreateManagedPrefixList":{
      "name":"CreateManagedPrefixList",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateManagedPrefixListRequest"},
      "output":{"shape":"CreateManagedPrefixListResult"},
      "documentation":"<p>Creates a managed prefix list. You can specify one or more entries for the prefix list. Each entry consists of a CIDR block and an optional description.</p>"
    },
    "CreateNatGateway":{
      "name":"CreateNatGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNatGatewayRequest"},
      "output":{"shape":"CreateNatGatewayResult"},
      "documentation":"<p>Creates a NAT gateway in the specified subnet. This action creates a network interface in the specified subnet with a private IP address from the IP address range of the subnet. You can create either a public NAT gateway or a private NAT gateway.</p> <p>With a public NAT gateway, internet-bound traffic from a private subnet can be routed to the NAT gateway, so that instances in a private subnet can connect to the internet.</p> <p>With a private NAT gateway, private communication is routed across VPCs and on-premises networks through a transit gateway or virtual private gateway. Common use cases include running large workloads behind a small pool of allowlisted IPv4 addresses, preserving private IPv4 addresses, and communicating between overlapping networks.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">NAT gateways</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateNetworkAcl":{
      "name":"CreateNetworkAcl",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNetworkAclRequest"},
      "output":{"shape":"CreateNetworkAclResult"},
      "documentation":"<p>Creates a network ACL in a VPC. Network ACLs provide an optional layer of security (in addition to security groups) for the instances in your VPC.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_ACLs.html\">Network ACLs</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateNetworkAclEntry":{
      "name":"CreateNetworkAclEntry",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNetworkAclEntryRequest"},
      "documentation":"<p>Creates an entry (a rule) in a network ACL with the specified rule number. Each network ACL has a set of numbered ingress rules and a separate set of numbered egress rules. When determining whether a packet should be allowed in or out of a subnet associated with the ACL, we process the entries in the ACL according to the rule numbers, in ascending order. Each network ACL has a set of ingress rules and a separate set of egress rules.</p> <p>We recommend that you leave room between the rule numbers (for example, 100, 110, 120, ...), and not number them one right after the other (for example, 101, 102, 103, ...). This makes it easier to add a rule between existing ones without having to renumber the rules.</p> <p>After you add an entry, you can't modify it; you must either replace it, or create an entry and delete the old one.</p> <p>For more information about network ACLs, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_ACLs.html\">Network ACLs</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateNetworkInsightsAccessScope":{
      "name":"CreateNetworkInsightsAccessScope",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNetworkInsightsAccessScopeRequest"},
      "output":{"shape":"CreateNetworkInsightsAccessScopeResult"},
      "documentation":"<p>Creates a Network Access Scope.</p> <p>Amazon Web Services Network Access Analyzer enables cloud networking and cloud operations teams to verify that their networks on Amazon Web Services conform to their network security and governance objectives. For more information, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/network-access-analyzer/\">Amazon Web Services Network Access Analyzer Guide</a>.</p>"
    },
    "CreateNetworkInsightsPath":{
      "name":"CreateNetworkInsightsPath",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNetworkInsightsPathRequest"},
      "output":{"shape":"CreateNetworkInsightsPathResult"},
      "documentation":"<p>Creates a path to analyze for reachability.</p> <p>Reachability Analyzer enables you to analyze and debug network reachability between two resources in your virtual private cloud (VPC). For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/reachability/\">What is Reachability Analyzer</a>.</p>"
    },
    "CreateNetworkInterface":{
      "name":"CreateNetworkInterface",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNetworkInterfaceRequest"},
      "output":{"shape":"CreateNetworkInterfaceResult"},
      "documentation":"<p>Creates a network interface in the specified subnet.</p> <p>The number of IP addresses you can assign to a network interface varies by instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html#AvailableIpPerENI\">IP Addresses Per ENI Per Instance Type</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>For more information about network interfaces, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-eni.html\">Elastic network interfaces</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateNetworkInterfacePermission":{
      "name":"CreateNetworkInterfacePermission",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateNetworkInterfacePermissionRequest"},
      "output":{"shape":"CreateNetworkInterfacePermissionResult"},
      "documentation":"<p>Grants an Amazon Web Services-authorized account permission to attach the specified network interface to an instance in their account.</p> <p>You can grant permission to a single Amazon Web Services account only, and only one account at a time.</p>"
    },
    "CreatePlacementGroup":{
      "name":"CreatePlacementGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreatePlacementGroupRequest"},
      "output":{"shape":"CreatePlacementGroupResult"},
      "documentation":"<p>Creates a placement group in which to launch instances. The strategy of the placement group determines how the instances are organized within the group. </p> <p>A <code>cluster</code> placement group is a logical grouping of instances within a single Availability Zone that benefit from low network latency, high network throughput. A <code>spread</code> placement group places instances on distinct hardware. A <code>partition</code> placement group places groups of instances in different partitions, where instances in one partition do not share the same hardware with instances in another partition.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/placement-groups.html\">Placement groups</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreatePublicIpv4Pool":{
      "name":"CreatePublicIpv4Pool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreatePublicIpv4PoolRequest"},
      "output":{"shape":"CreatePublicIpv4PoolResult"},
      "documentation":"<p>Creates a public IPv4 address pool. A public IPv4 pool is an EC2 IP address pool required for the public IPv4 CIDRs that you own and bring to Amazon Web Services to manage with IPAM. IPv6 addresses you bring to Amazon Web Services, however, use IPAM pools only. To monitor the status of pool creation, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribePublicIpv4Pools.html\">DescribePublicIpv4Pools</a>.</p>"
    },
    "CreateReplaceRootVolumeTask":{
      "name":"CreateReplaceRootVolumeTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateReplaceRootVolumeTaskRequest"},
      "output":{"shape":"CreateReplaceRootVolumeTaskResult"},
      "documentation":"<p>Replaces the EBS-backed root volume for a <code>running</code> instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, or that is restored from an AMI that has the same key characteristics as that of the instance.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/replace-root.html\">Replace a root volume</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateReservedInstancesListing":{
      "name":"CreateReservedInstancesListing",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateReservedInstancesListingRequest"},
      "output":{"shape":"CreateReservedInstancesListingResult"},
      "documentation":"<p>Creates a listing for Amazon EC2 Standard Reserved Instances to be sold in the Reserved Instance Marketplace. You can submit one Standard Reserved Instance listing at a time. To get a list of your Standard Reserved Instances, you can use the <a>DescribeReservedInstances</a> operation.</p> <note> <p>Only Standard Reserved Instances can be sold in the Reserved Instance Marketplace. Convertible Reserved Instances cannot be sold.</p> </note> <p>The Reserved Instance Marketplace matches sellers who want to resell Standard Reserved Instance capacity that they no longer need with buyers who want to purchase additional capacity. Reserved Instances bought and sold through the Reserved Instance Marketplace work like any other Reserved Instances.</p> <p>To sell your Standard Reserved Instances, you must first register as a seller in the Reserved Instance Marketplace. After completing the registration process, you can create a Reserved Instance Marketplace listing of some or all of your Standard Reserved Instances, and specify the upfront price to receive for them. Your Standard Reserved Instance listings then become available for purchase. To view the details of your Standard Reserved Instance listing, you can use the <a>DescribeReservedInstancesListings</a> operation.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-market-general.html\">Reserved Instance Marketplace</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreateRestoreImageTask":{
      "name":"CreateRestoreImageTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateRestoreImageTaskRequest"},
      "output":{"shape":"CreateRestoreImageTaskResult"},
      "documentation":"<p>Starts a task that restores an AMI from an Amazon S3 object that was previously created by using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateStoreImageTask.html\">CreateStoreImageTask</a>.</p> <p>To use this API, you must have the required permissions. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-store-restore.html#ami-s3-permissions\">Permissions for storing and restoring AMIs using Amazon S3</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-store-restore.html\">Store and restore an AMI using Amazon S3</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreateRoute":{
      "name":"CreateRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateRouteRequest"},
      "output":{"shape":"CreateRouteResult"},
      "documentation":"<p>Creates a route in a route table within a VPC.</p> <p>You must specify either a destination CIDR block or a prefix list ID. You must also specify exactly one of the resources from the parameter list.</p> <p>When determining how to route traffic, we use the route with the most specific match. For example, traffic is destined for the IPv4 address <code>192.0.2.3</code>, and the route table includes the following two IPv4 routes:</p> <ul> <li> <p> <code>192.0.2.0/24</code> (goes to some target A)</p> </li> <li> <p> <code>192.0.2.0/28</code> (goes to some target B)</p> </li> </ul> <p>Both routes apply to the traffic destined for <code>192.0.2.3</code>. However, the second route in the list covers a smaller number of IP addresses and is therefore more specific, so we use that route to determine where to target the traffic.</p> <p>For more information about route tables, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateRouteTable":{
      "name":"CreateRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateRouteTableRequest"},
      "output":{"shape":"CreateRouteTableResult"},
      "documentation":"<p>Creates a route table for the specified VPC. After you create a route table, you can add routes and associate the table with a subnet.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateSecurityGroup":{
      "name":"CreateSecurityGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateSecurityGroupRequest"},
      "output":{"shape":"CreateSecurityGroupResult"},
      "documentation":"<p>Creates a security group.</p> <p>A security group acts as a virtual firewall for your instance to control inbound and outbound traffic. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-network-security.html\">Amazon EC2 security groups</a> in the <i>Amazon Elastic Compute Cloud User Guide</i> and <a href=\"https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_SecurityGroups.html\">Security groups for your VPC</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>When you create a security group, you specify a friendly name of your choice. You can have a security group for use in EC2-Classic with the same name as a security group for use in a VPC. However, you can't have two security groups for use in EC2-Classic with the same name or two security groups for use in a VPC with the same name.</p> <p>You have a default security group for use in EC2-Classic and a default security group for use in your VPC. If you don't specify a security group when you launch an instance, the instance is launched into the appropriate default security group. A default security group includes a default rule that grants instances unrestricted network access to each other.</p> <p>You can add or remove rules from your security groups using <a>AuthorizeSecurityGroupIngress</a>, <a>AuthorizeSecurityGroupEgress</a>, <a>RevokeSecurityGroupIngress</a>, and <a>RevokeSecurityGroupEgress</a>.</p> <p>For more information about VPC security group limits, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html\">Amazon VPC Limits</a>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "CreateSnapshot":{
      "name":"CreateSnapshot",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateSnapshotRequest"},
      "output":{"shape":"Snapshot"},
      "documentation":"<p>Creates a snapshot of an EBS volume and stores it in Amazon S3. You can use snapshots for backups, to make copies of EBS volumes, and to save data before shutting down an instance.</p> <p>You can create snapshots of volumes in a Region and volumes on an Outpost. If you create a snapshot of a volume in a Region, the snapshot must be stored in the same Region as the volume. If you create a snapshot of a volume on an Outpost, the snapshot can be stored on the same Outpost as the volume, or in the Region for that Outpost.</p> <p>When a snapshot is created, any Amazon Web Services Marketplace product codes that are associated with the source volume are propagated to the snapshot.</p> <p>You can take a snapshot of an attached volume that is in use. However, snapshots only capture data that has been written to your Amazon EBS volume at the time the snapshot command is issued; this might exclude any data that has been cached by any applications or the operating system. If you can pause any file systems on the volume long enough to take a snapshot, your snapshot should be complete. However, if you cannot pause all file writes to the volume, you should unmount the volume from within the instance, issue the snapshot command, and then remount the volume to ensure a consistent and complete snapshot. You may remount and use your volume while the snapshot status is <code>pending</code>.</p> <p>To create a snapshot for Amazon EBS volumes that serve as root devices, you should stop the instance before taking the snapshot.</p> <p>Snapshots that are taken from encrypted volumes are automatically encrypted. Volumes that are created from encrypted snapshots are also automatically encrypted. Your encrypted volumes and any associated snapshots always remain protected.</p> <p>You can tag your snapshots during creation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html\">Tag your Amazon EC2 resources</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AmazonEBS.html\">Amazon Elastic Block Store</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateSnapshots":{
      "name":"CreateSnapshots",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateSnapshotsRequest"},
      "output":{"shape":"CreateSnapshotsResult"},
      "documentation":"<p>Creates crash-consistent snapshots of multiple EBS volumes and stores the data in S3. Volumes are chosen by specifying an instance. Any attached volumes will produce one snapshot each that is crash-consistent across the instance.</p> <p>You can include all of the volumes currently attached to the instance, or you can exclude the root volume or specific data (non-root) volumes from the multi-volume snapshot set.</p> <p>You can create multi-volume snapshots of instances in a Region and instances on an Outpost. If you create snapshots from an instance in a Region, the snapshots must be stored in the same Region as the instance. If you create snapshots from an instance on an Outpost, the snapshots can be stored on the same Outpost as the instance, or in the Region for that Outpost.</p>"
    },
    "CreateSpotDatafeedSubscription":{
      "name":"CreateSpotDatafeedSubscription",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateSpotDatafeedSubscriptionRequest"},
      "output":{"shape":"CreateSpotDatafeedSubscriptionResult"},
      "documentation":"<p>Creates a data feed for Spot Instances, enabling you to view Spot Instance usage logs. You can create one data feed per Amazon Web Services account. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-data-feeds.html\">Spot Instance data feed</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>"
    },
    "CreateStoreImageTask":{
      "name":"CreateStoreImageTask",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateStoreImageTaskRequest"},
      "output":{"shape":"CreateStoreImageTaskResult"},
      "documentation":"<p>Stores an AMI as a single object in an Amazon S3 bucket.</p> <p>To use this API, you must have the required permissions. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-store-restore.html#ami-s3-permissions\">Permissions for storing and restoring AMIs using Amazon S3</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-store-restore.html\">Store and restore an AMI using Amazon S3</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CreateSubnet":{
      "name":"CreateSubnet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateSubnetRequest"},
      "output":{"shape":"CreateSubnetResult"},
      "documentation":"<p>Creates a subnet in the specified VPC. For an IPv4 only subnet, specify an IPv4 CIDR block. If the VPC has an IPv6 CIDR block, you can create an IPv6 only subnet or a dual stack subnet instead. For an IPv6 only subnet, specify an IPv6 CIDR block. For a dual stack subnet, specify both an IPv4 CIDR block and an IPv6 CIDR block.</p> <p>A subnet CIDR block must not overlap the CIDR block of an existing subnet in the VPC. After you create a subnet, you can't change its CIDR block.</p> <p>The allowed size for an IPv4 subnet is between a /28 netmask (16 IP addresses) and a /16 netmask (65,536 IP addresses). Amazon Web Services reserves both the first four and the last IPv4 address in each subnet's CIDR block. They're not available for your use.</p> <p>If you've associated an IPv6 CIDR block with your VPC, you can associate an IPv6 CIDR block with a subnet when you create it. The allowed block size for an IPv6 subnet is a /64 netmask.</p> <p>If you add more than one subnet to a VPC, they're set up in a star topology with a logical router in the middle.</p> <p>When you stop an instance in a subnet, it retains its private IPv4 address. It's therefore possible to have a subnet with no running instances (they're all stopped), but no remaining IP addresses available.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/configure-subnets.html\">Subnets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateSubnetCidrReservation":{
      "name":"CreateSubnetCidrReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateSubnetCidrReservationRequest"},
      "output":{"shape":"CreateSubnetCidrReservationResult"},
      "documentation":"<p>Creates a subnet CIDR reservation. For information about subnet CIDR reservations, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/subnet-cidr-reservation.html\">Subnet CIDR reservations</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "CreateTags":{
      "name":"CreateTags",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTagsRequest"},
      "documentation":"<p>Adds or overwrites only the specified tags for the specified Amazon EC2 resource or resources. When you specify an existing tag key, the value is overwritten with the new value. Each resource can have a maximum of 50 tags. Each tag consists of a key and optional value. Tag keys must be unique per resource.</p> <p>For more information about tags, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html\">Tag your Amazon EC2 resources</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>. For more information about creating IAM policies that control users' access to resources based on tags, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-supported-iam-actions-resources.html\">Supported resource-level permissions for Amazon EC2 API actions</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateTrafficMirrorFilter":{
      "name":"CreateTrafficMirrorFilter",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTrafficMirrorFilterRequest"},
      "output":{"shape":"CreateTrafficMirrorFilterResult"},
      "documentation":"<p>Creates a Traffic Mirror filter.</p> <p>A Traffic Mirror filter is a set of rules that defines the traffic to mirror.</p> <p>By default, no traffic is mirrored. To mirror traffic, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorFilterRule.htm\">CreateTrafficMirrorFilterRule</a> to add Traffic Mirror rules to the filter. The rules you add define what traffic gets mirrored. You can also use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyTrafficMirrorFilterNetworkServices.html\">ModifyTrafficMirrorFilterNetworkServices</a> to mirror supported network services.</p>"
    },
    "CreateTrafficMirrorFilterRule":{
      "name":"CreateTrafficMirrorFilterRule",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTrafficMirrorFilterRuleRequest"},
      "output":{"shape":"CreateTrafficMirrorFilterRuleResult"},
      "documentation":"<p>Creates a Traffic Mirror filter rule.</p> <p>A Traffic Mirror rule defines the Traffic Mirror source traffic to mirror.</p> <p>You need the Traffic Mirror filter ID when you create the rule.</p>"
    },
    "CreateTrafficMirrorSession":{
      "name":"CreateTrafficMirrorSession",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTrafficMirrorSessionRequest"},
      "output":{"shape":"CreateTrafficMirrorSessionResult"},
      "documentation":"<p>Creates a Traffic Mirror session.</p> <p>A Traffic Mirror session actively copies packets from a Traffic Mirror source to a Traffic Mirror target. Create a filter, and then assign it to the session to define a subset of the traffic to mirror, for example all TCP traffic.</p> <p>The Traffic Mirror source and the Traffic Mirror target (monitoring appliances) can be in the same VPC, or in a different VPC connected via VPC peering or a transit gateway. </p> <p>By default, no traffic is mirrored. Use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorFilter.htm\">CreateTrafficMirrorFilter</a> to create filter rules that specify the traffic to mirror.</p>"
    },
    "CreateTrafficMirrorTarget":{
      "name":"CreateTrafficMirrorTarget",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTrafficMirrorTargetRequest"},
      "output":{"shape":"CreateTrafficMirrorTargetResult"},
      "documentation":"<p>Creates a target for your Traffic Mirror session.</p> <p>A Traffic Mirror target is the destination for mirrored traffic. The Traffic Mirror source and the Traffic Mirror target (monitoring appliances) can be in the same VPC, or in different VPCs connected via VPC peering or a transit gateway.</p> <p>A Traffic Mirror target can be a network interface, a Network Load Balancer, or a Gateway Load Balancer endpoint.</p> <p>To use the target in a Traffic Mirror session, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTrafficMirrorSession.htm\">CreateTrafficMirrorSession</a>.</p>"
    },
    "CreateTransitGateway":{
      "name":"CreateTransitGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayRequest"},
      "output":{"shape":"CreateTransitGatewayResult"},
      "documentation":"<p>Creates a transit gateway.</p> <p>You can use a transit gateway to interconnect your virtual private clouds (VPC) and on-premises networks. After the transit gateway enters the <code>available</code> state, you can attach your VPCs and VPN connections to the transit gateway.</p> <p>To attach your VPCs, use <a>CreateTransitGatewayVpcAttachment</a>.</p> <p>To attach a VPN connection, use <a>CreateCustomerGateway</a> to create a customer gateway and specify the ID of the customer gateway and the ID of the transit gateway in a call to <a>CreateVpnConnection</a>.</p> <p>When you create a transit gateway, we create a default transit gateway route table and use it as the default association route table and the default propagation route table. You can use <a>CreateTransitGatewayRouteTable</a> to create additional transit gateway route tables. If you disable automatic route propagation, we do not create a default transit gateway route table. You can use <a>EnableTransitGatewayRouteTablePropagation</a> to propagate routes from a resource attachment to a transit gateway route table. If you disable automatic associations, you can use <a>AssociateTransitGatewayRouteTable</a> to associate a resource attachment with a transit gateway route table.</p>"
    },
    "CreateTransitGatewayConnect":{
      "name":"CreateTransitGatewayConnect",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayConnectRequest"},
      "output":{"shape":"CreateTransitGatewayConnectResult"},
      "documentation":"<p>Creates a Connect attachment from a specified transit gateway attachment. A Connect attachment is a GRE-based tunnel attachment that you can use to establish a connection between a transit gateway and an appliance.</p> <p>A Connect attachment uses an existing VPC or Amazon Web Services Direct Connect attachment as the underlying transport mechanism.</p>"
    },
    "CreateTransitGatewayConnectPeer":{
      "name":"CreateTransitGatewayConnectPeer",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayConnectPeerRequest"},
      "output":{"shape":"CreateTransitGatewayConnectPeerResult"},
      "documentation":"<p>Creates a Connect peer for a specified transit gateway Connect attachment between a transit gateway and an appliance.</p> <p>The peer address and transit gateway address must be the same IP address family (IPv4 or IPv6).</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/tgw/tgw-connect.html#tgw-connect-peer\">Connect peers</a> in the <i>Transit Gateways Guide</i>.</p>"
    },
    "CreateTransitGatewayMulticastDomain":{
      "name":"CreateTransitGatewayMulticastDomain",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayMulticastDomainRequest"},
      "output":{"shape":"CreateTransitGatewayMulticastDomainResult"},
      "documentation":"<p>Creates a multicast domain using the specified transit gateway.</p> <p>The transit gateway must be in the available state before you create a domain. Use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeTransitGateways.html\">DescribeTransitGateways</a> to see the state of transit gateway.</p>"
    },
    "CreateTransitGatewayPeeringAttachment":{
      "name":"CreateTransitGatewayPeeringAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayPeeringAttachmentRequest"},
      "output":{"shape":"CreateTransitGatewayPeeringAttachmentResult"},
      "documentation":"<p>Requests a transit gateway peering attachment between the specified transit gateway (requester) and a peer transit gateway (accepter). The peer transit gateway can be in your account or a different Amazon Web Services account.</p> <p>After you create the peering attachment, the owner of the accepter transit gateway must accept the attachment request.</p>"
    },
    "CreateTransitGatewayPolicyTable":{
      "name":"CreateTransitGatewayPolicyTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayPolicyTableRequest"},
      "output":{"shape":"CreateTransitGatewayPolicyTableResult"},
      "documentation":"<p>Creates a transit gateway policy table.</p>"
    },
    "CreateTransitGatewayPrefixListReference":{
      "name":"CreateTransitGatewayPrefixListReference",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayPrefixListReferenceRequest"},
      "output":{"shape":"CreateTransitGatewayPrefixListReferenceResult"},
      "documentation":"<p>Creates a reference (route) to a prefix list in a specified transit gateway route table.</p>"
    },
    "CreateTransitGatewayRoute":{
      "name":"CreateTransitGatewayRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayRouteRequest"},
      "output":{"shape":"CreateTransitGatewayRouteResult"},
      "documentation":"<p>Creates a static route for the specified transit gateway route table.</p>"
    },
    "CreateTransitGatewayRouteTable":{
      "name":"CreateTransitGatewayRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayRouteTableRequest"},
      "output":{"shape":"CreateTransitGatewayRouteTableResult"},
      "documentation":"<p>Creates a route table for the specified transit gateway.</p>"
    },
    "CreateTransitGatewayRouteTableAnnouncement":{
      "name":"CreateTransitGatewayRouteTableAnnouncement",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayRouteTableAnnouncementRequest"},
      "output":{"shape":"CreateTransitGatewayRouteTableAnnouncementResult"},
      "documentation":"<p>Advertises a new transit gateway route table.</p>"
    },
    "CreateTransitGatewayVpcAttachment":{
      "name":"CreateTransitGatewayVpcAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateTransitGatewayVpcAttachmentRequest"},
      "output":{"shape":"CreateTransitGatewayVpcAttachmentResult"},
      "documentation":"<p>Attaches the specified VPC to the specified transit gateway.</p> <p>If you attach a VPC with a CIDR range that overlaps the CIDR range of a VPC that is already attached, the new VPC CIDR range is not propagated to the default propagation route table.</p> <p>To send VPC traffic to an attached transit gateway, add a route to the VPC route table using <a>CreateRoute</a>.</p>"
    },
    "CreateVerifiedAccessEndpoint":{
      "name":"CreateVerifiedAccessEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVerifiedAccessEndpointRequest"},
      "output":{"shape":"CreateVerifiedAccessEndpointResult"},
      "documentation":"<p>An Amazon Web Services Verified Access endpoint is where you define your application along with an optional endpoint-level access policy.</p>"
    },
    "CreateVerifiedAccessGroup":{
      "name":"CreateVerifiedAccessGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVerifiedAccessGroupRequest"},
      "output":{"shape":"CreateVerifiedAccessGroupResult"},
      "documentation":"<p>An Amazon Web Services Verified Access group is a collection of Amazon Web Services Verified Access endpoints who's associated applications have similar security requirements. Each instance within an Amazon Web Services Verified Access group shares an Amazon Web Services Verified Access policy. For example, you can group all Amazon Web Services Verified Access instances associated with “sales” applications together and use one common Amazon Web Services Verified Access policy.</p>"
    },
    "CreateVerifiedAccessInstance":{
      "name":"CreateVerifiedAccessInstance",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVerifiedAccessInstanceRequest"},
      "output":{"shape":"CreateVerifiedAccessInstanceResult"},
      "documentation":"<p>An Amazon Web Services Verified Access instance is a regional entity that evaluates application requests and grants access only when your security requirements are met.</p>"
    },
    "CreateVerifiedAccessTrustProvider":{
      "name":"CreateVerifiedAccessTrustProvider",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVerifiedAccessTrustProviderRequest"},
      "output":{"shape":"CreateVerifiedAccessTrustProviderResult"},
      "documentation":"<p>A trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices. When an application request is made, the identity information sent by the trust provider will be evaluated by Amazon Web Services Verified Access, before allowing or denying the application request.</p>"
    },
    "CreateVolume":{
      "name":"CreateVolume",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVolumeRequest"},
      "output":{"shape":"Volume"},
      "documentation":"<p>Creates an EBS volume that can be attached to an instance in the same Availability Zone.</p> <p>You can create a new empty volume or restore a volume from an EBS snapshot. Any Amazon Web Services Marketplace product codes from the snapshot are propagated to the volume.</p> <p>You can create encrypted volumes. Encrypted volumes must be attached to instances that support Amazon EBS encryption. Volumes that are created from encrypted snapshots are also automatically encrypted. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>You can tag your volumes during creation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html\">Tag your Amazon EC2 resources</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-creating-volume.html\">Create an Amazon EBS volume</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateVpc":{
      "name":"CreateVpc",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpcRequest"},
      "output":{"shape":"CreateVpcResult"},
      "documentation":"<p>Creates a VPC with the specified CIDR blocks. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/configure-your-vpc.html#vpc-cidr-blocks\">VPC CIDR blocks</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>You can optionally request an IPv6 CIDR block for the VPC. You can request an Amazon-provided IPv6 CIDR block from Amazon's pool of IPv6 addresses, or an IPv6 CIDR block from an IPv6 address pool that you provisioned through bring your own IP addresses (<a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-byoip.html\">BYOIP</a>).</p> <p>By default, each instance that you launch in the VPC has the default DHCP options, which include only a default DNS server that we provide (AmazonProvidedDNS). For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_DHCP_Options.html\">DHCP option sets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>You can specify the instance tenancy value for the VPC when you create it. You can't change this value for the VPC after you create it. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-instance.html\">Dedicated Instances</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CreateVpcEndpoint":{
      "name":"CreateVpcEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpcEndpointRequest"},
      "output":{"shape":"CreateVpcEndpointResult"},
      "documentation":"<p>Creates a VPC endpoint for a specified service. An endpoint enables you to create a private connection between your VPC and the service. The service may be provided by Amazon Web Services, an Amazon Web Services Marketplace Partner, or another Amazon Web Services account. For more information, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/privatelink/\">Amazon Web Services PrivateLink Guide</a>.</p>"
    },
    "CreateVpcEndpointConnectionNotification":{
      "name":"CreateVpcEndpointConnectionNotification",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpcEndpointConnectionNotificationRequest"},
      "output":{"shape":"CreateVpcEndpointConnectionNotificationResult"},
      "documentation":"<p>Creates a connection notification for a specified VPC endpoint or VPC endpoint service. A connection notification notifies you of specific endpoint events. You must create an SNS topic to receive notifications. For more information, see <a href=\"https://docs.aws.amazon.com/sns/latest/dg/CreateTopic.html\">Create a Topic</a> in the <i>Amazon Simple Notification Service Developer Guide</i>.</p> <p>You can create a connection notification for interface endpoints only.</p>"
    },
    "CreateVpcEndpointServiceConfiguration":{
      "name":"CreateVpcEndpointServiceConfiguration",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpcEndpointServiceConfigurationRequest"},
      "output":{"shape":"CreateVpcEndpointServiceConfigurationResult"},
      "documentation":"<p>Creates a VPC endpoint service to which service consumers (Amazon Web Services accounts, users, and IAM roles) can connect.</p> <p>Before you create an endpoint service, you must create one of the following for your service:</p> <ul> <li> <p>A <a href=\"https://docs.aws.amazon.com/elasticloadbalancing/latest/network/\">Network Load Balancer</a>. Service consumers connect to your service using an interface endpoint.</p> </li> <li> <p>A <a href=\"https://docs.aws.amazon.com/elasticloadbalancing/latest/gateway/\">Gateway Load Balancer</a>. Service consumers connect to your service using a Gateway Load Balancer endpoint.</p> </li> </ul> <p>If you set the private DNS name, you must prove that you own the private DNS domain name.</p> <p>For more information, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/privatelink/\">Amazon Web Services PrivateLink Guide</a>.</p>"
    },
    "CreateVpcPeeringConnection":{
      "name":"CreateVpcPeeringConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpcPeeringConnectionRequest"},
      "output":{"shape":"CreateVpcPeeringConnectionResult"},
      "documentation":"<p>Requests a VPC peering connection between two VPCs: a requester VPC that you own and an accepter VPC with which to create the connection. The accepter VPC can belong to another Amazon Web Services account and can be in a different Region to the requester VPC. The requester VPC and accepter VPC cannot have overlapping CIDR blocks.</p> <note> <p>Limitations and rules apply to a VPC peering connection. For more information, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/peering/vpc-peering-basics.html#vpc-peering-limitations\">limitations</a> section in the <i>VPC Peering Guide</i>.</p> </note> <p>The owner of the accepter VPC must accept the peering request to activate the peering connection. The VPC peering connection request expires after 7 days, after which it cannot be accepted or rejected.</p> <p>If you create a VPC peering connection request between VPCs with overlapping CIDR blocks, the VPC peering connection has a status of <code>failed</code>.</p>"
    },
    "CreateVpnConnection":{
      "name":"CreateVpnConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpnConnectionRequest"},
      "output":{"shape":"CreateVpnConnectionResult"},
      "documentation":"<p>Creates a VPN connection between an existing virtual private gateway or transit gateway and a customer gateway. The supported connection type is <code>ipsec.1</code>.</p> <p>The response includes information that you need to give to your network administrator to configure your customer gateway.</p> <important> <p>We strongly recommend that you use HTTPS when calling this operation because the response contains sensitive cryptographic information for configuring your customer gateway device.</p> </important> <p>If you decide to shut down your VPN connection for any reason and later create a new VPN connection, you must reconfigure your customer gateway with the new information returned from this call.</p> <p>This is an idempotent operation. If you perform the operation more than once, Amazon EC2 doesn't return an error.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "CreateVpnConnectionRoute":{
      "name":"CreateVpnConnectionRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpnConnectionRouteRequest"},
      "documentation":"<p>Creates a static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway. The static route allows traffic to be routed from the virtual private gateway to the VPN customer gateway.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "CreateVpnGateway":{
      "name":"CreateVpnGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"CreateVpnGatewayRequest"},
      "output":{"shape":"CreateVpnGatewayResult"},
      "documentation":"<p>Creates a virtual private gateway. A virtual private gateway is the endpoint on the VPC side of your VPN connection. You can create a virtual private gateway before creating the VPC itself.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "DeleteCarrierGateway":{
      "name":"DeleteCarrierGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteCarrierGatewayRequest"},
      "output":{"shape":"DeleteCarrierGatewayResult"},
      "documentation":"<p>Deletes a carrier gateway.</p> <important> <p>If you do not delete the route that contains the carrier gateway as the Target, the route is a blackhole route. For information about how to delete a route, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeleteRoute.html\">DeleteRoute</a>.</p> </important>"
    },
    "DeleteClientVpnEndpoint":{
      "name":"DeleteClientVpnEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteClientVpnEndpointRequest"},
      "output":{"shape":"DeleteClientVpnEndpointResult"},
      "documentation":"<p>Deletes the specified Client VPN endpoint. You must disassociate all target networks before you can delete a Client VPN endpoint.</p>"
    },
    "DeleteClientVpnRoute":{
      "name":"DeleteClientVpnRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteClientVpnRouteRequest"},
      "output":{"shape":"DeleteClientVpnRouteResult"},
      "documentation":"<p>Deletes a route from a Client VPN endpoint. You can only delete routes that you manually added using the <b>CreateClientVpnRoute</b> action. You cannot delete routes that were automatically added when associating a subnet. To remove routes that have been automatically added, disassociate the target subnet from the Client VPN endpoint.</p>"
    },
    "DeleteCoipCidr":{
      "name":"DeleteCoipCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteCoipCidrRequest"},
      "output":{"shape":"DeleteCoipCidrResult"},
      "documentation":"<p> Deletes a range of customer-owned IP addresses. </p>"
    },
    "DeleteCoipPool":{
      "name":"DeleteCoipPool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteCoipPoolRequest"},
      "output":{"shape":"DeleteCoipPoolResult"},
      "documentation":"<p>Deletes a pool of customer-owned IP (CoIP) addresses. </p>"
    },
    "DeleteCustomerGateway":{
      "name":"DeleteCustomerGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteCustomerGatewayRequest"},
      "documentation":"<p>Deletes the specified customer gateway. You must delete the VPN connection before you can delete the customer gateway.</p>"
    },
    "DeleteDhcpOptions":{
      "name":"DeleteDhcpOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteDhcpOptionsRequest"},
      "documentation":"<p>Deletes the specified set of DHCP options. You must disassociate the set of DHCP options before you can delete it. You can disassociate the set of DHCP options by associating either a new set of options or the default set of options with the VPC.</p>"
    },
    "DeleteEgressOnlyInternetGateway":{
      "name":"DeleteEgressOnlyInternetGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteEgressOnlyInternetGatewayRequest"},
      "output":{"shape":"DeleteEgressOnlyInternetGatewayResult"},
      "documentation":"<p>Deletes an egress-only internet gateway.</p>"
    },
    "DeleteFleets":{
      "name":"DeleteFleets",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteFleetsRequest"},
      "output":{"shape":"DeleteFleetsResult"},
      "documentation":"<p>Deletes the specified EC2 Fleet.</p> <p>After you delete an EC2 Fleet, it launches no new instances.</p> <p>You must specify whether a deleted EC2 Fleet should also terminate its instances. If you choose to terminate the instances, the EC2 Fleet enters the <code>deleted_terminating</code> state. Otherwise, the EC2 Fleet enters the <code>deleted_running</code> state, and the instances continue to run until they are interrupted or you terminate them manually.</p> <p>For <code>instant</code> fleets, EC2 Fleet must terminate the instances when the fleet is deleted. A deleted <code>instant</code> fleet with running instances is not supported.</p> <p class=\"title\"> <b>Restrictions</b> </p> <ul> <li> <p>You can delete up to 25 <code>instant</code> fleets in a single request. If you exceed this number, no <code>instant</code> fleets are deleted and an error is returned. There is no restriction on the number of fleets of type <code>maintain</code> or <code>request</code> that can be deleted in a single request.</p> </li> <li> <p>Up to 1000 instances can be terminated in a single request to delete <code>instant</code> fleets.</p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/manage-ec2-fleet.html#delete-fleet\">Delete an EC2 Fleet</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DeleteFlowLogs":{
      "name":"DeleteFlowLogs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteFlowLogsRequest"},
      "output":{"shape":"DeleteFlowLogsResult"},
      "documentation":"<p>Deletes one or more flow logs.</p>"
    },
    "DeleteFpgaImage":{
      "name":"DeleteFpgaImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteFpgaImageRequest"},
      "output":{"shape":"DeleteFpgaImageResult"},
      "documentation":"<p>Deletes the specified Amazon FPGA Image (AFI).</p>"
    },
    "DeleteInstanceEventWindow":{
      "name":"DeleteInstanceEventWindow",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteInstanceEventWindowRequest"},
      "output":{"shape":"DeleteInstanceEventWindowResult"},
      "documentation":"<p>Deletes the specified event window.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/event-windows.html\">Define event windows for scheduled events</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DeleteInternetGateway":{
      "name":"DeleteInternetGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteInternetGatewayRequest"},
      "documentation":"<p>Deletes the specified internet gateway. You must detach the internet gateway from the VPC before you can delete it.</p>"
    },
    "DeleteIpam":{
      "name":"DeleteIpam",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteIpamRequest"},
      "output":{"shape":"DeleteIpamResult"},
      "documentation":"<p>Delete an IPAM. Deleting an IPAM removes all monitored data associated with the IPAM including the historical data for CIDRs.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/delete-ipam.html\">Delete an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "DeleteIpamPool":{
      "name":"DeleteIpamPool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteIpamPoolRequest"},
      "output":{"shape":"DeleteIpamPoolResult"},
      "documentation":"<p>Delete an IPAM pool.</p> <note> <p>You cannot delete an IPAM pool if there are allocations in it or CIDRs provisioned to it. To release allocations, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ReleaseIpamPoolAllocation.html\">ReleaseIpamPoolAllocation</a>. To deprovision pool CIDRs, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeprovisionIpamPoolCidr.html\">DeprovisionIpamPoolCidr</a>.</p> </note> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/delete-pool-ipam.html\">Delete a pool</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "DeleteIpamResourceDiscovery":{
      "name":"DeleteIpamResourceDiscovery",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteIpamResourceDiscoveryRequest"},
      "output":{"shape":"DeleteIpamResourceDiscoveryResult"},
      "documentation":"<p>Deletes an IPAM resource discovery. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "DeleteIpamScope":{
      "name":"DeleteIpamScope",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteIpamScopeRequest"},
      "output":{"shape":"DeleteIpamScopeResult"},
      "documentation":"<p>Delete the scope for an IPAM. You cannot delete the default scopes.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/delete-scope-ipam.html\">Delete a scope</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "DeleteKeyPair":{
      "name":"DeleteKeyPair",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteKeyPairRequest"},
      "documentation":"<p>Deletes the specified key pair, by removing the public key from Amazon EC2.</p>"
    },
    "DeleteLaunchTemplate":{
      "name":"DeleteLaunchTemplate",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteLaunchTemplateRequest"},
      "output":{"shape":"DeleteLaunchTemplateResult"},
      "documentation":"<p>Deletes a launch template. Deleting a launch template deletes all of its versions.</p>"
    },
    "DeleteLaunchTemplateVersions":{
      "name":"DeleteLaunchTemplateVersions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteLaunchTemplateVersionsRequest"},
      "output":{"shape":"DeleteLaunchTemplateVersionsResult"},
      "documentation":"<p>Deletes one or more versions of a launch template. You cannot delete the default version of a launch template; you must first assign a different version as the default. If the default version is the only version for the launch template, you must delete the entire launch template using <a>DeleteLaunchTemplate</a>.</p>"
    },
    "DeleteLocalGatewayRoute":{
      "name":"DeleteLocalGatewayRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteLocalGatewayRouteRequest"},
      "output":{"shape":"DeleteLocalGatewayRouteResult"},
      "documentation":"<p>Deletes the specified route from the specified local gateway route table.</p>"
    },
    "DeleteLocalGatewayRouteTable":{
      "name":"DeleteLocalGatewayRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteLocalGatewayRouteTableRequest"},
      "output":{"shape":"DeleteLocalGatewayRouteTableResult"},
      "documentation":"<p> Deletes a local gateway route table. </p>"
    },
    "DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation":{
      "name":"DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationRequest"},
      "output":{"shape":"DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationResult"},
      "documentation":"<p> Deletes a local gateway route table virtual interface group association. </p>"
    },
    "DeleteLocalGatewayRouteTableVpcAssociation":{
      "name":"DeleteLocalGatewayRouteTableVpcAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteLocalGatewayRouteTableVpcAssociationRequest"},
      "output":{"shape":"DeleteLocalGatewayRouteTableVpcAssociationResult"},
      "documentation":"<p>Deletes the specified association between a VPC and local gateway route table.</p>"
    },
    "DeleteManagedPrefixList":{
      "name":"DeleteManagedPrefixList",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteManagedPrefixListRequest"},
      "output":{"shape":"DeleteManagedPrefixListResult"},
      "documentation":"<p>Deletes the specified managed prefix list. You must first remove all references to the prefix list in your resources.</p>"
    },
    "DeleteNatGateway":{
      "name":"DeleteNatGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNatGatewayRequest"},
      "output":{"shape":"DeleteNatGatewayResult"},
      "documentation":"<p>Deletes the specified NAT gateway. Deleting a public NAT gateway disassociates its Elastic IP address, but does not release the address from your account. Deleting a NAT gateway does not delete any NAT gateway routes in your route tables.</p>"
    },
    "DeleteNetworkAcl":{
      "name":"DeleteNetworkAcl",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkAclRequest"},
      "documentation":"<p>Deletes the specified network ACL. You can't delete the ACL if it's associated with any subnets. You can't delete the default network ACL.</p>"
    },
    "DeleteNetworkAclEntry":{
      "name":"DeleteNetworkAclEntry",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkAclEntryRequest"},
      "documentation":"<p>Deletes the specified ingress or egress entry (rule) from the specified network ACL.</p>"
    },
    "DeleteNetworkInsightsAccessScope":{
      "name":"DeleteNetworkInsightsAccessScope",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkInsightsAccessScopeRequest"},
      "output":{"shape":"DeleteNetworkInsightsAccessScopeResult"},
      "documentation":"<p>Deletes the specified Network Access Scope.</p>"
    },
    "DeleteNetworkInsightsAccessScopeAnalysis":{
      "name":"DeleteNetworkInsightsAccessScopeAnalysis",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkInsightsAccessScopeAnalysisRequest"},
      "output":{"shape":"DeleteNetworkInsightsAccessScopeAnalysisResult"},
      "documentation":"<p>Deletes the specified Network Access Scope analysis.</p>"
    },
    "DeleteNetworkInsightsAnalysis":{
      "name":"DeleteNetworkInsightsAnalysis",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkInsightsAnalysisRequest"},
      "output":{"shape":"DeleteNetworkInsightsAnalysisResult"},
      "documentation":"<p>Deletes the specified network insights analysis.</p>"
    },
    "DeleteNetworkInsightsPath":{
      "name":"DeleteNetworkInsightsPath",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkInsightsPathRequest"},
      "output":{"shape":"DeleteNetworkInsightsPathResult"},
      "documentation":"<p>Deletes the specified path.</p>"
    },
    "DeleteNetworkInterface":{
      "name":"DeleteNetworkInterface",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkInterfaceRequest"},
      "documentation":"<p>Deletes the specified network interface. You must detach the network interface before you can delete it.</p>"
    },
    "DeleteNetworkInterfacePermission":{
      "name":"DeleteNetworkInterfacePermission",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteNetworkInterfacePermissionRequest"},
      "output":{"shape":"DeleteNetworkInterfacePermissionResult"},
      "documentation":"<p>Deletes a permission for a network interface. By default, you cannot delete the permission if the account for which you're removing the permission has attached the network interface to an instance. However, you can force delete the permission, regardless of any attachment.</p>"
    },
    "DeletePlacementGroup":{
      "name":"DeletePlacementGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeletePlacementGroupRequest"},
      "documentation":"<p>Deletes the specified placement group. You must terminate all instances in the placement group before you can delete the placement group. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/placement-groups.html\">Placement groups</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DeletePublicIpv4Pool":{
      "name":"DeletePublicIpv4Pool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeletePublicIpv4PoolRequest"},
      "output":{"shape":"DeletePublicIpv4PoolResult"},
      "documentation":"<p>Delete a public IPv4 pool. A public IPv4 pool is an EC2 IP address pool required for the public IPv4 CIDRs that you own and bring to Amazon Web Services to manage with IPAM. IPv6 addresses you bring to Amazon Web Services, however, use IPAM pools only.</p>"
    },
    "DeleteQueuedReservedInstances":{
      "name":"DeleteQueuedReservedInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteQueuedReservedInstancesRequest"},
      "output":{"shape":"DeleteQueuedReservedInstancesResult"},
      "documentation":"<p>Deletes the queued purchases for the specified Reserved Instances.</p>"
    },
    "DeleteRoute":{
      "name":"DeleteRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteRouteRequest"},
      "documentation":"<p>Deletes the specified route from the specified route table.</p>"
    },
    "DeleteRouteTable":{
      "name":"DeleteRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteRouteTableRequest"},
      "documentation":"<p>Deletes the specified route table. You must disassociate the route table from any subnets before you can delete it. You can't delete the main route table.</p>"
    },
    "DeleteSecurityGroup":{
      "name":"DeleteSecurityGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteSecurityGroupRequest"},
      "documentation":"<p>Deletes a security group.</p> <p>If you attempt to delete a security group that is associated with an instance, or is referenced by another security group, the operation fails with <code>InvalidGroup.InUse</code> in EC2-Classic or <code>DependencyViolation</code> in EC2-VPC.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DeleteSnapshot":{
      "name":"DeleteSnapshot",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteSnapshotRequest"},
      "documentation":"<p>Deletes the specified snapshot.</p> <p>When you make periodic snapshots of a volume, the snapshots are incremental, and only the blocks on the device that have changed since your last snapshot are saved in the new snapshot. When you delete a snapshot, only the data not needed for any other snapshot is removed. So regardless of which prior snapshots have been deleted, all active snapshots will have access to all the information needed to restore the volume.</p> <p>You cannot delete a snapshot of the root device of an EBS volume used by a registered AMI. You must first de-register the AMI before you can delete the snapshot.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-deleting-snapshot.html\">Delete an Amazon EBS snapshot</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DeleteSpotDatafeedSubscription":{
      "name":"DeleteSpotDatafeedSubscription",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteSpotDatafeedSubscriptionRequest"},
      "documentation":"<p>Deletes the data feed for Spot Instances.</p>"
    },
    "DeleteSubnet":{
      "name":"DeleteSubnet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteSubnetRequest"},
      "documentation":"<p>Deletes the specified subnet. You must terminate all running instances in the subnet before you can delete the subnet.</p>"
    },
    "DeleteSubnetCidrReservation":{
      "name":"DeleteSubnetCidrReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteSubnetCidrReservationRequest"},
      "output":{"shape":"DeleteSubnetCidrReservationResult"},
      "documentation":"<p>Deletes a subnet CIDR reservation.</p>"
    },
    "DeleteTags":{
      "name":"DeleteTags",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTagsRequest"},
      "documentation":"<p>Deletes the specified set of tags from the specified set of resources.</p> <p>To list the current tags, use <a>DescribeTags</a>. For more information about tags, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html\">Tag your Amazon EC2 resources</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DeleteTrafficMirrorFilter":{
      "name":"DeleteTrafficMirrorFilter",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTrafficMirrorFilterRequest"},
      "output":{"shape":"DeleteTrafficMirrorFilterResult"},
      "documentation":"<p>Deletes the specified Traffic Mirror filter.</p> <p>You cannot delete a Traffic Mirror filter that is in use by a Traffic Mirror session.</p>"
    },
    "DeleteTrafficMirrorFilterRule":{
      "name":"DeleteTrafficMirrorFilterRule",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTrafficMirrorFilterRuleRequest"},
      "output":{"shape":"DeleteTrafficMirrorFilterRuleResult"},
      "documentation":"<p>Deletes the specified Traffic Mirror rule.</p>"
    },
    "DeleteTrafficMirrorSession":{
      "name":"DeleteTrafficMirrorSession",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTrafficMirrorSessionRequest"},
      "output":{"shape":"DeleteTrafficMirrorSessionResult"},
      "documentation":"<p>Deletes the specified Traffic Mirror session.</p>"
    },
    "DeleteTrafficMirrorTarget":{
      "name":"DeleteTrafficMirrorTarget",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTrafficMirrorTargetRequest"},
      "output":{"shape":"DeleteTrafficMirrorTargetResult"},
      "documentation":"<p>Deletes the specified Traffic Mirror target.</p> <p>You cannot delete a Traffic Mirror target that is in use by a Traffic Mirror session.</p>"
    },
    "DeleteTransitGateway":{
      "name":"DeleteTransitGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayRequest"},
      "output":{"shape":"DeleteTransitGatewayResult"},
      "documentation":"<p>Deletes the specified transit gateway.</p>"
    },
    "DeleteTransitGatewayConnect":{
      "name":"DeleteTransitGatewayConnect",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayConnectRequest"},
      "output":{"shape":"DeleteTransitGatewayConnectResult"},
      "documentation":"<p>Deletes the specified Connect attachment. You must first delete any Connect peers for the attachment.</p>"
    },
    "DeleteTransitGatewayConnectPeer":{
      "name":"DeleteTransitGatewayConnectPeer",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayConnectPeerRequest"},
      "output":{"shape":"DeleteTransitGatewayConnectPeerResult"},
      "documentation":"<p>Deletes the specified Connect peer.</p>"
    },
    "DeleteTransitGatewayMulticastDomain":{
      "name":"DeleteTransitGatewayMulticastDomain",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayMulticastDomainRequest"},
      "output":{"shape":"DeleteTransitGatewayMulticastDomainResult"},
      "documentation":"<p>Deletes the specified transit gateway multicast domain.</p>"
    },
    "DeleteTransitGatewayPeeringAttachment":{
      "name":"DeleteTransitGatewayPeeringAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayPeeringAttachmentRequest"},
      "output":{"shape":"DeleteTransitGatewayPeeringAttachmentResult"},
      "documentation":"<p>Deletes a transit gateway peering attachment.</p>"
    },
    "DeleteTransitGatewayPolicyTable":{
      "name":"DeleteTransitGatewayPolicyTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayPolicyTableRequest"},
      "output":{"shape":"DeleteTransitGatewayPolicyTableResult"},
      "documentation":"<p>Deletes the specified transit gateway policy table.</p>"
    },
    "DeleteTransitGatewayPrefixListReference":{
      "name":"DeleteTransitGatewayPrefixListReference",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayPrefixListReferenceRequest"},
      "output":{"shape":"DeleteTransitGatewayPrefixListReferenceResult"},
      "documentation":"<p>Deletes a reference (route) to a prefix list in a specified transit gateway route table.</p>"
    },
    "DeleteTransitGatewayRoute":{
      "name":"DeleteTransitGatewayRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayRouteRequest"},
      "output":{"shape":"DeleteTransitGatewayRouteResult"},
      "documentation":"<p>Deletes the specified route from the specified transit gateway route table.</p>"
    },
    "DeleteTransitGatewayRouteTable":{
      "name":"DeleteTransitGatewayRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayRouteTableRequest"},
      "output":{"shape":"DeleteTransitGatewayRouteTableResult"},
      "documentation":"<p>Deletes the specified transit gateway route table. You must disassociate the route table from any transit gateway route tables before you can delete it.</p>"
    },
    "DeleteTransitGatewayRouteTableAnnouncement":{
      "name":"DeleteTransitGatewayRouteTableAnnouncement",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayRouteTableAnnouncementRequest"},
      "output":{"shape":"DeleteTransitGatewayRouteTableAnnouncementResult"},
      "documentation":"<p>Advertises to the transit gateway that a transit gateway route table is deleted.</p>"
    },
    "DeleteTransitGatewayVpcAttachment":{
      "name":"DeleteTransitGatewayVpcAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteTransitGatewayVpcAttachmentRequest"},
      "output":{"shape":"DeleteTransitGatewayVpcAttachmentResult"},
      "documentation":"<p>Deletes the specified VPC attachment.</p>"
    },
    "DeleteVerifiedAccessEndpoint":{
      "name":"DeleteVerifiedAccessEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVerifiedAccessEndpointRequest"},
      "output":{"shape":"DeleteVerifiedAccessEndpointResult"},
      "documentation":"<p>Delete an Amazon Web Services Verified Access endpoint.</p>"
    },
    "DeleteVerifiedAccessGroup":{
      "name":"DeleteVerifiedAccessGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVerifiedAccessGroupRequest"},
      "output":{"shape":"DeleteVerifiedAccessGroupResult"},
      "documentation":"<p>Delete an Amazon Web Services Verified Access group.</p>"
    },
    "DeleteVerifiedAccessInstance":{
      "name":"DeleteVerifiedAccessInstance",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVerifiedAccessInstanceRequest"},
      "output":{"shape":"DeleteVerifiedAccessInstanceResult"},
      "documentation":"<p>Delete an Amazon Web Services Verified Access instance.</p>"
    },
    "DeleteVerifiedAccessTrustProvider":{
      "name":"DeleteVerifiedAccessTrustProvider",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVerifiedAccessTrustProviderRequest"},
      "output":{"shape":"DeleteVerifiedAccessTrustProviderResult"},
      "documentation":"<p>Delete an Amazon Web Services Verified Access trust provider.</p>"
    },
    "DeleteVolume":{
      "name":"DeleteVolume",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVolumeRequest"},
      "documentation":"<p>Deletes the specified EBS volume. The volume must be in the <code>available</code> state (not attached to an instance).</p> <p>The volume can remain in the <code>deleting</code> state for several minutes.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-deleting-volume.html\">Delete an Amazon EBS volume</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DeleteVpc":{
      "name":"DeleteVpc",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpcRequest"},
      "documentation":"<p>Deletes the specified VPC. You must detach or delete all gateways and resources that are associated with the VPC before you can delete it. For example, you must terminate all instances running in the VPC, delete all security groups associated with the VPC (except the default one), delete all route tables associated with the VPC (except the default one), and so on.</p>"
    },
    "DeleteVpcEndpointConnectionNotifications":{
      "name":"DeleteVpcEndpointConnectionNotifications",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpcEndpointConnectionNotificationsRequest"},
      "output":{"shape":"DeleteVpcEndpointConnectionNotificationsResult"},
      "documentation":"<p>Deletes the specified VPC endpoint connection notifications.</p>"
    },
    "DeleteVpcEndpointServiceConfigurations":{
      "name":"DeleteVpcEndpointServiceConfigurations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpcEndpointServiceConfigurationsRequest"},
      "output":{"shape":"DeleteVpcEndpointServiceConfigurationsResult"},
      "documentation":"<p>Deletes the specified VPC endpoint service configurations. Before you can delete an endpoint service configuration, you must reject any <code>Available</code> or <code>PendingAcceptance</code> interface endpoint connections that are attached to the service.</p>"
    },
    "DeleteVpcEndpoints":{
      "name":"DeleteVpcEndpoints",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpcEndpointsRequest"},
      "output":{"shape":"DeleteVpcEndpointsResult"},
      "documentation":"<p>Deletes the specified VPC endpoints.</p> <p>When you delete a gateway endpoint, we delete the endpoint routes in the route tables for the endpoint.</p> <p>When you delete a Gateway Load Balancer endpoint, we delete its endpoint network interfaces. You can only delete Gateway Load Balancer endpoints when the routes that are associated with the endpoint are deleted.</p> <p>When you delete an interface endpoint, we delete its endpoint network interfaces.</p>"
    },
    "DeleteVpcPeeringConnection":{
      "name":"DeleteVpcPeeringConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpcPeeringConnectionRequest"},
      "output":{"shape":"DeleteVpcPeeringConnectionResult"},
      "documentation":"<p>Deletes a VPC peering connection. Either the owner of the requester VPC or the owner of the accepter VPC can delete the VPC peering connection if it's in the <code>active</code> state. The owner of the requester VPC can delete a VPC peering connection in the <code>pending-acceptance</code> state. You cannot delete a VPC peering connection that's in the <code>failed</code> state.</p>"
    },
    "DeleteVpnConnection":{
      "name":"DeleteVpnConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpnConnectionRequest"},
      "documentation":"<p>Deletes the specified VPN connection.</p> <p>If you're deleting the VPC and its associated components, we recommend that you detach the virtual private gateway from the VPC and delete the VPC before deleting the VPN connection. If you believe that the tunnel credentials for your VPN connection have been compromised, you can delete the VPN connection and create a new one that has new keys, without needing to delete the VPC or virtual private gateway. If you create a new VPN connection, you must reconfigure the customer gateway device using the new configuration information returned with the new VPN connection ID.</p> <p>For certificate-based authentication, delete all Certificate Manager (ACM) private certificates used for the Amazon Web Services-side tunnel endpoints for the VPN connection before deleting the VPN connection.</p>"
    },
    "DeleteVpnConnectionRoute":{
      "name":"DeleteVpnConnectionRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpnConnectionRouteRequest"},
      "documentation":"<p>Deletes the specified static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway. The static route allows traffic to be routed from the virtual private gateway to the VPN customer gateway.</p>"
    },
    "DeleteVpnGateway":{
      "name":"DeleteVpnGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeleteVpnGatewayRequest"},
      "documentation":"<p>Deletes the specified virtual private gateway. You must first detach the virtual private gateway from the VPC. Note that you don't need to delete the virtual private gateway if you plan to delete and recreate the VPN connection between your VPC and your network.</p>"
    },
    "DeprovisionByoipCidr":{
      "name":"DeprovisionByoipCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeprovisionByoipCidrRequest"},
      "output":{"shape":"DeprovisionByoipCidrResult"},
      "documentation":"<p>Releases the specified address range that you provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and deletes the corresponding address pool.</p> <p>Before you can release an address range, you must stop advertising it using <a>WithdrawByoipCidr</a> and you must not have any IP addresses allocated from its address range.</p>"
    },
    "DeprovisionIpamPoolCidr":{
      "name":"DeprovisionIpamPoolCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeprovisionIpamPoolCidrRequest"},
      "output":{"shape":"DeprovisionIpamPoolCidrResult"},
      "documentation":"<p>Deprovision a CIDR provisioned from an IPAM pool. If you deprovision a CIDR from a pool that has a source pool, the CIDR is recycled back into the source pool. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/depro-pool-cidr-ipam.html\">Deprovision pool CIDRs</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "DeprovisionPublicIpv4PoolCidr":{
      "name":"DeprovisionPublicIpv4PoolCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeprovisionPublicIpv4PoolCidrRequest"},
      "output":{"shape":"DeprovisionPublicIpv4PoolCidrResult"},
      "documentation":"<p>Deprovision a CIDR from a public IPv4 pool.</p>"
    },
    "DeregisterImage":{
      "name":"DeregisterImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeregisterImageRequest"},
      "documentation":"<p>Deregisters the specified AMI. After you deregister an AMI, it can't be used to launch new instances.</p> <p>If you deregister an AMI that matches a Recycle Bin retention rule, the AMI is retained in the Recycle Bin for the specified retention period. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/recycle-bin.html\">Recycle Bin</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>When you deregister an AMI, it doesn't affect any instances that you've already launched from the AMI. You'll continue to incur usage costs for those instances until you terminate them.</p> <p>When you deregister an Amazon EBS-backed AMI, it doesn't affect the snapshot that was created for the root volume of the instance during the AMI creation process. When you deregister an instance store-backed AMI, it doesn't affect the files that you uploaded to Amazon S3 when you created the AMI.</p>"
    },
    "DeregisterInstanceEventNotificationAttributes":{
      "name":"DeregisterInstanceEventNotificationAttributes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeregisterInstanceEventNotificationAttributesRequest"},
      "output":{"shape":"DeregisterInstanceEventNotificationAttributesResult"},
      "documentation":"<p>Deregisters tag keys to prevent tags that have the specified tag keys from being included in scheduled event notifications for resources in the Region.</p>"
    },
    "DeregisterTransitGatewayMulticastGroupMembers":{
      "name":"DeregisterTransitGatewayMulticastGroupMembers",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeregisterTransitGatewayMulticastGroupMembersRequest"},
      "output":{"shape":"DeregisterTransitGatewayMulticastGroupMembersResult"},
      "documentation":"<p>Deregisters the specified members (network interfaces) from the transit gateway multicast group.</p>"
    },
    "DeregisterTransitGatewayMulticastGroupSources":{
      "name":"DeregisterTransitGatewayMulticastGroupSources",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DeregisterTransitGatewayMulticastGroupSourcesRequest"},
      "output":{"shape":"DeregisterTransitGatewayMulticastGroupSourcesResult"},
      "documentation":"<p>Deregisters the specified sources (network interfaces) from the transit gateway multicast group.</p>"
    },
    "DescribeAccountAttributes":{
      "name":"DescribeAccountAttributes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAccountAttributesRequest"},
      "output":{"shape":"DescribeAccountAttributesResult"},
      "documentation":"<p>Describes attributes of your Amazon Web Services account. The following are the supported account attributes:</p> <ul> <li> <p> <code>supported-platforms</code>: Indicates whether your account can launch instances into EC2-Classic and EC2-VPC, or only into EC2-VPC.</p> </li> <li> <p> <code>default-vpc</code>: The ID of the default VPC for your account, or <code>none</code>.</p> </li> <li> <p> <code>max-instances</code>: This attribute is no longer supported. The returned value does not reflect your actual vCPU limit for running On-Demand Instances. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-on-demand-instances.html#ec2-on-demand-instances-limits\">On-Demand Instance Limits</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </li> <li> <p> <code>vpc-max-security-groups-per-interface</code>: The maximum number of security groups that you can assign to a network interface.</p> </li> <li> <p> <code>max-elastic-ips</code>: The maximum number of Elastic IP addresses that you can allocate for use with EC2-Classic. </p> </li> <li> <p> <code>vpc-max-elastic-ips</code>: The maximum number of Elastic IP addresses that you can allocate for use with EC2-VPC.</p> </li> </ul> <note> <p>We are retiring EC2-Classic on August 15, 2022. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon EC2 User Guide</i>.</p> </note>"
    },
    "DescribeAddressTransfers":{
      "name":"DescribeAddressTransfers",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAddressTransfersRequest"},
      "output":{"shape":"DescribeAddressTransfersResult"},
      "documentation":"<p>Describes an Elastic IP address transfer. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-eips.html#transfer-EIPs-intro\">Transfer Elastic IP addresses</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DescribeAddresses":{
      "name":"DescribeAddresses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAddressesRequest"},
      "output":{"shape":"DescribeAddressesResult"},
      "documentation":"<p>Describes the specified Elastic IP addresses or all of your Elastic IP addresses.</p> <p>An Elastic IP address is for use in either the EC2-Classic platform or in a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html\">Elastic IP Addresses</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DescribeAddressesAttribute":{
      "name":"DescribeAddressesAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAddressesAttributeRequest"},
      "output":{"shape":"DescribeAddressesAttributeResult"},
      "documentation":"<p>Describes the attributes of the specified Elastic IP addresses. For requirements, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html#Using_Elastic_Addressing_Reverse_DNS\">Using reverse DNS for email applications</a>.</p>"
    },
    "DescribeAggregateIdFormat":{
      "name":"DescribeAggregateIdFormat",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAggregateIdFormatRequest"},
      "output":{"shape":"DescribeAggregateIdFormatResult"},
      "documentation":"<p>Describes the longer ID format settings for all resource types in a specific Region. This request is useful for performing a quick audit to determine whether a specific Region is fully opted in for longer IDs (17-character IDs).</p> <p>This request only returns information about resource types that support longer IDs.</p> <p>The following resource types support longer IDs: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>.</p>"
    },
    "DescribeAvailabilityZones":{
      "name":"DescribeAvailabilityZones",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAvailabilityZonesRequest"},
      "output":{"shape":"DescribeAvailabilityZonesResult"},
      "documentation":"<p>Describes the Availability Zones, Local Zones, and Wavelength Zones that are available to you. If there is an event impacting a zone, you can use this request to view the state and any provided messages for that zone.</p> <p>For more information about Availability Zones, Local Zones, and Wavelength Zones, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html\">Regions and zones</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeAwsNetworkPerformanceMetricSubscriptions":{
      "name":"DescribeAwsNetworkPerformanceMetricSubscriptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeAwsNetworkPerformanceMetricSubscriptionsRequest"},
      "output":{"shape":"DescribeAwsNetworkPerformanceMetricSubscriptionsResult"},
      "documentation":"<p>Describes the current Infrastructure Performance metric subscriptions.</p>"
    },
    "DescribeBundleTasks":{
      "name":"DescribeBundleTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeBundleTasksRequest"},
      "output":{"shape":"DescribeBundleTasksResult"},
      "documentation":"<p>Describes the specified bundle tasks or all of your bundle tasks.</p> <note> <p>Completed bundle tasks are listed for only a limited time. If your bundle task is no longer in the list, you can still register an AMI from it. Just use <code>RegisterImage</code> with the Amazon S3 bucket name and image manifest name you provided to the bundle task.</p> </note>"
    },
    "DescribeByoipCidrs":{
      "name":"DescribeByoipCidrs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeByoipCidrsRequest"},
      "output":{"shape":"DescribeByoipCidrsResult"},
      "documentation":"<p>Describes the IP address ranges that were specified in calls to <a>ProvisionByoipCidr</a>.</p> <p>To describe the address pools that were created when you provisioned the address ranges, use <a>DescribePublicIpv4Pools</a> or <a>DescribeIpv6Pools</a>.</p>"
    },
    "DescribeCapacityReservationFleets":{
      "name":"DescribeCapacityReservationFleets",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeCapacityReservationFleetsRequest"},
      "output":{"shape":"DescribeCapacityReservationFleetsResult"},
      "documentation":"<p>Describes one or more Capacity Reservation Fleets.</p>"
    },
    "DescribeCapacityReservations":{
      "name":"DescribeCapacityReservations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeCapacityReservationsRequest"},
      "output":{"shape":"DescribeCapacityReservationsResult"},
      "documentation":"<p>Describes one or more of your Capacity Reservations. The results describe only the Capacity Reservations in the Amazon Web Services Region that you're currently using.</p>"
    },
    "DescribeCarrierGateways":{
      "name":"DescribeCarrierGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeCarrierGatewaysRequest"},
      "output":{"shape":"DescribeCarrierGatewaysResult"},
      "documentation":"<p>Describes one or more of your carrier gateways.</p>"
    },
    "DescribeClassicLinkInstances":{
      "name":"DescribeClassicLinkInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeClassicLinkInstancesRequest"},
      "output":{"shape":"DescribeClassicLinkInstancesResult"},
      "documentation":"<p>Describes one or more of your linked EC2-Classic instances. This request only returns information about EC2-Classic instances linked to a VPC through ClassicLink. You cannot use this request to return information about other instances.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DescribeClientVpnAuthorizationRules":{
      "name":"DescribeClientVpnAuthorizationRules",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeClientVpnAuthorizationRulesRequest"},
      "output":{"shape":"DescribeClientVpnAuthorizationRulesResult"},
      "documentation":"<p>Describes the authorization rules for a specified Client VPN endpoint.</p>"
    },
    "DescribeClientVpnConnections":{
      "name":"DescribeClientVpnConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeClientVpnConnectionsRequest"},
      "output":{"shape":"DescribeClientVpnConnectionsResult"},
      "documentation":"<p>Describes active client connections and connections that have been terminated within the last 60 minutes for the specified Client VPN endpoint.</p>"
    },
    "DescribeClientVpnEndpoints":{
      "name":"DescribeClientVpnEndpoints",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeClientVpnEndpointsRequest"},
      "output":{"shape":"DescribeClientVpnEndpointsResult"},
      "documentation":"<p>Describes one or more Client VPN endpoints in the account.</p>"
    },
    "DescribeClientVpnRoutes":{
      "name":"DescribeClientVpnRoutes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeClientVpnRoutesRequest"},
      "output":{"shape":"DescribeClientVpnRoutesResult"},
      "documentation":"<p>Describes the routes for the specified Client VPN endpoint.</p>"
    },
    "DescribeClientVpnTargetNetworks":{
      "name":"DescribeClientVpnTargetNetworks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeClientVpnTargetNetworksRequest"},
      "output":{"shape":"DescribeClientVpnTargetNetworksResult"},
      "documentation":"<p>Describes the target networks associated with the specified Client VPN endpoint.</p>"
    },
    "DescribeCoipPools":{
      "name":"DescribeCoipPools",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeCoipPoolsRequest"},
      "output":{"shape":"DescribeCoipPoolsResult"},
      "documentation":"<p>Describes the specified customer-owned address pools or all of your customer-owned address pools.</p>"
    },
    "DescribeConversionTasks":{
      "name":"DescribeConversionTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeConversionTasksRequest"},
      "output":{"shape":"DescribeConversionTasksResult"},
      "documentation":"<p>Describes the specified conversion tasks or all your conversion tasks. For more information, see the <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/\">VM Import/Export User Guide</a>.</p> <p>For information about the import manifest referenced by this API action, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/manifest.html\">VM Import Manifest</a>.</p>"
    },
    "DescribeCustomerGateways":{
      "name":"DescribeCustomerGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeCustomerGatewaysRequest"},
      "output":{"shape":"DescribeCustomerGatewaysResult"},
      "documentation":"<p>Describes one or more of your VPN customer gateways.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "DescribeDhcpOptions":{
      "name":"DescribeDhcpOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeDhcpOptionsRequest"},
      "output":{"shape":"DescribeDhcpOptionsResult"},
      "documentation":"<p>Describes one or more of your DHCP options sets.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_DHCP_Options.html\">DHCP options sets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DescribeEgressOnlyInternetGateways":{
      "name":"DescribeEgressOnlyInternetGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeEgressOnlyInternetGatewaysRequest"},
      "output":{"shape":"DescribeEgressOnlyInternetGatewaysResult"},
      "documentation":"<p>Describes one or more of your egress-only internet gateways.</p>"
    },
    "DescribeElasticGpus":{
      "name":"DescribeElasticGpus",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeElasticGpusRequest"},
      "output":{"shape":"DescribeElasticGpusResult"},
      "documentation":"<p>Describes the Elastic Graphics accelerator associated with your instances. For more information about Elastic Graphics, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/elastic-graphics.html\">Amazon Elastic Graphics</a>.</p>"
    },
    "DescribeExportImageTasks":{
      "name":"DescribeExportImageTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeExportImageTasksRequest"},
      "output":{"shape":"DescribeExportImageTasksResult"},
      "documentation":"<p>Describes the specified export image tasks or all of your export image tasks.</p>"
    },
    "DescribeExportTasks":{
      "name":"DescribeExportTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeExportTasksRequest"},
      "output":{"shape":"DescribeExportTasksResult"},
      "documentation":"<p>Describes the specified export instance tasks or all of your export instance tasks.</p>"
    },
    "DescribeFastLaunchImages":{
      "name":"DescribeFastLaunchImages",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFastLaunchImagesRequest"},
      "output":{"shape":"DescribeFastLaunchImagesResult"},
      "documentation":"<p>Describe details for Windows AMIs that are configured for faster launching.</p>"
    },
    "DescribeFastSnapshotRestores":{
      "name":"DescribeFastSnapshotRestores",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFastSnapshotRestoresRequest"},
      "output":{"shape":"DescribeFastSnapshotRestoresResult"},
      "documentation":"<p>Describes the state of fast snapshot restores for your snapshots.</p>"
    },
    "DescribeFleetHistory":{
      "name":"DescribeFleetHistory",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFleetHistoryRequest"},
      "output":{"shape":"DescribeFleetHistoryResult"},
      "documentation":"<p>Describes the events for the specified EC2 Fleet during the specified time.</p> <p>EC2 Fleet events are delayed by up to 30 seconds before they can be described. This ensures that you can query by the last evaluated time and not miss a recorded event. EC2 Fleet events are available for 48 hours.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/fleet-monitor.html\">Monitor fleet events using Amazon EventBridge</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeFleetInstances":{
      "name":"DescribeFleetInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFleetInstancesRequest"},
      "output":{"shape":"DescribeFleetInstancesResult"},
      "documentation":"<p>Describes the running instances for the specified EC2 Fleet.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/manage-ec2-fleet.html#monitor-ec2-fleet\">Monitor your EC2 Fleet</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeFleets":{
      "name":"DescribeFleets",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFleetsRequest"},
      "output":{"shape":"DescribeFleetsResult"},
      "documentation":"<p>Describes the specified EC2 Fleets or all of your EC2 Fleets.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/manage-ec2-fleet.html#monitor-ec2-fleet\">Monitor your EC2 Fleet</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeFlowLogs":{
      "name":"DescribeFlowLogs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFlowLogsRequest"},
      "output":{"shape":"DescribeFlowLogsResult"},
      "documentation":"<p>Describes one or more flow logs.</p> <p>To view the published flow log records, you must view the log destination. For example, the CloudWatch Logs log group, the Amazon S3 bucket, or the Kinesis Data Firehose delivery stream.</p>"
    },
    "DescribeFpgaImageAttribute":{
      "name":"DescribeFpgaImageAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFpgaImageAttributeRequest"},
      "output":{"shape":"DescribeFpgaImageAttributeResult"},
      "documentation":"<p>Describes the specified attribute of the specified Amazon FPGA Image (AFI).</p>"
    },
    "DescribeFpgaImages":{
      "name":"DescribeFpgaImages",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeFpgaImagesRequest"},
      "output":{"shape":"DescribeFpgaImagesResult"},
      "documentation":"<p>Describes the Amazon FPGA Images (AFIs) available to you. These include public AFIs, private AFIs that you own, and AFIs owned by other Amazon Web Services accounts for which you have load permissions.</p>"
    },
    "DescribeHostReservationOfferings":{
      "name":"DescribeHostReservationOfferings",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeHostReservationOfferingsRequest"},
      "output":{"shape":"DescribeHostReservationOfferingsResult"},
      "documentation":"<p>Describes the Dedicated Host reservations that are available to purchase.</p> <p>The results describe all of the Dedicated Host reservation offerings, including offerings that might not match the instance family and Region of your Dedicated Hosts. When purchasing an offering, ensure that the instance family and Region of the offering matches that of the Dedicated Hosts with which it is to be associated. For more information about supported instance types, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html\">Dedicated Hosts</a> in the <i>Amazon EC2 User Guide</i>. </p>"
    },
    "DescribeHostReservations":{
      "name":"DescribeHostReservations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeHostReservationsRequest"},
      "output":{"shape":"DescribeHostReservationsResult"},
      "documentation":"<p>Describes reservations that are associated with Dedicated Hosts in your account.</p>"
    },
    "DescribeHosts":{
      "name":"DescribeHosts",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeHostsRequest"},
      "output":{"shape":"DescribeHostsResult"},
      "documentation":"<p>Describes the specified Dedicated Hosts or all your Dedicated Hosts.</p> <p>The results describe only the Dedicated Hosts in the Region you're currently using. All listed instances consume capacity on your Dedicated Host. Dedicated Hosts that have recently been released are listed with the state <code>released</code>.</p>"
    },
    "DescribeIamInstanceProfileAssociations":{
      "name":"DescribeIamInstanceProfileAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIamInstanceProfileAssociationsRequest"},
      "output":{"shape":"DescribeIamInstanceProfileAssociationsResult"},
      "documentation":"<p>Describes your IAM instance profile associations.</p>"
    },
    "DescribeIdFormat":{
      "name":"DescribeIdFormat",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIdFormatRequest"},
      "output":{"shape":"DescribeIdFormatResult"},
      "documentation":"<p>Describes the ID format settings for your resources on a per-Region basis, for example, to view which resource types are enabled for longer IDs. This request only returns information about resource types whose ID formats can be modified; it does not return information about other resource types.</p> <p>The following resource types support longer IDs: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>. </p> <p>These settings apply to the IAM user who makes the request; they do not apply to the entire Amazon Web Services account. By default, an IAM user defaults to the same settings as the root user, unless they explicitly override the settings by running the <a>ModifyIdFormat</a> command. Resources created with longer IDs are visible to all IAM users, regardless of these settings and provided that they have permission to use the relevant <code>Describe</code> command for the resource type.</p>"
    },
    "DescribeIdentityIdFormat":{
      "name":"DescribeIdentityIdFormat",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIdentityIdFormatRequest"},
      "output":{"shape":"DescribeIdentityIdFormatResult"},
      "documentation":"<p>Describes the ID format settings for resources for the specified IAM user, IAM role, or root user. For example, you can view the resource types that are enabled for longer IDs. This request only returns information about resource types whose ID formats can be modified; it does not return information about other resource types. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/resource-ids.html\">Resource IDs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>. </p> <p>The following resource types support longer IDs: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>. </p> <p>These settings apply to the principal specified in the request. They do not apply to the principal that makes the request.</p>"
    },
    "DescribeImageAttribute":{
      "name":"DescribeImageAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeImageAttributeRequest"},
      "output":{"shape":"ImageAttribute"},
      "documentation":"<p>Describes the specified attribute of the specified AMI. You can specify only one attribute at a time.</p>"
    },
    "DescribeImages":{
      "name":"DescribeImages",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeImagesRequest"},
      "output":{"shape":"DescribeImagesResult"},
      "documentation":"<p>Describes the specified images (AMIs, AKIs, and ARIs) available to you or all of the images available to you.</p> <p>The images available to you include public images, private images that you own, and private images owned by other Amazon Web Services accounts for which you have explicit launch permissions.</p> <p>Recently deregistered images appear in the returned results for a short interval and then return empty results. After all instances that reference a deregistered AMI are terminated, specifying the ID of the image will eventually return an error indicating that the AMI ID cannot be found.</p>"
    },
    "DescribeImportImageTasks":{
      "name":"DescribeImportImageTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeImportImageTasksRequest"},
      "output":{"shape":"DescribeImportImageTasksResult"},
      "documentation":"<p>Displays details about an import virtual machine or import snapshot tasks that are already created.</p>"
    },
    "DescribeImportSnapshotTasks":{
      "name":"DescribeImportSnapshotTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeImportSnapshotTasksRequest"},
      "output":{"shape":"DescribeImportSnapshotTasksResult"},
      "documentation":"<p>Describes your import snapshot tasks.</p>"
    },
    "DescribeInstanceAttribute":{
      "name":"DescribeInstanceAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceAttributeRequest"},
      "output":{"shape":"InstanceAttribute"},
      "documentation":"<p>Describes the specified attribute of the specified instance. You can specify only one attribute at a time. Valid attribute values are: <code>instanceType</code> | <code>kernel</code> | <code>ramdisk</code> | <code>userData</code> | <code>disableApiTermination</code> | <code>instanceInitiatedShutdownBehavior</code> | <code>rootDeviceName</code> | <code>blockDeviceMapping</code> | <code>productCodes</code> | <code>sourceDestCheck</code> | <code>groupSet</code> | <code>ebsOptimized</code> | <code>sriovNetSupport</code> </p>"
    },
    "DescribeInstanceCreditSpecifications":{
      "name":"DescribeInstanceCreditSpecifications",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceCreditSpecificationsRequest"},
      "output":{"shape":"DescribeInstanceCreditSpecificationsResult"},
      "documentation":"<p>Describes the credit option for CPU usage of the specified burstable performance instances. The credit options are <code>standard</code> and <code>unlimited</code>.</p> <p>If you do not specify an instance ID, Amazon EC2 returns burstable performance instances with the <code>unlimited</code> credit option, as well as instances that were previously configured as T2, T3, and T3a with the <code>unlimited</code> credit option. For example, if you resize a T2 instance, while it is configured as <code>unlimited</code>, to an M4 instance, Amazon EC2 returns the M4 instance.</p> <p>If you specify one or more instance IDs, Amazon EC2 returns the credit option (<code>standard</code> or <code>unlimited</code>) of those instances. If you specify an instance ID that is not valid, such as an instance that is not a burstable performance instance, an error is returned.</p> <p>Recently terminated instances might appear in the returned results. This interval is usually less than one hour.</p> <p>If an Availability Zone is experiencing a service disruption and you specify instance IDs in the affected zone, or do not specify any instance IDs at all, the call fails. If you specify only instance IDs in an unaffected zone, the call works normally.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeInstanceEventNotificationAttributes":{
      "name":"DescribeInstanceEventNotificationAttributes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceEventNotificationAttributesRequest"},
      "output":{"shape":"DescribeInstanceEventNotificationAttributesResult"},
      "documentation":"<p>Describes the tag keys that are registered to appear in scheduled event notifications for resources in the current Region.</p>"
    },
    "DescribeInstanceEventWindows":{
      "name":"DescribeInstanceEventWindows",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceEventWindowsRequest"},
      "output":{"shape":"DescribeInstanceEventWindowsResult"},
      "documentation":"<p>Describes the specified event windows or all event windows.</p> <p>If you specify event window IDs, the output includes information for only the specified event windows. If you specify filters, the output includes information for only those event windows that meet the filter criteria. If you do not specify event windows IDs or filters, the output includes information for all event windows, which can affect performance. We recommend that you use pagination to ensure that the operation returns quickly and successfully. </p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/event-windows.html\">Define event windows for scheduled events</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeInstanceStatus":{
      "name":"DescribeInstanceStatus",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceStatusRequest"},
      "output":{"shape":"DescribeInstanceStatusResult"},
      "documentation":"<p>Describes the status of the specified instances or all of your instances. By default, only running instances are described, unless you specifically indicate to return the status of all instances.</p> <p>Instance status includes the following components:</p> <ul> <li> <p> <b>Status checks</b> - Amazon EC2 performs status checks on running EC2 instances to identify hardware and software issues. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/monitoring-system-instance-status-check.html\">Status checks for your instances</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/TroubleshootingInstances.html\">Troubleshoot instances with failed status checks</a> in the <i>Amazon EC2 User Guide</i>.</p> </li> <li> <p> <b>Scheduled events</b> - Amazon EC2 can schedule events (such as reboot, stop, or terminate) for your instances related to hardware issues, software updates, or system maintenance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/monitoring-instances-status-check_sched.html\">Scheduled events for your instances</a> in the <i>Amazon EC2 User Guide</i>.</p> </li> <li> <p> <b>Instance state</b> - You can manage your instances from the moment you launch them through their termination. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-lifecycle.html\">Instance lifecycle</a> in the <i>Amazon EC2 User Guide</i>.</p> </li> </ul>"
    },
    "DescribeInstanceTypeOfferings":{
      "name":"DescribeInstanceTypeOfferings",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceTypeOfferingsRequest"},
      "output":{"shape":"DescribeInstanceTypeOfferingsResult"},
      "documentation":"<p>Returns a list of all instance types offered. The results can be filtered by location (Region or Availability Zone). If no location is specified, the instance types offered in the current Region are returned.</p>"
    },
    "DescribeInstanceTypes":{
      "name":"DescribeInstanceTypes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstanceTypesRequest"},
      "output":{"shape":"DescribeInstanceTypesResult"},
      "documentation":"<p>Describes the details of the instance types that are offered in a location. The results can be filtered by the attributes of the instance types.</p>"
    },
    "DescribeInstances":{
      "name":"DescribeInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInstancesRequest"},
      "output":{"shape":"DescribeInstancesResult"},
      "documentation":"<p>Describes the specified instances or all instances.</p> <p>If you specify instance IDs, the output includes information for only the specified instances. If you specify filters, the output includes information for only those instances that meet the filter criteria. If you do not specify instance IDs or filters, the output includes information for all instances, which can affect performance. We recommend that you use pagination to ensure that the operation returns quickly and successfully.</p> <p>If you specify an instance ID that is not valid, an error is returned. If you specify an instance that you do not own, it is not included in the output.</p> <p>Recently terminated instances might appear in the returned results. This interval is usually less than one hour.</p> <p>If you describe instances in the rare case where an Availability Zone is experiencing a service disruption and you specify instance IDs that are in the affected zone, or do not specify any instance IDs at all, the call fails. If you describe instances and specify only instance IDs that are in an unaffected zone, the call works normally.</p>"
    },
    "DescribeInternetGateways":{
      "name":"DescribeInternetGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeInternetGatewaysRequest"},
      "output":{"shape":"DescribeInternetGatewaysResult"},
      "documentation":"<p>Describes one or more of your internet gateways.</p>"
    },
    "DescribeIpamPools":{
      "name":"DescribeIpamPools",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIpamPoolsRequest"},
      "output":{"shape":"DescribeIpamPoolsResult"},
      "documentation":"<p>Get information about your IPAM pools.</p>"
    },
    "DescribeIpamResourceDiscoveries":{
      "name":"DescribeIpamResourceDiscoveries",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIpamResourceDiscoveriesRequest"},
      "output":{"shape":"DescribeIpamResourceDiscoveriesResult"},
      "documentation":"<p>Describes IPAM resource discoveries. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "DescribeIpamResourceDiscoveryAssociations":{
      "name":"DescribeIpamResourceDiscoveryAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIpamResourceDiscoveryAssociationsRequest"},
      "output":{"shape":"DescribeIpamResourceDiscoveryAssociationsResult"},
      "documentation":"<p>Describes resource discovery association with an Amazon VPC IPAM. An associated resource discovery is a resource discovery that has been associated with an IPAM..</p>"
    },
    "DescribeIpamScopes":{
      "name":"DescribeIpamScopes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIpamScopesRequest"},
      "output":{"shape":"DescribeIpamScopesResult"},
      "documentation":"<p>Get information about your IPAM scopes.</p>"
    },
    "DescribeIpams":{
      "name":"DescribeIpams",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIpamsRequest"},
      "output":{"shape":"DescribeIpamsResult"},
      "documentation":"<p>Get information about your IPAM pools.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "DescribeIpv6Pools":{
      "name":"DescribeIpv6Pools",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeIpv6PoolsRequest"},
      "output":{"shape":"DescribeIpv6PoolsResult"},
      "documentation":"<p>Describes your IPv6 address pools.</p>"
    },
    "DescribeKeyPairs":{
      "name":"DescribeKeyPairs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeKeyPairsRequest"},
      "output":{"shape":"DescribeKeyPairsResult"},
      "documentation":"<p>Describes the specified key pairs or all of your key pairs.</p> <p>For more information about key pairs, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html\">Amazon EC2 key pairs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeLaunchTemplateVersions":{
      "name":"DescribeLaunchTemplateVersions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLaunchTemplateVersionsRequest"},
      "output":{"shape":"DescribeLaunchTemplateVersionsResult"},
      "documentation":"<p>Describes one or more versions of a specified launch template. You can describe all versions, individual versions, or a range of versions. You can also describe all the latest versions or all the default versions of all the launch templates in your account.</p>"
    },
    "DescribeLaunchTemplates":{
      "name":"DescribeLaunchTemplates",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLaunchTemplatesRequest"},
      "output":{"shape":"DescribeLaunchTemplatesResult"},
      "documentation":"<p>Describes one or more launch templates.</p>"
    },
    "DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations":{
      "name":"DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsRequest"},
      "output":{"shape":"DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsResult"},
      "documentation":"<p>Describes the associations between virtual interface groups and local gateway route tables.</p>"
    },
    "DescribeLocalGatewayRouteTableVpcAssociations":{
      "name":"DescribeLocalGatewayRouteTableVpcAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLocalGatewayRouteTableVpcAssociationsRequest"},
      "output":{"shape":"DescribeLocalGatewayRouteTableVpcAssociationsResult"},
      "documentation":"<p>Describes the specified associations between VPCs and local gateway route tables.</p>"
    },
    "DescribeLocalGatewayRouteTables":{
      "name":"DescribeLocalGatewayRouteTables",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLocalGatewayRouteTablesRequest"},
      "output":{"shape":"DescribeLocalGatewayRouteTablesResult"},
      "documentation":"<p>Describes one or more local gateway route tables. By default, all local gateway route tables are described. Alternatively, you can filter the results.</p>"
    },
    "DescribeLocalGatewayVirtualInterfaceGroups":{
      "name":"DescribeLocalGatewayVirtualInterfaceGroups",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLocalGatewayVirtualInterfaceGroupsRequest"},
      "output":{"shape":"DescribeLocalGatewayVirtualInterfaceGroupsResult"},
      "documentation":"<p>Describes the specified local gateway virtual interface groups.</p>"
    },
    "DescribeLocalGatewayVirtualInterfaces":{
      "name":"DescribeLocalGatewayVirtualInterfaces",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLocalGatewayVirtualInterfacesRequest"},
      "output":{"shape":"DescribeLocalGatewayVirtualInterfacesResult"},
      "documentation":"<p>Describes the specified local gateway virtual interfaces.</p>"
    },
    "DescribeLocalGateways":{
      "name":"DescribeLocalGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeLocalGatewaysRequest"},
      "output":{"shape":"DescribeLocalGatewaysResult"},
      "documentation":"<p>Describes one or more local gateways. By default, all local gateways are described. Alternatively, you can filter the results.</p>"
    },
    "DescribeManagedPrefixLists":{
      "name":"DescribeManagedPrefixLists",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeManagedPrefixListsRequest"},
      "output":{"shape":"DescribeManagedPrefixListsResult"},
      "documentation":"<p>Describes your managed prefix lists and any Amazon Web Services-managed prefix lists.</p> <p>To view the entries for your prefix list, use <a>GetManagedPrefixListEntries</a>.</p>"
    },
    "DescribeMovingAddresses":{
      "name":"DescribeMovingAddresses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeMovingAddressesRequest"},
      "output":{"shape":"DescribeMovingAddressesResult"},
      "documentation":"<p>Describes your Elastic IP addresses that are being moved to the EC2-VPC platform, or that are being restored to the EC2-Classic platform. This request does not return information about any other Elastic IP addresses in your account.</p>"
    },
    "DescribeNatGateways":{
      "name":"DescribeNatGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNatGatewaysRequest"},
      "output":{"shape":"DescribeNatGatewaysResult"},
      "documentation":"<p>Describes one or more of your NAT gateways.</p>"
    },
    "DescribeNetworkAcls":{
      "name":"DescribeNetworkAcls",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkAclsRequest"},
      "output":{"shape":"DescribeNetworkAclsResult"},
      "documentation":"<p>Describes one or more of your network ACLs.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_ACLs.html\">Network ACLs</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DescribeNetworkInsightsAccessScopeAnalyses":{
      "name":"DescribeNetworkInsightsAccessScopeAnalyses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInsightsAccessScopeAnalysesRequest"},
      "output":{"shape":"DescribeNetworkInsightsAccessScopeAnalysesResult"},
      "documentation":"<p>Describes the specified Network Access Scope analyses.</p>"
    },
    "DescribeNetworkInsightsAccessScopes":{
      "name":"DescribeNetworkInsightsAccessScopes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInsightsAccessScopesRequest"},
      "output":{"shape":"DescribeNetworkInsightsAccessScopesResult"},
      "documentation":"<p>Describes the specified Network Access Scopes.</p>"
    },
    "DescribeNetworkInsightsAnalyses":{
      "name":"DescribeNetworkInsightsAnalyses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInsightsAnalysesRequest"},
      "output":{"shape":"DescribeNetworkInsightsAnalysesResult"},
      "documentation":"<p>Describes one or more of your network insights analyses.</p>"
    },
    "DescribeNetworkInsightsPaths":{
      "name":"DescribeNetworkInsightsPaths",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInsightsPathsRequest"},
      "output":{"shape":"DescribeNetworkInsightsPathsResult"},
      "documentation":"<p>Describes one or more of your paths.</p>"
    },
    "DescribeNetworkInterfaceAttribute":{
      "name":"DescribeNetworkInterfaceAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInterfaceAttributeRequest"},
      "output":{"shape":"DescribeNetworkInterfaceAttributeResult"},
      "documentation":"<p>Describes a network interface attribute. You can specify only one attribute at a time.</p>"
    },
    "DescribeNetworkInterfacePermissions":{
      "name":"DescribeNetworkInterfacePermissions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInterfacePermissionsRequest"},
      "output":{"shape":"DescribeNetworkInterfacePermissionsResult"},
      "documentation":"<p>Describes the permissions for your network interfaces. </p>"
    },
    "DescribeNetworkInterfaces":{
      "name":"DescribeNetworkInterfaces",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeNetworkInterfacesRequest"},
      "output":{"shape":"DescribeNetworkInterfacesResult"},
      "documentation":"<p>Describes one or more of your network interfaces.</p>"
    },
    "DescribePlacementGroups":{
      "name":"DescribePlacementGroups",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribePlacementGroupsRequest"},
      "output":{"shape":"DescribePlacementGroupsResult"},
      "documentation":"<p>Describes the specified placement groups or all of your placement groups. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/placement-groups.html\">Placement groups</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribePrefixLists":{
      "name":"DescribePrefixLists",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribePrefixListsRequest"},
      "output":{"shape":"DescribePrefixListsResult"},
      "documentation":"<p>Describes available Amazon Web Services services in a prefix list format, which includes the prefix list name and prefix list ID of the service and the IP address range for the service.</p> <p>We recommend that you use <a>DescribeManagedPrefixLists</a> instead.</p>"
    },
    "DescribePrincipalIdFormat":{
      "name":"DescribePrincipalIdFormat",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribePrincipalIdFormatRequest"},
      "output":{"shape":"DescribePrincipalIdFormatResult"},
      "documentation":"<p>Describes the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preference. </p> <p>By default, all IAM roles and IAM users default to the same ID settings as the root user, unless they explicitly override the settings. This request is useful for identifying those IAM users and IAM roles that have overridden the default ID settings.</p> <p>The following resource types support longer IDs: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>. </p>"
    },
    "DescribePublicIpv4Pools":{
      "name":"DescribePublicIpv4Pools",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribePublicIpv4PoolsRequest"},
      "output":{"shape":"DescribePublicIpv4PoolsResult"},
      "documentation":"<p>Describes the specified IPv4 address pools.</p>"
    },
    "DescribeRegions":{
      "name":"DescribeRegions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeRegionsRequest"},
      "output":{"shape":"DescribeRegionsResult"},
      "documentation":"<p>Describes the Regions that are enabled for your account, or all Regions.</p> <p>For a list of the Regions supported by Amazon EC2, see <a href=\"https://docs.aws.amazon.com/general/latest/gr/ec2-service.html\"> Amazon Elastic Compute Cloud endpoints and quotas</a>.</p> <p>For information about enabling and disabling Regions for your account, see <a href=\"https://docs.aws.amazon.com/general/latest/gr/rande-manage.html\">Managing Amazon Web Services Regions</a> in the <i>Amazon Web Services General Reference</i>.</p>"
    },
    "DescribeReplaceRootVolumeTasks":{
      "name":"DescribeReplaceRootVolumeTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeReplaceRootVolumeTasksRequest"},
      "output":{"shape":"DescribeReplaceRootVolumeTasksResult"},
      "documentation":"<p>Describes a root volume replacement task. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/replace-root.html\">Replace a root volume</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeReservedInstances":{
      "name":"DescribeReservedInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeReservedInstancesRequest"},
      "output":{"shape":"DescribeReservedInstancesResult"},
      "documentation":"<p>Describes one or more of the Reserved Instances that you purchased.</p> <p>For more information about Reserved Instances, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/concepts-on-demand-reserved-instances.html\">Reserved Instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeReservedInstancesListings":{
      "name":"DescribeReservedInstancesListings",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeReservedInstancesListingsRequest"},
      "output":{"shape":"DescribeReservedInstancesListingsResult"},
      "documentation":"<p>Describes your account's Reserved Instance listings in the Reserved Instance Marketplace.</p> <p>The Reserved Instance Marketplace matches sellers who want to resell Reserved Instance capacity that they no longer need with buyers who want to purchase additional capacity. Reserved Instances bought and sold through the Reserved Instance Marketplace work like any other Reserved Instances.</p> <p>As a seller, you choose to list some or all of your Reserved Instances, and you specify the upfront price to receive for them. Your Reserved Instances are then listed in the Reserved Instance Marketplace and are available for purchase.</p> <p>As a buyer, you specify the configuration of the Reserved Instance to purchase, and the Marketplace matches what you're searching for with what's available. The Marketplace first sells the lowest priced Reserved Instances to you, and continues to sell available Reserved Instance listings to you until your demand is met. You are charged based on the total price of all of the listings that you purchase.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-market-general.html\">Reserved Instance Marketplace</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeReservedInstancesModifications":{
      "name":"DescribeReservedInstancesModifications",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeReservedInstancesModificationsRequest"},
      "output":{"shape":"DescribeReservedInstancesModificationsResult"},
      "documentation":"<p>Describes the modifications made to your Reserved Instances. If no parameter is specified, information about all your Reserved Instances modification requests is returned. If a modification ID is specified, only information about the specific modification is returned.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-modifying.html\">Modifying Reserved Instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeReservedInstancesOfferings":{
      "name":"DescribeReservedInstancesOfferings",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeReservedInstancesOfferingsRequest"},
      "output":{"shape":"DescribeReservedInstancesOfferingsResult"},
      "documentation":"<p>Describes Reserved Instance offerings that are available for purchase. With Reserved Instances, you purchase the right to launch instances for a period of time. During that time period, you do not receive insufficient capacity errors, and you pay a lower usage rate than the rate charged for On-Demand instances for the actual time used.</p> <p>If you have listed your own Reserved Instances for sale in the Reserved Instance Marketplace, they will be excluded from these results. This is to ensure that you do not purchase your own Reserved Instances.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-market-general.html\">Reserved Instance Marketplace</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeRouteTables":{
      "name":"DescribeRouteTables",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeRouteTablesRequest"},
      "output":{"shape":"DescribeRouteTablesResult"},
      "documentation":"<p>Describes one or more of your route tables.</p> <p>Each subnet in your VPC must be associated with a route table. If a subnet is not explicitly associated with any route table, it is implicitly associated with the main route table. This command does not return the subnet ID for implicit associations.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DescribeScheduledInstanceAvailability":{
      "name":"DescribeScheduledInstanceAvailability",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeScheduledInstanceAvailabilityRequest"},
      "output":{"shape":"DescribeScheduledInstanceAvailabilityResult"},
      "documentation":"<p>Finds available schedules that meet the specified criteria.</p> <p>You can search for an available schedule no more than 3 months in advance. You must meet the minimum required duration of 1,200 hours per year. For example, the minimum daily schedule is 4 hours, the minimum weekly schedule is 24 hours, and the minimum monthly schedule is 100 hours.</p> <p>After you find a schedule that meets your needs, call <a>PurchaseScheduledInstances</a> to purchase Scheduled Instances with that schedule.</p>"
    },
    "DescribeScheduledInstances":{
      "name":"DescribeScheduledInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeScheduledInstancesRequest"},
      "output":{"shape":"DescribeScheduledInstancesResult"},
      "documentation":"<p>Describes the specified Scheduled Instances or all your Scheduled Instances.</p>"
    },
    "DescribeSecurityGroupReferences":{
      "name":"DescribeSecurityGroupReferences",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSecurityGroupReferencesRequest"},
      "output":{"shape":"DescribeSecurityGroupReferencesResult"},
      "documentation":"<p>[VPC only] Describes the VPCs on the other side of a VPC peering connection that are referencing the security groups you've specified in this request.</p>"
    },
    "DescribeSecurityGroupRules":{
      "name":"DescribeSecurityGroupRules",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSecurityGroupRulesRequest"},
      "output":{"shape":"DescribeSecurityGroupRulesResult"},
      "documentation":"<p>Describes one or more of your security group rules.</p>"
    },
    "DescribeSecurityGroups":{
      "name":"DescribeSecurityGroups",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSecurityGroupsRequest"},
      "output":{"shape":"DescribeSecurityGroupsResult"},
      "documentation":"<p>Describes the specified security groups or all of your security groups.</p> <p>A security group is for use with instances either in the EC2-Classic platform or in a specific VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-network-security.html\">Amazon EC2 security groups</a> in the <i>Amazon Elastic Compute Cloud User Guide</i> and <a href=\"https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_SecurityGroups.html\">Security groups for your VPC</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DescribeSnapshotAttribute":{
      "name":"DescribeSnapshotAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSnapshotAttributeRequest"},
      "output":{"shape":"DescribeSnapshotAttributeResult"},
      "documentation":"<p>Describes the specified attribute of the specified snapshot. You can specify only one attribute at a time.</p> <p>For more information about EBS snapshots, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSSnapshots.html\">Amazon EBS snapshots</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeSnapshotTierStatus":{
      "name":"DescribeSnapshotTierStatus",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSnapshotTierStatusRequest"},
      "output":{"shape":"DescribeSnapshotTierStatusResult"},
      "documentation":"<p>Describes the storage tier status of one or more Amazon EBS snapshots.</p>"
    },
    "DescribeSnapshots":{
      "name":"DescribeSnapshots",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSnapshotsRequest"},
      "output":{"shape":"DescribeSnapshotsResult"},
      "documentation":"<p>Describes the specified EBS snapshots available to you or all of the EBS snapshots available to you.</p> <p>The snapshots available to you include public snapshots, private snapshots that you own, and private snapshots owned by other Amazon Web Services accounts for which you have explicit create volume permissions.</p> <p>The create volume permissions fall into the following categories:</p> <ul> <li> <p> <i>public</i>: The owner of the snapshot granted create volume permissions for the snapshot to the <code>all</code> group. All Amazon Web Services accounts have create volume permissions for these snapshots.</p> </li> <li> <p> <i>explicit</i>: The owner of the snapshot granted create volume permissions to a specific Amazon Web Services account.</p> </li> <li> <p> <i>implicit</i>: An Amazon Web Services account has implicit create volume permissions for all snapshots it owns.</p> </li> </ul> <p>The list of snapshots returned can be filtered by specifying snapshot IDs, snapshot owners, or Amazon Web Services accounts with create volume permissions. If no options are specified, Amazon EC2 returns all snapshots for which you have create volume permissions.</p> <p>If you specify one or more snapshot IDs, only snapshots that have the specified IDs are returned. If you specify an invalid snapshot ID, an error is returned. If you specify a snapshot ID for which you do not have access, it is not included in the returned results.</p> <p>If you specify one or more snapshot owners using the <code>OwnerIds</code> option, only snapshots from the specified owners and for which you have access are returned. The results can include the Amazon Web Services account IDs of the specified owners, <code>amazon</code> for snapshots owned by Amazon, or <code>self</code> for snapshots that you own.</p> <p>If you specify a list of restorable users, only snapshots with create snapshot permissions for those users are returned. You can specify Amazon Web Services account IDs (if you own the snapshots), <code>self</code> for snapshots for which you own or have explicit permissions, or <code>all</code> for public snapshots.</p> <p>If you are describing a long list of snapshots, we recommend that you paginate the output to make the list more manageable. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p> <p>To get the state of fast snapshot restores for a snapshot, use <a>DescribeFastSnapshotRestores</a>.</p> <p>For more information about EBS snapshots, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSSnapshots.html\">Amazon EBS snapshots</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeSpotDatafeedSubscription":{
      "name":"DescribeSpotDatafeedSubscription",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSpotDatafeedSubscriptionRequest"},
      "output":{"shape":"DescribeSpotDatafeedSubscriptionResult"},
      "documentation":"<p>Describes the data feed for Spot Instances. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-data-feeds.html\">Spot Instance data feed</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>"
    },
    "DescribeSpotFleetInstances":{
      "name":"DescribeSpotFleetInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSpotFleetInstancesRequest"},
      "output":{"shape":"DescribeSpotFleetInstancesResponse"},
      "documentation":"<p>Describes the running instances for the specified Spot Fleet.</p>"
    },
    "DescribeSpotFleetRequestHistory":{
      "name":"DescribeSpotFleetRequestHistory",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSpotFleetRequestHistoryRequest"},
      "output":{"shape":"DescribeSpotFleetRequestHistoryResponse"},
      "documentation":"<p>Describes the events for the specified Spot Fleet request during the specified time.</p> <p>Spot Fleet events are delayed by up to 30 seconds before they can be described. This ensures that you can query by the last evaluated time and not miss a recorded event. Spot Fleet events are available for 48 hours.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/fleet-monitor.html\">Monitor fleet events using Amazon EventBridge</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeSpotFleetRequests":{
      "name":"DescribeSpotFleetRequests",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSpotFleetRequestsRequest"},
      "output":{"shape":"DescribeSpotFleetRequestsResponse"},
      "documentation":"<p>Describes your Spot Fleet requests.</p> <p>Spot Fleet requests are deleted 48 hours after they are canceled and their instances are terminated.</p>"
    },
    "DescribeSpotInstanceRequests":{
      "name":"DescribeSpotInstanceRequests",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSpotInstanceRequestsRequest"},
      "output":{"shape":"DescribeSpotInstanceRequestsResult"},
      "documentation":"<p>Describes the specified Spot Instance requests.</p> <p>You can use <code>DescribeSpotInstanceRequests</code> to find a running Spot Instance by examining the response. If the status of the Spot Instance is <code>fulfilled</code>, the instance ID appears in the response and contains the identifier of the instance. Alternatively, you can use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeInstances\">DescribeInstances</a> with a filter to look for instances where the instance lifecycle is <code>spot</code>.</p> <p>We recommend that you set <code>MaxResults</code> to a value between 5 and 1000 to limit the number of results returned. This paginates the output, which makes the list more manageable and returns the results faster. If the list of results exceeds your <code>MaxResults</code> value, then that number of results is returned along with a <code>NextToken</code> value that can be passed to a subsequent <code>DescribeSpotInstanceRequests</code> request to retrieve the remaining results.</p> <p>Spot Instance requests are deleted four hours after they are canceled and their instances are terminated.</p>"
    },
    "DescribeSpotPriceHistory":{
      "name":"DescribeSpotPriceHistory",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSpotPriceHistoryRequest"},
      "output":{"shape":"DescribeSpotPriceHistoryResult"},
      "documentation":"<p>Describes the Spot price history. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-spot-instances-history.html\">Spot Instance pricing history</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p> <p>When you specify a start and end time, the operation returns the prices of the instance types within that time range. It also returns the last price change before the start time, which is the effective price as of the start time.</p>"
    },
    "DescribeStaleSecurityGroups":{
      "name":"DescribeStaleSecurityGroups",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeStaleSecurityGroupsRequest"},
      "output":{"shape":"DescribeStaleSecurityGroupsResult"},
      "documentation":"<p>[VPC only] Describes the stale security group rules for security groups in a specified VPC. Rules are stale when they reference a deleted security group in the same VPC or in a peer VPC, or if they reference a security group in a peer VPC for which the VPC peering connection has been deleted.</p>"
    },
    "DescribeStoreImageTasks":{
      "name":"DescribeStoreImageTasks",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeStoreImageTasksRequest"},
      "output":{"shape":"DescribeStoreImageTasksResult"},
      "documentation":"<p>Describes the progress of the AMI store tasks. You can describe the store tasks for specified AMIs. If you don't specify the AMIs, you get a paginated list of store tasks from the last 31 days.</p> <p>For each AMI task, the response indicates if the task is <code>InProgress</code>, <code>Completed</code>, or <code>Failed</code>. For tasks <code>InProgress</code>, the response shows the estimated progress as a percentage.</p> <p>Tasks are listed in reverse chronological order. Currently, only tasks from the past 31 days can be viewed.</p> <p>To use this API, you must have the required permissions. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-store-restore.html#ami-s3-permissions\">Permissions for storing and restoring AMIs using Amazon S3</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-store-restore.html\">Store and restore an AMI using Amazon S3</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DescribeSubnets":{
      "name":"DescribeSubnets",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeSubnetsRequest"},
      "output":{"shape":"DescribeSubnetsResult"},
      "documentation":"<p>Describes one or more of your subnets.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Subnets.html\">Your VPC and subnets</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DescribeTags":{
      "name":"DescribeTags",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTagsRequest"},
      "output":{"shape":"DescribeTagsResult"},
      "documentation":"<p>Describes the specified tags for your EC2 resources.</p> <p>For more information about tags, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html\">Tag your Amazon EC2 resources</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeTrafficMirrorFilters":{
      "name":"DescribeTrafficMirrorFilters",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTrafficMirrorFiltersRequest"},
      "output":{"shape":"DescribeTrafficMirrorFiltersResult"},
      "documentation":"<p>Describes one or more Traffic Mirror filters.</p>"
    },
    "DescribeTrafficMirrorSessions":{
      "name":"DescribeTrafficMirrorSessions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTrafficMirrorSessionsRequest"},
      "output":{"shape":"DescribeTrafficMirrorSessionsResult"},
      "documentation":"<p>Describes one or more Traffic Mirror sessions. By default, all Traffic Mirror sessions are described. Alternatively, you can filter the results.</p>"
    },
    "DescribeTrafficMirrorTargets":{
      "name":"DescribeTrafficMirrorTargets",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTrafficMirrorTargetsRequest"},
      "output":{"shape":"DescribeTrafficMirrorTargetsResult"},
      "documentation":"<p>Information about one or more Traffic Mirror targets.</p>"
    },
    "DescribeTransitGatewayAttachments":{
      "name":"DescribeTransitGatewayAttachments",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayAttachmentsRequest"},
      "output":{"shape":"DescribeTransitGatewayAttachmentsResult"},
      "documentation":"<p>Describes one or more attachments between resources and transit gateways. By default, all attachments are described. Alternatively, you can filter the results by attachment ID, attachment state, resource ID, or resource owner.</p>"
    },
    "DescribeTransitGatewayConnectPeers":{
      "name":"DescribeTransitGatewayConnectPeers",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayConnectPeersRequest"},
      "output":{"shape":"DescribeTransitGatewayConnectPeersResult"},
      "documentation":"<p>Describes one or more Connect peers.</p>"
    },
    "DescribeTransitGatewayConnects":{
      "name":"DescribeTransitGatewayConnects",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayConnectsRequest"},
      "output":{"shape":"DescribeTransitGatewayConnectsResult"},
      "documentation":"<p>Describes one or more Connect attachments.</p>"
    },
    "DescribeTransitGatewayMulticastDomains":{
      "name":"DescribeTransitGatewayMulticastDomains",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayMulticastDomainsRequest"},
      "output":{"shape":"DescribeTransitGatewayMulticastDomainsResult"},
      "documentation":"<p>Describes one or more transit gateway multicast domains.</p>"
    },
    "DescribeTransitGatewayPeeringAttachments":{
      "name":"DescribeTransitGatewayPeeringAttachments",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayPeeringAttachmentsRequest"},
      "output":{"shape":"DescribeTransitGatewayPeeringAttachmentsResult"},
      "documentation":"<p>Describes your transit gateway peering attachments.</p>"
    },
    "DescribeTransitGatewayPolicyTables":{
      "name":"DescribeTransitGatewayPolicyTables",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayPolicyTablesRequest"},
      "output":{"shape":"DescribeTransitGatewayPolicyTablesResult"},
      "documentation":"<p>Describes one or more transit gateway route policy tables. </p>"
    },
    "DescribeTransitGatewayRouteTableAnnouncements":{
      "name":"DescribeTransitGatewayRouteTableAnnouncements",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayRouteTableAnnouncementsRequest"},
      "output":{"shape":"DescribeTransitGatewayRouteTableAnnouncementsResult"},
      "documentation":"<p>Describes one or more transit gateway route table advertisements.</p>"
    },
    "DescribeTransitGatewayRouteTables":{
      "name":"DescribeTransitGatewayRouteTables",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayRouteTablesRequest"},
      "output":{"shape":"DescribeTransitGatewayRouteTablesResult"},
      "documentation":"<p>Describes one or more transit gateway route tables. By default, all transit gateway route tables are described. Alternatively, you can filter the results.</p>"
    },
    "DescribeTransitGatewayVpcAttachments":{
      "name":"DescribeTransitGatewayVpcAttachments",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewayVpcAttachmentsRequest"},
      "output":{"shape":"DescribeTransitGatewayVpcAttachmentsResult"},
      "documentation":"<p>Describes one or more VPC attachments. By default, all VPC attachments are described. Alternatively, you can filter the results.</p>"
    },
    "DescribeTransitGateways":{
      "name":"DescribeTransitGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTransitGatewaysRequest"},
      "output":{"shape":"DescribeTransitGatewaysResult"},
      "documentation":"<p>Describes one or more transit gateways. By default, all transit gateways are described. Alternatively, you can filter the results.</p>"
    },
    "DescribeTrunkInterfaceAssociations":{
      "name":"DescribeTrunkInterfaceAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeTrunkInterfaceAssociationsRequest"},
      "output":{"shape":"DescribeTrunkInterfaceAssociationsResult"},
      "documentation":"<note> <p>This API action is currently in <b>limited preview only</b>. If you are interested in using this feature, contact your account manager.</p> </note> <p>Describes one or more network interface trunk associations.</p>"
    },
    "DescribeVerifiedAccessEndpoints":{
      "name":"DescribeVerifiedAccessEndpoints",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVerifiedAccessEndpointsRequest"},
      "output":{"shape":"DescribeVerifiedAccessEndpointsResult"},
      "documentation":"<p>Describe Amazon Web Services Verified Access endpoints.</p>"
    },
    "DescribeVerifiedAccessGroups":{
      "name":"DescribeVerifiedAccessGroups",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVerifiedAccessGroupsRequest"},
      "output":{"shape":"DescribeVerifiedAccessGroupsResult"},
      "documentation":"<p>Describe details of existing Verified Access groups.</p>"
    },
    "DescribeVerifiedAccessInstanceLoggingConfigurations":{
      "name":"DescribeVerifiedAccessInstanceLoggingConfigurations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVerifiedAccessInstanceLoggingConfigurationsRequest"},
      "output":{"shape":"DescribeVerifiedAccessInstanceLoggingConfigurationsResult"},
      "documentation":"<p>Describes the current logging configuration for the Amazon Web Services Verified Access instances.</p>"
    },
    "DescribeVerifiedAccessInstances":{
      "name":"DescribeVerifiedAccessInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVerifiedAccessInstancesRequest"},
      "output":{"shape":"DescribeVerifiedAccessInstancesResult"},
      "documentation":"<p>Describe Verified Access instances.</p>"
    },
    "DescribeVerifiedAccessTrustProviders":{
      "name":"DescribeVerifiedAccessTrustProviders",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVerifiedAccessTrustProvidersRequest"},
      "output":{"shape":"DescribeVerifiedAccessTrustProvidersResult"},
      "documentation":"<p>Describe details of existing Verified Access trust providers.</p>"
    },
    "DescribeVolumeAttribute":{
      "name":"DescribeVolumeAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVolumeAttributeRequest"},
      "output":{"shape":"DescribeVolumeAttributeResult"},
      "documentation":"<p>Describes the specified attribute of the specified volume. You can specify only one attribute at a time.</p> <p>For more information about EBS volumes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumes.html\">Amazon EBS volumes</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeVolumeStatus":{
      "name":"DescribeVolumeStatus",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVolumeStatusRequest"},
      "output":{"shape":"DescribeVolumeStatusResult"},
      "documentation":"<p>Describes the status of the specified volumes. Volume status provides the result of the checks performed on your volumes to determine events that can impair the performance of your volumes. The performance of a volume can be affected if an issue occurs on the volume's underlying host. If the volume's underlying host experiences a power outage or system issue, after the system is restored, there could be data inconsistencies on the volume. Volume events notify you if this occurs. Volume actions notify you if any action needs to be taken in response to the event.</p> <p>The <code>DescribeVolumeStatus</code> operation provides the following information about the specified volumes:</p> <p> <i>Status</i>: Reflects the current status of the volume. The possible values are <code>ok</code>, <code>impaired</code> , <code>warning</code>, or <code>insufficient-data</code>. If all checks pass, the overall status of the volume is <code>ok</code>. If the check fails, the overall status is <code>impaired</code>. If the status is <code>insufficient-data</code>, then the checks might still be taking place on your volume at the time. We recommend that you retry the request. For more information about volume status, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/monitoring-volume-status.html\">Monitor the status of your volumes</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p> <i>Events</i>: Reflect the cause of a volume status and might require you to take action. For example, if your volume returns an <code>impaired</code> status, then the volume event might be <code>potential-data-inconsistency</code>. This means that your volume has been affected by an issue with the underlying host, has all I/O operations disabled, and might have inconsistent data.</p> <p> <i>Actions</i>: Reflect the actions you might have to take in response to an event. For example, if the status of the volume is <code>impaired</code> and the volume event shows <code>potential-data-inconsistency</code>, then the action shows <code>enable-volume-io</code>. This means that you may want to enable the I/O operations for the volume by calling the <a>EnableVolumeIO</a> action and then check the volume for data consistency.</p> <p>Volume status is based on the volume status checks, and does not reflect the volume state. Therefore, volume status does not indicate volumes in the <code>error</code> state (for example, when a volume is incapable of accepting I/O.)</p>"
    },
    "DescribeVolumes":{
      "name":"DescribeVolumes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVolumesRequest"},
      "output":{"shape":"DescribeVolumesResult"},
      "documentation":"<p>Describes the specified EBS volumes or all of your EBS volumes.</p> <p>If you are describing a long list of volumes, we recommend that you paginate the output to make the list more manageable. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p> <p>For more information about EBS volumes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumes.html\">Amazon EBS volumes</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeVolumesModifications":{
      "name":"DescribeVolumesModifications",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVolumesModificationsRequest"},
      "output":{"shape":"DescribeVolumesModificationsResult"},
      "documentation":"<p>Describes the most recent volume modification request for the specified EBS volumes.</p> <p>If a volume has never been modified, some information in the output will be null. If a volume has been modified more than once, the output includes only the most recent modification request.</p> <p>You can also use CloudWatch Events to check the status of a modification to an EBS volume. For information about CloudWatch Events, see the <a href=\"https://docs.aws.amazon.com/AmazonCloudWatch/latest/events/\">Amazon CloudWatch Events User Guide</a>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/monitoring-volume-modifications.html\">Monitor the progress of volume modifications</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeVpcAttribute":{
      "name":"DescribeVpcAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcAttributeRequest"},
      "output":{"shape":"DescribeVpcAttributeResult"},
      "documentation":"<p>Describes the specified attribute of the specified VPC. You can specify only one attribute at a time.</p>"
    },
    "DescribeVpcClassicLink":{
      "name":"DescribeVpcClassicLink",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcClassicLinkRequest"},
      "output":{"shape":"DescribeVpcClassicLinkResult"},
      "documentation":"<p>Describes the ClassicLink status of one or more VPCs.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DescribeVpcClassicLinkDnsSupport":{
      "name":"DescribeVpcClassicLinkDnsSupport",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcClassicLinkDnsSupportRequest"},
      "output":{"shape":"DescribeVpcClassicLinkDnsSupportResult"},
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Describes the ClassicLink DNS support status of one or more VPCs. If enabled, the DNS hostname of a linked EC2-Classic instance resolves to its private IP address when addressed from an instance in the VPC to which it's linked. Similarly, the DNS hostname of an instance in a VPC resolves to its private IP address when addressed from a linked EC2-Classic instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-classiclink.html\">ClassicLink</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DescribeVpcEndpointConnectionNotifications":{
      "name":"DescribeVpcEndpointConnectionNotifications",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcEndpointConnectionNotificationsRequest"},
      "output":{"shape":"DescribeVpcEndpointConnectionNotificationsResult"},
      "documentation":"<p>Describes the connection notifications for VPC endpoints and VPC endpoint services.</p>"
    },
    "DescribeVpcEndpointConnections":{
      "name":"DescribeVpcEndpointConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcEndpointConnectionsRequest"},
      "output":{"shape":"DescribeVpcEndpointConnectionsResult"},
      "documentation":"<p>Describes the VPC endpoint connections to your VPC endpoint services, including any endpoints that are pending your acceptance.</p>"
    },
    "DescribeVpcEndpointServiceConfigurations":{
      "name":"DescribeVpcEndpointServiceConfigurations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcEndpointServiceConfigurationsRequest"},
      "output":{"shape":"DescribeVpcEndpointServiceConfigurationsResult"},
      "documentation":"<p>Describes the VPC endpoint service configurations in your account (your services).</p>"
    },
    "DescribeVpcEndpointServicePermissions":{
      "name":"DescribeVpcEndpointServicePermissions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcEndpointServicePermissionsRequest"},
      "output":{"shape":"DescribeVpcEndpointServicePermissionsResult"},
      "documentation":"<p>Describes the principals (service consumers) that are permitted to discover your VPC endpoint service.</p>"
    },
    "DescribeVpcEndpointServices":{
      "name":"DescribeVpcEndpointServices",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcEndpointServicesRequest"},
      "output":{"shape":"DescribeVpcEndpointServicesResult"},
      "documentation":"<p>Describes available services to which you can create a VPC endpoint.</p> <p>When the service provider and the consumer have different accounts in multiple Availability Zones, and the consumer views the VPC endpoint service information, the response only includes the common Availability Zones. For example, when the service provider account uses <code>us-east-1a</code> and <code>us-east-1c</code> and the consumer uses <code>us-east-1a</code> and <code>us-east-1b</code>, the response includes the VPC endpoint services in the common Availability Zone, <code>us-east-1a</code>.</p>"
    },
    "DescribeVpcEndpoints":{
      "name":"DescribeVpcEndpoints",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcEndpointsRequest"},
      "output":{"shape":"DescribeVpcEndpointsResult"},
      "documentation":"<p>Describes your VPC endpoints.</p>"
    },
    "DescribeVpcPeeringConnections":{
      "name":"DescribeVpcPeeringConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcPeeringConnectionsRequest"},
      "output":{"shape":"DescribeVpcPeeringConnectionsResult"},
      "documentation":"<p>Describes one or more of your VPC peering connections.</p>"
    },
    "DescribeVpcs":{
      "name":"DescribeVpcs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpcsRequest"},
      "output":{"shape":"DescribeVpcsResult"},
      "documentation":"<p>Describes one or more of your VPCs.</p>"
    },
    "DescribeVpnConnections":{
      "name":"DescribeVpnConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpnConnectionsRequest"},
      "output":{"shape":"DescribeVpnConnectionsResult"},
      "documentation":"<p>Describes one or more of your VPN connections.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "DescribeVpnGateways":{
      "name":"DescribeVpnGateways",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DescribeVpnGatewaysRequest"},
      "output":{"shape":"DescribeVpnGatewaysResult"},
      "documentation":"<p>Describes one or more of your virtual private gateways.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html\">Amazon Web Services Site-to-Site VPN</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "DetachClassicLinkVpc":{
      "name":"DetachClassicLinkVpc",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DetachClassicLinkVpcRequest"},
      "output":{"shape":"DetachClassicLinkVpcResult"},
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Unlinks (detaches) a linked EC2-Classic instance from a VPC. After the instance has been unlinked, the VPC security groups are no longer associated with it. An instance is automatically unlinked from a VPC when it's stopped.</p>"
    },
    "DetachInternetGateway":{
      "name":"DetachInternetGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DetachInternetGatewayRequest"},
      "documentation":"<p>Detaches an internet gateway from a VPC, disabling connectivity between the internet and the VPC. The VPC must not contain any running instances with Elastic IP addresses or public IPv4 addresses.</p>"
    },
    "DetachNetworkInterface":{
      "name":"DetachNetworkInterface",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DetachNetworkInterfaceRequest"},
      "documentation":"<p>Detaches a network interface from an instance.</p>"
    },
    "DetachVerifiedAccessTrustProvider":{
      "name":"DetachVerifiedAccessTrustProvider",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DetachVerifiedAccessTrustProviderRequest"},
      "output":{"shape":"DetachVerifiedAccessTrustProviderResult"},
      "documentation":"<p>Detach a trust provider from an Amazon Web Services Verified Access instance.</p>"
    },
    "DetachVolume":{
      "name":"DetachVolume",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DetachVolumeRequest"},
      "output":{"shape":"VolumeAttachment"},
      "documentation":"<p>Detaches an EBS volume from an instance. Make sure to unmount any file systems on the device within your operating system before detaching the volume. Failure to do so can result in the volume becoming stuck in the <code>busy</code> state while detaching. If this happens, detachment can be delayed indefinitely until you unmount the volume, force detachment, reboot the instance, or all three. If an EBS volume is the root device of an instance, it can't be detached while the instance is running. To detach the root volume, stop the instance first.</p> <p>When a volume with an Amazon Web Services Marketplace product code is detached from an instance, the product code is no longer associated with the instance.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-detaching-volume.html\">Detach an Amazon EBS volume</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DetachVpnGateway":{
      "name":"DetachVpnGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DetachVpnGatewayRequest"},
      "documentation":"<p>Detaches a virtual private gateway from a VPC. You do this if you're planning to turn off the VPC and not use it anymore. You can confirm a virtual private gateway has been completely detached from a VPC by describing the virtual private gateway (any attachments to the virtual private gateway are also described).</p> <p>You must wait for the attachment's state to switch to <code>detached</code> before you can delete the VPC or attach a different VPC to the virtual private gateway.</p>"
    },
    "DisableAddressTransfer":{
      "name":"DisableAddressTransfer",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableAddressTransferRequest"},
      "output":{"shape":"DisableAddressTransferResult"},
      "documentation":"<p>Disables Elastic IP address transfer. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-eips.html#transfer-EIPs-intro\">Transfer Elastic IP addresses</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DisableAwsNetworkPerformanceMetricSubscription":{
      "name":"DisableAwsNetworkPerformanceMetricSubscription",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableAwsNetworkPerformanceMetricSubscriptionRequest"},
      "output":{"shape":"DisableAwsNetworkPerformanceMetricSubscriptionResult"},
      "documentation":"<p>Disables Infrastructure Performance metric subscriptions.</p>"
    },
    "DisableEbsEncryptionByDefault":{
      "name":"DisableEbsEncryptionByDefault",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableEbsEncryptionByDefaultRequest"},
      "output":{"shape":"DisableEbsEncryptionByDefaultResult"},
      "documentation":"<p>Disables EBS encryption by default for your account in the current Region.</p> <p>After you disable encryption by default, you can still create encrypted volumes by enabling encryption when you create each volume.</p> <p>Disabling encryption by default does not change the encryption status of your existing volumes.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "DisableFastLaunch":{
      "name":"DisableFastLaunch",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableFastLaunchRequest"},
      "output":{"shape":"DisableFastLaunchResult"},
      "documentation":"<p>Discontinue faster launching for a Windows AMI, and clean up existing pre-provisioned snapshots. When you disable faster launching, the AMI uses the standard launch process for each instance. All pre-provisioned snapshots must be removed before you can enable faster launching again.</p> <note> <p>To change these settings, you must own the AMI.</p> </note>"
    },
    "DisableFastSnapshotRestores":{
      "name":"DisableFastSnapshotRestores",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableFastSnapshotRestoresRequest"},
      "output":{"shape":"DisableFastSnapshotRestoresResult"},
      "documentation":"<p>Disables fast snapshot restores for the specified snapshots in the specified Availability Zones.</p>"
    },
    "DisableImageDeprecation":{
      "name":"DisableImageDeprecation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableImageDeprecationRequest"},
      "output":{"shape":"DisableImageDeprecationResult"},
      "documentation":"<p>Cancels the deprecation of the specified AMI.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-deprecate.html\">Deprecate an AMI</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DisableIpamOrganizationAdminAccount":{
      "name":"DisableIpamOrganizationAdminAccount",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableIpamOrganizationAdminAccountRequest"},
      "output":{"shape":"DisableIpamOrganizationAdminAccountResult"},
      "documentation":"<p>Disable the IPAM account. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/enable-integ-ipam.html\">Enable integration with Organizations</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "DisableSerialConsoleAccess":{
      "name":"DisableSerialConsoleAccess",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableSerialConsoleAccessRequest"},
      "output":{"shape":"DisableSerialConsoleAccessResult"},
      "documentation":"<p>Disables access to the EC2 serial console of all instances for your account. By default, access to the EC2 serial console is disabled for your account. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configure-access-to-serial-console.html#serial-console-account-access\">Manage account access to the EC2 serial console</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DisableTransitGatewayRouteTablePropagation":{
      "name":"DisableTransitGatewayRouteTablePropagation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableTransitGatewayRouteTablePropagationRequest"},
      "output":{"shape":"DisableTransitGatewayRouteTablePropagationResult"},
      "documentation":"<p>Disables the specified resource attachment from propagating routes to the specified propagation route table.</p>"
    },
    "DisableVgwRoutePropagation":{
      "name":"DisableVgwRoutePropagation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableVgwRoutePropagationRequest"},
      "documentation":"<p>Disables a virtual private gateway (VGW) from propagating routes to a specified route table of a VPC.</p>"
    },
    "DisableVpcClassicLink":{
      "name":"DisableVpcClassicLink",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableVpcClassicLinkRequest"},
      "output":{"shape":"DisableVpcClassicLinkResult"},
      "documentation":"<p>Disables ClassicLink for a VPC. You cannot disable ClassicLink for a VPC that has EC2-Classic instances linked to it.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DisableVpcClassicLinkDnsSupport":{
      "name":"DisableVpcClassicLinkDnsSupport",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisableVpcClassicLinkDnsSupportRequest"},
      "output":{"shape":"DisableVpcClassicLinkDnsSupportResult"},
      "documentation":"<p>Disables ClassicLink DNS support for a VPC. If disabled, DNS hostnames resolve to public IP addresses when addressed between a linked EC2-Classic instance and instances in the VPC to which it's linked. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-classiclink.html\">ClassicLink</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>You must specify a VPC ID in the request.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "DisassociateAddress":{
      "name":"DisassociateAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateAddressRequest"},
      "documentation":"<p>Disassociates an Elastic IP address from the instance or network interface it's associated with.</p> <p>An Elastic IP address is for use in either the EC2-Classic platform or in a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html\">Elastic IP Addresses</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>This is an idempotent operation. If you perform the operation more than once, Amazon EC2 doesn't return an error.</p>"
    },
    "DisassociateClientVpnTargetNetwork":{
      "name":"DisassociateClientVpnTargetNetwork",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateClientVpnTargetNetworkRequest"},
      "output":{"shape":"DisassociateClientVpnTargetNetworkResult"},
      "documentation":"<p>Disassociates a target network from the specified Client VPN endpoint. When you disassociate the last target network from a Client VPN, the following happens:</p> <ul> <li> <p>The route that was automatically added for the VPC is deleted</p> </li> <li> <p>All active client connections are terminated</p> </li> <li> <p>New client connections are disallowed</p> </li> <li> <p>The Client VPN endpoint's status changes to <code>pending-associate</code> </p> </li> </ul>"
    },
    "DisassociateEnclaveCertificateIamRole":{
      "name":"DisassociateEnclaveCertificateIamRole",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateEnclaveCertificateIamRoleRequest"},
      "output":{"shape":"DisassociateEnclaveCertificateIamRoleResult"},
      "documentation":"<p>Disassociates an IAM role from an Certificate Manager (ACM) certificate. Disassociating an IAM role from an ACM certificate removes the Amazon S3 object that contains the certificate, certificate chain, and encrypted private key from the Amazon S3 bucket. It also revokes the IAM role's permission to use the KMS key used to encrypt the private key. This effectively revokes the role's permission to use the certificate.</p>"
    },
    "DisassociateIamInstanceProfile":{
      "name":"DisassociateIamInstanceProfile",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateIamInstanceProfileRequest"},
      "output":{"shape":"DisassociateIamInstanceProfileResult"},
      "documentation":"<p>Disassociates an IAM instance profile from a running or stopped instance.</p> <p>Use <a>DescribeIamInstanceProfileAssociations</a> to get the association ID.</p>"
    },
    "DisassociateInstanceEventWindow":{
      "name":"DisassociateInstanceEventWindow",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateInstanceEventWindowRequest"},
      "output":{"shape":"DisassociateInstanceEventWindowResult"},
      "documentation":"<p>Disassociates one or more targets from an event window.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/event-windows.html\">Define event windows for scheduled events</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "DisassociateIpamResourceDiscovery":{
      "name":"DisassociateIpamResourceDiscovery",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateIpamResourceDiscoveryRequest"},
      "output":{"shape":"DisassociateIpamResourceDiscoveryResult"},
      "documentation":"<p>Disassociates a resource discovery from an Amazon VPC IPAM. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "DisassociateNatGatewayAddress":{
      "name":"DisassociateNatGatewayAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateNatGatewayAddressRequest"},
      "output":{"shape":"DisassociateNatGatewayAddressResult"},
      "documentation":"<p>Disassociates secondary Elastic IP addresses (EIPs) from a public NAT gateway. You cannot disassociate your primary EIP. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-edit-secondary\">Edit secondary IP address associations</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>While disassociating is in progress, you cannot associate/disassociate additional EIPs while the connections are being drained. You are, however, allowed to delete the NAT gateway.</p> <p>An EIP will only be released at the end of MaxDrainDurationSeconds. The EIPs stay associated and support the existing connections but do not support any new connections (new connections are distributed across the remaining associated EIPs). As the existing connections drain out, the EIPs (and the corresponding private IPs mapped to them) get released.</p>"
    },
    "DisassociateRouteTable":{
      "name":"DisassociateRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateRouteTableRequest"},
      "documentation":"<p>Disassociates a subnet or gateway from a route table.</p> <p>After you perform this action, the subnet no longer uses the routes in the route table. Instead, it uses the routes in the VPC's main route table. For more information about route tables, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "DisassociateSubnetCidrBlock":{
      "name":"DisassociateSubnetCidrBlock",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateSubnetCidrBlockRequest"},
      "output":{"shape":"DisassociateSubnetCidrBlockResult"},
      "documentation":"<p>Disassociates a CIDR block from a subnet. Currently, you can disassociate an IPv6 CIDR block only. You must detach or delete all gateways and resources that are associated with the CIDR block before you can disassociate it. </p>"
    },
    "DisassociateTransitGatewayMulticastDomain":{
      "name":"DisassociateTransitGatewayMulticastDomain",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateTransitGatewayMulticastDomainRequest"},
      "output":{"shape":"DisassociateTransitGatewayMulticastDomainResult"},
      "documentation":"<p>Disassociates the specified subnets from the transit gateway multicast domain. </p>"
    },
    "DisassociateTransitGatewayPolicyTable":{
      "name":"DisassociateTransitGatewayPolicyTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateTransitGatewayPolicyTableRequest"},
      "output":{"shape":"DisassociateTransitGatewayPolicyTableResult"},
      "documentation":"<p>Removes the association between an an attachment and a policy table.</p>"
    },
    "DisassociateTransitGatewayRouteTable":{
      "name":"DisassociateTransitGatewayRouteTable",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateTransitGatewayRouteTableRequest"},
      "output":{"shape":"DisassociateTransitGatewayRouteTableResult"},
      "documentation":"<p>Disassociates a resource attachment from a transit gateway route table.</p>"
    },
    "DisassociateTrunkInterface":{
      "name":"DisassociateTrunkInterface",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateTrunkInterfaceRequest"},
      "output":{"shape":"DisassociateTrunkInterfaceResult"},
      "documentation":"<note> <p>This API action is currently in <b>limited preview only</b>. If you are interested in using this feature, contact your account manager.</p> </note> <p>Removes an association between a branch network interface with a trunk network interface.</p>"
    },
    "DisassociateVpcCidrBlock":{
      "name":"DisassociateVpcCidrBlock",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"DisassociateVpcCidrBlockRequest"},
      "output":{"shape":"DisassociateVpcCidrBlockResult"},
      "documentation":"<p>Disassociates a CIDR block from a VPC. To disassociate the CIDR block, you must specify its association ID. You can get the association ID by using <a>DescribeVpcs</a>. You must detach or delete all gateways and resources that are associated with the CIDR block before you can disassociate it. </p> <p>You cannot disassociate the CIDR block with which you originally created the VPC (the primary CIDR block).</p>"
    },
    "EnableAddressTransfer":{
      "name":"EnableAddressTransfer",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableAddressTransferRequest"},
      "output":{"shape":"EnableAddressTransferResult"},
      "documentation":"<p>Enables Elastic IP address transfer. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-eips.html#transfer-EIPs-intro\">Transfer Elastic IP addresses</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "EnableAwsNetworkPerformanceMetricSubscription":{
      "name":"EnableAwsNetworkPerformanceMetricSubscription",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableAwsNetworkPerformanceMetricSubscriptionRequest"},
      "output":{"shape":"EnableAwsNetworkPerformanceMetricSubscriptionResult"},
      "documentation":"<p>Enables Infrastructure Performance subscriptions.</p>"
    },
    "EnableEbsEncryptionByDefault":{
      "name":"EnableEbsEncryptionByDefault",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableEbsEncryptionByDefaultRequest"},
      "output":{"shape":"EnableEbsEncryptionByDefaultResult"},
      "documentation":"<p>Enables EBS encryption by default for your account in the current Region.</p> <p>After you enable encryption by default, the EBS volumes that you create are always encrypted, either using the default KMS key or the KMS key that you specified when you created each volume. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>You can specify the default KMS key for encryption by default using <a>ModifyEbsDefaultKmsKeyId</a> or <a>ResetEbsDefaultKmsKeyId</a>.</p> <p>Enabling encryption by default has no effect on the encryption status of your existing volumes.</p> <p>After you enable encryption by default, you can no longer launch instances using instance types that do not support encryption. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html#EBSEncryption_supported_instances\">Supported instance types</a>.</p>"
    },
    "EnableFastLaunch":{
      "name":"EnableFastLaunch",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableFastLaunchRequest"},
      "output":{"shape":"EnableFastLaunchResult"},
      "documentation":"<p>When you enable faster launching for a Windows AMI, images are pre-provisioned, using snapshots to launch instances up to 65% faster. To create the optimized Windows image, Amazon EC2 launches an instance and runs through Sysprep steps, rebooting as required. Then it creates a set of reserved snapshots that are used for subsequent launches. The reserved snapshots are automatically replenished as they are used, depending on your settings for launch frequency.</p> <note> <p>To change these settings, you must own the AMI.</p> </note>"
    },
    "EnableFastSnapshotRestores":{
      "name":"EnableFastSnapshotRestores",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableFastSnapshotRestoresRequest"},
      "output":{"shape":"EnableFastSnapshotRestoresResult"},
      "documentation":"<p>Enables fast snapshot restores for the specified snapshots in the specified Availability Zones.</p> <p>You get the full benefit of fast snapshot restores after they enter the <code>enabled</code> state. To get the current state of fast snapshot restores, use <a>DescribeFastSnapshotRestores</a>. To disable fast snapshot restores, use <a>DisableFastSnapshotRestores</a>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-fast-snapshot-restore.html\">Amazon EBS fast snapshot restore</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "EnableImageDeprecation":{
      "name":"EnableImageDeprecation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableImageDeprecationRequest"},
      "output":{"shape":"EnableImageDeprecationResult"},
      "documentation":"<p>Enables deprecation of the specified AMI at the specified date and time.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-deprecate.html\">Deprecate an AMI</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "EnableIpamOrganizationAdminAccount":{
      "name":"EnableIpamOrganizationAdminAccount",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableIpamOrganizationAdminAccountRequest"},
      "output":{"shape":"EnableIpamOrganizationAdminAccountResult"},
      "documentation":"<p>Enable an Organizations member account as the IPAM admin account. You cannot select the Organizations management account as the IPAM admin account. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/enable-integ-ipam.html\">Enable integration with Organizations</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "EnableReachabilityAnalyzerOrganizationSharing":{
      "name":"EnableReachabilityAnalyzerOrganizationSharing",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableReachabilityAnalyzerOrganizationSharingRequest"},
      "output":{"shape":"EnableReachabilityAnalyzerOrganizationSharingResult"},
      "documentation":"<p>Establishes a trust relationship between Reachability Analyzer and Organizations. This operation must be performed by the management account for the organization.</p> <p>After you establish a trust relationship, a user in the management account or a delegated administrator account can run a cross-account analysis using resources from the member accounts.</p>"
    },
    "EnableSerialConsoleAccess":{
      "name":"EnableSerialConsoleAccess",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableSerialConsoleAccessRequest"},
      "output":{"shape":"EnableSerialConsoleAccessResult"},
      "documentation":"<p>Enables access to the EC2 serial console of all instances for your account. By default, access to the EC2 serial console is disabled for your account. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configure-access-to-serial-console.html#serial-console-account-access\">Manage account access to the EC2 serial console</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "EnableTransitGatewayRouteTablePropagation":{
      "name":"EnableTransitGatewayRouteTablePropagation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableTransitGatewayRouteTablePropagationRequest"},
      "output":{"shape":"EnableTransitGatewayRouteTablePropagationResult"},
      "documentation":"<p>Enables the specified attachment to propagate routes to the specified propagation route table.</p>"
    },
    "EnableVgwRoutePropagation":{
      "name":"EnableVgwRoutePropagation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableVgwRoutePropagationRequest"},
      "documentation":"<p>Enables a virtual private gateway (VGW) to propagate routes to the specified route table of a VPC.</p>"
    },
    "EnableVolumeIO":{
      "name":"EnableVolumeIO",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableVolumeIORequest"},
      "documentation":"<p>Enables I/O operations for a volume that had I/O operations disabled because the data on the volume was potentially inconsistent.</p>"
    },
    "EnableVpcClassicLink":{
      "name":"EnableVpcClassicLink",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableVpcClassicLinkRequest"},
      "output":{"shape":"EnableVpcClassicLinkResult"},
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Enables a VPC for ClassicLink. You can then link EC2-Classic instances to your ClassicLink-enabled VPC to allow communication over private IP addresses. You cannot enable your VPC for ClassicLink if any of your VPC route tables have existing routes for address ranges within the <code>10.0.0.0/8</code> IP address range, excluding local routes for VPCs in the <code>10.0.0.0/16</code> and <code>10.1.0.0/16</code> IP address ranges. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-classiclink.html\">ClassicLink</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "EnableVpcClassicLinkDnsSupport":{
      "name":"EnableVpcClassicLinkDnsSupport",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"EnableVpcClassicLinkDnsSupportRequest"},
      "output":{"shape":"EnableVpcClassicLinkDnsSupportResult"},
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Enables a VPC to support DNS hostname resolution for ClassicLink. If enabled, the DNS hostname of a linked EC2-Classic instance resolves to its private IP address when addressed from an instance in the VPC to which it's linked. Similarly, the DNS hostname of an instance in a VPC resolves to its private IP address when addressed from a linked EC2-Classic instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-classiclink.html\">ClassicLink</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>You must specify a VPC ID in the request.</p>"
    },
    "ExportClientVpnClientCertificateRevocationList":{
      "name":"ExportClientVpnClientCertificateRevocationList",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ExportClientVpnClientCertificateRevocationListRequest"},
      "output":{"shape":"ExportClientVpnClientCertificateRevocationListResult"},
      "documentation":"<p>Downloads the client certificate revocation list for the specified Client VPN endpoint.</p>"
    },
    "ExportClientVpnClientConfiguration":{
      "name":"ExportClientVpnClientConfiguration",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ExportClientVpnClientConfigurationRequest"},
      "output":{"shape":"ExportClientVpnClientConfigurationResult"},
      "documentation":"<p>Downloads the contents of the Client VPN endpoint configuration file for the specified Client VPN endpoint. The Client VPN endpoint configuration file includes the Client VPN endpoint and certificate information clients need to establish a connection with the Client VPN endpoint.</p>"
    },
    "ExportImage":{
      "name":"ExportImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ExportImageRequest"},
      "output":{"shape":"ExportImageResult"},
      "documentation":"<p>Exports an Amazon Machine Image (AMI) to a VM file. For more information, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport_image.html\">Exporting a VM directly from an Amazon Machine Image (AMI)</a> in the <i>VM Import/Export User Guide</i>.</p>"
    },
    "ExportTransitGatewayRoutes":{
      "name":"ExportTransitGatewayRoutes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ExportTransitGatewayRoutesRequest"},
      "output":{"shape":"ExportTransitGatewayRoutesResult"},
      "documentation":"<p>Exports routes from the specified transit gateway route table to the specified S3 bucket. By default, all routes are exported. Alternatively, you can filter by CIDR range.</p> <p>The routes are saved to the specified bucket in a JSON file. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/tgw/tgw-route-tables.html#tgw-export-route-tables\">Export Route Tables to Amazon S3</a> in <i>Transit Gateways</i>.</p>"
    },
    "GetAssociatedEnclaveCertificateIamRoles":{
      "name":"GetAssociatedEnclaveCertificateIamRoles",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetAssociatedEnclaveCertificateIamRolesRequest"},
      "output":{"shape":"GetAssociatedEnclaveCertificateIamRolesResult"},
      "documentation":"<p>Returns the IAM roles that are associated with the specified ACM (ACM) certificate. It also returns the name of the Amazon S3 bucket and the Amazon S3 object key where the certificate, certificate chain, and encrypted private key bundle are stored, and the ARN of the KMS key that's used to encrypt the private key.</p>"
    },
    "GetAssociatedIpv6PoolCidrs":{
      "name":"GetAssociatedIpv6PoolCidrs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetAssociatedIpv6PoolCidrsRequest"},
      "output":{"shape":"GetAssociatedIpv6PoolCidrsResult"},
      "documentation":"<p>Gets information about the IPv6 CIDR block associations for a specified IPv6 address pool.</p>"
    },
    "GetAwsNetworkPerformanceData":{
      "name":"GetAwsNetworkPerformanceData",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetAwsNetworkPerformanceDataRequest"},
      "output":{"shape":"GetAwsNetworkPerformanceDataResult"},
      "documentation":"<p>Gets network performance data.</p>"
    },
    "GetCapacityReservationUsage":{
      "name":"GetCapacityReservationUsage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetCapacityReservationUsageRequest"},
      "output":{"shape":"GetCapacityReservationUsageResult"},
      "documentation":"<p>Gets usage information about a Capacity Reservation. If the Capacity Reservation is shared, it shows usage information for the Capacity Reservation owner and each Amazon Web Services account that is currently using the shared capacity. If the Capacity Reservation is not shared, it shows only the Capacity Reservation owner's usage.</p>"
    },
    "GetCoipPoolUsage":{
      "name":"GetCoipPoolUsage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetCoipPoolUsageRequest"},
      "output":{"shape":"GetCoipPoolUsageResult"},
      "documentation":"<p>Describes the allocations from the specified customer-owned address pool.</p>"
    },
    "GetConsoleOutput":{
      "name":"GetConsoleOutput",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetConsoleOutputRequest"},
      "output":{"shape":"GetConsoleOutputResult"},
      "documentation":"<p>Gets the console output for the specified instance. For Linux instances, the instance console output displays the exact console output that would normally be displayed on a physical monitor attached to a computer. For Windows instances, the instance console output includes the last three system event log errors.</p> <p>By default, the console output returns buffered information that was posted shortly after an instance transition state (start, stop, reboot, or terminate). This information is available for at least one hour after the most recent post. Only the most recent 64 KB of console output is available.</p> <p>You can optionally retrieve the latest serial console output at any time during the instance lifecycle. This option is supported on instance types that use the Nitro hypervisor.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-console.html#instance-console-console-output\">Instance console output</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "GetConsoleScreenshot":{
      "name":"GetConsoleScreenshot",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetConsoleScreenshotRequest"},
      "output":{"shape":"GetConsoleScreenshotResult"},
      "documentation":"<p>Retrieve a JPG-format screenshot of a running instance to help with troubleshooting.</p> <p>The returned content is Base64-encoded.</p>"
    },
    "GetDefaultCreditSpecification":{
      "name":"GetDefaultCreditSpecification",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetDefaultCreditSpecificationRequest"},
      "output":{"shape":"GetDefaultCreditSpecificationResult"},
      "documentation":"<p>Describes the default credit option for CPU usage of a burstable performance instance family.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "GetEbsDefaultKmsKeyId":{
      "name":"GetEbsDefaultKmsKeyId",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetEbsDefaultKmsKeyIdRequest"},
      "output":{"shape":"GetEbsDefaultKmsKeyIdResult"},
      "documentation":"<p>Describes the default KMS key for EBS encryption by default for your account in this Region. You can change the default KMS key for encryption by default using <a>ModifyEbsDefaultKmsKeyId</a> or <a>ResetEbsDefaultKmsKeyId</a>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "GetEbsEncryptionByDefault":{
      "name":"GetEbsEncryptionByDefault",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetEbsEncryptionByDefaultRequest"},
      "output":{"shape":"GetEbsEncryptionByDefaultResult"},
      "documentation":"<p>Describes whether EBS encryption by default is enabled for your account in the current Region.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "GetFlowLogsIntegrationTemplate":{
      "name":"GetFlowLogsIntegrationTemplate",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetFlowLogsIntegrationTemplateRequest"},
      "output":{"shape":"GetFlowLogsIntegrationTemplateResult"},
      "documentation":"<p>Generates a CloudFormation template that streamlines and automates the integration of VPC flow logs with Amazon Athena. This make it easier for you to query and gain insights from VPC flow logs data. Based on the information that you provide, we configure resources in the template to do the following:</p> <ul> <li> <p>Create a table in Athena that maps fields to a custom log format</p> </li> <li> <p>Create a Lambda function that updates the table with new partitions on a daily, weekly, or monthly basis</p> </li> <li> <p>Create a table partitioned between two timestamps in the past</p> </li> <li> <p>Create a set of named queries in Athena that you can use to get started quickly</p> </li> </ul>"
    },
    "GetGroupsForCapacityReservation":{
      "name":"GetGroupsForCapacityReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetGroupsForCapacityReservationRequest"},
      "output":{"shape":"GetGroupsForCapacityReservationResult"},
      "documentation":"<p>Lists the resource groups to which a Capacity Reservation has been added.</p>"
    },
    "GetHostReservationPurchasePreview":{
      "name":"GetHostReservationPurchasePreview",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetHostReservationPurchasePreviewRequest"},
      "output":{"shape":"GetHostReservationPurchasePreviewResult"},
      "documentation":"<p>Preview a reservation purchase with configurations that match those of your Dedicated Host. You must have active Dedicated Hosts in your account before you purchase a reservation.</p> <p>This is a preview of the <a>PurchaseHostReservation</a> action and does not result in the offering being purchased.</p>"
    },
    "GetInstanceTypesFromInstanceRequirements":{
      "name":"GetInstanceTypesFromInstanceRequirements",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetInstanceTypesFromInstanceRequirementsRequest"},
      "output":{"shape":"GetInstanceTypesFromInstanceRequirementsResult"},
      "documentation":"<p>Returns a list of instance types with the specified instance attributes. You can use the response to preview the instance types without launching instances. Note that the response does not consider capacity.</p> <p>When you specify multiple parameters, you get instance types that satisfy all of the specified parameters. If you specify multiple values for a parameter, you get instance types that satisfy any of the specified values.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-attribute-based-instance-type-selection.html#spotfleet-get-instance-types-from-instance-requirements\">Preview instance types with specified attributes</a>, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-attribute-based-instance-type-selection.html\">Attribute-based instance type selection for EC2 Fleet</a>, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-attribute-based-instance-type-selection.html\">Attribute-based instance type selection for Spot Fleet</a>, and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-placement-score.html\">Spot placement score</a> in the <i>Amazon EC2 User Guide</i>, and <a href=\"https://docs.aws.amazon.com/autoscaling/ec2/userguide/create-asg-instance-type-requirements.html\">Creating an Auto Scaling group using attribute-based instance type selection</a> in the <i>Amazon EC2 Auto Scaling User Guide</i>.</p>"
    },
    "GetInstanceUefiData":{
      "name":"GetInstanceUefiData",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetInstanceUefiDataRequest"},
      "output":{"shape":"GetInstanceUefiDataResult"},
      "documentation":"<p>A binary representation of the UEFI variable store. Only non-volatile variables are stored. This is a base64 encoded and zlib compressed binary value that must be properly encoded.</p> <p>When you use <a href=\"https://docs.aws.amazon.com/cli/latest/reference/ec2/register-image.html\">register-image</a> to create an AMI, you can create an exact copy of your variable store by passing the UEFI data in the <code>UefiData</code> parameter. You can modify the UEFI data by using the <a href=\"https://github.com/awslabs/python-uefivars\">python-uefivars tool</a> on GitHub. You can use the tool to convert the UEFI data into a human-readable format (JSON), which you can inspect and modify, and then convert back into the binary format to use with register-image.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/uefi-secure-boot.html\">UEFI Secure Boot</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "GetIpamAddressHistory":{
      "name":"GetIpamAddressHistory",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetIpamAddressHistoryRequest"},
      "output":{"shape":"GetIpamAddressHistoryResult"},
      "documentation":"<p>Retrieve historical information about a CIDR within an IPAM scope. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/view-history-cidr-ipam.html\">View the history of IP addresses</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "GetIpamDiscoveredAccounts":{
      "name":"GetIpamDiscoveredAccounts",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetIpamDiscoveredAccountsRequest"},
      "output":{"shape":"GetIpamDiscoveredAccountsResult"},
      "documentation":"<p>Gets IPAM discovered accounts. A discovered account is an Amazon Web Services account that is monitored under a resource discovery. If you have integrated IPAM with Amazon Web Services Organizations, all accounts in the organization are discovered accounts. Only the IPAM account can get all discovered accounts in the organization.</p>"
    },
    "GetIpamDiscoveredResourceCidrs":{
      "name":"GetIpamDiscoveredResourceCidrs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetIpamDiscoveredResourceCidrsRequest"},
      "output":{"shape":"GetIpamDiscoveredResourceCidrsResult"},
      "documentation":"<p>Returns the resource CIDRs that are monitored as part of a resource discovery. A discovered resource is a resource CIDR monitored under a resource discovery. The following resources can be discovered: VPCs, Public IPv4 pools, VPC subnets, and Elastic IP addresses. </p>"
    },
    "GetIpamPoolAllocations":{
      "name":"GetIpamPoolAllocations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetIpamPoolAllocationsRequest"},
      "output":{"shape":"GetIpamPoolAllocationsResult"},
      "documentation":"<p>Get a list of all the CIDR allocations in an IPAM pool.</p>"
    },
    "GetIpamPoolCidrs":{
      "name":"GetIpamPoolCidrs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetIpamPoolCidrsRequest"},
      "output":{"shape":"GetIpamPoolCidrsResult"},
      "documentation":"<p>Get the CIDRs provisioned to an IPAM pool.</p>"
    },
    "GetIpamResourceCidrs":{
      "name":"GetIpamResourceCidrs",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetIpamResourceCidrsRequest"},
      "output":{"shape":"GetIpamResourceCidrsResult"},
      "documentation":"<p>Returns resource CIDRs managed by IPAM in a given scope. If an IPAM is associated with more than one resource discovery, the resource CIDRs across all of the resource discoveries is returned. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "GetLaunchTemplateData":{
      "name":"GetLaunchTemplateData",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetLaunchTemplateDataRequest"},
      "output":{"shape":"GetLaunchTemplateDataResult"},
      "documentation":"<p>Retrieves the configuration data of the specified instance. You can use this data to create a launch template. </p> <p>This action calls on other describe actions to get instance information. Depending on your instance configuration, you may need to allow the following actions in your IAM policy: <code>DescribeSpotInstanceRequests</code>, <code>DescribeInstanceCreditSpecifications</code>, <code>DescribeVolumes</code>, <code>DescribeInstanceAttribute</code>, and <code>DescribeElasticGpus</code>. Or, you can allow <code>describe*</code> depending on your instance requirements.</p>"
    },
    "GetManagedPrefixListAssociations":{
      "name":"GetManagedPrefixListAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetManagedPrefixListAssociationsRequest"},
      "output":{"shape":"GetManagedPrefixListAssociationsResult"},
      "documentation":"<p>Gets information about the resources that are associated with the specified managed prefix list.</p>"
    },
    "GetManagedPrefixListEntries":{
      "name":"GetManagedPrefixListEntries",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetManagedPrefixListEntriesRequest"},
      "output":{"shape":"GetManagedPrefixListEntriesResult"},
      "documentation":"<p>Gets information about the entries for a specified managed prefix list.</p>"
    },
    "GetNetworkInsightsAccessScopeAnalysisFindings":{
      "name":"GetNetworkInsightsAccessScopeAnalysisFindings",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetNetworkInsightsAccessScopeAnalysisFindingsRequest"},
      "output":{"shape":"GetNetworkInsightsAccessScopeAnalysisFindingsResult"},
      "documentation":"<p>Gets the findings for the specified Network Access Scope analysis.</p>"
    },
    "GetNetworkInsightsAccessScopeContent":{
      "name":"GetNetworkInsightsAccessScopeContent",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetNetworkInsightsAccessScopeContentRequest"},
      "output":{"shape":"GetNetworkInsightsAccessScopeContentResult"},
      "documentation":"<p>Gets the content for the specified Network Access Scope.</p>"
    },
    "GetPasswordData":{
      "name":"GetPasswordData",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetPasswordDataRequest"},
      "output":{"shape":"GetPasswordDataResult"},
      "documentation":"<p>Retrieves the encrypted administrator password for a running Windows instance.</p> <p>The Windows password is generated at boot by the <code>EC2Config</code> service or <code>EC2Launch</code> scripts (Windows Server 2016 and later). This usually only happens the first time an instance is launched. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/UsingConfig_WinAMI.html\">EC2Config</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ec2launch.html\">EC2Launch</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For the <code>EC2Config</code> service, the password is not generated for rebundled AMIs unless <code>Ec2SetPassword</code> is enabled before bundling.</p> <p>The password is encrypted using the key pair that you specified when you launched the instance. You must provide the corresponding key pair file.</p> <p>When you launch an instance, password generation and encryption may take a few minutes. If you try to retrieve the password before it's available, the output returns an empty string. We recommend that you wait up to 15 minutes after launching an instance before trying to retrieve the generated password.</p>"
    },
    "GetReservedInstancesExchangeQuote":{
      "name":"GetReservedInstancesExchangeQuote",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetReservedInstancesExchangeQuoteRequest"},
      "output":{"shape":"GetReservedInstancesExchangeQuoteResult"},
      "documentation":"<p>Returns a quote and exchange information for exchanging one or more specified Convertible Reserved Instances for a new Convertible Reserved Instance. If the exchange cannot be performed, the reason is returned in the response. Use <a>AcceptReservedInstancesExchangeQuote</a> to perform the exchange.</p>"
    },
    "GetSerialConsoleAccessStatus":{
      "name":"GetSerialConsoleAccessStatus",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetSerialConsoleAccessStatusRequest"},
      "output":{"shape":"GetSerialConsoleAccessStatusResult"},
      "documentation":"<p>Retrieves the access status of your account to the EC2 serial console of all instances. By default, access to the EC2 serial console is disabled for your account. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configure-access-to-serial-console.html#serial-console-account-access\">Manage account access to the EC2 serial console</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "GetSpotPlacementScores":{
      "name":"GetSpotPlacementScores",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetSpotPlacementScoresRequest"},
      "output":{"shape":"GetSpotPlacementScoresResult"},
      "documentation":"<p>Calculates the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirements.</p> <p>You can specify your compute requirements either by using <code>InstanceRequirementsWithMetadata</code> and letting Amazon EC2 choose the optimal instance types to fulfill your Spot request, or you can specify the instance types by using <code>InstanceTypes</code>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-placement-score.html\">Spot placement score</a> in the Amazon EC2 User Guide.</p>"
    },
    "GetSubnetCidrReservations":{
      "name":"GetSubnetCidrReservations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetSubnetCidrReservationsRequest"},
      "output":{"shape":"GetSubnetCidrReservationsResult"},
      "documentation":"<p>Gets information about the subnet CIDR reservations.</p>"
    },
    "GetTransitGatewayAttachmentPropagations":{
      "name":"GetTransitGatewayAttachmentPropagations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayAttachmentPropagationsRequest"},
      "output":{"shape":"GetTransitGatewayAttachmentPropagationsResult"},
      "documentation":"<p>Lists the route tables to which the specified resource attachment propagates routes.</p>"
    },
    "GetTransitGatewayMulticastDomainAssociations":{
      "name":"GetTransitGatewayMulticastDomainAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayMulticastDomainAssociationsRequest"},
      "output":{"shape":"GetTransitGatewayMulticastDomainAssociationsResult"},
      "documentation":"<p>Gets information about the associations for the transit gateway multicast domain.</p>"
    },
    "GetTransitGatewayPolicyTableAssociations":{
      "name":"GetTransitGatewayPolicyTableAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayPolicyTableAssociationsRequest"},
      "output":{"shape":"GetTransitGatewayPolicyTableAssociationsResult"},
      "documentation":"<p>Gets a list of the transit gateway policy table associations.</p>"
    },
    "GetTransitGatewayPolicyTableEntries":{
      "name":"GetTransitGatewayPolicyTableEntries",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayPolicyTableEntriesRequest"},
      "output":{"shape":"GetTransitGatewayPolicyTableEntriesResult"},
      "documentation":"<p>Returns a list of transit gateway policy table entries.</p>"
    },
    "GetTransitGatewayPrefixListReferences":{
      "name":"GetTransitGatewayPrefixListReferences",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayPrefixListReferencesRequest"},
      "output":{"shape":"GetTransitGatewayPrefixListReferencesResult"},
      "documentation":"<p>Gets information about the prefix list references in a specified transit gateway route table.</p>"
    },
    "GetTransitGatewayRouteTableAssociations":{
      "name":"GetTransitGatewayRouteTableAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayRouteTableAssociationsRequest"},
      "output":{"shape":"GetTransitGatewayRouteTableAssociationsResult"},
      "documentation":"<p>Gets information about the associations for the specified transit gateway route table.</p>"
    },
    "GetTransitGatewayRouteTablePropagations":{
      "name":"GetTransitGatewayRouteTablePropagations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetTransitGatewayRouteTablePropagationsRequest"},
      "output":{"shape":"GetTransitGatewayRouteTablePropagationsResult"},
      "documentation":"<p>Gets information about the route table propagations for the specified transit gateway route table.</p>"
    },
    "GetVerifiedAccessEndpointPolicy":{
      "name":"GetVerifiedAccessEndpointPolicy",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetVerifiedAccessEndpointPolicyRequest"},
      "output":{"shape":"GetVerifiedAccessEndpointPolicyResult"},
      "documentation":"<p>Get the Verified Access policy associated with the endpoint.</p>"
    },
    "GetVerifiedAccessGroupPolicy":{
      "name":"GetVerifiedAccessGroupPolicy",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetVerifiedAccessGroupPolicyRequest"},
      "output":{"shape":"GetVerifiedAccessGroupPolicyResult"},
      "documentation":"<p>Shows the contents of the Verified Access policy associated with the group.</p>"
    },
    "GetVpnConnectionDeviceSampleConfiguration":{
      "name":"GetVpnConnectionDeviceSampleConfiguration",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetVpnConnectionDeviceSampleConfigurationRequest"},
      "output":{"shape":"GetVpnConnectionDeviceSampleConfigurationResult"},
      "documentation":"<p>Download an Amazon Web Services-provided sample configuration file to be used with the customer gateway device specified for your Site-to-Site VPN connection.</p>"
    },
    "GetVpnConnectionDeviceTypes":{
      "name":"GetVpnConnectionDeviceTypes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"GetVpnConnectionDeviceTypesRequest"},
      "output":{"shape":"GetVpnConnectionDeviceTypesResult"},
      "documentation":"<p>Obtain a list of customer gateway devices for which sample configuration files can be provided. The request has no additional parameters. You can also see the list of device types with sample configuration files available under <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/your-cgw.html\">Your customer gateway device</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "ImportClientVpnClientCertificateRevocationList":{
      "name":"ImportClientVpnClientCertificateRevocationList",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ImportClientVpnClientCertificateRevocationListRequest"},
      "output":{"shape":"ImportClientVpnClientCertificateRevocationListResult"},
      "documentation":"<p>Uploads a client certificate revocation list to the specified Client VPN endpoint. Uploading a client certificate revocation list overwrites the existing client certificate revocation list.</p> <p>Uploading a client certificate revocation list resets existing client connections.</p>"
    },
    "ImportImage":{
      "name":"ImportImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ImportImageRequest"},
      "output":{"shape":"ImportImageResult"},
      "documentation":"<p>Import single or multi-volume disk images or EBS snapshots into an Amazon Machine Image (AMI).</p> <important> <p>Amazon Web Services VM Import/Export strongly recommends specifying a value for either the <code>--license-type</code> or <code>--usage-operation</code> parameter when you create a new VM Import task. This ensures your operating system is licensed appropriately and your billing is optimized.</p> </important> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-image-import.html\">Importing a VM as an image using VM Import/Export</a> in the <i>VM Import/Export User Guide</i>.</p>"
    },
    "ImportInstance":{
      "name":"ImportInstance",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ImportInstanceRequest"},
      "output":{"shape":"ImportInstanceResult"},
      "documentation":"<p>Creates an import instance task using metadata from the specified disk image.</p> <p>This API action supports only single-volume VMs. To import multi-volume VMs, use <a>ImportImage</a> instead.</p> <p>This API action is not supported by the Command Line Interface (CLI). For information about using the Amazon EC2 CLI, which is deprecated, see <a href=\"https://awsdocs.s3.amazonaws.com/EC2/ec2-clt.pdf#UsingVirtualMachinesinAmazonEC2\">Importing a VM to Amazon EC2</a> in the <i>Amazon EC2 CLI Reference</i> PDF file.</p> <p>For information about the import manifest referenced by this API action, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/manifest.html\">VM Import Manifest</a>.</p>"
    },
    "ImportKeyPair":{
      "name":"ImportKeyPair",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ImportKeyPairRequest"},
      "output":{"shape":"ImportKeyPairResult"},
      "documentation":"<p>Imports the public key from an RSA or ED25519 key pair that you created with a third-party tool. Compare this with <a>CreateKeyPair</a>, in which Amazon Web Services creates the key pair and gives the keys to you (Amazon Web Services keeps a copy of the public key). With ImportKeyPair, you create the key pair and give Amazon Web Services just the public key. The private key is never transferred between you and Amazon Web Services.</p> <p>For more information about key pairs, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html\">Amazon EC2 key pairs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ImportSnapshot":{
      "name":"ImportSnapshot",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ImportSnapshotRequest"},
      "output":{"shape":"ImportSnapshotResult"},
      "documentation":"<p>Imports a disk into an EBS snapshot.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-import-snapshot.html\">Importing a disk as a snapshot using VM Import/Export</a> in the <i>VM Import/Export User Guide</i>.</p>"
    },
    "ImportVolume":{
      "name":"ImportVolume",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ImportVolumeRequest"},
      "output":{"shape":"ImportVolumeResult"},
      "documentation":"<p>Creates an import volume task using metadata from the specified disk image.</p> <p>This API action supports only single-volume VMs. To import multi-volume VMs, use <a>ImportImage</a> instead. To import a disk to a snapshot, use <a>ImportSnapshot</a> instead.</p> <p>This API action is not supported by the Command Line Interface (CLI). For information about using the Amazon EC2 CLI, which is deprecated, see <a href=\"https://awsdocs.s3.amazonaws.com/EC2/ec2-clt.pdf#importing-your-volumes-into-amazon-ebs\">Importing Disks to Amazon EBS</a> in the <i>Amazon EC2 CLI Reference</i> PDF file.</p> <p>For information about the import manifest referenced by this API action, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/manifest.html\">VM Import Manifest</a>.</p>"
    },
    "ListImagesInRecycleBin":{
      "name":"ListImagesInRecycleBin",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ListImagesInRecycleBinRequest"},
      "output":{"shape":"ListImagesInRecycleBinResult"},
      "documentation":"<p>Lists one or more AMIs that are currently in the Recycle Bin. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/recycle-bin.html\">Recycle Bin</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "ListSnapshotsInRecycleBin":{
      "name":"ListSnapshotsInRecycleBin",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ListSnapshotsInRecycleBinRequest"},
      "output":{"shape":"ListSnapshotsInRecycleBinResult"},
      "documentation":"<p>Lists one or more snapshots that are currently in the Recycle Bin.</p>"
    },
    "ModifyAddressAttribute":{
      "name":"ModifyAddressAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyAddressAttributeRequest"},
      "output":{"shape":"ModifyAddressAttributeResult"},
      "documentation":"<p>Modifies an attribute of the specified Elastic IP address. For requirements, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html#Using_Elastic_Addressing_Reverse_DNS\">Using reverse DNS for email applications</a>.</p>"
    },
    "ModifyAvailabilityZoneGroup":{
      "name":"ModifyAvailabilityZoneGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyAvailabilityZoneGroupRequest"},
      "output":{"shape":"ModifyAvailabilityZoneGroupResult"},
      "documentation":"<p>Changes the opt-in status of the Local Zone and Wavelength Zone group for your account.</p> <p>Use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAvailabilityZones.html\"> DescribeAvailabilityZones</a> to view the value for <code>GroupName</code>.</p>"
    },
    "ModifyCapacityReservation":{
      "name":"ModifyCapacityReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyCapacityReservationRequest"},
      "output":{"shape":"ModifyCapacityReservationResult"},
      "documentation":"<p>Modifies a Capacity Reservation's capacity and the conditions under which it is to be released. You cannot change a Capacity Reservation's instance type, EBS optimization, instance store settings, platform, Availability Zone, or instance eligibility. If you need to modify any of these attributes, we recommend that you cancel the Capacity Reservation, and then create a new one with the required attributes.</p>"
    },
    "ModifyCapacityReservationFleet":{
      "name":"ModifyCapacityReservationFleet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyCapacityReservationFleetRequest"},
      "output":{"shape":"ModifyCapacityReservationFleetResult"},
      "documentation":"<p>Modifies a Capacity Reservation Fleet.</p> <p>When you modify the total target capacity of a Capacity Reservation Fleet, the Fleet automatically creates new Capacity Reservations, or modifies or cancels existing Capacity Reservations in the Fleet to meet the new total target capacity. When you modify the end date for the Fleet, the end dates for all of the individual Capacity Reservations in the Fleet are updated accordingly.</p>"
    },
    "ModifyClientVpnEndpoint":{
      "name":"ModifyClientVpnEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyClientVpnEndpointRequest"},
      "output":{"shape":"ModifyClientVpnEndpointResult"},
      "documentation":"<p>Modifies the specified Client VPN endpoint. Modifying the DNS server resets existing client connections.</p>"
    },
    "ModifyDefaultCreditSpecification":{
      "name":"ModifyDefaultCreditSpecification",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyDefaultCreditSpecificationRequest"},
      "output":{"shape":"ModifyDefaultCreditSpecificationResult"},
      "documentation":"<p>Modifies the default credit option for CPU usage of burstable performance instances. The default credit option is set at the account level per Amazon Web Services Region, and is specified per instance family. All new burstable performance instances in the account launch using the default credit option.</p> <p> <code>ModifyDefaultCreditSpecification</code> is an asynchronous operation, which works at an Amazon Web Services Region level and modifies the credit option for each Availability Zone. All zones in a Region are updated within five minutes. But if instances are launched during this operation, they might not get the new credit option until the zone is updated. To verify whether the update has occurred, you can call <code>GetDefaultCreditSpecification</code> and check <code>DefaultCreditSpecification</code> for updates.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "ModifyEbsDefaultKmsKeyId":{
      "name":"ModifyEbsDefaultKmsKeyId",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyEbsDefaultKmsKeyIdRequest"},
      "output":{"shape":"ModifyEbsDefaultKmsKeyIdResult"},
      "documentation":"<p>Changes the default KMS key for EBS encryption by default for your account in this Region.</p> <p>Amazon Web Services creates a unique Amazon Web Services managed KMS key in each Region for use with encryption by default. If you change the default KMS key to a symmetric customer managed KMS key, it is used instead of the Amazon Web Services managed KMS key. To reset the default KMS key to the Amazon Web Services managed KMS key for EBS, use <a>ResetEbsDefaultKmsKeyId</a>. Amazon EBS does not support asymmetric KMS keys.</p> <p>If you delete or disable the customer managed KMS key that you specified for use with encryption by default, your instances will fail to launch.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ModifyFleet":{
      "name":"ModifyFleet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyFleetRequest"},
      "output":{"shape":"ModifyFleetResult"},
      "documentation":"<p>Modifies the specified EC2 Fleet.</p> <p>You can only modify an EC2 Fleet request of type <code>maintain</code>.</p> <p>While the EC2 Fleet is being modified, it is in the <code>modifying</code> state.</p> <p>To scale up your EC2 Fleet, increase its target capacity. The EC2 Fleet launches the additional Spot Instances according to the allocation strategy for the EC2 Fleet request. If the allocation strategy is <code>lowest-price</code>, the EC2 Fleet launches instances using the Spot Instance pool with the lowest price. If the allocation strategy is <code>diversified</code>, the EC2 Fleet distributes the instances across the Spot Instance pools. If the allocation strategy is <code>capacity-optimized</code>, EC2 Fleet launches instances from Spot Instance pools with optimal capacity for the number of instances that are launching.</p> <p>To scale down your EC2 Fleet, decrease its target capacity. First, the EC2 Fleet cancels any open requests that exceed the new target capacity. You can request that the EC2 Fleet terminate Spot Instances until the size of the fleet no longer exceeds the new target capacity. If the allocation strategy is <code>lowest-price</code>, the EC2 Fleet terminates the instances with the highest price per unit. If the allocation strategy is <code>capacity-optimized</code>, the EC2 Fleet terminates the instances in the Spot Instance pools that have the least available Spot Instance capacity. If the allocation strategy is <code>diversified</code>, the EC2 Fleet terminates instances across the Spot Instance pools. Alternatively, you can request that the EC2 Fleet keep the fleet at its current size, but not replace any Spot Instances that are interrupted or that you terminate manually.</p> <p>If you are finished with your EC2 Fleet for now, but will use it again later, you can set the target capacity to 0.</p>"
    },
    "ModifyFpgaImageAttribute":{
      "name":"ModifyFpgaImageAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyFpgaImageAttributeRequest"},
      "output":{"shape":"ModifyFpgaImageAttributeResult"},
      "documentation":"<p>Modifies the specified attribute of the specified Amazon FPGA Image (AFI).</p>"
    },
    "ModifyHosts":{
      "name":"ModifyHosts",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyHostsRequest"},
      "output":{"shape":"ModifyHostsResult"},
      "documentation":"<p>Modify the auto-placement setting of a Dedicated Host. When auto-placement is enabled, any instances that you launch with a tenancy of <code>host</code> but without a specific host ID are placed onto any available Dedicated Host in your account that has auto-placement enabled. When auto-placement is disabled, you need to provide a host ID to have the instance launch onto a specific host. If no host ID is provided, the instance is launched onto a suitable host with auto-placement enabled.</p> <p>You can also use this API action to modify a Dedicated Host to support either multiple instance types in an instance family, or to support a specific instance type only.</p>"
    },
    "ModifyIdFormat":{
      "name":"ModifyIdFormat",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIdFormatRequest"},
      "documentation":"<p>Modifies the ID format for the specified resource on a per-Region basis. You can specify that resources should receive longer IDs (17-character IDs) when they are created.</p> <p>This request can only be used to modify longer ID settings for resource types that are within the opt-in period. Resources currently in their opt-in period include: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>.</p> <p>This setting applies to the IAM user who makes the request; it does not apply to the entire Amazon Web Services account. By default, an IAM user defaults to the same settings as the root user. If you're using this action as the root user, then these settings apply to the entire account, unless an IAM user explicitly overrides these settings for themselves. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/resource-ids.html\">Resource IDs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Resources created with longer IDs are visible to all IAM roles and users, regardless of these settings and provided that they have permission to use the relevant <code>Describe</code> command for the resource type.</p>"
    },
    "ModifyIdentityIdFormat":{
      "name":"ModifyIdentityIdFormat",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIdentityIdFormatRequest"},
      "documentation":"<p>Modifies the ID format of a resource for a specified IAM user, IAM role, or the root user for an account; or all IAM users, IAM roles, and the root user for an account. You can specify that resources should receive longer IDs (17-character IDs) when they are created. </p> <p>This request can only be used to modify longer ID settings for resource types that are within the opt-in period. Resources currently in their opt-in period include: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>. </p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/resource-ids.html\">Resource IDs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>. </p> <p>This setting applies to the principal specified in the request; it does not apply to the principal that makes the request. </p> <p>Resources created with longer IDs are visible to all IAM roles and users, regardless of these settings and provided that they have permission to use the relevant <code>Describe</code> command for the resource type.</p>"
    },
    "ModifyImageAttribute":{
      "name":"ModifyImageAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyImageAttributeRequest"},
      "documentation":"<p>Modifies the specified attribute of the specified AMI. You can specify only one attribute at a time. You can use the <code>Attribute</code> parameter to specify the attribute or one of the following parameters: <code>Description</code> or <code>LaunchPermission</code>.</p> <p>Images with an Amazon Web Services Marketplace product code cannot be made public.</p> <p>To enable the SriovNetSupport enhanced networking attribute of an image, enable SriovNetSupport on an instance and create an AMI from the instance.</p>"
    },
    "ModifyInstanceAttribute":{
      "name":"ModifyInstanceAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceAttributeRequest"},
      "documentation":"<p>Modifies the specified attribute of the specified instance. You can specify only one attribute at a time.</p> <p> <b>Note: </b>Using this action to change the security groups associated with an elastic network interface (ENI) attached to an instance in a VPC can result in an error if the instance has more than one ENI. To change the security groups associated with an ENI attached to an instance that has multiple ENIs, we recommend that you use the <a>ModifyNetworkInterfaceAttribute</a> action.</p> <p>To modify some attributes, the instance must be stopped. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_ChangingAttributesWhileInstanceStopped.html\">Modify a stopped instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "ModifyInstanceCapacityReservationAttributes":{
      "name":"ModifyInstanceCapacityReservationAttributes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceCapacityReservationAttributesRequest"},
      "output":{"shape":"ModifyInstanceCapacityReservationAttributesResult"},
      "documentation":"<p>Modifies the Capacity Reservation settings for a stopped instance. Use this action to configure an instance to target a specific Capacity Reservation, run in any <code>open</code> Capacity Reservation with matching attributes, or run On-Demand Instance capacity.</p>"
    },
    "ModifyInstanceCreditSpecification":{
      "name":"ModifyInstanceCreditSpecification",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceCreditSpecificationRequest"},
      "output":{"shape":"ModifyInstanceCreditSpecificationResult"},
      "documentation":"<p>Modifies the credit option for CPU usage on a running or stopped burstable performance instance. The credit options are <code>standard</code> and <code>unlimited</code>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "ModifyInstanceEventStartTime":{
      "name":"ModifyInstanceEventStartTime",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceEventStartTimeRequest"},
      "output":{"shape":"ModifyInstanceEventStartTimeResult"},
      "documentation":"<p>Modifies the start time for a scheduled Amazon EC2 instance event.</p>"
    },
    "ModifyInstanceEventWindow":{
      "name":"ModifyInstanceEventWindow",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceEventWindowRequest"},
      "output":{"shape":"ModifyInstanceEventWindowResult"},
      "documentation":"<p>Modifies the specified event window.</p> <p>You can define either a set of time ranges or a cron expression when modifying the event window, but not both.</p> <p>To modify the targets associated with the event window, use the <a>AssociateInstanceEventWindow</a> and <a>DisassociateInstanceEventWindow</a> API.</p> <p>If Amazon Web Services has already scheduled an event, modifying an event window won't change the time of the scheduled event.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/event-windows.html\">Define event windows for scheduled events</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "ModifyInstanceMaintenanceOptions":{
      "name":"ModifyInstanceMaintenanceOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceMaintenanceOptionsRequest"},
      "output":{"shape":"ModifyInstanceMaintenanceOptionsResult"},
      "documentation":"<p>Modifies the recovery behavior of your instance to disable simplified automatic recovery or set the recovery behavior to default. The default configuration will not enable simplified automatic recovery for an unsupported instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-recover.html#instance-configuration-recovery\">Simplified automatic recovery</a>.</p>"
    },
    "ModifyInstanceMetadataOptions":{
      "name":"ModifyInstanceMetadataOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstanceMetadataOptionsRequest"},
      "output":{"shape":"ModifyInstanceMetadataOptionsResult"},
      "documentation":"<p>Modify the instance metadata parameters on a running or stopped instance. When you modify the parameters on a stopped instance, they are applied when the instance is started. When you modify the parameters on a running instance, the API responds with a state of “pending”. After the parameter modifications are successfully applied to the instance, the state of the modifications changes from “pending” to “applied” in subsequent describe-instances API calls. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">Instance metadata and user data</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "ModifyInstancePlacement":{
      "name":"ModifyInstancePlacement",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyInstancePlacementRequest"},
      "output":{"shape":"ModifyInstancePlacementResult"},
      "documentation":"<p>Modifies the placement attributes for a specified instance. You can do the following:</p> <ul> <li> <p>Modify the affinity between an instance and a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-overview.html\">Dedicated Host</a>. When affinity is set to <code>host</code> and the instance is not associated with a specific Dedicated Host, the next time the instance is launched, it is automatically associated with the host on which it lands. If the instance is restarted or rebooted, this relationship persists.</p> </li> <li> <p>Change the Dedicated Host with which an instance is associated.</p> </li> <li> <p>Change the instance tenancy of an instance.</p> </li> <li> <p>Move an instance to or from a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/placement-groups.html\">placement group</a>.</p> </li> </ul> <p>At least one attribute for affinity, host ID, tenancy, or placement group name must be specified in the request. Affinity and tenancy can be modified in the same request.</p> <p>To modify the host ID, tenancy, placement group, or partition for an instance, the instance must be in the <code>stopped</code> state.</p>"
    },
    "ModifyIpam":{
      "name":"ModifyIpam",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIpamRequest"},
      "output":{"shape":"ModifyIpamResult"},
      "documentation":"<p>Modify the configurations of an IPAM. </p>"
    },
    "ModifyIpamPool":{
      "name":"ModifyIpamPool",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIpamPoolRequest"},
      "output":{"shape":"ModifyIpamPoolResult"},
      "documentation":"<p>Modify the configurations of an IPAM pool.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/mod-pool-ipam.html\">Modify a pool</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "ModifyIpamResourceCidr":{
      "name":"ModifyIpamResourceCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIpamResourceCidrRequest"},
      "output":{"shape":"ModifyIpamResourceCidrResult"},
      "documentation":"<p>Modify a resource CIDR. You can use this action to transfer resource CIDRs between scopes and ignore resource CIDRs that you do not want to manage. If set to false, the resource will not be tracked for overlap, it cannot be auto-imported into a pool, and it will be removed from any pool it has an allocation in.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/move-resource-ipam.html\">Move resource CIDRs between scopes</a> and <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/change-monitoring-state-ipam.html\">Change the monitoring state of resource CIDRs</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "ModifyIpamResourceDiscovery":{
      "name":"ModifyIpamResourceDiscovery",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIpamResourceDiscoveryRequest"},
      "output":{"shape":"ModifyIpamResourceDiscoveryResult"},
      "documentation":"<p>Modifies a resource discovery. A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "ModifyIpamScope":{
      "name":"ModifyIpamScope",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyIpamScopeRequest"},
      "output":{"shape":"ModifyIpamScopeResult"},
      "documentation":"<p>Modify an IPAM scope.</p>"
    },
    "ModifyLaunchTemplate":{
      "name":"ModifyLaunchTemplate",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyLaunchTemplateRequest"},
      "output":{"shape":"ModifyLaunchTemplateResult"},
      "documentation":"<p>Modifies a launch template. You can specify which version of the launch template to set as the default version. When launching an instance, the default version applies when a launch template version is not specified.</p>"
    },
    "ModifyLocalGatewayRoute":{
      "name":"ModifyLocalGatewayRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyLocalGatewayRouteRequest"},
      "output":{"shape":"ModifyLocalGatewayRouteResult"},
      "documentation":"<p>Modifies the specified local gateway route.</p>"
    },
    "ModifyManagedPrefixList":{
      "name":"ModifyManagedPrefixList",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyManagedPrefixListRequest"},
      "output":{"shape":"ModifyManagedPrefixListResult"},
      "documentation":"<p>Modifies the specified managed prefix list.</p> <p>Adding or removing entries in a prefix list creates a new version of the prefix list. Changing the name of the prefix list does not affect the version.</p> <p>If you specify a current version number that does not match the true current version number, the request fails.</p>"
    },
    "ModifyNetworkInterfaceAttribute":{
      "name":"ModifyNetworkInterfaceAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyNetworkInterfaceAttributeRequest"},
      "documentation":"<p>Modifies the specified network interface attribute. You can specify only one attribute at a time. You can use this action to attach and detach security groups from an existing EC2 instance.</p>"
    },
    "ModifyPrivateDnsNameOptions":{
      "name":"ModifyPrivateDnsNameOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyPrivateDnsNameOptionsRequest"},
      "output":{"shape":"ModifyPrivateDnsNameOptionsResult"},
      "documentation":"<p>Modifies the options for instance hostnames for the specified instance.</p>"
    },
    "ModifyReservedInstances":{
      "name":"ModifyReservedInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyReservedInstancesRequest"},
      "output":{"shape":"ModifyReservedInstancesResult"},
      "documentation":"<p>Modifies the configuration of your Reserved Instances, such as the Availability Zone, instance count, or instance type. The Reserved Instances to be modified must be identical, except for Availability Zone, network platform, and instance type.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-modifying.html\">Modifying Reserved Instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "ModifySecurityGroupRules":{
      "name":"ModifySecurityGroupRules",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifySecurityGroupRulesRequest"},
      "output":{"shape":"ModifySecurityGroupRulesResult"},
      "documentation":"<p>Modifies the rules of a security group.</p>"
    },
    "ModifySnapshotAttribute":{
      "name":"ModifySnapshotAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifySnapshotAttributeRequest"},
      "documentation":"<p>Adds or removes permission settings for the specified snapshot. You may add or remove specified Amazon Web Services account IDs from a snapshot's list of create volume permissions, but you cannot do both in a single operation. If you need to both add and remove account IDs for a snapshot, you must use multiple operations. You can make up to 500 modifications to a snapshot in a single operation.</p> <p>Encrypted snapshots and snapshots with Amazon Web Services Marketplace product codes cannot be made public. Snapshots encrypted with your default KMS key cannot be shared with other accounts.</p> <p>For more information about modifying snapshot permissions, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-modifying-snapshot-permissions.html\">Share a snapshot</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ModifySnapshotTier":{
      "name":"ModifySnapshotTier",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifySnapshotTierRequest"},
      "output":{"shape":"ModifySnapshotTierResult"},
      "documentation":"<p>Archives an Amazon EBS snapshot. When you archive a snapshot, it is converted to a full snapshot that includes all of the blocks of data that were written to the volume at the time the snapshot was created, and moved from the standard tier to the archive tier. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshot-archive.html\">Archive Amazon EBS snapshots</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ModifySpotFleetRequest":{
      "name":"ModifySpotFleetRequest",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifySpotFleetRequestRequest"},
      "output":{"shape":"ModifySpotFleetRequestResponse"},
      "documentation":"<p>Modifies the specified Spot Fleet request.</p> <p>You can only modify a Spot Fleet request of type <code>maintain</code>.</p> <p>While the Spot Fleet request is being modified, it is in the <code>modifying</code> state.</p> <p>To scale up your Spot Fleet, increase its target capacity. The Spot Fleet launches the additional Spot Instances according to the allocation strategy for the Spot Fleet request. If the allocation strategy is <code>lowestPrice</code>, the Spot Fleet launches instances using the Spot Instance pool with the lowest price. If the allocation strategy is <code>diversified</code>, the Spot Fleet distributes the instances across the Spot Instance pools. If the allocation strategy is <code>capacityOptimized</code>, Spot Fleet launches instances from Spot Instance pools with optimal capacity for the number of instances that are launching.</p> <p>To scale down your Spot Fleet, decrease its target capacity. First, the Spot Fleet cancels any open requests that exceed the new target capacity. You can request that the Spot Fleet terminate Spot Instances until the size of the fleet no longer exceeds the new target capacity. If the allocation strategy is <code>lowestPrice</code>, the Spot Fleet terminates the instances with the highest price per unit. If the allocation strategy is <code>capacityOptimized</code>, the Spot Fleet terminates the instances in the Spot Instance pools that have the least available Spot Instance capacity. If the allocation strategy is <code>diversified</code>, the Spot Fleet terminates instances across the Spot Instance pools. Alternatively, you can request that the Spot Fleet keep the fleet at its current size, but not replace any Spot Instances that are interrupted or that you terminate manually.</p> <p>If you are finished with your Spot Fleet for now, but will use it again later, you can set the target capacity to 0.</p>"
    },
    "ModifySubnetAttribute":{
      "name":"ModifySubnetAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifySubnetAttributeRequest"},
      "documentation":"<p>Modifies a subnet attribute. You can only modify one attribute at a time.</p> <p>Use this action to modify subnets on Amazon Web Services Outposts.</p> <ul> <li> <p>To modify a subnet on an Outpost rack, set both <code>MapCustomerOwnedIpOnLaunch</code> and <code>CustomerOwnedIpv4Pool</code>. These two parameters act as a single attribute.</p> </li> <li> <p>To modify a subnet on an Outpost server, set either <code>EnableLniAtDeviceIndex</code> or <code>DisableLniAtDeviceIndex</code>.</p> </li> </ul> <p>For more information about Amazon Web Services Outposts, see the following:</p> <ul> <li> <p> <a href=\"https://docs.aws.amazon.com/outposts/latest/userguide/how-servers-work.html\">Outpost servers</a> </p> </li> <li> <p> <a href=\"https://docs.aws.amazon.com/outposts/latest/userguide/how-racks-work.html\">Outpost racks</a> </p> </li> </ul>"
    },
    "ModifyTrafficMirrorFilterNetworkServices":{
      "name":"ModifyTrafficMirrorFilterNetworkServices",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyTrafficMirrorFilterNetworkServicesRequest"},
      "output":{"shape":"ModifyTrafficMirrorFilterNetworkServicesResult"},
      "documentation":"<p>Allows or restricts mirroring network services.</p> <p> By default, Amazon DNS network services are not eligible for Traffic Mirror. Use <code>AddNetworkServices</code> to add network services to a Traffic Mirror filter. When a network service is added to the Traffic Mirror filter, all traffic related to that network service will be mirrored. When you no longer want to mirror network services, use <code>RemoveNetworkServices</code> to remove the network services from the Traffic Mirror filter. </p>"
    },
    "ModifyTrafficMirrorFilterRule":{
      "name":"ModifyTrafficMirrorFilterRule",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyTrafficMirrorFilterRuleRequest"},
      "output":{"shape":"ModifyTrafficMirrorFilterRuleResult"},
      "documentation":"<p>Modifies the specified Traffic Mirror rule.</p> <p> <code>DestinationCidrBlock</code> and <code>SourceCidrBlock</code> must both be an IPv4 range or an IPv6 range.</p>"
    },
    "ModifyTrafficMirrorSession":{
      "name":"ModifyTrafficMirrorSession",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyTrafficMirrorSessionRequest"},
      "output":{"shape":"ModifyTrafficMirrorSessionResult"},
      "documentation":"<p>Modifies a Traffic Mirror session.</p>"
    },
    "ModifyTransitGateway":{
      "name":"ModifyTransitGateway",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyTransitGatewayRequest"},
      "output":{"shape":"ModifyTransitGatewayResult"},
      "documentation":"<p>Modifies the specified transit gateway. When you modify a transit gateway, the modified options are applied to new transit gateway attachments only. Your existing transit gateway attachments are not modified.</p>"
    },
    "ModifyTransitGatewayPrefixListReference":{
      "name":"ModifyTransitGatewayPrefixListReference",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyTransitGatewayPrefixListReferenceRequest"},
      "output":{"shape":"ModifyTransitGatewayPrefixListReferenceResult"},
      "documentation":"<p>Modifies a reference (route) to a prefix list in a specified transit gateway route table.</p>"
    },
    "ModifyTransitGatewayVpcAttachment":{
      "name":"ModifyTransitGatewayVpcAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyTransitGatewayVpcAttachmentRequest"},
      "output":{"shape":"ModifyTransitGatewayVpcAttachmentResult"},
      "documentation":"<p>Modifies the specified VPC attachment.</p>"
    },
    "ModifyVerifiedAccessEndpoint":{
      "name":"ModifyVerifiedAccessEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessEndpointRequest"},
      "output":{"shape":"ModifyVerifiedAccessEndpointResult"},
      "documentation":"<p>Modifies the configuration of an Amazon Web Services Verified Access endpoint.</p>"
    },
    "ModifyVerifiedAccessEndpointPolicy":{
      "name":"ModifyVerifiedAccessEndpointPolicy",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessEndpointPolicyRequest"},
      "output":{"shape":"ModifyVerifiedAccessEndpointPolicyResult"},
      "documentation":"<p>Modifies the specified Verified Access endpoint policy.</p>"
    },
    "ModifyVerifiedAccessGroup":{
      "name":"ModifyVerifiedAccessGroup",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessGroupRequest"},
      "output":{"shape":"ModifyVerifiedAccessGroupResult"},
      "documentation":"<p>Modifies the specified Verified Access group configuration.</p>"
    },
    "ModifyVerifiedAccessGroupPolicy":{
      "name":"ModifyVerifiedAccessGroupPolicy",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessGroupPolicyRequest"},
      "output":{"shape":"ModifyVerifiedAccessGroupPolicyResult"},
      "documentation":"<p>Modifies the specified Verified Access group policy.</p>"
    },
    "ModifyVerifiedAccessInstance":{
      "name":"ModifyVerifiedAccessInstance",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessInstanceRequest"},
      "output":{"shape":"ModifyVerifiedAccessInstanceResult"},
      "documentation":"<p>Modifies the configuration of the specified Verified Access instance.</p>"
    },
    "ModifyVerifiedAccessInstanceLoggingConfiguration":{
      "name":"ModifyVerifiedAccessInstanceLoggingConfiguration",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessInstanceLoggingConfigurationRequest"},
      "output":{"shape":"ModifyVerifiedAccessInstanceLoggingConfigurationResult"},
      "documentation":"<p>Modifies the logging configuration for the specified Amazon Web Services Verified Access instance.</p>"
    },
    "ModifyVerifiedAccessTrustProvider":{
      "name":"ModifyVerifiedAccessTrustProvider",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVerifiedAccessTrustProviderRequest"},
      "output":{"shape":"ModifyVerifiedAccessTrustProviderResult"},
      "documentation":"<p>Modifies the configuration of the specified Amazon Web Services Verified Access trust provider.</p>"
    },
    "ModifyVolume":{
      "name":"ModifyVolume",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVolumeRequest"},
      "output":{"shape":"ModifyVolumeResult"},
      "documentation":"<p>You can modify several parameters of an existing EBS volume, including volume size, volume type, and IOPS capacity. If your EBS volume is attached to a current-generation EC2 instance type, you might be able to apply these changes without stopping the instance or detaching the volume from it. For more information about modifying EBS volumes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-modify-volume.html\">Amazon EBS Elastic Volumes</a> (Linux instances) or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ebs-modify-volume.html\">Amazon EBS Elastic Volumes</a> (Windows instances).</p> <p>When you complete a resize operation on your volume, you need to extend the volume's file-system size to take advantage of the new storage capacity. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-expand-volume.html#recognize-expanded-volume-linux\">Extend a Linux file system</a> or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ebs-expand-volume.html#recognize-expanded-volume-windows\">Extend a Windows file system</a>.</p> <p> You can use CloudWatch Events to check the status of a modification to an EBS volume. For information about CloudWatch Events, see the <a href=\"https://docs.aws.amazon.com/AmazonCloudWatch/latest/events/\">Amazon CloudWatch Events User Guide</a>. You can also track the status of a modification using <a>DescribeVolumesModifications</a>. For information about tracking status changes using either method, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/monitoring-volume-modifications.html\">Monitor the progress of volume modifications</a>.</p> <p>With previous-generation instance types, resizing an EBS volume might require detaching and reattaching the volume or stopping and restarting the instance.</p> <p>After modifying a volume, you must wait at least six hours and ensure that the volume is in the <code>in-use</code> or <code>available</code> state before you can modify the same volume. This is sometimes referred to as a cooldown period.</p>"
    },
    "ModifyVolumeAttribute":{
      "name":"ModifyVolumeAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVolumeAttributeRequest"},
      "documentation":"<p>Modifies a volume attribute.</p> <p>By default, all I/O operations for the volume are suspended when the data on the volume is determined to be potentially inconsistent, to prevent undetectable, latent data corruption. The I/O access to the volume can be resumed by first enabling I/O access and then checking the data consistency on your volume.</p> <p>You can change the default behavior to resume I/O operations. We recommend that you change this only for boot volumes or for volumes that are stateless or disposable.</p>"
    },
    "ModifyVpcAttribute":{
      "name":"ModifyVpcAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcAttributeRequest"},
      "documentation":"<p>Modifies the specified attribute of the specified VPC.</p>"
    },
    "ModifyVpcEndpoint":{
      "name":"ModifyVpcEndpoint",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcEndpointRequest"},
      "output":{"shape":"ModifyVpcEndpointResult"},
      "documentation":"<p>Modifies attributes of a specified VPC endpoint. The attributes that you can modify depend on the type of VPC endpoint (interface, gateway, or Gateway Load Balancer). For more information, see the <a href=\"https://docs.aws.amazon.com/vpc/latest/privatelink/\">Amazon Web Services PrivateLink Guide</a>.</p>"
    },
    "ModifyVpcEndpointConnectionNotification":{
      "name":"ModifyVpcEndpointConnectionNotification",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcEndpointConnectionNotificationRequest"},
      "output":{"shape":"ModifyVpcEndpointConnectionNotificationResult"},
      "documentation":"<p>Modifies a connection notification for VPC endpoint or VPC endpoint service. You can change the SNS topic for the notification, or the events for which to be notified. </p>"
    },
    "ModifyVpcEndpointServiceConfiguration":{
      "name":"ModifyVpcEndpointServiceConfiguration",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcEndpointServiceConfigurationRequest"},
      "output":{"shape":"ModifyVpcEndpointServiceConfigurationResult"},
      "documentation":"<p>Modifies the attributes of your VPC endpoint service configuration. You can change the Network Load Balancers or Gateway Load Balancers for your service, and you can specify whether acceptance is required for requests to connect to your endpoint service through an interface VPC endpoint.</p> <p>If you set or modify the private DNS name, you must prove that you own the private DNS domain name.</p>"
    },
    "ModifyVpcEndpointServicePayerResponsibility":{
      "name":"ModifyVpcEndpointServicePayerResponsibility",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcEndpointServicePayerResponsibilityRequest"},
      "output":{"shape":"ModifyVpcEndpointServicePayerResponsibilityResult"},
      "documentation":"<p>Modifies the payer responsibility for your VPC endpoint service.</p>"
    },
    "ModifyVpcEndpointServicePermissions":{
      "name":"ModifyVpcEndpointServicePermissions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcEndpointServicePermissionsRequest"},
      "output":{"shape":"ModifyVpcEndpointServicePermissionsResult"},
      "documentation":"<p>Modifies the permissions for your VPC endpoint service. You can add or remove permissions for service consumers (Amazon Web Services accounts, users, and IAM roles) to connect to your endpoint service.</p> <p>If you grant permissions to all principals, the service is public. Any users who know the name of a public service can send a request to attach an endpoint. If the service does not require manual approval, attachments are automatically approved.</p>"
    },
    "ModifyVpcPeeringConnectionOptions":{
      "name":"ModifyVpcPeeringConnectionOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcPeeringConnectionOptionsRequest"},
      "output":{"shape":"ModifyVpcPeeringConnectionOptionsResult"},
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Modifies the VPC peering connection options on one side of a VPC peering connection. You can do the following:</p> <ul> <li> <p>Enable/disable communication over the peering connection between an EC2-Classic instance that's linked to your VPC (using ClassicLink) and instances in the peer VPC.</p> </li> <li> <p>Enable/disable communication over the peering connection between instances in your VPC and an EC2-Classic instance that's linked to the peer VPC.</p> </li> <li> <p>Enable/disable the ability to resolve public DNS hostnames to private IP addresses when queried from instances in the peer VPC.</p> </li> </ul> <p>If the peered VPCs are in the same Amazon Web Services account, you can enable DNS resolution for queries from the local VPC. This ensures that queries from the local VPC resolve to private IP addresses in the peer VPC. This option is not available if the peered VPCs are in different different Amazon Web Services accounts or different Regions. For peered VPCs in different Amazon Web Services accounts, each Amazon Web Services account owner must initiate a separate request to modify the peering connection options. For inter-region peering connections, you must use the Region for the requester VPC to modify the requester VPC peering options and the Region for the accepter VPC to modify the accepter VPC peering options. To verify which VPCs are the accepter and the requester for a VPC peering connection, use the <a>DescribeVpcPeeringConnections</a> command.</p>"
    },
    "ModifyVpcTenancy":{
      "name":"ModifyVpcTenancy",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpcTenancyRequest"},
      "output":{"shape":"ModifyVpcTenancyResult"},
      "documentation":"<p>Modifies the instance tenancy attribute of the specified VPC. You can change the instance tenancy attribute of a VPC to <code>default</code> only. You cannot change the instance tenancy attribute to <code>dedicated</code>.</p> <p>After you modify the tenancy of the VPC, any new instances that you launch into the VPC have a tenancy of <code>default</code>, unless you specify otherwise during launch. The tenancy of any existing instances in the VPC is not affected.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-instance.html\">Dedicated Instances</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ModifyVpnConnection":{
      "name":"ModifyVpnConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpnConnectionRequest"},
      "output":{"shape":"ModifyVpnConnectionResult"},
      "documentation":"<p>Modifies the customer gateway or the target gateway of an Amazon Web Services Site-to-Site VPN connection. To modify the target gateway, the following migration options are available:</p> <ul> <li> <p>An existing virtual private gateway to a new virtual private gateway</p> </li> <li> <p>An existing virtual private gateway to a transit gateway</p> </li> <li> <p>An existing transit gateway to a new transit gateway</p> </li> <li> <p>An existing transit gateway to a virtual private gateway</p> </li> </ul> <p>Before you perform the migration to the new gateway, you must configure the new gateway. Use <a>CreateVpnGateway</a> to create a virtual private gateway, or <a>CreateTransitGateway</a> to create a transit gateway.</p> <p>This step is required when you migrate from a virtual private gateway with static routes to a transit gateway. </p> <p>You must delete the static routes before you migrate to the new gateway.</p> <p>Keep a copy of the static route before you delete it. You will need to add back these routes to the transit gateway after the VPN connection migration is complete.</p> <p>After you migrate to the new gateway, you might need to modify your VPC route table. Use <a>CreateRoute</a> and <a>DeleteRoute</a> to make the changes described in <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/modify-vpn-target.html#step-update-routing\">Update VPC route tables</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p> <p>When the new gateway is a transit gateway, modify the transit gateway route table to allow traffic between the VPC and the Amazon Web Services Site-to-Site VPN connection. Use <a>CreateTransitGatewayRoute</a> to add the routes.</p> <p> If you deleted VPN static routes, you must add the static routes to the transit gateway route table.</p> <p>After you perform this operation, the VPN endpoint's IP addresses on the Amazon Web Services side and the tunnel options remain intact. Your Amazon Web Services Site-to-Site VPN connection will be temporarily unavailable for a brief period while we provision the new endpoints.</p>"
    },
    "ModifyVpnConnectionOptions":{
      "name":"ModifyVpnConnectionOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpnConnectionOptionsRequest"},
      "output":{"shape":"ModifyVpnConnectionOptionsResult"},
      "documentation":"<p>Modifies the connection options for your Site-to-Site VPN connection.</p> <p>When you modify the VPN connection options, the VPN endpoint IP addresses on the Amazon Web Services side do not change, and the tunnel options do not change. Your VPN connection will be temporarily unavailable for a brief period while the VPN connection is updated.</p>"
    },
    "ModifyVpnTunnelCertificate":{
      "name":"ModifyVpnTunnelCertificate",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpnTunnelCertificateRequest"},
      "output":{"shape":"ModifyVpnTunnelCertificateResult"},
      "documentation":"<p>Modifies the VPN tunnel endpoint certificate.</p>"
    },
    "ModifyVpnTunnelOptions":{
      "name":"ModifyVpnTunnelOptions",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ModifyVpnTunnelOptionsRequest"},
      "output":{"shape":"ModifyVpnTunnelOptionsResult"},
      "documentation":"<p>Modifies the options for a VPN tunnel in an Amazon Web Services Site-to-Site VPN connection. You can modify multiple options for a tunnel in a single request, but you can only modify one tunnel at a time. For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/VPNTunnels.html\">Site-to-Site VPN tunnel options for your Site-to-Site VPN connection</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "MonitorInstances":{
      "name":"MonitorInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"MonitorInstancesRequest"},
      "output":{"shape":"MonitorInstancesResult"},
      "documentation":"<p>Enables detailed monitoring for a running instance. Otherwise, basic monitoring is enabled. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-cloudwatch.html\">Monitor your instances using CloudWatch</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>To disable detailed monitoring, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_UnmonitorInstances.html\">UnmonitorInstances</a>.</p>"
    },
    "MoveAddressToVpc":{
      "name":"MoveAddressToVpc",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"MoveAddressToVpcRequest"},
      "output":{"shape":"MoveAddressToVpcResult"},
      "documentation":"<p>Moves an Elastic IP address from the EC2-Classic platform to the EC2-VPC platform. The Elastic IP address must be allocated to your account for more than 24 hours, and it must not be associated with an instance. After the Elastic IP address is moved, it is no longer available for use in the EC2-Classic platform, unless you move it back using the <a>RestoreAddressToClassic</a> request. You cannot move an Elastic IP address that was originally allocated for use in the EC2-VPC platform to the EC2-Classic platform.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "MoveByoipCidrToIpam":{
      "name":"MoveByoipCidrToIpam",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"MoveByoipCidrToIpamRequest"},
      "output":{"shape":"MoveByoipCidrToIpamResult"},
      "documentation":"<p>Move a BYOIPv4 CIDR to IPAM from a public IPv4 pool.</p> <p>If you already have a BYOIPv4 CIDR with Amazon Web Services, you can move the CIDR to IPAM from a public IPv4 pool. You cannot move an IPv6 CIDR to IPAM. If you are bringing a new IP address to Amazon Web Services for the first time, complete the steps in <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/tutorials-byoip-ipam.html\">Tutorial: BYOIP address CIDRs to IPAM</a>.</p>"
    },
    "ProvisionByoipCidr":{
      "name":"ProvisionByoipCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ProvisionByoipCidrRequest"},
      "output":{"shape":"ProvisionByoipCidrResult"},
      "documentation":"<p>Provisions an IPv4 or IPv6 address range for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and creates a corresponding address pool. After the address range is provisioned, it is ready to be advertised using <a>AdvertiseByoipCidr</a>.</p> <p>Amazon Web Services verifies that you own the address range and are authorized to advertise it. You must ensure that the address range is registered to you and that you created an RPKI ROA to authorize Amazon ASNs 16509 and 14618 to advertise the address range. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-byoip.html\">Bring your own IP addresses (BYOIP)</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Provisioning an address range is an asynchronous operation, so the call returns immediately, but the address range is not ready to use until its status changes from <code>pending-provision</code> to <code>provisioned</code>. To monitor the status of an address range, use <a>DescribeByoipCidrs</a>. To allocate an Elastic IP address from your IPv4 address pool, use <a>AllocateAddress</a> with either the specific address from the address pool or the ID of the address pool.</p>"
    },
    "ProvisionIpamPoolCidr":{
      "name":"ProvisionIpamPoolCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ProvisionIpamPoolCidrRequest"},
      "output":{"shape":"ProvisionIpamPoolCidrResult"},
      "documentation":"<p>Provision a CIDR to an IPAM pool. You can use this action to provision new CIDRs to a top-level pool or to transfer a CIDR from a top-level pool to a pool within it.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/prov-cidr-ipam.html\">Provision CIDRs to pools</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "ProvisionPublicIpv4PoolCidr":{
      "name":"ProvisionPublicIpv4PoolCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ProvisionPublicIpv4PoolCidrRequest"},
      "output":{"shape":"ProvisionPublicIpv4PoolCidrResult"},
      "documentation":"<p>Provision a CIDR to a public IPv4 pool.</p> <p>For more information about IPAM, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "PurchaseHostReservation":{
      "name":"PurchaseHostReservation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"PurchaseHostReservationRequest"},
      "output":{"shape":"PurchaseHostReservationResult"},
      "documentation":"<p>Purchase a reservation with configurations that match those of your Dedicated Host. You must have active Dedicated Hosts in your account before you purchase a reservation. This action results in the specified reservation being purchased and charged to your account.</p>"
    },
    "PurchaseReservedInstancesOffering":{
      "name":"PurchaseReservedInstancesOffering",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"PurchaseReservedInstancesOfferingRequest"},
      "output":{"shape":"PurchaseReservedInstancesOfferingResult"},
      "documentation":"<p>Purchases a Reserved Instance for use with your account. With Reserved Instances, you pay a lower hourly rate compared to On-Demand instance pricing.</p> <p>Use <a>DescribeReservedInstancesOfferings</a> to get a list of Reserved Instance offerings that match your specifications. After you've purchased a Reserved Instance, you can check for your new Reserved Instance with <a>DescribeReservedInstances</a>.</p> <p>To queue a purchase for a future date and time, specify a purchase time. If you do not specify a purchase time, the default is the current time.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/concepts-on-demand-reserved-instances.html\">Reserved Instances</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ri-market-general.html\">Reserved Instance Marketplace</a> in the <i>Amazon EC2 User Guide</i>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "PurchaseScheduledInstances":{
      "name":"PurchaseScheduledInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"PurchaseScheduledInstancesRequest"},
      "output":{"shape":"PurchaseScheduledInstancesResult"},
      "documentation":"<note> <p>You can no longer purchase Scheduled Instances.</p> </note> <p>Purchases the Scheduled Instances with the specified schedule.</p> <p>Scheduled Instances enable you to purchase Amazon EC2 compute capacity by the hour for a one-year term. Before you can purchase a Scheduled Instance, you must call <a>DescribeScheduledInstanceAvailability</a> to check for available schedules and obtain a purchase token. After you purchase a Scheduled Instance, you must call <a>RunScheduledInstances</a> during each scheduled time period.</p> <p>After you purchase a Scheduled Instance, you can't cancel, modify, or resell your purchase.</p>"
    },
    "RebootInstances":{
      "name":"RebootInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RebootInstancesRequest"},
      "documentation":"<p>Requests a reboot of the specified instances. This operation is asynchronous; it only queues a request to reboot the specified instances. The operation succeeds if the instances are valid and belong to you. Requests to reboot terminated instances are ignored.</p> <p>If an instance does not cleanly shut down within a few minutes, Amazon EC2 performs a hard reboot.</p> <p>For more information about troubleshooting, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-console.html\">Troubleshoot an unreachable instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "RegisterImage":{
      "name":"RegisterImage",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RegisterImageRequest"},
      "output":{"shape":"RegisterImageResult"},
      "documentation":"<p>Registers an AMI. When you're creating an AMI, this is the final step you must complete before you can launch an instance from the AMI. For more information about creating AMIs, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/creating-an-ami.html\">Create your own AMI</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <note> <p>For Amazon EBS-backed instances, <a>CreateImage</a> creates and registers the AMI in a single request, so you don't have to register the AMI yourself. We recommend that you always use <a>CreateImage</a> unless you have a specific reason to use RegisterImage.</p> </note> <p>If needed, you can deregister an AMI at any time. Any modifications you make to an AMI backed by an instance store volume invalidates its registration. If you make changes to an image, deregister the previous image and register the new image.</p> <p> <b>Register a snapshot of a root device volume</b> </p> <p>You can use <code>RegisterImage</code> to create an Amazon EBS-backed Linux AMI from a snapshot of a root device volume. You specify the snapshot using a block device mapping. You can't set the encryption state of the volume using the block device mapping. If the snapshot is encrypted, or encryption by default is enabled, the root volume of an instance launched from the AMI is encrypted.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/creating-an-ami-ebs.html#creating-launching-ami-from-snapshot\">Create a Linux AMI from a snapshot</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/AMIEncryption.html\">Use encryption with Amazon EBS-backed AMIs</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p> <b>Amazon Web Services Marketplace product codes</b> </p> <p>If any snapshots have Amazon Web Services Marketplace product codes, they are copied to the new AMI.</p> <p>Windows and some Linux distributions, such as Red Hat Enterprise Linux (RHEL) and SUSE Linux Enterprise Server (SLES), use the Amazon EC2 billing product code associated with an AMI to verify the subscription status for package updates. To create a new AMI for operating systems that require a billing product code, instead of registering the AMI, do the following to preserve the billing product code association:</p> <ol> <li> <p>Launch an instance from an existing AMI with that billing product code.</p> </li> <li> <p>Customize the instance.</p> </li> <li> <p>Create an AMI from the instance using <a>CreateImage</a>.</p> </li> </ol> <p>If you purchase a Reserved Instance to apply to an On-Demand Instance that was launched from an AMI with a billing product code, make sure that the Reserved Instance has the matching billing product code. If you purchase a Reserved Instance without the matching billing product code, the Reserved Instance will not be applied to the On-Demand Instance. For information about how to obtain the platform details and billing information of an AMI, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-billing-info.html\">Understand AMI billing information</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "RegisterInstanceEventNotificationAttributes":{
      "name":"RegisterInstanceEventNotificationAttributes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RegisterInstanceEventNotificationAttributesRequest"},
      "output":{"shape":"RegisterInstanceEventNotificationAttributesResult"},
      "documentation":"<p>Registers a set of tag keys to include in scheduled event notifications for your resources. </p> <p>To remove tags, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DeregisterInstanceEventNotificationAttributes.html\">DeregisterInstanceEventNotificationAttributes</a>.</p>"
    },
    "RegisterTransitGatewayMulticastGroupMembers":{
      "name":"RegisterTransitGatewayMulticastGroupMembers",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RegisterTransitGatewayMulticastGroupMembersRequest"},
      "output":{"shape":"RegisterTransitGatewayMulticastGroupMembersResult"},
      "documentation":"<p>Registers members (network interfaces) with the transit gateway multicast group. A member is a network interface associated with a supported EC2 instance that receives multicast traffic. For information about supported instances, see <a href=\"https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-limits.html#multicast-limits\">Multicast Consideration</a> in <i>Amazon VPC Transit Gateways</i>.</p> <p>After you add the members, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayMulticastGroups.html\">SearchTransitGatewayMulticastGroups</a> to verify that the members were added to the transit gateway multicast group.</p>"
    },
    "RegisterTransitGatewayMulticastGroupSources":{
      "name":"RegisterTransitGatewayMulticastGroupSources",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RegisterTransitGatewayMulticastGroupSourcesRequest"},
      "output":{"shape":"RegisterTransitGatewayMulticastGroupSourcesResult"},
      "documentation":"<p>Registers sources (network interfaces) with the specified transit gateway multicast group.</p> <p>A multicast source is a network interface attached to a supported instance that sends multicast traffic. For information about supported instances, see <a href=\"https://docs.aws.amazon.com/vpc/latest/tgw/transit-gateway-limits.html#multicast-limits\">Multicast Considerations</a> in <i>Amazon VPC Transit Gateways</i>.</p> <p>After you add the source, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SearchTransitGatewayMulticastGroups.html\">SearchTransitGatewayMulticastGroups</a> to verify that the source was added to the multicast group.</p>"
    },
    "RejectTransitGatewayMulticastDomainAssociations":{
      "name":"RejectTransitGatewayMulticastDomainAssociations",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RejectTransitGatewayMulticastDomainAssociationsRequest"},
      "output":{"shape":"RejectTransitGatewayMulticastDomainAssociationsResult"},
      "documentation":"<p>Rejects a request to associate cross-account subnets with a transit gateway multicast domain.</p>"
    },
    "RejectTransitGatewayPeeringAttachment":{
      "name":"RejectTransitGatewayPeeringAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RejectTransitGatewayPeeringAttachmentRequest"},
      "output":{"shape":"RejectTransitGatewayPeeringAttachmentResult"},
      "documentation":"<p>Rejects a transit gateway peering attachment request.</p>"
    },
    "RejectTransitGatewayVpcAttachment":{
      "name":"RejectTransitGatewayVpcAttachment",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RejectTransitGatewayVpcAttachmentRequest"},
      "output":{"shape":"RejectTransitGatewayVpcAttachmentResult"},
      "documentation":"<p>Rejects a request to attach a VPC to a transit gateway.</p> <p>The VPC attachment must be in the <code>pendingAcceptance</code> state. Use <a>DescribeTransitGatewayVpcAttachments</a> to view your pending VPC attachment requests. Use <a>AcceptTransitGatewayVpcAttachment</a> to accept a VPC attachment request.</p>"
    },
    "RejectVpcEndpointConnections":{
      "name":"RejectVpcEndpointConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RejectVpcEndpointConnectionsRequest"},
      "output":{"shape":"RejectVpcEndpointConnectionsResult"},
      "documentation":"<p>Rejects VPC endpoint connection requests to your VPC endpoint service.</p>"
    },
    "RejectVpcPeeringConnection":{
      "name":"RejectVpcPeeringConnection",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RejectVpcPeeringConnectionRequest"},
      "output":{"shape":"RejectVpcPeeringConnectionResult"},
      "documentation":"<p>Rejects a VPC peering connection request. The VPC peering connection must be in the <code>pending-acceptance</code> state. Use the <a>DescribeVpcPeeringConnections</a> request to view your outstanding VPC peering connection requests. To delete an active VPC peering connection, or to delete a VPC peering connection request that you initiated, use <a>DeleteVpcPeeringConnection</a>.</p>"
    },
    "ReleaseAddress":{
      "name":"ReleaseAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReleaseAddressRequest"},
      "documentation":"<p>Releases the specified Elastic IP address.</p> <p>[EC2-Classic, default VPC] Releasing an Elastic IP address automatically disassociates it from any instance that it's associated with. To disassociate an Elastic IP address without releasing it, use <a>DisassociateAddress</a>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>[Nondefault VPC] You must use <a>DisassociateAddress</a> to disassociate the Elastic IP address before you can release it. Otherwise, Amazon EC2 returns an error (<code>InvalidIPAddress.InUse</code>).</p> <p>After releasing an Elastic IP address, it is released to the IP address pool. Be sure to update your DNS records and any servers or devices that communicate with the address. If you attempt to release an Elastic IP address that you already released, you'll get an <code>AuthFailure</code> error if the address is already allocated to another Amazon Web Services account.</p> <p>[EC2-VPC] After you release an Elastic IP address for use in a VPC, you might be able to recover it. For more information, see <a>AllocateAddress</a>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html\">Elastic IP Addresses</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ReleaseHosts":{
      "name":"ReleaseHosts",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReleaseHostsRequest"},
      "output":{"shape":"ReleaseHostsResult"},
      "documentation":"<p>When you no longer want to use an On-Demand Dedicated Host it can be released. On-Demand billing is stopped and the host goes into <code>released</code> state. The host ID of Dedicated Hosts that have been released can no longer be specified in another request, for example, to modify the host. You must stop or terminate all instances on a host before it can be released.</p> <p>When Dedicated Hosts are released, it may take some time for them to stop counting toward your limit and you may receive capacity errors when trying to allocate new Dedicated Hosts. Wait a few minutes and then try again.</p> <p>Released hosts still appear in a <a>DescribeHosts</a> response.</p>"
    },
    "ReleaseIpamPoolAllocation":{
      "name":"ReleaseIpamPoolAllocation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReleaseIpamPoolAllocationRequest"},
      "output":{"shape":"ReleaseIpamPoolAllocationResult"},
      "documentation":"<p>Release an allocation within an IPAM pool. You can only use this action to release manual allocations. To remove an allocation for a resource without deleting the resource, set its monitored state to false using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyIpamResourceCidr.html\">ModifyIpamResourceCidr</a>. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/release-pool-alloc-ipam.html\">Release an allocation</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "ReplaceIamInstanceProfileAssociation":{
      "name":"ReplaceIamInstanceProfileAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReplaceIamInstanceProfileAssociationRequest"},
      "output":{"shape":"ReplaceIamInstanceProfileAssociationResult"},
      "documentation":"<p>Replaces an IAM instance profile for the specified running instance. You can use this action to change the IAM instance profile that's associated with an instance without having to disassociate the existing IAM instance profile first.</p> <p>Use <a>DescribeIamInstanceProfileAssociations</a> to get the association ID.</p>"
    },
    "ReplaceNetworkAclAssociation":{
      "name":"ReplaceNetworkAclAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReplaceNetworkAclAssociationRequest"},
      "output":{"shape":"ReplaceNetworkAclAssociationResult"},
      "documentation":"<p>Changes which network ACL a subnet is associated with. By default when you create a subnet, it's automatically associated with the default network ACL. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_ACLs.html\">Network ACLs</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>This is an idempotent operation.</p>"
    },
    "ReplaceNetworkAclEntry":{
      "name":"ReplaceNetworkAclEntry",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReplaceNetworkAclEntryRequest"},
      "documentation":"<p>Replaces an entry (rule) in a network ACL. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_ACLs.html\">Network ACLs</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "ReplaceRoute":{
      "name":"ReplaceRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReplaceRouteRequest"},
      "documentation":"<p>Replaces an existing route within a route table in a VPC.</p> <p>You must specify either a destination CIDR block or a prefix list ID. You must also specify exactly one of the resources from the parameter list, or reset the local route to its default target.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "ReplaceRouteTableAssociation":{
      "name":"ReplaceRouteTableAssociation",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReplaceRouteTableAssociationRequest"},
      "output":{"shape":"ReplaceRouteTableAssociationResult"},
      "documentation":"<p>Changes the route table associated with a given subnet, internet gateway, or virtual private gateway in a VPC. After the operation completes, the subnet or gateway uses the routes in the new route table. For more information about route tables, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/VPC_Route_Tables.html\">Route tables</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>You can also use this operation to change which table is the main route table in the VPC. Specify the main route table's association ID and the route table ID of the new main route table.</p>"
    },
    "ReplaceTransitGatewayRoute":{
      "name":"ReplaceTransitGatewayRoute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReplaceTransitGatewayRouteRequest"},
      "output":{"shape":"ReplaceTransitGatewayRouteResult"},
      "documentation":"<p>Replaces the specified route in the specified transit gateway route table.</p>"
    },
    "ReportInstanceStatus":{
      "name":"ReportInstanceStatus",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ReportInstanceStatusRequest"},
      "documentation":"<p>Submits feedback about the status of an instance. The instance must be in the <code>running</code> state. If your experience with the instance differs from the instance status returned by <a>DescribeInstanceStatus</a>, use <a>ReportInstanceStatus</a> to report your experience with the instance. Amazon EC2 collects this information to improve the accuracy of status checks.</p> <p>Use of this action does not change the value returned by <a>DescribeInstanceStatus</a>.</p>"
    },
    "RequestSpotFleet":{
      "name":"RequestSpotFleet",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RequestSpotFleetRequest"},
      "output":{"shape":"RequestSpotFleetResponse"},
      "documentation":"<p>Creates a Spot Fleet request.</p> <p>The Spot Fleet request specifies the total target capacity and the On-Demand target capacity. Amazon EC2 calculates the difference between the total capacity and On-Demand capacity, and launches the difference as Spot capacity.</p> <p>You can submit a single request that includes multiple launch specifications that vary by instance type, AMI, Availability Zone, or subnet.</p> <p>By default, the Spot Fleet requests Spot Instances in the Spot Instance pool where the price per unit is the lowest. Each launch specification can include its own instance weighting that reflects the value of the instance type to your application workload.</p> <p>Alternatively, you can specify that the Spot Fleet distribute the target capacity across the Spot pools included in its launch specifications. By ensuring that the Spot Instances in your Spot Fleet are in different Spot pools, you can improve the availability of your fleet.</p> <p>You can specify tags for the Spot Fleet request and instances launched by the fleet. You cannot tag other resource types in a Spot Fleet request because only the <code>spot-fleet-request</code> and <code>instance</code> resource types are supported.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-requests.html\">Spot Fleet requests</a> in the <i>Amazon EC2 User Guide</i>.</p> <important> <p>We strongly discourage using the RequestSpotFleet API because it is a legacy API with no planned investment. For options for requesting Spot Instances, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-best-practices.html#which-spot-request-method-to-use\">Which is the best Spot request method to use?</a> in the <i>Amazon EC2 User Guide</i>.</p> </important>"
    },
    "RequestSpotInstances":{
      "name":"RequestSpotInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RequestSpotInstancesRequest"},
      "output":{"shape":"RequestSpotInstancesResult"},
      "documentation":"<p>Creates a Spot Instance request.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-requests.html\">Spot Instance requests</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p> <important> <p>We strongly discourage using the RequestSpotInstances API because it is a legacy API with no planned investment. For options for requesting Spot Instances, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-best-practices.html#which-spot-request-method-to-use\">Which is the best Spot request method to use?</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p> </important> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p> </note>"
    },
    "ResetAddressAttribute":{
      "name":"ResetAddressAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetAddressAttributeRequest"},
      "output":{"shape":"ResetAddressAttributeResult"},
      "documentation":"<p>Resets the attribute of the specified IP address. For requirements, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/elastic-ip-addresses-eip.html#Using_Elastic_Addressing_Reverse_DNS\">Using reverse DNS for email applications</a>.</p>"
    },
    "ResetEbsDefaultKmsKeyId":{
      "name":"ResetEbsDefaultKmsKeyId",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetEbsDefaultKmsKeyIdRequest"},
      "output":{"shape":"ResetEbsDefaultKmsKeyIdResult"},
      "documentation":"<p>Resets the default KMS key for EBS encryption for your account in this Region to the Amazon Web Services managed KMS key for EBS.</p> <p>After resetting the default KMS key to the Amazon Web Services managed KMS key, you can continue to encrypt by a customer managed KMS key by specifying it when you create the volume. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "ResetFpgaImageAttribute":{
      "name":"ResetFpgaImageAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetFpgaImageAttributeRequest"},
      "output":{"shape":"ResetFpgaImageAttributeResult"},
      "documentation":"<p>Resets the specified attribute of the specified Amazon FPGA Image (AFI) to its default value. You can only reset the load permission attribute.</p>"
    },
    "ResetImageAttribute":{
      "name":"ResetImageAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetImageAttributeRequest"},
      "documentation":"<p>Resets an attribute of an AMI to its default value.</p>"
    },
    "ResetInstanceAttribute":{
      "name":"ResetInstanceAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetInstanceAttributeRequest"},
      "documentation":"<p>Resets an attribute of an instance to its default value. To reset the <code>kernel</code> or <code>ramdisk</code>, the instance must be in a stopped state. To reset the <code>sourceDestCheck</code>, the instance can be either running or stopped.</p> <p>The <code>sourceDestCheck</code> attribute controls whether source/destination checking is enabled. The default value is <code>true</code>, which means checking is enabled. This value must be <code>false</code> for a NAT instance to perform NAT. For more information, see <a href=\"https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_NAT_Instance.html\">NAT Instances</a> in the <i>Amazon VPC User Guide</i>.</p>"
    },
    "ResetNetworkInterfaceAttribute":{
      "name":"ResetNetworkInterfaceAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetNetworkInterfaceAttributeRequest"},
      "documentation":"<p>Resets a network interface attribute. You can specify only one attribute at a time.</p>"
    },
    "ResetSnapshotAttribute":{
      "name":"ResetSnapshotAttribute",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"ResetSnapshotAttributeRequest"},
      "documentation":"<p>Resets permission settings for the specified snapshot.</p> <p>For more information about modifying snapshot permissions, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-modifying-snapshot-permissions.html\">Share a snapshot</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "RestoreAddressToClassic":{
      "name":"RestoreAddressToClassic",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RestoreAddressToClassicRequest"},
      "output":{"shape":"RestoreAddressToClassicResult"},
      "documentation":"<p>Restores an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platform. You cannot move an Elastic IP address that was originally allocated for use in EC2-VPC. The Elastic IP address must not be associated with an instance or network interface.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "RestoreImageFromRecycleBin":{
      "name":"RestoreImageFromRecycleBin",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RestoreImageFromRecycleBinRequest"},
      "output":{"shape":"RestoreImageFromRecycleBinResult"},
      "documentation":"<p>Restores an AMI from the Recycle Bin. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/recycle-bin.html\">Recycle Bin</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "RestoreManagedPrefixListVersion":{
      "name":"RestoreManagedPrefixListVersion",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RestoreManagedPrefixListVersionRequest"},
      "output":{"shape":"RestoreManagedPrefixListVersionResult"},
      "documentation":"<p>Restores the entries from a previous version of a managed prefix list to a new version of the prefix list.</p>"
    },
    "RestoreSnapshotFromRecycleBin":{
      "name":"RestoreSnapshotFromRecycleBin",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RestoreSnapshotFromRecycleBinRequest"},
      "output":{"shape":"RestoreSnapshotFromRecycleBinResult"},
      "documentation":"<p>Restores a snapshot from the Recycle Bin. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/recycle-bin-working-with-snaps.html#recycle-bin-restore-snaps\">Restore snapshots from the Recycle Bin</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "RestoreSnapshotTier":{
      "name":"RestoreSnapshotTier",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RestoreSnapshotTierRequest"},
      "output":{"shape":"RestoreSnapshotTierResult"},
      "documentation":"<p>Restores an archived Amazon EBS snapshot for use temporarily or permanently, or modifies the restore period or restore type for a snapshot that was previously temporarily restored.</p> <p>For more information see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/working-with-snapshot-archiving.html#restore-archived-snapshot\"> Restore an archived snapshot</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/working-with-snapshot-archiving.html#modify-temp-restore-period\"> modify the restore period or restore type for a temporarily restored snapshot</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "RevokeClientVpnIngress":{
      "name":"RevokeClientVpnIngress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RevokeClientVpnIngressRequest"},
      "output":{"shape":"RevokeClientVpnIngressResult"},
      "documentation":"<p>Removes an ingress authorization rule from a Client VPN endpoint. </p>"
    },
    "RevokeSecurityGroupEgress":{
      "name":"RevokeSecurityGroupEgress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RevokeSecurityGroupEgressRequest"},
      "output":{"shape":"RevokeSecurityGroupEgressResult"},
      "documentation":"<p>[VPC only] Removes the specified outbound (egress) rules from a security group for EC2-VPC. This action does not apply to security groups for use in EC2-Classic.</p> <p>You can specify rules using either rule IDs or security group rule properties. If you use rule properties, the values that you specify (for example, ports) must match the existing rule's values exactly. Each rule has a protocol, from and to ports, and destination (CIDR range, security group, or prefix list). For the TCP and UDP protocols, you must also specify the destination port or range of ports. For the ICMP protocol, you must also specify the ICMP type and code. If the security group rule has a description, you do not need to specify the description to revoke the rule.</p> <p>[Default VPC] If the values you specify do not match the existing rule's values, no error is returned, and the output describes the security group rules that were not revoked.</p> <p>Amazon Web Services recommends that you describe the security group to verify that the rules were removed.</p> <p>Rule changes are propagated to instances within the security group as quickly as possible. However, a small delay might occur.</p>"
    },
    "RevokeSecurityGroupIngress":{
      "name":"RevokeSecurityGroupIngress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RevokeSecurityGroupIngressRequest"},
      "output":{"shape":"RevokeSecurityGroupIngressResult"},
      "documentation":"<p>Removes the specified inbound (ingress) rules from a security group.</p> <p>You can specify rules using either rule IDs or security group rule properties. If you use rule properties, the values that you specify (for example, ports) must match the existing rule's values exactly. Each rule has a protocol, from and to ports, and source (CIDR range, security group, or prefix list). For the TCP and UDP protocols, you must also specify the destination port or range of ports. For the ICMP protocol, you must also specify the ICMP type and code. If the security group rule has a description, you do not need to specify the description to revoke the rule.</p> <p>[EC2-Classic, default VPC] If the values you specify do not match the existing rule's values, no error is returned, and the output describes the security group rules that were not revoked.</p> <p>Amazon Web Services recommends that you describe the security group to verify that the rules were removed.</p> <p>Rule changes are propagated to instances within the security group as quickly as possible. However, a small delay might occur.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "RunInstances":{
      "name":"RunInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RunInstancesRequest"},
      "output":{"shape":"Reservation"},
      "documentation":"<p>Launches the specified number of instances using an AMI for which you have permissions.</p> <p>You can specify a number of options, or leave the default options. The following rules apply:</p> <ul> <li> <p>[EC2-VPC] If you don't specify a subnet ID, we choose a default subnet from your default VPC for you. If you don't have a default VPC, you must specify a subnet ID in the request.</p> </li> <li> <p>[EC2-Classic] If don't specify an Availability Zone, we choose one for you.</p> </li> <li> <p>Some instance types must be launched into a VPC. If you do not have a default VPC, or if you do not specify a subnet ID, the request fails. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-vpc.html#vpc-only-instance-types\">Instance types available only in a VPC</a>.</p> </li> <li> <p>[EC2-VPC] All instances have a network interface with a primary private IPv4 address. If you don't specify this address, we choose one from the IPv4 range of your subnet.</p> </li> <li> <p>Not all instance types support IPv6 addresses. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a>.</p> </li> <li> <p>If you don't specify a security group ID, we use the default security group. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-network-security.html\">Security groups</a>.</p> </li> <li> <p>If any of the AMIs have a product code attached for which the user has not subscribed, the request fails.</p> </li> </ul> <p>You can create a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html\">launch template</a>, which is a resource that contains the parameters to launch an instance. When you launch an instance using <a>RunInstances</a>, you can specify the launch template instead of specifying the launch parameters.</p> <p>To ensure faster instance launches, break up large requests into smaller batches. For example, create five separate launch requests for 100 instances each instead of one launch request for 500 instances.</p> <p>An instance is ready for you to use when it's in the <code>running</code> state. You can check the state of your instance using <a>DescribeInstances</a>. You can tag instances and EBS volumes during launch, after launch, or both. For more information, see <a>CreateTags</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html\">Tagging your Amazon EC2 resources</a>.</p> <p>Linux instances have access to the public key of the key pair at boot. You can use this key to provide secure access to the instance. Amazon EC2 public images use this feature to provide secure access without passwords. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-key-pairs.html\">Key pairs</a>.</p> <p>For troubleshooting, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_InstanceStraightToTerminated.html\">What to do if an instance immediately terminates</a>, and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/TroubleshootingInstancesConnecting.html\">Troubleshooting connecting to your instance</a>.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon EC2 User Guide</i>.</p> </note>"
    },
    "RunScheduledInstances":{
      "name":"RunScheduledInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"RunScheduledInstancesRequest"},
      "output":{"shape":"RunScheduledInstancesResult"},
      "documentation":"<p>Launches the specified Scheduled Instances.</p> <p>Before you can launch a Scheduled Instance, you must purchase it and obtain an identifier using <a>PurchaseScheduledInstances</a>.</p> <p>You must launch a Scheduled Instance during its scheduled time period. You can't stop or reboot a Scheduled Instance, but you can terminate it as needed. If you terminate a Scheduled Instance before the current scheduled time period ends, you can launch it again after a few minutes. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-scheduled-instances.html\">Scheduled Instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "SearchLocalGatewayRoutes":{
      "name":"SearchLocalGatewayRoutes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"SearchLocalGatewayRoutesRequest"},
      "output":{"shape":"SearchLocalGatewayRoutesResult"},
      "documentation":"<p>Searches for routes in the specified local gateway route table.</p>"
    },
    "SearchTransitGatewayMulticastGroups":{
      "name":"SearchTransitGatewayMulticastGroups",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"SearchTransitGatewayMulticastGroupsRequest"},
      "output":{"shape":"SearchTransitGatewayMulticastGroupsResult"},
      "documentation":"<p>Searches one or more transit gateway multicast groups and returns the group membership information.</p>"
    },
    "SearchTransitGatewayRoutes":{
      "name":"SearchTransitGatewayRoutes",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"SearchTransitGatewayRoutesRequest"},
      "output":{"shape":"SearchTransitGatewayRoutesResult"},
      "documentation":"<p>Searches for routes in the specified transit gateway route table.</p>"
    },
    "SendDiagnosticInterrupt":{
      "name":"SendDiagnosticInterrupt",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"SendDiagnosticInterruptRequest"},
      "documentation":"<p>Sends a diagnostic interrupt to the specified Amazon EC2 instance to trigger a <i>kernel panic</i> (on Linux instances), or a <i>blue screen</i>/<i>stop error</i> (on Windows instances). For instances based on Intel and AMD processors, the interrupt is received as a <i>non-maskable interrupt</i> (NMI).</p> <p>In general, the operating system crashes and reboots when a kernel panic or stop error is triggered. The operating system can also be configured to perform diagnostic tasks, such as generating a memory dump file, loading a secondary kernel, or obtaining a call trace.</p> <p>Before sending a diagnostic interrupt to your instance, ensure that its operating system is configured to perform the required diagnostic tasks.</p> <p>For more information about configuring your operating system to generate a crash dump when a kernel panic or stop error occurs, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/diagnostic-interrupt.html\">Send a diagnostic interrupt (for advanced users)</a> (Linux instances) or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/diagnostic-interrupt.html\">Send a diagnostic interrupt (for advanced users)</a> (Windows instances).</p>"
    },
    "StartInstances":{
      "name":"StartInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"StartInstancesRequest"},
      "output":{"shape":"StartInstancesResult"},
      "documentation":"<p>Starts an Amazon EBS-backed instance that you've previously stopped.</p> <p>Instances that use Amazon EBS volumes as their root devices can be quickly stopped and started. When an instance is stopped, the compute resources are released and you are not billed for instance usage. However, your root partition Amazon EBS volume remains and continues to persist your data, and you are charged for Amazon EBS volume usage. You can restart your instance at any time. Every time you start your instance, Amazon EC2 charges a one-minute minimum for instance usage, and thereafter charges per second for instance usage.</p> <p>Before stopping an instance, make sure it is in a state from which it can be restarted. Stopping an instance does not preserve data stored in RAM.</p> <p>Performing this operation on an instance that uses an instance store as its root device returns an error.</p> <p>If you attempt to start a T3 instance with <code>host</code> tenancy and the <code>unlimted</code> CPU credit option, the request fails. The <code>unlimited</code> CPU credit option is not supported on Dedicated Hosts. Before you start the instance, either change its CPU credit option to <code>standard</code>, or change its tenancy to <code>default</code> or <code>dedicated</code>.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Stop_Start.html\">Stop and start your instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "StartNetworkInsightsAccessScopeAnalysis":{
      "name":"StartNetworkInsightsAccessScopeAnalysis",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"StartNetworkInsightsAccessScopeAnalysisRequest"},
      "output":{"shape":"StartNetworkInsightsAccessScopeAnalysisResult"},
      "documentation":"<p>Starts analyzing the specified Network Access Scope.</p>"
    },
    "StartNetworkInsightsAnalysis":{
      "name":"StartNetworkInsightsAnalysis",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"StartNetworkInsightsAnalysisRequest"},
      "output":{"shape":"StartNetworkInsightsAnalysisResult"},
      "documentation":"<p>Starts analyzing the specified path. If the path is reachable, the operation returns the shortest feasible path.</p>"
    },
    "StartVpcEndpointServicePrivateDnsVerification":{
      "name":"StartVpcEndpointServicePrivateDnsVerification",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"StartVpcEndpointServicePrivateDnsVerificationRequest"},
      "output":{"shape":"StartVpcEndpointServicePrivateDnsVerificationResult"},
      "documentation":"<p>Initiates the verification process to prove that the service provider owns the private DNS name domain for the endpoint service.</p> <p>The service provider must successfully perform the verification before the consumer can use the name to access the service.</p> <p>Before the service provider runs this command, they must add a record to the DNS server.</p>"
    },
    "StopInstances":{
      "name":"StopInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"StopInstancesRequest"},
      "output":{"shape":"StopInstancesResult"},
      "documentation":"<p>Stops an Amazon EBS-backed instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Stop_Start.html\">Stop and start your instance</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>You can use the Stop action to hibernate an instance if the instance is <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html#enabling-hibernation\">enabled for hibernation</a> and it meets the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html#hibernating-prerequisites\">hibernation prerequisites</a>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>We don't charge usage for a stopped instance, or data transfer fees; however, your root partition Amazon EBS volume remains and continues to persist your data, and you are charged for Amazon EBS volume usage. Every time you start your instance, Amazon EC2 charges a one-minute minimum for instance usage, and thereafter charges per second for instance usage.</p> <p>You can't stop or hibernate instance store-backed instances. You can't use the Stop action to hibernate Spot Instances, but you can specify that Amazon EC2 should hibernate Spot Instances when they are interrupted. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-interruptions.html#hibernate-spot-instances\">Hibernating interrupted Spot Instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>When you stop or hibernate an instance, we shut it down. You can restart your instance at any time. Before stopping or hibernating an instance, make sure it is in a state from which it can be restarted. Stopping an instance does not preserve data stored in RAM, but hibernating an instance does preserve data stored in RAM. If an instance cannot hibernate successfully, a normal shutdown occurs.</p> <p>Stopping and hibernating an instance is different to rebooting or terminating it. For example, when you stop or hibernate an instance, the root device and any other devices attached to the instance persist. When you terminate an instance, the root device and any other devices attached during the instance launch are automatically deleted. For more information about the differences between rebooting, stopping, hibernating, and terminating instances, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-lifecycle.html\">Instance lifecycle</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>When you stop an instance, we attempt to shut it down forcibly after a short while. If your instance appears stuck in the stopping state after a period of time, there may be an issue with the underlying host computer. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/TroubleshootingInstancesStopping.html\">Troubleshoot stopping your instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "TerminateClientVpnConnections":{
      "name":"TerminateClientVpnConnections",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"TerminateClientVpnConnectionsRequest"},
      "output":{"shape":"TerminateClientVpnConnectionsResult"},
      "documentation":"<p>Terminates active Client VPN endpoint connections. This action can be used to terminate a specific client connection, or up to five connections established by a specific user.</p>"
    },
    "TerminateInstances":{
      "name":"TerminateInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"TerminateInstancesRequest"},
      "output":{"shape":"TerminateInstancesResult"},
      "documentation":"<p>Shuts down the specified instances. This operation is idempotent; if you terminate an instance more than once, each call succeeds. </p> <p>If you specify multiple instances and the request fails (for example, because of a single incorrect instance ID), none of the instances are terminated.</p> <p>If you terminate multiple instances across multiple Availability Zones, and one or more of the specified instances are enabled for termination protection, the request fails with the following results:</p> <ul> <li> <p>The specified instances that are in the same Availability Zone as the protected instance are not terminated.</p> </li> <li> <p>The specified instances that are in different Availability Zones, where no other specified instances are protected, are successfully terminated.</p> </li> </ul> <p>For example, say you have the following instances:</p> <ul> <li> <p>Instance A: <code>us-east-1a</code>; Not protected</p> </li> <li> <p>Instance B: <code>us-east-1a</code>; Not protected</p> </li> <li> <p>Instance C: <code>us-east-1b</code>; Protected</p> </li> <li> <p>Instance D: <code>us-east-1b</code>; not protected</p> </li> </ul> <p>If you attempt to terminate all of these instances in the same request, the request reports failure with the following results:</p> <ul> <li> <p>Instance A and Instance B are successfully terminated because none of the specified instances in <code>us-east-1a</code> are enabled for termination protection.</p> </li> <li> <p>Instance C and Instance D fail to terminate because at least one of the specified instances in <code>us-east-1b</code> (Instance C) is enabled for termination protection.</p> </li> </ul> <p>Terminated instances remain visible after termination (for approximately one hour).</p> <p>By default, Amazon EC2 deletes all EBS volumes that were attached when the instance launched. Volumes attached after instance launch continue running.</p> <p>You can stop, start, and terminate EBS-backed instances. You can only terminate instance store-backed instances. What happens to an instance differs if you stop it or terminate it. For example, when you stop an instance, the root device and any other devices attached to the instance persist. When you terminate an instance, any attached EBS volumes with the <code>DeleteOnTermination</code> block device mapping parameter set to <code>true</code> are automatically deleted. For more information about the differences between stopping and terminating instances, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-lifecycle.html\">Instance lifecycle</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For more information about troubleshooting, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/TroubleshootingInstancesShuttingDown.html\">Troubleshooting terminating your instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "UnassignIpv6Addresses":{
      "name":"UnassignIpv6Addresses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"UnassignIpv6AddressesRequest"},
      "output":{"shape":"UnassignIpv6AddressesResult"},
      "documentation":"<p>Unassigns one or more IPv6 addresses IPv4 Prefix Delegation prefixes from a network interface.</p>"
    },
    "UnassignPrivateIpAddresses":{
      "name":"UnassignPrivateIpAddresses",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"UnassignPrivateIpAddressesRequest"},
      "documentation":"<p>Unassigns one or more secondary private IP addresses, or IPv4 Prefix Delegation prefixes from a network interface.</p>"
    },
    "UnassignPrivateNatGatewayAddress":{
      "name":"UnassignPrivateNatGatewayAddress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"UnassignPrivateNatGatewayAddressRequest"},
      "output":{"shape":"UnassignPrivateNatGatewayAddressResult"},
      "documentation":"<p>Unassigns secondary private IPv4 addresses from a private NAT gateway. You cannot unassign your primary private IP. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-edit-secondary\">Edit secondary IP address associations</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p> <p>While unassigning is in progress, you cannot assign/unassign additional IP addresses while the connections are being drained. You are, however, allowed to delete the NAT gateway.</p> <p>A private IP address will only be released at the end of MaxDrainDurationSeconds. The private IP addresses stay associated and support the existing connections but do not support any new connections (new connections are distributed across the remaining assigned private IP address). After the existing connections drain out, the private IP addresses get released. </p> <p/> <p/>"
    },
    "UnmonitorInstances":{
      "name":"UnmonitorInstances",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"UnmonitorInstancesRequest"},
      "output":{"shape":"UnmonitorInstancesResult"},
      "documentation":"<p>Disables detailed monitoring for a running instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-cloudwatch.html\">Monitoring your instances and volumes</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "UpdateSecurityGroupRuleDescriptionsEgress":{
      "name":"UpdateSecurityGroupRuleDescriptionsEgress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"UpdateSecurityGroupRuleDescriptionsEgressRequest"},
      "output":{"shape":"UpdateSecurityGroupRuleDescriptionsEgressResult"},
      "documentation":"<p>[VPC only] Updates the description of an egress (outbound) security group rule. You can replace an existing description, or add a description to a rule that did not have one previously. You can remove a description for a security group rule by omitting the description parameter in the request.</p>"
    },
    "UpdateSecurityGroupRuleDescriptionsIngress":{
      "name":"UpdateSecurityGroupRuleDescriptionsIngress",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"UpdateSecurityGroupRuleDescriptionsIngressRequest"},
      "output":{"shape":"UpdateSecurityGroupRuleDescriptionsIngressResult"},
      "documentation":"<p>Updates the description of an ingress (inbound) security group rule. You can replace an existing description, or add a description to a rule that did not have one previously. You can remove a description for a security group rule by omitting the description parameter in the request.</p>"
    },
    "WithdrawByoipCidr":{
      "name":"WithdrawByoipCidr",
      "http":{
        "method":"POST",
        "requestUri":"/"
      },
      "input":{"shape":"WithdrawByoipCidrRequest"},
      "output":{"shape":"WithdrawByoipCidrResult"},
      "documentation":"<p>Stops advertising an address range that is provisioned as an address pool.</p> <p>You can perform this operation at most once every 10 seconds, even if you specify different address ranges each time.</p> <p>It can take a few minutes before traffic to the specified addresses stops routing to Amazon Web Services because of BGP propagation delays.</p>"
    }
  },
  "shapes":{
    "AcceleratorCount":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of accelerators. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of accelerators. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum number of accelerators (GPUs, FPGAs, or Amazon Web Services Inferentia chips) on an instance.</p>"
    },
    "AcceleratorCountRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of accelerators. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of accelerators. To specify no maximum limit, omit this parameter. To exclude accelerator-enabled instance types, set <code>Max</code> to <code>0</code>.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum number of accelerators (GPUs, FPGAs, or Amazon Web Services Inferentia chips) on an instance. To exclude accelerator-enabled instance types, set <code>Max</code> to <code>0</code>.</p>"
    },
    "AcceleratorManufacturer":{
      "type":"string",
      "enum":[
        "nvidia",
        "amd",
        "amazon-web-services",
        "xilinx"
      ]
    },
    "AcceleratorManufacturerSet":{
      "type":"list",
      "member":{
        "shape":"AcceleratorManufacturer",
        "locationName":"item"
      }
    },
    "AcceleratorName":{
      "type":"string",
      "enum":[
        "a100",
        "v100",
        "k80",
        "t4",
        "m60",
        "radeon-pro-v520",
        "vu9p",
        "inferentia",
        "k520"
      ]
    },
    "AcceleratorNameSet":{
      "type":"list",
      "member":{
        "shape":"AcceleratorName",
        "locationName":"item"
      }
    },
    "AcceleratorTotalMemoryMiB":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum amount of accelerator memory, in MiB. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum amount of accelerator memory, in MiB. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum amount of total accelerator memory, in MiB.</p>"
    },
    "AcceleratorTotalMemoryMiBRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum amount of accelerator memory, in MiB. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum amount of accelerator memory, in MiB. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum amount of total accelerator memory, in MiB.</p>"
    },
    "AcceleratorType":{
      "type":"string",
      "enum":[
        "gpu",
        "fpga",
        "inference"
      ]
    },
    "AcceleratorTypeSet":{
      "type":"list",
      "member":{
        "shape":"AcceleratorType",
        "locationName":"item"
      }
    },
    "AcceptAddressTransferRequest":{
      "type":"structure",
      "required":["Address"],
      "members":{
        "Address":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address you are accepting for transfer.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AcceptAddressTransferResult":{
      "type":"structure",
      "members":{
        "AddressTransfer":{
          "shape":"AddressTransfer",
          "documentation":"<p>An Elastic IP address transfer.</p>",
          "locationName":"addressTransfer"
        }
      }
    },
    "AcceptReservedInstancesExchangeQuoteRequest":{
      "type":"structure",
      "required":["ReservedInstanceIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ReservedInstanceIds":{
          "shape":"ReservedInstanceIdSet",
          "documentation":"<p>The IDs of the Convertible Reserved Instances to exchange for another Convertible Reserved Instance of the same or higher value.</p>",
          "locationName":"ReservedInstanceId"
        },
        "TargetConfigurations":{
          "shape":"TargetConfigurationRequestSet",
          "documentation":"<p>The configuration of the target Convertible Reserved Instance to exchange for your current Convertible Reserved Instances.</p>",
          "locationName":"TargetConfiguration"
        }
      },
      "documentation":"<p>Contains the parameters for accepting the quote.</p>"
    },
    "AcceptReservedInstancesExchangeQuoteResult":{
      "type":"structure",
      "members":{
        "ExchangeId":{
          "shape":"String",
          "documentation":"<p>The ID of the successful exchange.</p>",
          "locationName":"exchangeId"
        }
      },
      "documentation":"<p>The result of the exchange and whether it was <code>successful</code>.</p>"
    },
    "AcceptTransitGatewayMulticastDomainAssociationsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment.</p>"
        },
        "SubnetIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the subnets to associate with the transit gateway multicast domain.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AcceptTransitGatewayMulticastDomainAssociationsResult":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"TransitGatewayMulticastDomainAssociations",
          "documentation":"<p>Information about the multicast domain associations.</p>",
          "locationName":"associations"
        }
      }
    },
    "AcceptTransitGatewayPeeringAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AcceptTransitGatewayPeeringAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPeeringAttachment":{
          "shape":"TransitGatewayPeeringAttachment",
          "documentation":"<p>The transit gateway peering attachment.</p>",
          "locationName":"transitGatewayPeeringAttachment"
        }
      }
    },
    "AcceptTransitGatewayVpcAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AcceptTransitGatewayVpcAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayVpcAttachment":{
          "shape":"TransitGatewayVpcAttachment",
          "documentation":"<p>The VPC attachment.</p>",
          "locationName":"transitGatewayVpcAttachment"
        }
      }
    },
    "AcceptVpcEndpointConnectionsRequest":{
      "type":"structure",
      "required":[
        "ServiceId",
        "VpcEndpointIds"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the VPC endpoint service.</p>"
        },
        "VpcEndpointIds":{
          "shape":"VpcEndpointIdList",
          "documentation":"<p>The IDs of the interface VPC endpoints.</p>",
          "locationName":"VpcEndpointId"
        }
      }
    },
    "AcceptVpcEndpointConnectionsResult":{
      "type":"structure",
      "members":{
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the interface endpoints that were not accepted, if applicable.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "AcceptVpcPeeringConnectionRequest":{
      "type":"structure",
      "required":["VpcPeeringConnectionId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcPeeringConnectionId":{
          "shape":"VpcPeeringConnectionIdWithResolver",
          "documentation":"<p>The ID of the VPC peering connection. You must specify this parameter in the request.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      }
    },
    "AcceptVpcPeeringConnectionResult":{
      "type":"structure",
      "members":{
        "VpcPeeringConnection":{
          "shape":"VpcPeeringConnection",
          "documentation":"<p>Information about the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnection"
        }
      }
    },
    "AccessScopeAnalysisFinding":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalysisId":{
          "shape":"NetworkInsightsAccessScopeAnalysisId",
          "documentation":"<p>The ID of the Network Access Scope analysis.</p>",
          "locationName":"networkInsightsAccessScopeAnalysisId"
        },
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScopeId"
        },
        "FindingId":{
          "shape":"String",
          "documentation":"<p>The ID of the finding.</p>",
          "locationName":"findingId"
        },
        "FindingComponents":{
          "shape":"PathComponentList",
          "documentation":"<p>The finding components.</p>",
          "locationName":"findingComponentSet"
        }
      },
      "documentation":"<p>Describes a finding for a Network Access Scope.</p>"
    },
    "AccessScopeAnalysisFindingList":{
      "type":"list",
      "member":{
        "shape":"AccessScopeAnalysisFinding",
        "locationName":"item"
      }
    },
    "AccessScopePath":{
      "type":"structure",
      "members":{
        "Source":{
          "shape":"PathStatement",
          "documentation":"<p>The source.</p>",
          "locationName":"source"
        },
        "Destination":{
          "shape":"PathStatement",
          "documentation":"<p>The destination.</p>",
          "locationName":"destination"
        },
        "ThroughResources":{
          "shape":"ThroughResourcesStatementList",
          "documentation":"<p>The through resources.</p>",
          "locationName":"throughResourceSet"
        }
      },
      "documentation":"<p>Describes a path.</p>"
    },
    "AccessScopePathList":{
      "type":"list",
      "member":{
        "shape":"AccessScopePath",
        "locationName":"item"
      }
    },
    "AccessScopePathListRequest":{
      "type":"list",
      "member":{
        "shape":"AccessScopePathRequest",
        "locationName":"item"
      }
    },
    "AccessScopePathRequest":{
      "type":"structure",
      "members":{
        "Source":{
          "shape":"PathStatementRequest",
          "documentation":"<p>The source.</p>"
        },
        "Destination":{
          "shape":"PathStatementRequest",
          "documentation":"<p>The destination.</p>"
        },
        "ThroughResources":{
          "shape":"ThroughResourcesStatementRequestList",
          "documentation":"<p>The through resources.</p>",
          "locationName":"ThroughResource"
        }
      },
      "documentation":"<p>Describes a path.</p>"
    },
    "AccountAttribute":{
      "type":"structure",
      "members":{
        "AttributeName":{
          "shape":"String",
          "documentation":"<p>The name of the account attribute.</p>",
          "locationName":"attributeName"
        },
        "AttributeValues":{
          "shape":"AccountAttributeValueList",
          "documentation":"<p>The values for the account attribute.</p>",
          "locationName":"attributeValueSet"
        }
      },
      "documentation":"<p>Describes an account attribute.</p>"
    },
    "AccountAttributeList":{
      "type":"list",
      "member":{
        "shape":"AccountAttribute",
        "locationName":"item"
      }
    },
    "AccountAttributeName":{
      "type":"string",
      "enum":[
        "supported-platforms",
        "default-vpc"
      ]
    },
    "AccountAttributeNameStringList":{
      "type":"list",
      "member":{
        "shape":"AccountAttributeName",
        "locationName":"attributeName"
      }
    },
    "AccountAttributeValue":{
      "type":"structure",
      "members":{
        "AttributeValue":{
          "shape":"String",
          "documentation":"<p>The value of the attribute.</p>",
          "locationName":"attributeValue"
        }
      },
      "documentation":"<p>Describes a value of an account attribute.</p>"
    },
    "AccountAttributeValueList":{
      "type":"list",
      "member":{
        "shape":"AccountAttributeValue",
        "locationName":"item"
      }
    },
    "ActiveInstance":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "SpotInstanceRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Instance request.</p>",
          "locationName":"spotInstanceRequestId"
        },
        "InstanceHealth":{
          "shape":"InstanceHealthStatus",
          "documentation":"<p>The health status of the instance. If the status of either the instance status check or the system status check is <code>impaired</code>, the health status of the instance is <code>unhealthy</code>. Otherwise, the health status is <code>healthy</code>.</p>",
          "locationName":"instanceHealth"
        }
      },
      "documentation":"<p>Describes a running instance in a Spot Fleet.</p>"
    },
    "ActiveInstanceSet":{
      "type":"list",
      "member":{
        "shape":"ActiveInstance",
        "locationName":"item"
      }
    },
    "ActivityStatus":{
      "type":"string",
      "enum":[
        "error",
        "pending_fulfillment",
        "pending_termination",
        "fulfilled"
      ]
    },
    "AddIpamOperatingRegion":{
      "type":"structure",
      "members":{
        "RegionName":{
          "shape":"String",
          "documentation":"<p>The name of the operating Region.</p>"
        }
      },
      "documentation":"<p>Add an operating Region to an IPAM. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p> <p>For more information about operating Regions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "AddIpamOperatingRegionSet":{
      "type":"list",
      "member":{"shape":"AddIpamOperatingRegion"},
      "max":50,
      "min":0
    },
    "AddPrefixListEntries":{
      "type":"list",
      "member":{"shape":"AddPrefixListEntry"},
      "max":100,
      "min":0
    },
    "AddPrefixListEntry":{
      "type":"structure",
      "required":["Cidr"],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR block.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the entry.</p> <p>Constraints: Up to 255 characters in length.</p>"
        }
      },
      "documentation":"<p>An entry for a prefix list.</p>"
    },
    "AddedPrincipal":{
      "type":"structure",
      "members":{
        "PrincipalType":{
          "shape":"PrincipalType",
          "documentation":"<p>The type of principal.</p>",
          "locationName":"principalType"
        },
        "Principal":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the principal.</p>",
          "locationName":"principal"
        },
        "ServicePermissionId":{
          "shape":"String",
          "documentation":"<p>The ID of the service permission.</p>",
          "locationName":"servicePermissionId"
        },
        "ServiceId":{
          "shape":"String",
          "documentation":"<p>The ID of the service.</p>",
          "locationName":"serviceId"
        }
      },
      "documentation":"<p>Describes a principal.</p>"
    },
    "AddedPrincipalSet":{
      "type":"list",
      "member":{
        "shape":"AddedPrincipal",
        "locationName":"item"
      }
    },
    "AdditionalDetail":{
      "type":"structure",
      "members":{
        "AdditionalDetailType":{
          "shape":"String",
          "documentation":"<p>The information type.</p>",
          "locationName":"additionalDetailType"
        },
        "Component":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The path component.</p>",
          "locationName":"component"
        }
      },
      "documentation":"<p>Describes an additional detail for a path analysis.</p>"
    },
    "AdditionalDetailList":{
      "type":"list",
      "member":{
        "shape":"AdditionalDetail",
        "locationName":"item"
      }
    },
    "Address":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance that the address is associated with (if any).</p>",
          "locationName":"instanceId"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address.</p>",
          "locationName":"publicIp"
        },
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>The ID representing the allocation of the address for use with EC2-VPC.</p>",
          "locationName":"allocationId"
        },
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The ID representing the association of the address with an instance in a VPC.</p>",
          "locationName":"associationId"
        },
        "Domain":{
          "shape":"DomainType",
          "documentation":"<p>Indicates whether this Elastic IP address is for use with instances in EC2-Classic (<code>standard</code>) or instances in a VPC (<code>vpc</code>).</p>",
          "locationName":"domain"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "NetworkInterfaceOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the network interface.</p>",
          "locationName":"networkInterfaceOwnerId"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IP address associated with the Elastic IP address.</p>",
          "locationName":"privateIpAddress"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the Elastic IP address.</p>",
          "locationName":"tagSet"
        },
        "PublicIpv4Pool":{
          "shape":"String",
          "documentation":"<p>The ID of an address pool.</p>",
          "locationName":"publicIpv4Pool"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The name of the unique set of Availability Zones, Local Zones, or Wavelength Zones from which Amazon Web Services advertises IP addresses.</p>",
          "locationName":"networkBorderGroup"
        },
        "CustomerOwnedIp":{
          "shape":"String",
          "documentation":"<p>The customer-owned IP address.</p>",
          "locationName":"customerOwnedIp"
        },
        "CustomerOwnedIpv4Pool":{
          "shape":"String",
          "documentation":"<p>The ID of the customer-owned address pool.</p>",
          "locationName":"customerOwnedIpv4Pool"
        },
        "CarrierIp":{
          "shape":"String",
          "documentation":"<p>The carrier IP address associated. This option is only available for network interfaces which reside in a subnet in a Wavelength Zone (for example an EC2 instance). </p>",
          "locationName":"carrierIp"
        }
      },
      "documentation":"<p>Describes an Elastic IP address, or a carrier IP address.</p>"
    },
    "AddressAttribute":{
      "type":"structure",
      "members":{
        "PublicIp":{
          "shape":"PublicIpAddress",
          "documentation":"<p>The public IP address.</p>",
          "locationName":"publicIp"
        },
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>[EC2-VPC] The allocation ID.</p>",
          "locationName":"allocationId"
        },
        "PtrRecord":{
          "shape":"String",
          "documentation":"<p>The pointer (PTR) record for the IP address.</p>",
          "locationName":"ptrRecord"
        },
        "PtrRecordUpdate":{
          "shape":"PtrUpdateStatus",
          "documentation":"<p>The updated PTR record for the IP address.</p>",
          "locationName":"ptrRecordUpdate"
        }
      },
      "documentation":"<p>The attributes associated with an Elastic IP address.</p>"
    },
    "AddressAttributeName":{
      "type":"string",
      "enum":["domain-name"]
    },
    "AddressFamily":{
      "type":"string",
      "enum":[
        "ipv4",
        "ipv6"
      ]
    },
    "AddressList":{
      "type":"list",
      "member":{
        "shape":"Address",
        "locationName":"item"
      }
    },
    "AddressMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "AddressSet":{
      "type":"list",
      "member":{
        "shape":"AddressAttribute",
        "locationName":"item"
      }
    },
    "AddressTransfer":{
      "type":"structure",
      "members":{
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address being transferred.</p>",
          "locationName":"publicIp"
        },
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>The allocation ID of an Elastic IP address.</p>",
          "locationName":"allocationId"
        },
        "TransferAccountId":{
          "shape":"String",
          "documentation":"<p>The ID of the account that you want to transfer the Elastic IP address to.</p>",
          "locationName":"transferAccountId"
        },
        "TransferOfferExpirationTimestamp":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The timestamp when the Elastic IP address transfer expired. When the source account starts the transfer, the transfer account has seven hours to allocate the Elastic IP address to complete the transfer, or the Elastic IP address will return to its original owner.</p>",
          "locationName":"transferOfferExpirationTimestamp"
        },
        "TransferOfferAcceptedTimestamp":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The timestamp when the Elastic IP address transfer was accepted.</p>",
          "locationName":"transferOfferAcceptedTimestamp"
        },
        "AddressTransferStatus":{
          "shape":"AddressTransferStatus",
          "documentation":"<p>The Elastic IP address transfer status.</p>",
          "locationName":"addressTransferStatus"
        }
      },
      "documentation":"<p>Details on the Elastic IP address transfer. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-eips.html#transfer-EIPs-intro\">Transfer Elastic IP addresses</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
    },
    "AddressTransferList":{
      "type":"list",
      "member":{
        "shape":"AddressTransfer",
        "locationName":"item"
      }
    },
    "AddressTransferStatus":{
      "type":"string",
      "enum":[
        "pending",
        "disabled",
        "accepted"
      ]
    },
    "AdvertiseByoipCidrRequest":{
      "type":"structure",
      "required":["Cidr"],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The address range, in CIDR notation. This must be the exact range that you provisioned. You can't advertise only a portion of the provisioned range.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AdvertiseByoipCidrResult":{
      "type":"structure",
      "members":{
        "ByoipCidr":{
          "shape":"ByoipCidr",
          "documentation":"<p>Information about the address range.</p>",
          "locationName":"byoipCidr"
        }
      }
    },
    "Affinity":{
      "type":"string",
      "enum":[
        "default",
        "host"
      ]
    },
    "AllocateAddressRequest":{
      "type":"structure",
      "members":{
        "Domain":{
          "shape":"DomainType",
          "documentation":"<p>Indicates whether the Elastic IP address is for use with instances in a VPC or instances in EC2-Classic.</p> <p>Default: If the Region supports EC2-Classic, the default is <code>standard</code>. Otherwise, the default is <code>vpc</code>.</p>"
        },
        "Address":{
          "shape":"PublicIpAddress",
          "documentation":"<p>[EC2-VPC] The Elastic IP address to recover or an IPv4 address from an address pool.</p>"
        },
        "PublicIpv4Pool":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of an address pool that you own. Use this parameter to let Amazon EC2 select an address from the address pool. To specify a specific address from the address pool, use the <code>Address</code> parameter instead.</p>"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p> A unique set of Availability Zones, Local Zones, or Wavelength Zones from which Amazon Web Services advertises IP addresses. Use this parameter to limit the IP address to this location. IP addresses cannot move between network border groups.</p> <p>Use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeAvailabilityZones.html\">DescribeAvailabilityZones</a> to view the network border groups.</p> <p>You cannot use a network border group with EC2 Classic. If you attempt this operation on EC2 Classic, you receive an <code>InvalidParameterCombination</code> error.</p>"
        },
        "CustomerOwnedIpv4Pool":{
          "shape":"String",
          "documentation":"<p>The ID of a customer-owned address pool. Use this parameter to let Amazon EC2 select an address from the address pool. Alternatively, specify a specific address from the address pool.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Elastic IP address.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "AllocateAddressResult":{
      "type":"structure",
      "members":{
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address.</p>",
          "locationName":"publicIp"
        },
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] The ID that Amazon Web Services assigns to represent the allocation of the Elastic IP address for use with instances in a VPC.</p>",
          "locationName":"allocationId"
        },
        "PublicIpv4Pool":{
          "shape":"String",
          "documentation":"<p>The ID of an address pool.</p>",
          "locationName":"publicIpv4Pool"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The set of Availability Zones, Local Zones, or Wavelength Zones from which Amazon Web Services advertises IP addresses.</p>",
          "locationName":"networkBorderGroup"
        },
        "Domain":{
          "shape":"DomainType",
          "documentation":"<p>Indicates whether the Elastic IP address is for use with instances in a VPC (<code>vpc</code>) or instances in EC2-Classic (<code>standard</code>).</p>",
          "locationName":"domain"
        },
        "CustomerOwnedIp":{
          "shape":"String",
          "documentation":"<p>The customer-owned IP address.</p>",
          "locationName":"customerOwnedIp"
        },
        "CustomerOwnedIpv4Pool":{
          "shape":"String",
          "documentation":"<p>The ID of the customer-owned address pool.</p>",
          "locationName":"customerOwnedIpv4Pool"
        },
        "CarrierIp":{
          "shape":"String",
          "documentation":"<p>The carrier IP address. This option is only available for network interfaces which reside in a subnet in a Wavelength Zone (for example an EC2 instance). </p>",
          "locationName":"carrierIp"
        }
      }
    },
    "AllocateHostsRequest":{
      "type":"structure",
      "required":[
        "AvailabilityZone",
        "Quantity"
      ],
      "members":{
        "AutoPlacement":{
          "shape":"AutoPlacement",
          "documentation":"<p>Indicates whether the host accepts any untargeted instance launches that match its instance type configuration, or if it only accepts Host tenancy instance launches that specify its unique host ID. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/how-dedicated-hosts-work.html#dedicated-hosts-understanding\"> Understanding auto-placement and affinity</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: <code>on</code> </p>",
          "locationName":"autoPlacement"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to allocate the Dedicated Host.</p>",
          "locationName":"availabilityZone"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>Specifies the instance type to be supported by the Dedicated Hosts. If you specify an instance type, the Dedicated Hosts support instances of the specified instance type only.</p> <p>If you want the Dedicated Hosts to support multiple instance types in a specific instance family, omit this parameter and specify <b>InstanceFamily</b> instead. You cannot specify <b>InstanceType</b> and <b>InstanceFamily</b> in the same request.</p>",
          "locationName":"instanceType"
        },
        "InstanceFamily":{
          "shape":"String",
          "documentation":"<p>Specifies the instance family to be supported by the Dedicated Hosts. If you specify an instance family, the Dedicated Hosts support multiple instance types within that instance family.</p> <p>If you want the Dedicated Hosts to support a specific instance type only, omit this parameter and specify <b>InstanceType</b> instead. You cannot specify <b>InstanceFamily</b> and <b>InstanceType</b> in the same request.</p>"
        },
        "Quantity":{
          "shape":"Integer",
          "documentation":"<p>The number of Dedicated Hosts to allocate to your account with these parameters.</p>",
          "locationName":"quantity"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the Dedicated Host during creation.</p>",
          "locationName":"TagSpecification"
        },
        "HostRecovery":{
          "shape":"HostRecovery",
          "documentation":"<p>Indicates whether to enable or disable host recovery for the Dedicated Host. Host recovery is disabled by default. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-recovery.html\"> Host recovery</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: <code>off</code> </p>"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Amazon Web Services Outpost on which to allocate the Dedicated Host.</p>"
        },
        "HostMaintenance":{
          "shape":"HostMaintenance",
          "documentation":"<p>Indicates whether to enable or disable host maintenance for the Dedicated Host. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-maintenance.html\"> Host maintenance</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: <code>on</code> </p>"
        }
      }
    },
    "AllocateHostsResult":{
      "type":"structure",
      "members":{
        "HostIds":{
          "shape":"ResponseHostIdList",
          "documentation":"<p>The ID of the allocated Dedicated Host. This is used to launch an instance onto a specific host.</p>",
          "locationName":"hostIdSet"
        }
      },
      "documentation":"<p>Contains the output of AllocateHosts.</p>"
    },
    "AllocateIpamPoolCidrRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool from which you would like to allocate a CIDR.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR you would like to allocate from the IPAM pool. Note the following:</p> <ul> <li> <p>If there is no DefaultNetmaskLength allocation rule set on the pool, you must specify either the NetmaskLength or the CIDR.</p> </li> <li> <p>If the DefaultNetmaskLength allocation rule is set on the pool, you can specify either the NetmaskLength or the CIDR and the DefaultNetmaskLength allocation rule will be ignored.</p> </li> </ul> <p>Possible values: Any available IPv4 or IPv6 CIDR.</p>"
        },
        "NetmaskLength":{
          "shape":"Integer",
          "documentation":"<p>The netmask length of the CIDR you would like to allocate from the IPAM pool. Note the following:</p> <ul> <li> <p>If there is no DefaultNetmaskLength allocation rule set on the pool, you must specify either the NetmaskLength or the CIDR.</p> </li> <li> <p>If the DefaultNetmaskLength allocation rule is set on the pool, you can specify either the NetmaskLength or the CIDR and the DefaultNetmaskLength allocation rule will be ignored.</p> </li> </ul> <p>Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the allocation.</p>"
        },
        "PreviewNextCidr":{
          "shape":"Boolean",
          "documentation":"<p>A preview of the next available CIDR in a pool.</p>"
        },
        "DisallowedCidrs":{
          "shape":"IpamPoolAllocationDisallowedCidrs",
          "documentation":"<p>Exclude a particular CIDR range from being returned by the pool. Disallowed CIDRs are only allowed if using netmask length for allocation.</p>",
          "locationName":"DisallowedCidr"
        }
      }
    },
    "AllocateIpamPoolCidrResult":{
      "type":"structure",
      "members":{
        "IpamPoolAllocation":{
          "shape":"IpamPoolAllocation",
          "documentation":"<p>Information about the allocation created.</p>",
          "locationName":"ipamPoolAllocation"
        }
      }
    },
    "AllocationId":{"type":"string"},
    "AllocationIdList":{
      "type":"list",
      "member":{
        "shape":"AllocationId",
        "locationName":"AllocationId"
      }
    },
    "AllocationIds":{
      "type":"list",
      "member":{
        "shape":"AllocationId",
        "locationName":"item"
      }
    },
    "AllocationState":{
      "type":"string",
      "enum":[
        "available",
        "under-assessment",
        "permanent-failure",
        "released",
        "released-permanent-failure",
        "pending"
      ]
    },
    "AllocationStrategy":{
      "type":"string",
      "enum":[
        "lowestPrice",
        "diversified",
        "capacityOptimized",
        "capacityOptimizedPrioritized",
        "priceCapacityOptimized"
      ]
    },
    "AllocationType":{
      "type":"string",
      "enum":["used"]
    },
    "AllowedInstanceType":{
      "type":"string",
      "max":30,
      "min":1,
      "pattern":"[a-zA-Z0-9\\.\\*]+"
    },
    "AllowedInstanceTypeSet":{
      "type":"list",
      "member":{
        "shape":"AllowedInstanceType",
        "locationName":"item"
      },
      "max":400,
      "min":0
    },
    "AllowedPrincipal":{
      "type":"structure",
      "members":{
        "PrincipalType":{
          "shape":"PrincipalType",
          "documentation":"<p>The type of principal.</p>",
          "locationName":"principalType"
        },
        "Principal":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the principal.</p>",
          "locationName":"principal"
        },
        "ServicePermissionId":{
          "shape":"String",
          "documentation":"<p>The ID of the service permission.</p>",
          "locationName":"servicePermissionId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        },
        "ServiceId":{
          "shape":"String",
          "documentation":"<p>The ID of the service.</p>",
          "locationName":"serviceId"
        }
      },
      "documentation":"<p>Describes a principal.</p>"
    },
    "AllowedPrincipalSet":{
      "type":"list",
      "member":{
        "shape":"AllowedPrincipal",
        "locationName":"item"
      }
    },
    "AllowsMultipleInstanceTypes":{
      "type":"string",
      "enum":[
        "on",
        "off"
      ]
    },
    "AlternatePathHint":{
      "type":"structure",
      "members":{
        "ComponentId":{
          "shape":"String",
          "documentation":"<p>The ID of the component.</p>",
          "locationName":"componentId"
        },
        "ComponentArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the component.</p>",
          "locationName":"componentArn"
        }
      },
      "documentation":"<p>Describes an potential intermediate component of a feasible path.</p>"
    },
    "AlternatePathHintList":{
      "type":"list",
      "member":{
        "shape":"AlternatePathHint",
        "locationName":"item"
      }
    },
    "AnalysisAclRule":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation.</p>",
          "locationName":"cidr"
        },
        "Egress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the rule is an outbound rule.</p>",
          "locationName":"egress"
        },
        "PortRange":{
          "shape":"PortRange",
          "documentation":"<p>The range of ports.</p>",
          "locationName":"portRange"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol.</p>",
          "locationName":"protocol"
        },
        "RuleAction":{
          "shape":"String",
          "documentation":"<p>Indicates whether to allow or deny traffic that matches the rule.</p>",
          "locationName":"ruleAction"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The rule number.</p>",
          "locationName":"ruleNumber"
        }
      },
      "documentation":"<p>Describes a network access control (ACL) rule.</p>"
    },
    "AnalysisComponent":{
      "type":"structure",
      "members":{
        "Id":{
          "shape":"String",
          "documentation":"<p>The ID of the component.</p>",
          "locationName":"id"
        },
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the component.</p>",
          "locationName":"arn"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the analysis component.</p>",
          "locationName":"name"
        }
      },
      "documentation":"<p>Describes a path component.</p>"
    },
    "AnalysisComponentList":{
      "type":"list",
      "member":{
        "shape":"AnalysisComponent",
        "locationName":"item"
      }
    },
    "AnalysisLoadBalancerListener":{
      "type":"structure",
      "members":{
        "LoadBalancerPort":{
          "shape":"Port",
          "documentation":"<p>The port on which the load balancer is listening.</p>",
          "locationName":"loadBalancerPort"
        },
        "InstancePort":{
          "shape":"Port",
          "documentation":"<p>[Classic Load Balancers] The back-end port for the listener.</p>",
          "locationName":"instancePort"
        }
      },
      "documentation":"<p>Describes a load balancer listener.</p>"
    },
    "AnalysisLoadBalancerTarget":{
      "type":"structure",
      "members":{
        "Address":{
          "shape":"IpAddress",
          "documentation":"<p>The IP address.</p>",
          "locationName":"address"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "Instance":{
          "shape":"AnalysisComponent",
          "documentation":"<p>Information about the instance.</p>",
          "locationName":"instance"
        },
        "Port":{
          "shape":"Port",
          "documentation":"<p>The port on which the target is listening.</p>",
          "locationName":"port"
        }
      },
      "documentation":"<p>Describes a load balancer target.</p>"
    },
    "AnalysisPacketHeader":{
      "type":"structure",
      "members":{
        "DestinationAddresses":{
          "shape":"IpAddressList",
          "documentation":"<p>The destination addresses.</p>",
          "locationName":"destinationAddressSet"
        },
        "DestinationPortRanges":{
          "shape":"PortRangeList",
          "documentation":"<p>The destination port ranges.</p>",
          "locationName":"destinationPortRangeSet"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol.</p>",
          "locationName":"protocol"
        },
        "SourceAddresses":{
          "shape":"IpAddressList",
          "documentation":"<p>The source addresses.</p>",
          "locationName":"sourceAddressSet"
        },
        "SourcePortRanges":{
          "shape":"PortRangeList",
          "documentation":"<p>The source port ranges.</p>",
          "locationName":"sourcePortRangeSet"
        }
      },
      "documentation":"<p>Describes a header. Reflects any changes made by a component as traffic passes through. The fields of an inbound header are null except for the first component of a path.</p>"
    },
    "AnalysisRouteTableRoute":{
      "type":"structure",
      "members":{
        "DestinationCidr":{
          "shape":"String",
          "documentation":"<p>The destination IPv4 address, in CIDR notation.</p>",
          "locationName":"destinationCidr"
        },
        "DestinationPrefixListId":{
          "shape":"String",
          "documentation":"<p>The prefix of the Amazon Web Service.</p>",
          "locationName":"destinationPrefixListId"
        },
        "EgressOnlyInternetGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of an egress-only internet gateway.</p>",
          "locationName":"egressOnlyInternetGatewayId"
        },
        "GatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the gateway, such as an internet gateway or virtual private gateway.</p>",
          "locationName":"gatewayId"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance, such as a NAT instance.</p>",
          "locationName":"instanceId"
        },
        "NatGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of a NAT gateway.</p>",
          "locationName":"natGatewayId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of a network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "Origin":{
          "shape":"String",
          "documentation":"<p>Describes how the route was created. The following are the possible values:</p> <ul> <li> <p>CreateRouteTable - The route was automatically created when the route table was created.</p> </li> <li> <p>CreateRoute - The route was manually added to the route table.</p> </li> <li> <p>EnableVgwRoutePropagation - The route was propagated by route propagation.</p> </li> </ul>",
          "locationName":"origin"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of a transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "VpcPeeringConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of a VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state. The following are the possible values:</p> <ul> <li> <p>active</p> </li> <li> <p>blackhole</p> </li> </ul>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a route table route.</p>"
    },
    "AnalysisSecurityGroupRule":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation.</p>",
          "locationName":"cidr"
        },
        "Direction":{
          "shape":"String",
          "documentation":"<p>The direction. The following are the possible values:</p> <ul> <li> <p>egress</p> </li> <li> <p>ingress</p> </li> </ul>",
          "locationName":"direction"
        },
        "SecurityGroupId":{
          "shape":"String",
          "documentation":"<p>The security group ID.</p>",
          "locationName":"securityGroupId"
        },
        "PortRange":{
          "shape":"PortRange",
          "documentation":"<p>The port range.</p>",
          "locationName":"portRange"
        },
        "PrefixListId":{
          "shape":"String",
          "documentation":"<p>The prefix list ID.</p>",
          "locationName":"prefixListId"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol name.</p>",
          "locationName":"protocol"
        }
      },
      "documentation":"<p>Describes a security group rule.</p>"
    },
    "AnalysisStatus":{
      "type":"string",
      "enum":[
        "running",
        "succeeded",
        "failed"
      ]
    },
    "ApplianceModeSupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "ApplySecurityGroupsToClientVpnTargetNetworkRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "VpcId",
        "SecurityGroupIds"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC in which the associated target network is located.</p>"
        },
        "SecurityGroupIds":{
          "shape":"ClientVpnSecurityGroupIdSet",
          "documentation":"<p>The IDs of the security groups to apply to the associated target network. Up to 5 security groups can be applied to an associated target network.</p>",
          "locationName":"SecurityGroupId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ApplySecurityGroupsToClientVpnTargetNetworkResult":{
      "type":"structure",
      "members":{
        "SecurityGroupIds":{
          "shape":"ClientVpnSecurityGroupIdSet",
          "documentation":"<p>The IDs of the applied security groups.</p>",
          "locationName":"securityGroupIds"
        }
      }
    },
    "ArchitectureType":{
      "type":"string",
      "enum":[
        "i386",
        "x86_64",
        "arm64",
        "x86_64_mac",
        "arm64_mac"
      ]
    },
    "ArchitectureTypeList":{
      "type":"list",
      "member":{
        "shape":"ArchitectureType",
        "locationName":"item"
      }
    },
    "ArchitectureTypeSet":{
      "type":"list",
      "member":{
        "shape":"ArchitectureType",
        "locationName":"item"
      },
      "max":3,
      "min":0
    },
    "ArchitectureValues":{
      "type":"string",
      "enum":[
        "i386",
        "x86_64",
        "arm64",
        "x86_64_mac",
        "arm64_mac"
      ]
    },
    "ArnList":{
      "type":"list",
      "member":{
        "shape":"ResourceArn",
        "locationName":"item"
      }
    },
    "AssignIpv6AddressesRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of additional IPv6 addresses to assign to the network interface. The specified number of IPv6 addresses are assigned in addition to the existing IPv6 addresses that are already assigned to the network interface. Amazon EC2 automatically selects the IPv6 addresses from the subnet range. You can't use this option if specifying specific IPv6 addresses.</p>",
          "locationName":"ipv6AddressCount"
        },
        "Ipv6Addresses":{
          "shape":"Ipv6AddressList",
          "documentation":"<p>The IPv6 addresses to be assigned to the network interface. You can't use this option if you're specifying a number of IPv6 addresses.</p>",
          "locationName":"ipv6Addresses"
        },
        "Ipv6PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 prefixes that Amazon Web Services automatically assigns to the network interface. You cannot use this option if you use the <code>Ipv6Prefixes</code> option.</p>"
        },
        "Ipv6Prefixes":{
          "shape":"IpPrefixList",
          "documentation":"<p>One or more IPv6 prefixes assigned to the network interface. You cannot use this option if you use the <code>Ipv6PrefixCount</code> option.</p>",
          "locationName":"Ipv6Prefix"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        }
      }
    },
    "AssignIpv6AddressesResult":{
      "type":"structure",
      "members":{
        "AssignedIpv6Addresses":{
          "shape":"Ipv6AddressList",
          "documentation":"<p>The new IPv6 addresses assigned to the network interface. Existing IPv6 addresses that were assigned to the network interface before the request are not included.</p>",
          "locationName":"assignedIpv6Addresses"
        },
        "AssignedIpv6Prefixes":{
          "shape":"IpPrefixList",
          "documentation":"<p>The IPv6 prefixes that are assigned to the network interface.</p>",
          "locationName":"assignedIpv6PrefixSet"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        }
      }
    },
    "AssignPrivateIpAddressesRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "AllowReassignment":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to allow an IP address that is already assigned to another network interface or instance to be reassigned to the specified network interface.</p>",
          "locationName":"allowReassignment"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "PrivateIpAddresses":{
          "shape":"PrivateIpAddressStringList",
          "documentation":"<p>The IP addresses to be assigned as a secondary private IP address to the network interface. You can't specify this parameter when also specifying a number of secondary IP addresses.</p> <p>If you don't specify an IP address, Amazon EC2 automatically selects an IP address within the subnet range.</p>",
          "locationName":"privateIpAddress"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of secondary IP addresses to assign to the network interface. You can't specify this parameter when also specifying private IP addresses.</p>",
          "locationName":"secondaryPrivateIpAddressCount"
        },
        "Ipv4Prefixes":{
          "shape":"IpPrefixList",
          "documentation":"<p>One or more IPv4 prefixes assigned to the network interface. You cannot use this option if you use the <code>Ipv4PrefixCount</code> option.</p>",
          "locationName":"Ipv4Prefix"
        },
        "Ipv4PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv4 prefixes that Amazon Web Services automatically assigns to the network interface. You cannot use this option if you use the <code>Ipv4 Prefixes</code> option.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for AssignPrivateIpAddresses.</p>"
    },
    "AssignPrivateIpAddressesResult":{
      "type":"structure",
      "members":{
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "AssignedPrivateIpAddresses":{
          "shape":"AssignedPrivateIpAddressList",
          "documentation":"<p>The private IP addresses assigned to the network interface.</p>",
          "locationName":"assignedPrivateIpAddressesSet"
        },
        "AssignedIpv4Prefixes":{
          "shape":"Ipv4PrefixesList",
          "documentation":"<p>The IPv4 prefixes that are assigned to the network interface.</p>",
          "locationName":"assignedIpv4PrefixSet"
        }
      }
    },
    "AssignPrivateNatGatewayAddressRequest":{
      "type":"structure",
      "required":["NatGatewayId"],
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>"
        },
        "PrivateIpAddresses":{
          "shape":"IpList",
          "documentation":"<p>The private IPv4 addresses you want to assign to the private NAT gateway.</p>",
          "locationName":"PrivateIpAddress"
        },
        "PrivateIpAddressCount":{
          "shape":"PrivateIpAddressCount",
          "documentation":"<p>The number of private IP addresses to assign to the NAT gateway. You can't specify this parameter when also specifying private IP addresses.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssignPrivateNatGatewayAddressResult":{
      "type":"structure",
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>",
          "locationName":"natGatewayId"
        },
        "NatGatewayAddresses":{
          "shape":"NatGatewayAddressList",
          "documentation":"<p>NAT gateway IP addresses.</p>",
          "locationName":"natGatewayAddressSet"
        }
      }
    },
    "AssignedPrivateIpAddress":{
      "type":"structure",
      "members":{
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IP address assigned to the network interface.</p>",
          "locationName":"privateIpAddress"
        }
      },
      "documentation":"<p>Describes the private IP addresses assigned to a network interface.</p>"
    },
    "AssignedPrivateIpAddressList":{
      "type":"list",
      "member":{
        "shape":"AssignedPrivateIpAddress",
        "locationName":"item"
      }
    },
    "AssociateAddressRequest":{
      "type":"structure",
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>[EC2-VPC] The allocation ID. This is required for EC2-VPC.</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance. The instance must have exactly one attached network interface. For EC2-VPC, you can specify either the instance ID or the network interface ID, but not both. For EC2-Classic, you must specify an instance ID and the instance must be in the running state.</p>"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>[EC2-Classic] The Elastic IP address to associate with the instance. This is required for EC2-Classic.</p>"
        },
        "AllowReassociation":{
          "shape":"Boolean",
          "documentation":"<p>[EC2-VPC] For a VPC in an EC2-Classic account, specify true to allow an Elastic IP address that is already associated with an instance or network interface to be reassociated with the specified instance or network interface. Otherwise, the operation fails. In a VPC in an EC2-VPC-only account, reassociation is automatic, therefore you can specify false to ensure the operation fails if the Elastic IP address is already associated with another resource.</p>",
          "locationName":"allowReassociation"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>[EC2-VPC] The ID of the network interface. If the instance has more than one network interface, you must specify a network interface ID.</p> <p>For EC2-VPC, you can specify either the instance ID or the network interface ID, but not both. </p>",
          "locationName":"networkInterfaceId"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] The primary or secondary private IP address to associate with the Elastic IP address. If no private IP address is specified, the Elastic IP address is associated with the primary private IP address.</p>",
          "locationName":"privateIpAddress"
        }
      }
    },
    "AssociateAddressResult":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] The ID that represents the association of the Elastic IP address with an instance.</p>",
          "locationName":"associationId"
        }
      }
    },
    "AssociateClientVpnTargetNetworkRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "SubnetId"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet to associate with the Client VPN endpoint.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateClientVpnTargetNetworkResult":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The unique ID of the target network association.</p>",
          "locationName":"associationId"
        },
        "Status":{
          "shape":"AssociationStatus",
          "documentation":"<p>The current state of the target network association.</p>",
          "locationName":"status"
        }
      }
    },
    "AssociateDhcpOptionsRequest":{
      "type":"structure",
      "required":[
        "DhcpOptionsId",
        "VpcId"
      ],
      "members":{
        "DhcpOptionsId":{
          "shape":"DefaultingDhcpOptionsId",
          "documentation":"<p>The ID of the DHCP options set, or <code>default</code> to associate no DHCP options with the VPC.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "AssociateEnclaveCertificateIamRoleRequest":{
      "type":"structure",
      "required":[
        "CertificateArn",
        "RoleArn"
      ],
      "members":{
        "CertificateArn":{
          "shape":"CertificateId",
          "documentation":"<p>The ARN of the ACM certificate with which to associate the IAM role.</p>"
        },
        "RoleArn":{
          "shape":"RoleId",
          "documentation":"<p>The ARN of the IAM role to associate with the ACM certificate. You can associate up to 16 IAM roles with an ACM certificate.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateEnclaveCertificateIamRoleResult":{
      "type":"structure",
      "members":{
        "CertificateS3BucketName":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket to which the certificate was uploaded.</p>",
          "locationName":"certificateS3BucketName"
        },
        "CertificateS3ObjectKey":{
          "shape":"String",
          "documentation":"<p>The Amazon S3 object key where the certificate, certificate chain, and encrypted private key bundle are stored. The object key is formatted as follows: <code>role_arn</code>/<code>certificate_arn</code>.</p>",
          "locationName":"certificateS3ObjectKey"
        },
        "EncryptionKmsKeyId":{
          "shape":"String",
          "documentation":"<p>The ID of the KMS key used to encrypt the private key of the certificate.</p>",
          "locationName":"encryptionKmsKeyId"
        }
      }
    },
    "AssociateIamInstanceProfileRequest":{
      "type":"structure",
      "required":[
        "IamInstanceProfile",
        "InstanceId"
      ],
      "members":{
        "IamInstanceProfile":{
          "shape":"IamInstanceProfileSpecification",
          "documentation":"<p>The IAM instance profile.</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        }
      }
    },
    "AssociateIamInstanceProfileResult":{
      "type":"structure",
      "members":{
        "IamInstanceProfileAssociation":{
          "shape":"IamInstanceProfileAssociation",
          "documentation":"<p>Information about the IAM instance profile association.</p>",
          "locationName":"iamInstanceProfileAssociation"
        }
      }
    },
    "AssociateInstanceEventWindowRequest":{
      "type":"structure",
      "required":[
        "InstanceEventWindowId",
        "AssociationTarget"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceEventWindowId":{
          "shape":"InstanceEventWindowId",
          "documentation":"<p>The ID of the event window.</p>"
        },
        "AssociationTarget":{
          "shape":"InstanceEventWindowAssociationRequest",
          "documentation":"<p>One or more targets associated with the specified event window.</p>"
        }
      }
    },
    "AssociateInstanceEventWindowResult":{
      "type":"structure",
      "members":{
        "InstanceEventWindow":{
          "shape":"InstanceEventWindow",
          "documentation":"<p>Information about the event window.</p>",
          "locationName":"instanceEventWindow"
        }
      }
    },
    "AssociateIpamResourceDiscoveryRequest":{
      "type":"structure",
      "required":[
        "IpamId",
        "IpamResourceDiscoveryId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>An IPAM ID.</p>"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>A resource discovery ID.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>Tag specifications.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A client token.</p>",
          "idempotencyToken":true
        }
      }
    },
    "AssociateIpamResourceDiscoveryResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscoveryAssociation":{
          "shape":"IpamResourceDiscoveryAssociation",
          "documentation":"<p>A resource discovery association. An associated resource discovery is a resource discovery that has been associated with an IPAM.</p>",
          "locationName":"ipamResourceDiscoveryAssociation"
        }
      }
    },
    "AssociateNatGatewayAddressRequest":{
      "type":"structure",
      "required":[
        "NatGatewayId",
        "AllocationIds"
      ],
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>"
        },
        "AllocationIds":{
          "shape":"AllocationIdList",
          "documentation":"<p>The allocation IDs of EIPs that you want to associate with your NAT gateway.</p>",
          "locationName":"AllocationId"
        },
        "PrivateIpAddresses":{
          "shape":"IpList",
          "documentation":"<p>The private IPv4 addresses that you want to assign to the NAT gateway.</p>",
          "locationName":"PrivateIpAddress"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateNatGatewayAddressResult":{
      "type":"structure",
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>",
          "locationName":"natGatewayId"
        },
        "NatGatewayAddresses":{
          "shape":"NatGatewayAddressList",
          "documentation":"<p>The IP addresses.</p>",
          "locationName":"natGatewayAddressSet"
        }
      }
    },
    "AssociateRouteTableRequest":{
      "type":"structure",
      "required":["RouteTableId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table.</p>",
          "locationName":"routeTableId"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "GatewayId":{
          "shape":"RouteGatewayId",
          "documentation":"<p>The ID of the internet gateway or virtual private gateway.</p>"
        }
      }
    },
    "AssociateRouteTableResult":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The route table association ID. This ID is required for disassociating the route table.</p>",
          "locationName":"associationId"
        },
        "AssociationState":{
          "shape":"RouteTableAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"associationState"
        }
      }
    },
    "AssociateSubnetCidrBlockRequest":{
      "type":"structure",
      "required":[
        "Ipv6CidrBlock",
        "SubnetId"
      ],
      "members":{
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block for your subnet. The subnet must have a /64 prefix length.</p>",
          "locationName":"ipv6CidrBlock"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of your subnet.</p>",
          "locationName":"subnetId"
        }
      }
    },
    "AssociateSubnetCidrBlockResult":{
      "type":"structure",
      "members":{
        "Ipv6CidrBlockAssociation":{
          "shape":"SubnetIpv6CidrBlockAssociation",
          "documentation":"<p>Information about the IPv6 association.</p>",
          "locationName":"ipv6CidrBlockAssociation"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        }
      }
    },
    "AssociateTransitGatewayMulticastDomainRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayMulticastDomainId",
        "TransitGatewayAttachmentId",
        "SubnetIds"
      ],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment to associate with the transit gateway multicast domain.</p>"
        },
        "SubnetIds":{
          "shape":"TransitGatewaySubnetIdList",
          "documentation":"<p>The IDs of the subnets to associate with the transit gateway multicast domain.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateTransitGatewayMulticastDomainResult":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"TransitGatewayMulticastDomainAssociations",
          "documentation":"<p>Information about the transit gateway multicast domain associations.</p>",
          "locationName":"associations"
        }
      }
    },
    "AssociateTransitGatewayPolicyTableRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayPolicyTableId",
        "TransitGatewayAttachmentId"
      ],
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The ID of the transit gateway policy table to associate with the transit gateway attachment.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment to associate with the policy table.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateTransitGatewayPolicyTableResult":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"TransitGatewayPolicyTableAssociation",
          "documentation":"<p>Describes the association of a transit gateway and a transit gateway policy table.</p>",
          "locationName":"association"
        }
      }
    },
    "AssociateTransitGatewayRouteTableRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "TransitGatewayAttachmentId"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateTransitGatewayRouteTableResult":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"TransitGatewayAssociation",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"association"
        }
      }
    },
    "AssociateTrunkInterfaceRequest":{
      "type":"structure",
      "required":[
        "BranchInterfaceId",
        "TrunkInterfaceId"
      ],
      "members":{
        "BranchInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the branch network interface.</p>"
        },
        "TrunkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the trunk network interface.</p>"
        },
        "VlanId":{
          "shape":"Integer",
          "documentation":"<p>The ID of the VLAN. This applies to the VLAN protocol.</p>"
        },
        "GreKey":{
          "shape":"Integer",
          "documentation":"<p>The application key. This applies to the GRE protocol.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to Ensure Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AssociateTrunkInterfaceResult":{
      "type":"structure",
      "members":{
        "InterfaceAssociation":{
          "shape":"TrunkInterfaceAssociation",
          "documentation":"<p>Information about the association between the trunk network interface and branch network interface.</p>",
          "locationName":"interfaceAssociation"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to Ensure Idempotency</a>.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "AssociateVpcCidrBlockRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "AmazonProvidedIpv6CidrBlock":{
          "shape":"Boolean",
          "documentation":"<p>Requests an Amazon-provided IPv6 CIDR block with a /56 prefix length for the VPC. You cannot specify the range of IPv6 addresses, or the size of the CIDR block.</p>",
          "locationName":"amazonProvidedIpv6CidrBlock"
        },
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>An IPv4 CIDR block to associate with the VPC.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "Ipv6CidrBlockNetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The name of the location from which we advertise the IPV6 CIDR block. Use this parameter to limit the CIDR block to this location.</p> <p> You must set <code>AmazonProvidedIpv6CidrBlock</code> to <code>true</code> to use this parameter.</p> <p> You can have one IPv6 CIDR block association per network border group.</p>"
        },
        "Ipv6Pool":{
          "shape":"Ipv6PoolEc2Id",
          "documentation":"<p>The ID of an IPv6 address pool from which to allocate the IPv6 CIDR block.</p>"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>An IPv6 CIDR block from the IPv6 address pool. You must also specify <code>Ipv6Pool</code> in the request.</p> <p>To let Amazon choose the IPv6 CIDR block for you, omit this parameter.</p>"
        },
        "Ipv4IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>Associate a CIDR allocated from an IPv4 IPAM pool to a VPC. For more information about Amazon VPC IP Address Manager (IPAM), see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
        },
        "Ipv4NetmaskLength":{
          "shape":"NetmaskLength",
          "documentation":"<p>The netmask length of the IPv4 CIDR you would like to associate from an Amazon VPC IP Address Manager (IPAM) pool. For more information about IPAM, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
        },
        "Ipv6IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>Associates a CIDR allocated from an IPv6 IPAM pool to a VPC. For more information about Amazon VPC IP Address Manager (IPAM), see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
        },
        "Ipv6NetmaskLength":{
          "shape":"NetmaskLength",
          "documentation":"<p>The netmask length of the IPv6 CIDR you would like to associate from an Amazon VPC IP Address Manager (IPAM) pool. For more information about IPAM, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
        }
      }
    },
    "AssociateVpcCidrBlockResult":{
      "type":"structure",
      "members":{
        "Ipv6CidrBlockAssociation":{
          "shape":"VpcIpv6CidrBlockAssociation",
          "documentation":"<p>Information about the IPv6 CIDR block association.</p>",
          "locationName":"ipv6CidrBlockAssociation"
        },
        "CidrBlockAssociation":{
          "shape":"VpcCidrBlockAssociation",
          "documentation":"<p>Information about the IPv4 CIDR block association.</p>",
          "locationName":"cidrBlockAssociation"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "AssociatedNetworkType":{
      "type":"string",
      "enum":["vpc"]
    },
    "AssociatedRole":{
      "type":"structure",
      "members":{
        "AssociatedRoleArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The ARN of the associated IAM role.</p>",
          "locationName":"associatedRoleArn"
        },
        "CertificateS3BucketName":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket in which the Amazon S3 object is stored.</p>",
          "locationName":"certificateS3BucketName"
        },
        "CertificateS3ObjectKey":{
          "shape":"String",
          "documentation":"<p>The key of the Amazon S3 object ey where the certificate, certificate chain, and encrypted private key bundle is stored. The object key is formated as follows: <code>role_arn</code>/<code>certificate_arn</code>. </p>",
          "locationName":"certificateS3ObjectKey"
        },
        "EncryptionKmsKeyId":{
          "shape":"String",
          "documentation":"<p>The ID of the KMS customer master key (CMK) used to encrypt the private key.</p>",
          "locationName":"encryptionKmsKeyId"
        }
      },
      "documentation":"<p>Information about the associated IAM roles.</p>"
    },
    "AssociatedRolesList":{
      "type":"list",
      "member":{
        "shape":"AssociatedRole",
        "locationName":"item"
      }
    },
    "AssociatedTargetNetwork":{
      "type":"structure",
      "members":{
        "NetworkId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"networkId"
        },
        "NetworkType":{
          "shape":"AssociatedNetworkType",
          "documentation":"<p>The target network type.</p>",
          "locationName":"networkType"
        }
      },
      "documentation":"<p>Describes a target network that is associated with a Client VPN endpoint. A target network is a subnet in a VPC.</p>"
    },
    "AssociatedTargetNetworkSet":{
      "type":"list",
      "member":{
        "shape":"AssociatedTargetNetwork",
        "locationName":"item"
      }
    },
    "AssociationIdList":{
      "type":"list",
      "member":{
        "shape":"IamInstanceProfileAssociationId",
        "locationName":"AssociationId"
      }
    },
    "AssociationStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"AssociationStatusCode",
          "documentation":"<p>The state of the target network association.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message about the status of the target network association, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the state of a target network association.</p>"
    },
    "AssociationStatusCode":{
      "type":"string",
      "enum":[
        "associating",
        "associated",
        "association-failed",
        "disassociating",
        "disassociated"
      ]
    },
    "AthenaIntegration":{
      "type":"structure",
      "required":[
        "IntegrationResultS3DestinationArn",
        "PartitionLoadFrequency"
      ],
      "members":{
        "IntegrationResultS3DestinationArn":{
          "shape":"String",
          "documentation":"<p>The location in Amazon S3 to store the generated CloudFormation template.</p>"
        },
        "PartitionLoadFrequency":{
          "shape":"PartitionLoadFrequency",
          "documentation":"<p>The schedule for adding new partitions to the table.</p>"
        },
        "PartitionStartDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The start date for the partition.</p>"
        },
        "PartitionEndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The end date for the partition.</p>"
        }
      },
      "documentation":"<p>Describes integration options for Amazon Athena.</p>"
    },
    "AthenaIntegrationsSet":{
      "type":"list",
      "member":{
        "shape":"AthenaIntegration",
        "locationName":"item"
      },
      "max":10,
      "min":1
    },
    "AttachClassicLinkVpcRequest":{
      "type":"structure",
      "required":[
        "Groups",
        "InstanceId",
        "VpcId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Groups":{
          "shape":"GroupIdStringList",
          "documentation":"<p>The ID of one or more of the VPC's security groups. You cannot specify security groups from a different VPC.</p>",
          "locationName":"SecurityGroupId"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of an EC2-Classic instance to link to the ClassicLink-enabled VPC.</p>",
          "locationName":"instanceId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of a ClassicLink-enabled VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "AttachClassicLinkVpcResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "AttachInternetGatewayRequest":{
      "type":"structure",
      "required":[
        "InternetGatewayId",
        "VpcId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InternetGatewayId":{
          "shape":"InternetGatewayId",
          "documentation":"<p>The ID of the internet gateway.</p>",
          "locationName":"internetGatewayId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "AttachNetworkInterfaceRequest":{
      "type":"structure",
      "required":[
        "DeviceIndex",
        "InstanceId",
        "NetworkInterfaceId"
      ],
      "members":{
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the device for the network interface attachment.</p>",
          "locationName":"deviceIndex"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card. Some instance types support multiple network cards. The primary network interface must be assigned to network card index 0. The default is network card index 0.</p>"
        },
        "EnaSrdSpecification":{
          "shape":"EnaSrdSpecification",
          "documentation":"<p>Configures ENA Express for the network interface that this action attaches to the instance.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for AttachNetworkInterface.</p>"
    },
    "AttachNetworkInterfaceResult":{
      "type":"structure",
      "members":{
        "AttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface attachment.</p>",
          "locationName":"attachmentId"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card.</p>",
          "locationName":"networkCardIndex"
        }
      },
      "documentation":"<p>Contains the output of AttachNetworkInterface.</p>"
    },
    "AttachVerifiedAccessTrustProviderRequest":{
      "type":"structure",
      "required":[
        "VerifiedAccessInstanceId",
        "VerifiedAccessTrustProviderId"
      ],
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "VerifiedAccessTrustProviderId":{
          "shape":"VerifiedAccessTrustProviderId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AttachVerifiedAccessTrustProviderResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProvider":{
          "shape":"VerifiedAccessTrustProvider",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"verifiedAccessTrustProvider"
        },
        "VerifiedAccessInstance":{
          "shape":"VerifiedAccessInstance",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstance"
        }
      }
    },
    "AttachVolumeRequest":{
      "type":"structure",
      "required":[
        "Device",
        "InstanceId",
        "VolumeId"
      ],
      "members":{
        "Device":{
          "shape":"String",
          "documentation":"<p>The device name (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the EBS volume. The volume and instance must be within the same Availability Zone.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "AttachVpnGatewayRequest":{
      "type":"structure",
      "required":[
        "VpcId",
        "VpnGatewayId"
      ],
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "VpnGatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for AttachVpnGateway.</p>"
    },
    "AttachVpnGatewayResult":{
      "type":"structure",
      "members":{
        "VpcAttachment":{
          "shape":"VpcAttachment",
          "documentation":"<p>Information about the attachment.</p>",
          "locationName":"attachment"
        }
      },
      "documentation":"<p>Contains the output of AttachVpnGateway.</p>"
    },
    "AttachmentEnaSrdSpecification":{
      "type":"structure",
      "members":{
        "EnaSrdEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether ENA Express is enabled for the network interface that's attached to the instance.</p>",
          "locationName":"enaSrdEnabled"
        },
        "EnaSrdUdpSpecification":{
          "shape":"AttachmentEnaSrdUdpSpecification",
          "documentation":"<p>ENA Express configuration for UDP network traffic.</p>",
          "locationName":"enaSrdUdpSpecification"
        }
      },
      "documentation":"<p>Describes the ENA Express configuration for the network interface that's attached to the instance.</p>"
    },
    "AttachmentEnaSrdUdpSpecification":{
      "type":"structure",
      "members":{
        "EnaSrdUdpEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether UDP traffic to and from the instance uses ENA Express. To specify this setting, you must first enable ENA Express.</p>",
          "locationName":"enaSrdUdpEnabled"
        }
      },
      "documentation":"<p>Describes the ENA Express configuration for UDP traffic on the network interface that's attached to the instance.</p>"
    },
    "AttachmentStatus":{
      "type":"string",
      "enum":[
        "attaching",
        "attached",
        "detaching",
        "detached"
      ]
    },
    "AttributeBooleanValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"Boolean",
          "documentation":"<p>The attribute value. The valid values are <code>true</code> or <code>false</code>.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>Describes a value for a resource attribute that is a Boolean value.</p>"
    },
    "AttributeValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The attribute value. The value is case-sensitive.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>Describes a value for a resource attribute that is a String.</p>"
    },
    "AuthorizationRule":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint with which the authorization rule is associated.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the authorization rule.</p>",
          "locationName":"description"
        },
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the Active Directory group to which the authorization rule grants access.</p>",
          "locationName":"groupId"
        },
        "AccessAll":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the authorization rule grants access to all clients.</p>",
          "locationName":"accessAll"
        },
        "DestinationCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the network to which the authorization rule applies.</p>",
          "locationName":"destinationCidr"
        },
        "Status":{
          "shape":"ClientVpnAuthorizationRuleStatus",
          "documentation":"<p>The current state of the authorization rule.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Information about an authorization rule.</p>"
    },
    "AuthorizationRuleSet":{
      "type":"list",
      "member":{
        "shape":"AuthorizationRule",
        "locationName":"item"
      }
    },
    "AuthorizeClientVpnIngressRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "TargetNetworkCidr"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "TargetNetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the network for which access is being authorized.</p>"
        },
        "AccessGroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the group to grant access to, for example, the Active Directory group or identity provider (IdP) group. Required if <code>AuthorizeAllGroups</code> is <code>false</code> or not specified.</p>"
        },
        "AuthorizeAllGroups":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to grant access to all clients. Specify <code>true</code> to grant all clients who successfully establish a VPN connection access to the network. Must be set to <code>true</code> if <code>AccessGroupId</code> is not specified.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the authorization rule.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "AuthorizeClientVpnIngressResult":{
      "type":"structure",
      "members":{
        "Status":{
          "shape":"ClientVpnAuthorizationRuleStatus",
          "documentation":"<p>The current state of the authorization rule.</p>",
          "locationName":"status"
        }
      }
    },
    "AuthorizeSecurityGroupEgressRequest":{
      "type":"structure",
      "required":["GroupId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The sets of IP permissions. You can't specify a destination security group and a CIDR IP address range in the same set of permissions.</p>",
          "locationName":"ipPermissions"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags applied to the security group rule.</p>",
          "locationName":"TagSpecification"
        },
        "CidrIp":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the CIDR.</p>",
          "locationName":"cidrIp"
        },
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the port.</p>",
          "locationName":"fromPort"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the protocol name or number.</p>",
          "locationName":"ipProtocol"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the port.</p>",
          "locationName":"toPort"
        },
        "SourceSecurityGroupName":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify a destination security group.</p>",
          "locationName":"sourceSecurityGroupName"
        },
        "SourceSecurityGroupOwnerId":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify a destination security group.</p>",
          "locationName":"sourceSecurityGroupOwnerId"
        }
      }
    },
    "AuthorizeSecurityGroupEgressResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        },
        "SecurityGroupRules":{
          "shape":"SecurityGroupRuleList",
          "documentation":"<p>Information about the outbound (egress) security group rules that were added.</p>",
          "locationName":"securityGroupRuleSet"
        }
      }
    },
    "AuthorizeSecurityGroupIngressRequest":{
      "type":"structure",
      "members":{
        "CidrIp":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR format. You can't specify this parameter when specifying a source security group. To specify an IPv6 address range, use a set of IP permissions.</p> <p>Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.</p>"
        },
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the start of the port range. If the protocol is ICMP, this is the type number. A value of -1 indicates all ICMP types. If you specify all ICMP types, you must specify all ICMP codes.</p> <p>Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.</p>"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "GroupName":{
          "shape":"SecurityGroupName",
          "documentation":"<p>[EC2-Classic, default VPC] The name of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The sets of IP permissions.</p>"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>The IP protocol name (<code>tcp</code>, <code>udp</code>, <code>icmp</code>) or number (see <a href=\"http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers</a>). To specify <code>icmpv6</code>, use a set of IP permissions.</p> <p>[VPC only] Use <code>-1</code> to specify all protocols. If you specify <code>-1</code> or a protocol other than <code>tcp</code>, <code>udp</code>, or <code>icmp</code>, traffic on all ports is allowed, regardless of any ports you specify.</p> <p>Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.</p>"
        },
        "SourceSecurityGroupName":{
          "shape":"String",
          "documentation":"<p>[EC2-Classic, default VPC] The name of the source security group. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the start of the port range, the IP protocol, and the end of the port range. Creates rules that grant full ICMP, UDP, and TCP access. To create a rule with a specific IP protocol and port range, use a set of IP permissions instead. For EC2-VPC, the source security group must be in the same VPC.</p>"
        },
        "SourceSecurityGroupOwnerId":{
          "shape":"String",
          "documentation":"<p>[nondefault VPC] The Amazon Web Services account ID for the source security group, if the source security group is in a different account. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the IP protocol, the start of the port range, and the end of the port range. Creates rules that grant full ICMP, UDP, and TCP access. To create a rule with a specific IP protocol and port range, use a set of IP permissions instead.</p>"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the end of the port range. If the protocol is ICMP, this is the code. A value of -1 indicates all ICMP codes. If you specify all ICMP types, you must specify all ICMP codes.</p> <p>Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>[VPC Only] The tags applied to the security group rule.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "AuthorizeSecurityGroupIngressResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        },
        "SecurityGroupRules":{
          "shape":"SecurityGroupRuleList",
          "documentation":"<p>Information about the inbound (ingress) security group rules that were added.</p>",
          "locationName":"securityGroupRuleSet"
        }
      }
    },
    "AutoAcceptSharedAssociationsValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "AutoAcceptSharedAttachmentsValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "AutoPlacement":{
      "type":"string",
      "enum":[
        "on",
        "off"
      ]
    },
    "AutoRecoveryFlag":{"type":"boolean"},
    "AvailabilityZone":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"AvailabilityZoneState",
          "documentation":"<p>The state of the Availability Zone, Local Zone, or Wavelength Zone. This value is always <code>available</code>.</p>",
          "locationName":"zoneState"
        },
        "OptInStatus":{
          "shape":"AvailabilityZoneOptInStatus",
          "documentation":"<p>For Availability Zones, this parameter always has the value of <code>opt-in-not-required</code>.</p> <p>For Local Zones and Wavelength Zones, this parameter is the opt-in status. The possible values are <code>opted-in</code>, and <code>not-opted-in</code>.</p>",
          "locationName":"optInStatus"
        },
        "Messages":{
          "shape":"AvailabilityZoneMessageList",
          "documentation":"<p>Any messages about the Availability Zone, Local Zone, or Wavelength Zone.</p>",
          "locationName":"messageSet"
        },
        "RegionName":{
          "shape":"String",
          "documentation":"<p>The name of the Region.</p>",
          "locationName":"regionName"
        },
        "ZoneName":{
          "shape":"String",
          "documentation":"<p>The name of the Availability Zone, Local Zone, or Wavelength Zone.</p>",
          "locationName":"zoneName"
        },
        "ZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the Availability Zone, Local Zone, or Wavelength Zone.</p>",
          "locationName":"zoneId"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p> For Availability Zones, this parameter has the same value as the Region name.</p> <p>For Local Zones, the name of the associated group, for example <code>us-west-2-lax-1</code>.</p> <p>For Wavelength Zones, the name of the associated group, for example <code>us-east-1-wl1-bos-wlz-1</code>.</p>",
          "locationName":"groupName"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The name of the network border group.</p>",
          "locationName":"networkBorderGroup"
        },
        "ZoneType":{
          "shape":"String",
          "documentation":"<p>The type of zone. The valid values are <code>availability-zone</code>, <code>local-zone</code>, and <code>wavelength-zone</code>.</p>",
          "locationName":"zoneType"
        },
        "ParentZoneName":{
          "shape":"String",
          "documentation":"<p>The name of the zone that handles some of the Local Zone or Wavelength Zone control plane operations, such as API calls.</p>",
          "locationName":"parentZoneName"
        },
        "ParentZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the zone that handles some of the Local Zone or Wavelength Zone control plane operations, such as API calls.</p>",
          "locationName":"parentZoneId"
        }
      },
      "documentation":"<p>Describes Availability Zones, Local Zones, and Wavelength Zones.</p>"
    },
    "AvailabilityZoneList":{
      "type":"list",
      "member":{
        "shape":"AvailabilityZone",
        "locationName":"item"
      }
    },
    "AvailabilityZoneMessage":{
      "type":"structure",
      "members":{
        "Message":{
          "shape":"String",
          "documentation":"<p>The message about the Availability Zone, Local Zone, or Wavelength Zone.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes a message about an Availability Zone, Local Zone, or Wavelength Zone.</p>"
    },
    "AvailabilityZoneMessageList":{
      "type":"list",
      "member":{
        "shape":"AvailabilityZoneMessage",
        "locationName":"item"
      }
    },
    "AvailabilityZoneOptInStatus":{
      "type":"string",
      "enum":[
        "opt-in-not-required",
        "opted-in",
        "not-opted-in"
      ]
    },
    "AvailabilityZoneState":{
      "type":"string",
      "enum":[
        "available",
        "information",
        "impaired",
        "unavailable"
      ]
    },
    "AvailabilityZoneStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"AvailabilityZone"
      }
    },
    "AvailableCapacity":{
      "type":"structure",
      "members":{
        "AvailableInstanceCapacity":{
          "shape":"AvailableInstanceCapacityList",
          "documentation":"<p>The number of instances that can be launched onto the Dedicated Host depending on the host's available capacity. For Dedicated Hosts that support multiple instance types, this parameter represents the number of instances for each instance size that is supported on the host.</p>",
          "locationName":"availableInstanceCapacity"
        },
        "AvailableVCpus":{
          "shape":"Integer",
          "documentation":"<p>The number of vCPUs available for launching instances onto the Dedicated Host.</p>",
          "locationName":"availableVCpus"
        }
      },
      "documentation":"<p>The capacity information for instances that can be launched onto the Dedicated Host. </p>"
    },
    "AvailableInstanceCapacityList":{
      "type":"list",
      "member":{
        "shape":"InstanceCapacity",
        "locationName":"item"
      }
    },
    "BareMetal":{
      "type":"string",
      "enum":[
        "included",
        "required",
        "excluded"
      ]
    },
    "BareMetalFlag":{"type":"boolean"},
    "BaselineBandwidthInMbps":{"type":"integer"},
    "BaselineEbsBandwidthMbps":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum baseline bandwidth, in Mbps. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum baseline bandwidth, in Mbps. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum baseline bandwidth to Amazon EBS, in Mbps. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-optimized.html\">Amazon EBS–optimized instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "BaselineEbsBandwidthMbpsRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum baseline bandwidth, in Mbps. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum baseline bandwidth, in Mbps. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum baseline bandwidth to Amazon EBS, in Mbps. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-optimized.html\">Amazon EBS–optimized instances</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "BaselineIops":{"type":"integer"},
    "BaselineThroughputInMBps":{"type":"double"},
    "BatchState":{
      "type":"string",
      "enum":[
        "submitted",
        "active",
        "cancelled",
        "failed",
        "cancelled_running",
        "cancelled_terminating",
        "modifying"
      ]
    },
    "BgpStatus":{
      "type":"string",
      "enum":[
        "up",
        "down"
      ]
    },
    "BillingProductList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "Blob":{"type":"blob"},
    "BlobAttributeValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"Blob",
          "locationName":"value"
        }
      }
    },
    "BlockDeviceMapping":{
      "type":"structure",
      "members":{
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The device name (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p>",
          "locationName":"deviceName"
        },
        "VirtualName":{
          "shape":"String",
          "documentation":"<p>The virtual device name (<code>ephemeral</code>N). Instance store volumes are numbered starting from 0. An instance type with 2 available instance store volumes can specify mappings for <code>ephemeral0</code> and <code>ephemeral1</code>. The number of available instance store volumes depends on the instance type. After you connect to the instance, you must mount the volume.</p> <p>NVMe instance store volumes are automatically enumerated and assigned a device name. Including them in your block device mapping has no effect.</p> <p>Constraints: For M3 instances, you must specify instance store volumes in the block device mapping for the instance. When you launch an M3 instance, we ignore any instance store volumes specified in the block device mapping for the AMI.</p>",
          "locationName":"virtualName"
        },
        "Ebs":{
          "shape":"EbsBlockDevice",
          "documentation":"<p>Parameters used to automatically set up EBS volumes when the instance is launched.</p>",
          "locationName":"ebs"
        },
        "NoDevice":{
          "shape":"String",
          "documentation":"<p>To omit the device from the block device mapping, specify an empty string. When this property is specified, the device is removed from the block device mapping regardless of the assigned value.</p>",
          "locationName":"noDevice"
        }
      },
      "documentation":"<p>Describes a block device mapping, which defines the EBS volumes and instance store volumes to attach to an instance at launch.</p>"
    },
    "BlockDeviceMappingList":{
      "type":"list",
      "member":{
        "shape":"BlockDeviceMapping",
        "locationName":"item"
      }
    },
    "BlockDeviceMappingRequestList":{
      "type":"list",
      "member":{
        "shape":"BlockDeviceMapping",
        "locationName":"BlockDeviceMapping"
      }
    },
    "Boolean":{"type":"boolean"},
    "BootModeType":{
      "type":"string",
      "enum":[
        "legacy-bios",
        "uefi"
      ]
    },
    "BootModeTypeList":{
      "type":"list",
      "member":{
        "shape":"BootModeType",
        "locationName":"item"
      }
    },
    "BootModeValues":{
      "type":"string",
      "enum":[
        "legacy-bios",
        "uefi"
      ]
    },
    "BoxedDouble":{"type":"double"},
    "BundleId":{"type":"string"},
    "BundleIdStringList":{
      "type":"list",
      "member":{
        "shape":"BundleId",
        "locationName":"BundleId"
      }
    },
    "BundleInstanceRequest":{
      "type":"structure",
      "required":[
        "InstanceId",
        "Storage"
      ],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance to bundle.</p> <p>Type: String</p> <p>Default: None</p> <p>Required: Yes</p>"
        },
        "Storage":{
          "shape":"Storage",
          "documentation":"<p>The bucket in which to store the AMI. You can specify a bucket that you already own or a new bucket that Amazon EC2 creates on your behalf. If you specify a bucket that belongs to someone else, Amazon EC2 returns an error.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for BundleInstance.</p>"
    },
    "BundleInstanceResult":{
      "type":"structure",
      "members":{
        "BundleTask":{
          "shape":"BundleTask",
          "documentation":"<p>Information about the bundle task.</p>",
          "locationName":"bundleInstanceTask"
        }
      },
      "documentation":"<p>Contains the output of BundleInstance.</p>"
    },
    "BundleTask":{
      "type":"structure",
      "members":{
        "BundleId":{
          "shape":"String",
          "documentation":"<p>The ID of the bundle task.</p>",
          "locationName":"bundleId"
        },
        "BundleTaskError":{
          "shape":"BundleTaskError",
          "documentation":"<p>If the task fails, a description of the error.</p>",
          "locationName":"error"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance associated with this bundle task.</p>",
          "locationName":"instanceId"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The level of task completion, as a percent (for example, 20%).</p>",
          "locationName":"progress"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The time this task started.</p>",
          "locationName":"startTime"
        },
        "State":{
          "shape":"BundleTaskState",
          "documentation":"<p>The state of the task.</p>",
          "locationName":"state"
        },
        "Storage":{
          "shape":"Storage",
          "documentation":"<p>The Amazon S3 storage locations.</p>",
          "locationName":"storage"
        },
        "UpdateTime":{
          "shape":"DateTime",
          "documentation":"<p>The time of the most recent update for the task.</p>",
          "locationName":"updateTime"
        }
      },
      "documentation":"<p>Describes a bundle task.</p>"
    },
    "BundleTaskError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes an error for <a>BundleInstance</a>.</p>"
    },
    "BundleTaskList":{
      "type":"list",
      "member":{
        "shape":"BundleTask",
        "locationName":"item"
      }
    },
    "BundleTaskState":{
      "type":"string",
      "enum":[
        "pending",
        "waiting-for-shutdown",
        "bundling",
        "storing",
        "cancelling",
        "complete",
        "failed"
      ]
    },
    "BurstablePerformance":{
      "type":"string",
      "enum":[
        "included",
        "required",
        "excluded"
      ]
    },
    "BurstablePerformanceFlag":{"type":"boolean"},
    "ByoipCidr":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The address range, in CIDR notation.</p>",
          "locationName":"cidr"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the address range.</p>",
          "locationName":"description"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>Upon success, contains the ID of the address pool. Otherwise, contains an error message.</p>",
          "locationName":"statusMessage"
        },
        "State":{
          "shape":"ByoipCidrState",
          "documentation":"<p>The state of the address pool.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Information about an address range that is provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP).</p>"
    },
    "ByoipCidrSet":{
      "type":"list",
      "member":{
        "shape":"ByoipCidr",
        "locationName":"item"
      }
    },
    "ByoipCidrState":{
      "type":"string",
      "enum":[
        "advertised",
        "deprovisioned",
        "failed-deprovision",
        "failed-provision",
        "pending-deprovision",
        "pending-provision",
        "provisioned",
        "provisioned-not-publicly-advertisable"
      ]
    },
    "CancelBatchErrorCode":{
      "type":"string",
      "enum":[
        "fleetRequestIdDoesNotExist",
        "fleetRequestIdMalformed",
        "fleetRequestNotInCancellableState",
        "unexpectedError"
      ]
    },
    "CancelBundleTaskRequest":{
      "type":"structure",
      "required":["BundleId"],
      "members":{
        "BundleId":{
          "shape":"BundleId",
          "documentation":"<p>The ID of the bundle task.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for CancelBundleTask.</p>"
    },
    "CancelBundleTaskResult":{
      "type":"structure",
      "members":{
        "BundleTask":{
          "shape":"BundleTask",
          "documentation":"<p>Information about the bundle task.</p>",
          "locationName":"bundleInstanceTask"
        }
      },
      "documentation":"<p>Contains the output of CancelBundleTask.</p>"
    },
    "CancelCapacityReservationFleetError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"CancelCapacityReservationFleetErrorCode",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"CancelCapacityReservationFleetErrorMessage",
          "documentation":"<p>The error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes a Capacity Reservation Fleet cancellation error.</p>"
    },
    "CancelCapacityReservationFleetErrorCode":{"type":"string"},
    "CancelCapacityReservationFleetErrorMessage":{"type":"string"},
    "CancelCapacityReservationFleetsRequest":{
      "type":"structure",
      "required":["CapacityReservationFleetIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "CapacityReservationFleetIds":{
          "shape":"CapacityReservationFleetIdSet",
          "documentation":"<p>The IDs of the Capacity Reservation Fleets to cancel.</p>",
          "locationName":"CapacityReservationFleetId"
        }
      }
    },
    "CancelCapacityReservationFleetsResult":{
      "type":"structure",
      "members":{
        "SuccessfulFleetCancellations":{
          "shape":"CapacityReservationFleetCancellationStateSet",
          "documentation":"<p>Information about the Capacity Reservation Fleets that were successfully cancelled.</p>",
          "locationName":"successfulFleetCancellationSet"
        },
        "FailedFleetCancellations":{
          "shape":"FailedCapacityReservationFleetCancellationResultSet",
          "documentation":"<p>Information about the Capacity Reservation Fleets that could not be cancelled.</p>",
          "locationName":"failedFleetCancellationSet"
        }
      }
    },
    "CancelCapacityReservationRequest":{
      "type":"structure",
      "required":["CapacityReservationId"],
      "members":{
        "CapacityReservationId":{
          "shape":"CapacityReservationId",
          "documentation":"<p>The ID of the Capacity Reservation to be cancelled.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CancelCapacityReservationResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "CancelConversionRequest":{
      "type":"structure",
      "required":["ConversionTaskId"],
      "members":{
        "ConversionTaskId":{
          "shape":"ConversionTaskId",
          "documentation":"<p>The ID of the conversion task.</p>",
          "locationName":"conversionTaskId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "ReasonMessage":{
          "shape":"String",
          "documentation":"<p>The reason for canceling the conversion task.</p>",
          "locationName":"reasonMessage"
        }
      }
    },
    "CancelExportTaskRequest":{
      "type":"structure",
      "required":["ExportTaskId"],
      "members":{
        "ExportTaskId":{
          "shape":"ExportVmTaskId",
          "documentation":"<p>The ID of the export task. This is the ID returned by <code>CreateInstanceExportTask</code>.</p>",
          "locationName":"exportTaskId"
        }
      }
    },
    "CancelImageLaunchPermissionRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI that was shared with your Amazon Web Services account.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CancelImageLaunchPermissionResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "CancelImportTaskRequest":{
      "type":"structure",
      "members":{
        "CancelReason":{
          "shape":"String",
          "documentation":"<p>The reason for canceling the task.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ImportTaskId":{
          "shape":"ImportTaskId",
          "documentation":"<p>The ID of the import image or import snapshot task to be canceled.</p>"
        }
      }
    },
    "CancelImportTaskResult":{
      "type":"structure",
      "members":{
        "ImportTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the task being canceled.</p>",
          "locationName":"importTaskId"
        },
        "PreviousState":{
          "shape":"String",
          "documentation":"<p>The current state of the task being canceled.</p>",
          "locationName":"previousState"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The current state of the task being canceled.</p>",
          "locationName":"state"
        }
      }
    },
    "CancelReservedInstancesListingRequest":{
      "type":"structure",
      "required":["ReservedInstancesListingId"],
      "members":{
        "ReservedInstancesListingId":{
          "shape":"ReservedInstancesListingId",
          "documentation":"<p>The ID of the Reserved Instance listing.</p>",
          "locationName":"reservedInstancesListingId"
        }
      },
      "documentation":"<p>Contains the parameters for CancelReservedInstancesListing.</p>"
    },
    "CancelReservedInstancesListingResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesListings":{
          "shape":"ReservedInstancesListingList",
          "documentation":"<p>The Reserved Instance listing.</p>",
          "locationName":"reservedInstancesListingsSet"
        }
      },
      "documentation":"<p>Contains the output of CancelReservedInstancesListing.</p>"
    },
    "CancelSpotFleetRequestsError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"CancelBatchErrorCode",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The description for the error code.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes a Spot Fleet error.</p>"
    },
    "CancelSpotFleetRequestsErrorItem":{
      "type":"structure",
      "members":{
        "Error":{
          "shape":"CancelSpotFleetRequestsError",
          "documentation":"<p>The error.</p>",
          "locationName":"error"
        },
        "SpotFleetRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        }
      },
      "documentation":"<p>Describes a Spot Fleet request that was not successfully canceled.</p>"
    },
    "CancelSpotFleetRequestsErrorSet":{
      "type":"list",
      "member":{
        "shape":"CancelSpotFleetRequestsErrorItem",
        "locationName":"item"
      }
    },
    "CancelSpotFleetRequestsRequest":{
      "type":"structure",
      "required":[
        "SpotFleetRequestIds",
        "TerminateInstances"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "SpotFleetRequestIds":{
          "shape":"SpotFleetRequestIdList",
          "documentation":"<p>The IDs of the Spot Fleet requests.</p>",
          "locationName":"spotFleetRequestId"
        },
        "TerminateInstances":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to terminate instances for a Spot Fleet request if it is canceled successfully.</p>",
          "locationName":"terminateInstances"
        }
      },
      "documentation":"<p>Contains the parameters for CancelSpotFleetRequests.</p>"
    },
    "CancelSpotFleetRequestsResponse":{
      "type":"structure",
      "members":{
        "SuccessfulFleetRequests":{
          "shape":"CancelSpotFleetRequestsSuccessSet",
          "documentation":"<p>Information about the Spot Fleet requests that are successfully canceled.</p>",
          "locationName":"successfulFleetRequestSet"
        },
        "UnsuccessfulFleetRequests":{
          "shape":"CancelSpotFleetRequestsErrorSet",
          "documentation":"<p>Information about the Spot Fleet requests that are not successfully canceled.</p>",
          "locationName":"unsuccessfulFleetRequestSet"
        }
      },
      "documentation":"<p>Contains the output of CancelSpotFleetRequests.</p>"
    },
    "CancelSpotFleetRequestsSuccessItem":{
      "type":"structure",
      "members":{
        "CurrentSpotFleetRequestState":{
          "shape":"BatchState",
          "documentation":"<p>The current state of the Spot Fleet request.</p>",
          "locationName":"currentSpotFleetRequestState"
        },
        "PreviousSpotFleetRequestState":{
          "shape":"BatchState",
          "documentation":"<p>The previous state of the Spot Fleet request.</p>",
          "locationName":"previousSpotFleetRequestState"
        },
        "SpotFleetRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        }
      },
      "documentation":"<p>Describes a Spot Fleet request that was successfully canceled.</p>"
    },
    "CancelSpotFleetRequestsSuccessSet":{
      "type":"list",
      "member":{
        "shape":"CancelSpotFleetRequestsSuccessItem",
        "locationName":"item"
      }
    },
    "CancelSpotInstanceRequestState":{
      "type":"string",
      "enum":[
        "active",
        "open",
        "closed",
        "cancelled",
        "completed"
      ]
    },
    "CancelSpotInstanceRequestsRequest":{
      "type":"structure",
      "required":["SpotInstanceRequestIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "SpotInstanceRequestIds":{
          "shape":"SpotInstanceRequestIdList",
          "documentation":"<p>One or more Spot Instance request IDs.</p>",
          "locationName":"SpotInstanceRequestId"
        }
      },
      "documentation":"<p>Contains the parameters for CancelSpotInstanceRequests.</p>"
    },
    "CancelSpotInstanceRequestsResult":{
      "type":"structure",
      "members":{
        "CancelledSpotInstanceRequests":{
          "shape":"CancelledSpotInstanceRequestList",
          "documentation":"<p>One or more Spot Instance requests.</p>",
          "locationName":"spotInstanceRequestSet"
        }
      },
      "documentation":"<p>Contains the output of CancelSpotInstanceRequests.</p>"
    },
    "CancelledSpotInstanceRequest":{
      "type":"structure",
      "members":{
        "SpotInstanceRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Instance request.</p>",
          "locationName":"spotInstanceRequestId"
        },
        "State":{
          "shape":"CancelSpotInstanceRequestState",
          "documentation":"<p>The state of the Spot Instance request.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a request to cancel a Spot Instance.</p>"
    },
    "CancelledSpotInstanceRequestList":{
      "type":"list",
      "member":{
        "shape":"CancelledSpotInstanceRequest",
        "locationName":"item"
      }
    },
    "CapacityAllocation":{
      "type":"structure",
      "members":{
        "AllocationType":{
          "shape":"AllocationType",
          "documentation":"<p>The usage type. <code>used</code> indicates that the instance capacity is in use by instances that are running in the Capacity Reservation.</p>",
          "locationName":"allocationType"
        },
        "Count":{
          "shape":"Integer",
          "documentation":"<p>The amount of instance capacity associated with the usage. For example a value of <code>4</code> indicates that instance capacity for 4 instances is currently in use.</p>",
          "locationName":"count"
        }
      },
      "documentation":"<p>Information about instance capacity usage for a Capacity Reservation.</p>"
    },
    "CapacityAllocations":{
      "type":"list",
      "member":{
        "shape":"CapacityAllocation",
        "locationName":"item"
      }
    },
    "CapacityReservation":{
      "type":"structure",
      "members":{
        "CapacityReservationId":{
          "shape":"String",
          "documentation":"<p>The ID of the Capacity Reservation.</p>",
          "locationName":"capacityReservationId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the Capacity Reservation.</p>",
          "locationName":"ownerId"
        },
        "CapacityReservationArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Capacity Reservation.</p>",
          "locationName":"capacityReservationArn"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The Availability Zone ID of the Capacity Reservation.</p>",
          "locationName":"availabilityZoneId"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The type of instance for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"instanceType"
        },
        "InstancePlatform":{
          "shape":"CapacityReservationInstancePlatform",
          "documentation":"<p>The type of operating system for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"instancePlatform"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the capacity is reserved.</p>",
          "locationName":"availabilityZone"
        },
        "Tenancy":{
          "shape":"CapacityReservationTenancy",
          "documentation":"<p>Indicates the tenancy of the Capacity Reservation. A Capacity Reservation can have one of the following tenancy settings:</p> <ul> <li> <p> <code>default</code> - The Capacity Reservation is created on hardware that is shared with other Amazon Web Services accounts.</p> </li> <li> <p> <code>dedicated</code> - The Capacity Reservation is created on single-tenant hardware that is dedicated to a single Amazon Web Services account.</p> </li> </ul>",
          "locationName":"tenancy"
        },
        "TotalInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The total number of instances for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"totalInstanceCount"
        },
        "AvailableInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The remaining capacity. Indicates the number of instances that can be launched in the Capacity Reservation.</p>",
          "locationName":"availableInstanceCount"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the Capacity Reservation supports EBS-optimized instances. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS- optimized instance.</p>",
          "locationName":"ebsOptimized"
        },
        "EphemeralStorage":{
          "shape":"Boolean",
          "documentation":"<p> <i>Deprecated.</i> </p>",
          "locationName":"ephemeralStorage"
        },
        "State":{
          "shape":"CapacityReservationState",
          "documentation":"<p>The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:</p> <ul> <li> <p> <code>active</code> - The Capacity Reservation is active and the capacity is available for your use.</p> </li> <li> <p> <code>expired</code> - The Capacity Reservation expired automatically at the date and time specified in your request. The reserved capacity is no longer available for your use.</p> </li> <li> <p> <code>cancelled</code> - The Capacity Reservation was cancelled. The reserved capacity is no longer available for your use.</p> </li> <li> <p> <code>pending</code> - The Capacity Reservation request was successful but the capacity provisioning is still pending.</p> </li> <li> <p> <code>failed</code> - The Capacity Reservation request has failed. A request might fail due to invalid request parameters, capacity constraints, or instance limit constraints. Failed requests are retained for 60 minutes.</p> </li> </ul>",
          "locationName":"state"
        },
        "StartDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation was started.</p>",
          "locationName":"startDate"
        },
        "EndDate":{
          "shape":"DateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation expires. When a Capacity Reservation expires, the reserved capacity is released and you can no longer launch instances into it. The Capacity Reservation's state changes to <code>expired</code> when it reaches its end date and time.</p>",
          "locationName":"endDate"
        },
        "EndDateType":{
          "shape":"EndDateType",
          "documentation":"<p>Indicates the way in which the Capacity Reservation ends. A Capacity Reservation can have one of the following end types:</p> <ul> <li> <p> <code>unlimited</code> - The Capacity Reservation remains active until you explicitly cancel it.</p> </li> <li> <p> <code>limited</code> - The Capacity Reservation expires automatically at a specified date and time.</p> </li> </ul>",
          "locationName":"endDateType"
        },
        "InstanceMatchCriteria":{
          "shape":"InstanceMatchCriteria",
          "documentation":"<p>Indicates the type of instance launches that the Capacity Reservation accepts. The options include:</p> <ul> <li> <p> <code>open</code> - The Capacity Reservation accepts all instances that have matching attributes (instance type, platform, and Availability Zone). Instances that have matching attributes launch into the Capacity Reservation automatically without specifying any additional parameters.</p> </li> <li> <p> <code>targeted</code> - The Capacity Reservation only accepts instances that have matching attributes (instance type, platform, and Availability Zone), and explicitly target the Capacity Reservation. This ensures that only permitted instances can use the reserved capacity. </p> </li> </ul>",
          "locationName":"instanceMatchCriteria"
        },
        "CreateDate":{
          "shape":"DateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation was created.</p>",
          "locationName":"createDate"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the Capacity Reservation.</p>",
          "locationName":"tagSet"
        },
        "OutpostArn":{
          "shape":"OutpostArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost on which the Capacity Reservation was created.</p>",
          "locationName":"outpostArn"
        },
        "CapacityReservationFleetId":{
          "shape":"String",
          "documentation":"<p>The ID of the Capacity Reservation Fleet to which the Capacity Reservation belongs. Only valid for Capacity Reservations that were created by a Capacity Reservation Fleet.</p>",
          "locationName":"capacityReservationFleetId"
        },
        "PlacementGroupArn":{
          "shape":"PlacementGroupArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the cluster placement group in which the Capacity Reservation was created. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/cr-cpg.html\"> Capacity Reservations for cluster placement groups</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"placementGroupArn"
        },
        "CapacityAllocations":{
          "shape":"CapacityAllocations",
          "documentation":"<p>Information about instance capacity usage.</p>",
          "locationName":"capacityAllocationSet"
        }
      },
      "documentation":"<p>Describes a Capacity Reservation.</p>"
    },
    "CapacityReservationFleet":{
      "type":"structure",
      "members":{
        "CapacityReservationFleetId":{
          "shape":"CapacityReservationFleetId",
          "documentation":"<p>The ID of the Capacity Reservation Fleet.</p>",
          "locationName":"capacityReservationFleetId"
        },
        "CapacityReservationFleetArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Capacity Reservation Fleet.</p>",
          "locationName":"capacityReservationFleetArn"
        },
        "State":{
          "shape":"CapacityReservationFleetState",
          "documentation":"<p>The state of the Capacity Reservation Fleet. Possible states include:</p> <ul> <li> <p> <code>submitted</code> - The Capacity Reservation Fleet request has been submitted and Amazon Elastic Compute Cloud is preparing to create the Capacity Reservations.</p> </li> <li> <p> <code>modifying</code> - The Capacity Reservation Fleet is being modified. The Fleet remains in this state until the modification is complete.</p> </li> <li> <p> <code>active</code> - The Capacity Reservation Fleet has fulfilled its total target capacity and it is attempting to maintain this capacity. The Fleet remains in this state until it is modified or deleted.</p> </li> <li> <p> <code>partially_fulfilled</code> - The Capacity Reservation Fleet has partially fulfilled its total target capacity. There is insufficient Amazon EC2 to fulfill the total target capacity. The Fleet is attempting to asynchronously fulfill its total target capacity.</p> </li> <li> <p> <code>expiring</code> - The Capacity Reservation Fleet has reach its end date and it is in the process of expiring. One or more of its Capacity reservations might still be active.</p> </li> <li> <p> <code>expired</code> - The Capacity Reservation Fleet has reach its end date. The Fleet and its Capacity Reservations are expired. The Fleet can't create new Capacity Reservations.</p> </li> <li> <p> <code>cancelling</code> - The Capacity Reservation Fleet is in the process of being cancelled. One or more of its Capacity reservations might still be active.</p> </li> <li> <p> <code>cancelled</code> - The Capacity Reservation Fleet has been manually cancelled. The Fleet and its Capacity Reservations are cancelled and the Fleet can't create new Capacity Reservations.</p> </li> <li> <p> <code>failed</code> - The Capacity Reservation Fleet failed to reserve capacity for the specified instance types.</p> </li> </ul>",
          "locationName":"state"
        },
        "TotalTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The total number of capacity units for which the Capacity Reservation Fleet reserves capacity. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#target-capacity\">Total target capacity</a> in the Amazon EC2 User Guide.</p>",
          "locationName":"totalTargetCapacity"
        },
        "TotalFulfilledCapacity":{
          "shape":"Double",
          "documentation":"<p>The capacity units that have been fulfilled.</p>",
          "locationName":"totalFulfilledCapacity"
        },
        "Tenancy":{
          "shape":"FleetCapacityReservationTenancy",
          "documentation":"<p>The tenancy of the Capacity Reservation Fleet. Tenancies include:</p> <ul> <li> <p> <code>default</code> - The Capacity Reservation Fleet is created on hardware that is shared with other Amazon Web Services accounts.</p> </li> <li> <p> <code>dedicated</code> - The Capacity Reservation Fleet is created on single-tenant hardware that is dedicated to a single Amazon Web Services account.</p> </li> </ul>",
          "locationName":"tenancy"
        },
        "EndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation Fleet expires.</p>",
          "locationName":"endDate"
        },
        "CreateTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation Fleet was created.</p>",
          "locationName":"createTime"
        },
        "InstanceMatchCriteria":{
          "shape":"FleetInstanceMatchCriteria",
          "documentation":"<p>Indicates the type of instance launches that the Capacity Reservation Fleet accepts. All Capacity Reservations in the Fleet inherit this instance matching criteria.</p> <p>Currently, Capacity Reservation Fleets support <code>open</code> instance matching criteria only. This means that instances that have matching attributes (instance type, platform, and Availability Zone) run in the Capacity Reservations automatically. Instances do not need to explicitly target a Capacity Reservation Fleet to use its reserved capacity.</p>",
          "locationName":"instanceMatchCriteria"
        },
        "AllocationStrategy":{
          "shape":"String",
          "documentation":"<p>The strategy used by the Capacity Reservation Fleet to determine which of the specified instance types to use. For more information, see For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#allocation-strategy\"> Allocation strategy</a> in the Amazon EC2 User Guide.</p>",
          "locationName":"allocationStrategy"
        },
        "InstanceTypeSpecifications":{
          "shape":"FleetCapacityReservationSet",
          "documentation":"<p>Information about the instance types for which to reserve the capacity.</p>",
          "locationName":"instanceTypeSpecificationSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the Capacity Reservation Fleet.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Information about a Capacity Reservation Fleet.</p>"
    },
    "CapacityReservationFleetCancellationState":{
      "type":"structure",
      "members":{
        "CurrentFleetState":{
          "shape":"CapacityReservationFleetState",
          "documentation":"<p>The current state of the Capacity Reservation Fleet.</p>",
          "locationName":"currentFleetState"
        },
        "PreviousFleetState":{
          "shape":"CapacityReservationFleetState",
          "documentation":"<p>The previous state of the Capacity Reservation Fleet.</p>",
          "locationName":"previousFleetState"
        },
        "CapacityReservationFleetId":{
          "shape":"CapacityReservationFleetId",
          "documentation":"<p>The ID of the Capacity Reservation Fleet that was successfully cancelled.</p>",
          "locationName":"capacityReservationFleetId"
        }
      },
      "documentation":"<p>Describes a Capacity Reservation Fleet that was successfully cancelled.</p>"
    },
    "CapacityReservationFleetCancellationStateSet":{
      "type":"list",
      "member":{
        "shape":"CapacityReservationFleetCancellationState",
        "locationName":"item"
      }
    },
    "CapacityReservationFleetId":{"type":"string"},
    "CapacityReservationFleetIdSet":{
      "type":"list",
      "member":{
        "shape":"CapacityReservationFleetId",
        "locationName":"item"
      }
    },
    "CapacityReservationFleetSet":{
      "type":"list",
      "member":{
        "shape":"CapacityReservationFleet",
        "locationName":"item"
      }
    },
    "CapacityReservationFleetState":{
      "type":"string",
      "enum":[
        "submitted",
        "modifying",
        "active",
        "partially_fulfilled",
        "expiring",
        "expired",
        "cancelling",
        "cancelled",
        "failed"
      ]
    },
    "CapacityReservationGroup":{
      "type":"structure",
      "members":{
        "GroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the resource group.</p>",
          "locationName":"groupArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the resource group.</p>",
          "locationName":"ownerId"
        }
      },
      "documentation":"<p>Describes a resource group to which a Capacity Reservation has been added.</p>"
    },
    "CapacityReservationGroupSet":{
      "type":"list",
      "member":{
        "shape":"CapacityReservationGroup",
        "locationName":"item"
      }
    },
    "CapacityReservationId":{"type":"string"},
    "CapacityReservationIdSet":{
      "type":"list",
      "member":{
        "shape":"CapacityReservationId",
        "locationName":"item"
      }
    },
    "CapacityReservationInstancePlatform":{
      "type":"string",
      "enum":[
        "Linux/UNIX",
        "Red Hat Enterprise Linux",
        "SUSE Linux",
        "Windows",
        "Windows with SQL Server",
        "Windows with SQL Server Enterprise",
        "Windows with SQL Server Standard",
        "Windows with SQL Server Web",
        "Linux with SQL Server Standard",
        "Linux with SQL Server Web",
        "Linux with SQL Server Enterprise",
        "RHEL with SQL Server Standard",
        "RHEL with SQL Server Enterprise",
        "RHEL with SQL Server Web",
        "RHEL with HA",
        "RHEL with HA and SQL Server Standard",
        "RHEL with HA and SQL Server Enterprise"
      ]
    },
    "CapacityReservationOptions":{
      "type":"structure",
      "members":{
        "UsageStrategy":{
          "shape":"FleetCapacityReservationUsageStrategy",
          "documentation":"<p>Indicates whether to use unused Capacity Reservations for fulfilling On-Demand capacity.</p> <p>If you specify <code>use-capacity-reservations-first</code>, the fleet uses unused Capacity Reservations to fulfill On-Demand capacity up to the target On-Demand capacity. If multiple instance pools have unused Capacity Reservations, the On-Demand allocation strategy (<code>lowest-price</code> or <code>prioritized</code>) is applied. If the number of unused Capacity Reservations is less than the On-Demand target capacity, the remaining On-Demand target capacity is launched according to the On-Demand allocation strategy (<code>lowest-price</code> or <code>prioritized</code>).</p> <p>If you do not specify a value, the fleet fulfils the On-Demand capacity according to the chosen On-Demand allocation strategy.</p>",
          "locationName":"usageStrategy"
        }
      },
      "documentation":"<p>Describes the strategy for using unused Capacity Reservations for fulfilling On-Demand capacity.</p> <note> <p>This strategy can only be used if the EC2 Fleet is of type <code>instant</code>.</p> </note> <p>For more information about Capacity Reservations, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-capacity-reservations.html\">On-Demand Capacity Reservations</a> in the <i>Amazon EC2 User Guide</i>. For examples of using Capacity Reservations in an EC2 Fleet, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-examples.html\">EC2 Fleet example configurations</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CapacityReservationOptionsRequest":{
      "type":"structure",
      "members":{
        "UsageStrategy":{
          "shape":"FleetCapacityReservationUsageStrategy",
          "documentation":"<p>Indicates whether to use unused Capacity Reservations for fulfilling On-Demand capacity.</p> <p>If you specify <code>use-capacity-reservations-first</code>, the fleet uses unused Capacity Reservations to fulfill On-Demand capacity up to the target On-Demand capacity. If multiple instance pools have unused Capacity Reservations, the On-Demand allocation strategy (<code>lowest-price</code> or <code>prioritized</code>) is applied. If the number of unused Capacity Reservations is less than the On-Demand target capacity, the remaining On-Demand target capacity is launched according to the On-Demand allocation strategy (<code>lowest-price</code> or <code>prioritized</code>).</p> <p>If you do not specify a value, the fleet fulfils the On-Demand capacity according to the chosen On-Demand allocation strategy.</p>"
        }
      },
      "documentation":"<p>Describes the strategy for using unused Capacity Reservations for fulfilling On-Demand capacity.</p> <note> <p>This strategy can only be used if the EC2 Fleet is of type <code>instant</code>.</p> </note> <p>For more information about Capacity Reservations, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-capacity-reservations.html\">On-Demand Capacity Reservations</a> in the <i>Amazon EC2 User Guide</i>. For examples of using Capacity Reservations in an EC2 Fleet, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-examples.html\">EC2 Fleet example configurations</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "CapacityReservationPreference":{
      "type":"string",
      "enum":[
        "open",
        "none"
      ]
    },
    "CapacityReservationSet":{
      "type":"list",
      "member":{
        "shape":"CapacityReservation",
        "locationName":"item"
      }
    },
    "CapacityReservationSpecification":{
      "type":"structure",
      "members":{
        "CapacityReservationPreference":{
          "shape":"CapacityReservationPreference",
          "documentation":"<p>Indicates the instance's Capacity Reservation preferences. Possible preferences include:</p> <ul> <li> <p> <code>open</code> - The instance can run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone).</p> </li> <li> <p> <code>none</code> - The instance avoids running in a Capacity Reservation even if one is available. The instance runs as an On-Demand Instance.</p> </li> </ul>"
        },
        "CapacityReservationTarget":{
          "shape":"CapacityReservationTarget",
          "documentation":"<p>Information about the target Capacity Reservation or Capacity Reservation group.</p>"
        }
      },
      "documentation":"<p>Describes an instance's Capacity Reservation targeting option. You can specify only one parameter at a time. If you specify <code>CapacityReservationPreference</code> and <code>CapacityReservationTarget</code>, the request fails.</p> <p>Use the <code>CapacityReservationPreference</code> parameter to configure the instance to run as an On-Demand Instance or to run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone). Use the <code>CapacityReservationTarget</code> parameter to explicitly target a specific Capacity Reservation or a Capacity Reservation group.</p>"
    },
    "CapacityReservationSpecificationResponse":{
      "type":"structure",
      "members":{
        "CapacityReservationPreference":{
          "shape":"CapacityReservationPreference",
          "documentation":"<p>Describes the instance's Capacity Reservation preferences. Possible preferences include:</p> <ul> <li> <p> <code>open</code> - The instance can run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone).</p> </li> <li> <p> <code>none</code> - The instance avoids running in a Capacity Reservation even if one is available. The instance runs in On-Demand capacity.</p> </li> </ul>",
          "locationName":"capacityReservationPreference"
        },
        "CapacityReservationTarget":{
          "shape":"CapacityReservationTargetResponse",
          "documentation":"<p>Information about the targeted Capacity Reservation or Capacity Reservation group.</p>",
          "locationName":"capacityReservationTarget"
        }
      },
      "documentation":"<p>Describes the instance's Capacity Reservation targeting preferences. The action returns the <code>capacityReservationPreference</code> response element if the instance is configured to run in On-Demand capacity, or if it is configured in run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone). The action returns the <code>capacityReservationTarget</code> response element if the instance explicily targets a specific Capacity Reservation or Capacity Reservation group.</p>"
    },
    "CapacityReservationState":{
      "type":"string",
      "enum":[
        "active",
        "expired",
        "cancelled",
        "pending",
        "failed"
      ]
    },
    "CapacityReservationTarget":{
      "type":"structure",
      "members":{
        "CapacityReservationId":{
          "shape":"CapacityReservationId",
          "documentation":"<p>The ID of the Capacity Reservation in which to run the instance.</p>"
        },
        "CapacityReservationResourceGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Capacity Reservation resource group in which to run the instance.</p>"
        }
      },
      "documentation":"<p>Describes a target Capacity Reservation or Capacity Reservation group.</p>"
    },
    "CapacityReservationTargetResponse":{
      "type":"structure",
      "members":{
        "CapacityReservationId":{
          "shape":"String",
          "documentation":"<p>The ID of the targeted Capacity Reservation.</p>",
          "locationName":"capacityReservationId"
        },
        "CapacityReservationResourceGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the targeted Capacity Reservation group.</p>",
          "locationName":"capacityReservationResourceGroupArn"
        }
      },
      "documentation":"<p>Describes a target Capacity Reservation or Capacity Reservation group.</p>"
    },
    "CapacityReservationTenancy":{
      "type":"string",
      "enum":[
        "default",
        "dedicated"
      ]
    },
    "CarrierGateway":{
      "type":"structure",
      "members":{
        "CarrierGatewayId":{
          "shape":"CarrierGatewayId",
          "documentation":"<p>The ID of the carrier gateway.</p>",
          "locationName":"carrierGatewayId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC associated with the carrier gateway.</p>",
          "locationName":"vpcId"
        },
        "State":{
          "shape":"CarrierGatewayState",
          "documentation":"<p>The state of the carrier gateway.</p>",
          "locationName":"state"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the carrier gateway.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the carrier gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a carrier gateway.</p>"
    },
    "CarrierGatewayId":{"type":"string"},
    "CarrierGatewayIdSet":{
      "type":"list",
      "member":{"shape":"CarrierGatewayId"}
    },
    "CarrierGatewayMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "CarrierGatewaySet":{
      "type":"list",
      "member":{
        "shape":"CarrierGateway",
        "locationName":"item"
      }
    },
    "CarrierGatewayState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "CertificateArn":{"type":"string"},
    "CertificateAuthentication":{
      "type":"structure",
      "members":{
        "ClientRootCertificateChain":{
          "shape":"String",
          "documentation":"<p>The ARN of the client certificate. </p>",
          "locationName":"clientRootCertificateChain"
        }
      },
      "documentation":"<p>Information about the client certificate used for authentication.</p>"
    },
    "CertificateAuthenticationRequest":{
      "type":"structure",
      "members":{
        "ClientRootCertificateChainArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the client certificate. The certificate must be signed by a certificate authority (CA) and it must be provisioned in Certificate Manager (ACM).</p>"
        }
      },
      "documentation":"<p>Information about the client certificate to be used for authentication.</p>"
    },
    "CertificateId":{"type":"string"},
    "CidrAuthorizationContext":{
      "type":"structure",
      "required":[
        "Message",
        "Signature"
      ],
      "members":{
        "Message":{
          "shape":"String",
          "documentation":"<p>The plain-text authorization message for the prefix and account.</p>"
        },
        "Signature":{
          "shape":"String",
          "documentation":"<p>The signed authorization message for the prefix and account.</p>"
        }
      },
      "documentation":"<p>Provides authorization for Amazon to bring a specific IP address range to a specific Amazon Web Services account using bring your own IP addresses (BYOIP). For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-byoip.html#prepare-for-byoip\">Configuring your BYOIP address range</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "CidrBlock":{
      "type":"structure",
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR block.</p>",
          "locationName":"cidrBlock"
        }
      },
      "documentation":"<p>Describes an IPv4 CIDR block.</p>"
    },
    "CidrBlockSet":{
      "type":"list",
      "member":{
        "shape":"CidrBlock",
        "locationName":"item"
      }
    },
    "ClassicLinkDnsSupport":{
      "type":"structure",
      "members":{
        "ClassicLinkDnsSupported":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether ClassicLink DNS support is enabled for the VPC.</p>",
          "locationName":"classicLinkDnsSupported"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<p>Describes the ClassicLink DNS support status of a VPC.</p>"
    },
    "ClassicLinkDnsSupportList":{
      "type":"list",
      "member":{
        "shape":"ClassicLinkDnsSupport",
        "locationName":"item"
      }
    },
    "ClassicLinkInstance":{
      "type":"structure",
      "members":{
        "Groups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>A list of security groups.</p>",
          "locationName":"groupSet"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the instance.</p>",
          "locationName":"tagSet"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Describes a linked EC2-Classic instance.</p>"
    },
    "ClassicLinkInstanceList":{
      "type":"list",
      "member":{
        "shape":"ClassicLinkInstance",
        "locationName":"item"
      }
    },
    "ClassicLoadBalancer":{
      "type":"structure",
      "members":{
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the load balancer.</p>",
          "locationName":"name"
        }
      },
      "documentation":"<p>Describes a Classic Load Balancer.</p>"
    },
    "ClassicLoadBalancers":{
      "type":"list",
      "member":{
        "shape":"ClassicLoadBalancer",
        "locationName":"item"
      },
      "max":5,
      "min":1
    },
    "ClassicLoadBalancersConfig":{
      "type":"structure",
      "members":{
        "ClassicLoadBalancers":{
          "shape":"ClassicLoadBalancers",
          "documentation":"<p>One or more Classic Load Balancers.</p>",
          "locationName":"classicLoadBalancers"
        }
      },
      "documentation":"<p>Describes the Classic Load Balancers to attach to a Spot Fleet. Spot Fleet registers the running Spot Instances with these Classic Load Balancers.</p>"
    },
    "ClientCertificateRevocationListStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"ClientCertificateRevocationListStatusCode",
          "documentation":"<p>The state of the client certificate revocation list.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message about the status of the client certificate revocation list, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the state of a client certificate revocation list.</p>"
    },
    "ClientCertificateRevocationListStatusCode":{
      "type":"string",
      "enum":[
        "pending",
        "active"
      ]
    },
    "ClientConnectOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether client connect options are enabled. The default is <code>false</code> (not enabled).</p>"
        },
        "LambdaFunctionArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Lambda function used for connection authorization.</p>"
        }
      },
      "documentation":"<p>The options for managing connection authorization for new client connections.</p>"
    },
    "ClientConnectResponseOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether client connect options are enabled.</p>",
          "locationName":"enabled"
        },
        "LambdaFunctionArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Lambda function used for connection authorization.</p>",
          "locationName":"lambdaFunctionArn"
        },
        "Status":{
          "shape":"ClientVpnEndpointAttributeStatus",
          "documentation":"<p>The status of any updates to the client connect options.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>The options for managing connection authorization for new client connections.</p>"
    },
    "ClientData":{
      "type":"structure",
      "members":{
        "Comment":{
          "shape":"String",
          "documentation":"<p>A user-defined comment about the disk upload.</p>"
        },
        "UploadEnd":{
          "shape":"DateTime",
          "documentation":"<p>The time that the disk upload ends.</p>"
        },
        "UploadSize":{
          "shape":"Double",
          "documentation":"<p>The size of the uploaded disk image, in GiB.</p>"
        },
        "UploadStart":{
          "shape":"DateTime",
          "documentation":"<p>The time that the disk upload starts.</p>"
        }
      },
      "documentation":"<p>Describes the client-specific data.</p>"
    },
    "ClientLoginBannerOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Enable or disable a customizable text banner that will be displayed on Amazon Web Services provided clients when a VPN session is established.</p> <p>Valid values: <code>true | false</code> </p> <p>Default value: <code>false</code> </p>"
        },
        "BannerText":{
          "shape":"String",
          "documentation":"<p>Customizable text that will be displayed in a banner on Amazon Web Services provided clients when a VPN session is established. UTF-8 encoded characters only. Maximum of 1400 characters.</p>"
        }
      },
      "documentation":"<p>Options for enabling a customizable text banner that will be displayed on Amazon Web Services provided clients when a VPN session is established.</p>"
    },
    "ClientLoginBannerResponseOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Current state of text banner feature.</p> <p>Valid values: <code>true | false</code> </p>",
          "locationName":"enabled"
        },
        "BannerText":{
          "shape":"String",
          "documentation":"<p>Customizable text that will be displayed in a banner on Amazon Web Services provided clients when a VPN session is established. UTF-8 encoded characters only. Maximum of 1400 characters.</p>",
          "locationName":"bannerText"
        }
      },
      "documentation":"<p>Current state of options for customizable text banner that will be displayed on Amazon Web Services provided clients when a VPN session is established.</p>"
    },
    "ClientVpnAssociationId":{"type":"string"},
    "ClientVpnAuthentication":{
      "type":"structure",
      "members":{
        "Type":{
          "shape":"ClientVpnAuthenticationType",
          "documentation":"<p>The authentication type used.</p>",
          "locationName":"type"
        },
        "ActiveDirectory":{
          "shape":"DirectoryServiceAuthentication",
          "documentation":"<p>Information about the Active Directory, if applicable.</p>",
          "locationName":"activeDirectory"
        },
        "MutualAuthentication":{
          "shape":"CertificateAuthentication",
          "documentation":"<p>Information about the authentication certificates, if applicable.</p>",
          "locationName":"mutualAuthentication"
        },
        "FederatedAuthentication":{
          "shape":"FederatedAuthentication",
          "documentation":"<p>Information about the IAM SAML identity provider, if applicable.</p>",
          "locationName":"federatedAuthentication"
        }
      },
      "documentation":"<p>Describes the authentication methods used by a Client VPN endpoint. For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/client-authentication.html\">Authentication</a> in the <i>Client VPN Administrator Guide</i>.</p>"
    },
    "ClientVpnAuthenticationList":{
      "type":"list",
      "member":{
        "shape":"ClientVpnAuthentication",
        "locationName":"item"
      }
    },
    "ClientVpnAuthenticationRequest":{
      "type":"structure",
      "members":{
        "Type":{
          "shape":"ClientVpnAuthenticationType",
          "documentation":"<p>The type of client authentication to be used.</p>"
        },
        "ActiveDirectory":{
          "shape":"DirectoryServiceAuthenticationRequest",
          "documentation":"<p>Information about the Active Directory to be used, if applicable. You must provide this information if <b>Type</b> is <code>directory-service-authentication</code>.</p>"
        },
        "MutualAuthentication":{
          "shape":"CertificateAuthenticationRequest",
          "documentation":"<p>Information about the authentication certificates to be used, if applicable. You must provide this information if <b>Type</b> is <code>certificate-authentication</code>.</p>"
        },
        "FederatedAuthentication":{
          "shape":"FederatedAuthenticationRequest",
          "documentation":"<p>Information about the IAM SAML identity provider to be used, if applicable. You must provide this information if <b>Type</b> is <code>federated-authentication</code>.</p>"
        }
      },
      "documentation":"<p>Describes the authentication method to be used by a Client VPN endpoint. For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/authentication-authrization.html#client-authentication\">Authentication</a> in the <i>Client VPN Administrator Guide</i>.</p>"
    },
    "ClientVpnAuthenticationRequestList":{
      "type":"list",
      "member":{"shape":"ClientVpnAuthenticationRequest"}
    },
    "ClientVpnAuthenticationType":{
      "type":"string",
      "enum":[
        "certificate-authentication",
        "directory-service-authentication",
        "federated-authentication"
      ]
    },
    "ClientVpnAuthorizationRuleStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"ClientVpnAuthorizationRuleStatusCode",
          "documentation":"<p>The state of the authorization rule.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message about the status of the authorization rule, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the state of an authorization rule.</p>"
    },
    "ClientVpnAuthorizationRuleStatusCode":{
      "type":"string",
      "enum":[
        "authorizing",
        "active",
        "failed",
        "revoking"
      ]
    },
    "ClientVpnConnection":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint to which the client is connected.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "Timestamp":{
          "shape":"String",
          "documentation":"<p>The current date and time.</p>",
          "locationName":"timestamp"
        },
        "ConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the client connection.</p>",
          "locationName":"connectionId"
        },
        "Username":{
          "shape":"String",
          "documentation":"<p>The username of the client who established the client connection. This information is only provided if Active Directory client authentication is used.</p>",
          "locationName":"username"
        },
        "ConnectionEstablishedTime":{
          "shape":"String",
          "documentation":"<p>The date and time the client connection was established.</p>",
          "locationName":"connectionEstablishedTime"
        },
        "IngressBytes":{
          "shape":"String",
          "documentation":"<p>The number of bytes sent by the client.</p>",
          "locationName":"ingressBytes"
        },
        "EgressBytes":{
          "shape":"String",
          "documentation":"<p>The number of bytes received by the client.</p>",
          "locationName":"egressBytes"
        },
        "IngressPackets":{
          "shape":"String",
          "documentation":"<p>The number of packets sent by the client.</p>",
          "locationName":"ingressPackets"
        },
        "EgressPackets":{
          "shape":"String",
          "documentation":"<p>The number of packets received by the client.</p>",
          "locationName":"egressPackets"
        },
        "ClientIp":{
          "shape":"String",
          "documentation":"<p>The IP address of the client.</p>",
          "locationName":"clientIp"
        },
        "CommonName":{
          "shape":"String",
          "documentation":"<p>The common name associated with the client. This is either the name of the client certificate, or the Active Directory user name.</p>",
          "locationName":"commonName"
        },
        "Status":{
          "shape":"ClientVpnConnectionStatus",
          "documentation":"<p>The current state of the client connection.</p>",
          "locationName":"status"
        },
        "ConnectionEndTime":{
          "shape":"String",
          "documentation":"<p>The date and time the client connection was terminated.</p>",
          "locationName":"connectionEndTime"
        },
        "PostureComplianceStatuses":{
          "shape":"ValueStringList",
          "documentation":"<p>The statuses returned by the client connect handler for posture compliance, if applicable.</p>",
          "locationName":"postureComplianceStatusSet"
        }
      },
      "documentation":"<p>Describes a client connection.</p>"
    },
    "ClientVpnConnectionSet":{
      "type":"list",
      "member":{
        "shape":"ClientVpnConnection",
        "locationName":"item"
      }
    },
    "ClientVpnConnectionStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"ClientVpnConnectionStatusCode",
          "documentation":"<p>The state of the client connection.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message about the status of the client connection, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the status of a client connection.</p>"
    },
    "ClientVpnConnectionStatusCode":{
      "type":"string",
      "enum":[
        "active",
        "failed-to-terminate",
        "terminating",
        "terminated"
      ]
    },
    "ClientVpnEndpoint":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the endpoint.</p>",
          "locationName":"description"
        },
        "Status":{
          "shape":"ClientVpnEndpointStatus",
          "documentation":"<p>The current state of the Client VPN endpoint.</p>",
          "locationName":"status"
        },
        "CreationTime":{
          "shape":"String",
          "documentation":"<p>The date and time the Client VPN endpoint was created.</p>",
          "locationName":"creationTime"
        },
        "DeletionTime":{
          "shape":"String",
          "documentation":"<p>The date and time the Client VPN endpoint was deleted, if applicable.</p>",
          "locationName":"deletionTime"
        },
        "DnsName":{
          "shape":"String",
          "documentation":"<p>The DNS name to be used by clients when connecting to the Client VPN endpoint.</p>",
          "locationName":"dnsName"
        },
        "ClientCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, from which client IP addresses are assigned.</p>",
          "locationName":"clientCidrBlock"
        },
        "DnsServers":{
          "shape":"ValueStringList",
          "documentation":"<p>Information about the DNS servers to be used for DNS resolution. </p>",
          "locationName":"dnsServer"
        },
        "SplitTunnel":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether split-tunnel is enabled in the Client VPN endpoint.</p> <p>For information about split-tunnel VPN endpoints, see <a href=\"https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/split-tunnel-vpn.html\">Split-Tunnel Client VPN endpoint</a> in the <i>Client VPN Administrator Guide</i>.</p>",
          "locationName":"splitTunnel"
        },
        "VpnProtocol":{
          "shape":"VpnProtocol",
          "documentation":"<p>The protocol used by the VPN session.</p>",
          "locationName":"vpnProtocol"
        },
        "TransportProtocol":{
          "shape":"TransportProtocol",
          "documentation":"<p>The transport protocol used by the Client VPN endpoint.</p>",
          "locationName":"transportProtocol"
        },
        "VpnPort":{
          "shape":"Integer",
          "documentation":"<p>The port number for the Client VPN endpoint.</p>",
          "locationName":"vpnPort"
        },
        "AssociatedTargetNetworks":{
          "shape":"AssociatedTargetNetworkSet",
          "documentation":"<p>Information about the associated target networks. A target network is a subnet in a VPC.</p>",
          "deprecated":true,
          "deprecatedMessage":"This property is deprecated. To view the target networks associated with a Client VPN endpoint, call DescribeClientVpnTargetNetworks and inspect the clientVpnTargetNetworks response element.",
          "locationName":"associatedTargetNetwork"
        },
        "ServerCertificateArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the server certificate.</p>",
          "locationName":"serverCertificateArn"
        },
        "AuthenticationOptions":{
          "shape":"ClientVpnAuthenticationList",
          "documentation":"<p>Information about the authentication method used by the Client VPN endpoint.</p>",
          "locationName":"authenticationOptions"
        },
        "ConnectionLogOptions":{
          "shape":"ConnectionLogResponseOptions",
          "documentation":"<p>Information about the client connection logging options for the Client VPN endpoint.</p>",
          "locationName":"connectionLogOptions"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the Client VPN endpoint.</p>",
          "locationName":"tagSet"
        },
        "SecurityGroupIds":{
          "shape":"ClientVpnSecurityGroupIdSet",
          "documentation":"<p>The IDs of the security groups for the target network.</p>",
          "locationName":"securityGroupIdSet"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "SelfServicePortalUrl":{
          "shape":"String",
          "documentation":"<p>The URL of the self-service portal.</p>",
          "locationName":"selfServicePortalUrl"
        },
        "ClientConnectOptions":{
          "shape":"ClientConnectResponseOptions",
          "documentation":"<p>The options for managing connection authorization for new client connections.</p>",
          "locationName":"clientConnectOptions"
        },
        "SessionTimeoutHours":{
          "shape":"Integer",
          "documentation":"<p>The maximum VPN session duration time in hours.</p> <p>Valid values: <code>8 | 10 | 12 | 24</code> </p> <p>Default value: <code>24</code> </p>",
          "locationName":"sessionTimeoutHours"
        },
        "ClientLoginBannerOptions":{
          "shape":"ClientLoginBannerResponseOptions",
          "documentation":"<p>Options for enabling a customizable text banner that will be displayed on Amazon Web Services provided clients when a VPN session is established.</p>",
          "locationName":"clientLoginBannerOptions"
        }
      },
      "documentation":"<p>Describes a Client VPN endpoint.</p>"
    },
    "ClientVpnEndpointAttributeStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"ClientVpnEndpointAttributeStatusCode",
          "documentation":"<p>The status code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The status message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the status of the Client VPN endpoint attribute.</p>"
    },
    "ClientVpnEndpointAttributeStatusCode":{
      "type":"string",
      "enum":[
        "applying",
        "applied"
      ]
    },
    "ClientVpnEndpointId":{"type":"string"},
    "ClientVpnEndpointIdList":{
      "type":"list",
      "member":{
        "shape":"ClientVpnEndpointId",
        "locationName":"item"
      }
    },
    "ClientVpnEndpointStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"ClientVpnEndpointStatusCode",
          "documentation":"<p>The state of the Client VPN endpoint. Possible states include:</p> <ul> <li> <p> <code>pending-associate</code> - The Client VPN endpoint has been created but no target networks have been associated. The Client VPN endpoint cannot accept connections.</p> </li> <li> <p> <code>available</code> - The Client VPN endpoint has been created and a target network has been associated. The Client VPN endpoint can accept connections.</p> </li> <li> <p> <code>deleting</code> - The Client VPN endpoint is being deleted. The Client VPN endpoint cannot accept connections.</p> </li> <li> <p> <code>deleted</code> - The Client VPN endpoint has been deleted. The Client VPN endpoint cannot accept connections.</p> </li> </ul>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message about the status of the Client VPN endpoint.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the state of a Client VPN endpoint.</p>"
    },
    "ClientVpnEndpointStatusCode":{
      "type":"string",
      "enum":[
        "pending-associate",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "ClientVpnRoute":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint with which the route is associated.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "DestinationCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the route destination.</p>",
          "locationName":"destinationCidr"
        },
        "TargetSubnet":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet through which traffic is routed.</p>",
          "locationName":"targetSubnet"
        },
        "Type":{
          "shape":"String",
          "documentation":"<p>The route type.</p>",
          "locationName":"type"
        },
        "Origin":{
          "shape":"String",
          "documentation":"<p>Indicates how the route was associated with the Client VPN endpoint. <code>associate</code> indicates that the route was automatically added when the target network was associated with the Client VPN endpoint. <code>add-route</code> indicates that the route was manually added using the <b>CreateClientVpnRoute</b> action.</p>",
          "locationName":"origin"
        },
        "Status":{
          "shape":"ClientVpnRouteStatus",
          "documentation":"<p>The current state of the route.</p>",
          "locationName":"status"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the route.</p>",
          "locationName":"description"
        }
      },
      "documentation":"<p>Information about a Client VPN endpoint route.</p>"
    },
    "ClientVpnRouteSet":{
      "type":"list",
      "member":{
        "shape":"ClientVpnRoute",
        "locationName":"item"
      }
    },
    "ClientVpnRouteStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"ClientVpnRouteStatusCode",
          "documentation":"<p>The state of the Client VPN endpoint route.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message about the status of the Client VPN endpoint route, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the state of a Client VPN endpoint route.</p>"
    },
    "ClientVpnRouteStatusCode":{
      "type":"string",
      "enum":[
        "creating",
        "active",
        "failed",
        "deleting"
      ]
    },
    "ClientVpnSecurityGroupIdSet":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"item"
      }
    },
    "CloudWatchLogGroupArn":{"type":"string"},
    "CloudWatchLogOptions":{
      "type":"structure",
      "members":{
        "LogEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Status of VPN tunnel logging feature. Default value is <code>False</code>.</p> <p>Valid values: <code>True</code> | <code>False</code> </p>",
          "locationName":"logEnabled"
        },
        "LogGroupArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the CloudWatch log group to send logs to.</p>",
          "locationName":"logGroupArn"
        },
        "LogOutputFormat":{
          "shape":"String",
          "documentation":"<p>Configured log format. Default format is <code>json</code>.</p> <p>Valid values: <code>json</code> | <code>text</code> </p>",
          "locationName":"logOutputFormat"
        }
      },
      "documentation":"<p>Options for sending VPN tunnel logs to CloudWatch.</p>"
    },
    "CloudWatchLogOptionsSpecification":{
      "type":"structure",
      "members":{
        "LogEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Enable or disable VPN tunnel logging feature. Default value is <code>False</code>.</p> <p>Valid values: <code>True</code> | <code>False</code> </p>"
        },
        "LogGroupArn":{
          "shape":"CloudWatchLogGroupArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the CloudWatch log group to send logs to.</p>"
        },
        "LogOutputFormat":{
          "shape":"String",
          "documentation":"<p>Set log format. Default format is <code>json</code>.</p> <p>Valid values: <code>json</code> | <code>text</code> </p>"
        }
      },
      "documentation":"<p>Options for sending VPN tunnel logs to CloudWatch.</p>"
    },
    "CoipAddressUsage":{
      "type":"structure",
      "members":{
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>The allocation ID of the address.</p>",
          "locationName":"allocationId"
        },
        "AwsAccountId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p>",
          "locationName":"awsAccountId"
        },
        "AwsService":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services service.</p>",
          "locationName":"awsService"
        },
        "CoIp":{
          "shape":"String",
          "documentation":"<p>The customer-owned IP address.</p>",
          "locationName":"coIp"
        }
      },
      "documentation":"<p>Describes address usage for a customer-owned address pool.</p>"
    },
    "CoipAddressUsageSet":{
      "type":"list",
      "member":{
        "shape":"CoipAddressUsage",
        "locationName":"item"
      }
    },
    "CoipCidr":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p> An address range in a customer-owned IP address space. </p>",
          "locationName":"cidr"
        },
        "CoipPoolId":{
          "shape":"Ipv4PoolCoipId",
          "documentation":"<p> The ID of the address pool. </p>",
          "locationName":"coipPoolId"
        },
        "LocalGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p> The ID of the local gateway route table. </p>",
          "locationName":"localGatewayRouteTableId"
        }
      },
      "documentation":"<p> Information about a customer-owned IP address range. </p>"
    },
    "CoipPool":{
      "type":"structure",
      "members":{
        "PoolId":{
          "shape":"Ipv4PoolCoipId",
          "documentation":"<p>The ID of the address pool.</p>",
          "locationName":"poolId"
        },
        "PoolCidrs":{
          "shape":"ValueStringList",
          "documentation":"<p>The address ranges of the address pool.</p>",
          "locationName":"poolCidrSet"
        },
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        },
        "PoolArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The ARN of the address pool.</p>",
          "locationName":"poolArn"
        }
      },
      "documentation":"<p>Describes a customer-owned address pool.</p>"
    },
    "CoipPoolId":{"type":"string"},
    "CoipPoolIdSet":{
      "type":"list",
      "member":{
        "shape":"Ipv4PoolCoipId",
        "locationName":"item"
      }
    },
    "CoipPoolMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "CoipPoolSet":{
      "type":"list",
      "member":{
        "shape":"CoipPool",
        "locationName":"item"
      }
    },
    "ComponentAccount":{
      "type":"string",
      "pattern":"\\d{12}"
    },
    "ComponentRegion":{
      "type":"string",
      "pattern":"[a-z]{2}-[a-z]+-[1-9]+"
    },
    "ConfirmProductInstanceRequest":{
      "type":"structure",
      "required":[
        "InstanceId",
        "ProductCode"
      ],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "ProductCode":{
          "shape":"String",
          "documentation":"<p>The product code. This must be a product code that you own.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "ConfirmProductInstanceResult":{
      "type":"structure",
      "members":{
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the instance owner. This is only present if the product code is attached to the instance.</p>",
          "locationName":"ownerId"
        },
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>The return value of the request. Returns <code>true</code> if the specified product code is owned by the requester and associated with the specified instance.</p>",
          "locationName":"return"
        }
      }
    },
    "ConnectionLogOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether connection logging is enabled.</p>"
        },
        "CloudwatchLogGroup":{
          "shape":"String",
          "documentation":"<p>The name of the CloudWatch Logs log group. Required if connection logging is enabled.</p>"
        },
        "CloudwatchLogStream":{
          "shape":"String",
          "documentation":"<p>The name of the CloudWatch Logs log stream to which the connection data is published.</p>"
        }
      },
      "documentation":"<p>Describes the client connection logging options for the Client VPN endpoint.</p>"
    },
    "ConnectionLogResponseOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether client connection logging is enabled for the Client VPN endpoint.</p>"
        },
        "CloudwatchLogGroup":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon CloudWatch Logs log group to which connection logging data is published.</p>"
        },
        "CloudwatchLogStream":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon CloudWatch Logs log stream to which connection logging data is published.</p>"
        }
      },
      "documentation":"<p>Information about the client connection logging options for a Client VPN endpoint.</p>"
    },
    "ConnectionNotification":{
      "type":"structure",
      "members":{
        "ConnectionNotificationId":{
          "shape":"String",
          "documentation":"<p>The ID of the notification.</p>",
          "locationName":"connectionNotificationId"
        },
        "ServiceId":{
          "shape":"String",
          "documentation":"<p>The ID of the endpoint service.</p>",
          "locationName":"serviceId"
        },
        "VpcEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC endpoint.</p>",
          "locationName":"vpcEndpointId"
        },
        "ConnectionNotificationType":{
          "shape":"ConnectionNotificationType",
          "documentation":"<p>The type of notification.</p>",
          "locationName":"connectionNotificationType"
        },
        "ConnectionNotificationArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the SNS topic for the notification.</p>",
          "locationName":"connectionNotificationArn"
        },
        "ConnectionEvents":{
          "shape":"ValueStringList",
          "documentation":"<p>The events for the notification. Valid values are <code>Accept</code>, <code>Connect</code>, <code>Delete</code>, and <code>Reject</code>.</p>",
          "locationName":"connectionEvents"
        },
        "ConnectionNotificationState":{
          "shape":"ConnectionNotificationState",
          "documentation":"<p>The state of the notification.</p>",
          "locationName":"connectionNotificationState"
        }
      },
      "documentation":"<p>Describes a connection notification for a VPC endpoint or VPC endpoint service.</p>"
    },
    "ConnectionNotificationId":{"type":"string"},
    "ConnectionNotificationIdsList":{
      "type":"list",
      "member":{
        "shape":"ConnectionNotificationId",
        "locationName":"item"
      }
    },
    "ConnectionNotificationSet":{
      "type":"list",
      "member":{
        "shape":"ConnectionNotification",
        "locationName":"item"
      }
    },
    "ConnectionNotificationState":{
      "type":"string",
      "enum":[
        "Enabled",
        "Disabled"
      ]
    },
    "ConnectionNotificationType":{
      "type":"string",
      "enum":["Topic"]
    },
    "ConnectivityType":{
      "type":"string",
      "enum":[
        "private",
        "public"
      ]
    },
    "ContainerFormat":{
      "type":"string",
      "enum":["ova"]
    },
    "ConversionIdStringList":{
      "type":"list",
      "member":{
        "shape":"ConversionTaskId",
        "locationName":"item"
      }
    },
    "ConversionTask":{
      "type":"structure",
      "members":{
        "ConversionTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the conversion task.</p>",
          "locationName":"conversionTaskId"
        },
        "ExpirationTime":{
          "shape":"String",
          "documentation":"<p>The time when the task expires. If the upload isn't complete before the expiration time, we automatically cancel the task.</p>",
          "locationName":"expirationTime"
        },
        "ImportInstance":{
          "shape":"ImportInstanceTaskDetails",
          "documentation":"<p>If the task is for importing an instance, this contains information about the import instance task.</p>",
          "locationName":"importInstance"
        },
        "ImportVolume":{
          "shape":"ImportVolumeTaskDetails",
          "documentation":"<p>If the task is for importing a volume, this contains information about the import volume task.</p>",
          "locationName":"importVolume"
        },
        "State":{
          "shape":"ConversionTaskState",
          "documentation":"<p>The state of the conversion task.</p>",
          "locationName":"state"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message related to the conversion task.</p>",
          "locationName":"statusMessage"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the task.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a conversion task.</p>"
    },
    "ConversionTaskId":{"type":"string"},
    "ConversionTaskState":{
      "type":"string",
      "enum":[
        "active",
        "cancelling",
        "cancelled",
        "completed"
      ]
    },
    "CopyFpgaImageRequest":{
      "type":"structure",
      "required":[
        "SourceFpgaImageId",
        "SourceRegion"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "SourceFpgaImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the source AFI.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the new AFI.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name for the new AFI. The default is the name of the source AFI.</p>"
        },
        "SourceRegion":{
          "shape":"String",
          "documentation":"<p>The Region that contains the source AFI.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p>"
        }
      }
    },
    "CopyFpgaImageResult":{
      "type":"structure",
      "members":{
        "FpgaImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the new AFI.</p>",
          "locationName":"fpgaImageId"
        }
      }
    },
    "CopyImageRequest":{
      "type":"structure",
      "required":[
        "Name",
        "SourceImageId",
        "SourceRegion"
      ],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a> in the <i>Amazon EC2 API Reference</i>.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the new AMI in the destination Region.</p>"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether the destination snapshots of the copied image should be encrypted. You can encrypt a copy of an unencrypted snapshot, but you cannot create an unencrypted copy of an encrypted snapshot. The default KMS key for Amazon EBS is used unless you specify a non-default Key Management Service (KMS) KMS key using <code>KmsKeyId</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"encrypted"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The identifier of the symmetric Key Management Service (KMS) KMS key to use when creating encrypted volumes. If this parameter is not specified, your Amazon Web Services managed KMS key for Amazon EBS is used. If you specify a KMS key, you must also set the encrypted state to <code>true</code>.</p> <p>You can specify a KMS key using any of the following:</p> <ul> <li> <p>Key ID. For example, 1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Key alias. For example, alias/ExampleAlias.</p> </li> <li> <p>Key ARN. For example, arn:aws:kms:us-east-1:012345678910:key/1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Alias ARN. For example, arn:aws:kms:us-east-1:012345678910:alias/ExampleAlias.</p> </li> </ul> <p>Amazon Web Services authenticates the KMS key asynchronously. Therefore, if you specify an identifier that is not valid, the action can appear to complete, but eventually fails.</p> <p>The specified KMS key must exist in the destination Region.</p> <p>Amazon EBS does not support asymmetric KMS keys.</p>",
          "locationName":"kmsKeyId"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the new AMI in the destination Region.</p>"
        },
        "SourceImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI to copy.</p>"
        },
        "SourceRegion":{
          "shape":"String",
          "documentation":"<p>The name of the Region that contains the AMI to copy.</p>"
        },
        "DestinationOutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost to which to copy the AMI. Only specify this parameter when copying an AMI from an Amazon Web Services Region to an Outpost. The AMI must be in the Region of the destination Outpost. You cannot copy an AMI from an Outpost to a Region, from one Outpost to another, or within the same Outpost.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#copy-amis\"> Copy AMIs from an Amazon Web Services Region to an Outpost</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "CopyImageTags":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to include your user-defined AMI tags when copying the AMI.</p> <p>The following tags will not be copied:</p> <ul> <li> <p>System tags (prefixed with <code>aws:</code>)</p> </li> <li> <p>For public and shared AMIs, user-defined tags that are attached by other Amazon Web Services accounts</p> </li> </ul> <p>Default: Your user-defined AMI tags are not copied.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for CopyImage.</p>"
    },
    "CopyImageResult":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the new AMI.</p>",
          "locationName":"imageId"
        }
      },
      "documentation":"<p>Contains the output of CopyImage.</p>"
    },
    "CopySnapshotRequest":{
      "type":"structure",
      "required":[
        "SourceRegion",
        "SourceSnapshotId"
      ],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the EBS snapshot.</p>"
        },
        "DestinationOutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost to which to copy the snapshot. Only specify this parameter when copying a snapshot from an Amazon Web Services Region to an Outpost. The snapshot must be in the Region for the destination Outpost. You cannot copy a snapshot from an Outpost to a Region, from one Outpost to another, or within the same Outpost.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#copy-snapshots\"> Copy snapshots from an Amazon Web Services Region to an Outpost</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "DestinationRegion":{
          "shape":"String",
          "documentation":"<p>The destination Region to use in the <code>PresignedUrl</code> parameter of a snapshot copy operation. This parameter is only valid for specifying the destination Region in a <code>PresignedUrl</code> parameter, where it is required.</p> <p>The snapshot copy is sent to the regional endpoint that you sent the HTTP request to (for example, <code>ec2.us-east-1.amazonaws.com</code>). With the CLI, this is specified using the <code>--region</code> parameter or the default Region in your Amazon Web Services configuration file.</p>",
          "locationName":"destinationRegion"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>To encrypt a copy of an unencrypted snapshot if encryption by default is not enabled, enable encryption using this parameter. Otherwise, omit this parameter. Encrypted snapshots are encrypted, even if you omit this parameter and encryption by default is not enabled. You cannot set this parameter to false. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"encrypted"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The identifier of the Key Management Service (KMS) KMS key to use for Amazon EBS encryption. If this parameter is not specified, your KMS key for Amazon EBS is used. If <code>KmsKeyId</code> is specified, the encrypted state must be <code>true</code>.</p> <p>You can specify the KMS key using any of the following:</p> <ul> <li> <p>Key ID. For example, 1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Key alias. For example, alias/ExampleAlias.</p> </li> <li> <p>Key ARN. For example, arn:aws:kms:us-east-1:012345678910:key/1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Alias ARN. For example, arn:aws:kms:us-east-1:012345678910:alias/ExampleAlias.</p> </li> </ul> <p>Amazon Web Services authenticates the KMS key asynchronously. Therefore, if you specify an ID, alias, or ARN that is not valid, the action can appear to complete, but eventually fails.</p>",
          "locationName":"kmsKeyId"
        },
        "PresignedUrl":{
          "shape":"CopySnapshotRequestPSU",
          "documentation":"<p>When you copy an encrypted source snapshot using the Amazon EC2 Query API, you must supply a pre-signed URL. This parameter is optional for unencrypted snapshots. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html\">Query requests</a>.</p> <p>The <code>PresignedUrl</code> should use the snapshot source endpoint, the <code>CopySnapshot</code> action, and include the <code>SourceRegion</code>, <code>SourceSnapshotId</code>, and <code>DestinationRegion</code> parameters. The <code>PresignedUrl</code> must be signed using Amazon Web Services Signature Version 4. Because EBS snapshots are stored in Amazon S3, the signing algorithm for this parameter uses the same logic that is described in <a href=\"https://docs.aws.amazon.com/AmazonS3/latest/API/sigv4-query-string-auth.html\">Authenticating Requests: Using Query Parameters (Amazon Web Services Signature Version 4)</a> in the <i>Amazon Simple Storage Service API Reference</i>. An invalid or improperly signed <code>PresignedUrl</code> will cause the copy operation to fail asynchronously, and the snapshot will move to an <code>error</code> state.</p>",
          "locationName":"presignedUrl"
        },
        "SourceRegion":{
          "shape":"String",
          "documentation":"<p>The ID of the Region that contains the snapshot to be copied.</p>"
        },
        "SourceSnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the EBS snapshot to copy.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the new snapshot.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "CopySnapshotRequestPSU":{
      "type":"string",
      "sensitive":true
    },
    "CopySnapshotResult":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the new snapshot.</p>",
          "locationName":"snapshotId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags applied to the new snapshot.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "CopyTagsFromSource":{
      "type":"string",
      "enum":["volume"]
    },
    "CoreCount":{"type":"integer"},
    "CoreCountList":{
      "type":"list",
      "member":{
        "shape":"CoreCount",
        "locationName":"item"
      }
    },
    "CoreNetworkArn":{"type":"string"},
    "CpuManufacturer":{
      "type":"string",
      "enum":[
        "intel",
        "amd",
        "amazon-web-services"
      ]
    },
    "CpuManufacturerSet":{
      "type":"list",
      "member":{
        "shape":"CpuManufacturer",
        "locationName":"item"
      }
    },
    "CpuOptions":{
      "type":"structure",
      "members":{
        "CoreCount":{
          "shape":"Integer",
          "documentation":"<p>The number of CPU cores for the instance.</p>",
          "locationName":"coreCount"
        },
        "ThreadsPerCore":{
          "shape":"Integer",
          "documentation":"<p>The number of threads per CPU core.</p>",
          "locationName":"threadsPerCore"
        }
      },
      "documentation":"<p>The CPU options for the instance.</p>"
    },
    "CpuOptionsRequest":{
      "type":"structure",
      "members":{
        "CoreCount":{
          "shape":"Integer",
          "documentation":"<p>The number of CPU cores for the instance.</p>"
        },
        "ThreadsPerCore":{
          "shape":"Integer",
          "documentation":"<p>The number of threads per CPU core. To disable multithreading for the instance, specify a value of <code>1</code>. Otherwise, specify the default value of <code>2</code>.</p>"
        }
      },
      "documentation":"<p>The CPU options for the instance. Both the core count and threads per core must be specified in the request.</p>"
    },
    "CreateCapacityReservationFleetRequest":{
      "type":"structure",
      "required":[
        "InstanceTypeSpecifications",
        "TotalTargetCapacity"
      ],
      "members":{
        "AllocationStrategy":{
          "shape":"String",
          "documentation":"<p>The strategy used by the Capacity Reservation Fleet to determine which of the specified instance types to use. Currently, only the <code>prioritized</code> allocation strategy is supported. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#allocation-strategy\"> Allocation strategy</a> in the Amazon EC2 User Guide.</p> <p>Valid values: <code>prioritized</code> </p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensure Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "InstanceTypeSpecifications":{
          "shape":"ReservationFleetInstanceSpecificationList",
          "documentation":"<p>Information about the instance types for which to reserve the capacity.</p>",
          "locationName":"InstanceTypeSpecification"
        },
        "Tenancy":{
          "shape":"FleetCapacityReservationTenancy",
          "documentation":"<p>Indicates the tenancy of the Capacity Reservation Fleet. All Capacity Reservations in the Fleet inherit this tenancy. The Capacity Reservation Fleet can have one of the following tenancy settings:</p> <ul> <li> <p> <code>default</code> - The Capacity Reservation Fleet is created on hardware that is shared with other Amazon Web Services accounts.</p> </li> <li> <p> <code>dedicated</code> - The Capacity Reservations are created on single-tenant hardware that is dedicated to a single Amazon Web Services account.</p> </li> </ul>"
        },
        "TotalTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The total number of capacity units to be reserved by the Capacity Reservation Fleet. This value, together with the instance type weights that you assign to each instance type used by the Fleet determine the number of instances for which the Fleet reserves capacity. Both values are based on units that make sense for your workload. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#target-capacity\"> Total target capacity</a> in the Amazon EC2 User Guide.</p>"
        },
        "EndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation Fleet expires. When the Capacity Reservation Fleet expires, its state changes to <code>expired</code> and all of the Capacity Reservations in the Fleet expire.</p> <p>The Capacity Reservation Fleet expires within an hour after the specified time. For example, if you specify <code>5/31/2019</code>, <code>13:30:55</code>, the Capacity Reservation Fleet is guaranteed to expire between <code>13:30:55</code> and <code>14:30:55</code> on <code>5/31/2019</code>. </p>"
        },
        "InstanceMatchCriteria":{
          "shape":"FleetInstanceMatchCriteria",
          "documentation":"<p>Indicates the type of instance launches that the Capacity Reservation Fleet accepts. All Capacity Reservations in the Fleet inherit this instance matching criteria.</p> <p>Currently, Capacity Reservation Fleets support <code>open</code> instance matching criteria only. This means that instances that have matching attributes (instance type, platform, and Availability Zone) run in the Capacity Reservations automatically. Instances do not need to explicitly target a Capacity Reservation Fleet to use its reserved capacity.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Capacity Reservation Fleet. The tags are automatically assigned to the Capacity Reservations in the Fleet.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateCapacityReservationFleetResult":{
      "type":"structure",
      "members":{
        "CapacityReservationFleetId":{
          "shape":"CapacityReservationFleetId",
          "documentation":"<p>The ID of the Capacity Reservation Fleet.</p>",
          "locationName":"capacityReservationFleetId"
        },
        "State":{
          "shape":"CapacityReservationFleetState",
          "documentation":"<p>The status of the Capacity Reservation Fleet.</p>",
          "locationName":"state"
        },
        "TotalTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The total number of capacity units for which the Capacity Reservation Fleet reserves capacity.</p>",
          "locationName":"totalTargetCapacity"
        },
        "TotalFulfilledCapacity":{
          "shape":"Double",
          "documentation":"<p>The requested capacity units that have been successfully reserved.</p>",
          "locationName":"totalFulfilledCapacity"
        },
        "InstanceMatchCriteria":{
          "shape":"FleetInstanceMatchCriteria",
          "documentation":"<p>The instance matching criteria for the Capacity Reservation Fleet.</p>",
          "locationName":"instanceMatchCriteria"
        },
        "AllocationStrategy":{
          "shape":"String",
          "documentation":"<p>The allocation strategy used by the Capacity Reservation Fleet.</p>",
          "locationName":"allocationStrategy"
        },
        "CreateTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation Fleet was created.</p>",
          "locationName":"createTime"
        },
        "EndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation Fleet expires.</p>",
          "locationName":"endDate"
        },
        "Tenancy":{
          "shape":"FleetCapacityReservationTenancy",
          "documentation":"<p>Indicates the tenancy of Capacity Reservation Fleet.</p>",
          "locationName":"tenancy"
        },
        "FleetCapacityReservations":{
          "shape":"FleetCapacityReservationSet",
          "documentation":"<p>Information about the individual Capacity Reservations in the Capacity Reservation Fleet.</p>",
          "locationName":"fleetCapacityReservationSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the Capacity Reservation Fleet.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "CreateCapacityReservationRequest":{
      "type":"structure",
      "required":[
        "InstanceType",
        "InstancePlatform",
        "InstanceCount"
      ],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensure Idempotency</a>.</p>"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type for which to reserve capacity. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "InstancePlatform":{
          "shape":"CapacityReservationInstancePlatform",
          "documentation":"<p>The type of operating system for which to reserve capacity.</p>"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to create the Capacity Reservation.</p>"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the Availability Zone in which to create the Capacity Reservation.</p>"
        },
        "Tenancy":{
          "shape":"CapacityReservationTenancy",
          "documentation":"<p>Indicates the tenancy of the Capacity Reservation. A Capacity Reservation can have one of the following tenancy settings:</p> <ul> <li> <p> <code>default</code> - The Capacity Reservation is created on hardware that is shared with other Amazon Web Services accounts.</p> </li> <li> <p> <code>dedicated</code> - The Capacity Reservation is created on single-tenant hardware that is dedicated to a single Amazon Web Services account.</p> </li> </ul>"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances for which to reserve capacity.</p> <p>Valid range: 1 - 1000</p>"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the Capacity Reservation supports EBS-optimized instances. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS- optimized instance.</p>"
        },
        "EphemeralStorage":{
          "shape":"Boolean",
          "documentation":"<p> <i>Deprecated.</i> </p>"
        },
        "EndDate":{
          "shape":"DateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation expires. When a Capacity Reservation expires, the reserved capacity is released and you can no longer launch instances into it. The Capacity Reservation's state changes to <code>expired</code> when it reaches its end date and time.</p> <p>You must provide an <code>EndDate</code> value if <code>EndDateType</code> is <code>limited</code>. Omit <code>EndDate</code> if <code>EndDateType</code> is <code>unlimited</code>.</p> <p>If the <code>EndDateType</code> is <code>limited</code>, the Capacity Reservation is cancelled within an hour from the specified time. For example, if you specify 5/31/2019, 13:30:55, the Capacity Reservation is guaranteed to end between 13:30:55 and 14:30:55 on 5/31/2019.</p>"
        },
        "EndDateType":{
          "shape":"EndDateType",
          "documentation":"<p>Indicates the way in which the Capacity Reservation ends. A Capacity Reservation can have one of the following end types:</p> <ul> <li> <p> <code>unlimited</code> - The Capacity Reservation remains active until you explicitly cancel it. Do not provide an <code>EndDate</code> if the <code>EndDateType</code> is <code>unlimited</code>.</p> </li> <li> <p> <code>limited</code> - The Capacity Reservation expires automatically at a specified date and time. You must provide an <code>EndDate</code> value if the <code>EndDateType</code> value is <code>limited</code>.</p> </li> </ul>"
        },
        "InstanceMatchCriteria":{
          "shape":"InstanceMatchCriteria",
          "documentation":"<p>Indicates the type of instance launches that the Capacity Reservation accepts. The options include:</p> <ul> <li> <p> <code>open</code> - The Capacity Reservation automatically matches all instances that have matching attributes (instance type, platform, and Availability Zone). Instances that have matching attributes run in the Capacity Reservation automatically without specifying any additional parameters.</p> </li> <li> <p> <code>targeted</code> - The Capacity Reservation only accepts instances that have matching attributes (instance type, platform, and Availability Zone), and explicitly target the Capacity Reservation. This ensures that only permitted instances can use the reserved capacity. </p> </li> </ul> <p>Default: <code>open</code> </p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the Capacity Reservation during launch.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "OutpostArn":{
          "shape":"OutpostArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost on which to create the Capacity Reservation.</p>"
        },
        "PlacementGroupArn":{
          "shape":"PlacementGroupArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the cluster placement group in which to create the Capacity Reservation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/cr-cpg.html\"> Capacity Reservations for cluster placement groups</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        }
      }
    },
    "CreateCapacityReservationResult":{
      "type":"structure",
      "members":{
        "CapacityReservation":{
          "shape":"CapacityReservation",
          "documentation":"<p>Information about the Capacity Reservation.</p>",
          "locationName":"capacityReservation"
        }
      }
    },
    "CreateCarrierGatewayRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC to associate with the carrier gateway.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to associate with the carrier gateway.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateCarrierGatewayResult":{
      "type":"structure",
      "members":{
        "CarrierGateway":{
          "shape":"CarrierGateway",
          "documentation":"<p>Information about the carrier gateway.</p>",
          "locationName":"carrierGateway"
        }
      }
    },
    "CreateClientVpnEndpointRequest":{
      "type":"structure",
      "required":[
        "ClientCidrBlock",
        "ServerCertificateArn",
        "AuthenticationOptions",
        "ConnectionLogOptions"
      ],
      "members":{
        "ClientCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, from which to assign client IP addresses. The address range cannot overlap with the local CIDR of the VPC in which the associated subnet is located, or the routes that you add manually. The address range cannot be changed after the Client VPN endpoint has been created. Client CIDR range must have a size of at least /22 and must not be greater than /12.</p>"
        },
        "ServerCertificateArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the server certificate. For more information, see the <a href=\"https://docs.aws.amazon.com/acm/latest/userguide/\">Certificate Manager User Guide</a>.</p>"
        },
        "AuthenticationOptions":{
          "shape":"ClientVpnAuthenticationRequestList",
          "documentation":"<p>Information about the authentication method to be used to authenticate clients.</p>",
          "locationName":"Authentication"
        },
        "ConnectionLogOptions":{
          "shape":"ConnectionLogOptions",
          "documentation":"<p>Information about the client connection logging options.</p> <p>If you enable client connection logging, data about client connections is sent to a Cloudwatch Logs log stream. The following information is logged:</p> <ul> <li> <p>Client connection requests</p> </li> <li> <p>Client connection results (successful and unsuccessful)</p> </li> <li> <p>Reasons for unsuccessful client connection requests</p> </li> <li> <p>Client connection termination time</p> </li> </ul>"
        },
        "DnsServers":{
          "shape":"ValueStringList",
          "documentation":"<p>Information about the DNS servers to be used for DNS resolution. A Client VPN endpoint can have up to two DNS servers. If no DNS server is specified, the DNS address configured on the device is used for the DNS server.</p>"
        },
        "TransportProtocol":{
          "shape":"TransportProtocol",
          "documentation":"<p>The transport protocol to be used by the VPN session.</p> <p>Default value: <code>udp</code> </p>"
        },
        "VpnPort":{
          "shape":"Integer",
          "documentation":"<p>The port number to assign to the Client VPN endpoint for TCP and UDP traffic.</p> <p>Valid Values: <code>443</code> | <code>1194</code> </p> <p>Default Value: <code>443</code> </p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the Client VPN endpoint.</p>"
        },
        "SplitTunnel":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether split-tunnel is enabled on the Client VPN endpoint.</p> <p>By default, split-tunnel on a VPN endpoint is disabled.</p> <p>For information about split-tunnel VPN endpoints, see <a href=\"https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/split-tunnel-vpn.html\">Split-tunnel Client VPN endpoint</a> in the <i>Client VPN Administrator Guide</i>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the Client VPN endpoint during creation.</p>",
          "locationName":"TagSpecification"
        },
        "SecurityGroupIds":{
          "shape":"ClientVpnSecurityGroupIdSet",
          "documentation":"<p>The IDs of one or more security groups to apply to the target network. You must also specify the ID of the VPC that contains the security groups.</p>",
          "locationName":"SecurityGroupId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC to associate with the Client VPN endpoint. If no security group IDs are specified in the request, the default security group for the VPC is applied.</p>"
        },
        "SelfServicePortal":{
          "shape":"SelfServicePortal",
          "documentation":"<p>Specify whether to enable the self-service portal for the Client VPN endpoint.</p> <p>Default Value: <code>enabled</code> </p>"
        },
        "ClientConnectOptions":{
          "shape":"ClientConnectOptions",
          "documentation":"<p>The options for managing connection authorization for new client connections.</p>"
        },
        "SessionTimeoutHours":{
          "shape":"Integer",
          "documentation":"<p>The maximum VPN session duration time in hours.</p> <p>Valid values: <code>8 | 10 | 12 | 24</code> </p> <p>Default value: <code>24</code> </p>"
        },
        "ClientLoginBannerOptions":{
          "shape":"ClientLoginBannerOptions",
          "documentation":"<p>Options for enabling a customizable text banner that will be displayed on Amazon Web Services provided clients when a VPN session is established.</p>"
        }
      }
    },
    "CreateClientVpnEndpointResult":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "Status":{
          "shape":"ClientVpnEndpointStatus",
          "documentation":"<p>The current state of the Client VPN endpoint.</p>",
          "locationName":"status"
        },
        "DnsName":{
          "shape":"String",
          "documentation":"<p>The DNS name to be used by clients when establishing their VPN session.</p>",
          "locationName":"dnsName"
        }
      }
    },
    "CreateClientVpnRouteRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "DestinationCidrBlock",
        "TargetVpcSubnetId"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint to which to add the route.</p>"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the route destination. For example:</p> <ul> <li> <p>To add a route for Internet access, enter <code>0.0.0.0/0</code> </p> </li> <li> <p>To add a route for a peered VPC, enter the peered VPC's IPv4 CIDR range</p> </li> <li> <p>To add a route for an on-premises network, enter the Amazon Web Services Site-to-Site VPN connection's IPv4 CIDR range</p> </li> <li> <p>To add a route for the local network, enter the client CIDR range</p> </li> </ul>"
        },
        "TargetVpcSubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet through which you want to route traffic. The specified subnet must be an existing target network of the Client VPN endpoint.</p> <p>Alternatively, if you're adding a route for the local network, specify <code>local</code>.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the route.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateClientVpnRouteResult":{
      "type":"structure",
      "members":{
        "Status":{
          "shape":"ClientVpnRouteStatus",
          "documentation":"<p>The current state of the route.</p>",
          "locationName":"status"
        }
      }
    },
    "CreateCoipCidrRequest":{
      "type":"structure",
      "required":[
        "Cidr",
        "CoipPoolId"
      ],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p> A customer-owned IP address range to create. </p>"
        },
        "CoipPoolId":{
          "shape":"Ipv4PoolCoipId",
          "documentation":"<p> The ID of the address pool. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateCoipCidrResult":{
      "type":"structure",
      "members":{
        "CoipCidr":{
          "shape":"CoipCidr",
          "documentation":"<p> Information about a range of customer-owned IP addresses. </p>",
          "locationName":"coipCidr"
        }
      }
    },
    "CreateCoipPoolRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableId"],
      "members":{
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p> The ID of the local gateway route table. </p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p> The tags to assign to the CoIP address pool. </p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateCoipPoolResult":{
      "type":"structure",
      "members":{
        "CoipPool":{
          "shape":"CoipPool",
          "documentation":"<p>Information about the CoIP address pool.</p>",
          "locationName":"coipPool"
        }
      }
    },
    "CreateCustomerGatewayRequest":{
      "type":"structure",
      "required":[
        "BgpAsn",
        "Type"
      ],
      "members":{
        "BgpAsn":{
          "shape":"Integer",
          "documentation":"<p>For devices that support BGP, the customer gateway's BGP ASN.</p> <p>Default: 65000</p>"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p> <i>This member has been deprecated.</i> The Internet-routable IP address for the customer gateway's outside interface. The address must be static.</p>"
        },
        "CertificateArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) for the customer gateway certificate.</p>"
        },
        "Type":{
          "shape":"GatewayType",
          "documentation":"<p>The type of VPN connection that this customer gateway supports (<code>ipsec.1</code>).</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the customer gateway.</p>",
          "locationName":"TagSpecification"
        },
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>A name for the customer gateway device.</p> <p>Length Constraints: Up to 255 characters.</p>"
        },
        "IpAddress":{
          "shape":"String",
          "documentation":"<p> IPv4 address for the customer gateway device's outside interface. The address must be static. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for CreateCustomerGateway.</p>"
    },
    "CreateCustomerGatewayResult":{
      "type":"structure",
      "members":{
        "CustomerGateway":{
          "shape":"CustomerGateway",
          "documentation":"<p>Information about the customer gateway.</p>",
          "locationName":"customerGateway"
        }
      },
      "documentation":"<p>Contains the output of CreateCustomerGateway.</p>"
    },
    "CreateDefaultSubnetRequest":{
      "type":"structure",
      "required":["AvailabilityZone"],
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to create the default subnet.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Ipv6Native":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to create an IPv6 only subnet. If you already have a default subnet for this Availability Zone, you must delete it before you can create an IPv6 only subnet.</p>"
        }
      }
    },
    "CreateDefaultSubnetResult":{
      "type":"structure",
      "members":{
        "Subnet":{
          "shape":"Subnet",
          "documentation":"<p>Information about the subnet.</p>",
          "locationName":"subnet"
        }
      }
    },
    "CreateDefaultVpcRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateDefaultVpcResult":{
      "type":"structure",
      "members":{
        "Vpc":{
          "shape":"Vpc",
          "documentation":"<p>Information about the VPC.</p>",
          "locationName":"vpc"
        }
      }
    },
    "CreateDhcpOptionsRequest":{
      "type":"structure",
      "required":["DhcpConfigurations"],
      "members":{
        "DhcpConfigurations":{
          "shape":"NewDhcpConfigurationList",
          "documentation":"<p>A DHCP configuration option.</p>",
          "locationName":"dhcpConfiguration"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the DHCP option.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "CreateDhcpOptionsResult":{
      "type":"structure",
      "members":{
        "DhcpOptions":{
          "shape":"DhcpOptions",
          "documentation":"<p>A set of DHCP options.</p>",
          "locationName":"dhcpOptions"
        }
      }
    },
    "CreateEgressOnlyInternetGatewayRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC for which to create the egress-only internet gateway.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the egress-only internet gateway.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateEgressOnlyInternetGatewayResult":{
      "type":"structure",
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request.</p>",
          "locationName":"clientToken"
        },
        "EgressOnlyInternetGateway":{
          "shape":"EgressOnlyInternetGateway",
          "documentation":"<p>Information about the egress-only internet gateway.</p>",
          "locationName":"egressOnlyInternetGateway"
        }
      }
    },
    "CreateFleetError":{
      "type":"structure",
      "members":{
        "LaunchTemplateAndOverrides":{
          "shape":"LaunchTemplateAndOverridesResponse",
          "documentation":"<p>The launch templates and overrides that were used for launching the instances. The values that you specify in the Overrides replace the values in the launch template.</p>",
          "locationName":"launchTemplateAndOverrides"
        },
        "Lifecycle":{
          "shape":"InstanceLifecycle",
          "documentation":"<p>Indicates if the instance that could not be launched was a Spot Instance or On-Demand Instance.</p>",
          "locationName":"lifecycle"
        },
        "ErrorCode":{
          "shape":"String",
          "documentation":"<p>The error code that indicates why the instance could not be launched. For more information about error codes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html.html\">Error codes</a>.</p>",
          "locationName":"errorCode"
        },
        "ErrorMessage":{
          "shape":"String",
          "documentation":"<p>The error message that describes why the instance could not be launched. For more information about error messages, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html.html\">Error codes</a>.</p>",
          "locationName":"errorMessage"
        }
      },
      "documentation":"<p>Describes the instances that could not be launched by the fleet.</p>"
    },
    "CreateFleetErrorsSet":{
      "type":"list",
      "member":{
        "shape":"CreateFleetError",
        "locationName":"item"
      }
    },
    "CreateFleetInstance":{
      "type":"structure",
      "members":{
        "LaunchTemplateAndOverrides":{
          "shape":"LaunchTemplateAndOverridesResponse",
          "documentation":"<p>The launch templates and overrides that were used for launching the instances. The values that you specify in the Overrides replace the values in the launch template.</p>",
          "locationName":"launchTemplateAndOverrides"
        },
        "Lifecycle":{
          "shape":"InstanceLifecycle",
          "documentation":"<p>Indicates if the instance that was launched is a Spot Instance or On-Demand Instance.</p>",
          "locationName":"lifecycle"
        },
        "InstanceIds":{
          "shape":"InstanceIdsSet",
          "documentation":"<p>The IDs of the instances.</p>",
          "locationName":"instanceIds"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "Platform":{
          "shape":"PlatformValues",
          "documentation":"<p>The value is <code>Windows</code> for Windows instances. Otherwise, the value is blank.</p>",
          "locationName":"platform"
        }
      },
      "documentation":"<p>Describes the instances that were launched by the fleet.</p>"
    },
    "CreateFleetInstancesSet":{
      "type":"list",
      "member":{
        "shape":"CreateFleetInstance",
        "locationName":"item"
      }
    },
    "CreateFleetRequest":{
      "type":"structure",
      "required":[
        "LaunchTemplateConfigs",
        "TargetCapacitySpecification"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p>"
        },
        "SpotOptions":{
          "shape":"SpotOptionsRequest",
          "documentation":"<p>Describes the configuration of Spot Instances in an EC2 Fleet.</p>"
        },
        "OnDemandOptions":{
          "shape":"OnDemandOptionsRequest",
          "documentation":"<p>Describes the configuration of On-Demand Instances in an EC2 Fleet.</p>"
        },
        "ExcessCapacityTerminationPolicy":{
          "shape":"FleetExcessCapacityTerminationPolicy",
          "documentation":"<p>Indicates whether running instances should be terminated if the total target capacity of the EC2 Fleet is decreased below the current size of the EC2 Fleet.</p> <p>Supported only for fleets of type <code>maintain</code>.</p>"
        },
        "LaunchTemplateConfigs":{
          "shape":"FleetLaunchTemplateConfigListRequest",
          "documentation":"<p>The configuration for the EC2 Fleet.</p>"
        },
        "TargetCapacitySpecification":{
          "shape":"TargetCapacitySpecificationRequest",
          "documentation":"<p>The number of units to request.</p>"
        },
        "TerminateInstancesWithExpiration":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether running instances should be terminated when the EC2 Fleet expires.</p>"
        },
        "Type":{
          "shape":"FleetType",
          "documentation":"<p>The fleet type. The default value is <code>maintain</code>.</p> <ul> <li> <p> <code>maintain</code> - The EC2 Fleet places an asynchronous request for your desired capacity, and continues to maintain your desired Spot capacity by replenishing interrupted Spot Instances.</p> </li> <li> <p> <code>request</code> - The EC2 Fleet places an asynchronous one-time request for your desired capacity, but does submit Spot requests in alternative capacity pools if Spot capacity is unavailable, and does not maintain Spot capacity if Spot Instances are interrupted.</p> </li> <li> <p> <code>instant</code> - The EC2 Fleet places a synchronous one-time request for your desired capacity, and returns errors for any instances that could not be launched.</p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-request-type.html\">EC2 Fleet request types</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "ValidFrom":{
          "shape":"DateTime",
          "documentation":"<p>The start date and time of the request, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). The default is to start fulfilling the request immediately.</p>"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date and time of the request, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). At this point, no new EC2 Fleet requests are placed or able to fulfill the request. If no value is specified, the request remains until you cancel it.</p>"
        },
        "ReplaceUnhealthyInstances":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether EC2 Fleet should replace unhealthy Spot Instances. Supported only for fleets of type <code>maintain</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/manage-ec2-fleet.html#ec2-fleet-health-checks\">EC2 Fleet health checks</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key-value pair for tagging the EC2 Fleet request on creation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#tag-resources\">Tagging your resources</a>.</p> <p>If the fleet type is <code>instant</code>, specify a resource type of <code>fleet</code> to tag the fleet or <code>instance</code> to tag the instances at launch.</p> <p>If the fleet type is <code>maintain</code> or <code>request</code>, specify a resource type of <code>fleet</code> to tag the fleet. You cannot specify a resource type of <code>instance</code>. To tag instances at launch, specify the tags in a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#create-launch-template\">launch template</a>.</p>",
          "locationName":"TagSpecification"
        },
        "Context":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>"
        }
      }
    },
    "CreateFleetResult":{
      "type":"structure",
      "members":{
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>",
          "locationName":"fleetId"
        },
        "Errors":{
          "shape":"CreateFleetErrorsSet",
          "documentation":"<p>Information about the instances that could not be launched by the fleet. Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"errorSet"
        },
        "Instances":{
          "shape":"CreateFleetInstancesSet",
          "documentation":"<p>Information about the instances that were launched by the fleet. Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"fleetInstanceSet"
        }
      }
    },
    "CreateFlowLogsRequest":{
      "type":"structure",
      "required":[
        "ResourceIds",
        "ResourceType"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>"
        },
        "DeliverLogsPermissionArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the IAM role that allows Amazon EC2 to publish flow logs to a CloudWatch Logs log group in your account.</p> <p>This parameter is required if the destination type is <code>cloud-watch-logs</code> and unsupported otherwise.</p>"
        },
        "DeliverCrossAccountRole":{
          "shape":"String",
          "documentation":"<p>The ARN of the IAM role that allows Amazon EC2 to publish flow logs across accounts.</p>"
        },
        "LogGroupName":{
          "shape":"String",
          "documentation":"<p>The name of a new or existing CloudWatch Logs log group where Amazon EC2 publishes your flow logs.</p> <p>This parameter is valid only if the destination type is <code>cloud-watch-logs</code>.</p>"
        },
        "ResourceIds":{
          "shape":"FlowLogResourceIds",
          "documentation":"<p>The IDs of the resources to monitor. For example, if the resource type is <code>VPC</code>, specify the IDs of the VPCs.</p> <p>Constraints: Maximum of 25 for transit gateway resource types. Maximum of 1000 for the other resource types.</p>",
          "locationName":"ResourceId"
        },
        "ResourceType":{
          "shape":"FlowLogsResourceType",
          "documentation":"<p>The type of resource to monitor.</p>"
        },
        "TrafficType":{
          "shape":"TrafficType",
          "documentation":"<p>The type of traffic to monitor (accepted traffic, rejected traffic, or all traffic). This parameter is not supported for transit gateway resource types. It is required for the other resource types.</p>"
        },
        "LogDestinationType":{
          "shape":"LogDestinationType",
          "documentation":"<p>The type of destination for the flow log data.</p> <p>Default: <code>cloud-watch-logs</code> </p>"
        },
        "LogDestination":{
          "shape":"String",
          "documentation":"<p>The destination for the flow log data. The meaning of this parameter depends on the destination type.</p> <ul> <li> <p>If the destination type is <code>cloud-watch-logs</code>, specify the ARN of a CloudWatch Logs log group. For example:</p> <p>arn:aws:logs:<i>region</i>:<i>account_id</i>:log-group:<i>my_group</i> </p> <p>Alternatively, use the <code>LogGroupName</code> parameter.</p> </li> <li> <p>If the destination type is <code>s3</code>, specify the ARN of an S3 bucket. For example:</p> <p>arn:aws:s3:::<i>my_bucket</i>/<i>my_subfolder</i>/</p> <p>The subfolder is optional. Note that you can't use <code>AWSLogs</code> as a subfolder name.</p> </li> <li> <p>If the destination type is <code>kinesis-data-firehose</code>, specify the ARN of a Kinesis Data Firehose delivery stream. For example:</p> <p>arn:aws:firehose:<i>region</i>:<i>account_id</i>:deliverystream:<i>my_stream</i> </p> </li> </ul>"
        },
        "LogFormat":{
          "shape":"String",
          "documentation":"<p>The fields to include in the flow log record. List the fields in the order in which they should appear. If you omit this parameter, the flow log is created using the default format. If you specify this parameter, you must include at least one field. For more information about the available fields, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/flow-logs.html#flow-log-records\">Flow log records</a> in the <i>Amazon VPC User Guide</i> or <a href=\"https://docs.aws.amazon.com/vpc/latest/tgw/tgw-flow-logs.html#flow-log-records\">Transit Gateway Flow Log records</a> in the <i>Amazon Web Services Transit Gateway Guide</i>.</p> <p>Specify the fields using the <code>${field-id}</code> format, separated by spaces. For the CLI, surround this parameter value with single quotes on Linux or double quotes on Windows.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the flow logs.</p>",
          "locationName":"TagSpecification"
        },
        "MaxAggregationInterval":{
          "shape":"Integer",
          "documentation":"<p>The maximum interval of time during which a flow of packets is captured and aggregated into a flow log record. The possible values are 60 seconds (1 minute) or 600 seconds (10 minutes). This parameter must be 60 seconds for transit gateway resource types.</p> <p>When a network interface is attached to a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">Nitro-based instance</a>, the aggregation interval is always 60 seconds or less, regardless of the value that you specify.</p> <p>Default: 600</p>"
        },
        "DestinationOptions":{
          "shape":"DestinationOptionsRequest",
          "documentation":"<p>The destination options.</p>"
        }
      }
    },
    "CreateFlowLogsResult":{
      "type":"structure",
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request.</p>",
          "locationName":"clientToken"
        },
        "FlowLogIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the flow logs.</p>",
          "locationName":"flowLogIdSet"
        },
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the flow logs that could not be created successfully.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "CreateFpgaImageRequest":{
      "type":"structure",
      "required":["InputStorageLocation"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InputStorageLocation":{
          "shape":"StorageLocation",
          "documentation":"<p>The location of the encrypted design checkpoint in Amazon S3. The input must be a tarball.</p>"
        },
        "LogsStorageLocation":{
          "shape":"StorageLocation",
          "documentation":"<p>The location in Amazon S3 for the output logs.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the AFI.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>A name for the AFI.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the FPGA image during creation.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateFpgaImageResult":{
      "type":"structure",
      "members":{
        "FpgaImageId":{
          "shape":"String",
          "documentation":"<p>The FPGA image identifier (AFI ID).</p>",
          "locationName":"fpgaImageId"
        },
        "FpgaImageGlobalId":{
          "shape":"String",
          "documentation":"<p>The global FPGA image identifier (AGFI ID).</p>",
          "locationName":"fpgaImageGlobalId"
        }
      }
    },
    "CreateImageRequest":{
      "type":"structure",
      "required":[
        "InstanceId",
        "Name"
      ],
      "members":{
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingRequestList",
          "documentation":"<p>The block device mappings. This parameter cannot be used to modify the encryption status of existing volumes or snapshots. To create an AMI with encrypted snapshots, use the <a>CopyImage</a> action.</p>",
          "locationName":"blockDeviceMapping"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the new image.</p>",
          "locationName":"description"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>A name for the new image.</p> <p>Constraints: 3-128 alphanumeric characters, parentheses (()), square brackets ([]), spaces ( ), periods (.), slashes (/), dashes (-), single quotes ('), at-signs (@), or underscores(_)</p>",
          "locationName":"name"
        },
        "NoReboot":{
          "shape":"Boolean",
          "documentation":"<p>By default, when Amazon EC2 creates the new AMI, it reboots the instance so that it can take snapshots of the attached volumes while data is at rest, in order to ensure a consistent state. You can set the <code>NoReboot</code> parameter to <code>true</code> in the API request, or use the <code>--no-reboot</code> option in the CLI to prevent Amazon EC2 from shutting down and rebooting the instance.</p> <important> <p>If you choose to bypass the shutdown and reboot process by setting the <code>NoReboot</code> parameter to <code>true</code> in the API request, or by using the <code>--no-reboot</code> option in the CLI, we can't guarantee the file system integrity of the created image.</p> </important> <p>Default: <code>false</code> (follow standard reboot process)</p>",
          "locationName":"noReboot"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the AMI and snapshots on creation. You can tag the AMI, the snapshots, or both.</p> <ul> <li> <p>To tag the AMI, the value for <code>ResourceType</code> must be <code>image</code>.</p> </li> <li> <p>To tag the snapshots that are created of the root volume and of other Amazon EBS volumes that are attached to the instance, the value for <code>ResourceType</code> must be <code>snapshot</code>. The same tag is applied to all of the snapshots that are created.</p> </li> </ul> <p>If you specify other values for <code>ResourceType</code>, the request fails.</p> <p>To tag an AMI or snapshot after it has been created, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html\">CreateTags</a>. </p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateImageResult":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the new AMI.</p>",
          "locationName":"imageId"
        }
      }
    },
    "CreateInstanceEventWindowRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the event window.</p>"
        },
        "TimeRanges":{
          "shape":"InstanceEventWindowTimeRangeRequestSet",
          "documentation":"<p>The time range for the event window. If you specify a time range, you can't specify a cron expression.</p>",
          "locationName":"TimeRange"
        },
        "CronExpression":{
          "shape":"InstanceEventWindowCronExpression",
          "documentation":"<p>The cron expression for the event window, for example, <code>* 0-4,20-23 * * 1,5</code>. If you specify a cron expression, you can't specify a time range.</p> <p>Constraints:</p> <ul> <li> <p>Only hour and day of the week values are supported.</p> </li> <li> <p>For day of the week values, you can specify either integers <code>0</code> through <code>6</code>, or alternative single values <code>SUN</code> through <code>SAT</code>.</p> </li> <li> <p>The minute, month, and year must be specified by <code>*</code>.</p> </li> <li> <p>The hour value must be one or a multiple range, for example, <code>0-4</code> or <code>0-4,20-23</code>.</p> </li> <li> <p>Each hour range must be >= 2 hours, for example, <code>0-2</code> or <code>20-23</code>.</p> </li> <li> <p>The event window must be >= 4 hours. The combined total time ranges in the event window must be >= 4 hours.</p> </li> </ul> <p>For more information about cron expressions, see <a href=\"https://en.wikipedia.org/wiki/Cron\">cron</a> on the <i>Wikipedia website</i>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the event window.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateInstanceEventWindowResult":{
      "type":"structure",
      "members":{
        "InstanceEventWindow":{
          "shape":"InstanceEventWindow",
          "documentation":"<p>Information about the event window.</p>",
          "locationName":"instanceEventWindow"
        }
      }
    },
    "CreateInstanceExportTaskRequest":{
      "type":"structure",
      "required":[
        "ExportToS3Task",
        "InstanceId",
        "TargetEnvironment"
      ],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the conversion task or the resource being exported. The maximum length is 255 characters.</p>",
          "locationName":"description"
        },
        "ExportToS3Task":{
          "shape":"ExportToS3TaskSpecification",
          "documentation":"<p>The format and location for an export instance task.</p>",
          "locationName":"exportToS3"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "TargetEnvironment":{
          "shape":"ExportEnvironment",
          "documentation":"<p>The target virtualization environment.</p>",
          "locationName":"targetEnvironment"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the export instance task during creation.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateInstanceExportTaskResult":{
      "type":"structure",
      "members":{
        "ExportTask":{
          "shape":"ExportTask",
          "documentation":"<p>Information about the export instance task.</p>",
          "locationName":"exportTask"
        }
      }
    },
    "CreateInternetGatewayRequest":{
      "type":"structure",
      "members":{
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the internet gateway.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "CreateInternetGatewayResult":{
      "type":"structure",
      "members":{
        "InternetGateway":{
          "shape":"InternetGateway",
          "documentation":"<p>Information about the internet gateway.</p>",
          "locationName":"internetGateway"
        }
      }
    },
    "CreateIpamPoolRequest":{
      "type":"structure",
      "required":[
        "IpamScopeId",
        "AddressFamily"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the scope in which you would like to create the IPAM pool.</p>"
        },
        "Locale":{
          "shape":"String",
          "documentation":"<p>In IPAM, the locale is the Amazon Web Services Region where you want to make an IPAM pool available for allocations. Only resources in the same Region as the locale of the pool can get IP address allocations from the pool. You can only allocate a CIDR for a VPC, for example, from an IPAM pool that shares a locale with the VPC’s Region. Note that once you choose a Locale for a pool, you cannot modify it. If you do not choose a locale, resources in Regions others than the IPAM's home region cannot use CIDRs from this pool.</p> <p>Possible values: Any Amazon Web Services Region, such as us-east-1.</p>"
        },
        "SourceIpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the source IPAM pool. Use this option to create a pool within an existing pool. Note that the CIDR you provision for the pool within the source pool must be available in the source pool's CIDR range.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the IPAM pool.</p>"
        },
        "AddressFamily":{
          "shape":"AddressFamily",
          "documentation":"<p>The IP protocol assigned to this IPAM pool. You must choose either IPv4 or IPv6 protocol for a pool.</p>"
        },
        "AutoImport":{
          "shape":"Boolean",
          "documentation":"<p>If selected, IPAM will continuously look for resources within the CIDR range of this pool and automatically import them as allocations into your IPAM. The CIDRs that will be allocated for these resources must not already be allocated to other resources in order for the import to succeed. IPAM will import a CIDR regardless of its compliance with the pool's allocation rules, so a resource might be imported and subsequently marked as noncompliant. If IPAM discovers multiple CIDRs that overlap, IPAM will import the largest CIDR only. If IPAM discovers multiple CIDRs with matching CIDRs, IPAM will randomly import one of them only. </p> <p>A locale must be set on the pool for this feature to work.</p>"
        },
        "PubliclyAdvertisable":{
          "shape":"Boolean",
          "documentation":"<p>Determines if the pool is publicly advertisable. This option is not available for pools with AddressFamily set to <code>ipv4</code>.</p>"
        },
        "AllocationMinNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The minimum netmask length required for CIDR allocations in this IPAM pool to be compliant. The minimum netmask length must be less than the maximum netmask length. Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128.</p>"
        },
        "AllocationMaxNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The maximum netmask length possible for CIDR allocations in this IPAM pool to be compliant. The maximum netmask length must be greater than the minimum netmask length. Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128.</p>"
        },
        "AllocationDefaultNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The default netmask length for allocations added to this pool. If, for example, the CIDR assigned to this pool is 10.0.0.0/8 and you enter 16 here, new allocations will default to 10.0.0.0/16.</p>"
        },
        "AllocationResourceTags":{
          "shape":"RequestIpamResourceTagList",
          "documentation":"<p>Tags that are required for resources that use CIDRs from this IPAM pool. Resources that do not have these tags will not be allowed to allocate space from the pool. If the resources have their tags changed after they have allocated space or if the allocation tagging requirements are changed on the pool, the resource may be marked as noncompliant.</p>",
          "locationName":"AllocationResourceTag"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "AwsService":{
          "shape":"IpamPoolAwsService",
          "documentation":"<p>Limits which service in Amazon Web Services that the pool can be used in. \"ec2\", for example, allows users to use space for Elastic IP addresses and VPCs.</p>"
        },
        "PublicIpSource":{
          "shape":"IpamPoolPublicIpSource",
          "documentation":"<p>The IP address source for pools in the public scope. Only used for provisioning IP address CIDRs to pools in the public scope. Default is <code>byoip</code>. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/intro-create-ipv6-pools.html\">Create IPv6 pools</a> in the <i>Amazon VPC IPAM User Guide</i>. By default, you can add only one Amazon-provided IPv6 CIDR block to a top-level IPv6 pool if PublicIpSource is <code>amazon</code>. For information on increasing the default limit, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/quotas-ipam.html\"> Quotas for your IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
        }
      }
    },
    "CreateIpamPoolResult":{
      "type":"structure",
      "members":{
        "IpamPool":{
          "shape":"IpamPool",
          "documentation":"<p>Information about the IPAM pool created.</p>",
          "locationName":"ipamPool"
        }
      }
    },
    "CreateIpamRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the IPAM.</p>"
        },
        "OperatingRegions":{
          "shape":"AddIpamOperatingRegionSet",
          "documentation":"<p>The operating Regions for the IPAM. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions. </p> <p>For more information about operating Regions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>",
          "locationName":"OperatingRegion"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateIpamResourceDiscoveryRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the IPAM resource discovery.</p>"
        },
        "OperatingRegions":{
          "shape":"AddIpamOperatingRegionSet",
          "documentation":"<p>Operating Regions for the IPAM resource discovery. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p>",
          "locationName":"OperatingRegion"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>Tag specifications for the IPAM resource discovery.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A client token for the IPAM resource discovery.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateIpamResourceDiscoveryResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscovery":{
          "shape":"IpamResourceDiscovery",
          "documentation":"<p>An IPAM resource discovery.</p>",
          "locationName":"ipamResourceDiscovery"
        }
      }
    },
    "CreateIpamResult":{
      "type":"structure",
      "members":{
        "Ipam":{
          "shape":"Ipam",
          "documentation":"<p>Information about the IPAM created.</p>",
          "locationName":"ipam"
        }
      }
    },
    "CreateIpamScopeRequest":{
      "type":"structure",
      "required":["IpamId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>The ID of the IPAM for which you're creating this scope.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the scope you're creating.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateIpamScopeResult":{
      "type":"structure",
      "members":{
        "IpamScope":{
          "shape":"IpamScope",
          "documentation":"<p>Information about the created scope.</p>",
          "locationName":"ipamScope"
        }
      }
    },
    "CreateKeyPairRequest":{
      "type":"structure",
      "required":["KeyName"],
      "members":{
        "KeyName":{
          "shape":"String",
          "documentation":"<p>A unique name for the key pair.</p> <p>Constraints: Up to 255 ASCII characters</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "KeyType":{
          "shape":"KeyType",
          "documentation":"<p>The type of key pair. Note that ED25519 keys are not supported for Windows instances.</p> <p>Default: <code>rsa</code> </p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the new key pair.</p>",
          "locationName":"TagSpecification"
        },
        "KeyFormat":{
          "shape":"KeyFormat",
          "documentation":"<p>The format of the key pair.</p> <p>Default: <code>pem</code> </p>"
        }
      }
    },
    "CreateLaunchTemplateRequest":{
      "type":"structure",
      "required":[
        "LaunchTemplateName",
        "LaunchTemplateData"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p> <p>Constraint: Maximum 128 ASCII characters.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>A name for the launch template.</p>"
        },
        "VersionDescription":{
          "shape":"VersionDescription",
          "documentation":"<p>A description for the first version of the launch template.</p>"
        },
        "LaunchTemplateData":{
          "shape":"RequestLaunchTemplateData",
          "documentation":"<p>The information for the launch template.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the launch template on creation. To tag the launch template, the resource type must be <code>launch-template</code>.</p> <note> <p>To specify the tags for the resources that are created when an instance is launched, you must use the <code>TagSpecifications</code> parameter in the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestLaunchTemplateData.html\">launch template data</a> structure.</p> </note>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateLaunchTemplateResult":{
      "type":"structure",
      "members":{
        "LaunchTemplate":{
          "shape":"LaunchTemplate",
          "documentation":"<p>Information about the launch template.</p>",
          "locationName":"launchTemplate"
        },
        "Warning":{
          "shape":"ValidationWarning",
          "documentation":"<p>If the launch template contains parameters or parameter combinations that are not valid, an error code and an error message are returned for each issue that's found.</p>",
          "locationName":"warning"
        }
      }
    },
    "CreateLaunchTemplateVersionRequest":{
      "type":"structure",
      "required":["LaunchTemplateData"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p> <p>Constraint: Maximum 128 ASCII characters.</p>"
        },
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify either the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>"
        },
        "SourceVersion":{
          "shape":"String",
          "documentation":"<p>The version number of the launch template version on which to base the new version. The new version inherits the same launch parameters as the source version, except for parameters that you specify in <code>LaunchTemplateData</code>. Snapshots applied to the block device mapping are ignored when creating a new version unless they are explicitly included.</p>"
        },
        "VersionDescription":{
          "shape":"VersionDescription",
          "documentation":"<p>A description for the version of the launch template.</p>"
        },
        "LaunchTemplateData":{
          "shape":"RequestLaunchTemplateData",
          "documentation":"<p>The information for the launch template.</p>"
        },
        "ResolveAlias":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, and if a Systems Manager parameter is specified for <code>ImageId</code>, the AMI ID is displayed in the response for <code>imageID</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#use-an-ssm-parameter-instead-of-an-ami-id\">Use a Systems Manager parameter instead of an AMI ID</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Default: <code>false</code> </p>"
        }
      }
    },
    "CreateLaunchTemplateVersionResult":{
      "type":"structure",
      "members":{
        "LaunchTemplateVersion":{
          "shape":"LaunchTemplateVersion",
          "documentation":"<p>Information about the launch template version.</p>",
          "locationName":"launchTemplateVersion"
        },
        "Warning":{
          "shape":"ValidationWarning",
          "documentation":"<p>If the new version of the launch template contains parameters or parameter combinations that are not valid, an error code and an error message are returned for each issue that's found.</p>",
          "locationName":"warning"
        }
      }
    },
    "CreateLocalGatewayRouteRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableId"],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR range used for destination matches. Routing decisions are based on the most specific match.</p>"
        },
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>"
        },
        "LocalGatewayVirtualInterfaceGroupId":{
          "shape":"LocalGatewayVirtualInterfaceGroupId",
          "documentation":"<p>The ID of the virtual interface group.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p> The ID of the prefix list. Use a prefix list in place of <code>DestinationCidrBlock</code>. You cannot use <code>DestinationPrefixListId</code> and <code>DestinationCidrBlock</code> in the same request. </p>"
        }
      }
    },
    "CreateLocalGatewayRouteResult":{
      "type":"structure",
      "members":{
        "Route":{
          "shape":"LocalGatewayRoute",
          "documentation":"<p>Information about the route.</p>",
          "locationName":"route"
        }
      }
    },
    "CreateLocalGatewayRouteTableRequest":{
      "type":"structure",
      "required":["LocalGatewayId"],
      "members":{
        "LocalGatewayId":{
          "shape":"LocalGatewayId",
          "documentation":"<p> The ID of the local gateway. </p>"
        },
        "Mode":{
          "shape":"LocalGatewayRouteTableMode",
          "documentation":"<p> The mode of the local gateway route table. </p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p> The tags assigned to the local gateway route table. </p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateLocalGatewayRouteTableResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTable":{
          "shape":"LocalGatewayRouteTable",
          "documentation":"<p>Information about the local gateway route table.</p>",
          "locationName":"localGatewayRouteTable"
        }
      }
    },
    "CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationRequest":{
      "type":"structure",
      "required":[
        "LocalGatewayRouteTableId",
        "LocalGatewayVirtualInterfaceGroupId"
      ],
      "members":{
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p> The ID of the local gateway route table. </p>"
        },
        "LocalGatewayVirtualInterfaceGroupId":{
          "shape":"LocalGatewayVirtualInterfaceGroupId",
          "documentation":"<p> The ID of the local gateway route table virtual interface group association. </p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p> The tags assigned to the local gateway route table virtual interface group association. </p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVirtualInterfaceGroupAssociation":{
          "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociation",
          "documentation":"<p>Information about the local gateway route table virtual interface group association.</p>",
          "locationName":"localGatewayRouteTableVirtualInterfaceGroupAssociation"
        }
      }
    },
    "CreateLocalGatewayRouteTableVpcAssociationRequest":{
      "type":"structure",
      "required":[
        "LocalGatewayRouteTableId",
        "VpcId"
      ],
      "members":{
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the local gateway route table VPC association.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateLocalGatewayRouteTableVpcAssociationResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVpcAssociation":{
          "shape":"LocalGatewayRouteTableVpcAssociation",
          "documentation":"<p>Information about the association.</p>",
          "locationName":"localGatewayRouteTableVpcAssociation"
        }
      }
    },
    "CreateManagedPrefixListRequest":{
      "type":"structure",
      "required":[
        "PrefixListName",
        "MaxEntries",
        "AddressFamily"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PrefixListName":{
          "shape":"String",
          "documentation":"<p>A name for the prefix list.</p> <p>Constraints: Up to 255 characters in length. The name cannot start with <code>com.amazonaws</code>.</p>"
        },
        "Entries":{
          "shape":"AddPrefixListEntries",
          "documentation":"<p>One or more entries for the prefix list.</p>",
          "locationName":"Entry"
        },
        "MaxEntries":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of entries for the prefix list.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the prefix list during creation.</p>",
          "locationName":"TagSpecification"
        },
        "AddressFamily":{
          "shape":"String",
          "documentation":"<p>The IP address type.</p> <p>Valid Values: <code>IPv4</code> | <code>IPv6</code> </p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p> <p>Constraints: Up to 255 UTF-8 characters in length.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateManagedPrefixListResult":{
      "type":"structure",
      "members":{
        "PrefixList":{
          "shape":"ManagedPrefixList",
          "documentation":"<p>Information about the prefix list.</p>",
          "locationName":"prefixList"
        }
      }
    },
    "CreateNatGatewayRequest":{
      "type":"structure",
      "required":["SubnetId"],
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>[Public NAT gateways only] The allocation ID of an Elastic IP address to associate with the NAT gateway. You cannot specify an Elastic IP address with a private NAT gateway. If the Elastic IP address is associated with another resource, you must first disassociate it.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p> <p>Constraint: Maximum 64 ASCII characters.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet in which to create the NAT gateway.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the NAT gateway.</p>",
          "locationName":"TagSpecification"
        },
        "ConnectivityType":{
          "shape":"ConnectivityType",
          "documentation":"<p>Indicates whether the NAT gateway supports public or private connectivity. The default is public connectivity.</p>"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IPv4 address to assign to the NAT gateway. If you don't provide an address, a private IPv4 address will be automatically assigned.</p>"
        },
        "SecondaryAllocationIds":{
          "shape":"AllocationIdList",
          "documentation":"<p>Secondary EIP allocation IDs. For more information about secondary addresses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-creating\">Create a NAT gateway</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>",
          "locationName":"SecondaryAllocationId"
        },
        "SecondaryPrivateIpAddresses":{
          "shape":"IpList",
          "documentation":"<p>Secondary private IPv4 addresses. For more information about secondary addresses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-creating\">Create a NAT gateway</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>",
          "locationName":"SecondaryPrivateIpAddress"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"PrivateIpAddressCount",
          "documentation":"<p>[Private NAT gateway only] The number of secondary private IPv4 addresses you want to assign to the NAT gateway. For more information about secondary addresses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-creating\">Create a NAT gateway</a> in the <i>Amazon Virtual Private Cloud User Guide</i>.</p>"
        }
      }
    },
    "CreateNatGatewayResult":{
      "type":"structure",
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier to ensure the idempotency of the request. Only returned if a client token was provided in the request.</p>",
          "locationName":"clientToken"
        },
        "NatGateway":{
          "shape":"NatGateway",
          "documentation":"<p>Information about the NAT gateway.</p>",
          "locationName":"natGateway"
        }
      }
    },
    "CreateNetworkAclEntryRequest":{
      "type":"structure",
      "required":[
        "Egress",
        "NetworkAclId",
        "Protocol",
        "RuleAction",
        "RuleNumber"
      ],
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 network range to allow or deny, in CIDR notation (for example <code>172.16.0.0/24</code>). We modify the specified CIDR block to its canonical form; for example, if you specify <code>100.68.0.18/18</code>, we modify it to <code>100.68.0.0/18</code>.</p>",
          "locationName":"cidrBlock"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Egress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is an egress rule (rule is applied to traffic leaving the subnet).</p>",
          "locationName":"egress"
        },
        "IcmpTypeCode":{
          "shape":"IcmpTypeCode",
          "documentation":"<p>ICMP protocol: The ICMP or ICMPv6 type and code. Required if specifying protocol 1 (ICMP) or protocol 58 (ICMPv6) with an IPv6 CIDR block.</p>",
          "locationName":"Icmp"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 network range to allow or deny, in CIDR notation (for example <code>2001:db8:1234:1a00::/64</code>).</p>",
          "locationName":"ipv6CidrBlock"
        },
        "NetworkAclId":{
          "shape":"NetworkAclId",
          "documentation":"<p>The ID of the network ACL.</p>",
          "locationName":"networkAclId"
        },
        "PortRange":{
          "shape":"PortRange",
          "documentation":"<p>TCP or UDP protocols: The range of ports the rule applies to. Required if specifying protocol 6 (TCP) or 17 (UDP).</p>",
          "locationName":"portRange"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol number. A value of \"-1\" means all protocols. If you specify \"-1\" or a protocol number other than \"6\" (TCP), \"17\" (UDP), or \"1\" (ICMP), traffic on all ports is allowed, regardless of any ports or ICMP types or codes that you specify. If you specify protocol \"58\" (ICMPv6) and specify an IPv4 CIDR block, traffic for all ICMP types and codes allowed, regardless of any that you specify. If you specify protocol \"58\" (ICMPv6) and specify an IPv6 CIDR block, you must specify an ICMP type and code.</p>",
          "locationName":"protocol"
        },
        "RuleAction":{
          "shape":"RuleAction",
          "documentation":"<p>Indicates whether to allow or deny the traffic that matches the rule.</p>",
          "locationName":"ruleAction"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The rule number for the entry (for example, 100). ACL entries are processed in ascending order by rule number.</p> <p>Constraints: Positive integer from 1 to 32766. The range 32767 to 65535 is reserved for internal use.</p>",
          "locationName":"ruleNumber"
        }
      }
    },
    "CreateNetworkAclRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the network ACL.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateNetworkAclResult":{
      "type":"structure",
      "members":{
        "NetworkAcl":{
          "shape":"NetworkAcl",
          "documentation":"<p>Information about the network ACL.</p>",
          "locationName":"networkAcl"
        }
      }
    },
    "CreateNetworkInsightsAccessScopeRequest":{
      "type":"structure",
      "required":["ClientToken"],
      "members":{
        "MatchPaths":{
          "shape":"AccessScopePathListRequest",
          "documentation":"<p>The paths to match.</p>",
          "locationName":"MatchPath"
        },
        "ExcludePaths":{
          "shape":"AccessScopePathListRequest",
          "documentation":"<p>The paths to exclude.</p>",
          "locationName":"ExcludePath"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateNetworkInsightsAccessScopeResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScope":{
          "shape":"NetworkInsightsAccessScope",
          "documentation":"<p>The Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScope"
        },
        "NetworkInsightsAccessScopeContent":{
          "shape":"NetworkInsightsAccessScopeContent",
          "documentation":"<p>The Network Access Scope content.</p>",
          "locationName":"networkInsightsAccessScopeContent"
        }
      }
    },
    "CreateNetworkInsightsPathRequest":{
      "type":"structure",
      "required":[
        "Source",
        "Destination",
        "Protocol",
        "ClientToken"
      ],
      "members":{
        "SourceIp":{
          "shape":"IpAddress",
          "documentation":"<p>The IP address of the Amazon Web Services resource that is the source of the path.</p>"
        },
        "DestinationIp":{
          "shape":"IpAddress",
          "documentation":"<p>The IP address of the Amazon Web Services resource that is the destination of the path.</p>"
        },
        "Source":{
          "shape":"NetworkInsightsResourceId",
          "documentation":"<p>The Amazon Web Services resource that is the source of the path.</p>"
        },
        "Destination":{
          "shape":"NetworkInsightsResourceId",
          "documentation":"<p>The Amazon Web Services resource that is the destination of the path.</p>"
        },
        "Protocol":{
          "shape":"Protocol",
          "documentation":"<p>The protocol.</p>"
        },
        "DestinationPort":{
          "shape":"Port",
          "documentation":"<p>The destination port.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to add to the path.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateNetworkInsightsPathResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsPath":{
          "shape":"NetworkInsightsPath",
          "documentation":"<p>Information about the path.</p>",
          "locationName":"networkInsightsPath"
        }
      }
    },
    "CreateNetworkInterfacePermissionRequest":{
      "type":"structure",
      "required":[
        "NetworkInterfaceId",
        "Permission"
      ],
      "members":{
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>"
        },
        "AwsAccountId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p>"
        },
        "AwsService":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Service. Currently not supported.</p>"
        },
        "Permission":{
          "shape":"InterfacePermissionType",
          "documentation":"<p>The type of permission to grant.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for CreateNetworkInterfacePermission.</p>"
    },
    "CreateNetworkInterfacePermissionResult":{
      "type":"structure",
      "members":{
        "InterfacePermission":{
          "shape":"NetworkInterfacePermission",
          "documentation":"<p>Information about the permission for the network interface.</p>",
          "locationName":"interfacePermission"
        }
      },
      "documentation":"<p>Contains the output of CreateNetworkInterfacePermission.</p>"
    },
    "CreateNetworkInterfaceRequest":{
      "type":"structure",
      "required":["SubnetId"],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the network interface.</p>",
          "locationName":"description"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Groups":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>The IDs of one or more security groups.</p>",
          "locationName":"SecurityGroupId"
        },
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 addresses to assign to a network interface. Amazon EC2 automatically selects the IPv6 addresses from the subnet range.</p> <p>You can't specify a count of IPv6 addresses using this parameter if you've specified one of the following: specific IPv6 addresses, specific IPv6 prefixes, or a count of IPv6 prefixes.</p> <p>If your subnet has the <code>AssignIpv6AddressOnCreation</code> attribute set, you can override that setting by specifying 0 as the IPv6 address count.</p>",
          "locationName":"ipv6AddressCount"
        },
        "Ipv6Addresses":{
          "shape":"InstanceIpv6AddressList",
          "documentation":"<p>The IPv6 addresses from the IPv6 CIDR block range of your subnet.</p> <p>You can't specify IPv6 addresses using this parameter if you've specified one of the following: a count of IPv6 addresses, specific IPv6 prefixes, or a count of IPv6 prefixes.</p>",
          "locationName":"ipv6Addresses"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The primary private IPv4 address of the network interface. If you don't specify an IPv4 address, Amazon EC2 selects one for you from the subnet's IPv4 CIDR range. If you specify an IP address, you cannot indicate any IP addresses specified in <code>privateIpAddresses</code> as primary (only one IP address can be designated as primary).</p>",
          "locationName":"privateIpAddress"
        },
        "PrivateIpAddresses":{
          "shape":"PrivateIpAddressSpecificationList",
          "documentation":"<p>The private IPv4 addresses.</p> <p>You can't specify private IPv4 addresses if you've specified one of the following: a count of private IPv4 addresses, specific IPv4 prefixes, or a count of IPv4 prefixes.</p>",
          "locationName":"privateIpAddresses"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of secondary private IPv4 addresses to assign to a network interface. When you specify a number of secondary IPv4 addresses, Amazon EC2 selects these IP addresses within the subnet's IPv4 CIDR range. You can't specify this option and specify more than one private IP address using <code>privateIpAddresses</code>.</p> <p>You can't specify a count of private IPv4 addresses if you've specified one of the following: specific private IPv4 addresses, specific IPv4 prefixes, or a count of IPv4 prefixes.</p>",
          "locationName":"secondaryPrivateIpAddressCount"
        },
        "Ipv4Prefixes":{
          "shape":"Ipv4PrefixList",
          "documentation":"<p>The IPv4 prefixes assigned to the network interface.</p> <p>You can't specify IPv4 prefixes if you've specified one of the following: a count of IPv4 prefixes, specific private IPv4 addresses, or a count of private IPv4 addresses.</p>",
          "locationName":"Ipv4Prefix"
        },
        "Ipv4PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv4 prefixes that Amazon Web Services automatically assigns to the network interface.</p> <p>You can't specify a count of IPv4 prefixes if you've specified one of the following: specific IPv4 prefixes, specific private IPv4 addresses, or a count of private IPv4 addresses.</p>"
        },
        "Ipv6Prefixes":{
          "shape":"Ipv6PrefixList",
          "documentation":"<p>The IPv6 prefixes assigned to the network interface.</p> <p>You can't specify IPv6 prefixes if you've specified one of the following: a count of IPv6 prefixes, specific IPv6 addresses, or a count of IPv6 addresses.</p>",
          "locationName":"Ipv6Prefix"
        },
        "Ipv6PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 prefixes that Amazon Web Services automatically assigns to the network interface.</p> <p>You can't specify a count of IPv6 prefixes if you've specified one of the following: specific IPv6 prefixes, specific IPv6 addresses, or a count of IPv6 addresses.</p>"
        },
        "InterfaceType":{
          "shape":"NetworkInterfaceCreationType",
          "documentation":"<p>The type of network interface. The default is <code>interface</code>.</p> <p>The only supported values are <code>efa</code> and <code>trunk</code>.</p>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet to associate with the network interface.</p>",
          "locationName":"subnetId"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the new network interface.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateNetworkInterfaceResult":{
      "type":"structure",
      "members":{
        "NetworkInterface":{
          "shape":"NetworkInterface",
          "documentation":"<p>Information about the network interface.</p>",
          "locationName":"networkInterface"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreatePlacementGroupRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>A name for the placement group. Must be unique within the scope of your account for the Region.</p> <p>Constraints: Up to 255 ASCII characters</p>",
          "locationName":"groupName"
        },
        "Strategy":{
          "shape":"PlacementStrategy",
          "documentation":"<p>The placement strategy.</p>",
          "locationName":"strategy"
        },
        "PartitionCount":{
          "shape":"Integer",
          "documentation":"<p>The number of partitions. Valid only when <b>Strategy</b> is set to <code>partition</code>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the new placement group.</p>",
          "locationName":"TagSpecification"
        },
        "SpreadLevel":{
          "shape":"SpreadLevel",
          "documentation":"<p>Determines how placement groups spread instances. </p> <ul> <li> <p>Host – You can use <code>host</code> only with Outpost placement groups.</p> </li> <li> <p>Rack – No usage restrictions.</p> </li> </ul>"
        }
      }
    },
    "CreatePlacementGroupResult":{
      "type":"structure",
      "members":{
        "PlacementGroup":{
          "shape":"PlacementGroup",
          "documentation":"<p>Information about the placement group.</p>",
          "locationName":"placementGroup"
        }
      }
    },
    "CreatePublicIpv4PoolRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreatePublicIpv4PoolResult":{
      "type":"structure",
      "members":{
        "PoolId":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of the public IPv4 pool.</p>",
          "locationName":"poolId"
        }
      }
    },
    "CreateReplaceRootVolumeTaskRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance for which to replace the root volume.</p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot from which to restore the replacement root volume. The specified snapshot must be a snapshot that you previously created from the original root volume.</p> <p>If you want to restore the replacement root volume to the initial launch state, or if you want to restore the replacement root volume from an AMI, omit this parameter.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure the idempotency of the request. If you do not specify a client token, a randomly generated token is used for the request to ensure idempotency. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the root volume replacement task.</p>",
          "locationName":"TagSpecification"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI to use to restore the root volume. The specified AMI must have the same product code, billing information, architecture type, and virtualization type as that of the instance.</p> <p>If you want to restore the replacement volume from a specific snapshot, or if you want to restore it to its launch state, omit this parameter.</p>"
        },
        "DeleteReplacedRootVolume":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to automatically delete the original root volume after the root volume replacement task completes. To delete the original root volume, specify <code>true</code>. If you choose to keep the original root volume after the replacement task completes, you must manually delete it when you no longer need it.</p>"
        }
      }
    },
    "CreateReplaceRootVolumeTaskResult":{
      "type":"structure",
      "members":{
        "ReplaceRootVolumeTask":{
          "shape":"ReplaceRootVolumeTask",
          "documentation":"<p>Information about the root volume replacement task.</p>",
          "locationName":"replaceRootVolumeTask"
        }
      }
    },
    "CreateReservedInstancesListingRequest":{
      "type":"structure",
      "required":[
        "ClientToken",
        "InstanceCount",
        "PriceSchedules",
        "ReservedInstancesId"
      ],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure idempotency of your listings. This helps avoid duplicate listings. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances that are a part of a Reserved Instance account to be listed in the Reserved Instance Marketplace. This number should be less than or equal to the instance count associated with the Reserved Instance ID specified in this call.</p>",
          "locationName":"instanceCount"
        },
        "PriceSchedules":{
          "shape":"PriceScheduleSpecificationList",
          "documentation":"<p>A list specifying the price of the Standard Reserved Instance for each month remaining in the Reserved Instance term.</p>",
          "locationName":"priceSchedules"
        },
        "ReservedInstancesId":{
          "shape":"ReservationId",
          "documentation":"<p>The ID of the active Standard Reserved Instance.</p>",
          "locationName":"reservedInstancesId"
        }
      },
      "documentation":"<p>Contains the parameters for CreateReservedInstancesListing.</p>"
    },
    "CreateReservedInstancesListingResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesListings":{
          "shape":"ReservedInstancesListingList",
          "documentation":"<p>Information about the Standard Reserved Instance listing.</p>",
          "locationName":"reservedInstancesListingsSet"
        }
      },
      "documentation":"<p>Contains the output of CreateReservedInstancesListing.</p>"
    },
    "CreateRestoreImageTaskRequest":{
      "type":"structure",
      "required":[
        "Bucket",
        "ObjectKey"
      ],
      "members":{
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket that contains the stored AMI object.</p>"
        },
        "ObjectKey":{
          "shape":"String",
          "documentation":"<p>The name of the stored AMI object in the bucket.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name for the restored AMI. The name must be unique for AMIs in the Region for this account. If you do not provide a name, the new AMI gets the same name as the original AMI.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the AMI and snapshots on restoration. You can tag the AMI, the snapshots, or both.</p> <ul> <li> <p>To tag the AMI, the value for <code>ResourceType</code> must be <code>image</code>.</p> </li> <li> <p>To tag the snapshots, the value for <code>ResourceType</code> must be <code>snapshot</code>. The same tag is applied to all of the snapshots that are created.</p> </li> </ul>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateRestoreImageTaskResult":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The AMI ID.</p>",
          "locationName":"imageId"
        }
      }
    },
    "CreateRouteRequest":{
      "type":"structure",
      "required":["RouteTableId"],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR address block used for the destination match. Routing decisions are based on the most specific match. We modify the specified CIDR block to its canonical form; for example, if you specify <code>100.68.0.18/18</code>, we modify it to <code>100.68.0.0/18</code>.</p>",
          "locationName":"destinationCidrBlock"
        },
        "DestinationIpv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block used for the destination match. Routing decisions are based on the most specific match.</p>",
          "locationName":"destinationIpv6CidrBlock"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of a prefix list used for the destination match.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcEndpointId":{
          "shape":"VpcEndpointId",
          "documentation":"<p>The ID of a VPC endpoint. Supported for Gateway Load Balancer endpoints only.</p>"
        },
        "EgressOnlyInternetGatewayId":{
          "shape":"EgressOnlyInternetGatewayId",
          "documentation":"<p>[IPv6 traffic only] The ID of an egress-only internet gateway.</p>",
          "locationName":"egressOnlyInternetGatewayId"
        },
        "GatewayId":{
          "shape":"RouteGatewayId",
          "documentation":"<p>The ID of an internet gateway or virtual private gateway attached to your VPC.</p>",
          "locationName":"gatewayId"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of a NAT instance in your VPC. The operation fails if you specify an instance ID unless exactly one network interface is attached.</p>",
          "locationName":"instanceId"
        },
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>[IPv4 traffic only] The ID of a NAT gateway.</p>",
          "locationName":"natGatewayId"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of a transit gateway.</p>"
        },
        "LocalGatewayId":{
          "shape":"LocalGatewayId",
          "documentation":"<p>The ID of the local gateway.</p>"
        },
        "CarrierGatewayId":{
          "shape":"CarrierGatewayId",
          "documentation":"<p>The ID of the carrier gateway.</p> <p>You can only use this option when the VPC contains a subnet which is associated with a Wavelength Zone.</p>"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of a network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table for the route.</p>",
          "locationName":"routeTableId"
        },
        "VpcPeeringConnectionId":{
          "shape":"VpcPeeringConnectionId",
          "documentation":"<p>The ID of a VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        },
        "CoreNetworkArn":{
          "shape":"CoreNetworkArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the core network.</p>"
        }
      }
    },
    "CreateRouteResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "CreateRouteTableRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the route table.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateRouteTableResult":{
      "type":"structure",
      "members":{
        "RouteTable":{
          "shape":"RouteTable",
          "documentation":"<p>Information about the route table.</p>",
          "locationName":"routeTable"
        }
      }
    },
    "CreateSecurityGroupRequest":{
      "type":"structure",
      "required":[
        "Description",
        "GroupName"
      ],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the security group. This is informational only.</p> <p>Constraints: Up to 255 characters in length</p> <p>Constraints for EC2-Classic: ASCII characters</p> <p>Constraints for EC2-VPC: a-z, A-Z, 0-9, spaces, and ._-:/()#,@[]+=&;{}!$*</p>",
          "locationName":"GroupDescription"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the security group.</p> <p>Constraints: Up to 255 characters in length. Cannot start with <code>sg-</code>.</p> <p>Constraints for EC2-Classic: ASCII characters</p> <p>Constraints for EC2-VPC: a-z, A-Z, 0-9, spaces, and ._-:/()#,@[]+=&;{}!$*</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>[EC2-VPC] The ID of the VPC. Required for EC2-VPC.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the security group.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "CreateSecurityGroupResult":{
      "type":"structure",
      "members":{
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the security group.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "CreateSnapshotRequest":{
      "type":"structure",
      "required":["VolumeId"],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the snapshot.</p>"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost on which to create a local snapshot.</p> <ul> <li> <p>To create a snapshot of a volume in a Region, omit this parameter. The snapshot is created in the same Region as the volume.</p> </li> <li> <p>To create a snapshot of a volume on an Outpost and store the snapshot in the Region, omit this parameter. The snapshot is created in the Region for the Outpost.</p> </li> <li> <p>To create a snapshot of a volume on an Outpost and store the snapshot on an Outpost, specify the ARN of the destination Outpost. The snapshot must be created on the same Outpost as the volume.</p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#create-snapshot\">Create local snapshots from volumes on an Outpost</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the Amazon EBS volume.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the snapshot during creation.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "CreateSnapshotsRequest":{
      "type":"structure",
      "required":["InstanceSpecification"],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p> A description propagated to every snapshot specified by the instance.</p>"
        },
        "InstanceSpecification":{
          "shape":"InstanceSpecification",
          "documentation":"<p>The instance to specify which volumes should be included in the snapshots.</p>"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost on which to create the local snapshots.</p> <ul> <li> <p>To create snapshots from an instance in a Region, omit this parameter. The snapshots are created in the same Region as the instance.</p> </li> <li> <p>To create snapshots from an instance on an Outpost and store the snapshots in the Region, omit this parameter. The snapshots are created in the Region for the Outpost.</p> </li> <li> <p>To create snapshots from an instance on an Outpost and store the snapshots on an Outpost, specify the ARN of the destination Outpost. The snapshots must be created on the same Outpost as the instance.</p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#create-multivol-snapshot\"> Create multi-volume local snapshots from instances on an Outpost</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>Tags to apply to every snapshot specified by the instance.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "CopyTagsFromSource":{
          "shape":"CopyTagsFromSource",
          "documentation":"<p>Copies the tags from the specified volume to corresponding snapshot.</p>"
        }
      }
    },
    "CreateSnapshotsResult":{
      "type":"structure",
      "members":{
        "Snapshots":{
          "shape":"SnapshotSet",
          "documentation":"<p>List of snapshots.</p>",
          "locationName":"snapshotSet"
        }
      }
    },
    "CreateSpotDatafeedSubscriptionRequest":{
      "type":"structure",
      "required":["Bucket"],
      "members":{
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket in which to store the Spot Instance data feed. For more information about bucket names, see <a href=\"https://docs.aws.amazon.com/AmazonS3/latest/dev/BucketRestrictions.html#bucketnamingrules\">Rules for bucket naming</a> in the <i>Amazon S3 Developer Guide</i>.</p>",
          "locationName":"bucket"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Prefix":{
          "shape":"String",
          "documentation":"<p>The prefix for the data feed file names.</p>",
          "locationName":"prefix"
        }
      },
      "documentation":"<p>Contains the parameters for CreateSpotDatafeedSubscription.</p>"
    },
    "CreateSpotDatafeedSubscriptionResult":{
      "type":"structure",
      "members":{
        "SpotDatafeedSubscription":{
          "shape":"SpotDatafeedSubscription",
          "documentation":"<p>The Spot Instance data feed subscription.</p>",
          "locationName":"spotDatafeedSubscription"
        }
      },
      "documentation":"<p>Contains the output of CreateSpotDatafeedSubscription.</p>"
    },
    "CreateStoreImageTaskRequest":{
      "type":"structure",
      "required":[
        "ImageId",
        "Bucket"
      ],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket in which the AMI object will be stored. The bucket must be in the Region in which the request is being made. The AMI object appears in the bucket only after the upload task has completed. </p>"
        },
        "S3ObjectTags":{
          "shape":"S3ObjectTagList",
          "documentation":"<p>The tags to apply to the AMI object that will be stored in the Amazon S3 bucket. </p>",
          "locationName":"S3ObjectTag"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateStoreImageTaskResult":{
      "type":"structure",
      "members":{
        "ObjectKey":{
          "shape":"String",
          "documentation":"<p>The name of the stored AMI object in the S3 bucket.</p>",
          "locationName":"objectKey"
        }
      }
    },
    "CreateSubnetCidrReservationRequest":{
      "type":"structure",
      "required":[
        "SubnetId",
        "Cidr",
        "ReservationType"
      ],
      "members":{
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 or IPV6 CIDR range to reserve.</p>"
        },
        "ReservationType":{
          "shape":"SubnetCidrReservationType",
          "documentation":"<p>The type of reservation.</p> <p>The following are valid values:</p> <ul> <li> <p> <code>prefix</code>: The Amazon EC2 Prefix Delegation feature assigns the IP addresses to network interfaces that are associated with an instance. For information about Prefix Delegation, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-prefix-delegation.html\">Prefix Delegation for Amazon EC2 network interfaces</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </li> <li> <p> <code>explicit</code>: You manually assign the IP addresses to resources that reside in your subnet. </p> </li> </ul>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description to assign to the subnet CIDR reservation.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the subnet CIDR reservation.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateSubnetCidrReservationResult":{
      "type":"structure",
      "members":{
        "SubnetCidrReservation":{
          "shape":"SubnetCidrReservation",
          "documentation":"<p>Information about the created subnet CIDR reservation.</p>",
          "locationName":"subnetCidrReservation"
        }
      }
    },
    "CreateSubnetRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the subnet.</p>",
          "locationName":"TagSpecification"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone or Local Zone for the subnet.</p> <p>Default: Amazon Web Services selects one for you. If you create more than one subnet in your VPC, we do not necessarily select a different zone for each subnet.</p> <p>To create a subnet in a Local Zone, set this value to the Local Zone ID, for example <code>us-west-2-lax-1a</code>. For information about the Regions that support Local Zones, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html#concepts-available-regions\">Available Regions</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>To create a subnet in an Outpost, set this value to the Availability Zone for the Outpost and specify the Outpost ARN.</p>"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The AZ ID or the Local Zone ID of the subnet.</p>"
        },
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 network range for the subnet, in CIDR notation. For example, <code>10.0.0.0/24</code>. We modify the specified CIDR block to its canonical form; for example, if you specify <code>100.68.0.18/18</code>, we modify it to <code>100.68.0.0/18</code>.</p> <p>This parameter is not supported for an IPv6 only subnet.</p>"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 network range for the subnet, in CIDR notation. The subnet size must use a /64 prefix length.</p> <p>This parameter is required for an IPv6 only subnet.</p>"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost. If you specify an Outpost ARN, you must also specify the Availability Zone of the Outpost subnet.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Ipv6Native":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to create an IPv6 only subnet.</p>"
        }
      }
    },
    "CreateSubnetResult":{
      "type":"structure",
      "members":{
        "Subnet":{
          "shape":"Subnet",
          "documentation":"<p>Information about the subnet.</p>",
          "locationName":"subnet"
        }
      }
    },
    "CreateTagsRequest":{
      "type":"structure",
      "required":[
        "Resources",
        "Tags"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Resources":{
          "shape":"ResourceIdList",
          "documentation":"<p>The IDs of the resources, separated by spaces.</p> <p>Constraints: Up to 1000 resource IDs. We recommend breaking up this request into smaller batches.</p>",
          "locationName":"ResourceId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags. The <code>value</code> parameter is required, but if you don't want the tag to have a value, specify the parameter with no value, and we set the value to an empty string.</p>",
          "locationName":"Tag"
        }
      }
    },
    "CreateTrafficMirrorFilterRequest":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror filter.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to a Traffic Mirror filter.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateTrafficMirrorFilterResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilter":{
          "shape":"TrafficMirrorFilter",
          "documentation":"<p>Information about the Traffic Mirror filter.</p>",
          "locationName":"trafficMirrorFilter"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateTrafficMirrorFilterRuleRequest":{
      "type":"structure",
      "required":[
        "TrafficMirrorFilterId",
        "TrafficDirection",
        "RuleNumber",
        "RuleAction",
        "DestinationCidrBlock",
        "SourceCidrBlock"
      ],
      "members":{
        "TrafficMirrorFilterId":{
          "shape":"TrafficMirrorFilterId",
          "documentation":"<p>The ID of the filter that this rule is associated with.</p>"
        },
        "TrafficDirection":{
          "shape":"TrafficDirection",
          "documentation":"<p>The type of traffic.</p>"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The number of the Traffic Mirror rule. This number must be unique for each Traffic Mirror rule in a given direction. The rules are processed in ascending order by rule number.</p>"
        },
        "RuleAction":{
          "shape":"TrafficMirrorRuleAction",
          "documentation":"<p>The action to take on the filtered traffic.</p>"
        },
        "DestinationPortRange":{
          "shape":"TrafficMirrorPortRangeRequest",
          "documentation":"<p>The destination port range.</p>"
        },
        "SourcePortRange":{
          "shape":"TrafficMirrorPortRangeRequest",
          "documentation":"<p>The source port range.</p>"
        },
        "Protocol":{
          "shape":"Integer",
          "documentation":"<p>The protocol, for example UDP, to assign to the Traffic Mirror rule.</p> <p>For information about the protocol value, see <a href=\"https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers</a> on the Internet Assigned Numbers Authority (IANA) website.</p>"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The destination CIDR block to assign to the Traffic Mirror rule.</p>"
        },
        "SourceCidrBlock":{
          "shape":"String",
          "documentation":"<p>The source CIDR block to assign to the Traffic Mirror rule.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror rule.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateTrafficMirrorFilterRuleResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterRule":{
          "shape":"TrafficMirrorFilterRule",
          "documentation":"<p>The Traffic Mirror rule.</p>",
          "locationName":"trafficMirrorFilterRule"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateTrafficMirrorSessionRequest":{
      "type":"structure",
      "required":[
        "NetworkInterfaceId",
        "TrafficMirrorTargetId",
        "TrafficMirrorFilterId",
        "SessionNumber"
      ],
      "members":{
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the source network interface.</p>"
        },
        "TrafficMirrorTargetId":{
          "shape":"TrafficMirrorTargetId",
          "documentation":"<p>The ID of the Traffic Mirror target.</p>"
        },
        "TrafficMirrorFilterId":{
          "shape":"TrafficMirrorFilterId",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>"
        },
        "PacketLength":{
          "shape":"Integer",
          "documentation":"<p>The number of bytes in each packet to mirror. These are bytes after the VXLAN header. Do not specify this parameter when you want to mirror the entire packet. To mirror a subset of the packet, set this to the length (in bytes) that you want to mirror. For example, if you set this value to 100, then the first 100 bytes that meet the filter criteria are copied to the target.</p> <p>If you do not want to mirror the entire packet, use the <code>PacketLength</code> parameter to specify the number of bytes in each packet to mirror.</p>"
        },
        "SessionNumber":{
          "shape":"Integer",
          "documentation":"<p>The session number determines the order in which sessions are evaluated when an interface is used by multiple sessions. The first session with a matching filter is the one that mirrors the packets.</p> <p>Valid values are 1-32766.</p>"
        },
        "VirtualNetworkId":{
          "shape":"Integer",
          "documentation":"<p>The VXLAN ID for the Traffic Mirror session. For more information about the VXLAN protocol, see <a href=\"https://tools.ietf.org/html/rfc7348\">RFC 7348</a>. If you do not specify a <code>VirtualNetworkId</code>, an account-wide unique id is chosen at random.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror session.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to a Traffic Mirror session.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateTrafficMirrorSessionResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorSession":{
          "shape":"TrafficMirrorSession",
          "documentation":"<p>Information about the Traffic Mirror session.</p>",
          "locationName":"trafficMirrorSession"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateTrafficMirrorTargetRequest":{
      "type":"structure",
      "members":{
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The network interface ID that is associated with the target.</p>"
        },
        "NetworkLoadBalancerArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Network Load Balancer that is associated with the target.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror target.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Traffic Mirror target.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "GatewayLoadBalancerEndpointId":{
          "shape":"VpcEndpointId",
          "documentation":"<p>The ID of the Gateway Load Balancer endpoint.</p>"
        }
      }
    },
    "CreateTrafficMirrorTargetResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorTarget":{
          "shape":"TrafficMirrorTarget",
          "documentation":"<p>Information about the Traffic Mirror target.</p>",
          "locationName":"trafficMirrorTarget"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateTransitGatewayConnectPeerRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayAttachmentId",
        "PeerAddress",
        "InsideCidrBlocks"
      ],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the Connect attachment.</p>"
        },
        "TransitGatewayAddress":{
          "shape":"String",
          "documentation":"<p>The peer IP address (GRE outer IP address) on the transit gateway side of the Connect peer, which must be specified from a transit gateway CIDR block. If not specified, Amazon automatically assigns the first available IP address from the transit gateway CIDR block.</p>"
        },
        "PeerAddress":{
          "shape":"String",
          "documentation":"<p>The peer IP address (GRE outer IP address) on the appliance side of the Connect peer.</p>"
        },
        "BgpOptions":{
          "shape":"TransitGatewayConnectRequestBgpOptions",
          "documentation":"<p>The BGP options for the Connect peer.</p>"
        },
        "InsideCidrBlocks":{
          "shape":"InsideCidrBlocksStringList",
          "documentation":"<p>The range of inside IP addresses that are used for BGP peering. You must specify a size /29 IPv4 CIDR block from the <code>169.254.0.0/16</code> range. The first address from the range must be configured on the appliance as the BGP IP address. You can also optionally specify a size /125 IPv6 CIDR block from the <code>fd00::/8</code> range.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the Connect peer.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayConnectPeerResult":{
      "type":"structure",
      "members":{
        "TransitGatewayConnectPeer":{
          "shape":"TransitGatewayConnectPeer",
          "documentation":"<p>Information about the Connect peer.</p>",
          "locationName":"transitGatewayConnectPeer"
        }
      }
    },
    "CreateTransitGatewayConnectRequest":{
      "type":"structure",
      "required":[
        "TransportTransitGatewayAttachmentId",
        "Options"
      ],
      "members":{
        "TransportTransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment. You can specify a VPC attachment or Amazon Web Services Direct Connect attachment.</p>"
        },
        "Options":{
          "shape":"CreateTransitGatewayConnectRequestOptions",
          "documentation":"<p>The Connect attachment options.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the Connect attachment.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayConnectRequestOptions":{
      "type":"structure",
      "required":["Protocol"],
      "members":{
        "Protocol":{
          "shape":"ProtocolValue",
          "documentation":"<p>The tunnel protocol.</p>"
        }
      },
      "documentation":"<p>The options for a Connect attachment.</p>"
    },
    "CreateTransitGatewayConnectResult":{
      "type":"structure",
      "members":{
        "TransitGatewayConnect":{
          "shape":"TransitGatewayConnect",
          "documentation":"<p>Information about the Connect attachment.</p>",
          "locationName":"transitGatewayConnect"
        }
      }
    },
    "CreateTransitGatewayMulticastDomainRequest":{
      "type":"structure",
      "required":["TransitGatewayId"],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "Options":{
          "shape":"CreateTransitGatewayMulticastDomainRequestOptions",
          "documentation":"<p>The options for the transit gateway multicast domain.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags for the transit gateway multicast domain.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayMulticastDomainRequestOptions":{
      "type":"structure",
      "members":{
        "Igmpv2Support":{
          "shape":"Igmpv2SupportValue",
          "documentation":"<p>Specify whether to enable Internet Group Management Protocol (IGMP) version 2 for the transit gateway multicast domain.</p>"
        },
        "StaticSourcesSupport":{
          "shape":"StaticSourcesSupportValue",
          "documentation":"<p>Specify whether to enable support for statically configuring multicast group sources for a domain.</p>"
        },
        "AutoAcceptSharedAssociations":{
          "shape":"AutoAcceptSharedAssociationsValue",
          "documentation":"<p>Indicates whether to automatically accept cross-account subnet associations that are associated with the transit gateway multicast domain.</p>"
        }
      },
      "documentation":"<p>The options for the transit gateway multicast domain.</p>"
    },
    "CreateTransitGatewayMulticastDomainResult":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomain":{
          "shape":"TransitGatewayMulticastDomain",
          "documentation":"<p>Information about the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomain"
        }
      }
    },
    "CreateTransitGatewayPeeringAttachmentRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayId",
        "PeerTransitGatewayId",
        "PeerAccountId",
        "PeerRegion"
      ],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "PeerTransitGatewayId":{
          "shape":"TransitAssociationGatewayId",
          "documentation":"<p>The ID of the peer transit gateway with which to create the peering attachment.</p>"
        },
        "PeerAccountId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the peer transit gateway.</p>"
        },
        "PeerRegion":{
          "shape":"String",
          "documentation":"<p>The Region where the peer transit gateway is located.</p>"
        },
        "Options":{
          "shape":"CreateTransitGatewayPeeringAttachmentRequestOptions",
          "documentation":"<p>Requests a transit gateway peering attachment.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the transit gateway peering attachment.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayPeeringAttachmentRequestOptions":{
      "type":"structure",
      "members":{
        "DynamicRouting":{
          "shape":"DynamicRoutingValue",
          "documentation":"<p>Indicates whether dynamic routing is enabled or disabled.</p>"
        }
      },
      "documentation":"<p>Describes whether dynamic routing is enabled or disabled for the transit gateway peering request.</p>"
    },
    "CreateTransitGatewayPeeringAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPeeringAttachment":{
          "shape":"TransitGatewayPeeringAttachment",
          "documentation":"<p>The transit gateway peering attachment.</p>",
          "locationName":"transitGatewayPeeringAttachment"
        }
      }
    },
    "CreateTransitGatewayPolicyTableRequest":{
      "type":"structure",
      "required":["TransitGatewayId"],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway used for the policy table.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags specification for the transit gateway policy table created during the request.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayPolicyTableResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTable":{
          "shape":"TransitGatewayPolicyTable",
          "documentation":"<p>Describes the created transit gateway policy table.</p>",
          "locationName":"transitGatewayPolicyTable"
        }
      }
    },
    "CreateTransitGatewayPrefixListReferenceRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "PrefixListId"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list that is used for destination matches.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment to which traffic is routed.</p>"
        },
        "Blackhole":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to drop traffic that matches this route.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayPrefixListReferenceResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPrefixListReference":{
          "shape":"TransitGatewayPrefixListReference",
          "documentation":"<p>Information about the prefix list reference.</p>",
          "locationName":"transitGatewayPrefixListReference"
        }
      }
    },
    "CreateTransitGatewayRequest":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the transit gateway.</p>"
        },
        "Options":{
          "shape":"TransitGatewayRequestOptions",
          "documentation":"<p>The transit gateway options.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the transit gateway.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayResult":{
      "type":"structure",
      "members":{
        "TransitGateway":{
          "shape":"TransitGateway",
          "documentation":"<p>Information about the transit gateway.</p>",
          "locationName":"transitGateway"
        }
      }
    },
    "CreateTransitGatewayRouteRequest":{
      "type":"structure",
      "required":[
        "DestinationCidrBlock",
        "TransitGatewayRouteTableId"
      ],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR range used for destination matches. Routing decisions are based on the most specific match.</p>"
        },
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "Blackhole":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to drop traffic that matches this route.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayRouteResult":{
      "type":"structure",
      "members":{
        "Route":{
          "shape":"TransitGatewayRoute",
          "documentation":"<p>Information about the route.</p>",
          "locationName":"route"
        }
      }
    },
    "CreateTransitGatewayRouteTableAnnouncementRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "PeeringAttachmentId"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "PeeringAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the peering attachment.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags specifications applied to the transit gateway route table announcement.</p>",
          "locationName":"TagSpecification"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayRouteTableAnnouncementResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableAnnouncement":{
          "shape":"TransitGatewayRouteTableAnnouncement",
          "documentation":"<p>Provides details about the transit gateway route table announcement.</p>",
          "locationName":"transitGatewayRouteTableAnnouncement"
        }
      }
    },
    "CreateTransitGatewayRouteTableRequest":{
      "type":"structure",
      "required":["TransitGatewayId"],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the transit gateway route table.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayRouteTableResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTable":{
          "shape":"TransitGatewayRouteTable",
          "documentation":"<p>Information about the transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTable"
        }
      }
    },
    "CreateTransitGatewayVpcAttachmentRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayId",
        "VpcId",
        "SubnetIds"
      ],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "SubnetIds":{
          "shape":"TransitGatewaySubnetIdList",
          "documentation":"<p>The IDs of one or more subnets. You can specify only one subnet per Availability Zone. You must specify at least one subnet, but we recommend that you specify two subnets for better availability. The transit gateway uses one IP address from each specified subnet.</p>"
        },
        "Options":{
          "shape":"CreateTransitGatewayVpcAttachmentRequestOptions",
          "documentation":"<p>The VPC attachment options.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the VPC attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateTransitGatewayVpcAttachmentRequestOptions":{
      "type":"structure",
      "members":{
        "DnsSupport":{
          "shape":"DnsSupportValue",
          "documentation":"<p>Enable or disable DNS support. The default is <code>enable</code>.</p>"
        },
        "Ipv6Support":{
          "shape":"Ipv6SupportValue",
          "documentation":"<p>Enable or disable IPv6 support. The default is <code>disable</code>.</p>"
        },
        "ApplianceModeSupport":{
          "shape":"ApplianceModeSupportValue",
          "documentation":"<p>Enable or disable support for appliance mode. If enabled, a traffic flow between a source and destination uses the same Availability Zone for the VPC attachment for the lifetime of that flow. The default is <code>disable</code>.</p>"
        }
      },
      "documentation":"<p>Describes the options for a VPC attachment.</p>"
    },
    "CreateTransitGatewayVpcAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayVpcAttachment":{
          "shape":"TransitGatewayVpcAttachment",
          "documentation":"<p>Information about the VPC attachment.</p>",
          "locationName":"transitGatewayVpcAttachment"
        }
      }
    },
    "CreateVerifiedAccessEndpointEniOptions":{
      "type":"structure",
      "members":{
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>"
        },
        "Protocol":{
          "shape":"VerifiedAccessEndpointProtocol",
          "documentation":"<p>The IP protocol.</p>"
        },
        "Port":{
          "shape":"VerifiedAccessEndpointPortNumber",
          "documentation":"<p>The IP port number.</p>"
        }
      },
      "documentation":"<p>Options for a network interface-type endpoint.</p>"
    },
    "CreateVerifiedAccessEndpointLoadBalancerOptions":{
      "type":"structure",
      "members":{
        "Protocol":{
          "shape":"VerifiedAccessEndpointProtocol",
          "documentation":"<p>The IP protocol.</p>"
        },
        "Port":{
          "shape":"VerifiedAccessEndpointPortNumber",
          "documentation":"<p>The IP port number.</p>"
        },
        "LoadBalancerArn":{
          "shape":"LoadBalancerArn",
          "documentation":"<p>The ARN of the load balancer.</p>"
        },
        "SubnetIds":{
          "shape":"CreateVerifiedAccessEndpointSubnetIdList",
          "documentation":"<p>The IDs of the subnets.</p>",
          "locationName":"SubnetId"
        }
      },
      "documentation":"<p>Describes a load balancer when creating an Amazon Web Services Verified Access endpoint using the <code>load-balancer</code> type.</p>"
    },
    "CreateVerifiedAccessEndpointRequest":{
      "type":"structure",
      "required":[
        "VerifiedAccessGroupId",
        "EndpointType",
        "AttachmentType",
        "DomainCertificateArn",
        "ApplicationDomain",
        "EndpointDomainPrefix"
      ],
      "members":{
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Verified Access group to associate the endpoint with.</p>"
        },
        "EndpointType":{
          "shape":"VerifiedAccessEndpointType",
          "documentation":"<p>The type of Amazon Web Services Verified Access endpoint to create.</p>"
        },
        "AttachmentType":{
          "shape":"VerifiedAccessEndpointAttachmentType",
          "documentation":"<p>The Amazon Web Services network component Verified Access attaches to.</p>"
        },
        "DomainCertificateArn":{
          "shape":"CertificateArn",
          "documentation":"<p>The ARN of the public TLS/SSL certificate in Amazon Web Services Certificate Manager to associate with the endpoint. The CN in the certificate must match the DNS name your end users will use to reach your application.</p>"
        },
        "ApplicationDomain":{
          "shape":"String",
          "documentation":"<p>The DNS name for users to reach your application.</p>"
        },
        "EndpointDomainPrefix":{
          "shape":"String",
          "documentation":"<p>A custom identifier that gets prepended to a DNS name that is generated for the endpoint.</p>"
        },
        "SecurityGroupIds":{
          "shape":"SecurityGroupIdList",
          "documentation":"<p>The Amazon EC2 security groups to associate with the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"SecurityGroupId"
        },
        "LoadBalancerOptions":{
          "shape":"CreateVerifiedAccessEndpointLoadBalancerOptions",
          "documentation":"<p>The load balancer details if creating the Amazon Web Services Verified Access endpoint as <code>load-balancer</code>type.</p>"
        },
        "NetworkInterfaceOptions":{
          "shape":"CreateVerifiedAccessEndpointEniOptions",
          "documentation":"<p>The network interface details if creating the Amazon Web Services Verified Access endpoint as <code>network-interface</code>type.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access endpoint.</p>"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateVerifiedAccessEndpointResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessEndpoint":{
          "shape":"VerifiedAccessEndpoint",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"verifiedAccessEndpoint"
        }
      }
    },
    "CreateVerifiedAccessEndpointSubnetIdList":{
      "type":"list",
      "member":{
        "shape":"SubnetId",
        "locationName":"item"
      }
    },
    "CreateVerifiedAccessGroupRequest":{
      "type":"structure",
      "required":["VerifiedAccessInstanceId"],
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access group.</p>"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Amazon Web Services Verified Access group.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateVerifiedAccessGroupResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessGroup":{
          "shape":"VerifiedAccessGroup",
          "documentation":"<p>The ID of the Verified Access group.</p>",
          "locationName":"verifiedAccessGroup"
        }
      }
    },
    "CreateVerifiedAccessInstanceRequest":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access instance.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Amazon Web Services Verified Access instance.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateVerifiedAccessInstanceResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstance":{
          "shape":"VerifiedAccessInstance",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstance"
        }
      }
    },
    "CreateVerifiedAccessTrustProviderDeviceOptions":{
      "type":"structure",
      "members":{
        "TenantId":{
          "shape":"String",
          "documentation":"<p>The ID of the tenant application with the device-identity provider.</p>"
        }
      },
      "documentation":"<p>Options for a device-identity type trust provider.</p>"
    },
    "CreateVerifiedAccessTrustProviderOidcOptions":{
      "type":"structure",
      "members":{
        "Issuer":{
          "shape":"String",
          "documentation":"<p>The OIDC issuer.</p>"
        },
        "AuthorizationEndpoint":{
          "shape":"String",
          "documentation":"<p>The OIDC authorization endpoint.</p>"
        },
        "TokenEndpoint":{
          "shape":"String",
          "documentation":"<p>The OIDC token endpoint.</p>"
        },
        "UserInfoEndpoint":{
          "shape":"String",
          "documentation":"<p>The OIDC user info endpoint.</p>"
        },
        "ClientId":{
          "shape":"String",
          "documentation":"<p>The client identifier.</p>"
        },
        "ClientSecret":{
          "shape":"String",
          "documentation":"<p>The client secret.</p>"
        },
        "Scope":{
          "shape":"String",
          "documentation":"<p>OpenID Connect (OIDC) scopes are used by an application during authentication to authorize access to a user's details. Each scope returns a specific set of user attributes.</p>"
        }
      },
      "documentation":"<p>Options for an OIDC-based, user-identity type trust provider.</p>"
    },
    "CreateVerifiedAccessTrustProviderRequest":{
      "type":"structure",
      "required":[
        "TrustProviderType",
        "PolicyReferenceName"
      ],
      "members":{
        "TrustProviderType":{
          "shape":"TrustProviderType",
          "documentation":"<p>The type of trust provider can be either user or device-based.</p>"
        },
        "UserTrustProviderType":{
          "shape":"UserTrustProviderType",
          "documentation":"<p>The type of user-based trust provider.</p>"
        },
        "DeviceTrustProviderType":{
          "shape":"DeviceTrustProviderType",
          "documentation":"<p>The type of device-based trust provider.</p>"
        },
        "OidcOptions":{
          "shape":"CreateVerifiedAccessTrustProviderOidcOptions",
          "documentation":"<p>The OpenID Connect details for an <code>oidc</code>-type, user-identity based trust provider.</p>"
        },
        "DeviceOptions":{
          "shape":"CreateVerifiedAccessTrustProviderDeviceOptions",
          "documentation":"<p>The options for device identity based trust providers.</p>"
        },
        "PolicyReferenceName":{
          "shape":"String",
          "documentation":"<p>The identifier to be used when working with policy rules.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access trust provider.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "CreateVerifiedAccessTrustProviderResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProvider":{
          "shape":"VerifiedAccessTrustProvider",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"verifiedAccessTrustProvider"
        }
      }
    },
    "CreateVolumePermission":{
      "type":"structure",
      "members":{
        "Group":{
          "shape":"PermissionGroup",
          "documentation":"<p>The group to be added or removed. The possible value is <code>all</code>.</p>",
          "locationName":"group"
        },
        "UserId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account to be added or removed.</p>",
          "locationName":"userId"
        }
      },
      "documentation":"<p>Describes the user or group to be added or removed from the list of create volume permissions for a volume.</p>"
    },
    "CreateVolumePermissionList":{
      "type":"list",
      "member":{
        "shape":"CreateVolumePermission",
        "locationName":"item"
      }
    },
    "CreateVolumePermissionModifications":{
      "type":"structure",
      "members":{
        "Add":{
          "shape":"CreateVolumePermissionList",
          "documentation":"<p>Adds the specified Amazon Web Services account ID or group to the list.</p>"
        },
        "Remove":{
          "shape":"CreateVolumePermissionList",
          "documentation":"<p>Removes the specified Amazon Web Services account ID or group from the list.</p>"
        }
      },
      "documentation":"<p>Describes modifications to the list of create volume permissions for a volume.</p>"
    },
    "CreateVolumeRequest":{
      "type":"structure",
      "required":["AvailabilityZone"],
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to create the volume.</p>"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume should be encrypted. The effect of setting the encryption state to <code>true</code> depends on the volume origin (new or from a snapshot), starting encryption state, ownership, and whether encryption by default is enabled. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html#encryption-by-default\">Encryption by default</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Encrypted Amazon EBS volumes must be attached to instances that support Amazon EBS encryption. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html#EBSEncryption_supported_instances\">Supported instance types</a>.</p>",
          "locationName":"encrypted"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The number of I/O operations per second (IOPS). For <code>gp3</code>, <code>io1</code>, and <code>io2</code> volumes, this represents the number of IOPS that are provisioned for the volume. For <code>gp2</code> volumes, this represents the baseline performance of the volume and the rate at which the volume accumulates I/O credits for bursting.</p> <p>The following are the supported values for each volume type:</p> <ul> <li> <p> <code>gp3</code>: 3,000-16,000 IOPS</p> </li> <li> <p> <code>io1</code>: 100-64,000 IOPS</p> </li> <li> <p> <code>io2</code>: 100-64,000 IOPS</p> </li> </ul> <p> <code>io1</code> and <code>io2</code> volumes support up to 64,000 IOPS only on <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">Instances built on the Nitro System</a>. Other instance families support performance up to 32,000 IOPS.</p> <p>This parameter is required for <code>io1</code> and <code>io2</code> volumes. The default for <code>gp3</code> volumes is 3,000 IOPS. This parameter is not supported for <code>gp2</code>, <code>st1</code>, <code>sc1</code>, or <code>standard</code> volumes.</p>"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The identifier of the Key Management Service (KMS) KMS key to use for Amazon EBS encryption. If this parameter is not specified, your KMS key for Amazon EBS is used. If <code>KmsKeyId</code> is specified, the encrypted state must be <code>true</code>.</p> <p>You can specify the KMS key using any of the following:</p> <ul> <li> <p>Key ID. For example, 1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Key alias. For example, alias/ExampleAlias.</p> </li> <li> <p>Key ARN. For example, arn:aws:kms:us-east-1:012345678910:key/1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Alias ARN. For example, arn:aws:kms:us-east-1:012345678910:alias/ExampleAlias.</p> </li> </ul> <p>Amazon Web Services authenticates the KMS key asynchronously. Therefore, if you specify an ID, alias, or ARN that is not valid, the action can appear to complete, but eventually fails.</p>"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>"
        },
        "Size":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiBs. You must specify either a snapshot ID or a volume size. If you specify a snapshot, the default is the snapshot size. You can specify a volume size that is equal to or larger than the snapshot size.</p> <p>The following are the supported volumes sizes for each volume type:</p> <ul> <li> <p> <code>gp2</code> and <code>gp3</code>: 1-16,384</p> </li> <li> <p> <code>io1</code> and <code>io2</code>: 4-16,384</p> </li> <li> <p> <code>st1</code> and <code>sc1</code>: 125-16,384</p> </li> <li> <p> <code>standard</code>: 1-1,024</p> </li> </ul>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The snapshot from which to create the volume. You must specify either a snapshot ID or a volume size.</p>"
        },
        "VolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The volume type. This parameter can be one of the following values:</p> <ul> <li> <p>General Purpose SSD: <code>gp2</code> | <code>gp3</code> </p> </li> <li> <p>Provisioned IOPS SSD: <code>io1</code> | <code>io2</code> </p> </li> <li> <p>Throughput Optimized HDD: <code>st1</code> </p> </li> <li> <p>Cold HDD: <code>sc1</code> </p> </li> <li> <p>Magnetic: <code>standard</code> </p> </li> </ul> <important> <p>Throughput Optimized HDD (<code>st1</code>) and Cold HDD (<code>sc1</code>) volumes can't be used as boot volumes.</p> </important> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html\">Amazon EBS volume types</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Default: <code>gp2</code> </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the volume during creation.</p>",
          "locationName":"TagSpecification"
        },
        "MultiAttachEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to enable Amazon EBS Multi-Attach. If you enable Multi-Attach, you can attach the volume to up to 16 <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">Instances built on the Nitro System</a> in the same Availability Zone. This parameter is supported with <code>io1</code> and <code>io2</code> volumes only. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volumes-multi.html\"> Amazon EBS Multi-Attach</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "Throughput":{
          "shape":"Integer",
          "documentation":"<p>The throughput to provision for a volume, with a maximum of 1,000 MiB/s.</p> <p>This parameter is valid only for <code>gp3</code> volumes.</p> <p>Valid Range: Minimum value of 125. Maximum value of 1000.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensure Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "CreateVpcEndpointConnectionNotificationRequest":{
      "type":"structure",
      "required":[
        "ConnectionNotificationArn",
        "ConnectionEvents"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the endpoint service.</p>"
        },
        "VpcEndpointId":{
          "shape":"VpcEndpointId",
          "documentation":"<p>The ID of the endpoint.</p>"
        },
        "ConnectionNotificationArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the SNS topic for the notifications.</p>"
        },
        "ConnectionEvents":{
          "shape":"ValueStringList",
          "documentation":"<p>The endpoint events for which to receive notifications. Valid values are <code>Accept</code>, <code>Connect</code>, <code>Delete</code>, and <code>Reject</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>"
        }
      }
    },
    "CreateVpcEndpointConnectionNotificationResult":{
      "type":"structure",
      "members":{
        "ConnectionNotification":{
          "shape":"ConnectionNotification",
          "documentation":"<p>Information about the notification.</p>",
          "locationName":"connectionNotification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateVpcEndpointRequest":{
      "type":"structure",
      "required":[
        "VpcId",
        "ServiceName"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VpcEndpointType":{
          "shape":"VpcEndpointType",
          "documentation":"<p>The type of endpoint.</p> <p>Default: Gateway</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC for the endpoint.</p>"
        },
        "ServiceName":{
          "shape":"String",
          "documentation":"<p>The service name.</p>"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>(Interface and gateway endpoints) A policy to attach to the endpoint that controls access to the service. The policy must be in valid JSON format. If this parameter is not specified, we attach a default policy that allows full access to the service.</p>"
        },
        "RouteTableIds":{
          "shape":"VpcEndpointRouteTableIdList",
          "documentation":"<p>(Gateway endpoint) The route table IDs.</p>",
          "locationName":"RouteTableId"
        },
        "SubnetIds":{
          "shape":"VpcEndpointSubnetIdList",
          "documentation":"<p>(Interface and Gateway Load Balancer endpoints) The IDs of the subnets in which to create an endpoint network interface. For a Gateway Load Balancer endpoint, you can specify only one subnet.</p>",
          "locationName":"SubnetId"
        },
        "SecurityGroupIds":{
          "shape":"VpcEndpointSecurityGroupIdList",
          "documentation":"<p>(Interface endpoint) The IDs of the security groups to associate with the endpoint network interface. If this parameter is not specified, we use the default security group for the VPC.</p>",
          "locationName":"SecurityGroupId"
        },
        "IpAddressType":{
          "shape":"IpAddressType",
          "documentation":"<p>The IP address type for the endpoint.</p>"
        },
        "DnsOptions":{
          "shape":"DnsOptionsSpecification",
          "documentation":"<p>The DNS options for the endpoint.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>"
        },
        "PrivateDnsEnabled":{
          "shape":"Boolean",
          "documentation":"<p>(Interface endpoint) Indicates whether to associate a private hosted zone with the specified VPC. The private hosted zone contains a record set for the default public DNS name for the service for the Region (for example, <code>kinesis.us-east-1.amazonaws.com</code>), which resolves to the private IP addresses of the endpoint network interfaces in the VPC. This enables you to make requests to the default public DNS name for the service instead of the public DNS names that are automatically generated by the VPC endpoint service.</p> <p>To use a private hosted zone, you must set the following VPC attributes to <code>true</code>: <code>enableDnsHostnames</code> and <code>enableDnsSupport</code>. Use <a>ModifyVpcAttribute</a> to set the VPC attributes.</p> <p>Default: <code>true</code> </p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to associate with the endpoint.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateVpcEndpointResult":{
      "type":"structure",
      "members":{
        "VpcEndpoint":{
          "shape":"VpcEndpoint",
          "documentation":"<p>Information about the endpoint.</p>",
          "locationName":"vpcEndpoint"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateVpcEndpointServiceConfigurationRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "AcceptanceRequired":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether requests from service consumers to create an endpoint to your service must be accepted manually.</p>"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>(Interface endpoint configuration) The private DNS name to assign to the VPC endpoint service.</p>"
        },
        "NetworkLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of the Network Load Balancers.</p>",
          "locationName":"NetworkLoadBalancerArn"
        },
        "GatewayLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of the Gateway Load Balancers.</p>",
          "locationName":"GatewayLoadBalancerArn"
        },
        "SupportedIpAddressTypes":{
          "shape":"ValueStringList",
          "documentation":"<p>The supported IP address types. The possible values are <code>ipv4</code> and <code>ipv6</code>.</p>",
          "locationName":"SupportedIpAddressType"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to associate with the service.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateVpcEndpointServiceConfigurationResult":{
      "type":"structure",
      "members":{
        "ServiceConfiguration":{
          "shape":"ServiceConfiguration",
          "documentation":"<p>Information about the service configuration.</p>",
          "locationName":"serviceConfiguration"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "CreateVpcPeeringConnectionRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "PeerOwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the accepter VPC.</p> <p>Default: Your Amazon Web Services account ID</p>",
          "locationName":"peerOwnerId"
        },
        "PeerVpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC with which you are creating the VPC peering connection. You must specify this parameter in the request.</p>",
          "locationName":"peerVpcId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the requester VPC. You must specify this parameter in the request.</p>",
          "locationName":"vpcId"
        },
        "PeerRegion":{
          "shape":"String",
          "documentation":"<p>The Region code for the accepter VPC, if the accepter VPC is located in a Region other than the Region in which you make the request.</p> <p>Default: The Region in which you make the request.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the peering connection.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateVpcPeeringConnectionResult":{
      "type":"structure",
      "members":{
        "VpcPeeringConnection":{
          "shape":"VpcPeeringConnection",
          "documentation":"<p>Information about the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnection"
        }
      }
    },
    "CreateVpcRequest":{
      "type":"structure",
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 network range for the VPC, in CIDR notation. For example, <code>10.0.0.0/16</code>. We modify the specified CIDR block to its canonical form; for example, if you specify <code>100.68.0.18/18</code>, we modify it to <code>100.68.0.0/18</code>.</p>"
        },
        "AmazonProvidedIpv6CidrBlock":{
          "shape":"Boolean",
          "documentation":"<p>Requests an Amazon-provided IPv6 CIDR block with a /56 prefix length for the VPC. You cannot specify the range of IP addresses, or the size of the CIDR block.</p>",
          "locationName":"amazonProvidedIpv6CidrBlock"
        },
        "Ipv6Pool":{
          "shape":"Ipv6PoolEc2Id",
          "documentation":"<p>The ID of an IPv6 address pool from which to allocate the IPv6 CIDR block.</p>"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block from the IPv6 address pool. You must also specify <code>Ipv6Pool</code> in the request.</p> <p>To let Amazon choose the IPv6 CIDR block for you, omit this parameter.</p>"
        },
        "Ipv4IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of an IPv4 IPAM pool you want to use for allocating this VPC's CIDR. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
        },
        "Ipv4NetmaskLength":{
          "shape":"NetmaskLength",
          "documentation":"<p>The netmask length of the IPv4 CIDR you want to allocate to this VPC from an Amazon VPC IP Address Manager (IPAM) pool. For more information about IPAM, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
        },
        "Ipv6IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of an IPv6 IPAM pool which will be used to allocate this VPC an IPv6 CIDR. IPAM is a VPC feature that you can use to automate your IP address management workflows including assigning, tracking, troubleshooting, and auditing IP addresses across Amazon Web Services Regions and accounts throughout your Amazon Web Services Organization. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
        },
        "Ipv6NetmaskLength":{
          "shape":"NetmaskLength",
          "documentation":"<p>The netmask length of the IPv6 CIDR you want to allocate to this VPC from an Amazon VPC IP Address Manager (IPAM) pool. For more information about IPAM, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceTenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy options for instances launched into the VPC. For <code>default</code>, instances are launched with shared tenancy by default. You can launch instances with any tenancy into a shared tenancy VPC. For <code>dedicated</code>, instances are launched as dedicated tenancy instances by default. You can only launch instances with a tenancy of <code>dedicated</code> or <code>host</code> into a dedicated tenancy VPC. </p> <p> <b>Important:</b> The <code>host</code> value cannot be used with this parameter. Use the <code>default</code> or <code>dedicated</code> values only.</p> <p>Default: <code>default</code> </p>",
          "locationName":"instanceTenancy"
        },
        "Ipv6CidrBlockNetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The name of the location from which we advertise the IPV6 CIDR block. Use this parameter to limit the address to this location.</p> <p> You must set <code>AmazonProvidedIpv6CidrBlock</code> to <code>true</code> to use this parameter.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to assign to the VPC.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "CreateVpcResult":{
      "type":"structure",
      "members":{
        "Vpc":{
          "shape":"Vpc",
          "documentation":"<p>Information about the VPC.</p>",
          "locationName":"vpc"
        }
      }
    },
    "CreateVpnConnectionRequest":{
      "type":"structure",
      "required":[
        "CustomerGatewayId",
        "Type"
      ],
      "members":{
        "CustomerGatewayId":{
          "shape":"CustomerGatewayId",
          "documentation":"<p>The ID of the customer gateway.</p>"
        },
        "Type":{
          "shape":"String",
          "documentation":"<p>The type of VPN connection (<code>ipsec.1</code>).</p>"
        },
        "VpnGatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway. If you specify a virtual private gateway, you cannot specify a transit gateway.</p>"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway. If you specify a transit gateway, you cannot specify a virtual private gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Options":{
          "shape":"VpnConnectionOptionsSpecification",
          "documentation":"<p>The options for the VPN connection.</p>",
          "locationName":"options"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the VPN connection.</p>",
          "locationName":"TagSpecification"
        }
      },
      "documentation":"<p>Contains the parameters for CreateVpnConnection.</p>"
    },
    "CreateVpnConnectionResult":{
      "type":"structure",
      "members":{
        "VpnConnection":{
          "shape":"VpnConnection",
          "documentation":"<p>Information about the VPN connection.</p>",
          "locationName":"vpnConnection"
        }
      },
      "documentation":"<p>Contains the output of CreateVpnConnection.</p>"
    },
    "CreateVpnConnectionRouteRequest":{
      "type":"structure",
      "required":[
        "DestinationCidrBlock",
        "VpnConnectionId"
      ],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR block associated with the local subnet of the customer network.</p>"
        },
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the VPN connection.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for CreateVpnConnectionRoute.</p>"
    },
    "CreateVpnGatewayRequest":{
      "type":"structure",
      "required":["Type"],
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone for the virtual private gateway.</p>"
        },
        "Type":{
          "shape":"GatewayType",
          "documentation":"<p>The type of VPN connection this virtual private gateway supports.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the virtual private gateway.</p>",
          "locationName":"TagSpecification"
        },
        "AmazonSideAsn":{
          "shape":"Long",
          "documentation":"<p>A private Autonomous System Number (ASN) for the Amazon side of a BGP session. If you're using a 16-bit ASN, it must be in the 64512 to 65534 range. If you're using a 32-bit ASN, it must be in the 4200000000 to 4294967294 range.</p> <p>Default: 64512</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for CreateVpnGateway.</p>"
    },
    "CreateVpnGatewayResult":{
      "type":"structure",
      "members":{
        "VpnGateway":{
          "shape":"VpnGateway",
          "documentation":"<p>Information about the virtual private gateway.</p>",
          "locationName":"vpnGateway"
        }
      },
      "documentation":"<p>Contains the output of CreateVpnGateway.</p>"
    },
    "CreditSpecification":{
      "type":"structure",
      "members":{
        "CpuCredits":{
          "shape":"String",
          "documentation":"<p>The credit option for CPU usage of a T instance.</p> <p>Valid values: <code>standard</code> | <code>unlimited</code> </p>",
          "locationName":"cpuCredits"
        }
      },
      "documentation":"<p>Describes the credit option for CPU usage of a T instance.</p>"
    },
    "CreditSpecificationRequest":{
      "type":"structure",
      "required":["CpuCredits"],
      "members":{
        "CpuCredits":{
          "shape":"String",
          "documentation":"<p>The credit option for CPU usage of a T instance.</p> <p>Valid values: <code>standard</code> | <code>unlimited</code> </p>"
        }
      },
      "documentation":"<p>The credit option for CPU usage of a T instance.</p>"
    },
    "CurrencyCodeValues":{
      "type":"string",
      "enum":["USD"]
    },
    "CurrentGenerationFlag":{"type":"boolean"},
    "CustomerGateway":{
      "type":"structure",
      "members":{
        "BgpAsn":{
          "shape":"String",
          "documentation":"<p>The customer gateway's Border Gateway Protocol (BGP) Autonomous System Number (ASN).</p>",
          "locationName":"bgpAsn"
        },
        "CustomerGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the customer gateway.</p>",
          "locationName":"customerGatewayId"
        },
        "IpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address of the customer gateway device's outside interface.</p>",
          "locationName":"ipAddress"
        },
        "CertificateArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) for the customer gateway certificate.</p>",
          "locationName":"certificateArn"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The current state of the customer gateway (<code>pending | available | deleting | deleted</code>).</p>",
          "locationName":"state"
        },
        "Type":{
          "shape":"String",
          "documentation":"<p>The type of VPN connection the customer gateway supports (<code>ipsec.1</code>).</p>",
          "locationName":"type"
        },
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The name of customer gateway device.</p>",
          "locationName":"deviceName"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the customer gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a customer gateway.</p>"
    },
    "CustomerGatewayId":{"type":"string"},
    "CustomerGatewayIdStringList":{
      "type":"list",
      "member":{
        "shape":"CustomerGatewayId",
        "locationName":"CustomerGatewayId"
      }
    },
    "CustomerGatewayList":{
      "type":"list",
      "member":{
        "shape":"CustomerGateway",
        "locationName":"item"
      }
    },
    "DITMaxResults":{
      "type":"integer",
      "max":100,
      "min":5
    },
    "DITOMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DataQueries":{
      "type":"list",
      "member":{"shape":"DataQuery"}
    },
    "DataQuery":{
      "type":"structure",
      "members":{
        "Id":{
          "shape":"String",
          "documentation":"<p>A user-defined ID associated with a data query that's returned in the <code>dataResponse</code> identifying the query. For example, if you set the Id to <code>MyQuery01</code>in the query, the <code>dataResponse</code> identifies the query as <code>MyQuery01</code>.</p>"
        },
        "Source":{
          "shape":"String",
          "documentation":"<p>The Region or Availability Zone that's the source for the data query. For example, <code>us-east-1</code>.</p>"
        },
        "Destination":{
          "shape":"String",
          "documentation":"<p>The Region or Availability Zone that's the target for the data query. For example, <code>eu-north-1</code>.</p>"
        },
        "Metric":{
          "shape":"MetricType",
          "documentation":"<p>The metric, <code>aggregation-latency</code>, indicating that network latency is aggregated for the query. This is the only supported metric.</p>"
        },
        "Statistic":{
          "shape":"StatisticType",
          "documentation":"<p>The metric data aggregation period, <code>p50</code>, between the specified <code>startDate</code> and <code>endDate</code>. For example, a metric of <code>five_minutes</code> is the median of all the data points gathered within those five minutes. <code>p50</code> is the only supported metric.</p>"
        },
        "Period":{
          "shape":"PeriodType",
          "documentation":"<p>The aggregation period used for the data query.</p>"
        }
      },
      "documentation":"<p>A query used for retrieving network health data. </p>"
    },
    "DataResponse":{
      "type":"structure",
      "members":{
        "Id":{
          "shape":"String",
          "documentation":"<p>The ID passed in the <code>DataQuery</code>.</p>",
          "locationName":"id"
        },
        "Source":{
          "shape":"String",
          "documentation":"<p>The Region or Availability Zone that's the source for the data query. For example, <code>us-east-1</code>.</p>",
          "locationName":"source"
        },
        "Destination":{
          "shape":"String",
          "documentation":"<p>The Region or Availability Zone that's the destination for the data query. For example, <code>eu-west-1</code>.</p>",
          "locationName":"destination"
        },
        "Metric":{
          "shape":"MetricType",
          "documentation":"<p>The metric used for the network performance request. Only <code>aggregate-latency</code> is supported, which shows network latency during a specified period. </p>",
          "locationName":"metric"
        },
        "Statistic":{
          "shape":"StatisticType",
          "documentation":"<p>The statistic used for the network performance request.</p>",
          "locationName":"statistic"
        },
        "Period":{
          "shape":"PeriodType",
          "documentation":"<p>The period used for the network performance request.</p>",
          "locationName":"period"
        },
        "MetricPoints":{
          "shape":"MetricPoints",
          "documentation":"<p>A list of <code>MetricPoint</code> objects.</p>",
          "locationName":"metricPointSet"
        }
      },
      "documentation":"<p>The response to a <code>DataQuery</code>.</p>"
    },
    "DataResponses":{
      "type":"list",
      "member":{
        "shape":"DataResponse",
        "locationName":"item"
      }
    },
    "DatafeedSubscriptionState":{
      "type":"string",
      "enum":[
        "Active",
        "Inactive"
      ]
    },
    "DateTime":{"type":"timestamp"},
    "DedicatedHostFlag":{"type":"boolean"},
    "DedicatedHostId":{"type":"string"},
    "DedicatedHostIdList":{
      "type":"list",
      "member":{
        "shape":"DedicatedHostId",
        "locationName":"item"
      }
    },
    "DefaultNetworkCardIndex":{"type":"integer"},
    "DefaultRouteTableAssociationValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "DefaultRouteTablePropagationValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "DefaultTargetCapacityType":{
      "type":"string",
      "enum":[
        "spot",
        "on-demand"
      ]
    },
    "DefaultingDhcpOptionsId":{"type":"string"},
    "DeleteCarrierGatewayRequest":{
      "type":"structure",
      "required":["CarrierGatewayId"],
      "members":{
        "CarrierGatewayId":{
          "shape":"CarrierGatewayId",
          "documentation":"<p>The ID of the carrier gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteCarrierGatewayResult":{
      "type":"structure",
      "members":{
        "CarrierGateway":{
          "shape":"CarrierGateway",
          "documentation":"<p>Information about the carrier gateway.</p>",
          "locationName":"carrierGateway"
        }
      }
    },
    "DeleteClientVpnEndpointRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN to be deleted.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteClientVpnEndpointResult":{
      "type":"structure",
      "members":{
        "Status":{
          "shape":"ClientVpnEndpointStatus",
          "documentation":"<p>The current state of the Client VPN endpoint.</p>",
          "locationName":"status"
        }
      }
    },
    "DeleteClientVpnRouteRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "DestinationCidrBlock"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint from which the route is to be deleted.</p>"
        },
        "TargetVpcSubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the target subnet used by the route.</p>"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the route to be deleted.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteClientVpnRouteResult":{
      "type":"structure",
      "members":{
        "Status":{
          "shape":"ClientVpnRouteStatus",
          "documentation":"<p>The current state of the route.</p>",
          "locationName":"status"
        }
      }
    },
    "DeleteCoipCidrRequest":{
      "type":"structure",
      "required":[
        "Cidr",
        "CoipPoolId"
      ],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p> A customer-owned IP address range that you want to delete. </p>"
        },
        "CoipPoolId":{
          "shape":"Ipv4PoolCoipId",
          "documentation":"<p> The ID of the customer-owned address pool. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteCoipCidrResult":{
      "type":"structure",
      "members":{
        "CoipCidr":{
          "shape":"CoipCidr",
          "documentation":"<p> Information about a range of customer-owned IP addresses. </p>",
          "locationName":"coipCidr"
        }
      }
    },
    "DeleteCoipPoolRequest":{
      "type":"structure",
      "required":["CoipPoolId"],
      "members":{
        "CoipPoolId":{
          "shape":"Ipv4PoolCoipId",
          "documentation":"<p>The ID of the CoIP pool that you want to delete. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteCoipPoolResult":{
      "type":"structure",
      "members":{
        "CoipPool":{
          "shape":"CoipPool",
          "documentation":"<p>Information about the CoIP address pool.</p>",
          "locationName":"coipPool"
        }
      }
    },
    "DeleteCustomerGatewayRequest":{
      "type":"structure",
      "required":["CustomerGatewayId"],
      "members":{
        "CustomerGatewayId":{
          "shape":"CustomerGatewayId",
          "documentation":"<p>The ID of the customer gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteCustomerGateway.</p>"
    },
    "DeleteDhcpOptionsRequest":{
      "type":"structure",
      "required":["DhcpOptionsId"],
      "members":{
        "DhcpOptionsId":{
          "shape":"DhcpOptionsId",
          "documentation":"<p>The ID of the DHCP options set.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteEgressOnlyInternetGatewayRequest":{
      "type":"structure",
      "required":["EgressOnlyInternetGatewayId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "EgressOnlyInternetGatewayId":{
          "shape":"EgressOnlyInternetGatewayId",
          "documentation":"<p>The ID of the egress-only internet gateway.</p>"
        }
      }
    },
    "DeleteEgressOnlyInternetGatewayResult":{
      "type":"structure",
      "members":{
        "ReturnCode":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"returnCode"
        }
      }
    },
    "DeleteFleetError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"DeleteFleetErrorCode",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The description for the error code.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes an EC2 Fleet error.</p>"
    },
    "DeleteFleetErrorCode":{
      "type":"string",
      "enum":[
        "fleetIdDoesNotExist",
        "fleetIdMalformed",
        "fleetNotInDeletableState",
        "unexpectedError"
      ]
    },
    "DeleteFleetErrorItem":{
      "type":"structure",
      "members":{
        "Error":{
          "shape":"DeleteFleetError",
          "documentation":"<p>The error.</p>",
          "locationName":"error"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>",
          "locationName":"fleetId"
        }
      },
      "documentation":"<p>Describes an EC2 Fleet that was not successfully deleted.</p>"
    },
    "DeleteFleetErrorSet":{
      "type":"list",
      "member":{
        "shape":"DeleteFleetErrorItem",
        "locationName":"item"
      }
    },
    "DeleteFleetSuccessItem":{
      "type":"structure",
      "members":{
        "CurrentFleetState":{
          "shape":"FleetStateCode",
          "documentation":"<p>The current state of the EC2 Fleet.</p>",
          "locationName":"currentFleetState"
        },
        "PreviousFleetState":{
          "shape":"FleetStateCode",
          "documentation":"<p>The previous state of the EC2 Fleet.</p>",
          "locationName":"previousFleetState"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>",
          "locationName":"fleetId"
        }
      },
      "documentation":"<p>Describes an EC2 Fleet that was successfully deleted.</p>"
    },
    "DeleteFleetSuccessSet":{
      "type":"list",
      "member":{
        "shape":"DeleteFleetSuccessItem",
        "locationName":"item"
      }
    },
    "DeleteFleetsRequest":{
      "type":"structure",
      "required":[
        "FleetIds",
        "TerminateInstances"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FleetIds":{
          "shape":"FleetIdSet",
          "documentation":"<p>The IDs of the EC2 Fleets.</p>",
          "locationName":"FleetId"
        },
        "TerminateInstances":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to terminate the instances when the EC2 Fleet is deleted. The default is to terminate the instances.</p> <p>To let the instances continue to run after the EC2 Fleet is deleted, specify <code>NoTerminateInstances</code>. Supported only for fleets of type <code>maintain</code> and <code>request</code>.</p> <p>For <code>instant</code> fleets, you cannot specify <code>NoTerminateInstances</code>. A deleted <code>instant</code> fleet with running instances is not supported.</p>"
        }
      }
    },
    "DeleteFleetsResult":{
      "type":"structure",
      "members":{
        "SuccessfulFleetDeletions":{
          "shape":"DeleteFleetSuccessSet",
          "documentation":"<p>Information about the EC2 Fleets that are successfully deleted.</p>",
          "locationName":"successfulFleetDeletionSet"
        },
        "UnsuccessfulFleetDeletions":{
          "shape":"DeleteFleetErrorSet",
          "documentation":"<p>Information about the EC2 Fleets that are not successfully deleted.</p>",
          "locationName":"unsuccessfulFleetDeletionSet"
        }
      }
    },
    "DeleteFlowLogsRequest":{
      "type":"structure",
      "required":["FlowLogIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FlowLogIds":{
          "shape":"FlowLogIdList",
          "documentation":"<p>One or more flow log IDs.</p> <p>Constraint: Maximum of 1000 flow log IDs.</p>",
          "locationName":"FlowLogId"
        }
      }
    },
    "DeleteFlowLogsResult":{
      "type":"structure",
      "members":{
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the flow logs that could not be deleted successfully.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "DeleteFpgaImageRequest":{
      "type":"structure",
      "required":["FpgaImageId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FpgaImageId":{
          "shape":"FpgaImageId",
          "documentation":"<p>The ID of the AFI.</p>"
        }
      }
    },
    "DeleteFpgaImageResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Is <code>true</code> if the request succeeds, and an error otherwise.</p>",
          "locationName":"return"
        }
      }
    },
    "DeleteInstanceEventWindowRequest":{
      "type":"structure",
      "required":["InstanceEventWindowId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ForceDelete":{
          "shape":"Boolean",
          "documentation":"<p>Specify <code>true</code> to force delete the event window. Use the force delete parameter if the event window is currently associated with targets.</p>"
        },
        "InstanceEventWindowId":{
          "shape":"InstanceEventWindowId",
          "documentation":"<p>The ID of the event window.</p>"
        }
      }
    },
    "DeleteInstanceEventWindowResult":{
      "type":"structure",
      "members":{
        "InstanceEventWindowState":{
          "shape":"InstanceEventWindowStateChange",
          "documentation":"<p>The state of the event window.</p>",
          "locationName":"instanceEventWindowState"
        }
      }
    },
    "DeleteInternetGatewayRequest":{
      "type":"structure",
      "required":["InternetGatewayId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InternetGatewayId":{
          "shape":"InternetGatewayId",
          "documentation":"<p>The ID of the internet gateway.</p>",
          "locationName":"internetGatewayId"
        }
      }
    },
    "DeleteIpamPoolRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the pool to delete.</p>"
        }
      }
    },
    "DeleteIpamPoolResult":{
      "type":"structure",
      "members":{
        "IpamPool":{
          "shape":"IpamPool",
          "documentation":"<p>Information about the results of the deletion.</p>",
          "locationName":"ipamPool"
        }
      }
    },
    "DeleteIpamRequest":{
      "type":"structure",
      "required":["IpamId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>The ID of the IPAM to delete.</p>"
        },
        "Cascade":{
          "shape":"Boolean",
          "documentation":"<p>Enables you to quickly delete an IPAM, private scopes, pools in private scopes, and any allocations in the pools in private scopes. You cannot delete the IPAM with this option if there is a pool in your public scope. If you use this option, IPAM does the following:</p> <ul> <li> <p>Deallocates any CIDRs allocated to VPC resources (such as VPCs) in pools in private scopes.</p> <note> <p>No VPC resources are deleted as a result of enabling this option. The CIDR associated with the resource will no longer be allocated from an IPAM pool, but the CIDR itself will remain unchanged.</p> </note> </li> <li> <p>Deprovisions all IPv4 CIDRs provisioned to IPAM pools in private scopes.</p> </li> <li> <p>Deletes all IPAM pools in private scopes.</p> </li> <li> <p>Deletes all non-default private scopes in the IPAM.</p> </li> <li> <p>Deletes the default public and private scopes and the IPAM.</p> </li> </ul>"
        }
      }
    },
    "DeleteIpamResourceDiscoveryRequest":{
      "type":"structure",
      "required":["IpamResourceDiscoveryId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>The IPAM resource discovery ID.</p>"
        }
      }
    },
    "DeleteIpamResourceDiscoveryResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscovery":{
          "shape":"IpamResourceDiscovery",
          "documentation":"<p>The IPAM resource discovery.</p>",
          "locationName":"ipamResourceDiscovery"
        }
      }
    },
    "DeleteIpamResult":{
      "type":"structure",
      "members":{
        "Ipam":{
          "shape":"Ipam",
          "documentation":"<p>Information about the results of the deletion.</p>",
          "locationName":"ipam"
        }
      }
    },
    "DeleteIpamScopeRequest":{
      "type":"structure",
      "required":["IpamScopeId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the scope to delete.</p>"
        }
      }
    },
    "DeleteIpamScopeResult":{
      "type":"structure",
      "members":{
        "IpamScope":{
          "shape":"IpamScope",
          "documentation":"<p>Information about the results of the deletion.</p>",
          "locationName":"ipamScope"
        }
      }
    },
    "DeleteKeyPairRequest":{
      "type":"structure",
      "members":{
        "KeyName":{
          "shape":"KeyPairName",
          "documentation":"<p>The name of the key pair.</p>"
        },
        "KeyPairId":{
          "shape":"KeyPairId",
          "documentation":"<p>The ID of the key pair.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteLaunchTemplateRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify either the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify either the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>"
        }
      }
    },
    "DeleteLaunchTemplateResult":{
      "type":"structure",
      "members":{
        "LaunchTemplate":{
          "shape":"LaunchTemplate",
          "documentation":"<p>Information about the launch template.</p>",
          "locationName":"launchTemplate"
        }
      }
    },
    "DeleteLaunchTemplateVersionsRequest":{
      "type":"structure",
      "required":["Versions"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify either the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify either the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>"
        },
        "Versions":{
          "shape":"VersionStringList",
          "documentation":"<p>The version numbers of one or more launch template versions to delete.</p>",
          "locationName":"LaunchTemplateVersion"
        }
      }
    },
    "DeleteLaunchTemplateVersionsResponseErrorItem":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"String",
          "documentation":"<p>The ID of the launch template.</p>",
          "locationName":"launchTemplateId"
        },
        "LaunchTemplateName":{
          "shape":"String",
          "documentation":"<p>The name of the launch template.</p>",
          "locationName":"launchTemplateName"
        },
        "VersionNumber":{
          "shape":"Long",
          "documentation":"<p>The version number of the launch template.</p>",
          "locationName":"versionNumber"
        },
        "ResponseError":{
          "shape":"ResponseError",
          "documentation":"<p>Information about the error.</p>",
          "locationName":"responseError"
        }
      },
      "documentation":"<p>Describes a launch template version that could not be deleted.</p>"
    },
    "DeleteLaunchTemplateVersionsResponseErrorSet":{
      "type":"list",
      "member":{
        "shape":"DeleteLaunchTemplateVersionsResponseErrorItem",
        "locationName":"item"
      }
    },
    "DeleteLaunchTemplateVersionsResponseSuccessItem":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"String",
          "documentation":"<p>The ID of the launch template.</p>",
          "locationName":"launchTemplateId"
        },
        "LaunchTemplateName":{
          "shape":"String",
          "documentation":"<p>The name of the launch template.</p>",
          "locationName":"launchTemplateName"
        },
        "VersionNumber":{
          "shape":"Long",
          "documentation":"<p>The version number of the launch template.</p>",
          "locationName":"versionNumber"
        }
      },
      "documentation":"<p>Describes a launch template version that was successfully deleted.</p>"
    },
    "DeleteLaunchTemplateVersionsResponseSuccessSet":{
      "type":"list",
      "member":{
        "shape":"DeleteLaunchTemplateVersionsResponseSuccessItem",
        "locationName":"item"
      }
    },
    "DeleteLaunchTemplateVersionsResult":{
      "type":"structure",
      "members":{
        "SuccessfullyDeletedLaunchTemplateVersions":{
          "shape":"DeleteLaunchTemplateVersionsResponseSuccessSet",
          "documentation":"<p>Information about the launch template versions that were successfully deleted.</p>",
          "locationName":"successfullyDeletedLaunchTemplateVersionSet"
        },
        "UnsuccessfullyDeletedLaunchTemplateVersions":{
          "shape":"DeleteLaunchTemplateVersionsResponseErrorSet",
          "documentation":"<p>Information about the launch template versions that could not be deleted.</p>",
          "locationName":"unsuccessfullyDeletedLaunchTemplateVersionSet"
        }
      }
    },
    "DeleteLocalGatewayRouteRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableId"],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR range for the route. This must match the CIDR for the route exactly.</p>"
        },
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p> Use a prefix list in place of <code>DestinationCidrBlock</code>. You cannot use <code>DestinationPrefixListId</code> and <code>DestinationCidrBlock</code> in the same request. </p>"
        }
      }
    },
    "DeleteLocalGatewayRouteResult":{
      "type":"structure",
      "members":{
        "Route":{
          "shape":"LocalGatewayRoute",
          "documentation":"<p>Information about the route.</p>",
          "locationName":"route"
        }
      }
    },
    "DeleteLocalGatewayRouteTableRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableId"],
      "members":{
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p> The ID of the local gateway route table. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteLocalGatewayRouteTableResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTable":{
          "shape":"LocalGatewayRouteTable",
          "documentation":"<p>Information about the local gateway route table.</p>",
          "locationName":"localGatewayRouteTable"
        }
      }
    },
    "DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableVirtualInterfaceGroupAssociationId"],
      "members":{
        "LocalGatewayRouteTableVirtualInterfaceGroupAssociationId":{
          "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociationId",
          "documentation":"<p> The ID of the local gateway route table virtual interface group association. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVirtualInterfaceGroupAssociation":{
          "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociation",
          "documentation":"<p>Information about the association.</p>",
          "locationName":"localGatewayRouteTableVirtualInterfaceGroupAssociation"
        }
      }
    },
    "DeleteLocalGatewayRouteTableVpcAssociationRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableVpcAssociationId"],
      "members":{
        "LocalGatewayRouteTableVpcAssociationId":{
          "shape":"LocalGatewayRouteTableVpcAssociationId",
          "documentation":"<p>The ID of the association.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteLocalGatewayRouteTableVpcAssociationResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVpcAssociation":{
          "shape":"LocalGatewayRouteTableVpcAssociation",
          "documentation":"<p>Information about the association.</p>",
          "locationName":"localGatewayRouteTableVpcAssociation"
        }
      }
    },
    "DeleteManagedPrefixListRequest":{
      "type":"structure",
      "required":["PrefixListId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        }
      }
    },
    "DeleteManagedPrefixListResult":{
      "type":"structure",
      "members":{
        "PrefixList":{
          "shape":"ManagedPrefixList",
          "documentation":"<p>Information about the prefix list.</p>",
          "locationName":"prefixList"
        }
      }
    },
    "DeleteNatGatewayRequest":{
      "type":"structure",
      "required":["NatGatewayId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The ID of the NAT gateway.</p>"
        }
      }
    },
    "DeleteNatGatewayResult":{
      "type":"structure",
      "members":{
        "NatGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the NAT gateway.</p>",
          "locationName":"natGatewayId"
        }
      }
    },
    "DeleteNetworkAclEntryRequest":{
      "type":"structure",
      "required":[
        "Egress",
        "NetworkAclId",
        "RuleNumber"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Egress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the rule is an egress rule.</p>",
          "locationName":"egress"
        },
        "NetworkAclId":{
          "shape":"NetworkAclId",
          "documentation":"<p>The ID of the network ACL.</p>",
          "locationName":"networkAclId"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The rule number of the entry to delete.</p>",
          "locationName":"ruleNumber"
        }
      }
    },
    "DeleteNetworkAclRequest":{
      "type":"structure",
      "required":["NetworkAclId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkAclId":{
          "shape":"NetworkAclId",
          "documentation":"<p>The ID of the network ACL.</p>",
          "locationName":"networkAclId"
        }
      }
    },
    "DeleteNetworkInsightsAccessScopeAnalysisRequest":{
      "type":"structure",
      "required":["NetworkInsightsAccessScopeAnalysisId"],
      "members":{
        "NetworkInsightsAccessScopeAnalysisId":{
          "shape":"NetworkInsightsAccessScopeAnalysisId",
          "documentation":"<p>The ID of the Network Access Scope analysis.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteNetworkInsightsAccessScopeAnalysisResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalysisId":{
          "shape":"NetworkInsightsAccessScopeAnalysisId",
          "documentation":"<p>The ID of the Network Access Scope analysis.</p>",
          "locationName":"networkInsightsAccessScopeAnalysisId"
        }
      }
    },
    "DeleteNetworkInsightsAccessScopeRequest":{
      "type":"structure",
      "required":["NetworkInsightsAccessScopeId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>"
        }
      }
    },
    "DeleteNetworkInsightsAccessScopeResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScopeId"
        }
      }
    },
    "DeleteNetworkInsightsAnalysisRequest":{
      "type":"structure",
      "required":["NetworkInsightsAnalysisId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NetworkInsightsAnalysisId":{
          "shape":"NetworkInsightsAnalysisId",
          "documentation":"<p>The ID of the network insights analysis.</p>"
        }
      }
    },
    "DeleteNetworkInsightsAnalysisResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAnalysisId":{
          "shape":"NetworkInsightsAnalysisId",
          "documentation":"<p>The ID of the network insights analysis.</p>",
          "locationName":"networkInsightsAnalysisId"
        }
      }
    },
    "DeleteNetworkInsightsPathRequest":{
      "type":"structure",
      "required":["NetworkInsightsPathId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NetworkInsightsPathId":{
          "shape":"NetworkInsightsPathId",
          "documentation":"<p>The ID of the path.</p>"
        }
      }
    },
    "DeleteNetworkInsightsPathResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsPathId":{
          "shape":"NetworkInsightsPathId",
          "documentation":"<p>The ID of the path.</p>",
          "locationName":"networkInsightsPathId"
        }
      }
    },
    "DeleteNetworkInterfacePermissionRequest":{
      "type":"structure",
      "required":["NetworkInterfacePermissionId"],
      "members":{
        "NetworkInterfacePermissionId":{
          "shape":"NetworkInterfacePermissionId",
          "documentation":"<p>The ID of the network interface permission.</p>"
        },
        "Force":{
          "shape":"Boolean",
          "documentation":"<p>Specify <code>true</code> to remove the permission even if the network interface is attached to an instance.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteNetworkInterfacePermission.</p>"
    },
    "DeleteNetworkInterfacePermissionResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds, otherwise returns an error.</p>",
          "locationName":"return"
        }
      },
      "documentation":"<p>Contains the output for DeleteNetworkInterfacePermission.</p>"
    },
    "DeleteNetworkInterfaceRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteNetworkInterface.</p>"
    },
    "DeletePlacementGroupRequest":{
      "type":"structure",
      "required":["GroupName"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group.</p>",
          "locationName":"groupName"
        }
      }
    },
    "DeletePublicIpv4PoolRequest":{
      "type":"structure",
      "required":["PoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PoolId":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of the public IPv4 pool you want to delete.</p>"
        }
      }
    },
    "DeletePublicIpv4PoolResult":{
      "type":"structure",
      "members":{
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Information about the result of deleting the public IPv4 pool.</p>",
          "locationName":"returnValue"
        }
      }
    },
    "DeleteQueuedReservedInstancesError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"DeleteQueuedReservedInstancesErrorCode",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the error for a Reserved Instance whose queued purchase could not be deleted.</p>"
    },
    "DeleteQueuedReservedInstancesErrorCode":{
      "type":"string",
      "enum":[
        "reserved-instances-id-invalid",
        "reserved-instances-not-in-queued-state",
        "unexpected-error"
      ]
    },
    "DeleteQueuedReservedInstancesIdList":{
      "type":"list",
      "member":{
        "shape":"ReservationId",
        "locationName":"item"
      },
      "max":100,
      "min":1
    },
    "DeleteQueuedReservedInstancesRequest":{
      "type":"structure",
      "required":["ReservedInstancesIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ReservedInstancesIds":{
          "shape":"DeleteQueuedReservedInstancesIdList",
          "documentation":"<p>The IDs of the Reserved Instances.</p>",
          "locationName":"ReservedInstancesId"
        }
      }
    },
    "DeleteQueuedReservedInstancesResult":{
      "type":"structure",
      "members":{
        "SuccessfulQueuedPurchaseDeletions":{
          "shape":"SuccessfulQueuedPurchaseDeletionSet",
          "documentation":"<p>Information about the queued purchases that were successfully deleted.</p>",
          "locationName":"successfulQueuedPurchaseDeletionSet"
        },
        "FailedQueuedPurchaseDeletions":{
          "shape":"FailedQueuedPurchaseDeletionSet",
          "documentation":"<p>Information about the queued purchases that could not be deleted.</p>",
          "locationName":"failedQueuedPurchaseDeletionSet"
        }
      }
    },
    "DeleteRouteRequest":{
      "type":"structure",
      "required":["RouteTableId"],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR range for the route. The value you specify must match the CIDR for the route exactly.</p>",
          "locationName":"destinationCidrBlock"
        },
        "DestinationIpv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR range for the route. The value you specify must match the CIDR for the route exactly.</p>",
          "locationName":"destinationIpv6CidrBlock"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list for the route.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table.</p>",
          "locationName":"routeTableId"
        }
      }
    },
    "DeleteRouteTableRequest":{
      "type":"structure",
      "required":["RouteTableId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table.</p>",
          "locationName":"routeTableId"
        }
      }
    },
    "DeleteSecurityGroupRequest":{
      "type":"structure",
      "members":{
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group. Required for a nondefault VPC.</p>"
        },
        "GroupName":{
          "shape":"SecurityGroupName",
          "documentation":"<p>[EC2-Classic, default VPC] The name of the security group. You can specify either the security group name or the security group ID. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteSnapshotRequest":{
      "type":"structure",
      "required":["SnapshotId"],
      "members":{
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the EBS snapshot.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteSpotDatafeedSubscriptionRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteSpotDatafeedSubscription.</p>"
    },
    "DeleteSubnetCidrReservationRequest":{
      "type":"structure",
      "required":["SubnetCidrReservationId"],
      "members":{
        "SubnetCidrReservationId":{
          "shape":"SubnetCidrReservationId",
          "documentation":"<p>The ID of the subnet CIDR reservation.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteSubnetCidrReservationResult":{
      "type":"structure",
      "members":{
        "DeletedSubnetCidrReservation":{
          "shape":"SubnetCidrReservation",
          "documentation":"<p>Information about the deleted subnet CIDR reservation.</p>",
          "locationName":"deletedSubnetCidrReservation"
        }
      }
    },
    "DeleteSubnetRequest":{
      "type":"structure",
      "required":["SubnetId"],
      "members":{
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteTagsRequest":{
      "type":"structure",
      "required":["Resources"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Resources":{
          "shape":"ResourceIdList",
          "documentation":"<p>The IDs of the resources, separated by spaces.</p> <p>Constraints: Up to 1000 resource IDs. We recommend breaking up this request into smaller batches.</p>",
          "locationName":"resourceId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags to delete. Specify a tag key and an optional tag value to delete specific tags. If you specify a tag key without a tag value, we delete any tag with this key regardless of its value. If you specify a tag key with an empty string as the tag value, we delete the tag only if its value is an empty string.</p> <p>If you omit this parameter, we delete all user-defined tags for the specified resources. We do not delete Amazon Web Services-generated tags (tags that have the <code>aws:</code> prefix).</p> <p>Constraints: Up to 1000 tags.</p>",
          "locationName":"tag"
        }
      }
    },
    "DeleteTrafficMirrorFilterRequest":{
      "type":"structure",
      "required":["TrafficMirrorFilterId"],
      "members":{
        "TrafficMirrorFilterId":{
          "shape":"TrafficMirrorFilterId",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTrafficMirrorFilterResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>",
          "locationName":"trafficMirrorFilterId"
        }
      }
    },
    "DeleteTrafficMirrorFilterRuleRequest":{
      "type":"structure",
      "required":["TrafficMirrorFilterRuleId"],
      "members":{
        "TrafficMirrorFilterRuleId":{
          "shape":"TrafficMirrorFilterRuleIdWithResolver",
          "documentation":"<p>The ID of the Traffic Mirror rule.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTrafficMirrorFilterRuleResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterRuleId":{
          "shape":"String",
          "documentation":"<p>The ID of the deleted Traffic Mirror rule.</p>",
          "locationName":"trafficMirrorFilterRuleId"
        }
      }
    },
    "DeleteTrafficMirrorSessionRequest":{
      "type":"structure",
      "required":["TrafficMirrorSessionId"],
      "members":{
        "TrafficMirrorSessionId":{
          "shape":"TrafficMirrorSessionId",
          "documentation":"<p>The ID of the Traffic Mirror session.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTrafficMirrorSessionResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorSessionId":{
          "shape":"String",
          "documentation":"<p>The ID of the deleted Traffic Mirror session.</p>",
          "locationName":"trafficMirrorSessionId"
        }
      }
    },
    "DeleteTrafficMirrorTargetRequest":{
      "type":"structure",
      "required":["TrafficMirrorTargetId"],
      "members":{
        "TrafficMirrorTargetId":{
          "shape":"TrafficMirrorTargetId",
          "documentation":"<p>The ID of the Traffic Mirror target.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTrafficMirrorTargetResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorTargetId":{
          "shape":"String",
          "documentation":"<p>The ID of the deleted Traffic Mirror target.</p>",
          "locationName":"trafficMirrorTargetId"
        }
      }
    },
    "DeleteTransitGatewayConnectPeerRequest":{
      "type":"structure",
      "required":["TransitGatewayConnectPeerId"],
      "members":{
        "TransitGatewayConnectPeerId":{
          "shape":"TransitGatewayConnectPeerId",
          "documentation":"<p>The ID of the Connect peer.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayConnectPeerResult":{
      "type":"structure",
      "members":{
        "TransitGatewayConnectPeer":{
          "shape":"TransitGatewayConnectPeer",
          "documentation":"<p>Information about the deleted Connect peer.</p>",
          "locationName":"transitGatewayConnectPeer"
        }
      }
    },
    "DeleteTransitGatewayConnectRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the Connect attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayConnectResult":{
      "type":"structure",
      "members":{
        "TransitGatewayConnect":{
          "shape":"TransitGatewayConnect",
          "documentation":"<p>Information about the deleted Connect attachment.</p>",
          "locationName":"transitGatewayConnect"
        }
      }
    },
    "DeleteTransitGatewayMulticastDomainRequest":{
      "type":"structure",
      "required":["TransitGatewayMulticastDomainId"],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayMulticastDomainResult":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomain":{
          "shape":"TransitGatewayMulticastDomain",
          "documentation":"<p>Information about the deleted transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomain"
        }
      }
    },
    "DeleteTransitGatewayPeeringAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway peering attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayPeeringAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPeeringAttachment":{
          "shape":"TransitGatewayPeeringAttachment",
          "documentation":"<p>The transit gateway peering attachment.</p>",
          "locationName":"transitGatewayPeeringAttachment"
        }
      }
    },
    "DeleteTransitGatewayPolicyTableRequest":{
      "type":"structure",
      "required":["TransitGatewayPolicyTableId"],
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The transit gateway policy table to delete.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayPolicyTableResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTable":{
          "shape":"TransitGatewayPolicyTable",
          "documentation":"<p>Provides details about the deleted transit gateway policy table.</p>",
          "locationName":"transitGatewayPolicyTable"
        }
      }
    },
    "DeleteTransitGatewayPrefixListReferenceRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "PrefixListId"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the route table.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayPrefixListReferenceResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPrefixListReference":{
          "shape":"TransitGatewayPrefixListReference",
          "documentation":"<p>Information about the deleted prefix list reference.</p>",
          "locationName":"transitGatewayPrefixListReference"
        }
      }
    },
    "DeleteTransitGatewayRequest":{
      "type":"structure",
      "required":["TransitGatewayId"],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayResult":{
      "type":"structure",
      "members":{
        "TransitGateway":{
          "shape":"TransitGateway",
          "documentation":"<p>Information about the deleted transit gateway.</p>",
          "locationName":"transitGateway"
        }
      }
    },
    "DeleteTransitGatewayRouteRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "DestinationCidrBlock"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR range for the route. This must match the CIDR for the route exactly.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayRouteResult":{
      "type":"structure",
      "members":{
        "Route":{
          "shape":"TransitGatewayRoute",
          "documentation":"<p>Information about the route.</p>",
          "locationName":"route"
        }
      }
    },
    "DeleteTransitGatewayRouteTableAnnouncementRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableAnnouncementId"],
      "members":{
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The transit gateway route table ID that's being deleted. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayRouteTableAnnouncementResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableAnnouncement":{
          "shape":"TransitGatewayRouteTableAnnouncement",
          "documentation":"<p>Provides details about a deleted transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableAnnouncement"
        }
      }
    },
    "DeleteTransitGatewayRouteTableRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableId"],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayRouteTableResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTable":{
          "shape":"TransitGatewayRouteTable",
          "documentation":"<p>Information about the deleted transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTable"
        }
      }
    },
    "DeleteTransitGatewayVpcAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteTransitGatewayVpcAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayVpcAttachment":{
          "shape":"TransitGatewayVpcAttachment",
          "documentation":"<p>Information about the deleted VPC attachment.</p>",
          "locationName":"transitGatewayVpcAttachment"
        }
      }
    },
    "DeleteVerifiedAccessEndpointRequest":{
      "type":"structure",
      "required":["VerifiedAccessEndpointId"],
      "members":{
        "VerifiedAccessEndpointId":{
          "shape":"VerifiedAccessEndpointId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteVerifiedAccessEndpointResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessEndpoint":{
          "shape":"VerifiedAccessEndpoint",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"verifiedAccessEndpoint"
        }
      }
    },
    "DeleteVerifiedAccessGroupRequest":{
      "type":"structure",
      "required":["VerifiedAccessGroupId"],
      "members":{
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeleteVerifiedAccessGroupResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessGroup":{
          "shape":"VerifiedAccessGroup",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>",
          "locationName":"verifiedAccessGroup"
        }
      }
    },
    "DeleteVerifiedAccessInstanceRequest":{
      "type":"structure",
      "required":["VerifiedAccessInstanceId"],
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "DeleteVerifiedAccessInstanceResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstance":{
          "shape":"VerifiedAccessInstance",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstance"
        }
      }
    },
    "DeleteVerifiedAccessTrustProviderRequest":{
      "type":"structure",
      "required":["VerifiedAccessTrustProviderId"],
      "members":{
        "VerifiedAccessTrustProviderId":{
          "shape":"VerifiedAccessTrustProviderId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "DeleteVerifiedAccessTrustProviderResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProvider":{
          "shape":"VerifiedAccessTrustProvider",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"verifiedAccessTrustProvider"
        }
      }
    },
    "DeleteVolumeRequest":{
      "type":"structure",
      "required":["VolumeId"],
      "members":{
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the volume.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteVpcEndpointConnectionNotificationsRequest":{
      "type":"structure",
      "required":["ConnectionNotificationIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ConnectionNotificationIds":{
          "shape":"ConnectionNotificationIdsList",
          "documentation":"<p>The IDs of the notifications.</p>",
          "locationName":"ConnectionNotificationId"
        }
      }
    },
    "DeleteVpcEndpointConnectionNotificationsResult":{
      "type":"structure",
      "members":{
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the notifications that could not be deleted successfully.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "DeleteVpcEndpointServiceConfigurationsRequest":{
      "type":"structure",
      "required":["ServiceIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceIds":{
          "shape":"VpcEndpointServiceIdList",
          "documentation":"<p>The IDs of the services.</p>",
          "locationName":"ServiceId"
        }
      }
    },
    "DeleteVpcEndpointServiceConfigurationsResult":{
      "type":"structure",
      "members":{
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the service configurations that were not deleted, if applicable.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "DeleteVpcEndpointsRequest":{
      "type":"structure",
      "required":["VpcEndpointIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VpcEndpointIds":{
          "shape":"VpcEndpointIdList",
          "documentation":"<p>The IDs of the VPC endpoints.</p>",
          "locationName":"VpcEndpointId"
        }
      }
    },
    "DeleteVpcEndpointsResult":{
      "type":"structure",
      "members":{
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the VPC endpoints that were not successfully deleted.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "DeleteVpcPeeringConnectionRequest":{
      "type":"structure",
      "required":["VpcPeeringConnectionId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcPeeringConnectionId":{
          "shape":"VpcPeeringConnectionId",
          "documentation":"<p>The ID of the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      }
    },
    "DeleteVpcPeeringConnectionResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "DeleteVpcRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DeleteVpnConnectionRequest":{
      "type":"structure",
      "required":["VpnConnectionId"],
      "members":{
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the VPN connection.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteVpnConnection.</p>"
    },
    "DeleteVpnConnectionRouteRequest":{
      "type":"structure",
      "required":[
        "DestinationCidrBlock",
        "VpnConnectionId"
      ],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR block associated with the local subnet of the customer network.</p>"
        },
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the VPN connection.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteVpnConnectionRoute.</p>"
    },
    "DeleteVpnGatewayRequest":{
      "type":"structure",
      "required":["VpnGatewayId"],
      "members":{
        "VpnGatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DeleteVpnGateway.</p>"
    },
    "DeprovisionByoipCidrRequest":{
      "type":"structure",
      "required":["Cidr"],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The address range, in CIDR notation. The prefix must be the same prefix that you specified when you provisioned the address range.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeprovisionByoipCidrResult":{
      "type":"structure",
      "members":{
        "ByoipCidr":{
          "shape":"ByoipCidr",
          "documentation":"<p>Information about the address range.</p>",
          "locationName":"byoipCidr"
        }
      }
    },
    "DeprovisionIpamPoolCidrRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the pool that has the CIDR you want to deprovision.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR which you want to deprovision from the pool.</p>"
        }
      }
    },
    "DeprovisionIpamPoolCidrResult":{
      "type":"structure",
      "members":{
        "IpamPoolCidr":{
          "shape":"IpamPoolCidr",
          "documentation":"<p>The deprovisioned pool CIDR.</p>",
          "locationName":"ipamPoolCidr"
        }
      }
    },
    "DeprovisionPublicIpv4PoolCidrRequest":{
      "type":"structure",
      "required":[
        "PoolId",
        "Cidr"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PoolId":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of the pool that you want to deprovision the CIDR from.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR you want to deprovision from the pool.</p>"
        }
      }
    },
    "DeprovisionPublicIpv4PoolCidrResult":{
      "type":"structure",
      "members":{
        "PoolId":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of the pool that you deprovisioned the CIDR from.</p>",
          "locationName":"poolId"
        },
        "DeprovisionedAddresses":{
          "shape":"DeprovisionedAddressSet",
          "documentation":"<p>The deprovisioned CIDRs.</p>",
          "locationName":"deprovisionedAddressSet"
        }
      }
    },
    "DeprovisionedAddressSet":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "DeregisterImageRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DeregisterImage.</p>"
    },
    "DeregisterInstanceEventNotificationAttributesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceTagAttribute":{
          "shape":"DeregisterInstanceTagAttributeRequest",
          "documentation":"<p>Information about the tag keys to deregister.</p>"
        }
      }
    },
    "DeregisterInstanceEventNotificationAttributesResult":{
      "type":"structure",
      "members":{
        "InstanceTagAttribute":{
          "shape":"InstanceTagNotificationAttribute",
          "documentation":"<p>The resulting set of tag keys.</p>",
          "locationName":"instanceTagAttribute"
        }
      }
    },
    "DeregisterInstanceTagAttributeRequest":{
      "type":"structure",
      "members":{
        "IncludeAllTagsOfInstance":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to deregister all tag keys in the current Region. Specify <code>false</code> to deregister all tag keys.</p>"
        },
        "InstanceTagKeys":{
          "shape":"InstanceTagKeySet",
          "documentation":"<p>Information about the tag keys to deregister.</p>",
          "locationName":"InstanceTagKey"
        }
      },
      "documentation":"<p>Information about the tag keys to deregister for the current Region. You can either specify individual tag keys or deregister all tag keys in the current Region. You must specify either <code>IncludeAllTagsOfInstance</code> or <code>InstanceTagKeys</code> in the request</p>"
    },
    "DeregisterTransitGatewayMulticastGroupMembersRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>"
        },
        "NetworkInterfaceIds":{
          "shape":"TransitGatewayNetworkInterfaceIdList",
          "documentation":"<p>The IDs of the group members' network interfaces.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeregisterTransitGatewayMulticastGroupMembersResult":{
      "type":"structure",
      "members":{
        "DeregisteredMulticastGroupMembers":{
          "shape":"TransitGatewayMulticastDeregisteredGroupMembers",
          "documentation":"<p>Information about the deregistered members.</p>",
          "locationName":"deregisteredMulticastGroupMembers"
        }
      }
    },
    "DeregisterTransitGatewayMulticastGroupSourcesRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>"
        },
        "NetworkInterfaceIds":{
          "shape":"TransitGatewayNetworkInterfaceIdList",
          "documentation":"<p>The IDs of the group sources' network interfaces.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DeregisterTransitGatewayMulticastGroupSourcesResult":{
      "type":"structure",
      "members":{
        "DeregisteredMulticastGroupSources":{
          "shape":"TransitGatewayMulticastDeregisteredGroupSources",
          "documentation":"<p>Information about the deregistered group sources.</p>",
          "locationName":"deregisteredMulticastGroupSources"
        }
      }
    },
    "DescribeAccountAttributesRequest":{
      "type":"structure",
      "members":{
        "AttributeNames":{
          "shape":"AccountAttributeNameStringList",
          "documentation":"<p>The account attribute names.</p>",
          "locationName":"attributeName"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeAccountAttributesResult":{
      "type":"structure",
      "members":{
        "AccountAttributes":{
          "shape":"AccountAttributeList",
          "documentation":"<p>Information about the account attributes.</p>",
          "locationName":"accountAttributeSet"
        }
      }
    },
    "DescribeAddressTransfersMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeAddressTransfersRequest":{
      "type":"structure",
      "members":{
        "AllocationIds":{
          "shape":"AllocationIdList",
          "documentation":"<p>The allocation IDs of Elastic IP addresses.</p>",
          "locationName":"AllocationId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeAddressTransfersMaxResults",
          "documentation":"<p>The maximum number of address transfers to return in one page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeAddressTransfersResult":{
      "type":"structure",
      "members":{
        "AddressTransfers":{
          "shape":"AddressTransferList",
          "documentation":"<p>The Elastic IP address transfer.</p>",
          "locationName":"addressTransferSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeAddressesAttributeRequest":{
      "type":"structure",
      "members":{
        "AllocationIds":{
          "shape":"AllocationIds",
          "documentation":"<p>[EC2-VPC] The allocation IDs.</p>",
          "locationName":"AllocationId"
        },
        "Attribute":{
          "shape":"AddressAttributeName",
          "documentation":"<p>The attribute of the IP address.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"AddressMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeAddressesAttributeResult":{
      "type":"structure",
      "members":{
        "Addresses":{
          "shape":"AddressSet",
          "documentation":"<p>Information about the IP addresses.</p>",
          "locationName":"addressSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeAddressesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>allocation-id</code> - [EC2-VPC] The allocation ID for the address.</p> </li> <li> <p> <code>association-id</code> - [EC2-VPC] The association ID for the address.</p> </li> <li> <p> <code>domain</code> - Indicates whether the address is for use in EC2-Classic (<code>standard</code>) or in a VPC (<code>vpc</code>).</p> </li> <li> <p> <code>instance-id</code> - The ID of the instance the address is associated with, if any.</p> </li> <li> <p> <code>network-border-group</code> - A unique set of Availability Zones, Local Zones, or Wavelength Zones from where Amazon Web Services advertises IP addresses. </p> </li> <li> <p> <code>network-interface-id</code> - [EC2-VPC] The ID of the network interface that the address is associated with, if any.</p> </li> <li> <p> <code>network-interface-owner-id</code> - The Amazon Web Services account ID of the owner.</p> </li> <li> <p> <code>private-ip-address</code> - [EC2-VPC] The private IP address associated with the Elastic IP address.</p> </li> <li> <p> <code>public-ip</code> - The Elastic IP address, or the carrier IP address.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "PublicIps":{
          "shape":"PublicIpStringList",
          "documentation":"<p>One or more Elastic IP addresses.</p> <p>Default: Describes all your Elastic IP addresses.</p>",
          "locationName":"PublicIp"
        },
        "AllocationIds":{
          "shape":"AllocationIdList",
          "documentation":"<p>[EC2-VPC] Information about the allocation IDs.</p>",
          "locationName":"AllocationId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeAddressesResult":{
      "type":"structure",
      "members":{
        "Addresses":{
          "shape":"AddressList",
          "documentation":"<p>Information about the Elastic IP addresses.</p>",
          "locationName":"addressesSet"
        }
      }
    },
    "DescribeAggregateIdFormatRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeAggregateIdFormatResult":{
      "type":"structure",
      "members":{
        "UseLongIdsAggregated":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether all resource types in the Region are configured to use longer IDs. This value is only <code>true</code> if all users are configured to use longer IDs for all resources types in the Region.</p>",
          "locationName":"useLongIdsAggregated"
        },
        "Statuses":{
          "shape":"IdFormatList",
          "documentation":"<p>Information about each resource's ID format.</p>",
          "locationName":"statusSet"
        }
      }
    },
    "DescribeAvailabilityZonesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>group-name</code> - For Availability Zones, use the Region name. For Local Zones, use the name of the group associated with the Local Zone (for example, <code>us-west-2-lax-1</code>) For Wavelength Zones, use the name of the group associated with the Wavelength Zone (for example, <code>us-east-1-wl1-bos-wlz-1</code>).</p> </li> <li> <p> <code>message</code> - The Zone message.</p> </li> <li> <p> <code>opt-in-status</code> - The opt-in status (<code>opted-in</code> | <code>not-opted-in</code> | <code>opt-in-not-required</code>).</p> </li> <li> <p> <code>parent-zoneID</code> - The ID of the zone that handles some of the Local Zone and Wavelength Zone control plane operations, such as API calls.</p> </li> <li> <p> <code>parent-zoneName</code> - The ID of the zone that handles some of the Local Zone and Wavelength Zone control plane operations, such as API calls.</p> </li> <li> <p> <code>region-name</code> - The name of the Region for the Zone (for example, <code>us-east-1</code>).</p> </li> <li> <p> <code>state</code> - The state of the Availability Zone, the Local Zone, or the Wavelength Zone (<code>available</code>).</p> </li> <li> <p> <code>zone-id</code> - The ID of the Availability Zone (for example, <code>use1-az1</code>), the Local Zone (for example, <code>usw2-lax1-az1</code>), or the Wavelength Zone (for example, <code>us-east-1-wl1-bos-wlz-1</code>).</p> </li> <li> <p> <code>zone-name</code> - The name of the Availability Zone (for example, <code>us-east-1a</code>), the Local Zone (for example, <code>us-west-2-lax-1a</code>), or the Wavelength Zone (for example, <code>us-east-1-wl1-bos-wlz-1</code>).</p> </li> <li> <p> <code>zone-type</code> - The type of zone (<code>availability-zone</code> | <code>local-zone</code> | <code>wavelength-zone</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "ZoneNames":{
          "shape":"ZoneNameStringList",
          "documentation":"<p>The names of the Availability Zones, Local Zones, and Wavelength Zones.</p>",
          "locationName":"ZoneName"
        },
        "ZoneIds":{
          "shape":"ZoneIdStringList",
          "documentation":"<p>The IDs of the Availability Zones, Local Zones, and Wavelength Zones.</p>",
          "locationName":"ZoneId"
        },
        "AllAvailabilityZones":{
          "shape":"Boolean",
          "documentation":"<p>Include all Availability Zones, Local Zones, and Wavelength Zones regardless of your opt-in status.</p> <p>If you do not use this parameter, the results include only the zones for the Regions where you have chosen the option to opt in.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeAvailabilityZonesResult":{
      "type":"structure",
      "members":{
        "AvailabilityZones":{
          "shape":"AvailabilityZoneList",
          "documentation":"<p>Information about the Availability Zones, Local Zones, and Wavelength Zones.</p>",
          "locationName":"availabilityZoneInfo"
        }
      }
    },
    "DescribeAwsNetworkPerformanceMetricSubscriptionsRequest":{
      "type":"structure",
      "members":{
        "MaxResults":{
          "shape":"MaxResultsParam",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeAwsNetworkPerformanceMetricSubscriptionsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "Subscriptions":{
          "shape":"SubscriptionList",
          "documentation":"<p>Describes the current Infrastructure Performance subscriptions.</p>",
          "locationName":"subscriptionSet"
        }
      }
    },
    "DescribeBundleTasksRequest":{
      "type":"structure",
      "members":{
        "BundleIds":{
          "shape":"BundleIdStringList",
          "documentation":"<p>The bundle task IDs.</p> <p>Default: Describes all your bundle tasks.</p>",
          "locationName":"BundleId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>bundle-id</code> - The ID of the bundle task.</p> </li> <li> <p> <code>error-code</code> - If the task failed, the error code returned.</p> </li> <li> <p> <code>error-message</code> - If the task failed, the error message returned.</p> </li> <li> <p> <code>instance-id</code> - The ID of the instance.</p> </li> <li> <p> <code>progress</code> - The level of task completion, as a percentage (for example, 20%).</p> </li> <li> <p> <code>s3-bucket</code> - The Amazon S3 bucket to store the AMI.</p> </li> <li> <p> <code>s3-prefix</code> - The beginning of the AMI name.</p> </li> <li> <p> <code>start-time</code> - The time the task started (for example, 2013-09-15T17:15:20.000Z).</p> </li> <li> <p> <code>state</code> - The state of the task (<code>pending</code> | <code>waiting-for-shutdown</code> | <code>bundling</code> | <code>storing</code> | <code>cancelling</code> | <code>complete</code> | <code>failed</code>).</p> </li> <li> <p> <code>update-time</code> - The time of the most recent update for the task.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeBundleTasksResult":{
      "type":"structure",
      "members":{
        "BundleTasks":{
          "shape":"BundleTaskList",
          "documentation":"<p>Information about the bundle tasks.</p>",
          "locationName":"bundleInstanceTasksSet"
        }
      }
    },
    "DescribeByoipCidrsMaxResults":{
      "type":"integer",
      "max":100,
      "min":1
    },
    "DescribeByoipCidrsRequest":{
      "type":"structure",
      "required":["MaxResults"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "MaxResults":{
          "shape":"DescribeByoipCidrsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeByoipCidrsResult":{
      "type":"structure",
      "members":{
        "ByoipCidrs":{
          "shape":"ByoipCidrSet",
          "documentation":"<p>Information about your address ranges.</p>",
          "locationName":"byoipCidrSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeCapacityReservationFleetsMaxResults":{
      "type":"integer",
      "max":100,
      "min":1
    },
    "DescribeCapacityReservationFleetsRequest":{
      "type":"structure",
      "members":{
        "CapacityReservationFleetIds":{
          "shape":"CapacityReservationFleetIdSet",
          "documentation":"<p>The IDs of the Capacity Reservation Fleets to describe.</p>",
          "locationName":"CapacityReservationFleetId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeCapacityReservationFleetsMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>state</code> - The state of the Fleet (<code>submitted</code> | <code>modifying</code> | <code>active</code> | <code>partially_fulfilled</code> | <code>expiring</code> | <code>expired</code> | <code>cancelling</code> | <code>cancelled</code> | <code>failed</code>).</p> </li> <li> <p> <code>instance-match-criteria</code> - The instance matching criteria for the Fleet. Only <code>open</code> is supported.</p> </li> <li> <p> <code>tenancy</code> - The tenancy of the Fleet (<code>default</code> | <code>dedicated</code>).</p> </li> <li> <p> <code>allocation-strategy</code> - The allocation strategy used by the Fleet. Only <code>prioritized</code> is supported.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeCapacityReservationFleetsResult":{
      "type":"structure",
      "members":{
        "CapacityReservationFleets":{
          "shape":"CapacityReservationFleetSet",
          "documentation":"<p>Information about the Capacity Reservation Fleets.</p>",
          "locationName":"capacityReservationFleetSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeCapacityReservationsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "DescribeCapacityReservationsRequest":{
      "type":"structure",
      "members":{
        "CapacityReservationIds":{
          "shape":"CapacityReservationIdSet",
          "documentation":"<p>The ID of the Capacity Reservation.</p>",
          "locationName":"CapacityReservationId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeCapacityReservationsMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>instance-type</code> - The type of instance for which the Capacity Reservation reserves capacity.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the Capacity Reservation.</p> </li> <li> <p> <code>instance-platform</code> - The type of operating system for which the Capacity Reservation reserves capacity.</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone of the Capacity Reservation.</p> </li> <li> <p> <code>tenancy</code> - Indicates the tenancy of the Capacity Reservation. A Capacity Reservation can have one of the following tenancy settings:</p> <ul> <li> <p> <code>default</code> - The Capacity Reservation is created on hardware that is shared with other Amazon Web Services accounts.</p> </li> <li> <p> <code>dedicated</code> - The Capacity Reservation is created on single-tenant hardware that is dedicated to a single Amazon Web Services account.</p> </li> </ul> </li> <li> <p> <code>outpost-arn</code> - The Amazon Resource Name (ARN) of the Outpost on which the Capacity Reservation was created.</p> </li> <li> <p> <code>state</code> - The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:</p> <ul> <li> <p> <code>active</code>- The Capacity Reservation is active and the capacity is available for your use.</p> </li> <li> <p> <code>expired</code> - The Capacity Reservation expired automatically at the date and time specified in your request. The reserved capacity is no longer available for your use.</p> </li> <li> <p> <code>cancelled</code> - The Capacity Reservation was cancelled. The reserved capacity is no longer available for your use.</p> </li> <li> <p> <code>pending</code> - The Capacity Reservation request was successful but the capacity provisioning is still pending.</p> </li> <li> <p> <code>failed</code> - The Capacity Reservation request has failed. A request might fail due to invalid request parameters, capacity constraints, or instance limit constraints. Failed requests are retained for 60 minutes.</p> </li> </ul> </li> <li> <p> <code>start-date</code> - The date and time at which the Capacity Reservation was started.</p> </li> <li> <p> <code>end-date</code> - The date and time at which the Capacity Reservation expires. When a Capacity Reservation expires, the reserved capacity is released and you can no longer launch instances into it. The Capacity Reservation's state changes to expired when it reaches its end date and time.</p> </li> <li> <p> <code>end-date-type</code> - Indicates the way in which the Capacity Reservation ends. A Capacity Reservation can have one of the following end types:</p> <ul> <li> <p> <code>unlimited</code> - The Capacity Reservation remains active until you explicitly cancel it.</p> </li> <li> <p> <code>limited</code> - The Capacity Reservation expires automatically at a specified date and time.</p> </li> </ul> </li> <li> <p> <code>instance-match-criteria</code> - Indicates the type of instance launches that the Capacity Reservation accepts. The options include:</p> <ul> <li> <p> <code>open</code> - The Capacity Reservation accepts all instances that have matching attributes (instance type, platform, and Availability Zone). Instances that have matching attributes launch into the Capacity Reservation automatically without specifying any additional parameters.</p> </li> <li> <p> <code>targeted</code> - The Capacity Reservation only accepts instances that have matching attributes (instance type, platform, and Availability Zone), and explicitly target the Capacity Reservation. This ensures that only permitted instances can use the reserved capacity.</p> </li> </ul> </li> <li> <p> <code>placement-group-arn</code> - The ARN of the cluster placement group in which the Capacity Reservation was created.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeCapacityReservationsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "CapacityReservations":{
          "shape":"CapacityReservationSet",
          "documentation":"<p>Information about the Capacity Reservations.</p>",
          "locationName":"capacityReservationSet"
        }
      }
    },
    "DescribeCarrierGatewaysRequest":{
      "type":"structure",
      "members":{
        "CarrierGatewayIds":{
          "shape":"CarrierGatewayIdSet",
          "documentation":"<p>One or more carrier gateway IDs.</p>",
          "locationName":"CarrierGatewayId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>carrier-gateway-id</code> - The ID of the carrier gateway.</p> </li> <li> <p> <code>state</code> - The state of the carrier gateway (<code>pending</code> | <code>failed</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the owner of the carrier gateway.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC associated with the carrier gateway.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"CarrierGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeCarrierGatewaysResult":{
      "type":"structure",
      "members":{
        "CarrierGateways":{
          "shape":"CarrierGatewaySet",
          "documentation":"<p>Information about the carrier gateway.</p>",
          "locationName":"carrierGatewaySet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClassicLinkInstancesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeClassicLinkInstancesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>group-id</code> - The ID of a VPC security group that's associated with the instance.</p> </li> <li> <p> <code>instance-id</code> - The ID of the instance.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC to which the instance is linked.</p> <p> <code>vpc-id</code> - The ID of the VPC that the instance is linked to.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>One or more instance IDs. Must be instances linked to a VPC through ClassicLink.</p>",
          "locationName":"InstanceId"
        },
        "MaxResults":{
          "shape":"DescribeClassicLinkInstancesMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p> <p>Constraint: If the value is greater than 1000, we return only 1000 items.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClassicLinkInstancesResult":{
      "type":"structure",
      "members":{
        "Instances":{
          "shape":"ClassicLinkInstanceList",
          "documentation":"<p>Information about one or more linked EC2-Classic instances.</p>",
          "locationName":"instancesSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClientVpnAuthorizationRulesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeClientVpnAuthorizationRulesRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>description</code> - The description of the authorization rule.</p> </li> <li> <p> <code>destination-cidr</code> - The CIDR of the network to which the authorization rule applies.</p> </li> <li> <p> <code>group-id</code> - The ID of the Active Directory group to which the authorization rule grants access.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeClientVpnAuthorizationRulesMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the nextToken value.</p>"
        }
      }
    },
    "DescribeClientVpnAuthorizationRulesResult":{
      "type":"structure",
      "members":{
        "AuthorizationRules":{
          "shape":"AuthorizationRuleSet",
          "documentation":"<p>Information about the authorization rules.</p>",
          "locationName":"authorizationRule"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClientVpnConnectionsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeClientVpnConnectionsRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>connection-id</code> - The ID of the connection.</p> </li> <li> <p> <code>username</code> - For Active Directory client authentication, the user name of the client who established the client connection.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeClientVpnConnectionsMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the nextToken value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeClientVpnConnectionsResult":{
      "type":"structure",
      "members":{
        "Connections":{
          "shape":"ClientVpnConnectionSet",
          "documentation":"<p>Information about the active and terminated client connections.</p>",
          "locationName":"connections"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClientVpnEndpointMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeClientVpnEndpointsRequest":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointIds":{
          "shape":"ClientVpnEndpointIdList",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>",
          "locationName":"ClientVpnEndpointId"
        },
        "MaxResults":{
          "shape":"DescribeClientVpnEndpointMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the nextToken value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>endpoint-id</code> - The ID of the Client VPN endpoint.</p> </li> <li> <p> <code>transport-protocol</code> - The transport protocol (<code>tcp</code> | <code>udp</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeClientVpnEndpointsResult":{
      "type":"structure",
      "members":{
        "ClientVpnEndpoints":{
          "shape":"EndpointSet",
          "documentation":"<p>Information about the Client VPN endpoints.</p>",
          "locationName":"clientVpnEndpoint"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClientVpnRoutesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeClientVpnRoutesRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>destination-cidr</code> - The CIDR of the route destination.</p> </li> <li> <p> <code>origin</code> - How the route was associated with the Client VPN endpoint (<code>associate</code> | <code>add-route</code>).</p> </li> <li> <p> <code>target-subnet</code> - The ID of the subnet through which traffic is routed.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeClientVpnRoutesMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the nextToken value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeClientVpnRoutesResult":{
      "type":"structure",
      "members":{
        "Routes":{
          "shape":"ClientVpnRouteSet",
          "documentation":"<p>Information about the Client VPN endpoint routes.</p>",
          "locationName":"routes"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeClientVpnTargetNetworksMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeClientVpnTargetNetworksRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "AssociationIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the target network associations.</p>"
        },
        "MaxResults":{
          "shape":"DescribeClientVpnTargetNetworksMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the nextToken value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>association-id</code> - The ID of the association.</p> </li> <li> <p> <code>target-network-id</code> - The ID of the subnet specified as the target network.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC in which the target network is located.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeClientVpnTargetNetworksResult":{
      "type":"structure",
      "members":{
        "ClientVpnTargetNetworks":{
          "shape":"TargetNetworkSet",
          "documentation":"<p>Information about the associated target networks.</p>",
          "locationName":"clientVpnTargetNetworks"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeCoipPoolsRequest":{
      "type":"structure",
      "members":{
        "PoolIds":{
          "shape":"CoipPoolIdSet",
          "documentation":"<p>The IDs of the address pools.</p>",
          "locationName":"PoolId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>coip-pool.local-gateway-route-table-id</code> - The ID of the local gateway route table.</p> </li> <li> <p> <code>coip-pool.pool-id</code> - The ID of the address pool.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"CoipPoolMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeCoipPoolsResult":{
      "type":"structure",
      "members":{
        "CoipPools":{
          "shape":"CoipPoolSet",
          "documentation":"<p>Information about the address pools.</p>",
          "locationName":"coipPoolSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeConversionTaskList":{
      "type":"list",
      "member":{
        "shape":"ConversionTask",
        "locationName":"item"
      }
    },
    "DescribeConversionTasksRequest":{
      "type":"structure",
      "members":{
        "ConversionTaskIds":{
          "shape":"ConversionIdStringList",
          "documentation":"<p>The conversion task IDs.</p>",
          "locationName":"conversionTaskId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeConversionTasksResult":{
      "type":"structure",
      "members":{
        "ConversionTasks":{
          "shape":"DescribeConversionTaskList",
          "documentation":"<p>Information about the conversion tasks.</p>",
          "locationName":"conversionTasks"
        }
      }
    },
    "DescribeCustomerGatewaysRequest":{
      "type":"structure",
      "members":{
        "CustomerGatewayIds":{
          "shape":"CustomerGatewayIdStringList",
          "documentation":"<p>One or more customer gateway IDs.</p> <p>Default: Describes all your customer gateways.</p>",
          "locationName":"CustomerGatewayId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>bgp-asn</code> - The customer gateway's Border Gateway Protocol (BGP) Autonomous System Number (ASN).</p> </li> <li> <p> <code>customer-gateway-id</code> - The ID of the customer gateway.</p> </li> <li> <p> <code>ip-address</code> - The IP address of the customer gateway device's external interface.</p> </li> <li> <p> <code>state</code> - The state of the customer gateway (<code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>type</code> - The type of customer gateway. Currently, the only supported type is <code>ipsec.1</code>.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeCustomerGateways.</p>"
    },
    "DescribeCustomerGatewaysResult":{
      "type":"structure",
      "members":{
        "CustomerGateways":{
          "shape":"CustomerGatewayList",
          "documentation":"<p>Information about one or more customer gateways.</p>",
          "locationName":"customerGatewaySet"
        }
      },
      "documentation":"<p>Contains the output of DescribeCustomerGateways.</p>"
    },
    "DescribeDhcpOptionsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeDhcpOptionsRequest":{
      "type":"structure",
      "members":{
        "DhcpOptionsIds":{
          "shape":"DhcpOptionsIdStringList",
          "documentation":"<p>The IDs of one or more DHCP options sets.</p> <p>Default: Describes all your DHCP options sets.</p>",
          "locationName":"DhcpOptionsId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>dhcp-options-id</code> - The ID of a DHCP options set.</p> </li> <li> <p> <code>key</code> - The key for one of the options (for example, <code>domain-name</code>).</p> </li> <li> <p> <code>value</code> - The value for one of the options.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the DHCP options set.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeDhcpOptionsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeDhcpOptionsResult":{
      "type":"structure",
      "members":{
        "DhcpOptions":{
          "shape":"DhcpOptionsList",
          "documentation":"<p>Information about one or more DHCP options sets.</p>",
          "locationName":"dhcpOptionsSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeEgressOnlyInternetGatewaysMaxResults":{
      "type":"integer",
      "max":255,
      "min":5
    },
    "DescribeEgressOnlyInternetGatewaysRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "EgressOnlyInternetGatewayIds":{
          "shape":"EgressOnlyInternetGatewayIdList",
          "documentation":"<p>One or more egress-only internet gateway IDs.</p>",
          "locationName":"EgressOnlyInternetGatewayId"
        },
        "MaxResults":{
          "shape":"DescribeEgressOnlyInternetGatewaysMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeEgressOnlyInternetGatewaysResult":{
      "type":"structure",
      "members":{
        "EgressOnlyInternetGateways":{
          "shape":"EgressOnlyInternetGatewayList",
          "documentation":"<p>Information about the egress-only internet gateways.</p>",
          "locationName":"egressOnlyInternetGatewaySet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeElasticGpusMaxResults":{
      "type":"integer",
      "max":1000,
      "min":10
    },
    "DescribeElasticGpusRequest":{
      "type":"structure",
      "members":{
        "ElasticGpuIds":{
          "shape":"ElasticGpuIdSet",
          "documentation":"<p>The Elastic Graphics accelerator IDs.</p>",
          "locationName":"ElasticGpuId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone in which the Elastic Graphics accelerator resides.</p> </li> <li> <p> <code>elastic-gpu-health</code> - The status of the Elastic Graphics accelerator (<code>OK</code> | <code>IMPAIRED</code>).</p> </li> <li> <p> <code>elastic-gpu-state</code> - The state of the Elastic Graphics accelerator (<code>ATTACHED</code>).</p> </li> <li> <p> <code>elastic-gpu-type</code> - The type of Elastic Graphics accelerator; for example, <code>eg1.medium</code>.</p> </li> <li> <p> <code>instance-id</code> - The ID of the instance to which the Elastic Graphics accelerator is associated.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeElasticGpusMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value. This value can be between 5 and 1000.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of results.</p>"
        }
      }
    },
    "DescribeElasticGpusResult":{
      "type":"structure",
      "members":{
        "ElasticGpuSet":{
          "shape":"ElasticGpuSet",
          "documentation":"<p>Information about the Elastic Graphics accelerators.</p>",
          "locationName":"elasticGpuSet"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The total number of items to return. If the total number of items available is more than the value specified in max-items then a Next-Token will be provided in the output that you can use to resume pagination.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeExportImageTasksMaxResults":{
      "type":"integer",
      "max":500,
      "min":1
    },
    "DescribeExportImageTasksRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>Filter tasks using the <code>task-state</code> filter and one of the following values: <code>active</code>, <code>completed</code>, <code>deleting</code>, or <code>deleted</code>.</p>",
          "locationName":"Filter"
        },
        "ExportImageTaskIds":{
          "shape":"ExportImageTaskIdList",
          "documentation":"<p>The IDs of the export image tasks.</p>",
          "locationName":"ExportImageTaskId"
        },
        "MaxResults":{
          "shape":"DescribeExportImageTasksMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>A token that indicates the next page of results.</p>"
        }
      }
    },
    "DescribeExportImageTasksResult":{
      "type":"structure",
      "members":{
        "ExportImageTasks":{
          "shape":"ExportImageTaskList",
          "documentation":"<p>Information about the export image tasks.</p>",
          "locationName":"exportImageTaskSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to get the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeExportTasksRequest":{
      "type":"structure",
      "members":{
        "ExportTaskIds":{
          "shape":"ExportTaskIdStringList",
          "documentation":"<p>The export task IDs.</p>",
          "locationName":"exportTaskId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>the filters for the export tasks.</p>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeExportTasksResult":{
      "type":"structure",
      "members":{
        "ExportTasks":{
          "shape":"ExportTaskList",
          "documentation":"<p>Information about the export tasks.</p>",
          "locationName":"exportTaskSet"
        }
      }
    },
    "DescribeFastLaunchImagesRequest":{
      "type":"structure",
      "members":{
        "ImageIds":{
          "shape":"FastLaunchImageIdList",
          "documentation":"<p>Details for one or more Windows AMI image IDs.</p>",
          "locationName":"ImageId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>Use the following filters to streamline results.</p> <ul> <li> <p> <code>resource-type</code> - The resource type for pre-provisioning.</p> </li> <li> <p> <code>launch-template</code> - The launch template that is associated with the pre-provisioned Windows AMI.</p> </li> <li> <p> <code>owner-id</code> - The owner ID for the pre-provisioning resource.</p> </li> <li> <p> <code>state</code> - The current state of fast launching for the Windows AMI.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeFastLaunchImagesRequestMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another request with the returned NextToken value. If this parameter is not specified, then all results are returned.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next set of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeFastLaunchImagesRequestMaxResults":{
      "type":"integer",
      "max":200,
      "min":0
    },
    "DescribeFastLaunchImagesResult":{
      "type":"structure",
      "members":{
        "FastLaunchImages":{
          "shape":"DescribeFastLaunchImagesSuccessSet",
          "documentation":"<p>A collection of details about the fast-launch enabled Windows images that meet the requested criteria.</p>",
          "locationName":"fastLaunchImageSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use for the next set of results. This value is null when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeFastLaunchImagesSuccessItem":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The image ID that identifies the fast-launch enabled Windows image.</p>",
          "locationName":"imageId"
        },
        "ResourceType":{
          "shape":"FastLaunchResourceType",
          "documentation":"<p>The resource type that is used for pre-provisioning the Windows AMI. Supported values include: <code>snapshot</code>.</p>",
          "locationName":"resourceType"
        },
        "SnapshotConfiguration":{
          "shape":"FastLaunchSnapshotConfigurationResponse",
          "documentation":"<p>A group of parameters that are used for pre-provisioning the associated Windows AMI using snapshots.</p>",
          "locationName":"snapshotConfiguration"
        },
        "LaunchTemplate":{
          "shape":"FastLaunchLaunchTemplateSpecificationResponse",
          "documentation":"<p>The launch template that the fast-launch enabled Windows AMI uses when it launches Windows instances from pre-provisioned snapshots.</p>",
          "locationName":"launchTemplate"
        },
        "MaxParallelLaunches":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of parallel instances that are launched for creating resources.</p>",
          "locationName":"maxParallelLaunches"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The owner ID for the fast-launch enabled Windows AMI.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"FastLaunchStateCode",
          "documentation":"<p>The current state of faster launching for the specified Windows AMI.</p>",
          "locationName":"state"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason that faster launching for the Windows AMI changed to the current state.</p>",
          "locationName":"stateTransitionReason"
        },
        "StateTransitionTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time that faster launching for the Windows AMI changed to the current state.</p>",
          "locationName":"stateTransitionTime"
        }
      },
      "documentation":"<p>Describe details about a fast-launch enabled Windows image that meets the requested criteria. Criteria are defined by the <code>DescribeFastLaunchImages</code> action filters.</p>"
    },
    "DescribeFastLaunchImagesSuccessSet":{
      "type":"list",
      "member":{
        "shape":"DescribeFastLaunchImagesSuccessItem",
        "locationName":"item"
      }
    },
    "DescribeFastSnapshotRestoreSuccessItem":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "State":{
          "shape":"FastSnapshotRestoreStateCode",
          "documentation":"<p>The state of fast snapshot restores.</p>",
          "locationName":"state"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason for the state transition. The possible values are as follows:</p> <ul> <li> <p> <code>Client.UserInitiated</code> - The state successfully transitioned to <code>enabling</code> or <code>disabling</code>.</p> </li> <li> <p> <code>Client.UserInitiated - Lifecycle state transition</code> - The state successfully transitioned to <code>optimizing</code>, <code>enabled</code>, or <code>disabled</code>.</p> </li> </ul>",
          "locationName":"stateTransitionReason"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that enabled fast snapshot restores on the snapshot.</p>",
          "locationName":"ownerId"
        },
        "OwnerAlias":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services owner alias that enabled fast snapshot restores on the snapshot. This is intended for future use.</p>",
          "locationName":"ownerAlias"
        },
        "EnablingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>enabling</code> state.</p>",
          "locationName":"enablingTime"
        },
        "OptimizingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>optimizing</code> state.</p>",
          "locationName":"optimizingTime"
        },
        "EnabledTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>enabled</code> state.</p>",
          "locationName":"enabledTime"
        },
        "DisablingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>disabling</code> state.</p>",
          "locationName":"disablingTime"
        },
        "DisabledTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>disabled</code> state.</p>",
          "locationName":"disabledTime"
        }
      },
      "documentation":"<p>Describes fast snapshot restores for a snapshot.</p>"
    },
    "DescribeFastSnapshotRestoreSuccessSet":{
      "type":"list",
      "member":{
        "shape":"DescribeFastSnapshotRestoreSuccessItem",
        "locationName":"item"
      }
    },
    "DescribeFastSnapshotRestoresMaxResults":{
      "type":"integer",
      "max":200,
      "min":0
    },
    "DescribeFastSnapshotRestoresRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters. The possible values are:</p> <ul> <li> <p> <code>availability-zone</code>: The Availability Zone of the snapshot.</p> </li> <li> <p> <code>owner-id</code>: The ID of the Amazon Web Services account that enabled fast snapshot restore on the snapshot.</p> </li> <li> <p> <code>snapshot-id</code>: The ID of the snapshot.</p> </li> <li> <p> <code>state</code>: The state of fast snapshot restores for the snapshot (<code>enabling</code> | <code>optimizing</code> | <code>enabled</code> | <code>disabling</code> | <code>disabled</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeFastSnapshotRestoresMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeFastSnapshotRestoresResult":{
      "type":"structure",
      "members":{
        "FastSnapshotRestores":{
          "shape":"DescribeFastSnapshotRestoreSuccessSet",
          "documentation":"<p>Information about the state of fast snapshot restores.</p>",
          "locationName":"fastSnapshotRestoreSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeFleetError":{
      "type":"structure",
      "members":{
        "LaunchTemplateAndOverrides":{
          "shape":"LaunchTemplateAndOverridesResponse",
          "documentation":"<p>The launch templates and overrides that were used for launching the instances. The values that you specify in the Overrides replace the values in the launch template.</p>",
          "locationName":"launchTemplateAndOverrides"
        },
        "Lifecycle":{
          "shape":"InstanceLifecycle",
          "documentation":"<p>Indicates if the instance that could not be launched was a Spot Instance or On-Demand Instance.</p>",
          "locationName":"lifecycle"
        },
        "ErrorCode":{
          "shape":"String",
          "documentation":"<p>The error code that indicates why the instance could not be launched. For more information about error codes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html.html\">Error codes</a>.</p>",
          "locationName":"errorCode"
        },
        "ErrorMessage":{
          "shape":"String",
          "documentation":"<p>The error message that describes why the instance could not be launched. For more information about error messages, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html.html\">Error codes</a>.</p>",
          "locationName":"errorMessage"
        }
      },
      "documentation":"<p>Describes the instances that could not be launched by the fleet.</p>"
    },
    "DescribeFleetHistoryRequest":{
      "type":"structure",
      "required":[
        "FleetId",
        "StartTime"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "EventType":{
          "shape":"FleetEventType",
          "documentation":"<p>The type of events to describe. By default, all events are described.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The start date and time for the events, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>"
        }
      }
    },
    "DescribeFleetHistoryResult":{
      "type":"structure",
      "members":{
        "HistoryRecords":{
          "shape":"HistoryRecordSet",
          "documentation":"<p>Information about the events in the history of the EC2 Fleet.</p>",
          "locationName":"historyRecordSet"
        },
        "LastEvaluatedTime":{
          "shape":"DateTime",
          "documentation":"<p>The last date and time for the events, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). All records up to this time were retrieved.</p> <p>If <code>nextToken</code> indicates that there are more results, this value is not present.</p>",
          "locationName":"lastEvaluatedTime"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC Fleet.</p>",
          "locationName":"fleetId"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The start date and time for the events, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"startTime"
        }
      }
    },
    "DescribeFleetInstancesRequest":{
      "type":"structure",
      "required":["FleetId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>instance-type</code> - The instance type.</p> </li> </ul>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeFleetInstancesResult":{
      "type":"structure",
      "members":{
        "ActiveInstances":{
          "shape":"ActiveInstanceSet",
          "documentation":"<p>The running instances. This list is refreshed periodically and might be out of date.</p>",
          "locationName":"activeInstanceSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>",
          "locationName":"fleetId"
        }
      }
    },
    "DescribeFleetsErrorSet":{
      "type":"list",
      "member":{
        "shape":"DescribeFleetError",
        "locationName":"item"
      }
    },
    "DescribeFleetsInstances":{
      "type":"structure",
      "members":{
        "LaunchTemplateAndOverrides":{
          "shape":"LaunchTemplateAndOverridesResponse",
          "documentation":"<p>The launch templates and overrides that were used for launching the instances. The values that you specify in the Overrides replace the values in the launch template.</p>",
          "locationName":"launchTemplateAndOverrides"
        },
        "Lifecycle":{
          "shape":"InstanceLifecycle",
          "documentation":"<p>Indicates if the instance that was launched is a Spot Instance or On-Demand Instance.</p>",
          "locationName":"lifecycle"
        },
        "InstanceIds":{
          "shape":"InstanceIdsSet",
          "documentation":"<p>The IDs of the instances.</p>",
          "locationName":"instanceIds"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "Platform":{
          "shape":"PlatformValues",
          "documentation":"<p>The value is <code>Windows</code> for Windows instances. Otherwise, the value is blank.</p>",
          "locationName":"platform"
        }
      },
      "documentation":"<p>Describes the instances that were launched by the fleet.</p>"
    },
    "DescribeFleetsInstancesSet":{
      "type":"list",
      "member":{
        "shape":"DescribeFleetsInstances",
        "locationName":"item"
      }
    },
    "DescribeFleetsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        },
        "FleetIds":{
          "shape":"FleetIdSet",
          "documentation":"<p>The IDs of the EC2 Fleets.</p> <note> <p>If a fleet is of type <code>instant</code>, you must specify the fleet ID, otherwise it does not appear in the response.</p> </note>",
          "locationName":"FleetId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>activity-status</code> - The progress of the EC2 Fleet ( <code>error</code> | <code>pending-fulfillment</code> | <code>pending-termination</code> | <code>fulfilled</code>).</p> </li> <li> <p> <code>excess-capacity-termination-policy</code> - Indicates whether to terminate running instances if the target capacity is decreased below the current EC2 Fleet size (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>fleet-state</code> - The state of the EC2 Fleet (<code>submitted</code> | <code>active</code> | <code>deleted</code> | <code>failed</code> | <code>deleted-running</code> | <code>deleted-terminating</code> | <code>modifying</code>).</p> </li> <li> <p> <code>replace-unhealthy-instances</code> - Indicates whether EC2 Fleet should replace unhealthy instances (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>type</code> - The type of request (<code>instant</code> | <code>request</code> | <code>maintain</code>).</p> </li> </ul>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeFleetsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "Fleets":{
          "shape":"FleetSet",
          "documentation":"<p>Information about the EC2 Fleets.</p>",
          "locationName":"fleetSet"
        }
      }
    },
    "DescribeFlowLogsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filter":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>deliver-log-status</code> - The status of the logs delivery (<code>SUCCESS</code> | <code>FAILED</code>).</p> </li> <li> <p> <code>log-destination-type</code> - The type of destination for the flow log data (<code>cloud-watch-logs</code> | <code>s3</code> | <code>kinesis-data-firehose</code>).</p> </li> <li> <p> <code>flow-log-id</code> - The ID of the flow log.</p> </li> <li> <p> <code>log-group-name</code> - The name of the log group.</p> </li> <li> <p> <code>resource-id</code> - The ID of the VPC, subnet, or network interface.</p> </li> <li> <p> <code>traffic-type</code> - The type of traffic (<code>ACCEPT</code> | <code>REJECT</code> | <code>ALL</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>"
        },
        "FlowLogIds":{
          "shape":"FlowLogIdList",
          "documentation":"<p>One or more flow log IDs.</p> <p>Constraint: Maximum of 1000 flow log IDs.</p>",
          "locationName":"FlowLogId"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of items. Pagination continues from the end of the items returned by the previous request.</p>"
        }
      }
    },
    "DescribeFlowLogsResult":{
      "type":"structure",
      "members":{
        "FlowLogs":{
          "shape":"FlowLogSet",
          "documentation":"<p>Information about the flow logs.</p>",
          "locationName":"flowLogSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeFpgaImageAttributeRequest":{
      "type":"structure",
      "required":[
        "FpgaImageId",
        "Attribute"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FpgaImageId":{
          "shape":"FpgaImageId",
          "documentation":"<p>The ID of the AFI.</p>"
        },
        "Attribute":{
          "shape":"FpgaImageAttributeName",
          "documentation":"<p>The AFI attribute.</p>"
        }
      }
    },
    "DescribeFpgaImageAttributeResult":{
      "type":"structure",
      "members":{
        "FpgaImageAttribute":{
          "shape":"FpgaImageAttribute",
          "documentation":"<p>Information about the attribute.</p>",
          "locationName":"fpgaImageAttribute"
        }
      }
    },
    "DescribeFpgaImagesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeFpgaImagesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FpgaImageIds":{
          "shape":"FpgaImageIdList",
          "documentation":"<p>The AFI IDs.</p>",
          "locationName":"FpgaImageId"
        },
        "Owners":{
          "shape":"OwnerStringList",
          "documentation":"<p>Filters the AFI by owner. Specify an Amazon Web Services account ID, <code>self</code> (owner is the sender of the request), or an Amazon Web Services owner alias (valid values are <code>amazon</code> | <code>aws-marketplace</code>).</p>",
          "locationName":"Owner"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>create-time</code> - The creation time of the AFI.</p> </li> <li> <p> <code>fpga-image-id</code> - The FPGA image identifier (AFI ID).</p> </li> <li> <p> <code>fpga-image-global-id</code> - The global FPGA image identifier (AGFI ID).</p> </li> <li> <p> <code>name</code> - The name of the AFI.</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the AFI owner.</p> </li> <li> <p> <code>product-code</code> - The product code.</p> </li> <li> <p> <code>shell-version</code> - The version of the Amazon Web Services Shell that was used to create the bitstream.</p> </li> <li> <p> <code>state</code> - The state of the AFI (<code>pending</code> | <code>failed</code> | <code>available</code> | <code>unavailable</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>update-time</code> - The time of the most recent update.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeFpgaImagesMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call.</p>"
        }
      }
    },
    "DescribeFpgaImagesResult":{
      "type":"structure",
      "members":{
        "FpgaImages":{
          "shape":"FpgaImageList",
          "documentation":"<p>Information about the FPGA images.</p>",
          "locationName":"fpgaImageSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeHostReservationOfferingsRequest":{
      "type":"structure",
      "members":{
        "Filter":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>instance-family</code> - The instance family of the offering (for example, <code>m4</code>).</p> </li> <li> <p> <code>payment-option</code> - The payment option (<code>NoUpfront</code> | <code>PartialUpfront</code> | <code>AllUpfront</code>).</p> </li> </ul>"
        },
        "MaxDuration":{
          "shape":"Integer",
          "documentation":"<p>This is the maximum duration of the reservation to purchase, specified in seconds. Reservations are available in one-year and three-year terms. The number of seconds specified must be the number of seconds in a year (365x24x60x60) times one of the supported durations (1 or 3). For example, specify 94608000 for three years.</p>"
        },
        "MaxResults":{
          "shape":"DescribeHostReservationsMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p>"
        },
        "MinDuration":{
          "shape":"Integer",
          "documentation":"<p>This is the minimum duration of the reservation you'd like to purchase, specified in seconds. Reservations are available in one-year and three-year terms. The number of seconds specified must be the number of seconds in a year (365x24x60x60) times one of the supported durations (1 or 3). For example, specify 31536000 for one year.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>"
        },
        "OfferingId":{
          "shape":"OfferingId",
          "documentation":"<p>The ID of the reservation offering.</p>"
        }
      }
    },
    "DescribeHostReservationOfferingsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "OfferingSet":{
          "shape":"HostOfferingSet",
          "documentation":"<p>Information about the offerings.</p>",
          "locationName":"offeringSet"
        }
      }
    },
    "DescribeHostReservationsMaxResults":{
      "type":"integer",
      "max":500,
      "min":5
    },
    "DescribeHostReservationsRequest":{
      "type":"structure",
      "members":{
        "Filter":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>instance-family</code> - The instance family (for example, <code>m4</code>).</p> </li> <li> <p> <code>payment-option</code> - The payment option (<code>NoUpfront</code> | <code>PartialUpfront</code> | <code>AllUpfront</code>).</p> </li> <li> <p> <code>state</code> - The state of the reservation (<code>payment-pending</code> | <code>payment-failed</code> | <code>active</code> | <code>retired</code>).</p> </li> <li> <p> <code>tag:<key></code> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>"
        },
        "HostReservationIdSet":{
          "shape":"HostReservationIdSet",
          "documentation":"<p>The host reservation IDs.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>"
        }
      }
    },
    "DescribeHostReservationsResult":{
      "type":"structure",
      "members":{
        "HostReservationSet":{
          "shape":"HostReservationSet",
          "documentation":"<p>Details about the reservation's configuration.</p>",
          "locationName":"hostReservationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeHostsRequest":{
      "type":"structure",
      "members":{
        "Filter":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>auto-placement</code> - Whether auto-placement is enabled or disabled (<code>on</code> | <code>off</code>).</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone of the host.</p> </li> <li> <p> <code>client-token</code> - The idempotency token that you provided when you allocated the host.</p> </li> <li> <p> <code>host-reservation-id</code> - The ID of the reservation assigned to this host.</p> </li> <li> <p> <code>instance-type</code> - The instance type size that the Dedicated Host is configured to support.</p> </li> <li> <p> <code>state</code> - The allocation state of the Dedicated Host (<code>available</code> | <code>under-assessment</code> | <code>permanent-failure</code> | <code>released</code> | <code>released-permanent-failure</code>).</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"filter"
        },
        "HostIds":{
          "shape":"RequestHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts. The IDs are used for targeted instance launches.</p>",
          "locationName":"hostId"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p> <p>You cannot specify this parameter and the host IDs parameter in the same request.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeHostsResult":{
      "type":"structure",
      "members":{
        "Hosts":{
          "shape":"HostList",
          "documentation":"<p>Information about the Dedicated Hosts.</p>",
          "locationName":"hostSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeIamInstanceProfileAssociationsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeIamInstanceProfileAssociationsRequest":{
      "type":"structure",
      "members":{
        "AssociationIds":{
          "shape":"AssociationIdList",
          "documentation":"<p>The IAM instance profile associations.</p>",
          "locationName":"AssociationId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>instance-id</code> - The ID of the instance.</p> </li> <li> <p> <code>state</code> - The state of the association (<code>associating</code> | <code>associated</code> | <code>disassociating</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeIamInstanceProfileAssociationsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        }
      }
    },
    "DescribeIamInstanceProfileAssociationsResult":{
      "type":"structure",
      "members":{
        "IamInstanceProfileAssociations":{
          "shape":"IamInstanceProfileAssociationSet",
          "documentation":"<p>Information about the IAM instance profile associations.</p>",
          "locationName":"iamInstanceProfileAssociationSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeIdFormatRequest":{
      "type":"structure",
      "members":{
        "Resource":{
          "shape":"String",
          "documentation":"<p>The type of resource: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code> </p>"
        }
      }
    },
    "DescribeIdFormatResult":{
      "type":"structure",
      "members":{
        "Statuses":{
          "shape":"IdFormatList",
          "documentation":"<p>Information about the ID format for the resource.</p>",
          "locationName":"statusSet"
        }
      }
    },
    "DescribeIdentityIdFormatRequest":{
      "type":"structure",
      "required":["PrincipalArn"],
      "members":{
        "PrincipalArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the principal, which can be an IAM role, IAM user, or the root user.</p>",
          "locationName":"principalArn"
        },
        "Resource":{
          "shape":"String",
          "documentation":"<p>The type of resource: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code> </p>",
          "locationName":"resource"
        }
      }
    },
    "DescribeIdentityIdFormatResult":{
      "type":"structure",
      "members":{
        "Statuses":{
          "shape":"IdFormatList",
          "documentation":"<p>Information about the ID format for the resources.</p>",
          "locationName":"statusSet"
        }
      }
    },
    "DescribeImageAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "ImageId"
      ],
      "members":{
        "Attribute":{
          "shape":"ImageAttributeName",
          "documentation":"<p>The AMI attribute.</p> <p> <b>Note</b>: The <code>blockDeviceMapping</code> attribute is deprecated. Using this attribute returns the <code>Client.AuthFailure</code> error. To get information about the block device mappings for an AMI, use the <a>DescribeImages</a> action.</p>"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeImageAttribute.</p>"
    },
    "DescribeImagesRequest":{
      "type":"structure",
      "members":{
        "ExecutableUsers":{
          "shape":"ExecutableByStringList",
          "documentation":"<p>Scopes the images by users with explicit launch permissions. Specify an Amazon Web Services account ID, <code>self</code> (the sender of the request), or <code>all</code> (public AMIs).</p> <ul> <li> <p>If you specify an Amazon Web Services account ID that is not your own, only AMIs shared with that specific Amazon Web Services account ID are returned. However, AMIs that are shared with the account’s organization or organizational unit (OU) are not returned.</p> </li> <li> <p>If you specify <code>self</code> or your own Amazon Web Services account ID, AMIs shared with your account are returned. In addition, AMIs that are shared with the organization or OU of which you are member are also returned. </p> </li> <li> <p>If you specify <code>all</code>, all public AMIs are returned.</p> </li> </ul>",
          "locationName":"ExecutableBy"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>architecture</code> - The image architecture (<code>i386</code> | <code>x86_64</code> | <code>arm64</code>).</p> </li> <li> <p> <code>block-device-mapping.delete-on-termination</code> - A Boolean value that indicates whether the Amazon EBS volume is deleted on instance termination.</p> </li> <li> <p> <code>block-device-mapping.device-name</code> - The device name specified in the block device mapping (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p> </li> <li> <p> <code>block-device-mapping.snapshot-id</code> - The ID of the snapshot used for the Amazon EBS volume.</p> </li> <li> <p> <code>block-device-mapping.volume-size</code> - The volume size of the Amazon EBS volume, in GiB.</p> </li> <li> <p> <code>block-device-mapping.volume-type</code> - The volume type of the Amazon EBS volume (<code>io1</code> | <code>io2</code> | <code>gp2</code> | <code>gp3</code> | <code>sc1 </code>| <code>st1</code> | <code>standard</code>).</p> </li> <li> <p> <code>block-device-mapping.encrypted</code> - A Boolean that indicates whether the Amazon EBS volume is encrypted.</p> </li> <li> <p> <code>creation-date</code> - The time when the image was created, in the ISO 8601 format in the UTC time zone (YYYY-MM-DDThh:mm:ss.sssZ), for example, <code>2021-09-29T11:04:43.305Z</code>. You can use a wildcard (<code>*</code>), for example, <code>2021-09-29T*</code>, which matches an entire day.</p> </li> <li> <p> <code>description</code> - The description of the image (provided during image creation).</p> </li> <li> <p> <code>ena-support</code> - A Boolean that indicates whether enhanced networking with ENA is enabled.</p> </li> <li> <p> <code>hypervisor</code> - The hypervisor type (<code>ovm</code> | <code>xen</code>).</p> </li> <li> <p> <code>image-id</code> - The ID of the image.</p> </li> <li> <p> <code>image-type</code> - The image type (<code>machine</code> | <code>kernel</code> | <code>ramdisk</code>).</p> </li> <li> <p> <code>is-public</code> - A Boolean that indicates whether the image is public.</p> </li> <li> <p> <code>kernel-id</code> - The kernel ID.</p> </li> <li> <p> <code>manifest-location</code> - The location of the image manifest.</p> </li> <li> <p> <code>name</code> - The name of the AMI (provided during image creation).</p> </li> <li> <p> <code>owner-alias</code> - The owner alias (<code>amazon</code> | <code>aws-marketplace</code>). The valid aliases are defined in an Amazon-maintained list. This is not the Amazon Web Services account alias that can be set using the IAM console. We recommend that you use the <b>Owner</b> request parameter instead of this filter.</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the owner. We recommend that you use the <b>Owner</b> request parameter instead of this filter.</p> </li> <li> <p> <code>platform</code> - The platform. The only supported value is <code>windows</code>.</p> </li> <li> <p> <code>product-code</code> - The product code.</p> </li> <li> <p> <code>product-code.type</code> - The type of the product code (<code>marketplace</code>).</p> </li> <li> <p> <code>ramdisk-id</code> - The RAM disk ID.</p> </li> <li> <p> <code>root-device-name</code> - The device name of the root device volume (for example, <code>/dev/sda1</code>).</p> </li> <li> <p> <code>root-device-type</code> - The type of the root device volume (<code>ebs</code> | <code>instance-store</code>).</p> </li> <li> <p> <code>state</code> - The state of the image (<code>available</code> | <code>pending</code> | <code>failed</code>).</p> </li> <li> <p> <code>state-reason-code</code> - The reason code for the state change.</p> </li> <li> <p> <code>state-reason-message</code> - The message for the state change.</p> </li> <li> <p> <code>sriov-net-support</code> - A value of <code>simple</code> indicates that enhanced networking with the Intel 82599 VF interface is enabled.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>virtualization-type</code> - The virtualization type (<code>paravirtual</code> | <code>hvm</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "ImageIds":{
          "shape":"ImageIdStringList",
          "documentation":"<p>The image IDs.</p> <p>Default: Describes all images available to you.</p>",
          "locationName":"ImageId"
        },
        "Owners":{
          "shape":"OwnerStringList",
          "documentation":"<p>Scopes the results to images with the specified owners. You can specify a combination of Amazon Web Services account IDs, <code>self</code>, <code>amazon</code>, and <code>aws-marketplace</code>. If you omit this parameter, the results include all images for which you have launch permissions, regardless of ownership.</p>",
          "locationName":"Owner"
        },
        "IncludeDeprecated":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether to include deprecated AMIs.</p> <p>Default: No deprecated AMIs are included in the response.</p> <note> <p>If you are the AMI owner, all deprecated AMIs appear in the response regardless of what you specify for this parameter.</p> </note>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeImagesResult":{
      "type":"structure",
      "members":{
        "Images":{
          "shape":"ImageList",
          "documentation":"<p>Information about the images.</p>",
          "locationName":"imagesSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeImportImageTasksRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>Filter tasks using the <code>task-state</code> filter and one of the following values: <code>active</code>, <code>completed</code>, <code>deleting</code>, or <code>deleted</code>.</p>"
        },
        "ImportTaskIds":{
          "shape":"ImportTaskIdList",
          "documentation":"<p>The IDs of the import image tasks.</p>",
          "locationName":"ImportTaskId"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>A token that indicates the next page of results.</p>"
        }
      }
    },
    "DescribeImportImageTasksResult":{
      "type":"structure",
      "members":{
        "ImportImageTasks":{
          "shape":"ImportImageTaskList",
          "documentation":"<p>A list of zero or more import image tasks that are currently active or were completed or canceled in the previous 7 days.</p>",
          "locationName":"importImageTaskSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to get the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeImportSnapshotTasksRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p>"
        },
        "ImportTaskIds":{
          "shape":"ImportSnapshotTaskIdList",
          "documentation":"<p>A list of import snapshot task IDs.</p>",
          "locationName":"ImportTaskId"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>A token that indicates the next page of results.</p>"
        }
      }
    },
    "DescribeImportSnapshotTasksResult":{
      "type":"structure",
      "members":{
        "ImportSnapshotTasks":{
          "shape":"ImportSnapshotTaskList",
          "documentation":"<p>A list of zero or more import snapshot tasks that are currently active or were completed or canceled in the previous 7 days.</p>",
          "locationName":"importSnapshotTaskSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to get the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstanceAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "InstanceId"
      ],
      "members":{
        "Attribute":{
          "shape":"InstanceAttributeName",
          "documentation":"<p>The instance attribute.</p> <p>Note: The <code>enaSupport</code> attribute is not supported at this time.</p>",
          "locationName":"attribute"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        }
      }
    },
    "DescribeInstanceCreditSpecificationsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeInstanceCreditSpecificationsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>instance-id</code> - The ID of the instance.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The instance IDs.</p> <p>Default: Describes all your instances.</p> <p>Constraints: Maximum 1000 explicitly specified instance IDs.</p>",
          "locationName":"InstanceId"
        },
        "MaxResults":{
          "shape":"DescribeInstanceCreditSpecificationsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. This value can be between 5 and 1000. You cannot specify this parameter and the instance IDs parameter in the same call. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        }
      }
    },
    "DescribeInstanceCreditSpecificationsResult":{
      "type":"structure",
      "members":{
        "InstanceCreditSpecifications":{
          "shape":"InstanceCreditSpecificationList",
          "documentation":"<p>Information about the credit option for CPU usage of an instance.</p>",
          "locationName":"instanceCreditSpecificationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstanceEventNotificationAttributesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeInstanceEventNotificationAttributesResult":{
      "type":"structure",
      "members":{
        "InstanceTagAttribute":{
          "shape":"InstanceTagNotificationAttribute",
          "documentation":"<p>Information about the registered tag keys.</p>",
          "locationName":"instanceTagAttribute"
        }
      }
    },
    "DescribeInstanceEventWindowsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceEventWindowIds":{
          "shape":"InstanceEventWindowIdSet",
          "documentation":"<p>The IDs of the event windows.</p>",
          "locationName":"InstanceEventWindowId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>dedicated-host-id</code> - The event windows associated with the specified Dedicated Host ID.</p> </li> <li> <p> <code>event-window-name</code> - The event windows associated with the specified names. </p> </li> <li> <p> <code>instance-id</code> - The event windows associated with the specified instance ID.</p> </li> <li> <p> <code>instance-tag</code> - The event windows associated with the specified tag and value.</p> </li> <li> <p> <code>instance-tag-key</code> - The event windows associated with the specified tag key, regardless of the value.</p> </li> <li> <p> <code>instance-tag-value</code> - The event windows associated with the specified tag value, regardless of the key.</p> </li> <li> <p> <code>tag:<key></code> - The key/value combination of a tag assigned to the event window. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>CMX</code>, specify <code>tag:Owner</code> for the filter name and <code>CMX</code> for the filter value. </p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the event window. Use this filter to find all event windows that have a tag with a specific key, regardless of the tag value. </p> </li> <li> <p> <code>tag-value</code> - The value of a tag assigned to the event window. Use this filter to find all event windows that have a tag with a specific value, regardless of the tag key. </p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"ResultRange",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value. This value can be between 20 and 500. You cannot specify this parameter and the event window IDs parameter in the same call.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of results.</p>"
        }
      },
      "documentation":"<para>Describe instance event windows by InstanceEventWindow.</para>"
    },
    "DescribeInstanceEventWindowsResult":{
      "type":"structure",
      "members":{
        "InstanceEventWindows":{
          "shape":"InstanceEventWindowSet",
          "documentation":"<p>Information about the event windows.</p>",
          "locationName":"instanceEventWindowSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return. </p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstanceStatusRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone of the instance.</p> </li> <li> <p> <code>event.code</code> - The code for the scheduled event (<code>instance-reboot</code> | <code>system-reboot</code> | <code>system-maintenance</code> | <code>instance-retirement</code> | <code>instance-stop</code>).</p> </li> <li> <p> <code>event.description</code> - A description of the event.</p> </li> <li> <p> <code>event.instance-event-id</code> - The ID of the event whose date and time you are modifying.</p> </li> <li> <p> <code>event.not-after</code> - The latest end time for the scheduled event (for example, <code>2014-09-15T17:15:20.000Z</code>).</p> </li> <li> <p> <code>event.not-before</code> - The earliest start time for the scheduled event (for example, <code>2014-09-15T17:15:20.000Z</code>).</p> </li> <li> <p> <code>event.not-before-deadline</code> - The deadline for starting the event (for example, <code>2014-09-15T17:15:20.000Z</code>).</p> </li> <li> <p> <code>instance-state-code</code> - The code for the instance state, as a 16-bit unsigned integer. The high byte is used for internal purposes and should be ignored. The low byte is set based on the state represented. The valid values are 0 (pending), 16 (running), 32 (shutting-down), 48 (terminated), 64 (stopping), and 80 (stopped).</p> </li> <li> <p> <code>instance-state-name</code> - The state of the instance (<code>pending</code> | <code>running</code> | <code>shutting-down</code> | <code>terminated</code> | <code>stopping</code> | <code>stopped</code>).</p> </li> <li> <p> <code>instance-status.reachability</code> - Filters on instance status where the name is <code>reachability</code> (<code>passed</code> | <code>failed</code> | <code>initializing</code> | <code>insufficient-data</code>).</p> </li> <li> <p> <code>instance-status.status</code> - The status of the instance (<code>ok</code> | <code>impaired</code> | <code>initializing</code> | <code>insufficient-data</code> | <code>not-applicable</code>).</p> </li> <li> <p> <code>system-status.reachability</code> - Filters on system status where the name is <code>reachability</code> (<code>passed</code> | <code>failed</code> | <code>initializing</code> | <code>insufficient-data</code>).</p> </li> <li> <p> <code>system-status.status</code> - The system status of the instance (<code>ok</code> | <code>impaired</code> | <code>initializing</code> | <code>insufficient-data</code> | <code>not-applicable</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The instance IDs.</p> <p>Default: Describes all your instances.</p> <p>Constraints: Maximum 100 explicitly specified instance IDs.</p>",
          "locationName":"InstanceId"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. To retrieve the next page of items, make another request with the token returned in the output. This value can be between 5 and 1000. You cannot specify this parameter and the instance IDs parameter in the same call. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "IncludeAllInstances":{
          "shape":"Boolean",
          "documentation":"<p>When <code>true</code>, includes the health status for all instances. When <code>false</code>, includes the health status for running instances only.</p> <p>Default: <code>false</code> </p>",
          "locationName":"includeAllInstances"
        }
      }
    },
    "DescribeInstanceStatusResult":{
      "type":"structure",
      "members":{
        "InstanceStatuses":{
          "shape":"InstanceStatusList",
          "documentation":"<p>Information about the status of the instances.</p>",
          "locationName":"instanceStatusSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstanceTypeOfferingsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "LocationType":{
          "shape":"LocationType",
          "documentation":"<p>The location type.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>location</code> - This depends on the location type. For example, if the location type is <code>region</code> (default), the location is the Region code (for example, <code>us-east-2</code>.)</p> </li> <li> <p> <code>instance-type</code> - The instance type. For example, <code>c5.2xlarge</code>.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DITOMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        }
      }
    },
    "DescribeInstanceTypeOfferingsResult":{
      "type":"structure",
      "members":{
        "InstanceTypeOfferings":{
          "shape":"InstanceTypeOfferingsList",
          "documentation":"<p>The instance types offered.</p>",
          "locationName":"instanceTypeOfferingSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstanceTypesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceTypes":{
          "shape":"RequestInstanceTypeList",
          "documentation":"<p>The instance types. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"InstanceType"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p> <ul> <li> <p> <code>auto-recovery-supported</code> - Indicates whether auto recovery is supported (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>bare-metal</code> - Indicates whether it is a bare metal instance type (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>burstable-performance-supported</code> - Indicates whether it is a burstable performance instance type (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>current-generation</code> - Indicates whether this instance type is the latest generation instance type of an instance family (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>ebs-info.ebs-optimized-info.baseline-bandwidth-in-mbps</code> - The baseline bandwidth performance for an EBS-optimized instance type, in Mbps.</p> </li> <li> <p> <code>ebs-info.ebs-optimized-info.baseline-iops</code> - The baseline input/output storage operations per second for an EBS-optimized instance type.</p> </li> <li> <p> <code>ebs-info.ebs-optimized-info.baseline-throughput-in-mbps</code> - The baseline throughput performance for an EBS-optimized instance type, in MB/s.</p> </li> <li> <p> <code>ebs-info.ebs-optimized-info.maximum-bandwidth-in-mbps</code> - The maximum bandwidth performance for an EBS-optimized instance type, in Mbps.</p> </li> <li> <p> <code>ebs-info.ebs-optimized-info.maximum-iops</code> - The maximum input/output storage operations per second for an EBS-optimized instance type.</p> </li> <li> <p> <code>ebs-info.ebs-optimized-info.maximum-throughput-in-mbps</code> - The maximum throughput performance for an EBS-optimized instance type, in MB/s.</p> </li> <li> <p> <code>ebs-info.ebs-optimized-support</code> - Indicates whether the instance type is EBS-optimized (<code>supported</code> | <code>unsupported</code> | <code>default</code>).</p> </li> <li> <p> <code>ebs-info.encryption-support</code> - Indicates whether EBS encryption is supported (<code>supported</code> | <code>unsupported</code>).</p> </li> <li> <p> <code>ebs-info.nvme-support</code> - Indicates whether non-volatile memory express (NVMe) is supported for EBS volumes (<code>required</code> | <code>supported</code> | <code>unsupported</code>).</p> </li> <li> <p> <code>free-tier-eligible</code> - Indicates whether the instance type is eligible to use in the free tier (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>hibernation-supported</code> - Indicates whether On-Demand hibernation is supported (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>hypervisor</code> - The hypervisor (<code>nitro</code> | <code>xen</code>).</p> </li> <li> <p> <code>instance-storage-info.disk.count</code> - The number of local disks.</p> </li> <li> <p> <code>instance-storage-info.disk.size-in-gb</code> - The storage size of each instance storage disk, in GB.</p> </li> <li> <p> <code>instance-storage-info.disk.type</code> - The storage technology for the local instance storage disks (<code>hdd</code> | <code>ssd</code>).</p> </li> <li> <p> <code>instance-storage-info.encryption-support</code> - Indicates whether data is encrypted at rest (<code>required</code> | <code>supported</code> | <code>unsupported</code>).</p> </li> <li> <p> <code>instance-storage-info.nvme-support</code> - Indicates whether non-volatile memory express (NVMe) is supported for instance store (<code>required</code> | <code>supported</code> | <code>unsupported</code>).</p> </li> <li> <p> <code>instance-storage-info.total-size-in-gb</code> - The total amount of storage available from all local instance storage, in GB.</p> </li> <li> <p> <code>instance-storage-supported</code> - Indicates whether the instance type has local instance storage (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>instance-type</code> - The instance type (for example <code>c5.2xlarge</code> or c5*).</p> </li> <li> <p> <code>memory-info.size-in-mib</code> - The memory size.</p> </li> <li> <p> <code>network-info.efa-info.maximum-efa-interfaces</code> - The maximum number of Elastic Fabric Adapters (EFAs) per instance.</p> </li> <li> <p> <code>network-info.efa-supported</code> - Indicates whether the instance type supports Elastic Fabric Adapter (EFA) (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>network-info.ena-support</code> - Indicates whether Elastic Network Adapter (ENA) is supported or required (<code>required</code> | <code>supported</code> | <code>unsupported</code>).</p> </li> <li> <p> <code>network-info.encryption-in-transit-supported</code> - Indicates whether the instance type automatically encrypts in-transit traffic between instances (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>network-info.ipv4-addresses-per-interface</code> - The maximum number of private IPv4 addresses per network interface.</p> </li> <li> <p> <code>network-info.ipv6-addresses-per-interface</code> - The maximum number of private IPv6 addresses per network interface.</p> </li> <li> <p> <code>network-info.ipv6-supported</code> - Indicates whether the instance type supports IPv6 (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>network-info.maximum-network-cards</code> - The maximum number of network cards per instance.</p> </li> <li> <p> <code>network-info.maximum-network-interfaces</code> - The maximum number of network interfaces per instance.</p> </li> <li> <p> <code>network-info.network-performance</code> - The network performance (for example, \"25 Gigabit\").</p> </li> <li> <p> <code>processor-info.supported-architecture</code> - The CPU architecture (<code>arm64</code> | <code>i386</code> | <code>x86_64</code>).</p> </li> <li> <p> <code>processor-info.sustained-clock-speed-in-ghz</code> - The CPU clock speed, in GHz.</p> </li> <li> <p> <code>supported-boot-mode</code> - The boot mode (<code>legacy-bios</code> | <code>uefi</code>).</p> </li> <li> <p> <code>supported-root-device-type</code> - The root device type (<code>ebs</code> | <code>instance-store</code>).</p> </li> <li> <p> <code>supported-usage-class</code> - The usage class (<code>on-demand</code> | <code>spot</code>).</p> </li> <li> <p> <code>supported-virtualization-type</code> - The virtualization type (<code>hvm</code> | <code>paravirtual</code>).</p> </li> <li> <p> <code>vcpu-info.default-cores</code> - The default number of cores for the instance type.</p> </li> <li> <p> <code>vcpu-info.default-threads-per-core</code> - The default number of threads per core for the instance type.</p> </li> <li> <p> <code>vcpu-info.default-vcpus</code> - The default number of vCPUs for the instance type.</p> </li> <li> <p> <code>vcpu-info.valid-cores</code> - The number of cores that can be configured for the instance type.</p> </li> <li> <p> <code>vcpu-info.valid-threads-per-core</code> - The number of threads per core that can be configured for the instance type. For example, \"1\" or \"1,2\".</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DITMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        }
      }
    },
    "DescribeInstanceTypesResult":{
      "type":"structure",
      "members":{
        "InstanceTypes":{
          "shape":"InstanceTypeInfoList",
          "documentation":"<p>The instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"instanceTypeSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstancesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>affinity</code> - The affinity setting for an instance running on a Dedicated Host (<code>default</code> | <code>host</code>).</p> </li> <li> <p> <code>architecture</code> - The instance architecture (<code>i386</code> | <code>x86_64</code> | <code>arm64</code>).</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone of the instance.</p> </li> <li> <p> <code>block-device-mapping.attach-time</code> - The attach time for an EBS volume mapped to the instance, for example, <code>2010-09-15T17:15:20.000Z</code>.</p> </li> <li> <p> <code>block-device-mapping.delete-on-termination</code> - A Boolean that indicates whether the EBS volume is deleted on instance termination.</p> </li> <li> <p> <code>block-device-mapping.device-name</code> - The device name specified in the block device mapping (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p> </li> <li> <p> <code>block-device-mapping.status</code> - The status for the EBS volume (<code>attaching</code> | <code>attached</code> | <code>detaching</code> | <code>detached</code>).</p> </li> <li> <p> <code>block-device-mapping.volume-id</code> - The volume ID of the EBS volume.</p> </li> <li> <p> <code>capacity-reservation-id</code> - The ID of the Capacity Reservation into which the instance was launched.</p> </li> <li> <p> <code>client-token</code> - The idempotency token you provided when you launched the instance.</p> </li> <li> <p> <code>dns-name</code> - The public DNS name of the instance.</p> </li> <li> <p> <code>group-id</code> - The ID of the security group for the instance. EC2-Classic only.</p> </li> <li> <p> <code>group-name</code> - The name of the security group for the instance. EC2-Classic only.</p> </li> <li> <p> <code>hibernation-options.configured</code> - A Boolean that indicates whether the instance is enabled for hibernation. A value of <code>true</code> means that the instance is enabled for hibernation. </p> </li> <li> <p> <code>host-id</code> - The ID of the Dedicated Host on which the instance is running, if applicable.</p> </li> <li> <p> <code>hypervisor</code> - The hypervisor type of the instance (<code>ovm</code> | <code>xen</code>). The value <code>xen</code> is used for both Xen and Nitro hypervisors.</p> </li> <li> <p> <code>iam-instance-profile.arn</code> - The instance profile associated with the instance. Specified as an ARN.</p> </li> <li> <p> <code>image-id</code> - The ID of the image used to launch the instance.</p> </li> <li> <p> <code>instance-id</code> - The ID of the instance.</p> </li> <li> <p> <code>instance-lifecycle</code> - Indicates whether this is a Spot Instance or a Scheduled Instance (<code>spot</code> | <code>scheduled</code>).</p> </li> <li> <p> <code>instance-state-code</code> - The state of the instance, as a 16-bit unsigned integer. The high byte is used for internal purposes and should be ignored. The low byte is set based on the state represented. The valid values are: 0 (pending), 16 (running), 32 (shutting-down), 48 (terminated), 64 (stopping), and 80 (stopped).</p> </li> <li> <p> <code>instance-state-name</code> - The state of the instance (<code>pending</code> | <code>running</code> | <code>shutting-down</code> | <code>terminated</code> | <code>stopping</code> | <code>stopped</code>).</p> </li> <li> <p> <code>instance-type</code> - The type of instance (for example, <code>t2.micro</code>).</p> </li> <li> <p> <code>instance.group-id</code> - The ID of the security group for the instance. </p> </li> <li> <p> <code>instance.group-name</code> - The name of the security group for the instance. </p> </li> <li> <p> <code>ip-address</code> - The public IPv4 address of the instance.</p> </li> <li> <p> <code>kernel-id</code> - The kernel ID.</p> </li> <li> <p> <code>key-name</code> - The name of the key pair used when the instance was launched.</p> </li> <li> <p> <code>launch-index</code> - When launching multiple instances, this is the index for the instance in the launch group (for example, 0, 1, 2, and so on). </p> </li> <li> <p> <code>launch-time</code> - The time when the instance was launched, in the ISO 8601 format in the UTC time zone (YYYY-MM-DDThh:mm:ss.sssZ), for example, <code>2021-09-29T11:04:43.305Z</code>. You can use a wildcard (<code>*</code>), for example, <code>2021-09-29T*</code>, which matches an entire day.</p> </li> <li> <p> <code>metadata-options.http-tokens</code> - The metadata request authorization state (<code>optional</code> | <code>required</code>)</p> </li> <li> <p> <code>metadata-options.http-put-response-hop-limit</code> - The HTTP metadata request put response hop limit (integer, possible values <code>1</code> to <code>64</code>)</p> </li> <li> <p> <code>metadata-options.http-endpoint</code> - The status of access to the HTTP metadata endpoint on your instance (<code>enabled</code> | <code>disabled</code>)</p> </li> <li> <p> <code>metadata-options.instance-metadata-tags</code> - The status of access to instance tags from the instance metadata (<code>enabled</code> | <code>disabled</code>)</p> </li> <li> <p> <code>monitoring-state</code> - Indicates whether detailed monitoring is enabled (<code>disabled</code> | <code>enabled</code>).</p> </li> <li> <p> <code>network-interface.addresses.private-ip-address</code> - The private IPv4 address associated with the network interface.</p> </li> <li> <p> <code>network-interface.addresses.primary</code> - Specifies whether the IPv4 address of the network interface is the primary private IPv4 address.</p> </li> <li> <p> <code>network-interface.addresses.association.public-ip</code> - The ID of the association of an Elastic IP address (IPv4) with a network interface.</p> </li> <li> <p> <code>network-interface.addresses.association.ip-owner-id</code> - The owner ID of the private IPv4 address associated with the network interface.</p> </li> <li> <p> <code>network-interface.association.public-ip</code> - The address of the Elastic IP address (IPv4) bound to the network interface.</p> </li> <li> <p> <code>network-interface.association.ip-owner-id</code> - The owner of the Elastic IP address (IPv4) associated with the network interface.</p> </li> <li> <p> <code>network-interface.association.allocation-id</code> - The allocation ID returned when you allocated the Elastic IP address (IPv4) for your network interface.</p> </li> <li> <p> <code>network-interface.association.association-id</code> - The association ID returned when the network interface was associated with an IPv4 address.</p> </li> <li> <p> <code>network-interface.attachment.attachment-id</code> - The ID of the interface attachment.</p> </li> <li> <p> <code>network-interface.attachment.instance-id</code> - The ID of the instance to which the network interface is attached.</p> </li> <li> <p> <code>network-interface.attachment.instance-owner-id</code> - The owner ID of the instance to which the network interface is attached.</p> </li> <li> <p> <code>network-interface.attachment.device-index</code> - The device index to which the network interface is attached.</p> </li> <li> <p> <code>network-interface.attachment.status</code> - The status of the attachment (<code>attaching</code> | <code>attached</code> | <code>detaching</code> | <code>detached</code>).</p> </li> <li> <p> <code>network-interface.attachment.attach-time</code> - The time that the network interface was attached to an instance.</p> </li> <li> <p> <code>network-interface.attachment.delete-on-termination</code> - Specifies whether the attachment is deleted when an instance is terminated.</p> </li> <li> <p> <code>network-interface.availability-zone</code> - The Availability Zone for the network interface.</p> </li> <li> <p> <code>network-interface.description</code> - The description of the network interface.</p> </li> <li> <p> <code>network-interface.group-id</code> - The ID of a security group associated with the network interface.</p> </li> <li> <p> <code>network-interface.group-name</code> - The name of a security group associated with the network interface.</p> </li> <li> <p> <code>network-interface.ipv6-addresses.ipv6-address</code> - The IPv6 address associated with the network interface.</p> </li> <li> <p> <code>network-interface.mac-address</code> - The MAC address of the network interface.</p> </li> <li> <p> <code>network-interface.network-interface-id</code> - The ID of the network interface.</p> </li> <li> <p> <code>network-interface.owner-id</code> - The ID of the owner of the network interface.</p> </li> <li> <p> <code>network-interface.private-dns-name</code> - The private DNS name of the network interface.</p> </li> <li> <p> <code>network-interface.requester-id</code> - The requester ID for the network interface.</p> </li> <li> <p> <code>network-interface.requester-managed</code> - Indicates whether the network interface is being managed by Amazon Web Services.</p> </li> <li> <p> <code>network-interface.status</code> - The status of the network interface (<code>available</code>) | <code>in-use</code>).</p> </li> <li> <p> <code>network-interface.source-dest-check</code> - Whether the network interface performs source/destination checking. A value of <code>true</code> means that checking is enabled, and <code>false</code> means that checking is disabled. The value must be <code>false</code> for the network interface to perform network address translation (NAT) in your VPC.</p> </li> <li> <p> <code>network-interface.subnet-id</code> - The ID of the subnet for the network interface.</p> </li> <li> <p> <code>network-interface.vpc-id</code> - The ID of the VPC for the network interface.</p> </li> <li> <p> <code>outpost-arn</code> - The Amazon Resource Name (ARN) of the Outpost.</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the instance owner.</p> </li> <li> <p> <code>placement-group-name</code> - The name of the placement group for the instance.</p> </li> <li> <p> <code>placement-partition-number</code> - The partition in which the instance is located.</p> </li> <li> <p> <code>platform</code> - The platform. To list only Windows instances, use <code>windows</code>.</p> </li> <li> <p> <code>private-dns-name</code> - The private IPv4 DNS name of the instance.</p> </li> <li> <p> <code>private-ip-address</code> - The private IPv4 address of the instance.</p> </li> <li> <p> <code>product-code</code> - The product code associated with the AMI used to launch the instance.</p> </li> <li> <p> <code>product-code.type</code> - The type of product code (<code>devpay</code> | <code>marketplace</code>).</p> </li> <li> <p> <code>ramdisk-id</code> - The RAM disk ID.</p> </li> <li> <p> <code>reason</code> - The reason for the current state of the instance (for example, shows \"User Initiated [date]\" when you stop or terminate the instance). Similar to the state-reason-code filter.</p> </li> <li> <p> <code>requester-id</code> - The ID of the entity that launched the instance on your behalf (for example, Amazon Web Services Management Console, Auto Scaling, and so on).</p> </li> <li> <p> <code>reservation-id</code> - The ID of the instance's reservation. A reservation ID is created any time you launch an instance. A reservation ID has a one-to-one relationship with an instance launch request, but can be associated with more than one instance if you launch multiple instances using the same launch request. For example, if you launch one instance, you get one reservation ID. If you launch ten instances using the same launch request, you also get one reservation ID.</p> </li> <li> <p> <code>root-device-name</code> - The device name of the root device volume (for example, <code>/dev/sda1</code>).</p> </li> <li> <p> <code>root-device-type</code> - The type of the root device volume (<code>ebs</code> | <code>instance-store</code>).</p> </li> <li> <p> <code>source-dest-check</code> - Indicates whether the instance performs source/destination checking. A value of <code>true</code> means that checking is enabled, and <code>false</code> means that checking is disabled. The value must be <code>false</code> for the instance to perform network address translation (NAT) in your VPC. </p> </li> <li> <p> <code>spot-instance-request-id</code> - The ID of the Spot Instance request.</p> </li> <li> <p> <code>state-reason-code</code> - The reason code for the state change.</p> </li> <li> <p> <code>state-reason-message</code> - A message that describes the state change.</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet for the instance.</p> </li> <li> <p> <code>tag:<key></code> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources that have a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>tenancy</code> - The tenancy of an instance (<code>dedicated</code> | <code>default</code> | <code>host</code>).</p> </li> <li> <p> <code>virtualization-type</code> - The virtualization type of the instance (<code>paravirtual</code> | <code>hvm</code>).</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC that the instance is running in.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The instance IDs.</p> <p>Default: Describes all your instances.</p>",
          "locationName":"InstanceId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. This value can be between 5 and 1000. You cannot specify this parameter and the instance IDs parameter in the same request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInstancesResult":{
      "type":"structure",
      "members":{
        "Reservations":{
          "shape":"ReservationList",
          "documentation":"<p>Information about the reservations.</p>",
          "locationName":"reservationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeInternetGatewaysMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeInternetGatewaysRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>attachment.state</code> - The current state of the attachment between the gateway and the VPC (<code>available</code>). Present only if a VPC is attached.</p> </li> <li> <p> <code>attachment.vpc-id</code> - The ID of an attached VPC.</p> </li> <li> <p> <code>internet-gateway-id</code> - The ID of the Internet gateway.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the internet gateway.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InternetGatewayIds":{
          "shape":"InternetGatewayIdList",
          "documentation":"<p>One or more internet gateway IDs.</p> <p>Default: Describes all your internet gateways.</p>",
          "locationName":"internetGatewayId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeInternetGatewaysMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeInternetGatewaysResult":{
      "type":"structure",
      "members":{
        "InternetGateways":{
          "shape":"InternetGatewayList",
          "documentation":"<p>Information about one or more internet gateways.</p>",
          "locationName":"internetGatewaySet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeIpamPoolsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters for the request. For more information about filtering, see <a href=\"https://docs.aws.amazon.com/cli/latest/userguide/cli-usage-filter.html\">Filtering CLI output</a>.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of results to return in the request.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "IpamPoolIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the IPAM pools you would like information on.</p>",
          "locationName":"IpamPoolId"
        }
      }
    },
    "DescribeIpamPoolsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "IpamPools":{
          "shape":"IpamPoolSet",
          "documentation":"<p>Information about the IPAM pools.</p>",
          "locationName":"ipamPoolSet"
        }
      }
    },
    "DescribeIpamResourceDiscoveriesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IPAM resource discovery IDs.</p>",
          "locationName":"IpamResourceDiscoveryId"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of resource discoveries to return in one page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The resource discovery filters.</p>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeIpamResourceDiscoveriesResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscoveries":{
          "shape":"IpamResourceDiscoverySet",
          "documentation":"<p>The resource discoveries.</p>",
          "locationName":"ipamResourceDiscoverySet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeIpamResourceDiscoveryAssociationsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryAssociationIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The resource discovery association IDs.</p>",
          "locationName":"IpamResourceDiscoveryAssociationId"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of resource discovery associations to return in one page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The resource discovery association filters.</p>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeIpamResourceDiscoveryAssociationsResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscoveryAssociations":{
          "shape":"IpamResourceDiscoveryAssociationSet",
          "documentation":"<p>The resource discovery associations.</p>",
          "locationName":"ipamResourceDiscoveryAssociationSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeIpamScopesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters for the request. For more information about filtering, see <a href=\"https://docs.aws.amazon.com/cli/latest/userguide/cli-usage-filter.html\">Filtering CLI output</a>.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of results to return in the request.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "IpamScopeIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the scopes you want information on.</p>",
          "locationName":"IpamScopeId"
        }
      }
    },
    "DescribeIpamScopesResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "IpamScopes":{
          "shape":"IpamScopeSet",
          "documentation":"<p>The scopes you want information on.</p>",
          "locationName":"ipamScopeSet"
        }
      }
    },
    "DescribeIpamsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters for the request. For more information about filtering, see <a href=\"https://docs.aws.amazon.com/cli/latest/userguide/cli-usage-filter.html\">Filtering CLI output</a>.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of results to return in the request.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "IpamIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the IPAMs you want information on.</p>",
          "locationName":"IpamId"
        }
      }
    },
    "DescribeIpamsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "Ipams":{
          "shape":"IpamSet",
          "documentation":"<p>Information about the IPAMs.</p>",
          "locationName":"ipamSet"
        }
      }
    },
    "DescribeIpv6PoolsRequest":{
      "type":"structure",
      "members":{
        "PoolIds":{
          "shape":"Ipv6PoolIdList",
          "documentation":"<p>The IDs of the IPv6 address pools.</p>",
          "locationName":"PoolId"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"Ipv6PoolMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        }
      }
    },
    "DescribeIpv6PoolsResult":{
      "type":"structure",
      "members":{
        "Ipv6Pools":{
          "shape":"Ipv6PoolSet",
          "documentation":"<p>Information about the IPv6 address pools.</p>",
          "locationName":"ipv6PoolSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeKeyPairsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>key-pair-id</code> - The ID of the key pair.</p> </li> <li> <p> <code>fingerprint</code> - The fingerprint of the key pair.</p> </li> <li> <p> <code>key-name</code> - The name of the key pair.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "KeyNames":{
          "shape":"KeyNameStringList",
          "documentation":"<p>The key pair names.</p> <p>Default: Describes all of your key pairs.</p>",
          "locationName":"KeyName"
        },
        "KeyPairIds":{
          "shape":"KeyPairIdStringList",
          "documentation":"<p>The IDs of the key pairs.</p>",
          "locationName":"KeyPairId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "IncludePublicKey":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, the public key material is included in the response.</p> <p>Default: <code>false</code> </p>"
        }
      }
    },
    "DescribeKeyPairsResult":{
      "type":"structure",
      "members":{
        "KeyPairs":{
          "shape":"KeyPairList",
          "documentation":"<p>Information about the key pairs.</p>",
          "locationName":"keySet"
        }
      }
    },
    "DescribeLaunchTemplateVersionsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>To describe one or more versions of a specified launch template, you must specify either the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p> <p>To describe all the latest or default launch template versions in your account, you must omit this parameter.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>To describe one or more versions of a specified launch template, you must specify either the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p> <p>To describe all the latest or default launch template versions in your account, you must omit this parameter.</p>"
        },
        "Versions":{
          "shape":"VersionStringList",
          "documentation":"<p>One or more versions of the launch template. Valid values depend on whether you are describing a specified launch template (by ID or name) or all launch templates in your account.</p> <p>To describe one or more versions of a specified launch template, valid values are <code>$Latest</code>, <code>$Default</code>, and numbers.</p> <p>To describe all launch templates in your account that are defined as the latest version, the valid value is <code>$Latest</code>. To describe all launch templates in your account that are defined as the default version, the valid value is <code>$Default</code>. You can specify <code>$Latest</code> and <code>$Default</code> in the same request. You cannot specify numbers.</p>",
          "locationName":"LaunchTemplateVersion"
        },
        "MinVersion":{
          "shape":"String",
          "documentation":"<p>The version number after which to describe launch template versions.</p>"
        },
        "MaxVersion":{
          "shape":"String",
          "documentation":"<p>The version number up to which to describe launch template versions.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value. This value can be between 1 and 200.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>create-time</code> - The time the launch template version was created.</p> </li> <li> <p> <code>ebs-optimized</code> - A boolean that indicates whether the instance is optimized for Amazon EBS I/O.</p> </li> <li> <p> <code>http-endpoint</code> - Indicates whether the HTTP metadata endpoint on your instances is enabled (<code>enabled</code> | <code>disabled</code>).</p> </li> <li> <p> <code>http-protocol-ipv4</code> - Indicates whether the IPv4 endpoint for the instance metadata service is enabled (<code>enabled</code> | <code>disabled</code>).</p> </li> <li> <p> <code>host-resource-group-arn</code> - The ARN of the host resource group in which to launch the instances.</p> </li> <li> <p> <code>http-tokens</code> - The state of token usage for your instance metadata requests (<code>optional</code> | <code>required</code>).</p> </li> <li> <p> <code>iam-instance-profile</code> - The ARN of the IAM instance profile.</p> </li> <li> <p> <code>image-id</code> - The ID of the AMI.</p> </li> <li> <p> <code>instance-type</code> - The instance type.</p> </li> <li> <p> <code>is-default-version</code> - A boolean that indicates whether the launch template version is the default version.</p> </li> <li> <p> <code>kernel-id</code> - The kernel ID.</p> </li> <li> <p> <code>license-configuration-arn</code> - The ARN of the license configuration.</p> </li> <li> <p> <code>network-card-index</code> - The index of the network card.</p> </li> <li> <p> <code>ram-disk-id</code> - The RAM disk ID.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "ResolveAlias":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, and if a Systems Manager parameter is specified for <code>ImageId</code>, the AMI ID is displayed in the response for <code>imageId</code>.</p> <p>If <code>false</code>, and if a Systems Manager parameter is specified for <code>ImageId</code>, the parameter is displayed in the response for <code>imageId</code>.</p> <p> For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#use-an-ssm-parameter-instead-of-an-ami-id\">Use a Systems Manager parameter instead of an AMI ID</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Default: <code>false</code> </p>"
        }
      }
    },
    "DescribeLaunchTemplateVersionsResult":{
      "type":"structure",
      "members":{
        "LaunchTemplateVersions":{
          "shape":"LaunchTemplateVersionSet",
          "documentation":"<p>Information about the launch template versions.</p>",
          "locationName":"launchTemplateVersionSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLaunchTemplatesMaxResults":{
      "type":"integer",
      "max":200,
      "min":1
    },
    "DescribeLaunchTemplatesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "LaunchTemplateIds":{
          "shape":"LaunchTemplateIdStringList",
          "documentation":"<p>One or more launch template IDs.</p>",
          "locationName":"LaunchTemplateId"
        },
        "LaunchTemplateNames":{
          "shape":"LaunchTemplateNameStringList",
          "documentation":"<p>One or more launch template names.</p>",
          "locationName":"LaunchTemplateName"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>create-time</code> - The time the launch template was created.</p> </li> <li> <p> <code>launch-template-name</code> - The name of the launch template.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeLaunchTemplatesMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value. This value can be between 1 and 200.</p>"
        }
      }
    },
    "DescribeLaunchTemplatesResult":{
      "type":"structure",
      "members":{
        "LaunchTemplates":{
          "shape":"LaunchTemplateSet",
          "documentation":"<p>Information about the launch templates.</p>",
          "locationName":"launchTemplates"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsRequest":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVirtualInterfaceGroupAssociationIds":{
          "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociationIdSet",
          "documentation":"<p>The IDs of the associations.</p>",
          "locationName":"LocalGatewayRouteTableVirtualInterfaceGroupAssociationId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>local-gateway-id</code> - The ID of a local gateway.</p> </li> <li> <p> <code>local-gateway-route-table-arn</code> - The Amazon Resource Name (ARN) of the local gateway route table for the virtual interface group.</p> </li> <li> <p> <code>local-gateway-route-table-id</code> - The ID of the local gateway route table.</p> </li> <li> <p> <code>local-gateway-route-table-virtual-interface-group-association-id</code> - The ID of the association.</p> </li> <li> <p> <code>local-gateway-route-table-virtual-interface-group-id</code> - The ID of the virtual interface group.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the local gateway virtual interface group association.</p> </li> <li> <p> <code>state</code> - The state of the association.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"LocalGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVirtualInterfaceGroupAssociations":{
          "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociationSet",
          "documentation":"<p>Information about the associations.</p>",
          "locationName":"localGatewayRouteTableVirtualInterfaceGroupAssociationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLocalGatewayRouteTableVpcAssociationsRequest":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVpcAssociationIds":{
          "shape":"LocalGatewayRouteTableVpcAssociationIdSet",
          "documentation":"<p>The IDs of the associations.</p>",
          "locationName":"LocalGatewayRouteTableVpcAssociationId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>local-gateway-id</code> - The ID of a local gateway.</p> </li> <li> <p> <code>local-gateway-route-table-arn</code> - The Amazon Resource Name (ARN) of the local gateway route table for the association.</p> </li> <li> <p> <code>local-gateway-route-table-id</code> - The ID of the local gateway route table.</p> </li> <li> <p> <code>local-gateway-route-table-vpc-association-id</code> - The ID of the association.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the local gateway route table for the association.</p> </li> <li> <p> <code>state</code> - The state of the association.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"LocalGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeLocalGatewayRouteTableVpcAssociationsResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVpcAssociations":{
          "shape":"LocalGatewayRouteTableVpcAssociationSet",
          "documentation":"<p>Information about the associations.</p>",
          "locationName":"localGatewayRouteTableVpcAssociationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLocalGatewayRouteTablesRequest":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableIds":{
          "shape":"LocalGatewayRouteTableIdSet",
          "documentation":"<p>The IDs of the local gateway route tables.</p>",
          "locationName":"LocalGatewayRouteTableId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>local-gateway-id</code> - The ID of a local gateway.</p> </li> <li> <p> <code>local-gateway-route-table-arn</code> - The Amazon Resource Name (ARN) of the local gateway route table.</p> </li> <li> <p> <code>local-gateway-route-table-id</code> - The ID of a local gateway route table.</p> </li> <li> <p> <code>outpost-arn</code> - The Amazon Resource Name (ARN) of the Outpost.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the local gateway route table.</p> </li> <li> <p> <code>state</code> - The state of the local gateway route table.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"LocalGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeLocalGatewayRouteTablesResult":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTables":{
          "shape":"LocalGatewayRouteTableSet",
          "documentation":"<p>Information about the local gateway route tables.</p>",
          "locationName":"localGatewayRouteTableSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLocalGatewayVirtualInterfaceGroupsRequest":{
      "type":"structure",
      "members":{
        "LocalGatewayVirtualInterfaceGroupIds":{
          "shape":"LocalGatewayVirtualInterfaceGroupIdSet",
          "documentation":"<p>The IDs of the virtual interface groups.</p>",
          "locationName":"LocalGatewayVirtualInterfaceGroupId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>local-gateway-id</code> - The ID of a local gateway.</p> </li> <li> <p> <code>local-gateway-virtual-interface-group-id</code> - The ID of the virtual interface group.</p> </li> <li> <p> <code>local-gateway-virtual-interface-id</code> - The ID of the virtual interface.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the local gateway virtual interface group.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"LocalGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeLocalGatewayVirtualInterfaceGroupsResult":{
      "type":"structure",
      "members":{
        "LocalGatewayVirtualInterfaceGroups":{
          "shape":"LocalGatewayVirtualInterfaceGroupSet",
          "documentation":"<p>The virtual interface groups.</p>",
          "locationName":"localGatewayVirtualInterfaceGroupSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLocalGatewayVirtualInterfacesRequest":{
      "type":"structure",
      "members":{
        "LocalGatewayVirtualInterfaceIds":{
          "shape":"LocalGatewayVirtualInterfaceIdSet",
          "documentation":"<p>The IDs of the virtual interfaces.</p>",
          "locationName":"LocalGatewayVirtualInterfaceId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>local-address</code> - The local address.</p> </li> <li> <p> <code>local-bgp-asn</code> - The Border Gateway Protocol (BGP) Autonomous System Number (ASN) of the local gateway.</p> </li> <li> <p> <code>local-gateway-id</code> - The ID of the local gateway.</p> </li> <li> <p> <code>local-gateway-virtual-interface-id</code> - The ID of the virtual interface.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the local gateway virtual interface.</p> </li> <li> <p> <code>peer-address</code> - The peer address.</p> </li> <li> <p> <code>peer-bgp-asn</code> - The peer BGP ASN.</p> </li> <li> <p> <code>vlan</code> - The ID of the VLAN.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"LocalGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeLocalGatewayVirtualInterfacesResult":{
      "type":"structure",
      "members":{
        "LocalGatewayVirtualInterfaces":{
          "shape":"LocalGatewayVirtualInterfaceSet",
          "documentation":"<p>Information about the virtual interfaces.</p>",
          "locationName":"localGatewayVirtualInterfaceSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeLocalGatewaysRequest":{
      "type":"structure",
      "members":{
        "LocalGatewayIds":{
          "shape":"LocalGatewayIdSet",
          "documentation":"<p>The IDs of the local gateways.</p>",
          "locationName":"LocalGatewayId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>local-gateway-id</code> - The ID of a local gateway.</p> </li> <li> <p> <code>outpost-arn</code> - The Amazon Resource Name (ARN) of the Outpost.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the local gateway.</p> </li> <li> <p> <code>state</code> - The state of the association.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"LocalGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeLocalGatewaysResult":{
      "type":"structure",
      "members":{
        "LocalGateways":{
          "shape":"LocalGatewaySet",
          "documentation":"<p>Information about the local gateways.</p>",
          "locationName":"localGatewaySet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeManagedPrefixListsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>owner-id</code> - The ID of the prefix list owner.</p> </li> <li> <p> <code>prefix-list-id</code> - The ID of the prefix list.</p> </li> <li> <p> <code>prefix-list-name</code> - The name of the prefix list.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"PrefixListMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "PrefixListIds":{
          "shape":"ValueStringList",
          "documentation":"<p>One or more prefix list IDs.</p>",
          "locationName":"PrefixListId"
        }
      }
    },
    "DescribeManagedPrefixListsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "PrefixLists":{
          "shape":"ManagedPrefixListSet",
          "documentation":"<p>Information about the prefix lists.</p>",
          "locationName":"prefixListSet"
        }
      }
    },
    "DescribeMovingAddressesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeMovingAddressesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>moving-status</code> - The status of the Elastic IP address (<code>MovingToVpc</code> | <code>RestoringToClassic</code>).</p> </li> </ul>",
          "locationName":"filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "MaxResults":{
          "shape":"DescribeMovingAddressesMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results of the initial request can be seen by sending another request with the returned <code>NextToken</code> value. This value can be between 5 and 1000; if <code>MaxResults</code> is given a value outside of this range, an error is returned.</p> <p>Default: If no value is provided, the default is 1000.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>",
          "locationName":"nextToken"
        },
        "PublicIps":{
          "shape":"ValueStringList",
          "documentation":"<p>One or more Elastic IP addresses.</p>",
          "locationName":"publicIp"
        }
      }
    },
    "DescribeMovingAddressesResult":{
      "type":"structure",
      "members":{
        "MovingAddressStatuses":{
          "shape":"MovingAddressStatusSet",
          "documentation":"<p>The status for each Elastic IP address.</p>",
          "locationName":"movingAddressStatusSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNatGatewaysMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeNatGatewaysRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filter":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>nat-gateway-id</code> - The ID of the NAT gateway.</p> </li> <li> <p> <code>state</code> - The state of the NAT gateway (<code>pending</code> | <code>failed</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet in which the NAT gateway resides.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC in which the NAT gateway resides.</p> </li> </ul>"
        },
        "MaxResults":{
          "shape":"DescribeNatGatewaysMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NatGatewayIds":{
          "shape":"NatGatewayIdStringList",
          "documentation":"<p>One or more NAT gateway IDs.</p>",
          "locationName":"NatGatewayId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        }
      }
    },
    "DescribeNatGatewaysResult":{
      "type":"structure",
      "members":{
        "NatGateways":{
          "shape":"NatGatewayList",
          "documentation":"<p>Information about the NAT gateways.</p>",
          "locationName":"natGatewaySet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNetworkAclsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeNetworkAclsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>association.association-id</code> - The ID of an association ID for the ACL.</p> </li> <li> <p> <code>association.network-acl-id</code> - The ID of the network ACL involved in the association.</p> </li> <li> <p> <code>association.subnet-id</code> - The ID of the subnet involved in the association.</p> </li> <li> <p> <code>default</code> - Indicates whether the ACL is the default network ACL for the VPC.</p> </li> <li> <p> <code>entry.cidr</code> - The IPv4 CIDR range specified in the entry.</p> </li> <li> <p> <code>entry.icmp.code</code> - The ICMP code specified in the entry, if any.</p> </li> <li> <p> <code>entry.icmp.type</code> - The ICMP type specified in the entry, if any.</p> </li> <li> <p> <code>entry.ipv6-cidr</code> - The IPv6 CIDR range specified in the entry.</p> </li> <li> <p> <code>entry.port-range.from</code> - The start of the port range specified in the entry. </p> </li> <li> <p> <code>entry.port-range.to</code> - The end of the port range specified in the entry. </p> </li> <li> <p> <code>entry.protocol</code> - The protocol specified in the entry (<code>tcp</code> | <code>udp</code> | <code>icmp</code> or a protocol number).</p> </li> <li> <p> <code>entry.rule-action</code> - Allows or denies the matching traffic (<code>allow</code> | <code>deny</code>).</p> </li> <li> <p> <code>entry.egress</code> - A Boolean that indicates the type of rule. Specify <code>true</code> for egress rules, or <code>false</code> for ingress rules.</p> </li> <li> <p> <code>entry.rule-number</code> - The number of an entry (in other words, rule) in the set of ACL entries.</p> </li> <li> <p> <code>network-acl-id</code> - The ID of the network ACL.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the network ACL.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC for the network ACL.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkAclIds":{
          "shape":"NetworkAclIdStringList",
          "documentation":"<p>One or more network ACL IDs.</p> <p>Default: Describes all your network ACLs.</p>",
          "locationName":"NetworkAclId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeNetworkAclsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeNetworkAclsResult":{
      "type":"structure",
      "members":{
        "NetworkAcls":{
          "shape":"NetworkAclList",
          "documentation":"<p>Information about one or more network ACLs.</p>",
          "locationName":"networkAclSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNetworkInsightsAccessScopeAnalysesRequest":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalysisIds":{
          "shape":"NetworkInsightsAccessScopeAnalysisIdList",
          "documentation":"<p>The IDs of the Network Access Scope analyses.</p>",
          "locationName":"NetworkInsightsAccessScopeAnalysisId"
        },
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>"
        },
        "AnalysisStartTimeBegin":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Filters the results based on the start time. The analysis must have started on or after this time.</p>"
        },
        "AnalysisStartTimeEnd":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Filters the results based on the start time. The analysis must have started on or before this time.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>There are no supported filters.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"NetworkInsightsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeNetworkInsightsAccessScopeAnalysesResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalyses":{
          "shape":"NetworkInsightsAccessScopeAnalysisList",
          "documentation":"<p>The Network Access Scope analyses.</p>",
          "locationName":"networkInsightsAccessScopeAnalysisSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNetworkInsightsAccessScopesRequest":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeIds":{
          "shape":"NetworkInsightsAccessScopeIdList",
          "documentation":"<p>The IDs of the Network Access Scopes.</p>",
          "locationName":"NetworkInsightsAccessScopeId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>There are no supported filters.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"NetworkInsightsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeNetworkInsightsAccessScopesResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopes":{
          "shape":"NetworkInsightsAccessScopeList",
          "documentation":"<p>The Network Access Scopes.</p>",
          "locationName":"networkInsightsAccessScopeSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNetworkInsightsAnalysesRequest":{
      "type":"structure",
      "members":{
        "NetworkInsightsAnalysisIds":{
          "shape":"NetworkInsightsAnalysisIdList",
          "documentation":"<p>The ID of the network insights analyses. You must specify either analysis IDs or a path ID.</p>",
          "locationName":"NetworkInsightsAnalysisId"
        },
        "NetworkInsightsPathId":{
          "shape":"NetworkInsightsPathId",
          "documentation":"<p>The ID of the path. You must specify either a path ID or analysis IDs.</p>"
        },
        "AnalysisStartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time when the network insights analyses started.</p>"
        },
        "AnalysisEndTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time when the network insights analyses ended.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters. The following are the possible values:</p> <ul> <li> <p>path-found - A Boolean value that indicates whether a feasible path is found.</p> </li> <li> <p>status - The status of the analysis (running | succeeded | failed).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"NetworkInsightsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeNetworkInsightsAnalysesResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAnalyses":{
          "shape":"NetworkInsightsAnalysisList",
          "documentation":"<p>Information about the network insights analyses.</p>",
          "locationName":"networkInsightsAnalysisSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNetworkInsightsPathsRequest":{
      "type":"structure",
      "members":{
        "NetworkInsightsPathIds":{
          "shape":"NetworkInsightsPathIdList",
          "documentation":"<p>The IDs of the paths.</p>",
          "locationName":"NetworkInsightsPathId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters. The following are the possible values:</p> <ul> <li> <p>destination - The ID of the resource.</p> </li> <li> <p>destination-port - The destination port.</p> </li> <li> <p>protocol - The protocol.</p> </li> <li> <p>source - The ID of the resource.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"NetworkInsightsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeNetworkInsightsPathsResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsPaths":{
          "shape":"NetworkInsightsPathList",
          "documentation":"<p>Information about the paths.</p>",
          "locationName":"networkInsightsPathSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeNetworkInterfaceAttributeRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "Attribute":{
          "shape":"NetworkInterfaceAttribute",
          "documentation":"<p>The attribute of the network interface. This parameter is required.</p>",
          "locationName":"attribute"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeNetworkInterfaceAttribute.</p>"
    },
    "DescribeNetworkInterfaceAttributeResult":{
      "type":"structure",
      "members":{
        "Attachment":{
          "shape":"NetworkInterfaceAttachment",
          "documentation":"<p>The attachment (if any) of the network interface.</p>",
          "locationName":"attachment"
        },
        "Description":{
          "shape":"AttributeValue",
          "documentation":"<p>The description of the network interface.</p>",
          "locationName":"description"
        },
        "Groups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>The security groups associated with the network interface.</p>",
          "locationName":"groupSet"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "SourceDestCheck":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether source/destination checking is enabled.</p>",
          "locationName":"sourceDestCheck"
        }
      },
      "documentation":"<p>Contains the output of DescribeNetworkInterfaceAttribute.</p>"
    },
    "DescribeNetworkInterfacePermissionsMaxResults":{
      "type":"integer",
      "max":255,
      "min":5
    },
    "DescribeNetworkInterfacePermissionsRequest":{
      "type":"structure",
      "members":{
        "NetworkInterfacePermissionIds":{
          "shape":"NetworkInterfacePermissionIdList",
          "documentation":"<p>The network interface permission IDs.</p>",
          "locationName":"NetworkInterfacePermissionId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>network-interface-permission.network-interface-permission-id</code> - The ID of the permission.</p> </li> <li> <p> <code>network-interface-permission.network-interface-id</code> - The ID of the network interface.</p> </li> <li> <p> <code>network-interface-permission.aws-account-id</code> - The Amazon Web Services account ID.</p> </li> <li> <p> <code>network-interface-permission.aws-service</code> - The Amazon Web Service.</p> </li> <li> <p> <code>network-interface-permission.permission</code> - The type of permission (<code>INSTANCE-ATTACH</code> | <code>EIP-ASSOCIATE</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeNetworkInterfacePermissionsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. If this parameter is not specified, up to 50 results are returned by default. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeNetworkInterfacePermissions.</p>"
    },
    "DescribeNetworkInterfacePermissionsResult":{
      "type":"structure",
      "members":{
        "NetworkInterfacePermissions":{
          "shape":"NetworkInterfacePermissionList",
          "documentation":"<p>The network interface permissions.</p>",
          "locationName":"networkInterfacePermissions"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      },
      "documentation":"<p>Contains the output for DescribeNetworkInterfacePermissions.</p>"
    },
    "DescribeNetworkInterfacesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeNetworkInterfacesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>addresses.private-ip-address</code> - The private IPv4 addresses associated with the network interface.</p> </li> <li> <p> <code>addresses.primary</code> - Whether the private IPv4 address is the primary IP address associated with the network interface. </p> </li> <li> <p> <code>addresses.association.public-ip</code> - The association ID returned when the network interface was associated with the Elastic IP address (IPv4).</p> </li> <li> <p> <code>addresses.association.owner-id</code> - The owner ID of the addresses associated with the network interface.</p> </li> <li> <p> <code>association.association-id</code> - The association ID returned when the network interface was associated with an IPv4 address.</p> </li> <li> <p> <code>association.allocation-id</code> - The allocation ID returned when you allocated the Elastic IP address (IPv4) for your network interface.</p> </li> <li> <p> <code>association.ip-owner-id</code> - The owner of the Elastic IP address (IPv4) associated with the network interface.</p> </li> <li> <p> <code>association.public-ip</code> - The address of the Elastic IP address (IPv4) bound to the network interface.</p> </li> <li> <p> <code>association.public-dns-name</code> - The public DNS name for the network interface (IPv4).</p> </li> <li> <p> <code>attachment.attachment-id</code> - The ID of the interface attachment.</p> </li> <li> <p> <code>attachment.attach-time</code> - The time that the network interface was attached to an instance.</p> </li> <li> <p> <code>attachment.delete-on-termination</code> - Indicates whether the attachment is deleted when an instance is terminated.</p> </li> <li> <p> <code>attachment.device-index</code> - The device index to which the network interface is attached.</p> </li> <li> <p> <code>attachment.instance-id</code> - The ID of the instance to which the network interface is attached.</p> </li> <li> <p> <code>attachment.instance-owner-id</code> - The owner ID of the instance to which the network interface is attached.</p> </li> <li> <p> <code>attachment.status</code> - The status of the attachment (<code>attaching</code> | <code>attached</code> | <code>detaching</code> | <code>detached</code>).</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone of the network interface.</p> </li> <li> <p> <code>description</code> - The description of the network interface.</p> </li> <li> <p> <code>group-id</code> - The ID of a security group associated with the network interface.</p> </li> <li> <p> <code>group-name</code> - The name of a security group associated with the network interface.</p> </li> <li> <p> <code>ipv6-addresses.ipv6-address</code> - An IPv6 address associated with the network interface.</p> </li> <li> <p> <code>interface-type</code> - The type of network interface (<code>api_gateway_managed</code> | <code>aws_codestar_connections_managed</code> | <code>branch</code> | <code>efa</code> | <code>gateway_load_balancer</code> | <code>gateway_load_balancer_endpoint</code> | <code>global_accelerator_managed</code> | <code>interface</code> | <code>iot_rules_managed</code> | <code>lambda</code> | <code>load_balancer</code> | <code>nat_gateway</code> | <code>network_load_balancer</code> | <code>quicksight</code> | <code>transit_gateway</code> | <code>trunk</code> | <code>vpc_endpoint</code>).</p> </li> <li> <p> <code>mac-address</code> - The MAC address of the network interface.</p> </li> <li> <p> <code>network-interface-id</code> - The ID of the network interface.</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the network interface owner.</p> </li> <li> <p> <code>private-ip-address</code> - The private IPv4 address or addresses of the network interface.</p> </li> <li> <p> <code>private-dns-name</code> - The private DNS name of the network interface (IPv4).</p> </li> <li> <p> <code>requester-id</code> - The alias or Amazon Web Services account ID of the principal or service that created the network interface.</p> </li> <li> <p> <code>requester-managed</code> - Indicates whether the network interface is being managed by an Amazon Web Service (for example, Amazon Web Services Management Console, Auto Scaling, and so on).</p> </li> <li> <p> <code>source-dest-check</code> - Indicates whether the network interface performs source/destination checking. A value of <code>true</code> means checking is enabled, and <code>false</code> means checking is disabled. The value must be <code>false</code> for the network interface to perform network address translation (NAT) in your VPC. </p> </li> <li> <p> <code>status</code> - The status of the network interface. If the network interface is not attached to an instance, the status is <code>available</code>; if a network interface is attached to an instance the status is <code>in-use</code>.</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet for the network interface.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC for the network interface.</p> </li> </ul>",
          "locationName":"filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkInterfaceIds":{
          "shape":"NetworkInterfaceIdList",
          "documentation":"<p>The network interface IDs.</p> <p>Default: Describes all your network interfaces.</p>",
          "locationName":"NetworkInterfaceId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeNetworkInterfacesMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. You cannot specify this parameter and the network interface IDs parameter in the same request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeNetworkInterfaces.</p>"
    },
    "DescribeNetworkInterfacesResult":{
      "type":"structure",
      "members":{
        "NetworkInterfaces":{
          "shape":"NetworkInterfaceList",
          "documentation":"<p>Information about one or more network interfaces.</p>",
          "locationName":"networkInterfaceSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribePlacementGroupsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>group-name</code> - The name of the placement group.</p> </li> <li> <p> <code>group-arn</code> - The Amazon Resource Name (ARN) of the placement group.</p> </li> <li> <p> <code>spread-level</code> - The spread level for the placement group (<code>host</code> | <code>rack</code>). </p> </li> <li> <p> <code>state</code> - The state of the placement group (<code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>strategy</code> - The strategy of the placement group (<code>cluster</code> | <code>spread</code> | <code>partition</code>).</p> </li> <li> <p> <code>tag:<key></code> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources that have a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "GroupNames":{
          "shape":"PlacementGroupStringList",
          "documentation":"<p>The names of the placement groups.</p> <p>Default: Describes all your placement groups, or only those otherwise specified.</p>",
          "locationName":"groupName"
        },
        "GroupIds":{
          "shape":"PlacementGroupIdStringList",
          "documentation":"<p>The IDs of the placement groups.</p>",
          "locationName":"GroupId"
        }
      }
    },
    "DescribePlacementGroupsResult":{
      "type":"structure",
      "members":{
        "PlacementGroups":{
          "shape":"PlacementGroupList",
          "documentation":"<p>Information about the placement groups.</p>",
          "locationName":"placementGroupSet"
        }
      }
    },
    "DescribePrefixListsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>prefix-list-id</code>: The ID of a prefix list.</p> </li> <li> <p> <code>prefix-list-name</code>: The name of a prefix list.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "PrefixListIds":{
          "shape":"PrefixListResourceIdStringList",
          "documentation":"<p>One or more prefix list IDs.</p>",
          "locationName":"PrefixListId"
        }
      }
    },
    "DescribePrefixListsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "PrefixLists":{
          "shape":"PrefixListSet",
          "documentation":"<p>All available prefix lists.</p>",
          "locationName":"prefixListSet"
        }
      }
    },
    "DescribePrincipalIdFormatMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "DescribePrincipalIdFormatRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Resources":{
          "shape":"ResourceList",
          "documentation":"<p>The type of resource: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>instance</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>reservation</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>snapshot</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code> </p>",
          "locationName":"Resource"
        },
        "MaxResults":{
          "shape":"DescribePrincipalIdFormatMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned NextToken value. </p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of results.</p>"
        }
      }
    },
    "DescribePrincipalIdFormatResult":{
      "type":"structure",
      "members":{
        "Principals":{
          "shape":"PrincipalIdFormatList",
          "documentation":"<p>Information about the ID format settings for the ARN.</p>",
          "locationName":"principalSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is null when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribePublicIpv4PoolsRequest":{
      "type":"structure",
      "members":{
        "PoolIds":{
          "shape":"PublicIpv4PoolIdStringList",
          "documentation":"<p>The IDs of the address pools.</p>",
          "locationName":"PoolId"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"PoolMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        }
      }
    },
    "DescribePublicIpv4PoolsResult":{
      "type":"structure",
      "members":{
        "PublicIpv4Pools":{
          "shape":"PublicIpv4PoolSet",
          "documentation":"<p>Information about the address pools.</p>",
          "locationName":"publicIpv4PoolSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeRegionsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>endpoint</code> - The endpoint of the Region (for example, <code>ec2.us-east-1.amazonaws.com</code>).</p> </li> <li> <p> <code>opt-in-status</code> - The opt-in status of the Region (<code>opt-in-not-required</code> | <code>opted-in</code> | <code>not-opted-in</code>).</p> </li> <li> <p> <code>region-name</code> - The name of the Region (for example, <code>us-east-1</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "RegionNames":{
          "shape":"RegionNameStringList",
          "documentation":"<p>The names of the Regions. You can specify any Regions, whether they are enabled and disabled for your account.</p>",
          "locationName":"RegionName"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "AllRegions":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to display all Regions, including Regions that are disabled for your account.</p>"
        }
      }
    },
    "DescribeRegionsResult":{
      "type":"structure",
      "members":{
        "Regions":{
          "shape":"RegionList",
          "documentation":"<p>Information about the Regions.</p>",
          "locationName":"regionInfo"
        }
      }
    },
    "DescribeReplaceRootVolumeTasksMaxResults":{
      "type":"integer",
      "max":50,
      "min":1
    },
    "DescribeReplaceRootVolumeTasksRequest":{
      "type":"structure",
      "members":{
        "ReplaceRootVolumeTaskIds":{
          "shape":"ReplaceRootVolumeTaskIds",
          "documentation":"<p>The ID of the root volume replacement task to view.</p>",
          "locationName":"ReplaceRootVolumeTaskId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>Filter to use:</p> <ul> <li> <p> <code>instance-id</code> - The ID of the instance for which the root volume replacement task was created.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"DescribeReplaceRootVolumeTasksMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeReplaceRootVolumeTasksResult":{
      "type":"structure",
      "members":{
        "ReplaceRootVolumeTasks":{
          "shape":"ReplaceRootVolumeTasks",
          "documentation":"<p>Information about the root volume replacement task.</p>",
          "locationName":"replaceRootVolumeTaskSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeReservedInstancesListingsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>reserved-instances-id</code> - The ID of the Reserved Instances.</p> </li> <li> <p> <code>reserved-instances-listing-id</code> - The ID of the Reserved Instances listing.</p> </li> <li> <p> <code>status</code> - The status of the Reserved Instance listing (<code>pending</code> | <code>active</code> | <code>cancelled</code> | <code>closed</code>).</p> </li> <li> <p> <code>status-message</code> - The reason for the status.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "ReservedInstancesId":{
          "shape":"ReservationId",
          "documentation":"<p>One or more Reserved Instance IDs.</p>",
          "locationName":"reservedInstancesId"
        },
        "ReservedInstancesListingId":{
          "shape":"ReservedInstancesListingId",
          "documentation":"<p>One or more Reserved Instance listing IDs.</p>",
          "locationName":"reservedInstancesListingId"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeReservedInstancesListings.</p>"
    },
    "DescribeReservedInstancesListingsResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesListings":{
          "shape":"ReservedInstancesListingList",
          "documentation":"<p>Information about the Reserved Instance listing.</p>",
          "locationName":"reservedInstancesListingsSet"
        }
      },
      "documentation":"<p>Contains the output of DescribeReservedInstancesListings.</p>"
    },
    "DescribeReservedInstancesModificationsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>client-token</code> - The idempotency token for the modification request.</p> </li> <li> <p> <code>create-date</code> - The time when the modification request was created.</p> </li> <li> <p> <code>effective-date</code> - The time when the modification becomes effective.</p> </li> <li> <p> <code>modification-result.reserved-instances-id</code> - The ID for the Reserved Instances created as part of the modification request. This ID is only available when the status of the modification is <code>fulfilled</code>.</p> </li> <li> <p> <code>modification-result.target-configuration.availability-zone</code> - The Availability Zone for the new Reserved Instances.</p> </li> <li> <p> <code>modification-result.target-configuration.instance-count </code> - The number of new Reserved Instances.</p> </li> <li> <p> <code>modification-result.target-configuration.instance-type</code> - The instance type of the new Reserved Instances.</p> </li> <li> <p> <code>modification-result.target-configuration.platform</code> - The network platform of the new Reserved Instances (<code>EC2-Classic</code> | <code>EC2-VPC</code>).</p> </li> <li> <p> <code>reserved-instances-id</code> - The ID of the Reserved Instances modified.</p> </li> <li> <p> <code>reserved-instances-modification-id</code> - The ID of the modification request.</p> </li> <li> <p> <code>status</code> - The status of the Reserved Instances modification request (<code>processing</code> | <code>fulfilled</code> | <code>failed</code>).</p> </li> <li> <p> <code>status-message</code> - The reason for the status.</p> </li> <li> <p> <code>update-date</code> - The time when the modification request was last updated.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "ReservedInstancesModificationIds":{
          "shape":"ReservedInstancesModificationIdStringList",
          "documentation":"<p>IDs for the submitted modification request.</p>",
          "locationName":"ReservedInstancesModificationId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeReservedInstancesModifications.</p>"
    },
    "DescribeReservedInstancesModificationsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "ReservedInstancesModifications":{
          "shape":"ReservedInstancesModificationList",
          "documentation":"<p>The Reserved Instance modification information.</p>",
          "locationName":"reservedInstancesModificationsSet"
        }
      },
      "documentation":"<p>Contains the output of DescribeReservedInstancesModifications.</p>"
    },
    "DescribeReservedInstancesOfferingsRequest":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the Reserved Instance can be used.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone where the Reserved Instance can be used.</p> </li> <li> <p> <code>duration</code> - The duration of the Reserved Instance (for example, one year or three years), in seconds (<code>31536000</code> | <code>94608000</code>).</p> </li> <li> <p> <code>fixed-price</code> - The purchase price of the Reserved Instance (for example, 9800.0).</p> </li> <li> <p> <code>instance-type</code> - The instance type that is covered by the reservation.</p> </li> <li> <p> <code>marketplace</code> - Set to <code>true</code> to show only Reserved Instance Marketplace offerings. When this filter is not used, which is the default behavior, all offerings from both Amazon Web Services and the Reserved Instance Marketplace are listed.</p> </li> <li> <p> <code>product-description</code> - The Reserved Instance product platform description. Instances that include <code>(Amazon VPC)</code> in the product platform description will only be displayed to EC2-Classic account holders and are for use with Amazon VPC. (<code>Linux/UNIX</code> | <code>Linux/UNIX (Amazon VPC)</code> | <code>SUSE Linux</code> | <code>SUSE Linux (Amazon VPC)</code> | <code>Red Hat Enterprise Linux</code> | <code>Red Hat Enterprise Linux (Amazon VPC)</code> | <code>Red Hat Enterprise Linux with HA (Amazon VPC)</code> | <code>Windows</code> | <code>Windows (Amazon VPC)</code> | <code>Windows with SQL Server Standard</code> | <code>Windows with SQL Server Standard (Amazon VPC)</code> | <code>Windows with SQL Server Web</code> | <code> Windows with SQL Server Web (Amazon VPC)</code> | <code>Windows with SQL Server Enterprise</code> | <code>Windows with SQL Server Enterprise (Amazon VPC)</code>) </p> </li> <li> <p> <code>reserved-instances-offering-id</code> - The Reserved Instances offering ID.</p> </li> <li> <p> <code>scope</code> - The scope of the Reserved Instance (<code>Availability Zone</code> or <code>Region</code>).</p> </li> <li> <p> <code>usage-price</code> - The usage price of the Reserved Instance, per hour (for example, 0.84).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "IncludeMarketplace":{
          "shape":"Boolean",
          "documentation":"<p>Include Reserved Instance Marketplace offerings in the response.</p>"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type that the reservation will cover (for example, <code>m1.small</code>). For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "MaxDuration":{
          "shape":"Long",
          "documentation":"<p>The maximum duration (in seconds) to filter when searching for offerings.</p> <p>Default: 94608000 (3 years)</p>"
        },
        "MaxInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of instances to filter when searching for offerings.</p> <p>Default: 20</p>"
        },
        "MinDuration":{
          "shape":"Long",
          "documentation":"<p>The minimum duration (in seconds) to filter when searching for offerings.</p> <p>Default: 2592000 (1 month)</p>"
        },
        "OfferingClass":{
          "shape":"OfferingClassType",
          "documentation":"<p>The offering class of the Reserved Instance. Can be <code>standard</code> or <code>convertible</code>.</p>"
        },
        "ProductDescription":{
          "shape":"RIProductDescription",
          "documentation":"<p>The Reserved Instance product platform description. Instances that include <code>(Amazon VPC)</code> in the description are for use with Amazon VPC.</p>"
        },
        "ReservedInstancesOfferingIds":{
          "shape":"ReservedInstancesOfferingIdStringList",
          "documentation":"<p>One or more Reserved Instances offering IDs.</p>",
          "locationName":"ReservedInstancesOfferingId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceTenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instances covered by the reservation. A Reserved Instance with a tenancy of <code>dedicated</code> is applied to instances that run in a VPC on single-tenant hardware (i.e., Dedicated Instances).</p> <p> <b>Important:</b> The <code>host</code> value cannot be used with this parameter. Use the <code>default</code> or <code>dedicated</code> values only.</p> <p>Default: <code>default</code> </p>",
          "locationName":"instanceTenancy"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results of the initial request can be seen by sending another request with the returned <code>NextToken</code> value. The maximum is 100.</p> <p>Default: 100</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        },
        "OfferingType":{
          "shape":"OfferingTypeValues",
          "documentation":"<p>The Reserved Instance offering type. If you are using tools that predate the 2011-11-01 API version, you only have access to the <code>Medium Utilization</code> Reserved Instance offering type. </p>",
          "locationName":"offeringType"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeReservedInstancesOfferings.</p>"
    },
    "DescribeReservedInstancesOfferingsResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesOfferings":{
          "shape":"ReservedInstancesOfferingList",
          "documentation":"<p>A list of Reserved Instances offerings.</p>",
          "locationName":"reservedInstancesOfferingsSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      },
      "documentation":"<p>Contains the output of DescribeReservedInstancesOfferings.</p>"
    },
    "DescribeReservedInstancesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone where the Reserved Instance can be used.</p> </li> <li> <p> <code>duration</code> - The duration of the Reserved Instance (one year or three years), in seconds (<code>31536000</code> | <code>94608000</code>).</p> </li> <li> <p> <code>end</code> - The time when the Reserved Instance expires (for example, 2015-08-07T11:54:42.000Z).</p> </li> <li> <p> <code>fixed-price</code> - The purchase price of the Reserved Instance (for example, 9800.0).</p> </li> <li> <p> <code>instance-type</code> - The instance type that is covered by the reservation.</p> </li> <li> <p> <code>scope</code> - The scope of the Reserved Instance (<code>Region</code> or <code>Availability Zone</code>).</p> </li> <li> <p> <code>product-description</code> - The Reserved Instance product platform description. Instances that include <code>(Amazon VPC)</code> in the product platform description will only be displayed to EC2-Classic account holders and are for use with Amazon VPC (<code>Linux/UNIX</code> | <code>Linux/UNIX (Amazon VPC)</code> | <code>SUSE Linux</code> | <code>SUSE Linux (Amazon VPC)</code> | <code>Red Hat Enterprise Linux</code> | <code>Red Hat Enterprise Linux (Amazon VPC)</code> | <code>Red Hat Enterprise Linux with HA (Amazon VPC)</code> | <code>Windows</code> | <code>Windows (Amazon VPC)</code> | <code>Windows with SQL Server Standard</code> | <code>Windows with SQL Server Standard (Amazon VPC)</code> | <code>Windows with SQL Server Web</code> | <code>Windows with SQL Server Web (Amazon VPC)</code> | <code>Windows with SQL Server Enterprise</code> | <code>Windows with SQL Server Enterprise (Amazon VPC)</code>).</p> </li> <li> <p> <code>reserved-instances-id</code> - The ID of the Reserved Instance.</p> </li> <li> <p> <code>start</code> - The time at which the Reserved Instance purchase request was placed (for example, 2014-08-07T11:54:42.000Z).</p> </li> <li> <p> <code>state</code> - The state of the Reserved Instance (<code>payment-pending</code> | <code>active</code> | <code>payment-failed</code> | <code>retired</code>).</p> </li> <li> <p> <code>tag:<key></code> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>usage-price</code> - The usage price of the Reserved Instance, per hour (for example, 0.84).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "OfferingClass":{
          "shape":"OfferingClassType",
          "documentation":"<p>Describes whether the Reserved Instance is Standard or Convertible.</p>"
        },
        "ReservedInstancesIds":{
          "shape":"ReservedInstancesIdStringList",
          "documentation":"<p>One or more Reserved Instance IDs.</p> <p>Default: Describes all your Reserved Instances, or only those otherwise specified.</p>",
          "locationName":"ReservedInstancesId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "OfferingType":{
          "shape":"OfferingTypeValues",
          "documentation":"<p>The Reserved Instance offering type. If you are using tools that predate the 2011-11-01 API version, you only have access to the <code>Medium Utilization</code> Reserved Instance offering type.</p>",
          "locationName":"offeringType"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeReservedInstances.</p>"
    },
    "DescribeReservedInstancesResult":{
      "type":"structure",
      "members":{
        "ReservedInstances":{
          "shape":"ReservedInstancesList",
          "documentation":"<p>A list of Reserved Instances.</p>",
          "locationName":"reservedInstancesSet"
        }
      },
      "documentation":"<p>Contains the output for DescribeReservedInstances.</p>"
    },
    "DescribeRouteTablesMaxResults":{
      "type":"integer",
      "max":100,
      "min":5
    },
    "DescribeRouteTablesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>association.route-table-association-id</code> - The ID of an association ID for the route table.</p> </li> <li> <p> <code>association.route-table-id</code> - The ID of the route table involved in the association.</p> </li> <li> <p> <code>association.subnet-id</code> - The ID of the subnet involved in the association.</p> </li> <li> <p> <code>association.main</code> - Indicates whether the route table is the main route table for the VPC (<code>true</code> | <code>false</code>). Route tables that do not have an association ID are not returned in the response.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the route table.</p> </li> <li> <p> <code>route-table-id</code> - The ID of the route table.</p> </li> <li> <p> <code>route.destination-cidr-block</code> - The IPv4 CIDR range specified in a route in the table.</p> </li> <li> <p> <code>route.destination-ipv6-cidr-block</code> - The IPv6 CIDR range specified in a route in the route table.</p> </li> <li> <p> <code>route.destination-prefix-list-id</code> - The ID (prefix) of the Amazon Web Service specified in a route in the table.</p> </li> <li> <p> <code>route.egress-only-internet-gateway-id</code> - The ID of an egress-only Internet gateway specified in a route in the route table.</p> </li> <li> <p> <code>route.gateway-id</code> - The ID of a gateway specified in a route in the table.</p> </li> <li> <p> <code>route.instance-id</code> - The ID of an instance specified in a route in the table.</p> </li> <li> <p> <code>route.nat-gateway-id</code> - The ID of a NAT gateway.</p> </li> <li> <p> <code>route.transit-gateway-id</code> - The ID of a transit gateway.</p> </li> <li> <p> <code>route.origin</code> - Describes how the route was created. <code>CreateRouteTable</code> indicates that the route was automatically created when the route table was created; <code>CreateRoute</code> indicates that the route was manually added to the route table; <code>EnableVgwRoutePropagation</code> indicates that the route was propagated by route propagation.</p> </li> <li> <p> <code>route.state</code> - The state of a route in the route table (<code>active</code> | <code>blackhole</code>). The blackhole state indicates that the route's target isn't available (for example, the specified gateway isn't attached to the VPC, the specified NAT instance has been terminated, and so on).</p> </li> <li> <p> <code>route.vpc-peering-connection-id</code> - The ID of a VPC peering connection specified in a route in the table.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC for the route table.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "RouteTableIds":{
          "shape":"RouteTableIdStringList",
          "documentation":"<p>One or more route table IDs.</p> <p>Default: Describes all your route tables.</p>",
          "locationName":"RouteTableId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeRouteTablesMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeRouteTablesResult":{
      "type":"structure",
      "members":{
        "RouteTables":{
          "shape":"RouteTableList",
          "documentation":"<p>Information about one or more route tables.</p>",
          "locationName":"routeTableSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      },
      "documentation":"<p>Contains the output of DescribeRouteTables.</p>"
    },
    "DescribeScheduledInstanceAvailabilityMaxResults":{
      "type":"integer",
      "max":300,
      "min":5
    },
    "DescribeScheduledInstanceAvailabilityRequest":{
      "type":"structure",
      "required":[
        "FirstSlotStartTimeRange",
        "Recurrence"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone (for example, <code>us-west-2a</code>).</p> </li> <li> <p> <code>instance-type</code> - The instance type (for example, <code>c4.large</code>).</p> </li> <li> <p> <code>network-platform</code> - The network platform (<code>EC2-Classic</code> or <code>EC2-VPC</code>).</p> </li> <li> <p> <code>platform</code> - The platform (<code>Linux/UNIX</code> or <code>Windows</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "FirstSlotStartTimeRange":{
          "shape":"SlotDateTimeRangeRequest",
          "documentation":"<p>The time period for the first schedule to start.</p>"
        },
        "MaxResults":{
          "shape":"DescribeScheduledInstanceAvailabilityMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. This value can be between 5 and 300. The default value is 300. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        },
        "MaxSlotDurationInHours":{
          "shape":"Integer",
          "documentation":"<p>The maximum available duration, in hours. This value must be greater than <code>MinSlotDurationInHours</code> and less than 1,720.</p>"
        },
        "MinSlotDurationInHours":{
          "shape":"Integer",
          "documentation":"<p>The minimum available duration, in hours. The minimum required duration is 1,200 hours per year. For example, the minimum daily schedule is 4 hours, the minimum weekly schedule is 24 hours, and the minimum monthly schedule is 100 hours.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        },
        "Recurrence":{
          "shape":"ScheduledInstanceRecurrenceRequest",
          "documentation":"<p>The schedule recurrence.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeScheduledInstanceAvailability.</p>"
    },
    "DescribeScheduledInstanceAvailabilityResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token required to retrieve the next set of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "ScheduledInstanceAvailabilitySet":{
          "shape":"ScheduledInstanceAvailabilitySet",
          "documentation":"<p>Information about the available Scheduled Instances.</p>",
          "locationName":"scheduledInstanceAvailabilitySet"
        }
      },
      "documentation":"<p>Contains the output of DescribeScheduledInstanceAvailability.</p>"
    },
    "DescribeScheduledInstancesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone (for example, <code>us-west-2a</code>).</p> </li> <li> <p> <code>instance-type</code> - The instance type (for example, <code>c4.large</code>).</p> </li> <li> <p> <code>network-platform</code> - The network platform (<code>EC2-Classic</code> or <code>EC2-VPC</code>).</p> </li> <li> <p> <code>platform</code> - The platform (<code>Linux/UNIX</code> or <code>Windows</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. This value can be between 5 and 300. The default value is 100. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        },
        "ScheduledInstanceIds":{
          "shape":"ScheduledInstanceIdRequestSet",
          "documentation":"<p>The Scheduled Instance IDs.</p>",
          "locationName":"ScheduledInstanceId"
        },
        "SlotStartTimeRange":{
          "shape":"SlotStartTimeRangeRequest",
          "documentation":"<p>The time period for the first schedule to start.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeScheduledInstances.</p>"
    },
    "DescribeScheduledInstancesResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token required to retrieve the next set of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "ScheduledInstanceSet":{
          "shape":"ScheduledInstanceSet",
          "documentation":"<p>Information about the Scheduled Instances.</p>",
          "locationName":"scheduledInstanceSet"
        }
      },
      "documentation":"<p>Contains the output of DescribeScheduledInstances.</p>"
    },
    "DescribeSecurityGroupReferencesRequest":{
      "type":"structure",
      "required":["GroupId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "GroupId":{
          "shape":"GroupIds",
          "documentation":"<p>The IDs of the security groups in your account.</p>"
        }
      }
    },
    "DescribeSecurityGroupReferencesResult":{
      "type":"structure",
      "members":{
        "SecurityGroupReferenceSet":{
          "shape":"SecurityGroupReferences",
          "documentation":"<p>Information about the VPCs with the referencing security groups.</p>",
          "locationName":"securityGroupReferenceSet"
        }
      }
    },
    "DescribeSecurityGroupRulesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeSecurityGroupRulesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>group-id</code> - The ID of the security group.</p> </li> <li> <p> <code>security-group-rule-id</code> - The ID of the security group rule.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "SecurityGroupRuleIds":{
          "shape":"SecurityGroupRuleIdList",
          "documentation":"<p>The IDs of the security group rules.</p>",
          "locationName":"SecurityGroupRuleId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeSecurityGroupRulesMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. This value can be between 5 and 1000. If this parameter is not specified, then all items are returned. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeSecurityGroupRulesResult":{
      "type":"structure",
      "members":{
        "SecurityGroupRules":{
          "shape":"SecurityGroupRuleList",
          "documentation":"<p>Information about security group rules.</p>",
          "locationName":"securityGroupRuleSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeSecurityGroupsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeSecurityGroupsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters. If using multiple filters for rules, the results include security groups for which any combination of rules - not necessarily a single rule - match all filters.</p> <ul> <li> <p> <code>description</code> - The description of the security group.</p> </li> <li> <p> <code>egress.ip-permission.cidr</code> - An IPv4 CIDR block for an outbound security group rule.</p> </li> <li> <p> <code>egress.ip-permission.from-port</code> - For an outbound rule, the start of port range for the TCP and UDP protocols, or an ICMP type number.</p> </li> <li> <p> <code>egress.ip-permission.group-id</code> - The ID of a security group that has been referenced in an outbound security group rule.</p> </li> <li> <p> <code>egress.ip-permission.group-name</code> - The name of a security group that is referenced in an outbound security group rule.</p> </li> <li> <p> <code>egress.ip-permission.ipv6-cidr</code> - An IPv6 CIDR block for an outbound security group rule.</p> </li> <li> <p> <code>egress.ip-permission.prefix-list-id</code> - The ID of a prefix list to which a security group rule allows outbound access.</p> </li> <li> <p> <code>egress.ip-permission.protocol</code> - The IP protocol for an outbound security group rule (<code>tcp</code> | <code>udp</code> | <code>icmp</code>, a protocol number, or -1 for all protocols).</p> </li> <li> <p> <code>egress.ip-permission.to-port</code> - For an outbound rule, the end of port range for the TCP and UDP protocols, or an ICMP code.</p> </li> <li> <p> <code>egress.ip-permission.user-id</code> - The ID of an Amazon Web Services account that has been referenced in an outbound security group rule.</p> </li> <li> <p> <code>group-id</code> - The ID of the security group. </p> </li> <li> <p> <code>group-name</code> - The name of the security group.</p> </li> <li> <p> <code>ip-permission.cidr</code> - An IPv4 CIDR block for an inbound security group rule.</p> </li> <li> <p> <code>ip-permission.from-port</code> - For an inbound rule, the start of port range for the TCP and UDP protocols, or an ICMP type number.</p> </li> <li> <p> <code>ip-permission.group-id</code> - The ID of a security group that has been referenced in an inbound security group rule.</p> </li> <li> <p> <code>ip-permission.group-name</code> - The name of a security group that is referenced in an inbound security group rule.</p> </li> <li> <p> <code>ip-permission.ipv6-cidr</code> - An IPv6 CIDR block for an inbound security group rule.</p> </li> <li> <p> <code>ip-permission.prefix-list-id</code> - The ID of a prefix list from which a security group rule allows inbound access.</p> </li> <li> <p> <code>ip-permission.protocol</code> - The IP protocol for an inbound security group rule (<code>tcp</code> | <code>udp</code> | <code>icmp</code>, a protocol number, or -1 for all protocols).</p> </li> <li> <p> <code>ip-permission.to-port</code> - For an inbound rule, the end of port range for the TCP and UDP protocols, or an ICMP code.</p> </li> <li> <p> <code>ip-permission.user-id</code> - The ID of an Amazon Web Services account that has been referenced in an inbound security group rule.</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the owner of the security group.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC specified when the security group was created.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "GroupIds":{
          "shape":"GroupIdStringList",
          "documentation":"<p>The IDs of the security groups. Required for security groups in a nondefault VPC.</p> <p>Default: Describes all of your security groups.</p>",
          "locationName":"GroupId"
        },
        "GroupNames":{
          "shape":"GroupNameStringList",
          "documentation":"<p>[EC2-Classic and default VPC only] The names of the security groups. You can specify either the security group name or the security group ID. For security groups in a nondefault VPC, use the <code>group-name</code> filter to describe security groups by name.</p> <p>Default: Describes all of your security groups.</p>",
          "locationName":"GroupName"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeSecurityGroupsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. This value can be between 5 and 1000. If this parameter is not specified, then all items are returned. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeSecurityGroupsResult":{
      "type":"structure",
      "members":{
        "SecurityGroups":{
          "shape":"SecurityGroupList",
          "documentation":"<p>Information about the security groups.</p>",
          "locationName":"securityGroupInfo"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeSnapshotAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "SnapshotId"
      ],
      "members":{
        "Attribute":{
          "shape":"SnapshotAttributeName",
          "documentation":"<p>The snapshot attribute you would like to view.</p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the EBS snapshot.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeSnapshotAttributeResult":{
      "type":"structure",
      "members":{
        "CreateVolumePermissions":{
          "shape":"CreateVolumePermissionList",
          "documentation":"<p>The users and groups that have the permissions for creating volumes from the snapshot.</p>",
          "locationName":"createVolumePermission"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>The product codes.</p>",
          "locationName":"productCodes"
        },
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the EBS snapshot.</p>",
          "locationName":"snapshotId"
        }
      }
    },
    "DescribeSnapshotTierStatusMaxResults":{"type":"integer"},
    "DescribeSnapshotTierStatusRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>snapshot-id</code> - The snapshot ID.</p> </li> <li> <p> <code>volume-id</code> - The ID of the volume the snapshot is for.</p> </li> <li> <p> <code>last-tiering-operation</code> - The state of the last archive or restore action. (<code>archival-in-progress</code> | <code>archival-completed</code> | <code>archival-failed</code> | <code>permanent-restore-in-progress</code> | <code>permanent-restore-completed</code> | <code>permanent-restore-failed</code> | <code>temporary-restore-in-progress</code> | <code>temporary-restore-completed</code> | <code>temporary-restore-failed</code>)</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeSnapshotTierStatusMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeSnapshotTierStatusResult":{
      "type":"structure",
      "members":{
        "SnapshotTierStatuses":{
          "shape":"snapshotTierStatusSet",
          "documentation":"<p>Information about the snapshot's storage tier.</p>",
          "locationName":"snapshotTierStatusSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeSnapshotsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>description</code> - A description of the snapshot.</p> </li> <li> <p> <code>encrypted</code> - Indicates whether the snapshot is encrypted (<code>true</code> | <code>false</code>)</p> </li> <li> <p> <code>owner-alias</code> - The owner alias, from an Amazon-maintained list (<code>amazon</code>). This is not the user-configured Amazon Web Services account alias set using the IAM console. We recommend that you use the related parameter instead of this filter.</p> </li> <li> <p> <code>owner-id</code> - The Amazon Web Services account ID of the owner. We recommend that you use the related parameter instead of this filter.</p> </li> <li> <p> <code>progress</code> - The progress of the snapshot, as a percentage (for example, 80%).</p> </li> <li> <p> <code>snapshot-id</code> - The snapshot ID.</p> </li> <li> <p> <code>start-time</code> - The time stamp when the snapshot was initiated.</p> </li> <li> <p> <code>status</code> - The status of the snapshot (<code>pending</code> | <code>completed</code> | <code>error</code>).</p> </li> <li> <p> <code>storage-tier</code> - The storage tier of the snapshot (<code>archive</code> | <code>standard</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>volume-id</code> - The ID of the volume the snapshot is for.</p> </li> <li> <p> <code>volume-size</code> - The size of the volume, in GiB.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of snapshots to return for this request. This value can be between 5 and 1,000; if this value is larger than 1,000, only 1,000 results are returned. If this parameter is not used, then the request returns all snapshots. You cannot specify this parameter and the snapshot IDs parameter in the same request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "OwnerIds":{
          "shape":"OwnerStringList",
          "documentation":"<p>Scopes the results to snapshots with the specified owners. You can specify a combination of Amazon Web Services account IDs, <code>self</code>, and <code>amazon</code>.</p>",
          "locationName":"Owner"
        },
        "RestorableByUserIds":{
          "shape":"RestorableByStringList",
          "documentation":"<p>The IDs of the Amazon Web Services accounts that can create volumes from the snapshot.</p>",
          "locationName":"RestorableBy"
        },
        "SnapshotIds":{
          "shape":"SnapshotIdStringList",
          "documentation":"<p>The snapshot IDs.</p> <p>Default: Describes the snapshots for which you have create volume permissions.</p>",
          "locationName":"SnapshotId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeSnapshotsResult":{
      "type":"structure",
      "members":{
        "Snapshots":{
          "shape":"SnapshotList",
          "documentation":"<p>Information about the snapshots.</p>",
          "locationName":"snapshotSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to return the next page of snapshots. This value is <code>null</code> when there are no more snapshots to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeSpotDatafeedSubscriptionRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeSpotDatafeedSubscription.</p>"
    },
    "DescribeSpotDatafeedSubscriptionResult":{
      "type":"structure",
      "members":{
        "SpotDatafeedSubscription":{
          "shape":"SpotDatafeedSubscription",
          "documentation":"<p>The Spot Instance data feed subscription.</p>",
          "locationName":"spotDatafeedSubscription"
        }
      },
      "documentation":"<p>Contains the output of DescribeSpotDatafeedSubscription.</p>"
    },
    "DescribeSpotFleetInstancesMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "DescribeSpotFleetInstancesRequest":{
      "type":"structure",
      "required":["SpotFleetRequestId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "MaxResults":{
          "shape":"DescribeSpotFleetInstancesMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "SpotFleetRequestId":{
          "shape":"SpotFleetRequestId",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeSpotFleetInstances.</p>"
    },
    "DescribeSpotFleetInstancesResponse":{
      "type":"structure",
      "members":{
        "ActiveInstances":{
          "shape":"ActiveInstanceSet",
          "documentation":"<p>The running instances. This list is refreshed periodically and might be out of date.</p>",
          "locationName":"activeInstanceSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token required to retrieve the next set of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "SpotFleetRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        }
      },
      "documentation":"<p>Contains the output of DescribeSpotFleetInstances.</p>"
    },
    "DescribeSpotFleetRequestHistoryMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "DescribeSpotFleetRequestHistoryRequest":{
      "type":"structure",
      "required":[
        "SpotFleetRequestId",
        "StartTime"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "EventType":{
          "shape":"EventType",
          "documentation":"<p>The type of events to describe. By default, all events are described.</p>",
          "locationName":"eventType"
        },
        "MaxResults":{
          "shape":"DescribeSpotFleetRequestHistoryMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "SpotFleetRequestId":{
          "shape":"SpotFleetRequestId",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The starting date and time for the events, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"startTime"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeSpotFleetRequestHistory.</p>"
    },
    "DescribeSpotFleetRequestHistoryResponse":{
      "type":"structure",
      "members":{
        "HistoryRecords":{
          "shape":"HistoryRecords",
          "documentation":"<p>Information about the events in the history of the Spot Fleet request.</p>",
          "locationName":"historyRecordSet"
        },
        "LastEvaluatedTime":{
          "shape":"DateTime",
          "documentation":"<p>The last date and time for the events, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). All records up to this time were retrieved.</p> <p>If <code>nextToken</code> indicates that there are more results, this value is not present.</p>",
          "locationName":"lastEvaluatedTime"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token required to retrieve the next set of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "SpotFleetRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The starting date and time for the events, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"startTime"
        }
      },
      "documentation":"<p>Contains the output of DescribeSpotFleetRequestHistory.</p>"
    },
    "DescribeSpotFleetRequestsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "SpotFleetRequestIds":{
          "shape":"SpotFleetRequestIdList",
          "documentation":"<p>The IDs of the Spot Fleet requests.</p>",
          "locationName":"spotFleetRequestId"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeSpotFleetRequests.</p>"
    },
    "DescribeSpotFleetRequestsResponse":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token required to retrieve the next set of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "SpotFleetRequestConfigs":{
          "shape":"SpotFleetRequestConfigSet",
          "documentation":"<p>Information about the configuration of your Spot Fleet.</p>",
          "locationName":"spotFleetRequestConfigSet"
        }
      },
      "documentation":"<p>Contains the output of DescribeSpotFleetRequests.</p>"
    },
    "DescribeSpotInstanceRequestsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>availability-zone-group</code> - The Availability Zone group.</p> </li> <li> <p> <code>create-time</code> - The time stamp when the Spot Instance request was created.</p> </li> <li> <p> <code>fault-code</code> - The fault code related to the request.</p> </li> <li> <p> <code>fault-message</code> - The fault message related to the request.</p> </li> <li> <p> <code>instance-id</code> - The ID of the instance that fulfilled the request.</p> </li> <li> <p> <code>launch-group</code> - The Spot Instance launch group.</p> </li> <li> <p> <code>launch.block-device-mapping.delete-on-termination</code> - Indicates whether the EBS volume is deleted on instance termination.</p> </li> <li> <p> <code>launch.block-device-mapping.device-name</code> - The device name for the volume in the block device mapping (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p> </li> <li> <p> <code>launch.block-device-mapping.snapshot-id</code> - The ID of the snapshot for the EBS volume.</p> </li> <li> <p> <code>launch.block-device-mapping.volume-size</code> - The size of the EBS volume, in GiB.</p> </li> <li> <p> <code>launch.block-device-mapping.volume-type</code> - The type of EBS volume: <code>gp2</code> for General Purpose SSD, <code>io1</code> or <code>io2</code> for Provisioned IOPS SSD, <code>st1</code> for Throughput Optimized HDD, <code>sc1</code>for Cold HDD, or <code>standard</code> for Magnetic.</p> </li> <li> <p> <code>launch.group-id</code> - The ID of the security group for the instance.</p> </li> <li> <p> <code>launch.group-name</code> - The name of the security group for the instance.</p> </li> <li> <p> <code>launch.image-id</code> - The ID of the AMI.</p> </li> <li> <p> <code>launch.instance-type</code> - The type of instance (for example, <code>m3.medium</code>).</p> </li> <li> <p> <code>launch.kernel-id</code> - The kernel ID.</p> </li> <li> <p> <code>launch.key-name</code> - The name of the key pair the instance launched with.</p> </li> <li> <p> <code>launch.monitoring-enabled</code> - Whether detailed monitoring is enabled for the Spot Instance.</p> </li> <li> <p> <code>launch.ramdisk-id</code> - The RAM disk ID.</p> </li> <li> <p> <code>launched-availability-zone</code> - The Availability Zone in which the request is launched.</p> </li> <li> <p> <code>network-interface.addresses.primary</code> - Indicates whether the IP address is the primary private IP address.</p> </li> <li> <p> <code>network-interface.delete-on-termination</code> - Indicates whether the network interface is deleted when the instance is terminated.</p> </li> <li> <p> <code>network-interface.description</code> - A description of the network interface.</p> </li> <li> <p> <code>network-interface.device-index</code> - The index of the device for the network interface attachment on the instance.</p> </li> <li> <p> <code>network-interface.group-id</code> - The ID of the security group associated with the network interface.</p> </li> <li> <p> <code>network-interface.network-interface-id</code> - The ID of the network interface.</p> </li> <li> <p> <code>network-interface.private-ip-address</code> - The primary private IP address of the network interface.</p> </li> <li> <p> <code>network-interface.subnet-id</code> - The ID of the subnet for the instance.</p> </li> <li> <p> <code>product-description</code> - The product description associated with the instance (<code>Linux/UNIX</code> | <code>Windows</code>).</p> </li> <li> <p> <code>spot-instance-request-id</code> - The Spot Instance request ID.</p> </li> <li> <p> <code>spot-price</code> - The maximum hourly price for any Spot Instance launched to fulfill the request.</p> </li> <li> <p> <code>state</code> - The state of the Spot Instance request (<code>open</code> | <code>active</code> | <code>closed</code> | <code>cancelled</code> | <code>failed</code>). Spot request status information can help you track your Amazon EC2 Spot Instance requests. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-request-status.html\">Spot request status</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p> </li> <li> <p> <code>status-code</code> - The short code describing the most recent evaluation of your Spot Instance request.</p> </li> <li> <p> <code>status-message</code> - The message explaining the status of the Spot Instance request.</p> </li> <li> <p> <code>tag:<key></code> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>type</code> - The type of Spot Instance request (<code>one-time</code> | <code>persistent</code>).</p> </li> <li> <p> <code>valid-from</code> - The start date of the request.</p> </li> <li> <p> <code>valid-until</code> - The end date of the request.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "SpotInstanceRequestIds":{
          "shape":"SpotInstanceRequestIdList",
          "documentation":"<p>One or more Spot Instance request IDs.</p>",
          "locationName":"SpotInstanceRequestId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next set of results. This value is <code>null</code> when there are no more results to return.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 5 and 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeSpotInstanceRequests.</p>"
    },
    "DescribeSpotInstanceRequestsResult":{
      "type":"structure",
      "members":{
        "SpotInstanceRequests":{
          "shape":"SpotInstanceRequestList",
          "documentation":"<p>One or more Spot Instance requests.</p>",
          "locationName":"spotInstanceRequestSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next set of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      },
      "documentation":"<p>Contains the output of DescribeSpotInstanceRequests.</p>"
    },
    "DescribeSpotPriceHistoryRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone for which prices should be returned.</p> </li> <li> <p> <code>instance-type</code> - The type of instance (for example, <code>m3.medium</code>).</p> </li> <li> <p> <code>product-description</code> - The product description for the Spot price (<code>Linux/UNIX</code> | <code>Red Hat Enterprise Linux</code> | <code>SUSE Linux</code> | <code>Windows</code> | <code>Linux/UNIX (Amazon VPC)</code> | <code>Red Hat Enterprise Linux (Amazon VPC)</code> | <code>SUSE Linux (Amazon VPC)</code> | <code>Windows (Amazon VPC)</code>).</p> </li> <li> <p> <code>spot-price</code> - The Spot price. The value must match exactly (or use wildcards; greater than or less than comparison is not supported).</p> </li> <li> <p> <code>timestamp</code> - The time stamp of the Spot price history, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). You can use wildcards (* and ?). Greater than or less than comparison is not supported.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>Filters the results by the specified Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "EndTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time, up to the current date, from which to stop retrieving the price history data, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"endTime"
        },
        "InstanceTypes":{
          "shape":"InstanceTypeList",
          "documentation":"<p>Filters the results by the specified instance types.</p>",
          "locationName":"InstanceType"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and 1000. The default value is 1000. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        },
        "ProductDescriptions":{
          "shape":"ProductDescriptionList",
          "documentation":"<p>Filters the results by the specified basic product descriptions.</p>",
          "locationName":"ProductDescription"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time, up to the past 90 days, from which to start retrieving the price history data, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"startTime"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeSpotPriceHistory.</p>"
    },
    "DescribeSpotPriceHistoryResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token required to retrieve the next set of results. This value is null or an empty string when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "SpotPriceHistory":{
          "shape":"SpotPriceHistoryList",
          "documentation":"<p>The historical Spot prices.</p>",
          "locationName":"spotPriceHistorySet"
        }
      },
      "documentation":"<p>Contains the output of DescribeSpotPriceHistory.</p>"
    },
    "DescribeStaleSecurityGroupsMaxResults":{
      "type":"integer",
      "max":255,
      "min":5
    },
    "DescribeStaleSecurityGroupsNextToken":{
      "type":"string",
      "max":1024,
      "min":1
    },
    "DescribeStaleSecurityGroupsRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "MaxResults":{
          "shape":"DescribeStaleSecurityGroupsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"DescribeStaleSecurityGroupsNextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        }
      }
    },
    "DescribeStaleSecurityGroupsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. If there are no additional items to return, the string is empty.</p>",
          "locationName":"nextToken"
        },
        "StaleSecurityGroupSet":{
          "shape":"StaleSecurityGroupSet",
          "documentation":"<p>Information about the stale security groups.</p>",
          "locationName":"staleSecurityGroupSet"
        }
      }
    },
    "DescribeStoreImageTasksRequest":{
      "type":"structure",
      "members":{
        "ImageIds":{
          "shape":"ImageIdList",
          "documentation":"<p>The AMI IDs for which to show progress. Up to 20 AMI IDs can be included in a request.</p>",
          "locationName":"ImageId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>task-state</code> - Returns tasks in a certain state (<code>InProgress</code> | <code>Completed</code> | <code>Failed</code>)</p> </li> <li> <p> <code>bucket</code> - Returns task information for tasks that targeted a specific bucket. For the filter value, specify the bucket name.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeStoreImageTasksRequestMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another call with the returned <code>NextToken</code> value. This value can be between 1 and 200. You cannot specify this parameter and the <code>ImageIDs</code> parameter in the same call.</p>"
        }
      }
    },
    "DescribeStoreImageTasksRequestMaxResults":{
      "type":"integer",
      "max":200,
      "min":1
    },
    "DescribeStoreImageTasksResult":{
      "type":"structure",
      "members":{
        "StoreImageTaskResults":{
          "shape":"StoreImageTaskResultSet",
          "documentation":"<p>The information about the AMI store tasks.</p>",
          "locationName":"storeImageTaskResultSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeSubnetsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeSubnetsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>availability-zone</code> - The Availability Zone for the subnet. You can also use <code>availabilityZone</code> as the filter name.</p> </li> <li> <p> <code>availability-zone-id</code> - The ID of the Availability Zone for the subnet. You can also use <code>availabilityZoneId</code> as the filter name.</p> </li> <li> <p> <code>available-ip-address-count</code> - The number of IPv4 addresses in the subnet that are available.</p> </li> <li> <p> <code>cidr-block</code> - The IPv4 CIDR block of the subnet. The CIDR block you specify must exactly match the subnet's CIDR block for information to be returned for the subnet. You can also use <code>cidr</code> or <code>cidrBlock</code> as the filter names.</p> </li> <li> <p> <code>customer-owned-ipv4-pool</code> - The customer-owned IPv4 address pool associated with the subnet.</p> </li> <li> <p> <code>default-for-az</code> - Indicates whether this is the default subnet for the Availability Zone (<code>true</code> | <code>false</code>). You can also use <code>defaultForAz</code> as the filter name.</p> </li> <li> <p> <code>enable-dns64</code> - Indicates whether DNS queries made to the Amazon-provided DNS Resolver in this subnet should return synthetic IPv6 addresses for IPv4-only destinations.</p> </li> <li> <p> <code>enable-lni-at-device-index</code> - Indicates the device position for local network interfaces in this subnet. For example, <code>1</code> indicates local network interfaces in this subnet are the secondary network interface (eth1). </p> </li> <li> <p> <code>ipv6-cidr-block-association.ipv6-cidr-block</code> - An IPv6 CIDR block associated with the subnet.</p> </li> <li> <p> <code>ipv6-cidr-block-association.association-id</code> - An association ID for an IPv6 CIDR block associated with the subnet.</p> </li> <li> <p> <code>ipv6-cidr-block-association.state</code> - The state of an IPv6 CIDR block associated with the subnet.</p> </li> <li> <p> <code>ipv6-native</code> - Indicates whether this is an IPv6 only subnet (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>map-customer-owned-ip-on-launch</code> - Indicates whether a network interface created in this subnet (including a network interface created by <a>RunInstances</a>) receives a customer-owned IPv4 address.</p> </li> <li> <p> <code>map-public-ip-on-launch</code> - Indicates whether instances launched in this subnet receive a public IPv4 address.</p> </li> <li> <p> <code>outpost-arn</code> - The Amazon Resource Name (ARN) of the Outpost.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the subnet.</p> </li> <li> <p> <code>private-dns-name-options-on-launch.hostname-type</code> - The type of hostname to assign to instances in the subnet at launch. For IPv4-only and dual-stack (IPv4 and IPv6) subnets, an instance DNS name can be based on the instance IPv4 address (ip-name) or the instance ID (resource-name). For IPv6 only subnets, an instance DNS name must be based on the instance ID (resource-name).</p> </li> <li> <p> <code>private-dns-name-options-on-launch.enable-resource-name-dns-a-record</code> - Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p> </li> <li> <p> <code>private-dns-name-options-on-launch.enable-resource-name-dns-aaaa-record</code> - Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p> </li> <li> <p> <code>state</code> - The state of the subnet (<code>pending</code> | <code>available</code>).</p> </li> <li> <p> <code>subnet-arn</code> - The Amazon Resource Name (ARN) of the subnet.</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC for the subnet.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "SubnetIds":{
          "shape":"SubnetIdStringList",
          "documentation":"<p>One or more subnet IDs.</p> <p>Default: Describes all your subnets.</p>",
          "locationName":"SubnetId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeSubnetsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeSubnetsResult":{
      "type":"structure",
      "members":{
        "Subnets":{
          "shape":"SubnetList",
          "documentation":"<p>Information about one or more subnets.</p>",
          "locationName":"subnetSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTagsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>key</code> - The tag key.</p> </li> <li> <p> <code>resource-id</code> - The ID of the resource.</p> </li> <li> <p> <code>resource-type</code> - The resource type (<code>customer-gateway</code> | <code>dedicated-host</code> | <code>dhcp-options</code> | <code>elastic-ip</code> | <code>fleet</code> | <code>fpga-image</code> | <code>host-reservation</code> | <code>image</code> | <code>instance</code> | <code>internet-gateway</code> | <code>key-pair</code> | <code>launch-template</code> | <code>natgateway</code> | <code>network-acl</code> | <code>network-interface</code> | <code>placement-group</code> | <code>reserved-instances</code> | <code>route-table</code> | <code>security-group</code> | <code>snapshot</code> | <code>spot-instances-request</code> | <code>subnet</code> | <code>volume</code> | <code>vpc</code> | <code>vpc-endpoint</code> | <code>vpc-endpoint-service</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of the tag. For example, specify \"tag:Owner\" for the filter name and \"TeamA\" for the filter value to find resources with the tag \"Owner=TeamA\".</p> </li> <li> <p> <code>value</code> - The tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. This value can be between 5 and 1000. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTagsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        },
        "Tags":{
          "shape":"TagDescriptionList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "DescribeTrafficMirrorFiltersRequest":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterIds":{
          "shape":"TrafficMirrorFilterIdList",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>",
          "locationName":"TrafficMirrorFilterId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>description</code>: The Traffic Mirror filter description.</p> </li> <li> <p> <code>traffic-mirror-filter-id</code>: The ID of the Traffic Mirror filter.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TrafficMirroringMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeTrafficMirrorFiltersResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilters":{
          "shape":"TrafficMirrorFilterSet",
          "documentation":"<p>Information about one or more Traffic Mirror filters.</p>",
          "locationName":"trafficMirrorFilterSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. The value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTrafficMirrorSessionsRequest":{
      "type":"structure",
      "members":{
        "TrafficMirrorSessionIds":{
          "shape":"TrafficMirrorSessionIdList",
          "documentation":"<p>The ID of the Traffic Mirror session.</p>",
          "locationName":"TrafficMirrorSessionId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>description</code>: The Traffic Mirror session description.</p> </li> <li> <p> <code>network-interface-id</code>: The ID of the Traffic Mirror session network interface.</p> </li> <li> <p> <code>owner-id</code>: The ID of the account that owns the Traffic Mirror session.</p> </li> <li> <p> <code>packet-length</code>: The assigned number of packets to mirror. </p> </li> <li> <p> <code>session-number</code>: The assigned session number. </p> </li> <li> <p> <code>traffic-mirror-filter-id</code>: The ID of the Traffic Mirror filter.</p> </li> <li> <p> <code>traffic-mirror-session-id</code>: The ID of the Traffic Mirror session.</p> </li> <li> <p> <code>traffic-mirror-target-id</code>: The ID of the Traffic Mirror target.</p> </li> <li> <p> <code>virtual-network-id</code>: The virtual network ID of the Traffic Mirror session.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TrafficMirroringMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeTrafficMirrorSessionsResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorSessions":{
          "shape":"TrafficMirrorSessionSet",
          "documentation":"<p>Describes one or more Traffic Mirror sessions. By default, all Traffic Mirror sessions are described. Alternatively, you can filter the results.</p>",
          "locationName":"trafficMirrorSessionSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. The value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTrafficMirrorTargetsRequest":{
      "type":"structure",
      "members":{
        "TrafficMirrorTargetIds":{
          "shape":"TrafficMirrorTargetIdList",
          "documentation":"<p>The ID of the Traffic Mirror targets.</p>",
          "locationName":"TrafficMirrorTargetId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>description</code>: The Traffic Mirror target description.</p> </li> <li> <p> <code>network-interface-id</code>: The ID of the Traffic Mirror session network interface.</p> </li> <li> <p> <code>network-load-balancer-arn</code>: The Amazon Resource Name (ARN) of the Network Load Balancer that is associated with the session.</p> </li> <li> <p> <code>owner-id</code>: The ID of the account that owns the Traffic Mirror session.</p> </li> <li> <p> <code>traffic-mirror-target-id</code>: The ID of the Traffic Mirror target.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TrafficMirroringMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "DescribeTrafficMirrorTargetsResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorTargets":{
          "shape":"TrafficMirrorTargetSet",
          "documentation":"<p>Information about one or more Traffic Mirror targets.</p>",
          "locationName":"trafficMirrorTargetSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. The value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayAttachmentsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentIds":{
          "shape":"TransitGatewayAttachmentIdStringList",
          "documentation":"<p>The IDs of the attachments.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>association.state</code> - The state of the association (<code>associating</code> | <code>associated</code> | <code>disassociating</code>).</p> </li> <li> <p> <code>association.transit-gateway-route-table-id</code> - The ID of the route table for the transit gateway.</p> </li> <li> <p> <code>resource-id</code> - The ID of the resource.</p> </li> <li> <p> <code>resource-owner-id</code> - The ID of the Amazon Web Services account that owns the resource.</p> </li> <li> <p> <code>resource-type</code> - The resource type. Valid values are <code>vpc</code> | <code>vpn</code> | <code>direct-connect-gateway</code> | <code>peering</code> | <code>connect</code>.</p> </li> <li> <p> <code>state</code> - The state of the attachment. Valid values are <code>available</code> | <code>deleted</code> | <code>deleting</code> | <code>failed</code> | <code>failing</code> | <code>initiatingRequest</code> | <code>modifying</code> | <code>pendingAcceptance</code> | <code>pending</code> | <code>rollingBack</code> | <code>rejected</code> | <code>rejecting</code>.</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the attachment.</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> <li> <p> <code>transit-gateway-owner-id</code> - The ID of the Amazon Web Services account that owns the transit gateway.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayAttachmentsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachments":{
          "shape":"TransitGatewayAttachmentList",
          "documentation":"<p>Information about the attachments.</p>",
          "locationName":"transitGatewayAttachments"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayConnectPeersRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayConnectPeerIds":{
          "shape":"TransitGatewayConnectPeerIdStringList",
          "documentation":"<p>The IDs of the Connect peers.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>state</code> - The state of the Connect peer (<code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the attachment.</p> </li> <li> <p> <code>transit-gateway-connect-peer-id</code> - The ID of the Connect peer.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayConnectPeersResult":{
      "type":"structure",
      "members":{
        "TransitGatewayConnectPeers":{
          "shape":"TransitGatewayConnectPeerList",
          "documentation":"<p>Information about the Connect peers.</p>",
          "locationName":"transitGatewayConnectPeerSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayConnectsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentIds":{
          "shape":"TransitGatewayAttachmentIdStringList",
          "documentation":"<p>The IDs of the attachments.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>options.protocol</code> - The tunnel protocol (<code>gre</code>).</p> </li> <li> <p> <code>state</code> - The state of the attachment (<code>initiating</code> | <code>initiatingRequest</code> | <code>pendingAcceptance</code> | <code>rollingBack</code> | <code>pending</code> | <code>available</code> | <code>modifying</code> | <code>deleting</code> | <code>deleted</code> | <code>failed</code> | <code>rejected</code> | <code>rejecting</code> | <code>failing</code>).</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the Connect attachment.</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> <li> <p> <code>transport-transit-gateway-attachment-id</code> - The ID of the transit gateway attachment from which the Connect attachment was created.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayConnectsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayConnects":{
          "shape":"TransitGatewayConnectList",
          "documentation":"<p>Information about the Connect attachments.</p>",
          "locationName":"transitGatewayConnectSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayMulticastDomainsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainIds":{
          "shape":"TransitGatewayMulticastDomainIdStringList",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>state</code> - The state of the transit gateway multicast domain. Valid values are <code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>.</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> <li> <p> <code>transit-gateway-multicast-domain-id</code> - The ID of the transit gateway multicast domain.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayMulticastDomainsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomains":{
          "shape":"TransitGatewayMulticastDomainList",
          "documentation":"<p>Information about the transit gateway multicast domains.</p>",
          "locationName":"transitGatewayMulticastDomains"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayPeeringAttachmentsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentIds":{
          "shape":"TransitGatewayAttachmentIdStringList",
          "documentation":"<p>One or more IDs of the transit gateway peering attachments.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the transit gateway attachment.</p> </li> <li> <p> <code>local-owner-id</code> - The ID of your Amazon Web Services account.</p> </li> <li> <p> <code>remote-owner-id</code> - The ID of the Amazon Web Services account in the remote Region that owns the transit gateway.</p> </li> <li> <p> <code>state</code> - The state of the peering attachment. Valid values are <code>available</code> | <code>deleted</code> | <code>deleting</code> | <code>failed</code> | <code>failing</code> | <code>initiatingRequest</code> | <code>modifying</code> | <code>pendingAcceptance</code> | <code>pending</code> | <code>rollingBack</code> | <code>rejected</code> | <code>rejecting</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources that have a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayPeeringAttachmentsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPeeringAttachments":{
          "shape":"TransitGatewayPeeringAttachmentList",
          "documentation":"<p>The transit gateway peering attachments.</p>",
          "locationName":"transitGatewayPeeringAttachments"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayPolicyTablesRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTableIds":{
          "shape":"TransitGatewayPolicyTableIdStringList",
          "documentation":"<p>The IDs of the transit gateway policy tables.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters associated with the transit gateway policy table.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayPolicyTablesResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTables":{
          "shape":"TransitGatewayPolicyTableList",
          "documentation":"<p>Describes the transit gateway policy tables.</p>",
          "locationName":"transitGatewayPolicyTables"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayRouteTableAnnouncementsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableAnnouncementIds":{
          "shape":"TransitGatewayRouteTableAnnouncementIdStringList",
          "documentation":"<p>The IDs of the transit gateway route tables that are being advertised.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters associated with the transit gateway policy table.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayRouteTableAnnouncementsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableAnnouncements":{
          "shape":"TransitGatewayRouteTableAnnouncementList",
          "documentation":"<p>Describes the transit gateway route table announcement.</p>",
          "locationName":"transitGatewayRouteTableAnnouncements"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayRouteTablesRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableIds":{
          "shape":"TransitGatewayRouteTableIdStringList",
          "documentation":"<p>The IDs of the transit gateway route tables.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>default-association-route-table</code> - Indicates whether this is the default association route table for the transit gateway (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>default-propagation-route-table</code> - Indicates whether this is the default propagation route table for the transit gateway (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>state</code> - The state of the route table (<code>available</code> | <code>deleting</code> | <code>deleted</code> | <code>pending</code>).</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> <li> <p> <code>transit-gateway-route-table-id</code> - The ID of the transit gateway route table.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayRouteTablesResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTables":{
          "shape":"TransitGatewayRouteTableList",
          "documentation":"<p>Information about the transit gateway route tables.</p>",
          "locationName":"transitGatewayRouteTables"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewayVpcAttachmentsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentIds":{
          "shape":"TransitGatewayAttachmentIdStringList",
          "documentation":"<p>The IDs of the attachments.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>state</code> - The state of the attachment. Valid values are <code>available</code> | <code>deleted</code> | <code>deleting</code> | <code>failed</code> | <code>failing</code> | <code>initiatingRequest</code> | <code>modifying</code> | <code>pendingAcceptance</code> | <code>pending</code> | <code>rollingBack</code> | <code>rejected</code> | <code>rejecting</code>.</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the attachment.</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewayVpcAttachmentsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayVpcAttachments":{
          "shape":"TransitGatewayVpcAttachmentList",
          "documentation":"<p>Information about the VPC attachments.</p>",
          "locationName":"transitGatewayVpcAttachments"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTransitGatewaysRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayIds":{
          "shape":"TransitGatewayIdStringList",
          "documentation":"<p>The IDs of the transit gateways.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>options.propagation-default-route-table-id</code> - The ID of the default propagation route table.</p> </li> <li> <p> <code>options.amazon-side-asn</code> - The private ASN for the Amazon side of a BGP session.</p> </li> <li> <p> <code>options.association-default-route-table-id</code> - The ID of the default association route table.</p> </li> <li> <p> <code>options.auto-accept-shared-attachments</code> - Indicates whether there is automatic acceptance of attachment requests (<code>enable</code> | <code>disable</code>).</p> </li> <li> <p> <code>options.default-route-table-association</code> - Indicates whether resource attachments are automatically associated with the default association route table (<code>enable</code> | <code>disable</code>).</p> </li> <li> <p> <code>options.default-route-table-propagation</code> - Indicates whether resource attachments automatically propagate routes to the default propagation route table (<code>enable</code> | <code>disable</code>).</p> </li> <li> <p> <code>options.dns-support</code> - Indicates whether DNS support is enabled (<code>enable</code> | <code>disable</code>).</p> </li> <li> <p> <code>options.vpn-ecmp-support</code> - Indicates whether Equal Cost Multipath Protocol support is enabled (<code>enable</code> | <code>disable</code>).</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the transit gateway.</p> </li> <li> <p> <code>state</code> - The state of the transit gateway (<code>available</code> | <code>deleted</code> | <code>deleting</code> | <code>modifying</code> | <code>pending</code>).</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of the transit gateway.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeTransitGatewaysResult":{
      "type":"structure",
      "members":{
        "TransitGateways":{
          "shape":"TransitGatewayList",
          "documentation":"<p>Information about the transit gateways.</p>",
          "locationName":"transitGatewaySet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeTrunkInterfaceAssociationsMaxResults":{
      "type":"integer",
      "max":255,
      "min":5
    },
    "DescribeTrunkInterfaceAssociationsRequest":{
      "type":"structure",
      "members":{
        "AssociationIds":{
          "shape":"TrunkInterfaceAssociationIdList",
          "documentation":"<p>The IDs of the associations.</p>",
          "locationName":"AssociationId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>gre-key</code> - The ID of a trunk interface association.</p> </li> <li> <p> <code>interface-protocol</code> - The interface protocol. Valid values are <code>VLAN</code> and <code>GRE</code>.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"DescribeTrunkInterfaceAssociationsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        }
      }
    },
    "DescribeTrunkInterfaceAssociationsResult":{
      "type":"structure",
      "members":{
        "InterfaceAssociations":{
          "shape":"TrunkInterfaceAssociationList",
          "documentation":"<p>Information about the trunk associations.</p>",
          "locationName":"interfaceAssociationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVerifiedAccessEndpointsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeVerifiedAccessEndpointsRequest":{
      "type":"structure",
      "members":{
        "VerifiedAccessEndpointIds":{
          "shape":"VerifiedAccessEndpointIdList",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"VerifiedAccessEndpointId"
        },
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>"
        },
        "MaxResults":{
          "shape":"DescribeVerifiedAccessEndpointsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeVerifiedAccessEndpointsResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessEndpoints":{
          "shape":"VerifiedAccessEndpointList",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"verifiedAccessEndpointSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVerifiedAccessGroupMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeVerifiedAccessGroupsRequest":{
      "type":"structure",
      "members":{
        "VerifiedAccessGroupIds":{
          "shape":"VerifiedAccessGroupIdList",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access groups.</p>",
          "locationName":"VerifiedAccessGroupId"
        },
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "MaxResults":{
          "shape":"DescribeVerifiedAccessGroupMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeVerifiedAccessGroupsResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessGroups":{
          "shape":"VerifiedAccessGroupList",
          "documentation":"<p>The ID of the Verified Access group.</p>",
          "locationName":"verifiedAccessGroupSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVerifiedAccessInstanceLoggingConfigurationsMaxResults":{
      "type":"integer",
      "max":10,
      "min":1
    },
    "DescribeVerifiedAccessInstanceLoggingConfigurationsRequest":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstanceIds":{
          "shape":"VerifiedAccessInstanceIdList",
          "documentation":"<p>The IDs of the Amazon Web Services Verified Access instances.</p>",
          "locationName":"VerifiedAccessInstanceId"
        },
        "MaxResults":{
          "shape":"DescribeVerifiedAccessInstanceLoggingConfigurationsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeVerifiedAccessInstanceLoggingConfigurationsResult":{
      "type":"structure",
      "members":{
        "LoggingConfigurations":{
          "shape":"VerifiedAccessInstanceLoggingConfigurationList",
          "documentation":"<p>The current logging configuration for the Amazon Web Services Verified Access instances.</p>",
          "locationName":"loggingConfigurationSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVerifiedAccessInstancesMaxResults":{
      "type":"integer",
      "max":200,
      "min":5
    },
    "DescribeVerifiedAccessInstancesRequest":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstanceIds":{
          "shape":"VerifiedAccessInstanceIdList",
          "documentation":"<p>The IDs of the Amazon Web Services Verified Access instances.</p>",
          "locationName":"VerifiedAccessInstanceId"
        },
        "MaxResults":{
          "shape":"DescribeVerifiedAccessInstancesMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeVerifiedAccessInstancesResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstances":{
          "shape":"VerifiedAccessInstanceList",
          "documentation":"<p>The IDs of the Amazon Web Services Verified Access instances.</p>",
          "locationName":"verifiedAccessInstanceSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVerifiedAccessTrustProvidersMaxResults":{
      "type":"integer",
      "max":200,
      "min":5
    },
    "DescribeVerifiedAccessTrustProvidersRequest":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProviderIds":{
          "shape":"VerifiedAccessTrustProviderIdList",
          "documentation":"<p>The IDs of the Amazon Web Services Verified Access trust providers.</p>",
          "locationName":"VerifiedAccessTrustProviderId"
        },
        "MaxResults":{
          "shape":"DescribeVerifiedAccessTrustProvidersMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. Filter names and values are case-sensitive.</p>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DescribeVerifiedAccessTrustProvidersResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProviders":{
          "shape":"VerifiedAccessTrustProviderList",
          "documentation":"<p>The IDs of the Amazon Web Services Verified Access trust providers.</p>",
          "locationName":"verifiedAccessTrustProviderSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVolumeAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "VolumeId"
      ],
      "members":{
        "Attribute":{
          "shape":"VolumeAttributeName",
          "documentation":"<p>The attribute of the volume. This parameter is required.</p>"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the volume.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeVolumeAttributeResult":{
      "type":"structure",
      "members":{
        "AutoEnableIO":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>The state of <code>autoEnableIO</code> attribute.</p>",
          "locationName":"autoEnableIO"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>A list of product codes.</p>",
          "locationName":"productCodes"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume.</p>",
          "locationName":"volumeId"
        }
      }
    },
    "DescribeVolumeStatusRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>action.code</code> - The action code for the event (for example, <code>enable-volume-io</code>).</p> </li> <li> <p> <code>action.description</code> - A description of the action.</p> </li> <li> <p> <code>action.event-id</code> - The event ID associated with the action.</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone of the instance.</p> </li> <li> <p> <code>event.description</code> - A description of the event.</p> </li> <li> <p> <code>event.event-id</code> - The event ID.</p> </li> <li> <p> <code>event.event-type</code> - The event type (for <code>io-enabled</code>: <code>passed</code> | <code>failed</code>; for <code>io-performance</code>: <code>io-performance:degraded</code> | <code>io-performance:severely-degraded</code> | <code>io-performance:stalled</code>).</p> </li> <li> <p> <code>event.not-after</code> - The latest end time for the event.</p> </li> <li> <p> <code>event.not-before</code> - The earliest start time for the event.</p> </li> <li> <p> <code>volume-status.details-name</code> - The cause for <code>volume-status.status</code> (<code>io-enabled</code> | <code>io-performance</code>).</p> </li> <li> <p> <code>volume-status.details-status</code> - The status of <code>volume-status.details-name</code> (for <code>io-enabled</code>: <code>passed</code> | <code>failed</code>; for <code>io-performance</code>: <code>normal</code> | <code>degraded</code> | <code>severely-degraded</code> | <code>stalled</code>).</p> </li> <li> <p> <code>volume-status.status</code> - The status of the volume (<code>ok</code> | <code>impaired</code> | <code>warning</code> | <code>insufficient-data</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. This value can be between 5 and 1,000; if the value is larger than 1,000, only 1,000 results are returned. If this parameter is not used, then all items are returned. You cannot specify this parameter and the volume IDs parameter in the same request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "VolumeIds":{
          "shape":"VolumeIdStringList",
          "documentation":"<p>The IDs of the volumes.</p> <p>Default: Describes all your volumes.</p>",
          "locationName":"VolumeId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeVolumeStatusResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        },
        "VolumeStatuses":{
          "shape":"VolumeStatusList",
          "documentation":"<p>Information about the status of the volumes.</p>",
          "locationName":"volumeStatusSet"
        }
      }
    },
    "DescribeVolumesModificationsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VolumeIds":{
          "shape":"VolumeIdStringList",
          "documentation":"<p>The IDs of the volumes.</p>",
          "locationName":"VolumeId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>modification-state</code> - The current modification state (modifying | optimizing | completed | failed).</p> </li> <li> <p> <code>original-iops</code> - The original IOPS rate of the volume.</p> </li> <li> <p> <code>original-size</code> - The original size of the volume, in GiB.</p> </li> <li> <p> <code>original-volume-type</code> - The original volume type of the volume (standard | io1 | io2 | gp2 | sc1 | st1).</p> </li> <li> <p> <code>originalMultiAttachEnabled</code> - Indicates whether Multi-Attach support was enabled (true | false).</p> </li> <li> <p> <code>start-time</code> - The modification start time.</p> </li> <li> <p> <code>target-iops</code> - The target IOPS rate of the volume.</p> </li> <li> <p> <code>target-size</code> - The target size of the volume, in GiB.</p> </li> <li> <p> <code>target-volume-type</code> - The target volume type of the volume (standard | io1 | io2 | gp2 | sc1 | st1).</p> </li> <li> <p> <code>targetMultiAttachEnabled</code> - Indicates whether Multi-Attach support is to be enabled (true | false).</p> </li> <li> <p> <code>volume-id</code> - The ID of the volume.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned by a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results (up to a limit of 500) to be returned in a paginated request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeVolumesModificationsResult":{
      "type":"structure",
      "members":{
        "VolumesModifications":{
          "shape":"VolumeModificationList",
          "documentation":"<p>Information about the volume modifications.</p>",
          "locationName":"volumeModificationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> if there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVolumesRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>attachment.attach-time</code> - The time stamp when the attachment initiated.</p> </li> <li> <p> <code>attachment.delete-on-termination</code> - Whether the volume is deleted on instance termination.</p> </li> <li> <p> <code>attachment.device</code> - The device name specified in the block device mapping (for example, <code>/dev/sda1</code>).</p> </li> <li> <p> <code>attachment.instance-id</code> - The ID of the instance the volume is attached to.</p> </li> <li> <p> <code>attachment.status</code> - The attachment state (<code>attaching</code> | <code>attached</code> | <code>detaching</code>).</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone in which the volume was created.</p> </li> <li> <p> <code>create-time</code> - The time stamp when the volume was created.</p> </li> <li> <p> <code>encrypted</code> - Indicates whether the volume is encrypted (<code>true</code> | <code>false</code>)</p> </li> <li> <p> <code>multi-attach-enabled</code> - Indicates whether the volume is enabled for Multi-Attach (<code>true</code> | <code>false</code>)</p> </li> <li> <p> <code>fast-restored</code> - Indicates whether the volume was created from a snapshot that is enabled for fast snapshot restore (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>size</code> - The size of the volume, in GiB.</p> </li> <li> <p> <code>snapshot-id</code> - The snapshot from which the volume was created.</p> </li> <li> <p> <code>status</code> - The state of the volume (<code>creating</code> | <code>available</code> | <code>in-use</code> | <code>deleting</code> | <code>deleted</code> | <code>error</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>volume-id</code> - The volume ID.</p> </li> <li> <p> <code>volume-type</code> - The Amazon EBS volume type (<code>gp2</code> | <code>gp3</code> | <code>io1</code> | <code>io2</code> | <code>st1</code> | <code>sc1</code>| <code>standard</code>)</p> </li> </ul>",
          "locationName":"Filter"
        },
        "VolumeIds":{
          "shape":"VolumeIdStringList",
          "documentation":"<p>The volume IDs.</p>",
          "locationName":"VolumeId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of volumes to return for this request. This value can be between 5 and 500; if you specify a value larger than 500, only 500 items are returned. If this parameter is not used, then all items are returned. You cannot specify this parameter and the volume IDs parameter in the same request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned from the previous request.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVolumesResult":{
      "type":"structure",
      "members":{
        "Volumes":{
          "shape":"VolumeList",
          "documentation":"<p>Information about the volumes.</p>",
          "locationName":"volumeSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "VpcId"
      ],
      "members":{
        "Attribute":{
          "shape":"VpcAttributeName",
          "documentation":"<p>The VPC attribute.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DescribeVpcAttributeResult":{
      "type":"structure",
      "members":{
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "EnableDnsHostnames":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether the instances launched in the VPC get DNS hostnames. If this attribute is <code>true</code>, instances in the VPC get DNS hostnames; otherwise, they do not.</p>",
          "locationName":"enableDnsHostnames"
        },
        "EnableDnsSupport":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether DNS resolution is enabled for the VPC. If this attribute is <code>true</code>, the Amazon DNS server resolves DNS hostnames for your instances to their corresponding IP addresses; otherwise, it does not.</p>",
          "locationName":"enableDnsSupport"
        },
        "EnableNetworkAddressUsageMetrics":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether Network Address Usage metrics are enabled for your VPC.</p>",
          "locationName":"enableNetworkAddressUsageMetrics"
        }
      }
    },
    "DescribeVpcClassicLinkDnsSupportMaxResults":{
      "type":"integer",
      "max":255,
      "min":5
    },
    "DescribeVpcClassicLinkDnsSupportNextToken":{
      "type":"string",
      "max":1024,
      "min":1
    },
    "DescribeVpcClassicLinkDnsSupportRequest":{
      "type":"structure",
      "members":{
        "MaxResults":{
          "shape":"DescribeVpcClassicLinkDnsSupportMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>",
          "locationName":"maxResults"
        },
        "NextToken":{
          "shape":"DescribeVpcClassicLinkDnsSupportNextToken",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>",
          "locationName":"nextToken"
        },
        "VpcIds":{
          "shape":"VpcClassicLinkIdList",
          "documentation":"<p>One or more VPC IDs.</p>"
        }
      }
    },
    "DescribeVpcClassicLinkDnsSupportResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"DescribeVpcClassicLinkDnsSupportNextToken",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        },
        "Vpcs":{
          "shape":"ClassicLinkDnsSupportList",
          "documentation":"<p>Information about the ClassicLink DNS support status of the VPCs.</p>",
          "locationName":"vpcs"
        }
      }
    },
    "DescribeVpcClassicLinkRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>is-classic-link-enabled</code> - Whether the VPC is enabled for ClassicLink (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcIds":{
          "shape":"VpcClassicLinkIdList",
          "documentation":"<p>One or more VPCs for which you want to describe the ClassicLink status.</p>",
          "locationName":"VpcId"
        }
      }
    },
    "DescribeVpcClassicLinkResult":{
      "type":"structure",
      "members":{
        "Vpcs":{
          "shape":"VpcClassicLinkList",
          "documentation":"<p>The ClassicLink status of one or more VPCs.</p>",
          "locationName":"vpcSet"
        }
      }
    },
    "DescribeVpcEndpointConnectionNotificationsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ConnectionNotificationId":{
          "shape":"ConnectionNotificationId",
          "documentation":"<p>The ID of the notification.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>connection-notification-arn</code> - The ARN of the SNS topic for the notification.</p> </li> <li> <p> <code>connection-notification-id</code> - The ID of the notification.</p> </li> <li> <p> <code>connection-notification-state</code> - The state of the notification (<code>Enabled</code> | <code>Disabled</code>).</p> </li> <li> <p> <code>connection-notification-type</code> - The type of notification (<code>Topic</code>).</p> </li> <li> <p> <code>service-id</code> - The ID of the endpoint service.</p> </li> <li> <p> <code>vpc-endpoint-id</code> - The ID of the VPC endpoint.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. To retrieve the remaining results, make another request with the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to request the next page of results.</p>"
        }
      }
    },
    "DescribeVpcEndpointConnectionNotificationsResult":{
      "type":"structure",
      "members":{
        "ConnectionNotificationSet":{
          "shape":"ConnectionNotificationSet",
          "documentation":"<p>The notifications.</p>",
          "locationName":"connectionNotificationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcEndpointConnectionsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>ip-address-type</code> - The IP address type (<code>ipv4</code> | <code>ipv6</code>).</p> </li> <li> <p> <code>service-id</code> - The ID of the service.</p> </li> <li> <p> <code>vpc-endpoint-owner</code> - The ID of the Amazon Web Services account ID that owns the endpoint.</p> </li> <li> <p> <code>vpc-endpoint-state</code> - The state of the endpoint (<code>pendingAcceptance</code> | <code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code> | <code>rejected</code> | <code>failed</code>).</p> </li> <li> <p> <code>vpc-endpoint-id</code> - The ID of the endpoint.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results of the initial request can be seen by sending another request with the returned <code>NextToken</code> value. This value can be between 5 and 1,000; if <code>MaxResults</code> is given a value larger than 1,000, only 1,000 results are returned.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        }
      }
    },
    "DescribeVpcEndpointConnectionsResult":{
      "type":"structure",
      "members":{
        "VpcEndpointConnections":{
          "shape":"VpcEndpointConnectionSet",
          "documentation":"<p>Information about the VPC endpoint connections.</p>",
          "locationName":"vpcEndpointConnectionSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcEndpointServiceConfigurationsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceIds":{
          "shape":"VpcEndpointServiceIdList",
          "documentation":"<p>The IDs of the endpoint services.</p>",
          "locationName":"ServiceId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>service-name</code> - The name of the service.</p> </li> <li> <p> <code>service-id</code> - The ID of the service.</p> </li> <li> <p> <code>service-state</code> - The state of the service (<code>Pending</code> | <code>Available</code> | <code>Deleting</code> | <code>Deleted</code> | <code>Failed</code>). </p> </li> <li> <p> <code>supported-ip-address-types</code> - The IP address type (<code>ipv4</code> | <code>ipv6</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results of the initial request can be seen by sending another request with the returned <code>NextToken</code> value. This value can be between 5 and 1,000; if <code>MaxResults</code> is given a value larger than 1,000, only 1,000 results are returned.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        }
      }
    },
    "DescribeVpcEndpointServiceConfigurationsResult":{
      "type":"structure",
      "members":{
        "ServiceConfigurations":{
          "shape":"ServiceConfigurationSet",
          "documentation":"<p>Information about the services.</p>",
          "locationName":"serviceConfigurationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcEndpointServicePermissionsRequest":{
      "type":"structure",
      "required":["ServiceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the service.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>principal</code> - The ARN of the principal.</p> </li> <li> <p> <code>principal-type</code> - The principal type (<code>All</code> | <code>Service</code> | <code>OrganizationUnit</code> | <code>Account</code> | <code>User</code> | <code>Role</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results of the initial request can be seen by sending another request with the returned <code>NextToken</code> value. This value can be between 5 and 1,000; if <code>MaxResults</code> is given a value larger than 1,000, only 1,000 results are returned.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to retrieve the next page of results.</p>"
        }
      }
    },
    "DescribeVpcEndpointServicePermissionsResult":{
      "type":"structure",
      "members":{
        "AllowedPrincipals":{
          "shape":"AllowedPrincipalSet",
          "documentation":"<p>Information about the allowed principals.</p>",
          "locationName":"allowedPrincipals"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcEndpointServicesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceNames":{
          "shape":"ValueStringList",
          "documentation":"<p>The service names.</p>",
          "locationName":"ServiceName"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>owner</code> - The ID or alias of the Amazon Web Services account that owns the service.</p> </li> <li> <p> <code>service-name</code> - The name of the service.</p> </li> <li> <p> <code>service-type</code> - The type of service (<code>Interface</code> | <code>Gateway</code> | <code>GatewayLoadBalancer</code>).</p> </li> <li> <p> <code>supported-ip-address-types</code> - The IP address type (<code>ipv4</code> | <code>ipv6</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. The request returns a token that you can specify in a subsequent call to get the next set of results.</p> <p>Constraint: If the value is greater than 1,000, we return only 1,000 items.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of items to return. (You received this token from a prior call.)</p>"
        }
      }
    },
    "DescribeVpcEndpointServicesResult":{
      "type":"structure",
      "members":{
        "ServiceNames":{
          "shape":"ValueStringList",
          "documentation":"<p>The supported services.</p>",
          "locationName":"serviceNameSet"
        },
        "ServiceDetails":{
          "shape":"ServiceDetailSet",
          "documentation":"<p>Information about the service.</p>",
          "locationName":"serviceDetailSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use when requesting the next set of items. If there are no additional items to return, the string is empty.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcEndpointsRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VpcEndpointIds":{
          "shape":"VpcEndpointIdList",
          "documentation":"<p>The IDs of the VPC endpoints.</p>",
          "locationName":"VpcEndpointId"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters.</p> <ul> <li> <p> <code>ip-address-type</code> - The IP address type (<code>ipv4</code> | <code>ipv6</code>).</p> </li> <li> <p> <code>service-name</code> - The name of the service.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC in which the endpoint resides.</p> </li> <li> <p> <code>vpc-endpoint-id</code> - The ID of the endpoint.</p> </li> <li> <p> <code>vpc-endpoint-state</code> - The state of the endpoint (<code>pendingAcceptance</code> | <code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code> | <code>rejected</code> | <code>failed</code>).</p> </li> <li> <p> <code>vpc-endpoint-type</code> - The type of VPC endpoint (<code>Interface</code> | <code>Gateway</code> | <code>GatewayLoadBalancer</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of items to return for this request. The request returns a token that you can specify in a subsequent call to get the next set of results.</p> <p>Constraint: If the value is greater than 1,000, we return only 1,000 items.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of items to return. (You received this token from a prior call.)</p>"
        }
      }
    },
    "DescribeVpcEndpointsResult":{
      "type":"structure",
      "members":{
        "VpcEndpoints":{
          "shape":"VpcEndpointSet",
          "documentation":"<p>Information about the endpoints.</p>",
          "locationName":"vpcEndpointSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use when requesting the next set of items. If there are no additional items to return, the string is empty.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcPeeringConnectionsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeVpcPeeringConnectionsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>accepter-vpc-info.cidr-block</code> - The IPv4 CIDR block of the accepter VPC.</p> </li> <li> <p> <code>accepter-vpc-info.owner-id</code> - The ID of the Amazon Web Services account that owns the accepter VPC.</p> </li> <li> <p> <code>accepter-vpc-info.vpc-id</code> - The ID of the accepter VPC.</p> </li> <li> <p> <code>expiration-time</code> - The expiration date and time for the VPC peering connection.</p> </li> <li> <p> <code>requester-vpc-info.cidr-block</code> - The IPv4 CIDR block of the requester's VPC.</p> </li> <li> <p> <code>requester-vpc-info.owner-id</code> - The ID of the Amazon Web Services account that owns the requester VPC.</p> </li> <li> <p> <code>requester-vpc-info.vpc-id</code> - The ID of the requester VPC.</p> </li> <li> <p> <code>status-code</code> - The status of the VPC peering connection (<code>pending-acceptance</code> | <code>failed</code> | <code>expired</code> | <code>provisioning</code> | <code>active</code> | <code>deleting</code> | <code>deleted</code> | <code>rejected</code>).</p> </li> <li> <p> <code>status-message</code> - A message that provides more information about the status of the VPC peering connection, if applicable.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-peering-connection-id</code> - The ID of the VPC peering connection.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcPeeringConnectionIds":{
          "shape":"VpcPeeringConnectionIdList",
          "documentation":"<p>One or more VPC peering connection IDs.</p> <p>Default: Describes all your VPC peering connections.</p>",
          "locationName":"VpcPeeringConnectionId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeVpcPeeringConnectionsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeVpcPeeringConnectionsResult":{
      "type":"structure",
      "members":{
        "VpcPeeringConnections":{
          "shape":"VpcPeeringConnectionList",
          "documentation":"<p>Information about the VPC peering connections.</p>",
          "locationName":"vpcPeeringConnectionSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpcsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "DescribeVpcsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>cidr</code> - The primary IPv4 CIDR block of the VPC. The CIDR block you specify must exactly match the VPC's CIDR block for information to be returned for the VPC. Must contain the slash followed by one or two digits (for example, <code>/28</code>).</p> </li> <li> <p> <code>cidr-block-association.cidr-block</code> - An IPv4 CIDR block associated with the VPC.</p> </li> <li> <p> <code>cidr-block-association.association-id</code> - The association ID for an IPv4 CIDR block associated with the VPC.</p> </li> <li> <p> <code>cidr-block-association.state</code> - The state of an IPv4 CIDR block associated with the VPC.</p> </li> <li> <p> <code>dhcp-options-id</code> - The ID of a set of DHCP options.</p> </li> <li> <p> <code>ipv6-cidr-block-association.ipv6-cidr-block</code> - An IPv6 CIDR block associated with the VPC.</p> </li> <li> <p> <code>ipv6-cidr-block-association.ipv6-pool</code> - The ID of the IPv6 address pool from which the IPv6 CIDR block is allocated.</p> </li> <li> <p> <code>ipv6-cidr-block-association.association-id</code> - The association ID for an IPv6 CIDR block associated with the VPC.</p> </li> <li> <p> <code>ipv6-cidr-block-association.state</code> - The state of an IPv6 CIDR block associated with the VPC.</p> </li> <li> <p> <code>is-default</code> - Indicates whether the VPC is the default VPC.</p> </li> <li> <p> <code>owner-id</code> - The ID of the Amazon Web Services account that owns the VPC.</p> </li> <li> <p> <code>state</code> - The state of the VPC (<code>pending</code> | <code>available</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>vpc-id</code> - The ID of the VPC.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "VpcIds":{
          "shape":"VpcIdStringList",
          "documentation":"<p>One or more VPC IDs.</p> <p>Default: Describes all your VPCs.</p>",
          "locationName":"VpcId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "MaxResults":{
          "shape":"DescribeVpcsMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        }
      }
    },
    "DescribeVpcsResult":{
      "type":"structure",
      "members":{
        "Vpcs":{
          "shape":"VpcList",
          "documentation":"<p>Information about one or more VPCs.</p>",
          "locationName":"vpcSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "DescribeVpnConnectionsRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>customer-gateway-configuration</code> - The configuration information for the customer gateway.</p> </li> <li> <p> <code>customer-gateway-id</code> - The ID of a customer gateway associated with the VPN connection.</p> </li> <li> <p> <code>state</code> - The state of the VPN connection (<code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>option.static-routes-only</code> - Indicates whether the connection has static routes only. Used for devices that do not support Border Gateway Protocol (BGP).</p> </li> <li> <p> <code>route.destination-cidr-block</code> - The destination CIDR block. This corresponds to the subnet used in a customer data center.</p> </li> <li> <p> <code>bgp-asn</code> - The BGP Autonomous System Number (ASN) associated with a BGP device.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>type</code> - The type of VPN connection. Currently the only supported type is <code>ipsec.1</code>.</p> </li> <li> <p> <code>vpn-connection-id</code> - The ID of the VPN connection.</p> </li> <li> <p> <code>vpn-gateway-id</code> - The ID of a virtual private gateway associated with the VPN connection.</p> </li> <li> <p> <code>transit-gateway-id</code> - The ID of a transit gateway associated with the VPN connection.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "VpnConnectionIds":{
          "shape":"VpnConnectionIdStringList",
          "documentation":"<p>One or more VPN connection IDs.</p> <p>Default: Describes your VPN connections.</p>",
          "locationName":"VpnConnectionId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeVpnConnections.</p>"
    },
    "DescribeVpnConnectionsResult":{
      "type":"structure",
      "members":{
        "VpnConnections":{
          "shape":"VpnConnectionList",
          "documentation":"<p>Information about one or more VPN connections.</p>",
          "locationName":"vpnConnectionSet"
        }
      },
      "documentation":"<p>Contains the output of DescribeVpnConnections.</p>"
    },
    "DescribeVpnGatewaysRequest":{
      "type":"structure",
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>amazon-side-asn</code> - The Autonomous System Number (ASN) for the Amazon side of the gateway.</p> </li> <li> <p> <code>attachment.state</code> - The current state of the attachment between the gateway and the VPC (<code>attaching</code> | <code>attached</code> | <code>detaching</code> | <code>detached</code>).</p> </li> <li> <p> <code>attachment.vpc-id</code> - The ID of an attached VPC.</p> </li> <li> <p> <code>availability-zone</code> - The Availability Zone for the virtual private gateway (if applicable).</p> </li> <li> <p> <code>state</code> - The state of the virtual private gateway (<code>pending</code> | <code>available</code> | <code>deleting</code> | <code>deleted</code>).</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> <li> <p> <code>type</code> - The type of virtual private gateway. Currently the only supported type is <code>ipsec.1</code>.</p> </li> <li> <p> <code>vpn-gateway-id</code> - The ID of the virtual private gateway.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "VpnGatewayIds":{
          "shape":"VpnGatewayIdStringList",
          "documentation":"<p>One or more virtual private gateway IDs.</p> <p>Default: Describes all your virtual private gateways.</p>",
          "locationName":"VpnGatewayId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DescribeVpnGateways.</p>"
    },
    "DescribeVpnGatewaysResult":{
      "type":"structure",
      "members":{
        "VpnGateways":{
          "shape":"VpnGatewayList",
          "documentation":"<p>Information about one or more virtual private gateways.</p>",
          "locationName":"vpnGatewaySet"
        }
      },
      "documentation":"<p>Contains the output of DescribeVpnGateways.</p>"
    },
    "DestinationFileFormat":{
      "type":"string",
      "enum":[
        "plain-text",
        "parquet"
      ]
    },
    "DestinationOptionsRequest":{
      "type":"structure",
      "members":{
        "FileFormat":{
          "shape":"DestinationFileFormat",
          "documentation":"<p>The format for the flow log. The default is <code>plain-text</code>.</p>"
        },
        "HiveCompatiblePartitions":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to use Hive-compatible prefixes for flow logs stored in Amazon S3. The default is <code>false</code>.</p>"
        },
        "PerHourPartition":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to partition the flow log per hour. This reduces the cost and response time for queries. The default is <code>false</code>.</p>"
        }
      },
      "documentation":"<p>Describes the destination options for a flow log.</p>"
    },
    "DestinationOptionsResponse":{
      "type":"structure",
      "members":{
        "FileFormat":{
          "shape":"DestinationFileFormat",
          "documentation":"<p>The format for the flow log.</p>",
          "locationName":"fileFormat"
        },
        "HiveCompatiblePartitions":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to use Hive-compatible prefixes for flow logs stored in Amazon S3.</p>",
          "locationName":"hiveCompatiblePartitions"
        },
        "PerHourPartition":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to partition the flow log per hour.</p>",
          "locationName":"perHourPartition"
        }
      },
      "documentation":"<p>Describes the destination options for a flow log.</p>"
    },
    "DetachClassicLinkVpcRequest":{
      "type":"structure",
      "required":[
        "InstanceId",
        "VpcId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance to unlink from the VPC.</p>",
          "locationName":"instanceId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC to which the instance is linked.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "DetachClassicLinkVpcResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "DetachInternetGatewayRequest":{
      "type":"structure",
      "required":[
        "InternetGatewayId",
        "VpcId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InternetGatewayId":{
          "shape":"InternetGatewayId",
          "documentation":"<p>The ID of the internet gateway.</p>",
          "locationName":"internetGatewayId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "DetachNetworkInterfaceRequest":{
      "type":"structure",
      "required":["AttachmentId"],
      "members":{
        "AttachmentId":{
          "shape":"NetworkInterfaceAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"attachmentId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Force":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether to force a detachment.</p> <note> <ul> <li> <p>Use the <code>Force</code> parameter only as a last resort to detach a network interface from a failed instance. </p> </li> <li> <p>If you use the <code>Force</code> parameter to detach a network interface, you might not be able to attach a different network interface to the same index on the instance without first stopping and starting the instance.</p> </li> <li> <p>If you force the detachment of a network interface, the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">instance metadata</a> might not get updated. This means that the attributes associated with the detached network interface might still be visible. The instance metadata will get updated when you stop and start the instance.</p> </li> </ul> </note>",
          "locationName":"force"
        }
      },
      "documentation":"<p>Contains the parameters for DetachNetworkInterface.</p>"
    },
    "DetachVerifiedAccessTrustProviderRequest":{
      "type":"structure",
      "required":[
        "VerifiedAccessInstanceId",
        "VerifiedAccessTrustProviderId"
      ],
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "VerifiedAccessTrustProviderId":{
          "shape":"VerifiedAccessTrustProviderId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DetachVerifiedAccessTrustProviderResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProvider":{
          "shape":"VerifiedAccessTrustProvider",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"verifiedAccessTrustProvider"
        },
        "VerifiedAccessInstance":{
          "shape":"VerifiedAccessInstance",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstance"
        }
      }
    },
    "DetachVolumeRequest":{
      "type":"structure",
      "required":["VolumeId"],
      "members":{
        "Device":{
          "shape":"String",
          "documentation":"<p>The device name.</p>"
        },
        "Force":{
          "shape":"Boolean",
          "documentation":"<p>Forces detachment if the previous detachment attempt did not occur cleanly (for example, logging into an instance, unmounting the volume, and detaching normally). This option can lead to data loss or a corrupted file system. Use this option only as a last resort to detach a volume from a failed instance. The instance won't have an opportunity to flush file system caches or file system metadata. If you use this option, you must perform file system check and repair procedures.</p>"
        },
        "InstanceId":{
          "shape":"InstanceIdForResolver",
          "documentation":"<p>The ID of the instance. If you are detaching a Multi-Attach enabled volume, you must specify an instance ID.</p>"
        },
        "VolumeId":{
          "shape":"VolumeIdWithResolver",
          "documentation":"<p>The ID of the volume.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DetachVpnGatewayRequest":{
      "type":"structure",
      "required":[
        "VpcId",
        "VpnGatewayId"
      ],
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "VpnGatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for DetachVpnGateway.</p>"
    },
    "DeviceOptions":{
      "type":"structure",
      "members":{
        "TenantId":{
          "shape":"String",
          "documentation":"<p>The ID of the tenant application with the device-identity provider.</p>",
          "locationName":"tenantId"
        }
      },
      "documentation":"<p>Options for an Amazon Web Services Verified Access device-identity based trust provider.</p>"
    },
    "DeviceTrustProviderType":{
      "type":"string",
      "enum":[
        "jamf",
        "crowdstrike"
      ]
    },
    "DeviceType":{
      "type":"string",
      "enum":[
        "ebs",
        "instance-store"
      ]
    },
    "DhcpConfiguration":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "documentation":"<p>The name of a DHCP option.</p>",
          "locationName":"key"
        },
        "Values":{
          "shape":"DhcpConfigurationValueList",
          "documentation":"<p>One or more values for the DHCP option.</p>",
          "locationName":"valueSet"
        }
      },
      "documentation":"<p>Describes a DHCP configuration option.</p>"
    },
    "DhcpConfigurationList":{
      "type":"list",
      "member":{
        "shape":"DhcpConfiguration",
        "locationName":"item"
      }
    },
    "DhcpConfigurationValueList":{
      "type":"list",
      "member":{
        "shape":"AttributeValue",
        "locationName":"item"
      }
    },
    "DhcpOptions":{
      "type":"structure",
      "members":{
        "DhcpConfigurations":{
          "shape":"DhcpConfigurationList",
          "documentation":"<p>One or more DHCP options in the set.</p>",
          "locationName":"dhcpConfigurationSet"
        },
        "DhcpOptionsId":{
          "shape":"String",
          "documentation":"<p>The ID of the set of DHCP options.</p>",
          "locationName":"dhcpOptionsId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the DHCP options set.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the DHCP options set.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a set of DHCP options.</p>"
    },
    "DhcpOptionsId":{"type":"string"},
    "DhcpOptionsIdStringList":{
      "type":"list",
      "member":{
        "shape":"DhcpOptionsId",
        "locationName":"DhcpOptionsId"
      }
    },
    "DhcpOptionsList":{
      "type":"list",
      "member":{
        "shape":"DhcpOptions",
        "locationName":"item"
      }
    },
    "DirectoryServiceAuthentication":{
      "type":"structure",
      "members":{
        "DirectoryId":{
          "shape":"String",
          "documentation":"<p>The ID of the Active Directory used for authentication.</p>",
          "locationName":"directoryId"
        }
      },
      "documentation":"<p>Describes an Active Directory.</p>"
    },
    "DirectoryServiceAuthenticationRequest":{
      "type":"structure",
      "members":{
        "DirectoryId":{
          "shape":"String",
          "documentation":"<p>The ID of the Active Directory to be used for authentication.</p>"
        }
      },
      "documentation":"<p>Describes the Active Directory to be used for client authentication.</p>"
    },
    "DisableAddressTransferRequest":{
      "type":"structure",
      "required":["AllocationId"],
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>The allocation ID of an Elastic IP address.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableAddressTransferResult":{
      "type":"structure",
      "members":{
        "AddressTransfer":{
          "shape":"AddressTransfer",
          "documentation":"<p>An Elastic IP address transfer.</p>",
          "locationName":"addressTransfer"
        }
      }
    },
    "DisableAwsNetworkPerformanceMetricSubscriptionRequest":{
      "type":"structure",
      "members":{
        "Source":{
          "shape":"String",
          "documentation":"<p>The source Region or Availability Zone that the metric subscription is disabled for. For example, <code>us-east-1</code>.</p>"
        },
        "Destination":{
          "shape":"String",
          "documentation":"<p>The target Region or Availability Zone that the metric subscription is disabled for. For example, <code>eu-north-1</code>.</p>"
        },
        "Metric":{
          "shape":"MetricType",
          "documentation":"<p>The metric used for the disabled subscription.</p>"
        },
        "Statistic":{
          "shape":"StatisticType",
          "documentation":"<p>The statistic used for the disabled subscription. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableAwsNetworkPerformanceMetricSubscriptionResult":{
      "type":"structure",
      "members":{
        "Output":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the unsubscribe action was successful.</p>",
          "locationName":"output"
        }
      }
    },
    "DisableEbsEncryptionByDefaultRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableEbsEncryptionByDefaultResult":{
      "type":"structure",
      "members":{
        "EbsEncryptionByDefault":{
          "shape":"Boolean",
          "documentation":"<p>The updated status of encryption by default.</p>",
          "locationName":"ebsEncryptionByDefault"
        }
      }
    },
    "DisableFastLaunchRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the image for which you’re turning off faster launching, and removing pre-provisioned snapshots.</p>"
        },
        "Force":{
          "shape":"Boolean",
          "documentation":"<p>Forces the image settings to turn off faster launching for your Windows AMI. This parameter overrides any errors that are encountered while cleaning up resources in your account.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableFastLaunchResult":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the image for which faster-launching has been turned off.</p>",
          "locationName":"imageId"
        },
        "ResourceType":{
          "shape":"FastLaunchResourceType",
          "documentation":"<p>The pre-provisioning resource type that must be cleaned after turning off faster launching for the Windows AMI. Supported values include: <code>snapshot</code>.</p>",
          "locationName":"resourceType"
        },
        "SnapshotConfiguration":{
          "shape":"FastLaunchSnapshotConfigurationResponse",
          "documentation":"<p>Parameters that were used for faster launching for the Windows AMI before faster launching was turned off. This informs the clean-up process.</p>",
          "locationName":"snapshotConfiguration"
        },
        "LaunchTemplate":{
          "shape":"FastLaunchLaunchTemplateSpecificationResponse",
          "documentation":"<p>The launch template that was used to launch Windows instances from pre-provisioned snapshots.</p>",
          "locationName":"launchTemplate"
        },
        "MaxParallelLaunches":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of parallel instances to launch for creating resources.</p>",
          "locationName":"maxParallelLaunches"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The owner of the Windows AMI for which faster launching was turned off.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"FastLaunchStateCode",
          "documentation":"<p>The current state of faster launching for the specified Windows AMI.</p>",
          "locationName":"state"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason that the state changed for faster launching for the Windows AMI.</p>",
          "locationName":"stateTransitionReason"
        },
        "StateTransitionTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time that the state changed for faster launching for the Windows AMI.</p>",
          "locationName":"stateTransitionTime"
        }
      }
    },
    "DisableFastSnapshotRestoreErrorItem":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "FastSnapshotRestoreStateErrors":{
          "shape":"DisableFastSnapshotRestoreStateErrorSet",
          "documentation":"<p>The errors.</p>",
          "locationName":"fastSnapshotRestoreStateErrorSet"
        }
      },
      "documentation":"<p>Contains information about the errors that occurred when disabling fast snapshot restores.</p>"
    },
    "DisableFastSnapshotRestoreErrorSet":{
      "type":"list",
      "member":{
        "shape":"DisableFastSnapshotRestoreErrorItem",
        "locationName":"item"
      }
    },
    "DisableFastSnapshotRestoreStateError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes an error that occurred when disabling fast snapshot restores.</p>"
    },
    "DisableFastSnapshotRestoreStateErrorItem":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "Error":{
          "shape":"DisableFastSnapshotRestoreStateError",
          "documentation":"<p>The error.</p>",
          "locationName":"error"
        }
      },
      "documentation":"<p>Contains information about an error that occurred when disabling fast snapshot restores.</p>"
    },
    "DisableFastSnapshotRestoreStateErrorSet":{
      "type":"list",
      "member":{
        "shape":"DisableFastSnapshotRestoreStateErrorItem",
        "locationName":"item"
      }
    },
    "DisableFastSnapshotRestoreSuccessItem":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "State":{
          "shape":"FastSnapshotRestoreStateCode",
          "documentation":"<p>The state of fast snapshot restores for the snapshot.</p>",
          "locationName":"state"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason for the state transition. The possible values are as follows:</p> <ul> <li> <p> <code>Client.UserInitiated</code> - The state successfully transitioned to <code>enabling</code> or <code>disabling</code>.</p> </li> <li> <p> <code>Client.UserInitiated - Lifecycle state transition</code> - The state successfully transitioned to <code>optimizing</code>, <code>enabled</code>, or <code>disabled</code>.</p> </li> </ul>",
          "locationName":"stateTransitionReason"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that enabled fast snapshot restores on the snapshot.</p>",
          "locationName":"ownerId"
        },
        "OwnerAlias":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services owner alias that enabled fast snapshot restores on the snapshot. This is intended for future use.</p>",
          "locationName":"ownerAlias"
        },
        "EnablingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>enabling</code> state.</p>",
          "locationName":"enablingTime"
        },
        "OptimizingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>optimizing</code> state.</p>",
          "locationName":"optimizingTime"
        },
        "EnabledTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>enabled</code> state.</p>",
          "locationName":"enabledTime"
        },
        "DisablingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>disabling</code> state.</p>",
          "locationName":"disablingTime"
        },
        "DisabledTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>disabled</code> state.</p>",
          "locationName":"disabledTime"
        }
      },
      "documentation":"<p>Describes fast snapshot restores that were successfully disabled.</p>"
    },
    "DisableFastSnapshotRestoreSuccessSet":{
      "type":"list",
      "member":{
        "shape":"DisableFastSnapshotRestoreSuccessItem",
        "locationName":"item"
      }
    },
    "DisableFastSnapshotRestoresRequest":{
      "type":"structure",
      "required":[
        "AvailabilityZones",
        "SourceSnapshotIds"
      ],
      "members":{
        "AvailabilityZones":{
          "shape":"AvailabilityZoneStringList",
          "documentation":"<p>One or more Availability Zones. For example, <code>us-east-2a</code>.</p>",
          "locationName":"AvailabilityZone"
        },
        "SourceSnapshotIds":{
          "shape":"SnapshotIdStringList",
          "documentation":"<p>The IDs of one or more snapshots. For example, <code>snap-1234567890abcdef0</code>.</p>",
          "locationName":"SourceSnapshotId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableFastSnapshotRestoresResult":{
      "type":"structure",
      "members":{
        "Successful":{
          "shape":"DisableFastSnapshotRestoreSuccessSet",
          "documentation":"<p>Information about the snapshots for which fast snapshot restores were successfully disabled.</p>",
          "locationName":"successful"
        },
        "Unsuccessful":{
          "shape":"DisableFastSnapshotRestoreErrorSet",
          "documentation":"<p>Information about the snapshots for which fast snapshot restores could not be disabled.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "DisableImageDeprecationRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableImageDeprecationResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "DisableIpamOrganizationAdminAccountRequest":{
      "type":"structure",
      "required":["DelegatedAdminAccountId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "DelegatedAdminAccountId":{
          "shape":"String",
          "documentation":"<p>The Organizations member account ID that you want to disable as IPAM account.</p>"
        }
      }
    },
    "DisableIpamOrganizationAdminAccountResult":{
      "type":"structure",
      "members":{
        "Success":{
          "shape":"Boolean",
          "documentation":"<p>The result of disabling the IPAM account.</p>",
          "locationName":"success"
        }
      }
    },
    "DisableSerialConsoleAccessRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisableSerialConsoleAccessResult":{
      "type":"structure",
      "members":{
        "SerialConsoleAccessEnabled":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, access to the EC2 serial console of all instances is enabled for your account. If <code>false</code>, access to the EC2 serial console of all instances is disabled for your account.</p>",
          "locationName":"serialConsoleAccessEnabled"
        }
      }
    },
    "DisableTransitGatewayRouteTablePropagationRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableId"],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the propagation route table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The ID of the route table announcement.</p>"
        }
      }
    },
    "DisableTransitGatewayRouteTablePropagationResult":{
      "type":"structure",
      "members":{
        "Propagation":{
          "shape":"TransitGatewayPropagation",
          "documentation":"<p>Information about route propagation.</p>",
          "locationName":"propagation"
        }
      }
    },
    "DisableVgwRoutePropagationRequest":{
      "type":"structure",
      "required":[
        "GatewayId",
        "RouteTableId"
      ],
      "members":{
        "GatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway.</p>"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for DisableVgwRoutePropagation.</p>"
    },
    "DisableVpcClassicLinkDnsSupportRequest":{
      "type":"structure",
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        }
      }
    },
    "DisableVpcClassicLinkDnsSupportResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "DisableVpcClassicLinkRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "DisableVpcClassicLinkResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "DisassociateAddressRequest":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"ElasticIpAssociationId",
          "documentation":"<p>[EC2-VPC] The association ID. Required for EC2-VPC.</p>"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>[EC2-Classic] The Elastic IP address. Required for EC2-Classic.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DisassociateClientVpnTargetNetworkRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "AssociationId"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint from which to disassociate the target network.</p>"
        },
        "AssociationId":{
          "shape":"ClientVpnAssociationId",
          "documentation":"<p>The ID of the target network association.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateClientVpnTargetNetworkResult":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the target network association.</p>",
          "locationName":"associationId"
        },
        "Status":{
          "shape":"AssociationStatus",
          "documentation":"<p>The current state of the target network association.</p>",
          "locationName":"status"
        }
      }
    },
    "DisassociateEnclaveCertificateIamRoleRequest":{
      "type":"structure",
      "required":[
        "CertificateArn",
        "RoleArn"
      ],
      "members":{
        "CertificateArn":{
          "shape":"CertificateId",
          "documentation":"<p>The ARN of the ACM certificate from which to disassociate the IAM role.</p>"
        },
        "RoleArn":{
          "shape":"RoleId",
          "documentation":"<p>The ARN of the IAM role to disassociate.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateEnclaveCertificateIamRoleResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "DisassociateIamInstanceProfileRequest":{
      "type":"structure",
      "required":["AssociationId"],
      "members":{
        "AssociationId":{
          "shape":"IamInstanceProfileAssociationId",
          "documentation":"<p>The ID of the IAM instance profile association.</p>"
        }
      }
    },
    "DisassociateIamInstanceProfileResult":{
      "type":"structure",
      "members":{
        "IamInstanceProfileAssociation":{
          "shape":"IamInstanceProfileAssociation",
          "documentation":"<p>Information about the IAM instance profile association.</p>",
          "locationName":"iamInstanceProfileAssociation"
        }
      }
    },
    "DisassociateInstanceEventWindowRequest":{
      "type":"structure",
      "required":[
        "InstanceEventWindowId",
        "AssociationTarget"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceEventWindowId":{
          "shape":"InstanceEventWindowId",
          "documentation":"<p>The ID of the event window.</p>"
        },
        "AssociationTarget":{
          "shape":"InstanceEventWindowDisassociationRequest",
          "documentation":"<p>One or more targets to disassociate from the specified event window.</p>"
        }
      }
    },
    "DisassociateInstanceEventWindowResult":{
      "type":"structure",
      "members":{
        "InstanceEventWindow":{
          "shape":"InstanceEventWindow",
          "documentation":"<p>Information about the event window.</p>",
          "locationName":"instanceEventWindow"
        }
      }
    },
    "DisassociateIpamResourceDiscoveryRequest":{
      "type":"structure",
      "required":["IpamResourceDiscoveryAssociationId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryAssociationId":{
          "shape":"IpamResourceDiscoveryAssociationId",
          "documentation":"<p>A resource discovery association ID.</p>"
        }
      }
    },
    "DisassociateIpamResourceDiscoveryResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscoveryAssociation":{
          "shape":"IpamResourceDiscoveryAssociation",
          "documentation":"<p>A resource discovery association.</p>",
          "locationName":"ipamResourceDiscoveryAssociation"
        }
      }
    },
    "DisassociateNatGatewayAddressRequest":{
      "type":"structure",
      "required":[
        "NatGatewayId",
        "AssociationIds"
      ],
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>"
        },
        "AssociationIds":{
          "shape":"EipAssociationIdList",
          "documentation":"<p>The association IDs of EIPs that have been associated with the NAT gateway.</p>",
          "locationName":"AssociationId"
        },
        "MaxDrainDurationSeconds":{
          "shape":"DrainSeconds",
          "documentation":"<p>The maximum amount of time to wait (in seconds) before forcibly releasing the IP addresses if connections are still in progress. Default value is 350 seconds.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateNatGatewayAddressResult":{
      "type":"structure",
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>",
          "locationName":"natGatewayId"
        },
        "NatGatewayAddresses":{
          "shape":"NatGatewayAddressList",
          "documentation":"<p>Information about the NAT gateway IP addresses.</p>",
          "locationName":"natGatewayAddressSet"
        }
      }
    },
    "DisassociateRouteTableRequest":{
      "type":"structure",
      "required":["AssociationId"],
      "members":{
        "AssociationId":{
          "shape":"RouteTableAssociationId",
          "documentation":"<p>The association ID representing the current association between the route table and subnet or gateway.</p>",
          "locationName":"associationId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "DisassociateSubnetCidrBlockRequest":{
      "type":"structure",
      "required":["AssociationId"],
      "members":{
        "AssociationId":{
          "shape":"SubnetCidrAssociationId",
          "documentation":"<p>The association ID for the CIDR block.</p>",
          "locationName":"associationId"
        }
      }
    },
    "DisassociateSubnetCidrBlockResult":{
      "type":"structure",
      "members":{
        "Ipv6CidrBlockAssociation":{
          "shape":"SubnetIpv6CidrBlockAssociation",
          "documentation":"<p>Information about the IPv6 CIDR block association.</p>",
          "locationName":"ipv6CidrBlockAssociation"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        }
      }
    },
    "DisassociateTransitGatewayMulticastDomainRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayMulticastDomainId",
        "TransitGatewayAttachmentId",
        "SubnetIds"
      ],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "SubnetIds":{
          "shape":"TransitGatewaySubnetIdList",
          "documentation":"<p>The IDs of the subnets;</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateTransitGatewayMulticastDomainResult":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"TransitGatewayMulticastDomainAssociations",
          "documentation":"<p>Information about the association.</p>",
          "locationName":"associations"
        }
      }
    },
    "DisassociateTransitGatewayPolicyTableRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayPolicyTableId",
        "TransitGatewayAttachmentId"
      ],
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The ID of the disassociated policy table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment to disassociate from the policy table.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateTransitGatewayPolicyTableResult":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"TransitGatewayPolicyTableAssociation",
          "documentation":"<p>Returns details about the transit gateway policy table disassociation.</p>",
          "locationName":"association"
        }
      }
    },
    "DisassociateTransitGatewayRouteTableRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "TransitGatewayAttachmentId"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateTransitGatewayRouteTableResult":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"TransitGatewayAssociation",
          "documentation":"<p>Information about the association.</p>",
          "locationName":"association"
        }
      }
    },
    "DisassociateTrunkInterfaceRequest":{
      "type":"structure",
      "required":["AssociationId"],
      "members":{
        "AssociationId":{
          "shape":"TrunkInterfaceAssociationId",
          "documentation":"<p>The ID of the association</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to Ensure Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "DisassociateTrunkInterfaceResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to Ensure Idempotency</a>.</p>",
          "locationName":"clientToken"
        }
      }
    },
    "DisassociateVpcCidrBlockRequest":{
      "type":"structure",
      "required":["AssociationId"],
      "members":{
        "AssociationId":{
          "shape":"VpcCidrAssociationId",
          "documentation":"<p>The association ID for the CIDR block.</p>",
          "locationName":"associationId"
        }
      }
    },
    "DisassociateVpcCidrBlockResult":{
      "type":"structure",
      "members":{
        "Ipv6CidrBlockAssociation":{
          "shape":"VpcIpv6CidrBlockAssociation",
          "documentation":"<p>Information about the IPv6 CIDR block association.</p>",
          "locationName":"ipv6CidrBlockAssociation"
        },
        "CidrBlockAssociation":{
          "shape":"VpcCidrBlockAssociation",
          "documentation":"<p>Information about the IPv4 CIDR block association.</p>",
          "locationName":"cidrBlockAssociation"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "DiskCount":{"type":"integer"},
    "DiskImage":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the disk image.</p>"
        },
        "Image":{
          "shape":"DiskImageDetail",
          "documentation":"<p>Information about the disk image.</p>"
        },
        "Volume":{
          "shape":"VolumeDetail",
          "documentation":"<p>Information about the volume.</p>"
        }
      },
      "documentation":"<p>Describes a disk image.</p>"
    },
    "DiskImageDescription":{
      "type":"structure",
      "members":{
        "Checksum":{
          "shape":"String",
          "documentation":"<p>The checksum computed for the disk image.</p>",
          "locationName":"checksum"
        },
        "Format":{
          "shape":"DiskImageFormat",
          "documentation":"<p>The disk image format.</p>",
          "locationName":"format"
        },
        "ImportManifestUrl":{
          "shape":"String",
          "documentation":"<p>A presigned URL for the import manifest stored in Amazon S3. For information about creating a presigned URL for an Amazon S3 object, read the \"Query String Request Authentication Alternative\" section of the <a href=\"https://docs.aws.amazon.com/AmazonS3/latest/dev/RESTAuthentication.html\">Authenticating REST Requests</a> topic in the <i>Amazon Simple Storage Service Developer Guide</i>.</p> <p>For information about the import manifest referenced by this API action, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/manifest.html\">VM Import Manifest</a>.</p>",
          "locationName":"importManifestUrl"
        },
        "Size":{
          "shape":"Long",
          "documentation":"<p>The size of the disk image, in GiB.</p>",
          "locationName":"size"
        }
      },
      "documentation":"<p>Describes a disk image.</p>"
    },
    "DiskImageDetail":{
      "type":"structure",
      "required":[
        "Bytes",
        "Format",
        "ImportManifestUrl"
      ],
      "members":{
        "Bytes":{
          "shape":"Long",
          "documentation":"<p>The size of the disk image, in GiB.</p>",
          "locationName":"bytes"
        },
        "Format":{
          "shape":"DiskImageFormat",
          "documentation":"<p>The disk image format.</p>",
          "locationName":"format"
        },
        "ImportManifestUrl":{
          "shape":"String",
          "documentation":"<p>A presigned URL for the import manifest stored in Amazon S3 and presented here as an Amazon S3 presigned URL. For information about creating a presigned URL for an Amazon S3 object, read the \"Query String Request Authentication Alternative\" section of the <a href=\"https://docs.aws.amazon.com/AmazonS3/latest/dev/RESTAuthentication.html\">Authenticating REST Requests</a> topic in the <i>Amazon Simple Storage Service Developer Guide</i>.</p> <p>For information about the import manifest referenced by this API action, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/manifest.html\">VM Import Manifest</a>.</p>",
          "locationName":"importManifestUrl"
        }
      },
      "documentation":"<p>Describes a disk image.</p>"
    },
    "DiskImageFormat":{
      "type":"string",
      "enum":[
        "VMDK",
        "RAW",
        "VHD"
      ]
    },
    "DiskImageList":{
      "type":"list",
      "member":{"shape":"DiskImage"}
    },
    "DiskImageVolumeDescription":{
      "type":"structure",
      "members":{
        "Id":{
          "shape":"String",
          "documentation":"<p>The volume identifier.</p>",
          "locationName":"id"
        },
        "Size":{
          "shape":"Long",
          "documentation":"<p>The size of the volume, in GiB.</p>",
          "locationName":"size"
        }
      },
      "documentation":"<p>Describes a disk image volume.</p>"
    },
    "DiskInfo":{
      "type":"structure",
      "members":{
        "SizeInGB":{
          "shape":"DiskSize",
          "documentation":"<p>The size of the disk in GB.</p>",
          "locationName":"sizeInGB"
        },
        "Count":{
          "shape":"DiskCount",
          "documentation":"<p>The number of disks with this configuration.</p>",
          "locationName":"count"
        },
        "Type":{
          "shape":"DiskType",
          "documentation":"<p>The type of disk.</p>",
          "locationName":"type"
        }
      },
      "documentation":"<p>Describes a disk.</p>"
    },
    "DiskInfoList":{
      "type":"list",
      "member":{
        "shape":"DiskInfo",
        "locationName":"item"
      }
    },
    "DiskSize":{"type":"long"},
    "DiskType":{
      "type":"string",
      "enum":[
        "hdd",
        "ssd"
      ]
    },
    "DnsEntry":{
      "type":"structure",
      "members":{
        "DnsName":{
          "shape":"String",
          "documentation":"<p>The DNS name.</p>",
          "locationName":"dnsName"
        },
        "HostedZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the private hosted zone.</p>",
          "locationName":"hostedZoneId"
        }
      },
      "documentation":"<p>Describes a DNS entry.</p>"
    },
    "DnsEntrySet":{
      "type":"list",
      "member":{
        "shape":"DnsEntry",
        "locationName":"item"
      }
    },
    "DnsNameState":{
      "type":"string",
      "enum":[
        "pendingVerification",
        "verified",
        "failed"
      ]
    },
    "DnsOptions":{
      "type":"structure",
      "members":{
        "DnsRecordIpType":{
          "shape":"DnsRecordIpType",
          "documentation":"<p>The DNS records created for the endpoint.</p>",
          "locationName":"dnsRecordIpType"
        }
      },
      "documentation":"<p>Describes the DNS options for an endpoint.</p>"
    },
    "DnsOptionsSpecification":{
      "type":"structure",
      "members":{
        "DnsRecordIpType":{
          "shape":"DnsRecordIpType",
          "documentation":"<p>The DNS records created for the endpoint.</p>"
        }
      },
      "documentation":"<p>Describes the DNS options for an endpoint.</p>"
    },
    "DnsRecordIpType":{
      "type":"string",
      "enum":[
        "ipv4",
        "dualstack",
        "ipv6",
        "service-defined"
      ]
    },
    "DnsServersOptionsModifyStructure":{
      "type":"structure",
      "members":{
        "CustomDnsServers":{
          "shape":"ValueStringList",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the DNS servers to be used. You can specify up to two DNS servers. Ensure that the DNS servers can be reached by the clients. The specified values overwrite the existing values.</p>"
        },
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether DNS servers should be used. Specify <code>False</code> to delete the existing DNS servers.</p>"
        }
      },
      "documentation":"<p>Information about the DNS server to be used.</p>"
    },
    "DnsSupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "DomainType":{
      "type":"string",
      "enum":[
        "vpc",
        "standard"
      ]
    },
    "Double":{"type":"double"},
    "DoubleWithConstraints":{
      "type":"double",
      "max":99.999,
      "min":0.001
    },
    "DrainSeconds":{
      "type":"integer",
      "max":4000,
      "min":1
    },
    "DynamicRoutingValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "EbsBlockDevice":{
      "type":"structure",
      "members":{
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the EBS volume is deleted on instance termination. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/terminating-instances.html#preserving-volumes-on-termination\">Preserving Amazon EBS volumes on instance termination</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"deleteOnTermination"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The number of I/O operations per second (IOPS). For <code>gp3</code>, <code>io1</code>, and <code>io2</code> volumes, this represents the number of IOPS that are provisioned for the volume. For <code>gp2</code> volumes, this represents the baseline performance of the volume and the rate at which the volume accumulates I/O credits for bursting.</p> <p>The following are the supported values for each volume type:</p> <ul> <li> <p> <code>gp3</code>: 3,000-16,000 IOPS</p> </li> <li> <p> <code>io1</code>: 100-64,000 IOPS</p> </li> <li> <p> <code>io2</code>: 100-64,000 IOPS</p> </li> </ul> <p>For <code>io1</code> and <code>io2</code> volumes, we guarantee 64,000 IOPS only for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">Instances built on the Nitro System</a>. Other instance families guarantee performance up to 32,000 IOPS.</p> <p>This parameter is required for <code>io1</code> and <code>io2</code> volumes. The default for <code>gp3</code> volumes is 3,000 IOPS. This parameter is not supported for <code>gp2</code>, <code>st1</code>, <code>sc1</code>, or <code>standard</code> volumes.</p>",
          "locationName":"iops"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiBs. You must specify either a snapshot ID or a volume size. If you specify a snapshot, the default is the snapshot size. You can specify a volume size that is equal to or larger than the snapshot size.</p> <p>The following are the supported volumes sizes for each volume type:</p> <ul> <li> <p> <code>gp2</code> and <code>gp3</code>:1-16,384</p> </li> <li> <p> <code>io1</code> and <code>io2</code>: 4-16,384</p> </li> <li> <p> <code>st1</code> and <code>sc1</code>: 125-16,384</p> </li> <li> <p> <code>standard</code>: 1-1,024</p> </li> </ul>",
          "locationName":"volumeSize"
        },
        "VolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The volume type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html\">Amazon EBS volume types</a> in the <i>Amazon EC2 User Guide</i>. If the volume type is <code>io1</code> or <code>io2</code>, you must specify the IOPS that the volume supports.</p>",
          "locationName":"volumeType"
        },
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>Identifier (key ID, key alias, ID ARN, or alias ARN) for a customer managed CMK under which the EBS volume is encrypted.</p> <p>This parameter is only supported on <code>BlockDeviceMapping</code> objects called by <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html\">RunInstances</a>, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotFleet.html\">RequestSpotFleet</a>, and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotInstances.html\">RequestSpotInstances</a>.</p>",
          "locationName":"kmsKeyId"
        },
        "Throughput":{
          "shape":"Integer",
          "documentation":"<p>The throughput that the volume supports, in MiB/s.</p> <p>This parameter is valid only for <code>gp3</code> volumes.</p> <p>Valid Range: Minimum value of 125. Maximum value of 1000.</p>",
          "locationName":"throughput"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Outpost on which the snapshot is stored.</p> <p>This parameter is only supported on <code>BlockDeviceMapping</code> objects called by <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateImage.html\"> CreateImage</a>.</p>",
          "locationName":"outpostArn"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the encryption state of an EBS volume is changed while being restored from a backing snapshot. The effect of setting the encryption state to <code>true</code> depends on the volume origin (new or from a snapshot), starting encryption state, ownership, and whether encryption by default is enabled. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html#encryption-parameters\">Amazon EBS encryption</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>In no case can you remove encryption from an encrypted volume.</p> <p>Encrypted volumes can only be attached to instances that support Amazon EBS encryption. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html#EBSEncryption_supported_instances\">Supported instance types</a>.</p> <p>This parameter is not returned by <a>DescribeImageAttribute</a>.</p> <p>For <a>CreateImage</a> and <a>RegisterImage</a>, whether you can include this parameter, and the allowed values differ depending on the type of block device mapping you are creating.</p> <ul> <li> <p>If you are creating a block device mapping for a <b>new (empty) volume</b>, you can include this parameter, and specify either <code>true</code> for an encrypted volume, or <code>false</code> for an unencrypted volume. If you omit this parameter, it defaults to <code>false</code> (unencrypted).</p> </li> <li> <p>If you are creating a block device mapping from an <b>existing encrypted or unencrypted snapshot</b>, you must omit this parameter. If you include this parameter, the request will fail, regardless of the value that you specify.</p> </li> <li> <p>If you are creating a block device mapping from an <b>existing unencrypted volume</b>, you can include this parameter, but you must specify <code>false</code>. If you specify <code>true</code>, the request will fail. In this case, we recommend that you omit the parameter.</p> </li> <li> <p>If you are creating a block device mapping from an <b>existing encrypted volume</b>, you can include this parameter, and specify either <code>true</code> or <code>false</code>. However, if you specify <code>false</code>, the parameter is ignored and the block device mapping is always encrypted. In this case, we recommend that you omit the parameter.</p> </li> </ul>",
          "locationName":"encrypted"
        }
      },
      "documentation":"<p>Describes a block device for an EBS volume.</p>"
    },
    "EbsEncryptionSupport":{
      "type":"string",
      "enum":[
        "unsupported",
        "supported"
      ]
    },
    "EbsInfo":{
      "type":"structure",
      "members":{
        "EbsOptimizedSupport":{
          "shape":"EbsOptimizedSupport",
          "documentation":"<p>Indicates whether the instance type is Amazon EBS-optimized. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSOptimized.html\">Amazon EBS-optimized instances</a> in <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"ebsOptimizedSupport"
        },
        "EncryptionSupport":{
          "shape":"EbsEncryptionSupport",
          "documentation":"<p>Indicates whether Amazon EBS encryption is supported.</p>",
          "locationName":"encryptionSupport"
        },
        "EbsOptimizedInfo":{
          "shape":"EbsOptimizedInfo",
          "documentation":"<p>Describes the optimized EBS performance for the instance type.</p>",
          "locationName":"ebsOptimizedInfo"
        },
        "NvmeSupport":{
          "shape":"EbsNvmeSupport",
          "documentation":"<p>Indicates whether non-volatile memory express (NVMe) is supported.</p>",
          "locationName":"nvmeSupport"
        }
      },
      "documentation":"<p>Describes the Amazon EBS features supported by the instance type.</p>"
    },
    "EbsInstanceBlockDevice":{
      "type":"structure",
      "members":{
        "AttachTime":{
          "shape":"DateTime",
          "documentation":"<p>The time stamp when the attachment initiated.</p>",
          "locationName":"attachTime"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume is deleted on instance termination.</p>",
          "locationName":"deleteOnTermination"
        },
        "Status":{
          "shape":"AttachmentStatus",
          "documentation":"<p>The attachment state.</p>",
          "locationName":"status"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the EBS volume.</p>",
          "locationName":"volumeId"
        }
      },
      "documentation":"<p>Describes a parameter used to set up an EBS volume in a block device mapping.</p>"
    },
    "EbsInstanceBlockDeviceSpecification":{
      "type":"structure",
      "members":{
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume is deleted on instance termination.</p>",
          "locationName":"deleteOnTermination"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the EBS volume.</p>",
          "locationName":"volumeId"
        }
      },
      "documentation":"<p>Describes information used to set up an EBS volume specified in a block device mapping.</p>"
    },
    "EbsNvmeSupport":{
      "type":"string",
      "enum":[
        "unsupported",
        "supported",
        "required"
      ]
    },
    "EbsOptimizedInfo":{
      "type":"structure",
      "members":{
        "BaselineBandwidthInMbps":{
          "shape":"BaselineBandwidthInMbps",
          "documentation":"<p>The baseline bandwidth performance for an EBS-optimized instance type, in Mbps.</p>",
          "locationName":"baselineBandwidthInMbps"
        },
        "BaselineThroughputInMBps":{
          "shape":"BaselineThroughputInMBps",
          "documentation":"<p>The baseline throughput performance for an EBS-optimized instance type, in MB/s.</p>",
          "locationName":"baselineThroughputInMBps"
        },
        "BaselineIops":{
          "shape":"BaselineIops",
          "documentation":"<p>The baseline input/output storage operations per seconds for an EBS-optimized instance type.</p>",
          "locationName":"baselineIops"
        },
        "MaximumBandwidthInMbps":{
          "shape":"MaximumBandwidthInMbps",
          "documentation":"<p>The maximum bandwidth performance for an EBS-optimized instance type, in Mbps.</p>",
          "locationName":"maximumBandwidthInMbps"
        },
        "MaximumThroughputInMBps":{
          "shape":"MaximumThroughputInMBps",
          "documentation":"<p>The maximum throughput performance for an EBS-optimized instance type, in MB/s.</p>",
          "locationName":"maximumThroughputInMBps"
        },
        "MaximumIops":{
          "shape":"MaximumIops",
          "documentation":"<p>The maximum input/output storage operations per second for an EBS-optimized instance type.</p>",
          "locationName":"maximumIops"
        }
      },
      "documentation":"<p>Describes the optimized EBS performance for supported instance types.</p>"
    },
    "EbsOptimizedSupport":{
      "type":"string",
      "enum":[
        "unsupported",
        "supported",
        "default"
      ]
    },
    "EfaInfo":{
      "type":"structure",
      "members":{
        "MaximumEfaInterfaces":{
          "shape":"MaximumEfaInterfaces",
          "documentation":"<p>The maximum number of Elastic Fabric Adapters for the instance type.</p>",
          "locationName":"maximumEfaInterfaces"
        }
      },
      "documentation":"<p>Describes the Elastic Fabric Adapters for the instance type.</p>"
    },
    "EfaSupportedFlag":{"type":"boolean"},
    "EgressOnlyInternetGateway":{
      "type":"structure",
      "members":{
        "Attachments":{
          "shape":"InternetGatewayAttachmentList",
          "documentation":"<p>Information about the attachment of the egress-only internet gateway.</p>",
          "locationName":"attachmentSet"
        },
        "EgressOnlyInternetGatewayId":{
          "shape":"EgressOnlyInternetGatewayId",
          "documentation":"<p>The ID of the egress-only internet gateway.</p>",
          "locationName":"egressOnlyInternetGatewayId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the egress-only internet gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an egress-only internet gateway.</p>"
    },
    "EgressOnlyInternetGatewayId":{"type":"string"},
    "EgressOnlyInternetGatewayIdList":{
      "type":"list",
      "member":{
        "shape":"EgressOnlyInternetGatewayId",
        "locationName":"item"
      }
    },
    "EgressOnlyInternetGatewayList":{
      "type":"list",
      "member":{
        "shape":"EgressOnlyInternetGateway",
        "locationName":"item"
      }
    },
    "EipAssociationIdList":{
      "type":"list",
      "member":{
        "shape":"ElasticIpAssociationId",
        "locationName":"item"
      }
    },
    "ElasticGpuAssociation":{
      "type":"structure",
      "members":{
        "ElasticGpuId":{
          "shape":"ElasticGpuId",
          "documentation":"<p>The ID of the Elastic Graphics accelerator.</p>",
          "locationName":"elasticGpuId"
        },
        "ElasticGpuAssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"elasticGpuAssociationId"
        },
        "ElasticGpuAssociationState":{
          "shape":"String",
          "documentation":"<p>The state of the association between the instance and the Elastic Graphics accelerator.</p>",
          "locationName":"elasticGpuAssociationState"
        },
        "ElasticGpuAssociationTime":{
          "shape":"String",
          "documentation":"<p>The time the Elastic Graphics accelerator was associated with the instance.</p>",
          "locationName":"elasticGpuAssociationTime"
        }
      },
      "documentation":"<p>Describes the association between an instance and an Elastic Graphics accelerator.</p>"
    },
    "ElasticGpuAssociationList":{
      "type":"list",
      "member":{
        "shape":"ElasticGpuAssociation",
        "locationName":"item"
      }
    },
    "ElasticGpuHealth":{
      "type":"structure",
      "members":{
        "Status":{
          "shape":"ElasticGpuStatus",
          "documentation":"<p>The health status.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Describes the status of an Elastic Graphics accelerator.</p>"
    },
    "ElasticGpuId":{"type":"string"},
    "ElasticGpuIdSet":{
      "type":"list",
      "member":{
        "shape":"ElasticGpuId",
        "locationName":"item"
      }
    },
    "ElasticGpuSet":{
      "type":"list",
      "member":{
        "shape":"ElasticGpus",
        "locationName":"item"
      }
    },
    "ElasticGpuSpecification":{
      "type":"structure",
      "required":["Type"],
      "members":{
        "Type":{
          "shape":"String",
          "documentation":"<p>The type of Elastic Graphics accelerator. For more information about the values to specify for <code>Type</code>, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/elastic-graphics.html#elastic-graphics-basics\">Elastic Graphics Basics</a>, specifically the Elastic Graphics accelerator column, in the <i>Amazon Elastic Compute Cloud User Guide for Windows Instances</i>.</p>"
        }
      },
      "documentation":"<p>A specification for an Elastic Graphics accelerator.</p>"
    },
    "ElasticGpuSpecificationList":{
      "type":"list",
      "member":{
        "shape":"ElasticGpuSpecification",
        "locationName":"ElasticGpuSpecification"
      }
    },
    "ElasticGpuSpecificationResponse":{
      "type":"structure",
      "members":{
        "Type":{
          "shape":"String",
          "documentation":"<p>The elastic GPU type.</p>",
          "locationName":"type"
        }
      },
      "documentation":"<p>Describes an elastic GPU.</p>"
    },
    "ElasticGpuSpecificationResponseList":{
      "type":"list",
      "member":{
        "shape":"ElasticGpuSpecificationResponse",
        "locationName":"item"
      }
    },
    "ElasticGpuSpecifications":{
      "type":"list",
      "member":{
        "shape":"ElasticGpuSpecification",
        "locationName":"item"
      }
    },
    "ElasticGpuState":{
      "type":"string",
      "enum":["ATTACHED"]
    },
    "ElasticGpuStatus":{
      "type":"string",
      "enum":[
        "OK",
        "IMPAIRED"
      ]
    },
    "ElasticGpus":{
      "type":"structure",
      "members":{
        "ElasticGpuId":{
          "shape":"String",
          "documentation":"<p>The ID of the Elastic Graphics accelerator.</p>",
          "locationName":"elasticGpuId"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in the which the Elastic Graphics accelerator resides.</p>",
          "locationName":"availabilityZone"
        },
        "ElasticGpuType":{
          "shape":"String",
          "documentation":"<p>The type of Elastic Graphics accelerator.</p>",
          "locationName":"elasticGpuType"
        },
        "ElasticGpuHealth":{
          "shape":"ElasticGpuHealth",
          "documentation":"<p>The status of the Elastic Graphics accelerator.</p>",
          "locationName":"elasticGpuHealth"
        },
        "ElasticGpuState":{
          "shape":"ElasticGpuState",
          "documentation":"<p>The state of the Elastic Graphics accelerator.</p>",
          "locationName":"elasticGpuState"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance to which the Elastic Graphics accelerator is attached.</p>",
          "locationName":"instanceId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the Elastic Graphics accelerator.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an Elastic Graphics accelerator.</p>"
    },
    "ElasticInferenceAccelerator":{
      "type":"structure",
      "required":["Type"],
      "members":{
        "Type":{
          "shape":"String",
          "documentation":"<p> The type of elastic inference accelerator. The possible values are <code>eia1.medium</code>, <code>eia1.large</code>, <code>eia1.xlarge</code>, <code>eia2.medium</code>, <code>eia2.large</code>, and <code>eia2.xlarge</code>. </p>"
        },
        "Count":{
          "shape":"ElasticInferenceAcceleratorCount",
          "documentation":"<p> The number of elastic inference accelerators to attach to the instance. </p> <p>Default: 1</p>"
        }
      },
      "documentation":"<p> Describes an elastic inference accelerator. </p>"
    },
    "ElasticInferenceAcceleratorAssociation":{
      "type":"structure",
      "members":{
        "ElasticInferenceAcceleratorArn":{
          "shape":"String",
          "documentation":"<p> The Amazon Resource Name (ARN) of the elastic inference accelerator. </p>",
          "locationName":"elasticInferenceAcceleratorArn"
        },
        "ElasticInferenceAcceleratorAssociationId":{
          "shape":"String",
          "documentation":"<p> The ID of the association. </p>",
          "locationName":"elasticInferenceAcceleratorAssociationId"
        },
        "ElasticInferenceAcceleratorAssociationState":{
          "shape":"String",
          "documentation":"<p> The state of the elastic inference accelerator. </p>",
          "locationName":"elasticInferenceAcceleratorAssociationState"
        },
        "ElasticInferenceAcceleratorAssociationTime":{
          "shape":"DateTime",
          "documentation":"<p> The time at which the elastic inference accelerator is associated with an instance. </p>",
          "locationName":"elasticInferenceAcceleratorAssociationTime"
        }
      },
      "documentation":"<p> Describes the association between an instance and an elastic inference accelerator. </p>"
    },
    "ElasticInferenceAcceleratorAssociationList":{
      "type":"list",
      "member":{
        "shape":"ElasticInferenceAcceleratorAssociation",
        "locationName":"item"
      }
    },
    "ElasticInferenceAcceleratorCount":{
      "type":"integer",
      "min":1
    },
    "ElasticInferenceAccelerators":{
      "type":"list",
      "member":{
        "shape":"ElasticInferenceAccelerator",
        "locationName":"item"
      }
    },
    "ElasticIpAssociationId":{"type":"string"},
    "EnaSrdSpecification":{
      "type":"structure",
      "members":{
        "EnaSrdEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether ENA Express is enabled for the network interface.</p>"
        },
        "EnaSrdUdpSpecification":{
          "shape":"EnaSrdUdpSpecification",
          "documentation":"<p>Configures ENA Express for UDP network traffic.</p>"
        }
      },
      "documentation":"<p>ENA Express uses Amazon Web Services Scalable Reliable Datagram (SRD) technology to increase the maximum bandwidth used per stream and minimize tail latency of network traffic between EC2 instances. With ENA Express, you can communicate between two EC2 instances in the same subnet within the same account, or in different accounts. Both sending and receiving instances must have ENA Express enabled.</p> <p>To improve the reliability of network packet delivery, ENA Express reorders network packets on the receiving end by default. However, some UDP-based applications are designed to handle network packets that are out of order to reduce the overhead for packet delivery at the network layer. When ENA Express is enabled, you can specify whether UDP network traffic uses it.</p>"
    },
    "EnaSrdSupported":{"type":"boolean"},
    "EnaSrdUdpSpecification":{
      "type":"structure",
      "members":{
        "EnaSrdUdpEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether UDP traffic uses ENA Express. To specify this setting, you must first enable ENA Express.</p>"
        }
      },
      "documentation":"<p>ENA Express is compatible with both TCP and UDP transport protocols. When it’s enabled, TCP traffic automatically uses it. However, some UDP-based applications are designed to handle network packets that are out of order, without a need for retransmission, such as live video broadcasting or other near-real-time applications. For UDP traffic, you can specify whether to use ENA Express, based on your application environment needs.</p>"
    },
    "EnaSupport":{
      "type":"string",
      "enum":[
        "unsupported",
        "supported",
        "required"
      ]
    },
    "EnableAddressTransferRequest":{
      "type":"structure",
      "required":[
        "AllocationId",
        "TransferAccountId"
      ],
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>The allocation ID of an Elastic IP address.</p>"
        },
        "TransferAccountId":{
          "shape":"String",
          "documentation":"<p>The ID of the account that you want to transfer the Elastic IP address to.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableAddressTransferResult":{
      "type":"structure",
      "members":{
        "AddressTransfer":{
          "shape":"AddressTransfer",
          "documentation":"<p>An Elastic IP address transfer.</p>",
          "locationName":"addressTransfer"
        }
      }
    },
    "EnableAwsNetworkPerformanceMetricSubscriptionRequest":{
      "type":"structure",
      "members":{
        "Source":{
          "shape":"String",
          "documentation":"<p>The source Region or Availability Zone that the metric subscription is enabled for. For example, <code>us-east-1</code>.</p>"
        },
        "Destination":{
          "shape":"String",
          "documentation":"<p>The target Region or Availability Zone that the metric subscription is enabled for. For example, <code>eu-west-1</code>.</p>"
        },
        "Metric":{
          "shape":"MetricType",
          "documentation":"<p>The metric used for the enabled subscription.</p>"
        },
        "Statistic":{
          "shape":"StatisticType",
          "documentation":"<p>The statistic used for the enabled subscription.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableAwsNetworkPerformanceMetricSubscriptionResult":{
      "type":"structure",
      "members":{
        "Output":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the subscribe action was successful.</p>",
          "locationName":"output"
        }
      }
    },
    "EnableEbsEncryptionByDefaultRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableEbsEncryptionByDefaultResult":{
      "type":"structure",
      "members":{
        "EbsEncryptionByDefault":{
          "shape":"Boolean",
          "documentation":"<p>The updated status of encryption by default.</p>",
          "locationName":"ebsEncryptionByDefault"
        }
      }
    },
    "EnableFastLaunchRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the image for which you’re enabling faster launching.</p>"
        },
        "ResourceType":{
          "shape":"String",
          "documentation":"<p>The type of resource to use for pre-provisioning the Windows AMI for faster launching. Supported values include: <code>snapshot</code>, which is the default value.</p>"
        },
        "SnapshotConfiguration":{
          "shape":"FastLaunchSnapshotConfigurationRequest",
          "documentation":"<p>Configuration settings for creating and managing the snapshots that are used for pre-provisioning the Windows AMI for faster launching. The associated <code>ResourceType</code> must be <code>snapshot</code>.</p>"
        },
        "LaunchTemplate":{
          "shape":"FastLaunchLaunchTemplateSpecificationRequest",
          "documentation":"<p>The launch template to use when launching Windows instances from pre-provisioned snapshots. Launch template parameters can include either the name or ID of the launch template, but not both.</p>"
        },
        "MaxParallelLaunches":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of parallel instances to launch for creating resources. Value must be <code>6</code> or greater. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableFastLaunchResult":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The image ID that identifies the Windows AMI for which faster launching was enabled.</p>",
          "locationName":"imageId"
        },
        "ResourceType":{
          "shape":"FastLaunchResourceType",
          "documentation":"<p>The type of resource that was defined for pre-provisioning the Windows AMI for faster launching.</p>",
          "locationName":"resourceType"
        },
        "SnapshotConfiguration":{
          "shape":"FastLaunchSnapshotConfigurationResponse",
          "documentation":"<p>The configuration settings that were defined for creating and managing the pre-provisioned snapshots for faster launching of the Windows AMI. This property is returned when the associated <code>resourceType</code> is <code>snapshot</code>.</p>",
          "locationName":"snapshotConfiguration"
        },
        "LaunchTemplate":{
          "shape":"FastLaunchLaunchTemplateSpecificationResponse",
          "documentation":"<p>The launch template that is used when launching Windows instances from pre-provisioned snapshots.</p>",
          "locationName":"launchTemplate"
        },
        "MaxParallelLaunches":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of parallel instances to launch for creating resources.</p>",
          "locationName":"maxParallelLaunches"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The owner ID for the Windows AMI for which faster launching was enabled.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"FastLaunchStateCode",
          "documentation":"<p>The current state of faster launching for the specified Windows AMI.</p>",
          "locationName":"state"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason that the state changed for faster launching for the Windows AMI.</p>",
          "locationName":"stateTransitionReason"
        },
        "StateTransitionTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time that the state changed for faster launching for the Windows AMI.</p>",
          "locationName":"stateTransitionTime"
        }
      }
    },
    "EnableFastSnapshotRestoreErrorItem":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "FastSnapshotRestoreStateErrors":{
          "shape":"EnableFastSnapshotRestoreStateErrorSet",
          "documentation":"<p>The errors.</p>",
          "locationName":"fastSnapshotRestoreStateErrorSet"
        }
      },
      "documentation":"<p>Contains information about the errors that occurred when enabling fast snapshot restores.</p>"
    },
    "EnableFastSnapshotRestoreErrorSet":{
      "type":"list",
      "member":{
        "shape":"EnableFastSnapshotRestoreErrorItem",
        "locationName":"item"
      }
    },
    "EnableFastSnapshotRestoreStateError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes an error that occurred when enabling fast snapshot restores.</p>"
    },
    "EnableFastSnapshotRestoreStateErrorItem":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "Error":{
          "shape":"EnableFastSnapshotRestoreStateError",
          "documentation":"<p>The error.</p>",
          "locationName":"error"
        }
      },
      "documentation":"<p>Contains information about an error that occurred when enabling fast snapshot restores.</p>"
    },
    "EnableFastSnapshotRestoreStateErrorSet":{
      "type":"list",
      "member":{
        "shape":"EnableFastSnapshotRestoreStateErrorItem",
        "locationName":"item"
      }
    },
    "EnableFastSnapshotRestoreSuccessItem":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "State":{
          "shape":"FastSnapshotRestoreStateCode",
          "documentation":"<p>The state of fast snapshot restores.</p>",
          "locationName":"state"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason for the state transition. The possible values are as follows:</p> <ul> <li> <p> <code>Client.UserInitiated</code> - The state successfully transitioned to <code>enabling</code> or <code>disabling</code>.</p> </li> <li> <p> <code>Client.UserInitiated - Lifecycle state transition</code> - The state successfully transitioned to <code>optimizing</code>, <code>enabled</code>, or <code>disabled</code>.</p> </li> </ul>",
          "locationName":"stateTransitionReason"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that enabled fast snapshot restores on the snapshot.</p>",
          "locationName":"ownerId"
        },
        "OwnerAlias":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services owner alias that enabled fast snapshot restores on the snapshot. This is intended for future use.</p>",
          "locationName":"ownerAlias"
        },
        "EnablingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>enabling</code> state.</p>",
          "locationName":"enablingTime"
        },
        "OptimizingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>optimizing</code> state.</p>",
          "locationName":"optimizingTime"
        },
        "EnabledTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>enabled</code> state.</p>",
          "locationName":"enabledTime"
        },
        "DisablingTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>disabling</code> state.</p>",
          "locationName":"disablingTime"
        },
        "DisabledTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time at which fast snapshot restores entered the <code>disabled</code> state.</p>",
          "locationName":"disabledTime"
        }
      },
      "documentation":"<p>Describes fast snapshot restores that were successfully enabled.</p>"
    },
    "EnableFastSnapshotRestoreSuccessSet":{
      "type":"list",
      "member":{
        "shape":"EnableFastSnapshotRestoreSuccessItem",
        "locationName":"item"
      }
    },
    "EnableFastSnapshotRestoresRequest":{
      "type":"structure",
      "required":[
        "AvailabilityZones",
        "SourceSnapshotIds"
      ],
      "members":{
        "AvailabilityZones":{
          "shape":"AvailabilityZoneStringList",
          "documentation":"<p>One or more Availability Zones. For example, <code>us-east-2a</code>.</p>",
          "locationName":"AvailabilityZone"
        },
        "SourceSnapshotIds":{
          "shape":"SnapshotIdStringList",
          "documentation":"<p>The IDs of one or more snapshots. For example, <code>snap-1234567890abcdef0</code>. You can specify a snapshot that was shared with you from another Amazon Web Services account.</p>",
          "locationName":"SourceSnapshotId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableFastSnapshotRestoresResult":{
      "type":"structure",
      "members":{
        "Successful":{
          "shape":"EnableFastSnapshotRestoreSuccessSet",
          "documentation":"<p>Information about the snapshots for which fast snapshot restores were successfully enabled.</p>",
          "locationName":"successful"
        },
        "Unsuccessful":{
          "shape":"EnableFastSnapshotRestoreErrorSet",
          "documentation":"<p>Information about the snapshots for which fast snapshot restores could not be enabled.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "EnableImageDeprecationRequest":{
      "type":"structure",
      "required":[
        "ImageId",
        "DeprecateAt"
      ],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "DeprecateAt":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time to deprecate the AMI, in UTC, in the following format: <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z. If you specify a value for seconds, Amazon EC2 rounds the seconds to the nearest minute.</p> <p>You can’t specify a date in the past. The upper limit for <code>DeprecateAt</code> is 10 years from now, except for public AMIs, where the upper limit is 2 years from the creation date.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableImageDeprecationResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "EnableIpamOrganizationAdminAccountRequest":{
      "type":"structure",
      "required":["DelegatedAdminAccountId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "DelegatedAdminAccountId":{
          "shape":"String",
          "documentation":"<p>The Organizations member account ID that you want to enable as the IPAM account.</p>"
        }
      }
    },
    "EnableIpamOrganizationAdminAccountResult":{
      "type":"structure",
      "members":{
        "Success":{
          "shape":"Boolean",
          "documentation":"<p>The result of enabling the IPAM account.</p>",
          "locationName":"success"
        }
      }
    },
    "EnableReachabilityAnalyzerOrganizationSharingRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableReachabilityAnalyzerOrganizationSharingResult":{
      "type":"structure",
      "members":{
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"returnValue"
        }
      }
    },
    "EnableSerialConsoleAccessRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "EnableSerialConsoleAccessResult":{
      "type":"structure",
      "members":{
        "SerialConsoleAccessEnabled":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, access to the EC2 serial console of all instances is enabled for your account. If <code>false</code>, access to the EC2 serial console of all instances is disabled for your account.</p>",
          "locationName":"serialConsoleAccessEnabled"
        }
      }
    },
    "EnableTransitGatewayRouteTablePropagationRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableId"],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the propagation route table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The ID of the transit gateway route table announcement.</p>"
        }
      }
    },
    "EnableTransitGatewayRouteTablePropagationResult":{
      "type":"structure",
      "members":{
        "Propagation":{
          "shape":"TransitGatewayPropagation",
          "documentation":"<p>Information about route propagation.</p>",
          "locationName":"propagation"
        }
      }
    },
    "EnableVgwRoutePropagationRequest":{
      "type":"structure",
      "required":[
        "GatewayId",
        "RouteTableId"
      ],
      "members":{
        "GatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway that is attached to a VPC. The virtual private gateway must be attached to the same VPC that the routing tables are associated with. </p>"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table. The routing table must be associated with the same VPC that the virtual private gateway is attached to. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for EnableVgwRoutePropagation.</p>"
    },
    "EnableVolumeIORequest":{
      "type":"structure",
      "required":["VolumeId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the volume.</p>",
          "locationName":"volumeId"
        }
      }
    },
    "EnableVpcClassicLinkDnsSupportRequest":{
      "type":"structure",
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        }
      }
    },
    "EnableVpcClassicLinkDnsSupportResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "EnableVpcClassicLinkRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      }
    },
    "EnableVpcClassicLinkResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "EnclaveOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>If this parameter is set to <code>true</code>, the instance is enabled for Amazon Web Services Nitro Enclaves; otherwise, it is not enabled for Amazon Web Services Nitro Enclaves.</p>",
          "locationName":"enabled"
        }
      },
      "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves.</p>"
    },
    "EnclaveOptionsRequest":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>To enable the instance for Amazon Web Services Nitro Enclaves, set this parameter to <code>true</code>.</p>"
        }
      },
      "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves. For more information, see <a href=\"https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html\"> What is Amazon Web Services Nitro Enclaves?</a> in the <i>Amazon Web Services Nitro Enclaves User Guide</i>.</p>"
    },
    "EncryptionInTransitSupported":{"type":"boolean"},
    "EndDateType":{
      "type":"string",
      "enum":[
        "unlimited",
        "limited"
      ]
    },
    "EndpointSet":{
      "type":"list",
      "member":{
        "shape":"ClientVpnEndpoint",
        "locationName":"item"
      }
    },
    "EphemeralNvmeSupport":{
      "type":"string",
      "enum":[
        "unsupported",
        "supported",
        "required"
      ]
    },
    "ErrorSet":{
      "type":"list",
      "member":{
        "shape":"ValidationError",
        "locationName":"item"
      }
    },
    "EventCode":{
      "type":"string",
      "enum":[
        "instance-reboot",
        "system-reboot",
        "system-maintenance",
        "instance-retirement",
        "instance-stop"
      ]
    },
    "EventInformation":{
      "type":"structure",
      "members":{
        "EventDescription":{
          "shape":"String",
          "documentation":"<p>The description of the event.</p>",
          "locationName":"eventDescription"
        },
        "EventSubType":{
          "shape":"String",
          "documentation":"<p>The event.</p> <p> <code>error</code> events:</p> <ul> <li> <p> <code>iamFleetRoleInvalid</code> - The EC2 Fleet or Spot Fleet does not have the required permissions either to launch or terminate an instance.</p> </li> <li> <p> <code>allLaunchSpecsTemporarilyBlacklisted</code> - None of the configurations are valid, and several attempts to launch instances have failed. For more information, see the description of the event.</p> </li> <li> <p> <code>spotInstanceCountLimitExceeded</code> - You've reached the limit on the number of Spot Instances that you can launch.</p> </li> <li> <p> <code>spotFleetRequestConfigurationInvalid</code> - The configuration is not valid. For more information, see the description of the event.</p> </li> </ul> <p> <code>fleetRequestChange</code> events:</p> <ul> <li> <p> <code>active</code> - The EC2 Fleet or Spot Fleet request has been validated and Amazon EC2 is attempting to maintain the target number of running instances.</p> </li> <li> <p> <code>deleted</code> (EC2 Fleet) / <code>cancelled</code> (Spot Fleet) - The EC2 Fleet is deleted or the Spot Fleet request is canceled and has no running instances. The EC2 Fleet or Spot Fleet will be deleted two days after its instances are terminated.</p> </li> <li> <p> <code>deleted_running</code> (EC2 Fleet) / <code>cancelled_running</code> (Spot Fleet) - The EC2 Fleet is deleted or the Spot Fleet request is canceled and does not launch additional instances. Its existing instances continue to run until they are interrupted or terminated. The request remains in this state until all instances are interrupted or terminated.</p> </li> <li> <p> <code>deleted_terminating</code> (EC2 Fleet) / <code>cancelled_terminating</code> (Spot Fleet) - The EC2 Fleet is deleted or the Spot Fleet request is canceled and its instances are terminating. The request remains in this state until all instances are terminated.</p> </li> <li> <p> <code>expired</code> - The EC2 Fleet or Spot Fleet request has expired. If the request was created with <code>TerminateInstancesWithExpiration</code> set, a subsequent <code>terminated</code> event indicates that the instances are terminated.</p> </li> <li> <p> <code>modify_in_progress</code> - The EC2 Fleet or Spot Fleet request is being modified. The request remains in this state until the modification is fully processed.</p> </li> <li> <p> <code>modify_succeeded</code> - The EC2 Fleet or Spot Fleet request was modified.</p> </li> <li> <p> <code>submitted</code> - The EC2 Fleet or Spot Fleet request is being evaluated and Amazon EC2 is preparing to launch the target number of instances.</p> </li> <li> <p> <code>progress</code> - The EC2 Fleet or Spot Fleet request is in the process of being fulfilled.</p> </li> </ul> <p> <code>instanceChange</code> events:</p> <ul> <li> <p> <code>launched</code> - A new instance was launched.</p> </li> <li> <p> <code>terminated</code> - An instance was terminated by the user.</p> </li> <li> <p> <code>termination_notified</code> - An instance termination notification was sent when a Spot Instance was terminated by Amazon EC2 during scale-down, when the target capacity of the fleet was modified down, for example, from a target capacity of 4 to a target capacity of 3.</p> </li> </ul> <p> <code>Information</code> events:</p> <ul> <li> <p> <code>fleetProgressHalted</code> - The price in every launch specification is not valid because it is below the Spot price (all the launch specifications have produced <code>launchSpecUnusable</code> events). A launch specification might become valid if the Spot price changes.</p> </li> <li> <p> <code>launchSpecTemporarilyBlacklisted</code> - The configuration is not valid and several attempts to launch instances have failed. For more information, see the description of the event.</p> </li> <li> <p> <code>launchSpecUnusable</code> - The price in a launch specification is not valid because it is below the Spot price.</p> </li> <li> <p> <code>registerWithLoadBalancersFailed</code> - An attempt to register instances with load balancers failed. For more information, see the description of the event.</p> </li> </ul>",
          "locationName":"eventSubType"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance. This information is available only for <code>instanceChange</code> events.</p>",
          "locationName":"instanceId"
        }
      },
      "documentation":"<p>Describes an EC2 Fleet or Spot Fleet event.</p>"
    },
    "EventType":{
      "type":"string",
      "enum":[
        "instanceChange",
        "fleetRequestChange",
        "error",
        "information"
      ]
    },
    "ExcessCapacityTerminationPolicy":{
      "type":"string",
      "enum":[
        "noTermination",
        "default"
      ]
    },
    "ExcludedInstanceType":{
      "type":"string",
      "max":30,
      "min":1,
      "pattern":"[a-zA-Z0-9\\.\\*]+"
    },
    "ExcludedInstanceTypeSet":{
      "type":"list",
      "member":{
        "shape":"ExcludedInstanceType",
        "locationName":"item"
      },
      "max":400,
      "min":0
    },
    "ExecutableByStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"ExecutableBy"
      }
    },
    "Explanation":{
      "type":"structure",
      "members":{
        "Acl":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The network ACL.</p>",
          "locationName":"acl"
        },
        "AclRule":{
          "shape":"AnalysisAclRule",
          "documentation":"<p>The network ACL rule.</p>",
          "locationName":"aclRule"
        },
        "Address":{
          "shape":"IpAddress",
          "documentation":"<p>The IPv4 address, in CIDR notation.</p>",
          "locationName":"address"
        },
        "Addresses":{
          "shape":"IpAddressList",
          "documentation":"<p>The IPv4 addresses, in CIDR notation.</p>",
          "locationName":"addressSet"
        },
        "AttachedTo":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The resource to which the component is attached.</p>",
          "locationName":"attachedTo"
        },
        "AvailabilityZones":{
          "shape":"ValueStringList",
          "documentation":"<p>The Availability Zones.</p>",
          "locationName":"availabilityZoneSet"
        },
        "Cidrs":{
          "shape":"ValueStringList",
          "documentation":"<p>The CIDR ranges.</p>",
          "locationName":"cidrSet"
        },
        "Component":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The component.</p>",
          "locationName":"component"
        },
        "CustomerGateway":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The customer gateway.</p>",
          "locationName":"customerGateway"
        },
        "Destination":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The destination.</p>",
          "locationName":"destination"
        },
        "DestinationVpc":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The destination VPC.</p>",
          "locationName":"destinationVpc"
        },
        "Direction":{
          "shape":"String",
          "documentation":"<p>The direction. The following are the possible values:</p> <ul> <li> <p>egress</p> </li> <li> <p>ingress</p> </li> </ul>",
          "locationName":"direction"
        },
        "ExplanationCode":{
          "shape":"String",
          "documentation":"<p>The explanation code.</p>",
          "locationName":"explanationCode"
        },
        "IngressRouteTable":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The route table.</p>",
          "locationName":"ingressRouteTable"
        },
        "InternetGateway":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The internet gateway.</p>",
          "locationName":"internetGateway"
        },
        "LoadBalancerArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the load balancer.</p>",
          "locationName":"loadBalancerArn"
        },
        "ClassicLoadBalancerListener":{
          "shape":"AnalysisLoadBalancerListener",
          "documentation":"<p>The listener for a Classic Load Balancer.</p>",
          "locationName":"classicLoadBalancerListener"
        },
        "LoadBalancerListenerPort":{
          "shape":"Port",
          "documentation":"<p>The listener port of the load balancer.</p>",
          "locationName":"loadBalancerListenerPort"
        },
        "LoadBalancerTarget":{
          "shape":"AnalysisLoadBalancerTarget",
          "documentation":"<p>The target.</p>",
          "locationName":"loadBalancerTarget"
        },
        "LoadBalancerTargetGroup":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The target group.</p>",
          "locationName":"loadBalancerTargetGroup"
        },
        "LoadBalancerTargetGroups":{
          "shape":"AnalysisComponentList",
          "documentation":"<p>The target groups.</p>",
          "locationName":"loadBalancerTargetGroupSet"
        },
        "LoadBalancerTargetPort":{
          "shape":"Port",
          "documentation":"<p>The target port.</p>",
          "locationName":"loadBalancerTargetPort"
        },
        "ElasticLoadBalancerListener":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The load balancer listener.</p>",
          "locationName":"elasticLoadBalancerListener"
        },
        "MissingComponent":{
          "shape":"String",
          "documentation":"<p>The missing component.</p>",
          "locationName":"missingComponent"
        },
        "NatGateway":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The NAT gateway.</p>",
          "locationName":"natGateway"
        },
        "NetworkInterface":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The network interface.</p>",
          "locationName":"networkInterface"
        },
        "PacketField":{
          "shape":"String",
          "documentation":"<p>The packet field.</p>",
          "locationName":"packetField"
        },
        "VpcPeeringConnection":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The VPC peering connection.</p>",
          "locationName":"vpcPeeringConnection"
        },
        "Port":{
          "shape":"Port",
          "documentation":"<p>The port.</p>",
          "locationName":"port"
        },
        "PortRanges":{
          "shape":"PortRangeList",
          "documentation":"<p>The port ranges.</p>",
          "locationName":"portRangeSet"
        },
        "PrefixList":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The prefix list.</p>",
          "locationName":"prefixList"
        },
        "Protocols":{
          "shape":"StringList",
          "documentation":"<p>The protocols.</p>",
          "locationName":"protocolSet"
        },
        "RouteTableRoute":{
          "shape":"AnalysisRouteTableRoute",
          "documentation":"<p>The route table route.</p>",
          "locationName":"routeTableRoute"
        },
        "RouteTable":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The route table.</p>",
          "locationName":"routeTable"
        },
        "SecurityGroup":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The security group.</p>",
          "locationName":"securityGroup"
        },
        "SecurityGroupRule":{
          "shape":"AnalysisSecurityGroupRule",
          "documentation":"<p>The security group rule.</p>",
          "locationName":"securityGroupRule"
        },
        "SecurityGroups":{
          "shape":"AnalysisComponentList",
          "documentation":"<p>The security groups.</p>",
          "locationName":"securityGroupSet"
        },
        "SourceVpc":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The source VPC.</p>",
          "locationName":"sourceVpc"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state.</p>",
          "locationName":"state"
        },
        "Subnet":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The subnet.</p>",
          "locationName":"subnet"
        },
        "SubnetRouteTable":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The route table for the subnet.</p>",
          "locationName":"subnetRouteTable"
        },
        "Vpc":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The component VPC.</p>",
          "locationName":"vpc"
        },
        "VpcEndpoint":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The VPC endpoint.</p>",
          "locationName":"vpcEndpoint"
        },
        "VpnConnection":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The VPN connection.</p>",
          "locationName":"vpnConnection"
        },
        "VpnGateway":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The VPN gateway.</p>",
          "locationName":"vpnGateway"
        },
        "TransitGateway":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The transit gateway.</p>",
          "locationName":"transitGateway"
        },
        "TransitGatewayRouteTable":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTable"
        },
        "TransitGatewayRouteTableRoute":{
          "shape":"TransitGatewayRouteTableRoute",
          "documentation":"<p>The transit gateway route table route.</p>",
          "locationName":"transitGatewayRouteTableRoute"
        },
        "TransitGatewayAttachment":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The transit gateway attachment.</p>",
          "locationName":"transitGatewayAttachment"
        },
        "ComponentAccount":{
          "shape":"ComponentAccount",
          "documentation":"<p>The Amazon Web Services account for the component.</p>",
          "locationName":"componentAccount"
        },
        "ComponentRegion":{
          "shape":"ComponentRegion",
          "documentation":"<p>The Region for the component.</p>",
          "locationName":"componentRegion"
        }
      },
      "documentation":"<p>Describes an explanation code for an unreachable path. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/reachability/explanation-codes.html\">Reachability Analyzer explanation codes</a>.</p>"
    },
    "ExplanationList":{
      "type":"list",
      "member":{
        "shape":"Explanation",
        "locationName":"item"
      }
    },
    "ExportClientVpnClientCertificateRevocationListRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ExportClientVpnClientCertificateRevocationListResult":{
      "type":"structure",
      "members":{
        "CertificateRevocationList":{
          "shape":"String",
          "documentation":"<p>Information about the client certificate revocation list.</p>",
          "locationName":"certificateRevocationList"
        },
        "Status":{
          "shape":"ClientCertificateRevocationListStatus",
          "documentation":"<p>The current state of the client certificate revocation list.</p>",
          "locationName":"status"
        }
      }
    },
    "ExportClientVpnClientConfigurationRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ExportClientVpnClientConfigurationResult":{
      "type":"structure",
      "members":{
        "ClientConfiguration":{
          "shape":"String",
          "documentation":"<p>The contents of the Client VPN endpoint configuration file.</p>",
          "locationName":"clientConfiguration"
        }
      }
    },
    "ExportEnvironment":{
      "type":"string",
      "enum":[
        "citrix",
        "vmware",
        "microsoft"
      ]
    },
    "ExportImageRequest":{
      "type":"structure",
      "required":[
        "DiskImageFormat",
        "ImageId",
        "S3ExportLocation"
      ],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Token to enable idempotency for export image requests.</p>",
          "idempotencyToken":true
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the image being exported. The maximum length is 255 characters.</p>"
        },
        "DiskImageFormat":{
          "shape":"DiskImageFormat",
          "documentation":"<p>The disk image format.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the image.</p>"
        },
        "S3ExportLocation":{
          "shape":"ExportTaskS3LocationRequest",
          "documentation":"<p>The Amazon S3 bucket for the destination image. The destination bucket must exist.</p>"
        },
        "RoleName":{
          "shape":"String",
          "documentation":"<p>The name of the role that grants VM Import/Export permission to export images to your Amazon S3 bucket. If this parameter is not specified, the default role is named 'vmimport'.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the export image task during creation.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "ExportImageResult":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the image being exported.</p>",
          "locationName":"description"
        },
        "DiskImageFormat":{
          "shape":"DiskImageFormat",
          "documentation":"<p>The disk image format for the exported image.</p>",
          "locationName":"diskImageFormat"
        },
        "ExportImageTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the export image task.</p>",
          "locationName":"exportImageTaskId"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the image.</p>",
          "locationName":"imageId"
        },
        "RoleName":{
          "shape":"String",
          "documentation":"<p>The name of the role that grants VM Import/Export permission to export images to your Amazon S3 bucket.</p>",
          "locationName":"roleName"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The percent complete of the export image task.</p>",
          "locationName":"progress"
        },
        "S3ExportLocation":{
          "shape":"ExportTaskS3Location",
          "documentation":"<p>Information about the destination Amazon S3 bucket.</p>",
          "locationName":"s3ExportLocation"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The status of the export image task. The possible values are <code>active</code>, <code>completed</code>, <code>deleting</code>, and <code>deleted</code>.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message for the export image task.</p>",
          "locationName":"statusMessage"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the export image task.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "ExportImageTask":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the image being exported.</p>",
          "locationName":"description"
        },
        "ExportImageTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the export image task.</p>",
          "locationName":"exportImageTaskId"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the image.</p>",
          "locationName":"imageId"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The percent complete of the export image task.</p>",
          "locationName":"progress"
        },
        "S3ExportLocation":{
          "shape":"ExportTaskS3Location",
          "documentation":"<p>Information about the destination Amazon S3 bucket.</p>",
          "locationName":"s3ExportLocation"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The status of the export image task. The possible values are <code>active</code>, <code>completed</code>, <code>deleting</code>, and <code>deleted</code>.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message for the export image task.</p>",
          "locationName":"statusMessage"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the export image task.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an export image task.</p>"
    },
    "ExportImageTaskId":{"type":"string"},
    "ExportImageTaskIdList":{
      "type":"list",
      "member":{
        "shape":"ExportImageTaskId",
        "locationName":"ExportImageTaskId"
      }
    },
    "ExportImageTaskList":{
      "type":"list",
      "member":{
        "shape":"ExportImageTask",
        "locationName":"item"
      }
    },
    "ExportTask":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the resource being exported.</p>",
          "locationName":"description"
        },
        "ExportTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the export task.</p>",
          "locationName":"exportTaskId"
        },
        "ExportToS3Task":{
          "shape":"ExportToS3Task",
          "documentation":"<p>Information about the export task.</p>",
          "locationName":"exportToS3"
        },
        "InstanceExportDetails":{
          "shape":"InstanceExportDetails",
          "documentation":"<p>Information about the instance to export.</p>",
          "locationName":"instanceExport"
        },
        "State":{
          "shape":"ExportTaskState",
          "documentation":"<p>The state of the export task.</p>",
          "locationName":"state"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message related to the export task.</p>",
          "locationName":"statusMessage"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the export task.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an export instance task.</p>"
    },
    "ExportTaskId":{"type":"string"},
    "ExportTaskIdStringList":{
      "type":"list",
      "member":{
        "shape":"ExportTaskId",
        "locationName":"ExportTaskId"
      }
    },
    "ExportTaskList":{
      "type":"list",
      "member":{
        "shape":"ExportTask",
        "locationName":"item"
      }
    },
    "ExportTaskS3Location":{
      "type":"structure",
      "members":{
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The destination Amazon S3 bucket.</p>",
          "locationName":"s3Bucket"
        },
        "S3Prefix":{
          "shape":"String",
          "documentation":"<p>The prefix (logical hierarchy) in the bucket.</p>",
          "locationName":"s3Prefix"
        }
      },
      "documentation":"<p>Describes the destination for an export image task.</p>"
    },
    "ExportTaskS3LocationRequest":{
      "type":"structure",
      "required":["S3Bucket"],
      "members":{
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The destination Amazon S3 bucket.</p>"
        },
        "S3Prefix":{
          "shape":"String",
          "documentation":"<p>The prefix (logical hierarchy) in the bucket.</p>"
        }
      },
      "documentation":"<p>Describes the destination for an export image task.</p>"
    },
    "ExportTaskState":{
      "type":"string",
      "enum":[
        "active",
        "cancelling",
        "cancelled",
        "completed"
      ]
    },
    "ExportToS3Task":{
      "type":"structure",
      "members":{
        "ContainerFormat":{
          "shape":"ContainerFormat",
          "documentation":"<p>The container format used to combine disk images with metadata (such as OVF). If absent, only the disk image is exported.</p>",
          "locationName":"containerFormat"
        },
        "DiskImageFormat":{
          "shape":"DiskImageFormat",
          "documentation":"<p>The format for the exported image.</p>",
          "locationName":"diskImageFormat"
        },
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The Amazon S3 bucket for the destination image. The destination bucket must exist and have an access control list (ACL) attached that specifies the Region-specific canonical account ID for the <code>Grantee</code>. For more information about the ACL to your S3 bucket, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport.html#vmexport-prerequisites\">Prerequisites</a> in the VM Import/Export User Guide.</p>",
          "locationName":"s3Bucket"
        },
        "S3Key":{
          "shape":"String",
          "documentation":"<p>The encryption key for your S3 bucket.</p>",
          "locationName":"s3Key"
        }
      },
      "documentation":"<p>Describes the format and location for the export task.</p>"
    },
    "ExportToS3TaskSpecification":{
      "type":"structure",
      "members":{
        "ContainerFormat":{
          "shape":"ContainerFormat",
          "documentation":"<p>The container format used to combine disk images with metadata (such as OVF). If absent, only the disk image is exported.</p>",
          "locationName":"containerFormat"
        },
        "DiskImageFormat":{
          "shape":"DiskImageFormat",
          "documentation":"<p>The format for the exported image.</p>",
          "locationName":"diskImageFormat"
        },
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The Amazon S3 bucket for the destination image. The destination bucket must exist and have an access control list (ACL) attached that specifies the Region-specific canonical account ID for the <code>Grantee</code>. For more information about the ACL to your S3 bucket, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmexport.html#vmexport-prerequisites\">Prerequisites</a> in the VM Import/Export User Guide.</p>",
          "locationName":"s3Bucket"
        },
        "S3Prefix":{
          "shape":"String",
          "documentation":"<p>The image is written to a single object in the Amazon S3 bucket at the S3 key s3prefix + exportTaskId + '.' + diskImageFormat.</p>",
          "locationName":"s3Prefix"
        }
      },
      "documentation":"<p>Describes an export instance task.</p>"
    },
    "ExportTransitGatewayRoutesRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "S3Bucket"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the route table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>attachment.transit-gateway-attachment-id</code> - The id of the transit gateway attachment.</p> </li> <li> <p> <code>attachment.resource-id</code> - The resource id of the transit gateway attachment.</p> </li> <li> <p> <code>route-search.exact-match</code> - The exact match of the specified filter.</p> </li> <li> <p> <code>route-search.longest-prefix-match</code> - The longest prefix that matches the route.</p> </li> <li> <p> <code>route-search.subnet-of-match</code> - The routes with a subnet that match the specified CIDR filter.</p> </li> <li> <p> <code>route-search.supernet-of-match</code> - The routes with a CIDR that encompass the CIDR filter. For example, if you have 10.0.1.0/29 and 10.0.1.0/31 routes in your route table and you specify supernet-of-match as 10.0.1.0/30, then the result returns 10.0.1.0/29.</p> </li> <li> <p> <code>state</code> - The state of the route (<code>active</code> | <code>blackhole</code>).</p> </li> <li> <p> <code>transit-gateway-route-destination-cidr-block</code> - The CIDR range.</p> </li> <li> <p> <code>type</code> - The type of route (<code>propagated</code> | <code>static</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the S3 bucket.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ExportTransitGatewayRoutesResult":{
      "type":"structure",
      "members":{
        "S3Location":{
          "shape":"String",
          "documentation":"<p>The URL of the exported file in Amazon S3. For example, s3://<i>bucket_name</i>/VPCTransitGateway/TransitGatewayRouteTables/<i>file_name</i>.</p>",
          "locationName":"s3Location"
        }
      }
    },
    "ExportVmTaskId":{"type":"string"},
    "FailedCapacityReservationFleetCancellationResult":{
      "type":"structure",
      "members":{
        "CapacityReservationFleetId":{
          "shape":"CapacityReservationFleetId",
          "documentation":"<p>The ID of the Capacity Reservation Fleet that could not be cancelled.</p>",
          "locationName":"capacityReservationFleetId"
        },
        "CancelCapacityReservationFleetError":{
          "shape":"CancelCapacityReservationFleetError",
          "documentation":"<p>Information about the Capacity Reservation Fleet cancellation error.</p>",
          "locationName":"cancelCapacityReservationFleetError"
        }
      },
      "documentation":"<p>Describes a Capacity Reservation Fleet that could not be cancelled.</p>"
    },
    "FailedCapacityReservationFleetCancellationResultSet":{
      "type":"list",
      "member":{
        "shape":"FailedCapacityReservationFleetCancellationResult",
        "locationName":"item"
      }
    },
    "FailedQueuedPurchaseDeletion":{
      "type":"structure",
      "members":{
        "Error":{
          "shape":"DeleteQueuedReservedInstancesError",
          "documentation":"<p>The error.</p>",
          "locationName":"error"
        },
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance.</p>",
          "locationName":"reservedInstancesId"
        }
      },
      "documentation":"<p>Describes a Reserved Instance whose queued purchase was not deleted.</p>"
    },
    "FailedQueuedPurchaseDeletionSet":{
      "type":"list",
      "member":{
        "shape":"FailedQueuedPurchaseDeletion",
        "locationName":"item"
      }
    },
    "FastLaunchImageIdList":{
      "type":"list",
      "member":{
        "shape":"ImageId",
        "locationName":"ImageId"
      }
    },
    "FastLaunchLaunchTemplateSpecificationRequest":{
      "type":"structure",
      "required":["Version"],
      "members":{
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template to use for faster launching for a Windows AMI.</p>"
        },
        "LaunchTemplateName":{
          "shape":"String",
          "documentation":"<p>The name of the launch template to use for faster launching for a Windows AMI.</p>"
        },
        "Version":{
          "shape":"String",
          "documentation":"<p>The version of the launch template to use for faster launching for a Windows AMI.</p>"
        }
      },
      "documentation":"<p>Request to create a launch template for a fast-launch enabled Windows AMI.</p> <note> <p>Note - You can specify either the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p> </note>"
    },
    "FastLaunchLaunchTemplateSpecificationResponse":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template for faster launching of the associated Windows AMI.</p>",
          "locationName":"launchTemplateId"
        },
        "LaunchTemplateName":{
          "shape":"String",
          "documentation":"<p>The name of the launch template for faster launching of the associated Windows AMI.</p>",
          "locationName":"launchTemplateName"
        },
        "Version":{
          "shape":"String",
          "documentation":"<p>The version of the launch template for faster launching of the associated Windows AMI.</p>",
          "locationName":"version"
        }
      },
      "documentation":"<p>Identifies the launch template to use for faster launching of the Windows AMI.</p>"
    },
    "FastLaunchResourceType":{
      "type":"string",
      "enum":["snapshot"]
    },
    "FastLaunchSnapshotConfigurationRequest":{
      "type":"structure",
      "members":{
        "TargetResourceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of pre-provisioned snapshots to keep on hand for a fast-launch enabled Windows AMI.</p>"
        }
      },
      "documentation":"<p>Configuration settings for creating and managing pre-provisioned snapshots for a fast-launch enabled Windows AMI.</p>"
    },
    "FastLaunchSnapshotConfigurationResponse":{
      "type":"structure",
      "members":{
        "TargetResourceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of pre-provisioned snapshots requested to keep on hand for a fast-launch enabled Windows AMI.</p>",
          "locationName":"targetResourceCount"
        }
      },
      "documentation":"<p>Configuration settings for creating and managing pre-provisioned snapshots for a fast-launch enabled Windows AMI.</p>"
    },
    "FastLaunchStateCode":{
      "type":"string",
      "enum":[
        "enabling",
        "enabling-failed",
        "enabled",
        "enabled-failed",
        "disabling",
        "disabling-failed"
      ]
    },
    "FastSnapshotRestoreStateCode":{
      "type":"string",
      "enum":[
        "enabling",
        "optimizing",
        "enabled",
        "disabling",
        "disabled"
      ]
    },
    "FederatedAuthentication":{
      "type":"structure",
      "members":{
        "SamlProviderArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the IAM SAML identity provider.</p>",
          "locationName":"samlProviderArn"
        },
        "SelfServiceSamlProviderArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the IAM SAML identity provider for the self-service portal.</p>",
          "locationName":"selfServiceSamlProviderArn"
        }
      },
      "documentation":"<p>Describes the IAM SAML identity providers used for federated authentication.</p>"
    },
    "FederatedAuthenticationRequest":{
      "type":"structure",
      "members":{
        "SAMLProviderArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the IAM SAML identity provider.</p>"
        },
        "SelfServiceSAMLProviderArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the IAM SAML identity provider for the self-service portal.</p>"
        }
      },
      "documentation":"<p>The IAM SAML identity provider used for federated authentication.</p>"
    },
    "Filter":{
      "type":"structure",
      "members":{
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the filter. Filter names are case-sensitive.</p>"
        },
        "Values":{
          "shape":"ValueStringList",
          "documentation":"<p>The filter values. Filter values are case-sensitive. If you specify multiple values for a filter, the values are joined with an <code>OR</code>, and the request returns all results that match any of the specified values.</p>",
          "locationName":"Value"
        }
      },
      "documentation":"<p>A filter name and value pair that is used to return a more specific list of results from a describe operation. Filters can be used to match a set of resources by specific criteria, such as tags, attributes, or IDs.</p> <p>If you specify multiple filters, the filters are joined with an <code>AND</code>, and the request returns only results that match all of the specified filters.</p>"
    },
    "FilterList":{
      "type":"list",
      "member":{
        "shape":"Filter",
        "locationName":"Filter"
      }
    },
    "FindingsFound":{
      "type":"string",
      "enum":[
        "true",
        "false",
        "unknown"
      ]
    },
    "FleetActivityStatus":{
      "type":"string",
      "enum":[
        "error",
        "pending_fulfillment",
        "pending_termination",
        "fulfilled"
      ]
    },
    "FleetCapacityReservation":{
      "type":"structure",
      "members":{
        "CapacityReservationId":{
          "shape":"CapacityReservationId",
          "documentation":"<p>The ID of the Capacity Reservation.</p>",
          "locationName":"capacityReservationId"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the Availability Zone in which the Capacity Reservation reserves capacity.</p>",
          "locationName":"availabilityZoneId"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"instanceType"
        },
        "InstancePlatform":{
          "shape":"CapacityReservationInstancePlatform",
          "documentation":"<p>The type of operating system for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"instancePlatform"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the Capacity Reservation reserves capacity.</p>",
          "locationName":"availabilityZone"
        },
        "TotalInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The total number of instances for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"totalInstanceCount"
        },
        "FulfilledCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of capacity units fulfilled by the Capacity Reservation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#target-capacity\"> Total target capacity</a> in the Amazon EC2 User Guide.</p>",
          "locationName":"fulfilledCapacity"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the Capacity Reservation reserves capacity for EBS-optimized instance types.</p>",
          "locationName":"ebsOptimized"
        },
        "CreateDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation was created.</p>",
          "locationName":"createDate"
        },
        "Weight":{
          "shape":"DoubleWithConstraints",
          "documentation":"<p>The weight of the instance type in the Capacity Reservation Fleet. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#instance-weight\"> Instance type weight</a> in the Amazon EC2 User Guide.</p>",
          "locationName":"weight"
        },
        "Priority":{
          "shape":"IntegerWithConstraints",
          "documentation":"<p>The priority of the instance type in the Capacity Reservation Fleet. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#instance-priority\"> Instance type priority</a> in the Amazon EC2 User Guide.</p>",
          "locationName":"priority"
        }
      },
      "documentation":"<p>Information about a Capacity Reservation in a Capacity Reservation Fleet.</p>"
    },
    "FleetCapacityReservationSet":{
      "type":"list",
      "member":{
        "shape":"FleetCapacityReservation",
        "locationName":"item"
      }
    },
    "FleetCapacityReservationTenancy":{
      "type":"string",
      "enum":["default"]
    },
    "FleetCapacityReservationUsageStrategy":{
      "type":"string",
      "enum":["use-capacity-reservations-first"]
    },
    "FleetData":{
      "type":"structure",
      "members":{
        "ActivityStatus":{
          "shape":"FleetActivityStatus",
          "documentation":"<p>The progress of the EC2 Fleet. If there is an error, the status is <code>error</code>. After all requests are placed, the status is <code>pending_fulfillment</code>. If the size of the EC2 Fleet is equal to or greater than its target capacity, the status is <code>fulfilled</code>. If the size of the EC2 Fleet is decreased, the status is <code>pending_termination</code> while instances are terminating.</p>",
          "locationName":"activityStatus"
        },
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation date and time of the EC2 Fleet.</p>",
          "locationName":"createTime"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>",
          "locationName":"fleetId"
        },
        "FleetState":{
          "shape":"FleetStateCode",
          "documentation":"<p>The state of the EC2 Fleet.</p>",
          "locationName":"fleetState"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p> <p>Constraints: Maximum 64 ASCII characters</p>",
          "locationName":"clientToken"
        },
        "ExcessCapacityTerminationPolicy":{
          "shape":"FleetExcessCapacityTerminationPolicy",
          "documentation":"<p>Indicates whether running instances should be terminated if the target capacity of the EC2 Fleet is decreased below the current size of the EC2 Fleet.</p> <p>Supported only for fleets of type <code>maintain</code>.</p>",
          "locationName":"excessCapacityTerminationPolicy"
        },
        "FulfilledCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units fulfilled by this request compared to the set target capacity.</p>",
          "locationName":"fulfilledCapacity"
        },
        "FulfilledOnDemandCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units fulfilled by this request compared to the set target On-Demand capacity.</p>",
          "locationName":"fulfilledOnDemandCapacity"
        },
        "LaunchTemplateConfigs":{
          "shape":"FleetLaunchTemplateConfigList",
          "documentation":"<p>The launch template and overrides.</p>",
          "locationName":"launchTemplateConfigs"
        },
        "TargetCapacitySpecification":{
          "shape":"TargetCapacitySpecification",
          "documentation":"<p>The number of units to request. You can choose to set the target capacity in terms of instances or a performance characteristic that is important to your application workload, such as vCPUs, memory, or I/O. If the request type is <code>maintain</code>, you can specify a target capacity of 0 and add capacity later.</p>",
          "locationName":"targetCapacitySpecification"
        },
        "TerminateInstancesWithExpiration":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether running instances should be terminated when the EC2 Fleet expires. </p>",
          "locationName":"terminateInstancesWithExpiration"
        },
        "Type":{
          "shape":"FleetType",
          "documentation":"<p>The type of request. Indicates whether the EC2 Fleet only <code>requests</code> the target capacity, or also attempts to <code>maintain</code> it. If you request a certain target capacity, EC2 Fleet only places the required requests; it does not attempt to replenish instances if capacity is diminished, and it does not submit requests in alternative capacity pools if capacity is unavailable. To maintain a certain target capacity, EC2 Fleet places the required requests to meet this target capacity. It also automatically replenishes any interrupted Spot Instances. Default: <code>maintain</code>.</p>",
          "locationName":"type"
        },
        "ValidFrom":{
          "shape":"DateTime",
          "documentation":"<p>The start date and time of the request, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). The default is to start fulfilling the request immediately. </p>",
          "locationName":"validFrom"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date and time of the request, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). At this point, no new instance requests are placed or able to fulfill the request. The default end date is 7 days from the current date. </p>",
          "locationName":"validUntil"
        },
        "ReplaceUnhealthyInstances":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether EC2 Fleet should replace unhealthy Spot Instances. Supported only for fleets of type <code>maintain</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/manage-ec2-fleet.html#ec2-fleet-health-checks\">EC2 Fleet health checks</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"replaceUnhealthyInstances"
        },
        "SpotOptions":{
          "shape":"SpotOptions",
          "documentation":"<p>The configuration of Spot Instances in an EC2 Fleet.</p>",
          "locationName":"spotOptions"
        },
        "OnDemandOptions":{
          "shape":"OnDemandOptions",
          "documentation":"<p>The allocation strategy of On-Demand Instances in an EC2 Fleet.</p>",
          "locationName":"onDemandOptions"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for an EC2 Fleet resource.</p>",
          "locationName":"tagSet"
        },
        "Errors":{
          "shape":"DescribeFleetsErrorSet",
          "documentation":"<p>Information about the instances that could not be launched by the fleet. Valid only when <b>Type</b> is set to <code>instant</code>.</p>",
          "locationName":"errorSet"
        },
        "Instances":{
          "shape":"DescribeFleetsInstancesSet",
          "documentation":"<p>Information about the instances that were launched by the fleet. Valid only when <b>Type</b> is set to <code>instant</code>.</p>",
          "locationName":"fleetInstanceSet"
        },
        "Context":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>",
          "locationName":"context"
        }
      },
      "documentation":"<p>Describes an EC2 Fleet.</p>"
    },
    "FleetEventType":{
      "type":"string",
      "enum":[
        "instance-change",
        "fleet-change",
        "service-error"
      ]
    },
    "FleetExcessCapacityTerminationPolicy":{
      "type":"string",
      "enum":[
        "no-termination",
        "termination"
      ]
    },
    "FleetId":{"type":"string"},
    "FleetIdSet":{
      "type":"list",
      "member":{"shape":"FleetId"}
    },
    "FleetInstanceMatchCriteria":{
      "type":"string",
      "enum":["open"]
    },
    "FleetLaunchTemplateConfig":{
      "type":"structure",
      "members":{
        "LaunchTemplateSpecification":{
          "shape":"FleetLaunchTemplateSpecification",
          "documentation":"<p>The launch template.</p>",
          "locationName":"launchTemplateSpecification"
        },
        "Overrides":{
          "shape":"FleetLaunchTemplateOverridesList",
          "documentation":"<p>Any parameters that you specify override the same parameters in the launch template.</p>",
          "locationName":"overrides"
        }
      },
      "documentation":"<p>Describes a launch template and overrides.</p>"
    },
    "FleetLaunchTemplateConfigList":{
      "type":"list",
      "member":{
        "shape":"FleetLaunchTemplateConfig",
        "locationName":"item"
      }
    },
    "FleetLaunchTemplateConfigListRequest":{
      "type":"list",
      "member":{
        "shape":"FleetLaunchTemplateConfigRequest",
        "locationName":"item"
      },
      "max":50,
      "min":0
    },
    "FleetLaunchTemplateConfigRequest":{
      "type":"structure",
      "members":{
        "LaunchTemplateSpecification":{
          "shape":"FleetLaunchTemplateSpecificationRequest",
          "documentation":"<p>The launch template to use. You must specify either the launch template ID or launch template name in the request. </p>"
        },
        "Overrides":{
          "shape":"FleetLaunchTemplateOverridesListRequest",
          "documentation":"<p>Any parameters that you specify override the same parameters in the launch template.</p> <p>For fleets of type <code>request</code> and <code>maintain</code>, a maximum of 300 items is allowed across all launch templates.</p>"
        }
      },
      "documentation":"<p>Describes a launch template and overrides.</p>"
    },
    "FleetLaunchTemplateOverrides":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p> <note> <p>If you specify <code>InstanceType</code>, you can't specify <code>InstanceRequirements</code>.</p> </note>",
          "locationName":"instanceType"
        },
        "MaxPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price. </p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"maxPrice"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet in which to launch the instances.</p>",
          "locationName":"subnetId"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to launch the instances.</p>",
          "locationName":"availabilityZone"
        },
        "WeightedCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units provided by the specified instance type.</p>",
          "locationName":"weightedCapacity"
        },
        "Priority":{
          "shape":"Double",
          "documentation":"<p>The priority for the launch template override. The highest priority is launched first.</p> <p>If the On-Demand <code>AllocationStrategy</code> is set to <code>prioritized</code>, EC2 Fleet uses priority to determine which launch template override to use first in fulfilling On-Demand capacity.</p> <p>If the Spot <code>AllocationStrategy</code> is set to <code>capacity-optimized-prioritized</code>, EC2 Fleet uses priority on a best-effort basis to determine which launch template override to use in fulfilling Spot capacity, but optimizes for capacity first.</p> <p>Valid values are whole numbers starting at <code>0</code>. The lower the number, the higher the priority. If no number is set, the override has the lowest priority. You can set the same priority for different launch template overrides.</p>",
          "locationName":"priority"
        },
        "Placement":{
          "shape":"PlacementResponse",
          "documentation":"<p>The location where the instance launched, if applicable.</p>",
          "locationName":"placement"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirements",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.</p> <note> <p>If you specify <code>InstanceRequirements</code>, you can't specify <code>InstanceType</code>.</p> </note>",
          "locationName":"instanceRequirements"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI. An AMI is required to launch an instance. The AMI ID must be specified here or in the launch template.</p>",
          "locationName":"imageId"
        }
      },
      "documentation":"<p>Describes overrides for a launch template.</p>"
    },
    "FleetLaunchTemplateOverridesList":{
      "type":"list",
      "member":{
        "shape":"FleetLaunchTemplateOverrides",
        "locationName":"item"
      }
    },
    "FleetLaunchTemplateOverridesListRequest":{
      "type":"list",
      "member":{
        "shape":"FleetLaunchTemplateOverridesRequest",
        "locationName":"item"
      }
    },
    "FleetLaunchTemplateOverridesRequest":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p> <note> <p>If you specify <code>InstanceType</code>, you can't specify <code>InstanceRequirements</code>.</p> </note>"
        },
        "MaxPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price. </p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The IDs of the subnets in which to launch the instances. Separate multiple subnet IDs using commas (for example, <code>subnet-1234abcdeexample1, subnet-0987cdef6example2</code>). A request of type <code>instant</code> can have only one subnet ID.</p>"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to launch the instances.</p>"
        },
        "WeightedCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units provided by the specified instance type.</p>"
        },
        "Priority":{
          "shape":"Double",
          "documentation":"<p>The priority for the launch template override. The highest priority is launched first.</p> <p>If the On-Demand <code>AllocationStrategy</code> is set to <code>prioritized</code>, EC2 Fleet uses priority to determine which launch template override to use first in fulfilling On-Demand capacity.</p> <p>If the Spot <code>AllocationStrategy</code> is set to <code>capacity-optimized-prioritized</code>, EC2 Fleet uses priority on a best-effort basis to determine which launch template override to use in fulfilling Spot capacity, but optimizes for capacity first.</p> <p>Valid values are whole numbers starting at <code>0</code>. The lower the number, the higher the priority. If no number is set, the launch template override has the lowest priority. You can set the same priority for different launch template overrides.</p>"
        },
        "Placement":{
          "shape":"Placement",
          "documentation":"<p>The location where the instance launched, if applicable.</p>"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirementsRequest",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.</p> <note> <p>If you specify <code>InstanceRequirements</code>, you can't specify <code>InstanceType</code>.</p> </note>"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI. An AMI is required to launch an instance. The AMI ID must be specified here or in the launch template.</p>"
        }
      },
      "documentation":"<p>Describes overrides for a launch template.</p>"
    },
    "FleetLaunchTemplateSpecification":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"String",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>",
          "locationName":"launchTemplateId"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>",
          "locationName":"launchTemplateName"
        },
        "Version":{
          "shape":"String",
          "documentation":"<p>The launch template version number, <code>$Latest</code>, or <code>$Default</code>. You must specify a value, otherwise the request fails.</p> <p>If the value is <code>$Latest</code>, Amazon EC2 uses the latest version of the launch template.</p> <p>If the value is <code>$Default</code>, Amazon EC2 uses the default version of the launch template.</p>",
          "locationName":"version"
        }
      },
      "documentation":"<p>The Amazon EC2 launch template that can be used by a Spot Fleet to configure Amazon EC2 instances. You must specify either the ID or name of the launch template in the request, but not both.</p> <p>For information about launch templates, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html\">Launch an instance from a launch template</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "FleetLaunchTemplateSpecificationRequest":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>"
        },
        "Version":{
          "shape":"String",
          "documentation":"<p>The launch template version number, <code>$Latest</code>, or <code>$Default</code>. You must specify a value, otherwise the request fails.</p> <p>If the value is <code>$Latest</code>, Amazon EC2 uses the latest version of the launch template.</p> <p>If the value is <code>$Default</code>, Amazon EC2 uses the default version of the launch template.</p>"
        }
      },
      "documentation":"<p>The Amazon EC2 launch template that can be used by an EC2 Fleet to configure Amazon EC2 instances. You must specify either the ID or name of the launch template in the request, but not both.</p> <p>For information about launch templates, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html\">Launch an instance from a launch template</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "FleetOnDemandAllocationStrategy":{
      "type":"string",
      "enum":[
        "lowest-price",
        "prioritized"
      ]
    },
    "FleetReplacementStrategy":{
      "type":"string",
      "enum":[
        "launch",
        "launch-before-terminate"
      ]
    },
    "FleetSet":{
      "type":"list",
      "member":{
        "shape":"FleetData",
        "locationName":"item"
      }
    },
    "FleetSpotCapacityRebalance":{
      "type":"structure",
      "members":{
        "ReplacementStrategy":{
          "shape":"FleetReplacementStrategy",
          "documentation":"<p>The replacement strategy to use. Only available for fleets of type <code>maintain</code>.</p> <p> <code>launch</code> - EC2 Fleet launches a new replacement Spot Instance when a rebalance notification is emitted for an existing Spot Instance in the fleet. EC2 Fleet does not terminate the instances that receive a rebalance notification. You can terminate the old instances, or you can leave them running. You are charged for all instances while they are running. </p> <p> <code>launch-before-terminate</code> - EC2 Fleet launches a new replacement Spot Instance when a rebalance notification is emitted for an existing Spot Instance in the fleet, and then, after a delay that you specify (in <code>TerminationDelay</code>), terminates the instances that received a rebalance notification.</p>",
          "locationName":"replacementStrategy"
        },
        "TerminationDelay":{
          "shape":"Integer",
          "documentation":"<p>The amount of time (in seconds) that Amazon EC2 waits before terminating the old Spot Instance after launching a new replacement Spot Instance.</p> <p>Required when <code>ReplacementStrategy</code> is set to <code>launch-before-terminate</code>.</p> <p>Not valid when <code>ReplacementStrategy</code> is set to <code>launch</code>.</p> <p>Valid values: Minimum value of <code>120</code> seconds. Maximum value of <code>7200</code> seconds.</p>",
          "locationName":"terminationDelay"
        }
      },
      "documentation":"<p>The strategy to use when Amazon EC2 emits a signal that your Spot Instance is at an elevated risk of being interrupted.</p>"
    },
    "FleetSpotCapacityRebalanceRequest":{
      "type":"structure",
      "members":{
        "ReplacementStrategy":{
          "shape":"FleetReplacementStrategy",
          "documentation":"<p>The replacement strategy to use. Only available for fleets of type <code>maintain</code>.</p> <p> <code>launch</code> - EC2 Fleet launches a replacement Spot Instance when a rebalance notification is emitted for an existing Spot Instance in the fleet. EC2 Fleet does not terminate the instances that receive a rebalance notification. You can terminate the old instances, or you can leave them running. You are charged for all instances while they are running. </p> <p> <code>launch-before-terminate</code> - EC2 Fleet launches a replacement Spot Instance when a rebalance notification is emitted for an existing Spot Instance in the fleet, and then, after a delay that you specify (in <code>TerminationDelay</code>), terminates the instances that received a rebalance notification.</p>"
        },
        "TerminationDelay":{
          "shape":"Integer",
          "documentation":"<p>The amount of time (in seconds) that Amazon EC2 waits before terminating the old Spot Instance after launching a new replacement Spot Instance.</p> <p>Required when <code>ReplacementStrategy</code> is set to <code>launch-before-terminate</code>.</p> <p>Not valid when <code>ReplacementStrategy</code> is set to <code>launch</code>.</p> <p>Valid values: Minimum value of <code>120</code> seconds. Maximum value of <code>7200</code> seconds.</p>"
        }
      },
      "documentation":"<p>The Spot Instance replacement strategy to use when Amazon EC2 emits a rebalance notification signal that your Spot Instance is at an elevated risk of being interrupted. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-capacity-rebalance.html\">Capacity rebalancing</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "FleetSpotMaintenanceStrategies":{
      "type":"structure",
      "members":{
        "CapacityRebalance":{
          "shape":"FleetSpotCapacityRebalance",
          "documentation":"<p>The strategy to use when Amazon EC2 emits a signal that your Spot Instance is at an elevated risk of being interrupted.</p>",
          "locationName":"capacityRebalance"
        }
      },
      "documentation":"<p>The strategies for managing your Spot Instances that are at an elevated risk of being interrupted.</p>"
    },
    "FleetSpotMaintenanceStrategiesRequest":{
      "type":"structure",
      "members":{
        "CapacityRebalance":{
          "shape":"FleetSpotCapacityRebalanceRequest",
          "documentation":"<p>The strategy to use when Amazon EC2 emits a signal that your Spot Instance is at an elevated risk of being interrupted.</p>"
        }
      },
      "documentation":"<p>The strategies for managing your Spot Instances that are at an elevated risk of being interrupted.</p>"
    },
    "FleetStateCode":{
      "type":"string",
      "enum":[
        "submitted",
        "active",
        "deleted",
        "failed",
        "deleted_running",
        "deleted_terminating",
        "modifying"
      ]
    },
    "FleetType":{
      "type":"string",
      "enum":[
        "request",
        "maintain",
        "instant"
      ]
    },
    "Float":{"type":"float"},
    "FlowLog":{
      "type":"structure",
      "members":{
        "CreationTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time the flow log was created.</p>",
          "locationName":"creationTime"
        },
        "DeliverLogsErrorMessage":{
          "shape":"String",
          "documentation":"<p>Information about the error that occurred. <code>Rate limited</code> indicates that CloudWatch Logs throttling has been applied for one or more network interfaces, or that you've reached the limit on the number of log groups that you can create. <code>Access error</code> indicates that the IAM role associated with the flow log does not have sufficient permissions to publish to CloudWatch Logs. <code>Unknown error</code> indicates an internal error.</p>",
          "locationName":"deliverLogsErrorMessage"
        },
        "DeliverLogsPermissionArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the IAM role allows the service to publish logs to CloudWatch Logs.</p>",
          "locationName":"deliverLogsPermissionArn"
        },
        "DeliverCrossAccountRole":{
          "shape":"String",
          "documentation":"<p>The ARN of the IAM role that allows the service to publish flow logs across accounts.</p>",
          "locationName":"deliverCrossAccountRole"
        },
        "DeliverLogsStatus":{
          "shape":"String",
          "documentation":"<p>The status of the logs delivery (<code>SUCCESS</code> | <code>FAILED</code>).</p>",
          "locationName":"deliverLogsStatus"
        },
        "FlowLogId":{
          "shape":"String",
          "documentation":"<p>The ID of the flow log.</p>",
          "locationName":"flowLogId"
        },
        "FlowLogStatus":{
          "shape":"String",
          "documentation":"<p>The status of the flow log (<code>ACTIVE</code>).</p>",
          "locationName":"flowLogStatus"
        },
        "LogGroupName":{
          "shape":"String",
          "documentation":"<p>The name of the flow log group.</p>",
          "locationName":"logGroupName"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource being monitored.</p>",
          "locationName":"resourceId"
        },
        "TrafficType":{
          "shape":"TrafficType",
          "documentation":"<p>The type of traffic captured for the flow log.</p>",
          "locationName":"trafficType"
        },
        "LogDestinationType":{
          "shape":"LogDestinationType",
          "documentation":"<p>The type of destination for the flow log data.</p>",
          "locationName":"logDestinationType"
        },
        "LogDestination":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the destination for the flow log data.</p>",
          "locationName":"logDestination"
        },
        "LogFormat":{
          "shape":"String",
          "documentation":"<p>The format of the flow log record.</p>",
          "locationName":"logFormat"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the flow log.</p>",
          "locationName":"tagSet"
        },
        "MaxAggregationInterval":{
          "shape":"Integer",
          "documentation":"<p>The maximum interval of time, in seconds, during which a flow of packets is captured and aggregated into a flow log record.</p> <p>When a network interface is attached to a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">Nitro-based instance</a>, the aggregation interval is always 60 seconds (1 minute) or less, regardless of the specified value.</p> <p>Valid Values: <code>60</code> | <code>600</code> </p>",
          "locationName":"maxAggregationInterval"
        },
        "DestinationOptions":{
          "shape":"DestinationOptionsResponse",
          "documentation":"<p>The destination options.</p>",
          "locationName":"destinationOptions"
        }
      },
      "documentation":"<p>Describes a flow log.</p>"
    },
    "FlowLogIdList":{
      "type":"list",
      "member":{
        "shape":"VpcFlowLogId",
        "locationName":"item"
      }
    },
    "FlowLogResourceId":{"type":"string"},
    "FlowLogResourceIds":{
      "type":"list",
      "member":{
        "shape":"FlowLogResourceId",
        "locationName":"item"
      }
    },
    "FlowLogSet":{
      "type":"list",
      "member":{
        "shape":"FlowLog",
        "locationName":"item"
      }
    },
    "FlowLogsResourceType":{
      "type":"string",
      "enum":[
        "VPC",
        "Subnet",
        "NetworkInterface",
        "TransitGateway",
        "TransitGatewayAttachment"
      ]
    },
    "FpgaDeviceCount":{"type":"integer"},
    "FpgaDeviceInfo":{
      "type":"structure",
      "members":{
        "Name":{
          "shape":"FpgaDeviceName",
          "documentation":"<p>The name of the FPGA accelerator.</p>",
          "locationName":"name"
        },
        "Manufacturer":{
          "shape":"FpgaDeviceManufacturerName",
          "documentation":"<p>The manufacturer of the FPGA accelerator.</p>",
          "locationName":"manufacturer"
        },
        "Count":{
          "shape":"FpgaDeviceCount",
          "documentation":"<p>The count of FPGA accelerators for the instance type.</p>",
          "locationName":"count"
        },
        "MemoryInfo":{
          "shape":"FpgaDeviceMemoryInfo",
          "documentation":"<p>Describes the memory for the FPGA accelerator for the instance type.</p>",
          "locationName":"memoryInfo"
        }
      },
      "documentation":"<p>Describes the FPGA accelerator for the instance type.</p>"
    },
    "FpgaDeviceInfoList":{
      "type":"list",
      "member":{
        "shape":"FpgaDeviceInfo",
        "locationName":"item"
      }
    },
    "FpgaDeviceManufacturerName":{"type":"string"},
    "FpgaDeviceMemoryInfo":{
      "type":"structure",
      "members":{
        "SizeInMiB":{
          "shape":"FpgaDeviceMemorySize",
          "documentation":"<p>The size of the memory available to the FPGA accelerator, in MiB.</p>",
          "locationName":"sizeInMiB"
        }
      },
      "documentation":"<p>Describes the memory for the FPGA accelerator for the instance type.</p>"
    },
    "FpgaDeviceMemorySize":{"type":"integer"},
    "FpgaDeviceName":{"type":"string"},
    "FpgaImage":{
      "type":"structure",
      "members":{
        "FpgaImageId":{
          "shape":"String",
          "documentation":"<p>The FPGA image identifier (AFI ID).</p>",
          "locationName":"fpgaImageId"
        },
        "FpgaImageGlobalId":{
          "shape":"String",
          "documentation":"<p>The global FPGA image identifier (AGFI ID).</p>",
          "locationName":"fpgaImageGlobalId"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the AFI.</p>",
          "locationName":"name"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the AFI.</p>",
          "locationName":"description"
        },
        "ShellVersion":{
          "shape":"String",
          "documentation":"<p>The version of the Amazon Web Services Shell that was used to create the bitstream.</p>",
          "locationName":"shellVersion"
        },
        "PciId":{
          "shape":"PciId",
          "documentation":"<p>Information about the PCI bus.</p>",
          "locationName":"pciId"
        },
        "State":{
          "shape":"FpgaImageState",
          "documentation":"<p>Information about the state of the AFI.</p>",
          "locationName":"state"
        },
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time the AFI was created.</p>",
          "locationName":"createTime"
        },
        "UpdateTime":{
          "shape":"DateTime",
          "documentation":"<p>The time of the most recent update to the AFI.</p>",
          "locationName":"updateTime"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the AFI.</p>",
          "locationName":"ownerId"
        },
        "OwnerAlias":{
          "shape":"String",
          "documentation":"<p>The alias of the AFI owner. Possible values include <code>self</code>, <code>amazon</code>, and <code>aws-marketplace</code>.</p>",
          "locationName":"ownerAlias"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>The product codes for the AFI.</p>",
          "locationName":"productCodes"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the AFI.</p>",
          "locationName":"tags"
        },
        "Public":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the AFI is public.</p>",
          "locationName":"public"
        },
        "DataRetentionSupport":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether data retention support is enabled for the AFI.</p>",
          "locationName":"dataRetentionSupport"
        },
        "InstanceTypes":{
          "shape":"InstanceTypesList",
          "documentation":"<p>The instance types supported by the AFI.</p>",
          "locationName":"instanceTypes"
        }
      },
      "documentation":"<p>Describes an Amazon FPGA image (AFI).</p>"
    },
    "FpgaImageAttribute":{
      "type":"structure",
      "members":{
        "FpgaImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AFI.</p>",
          "locationName":"fpgaImageId"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the AFI.</p>",
          "locationName":"name"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the AFI.</p>",
          "locationName":"description"
        },
        "LoadPermissions":{
          "shape":"LoadPermissionList",
          "documentation":"<p>The load permissions.</p>",
          "locationName":"loadPermissions"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>The product codes.</p>",
          "locationName":"productCodes"
        }
      },
      "documentation":"<p>Describes an Amazon FPGA image (AFI) attribute.</p>"
    },
    "FpgaImageAttributeName":{
      "type":"string",
      "enum":[
        "description",
        "name",
        "loadPermission",
        "productCodes"
      ]
    },
    "FpgaImageId":{"type":"string"},
    "FpgaImageIdList":{
      "type":"list",
      "member":{
        "shape":"FpgaImageId",
        "locationName":"item"
      }
    },
    "FpgaImageList":{
      "type":"list",
      "member":{
        "shape":"FpgaImage",
        "locationName":"item"
      }
    },
    "FpgaImageState":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"FpgaImageStateCode",
          "documentation":"<p>The state. The following are the possible values:</p> <ul> <li> <p> <code>pending</code> - AFI bitstream generation is in progress.</p> </li> <li> <p> <code>available</code> - The AFI is available for use.</p> </li> <li> <p> <code>failed</code> - AFI bitstream generation failed.</p> </li> <li> <p> <code>unavailable</code> - The AFI is no longer available for use.</p> </li> </ul>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>If the state is <code>failed</code>, this is the error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the state of the bitstream generation process for an Amazon FPGA image (AFI).</p>"
    },
    "FpgaImageStateCode":{
      "type":"string",
      "enum":[
        "pending",
        "failed",
        "available",
        "unavailable"
      ]
    },
    "FpgaInfo":{
      "type":"structure",
      "members":{
        "Fpgas":{
          "shape":"FpgaDeviceInfoList",
          "documentation":"<p>Describes the FPGAs for the instance type.</p>",
          "locationName":"fpgas"
        },
        "TotalFpgaMemoryInMiB":{
          "shape":"totalFpgaMemory",
          "documentation":"<p>The total memory of all FPGA accelerators for the instance type.</p>",
          "locationName":"totalFpgaMemoryInMiB"
        }
      },
      "documentation":"<p>Describes the FPGAs for the instance type.</p>"
    },
    "FreeTierEligibleFlag":{"type":"boolean"},
    "GVCDMaxResults":{
      "type":"integer",
      "max":1000,
      "min":200
    },
    "GatewayAssociationState":{
      "type":"string",
      "enum":[
        "associated",
        "not-associated",
        "associating",
        "disassociating"
      ]
    },
    "GatewayType":{
      "type":"string",
      "enum":["ipsec.1"]
    },
    "GetAssociatedEnclaveCertificateIamRolesRequest":{
      "type":"structure",
      "required":["CertificateArn"],
      "members":{
        "CertificateArn":{
          "shape":"CertificateId",
          "documentation":"<p>The ARN of the ACM certificate for which to view the associated IAM roles, encryption keys, and Amazon S3 object information.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetAssociatedEnclaveCertificateIamRolesResult":{
      "type":"structure",
      "members":{
        "AssociatedRoles":{
          "shape":"AssociatedRolesList",
          "documentation":"<p>Information about the associated IAM roles.</p>",
          "locationName":"associatedRoleSet"
        }
      }
    },
    "GetAssociatedIpv6PoolCidrsRequest":{
      "type":"structure",
      "required":["PoolId"],
      "members":{
        "PoolId":{
          "shape":"Ipv6PoolEc2Id",
          "documentation":"<p>The ID of the IPv6 address pool.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"Ipv6PoolMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetAssociatedIpv6PoolCidrsResult":{
      "type":"structure",
      "members":{
        "Ipv6CidrAssociations":{
          "shape":"Ipv6CidrAssociationSet",
          "documentation":"<p>Information about the IPv6 CIDR block associations.</p>",
          "locationName":"ipv6CidrAssociationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetAwsNetworkPerformanceDataRequest":{
      "type":"structure",
      "members":{
        "DataQueries":{
          "shape":"DataQueries",
          "documentation":"<p>A list of network performance data queries.</p>",
          "locationName":"DataQuery"
        },
        "StartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The starting time for the performance data request. The starting time must be formatted as <code>yyyy-mm-ddThh:mm:ss</code>. For example, <code>2022-06-10T12:00:00.000Z</code>.</p>"
        },
        "EndTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The ending time for the performance data request. The end time must be formatted as <code>yyyy-mm-ddThh:mm:ss</code>. For example, <code>2022-06-12T12:00:00.000Z</code>.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetAwsNetworkPerformanceDataResult":{
      "type":"structure",
      "members":{
        "DataResponses":{
          "shape":"DataResponses",
          "documentation":"<p>The list of data responses.</p>",
          "locationName":"dataResponseSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetCapacityReservationUsageRequest":{
      "type":"structure",
      "required":["CapacityReservationId"],
      "members":{
        "CapacityReservationId":{
          "shape":"CapacityReservationId",
          "documentation":"<p>The ID of the Capacity Reservation.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"GetCapacityReservationUsageRequestMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p> <p>Valid range: Minimum value of 1. Maximum value of 1000.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetCapacityReservationUsageRequestMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "GetCapacityReservationUsageResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "CapacityReservationId":{
          "shape":"String",
          "documentation":"<p>The ID of the Capacity Reservation.</p>",
          "locationName":"capacityReservationId"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The type of instance for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"instanceType"
        },
        "TotalInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances for which the Capacity Reservation reserves capacity.</p>",
          "locationName":"totalInstanceCount"
        },
        "AvailableInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The remaining capacity. Indicates the number of instances that can be launched in the Capacity Reservation.</p>",
          "locationName":"availableInstanceCount"
        },
        "State":{
          "shape":"CapacityReservationState",
          "documentation":"<p>The current state of the Capacity Reservation. A Capacity Reservation can be in one of the following states:</p> <ul> <li> <p> <code>active</code> - The Capacity Reservation is active and the capacity is available for your use.</p> </li> <li> <p> <code>expired</code> - The Capacity Reservation expired automatically at the date and time specified in your request. The reserved capacity is no longer available for your use.</p> </li> <li> <p> <code>cancelled</code> - The Capacity Reservation was cancelled. The reserved capacity is no longer available for your use.</p> </li> <li> <p> <code>pending</code> - The Capacity Reservation request was successful but the capacity provisioning is still pending.</p> </li> <li> <p> <code>failed</code> - The Capacity Reservation request has failed. A request might fail due to invalid request parameters, capacity constraints, or instance limit constraints. Failed requests are retained for 60 minutes.</p> </li> </ul>",
          "locationName":"state"
        },
        "InstanceUsages":{
          "shape":"InstanceUsageSet",
          "documentation":"<p>Information about the Capacity Reservation usage.</p>",
          "locationName":"instanceUsageSet"
        }
      }
    },
    "GetCoipPoolUsageRequest":{
      "type":"structure",
      "required":["PoolId"],
      "members":{
        "PoolId":{
          "shape":"Ipv4PoolCoipId",
          "documentation":"<p>The ID of the address pool.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>coip-address-usage.allocation-id</code> - The allocation ID of the address.</p> </li> <li> <p> <code>coip-address-usage.aws-account-id</code> - The ID of the Amazon Web Services account that is using the customer-owned IP address.</p> </li> <li> <p> <code>coip-address-usage.aws-service</code> - The Amazon Web Services service that is using the customer-owned IP address.</p> </li> <li> <p> <code>coip-address-usage.co-ip</code> - The customer-owned IP address.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"CoipPoolMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetCoipPoolUsageResult":{
      "type":"structure",
      "members":{
        "CoipPoolId":{
          "shape":"String",
          "documentation":"<p>The ID of the customer-owned address pool.</p>",
          "locationName":"coipPoolId"
        },
        "CoipAddressUsages":{
          "shape":"CoipAddressUsageSet",
          "documentation":"<p>Information about the address usage.</p>",
          "locationName":"coipAddressUsageSet"
        },
        "LocalGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableId"
        }
      }
    },
    "GetConsoleOutputRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Latest":{
          "shape":"Boolean",
          "documentation":"<p>When enabled, retrieves the latest console output for the instance.</p> <p>Default: disabled (<code>false</code>)</p>"
        }
      }
    },
    "GetConsoleOutputResult":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "Output":{
          "shape":"String",
          "documentation":"<p>The console output, base64-encoded. If you are using a command line tool, the tool decodes the output for you.</p>",
          "locationName":"output"
        },
        "Timestamp":{
          "shape":"DateTime",
          "documentation":"<p>The time at which the output was last updated.</p>",
          "locationName":"timestamp"
        }
      }
    },
    "GetConsoleScreenshotRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "WakeUp":{
          "shape":"Boolean",
          "documentation":"<p>When set to <code>true</code>, acts as keystroke input and wakes up an instance that's in standby or \"sleep\" mode.</p>"
        }
      }
    },
    "GetConsoleScreenshotResult":{
      "type":"structure",
      "members":{
        "ImageData":{
          "shape":"String",
          "documentation":"<p>The data that comprises the image.</p>",
          "locationName":"imageData"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        }
      }
    },
    "GetDefaultCreditSpecificationRequest":{
      "type":"structure",
      "required":["InstanceFamily"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceFamily":{
          "shape":"UnlimitedSupportedInstanceFamily",
          "documentation":"<p>The instance family.</p>"
        }
      }
    },
    "GetDefaultCreditSpecificationResult":{
      "type":"structure",
      "members":{
        "InstanceFamilyCreditSpecification":{
          "shape":"InstanceFamilyCreditSpecification",
          "documentation":"<p>The default credit option for CPU usage of the instance family.</p>",
          "locationName":"instanceFamilyCreditSpecification"
        }
      }
    },
    "GetEbsDefaultKmsKeyIdRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetEbsDefaultKmsKeyIdResult":{
      "type":"structure",
      "members":{
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the default KMS key for encryption by default.</p>",
          "locationName":"kmsKeyId"
        }
      }
    },
    "GetEbsEncryptionByDefaultRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetEbsEncryptionByDefaultResult":{
      "type":"structure",
      "members":{
        "EbsEncryptionByDefault":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether encryption by default is enabled.</p>",
          "locationName":"ebsEncryptionByDefault"
        }
      }
    },
    "GetFlowLogsIntegrationTemplateRequest":{
      "type":"structure",
      "required":[
        "FlowLogId",
        "ConfigDeliveryS3DestinationArn",
        "IntegrateServices"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FlowLogId":{
          "shape":"VpcFlowLogId",
          "documentation":"<p>The ID of the flow log.</p>"
        },
        "ConfigDeliveryS3DestinationArn":{
          "shape":"String",
          "documentation":"<p>To store the CloudFormation template in Amazon S3, specify the location in Amazon S3.</p>"
        },
        "IntegrateServices":{
          "shape":"IntegrateServices",
          "documentation":"<p>Information about the service integration.</p>",
          "locationName":"IntegrateService"
        }
      }
    },
    "GetFlowLogsIntegrationTemplateResult":{
      "type":"structure",
      "members":{
        "Result":{
          "shape":"String",
          "documentation":"<p>The generated CloudFormation template.</p>",
          "locationName":"result"
        }
      }
    },
    "GetGroupsForCapacityReservationRequest":{
      "type":"structure",
      "required":["CapacityReservationId"],
      "members":{
        "CapacityReservationId":{
          "shape":"CapacityReservationId",
          "documentation":"<p>The ID of the Capacity Reservation.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"GetGroupsForCapacityReservationRequestMaxResults",
          "documentation":"<p>The maximum number of results to return for the request in a single page. The remaining results can be seen by sending another request with the returned <code>nextToken</code> value. This value can be between 5 and 500. If <code>maxResults</code> is given a larger value than 500, you receive an error.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetGroupsForCapacityReservationRequestMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "GetGroupsForCapacityReservationResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "CapacityReservationGroups":{
          "shape":"CapacityReservationGroupSet",
          "documentation":"<p>Information about the resource groups to which the Capacity Reservation has been added.</p>",
          "locationName":"capacityReservationGroupSet"
        }
      }
    },
    "GetHostReservationPurchasePreviewRequest":{
      "type":"structure",
      "required":[
        "HostIdSet",
        "OfferingId"
      ],
      "members":{
        "HostIdSet":{
          "shape":"RequestHostIdSet",
          "documentation":"<p>The IDs of the Dedicated Hosts with which the reservation is associated.</p>"
        },
        "OfferingId":{
          "shape":"OfferingId",
          "documentation":"<p>The offering ID of the reservation.</p>"
        }
      }
    },
    "GetHostReservationPurchasePreviewResult":{
      "type":"structure",
      "members":{
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency in which the <code>totalUpfrontPrice</code> and <code>totalHourlyPrice</code> amounts are specified. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "Purchase":{
          "shape":"PurchaseSet",
          "documentation":"<p>The purchase information of the Dedicated Host reservation and the Dedicated Hosts associated with it.</p>",
          "locationName":"purchase"
        },
        "TotalHourlyPrice":{
          "shape":"String",
          "documentation":"<p>The potential total hourly price of the reservation per hour.</p>",
          "locationName":"totalHourlyPrice"
        },
        "TotalUpfrontPrice":{
          "shape":"String",
          "documentation":"<p>The potential total upfront price. This is billed immediately.</p>",
          "locationName":"totalUpfrontPrice"
        }
      }
    },
    "GetInstanceTypesFromInstanceRequirementsRequest":{
      "type":"structure",
      "required":[
        "ArchitectureTypes",
        "VirtualizationTypes",
        "InstanceRequirements"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ArchitectureTypes":{
          "shape":"ArchitectureTypeSet",
          "documentation":"<p>The processor architecture type.</p>",
          "locationName":"ArchitectureType"
        },
        "VirtualizationTypes":{
          "shape":"VirtualizationTypeSet",
          "documentation":"<p>The virtualization type.</p>",
          "locationName":"VirtualizationType"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirementsRequest",
          "documentation":"<p>The attributes required for the instance types.</p>"
        },
        "MaxResults":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and
 1000. The default value is 1000. To retrieve the remaining results, make another call with
 the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        }
      }
    },
    "GetInstanceTypesFromInstanceRequirementsResult":{
      "type":"structure",
      "members":{
        "InstanceTypes":{
          "shape":"InstanceTypeInfoFromInstanceRequirementsSet",
          "documentation":"<p>The instance types with the specified instance attributes.</p>",
          "locationName":"instanceTypeSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetInstanceUefiDataRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance from which to retrieve the UEFI data.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetInstanceUefiDataResult":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance from which to retrieve the UEFI data.</p>",
          "locationName":"instanceId"
        },
        "UefiData":{
          "shape":"String",
          "documentation":"<p>Base64 representation of the non-volatile UEFI variable store.</p>",
          "locationName":"uefiData"
        }
      }
    },
    "GetIpamAddressHistoryRequest":{
      "type":"structure",
      "required":[
        "Cidr",
        "IpamScopeId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR you want the history of. The CIDR can be an IPv4 or IPv6 IP address range. If you enter a /16 IPv4 CIDR, you will get records that match it exactly. You will not get records for any subnets within the /16 CIDR.</p>"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the IPAM scope that the CIDR is in.</p>"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC you want your history records filtered by.</p>"
        },
        "StartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The start of the time period for which you are looking for history. If you omit this option, it will default to the value of EndTime.</p>"
        },
        "EndTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The end of the time period for which you are looking for history. If you omit this option, it will default to the current time.</p>"
        },
        "MaxResults":{
          "shape":"IpamAddressHistoryMaxResults",
          "documentation":"<p>The maximum number of historical results you would like returned per page. Defaults to 100.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "GetIpamAddressHistoryResult":{
      "type":"structure",
      "members":{
        "HistoryRecords":{
          "shape":"IpamAddressHistoryRecordSet",
          "documentation":"<p>A historical record for a CIDR within an IPAM scope. If the CIDR is associated with an EC2 instance, you will see an object in the response for the instance and one for the network interface.</p>",
          "locationName":"historyRecordSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetIpamDiscoveredAccountsRequest":{
      "type":"structure",
      "required":[
        "IpamResourceDiscoveryId",
        "DiscoveryRegion"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>A resource discovery ID.</p>"
        },
        "DiscoveryRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region that the account information is returned from.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>Discovered account filters.</p>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of discovered accounts to return in one page of results.</p>"
        }
      }
    },
    "GetIpamDiscoveredAccountsResult":{
      "type":"structure",
      "members":{
        "IpamDiscoveredAccounts":{
          "shape":"IpamDiscoveredAccountSet",
          "documentation":"<p>Discovered accounts.</p>",
          "locationName":"ipamDiscoveredAccountSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetIpamDiscoveredResourceCidrsRequest":{
      "type":"structure",
      "required":[
        "IpamResourceDiscoveryId",
        "ResourceRegion"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>A resource discovery ID.</p>"
        },
        "ResourceRegion":{
          "shape":"String",
          "documentation":"<p>A resource Region.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>Filters.</p>",
          "locationName":"Filter"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of discovered resource CIDRs to return in one page of results.</p>"
        }
      }
    },
    "GetIpamDiscoveredResourceCidrsResult":{
      "type":"structure",
      "members":{
        "IpamDiscoveredResourceCidrs":{
          "shape":"IpamDiscoveredResourceCidrSet",
          "documentation":"<p>Discovered resource CIDRs.</p>",
          "locationName":"ipamDiscoveredResourceCidrSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>Specify the pagination token from a previous request to retrieve the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetIpamPoolAllocationsMaxResults":{
      "type":"integer",
      "max":100000,
      "min":1000
    },
    "GetIpamPoolAllocationsRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool you want to see the allocations for.</p>"
        },
        "IpamPoolAllocationId":{
          "shape":"IpamPoolAllocationId",
          "documentation":"<p>The ID of the allocation.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters for the request. For more information about filtering, see <a href=\"https://docs.aws.amazon.com/cli/latest/userguide/cli-usage-filter.html\">Filtering CLI output</a>.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"GetIpamPoolAllocationsMaxResults",
          "documentation":"<p>The maximum number of results you would like returned per page.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "GetIpamPoolAllocationsResult":{
      "type":"structure",
      "members":{
        "IpamPoolAllocations":{
          "shape":"IpamPoolAllocationSet",
          "documentation":"<p>The IPAM pool allocations you want information on.</p>",
          "locationName":"ipamPoolAllocationSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetIpamPoolCidrsRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool you want the CIDR for.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters for the request. For more information about filtering, see <a href=\"https://docs.aws.amazon.com/cli/latest/userguide/cli-usage-filter.html\">Filtering CLI output</a>.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of results to return in the request.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "GetIpamPoolCidrsResult":{
      "type":"structure",
      "members":{
        "IpamPoolCidrs":{
          "shape":"IpamPoolCidrSet",
          "documentation":"<p>Information about the CIDRs provisioned to an IPAM pool.</p>",
          "locationName":"ipamPoolCidrSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetIpamResourceCidrsRequest":{
      "type":"structure",
      "required":["IpamScopeId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters for the request. For more information about filtering, see <a href=\"https://docs.aws.amazon.com/cli/latest/userguide/cli-usage-filter.html\">Filtering CLI output</a>.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"IpamMaxResults",
          "documentation":"<p>The maximum number of results to return in the request.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the scope that the resource is in.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool that the resource is in.</p>"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>"
        },
        "ResourceType":{
          "shape":"IpamResourceType",
          "documentation":"<p>The resource type.</p>"
        },
        "ResourceTag":{
          "shape":"RequestIpamResourceTag",
          "documentation":"<p>The resource tag.</p>"
        },
        "ResourceOwner":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the resource.</p>"
        }
      }
    },
    "GetIpamResourceCidrsResult":{
      "type":"structure",
      "members":{
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        },
        "IpamResourceCidrs":{
          "shape":"IpamResourceCidrSet",
          "documentation":"<p>The resource CIDRs.</p>",
          "locationName":"ipamResourceCidrSet"
        }
      }
    },
    "GetLaunchTemplateDataRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        }
      }
    },
    "GetLaunchTemplateDataResult":{
      "type":"structure",
      "members":{
        "LaunchTemplateData":{
          "shape":"ResponseLaunchTemplateData",
          "documentation":"<p>The instance data.</p>",
          "locationName":"launchTemplateData"
        }
      }
    },
    "GetManagedPrefixListAssociationsMaxResults":{
      "type":"integer",
      "max":255,
      "min":5
    },
    "GetManagedPrefixListAssociationsRequest":{
      "type":"structure",
      "required":["PrefixListId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "MaxResults":{
          "shape":"GetManagedPrefixListAssociationsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "GetManagedPrefixListAssociationsResult":{
      "type":"structure",
      "members":{
        "PrefixListAssociations":{
          "shape":"PrefixListAssociationSet",
          "documentation":"<p>Information about the associations.</p>",
          "locationName":"prefixListAssociationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetManagedPrefixListEntriesRequest":{
      "type":"structure",
      "required":["PrefixListId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "TargetVersion":{
          "shape":"Long",
          "documentation":"<p>The version of the prefix list for which to return the entries. The default is the current version.</p>"
        },
        "MaxResults":{
          "shape":"PrefixListMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        }
      }
    },
    "GetManagedPrefixListEntriesResult":{
      "type":"structure",
      "members":{
        "Entries":{
          "shape":"PrefixListEntrySet",
          "documentation":"<p>Information about the prefix list entries.</p>",
          "locationName":"entrySet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetNetworkInsightsAccessScopeAnalysisFindingsRequest":{
      "type":"structure",
      "required":["NetworkInsightsAccessScopeAnalysisId"],
      "members":{
        "NetworkInsightsAccessScopeAnalysisId":{
          "shape":"NetworkInsightsAccessScopeAnalysisId",
          "documentation":"<p>The ID of the Network Access Scope analysis.</p>"
        },
        "MaxResults":{
          "shape":"NetworkInsightsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetNetworkInsightsAccessScopeAnalysisFindingsResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalysisId":{
          "shape":"NetworkInsightsAccessScopeAnalysisId",
          "documentation":"<p>The ID of the Network Access Scope analysis.</p>",
          "locationName":"networkInsightsAccessScopeAnalysisId"
        },
        "AnalysisStatus":{
          "shape":"AnalysisStatus",
          "documentation":"<p>The status of Network Access Scope Analysis.</p>",
          "locationName":"analysisStatus"
        },
        "AnalysisFindings":{
          "shape":"AccessScopeAnalysisFindingList",
          "documentation":"<p>The findings associated with Network Access Scope Analysis.</p>",
          "locationName":"analysisFindingSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetNetworkInsightsAccessScopeContentRequest":{
      "type":"structure",
      "required":["NetworkInsightsAccessScopeId"],
      "members":{
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetNetworkInsightsAccessScopeContentResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeContent":{
          "shape":"NetworkInsightsAccessScopeContent",
          "documentation":"<p>The Network Access Scope content.</p>",
          "locationName":"networkInsightsAccessScopeContent"
        }
      }
    },
    "GetPasswordDataRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the Windows instance.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "GetPasswordDataResult":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Windows instance.</p>",
          "locationName":"instanceId"
        },
        "PasswordData":{
          "shape":"String",
          "documentation":"<p>The password of the instance. Returns an empty string if the password is not available.</p>",
          "locationName":"passwordData"
        },
        "Timestamp":{
          "shape":"DateTime",
          "documentation":"<p>The time the data was last updated.</p>",
          "locationName":"timestamp"
        }
      }
    },
    "GetReservedInstancesExchangeQuoteRequest":{
      "type":"structure",
      "required":["ReservedInstanceIds"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ReservedInstanceIds":{
          "shape":"ReservedInstanceIdSet",
          "documentation":"<p>The IDs of the Convertible Reserved Instances to exchange.</p>",
          "locationName":"ReservedInstanceId"
        },
        "TargetConfigurations":{
          "shape":"TargetConfigurationRequestSet",
          "documentation":"<p>The configuration of the target Convertible Reserved Instance to exchange for your current Convertible Reserved Instances.</p>",
          "locationName":"TargetConfiguration"
        }
      },
      "documentation":"<p>Contains the parameters for GetReservedInstanceExchangeQuote.</p>"
    },
    "GetReservedInstancesExchangeQuoteResult":{
      "type":"structure",
      "members":{
        "CurrencyCode":{
          "shape":"String",
          "documentation":"<p>The currency of the transaction.</p>",
          "locationName":"currencyCode"
        },
        "IsValidExchange":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, the exchange is valid. If <code>false</code>, the exchange cannot be completed.</p>",
          "locationName":"isValidExchange"
        },
        "OutputReservedInstancesWillExpireAt":{
          "shape":"DateTime",
          "documentation":"<p>The new end date of the reservation term.</p>",
          "locationName":"outputReservedInstancesWillExpireAt"
        },
        "PaymentDue":{
          "shape":"String",
          "documentation":"<p>The total true upfront charge for the exchange.</p>",
          "locationName":"paymentDue"
        },
        "ReservedInstanceValueRollup":{
          "shape":"ReservationValue",
          "documentation":"<p>The cost associated with the Reserved Instance.</p>",
          "locationName":"reservedInstanceValueRollup"
        },
        "ReservedInstanceValueSet":{
          "shape":"ReservedInstanceReservationValueSet",
          "documentation":"<p>The configuration of your Convertible Reserved Instances.</p>",
          "locationName":"reservedInstanceValueSet"
        },
        "TargetConfigurationValueRollup":{
          "shape":"ReservationValue",
          "documentation":"<p>The cost associated with the Reserved Instance.</p>",
          "locationName":"targetConfigurationValueRollup"
        },
        "TargetConfigurationValueSet":{
          "shape":"TargetReservationValueSet",
          "documentation":"<p>The values of the target Convertible Reserved Instances.</p>",
          "locationName":"targetConfigurationValueSet"
        },
        "ValidationFailureReason":{
          "shape":"String",
          "documentation":"<p>Describes the reason why the exchange cannot be completed.</p>",
          "locationName":"validationFailureReason"
        }
      },
      "documentation":"<p>Contains the output of GetReservedInstancesExchangeQuote.</p>"
    },
    "GetSerialConsoleAccessStatusRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetSerialConsoleAccessStatusResult":{
      "type":"structure",
      "members":{
        "SerialConsoleAccessEnabled":{
          "shape":"Boolean",
          "documentation":"<p>If <code>true</code>, access to the EC2 serial console of all instances is enabled for your account. If <code>false</code>, access to the EC2 serial console of all instances is disabled for your account.</p>",
          "locationName":"serialConsoleAccessEnabled"
        }
      }
    },
    "GetSpotPlacementScoresRequest":{
      "type":"structure",
      "required":["TargetCapacity"],
      "members":{
        "InstanceTypes":{
          "shape":"InstanceTypes",
          "documentation":"<p>The instance types. We recommend that you specify at least three instance types. If you specify one or two instance types, or specify variations of a single instance type (for example, an <code>m3.xlarge</code> with and without instance storage), the returned placement score will always be low. </p> <p>If you specify <code>InstanceTypes</code>, you can't specify <code>InstanceRequirementsWithMetadata</code>.</p>",
          "locationName":"InstanceType"
        },
        "TargetCapacity":{
          "shape":"SpotPlacementScoresTargetCapacity",
          "documentation":"<p>The target capacity.</p>"
        },
        "TargetCapacityUnitType":{
          "shape":"TargetCapacityUnitType",
          "documentation":"<p>The unit for the target capacity.</p> <p>Default: <code>units</code> (translates to number of instances)</p>"
        },
        "SingleAvailabilityZone":{
          "shape":"Boolean",
          "documentation":"<p>Specify <code>true</code> so that the response returns a list of scored Availability Zones. Otherwise, the response returns a list of scored Regions.</p> <p>A list of scored Availability Zones is useful if you want to launch all of your Spot capacity into a single Availability Zone.</p>"
        },
        "RegionNames":{
          "shape":"RegionNames",
          "documentation":"<p>The Regions used to narrow down the list of Regions to be scored. Enter the Region code, for example, <code>us-east-1</code>.</p>",
          "locationName":"RegionName"
        },
        "InstanceRequirementsWithMetadata":{
          "shape":"InstanceRequirementsWithMetadataRequest",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.</p> <p>If you specify <code>InstanceRequirementsWithMetadata</code>, you can't specify <code>InstanceTypes</code>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "MaxResults":{
          "shape":"SpotPlacementScoresMaxResults",
          "documentation":"<p>The maximum number of results to return in a single call. Specify a value between 1 and
 1000. The default value is 1000. To retrieve the remaining results, make another call with
 the returned <code>NextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>"
        }
      }
    },
    "GetSpotPlacementScoresResult":{
      "type":"structure",
      "members":{
        "SpotPlacementScores":{
          "shape":"SpotPlacementScores",
          "documentation":"<p>The Spot placement score for the top 10 Regions or Availability Zones, scored on a scale from 1 to 10. Each score
 reflects how likely it is that each Region or Availability Zone will succeed at fulfilling the specified target capacity
 <i>at the time of the Spot placement score request</i>. A score of <code>10</code> means that your Spot capacity request is highly likely to succeed in that Region or Availability Zone. </p> <p>If you request a Spot placement score for Regions, a high score assumes that your fleet request will be configured to use all Availability Zones and the <code>capacity-optimized</code> allocation strategy. If you request a Spot placement score for Availability Zones, a high score assumes that your fleet request will be configured to use a single Availability Zone and the <code>capacity-optimized</code> allocation strategy.</p> <p>Different
 Regions or Availability Zones might return the same score.</p> <note> <p>The Spot placement score serves as a recommendation only. No score guarantees that your Spot request will be fully or partially fulfilled.</p> </note>",
          "locationName":"spotPlacementScoreSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next set of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetSubnetCidrReservationsMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "GetSubnetCidrReservationsRequest":{
      "type":"structure",
      "required":["SubnetId"],
      "members":{
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>reservationType</code> - The type of reservation (<code>prefix</code> | <code>explicit</code>).</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet.</p> </li> <li> <p> <code>tag</code>:<key> - The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p> </li> <li> <p> <code>tag-key</code> - The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"GetSubnetCidrReservationsMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        }
      }
    },
    "GetSubnetCidrReservationsResult":{
      "type":"structure",
      "members":{
        "SubnetIpv4CidrReservations":{
          "shape":"SubnetCidrReservationList",
          "documentation":"<p>Information about the IPv4 subnet CIDR reservations.</p>",
          "locationName":"subnetIpv4CidrReservationSet"
        },
        "SubnetIpv6CidrReservations":{
          "shape":"SubnetCidrReservationList",
          "documentation":"<p>Information about the IPv6 subnet CIDR reservations.</p>",
          "locationName":"subnetIpv6CidrReservationSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetTransitGatewayAttachmentPropagationsRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>transit-gateway-route-table-id</code> - The ID of the transit gateway route table.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayAttachmentPropagationsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentPropagations":{
          "shape":"TransitGatewayAttachmentPropagationList",
          "documentation":"<p>Information about the propagation route tables.</p>",
          "locationName":"transitGatewayAttachmentPropagations"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetTransitGatewayMulticastDomainAssociationsRequest":{
      "type":"structure",
      "required":["TransitGatewayMulticastDomainId"],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>resource-id</code> - The ID of the resource.</p> </li> <li> <p> <code>resource-type</code> - The type of resource. The valid value is: <code>vpc</code>.</p> </li> <li> <p> <code>state</code> - The state of the subnet association. Valid values are <code>associated</code> | <code>associating</code> | <code>disassociated</code> | <code>disassociating</code>.</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet.</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The id of the transit gateway attachment.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayMulticastDomainAssociationsResult":{
      "type":"structure",
      "members":{
        "MulticastDomainAssociations":{
          "shape":"TransitGatewayMulticastDomainAssociationList",
          "documentation":"<p>Information about the multicast domain associations.</p>",
          "locationName":"multicastDomainAssociations"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetTransitGatewayPolicyTableAssociationsRequest":{
      "type":"structure",
      "required":["TransitGatewayPolicyTableId"],
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The ID of the transit gateway policy table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters associated with the transit gateway policy table.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayPolicyTableAssociationsResult":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"TransitGatewayPolicyTableAssociationList",
          "documentation":"<p>Returns details about the transit gateway policy table association.</p>",
          "locationName":"associations"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetTransitGatewayPolicyTableEntriesRequest":{
      "type":"structure",
      "required":["TransitGatewayPolicyTableId"],
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The ID of the transit gateway policy table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>The filters associated with the transit gateway policy table.</p>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayPolicyTableEntriesResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTableEntries":{
          "shape":"TransitGatewayPolicyTableEntryList",
          "documentation":"<p>The entries for the transit gateway policy table.</p>",
          "locationName":"transitGatewayPolicyTableEntries"
        }
      }
    },
    "GetTransitGatewayPrefixListReferencesRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableId"],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>attachment.resource-id</code> - The ID of the resource for the attachment.</p> </li> <li> <p> <code>attachment.resource-type</code> - The type of resource for the attachment. Valid values are <code>vpc</code> | <code>vpn</code> | <code>direct-connect-gateway</code> | <code>peering</code>.</p> </li> <li> <p> <code>attachment.transit-gateway-attachment-id</code> - The ID of the attachment.</p> </li> <li> <p> <code>is-blackhole</code> - Whether traffic matching the route is blocked (<code>true</code> | <code>false</code>).</p> </li> <li> <p> <code>prefix-list-id</code> - The ID of the prefix list.</p> </li> <li> <p> <code>prefix-list-owner-id</code> - The ID of the owner of the prefix list.</p> </li> <li> <p> <code>state</code> - The state of the prefix list reference (<code>pending</code> | <code>available</code> | <code>modifying</code> | <code>deleting</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayPrefixListReferencesResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPrefixListReferences":{
          "shape":"TransitGatewayPrefixListReferenceSet",
          "documentation":"<p>Information about the prefix list references.</p>",
          "locationName":"transitGatewayPrefixListReferenceSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetTransitGatewayRouteTableAssociationsRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableId"],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>resource-id</code> - The ID of the resource.</p> </li> <li> <p> <code>resource-type</code> - The resource type. Valid values are <code>vpc</code> | <code>vpn</code> | <code>direct-connect-gateway</code> | <code>peering</code> | <code>connect</code>.</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the attachment.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayRouteTableAssociationsResult":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"TransitGatewayRouteTableAssociationList",
          "documentation":"<p>Information about the associations.</p>",
          "locationName":"associations"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetTransitGatewayRouteTablePropagationsRequest":{
      "type":"structure",
      "required":["TransitGatewayRouteTableId"],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>resource-id</code> - The ID of the resource.</p> </li> <li> <p> <code>resource-type</code> - The resource type. Valid values are <code>vpc</code> | <code>vpn</code> | <code>direct-connect-gateway</code> | <code>peering</code> | <code>connect</code>.</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The ID of the attachment.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetTransitGatewayRouteTablePropagationsResult":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTablePropagations":{
          "shape":"TransitGatewayRouteTablePropagationList",
          "documentation":"<p>Information about the route table propagations.</p>",
          "locationName":"transitGatewayRouteTablePropagations"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GetVerifiedAccessEndpointPolicyRequest":{
      "type":"structure",
      "required":["VerifiedAccessEndpointId"],
      "members":{
        "VerifiedAccessEndpointId":{
          "shape":"VerifiedAccessEndpointId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetVerifiedAccessEndpointPolicyResult":{
      "type":"structure",
      "members":{
        "PolicyEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The status of the Verified Access policy.</p>",
          "locationName":"policyEnabled"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>",
          "locationName":"policyDocument"
        }
      }
    },
    "GetVerifiedAccessGroupPolicyRequest":{
      "type":"structure",
      "required":["VerifiedAccessGroupId"],
      "members":{
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetVerifiedAccessGroupPolicyResult":{
      "type":"structure",
      "members":{
        "PolicyEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The status of the Verified Access policy.</p>",
          "locationName":"policyEnabled"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>",
          "locationName":"policyDocument"
        }
      }
    },
    "GetVpnConnectionDeviceSampleConfigurationRequest":{
      "type":"structure",
      "required":[
        "VpnConnectionId",
        "VpnConnectionDeviceTypeId"
      ],
      "members":{
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The <code>VpnConnectionId</code> specifies the Site-to-Site VPN connection used for the sample configuration.</p>"
        },
        "VpnConnectionDeviceTypeId":{
          "shape":"VpnConnectionDeviceTypeId",
          "documentation":"<p>Device identifier provided by the <code>GetVpnConnectionDeviceTypes</code> API.</p>"
        },
        "InternetKeyExchangeVersion":{
          "shape":"String",
          "documentation":"<p>The IKE version to be used in the sample configuration file for your customer gateway device. You can specify one of the following versions: <code>ikev1</code> or <code>ikev2</code>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetVpnConnectionDeviceSampleConfigurationResult":{
      "type":"structure",
      "members":{
        "VpnConnectionDeviceSampleConfiguration":{
          "shape":"VpnConnectionDeviceSampleConfiguration",
          "documentation":"<p>Sample configuration file for the specified customer gateway device.</p>",
          "locationName":"vpnConnectionDeviceSampleConfiguration"
        }
      }
    },
    "GetVpnConnectionDeviceTypesRequest":{
      "type":"structure",
      "members":{
        "MaxResults":{
          "shape":"GVCDMaxResults",
          "documentation":"<p>The maximum number of results returned by <code>GetVpnConnectionDeviceTypes</code> in paginated output. When this parameter is used, <code>GetVpnConnectionDeviceTypes</code> only returns <code>MaxResults</code> results in a single page along with a <code>NextToken</code> response element. The remaining results of the initial request can be seen by sending another <code>GetVpnConnectionDeviceTypes</code> request with the returned <code>NextToken</code> value. This value can be between 200 and 1000. If this parameter is not used, then <code>GetVpnConnectionDeviceTypes</code> returns all results.</p>"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The <code>NextToken</code> value returned from a previous paginated <code>GetVpnConnectionDeviceTypes</code> request where <code>MaxResults</code> was used and the results exceeded the value of that parameter. Pagination continues from the end of the previous results that returned the <code>NextToken</code> value. This value is null when there are no more results to return. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "GetVpnConnectionDeviceTypesResult":{
      "type":"structure",
      "members":{
        "VpnConnectionDeviceTypes":{
          "shape":"VpnConnectionDeviceTypeList",
          "documentation":"<p>List of customer gateway devices that have a sample configuration file available for use.</p>",
          "locationName":"vpnConnectionDeviceTypeSet"
        },
        "NextToken":{
          "shape":"NextToken",
          "documentation":"<p>The <code>NextToken</code> value to include in a future <code>GetVpnConnectionDeviceTypes</code> request. When the results of a <code>GetVpnConnectionDeviceTypes</code> request exceed <code>MaxResults</code>, this value can be used to retrieve the next page of results. This value is null when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "GpuDeviceCount":{"type":"integer"},
    "GpuDeviceInfo":{
      "type":"structure",
      "members":{
        "Name":{
          "shape":"GpuDeviceName",
          "documentation":"<p>The name of the GPU accelerator.</p>",
          "locationName":"name"
        },
        "Manufacturer":{
          "shape":"GpuDeviceManufacturerName",
          "documentation":"<p>The manufacturer of the GPU accelerator.</p>",
          "locationName":"manufacturer"
        },
        "Count":{
          "shape":"GpuDeviceCount",
          "documentation":"<p>The number of GPUs for the instance type.</p>",
          "locationName":"count"
        },
        "MemoryInfo":{
          "shape":"GpuDeviceMemoryInfo",
          "documentation":"<p>Describes the memory available to the GPU accelerator.</p>",
          "locationName":"memoryInfo"
        }
      },
      "documentation":"<p>Describes the GPU accelerators for the instance type.</p>"
    },
    "GpuDeviceInfoList":{
      "type":"list",
      "member":{
        "shape":"GpuDeviceInfo",
        "locationName":"item"
      }
    },
    "GpuDeviceManufacturerName":{"type":"string"},
    "GpuDeviceMemoryInfo":{
      "type":"structure",
      "members":{
        "SizeInMiB":{
          "shape":"GpuDeviceMemorySize",
          "documentation":"<p>The size of the memory available to the GPU accelerator, in MiB.</p>",
          "locationName":"sizeInMiB"
        }
      },
      "documentation":"<p>Describes the memory available to the GPU accelerator.</p>"
    },
    "GpuDeviceMemorySize":{"type":"integer"},
    "GpuDeviceName":{"type":"string"},
    "GpuInfo":{
      "type":"structure",
      "members":{
        "Gpus":{
          "shape":"GpuDeviceInfoList",
          "documentation":"<p>Describes the GPU accelerators for the instance type.</p>",
          "locationName":"gpus"
        },
        "TotalGpuMemoryInMiB":{
          "shape":"totalGpuMemory",
          "documentation":"<p>The total size of the memory for the GPU accelerators for the instance type, in MiB.</p>",
          "locationName":"totalGpuMemoryInMiB"
        }
      },
      "documentation":"<p>Describes the GPU accelerators for the instance type.</p>"
    },
    "GroupIdStringList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"groupId"
      }
    },
    "GroupIdentifier":{
      "type":"structure",
      "members":{
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the security group.</p>",
          "locationName":"groupName"
        },
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        }
      },
      "documentation":"<p>Describes a security group.</p>"
    },
    "GroupIdentifierList":{
      "type":"list",
      "member":{
        "shape":"GroupIdentifier",
        "locationName":"item"
      }
    },
    "GroupIdentifierSet":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupIdentifier",
        "locationName":"item"
      }
    },
    "GroupIds":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"item"
      }
    },
    "GroupNameStringList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupName",
        "locationName":"GroupName"
      }
    },
    "HibernationFlag":{"type":"boolean"},
    "HibernationOptions":{
      "type":"structure",
      "members":{
        "Configured":{
          "shape":"Boolean",
          "documentation":"<p>If this parameter is set to <code>true</code>, your instance is enabled for hibernation; otherwise, it is not enabled for hibernation.</p>",
          "locationName":"configured"
        }
      },
      "documentation":"<p>Indicates whether your instance is configured for hibernation. This parameter is valid only if the instance meets the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html#hibernating-prerequisites\">hibernation prerequisites</a>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "HibernationOptionsRequest":{
      "type":"structure",
      "members":{
        "Configured":{
          "shape":"Boolean",
          "documentation":"<p>If you set this parameter to <code>true</code>, your instance is enabled for hibernation.</p> <p>Default: <code>false</code> </p>"
        }
      },
      "documentation":"<p>Indicates whether your instance is configured for hibernation. This parameter is valid only if the instance meets the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html#hibernating-prerequisites\">hibernation prerequisites</a>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "HistoryRecord":{
      "type":"structure",
      "members":{
        "EventInformation":{
          "shape":"EventInformation",
          "documentation":"<p>Information about the event.</p>",
          "locationName":"eventInformation"
        },
        "EventType":{
          "shape":"EventType",
          "documentation":"<p>The event type.</p> <ul> <li> <p> <code>error</code> - An error with the Spot Fleet request.</p> </li> <li> <p> <code>fleetRequestChange</code> - A change in the status or configuration of the Spot Fleet request.</p> </li> <li> <p> <code>instanceChange</code> - An instance was launched or terminated.</p> </li> <li> <p> <code>Information</code> - An informational event.</p> </li> </ul>",
          "locationName":"eventType"
        },
        "Timestamp":{
          "shape":"DateTime",
          "documentation":"<p>The date and time of the event, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"timestamp"
        }
      },
      "documentation":"<p>Describes an event in the history of the Spot Fleet request.</p>"
    },
    "HistoryRecordEntry":{
      "type":"structure",
      "members":{
        "EventInformation":{
          "shape":"EventInformation",
          "documentation":"<p>Information about the event.</p>",
          "locationName":"eventInformation"
        },
        "EventType":{
          "shape":"FleetEventType",
          "documentation":"<p>The event type.</p>",
          "locationName":"eventType"
        },
        "Timestamp":{
          "shape":"DateTime",
          "documentation":"<p>The date and time of the event, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"timestamp"
        }
      },
      "documentation":"<p>Describes an event in the history of an EC2 Fleet.</p>"
    },
    "HistoryRecordSet":{
      "type":"list",
      "member":{
        "shape":"HistoryRecordEntry",
        "locationName":"item"
      }
    },
    "HistoryRecords":{
      "type":"list",
      "member":{
        "shape":"HistoryRecord",
        "locationName":"item"
      }
    },
    "Host":{
      "type":"structure",
      "members":{
        "AutoPlacement":{
          "shape":"AutoPlacement",
          "documentation":"<p>Whether auto-placement is on or off.</p>",
          "locationName":"autoPlacement"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone of the Dedicated Host.</p>",
          "locationName":"availabilityZone"
        },
        "AvailableCapacity":{
          "shape":"AvailableCapacity",
          "documentation":"<p>Information about the instances running on the Dedicated Host.</p>",
          "locationName":"availableCapacity"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "HostId":{
          "shape":"String",
          "documentation":"<p>The ID of the Dedicated Host.</p>",
          "locationName":"hostId"
        },
        "HostProperties":{
          "shape":"HostProperties",
          "documentation":"<p>The hardware specifications of the Dedicated Host.</p>",
          "locationName":"hostProperties"
        },
        "HostReservationId":{
          "shape":"String",
          "documentation":"<p>The reservation ID of the Dedicated Host. This returns a <code>null</code> response if the Dedicated Host doesn't have an associated reservation.</p>",
          "locationName":"hostReservationId"
        },
        "Instances":{
          "shape":"HostInstanceList",
          "documentation":"<p>The IDs and instance type that are currently running on the Dedicated Host.</p>",
          "locationName":"instances"
        },
        "State":{
          "shape":"AllocationState",
          "documentation":"<p>The Dedicated Host's state.</p>",
          "locationName":"state"
        },
        "AllocationTime":{
          "shape":"DateTime",
          "documentation":"<p>The time that the Dedicated Host was allocated.</p>",
          "locationName":"allocationTime"
        },
        "ReleaseTime":{
          "shape":"DateTime",
          "documentation":"<p>The time that the Dedicated Host was released.</p>",
          "locationName":"releaseTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the Dedicated Host.</p>",
          "locationName":"tagSet"
        },
        "HostRecovery":{
          "shape":"HostRecovery",
          "documentation":"<p>Indicates whether host recovery is enabled or disabled for the Dedicated Host.</p>",
          "locationName":"hostRecovery"
        },
        "AllowsMultipleInstanceTypes":{
          "shape":"AllowsMultipleInstanceTypes",
          "documentation":"<p>Indicates whether the Dedicated Host supports multiple instance types of the same instance family. If the value is <code>on</code>, the Dedicated Host supports multiple instance types in the instance family. If the value is <code>off</code>, the Dedicated Host supports a single instance type only.</p>",
          "locationName":"allowsMultipleInstanceTypes"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the Dedicated Host.</p>",
          "locationName":"ownerId"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the Availability Zone in which the Dedicated Host is allocated.</p>",
          "locationName":"availabilityZoneId"
        },
        "MemberOfServiceLinkedResourceGroup":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the Dedicated Host is in a host resource group. If <b>memberOfServiceLinkedResourceGroup</b> is <code>true</code>, the host is in a host resource group; otherwise, it is not.</p>",
          "locationName":"memberOfServiceLinkedResourceGroup"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Amazon Web Services Outpost on which the Dedicated Host is allocated.</p>",
          "locationName":"outpostArn"
        },
        "HostMaintenance":{
          "shape":"HostMaintenance",
          "documentation":"<p>Indicates whether host maintenance is enabled or disabled for the Dedicated Host.</p>",
          "locationName":"hostMaintenance"
        }
      },
      "documentation":"<p>Describes the properties of the Dedicated Host.</p>"
    },
    "HostInstance":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of instance that is running on the Dedicated Host.</p>",
          "locationName":"instanceId"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type (for example, <code>m3.medium</code>) of the running instance.</p>",
          "locationName":"instanceType"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the instance.</p>",
          "locationName":"ownerId"
        }
      },
      "documentation":"<p>Describes an instance running on a Dedicated Host.</p>"
    },
    "HostInstanceList":{
      "type":"list",
      "member":{
        "shape":"HostInstance",
        "locationName":"item"
      }
    },
    "HostList":{
      "type":"list",
      "member":{
        "shape":"Host",
        "locationName":"item"
      }
    },
    "HostMaintenance":{
      "type":"string",
      "enum":[
        "on",
        "off"
      ]
    },
    "HostOffering":{
      "type":"structure",
      "members":{
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency of the offering.</p>",
          "locationName":"currencyCode"
        },
        "Duration":{
          "shape":"Integer",
          "documentation":"<p>The duration of the offering (in seconds).</p>",
          "locationName":"duration"
        },
        "HourlyPrice":{
          "shape":"String",
          "documentation":"<p>The hourly price of the offering.</p>",
          "locationName":"hourlyPrice"
        },
        "InstanceFamily":{
          "shape":"String",
          "documentation":"<p>The instance family of the offering.</p>",
          "locationName":"instanceFamily"
        },
        "OfferingId":{
          "shape":"OfferingId",
          "documentation":"<p>The ID of the offering.</p>",
          "locationName":"offeringId"
        },
        "PaymentOption":{
          "shape":"PaymentOption",
          "documentation":"<p>The available payment option.</p>",
          "locationName":"paymentOption"
        },
        "UpfrontPrice":{
          "shape":"String",
          "documentation":"<p>The upfront price of the offering. Does not apply to No Upfront offerings.</p>",
          "locationName":"upfrontPrice"
        }
      },
      "documentation":"<p>Details about the Dedicated Host Reservation offering.</p>"
    },
    "HostOfferingSet":{
      "type":"list",
      "member":{
        "shape":"HostOffering",
        "locationName":"item"
      }
    },
    "HostProperties":{
      "type":"structure",
      "members":{
        "Cores":{
          "shape":"Integer",
          "documentation":"<p>The number of cores on the Dedicated Host.</p>",
          "locationName":"cores"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type supported by the Dedicated Host. For example, <code>m5.large</code>. If the host supports multiple instance types, no <b>instanceType</b> is returned.</p>",
          "locationName":"instanceType"
        },
        "InstanceFamily":{
          "shape":"String",
          "documentation":"<p>The instance family supported by the Dedicated Host. For example, <code>m5</code>.</p>",
          "locationName":"instanceFamily"
        },
        "Sockets":{
          "shape":"Integer",
          "documentation":"<p>The number of sockets on the Dedicated Host.</p>",
          "locationName":"sockets"
        },
        "TotalVCpus":{
          "shape":"Integer",
          "documentation":"<p>The total number of vCPUs on the Dedicated Host.</p>",
          "locationName":"totalVCpus"
        }
      },
      "documentation":"<p>Describes the properties of a Dedicated Host.</p>"
    },
    "HostRecovery":{
      "type":"string",
      "enum":[
        "on",
        "off"
      ]
    },
    "HostReservation":{
      "type":"structure",
      "members":{
        "Count":{
          "shape":"Integer",
          "documentation":"<p>The number of Dedicated Hosts the reservation is associated with.</p>",
          "locationName":"count"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency in which the <code>upfrontPrice</code> and <code>hourlyPrice</code> amounts are specified. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "Duration":{
          "shape":"Integer",
          "documentation":"<p>The length of the reservation's term, specified in seconds. Can be <code>31536000 (1 year)</code> | <code>94608000 (3 years)</code>.</p>",
          "locationName":"duration"
        },
        "End":{
          "shape":"DateTime",
          "documentation":"<p>The date and time that the reservation ends.</p>",
          "locationName":"end"
        },
        "HostIdSet":{
          "shape":"ResponseHostIdSet",
          "documentation":"<p>The IDs of the Dedicated Hosts associated with the reservation.</p>",
          "locationName":"hostIdSet"
        },
        "HostReservationId":{
          "shape":"HostReservationId",
          "documentation":"<p>The ID of the reservation that specifies the associated Dedicated Hosts.</p>",
          "locationName":"hostReservationId"
        },
        "HourlyPrice":{
          "shape":"String",
          "documentation":"<p>The hourly price of the reservation.</p>",
          "locationName":"hourlyPrice"
        },
        "InstanceFamily":{
          "shape":"String",
          "documentation":"<p>The instance family of the Dedicated Host Reservation. The instance family on the Dedicated Host must be the same in order for it to benefit from the reservation.</p>",
          "locationName":"instanceFamily"
        },
        "OfferingId":{
          "shape":"OfferingId",
          "documentation":"<p>The ID of the reservation. This remains the same regardless of which Dedicated Hosts are associated with it.</p>",
          "locationName":"offeringId"
        },
        "PaymentOption":{
          "shape":"PaymentOption",
          "documentation":"<p>The payment option selected for this reservation.</p>",
          "locationName":"paymentOption"
        },
        "Start":{
          "shape":"DateTime",
          "documentation":"<p>The date and time that the reservation started.</p>",
          "locationName":"start"
        },
        "State":{
          "shape":"ReservationState",
          "documentation":"<p>The state of the reservation.</p>",
          "locationName":"state"
        },
        "UpfrontPrice":{
          "shape":"String",
          "documentation":"<p>The upfront price of the reservation.</p>",
          "locationName":"upfrontPrice"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the Dedicated Host Reservation.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Details about the Dedicated Host Reservation and associated Dedicated Hosts.</p>"
    },
    "HostReservationId":{"type":"string"},
    "HostReservationIdSet":{
      "type":"list",
      "member":{
        "shape":"HostReservationId",
        "locationName":"item"
      }
    },
    "HostReservationSet":{
      "type":"list",
      "member":{
        "shape":"HostReservation",
        "locationName":"item"
      }
    },
    "HostTenancy":{
      "type":"string",
      "enum":[
        "dedicated",
        "host"
      ]
    },
    "HostnameType":{
      "type":"string",
      "enum":[
        "ip-name",
        "resource-name"
      ]
    },
    "Hour":{
      "type":"integer",
      "max":23,
      "min":0
    },
    "HttpTokensState":{
      "type":"string",
      "enum":[
        "optional",
        "required"
      ]
    },
    "HypervisorType":{
      "type":"string",
      "enum":[
        "ovm",
        "xen"
      ]
    },
    "IKEVersionsList":{
      "type":"list",
      "member":{
        "shape":"IKEVersionsListValue",
        "locationName":"item"
      }
    },
    "IKEVersionsListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The IKE version.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The internet key exchange (IKE) version permitted for the VPN tunnel.</p>"
    },
    "IKEVersionsRequestList":{
      "type":"list",
      "member":{
        "shape":"IKEVersionsRequestListValue",
        "locationName":"item"
      }
    },
    "IKEVersionsRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The IKE version.</p>"
        }
      },
      "documentation":"<p>The IKE version that is permitted for the VPN tunnel.</p>"
    },
    "IamInstanceProfile":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the instance profile.</p>",
          "locationName":"arn"
        },
        "Id":{
          "shape":"String",
          "documentation":"<p>The ID of the instance profile.</p>",
          "locationName":"id"
        }
      },
      "documentation":"<p>Describes an IAM instance profile.</p>"
    },
    "IamInstanceProfileAssociation":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"associationId"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "IamInstanceProfile":{
          "shape":"IamInstanceProfile",
          "documentation":"<p>The IAM instance profile.</p>",
          "locationName":"iamInstanceProfile"
        },
        "State":{
          "shape":"IamInstanceProfileAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        },
        "Timestamp":{
          "shape":"DateTime",
          "documentation":"<p>The time the IAM instance profile was associated with the instance.</p>",
          "locationName":"timestamp"
        }
      },
      "documentation":"<p>Describes an association between an IAM instance profile and an instance.</p>"
    },
    "IamInstanceProfileAssociationId":{"type":"string"},
    "IamInstanceProfileAssociationSet":{
      "type":"list",
      "member":{
        "shape":"IamInstanceProfileAssociation",
        "locationName":"item"
      }
    },
    "IamInstanceProfileAssociationState":{
      "type":"string",
      "enum":[
        "associating",
        "associated",
        "disassociating",
        "disassociated"
      ]
    },
    "IamInstanceProfileSpecification":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the instance profile.</p>",
          "locationName":"arn"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the instance profile.</p>",
          "locationName":"name"
        }
      },
      "documentation":"<p>Describes an IAM instance profile.</p>"
    },
    "IcmpTypeCode":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"Integer",
          "documentation":"<p>The ICMP code. A value of -1 means all codes for the specified ICMP type.</p>",
          "locationName":"code"
        },
        "Type":{
          "shape":"Integer",
          "documentation":"<p>The ICMP type. A value of -1 means all types.</p>",
          "locationName":"type"
        }
      },
      "documentation":"<p>Describes the ICMP type and code.</p>"
    },
    "IdFormat":{
      "type":"structure",
      "members":{
        "Deadline":{
          "shape":"DateTime",
          "documentation":"<p>The date in UTC at which you are permanently switched over to using longer IDs. If a deadline is not yet available for this resource type, this field is not returned.</p>",
          "locationName":"deadline"
        },
        "Resource":{
          "shape":"String",
          "documentation":"<p>The type of resource.</p>",
          "locationName":"resource"
        },
        "UseLongIds":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether longer IDs (17-character IDs) are enabled for the resource.</p>",
          "locationName":"useLongIds"
        }
      },
      "documentation":"<p>Describes the ID format for a resource.</p>"
    },
    "IdFormatList":{
      "type":"list",
      "member":{
        "shape":"IdFormat",
        "locationName":"item"
      }
    },
    "Igmpv2SupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "Image":{
      "type":"structure",
      "members":{
        "Architecture":{
          "shape":"ArchitectureValues",
          "documentation":"<p>The architecture of the image.</p>",
          "locationName":"architecture"
        },
        "CreationDate":{
          "shape":"String",
          "documentation":"<p>The date and time the image was created.</p>",
          "locationName":"creationDate"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI.</p>",
          "locationName":"imageId"
        },
        "ImageLocation":{
          "shape":"String",
          "documentation":"<p>The location of the AMI.</p>",
          "locationName":"imageLocation"
        },
        "ImageType":{
          "shape":"ImageTypeValues",
          "documentation":"<p>The type of image.</p>",
          "locationName":"imageType"
        },
        "Public":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the image has public launch permissions. The value is <code>true</code> if this image has public launch permissions or <code>false</code> if it has only implicit and explicit launch permissions.</p>",
          "locationName":"isPublic"
        },
        "KernelId":{
          "shape":"String",
          "documentation":"<p>The kernel associated with the image, if any. Only applicable for machine images.</p>",
          "locationName":"kernelId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the image.</p>",
          "locationName":"imageOwnerId"
        },
        "Platform":{
          "shape":"PlatformValues",
          "documentation":"<p>This value is set to <code>windows</code> for Windows AMIs; otherwise, it is blank.</p>",
          "locationName":"platform"
        },
        "PlatformDetails":{
          "shape":"String",
          "documentation":"<p>The platform details associated with the billing code of the AMI. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-billing-info.html\">Understand AMI billing information</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"platformDetails"
        },
        "UsageOperation":{
          "shape":"String",
          "documentation":"<p>The operation of the Amazon EC2 instance and the billing code that is associated with the AMI. <code>usageOperation</code> corresponds to the <a href=\"https://docs.aws.amazon.com/cur/latest/userguide/Lineitem-columns.html#Lineitem-details-O-Operation\">lineitem/Operation</a> column on your Amazon Web Services Cost and Usage Report and in the <a href=\"https://docs.aws.amazon.com/awsaccountbilling/latest/aboutv2/price-changes.html\">Amazon Web Services Price List API</a>. You can view these fields on the <b>Instances</b> or <b>AMIs</b> pages in the Amazon EC2 console, or in the responses that are returned by the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_DescribeImages.html\">DescribeImages</a> command in the Amazon EC2 API, or the <a href=\"https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-images.html\">describe-images</a> command in the CLI.</p>",
          "locationName":"usageOperation"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>Any product codes associated with the AMI.</p>",
          "locationName":"productCodes"
        },
        "RamdiskId":{
          "shape":"String",
          "documentation":"<p>The RAM disk associated with the image, if any. Only applicable for machine images.</p>",
          "locationName":"ramdiskId"
        },
        "State":{
          "shape":"ImageState",
          "documentation":"<p>The current state of the AMI. If the state is <code>available</code>, the image is successfully registered and can be used to launch an instance.</p>",
          "locationName":"imageState"
        },
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingList",
          "documentation":"<p>Any block device mapping entries.</p>",
          "locationName":"blockDeviceMapping"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the AMI that was provided during image creation.</p>",
          "locationName":"description"
        },
        "EnaSupport":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether enhanced networking with ENA is enabled.</p>",
          "locationName":"enaSupport"
        },
        "Hypervisor":{
          "shape":"HypervisorType",
          "documentation":"<p>The hypervisor type of the image.</p>",
          "locationName":"hypervisor"
        },
        "ImageOwnerAlias":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account alias (for example, <code>amazon</code>, <code>self</code>) or the Amazon Web Services account ID of the AMI owner.</p>",
          "locationName":"imageOwnerAlias"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the AMI that was provided during image creation.</p>",
          "locationName":"name"
        },
        "RootDeviceName":{
          "shape":"String",
          "documentation":"<p>The device name of the root device volume (for example, <code>/dev/sda1</code>).</p>",
          "locationName":"rootDeviceName"
        },
        "RootDeviceType":{
          "shape":"DeviceType",
          "documentation":"<p>The type of root device used by the AMI. The AMI can use an Amazon EBS volume or an instance store volume.</p>",
          "locationName":"rootDeviceType"
        },
        "SriovNetSupport":{
          "shape":"String",
          "documentation":"<p>Specifies whether enhanced networking with the Intel 82599 Virtual Function interface is enabled.</p>",
          "locationName":"sriovNetSupport"
        },
        "StateReason":{
          "shape":"StateReason",
          "documentation":"<p>The reason for the state change.</p>",
          "locationName":"stateReason"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the image.</p>",
          "locationName":"tagSet"
        },
        "VirtualizationType":{
          "shape":"VirtualizationType",
          "documentation":"<p>The type of virtualization of the AMI.</p>",
          "locationName":"virtualizationType"
        },
        "BootMode":{
          "shape":"BootModeValues",
          "documentation":"<p>The boot mode of the image. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-boot.html\">Boot modes</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"bootMode"
        },
        "TpmSupport":{
          "shape":"TpmSupportValues",
          "documentation":"<p>If the image is configured for NitroTPM support, the value is <code>v2.0</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/nitrotpm.html\">NitroTPM</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"tpmSupport"
        },
        "DeprecationTime":{
          "shape":"String",
          "documentation":"<p>The date and time to deprecate the AMI, in UTC, in the following format: <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z. If you specified a value for seconds, Amazon EC2 rounds the seconds to the nearest minute.</p>",
          "locationName":"deprecationTime"
        },
        "ImdsSupport":{
          "shape":"ImdsSupportValues",
          "documentation":"<p>If <code>v2.0</code>, it indicates that IMDSv2 is specified in the AMI. Instances launched from this AMI will have <code>HttpTokens</code> automatically set to <code>required</code> so that, by default, the instance requires that IMDSv2 is used when requesting instance metadata. In addition, <code>HttpPutResponseHopLimit</code> is set to <code>2</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-IMDS-new-instances.html#configure-IMDS-new-instances-ami-configuration\">Configure the AMI</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"imdsSupport"
        }
      },
      "documentation":"<p>Describes an image.</p>"
    },
    "ImageAttribute":{
      "type":"structure",
      "members":{
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingList",
          "documentation":"<p>The block device mapping entries.</p>",
          "locationName":"blockDeviceMapping"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI.</p>",
          "locationName":"imageId"
        },
        "LaunchPermissions":{
          "shape":"LaunchPermissionList",
          "documentation":"<p>The launch permissions.</p>",
          "locationName":"launchPermission"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>The product codes.</p>",
          "locationName":"productCodes"
        },
        "Description":{
          "shape":"AttributeValue",
          "documentation":"<p>A description for the AMI.</p>",
          "locationName":"description"
        },
        "KernelId":{
          "shape":"AttributeValue",
          "documentation":"<p>The kernel ID.</p>",
          "locationName":"kernel"
        },
        "RamdiskId":{
          "shape":"AttributeValue",
          "documentation":"<p>The RAM disk ID.</p>",
          "locationName":"ramdisk"
        },
        "SriovNetSupport":{
          "shape":"AttributeValue",
          "documentation":"<p>Indicates whether enhanced networking with the Intel 82599 Virtual Function interface is enabled.</p>",
          "locationName":"sriovNetSupport"
        },
        "BootMode":{
          "shape":"AttributeValue",
          "documentation":"<p>The boot mode.</p>",
          "locationName":"bootMode"
        },
        "TpmSupport":{
          "shape":"AttributeValue",
          "documentation":"<p>If the image is configured for NitroTPM support, the value is <code>v2.0</code>.</p>",
          "locationName":"tpmSupport"
        },
        "UefiData":{
          "shape":"AttributeValue",
          "documentation":"<p>Base64 representation of the non-volatile UEFI variable store. To retrieve the UEFI data, use the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceUefiData\">GetInstanceUefiData</a> command. You can inspect and modify the UEFI data by using the <a href=\"https://github.com/awslabs/python-uefivars\">python-uefivars tool</a> on GitHub. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/uefi-secure-boot.html\">UEFI Secure Boot</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"uefiData"
        },
        "LastLaunchedTime":{
          "shape":"AttributeValue",
          "documentation":"<p>The date and time, in <a href=\"http://www.iso.org/iso/iso8601\">ISO 8601 date-time format</a>, when the AMI was last used to launch an EC2 instance. When the AMI is used to launch an instance, there is a 24-hour delay before that usage is reported.</p> <note> <p> <code>lastLaunchedTime</code> data is available starting April 2017.</p> </note>",
          "locationName":"lastLaunchedTime"
        },
        "ImdsSupport":{
          "shape":"AttributeValue",
          "documentation":"<p>If <code>v2.0</code>, it indicates that IMDSv2 is specified in the AMI. Instances launched from this AMI will have <code>HttpTokens</code> automatically set to <code>required</code> so that, by default, the instance requires that IMDSv2 is used when requesting instance metadata. In addition, <code>HttpPutResponseHopLimit</code> is set to <code>2</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-IMDS-new-instances.html#configure-IMDS-new-instances-ami-configuration\">Configure the AMI</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"imdsSupport"
        }
      },
      "documentation":"<p>Describes an image attribute.</p>"
    },
    "ImageAttributeName":{
      "type":"string",
      "enum":[
        "description",
        "kernel",
        "ramdisk",
        "launchPermission",
        "productCodes",
        "blockDeviceMapping",
        "sriovNetSupport",
        "bootMode",
        "tpmSupport",
        "uefiData",
        "lastLaunchedTime",
        "imdsSupport"
      ]
    },
    "ImageDiskContainer":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the disk image.</p>"
        },
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The block device mapping for the disk.</p>"
        },
        "Format":{
          "shape":"String",
          "documentation":"<p>The format of the disk image being imported.</p> <p>Valid values: <code>OVA</code> | <code>VHD</code> | <code>VHDX</code> | <code>VMDK</code> | <code>RAW</code> </p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the EBS snapshot to be used for importing the snapshot.</p>"
        },
        "Url":{
          "shape":"String",
          "documentation":"<p>The URL to the Amazon S3-based disk image being imported. The URL can either be a https URL (https://..) or an Amazon S3 URL (s3://..)</p>"
        },
        "UserBucket":{
          "shape":"UserBucket",
          "documentation":"<p>The S3 bucket for the disk image.</p>"
        }
      },
      "documentation":"<p>Describes the disk container object for an import image task.</p>"
    },
    "ImageDiskContainerList":{
      "type":"list",
      "member":{
        "shape":"ImageDiskContainer",
        "locationName":"item"
      }
    },
    "ImageId":{"type":"string"},
    "ImageIdList":{
      "type":"list",
      "member":{
        "shape":"ImageId",
        "locationName":"item"
      }
    },
    "ImageIdStringList":{
      "type":"list",
      "member":{
        "shape":"ImageId",
        "locationName":"ImageId"
      }
    },
    "ImageList":{
      "type":"list",
      "member":{
        "shape":"Image",
        "locationName":"item"
      }
    },
    "ImageRecycleBinInfo":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI.</p>",
          "locationName":"imageId"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the AMI.</p>",
          "locationName":"name"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the AMI.</p>",
          "locationName":"description"
        },
        "RecycleBinEnterTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the AMI entered the Recycle Bin.</p>",
          "locationName":"recycleBinEnterTime"
        },
        "RecycleBinExitTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the AMI is to be permanently deleted from the Recycle Bin.</p>",
          "locationName":"recycleBinExitTime"
        }
      },
      "documentation":"<p>Information about an AMI that is currently in the Recycle Bin.</p>"
    },
    "ImageRecycleBinInfoList":{
      "type":"list",
      "member":{
        "shape":"ImageRecycleBinInfo",
        "locationName":"item"
      }
    },
    "ImageState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "invalid",
        "deregistered",
        "transient",
        "failed",
        "error"
      ]
    },
    "ImageTypeValues":{
      "type":"string",
      "enum":[
        "machine",
        "kernel",
        "ramdisk"
      ]
    },
    "ImdsSupportValues":{
      "type":"string",
      "enum":["v2.0"]
    },
    "ImportClientVpnClientCertificateRevocationListRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "CertificateRevocationList"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint to which the client certificate revocation list applies.</p>"
        },
        "CertificateRevocationList":{
          "shape":"String",
          "documentation":"<p>The client certificate revocation list file. For more information, see <a href=\"https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/cvpn-working-certificates.html#cvpn-working-certificates-generate\">Generate a Client Certificate Revocation List</a> in the <i>Client VPN Administrator Guide</i>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ImportClientVpnClientCertificateRevocationListResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ImportImageLicenseConfigurationRequest":{
      "type":"structure",
      "members":{
        "LicenseConfigurationArn":{
          "shape":"String",
          "documentation":"<p>The ARN of a license configuration.</p>"
        }
      },
      "documentation":"<p>The request information of license configurations.</p>"
    },
    "ImportImageLicenseConfigurationResponse":{
      "type":"structure",
      "members":{
        "LicenseConfigurationArn":{
          "shape":"String",
          "documentation":"<p>The ARN of a license configuration.</p>",
          "locationName":"licenseConfigurationArn"
        }
      },
      "documentation":"<p> The response information for license configurations.</p>"
    },
    "ImportImageLicenseSpecificationListRequest":{
      "type":"list",
      "member":{
        "shape":"ImportImageLicenseConfigurationRequest",
        "locationName":"item"
      }
    },
    "ImportImageLicenseSpecificationListResponse":{
      "type":"list",
      "member":{
        "shape":"ImportImageLicenseConfigurationResponse",
        "locationName":"item"
      }
    },
    "ImportImageRequest":{
      "type":"structure",
      "members":{
        "Architecture":{
          "shape":"String",
          "documentation":"<p>The architecture of the virtual machine.</p> <p>Valid values: <code>i386</code> | <code>x86_64</code> </p>"
        },
        "ClientData":{
          "shape":"ClientData",
          "documentation":"<p>The client-specific data.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>The token to enable idempotency for VM import requests.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description string for the import image task.</p>"
        },
        "DiskContainers":{
          "shape":"ImageDiskContainerList",
          "documentation":"<p>Information about the disk containers.</p>",
          "locationName":"DiskContainer"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether the destination AMI of the imported image should be encrypted. The default KMS key for EBS is used unless you specify a non-default KMS key using <code>KmsKeyId</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS Encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "Hypervisor":{
          "shape":"String",
          "documentation":"<p>The target hypervisor platform.</p> <p>Valid values: <code>xen</code> </p>"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>An identifier for the symmetric KMS key to use when creating the encrypted AMI. This parameter is only required if you want to use a non-default KMS key; if this parameter is not specified, the default KMS key for EBS is used. If a <code>KmsKeyId</code> is specified, the <code>Encrypted</code> flag must also be set. </p> <p>The KMS key identifier may be provided in any of the following formats: </p> <ul> <li> <p>Key ID</p> </li> <li> <p>Key alias. The alias ARN contains the <code>arn:aws:kms</code> namespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the <code>alias</code> namespace, and then the key alias. For example, arn:aws:kms:<i>us-east-1</i>:<i>012345678910</i>:alias/<i>ExampleAlias</i>.</p> </li> <li> <p>ARN using key ID. The ID ARN contains the <code>arn:aws:kms</code> namespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the <code>key</code> namespace, and then the key ID. For example, arn:aws:kms:<i>us-east-1</i>:<i>012345678910</i>:key/<i>abcd1234-a123-456a-a12b-a123b4cd56ef</i>.</p> </li> <li> <p>ARN using key alias. The alias ARN contains the <code>arn:aws:kms</code> namespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the <code>alias</code> namespace, and then the key alias. For example, arn:aws:kms:<i>us-east-1</i>:<i>012345678910</i>:alias/<i>ExampleAlias</i>. </p> </li> </ul> <p>Amazon Web Services parses <code>KmsKeyId</code> asynchronously, meaning that the action you call may appear to complete even though you provided an invalid identifier. This action will eventually report failure. </p> <p>The specified KMS key must exist in the Region that the AMI is being copied to.</p> <p>Amazon EBS does not support asymmetric KMS keys.</p>"
        },
        "LicenseType":{
          "shape":"String",
          "documentation":"<p>The license type to be used for the Amazon Machine Image (AMI) after importing.</p> <p>Specify <code>AWS</code> to replace the source-system license with an Amazon Web Services license or <code>BYOL</code> to retain the source-system license. Leaving this parameter undefined is the same as choosing <code>AWS</code> when importing a Windows Server operating system, and the same as choosing <code>BYOL</code> when importing a Windows client operating system (such as Windows 10) or a Linux operating system.</p> <p>To use <code>BYOL</code>, you must have existing licenses with rights to use these licenses in a third party cloud, such as Amazon Web Services. For more information, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmimport-image-import.html#prerequisites-image\">Prerequisites</a> in the VM Import/Export User Guide.</p>"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>The operating system of the virtual machine.</p> <p>Valid values: <code>Windows</code> | <code>Linux</code> </p>"
        },
        "RoleName":{
          "shape":"String",
          "documentation":"<p>The name of the role to use when not using the default role, 'vmimport'.</p>"
        },
        "LicenseSpecifications":{
          "shape":"ImportImageLicenseSpecificationListRequest",
          "documentation":"<p>The ARNs of the license configurations.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the import image task during creation.</p>",
          "locationName":"TagSpecification"
        },
        "UsageOperation":{
          "shape":"String",
          "documentation":"<p>The usage operation value. For more information, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmie_prereqs.html#prerequisites\">Licensing options</a> in the <i>VM Import/Export User Guide</i>.</p>"
        },
        "BootMode":{
          "shape":"BootModeValues",
          "documentation":"<p>The boot mode of the virtual machine.</p>"
        }
      }
    },
    "ImportImageResult":{
      "type":"structure",
      "members":{
        "Architecture":{
          "shape":"String",
          "documentation":"<p>The architecture of the virtual machine.</p>",
          "locationName":"architecture"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the import task.</p>",
          "locationName":"description"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the AMI is encrypted.</p>",
          "locationName":"encrypted"
        },
        "Hypervisor":{
          "shape":"String",
          "documentation":"<p>The target hypervisor of the import task.</p>",
          "locationName":"hypervisor"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Machine Image (AMI) created by the import task.</p>",
          "locationName":"imageId"
        },
        "ImportTaskId":{
          "shape":"ImportImageTaskId",
          "documentation":"<p>The task ID of the import image task.</p>",
          "locationName":"importTaskId"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The identifier for the symmetric KMS key that was used to create the encrypted AMI.</p>",
          "locationName":"kmsKeyId"
        },
        "LicenseType":{
          "shape":"String",
          "documentation":"<p>The license type of the virtual machine.</p>",
          "locationName":"licenseType"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>The operating system of the virtual machine.</p>",
          "locationName":"platform"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The progress of the task.</p>",
          "locationName":"progress"
        },
        "SnapshotDetails":{
          "shape":"SnapshotDetailList",
          "documentation":"<p>Information about the snapshots.</p>",
          "locationName":"snapshotDetailSet"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>A brief status of the task.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A detailed status message of the import task.</p>",
          "locationName":"statusMessage"
        },
        "LicenseSpecifications":{
          "shape":"ImportImageLicenseSpecificationListResponse",
          "documentation":"<p>The ARNs of the license configurations.</p>",
          "locationName":"licenseSpecifications"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the import image task.</p>",
          "locationName":"tagSet"
        },
        "UsageOperation":{
          "shape":"String",
          "documentation":"<p>The usage operation value.</p>",
          "locationName":"usageOperation"
        }
      }
    },
    "ImportImageTask":{
      "type":"structure",
      "members":{
        "Architecture":{
          "shape":"String",
          "documentation":"<p>The architecture of the virtual machine.</p> <p>Valid values: <code>i386</code> | <code>x86_64</code> | <code>arm64</code> </p>",
          "locationName":"architecture"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the import task.</p>",
          "locationName":"description"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the image is encrypted.</p>",
          "locationName":"encrypted"
        },
        "Hypervisor":{
          "shape":"String",
          "documentation":"<p>The target hypervisor for the import task.</p> <p>Valid values: <code>xen</code> </p>",
          "locationName":"hypervisor"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Machine Image (AMI) of the imported virtual machine.</p>",
          "locationName":"imageId"
        },
        "ImportTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the import image task.</p>",
          "locationName":"importTaskId"
        },
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The identifier for the KMS key that was used to create the encrypted image.</p>",
          "locationName":"kmsKeyId"
        },
        "LicenseType":{
          "shape":"String",
          "documentation":"<p>The license type of the virtual machine.</p>",
          "locationName":"licenseType"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>The description string for the import image task.</p>",
          "locationName":"platform"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The percentage of progress of the import image task.</p>",
          "locationName":"progress"
        },
        "SnapshotDetails":{
          "shape":"SnapshotDetailList",
          "documentation":"<p>Information about the snapshots.</p>",
          "locationName":"snapshotDetailSet"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>A brief status for the import image task.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A descriptive status message for the import image task.</p>",
          "locationName":"statusMessage"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the import image task.</p>",
          "locationName":"tagSet"
        },
        "LicenseSpecifications":{
          "shape":"ImportImageLicenseSpecificationListResponse",
          "documentation":"<p>The ARNs of the license configurations that are associated with the import image task.</p>",
          "locationName":"licenseSpecifications"
        },
        "UsageOperation":{
          "shape":"String",
          "documentation":"<p>The usage operation value.</p>",
          "locationName":"usageOperation"
        },
        "BootMode":{
          "shape":"BootModeValues",
          "documentation":"<p>The boot mode of the virtual machine.</p>",
          "locationName":"bootMode"
        }
      },
      "documentation":"<p>Describes an import image task.</p>"
    },
    "ImportImageTaskId":{"type":"string"},
    "ImportImageTaskList":{
      "type":"list",
      "member":{
        "shape":"ImportImageTask",
        "locationName":"item"
      }
    },
    "ImportInstanceLaunchSpecification":{
      "type":"structure",
      "members":{
        "AdditionalInfo":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>",
          "locationName":"additionalInfo"
        },
        "Architecture":{
          "shape":"ArchitectureValues",
          "documentation":"<p>The architecture of the instance.</p>",
          "locationName":"architecture"
        },
        "GroupIds":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>The security group IDs.</p>",
          "locationName":"GroupId"
        },
        "GroupNames":{
          "shape":"SecurityGroupStringList",
          "documentation":"<p>The security group names.</p>",
          "locationName":"GroupName"
        },
        "InstanceInitiatedShutdownBehavior":{
          "shape":"ShutdownBehavior",
          "documentation":"<p>Indicates whether an instance stops or terminates when you initiate shutdown from the instance (using the operating system command for system shutdown).</p>",
          "locationName":"instanceInitiatedShutdownBehavior"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. For more information about the instance types that you can import, see <a href=\"https://docs.aws.amazon.com/vm-import/latest/userguide/vmie_prereqs.html#vmimport-instance-types\">Instance Types</a> in the VM Import/Export User Guide.</p>",
          "locationName":"instanceType"
        },
        "Monitoring":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether monitoring is enabled.</p>",
          "locationName":"monitoring"
        },
        "Placement":{
          "shape":"Placement",
          "documentation":"<p>The placement information for the instance.</p>",
          "locationName":"placement"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] An available IP address from the IP address range of the subnet.</p>",
          "locationName":"privateIpAddress"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>[EC2-VPC] The ID of the subnet in which to launch the instance.</p>",
          "locationName":"subnetId"
        },
        "UserData":{
          "shape":"UserData",
          "documentation":"<p>The Base64-encoded user data to make available to the instance.</p>",
          "locationName":"userData"
        }
      },
      "documentation":"<p>Describes the launch specification for VM import.</p>"
    },
    "ImportInstanceRequest":{
      "type":"structure",
      "required":["Platform"],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the instance being imported.</p>",
          "locationName":"description"
        },
        "DiskImages":{
          "shape":"DiskImageList",
          "documentation":"<p>The disk image.</p>",
          "locationName":"diskImage"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "LaunchSpecification":{
          "shape":"ImportInstanceLaunchSpecification",
          "documentation":"<p>The launch specification.</p>",
          "locationName":"launchSpecification"
        },
        "Platform":{
          "shape":"PlatformValues",
          "documentation":"<p>The instance operating system.</p>",
          "locationName":"platform"
        }
      }
    },
    "ImportInstanceResult":{
      "type":"structure",
      "members":{
        "ConversionTask":{
          "shape":"ConversionTask",
          "documentation":"<p>Information about the conversion task.</p>",
          "locationName":"conversionTask"
        }
      }
    },
    "ImportInstanceTaskDetails":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the task.</p>",
          "locationName":"description"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "Platform":{
          "shape":"PlatformValues",
          "documentation":"<p>The instance operating system.</p>",
          "locationName":"platform"
        },
        "Volumes":{
          "shape":"ImportInstanceVolumeDetailSet",
          "documentation":"<p>The volumes.</p>",
          "locationName":"volumes"
        }
      },
      "documentation":"<p>Describes an import instance task.</p>"
    },
    "ImportInstanceVolumeDetailItem":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone where the resulting instance will reside.</p>",
          "locationName":"availabilityZone"
        },
        "BytesConverted":{
          "shape":"Long",
          "documentation":"<p>The number of bytes converted so far.</p>",
          "locationName":"bytesConverted"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the task.</p>",
          "locationName":"description"
        },
        "Image":{
          "shape":"DiskImageDescription",
          "documentation":"<p>The image.</p>",
          "locationName":"image"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The status of the import of this particular disk image.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status information or errors related to the disk image.</p>",
          "locationName":"statusMessage"
        },
        "Volume":{
          "shape":"DiskImageVolumeDescription",
          "documentation":"<p>The volume.</p>",
          "locationName":"volume"
        }
      },
      "documentation":"<p>Describes an import volume task.</p>"
    },
    "ImportInstanceVolumeDetailSet":{
      "type":"list",
      "member":{
        "shape":"ImportInstanceVolumeDetailItem",
        "locationName":"item"
      }
    },
    "ImportKeyPairRequest":{
      "type":"structure",
      "required":[
        "KeyName",
        "PublicKeyMaterial"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>A unique name for the key pair.</p>",
          "locationName":"keyName"
        },
        "PublicKeyMaterial":{
          "shape":"Blob",
          "documentation":"<p>The public key. For API calls, the text must be base64-encoded. For command line tools, base64 encoding is performed for you.</p>",
          "locationName":"publicKeyMaterial"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the imported key pair.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "ImportKeyPairResult":{
      "type":"structure",
      "members":{
        "KeyFingerprint":{
          "shape":"String",
          "documentation":"<ul> <li> <p>For RSA key pairs, the key fingerprint is the MD5 public key fingerprint as specified in section 4 of RFC 4716.</p> </li> <li> <p>For ED25519 key pairs, the key fingerprint is the base64-encoded SHA-256 digest, which is the default for OpenSSH, starting with <a href=\"http://www.openssh.com/txt/release-6.8\">OpenSSH 6.8</a>.</p> </li> </ul>",
          "locationName":"keyFingerprint"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>The key pair name that you provided.</p>",
          "locationName":"keyName"
        },
        "KeyPairId":{
          "shape":"String",
          "documentation":"<p>The ID of the resulting key pair.</p>",
          "locationName":"keyPairId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags applied to the imported key pair.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "ImportSnapshotRequest":{
      "type":"structure",
      "members":{
        "ClientData":{
          "shape":"ClientData",
          "documentation":"<p>The client-specific data.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Token to enable idempotency for VM import requests.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description string for the import snapshot task.</p>"
        },
        "DiskContainer":{
          "shape":"SnapshotDiskContainer",
          "documentation":"<p>Information about the disk container.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether the destination snapshot of the imported image should be encrypted. The default KMS key for EBS is used unless you specify a non-default KMS key using <code>KmsKeyId</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSEncryption.html\">Amazon EBS Encryption</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>An identifier for the symmetric KMS key to use when creating the encrypted snapshot. This parameter is only required if you want to use a non-default KMS key; if this parameter is not specified, the default KMS key for EBS is used. If a <code>KmsKeyId</code> is specified, the <code>Encrypted</code> flag must also be set. </p> <p>The KMS key identifier may be provided in any of the following formats: </p> <ul> <li> <p>Key ID</p> </li> <li> <p>Key alias. The alias ARN contains the <code>arn:aws:kms</code> namespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the <code>alias</code> namespace, and then the key alias. For example, arn:aws:kms:<i>us-east-1</i>:<i>012345678910</i>:alias/<i>ExampleAlias</i>.</p> </li> <li> <p>ARN using key ID. The ID ARN contains the <code>arn:aws:kms</code> namespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the <code>key</code> namespace, and then the key ID. For example, arn:aws:kms:<i>us-east-1</i>:<i>012345678910</i>:key/<i>abcd1234-a123-456a-a12b-a123b4cd56ef</i>.</p> </li> <li> <p>ARN using key alias. The alias ARN contains the <code>arn:aws:kms</code> namespace, followed by the Region of the key, the Amazon Web Services account ID of the key owner, the <code>alias</code> namespace, and then the key alias. For example, arn:aws:kms:<i>us-east-1</i>:<i>012345678910</i>:alias/<i>ExampleAlias</i>. </p> </li> </ul> <p>Amazon Web Services parses <code>KmsKeyId</code> asynchronously, meaning that the action you call may appear to complete even though you provided an invalid identifier. This action will eventually report failure. </p> <p>The specified KMS key must exist in the Region that the snapshot is being copied to.</p> <p>Amazon EBS does not support asymmetric KMS keys.</p>"
        },
        "RoleName":{
          "shape":"String",
          "documentation":"<p>The name of the role to use when not using the default role, 'vmimport'.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the import snapshot task during creation.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "ImportSnapshotResult":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the import snapshot task.</p>",
          "locationName":"description"
        },
        "ImportTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the import snapshot task.</p>",
          "locationName":"importTaskId"
        },
        "SnapshotTaskDetail":{
          "shape":"SnapshotTaskDetail",
          "documentation":"<p>Information about the import snapshot task.</p>",
          "locationName":"snapshotTaskDetail"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the import snapshot task.</p>",
          "locationName":"tagSet"
        }
      }
    },
    "ImportSnapshotTask":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the import snapshot task.</p>",
          "locationName":"description"
        },
        "ImportTaskId":{
          "shape":"String",
          "documentation":"<p>The ID of the import snapshot task.</p>",
          "locationName":"importTaskId"
        },
        "SnapshotTaskDetail":{
          "shape":"SnapshotTaskDetail",
          "documentation":"<p>Describes an import snapshot task.</p>",
          "locationName":"snapshotTaskDetail"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the import snapshot task.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an import snapshot task.</p>"
    },
    "ImportSnapshotTaskId":{"type":"string"},
    "ImportSnapshotTaskIdList":{
      "type":"list",
      "member":{
        "shape":"ImportSnapshotTaskId",
        "locationName":"ImportTaskId"
      }
    },
    "ImportSnapshotTaskList":{
      "type":"list",
      "member":{
        "shape":"ImportSnapshotTask",
        "locationName":"item"
      }
    },
    "ImportTaskId":{"type":"string"},
    "ImportTaskIdList":{
      "type":"list",
      "member":{
        "shape":"ImportImageTaskId",
        "locationName":"ImportTaskId"
      }
    },
    "ImportVolumeRequest":{
      "type":"structure",
      "required":[
        "AvailabilityZone",
        "Image",
        "Volume"
      ],
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone for the resulting EBS volume.</p>",
          "locationName":"availabilityZone"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the volume.</p>",
          "locationName":"description"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Image":{
          "shape":"DiskImageDetail",
          "documentation":"<p>The disk image.</p>",
          "locationName":"image"
        },
        "Volume":{
          "shape":"VolumeDetail",
          "documentation":"<p>The volume size.</p>",
          "locationName":"volume"
        }
      }
    },
    "ImportVolumeResult":{
      "type":"structure",
      "members":{
        "ConversionTask":{
          "shape":"ConversionTask",
          "documentation":"<p>Information about the conversion task.</p>",
          "locationName":"conversionTask"
        }
      }
    },
    "ImportVolumeTaskDetails":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone where the resulting volume will reside.</p>",
          "locationName":"availabilityZone"
        },
        "BytesConverted":{
          "shape":"Long",
          "documentation":"<p>The number of bytes converted so far.</p>",
          "locationName":"bytesConverted"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description you provided when starting the import volume task.</p>",
          "locationName":"description"
        },
        "Image":{
          "shape":"DiskImageDescription",
          "documentation":"<p>The image.</p>",
          "locationName":"image"
        },
        "Volume":{
          "shape":"DiskImageVolumeDescription",
          "documentation":"<p>The volume.</p>",
          "locationName":"volume"
        }
      },
      "documentation":"<p>Describes an import volume task.</p>"
    },
    "InferenceAcceleratorInfo":{
      "type":"structure",
      "members":{
        "Accelerators":{
          "shape":"InferenceDeviceInfoList",
          "documentation":"<p>Describes the Inference accelerators for the instance type.</p>",
          "locationName":"accelerators"
        }
      },
      "documentation":"<p>Describes the Inference accelerators for the instance type.</p>"
    },
    "InferenceDeviceCount":{"type":"integer"},
    "InferenceDeviceInfo":{
      "type":"structure",
      "members":{
        "Count":{
          "shape":"InferenceDeviceCount",
          "documentation":"<p>The number of Inference accelerators for the instance type.</p>",
          "locationName":"count"
        },
        "Name":{
          "shape":"InferenceDeviceName",
          "documentation":"<p>The name of the Inference accelerator.</p>",
          "locationName":"name"
        },
        "Manufacturer":{
          "shape":"InferenceDeviceManufacturerName",
          "documentation":"<p>The manufacturer of the Inference accelerator.</p>",
          "locationName":"manufacturer"
        }
      },
      "documentation":"<p>Describes the Inference accelerators for the instance type.</p>"
    },
    "InferenceDeviceInfoList":{
      "type":"list",
      "member":{"shape":"InferenceDeviceInfo"},
      "locationName":"item"
    },
    "InferenceDeviceManufacturerName":{"type":"string"},
    "InferenceDeviceName":{"type":"string"},
    "InsideCidrBlocksStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "Instance":{
      "type":"structure",
      "members":{
        "AmiLaunchIndex":{
          "shape":"Integer",
          "documentation":"<p>The AMI launch index, which can be used to find this instance in the launch group.</p>",
          "locationName":"amiLaunchIndex"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI used to launch the instance.</p>",
          "locationName":"imageId"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "KernelId":{
          "shape":"String",
          "documentation":"<p>The kernel associated with this instance, if applicable.</p>",
          "locationName":"kernelId"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>The name of the key pair, if this instance was launched with an associated key pair.</p>",
          "locationName":"keyName"
        },
        "LaunchTime":{
          "shape":"DateTime",
          "documentation":"<p>The time the instance was launched.</p>",
          "locationName":"launchTime"
        },
        "Monitoring":{
          "shape":"Monitoring",
          "documentation":"<p>The monitoring for the instance.</p>",
          "locationName":"monitoring"
        },
        "Placement":{
          "shape":"Placement",
          "documentation":"<p>The location where the instance launched, if applicable.</p>",
          "locationName":"placement"
        },
        "Platform":{
          "shape":"PlatformValues",
          "documentation":"<p>The value is <code>Windows</code> for Windows instances; otherwise blank.</p>",
          "locationName":"platform"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>(IPv4 only) The private DNS hostname name assigned to the instance. This DNS hostname can only be used inside the Amazon EC2 network. This name is not available until the instance enters the <code>running</code> state. </p> <p>[EC2-VPC] The Amazon-provided DNS server resolves Amazon-provided private DNS hostnames if you've enabled DNS resolution and DNS hostnames in your VPC. If you are not using the Amazon-provided DNS server in your VPC, your custom domain name servers must resolve the hostname as appropriate.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IPv4 address assigned to the instance.</p>",
          "locationName":"privateIpAddress"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>The product codes attached to this instance, if applicable.</p>",
          "locationName":"productCodes"
        },
        "PublicDnsName":{
          "shape":"String",
          "documentation":"<p>(IPv4 only) The public DNS name assigned to the instance. This name is not available until the instance enters the <code>running</code> state. For EC2-VPC, this name is only available if you've enabled DNS hostnames for your VPC.</p>",
          "locationName":"dnsName"
        },
        "PublicIpAddress":{
          "shape":"String",
          "documentation":"<p>The public IPv4 address, or the Carrier IP address assigned to the instance, if applicable.</p> <p>A Carrier IP address only applies to an instance launched in a subnet associated with a Wavelength Zone.</p>",
          "locationName":"ipAddress"
        },
        "RamdiskId":{
          "shape":"String",
          "documentation":"<p>The RAM disk associated with this instance, if applicable.</p>",
          "locationName":"ramdiskId"
        },
        "State":{
          "shape":"InstanceState",
          "documentation":"<p>The current state of the instance.</p>",
          "locationName":"instanceState"
        },
        "StateTransitionReason":{
          "shape":"String",
          "documentation":"<p>The reason for the most recent state transition. This might be an empty string.</p>",
          "locationName":"reason"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] The ID of the subnet in which the instance is running.</p>",
          "locationName":"subnetId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] The ID of the VPC in which the instance is running.</p>",
          "locationName":"vpcId"
        },
        "Architecture":{
          "shape":"ArchitectureValues",
          "documentation":"<p>The architecture of the image.</p>",
          "locationName":"architecture"
        },
        "BlockDeviceMappings":{
          "shape":"InstanceBlockDeviceMappingList",
          "documentation":"<p>Any block device mapping entries for the instance.</p>",
          "locationName":"blockDeviceMapping"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>The idempotency token you provided when you launched the instance, if applicable.</p>",
          "locationName":"clientToken"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is optimized for Amazon EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS Optimized instance.</p>",
          "locationName":"ebsOptimized"
        },
        "EnaSupport":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether enhanced networking with ENA is enabled.</p>",
          "locationName":"enaSupport"
        },
        "Hypervisor":{
          "shape":"HypervisorType",
          "documentation":"<p>The hypervisor type of the instance. The value <code>xen</code> is used for both Xen and Nitro hypervisors.</p>",
          "locationName":"hypervisor"
        },
        "IamInstanceProfile":{
          "shape":"IamInstanceProfile",
          "documentation":"<p>The IAM instance profile associated with the instance, if applicable.</p>",
          "locationName":"iamInstanceProfile"
        },
        "InstanceLifecycle":{
          "shape":"InstanceLifecycleType",
          "documentation":"<p>Indicates whether this is a Spot Instance or a Scheduled Instance.</p>",
          "locationName":"instanceLifecycle"
        },
        "ElasticGpuAssociations":{
          "shape":"ElasticGpuAssociationList",
          "documentation":"<p>The Elastic GPU associated with the instance.</p>",
          "locationName":"elasticGpuAssociationSet"
        },
        "ElasticInferenceAcceleratorAssociations":{
          "shape":"ElasticInferenceAcceleratorAssociationList",
          "documentation":"<p> The elastic inference accelerator associated with the instance.</p>",
          "locationName":"elasticInferenceAcceleratorAssociationSet"
        },
        "NetworkInterfaces":{
          "shape":"InstanceNetworkInterfaceList",
          "documentation":"<p>[EC2-VPC] The network interfaces for the instance.</p>",
          "locationName":"networkInterfaceSet"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "RootDeviceName":{
          "shape":"String",
          "documentation":"<p>The device name of the root device volume (for example, <code>/dev/sda1</code>).</p>",
          "locationName":"rootDeviceName"
        },
        "RootDeviceType":{
          "shape":"DeviceType",
          "documentation":"<p>The root device type used by the AMI. The AMI can use an EBS volume or an instance store volume.</p>",
          "locationName":"rootDeviceType"
        },
        "SecurityGroups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>The security groups for the instance.</p>",
          "locationName":"groupSet"
        },
        "SourceDestCheck":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether source/destination checking is enabled.</p>",
          "locationName":"sourceDestCheck"
        },
        "SpotInstanceRequestId":{
          "shape":"String",
          "documentation":"<p>If the request is a Spot Instance request, the ID of the request.</p>",
          "locationName":"spotInstanceRequestId"
        },
        "SriovNetSupport":{
          "shape":"String",
          "documentation":"<p>Specifies whether enhanced networking with the Intel 82599 Virtual Function interface is enabled.</p>",
          "locationName":"sriovNetSupport"
        },
        "StateReason":{
          "shape":"StateReason",
          "documentation":"<p>The reason for the most recent state transition.</p>",
          "locationName":"stateReason"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the instance.</p>",
          "locationName":"tagSet"
        },
        "VirtualizationType":{
          "shape":"VirtualizationType",
          "documentation":"<p>The virtualization type of the instance.</p>",
          "locationName":"virtualizationType"
        },
        "CpuOptions":{
          "shape":"CpuOptions",
          "documentation":"<p>The CPU options for the instance.</p>",
          "locationName":"cpuOptions"
        },
        "CapacityReservationId":{
          "shape":"String",
          "documentation":"<p>The ID of the Capacity Reservation.</p>",
          "locationName":"capacityReservationId"
        },
        "CapacityReservationSpecification":{
          "shape":"CapacityReservationSpecificationResponse",
          "documentation":"<p>Information about the Capacity Reservation targeting option.</p>",
          "locationName":"capacityReservationSpecification"
        },
        "HibernationOptions":{
          "shape":"HibernationOptions",
          "documentation":"<p>Indicates whether the instance is enabled for hibernation.</p>",
          "locationName":"hibernationOptions"
        },
        "Licenses":{
          "shape":"LicenseList",
          "documentation":"<p>The license configurations for the instance.</p>",
          "locationName":"licenseSet"
        },
        "MetadataOptions":{
          "shape":"InstanceMetadataOptionsResponse",
          "documentation":"<p>The metadata options for the instance.</p>",
          "locationName":"metadataOptions"
        },
        "EnclaveOptions":{
          "shape":"EnclaveOptions",
          "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves.</p>",
          "locationName":"enclaveOptions"
        },
        "BootMode":{
          "shape":"BootModeValues",
          "documentation":"<p>The boot mode of the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-boot.html\">Boot modes</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"bootMode"
        },
        "PlatformDetails":{
          "shape":"String",
          "documentation":"<p>The platform details value for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/billing-info-fields.html\">AMI billing information fields</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"platformDetails"
        },
        "UsageOperation":{
          "shape":"String",
          "documentation":"<p>The usage operation value for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/billing-info-fields.html\">AMI billing information fields</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"usageOperation"
        },
        "UsageOperationUpdateTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time that the usage operation was last updated.</p>",
          "locationName":"usageOperationUpdateTime"
        },
        "PrivateDnsNameOptions":{
          "shape":"PrivateDnsNameOptionsResponse",
          "documentation":"<p>The options for the instance hostname.</p>",
          "locationName":"privateDnsNameOptions"
        },
        "Ipv6Address":{
          "shape":"String",
          "documentation":"<p>The IPv6 address assigned to the instance.</p>",
          "locationName":"ipv6Address"
        },
        "TpmSupport":{
          "shape":"String",
          "documentation":"<p>If the instance is configured for NitroTPM support, the value is <code>v2.0</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/nitrotpm.html\">NitroTPM</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"tpmSupport"
        },
        "MaintenanceOptions":{
          "shape":"InstanceMaintenanceOptions",
          "documentation":"<p>Provides information on the recovery and maintenance options of your instance.</p>",
          "locationName":"maintenanceOptions"
        }
      },
      "documentation":"<p>Describes an instance.</p>"
    },
    "InstanceAttribute":{
      "type":"structure",
      "members":{
        "Groups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>The security groups associated with the instance.</p>",
          "locationName":"groupSet"
        },
        "BlockDeviceMappings":{
          "shape":"InstanceBlockDeviceMappingList",
          "documentation":"<p>The block device mapping of the instance.</p>",
          "locationName":"blockDeviceMapping"
        },
        "DisableApiTermination":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>If the value is <code>true</code>, you can't terminate the instance through the Amazon EC2 console, CLI, or API; otherwise, you can.</p>",
          "locationName":"disableApiTermination"
        },
        "EnaSupport":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether enhanced networking with ENA is enabled.</p>",
          "locationName":"enaSupport"
        },
        "EnclaveOptions":{
          "shape":"EnclaveOptions",
          "documentation":"<p>To enable the instance for Amazon Web Services Nitro Enclaves, set this parameter to <code>true</code>; otherwise, set it to <code>false</code>.</p>",
          "locationName":"enclaveOptions"
        },
        "EbsOptimized":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether the instance is optimized for Amazon EBS I/O.</p>",
          "locationName":"ebsOptimized"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceInitiatedShutdownBehavior":{
          "shape":"AttributeValue",
          "documentation":"<p>Indicates whether an instance stops or terminates when you initiate shutdown from the instance (using the operating system command for system shutdown).</p>",
          "locationName":"instanceInitiatedShutdownBehavior"
        },
        "InstanceType":{
          "shape":"AttributeValue",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "KernelId":{
          "shape":"AttributeValue",
          "documentation":"<p>The kernel ID.</p>",
          "locationName":"kernel"
        },
        "ProductCodes":{
          "shape":"ProductCodeList",
          "documentation":"<p>A list of product codes.</p>",
          "locationName":"productCodes"
        },
        "RamdiskId":{
          "shape":"AttributeValue",
          "documentation":"<p>The RAM disk ID.</p>",
          "locationName":"ramdisk"
        },
        "RootDeviceName":{
          "shape":"AttributeValue",
          "documentation":"<p>The device name of the root device volume (for example, <code>/dev/sda1</code>).</p>",
          "locationName":"rootDeviceName"
        },
        "SourceDestCheck":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Enable or disable source/destination checks, which ensure that the instance is either the source or the destination of any traffic that it receives. If the value is <code>true</code>, source/destination checks are enabled; otherwise, they are disabled. The default value is <code>true</code>. You must disable source/destination checks if the instance runs services such as network address translation, routing, or firewalls.</p>",
          "locationName":"sourceDestCheck"
        },
        "SriovNetSupport":{
          "shape":"AttributeValue",
          "documentation":"<p>Indicates whether enhanced networking with the Intel 82599 Virtual Function interface is enabled.</p>",
          "locationName":"sriovNetSupport"
        },
        "UserData":{
          "shape":"AttributeValue",
          "documentation":"<p>The user data.</p>",
          "locationName":"userData"
        },
        "DisableApiStop":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>To enable the instance for Amazon Web Services Stop Protection, set this parameter to <code>true</code>; otherwise, set it to <code>false</code>.</p>",
          "locationName":"disableApiStop"
        }
      },
      "documentation":"<p>Describes an instance attribute.</p>"
    },
    "InstanceAttributeName":{
      "type":"string",
      "enum":[
        "instanceType",
        "kernel",
        "ramdisk",
        "userData",
        "disableApiTermination",
        "instanceInitiatedShutdownBehavior",
        "rootDeviceName",
        "blockDeviceMapping",
        "productCodes",
        "sourceDestCheck",
        "groupSet",
        "ebsOptimized",
        "sriovNetSupport",
        "enaSupport",
        "enclaveOptions",
        "disableApiStop"
      ]
    },
    "InstanceAutoRecoveryState":{
      "type":"string",
      "enum":[
        "disabled",
        "default"
      ]
    },
    "InstanceBlockDeviceMapping":{
      "type":"structure",
      "members":{
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The device name (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p>",
          "locationName":"deviceName"
        },
        "Ebs":{
          "shape":"EbsInstanceBlockDevice",
          "documentation":"<p>Parameters used to automatically set up EBS volumes when the instance is launched.</p>",
          "locationName":"ebs"
        }
      },
      "documentation":"<p>Describes a block device mapping.</p>"
    },
    "InstanceBlockDeviceMappingList":{
      "type":"list",
      "member":{
        "shape":"InstanceBlockDeviceMapping",
        "locationName":"item"
      }
    },
    "InstanceBlockDeviceMappingSpecification":{
      "type":"structure",
      "members":{
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The device name (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p>",
          "locationName":"deviceName"
        },
        "Ebs":{
          "shape":"EbsInstanceBlockDeviceSpecification",
          "documentation":"<p>Parameters used to automatically set up EBS volumes when the instance is launched.</p>",
          "locationName":"ebs"
        },
        "NoDevice":{
          "shape":"String",
          "documentation":"<p>suppress the specified device included in the block device mapping.</p>",
          "locationName":"noDevice"
        },
        "VirtualName":{
          "shape":"String",
          "documentation":"<p>The virtual device name.</p>",
          "locationName":"virtualName"
        }
      },
      "documentation":"<p>Describes a block device mapping entry.</p>"
    },
    "InstanceBlockDeviceMappingSpecificationList":{
      "type":"list",
      "member":{
        "shape":"InstanceBlockDeviceMappingSpecification",
        "locationName":"item"
      }
    },
    "InstanceCapacity":{
      "type":"structure",
      "members":{
        "AvailableCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of instances that can be launched onto the Dedicated Host based on the host's available capacity.</p>",
          "locationName":"availableCapacity"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type supported by the Dedicated Host.</p>",
          "locationName":"instanceType"
        },
        "TotalCapacity":{
          "shape":"Integer",
          "documentation":"<p>The total number of instances that can be launched onto the Dedicated Host if there are no instances running on it.</p>",
          "locationName":"totalCapacity"
        }
      },
      "documentation":"<p>Information about the number of instances that can be launched onto the Dedicated Host.</p>"
    },
    "InstanceCount":{
      "type":"structure",
      "members":{
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of listed Reserved Instances in the state specified by the <code>state</code>.</p>",
          "locationName":"instanceCount"
        },
        "State":{
          "shape":"ListingState",
          "documentation":"<p>The states of the listed Reserved Instances.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a Reserved Instance listing state.</p>"
    },
    "InstanceCountList":{
      "type":"list",
      "member":{
        "shape":"InstanceCount",
        "locationName":"item"
      }
    },
    "InstanceCreditSpecification":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "CpuCredits":{
          "shape":"String",
          "documentation":"<p>The credit option for CPU usage of the instance.</p> <p>Valid values: <code>standard</code> | <code>unlimited</code> </p>",
          "locationName":"cpuCredits"
        }
      },
      "documentation":"<p>Describes the credit option for CPU usage of a burstable performance instance. </p>"
    },
    "InstanceCreditSpecificationList":{
      "type":"list",
      "member":{
        "shape":"InstanceCreditSpecification",
        "locationName":"item"
      }
    },
    "InstanceCreditSpecificationListRequest":{
      "type":"list",
      "member":{
        "shape":"InstanceCreditSpecificationRequest",
        "locationName":"item"
      }
    },
    "InstanceCreditSpecificationRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "CpuCredits":{
          "shape":"String",
          "documentation":"<p>The credit option for CPU usage of the instance.</p> <p>Valid values: <code>standard</code> | <code>unlimited</code> </p> <p>T3 instances with <code>host</code> tenancy do not support the <code>unlimited</code> CPU credit option.</p>"
        }
      },
      "documentation":"<p>Describes the credit option for CPU usage of a burstable performance instance.</p>"
    },
    "InstanceEventId":{"type":"string"},
    "InstanceEventWindow":{
      "type":"structure",
      "members":{
        "InstanceEventWindowId":{
          "shape":"InstanceEventWindowId",
          "documentation":"<p>The ID of the event window.</p>",
          "locationName":"instanceEventWindowId"
        },
        "TimeRanges":{
          "shape":"InstanceEventWindowTimeRangeList",
          "documentation":"<p>One or more time ranges defined for the event window.</p>",
          "locationName":"timeRangeSet"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the event window.</p>",
          "locationName":"name"
        },
        "CronExpression":{
          "shape":"InstanceEventWindowCronExpression",
          "documentation":"<p>The cron expression defined for the event window.</p>",
          "locationName":"cronExpression"
        },
        "AssociationTarget":{
          "shape":"InstanceEventWindowAssociationTarget",
          "documentation":"<p>One or more targets associated with the event window.</p>",
          "locationName":"associationTarget"
        },
        "State":{
          "shape":"InstanceEventWindowState",
          "documentation":"<p>The current state of the event window.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The instance tags associated with the event window.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>The event window.</p>"
    },
    "InstanceEventWindowAssociationRequest":{
      "type":"structure",
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdList",
          "documentation":"<p>The IDs of the instances to associate with the event window. If the instance is on a Dedicated Host, you can't specify the Instance ID parameter; you must use the Dedicated Host ID parameter.</p>",
          "locationName":"InstanceId"
        },
        "InstanceTags":{
          "shape":"TagList",
          "documentation":"<p>The instance tags to associate with the event window. Any instances associated with the tags will be associated with the event window.</p>",
          "locationName":"InstanceTag"
        },
        "DedicatedHostIds":{
          "shape":"DedicatedHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts to associate with the event window.</p>",
          "locationName":"DedicatedHostId"
        }
      },
      "documentation":"<p>One or more targets associated with the specified event window. Only one <i>type</i> of target (instance ID, instance tag, or Dedicated Host ID) can be associated with an event window.</p>"
    },
    "InstanceEventWindowAssociationTarget":{
      "type":"structure",
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdList",
          "documentation":"<p>The IDs of the instances associated with the event window.</p>",
          "locationName":"instanceIdSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The instance tags associated with the event window. Any instances associated with the tags will be associated with the event window.</p>",
          "locationName":"tagSet"
        },
        "DedicatedHostIds":{
          "shape":"DedicatedHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts associated with the event window.</p>",
          "locationName":"dedicatedHostIdSet"
        }
      },
      "documentation":"<p>One or more targets associated with the event window.</p>"
    },
    "InstanceEventWindowCronExpression":{"type":"string"},
    "InstanceEventWindowDisassociationRequest":{
      "type":"structure",
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdList",
          "documentation":"<p>The IDs of the instances to disassociate from the event window.</p>",
          "locationName":"InstanceId"
        },
        "InstanceTags":{
          "shape":"TagList",
          "documentation":"<p>The instance tags to disassociate from the event window. Any instances associated with the tags will be disassociated from the event window.</p>",
          "locationName":"InstanceTag"
        },
        "DedicatedHostIds":{
          "shape":"DedicatedHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts to disassociate from the event window.</p>",
          "locationName":"DedicatedHostId"
        }
      },
      "documentation":"<p>The targets to disassociate from the specified event window.</p>"
    },
    "InstanceEventWindowId":{"type":"string"},
    "InstanceEventWindowIdSet":{
      "type":"list",
      "member":{
        "shape":"InstanceEventWindowId",
        "locationName":"InstanceEventWindowId"
      }
    },
    "InstanceEventWindowSet":{
      "type":"list",
      "member":{
        "shape":"InstanceEventWindow",
        "locationName":"item"
      }
    },
    "InstanceEventWindowState":{
      "type":"string",
      "enum":[
        "creating",
        "deleting",
        "active",
        "deleted"
      ]
    },
    "InstanceEventWindowStateChange":{
      "type":"structure",
      "members":{
        "InstanceEventWindowId":{
          "shape":"InstanceEventWindowId",
          "documentation":"<p>The ID of the event window.</p>",
          "locationName":"instanceEventWindowId"
        },
        "State":{
          "shape":"InstanceEventWindowState",
          "documentation":"<p>The current state of the event window.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>The state of the event window.</p>"
    },
    "InstanceEventWindowTimeRange":{
      "type":"structure",
      "members":{
        "StartWeekDay":{
          "shape":"WeekDay",
          "documentation":"<p>The day on which the time range begins.</p>",
          "locationName":"startWeekDay"
        },
        "StartHour":{
          "shape":"Hour",
          "documentation":"<p>The hour when the time range begins.</p>",
          "locationName":"startHour"
        },
        "EndWeekDay":{
          "shape":"WeekDay",
          "documentation":"<p>The day on which the time range ends.</p>",
          "locationName":"endWeekDay"
        },
        "EndHour":{
          "shape":"Hour",
          "documentation":"<p>The hour when the time range ends.</p>",
          "locationName":"endHour"
        }
      },
      "documentation":"<p>The start day and time and the end day and time of the time range, in UTC.</p>"
    },
    "InstanceEventWindowTimeRangeList":{
      "type":"list",
      "member":{
        "shape":"InstanceEventWindowTimeRange",
        "locationName":"item"
      }
    },
    "InstanceEventWindowTimeRangeRequest":{
      "type":"structure",
      "members":{
        "StartWeekDay":{
          "shape":"WeekDay",
          "documentation":"<p>The day on which the time range begins.</p>"
        },
        "StartHour":{
          "shape":"Hour",
          "documentation":"<p>The hour when the time range begins.</p>"
        },
        "EndWeekDay":{
          "shape":"WeekDay",
          "documentation":"<p>The day on which the time range ends.</p>"
        },
        "EndHour":{
          "shape":"Hour",
          "documentation":"<p>The hour when the time range ends.</p>"
        }
      },
      "documentation":"<p>The start day and time and the end day and time of the time range, in UTC.</p>"
    },
    "InstanceEventWindowTimeRangeRequestSet":{
      "type":"list",
      "member":{"shape":"InstanceEventWindowTimeRangeRequest"}
    },
    "InstanceExportDetails":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource being exported.</p>",
          "locationName":"instanceId"
        },
        "TargetEnvironment":{
          "shape":"ExportEnvironment",
          "documentation":"<p>The target virtualization environment.</p>",
          "locationName":"targetEnvironment"
        }
      },
      "documentation":"<p>Describes an instance to export.</p>"
    },
    "InstanceFamilyCreditSpecification":{
      "type":"structure",
      "members":{
        "InstanceFamily":{
          "shape":"UnlimitedSupportedInstanceFamily",
          "documentation":"<p>The instance family.</p>",
          "locationName":"instanceFamily"
        },
        "CpuCredits":{
          "shape":"String",
          "documentation":"<p>The default credit option for CPU usage of the instance family. Valid values are <code>standard</code> and <code>unlimited</code>.</p>",
          "locationName":"cpuCredits"
        }
      },
      "documentation":"<p>Describes the default credit option for CPU usage of a burstable performance instance family.</p>"
    },
    "InstanceGeneration":{
      "type":"string",
      "enum":[
        "current",
        "previous"
      ]
    },
    "InstanceGenerationSet":{
      "type":"list",
      "member":{
        "shape":"InstanceGeneration",
        "locationName":"item"
      }
    },
    "InstanceHealthStatus":{
      "type":"string",
      "enum":[
        "healthy",
        "unhealthy"
      ]
    },
    "InstanceId":{"type":"string"},
    "InstanceIdForResolver":{"type":"string"},
    "InstanceIdList":{
      "type":"list",
      "member":{
        "shape":"InstanceId",
        "locationName":"item"
      }
    },
    "InstanceIdSet":{
      "type":"list",
      "member":{
        "shape":"InstanceId",
        "locationName":"item"
      }
    },
    "InstanceIdStringList":{
      "type":"list",
      "member":{
        "shape":"InstanceId",
        "locationName":"InstanceId"
      }
    },
    "InstanceIdWithVolumeResolver":{"type":"string"},
    "InstanceIdsSet":{
      "type":"list",
      "member":{
        "shape":"InstanceId",
        "locationName":"item"
      }
    },
    "InstanceInterruptionBehavior":{
      "type":"string",
      "enum":[
        "hibernate",
        "stop",
        "terminate"
      ]
    },
    "InstanceIpv4Prefix":{
      "type":"structure",
      "members":{
        "Ipv4Prefix":{
          "shape":"String",
          "documentation":"<p>One or more IPv4 prefixes assigned to the network interface.</p>",
          "locationName":"ipv4Prefix"
        }
      },
      "documentation":"<p>Information about an IPv4 prefix.</p>"
    },
    "InstanceIpv4PrefixList":{
      "type":"list",
      "member":{
        "shape":"InstanceIpv4Prefix",
        "locationName":"item"
      }
    },
    "InstanceIpv6Address":{
      "type":"structure",
      "members":{
        "Ipv6Address":{
          "shape":"String",
          "documentation":"<p>The IPv6 address.</p>",
          "locationName":"ipv6Address"
        }
      },
      "documentation":"<p>Describes an IPv6 address.</p>"
    },
    "InstanceIpv6AddressList":{
      "type":"list",
      "member":{
        "shape":"InstanceIpv6Address",
        "locationName":"item"
      }
    },
    "InstanceIpv6AddressListRequest":{
      "type":"list",
      "member":{
        "shape":"InstanceIpv6AddressRequest",
        "locationName":"InstanceIpv6Address"
      }
    },
    "InstanceIpv6AddressRequest":{
      "type":"structure",
      "members":{
        "Ipv6Address":{
          "shape":"String",
          "documentation":"<p>The IPv6 address.</p>"
        }
      },
      "documentation":"<p>Describes an IPv6 address.</p>"
    },
    "InstanceIpv6Prefix":{
      "type":"structure",
      "members":{
        "Ipv6Prefix":{
          "shape":"String",
          "documentation":"<p>One or more IPv6 prefixes assigned to the network interface.</p>",
          "locationName":"ipv6Prefix"
        }
      },
      "documentation":"<p>Information about an IPv6 prefix.</p>"
    },
    "InstanceIpv6PrefixList":{
      "type":"list",
      "member":{
        "shape":"InstanceIpv6Prefix",
        "locationName":"item"
      }
    },
    "InstanceLifecycle":{
      "type":"string",
      "enum":[
        "spot",
        "on-demand"
      ]
    },
    "InstanceLifecycleType":{
      "type":"string",
      "enum":[
        "spot",
        "scheduled"
      ]
    },
    "InstanceList":{
      "type":"list",
      "member":{
        "shape":"Instance",
        "locationName":"item"
      }
    },
    "InstanceMaintenanceOptions":{
      "type":"structure",
      "members":{
        "AutoRecovery":{
          "shape":"InstanceAutoRecoveryState",
          "documentation":"<p>Provides information on the current automatic recovery behavior of your instance.</p>",
          "locationName":"autoRecovery"
        }
      },
      "documentation":"<p>The maintenance options for the instance.</p>"
    },
    "InstanceMaintenanceOptionsRequest":{
      "type":"structure",
      "members":{
        "AutoRecovery":{
          "shape":"InstanceAutoRecoveryState",
          "documentation":"<p>Disables the automatic recovery behavior of your instance or sets it to default. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-recover.html#instance-configuration-recovery\">Simplified automatic recovery</a>.</p>"
        }
      },
      "documentation":"<p>The maintenance options for the instance.</p>"
    },
    "InstanceMarketOptionsRequest":{
      "type":"structure",
      "members":{
        "MarketType":{
          "shape":"MarketType",
          "documentation":"<p>The market type.</p>"
        },
        "SpotOptions":{
          "shape":"SpotMarketOptions",
          "documentation":"<p>The options for Spot Instances.</p>"
        }
      },
      "documentation":"<p>Describes the market (purchasing) option for the instances.</p>"
    },
    "InstanceMatchCriteria":{
      "type":"string",
      "enum":[
        "open",
        "targeted"
      ]
    },
    "InstanceMetadataEndpointState":{
      "type":"string",
      "enum":[
        "disabled",
        "enabled"
      ]
    },
    "InstanceMetadataOptionsRequest":{
      "type":"structure",
      "members":{
        "HttpTokens":{
          "shape":"HttpTokensState",
          "documentation":"<p>IMDSv2 uses token-backed sessions. Set the use of HTTP tokens to <code>optional</code> (in other words, set the use of IMDSv2 to <code>optional</code>) or <code>required</code> (in other words, set the use of IMDSv2 to <code>required</code>).</p> <ul> <li> <p> <code>optional</code> - When IMDSv2 is optional, you can choose to retrieve instance metadata with or without a session token in your request. If you retrieve the IAM role credentials without a token, the IMDSv1 role credentials are returned. If you retrieve the IAM role credentials using a valid session token, the IMDSv2 role credentials are returned.</p> </li> <li> <p> <code>required</code> - When IMDSv2 is required, you must send a session token with any instance metadata retrieval requests. In this state, retrieving the IAM role credentials always returns IMDSv2 credentials; IMDSv1 credentials are not available.</p> </li> </ul> <p>Default: <code>optional</code> </p>"
        },
        "HttpPutResponseHopLimit":{
          "shape":"Integer",
          "documentation":"<p>The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel.</p> <p>Default: 1</p> <p>Possible values: Integers from 1 to 64</p>"
        },
        "HttpEndpoint":{
          "shape":"InstanceMetadataEndpointState",
          "documentation":"<p>Enables or disables the HTTP metadata endpoint on your instances.</p> <p>If you specify a value of <code>disabled</code>, you cannot access your instance metadata.</p> <p>Default: <code>enabled</code> </p>"
        },
        "HttpProtocolIpv6":{
          "shape":"InstanceMetadataProtocolState",
          "documentation":"<p>Enables or disables the IPv6 endpoint for the instance metadata service.</p>"
        },
        "InstanceMetadataTags":{
          "shape":"InstanceMetadataTagsState",
          "documentation":"<p>Set to <code>enabled</code> to allow access to instance tags from the instance metadata. Set to <code>disabled</code> to turn off access to instance tags from the instance metadata. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#work-with-tags-in-IMDS\">Work with instance tags using the instance metadata</a>.</p> <p>Default: <code>disabled</code> </p>"
        }
      },
      "documentation":"<p>The metadata options for the instance.</p>"
    },
    "InstanceMetadataOptionsResponse":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"InstanceMetadataOptionsState",
          "documentation":"<p>The state of the metadata option changes.</p> <p> <code>pending</code> - The metadata options are being updated and the instance is not ready to process metadata traffic with the new selection.</p> <p> <code>applied</code> - The metadata options have been successfully applied on the instance.</p>",
          "locationName":"state"
        },
        "HttpTokens":{
          "shape":"HttpTokensState",
          "documentation":"<p>IMDSv2 uses token-backed sessions. Indicates whether the use of HTTP tokens is <code>optional</code> (in other words, indicates whether the use of IMDSv2 is <code>optional</code>) or <code>required</code> (in other words, indicates whether the use of IMDSv2 is <code>required</code>).</p> <ul> <li> <p> <code>optional</code> - When IMDSv2 is optional, you can choose to retrieve instance metadata with or without a session token in your request. If you retrieve the IAM role credentials without a token, the IMDSv1 role credentials are returned. If you retrieve the IAM role credentials using a valid session token, the IMDSv2 role credentials are returned.</p> </li> <li> <p> <code>required</code> - When IMDSv2 is required, you must send a session token with any instance metadata retrieval requests. In this state, retrieving the IAM role credentials always returns IMDSv2 credentials; IMDSv1 credentials are not available.</p> </li> </ul> <p>Default: <code>optional</code> </p>",
          "locationName":"httpTokens"
        },
        "HttpPutResponseHopLimit":{
          "shape":"Integer",
          "documentation":"<p>The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel.</p> <p>Default: 1</p> <p>Possible values: Integers from 1 to 64</p>",
          "locationName":"httpPutResponseHopLimit"
        },
        "HttpEndpoint":{
          "shape":"InstanceMetadataEndpointState",
          "documentation":"<p>Indicates whether the HTTP metadata endpoint on your instances is enabled or disabled.</p> <p>If the value is <code>disabled</code>, you cannot access your instance metadata.</p>",
          "locationName":"httpEndpoint"
        },
        "HttpProtocolIpv6":{
          "shape":"InstanceMetadataProtocolState",
          "documentation":"<p>Indicates whether the IPv6 endpoint for the instance metadata service is enabled or disabled.</p>",
          "locationName":"httpProtocolIpv6"
        },
        "InstanceMetadataTags":{
          "shape":"InstanceMetadataTagsState",
          "documentation":"<p>Indicates whether access to instance tags from the instance metadata is enabled or disabled. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#work-with-tags-in-IMDS\">Work with instance tags using the instance metadata</a>.</p>",
          "locationName":"instanceMetadataTags"
        }
      },
      "documentation":"<p>The metadata options for the instance.</p>"
    },
    "InstanceMetadataOptionsState":{
      "type":"string",
      "enum":[
        "pending",
        "applied"
      ]
    },
    "InstanceMetadataProtocolState":{
      "type":"string",
      "enum":[
        "disabled",
        "enabled"
      ]
    },
    "InstanceMetadataTagsState":{
      "type":"string",
      "enum":[
        "disabled",
        "enabled"
      ]
    },
    "InstanceMonitoring":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "Monitoring":{
          "shape":"Monitoring",
          "documentation":"<p>The monitoring for the instance.</p>",
          "locationName":"monitoring"
        }
      },
      "documentation":"<p>Describes the monitoring of an instance.</p>"
    },
    "InstanceMonitoringList":{
      "type":"list",
      "member":{
        "shape":"InstanceMonitoring",
        "locationName":"item"
      }
    },
    "InstanceNetworkInterface":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"InstanceNetworkInterfaceAssociation",
          "documentation":"<p>The association information for an Elastic IPv4 associated with the network interface.</p>",
          "locationName":"association"
        },
        "Attachment":{
          "shape":"InstanceNetworkInterfaceAttachment",
          "documentation":"<p>The network interface attachment.</p>",
          "locationName":"attachment"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description.</p>",
          "locationName":"description"
        },
        "Groups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>The security groups.</p>",
          "locationName":"groupSet"
        },
        "Ipv6Addresses":{
          "shape":"InstanceIpv6AddressList",
          "documentation":"<p>The IPv6 addresses associated with the network interface.</p>",
          "locationName":"ipv6AddressesSet"
        },
        "MacAddress":{
          "shape":"String",
          "documentation":"<p>The MAC address.</p>",
          "locationName":"macAddress"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that created the network interface.</p>",
          "locationName":"ownerId"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private DNS name.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The IPv4 address of the network interface within the subnet.</p>",
          "locationName":"privateIpAddress"
        },
        "PrivateIpAddresses":{
          "shape":"InstancePrivateIpAddressList",
          "documentation":"<p>The private IPv4 addresses associated with the network interface.</p>",
          "locationName":"privateIpAddressesSet"
        },
        "SourceDestCheck":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether source/destination checking is enabled.</p>",
          "locationName":"sourceDestCheck"
        },
        "Status":{
          "shape":"NetworkInterfaceStatus",
          "documentation":"<p>The status of the network interface.</p>",
          "locationName":"status"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "InterfaceType":{
          "shape":"String",
          "documentation":"<p>The type of network interface.</p> <p>Valid values: <code>interface</code> | <code>efa</code> | <code>trunk</code> </p>",
          "locationName":"interfaceType"
        },
        "Ipv4Prefixes":{
          "shape":"InstanceIpv4PrefixList",
          "documentation":"<p>The IPv4 delegated prefixes that are assigned to the network interface.</p>",
          "locationName":"ipv4PrefixSet"
        },
        "Ipv6Prefixes":{
          "shape":"InstanceIpv6PrefixList",
          "documentation":"<p>The IPv6 delegated prefixes that are assigned to the network interface.</p>",
          "locationName":"ipv6PrefixSet"
        }
      },
      "documentation":"<p>Describes a network interface.</p>"
    },
    "InstanceNetworkInterfaceAssociation":{
      "type":"structure",
      "members":{
        "CarrierIp":{
          "shape":"String",
          "documentation":"<p>The carrier IP address associated with the network interface.</p>",
          "locationName":"carrierIp"
        },
        "CustomerOwnedIp":{
          "shape":"String",
          "documentation":"<p>The customer-owned IP address associated with the network interface.</p>",
          "locationName":"customerOwnedIp"
        },
        "IpOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the owner of the Elastic IP address.</p>",
          "locationName":"ipOwnerId"
        },
        "PublicDnsName":{
          "shape":"String",
          "documentation":"<p>The public DNS name.</p>",
          "locationName":"publicDnsName"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The public IP address or Elastic IP address bound to the network interface.</p>",
          "locationName":"publicIp"
        }
      },
      "documentation":"<p>Describes association information for an Elastic IP address (IPv4).</p>"
    },
    "InstanceNetworkInterfaceAttachment":{
      "type":"structure",
      "members":{
        "AttachTime":{
          "shape":"DateTime",
          "documentation":"<p>The time stamp when the attachment initiated.</p>",
          "locationName":"attachTime"
        },
        "AttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface attachment.</p>",
          "locationName":"attachmentId"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the network interface is deleted when the instance is terminated.</p>",
          "locationName":"deleteOnTermination"
        },
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the device on the instance for the network interface attachment.</p>",
          "locationName":"deviceIndex"
        },
        "Status":{
          "shape":"AttachmentStatus",
          "documentation":"<p>The attachment state.</p>",
          "locationName":"status"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card.</p>",
          "locationName":"networkCardIndex"
        }
      },
      "documentation":"<p>Describes a network interface attachment.</p>"
    },
    "InstanceNetworkInterfaceList":{
      "type":"list",
      "member":{
        "shape":"InstanceNetworkInterface",
        "locationName":"item"
      }
    },
    "InstanceNetworkInterfaceSpecification":{
      "type":"structure",
      "members":{
        "AssociatePublicIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to assign a public IPv4 address to an instance you launch in a VPC. The public IP address can only be assigned to a network interface for eth0, and can only be assigned to a new network interface, not an existing one. You cannot specify more than one network interface in the request. If launching into a default subnet, the default value is <code>true</code>.</p>",
          "locationName":"associatePublicIpAddress"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>If set to <code>true</code>, the interface is deleted when the instance is terminated. You can specify <code>true</code> only if creating a new network interface when launching an instance.</p>",
          "locationName":"deleteOnTermination"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the network interface. Applies only if creating a network interface when launching an instance.</p>",
          "locationName":"description"
        },
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The position of the network interface in the attachment order. A primary network interface has a device index of 0.</p> <p>If you specify a network interface when launching an instance, you must specify the device index.</p>",
          "locationName":"deviceIndex"
        },
        "Groups":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>The IDs of the security groups for the network interface. Applies only if creating a network interface when launching an instance.</p>",
          "locationName":"SecurityGroupId"
        },
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>A number of IPv6 addresses to assign to the network interface. Amazon EC2 chooses the IPv6 addresses from the range of the subnet. You cannot specify this option and the option to assign specific IPv6 addresses in the same request. You can specify this option if you've specified a minimum number of instances to launch.</p>",
          "locationName":"ipv6AddressCount"
        },
        "Ipv6Addresses":{
          "shape":"InstanceIpv6AddressList",
          "documentation":"<p>The IPv6 addresses to assign to the network interface. You cannot specify this option and the option to assign a number of IPv6 addresses in the same request. You cannot specify this option if you've specified a minimum number of instances to launch.</p>",
          "locationName":"ipv6AddressesSet",
          "queryName":"Ipv6Addresses"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p> <p>If you are creating a Spot Fleet, omit this parameter because you can’t specify a network interface ID in a launch specification.</p>",
          "locationName":"networkInterfaceId"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IPv4 address of the network interface. Applies only if creating a network interface when launching an instance. You cannot specify this option if you're launching more than one instance in a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html\">RunInstances</a> request.</p>",
          "locationName":"privateIpAddress"
        },
        "PrivateIpAddresses":{
          "shape":"PrivateIpAddressSpecificationList",
          "documentation":"<p>The private IPv4 addresses to assign to the network interface. Only one private IPv4 address can be designated as primary. You cannot specify this option if you're launching more than one instance in a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html\">RunInstances</a> request.</p>",
          "locationName":"privateIpAddressesSet",
          "queryName":"PrivateIpAddresses"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of secondary private IPv4 addresses. You can't specify this option and specify more than one private IP address using the private IP addresses option. You cannot specify this option if you're launching more than one instance in a <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html\">RunInstances</a> request.</p>",
          "locationName":"secondaryPrivateIpAddressCount"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet associated with the network interface. Applies only if creating a network interface when launching an instance.</p>",
          "locationName":"subnetId"
        },
        "AssociateCarrierIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to assign a carrier IP address to the network interface.</p> <p>You can only assign a carrier IP address to a network interface that is in a subnet in a Wavelength Zone. For more information about carrier IP addresses, see <a href=\"https://docs.aws.amazon.com/wavelength/latest/developerguide/how-wavelengths-work.html#provider-owned-ip\">Carrier IP address</a> in the <i>Amazon Web Services Wavelength Developer Guide</i>.</p>"
        },
        "InterfaceType":{
          "shape":"String",
          "documentation":"<p>The type of network interface.</p> <p>Valid values: <code>interface</code> | <code>efa</code> </p>"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card. Some instance types support multiple network cards. The primary network interface must be assigned to network card index 0. The default is network card index 0.</p> <p>If you are using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RequestSpotInstances.html\">RequestSpotInstances</a> to create Spot Instances, omit this parameter because you can’t specify the network card index when using this API. To specify the network card index, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances.html\">RunInstances</a>.</p>"
        },
        "Ipv4Prefixes":{
          "shape":"Ipv4PrefixList",
          "documentation":"<p>The IPv4 delegated prefixes to be assigned to the network interface. You cannot use this option if you use the <code>Ipv4PrefixCount</code> option.</p>",
          "locationName":"Ipv4Prefix"
        },
        "Ipv4PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv4 delegated prefixes to be automatically assigned to the network interface. You cannot use this option if you use the <code>Ipv4Prefix</code> option.</p>"
        },
        "Ipv6Prefixes":{
          "shape":"Ipv6PrefixList",
          "documentation":"<p>The IPv6 delegated prefixes to be assigned to the network interface. You cannot use this option if you use the <code>Ipv6PrefixCount</code> option.</p>",
          "locationName":"Ipv6Prefix"
        },
        "Ipv6PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 delegated prefixes to be automatically assigned to the network interface. You cannot use this option if you use the <code>Ipv6Prefix</code> option.</p>"
        }
      },
      "documentation":"<p>Describes a network interface.</p>"
    },
    "InstanceNetworkInterfaceSpecificationList":{
      "type":"list",
      "member":{
        "shape":"InstanceNetworkInterfaceSpecification",
        "locationName":"item"
      }
    },
    "InstancePrivateIpAddress":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"InstanceNetworkInterfaceAssociation",
          "documentation":"<p>The association information for an Elastic IP address for the network interface.</p>",
          "locationName":"association"
        },
        "Primary":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this IPv4 address is the primary private IP address of the network interface.</p>",
          "locationName":"primary"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private IPv4 DNS name.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IPv4 address of the network interface.</p>",
          "locationName":"privateIpAddress"
        }
      },
      "documentation":"<p>Describes a private IPv4 address.</p>"
    },
    "InstancePrivateIpAddressList":{
      "type":"list",
      "member":{
        "shape":"InstancePrivateIpAddress",
        "locationName":"item"
      }
    },
    "InstanceRequirements":{
      "type":"structure",
      "members":{
        "VCpuCount":{
          "shape":"VCpuCountRange",
          "documentation":"<p>The minimum and maximum number of vCPUs.</p>",
          "locationName":"vCpuCount"
        },
        "MemoryMiB":{
          "shape":"MemoryMiB",
          "documentation":"<p>The minimum and maximum amount of memory, in MiB.</p>",
          "locationName":"memoryMiB"
        },
        "CpuManufacturers":{
          "shape":"CpuManufacturerSet",
          "documentation":"<p>The CPU manufacturers to include.</p> <ul> <li> <p>For instance types with Intel CPUs, specify <code>intel</code>.</p> </li> <li> <p>For instance types with AMD CPUs, specify <code>amd</code>.</p> </li> <li> <p>For instance types with Amazon Web Services CPUs, specify <code>amazon-web-services</code>.</p> </li> </ul> <note> <p>Don't confuse the CPU manufacturer with the CPU architecture. Instances will be launched with a compatible CPU architecture based on the Amazon Machine Image (AMI) that you specify in your launch template.</p> </note> <p>Default: Any manufacturer</p>",
          "locationName":"cpuManufacturerSet"
        },
        "MemoryGiBPerVCpu":{
          "shape":"MemoryGiBPerVCpu",
          "documentation":"<p>The minimum and maximum amount of memory per vCPU, in GiB.</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"memoryGiBPerVCpu"
        },
        "ExcludedInstanceTypes":{
          "shape":"ExcludedInstanceTypeSet",
          "documentation":"<p>The instance types to exclude.</p> <p>You can use strings with one or more wild cards, represented by an asterisk (<code>*</code>), to exclude an instance type, size, or generation. The following are examples: <code>m5.8xlarge</code>, <code>c5*.*</code>, <code>m5a.*</code>, <code>r*</code>, <code>*3*</code>.</p> <p>For example, if you specify <code>c5*</code>,Amazon EC2 will exclude the entire C5 instance family, which includes all C5a and C5n instance types. If you specify <code>m5a.*</code>, Amazon EC2 will exclude all the M5a instance types, but not the M5n instance types.</p> <note> <p>If you specify <code>ExcludedInstanceTypes</code>, you can't specify <code>AllowedInstanceTypes</code>.</p> </note> <p>Default: No excluded instance types</p>",
          "locationName":"excludedInstanceTypeSet"
        },
        "InstanceGenerations":{
          "shape":"InstanceGenerationSet",
          "documentation":"<p>Indicates whether current or previous generation instance types are included. The current generation instance types are recommended for use. Current generation instance types are typically the latest two to three generations in each instance family. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For current generation instance types, specify <code>current</code>.</p> <p>For previous generation instance types, specify <code>previous</code>.</p> <p>Default: Current and previous generation instance types</p>",
          "locationName":"instanceGenerationSet"
        },
        "SpotMaxPricePercentageOverLowestPrice":{
          "shape":"Integer",
          "documentation":"<p>The price protection threshold for Spot Instances. This is the maximum you’ll pay for a Spot Instance, expressed as a percentage above the least expensive current generation M, C, or R instance type with your specified attributes. When Amazon EC2 selects instance types with your attributes, it excludes instance types priced above your threshold.</p> <p>The parameter accepts an integer, which Amazon EC2 interprets as a percentage.</p> <p>To turn off price protection, specify a high value, such as <code>999999</code>.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html\">GetSpotPlacementScores</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTypesFromInstanceRequirements.html\">GetInstanceTypesFromInstanceRequirements</a>.</p> <note> <p>If you set <code>TargetCapacityUnitType</code> to <code>vcpu</code> or <code>memory-mib</code>, the price protection threshold is applied based on the per-vCPU or per-memory price instead of the per-instance price.</p> </note> <p>Default: <code>100</code> </p>",
          "locationName":"spotMaxPricePercentageOverLowestPrice"
        },
        "OnDemandMaxPricePercentageOverLowestPrice":{
          "shape":"Integer",
          "documentation":"<p>The price protection threshold for On-Demand Instances. This is the maximum you’ll pay for an On-Demand Instance, expressed as a percentage above the least expensive current generation M, C, or R instance type with your specified attributes. When Amazon EC2 selects instance types with your attributes, it excludes instance types priced above your threshold.</p> <p>The parameter accepts an integer, which Amazon EC2 interprets as a percentage.</p> <p>To turn off price protection, specify a high value, such as <code>999999</code>.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html\">GetSpotPlacementScores</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTypesFromInstanceRequirements.html\">GetInstanceTypesFromInstanceRequirements</a>.</p> <note> <p>If you set <code>TargetCapacityUnitType</code> to <code>vcpu</code> or <code>memory-mib</code>, the price protection threshold is applied based on the per-vCPU or per-memory price instead of the per-instance price.</p> </note> <p>Default: <code>20</code> </p>",
          "locationName":"onDemandMaxPricePercentageOverLowestPrice"
        },
        "BareMetal":{
          "shape":"BareMetal",
          "documentation":"<p>Indicates whether bare metal instance types must be included, excluded, or required.</p> <ul> <li> <p>To include bare metal instance types, specify <code>included</code>.</p> </li> <li> <p>To require only bare metal instance types, specify <code>required</code>.</p> </li> <li> <p>To exclude bare metal instance types, specify <code>excluded</code>.</p> </li> </ul> <p>Default: <code>excluded</code> </p>",
          "locationName":"bareMetal"
        },
        "BurstablePerformance":{
          "shape":"BurstablePerformance",
          "documentation":"<p>Indicates whether burstable performance T instance types are included, excluded, or required. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a>.</p> <ul> <li> <p>To include burstable performance instance types, specify <code>included</code>.</p> </li> <li> <p>To require only burstable performance instance types, specify <code>required</code>.</p> </li> <li> <p>To exclude burstable performance instance types, specify <code>excluded</code>.</p> </li> </ul> <p>Default: <code>excluded</code> </p>",
          "locationName":"burstablePerformance"
        },
        "RequireHibernateSupport":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether instance types must support hibernation for On-Demand Instances.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html\">GetSpotPlacementScores</a>.</p> <p>Default: <code>false</code> </p>",
          "locationName":"requireHibernateSupport"
        },
        "NetworkInterfaceCount":{
          "shape":"NetworkInterfaceCount",
          "documentation":"<p>The minimum and maximum number of network interfaces.</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"networkInterfaceCount"
        },
        "LocalStorage":{
          "shape":"LocalStorage",
          "documentation":"<p>Indicates whether instance types with instance store volumes are included, excluded, or required. For more information, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html\">Amazon EC2 instance store</a> in the <i>Amazon EC2 User Guide</i>.</p> <ul> <li> <p>To include instance types with instance store volumes, specify <code>included</code>.</p> </li> <li> <p>To require only instance types with instance store volumes, specify <code>required</code>.</p> </li> <li> <p>To exclude instance types with instance store volumes, specify <code>excluded</code>.</p> </li> </ul> <p>Default: <code>included</code> </p>",
          "locationName":"localStorage"
        },
        "LocalStorageTypes":{
          "shape":"LocalStorageTypeSet",
          "documentation":"<p>The type of local storage that is required.</p> <ul> <li> <p>For instance types with hard disk drive (HDD) storage, specify <code>hdd</code>.</p> </li> <li> <p>For instance types with solid state drive (SSD) storage, specify <code>ssd</code>.</p> </li> </ul> <p>Default: <code>hdd</code> and <code>ssd</code> </p>",
          "locationName":"localStorageTypeSet"
        },
        "TotalLocalStorageGB":{
          "shape":"TotalLocalStorageGB",
          "documentation":"<p>The minimum and maximum amount of total local storage, in GB.</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"totalLocalStorageGB"
        },
        "BaselineEbsBandwidthMbps":{
          "shape":"BaselineEbsBandwidthMbps",
          "documentation":"<p>The minimum and maximum baseline bandwidth to Amazon EBS, in Mbps. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-optimized.html\">Amazon EBS–optimized instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"baselineEbsBandwidthMbps"
        },
        "AcceleratorTypes":{
          "shape":"AcceleratorTypeSet",
          "documentation":"<p>The accelerator types that must be on the instance type.</p> <ul> <li> <p>For instance types with GPU accelerators, specify <code>gpu</code>.</p> </li> <li> <p>For instance types with FPGA accelerators, specify <code>fpga</code>.</p> </li> <li> <p>For instance types with inference accelerators, specify <code>inference</code>.</p> </li> </ul> <p>Default: Any accelerator type</p>",
          "locationName":"acceleratorTypeSet"
        },
        "AcceleratorCount":{
          "shape":"AcceleratorCount",
          "documentation":"<p>The minimum and maximum number of accelerators (GPUs, FPGAs, or Amazon Web Services Inferentia chips) on an instance.</p> <p>To exclude accelerator-enabled instance types, set <code>Max</code> to <code>0</code>.</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"acceleratorCount"
        },
        "AcceleratorManufacturers":{
          "shape":"AcceleratorManufacturerSet",
          "documentation":"<p>Indicates whether instance types must have accelerators by specific manufacturers.</p> <ul> <li> <p>For instance types with NVIDIA devices, specify <code>nvidia</code>.</p> </li> <li> <p>For instance types with AMD devices, specify <code>amd</code>.</p> </li> <li> <p>For instance types with Amazon Web Services devices, specify <code>amazon-web-services</code>.</p> </li> <li> <p>For instance types with Xilinx devices, specify <code>xilinx</code>.</p> </li> </ul> <p>Default: Any manufacturer</p>",
          "locationName":"acceleratorManufacturerSet"
        },
        "AcceleratorNames":{
          "shape":"AcceleratorNameSet",
          "documentation":"<p>The accelerators that must be on the instance type.</p> <ul> <li> <p>For instance types with NVIDIA A100 GPUs, specify <code>a100</code>.</p> </li> <li> <p>For instance types with NVIDIA V100 GPUs, specify <code>v100</code>.</p> </li> <li> <p>For instance types with NVIDIA K80 GPUs, specify <code>k80</code>.</p> </li> <li> <p>For instance types with NVIDIA T4 GPUs, specify <code>t4</code>.</p> </li> <li> <p>For instance types with NVIDIA M60 GPUs, specify <code>m60</code>.</p> </li> <li> <p>For instance types with AMD Radeon Pro V520 GPUs, specify <code>radeon-pro-v520</code>.</p> </li> <li> <p>For instance types with Xilinx VU9P FPGAs, specify <code>vu9p</code>.</p> </li> <li> <p>For instance types with Amazon Web Services Inferentia chips, specify <code>inferentia</code>.</p> </li> <li> <p>For instance types with NVIDIA GRID K520 GPUs, specify <code>k520</code>.</p> </li> </ul> <p>Default: Any accelerator</p>",
          "locationName":"acceleratorNameSet"
        },
        "AcceleratorTotalMemoryMiB":{
          "shape":"AcceleratorTotalMemoryMiB",
          "documentation":"<p>The minimum and maximum amount of total accelerator memory, in MiB.</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"acceleratorTotalMemoryMiB"
        },
        "NetworkBandwidthGbps":{
          "shape":"NetworkBandwidthGbps",
          "documentation":"<p>The minimum and maximum amount of network bandwidth, in gigabits per second (Gbps).</p> <p>Default: No minimum or maximum limits</p>",
          "locationName":"networkBandwidthGbps"
        },
        "AllowedInstanceTypes":{
          "shape":"AllowedInstanceTypeSet",
          "documentation":"<p>The instance types to apply your specified attributes against. All other instance types are ignored, even if they match your specified attributes.</p> <p>You can use strings with one or more wild cards, represented by an asterisk (<code>*</code>), to allow an instance type, size, or generation. The following are examples: <code>m5.8xlarge</code>, <code>c5*.*</code>, <code>m5a.*</code>, <code>r*</code>, <code>*3*</code>.</p> <p>For example, if you specify <code>c5*</code>,Amazon EC2 will allow the entire C5 instance family, which includes all C5a and C5n instance types. If you specify <code>m5a.*</code>, Amazon EC2 will allow all the M5a instance types, but not the M5n instance types.</p> <note> <p>If you specify <code>AllowedInstanceTypes</code>, you can't specify <code>ExcludedInstanceTypes</code>.</p> </note> <p>Default: All instance types</p>",
          "locationName":"allowedInstanceTypeSet"
        }
      },
      "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with these attributes.</p> <p>When you specify multiple attributes, you get instance types that satisfy all of the specified attributes. If you specify multiple values for an attribute, you get instance types that satisfy any of the specified values.</p> <p>To limit the list of instance types from which Amazon EC2 can identify matching instance types, you can use one of the following parameters, but not both in the same request:</p> <ul> <li> <p> <code>AllowedInstanceTypes</code> - The instance types to include in the list. All other instance types are ignored, even if they match your specified attributes.</p> </li> <li> <p> <code>ExcludedInstanceTypes</code> - The instance types to exclude from the list, even if they match your specified attributes.</p> </li> </ul> <note> <p>You must specify <code>VCpuCount</code> and <code>MemoryMiB</code>. All other attributes are optional. Any unspecified optional attribute is set to its default.</p> </note> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-attribute-based-instance-type-selection.html\">Attribute-based instance type selection for EC2 Fleet</a>, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-attribute-based-instance-type-selection.html\">Attribute-based instance type selection for Spot Fleet</a>, and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-placement-score.html\">Spot placement score</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "InstanceRequirementsRequest":{
      "type":"structure",
      "required":[
        "VCpuCount",
        "MemoryMiB"
      ],
      "members":{
        "VCpuCount":{
          "shape":"VCpuCountRangeRequest",
          "documentation":"<p>The minimum and maximum number of vCPUs.</p>"
        },
        "MemoryMiB":{
          "shape":"MemoryMiBRequest",
          "documentation":"<p>The minimum and maximum amount of memory, in MiB.</p>"
        },
        "CpuManufacturers":{
          "shape":"CpuManufacturerSet",
          "documentation":"<p>The CPU manufacturers to include.</p> <ul> <li> <p>For instance types with Intel CPUs, specify <code>intel</code>.</p> </li> <li> <p>For instance types with AMD CPUs, specify <code>amd</code>.</p> </li> <li> <p>For instance types with Amazon Web Services CPUs, specify <code>amazon-web-services</code>.</p> </li> </ul> <note> <p>Don't confuse the CPU manufacturer with the CPU architecture. Instances will be launched with a compatible CPU architecture based on the Amazon Machine Image (AMI) that you specify in your launch template.</p> </note> <p>Default: Any manufacturer</p>",
          "locationName":"CpuManufacturer"
        },
        "MemoryGiBPerVCpu":{
          "shape":"MemoryGiBPerVCpuRequest",
          "documentation":"<p>The minimum and maximum amount of memory per vCPU, in GiB.</p> <p>Default: No minimum or maximum limits</p>"
        },
        "ExcludedInstanceTypes":{
          "shape":"ExcludedInstanceTypeSet",
          "documentation":"<p>The instance types to exclude.</p> <p>You can use strings with one or more wild cards, represented by an asterisk (<code>*</code>), to exclude an instance family, type, size, or generation. The following are examples: <code>m5.8xlarge</code>, <code>c5*.*</code>, <code>m5a.*</code>, <code>r*</code>, <code>*3*</code>.</p> <p>For example, if you specify <code>c5*</code>,Amazon EC2 will exclude the entire C5 instance family, which includes all C5a and C5n instance types. If you specify <code>m5a.*</code>, Amazon EC2 will exclude all the M5a instance types, but not the M5n instance types.</p> <note> <p>If you specify <code>ExcludedInstanceTypes</code>, you can't specify <code>AllowedInstanceTypes</code>.</p> </note> <p>Default: No excluded instance types</p>",
          "locationName":"ExcludedInstanceType"
        },
        "InstanceGenerations":{
          "shape":"InstanceGenerationSet",
          "documentation":"<p>Indicates whether current or previous generation instance types are included. The current generation instance types are recommended for use. Current generation instance types are typically the latest two to three generations in each instance family. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>For current generation instance types, specify <code>current</code>.</p> <p>For previous generation instance types, specify <code>previous</code>.</p> <p>Default: Current and previous generation instance types</p>",
          "locationName":"InstanceGeneration"
        },
        "SpotMaxPricePercentageOverLowestPrice":{
          "shape":"Integer",
          "documentation":"<p>The price protection threshold for Spot Instance. This is the maximum you’ll pay for an Spot Instance, expressed as a percentage above the least expensive current generation M, C, or R instance type with your specified attributes. When Amazon EC2 selects instance types with your attributes, it excludes instance types priced above your threshold.</p> <p>The parameter accepts an integer, which Amazon EC2 interprets as a percentage.</p> <p>To turn off price protection, specify a high value, such as <code>999999</code>.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html\">GetSpotPlacementScores</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTypesFromInstanceRequirements.html\">GetInstanceTypesFromInstanceRequirements</a>.</p> <note> <p>If you set <code>TargetCapacityUnitType</code> to <code>vcpu</code> or <code>memory-mib</code>, the price protection threshold is applied based on the per-vCPU or per-memory price instead of the per-instance price.</p> </note> <p>Default: <code>100</code> </p>"
        },
        "OnDemandMaxPricePercentageOverLowestPrice":{
          "shape":"Integer",
          "documentation":"<p>The price protection threshold for On-Demand Instances. This is the maximum you’ll pay for an On-Demand Instance, expressed as a percentage above the least expensive current generation M, C, or R instance type with your specified attributes. When Amazon EC2 selects instance types with your attributes, it excludes instance types priced above your threshold.</p> <p>The parameter accepts an integer, which Amazon EC2 interprets as a percentage.</p> <p>To turn off price protection, specify a high value, such as <code>999999</code>.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html\">GetSpotPlacementScores</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceTypesFromInstanceRequirements.html\">GetInstanceTypesFromInstanceRequirements</a>.</p> <note> <p>If you set <code>TargetCapacityUnitType</code> to <code>vcpu</code> or <code>memory-mib</code>, the price protection threshold is applied based on the per-vCPU or per-memory price instead of the per-instance price.</p> </note> <p>Default: <code>20</code> </p>"
        },
        "BareMetal":{
          "shape":"BareMetal",
          "documentation":"<p>Indicates whether bare metal instance types must be included, excluded, or required.</p> <ul> <li> <p>To include bare metal instance types, specify <code>included</code>.</p> </li> <li> <p>To require only bare metal instance types, specify <code>required</code>.</p> </li> <li> <p>To exclude bare metal instance types, specify <code>excluded</code>.</p> </li> </ul> <p>Default: <code>excluded</code> </p>"
        },
        "BurstablePerformance":{
          "shape":"BurstablePerformance",
          "documentation":"<p>Indicates whether burstable performance T instance types are included, excluded, or required. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a>.</p> <ul> <li> <p>To include burstable performance instance types, specify <code>included</code>.</p> </li> <li> <p>To require only burstable performance instance types, specify <code>required</code>.</p> </li> <li> <p>To exclude burstable performance instance types, specify <code>excluded</code>.</p> </li> </ul> <p>Default: <code>excluded</code> </p>"
        },
        "RequireHibernateSupport":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether instance types must support hibernation for On-Demand Instances.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetSpotPlacementScores.html\">GetSpotPlacementScores</a>.</p> <p>Default: <code>false</code> </p>"
        },
        "NetworkInterfaceCount":{
          "shape":"NetworkInterfaceCountRequest",
          "documentation":"<p>The minimum and maximum number of network interfaces.</p> <p>Default: No minimum or maximum limits</p>"
        },
        "LocalStorage":{
          "shape":"LocalStorage",
          "documentation":"<p>Indicates whether instance types with instance store volumes are included, excluded, or required. For more information, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/InstanceStorage.html\">Amazon EC2 instance store</a> in the <i>Amazon EC2 User Guide</i>.</p> <ul> <li> <p>To include instance types with instance store volumes, specify <code>included</code>.</p> </li> <li> <p>To require only instance types with instance store volumes, specify <code>required</code>.</p> </li> <li> <p>To exclude instance types with instance store volumes, specify <code>excluded</code>.</p> </li> </ul> <p>Default: <code>included</code> </p>"
        },
        "LocalStorageTypes":{
          "shape":"LocalStorageTypeSet",
          "documentation":"<p>The type of local storage that is required.</p> <ul> <li> <p>For instance types with hard disk drive (HDD) storage, specify <code>hdd</code>.</p> </li> <li> <p>For instance types with solid state drive (SSD) storage, specify <code>ssd</code>.</p> </li> </ul> <p>Default: <code>hdd</code> and <code>ssd</code> </p>",
          "locationName":"LocalStorageType"
        },
        "TotalLocalStorageGB":{
          "shape":"TotalLocalStorageGBRequest",
          "documentation":"<p>The minimum and maximum amount of total local storage, in GB.</p> <p>Default: No minimum or maximum limits</p>"
        },
        "BaselineEbsBandwidthMbps":{
          "shape":"BaselineEbsBandwidthMbpsRequest",
          "documentation":"<p>The minimum and maximum baseline bandwidth to Amazon EBS, in Mbps. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-optimized.html\">Amazon EBS–optimized instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: No minimum or maximum limits</p>"
        },
        "AcceleratorTypes":{
          "shape":"AcceleratorTypeSet",
          "documentation":"<p>The accelerator types that must be on the instance type.</p> <ul> <li> <p>To include instance types with GPU hardware, specify <code>gpu</code>.</p> </li> <li> <p>To include instance types with FPGA hardware, specify <code>fpga</code>.</p> </li> <li> <p>To include instance types with inference hardware, specify <code>inference</code>.</p> </li> </ul> <p>Default: Any accelerator type</p>",
          "locationName":"AcceleratorType"
        },
        "AcceleratorCount":{
          "shape":"AcceleratorCountRequest",
          "documentation":"<p>The minimum and maximum number of accelerators (GPUs, FPGAs, or Amazon Web Services Inferentia chips) on an instance.</p> <p>To exclude accelerator-enabled instance types, set <code>Max</code> to <code>0</code>.</p> <p>Default: No minimum or maximum limits</p>"
        },
        "AcceleratorManufacturers":{
          "shape":"AcceleratorManufacturerSet",
          "documentation":"<p>Indicates whether instance types must have accelerators by specific manufacturers.</p> <ul> <li> <p>For instance types with NVIDIA devices, specify <code>nvidia</code>.</p> </li> <li> <p>For instance types with AMD devices, specify <code>amd</code>.</p> </li> <li> <p>For instance types with Amazon Web Services devices, specify <code>amazon-web-services</code>.</p> </li> <li> <p>For instance types with Xilinx devices, specify <code>xilinx</code>.</p> </li> </ul> <p>Default: Any manufacturer</p>",
          "locationName":"AcceleratorManufacturer"
        },
        "AcceleratorNames":{
          "shape":"AcceleratorNameSet",
          "documentation":"<p>The accelerators that must be on the instance type.</p> <ul> <li> <p>For instance types with NVIDIA A100 GPUs, specify <code>a100</code>.</p> </li> <li> <p>For instance types with NVIDIA V100 GPUs, specify <code>v100</code>.</p> </li> <li> <p>For instance types with NVIDIA K80 GPUs, specify <code>k80</code>.</p> </li> <li> <p>For instance types with NVIDIA T4 GPUs, specify <code>t4</code>.</p> </li> <li> <p>For instance types with NVIDIA M60 GPUs, specify <code>m60</code>.</p> </li> <li> <p>For instance types with AMD Radeon Pro V520 GPUs, specify <code>radeon-pro-v520</code>.</p> </li> <li> <p>For instance types with Xilinx VU9P FPGAs, specify <code> vu9p</code>.</p> </li> <li> <p>For instance types with Amazon Web Services Inferentia chips, specify <code>inferentia</code>.</p> </li> <li> <p>For instance types with NVIDIA GRID K520 GPUs, specify <code>k520</code>.</p> </li> </ul> <p>Default: Any accelerator</p>",
          "locationName":"AcceleratorName"
        },
        "AcceleratorTotalMemoryMiB":{
          "shape":"AcceleratorTotalMemoryMiBRequest",
          "documentation":"<p>The minimum and maximum amount of total accelerator memory, in MiB.</p> <p>Default: No minimum or maximum limits</p>"
        },
        "NetworkBandwidthGbps":{
          "shape":"NetworkBandwidthGbpsRequest",
          "documentation":"<p>The minimum and maximum amount of network bandwidth, in gigabits per second (Gbps).</p> <p>Default: No minimum or maximum limits</p>"
        },
        "AllowedInstanceTypes":{
          "shape":"AllowedInstanceTypeSet",
          "documentation":"<p>The instance types to apply your specified attributes against. All other instance types are ignored, even if they match your specified attributes.</p> <p>You can use strings with one or more wild cards, represented by an asterisk (<code>*</code>), to allow an instance type, size, or generation. The following are examples: <code>m5.8xlarge</code>, <code>c5*.*</code>, <code>m5a.*</code>, <code>r*</code>, <code>*3*</code>.</p> <p>For example, if you specify <code>c5*</code>,Amazon EC2 will allow the entire C5 instance family, which includes all C5a and C5n instance types. If you specify <code>m5a.*</code>, Amazon EC2 will allow all the M5a instance types, but not the M5n instance types.</p> <note> <p>If you specify <code>AllowedInstanceTypes</code>, you can't specify <code>ExcludedInstanceTypes</code>.</p> </note> <p>Default: All instance types</p>",
          "locationName":"AllowedInstanceType"
        }
      },
      "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with these attributes.</p> <p>When you specify multiple attributes, you get instance types that satisfy all of the specified attributes. If you specify multiple values for an attribute, you get instance types that satisfy any of the specified values.</p> <p>To limit the list of instance types from which Amazon EC2 can identify matching instance types, you can use one of the following parameters, but not both in the same request:</p> <ul> <li> <p> <code>AllowedInstanceTypes</code> - The instance types to include in the list. All other instance types are ignored, even if they match your specified attributes.</p> </li> <li> <p> <code>ExcludedInstanceTypes</code> - The instance types to exclude from the list, even if they match your specified attributes.</p> </li> </ul> <note> <p>You must specify <code>VCpuCount</code> and <code>MemoryMiB</code>. All other attributes are optional. Any unspecified optional attribute is set to its default.</p> </note> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-attribute-based-instance-type-selection.html\">Attribute-based instance type selection for EC2 Fleet</a>, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-attribute-based-instance-type-selection.html\">Attribute-based instance type selection for Spot Fleet</a>, and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-placement-score.html\">Spot placement score</a> in the <i>Amazon EC2 User Guide</i>.</p>"
    },
    "InstanceRequirementsWithMetadataRequest":{
      "type":"structure",
      "members":{
        "ArchitectureTypes":{
          "shape":"ArchitectureTypeSet",
          "documentation":"<p>The architecture type.</p>",
          "locationName":"ArchitectureType"
        },
        "VirtualizationTypes":{
          "shape":"VirtualizationTypeSet",
          "documentation":"<p>The virtualization type.</p>",
          "locationName":"VirtualizationType"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirementsRequest",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.</p>"
        }
      },
      "documentation":"<p>The architecture type, virtualization type, and other attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.</p> <p>If you specify <code>InstanceRequirementsWithMetadataRequest</code>, you can't specify <code>InstanceTypes</code>.</p>"
    },
    "InstanceSpecification":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceIdWithVolumeResolver",
          "documentation":"<p>The instance to specify which volumes should be snapshotted.</p>"
        },
        "ExcludeBootVolume":{
          "shape":"Boolean",
          "documentation":"<p>Excludes the root volume from being snapshotted.</p>"
        },
        "ExcludeDataVolumeIds":{
          "shape":"VolumeIdStringList",
          "documentation":"<p>The IDs of the data (non-root) volumes to exclude from the multi-volume snapshot set. If you specify the ID of the root volume, the request fails. To exclude the root volume, use <b>ExcludeBootVolume</b>.</p> <p>You can specify up to 40 volume IDs per request.</p>",
          "locationName":"ExcludeDataVolumeId"
        }
      },
      "documentation":"<p>The instance details to specify which volumes should be snapshotted.</p>"
    },
    "InstanceState":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"Integer",
          "documentation":"<p>The state of the instance as a 16-bit unsigned integer. </p> <p>The high byte is all of the bits between 2^8 and (2^16)-1, which equals decimal values between 256 and 65,535. These numerical values are used for internal purposes and should be ignored.</p> <p>The low byte is all of the bits between 2^0 and (2^8)-1, which equals decimal values between 0 and 255. </p> <p>The valid values for instance-state-code will all be in the range of the low byte and they are:</p> <ul> <li> <p> <code>0</code> : <code>pending</code> </p> </li> <li> <p> <code>16</code> : <code>running</code> </p> </li> <li> <p> <code>32</code> : <code>shutting-down</code> </p> </li> <li> <p> <code>48</code> : <code>terminated</code> </p> </li> <li> <p> <code>64</code> : <code>stopping</code> </p> </li> <li> <p> <code>80</code> : <code>stopped</code> </p> </li> </ul> <p>You can ignore the high byte value by zeroing out all of the bits above 2^8 or 256 in decimal.</p>",
          "locationName":"code"
        },
        "Name":{
          "shape":"InstanceStateName",
          "documentation":"<p>The current state of the instance.</p>",
          "locationName":"name"
        }
      },
      "documentation":"<p>Describes the current state of an instance.</p>"
    },
    "InstanceStateChange":{
      "type":"structure",
      "members":{
        "CurrentState":{
          "shape":"InstanceState",
          "documentation":"<p>The current state of the instance.</p>",
          "locationName":"currentState"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "PreviousState":{
          "shape":"InstanceState",
          "documentation":"<p>The previous state of the instance.</p>",
          "locationName":"previousState"
        }
      },
      "documentation":"<p>Describes an instance state change.</p>"
    },
    "InstanceStateChangeList":{
      "type":"list",
      "member":{
        "shape":"InstanceStateChange",
        "locationName":"item"
      }
    },
    "InstanceStateName":{
      "type":"string",
      "enum":[
        "pending",
        "running",
        "shutting-down",
        "terminated",
        "stopping",
        "stopped"
      ]
    },
    "InstanceStatus":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone of the instance.</p>",
          "locationName":"availabilityZone"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "Events":{
          "shape":"InstanceStatusEventList",
          "documentation":"<p>Any scheduled events associated with the instance.</p>",
          "locationName":"eventsSet"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceState":{
          "shape":"InstanceState",
          "documentation":"<p>The intended state of the instance. <a>DescribeInstanceStatus</a> requires that an instance be in the <code>running</code> state.</p>",
          "locationName":"instanceState"
        },
        "InstanceStatus":{
          "shape":"InstanceStatusSummary",
          "documentation":"<p>Reports impaired functionality that stems from issues internal to the instance, such as impaired reachability.</p>",
          "locationName":"instanceStatus"
        },
        "SystemStatus":{
          "shape":"InstanceStatusSummary",
          "documentation":"<p>Reports impaired functionality that stems from issues related to the systems that support an instance, such as hardware failures and network connectivity problems.</p>",
          "locationName":"systemStatus"
        }
      },
      "documentation":"<p>Describes the status of an instance.</p>"
    },
    "InstanceStatusDetails":{
      "type":"structure",
      "members":{
        "ImpairedSince":{
          "shape":"DateTime",
          "documentation":"<p>The time when a status check failed. For an instance that was launched and impaired, this is the time when the instance was launched.</p>",
          "locationName":"impairedSince"
        },
        "Name":{
          "shape":"StatusName",
          "documentation":"<p>The type of instance status.</p>",
          "locationName":"name"
        },
        "Status":{
          "shape":"StatusType",
          "documentation":"<p>The status.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Describes the instance status.</p>"
    },
    "InstanceStatusDetailsList":{
      "type":"list",
      "member":{
        "shape":"InstanceStatusDetails",
        "locationName":"item"
      }
    },
    "InstanceStatusEvent":{
      "type":"structure",
      "members":{
        "InstanceEventId":{
          "shape":"InstanceEventId",
          "documentation":"<p>The ID of the event.</p>",
          "locationName":"instanceEventId"
        },
        "Code":{
          "shape":"EventCode",
          "documentation":"<p>The event code.</p>",
          "locationName":"code"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the event.</p> <p>After a scheduled event is completed, it can still be described for up to a week. If the event has been completed, this description starts with the following text: [Completed].</p>",
          "locationName":"description"
        },
        "NotAfter":{
          "shape":"DateTime",
          "documentation":"<p>The latest scheduled end time for the event.</p>",
          "locationName":"notAfter"
        },
        "NotBefore":{
          "shape":"DateTime",
          "documentation":"<p>The earliest scheduled start time for the event.</p>",
          "locationName":"notBefore"
        },
        "NotBeforeDeadline":{
          "shape":"DateTime",
          "documentation":"<p>The deadline for starting the event.</p>",
          "locationName":"notBeforeDeadline"
        }
      },
      "documentation":"<p>Describes a scheduled event for an instance.</p>"
    },
    "InstanceStatusEventList":{
      "type":"list",
      "member":{
        "shape":"InstanceStatusEvent",
        "locationName":"item"
      }
    },
    "InstanceStatusList":{
      "type":"list",
      "member":{
        "shape":"InstanceStatus",
        "locationName":"item"
      }
    },
    "InstanceStatusSummary":{
      "type":"structure",
      "members":{
        "Details":{
          "shape":"InstanceStatusDetailsList",
          "documentation":"<p>The system instance health or application instance health.</p>",
          "locationName":"details"
        },
        "Status":{
          "shape":"SummaryStatus",
          "documentation":"<p>The status.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Describes the status of an instance.</p>"
    },
    "InstanceStorageEncryptionSupport":{
      "type":"string",
      "enum":[
        "unsupported",
        "required"
      ]
    },
    "InstanceStorageFlag":{"type":"boolean"},
    "InstanceStorageInfo":{
      "type":"structure",
      "members":{
        "TotalSizeInGB":{
          "shape":"DiskSize",
          "documentation":"<p>The total size of the disks, in GB.</p>",
          "locationName":"totalSizeInGB"
        },
        "Disks":{
          "shape":"DiskInfoList",
          "documentation":"<p>Describes the disks that are available for the instance type.</p>",
          "locationName":"disks"
        },
        "NvmeSupport":{
          "shape":"EphemeralNvmeSupport",
          "documentation":"<p>Indicates whether non-volatile memory express (NVMe) is supported.</p>",
          "locationName":"nvmeSupport"
        },
        "EncryptionSupport":{
          "shape":"InstanceStorageEncryptionSupport",
          "documentation":"<p>Indicates whether data is encrypted at rest.</p>",
          "locationName":"encryptionSupport"
        }
      },
      "documentation":"<p>Describes the instance store features that are supported by the instance type.</p>"
    },
    "InstanceTagKeySet":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "InstanceTagNotificationAttribute":{
      "type":"structure",
      "members":{
        "InstanceTagKeys":{
          "shape":"InstanceTagKeySet",
          "documentation":"<p>The registered tag keys.</p>",
          "locationName":"instanceTagKeySet"
        },
        "IncludeAllTagsOfInstance":{
          "shape":"Boolean",
          "documentation":"<p>Indicates wheter all tag keys in the current Region are registered to appear in scheduled event notifications. <code>true</code> indicates that all tag keys in the current Region are registered.</p>",
          "locationName":"includeAllTagsOfInstance"
        }
      },
      "documentation":"<p>Describes the registered tag keys for the current Region.</p>"
    },
    "InstanceType":{
      "type":"string",
      "enum":[
        "a1.medium",
        "a1.large",
        "a1.xlarge",
        "a1.2xlarge",
        "a1.4xlarge",
        "a1.metal",
        "c1.medium",
        "c1.xlarge",
        "c3.large",
        "c3.xlarge",
        "c3.2xlarge",
        "c3.4xlarge",
        "c3.8xlarge",
        "c4.large",
        "c4.xlarge",
        "c4.2xlarge",
        "c4.4xlarge",
        "c4.8xlarge",
        "c5.large",
        "c5.xlarge",
        "c5.2xlarge",
        "c5.4xlarge",
        "c5.9xlarge",
        "c5.12xlarge",
        "c5.18xlarge",
        "c5.24xlarge",
        "c5.metal",
        "c5a.large",
        "c5a.xlarge",
        "c5a.2xlarge",
        "c5a.4xlarge",
        "c5a.8xlarge",
        "c5a.12xlarge",
        "c5a.16xlarge",
        "c5a.24xlarge",
        "c5ad.large",
        "c5ad.xlarge",
        "c5ad.2xlarge",
        "c5ad.4xlarge",
        "c5ad.8xlarge",
        "c5ad.12xlarge",
        "c5ad.16xlarge",
        "c5ad.24xlarge",
        "c5d.large",
        "c5d.xlarge",
        "c5d.2xlarge",
        "c5d.4xlarge",
        "c5d.9xlarge",
        "c5d.12xlarge",
        "c5d.18xlarge",
        "c5d.24xlarge",
        "c5d.metal",
        "c5n.large",
        "c5n.xlarge",
        "c5n.2xlarge",
        "c5n.4xlarge",
        "c5n.9xlarge",
        "c5n.18xlarge",
        "c5n.metal",
        "c6g.medium",
        "c6g.large",
        "c6g.xlarge",
        "c6g.2xlarge",
        "c6g.4xlarge",
        "c6g.8xlarge",
        "c6g.12xlarge",
        "c6g.16xlarge",
        "c6g.metal",
        "c6gd.medium",
        "c6gd.large",
        "c6gd.xlarge",
        "c6gd.2xlarge",
        "c6gd.4xlarge",
        "c6gd.8xlarge",
        "c6gd.12xlarge",
        "c6gd.16xlarge",
        "c6gd.metal",
        "c6gn.medium",
        "c6gn.large",
        "c6gn.xlarge",
        "c6gn.2xlarge",
        "c6gn.4xlarge",
        "c6gn.8xlarge",
        "c6gn.12xlarge",
        "c6gn.16xlarge",
        "c6i.large",
        "c6i.xlarge",
        "c6i.2xlarge",
        "c6i.4xlarge",
        "c6i.8xlarge",
        "c6i.12xlarge",
        "c6i.16xlarge",
        "c6i.24xlarge",
        "c6i.32xlarge",
        "c6i.metal",
        "cc1.4xlarge",
        "cc2.8xlarge",
        "cg1.4xlarge",
        "cr1.8xlarge",
        "d2.xlarge",
        "d2.2xlarge",
        "d2.4xlarge",
        "d2.8xlarge",
        "d3.xlarge",
        "d3.2xlarge",
        "d3.4xlarge",
        "d3.8xlarge",
        "d3en.xlarge",
        "d3en.2xlarge",
        "d3en.4xlarge",
        "d3en.6xlarge",
        "d3en.8xlarge",
        "d3en.12xlarge",
        "dl1.24xlarge",
        "f1.2xlarge",
        "f1.4xlarge",
        "f1.16xlarge",
        "g2.2xlarge",
        "g2.8xlarge",
        "g3.4xlarge",
        "g3.8xlarge",
        "g3.16xlarge",
        "g3s.xlarge",
        "g4ad.xlarge",
        "g4ad.2xlarge",
        "g4ad.4xlarge",
        "g4ad.8xlarge",
        "g4ad.16xlarge",
        "g4dn.xlarge",
        "g4dn.2xlarge",
        "g4dn.4xlarge",
        "g4dn.8xlarge",
        "g4dn.12xlarge",
        "g4dn.16xlarge",
        "g4dn.metal",
        "g5.xlarge",
        "g5.2xlarge",
        "g5.4xlarge",
        "g5.8xlarge",
        "g5.12xlarge",
        "g5.16xlarge",
        "g5.24xlarge",
        "g5.48xlarge",
        "g5g.xlarge",
        "g5g.2xlarge",
        "g5g.4xlarge",
        "g5g.8xlarge",
        "g5g.16xlarge",
        "g5g.metal",
        "hi1.4xlarge",
        "hpc6a.48xlarge",
        "hs1.8xlarge",
        "h1.2xlarge",
        "h1.4xlarge",
        "h1.8xlarge",
        "h1.16xlarge",
        "i2.xlarge",
        "i2.2xlarge",
        "i2.4xlarge",
        "i2.8xlarge",
        "i3.large",
        "i3.xlarge",
        "i3.2xlarge",
        "i3.4xlarge",
        "i3.8xlarge",
        "i3.16xlarge",
        "i3.metal",
        "i3en.large",
        "i3en.xlarge",
        "i3en.2xlarge",
        "i3en.3xlarge",
        "i3en.6xlarge",
        "i3en.12xlarge",
        "i3en.24xlarge",
        "i3en.metal",
        "im4gn.large",
        "im4gn.xlarge",
        "im4gn.2xlarge",
        "im4gn.4xlarge",
        "im4gn.8xlarge",
        "im4gn.16xlarge",
        "inf1.xlarge",
        "inf1.2xlarge",
        "inf1.6xlarge",
        "inf1.24xlarge",
        "is4gen.medium",
        "is4gen.large",
        "is4gen.xlarge",
        "is4gen.2xlarge",
        "is4gen.4xlarge",
        "is4gen.8xlarge",
        "m1.small",
        "m1.medium",
        "m1.large",
        "m1.xlarge",
        "m2.xlarge",
        "m2.2xlarge",
        "m2.4xlarge",
        "m3.medium",
        "m3.large",
        "m3.xlarge",
        "m3.2xlarge",
        "m4.large",
        "m4.xlarge",
        "m4.2xlarge",
        "m4.4xlarge",
        "m4.10xlarge",
        "m4.16xlarge",
        "m5.large",
        "m5.xlarge",
        "m5.2xlarge",
        "m5.4xlarge",
        "m5.8xlarge",
        "m5.12xlarge",
        "m5.16xlarge",
        "m5.24xlarge",
        "m5.metal",
        "m5a.large",
        "m5a.xlarge",
        "m5a.2xlarge",
        "m5a.4xlarge",
        "m5a.8xlarge",
        "m5a.12xlarge",
        "m5a.16xlarge",
        "m5a.24xlarge",
        "m5ad.large",
        "m5ad.xlarge",
        "m5ad.2xlarge",
        "m5ad.4xlarge",
        "m5ad.8xlarge",
        "m5ad.12xlarge",
        "m5ad.16xlarge",
        "m5ad.24xlarge",
        "m5d.large",
        "m5d.xlarge",
        "m5d.2xlarge",
        "m5d.4xlarge",
        "m5d.8xlarge",
        "m5d.12xlarge",
        "m5d.16xlarge",
        "m5d.24xlarge",
        "m5d.metal",
        "m5dn.large",
        "m5dn.xlarge",
        "m5dn.2xlarge",
        "m5dn.4xlarge",
        "m5dn.8xlarge",
        "m5dn.12xlarge",
        "m5dn.16xlarge",
        "m5dn.24xlarge",
        "m5dn.metal",
        "m5n.large",
        "m5n.xlarge",
        "m5n.2xlarge",
        "m5n.4xlarge",
        "m5n.8xlarge",
        "m5n.12xlarge",
        "m5n.16xlarge",
        "m5n.24xlarge",
        "m5n.metal",
        "m5zn.large",
        "m5zn.xlarge",
        "m5zn.2xlarge",
        "m5zn.3xlarge",
        "m5zn.6xlarge",
        "m5zn.12xlarge",
        "m5zn.metal",
        "m6a.large",
        "m6a.xlarge",
        "m6a.2xlarge",
        "m6a.4xlarge",
        "m6a.8xlarge",
        "m6a.12xlarge",
        "m6a.16xlarge",
        "m6a.24xlarge",
        "m6a.32xlarge",
        "m6a.48xlarge",
        "m6g.metal",
        "m6g.medium",
        "m6g.large",
        "m6g.xlarge",
        "m6g.2xlarge",
        "m6g.4xlarge",
        "m6g.8xlarge",
        "m6g.12xlarge",
        "m6g.16xlarge",
        "m6gd.metal",
        "m6gd.medium",
        "m6gd.large",
        "m6gd.xlarge",
        "m6gd.2xlarge",
        "m6gd.4xlarge",
        "m6gd.8xlarge",
        "m6gd.12xlarge",
        "m6gd.16xlarge",
        "m6i.large",
        "m6i.xlarge",
        "m6i.2xlarge",
        "m6i.4xlarge",
        "m6i.8xlarge",
        "m6i.12xlarge",
        "m6i.16xlarge",
        "m6i.24xlarge",
        "m6i.32xlarge",
        "m6i.metal",
        "mac1.metal",
        "p2.xlarge",
        "p2.8xlarge",
        "p2.16xlarge",
        "p3.2xlarge",
        "p3.8xlarge",
        "p3.16xlarge",
        "p3dn.24xlarge",
        "p4d.24xlarge",
        "r3.large",
        "r3.xlarge",
        "r3.2xlarge",
        "r3.4xlarge",
        "r3.8xlarge",
        "r4.large",
        "r4.xlarge",
        "r4.2xlarge",
        "r4.4xlarge",
        "r4.8xlarge",
        "r4.16xlarge",
        "r5.large",
        "r5.xlarge",
        "r5.2xlarge",
        "r5.4xlarge",
        "r5.8xlarge",
        "r5.12xlarge",
        "r5.16xlarge",
        "r5.24xlarge",
        "r5.metal",
        "r5a.large",
        "r5a.xlarge",
        "r5a.2xlarge",
        "r5a.4xlarge",
        "r5a.8xlarge",
        "r5a.12xlarge",
        "r5a.16xlarge",
        "r5a.24xlarge",
        "r5ad.large",
        "r5ad.xlarge",
        "r5ad.2xlarge",
        "r5ad.4xlarge",
        "r5ad.8xlarge",
        "r5ad.12xlarge",
        "r5ad.16xlarge",
        "r5ad.24xlarge",
        "r5b.large",
        "r5b.xlarge",
        "r5b.2xlarge",
        "r5b.4xlarge",
        "r5b.8xlarge",
        "r5b.12xlarge",
        "r5b.16xlarge",
        "r5b.24xlarge",
        "r5b.metal",
        "r5d.large",
        "r5d.xlarge",
        "r5d.2xlarge",
        "r5d.4xlarge",
        "r5d.8xlarge",
        "r5d.12xlarge",
        "r5d.16xlarge",
        "r5d.24xlarge",
        "r5d.metal",
        "r5dn.large",
        "r5dn.xlarge",
        "r5dn.2xlarge",
        "r5dn.4xlarge",
        "r5dn.8xlarge",
        "r5dn.12xlarge",
        "r5dn.16xlarge",
        "r5dn.24xlarge",
        "r5dn.metal",
        "r5n.large",
        "r5n.xlarge",
        "r5n.2xlarge",
        "r5n.4xlarge",
        "r5n.8xlarge",
        "r5n.12xlarge",
        "r5n.16xlarge",
        "r5n.24xlarge",
        "r5n.metal",
        "r6g.medium",
        "r6g.large",
        "r6g.xlarge",
        "r6g.2xlarge",
        "r6g.4xlarge",
        "r6g.8xlarge",
        "r6g.12xlarge",
        "r6g.16xlarge",
        "r6g.metal",
        "r6gd.medium",
        "r6gd.large",
        "r6gd.xlarge",
        "r6gd.2xlarge",
        "r6gd.4xlarge",
        "r6gd.8xlarge",
        "r6gd.12xlarge",
        "r6gd.16xlarge",
        "r6gd.metal",
        "r6i.large",
        "r6i.xlarge",
        "r6i.2xlarge",
        "r6i.4xlarge",
        "r6i.8xlarge",
        "r6i.12xlarge",
        "r6i.16xlarge",
        "r6i.24xlarge",
        "r6i.32xlarge",
        "r6i.metal",
        "t1.micro",
        "t2.nano",
        "t2.micro",
        "t2.small",
        "t2.medium",
        "t2.large",
        "t2.xlarge",
        "t2.2xlarge",
        "t3.nano",
        "t3.micro",
        "t3.small",
        "t3.medium",
        "t3.large",
        "t3.xlarge",
        "t3.2xlarge",
        "t3a.nano",
        "t3a.micro",
        "t3a.small",
        "t3a.medium",
        "t3a.large",
        "t3a.xlarge",
        "t3a.2xlarge",
        "t4g.nano",
        "t4g.micro",
        "t4g.small",
        "t4g.medium",
        "t4g.large",
        "t4g.xlarge",
        "t4g.2xlarge",
        "u-6tb1.56xlarge",
        "u-6tb1.112xlarge",
        "u-9tb1.112xlarge",
        "u-12tb1.112xlarge",
        "u-6tb1.metal",
        "u-9tb1.metal",
        "u-12tb1.metal",
        "u-18tb1.metal",
        "u-24tb1.metal",
        "vt1.3xlarge",
        "vt1.6xlarge",
        "vt1.24xlarge",
        "x1.16xlarge",
        "x1.32xlarge",
        "x1e.xlarge",
        "x1e.2xlarge",
        "x1e.4xlarge",
        "x1e.8xlarge",
        "x1e.16xlarge",
        "x1e.32xlarge",
        "x2iezn.2xlarge",
        "x2iezn.4xlarge",
        "x2iezn.6xlarge",
        "x2iezn.8xlarge",
        "x2iezn.12xlarge",
        "x2iezn.metal",
        "x2gd.medium",
        "x2gd.large",
        "x2gd.xlarge",
        "x2gd.2xlarge",
        "x2gd.4xlarge",
        "x2gd.8xlarge",
        "x2gd.12xlarge",
        "x2gd.16xlarge",
        "x2gd.metal",
        "z1d.large",
        "z1d.xlarge",
        "z1d.2xlarge",
        "z1d.3xlarge",
        "z1d.6xlarge",
        "z1d.12xlarge",
        "z1d.metal",
        "x2idn.16xlarge",
        "x2idn.24xlarge",
        "x2idn.32xlarge",
        "x2iedn.xlarge",
        "x2iedn.2xlarge",
        "x2iedn.4xlarge",
        "x2iedn.8xlarge",
        "x2iedn.16xlarge",
        "x2iedn.24xlarge",
        "x2iedn.32xlarge",
        "c6a.large",
        "c6a.xlarge",
        "c6a.2xlarge",
        "c6a.4xlarge",
        "c6a.8xlarge",
        "c6a.12xlarge",
        "c6a.16xlarge",
        "c6a.24xlarge",
        "c6a.32xlarge",
        "c6a.48xlarge",
        "c6a.metal",
        "m6a.metal",
        "i4i.large",
        "i4i.xlarge",
        "i4i.2xlarge",
        "i4i.4xlarge",
        "i4i.8xlarge",
        "i4i.16xlarge",
        "i4i.32xlarge",
        "i4i.metal",
        "x2idn.metal",
        "x2iedn.metal",
        "c7g.medium",
        "c7g.large",
        "c7g.xlarge",
        "c7g.2xlarge",
        "c7g.4xlarge",
        "c7g.8xlarge",
        "c7g.12xlarge",
        "c7g.16xlarge",
        "mac2.metal",
        "c6id.large",
        "c6id.xlarge",
        "c6id.2xlarge",
        "c6id.4xlarge",
        "c6id.8xlarge",
        "c6id.12xlarge",
        "c6id.16xlarge",
        "c6id.24xlarge",
        "c6id.32xlarge",
        "c6id.metal",
        "m6id.large",
        "m6id.xlarge",
        "m6id.2xlarge",
        "m6id.4xlarge",
        "m6id.8xlarge",
        "m6id.12xlarge",
        "m6id.16xlarge",
        "m6id.24xlarge",
        "m6id.32xlarge",
        "m6id.metal",
        "r6id.large",
        "r6id.xlarge",
        "r6id.2xlarge",
        "r6id.4xlarge",
        "r6id.8xlarge",
        "r6id.12xlarge",
        "r6id.16xlarge",
        "r6id.24xlarge",
        "r6id.32xlarge",
        "r6id.metal",
        "r6a.large",
        "r6a.xlarge",
        "r6a.2xlarge",
        "r6a.4xlarge",
        "r6a.8xlarge",
        "r6a.12xlarge",
        "r6a.16xlarge",
        "r6a.24xlarge",
        "r6a.32xlarge",
        "r6a.48xlarge",
        "r6a.metal",
        "p4de.24xlarge",
        "u-3tb1.56xlarge",
        "u-18tb1.112xlarge",
        "u-24tb1.112xlarge",
        "trn1.2xlarge",
        "trn1.32xlarge",
        "hpc6id.32xlarge",
        "c6in.large",
        "c6in.xlarge",
        "c6in.2xlarge",
        "c6in.4xlarge",
        "c6in.8xlarge",
        "c6in.12xlarge",
        "c6in.16xlarge",
        "c6in.24xlarge",
        "c6in.32xlarge",
        "m6in.large",
        "m6in.xlarge",
        "m6in.2xlarge",
        "m6in.4xlarge",
        "m6in.8xlarge",
        "m6in.12xlarge",
        "m6in.16xlarge",
        "m6in.24xlarge",
        "m6in.32xlarge",
        "m6idn.large",
        "m6idn.xlarge",
        "m6idn.2xlarge",
        "m6idn.4xlarge",
        "m6idn.8xlarge",
        "m6idn.12xlarge",
        "m6idn.16xlarge",
        "m6idn.24xlarge",
        "m6idn.32xlarge",
        "r6in.large",
        "r6in.xlarge",
        "r6in.2xlarge",
        "r6in.4xlarge",
        "r6in.8xlarge",
        "r6in.12xlarge",
        "r6in.16xlarge",
        "r6in.24xlarge",
        "r6in.32xlarge",
        "r6idn.large",
        "r6idn.xlarge",
        "r6idn.2xlarge",
        "r6idn.4xlarge",
        "r6idn.8xlarge",
        "r6idn.12xlarge",
        "r6idn.16xlarge",
        "r6idn.24xlarge",
        "r6idn.32xlarge"
      ]
    },
    "InstanceTypeHypervisor":{
      "type":"string",
      "enum":[
        "nitro",
        "xen"
      ]
    },
    "InstanceTypeInfo":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"instanceType"
        },
        "CurrentGeneration":{
          "shape":"CurrentGenerationFlag",
          "documentation":"<p>Indicates whether the instance type is current generation.</p>",
          "locationName":"currentGeneration"
        },
        "FreeTierEligible":{
          "shape":"FreeTierEligibleFlag",
          "documentation":"<p>Indicates whether the instance type is eligible for the free tier.</p>",
          "locationName":"freeTierEligible"
        },
        "SupportedUsageClasses":{
          "shape":"UsageClassTypeList",
          "documentation":"<p>Indicates whether the instance type is offered for spot or On-Demand.</p>",
          "locationName":"supportedUsageClasses"
        },
        "SupportedRootDeviceTypes":{
          "shape":"RootDeviceTypeList",
          "documentation":"<p>The supported root device types.</p>",
          "locationName":"supportedRootDeviceTypes"
        },
        "SupportedVirtualizationTypes":{
          "shape":"VirtualizationTypeList",
          "documentation":"<p>The supported virtualization types.</p>",
          "locationName":"supportedVirtualizationTypes"
        },
        "BareMetal":{
          "shape":"BareMetalFlag",
          "documentation":"<p>Indicates whether the instance is a bare metal instance type.</p>",
          "locationName":"bareMetal"
        },
        "Hypervisor":{
          "shape":"InstanceTypeHypervisor",
          "documentation":"<p>The hypervisor for the instance type.</p>",
          "locationName":"hypervisor"
        },
        "ProcessorInfo":{
          "shape":"ProcessorInfo",
          "documentation":"<p>Describes the processor.</p>",
          "locationName":"processorInfo"
        },
        "VCpuInfo":{
          "shape":"VCpuInfo",
          "documentation":"<p>Describes the vCPU configurations for the instance type.</p>",
          "locationName":"vCpuInfo"
        },
        "MemoryInfo":{
          "shape":"MemoryInfo",
          "documentation":"<p>Describes the memory for the instance type.</p>",
          "locationName":"memoryInfo"
        },
        "InstanceStorageSupported":{
          "shape":"InstanceStorageFlag",
          "documentation":"<p>Indicates whether instance storage is supported.</p>",
          "locationName":"instanceStorageSupported"
        },
        "InstanceStorageInfo":{
          "shape":"InstanceStorageInfo",
          "documentation":"<p>Describes the instance storage for the instance type.</p>",
          "locationName":"instanceStorageInfo"
        },
        "EbsInfo":{
          "shape":"EbsInfo",
          "documentation":"<p>Describes the Amazon EBS settings for the instance type.</p>",
          "locationName":"ebsInfo"
        },
        "NetworkInfo":{
          "shape":"NetworkInfo",
          "documentation":"<p>Describes the network settings for the instance type.</p>",
          "locationName":"networkInfo"
        },
        "GpuInfo":{
          "shape":"GpuInfo",
          "documentation":"<p>Describes the GPU accelerator settings for the instance type.</p>",
          "locationName":"gpuInfo"
        },
        "FpgaInfo":{
          "shape":"FpgaInfo",
          "documentation":"<p>Describes the FPGA accelerator settings for the instance type.</p>",
          "locationName":"fpgaInfo"
        },
        "PlacementGroupInfo":{
          "shape":"PlacementGroupInfo",
          "documentation":"<p>Describes the placement group settings for the instance type.</p>",
          "locationName":"placementGroupInfo"
        },
        "InferenceAcceleratorInfo":{
          "shape":"InferenceAcceleratorInfo",
          "documentation":"<p>Describes the Inference accelerator settings for the instance type.</p>",
          "locationName":"inferenceAcceleratorInfo"
        },
        "HibernationSupported":{
          "shape":"HibernationFlag",
          "documentation":"<p>Indicates whether On-Demand hibernation is supported.</p>",
          "locationName":"hibernationSupported"
        },
        "BurstablePerformanceSupported":{
          "shape":"BurstablePerformanceFlag",
          "documentation":"<p>Indicates whether the instance type is a burstable performance instance type.</p>",
          "locationName":"burstablePerformanceSupported"
        },
        "DedicatedHostsSupported":{
          "shape":"DedicatedHostFlag",
          "documentation":"<p>Indicates whether Dedicated Hosts are supported on the instance type.</p>",
          "locationName":"dedicatedHostsSupported"
        },
        "AutoRecoverySupported":{
          "shape":"AutoRecoveryFlag",
          "documentation":"<p>Indicates whether auto recovery is supported.</p>",
          "locationName":"autoRecoverySupported"
        },
        "SupportedBootModes":{
          "shape":"BootModeTypeList",
          "documentation":"<p>The supported boot modes. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-boot.html\">Boot modes</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"supportedBootModes"
        }
      },
      "documentation":"<p>Describes the instance type.</p>"
    },
    "InstanceTypeInfoFromInstanceRequirements":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The matching instance type.</p>",
          "locationName":"instanceType"
        }
      },
      "documentation":"<p>The list of instance types with the specified instance attributes.</p>"
    },
    "InstanceTypeInfoFromInstanceRequirementsSet":{
      "type":"list",
      "member":{
        "shape":"InstanceTypeInfoFromInstanceRequirements",
        "locationName":"item"
      }
    },
    "InstanceTypeInfoList":{
      "type":"list",
      "member":{
        "shape":"InstanceTypeInfo",
        "locationName":"item"
      }
    },
    "InstanceTypeList":{
      "type":"list",
      "member":{"shape":"InstanceType"}
    },
    "InstanceTypeOffering":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"instanceType"
        },
        "LocationType":{
          "shape":"LocationType",
          "documentation":"<p>The location type.</p>",
          "locationName":"locationType"
        },
        "Location":{
          "shape":"Location",
          "documentation":"<p>The identifier for the location. This depends on the location type. For example, if the location type is <code>region</code>, the location is the Region code (for example, <code>us-east-2</code>.)</p>",
          "locationName":"location"
        }
      },
      "documentation":"<p>The instance types offered.</p>"
    },
    "InstanceTypeOfferingsList":{
      "type":"list",
      "member":{
        "shape":"InstanceTypeOffering",
        "locationName":"item"
      }
    },
    "InstanceTypes":{
      "type":"list",
      "member":{"shape":"String"},
      "max":1000,
      "min":0
    },
    "InstanceTypesList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "InstanceUsage":{
      "type":"structure",
      "members":{
        "AccountId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that is making use of the Capacity Reservation.</p>",
          "locationName":"accountId"
        },
        "UsedInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances the Amazon Web Services account currently has in the Capacity Reservation.</p>",
          "locationName":"usedInstanceCount"
        }
      },
      "documentation":"<p>Information about the Capacity Reservation usage.</p>"
    },
    "InstanceUsageSet":{
      "type":"list",
      "member":{
        "shape":"InstanceUsage",
        "locationName":"item"
      }
    },
    "Integer":{"type":"integer"},
    "IntegerWithConstraints":{
      "type":"integer",
      "min":0
    },
    "IntegrateServices":{
      "type":"structure",
      "members":{
        "AthenaIntegrations":{
          "shape":"AthenaIntegrationsSet",
          "documentation":"<p>Information about the integration with Amazon Athena.</p>",
          "locationName":"AthenaIntegration"
        }
      },
      "documentation":"<p>Describes service integrations with VPC Flow logs.</p>"
    },
    "InterfacePermissionType":{
      "type":"string",
      "enum":[
        "INSTANCE-ATTACH",
        "EIP-ASSOCIATE"
      ]
    },
    "InterfaceProtocolType":{
      "type":"string",
      "enum":[
        "VLAN",
        "GRE"
      ]
    },
    "InternetGateway":{
      "type":"structure",
      "members":{
        "Attachments":{
          "shape":"InternetGatewayAttachmentList",
          "documentation":"<p>Any VPCs attached to the internet gateway.</p>",
          "locationName":"attachmentSet"
        },
        "InternetGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the internet gateway.</p>",
          "locationName":"internetGatewayId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the internet gateway.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the internet gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an internet gateway.</p>"
    },
    "InternetGatewayAttachment":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"AttachmentStatus",
          "documentation":"<p>The current state of the attachment. For an internet gateway, the state is <code>available</code> when attached to a VPC; otherwise, this value is not returned.</p>",
          "locationName":"state"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<p>Describes the attachment of a VPC to an internet gateway or an egress-only internet gateway.</p>"
    },
    "InternetGatewayAttachmentList":{
      "type":"list",
      "member":{
        "shape":"InternetGatewayAttachment",
        "locationName":"item"
      }
    },
    "InternetGatewayId":{"type":"string"},
    "InternetGatewayIdList":{
      "type":"list",
      "member":{
        "shape":"InternetGatewayId",
        "locationName":"item"
      }
    },
    "InternetGatewayList":{
      "type":"list",
      "member":{
        "shape":"InternetGateway",
        "locationName":"item"
      }
    },
    "IpAddress":{
      "type":"string",
      "max":15,
      "min":0,
      "pattern":"^([0-9]{1,3}.){3}[0-9]{1,3}$"
    },
    "IpAddressList":{
      "type":"list",
      "member":{
        "shape":"IpAddress",
        "locationName":"item"
      }
    },
    "IpAddressType":{
      "type":"string",
      "enum":[
        "ipv4",
        "dualstack",
        "ipv6"
      ]
    },
    "IpList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "IpPermission":{
      "type":"structure",
      "members":{
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the start of the port range. If the protocol is ICMP or ICMPv6, this is the type number. A value of -1 indicates all ICMP/ICMPv6 types. If you specify all ICMP/ICMPv6 types, you must specify all ICMP/ICMPv6 codes.</p>",
          "locationName":"fromPort"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>The IP protocol name (<code>tcp</code>, <code>udp</code>, <code>icmp</code>, <code>icmpv6</code>) or number (see <a href=\"http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers</a>).</p> <p>[VPC only] Use <code>-1</code> to specify all protocols. When authorizing security group rules, specifying <code>-1</code> or a protocol number other than <code>tcp</code>, <code>udp</code>, <code>icmp</code>, or <code>icmpv6</code> allows traffic on all ports, regardless of any port range you specify. For <code>tcp</code>, <code>udp</code>, and <code>icmp</code>, you must specify a port range. For <code>icmpv6</code>, the port range is optional; if you omit the port range, traffic for all types and codes is allowed.</p>",
          "locationName":"ipProtocol"
        },
        "IpRanges":{
          "shape":"IpRangeList",
          "documentation":"<p>The IPv4 ranges.</p>",
          "locationName":"ipRanges"
        },
        "Ipv6Ranges":{
          "shape":"Ipv6RangeList",
          "documentation":"<p>[VPC only] The IPv6 ranges.</p>",
          "locationName":"ipv6Ranges"
        },
        "PrefixListIds":{
          "shape":"PrefixListIdList",
          "documentation":"<p>[VPC only] The prefix list IDs.</p>",
          "locationName":"prefixListIds"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the end of the port range. If the protocol is ICMP or ICMPv6, this is the code. A value of -1 indicates all ICMP/ICMPv6 codes. If you specify all ICMP/ICMPv6 types, you must specify all ICMP/ICMPv6 codes.</p>",
          "locationName":"toPort"
        },
        "UserIdGroupPairs":{
          "shape":"UserIdGroupPairList",
          "documentation":"<p>The security group and Amazon Web Services account ID pairs.</p>",
          "locationName":"groups"
        }
      },
      "documentation":"<p>Describes a set of permissions for a security group rule.</p>"
    },
    "IpPermissionList":{
      "type":"list",
      "member":{
        "shape":"IpPermission",
        "locationName":"item"
      }
    },
    "IpPrefixList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "IpRange":{
      "type":"structure",
      "members":{
        "CidrIp":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR range. You can either specify a CIDR range or a source security group, not both. To specify a single IPv4 address, use the /32 prefix length.</p>",
          "locationName":"cidrIp"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the security group rule that references this IPv4 address range.</p> <p>Constraints: Up to 255 characters in length. Allowed characters are a-z, A-Z, 0-9, spaces, and ._-:/()#,@[]+=&;{}!$*</p>",
          "locationName":"description"
        }
      },
      "documentation":"<p>Describes an IPv4 range.</p>"
    },
    "IpRangeList":{
      "type":"list",
      "member":{
        "shape":"IpRange",
        "locationName":"item"
      }
    },
    "IpRanges":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "Ipam":{
      "type":"structure",
      "members":{
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the IPAM.</p>",
          "locationName":"ownerId"
        },
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>The ID of the IPAM.</p>",
          "locationName":"ipamId"
        },
        "IpamArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the IPAM.</p>",
          "locationName":"ipamArn"
        },
        "IpamRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region of the IPAM.</p>",
          "locationName":"ipamRegion"
        },
        "PublicDefaultScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the IPAM's default public scope.</p>",
          "locationName":"publicDefaultScopeId"
        },
        "PrivateDefaultScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the IPAM's default private scope.</p>",
          "locationName":"privateDefaultScopeId"
        },
        "ScopeCount":{
          "shape":"Integer",
          "documentation":"<p>The number of scopes in the IPAM. The scope quota is 5. For more information on quotas, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/quotas-ipam.html\">Quotas in IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>",
          "locationName":"scopeCount"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the IPAM.</p>",
          "locationName":"description"
        },
        "OperatingRegions":{
          "shape":"IpamOperatingRegionSet",
          "documentation":"<p>The operating Regions for an IPAM. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p> <p>For more information about operating Regions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"operatingRegionSet"
        },
        "State":{
          "shape":"IpamState",
          "documentation":"<p>The state of the IPAM.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"tagSet"
        },
        "DefaultResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>The IPAM's default resource discovery ID.</p>",
          "locationName":"defaultResourceDiscoveryId"
        },
        "DefaultResourceDiscoveryAssociationId":{
          "shape":"IpamResourceDiscoveryAssociationId",
          "documentation":"<p>The IPAM's default resource discovery association ID.</p>",
          "locationName":"defaultResourceDiscoveryAssociationId"
        },
        "ResourceDiscoveryAssociationCount":{
          "shape":"Integer",
          "documentation":"<p>The IPAM's resource discovery association count.</p>",
          "locationName":"resourceDiscoveryAssociationCount"
        }
      },
      "documentation":"<p>IPAM is a VPC feature that you can use to automate your IP address management workflows including assigning, tracking, troubleshooting, and auditing IP addresses across Amazon Web Services Regions and accounts throughout your Amazon Web Services Organization. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/what-is-it-ipam.html\">What is IPAM?</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "IpamAddressHistoryMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "IpamAddressHistoryRecord":{
      "type":"structure",
      "members":{
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource owner.</p>",
          "locationName":"resourceOwnerId"
        },
        "ResourceRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region of the resource.</p>",
          "locationName":"resourceRegion"
        },
        "ResourceType":{
          "shape":"IpamAddressHistoryResourceType",
          "documentation":"<p>The type of the resource.</p>",
          "locationName":"resourceType"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceCidr":{
          "shape":"String",
          "documentation":"<p>The CIDR of the resource.</p>",
          "locationName":"resourceCidr"
        },
        "ResourceName":{
          "shape":"String",
          "documentation":"<p>The name of the resource.</p>",
          "locationName":"resourceName"
        },
        "ResourceComplianceStatus":{
          "shape":"IpamComplianceStatus",
          "documentation":"<p>The compliance status of a resource. For more information on compliance statuses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/monitor-cidr-compliance-ipam.html\">Monitor CIDR usage by resource</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"resourceComplianceStatus"
        },
        "ResourceOverlapStatus":{
          "shape":"IpamOverlapStatus",
          "documentation":"<p>The overlap status of an IPAM resource. The overlap status tells you if the CIDR for a resource overlaps with another CIDR in the scope. For more information on overlap statuses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/monitor-cidr-compliance-ipam.html\">Monitor CIDR usage by resource</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"resourceOverlapStatus"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The VPC ID of the resource.</p>",
          "locationName":"vpcId"
        },
        "SampledStartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Sampled start time of the resource-to-CIDR association within the IPAM scope. Changes are picked up in periodic snapshots, so the start time may have occurred before this specific time.</p>",
          "locationName":"sampledStartTime"
        },
        "SampledEndTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Sampled end time of the resource-to-CIDR association within the IPAM scope. Changes are picked up in periodic snapshots, so the end time may have occurred before this specific time.</p>",
          "locationName":"sampledEndTime"
        }
      },
      "documentation":"<p>The historical record of a CIDR within an IPAM scope. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/view-history-cidr-ipam.html\">View the history of IP addresses</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>"
    },
    "IpamAddressHistoryRecordSet":{
      "type":"list",
      "member":{
        "shape":"IpamAddressHistoryRecord",
        "locationName":"item"
      }
    },
    "IpamAddressHistoryResourceType":{
      "type":"string",
      "enum":[
        "eip",
        "vpc",
        "subnet",
        "network-interface",
        "instance"
      ]
    },
    "IpamAssociatedResourceDiscoveryStatus":{
      "type":"string",
      "enum":[
        "active",
        "not-found"
      ]
    },
    "IpamCidrAuthorizationContext":{
      "type":"structure",
      "members":{
        "Message":{
          "shape":"String",
          "documentation":"<p>The plain-text authorization message for the prefix and account.</p>"
        },
        "Signature":{
          "shape":"String",
          "documentation":"<p>The signed authorization message for the prefix and account.</p>"
        }
      },
      "documentation":"<p>A signed document that proves that you are authorized to bring the specified IP address range to Amazon using BYOIP.</p>"
    },
    "IpamComplianceStatus":{
      "type":"string",
      "enum":[
        "compliant",
        "noncompliant",
        "unmanaged",
        "ignored"
      ]
    },
    "IpamDiscoveredAccount":{
      "type":"structure",
      "members":{
        "AccountId":{
          "shape":"String",
          "documentation":"<p>The account ID.</p>",
          "locationName":"accountId"
        },
        "DiscoveryRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region that the account information is returned from. An account can be discovered in multiple regions and will have a separate discovered account for each Region.</p>",
          "locationName":"discoveryRegion"
        },
        "FailureReason":{
          "shape":"IpamDiscoveryFailureReason",
          "documentation":"<p>The resource discovery failure reason.</p>",
          "locationName":"failureReason"
        },
        "LastAttemptedDiscoveryTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The last attempted resource discovery time.</p>",
          "locationName":"lastAttemptedDiscoveryTime"
        },
        "LastSuccessfulDiscoveryTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The last successful resource discovery time.</p>",
          "locationName":"lastSuccessfulDiscoveryTime"
        }
      },
      "documentation":"<p>An IPAM discovered account. A discovered account is an Amazon Web Services account that is monitored under a resource discovery. If you have integrated IPAM with Amazon Web Services Organizations, all accounts in the organization are discovered accounts.</p>"
    },
    "IpamDiscoveredAccountSet":{
      "type":"list",
      "member":{
        "shape":"IpamDiscoveredAccount",
        "locationName":"item"
      }
    },
    "IpamDiscoveredResourceCidr":{
      "type":"structure",
      "members":{
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>The resource discovery ID.</p>",
          "locationName":"ipamResourceDiscoveryId"
        },
        "ResourceRegion":{
          "shape":"String",
          "documentation":"<p>The resource Region.</p>",
          "locationName":"resourceRegion"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The resource ID.</p>",
          "locationName":"resourceId"
        },
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p>The resource owner ID.</p>",
          "locationName":"resourceOwnerId"
        },
        "ResourceCidr":{
          "shape":"String",
          "documentation":"<p>The resource CIDR.</p>",
          "locationName":"resourceCidr"
        },
        "ResourceType":{
          "shape":"IpamResourceType",
          "documentation":"<p>The resource type.</p>",
          "locationName":"resourceType"
        },
        "ResourceTags":{
          "shape":"IpamResourceTagList",
          "documentation":"<p>The resource tags.</p>",
          "locationName":"resourceTagSet"
        },
        "IpUsage":{
          "shape":"BoxedDouble",
          "documentation":"<p>The percentage of IP address space in use. To convert the decimal to a percentage, multiply the decimal by 100. Note the following:</p> <ul> <li> <p>For resources that are VPCs, this is the percentage of IP address space in the VPC that's taken up by subnet CIDRs. </p> </li> <li> <p>For resources that are subnets, if the subnet has an IPv4 CIDR provisioned to it, this is the percentage of IPv4 address space in the subnet that's in use. If the subnet has an IPv6 CIDR provisioned to it, the percentage of IPv6 address space in use is not represented. The percentage of IPv6 address space in use cannot currently be calculated. </p> </li> <li> <p>For resources that are public IPv4 pools, this is the percentage of IP address space in the pool that's been allocated to Elastic IP addresses (EIPs). </p> </li> </ul>",
          "locationName":"ipUsage"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The VPC ID.</p>",
          "locationName":"vpcId"
        },
        "SampleTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The last successful resource discovery time.</p>",
          "locationName":"sampleTime"
        }
      },
      "documentation":"<p>An IPAM discovered resource CIDR. A discovered resource is a resource CIDR monitored under a resource discovery. The following resources can be discovered: VPCs, Public IPv4 pools, VPC subnets, and Elastic IP addresses. The discovered resource CIDR is the IP address range in CIDR notation that is associated with the resource.</p>"
    },
    "IpamDiscoveredResourceCidrSet":{
      "type":"list",
      "member":{
        "shape":"IpamDiscoveredResourceCidr",
        "locationName":"item"
      }
    },
    "IpamDiscoveryFailureCode":{
      "type":"string",
      "enum":[
        "assume-role-failure",
        "throttling-failure",
        "unauthorized-failure"
      ]
    },
    "IpamDiscoveryFailureReason":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"IpamDiscoveryFailureCode",
          "documentation":"<p>The discovery failure code.</p> <ul> <li> <p> <code>assume-role-failure</code> - IPAM could not assume the Amazon Web Services IAM service-linked role. This could be because of any of the following:</p> <ul> <li> <p>SLR has not been created yet and IPAM is still creating it.</p> </li> <li> <p>You have opted-out of the IPAM home Region.</p> </li> <li> <p>Account you are using as your IPAM account has been suspended.</p> </li> </ul> </li> <li> <p> <code>throttling-failure</code> - IPAM account is already using the allotted transactions per second and IPAM is receiving a throttling error when assuming the Amazon Web Services IAM SLR.</p> </li> <li> <p> <code>unauthorized-failure</code> - Amazon Web Services account making the request is not authorized. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html\">AuthFailure</a> in the <i>Amazon Elastic Compute Cloud API Reference</i>.</p> </li> </ul>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The discovery failure message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>The discovery failure reason.</p>"
    },
    "IpamId":{"type":"string"},
    "IpamManagementState":{
      "type":"string",
      "enum":[
        "managed",
        "unmanaged",
        "ignored"
      ]
    },
    "IpamMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "IpamNetmaskLength":{
      "type":"integer",
      "max":128,
      "min":0
    },
    "IpamOperatingRegion":{
      "type":"structure",
      "members":{
        "RegionName":{
          "shape":"String",
          "documentation":"<p>The name of the operating Region.</p>",
          "locationName":"regionName"
        }
      },
      "documentation":"<p>The operating Regions for an IPAM. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p> <p>For more information about operating Regions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "IpamOperatingRegionSet":{
      "type":"list",
      "member":{
        "shape":"IpamOperatingRegion",
        "locationName":"item"
      }
    },
    "IpamOverlapStatus":{
      "type":"string",
      "enum":[
        "overlapping",
        "nonoverlapping",
        "ignored"
      ]
    },
    "IpamPool":{
      "type":"structure",
      "members":{
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the IPAM pool.</p>",
          "locationName":"ownerId"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool.</p>",
          "locationName":"ipamPoolId"
        },
        "SourceIpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the source IPAM pool. You can use this option to create an IPAM pool within an existing source pool.</p>",
          "locationName":"sourceIpamPoolId"
        },
        "IpamPoolArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the IPAM pool.</p>",
          "locationName":"ipamPoolArn"
        },
        "IpamScopeArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The ARN of the scope of the IPAM pool.</p>",
          "locationName":"ipamScopeArn"
        },
        "IpamScopeType":{
          "shape":"IpamScopeType",
          "documentation":"<p>In IPAM, a scope is the highest-level container within IPAM. An IPAM contains two default scopes. Each scope represents the IP space for a single network. The private scope is intended for all private IP address space. The public scope is intended for all public IP address space. Scopes enable you to reuse IP addresses across multiple unconnected networks without causing IP address overlap or conflict.</p>",
          "locationName":"ipamScopeType"
        },
        "IpamArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The ARN of the IPAM.</p>",
          "locationName":"ipamArn"
        },
        "IpamRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region of the IPAM pool.</p>",
          "locationName":"ipamRegion"
        },
        "Locale":{
          "shape":"String",
          "documentation":"<p>The locale of the IPAM pool. In IPAM, the locale is the Amazon Web Services Region where you want to make an IPAM pool available for allocations. Only resources in the same Region as the locale of the pool can get IP address allocations from the pool. You can only allocate a CIDR for a VPC, for example, from an IPAM pool that shares a locale with the VPC’s Region. Note that once you choose a Locale for a pool, you cannot modify it. If you choose an Amazon Web Services Region for locale that has not been configured as an operating Region for the IPAM, you'll get an error.</p>",
          "locationName":"locale"
        },
        "PoolDepth":{
          "shape":"Integer",
          "documentation":"<p>The depth of pools in your IPAM pool. The pool depth quota is 10. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/quotas-ipam.html\">Quotas in IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>. </p>",
          "locationName":"poolDepth"
        },
        "State":{
          "shape":"IpamPoolState",
          "documentation":"<p>The state of the IPAM pool.</p>",
          "locationName":"state"
        },
        "StateMessage":{
          "shape":"String",
          "documentation":"<p>A message related to the failed creation of an IPAM pool.</p>",
          "locationName":"stateMessage"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the IPAM pool.</p>",
          "locationName":"description"
        },
        "AutoImport":{
          "shape":"Boolean",
          "documentation":"<p>If selected, IPAM will continuously look for resources within the CIDR range of this pool and automatically import them as allocations into your IPAM. The CIDRs that will be allocated for these resources must not already be allocated to other resources in order for the import to succeed. IPAM will import a CIDR regardless of its compliance with the pool's allocation rules, so a resource might be imported and subsequently marked as noncompliant. If IPAM discovers multiple CIDRs that overlap, IPAM will import the largest CIDR only. If IPAM discovers multiple CIDRs with matching CIDRs, IPAM will randomly import one of them only. </p> <p>A locale must be set on the pool for this feature to work.</p>",
          "locationName":"autoImport"
        },
        "PubliclyAdvertisable":{
          "shape":"Boolean",
          "documentation":"<p>Determines if a pool is publicly advertisable. This option is not available for pools with AddressFamily set to <code>ipv4</code>.</p>",
          "locationName":"publiclyAdvertisable"
        },
        "AddressFamily":{
          "shape":"AddressFamily",
          "documentation":"<p>The address family of the pool.</p>",
          "locationName":"addressFamily"
        },
        "AllocationMinNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The minimum netmask length required for CIDR allocations in this IPAM pool to be compliant. The minimum netmask length must be less than the maximum netmask length. Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128.</p>",
          "locationName":"allocationMinNetmaskLength"
        },
        "AllocationMaxNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The maximum netmask length possible for CIDR allocations in this IPAM pool to be compliant. The maximum netmask length must be greater than the minimum netmask length. Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128.</p>",
          "locationName":"allocationMaxNetmaskLength"
        },
        "AllocationDefaultNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The default netmask length for allocations added to this pool. If, for example, the CIDR assigned to this pool is 10.0.0.0/8 and you enter 16 here, new allocations will default to 10.0.0.0/16.</p>",
          "locationName":"allocationDefaultNetmaskLength"
        },
        "AllocationResourceTags":{
          "shape":"IpamResourceTagList",
          "documentation":"<p>Tags that are required for resources that use CIDRs from this IPAM pool. Resources that do not have these tags will not be allowed to allocate space from the pool. If the resources have their tags changed after they have allocated space or if the allocation tagging requirements are changed on the pool, the resource may be marked as noncompliant.</p>",
          "locationName":"allocationResourceTagSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"tagSet"
        },
        "AwsService":{
          "shape":"IpamPoolAwsService",
          "documentation":"<p>Limits which service in Amazon Web Services that the pool can be used in. \"ec2\", for example, allows users to use space for Elastic IP addresses and VPCs.</p>",
          "locationName":"awsService"
        },
        "PublicIpSource":{
          "shape":"IpamPoolPublicIpSource",
          "documentation":"<p>The IP address source for pools in the public scope. Only used for provisioning IP address CIDRs to pools in the public scope. Default is <code>BYOIP</code>. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/intro-create-ipv6-pools.html\">Create IPv6 pools</a> in the <i>Amazon VPC IPAM User Guide</i>. By default, you can add only one Amazon-provided IPv6 CIDR block to a top-level IPv6 pool. For information on increasing the default limit, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/quotas-ipam.html\"> Quotas for your IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"publicIpSource"
        }
      },
      "documentation":"<p>In IPAM, a pool is a collection of contiguous IP addresses CIDRs. Pools enable you to organize your IP addresses according to your routing and security needs. For example, if you have separate routing and security needs for development and production applications, you can create a pool for each.</p>"
    },
    "IpamPoolAllocation":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR for the allocation. A CIDR is a representation of an IP address and its associated network mask (or netmask) and refers to a range of IP addresses. An IPv4 CIDR example is <code>10.24.34.0/23</code>. An IPv6 CIDR example is <code>2001:DB8::/32</code>.</p>",
          "locationName":"cidr"
        },
        "IpamPoolAllocationId":{
          "shape":"IpamPoolAllocationId",
          "documentation":"<p>The ID of an allocation.</p>",
          "locationName":"ipamPoolAllocationId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the pool allocation.</p>",
          "locationName":"description"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"IpamPoolAllocationResourceType",
          "documentation":"<p>The type of the resource.</p>",
          "locationName":"resourceType"
        },
        "ResourceRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region of the resource.</p>",
          "locationName":"resourceRegion"
        },
        "ResourceOwner":{
          "shape":"String",
          "documentation":"<p>The owner of the resource.</p>",
          "locationName":"resourceOwner"
        }
      },
      "documentation":"<p>In IPAM, an allocation is a CIDR assignment from an IPAM pool to another IPAM pool or to a resource.</p>"
    },
    "IpamPoolAllocationDisallowedCidrs":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "IpamPoolAllocationId":{"type":"string"},
    "IpamPoolAllocationResourceType":{
      "type":"string",
      "enum":[
        "ipam-pool",
        "vpc",
        "ec2-public-ipv4-pool",
        "custom"
      ]
    },
    "IpamPoolAllocationSet":{
      "type":"list",
      "member":{
        "shape":"IpamPoolAllocation",
        "locationName":"item"
      }
    },
    "IpamPoolAwsService":{
      "type":"string",
      "enum":["ec2"]
    },
    "IpamPoolCidr":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR provisioned to the IPAM pool. A CIDR is a representation of an IP address and its associated network mask (or netmask) and refers to a range of IP addresses. An IPv4 CIDR example is <code>10.24.34.0/23</code>. An IPv6 CIDR example is <code>2001:DB8::/32</code>.</p>",
          "locationName":"cidr"
        },
        "State":{
          "shape":"IpamPoolCidrState",
          "documentation":"<p>The state of the CIDR.</p>",
          "locationName":"state"
        },
        "FailureReason":{
          "shape":"IpamPoolCidrFailureReason",
          "documentation":"<p>Details related to why an IPAM pool CIDR failed to be provisioned.</p>",
          "locationName":"failureReason"
        },
        "IpamPoolCidrId":{
          "shape":"IpamPoolCidrId",
          "documentation":"<p>The IPAM pool CIDR ID.</p>",
          "locationName":"ipamPoolCidrId"
        },
        "NetmaskLength":{
          "shape":"Integer",
          "documentation":"<p>The netmask length of the CIDR you'd like to provision to a pool. Can be used for provisioning Amazon-provided IPv6 CIDRs to top-level pools and for provisioning CIDRs to pools with source pools. Cannot be used to provision BYOIP CIDRs to top-level pools. \"NetmaskLength\" or \"Cidr\" is required.</p>",
          "locationName":"netmaskLength"
        }
      },
      "documentation":"<p>A CIDR provisioned to an IPAM pool.</p>"
    },
    "IpamPoolCidrFailureCode":{
      "type":"string",
      "enum":[
        "cidr-not-available",
        "limit-exceeded"
      ]
    },
    "IpamPoolCidrFailureReason":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"IpamPoolCidrFailureCode",
          "documentation":"<p>An error code related to why an IPAM pool CIDR failed to be provisioned.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message related to why an IPAM pool CIDR failed to be provisioned.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Details related to why an IPAM pool CIDR failed to be provisioned.</p>"
    },
    "IpamPoolCidrId":{"type":"string"},
    "IpamPoolCidrSet":{
      "type":"list",
      "member":{
        "shape":"IpamPoolCidr",
        "locationName":"item"
      }
    },
    "IpamPoolCidrState":{
      "type":"string",
      "enum":[
        "pending-provision",
        "provisioned",
        "failed-provision",
        "pending-deprovision",
        "deprovisioned",
        "failed-deprovision",
        "pending-import",
        "failed-import"
      ]
    },
    "IpamPoolId":{"type":"string"},
    "IpamPoolPublicIpSource":{
      "type":"string",
      "enum":[
        "amazon",
        "byoip"
      ]
    },
    "IpamPoolSet":{
      "type":"list",
      "member":{
        "shape":"IpamPool",
        "locationName":"item"
      }
    },
    "IpamPoolState":{
      "type":"string",
      "enum":[
        "create-in-progress",
        "create-complete",
        "create-failed",
        "modify-in-progress",
        "modify-complete",
        "modify-failed",
        "delete-in-progress",
        "delete-complete",
        "delete-failed",
        "isolate-in-progress",
        "isolate-complete",
        "restore-in-progress"
      ]
    },
    "IpamResourceCidr":{
      "type":"structure",
      "members":{
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>The IPAM ID for an IPAM resource.</p>",
          "locationName":"ipamId"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The scope ID for an IPAM resource.</p>",
          "locationName":"ipamScopeId"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The pool ID for an IPAM resource.</p>",
          "locationName":"ipamPoolId"
        },
        "ResourceRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region for an IPAM resource.</p>",
          "locationName":"resourceRegion"
        },
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account number of the owner of an IPAM resource.</p>",
          "locationName":"resourceOwnerId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of an IPAM resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceName":{
          "shape":"String",
          "documentation":"<p>The name of an IPAM resource.</p>",
          "locationName":"resourceName"
        },
        "ResourceCidr":{
          "shape":"String",
          "documentation":"<p>The CIDR for an IPAM resource.</p>",
          "locationName":"resourceCidr"
        },
        "ResourceType":{
          "shape":"IpamResourceType",
          "documentation":"<p>The type of IPAM resource.</p>",
          "locationName":"resourceType"
        },
        "ResourceTags":{
          "shape":"IpamResourceTagList",
          "documentation":"<p>The tags for an IPAM resource.</p>",
          "locationName":"resourceTagSet"
        },
        "IpUsage":{
          "shape":"BoxedDouble",
          "documentation":"<p>The percentage of IP address space in use. To convert the decimal to a percentage, multiply the decimal by 100. Note the following:</p> <ul> <li> <p>For resources that are VPCs, this is the percentage of IP address space in the VPC that's taken up by subnet CIDRs. </p> </li> <li> <p>For resources that are subnets, if the subnet has an IPv4 CIDR provisioned to it, this is the percentage of IPv4 address space in the subnet that's in use. If the subnet has an IPv6 CIDR provisioned to it, the percentage of IPv6 address space in use is not represented. The percentage of IPv6 address space in use cannot currently be calculated. </p> </li> <li> <p>For resources that are public IPv4 pools, this is the percentage of IP address space in the pool that's been allocated to Elastic IP addresses (EIPs). </p> </li> </ul>",
          "locationName":"ipUsage"
        },
        "ComplianceStatus":{
          "shape":"IpamComplianceStatus",
          "documentation":"<p>The compliance status of the IPAM resource. For more information on compliance statuses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/monitor-cidr-compliance-ipam.html\">Monitor CIDR usage by resource</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"complianceStatus"
        },
        "ManagementState":{
          "shape":"IpamManagementState",
          "documentation":"<p>The management state of the resource. For more information about management states, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/monitor-cidr-compliance-ipam.html\">Monitor CIDR usage by resource</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"managementState"
        },
        "OverlapStatus":{
          "shape":"IpamOverlapStatus",
          "documentation":"<p>The overlap status of an IPAM resource. The overlap status tells you if the CIDR for a resource overlaps with another CIDR in the scope. For more information on overlap statuses, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/monitor-cidr-compliance-ipam.html\">Monitor CIDR usage by resource</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"overlapStatus"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of a VPC.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<p>The CIDR for an IPAM resource.</p>"
    },
    "IpamResourceCidrSet":{
      "type":"list",
      "member":{
        "shape":"IpamResourceCidr",
        "locationName":"item"
      }
    },
    "IpamResourceDiscovery":{
      "type":"structure",
      "members":{
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the owner.</p>",
          "locationName":"ownerId"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>The resource discovery ID.</p>",
          "locationName":"ipamResourceDiscoveryId"
        },
        "IpamResourceDiscoveryArn":{
          "shape":"String",
          "documentation":"<p>The resource discovery Amazon Resource Name (ARN).</p>",
          "locationName":"ipamResourceDiscoveryArn"
        },
        "IpamResourceDiscoveryRegion":{
          "shape":"String",
          "documentation":"<p>The resource discovery Region.</p>",
          "locationName":"ipamResourceDiscoveryRegion"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The resource discovery description.</p>",
          "locationName":"description"
        },
        "OperatingRegions":{
          "shape":"IpamOperatingRegionSet",
          "documentation":"<p>The operating Regions for the resource discovery. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p>",
          "locationName":"operatingRegionSet"
        },
        "IsDefault":{
          "shape":"Boolean",
          "documentation":"<p>Defines if the resource discovery is the default. The default resource discovery is the resource discovery automatically created when you create an IPAM.</p>",
          "locationName":"isDefault"
        },
        "State":{
          "shape":"IpamResourceDiscoveryState",
          "documentation":"<p>The lifecycle state of the resource discovery.</p> <ul> <li> <p> <code>create-in-progress</code> - Resource discovery is being created.</p> </li> <li> <p> <code>create-complete</code> - Resource discovery creation is complete.</p> </li> <li> <p> <code>create-failed</code> - Resource discovery creation has failed.</p> </li> <li> <p> <code>modify-in-progress</code> - Resource discovery is being modified.</p> </li> <li> <p> <code>modify-complete</code> - Resource discovery modification is complete.</p> </li> <li> <p> <code>modify-failed</code> - Resource discovery modification has failed.</p> </li> <li> <p> <code>delete-in-progress</code> - Resource discovery is being deleted.</p> </li> <li> <p> <code>delete-complete</code> - Resource discovery deletion is complete.</p> </li> <li> <p> <code>delete-failed</code> - Resource discovery deletion has failed.</p> </li> <li> <p> <code>isolate-in-progress</code> - Amazon Web Services account that created the resource discovery has been removed and the resource discovery is being isolated.</p> </li> <li> <p> <code>isolate-complete</code> - Resource discovery isolation is complete.</p> </li> <li> <p> <code>restore-in-progress</code> - Amazon Web Services account that created the resource discovery and was isolated has been restored.</p> </li> </ul>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>A tag is a label that you assign to an Amazon Web Services resource. Each tag consists of a key and an optional value. You can use tags to search and filter your resources or track your Amazon Web Services costs.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>A resource discovery is an IPAM component that enables IPAM to manage and monitor resources that belong to the owning account.</p>"
    },
    "IpamResourceDiscoveryAssociation":{
      "type":"structure",
      "members":{
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the resource discovery owner.</p>",
          "locationName":"ownerId"
        },
        "IpamResourceDiscoveryAssociationId":{
          "shape":"IpamResourceDiscoveryAssociationId",
          "documentation":"<p>The resource discovery association ID.</p>",
          "locationName":"ipamResourceDiscoveryAssociationId"
        },
        "IpamResourceDiscoveryAssociationArn":{
          "shape":"String",
          "documentation":"<p>The resource discovery association Amazon Resource Name (ARN).</p>",
          "locationName":"ipamResourceDiscoveryAssociationArn"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>The resource discovery ID.</p>",
          "locationName":"ipamResourceDiscoveryId"
        },
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>The IPAM ID.</p>",
          "locationName":"ipamId"
        },
        "IpamArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The IPAM ARN.</p>",
          "locationName":"ipamArn"
        },
        "IpamRegion":{
          "shape":"String",
          "documentation":"<p>The IPAM home Region.</p>",
          "locationName":"ipamRegion"
        },
        "IsDefault":{
          "shape":"Boolean",
          "documentation":"<p>Defines if the resource discovery is the default. When you create an IPAM, a default resource discovery is created for your IPAM and it's associated with your IPAM.</p>",
          "locationName":"isDefault"
        },
        "ResourceDiscoveryStatus":{
          "shape":"IpamAssociatedResourceDiscoveryStatus",
          "documentation":"<p>The resource discovery status.</p> <ul> <li> <p> <code>active</code> - Connection or permissions required to read the results of the resource discovery are intact.</p> </li> <li> <p> <code>not-found</code> - Connection or permissions required to read the results of the resource discovery are broken. This may happen if the owner of the resource discovery stopped sharing it or deleted the resource discovery. Verify the resource discovery still exists and the Amazon Web Services RAM resource share is still intact.</p> </li> </ul>",
          "locationName":"resourceDiscoveryStatus"
        },
        "State":{
          "shape":"IpamResourceDiscoveryAssociationState",
          "documentation":"<p>The lifecycle state of the association when you associate or disassociate a resource discovery.</p> <ul> <li> <p> <code>associate-in-progress</code> - Resource discovery is being associated.</p> </li> <li> <p> <code>associate-complete</code> - Resource discovery association is complete.</p> </li> <li> <p> <code>associate-failed</code> - Resource discovery association has failed.</p> </li> <li> <p> <code>disassociate-in-progress</code> - Resource discovery is being disassociated.</p> </li> <li> <p> <code>disassociate-complete</code> - Resource discovery disassociation is complete.</p> </li> <li> <p> <code>disassociate-failed </code> - Resource discovery disassociation has failed.</p> </li> <li> <p> <code>isolate-in-progress</code> - Amazon Web Services account that created the resource discovery association has been removed and the resource discovery associatation is being isolated.</p> </li> <li> <p> <code>isolate-complete</code> - Resource discovery isolation is complete..</p> </li> <li> <p> <code>restore-in-progress</code> - Resource discovery is being restored.</p> </li> </ul>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>A tag is a label that you assign to an Amazon Web Services resource. Each tag consists of a key and an optional value. You can use tags to search and filter your resources or track your Amazon Web Services costs.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>An IPAM resource discovery association. An associated resource discovery is a resource discovery that has been associated with an IPAM. IPAM aggregates the resource CIDRs discovered by the associated resource discovery.</p>"
    },
    "IpamResourceDiscoveryAssociationId":{"type":"string"},
    "IpamResourceDiscoveryAssociationSet":{
      "type":"list",
      "member":{
        "shape":"IpamResourceDiscoveryAssociation",
        "locationName":"item"
      }
    },
    "IpamResourceDiscoveryAssociationState":{
      "type":"string",
      "enum":[
        "associate-in-progress",
        "associate-complete",
        "associate-failed",
        "disassociate-in-progress",
        "disassociate-complete",
        "disassociate-failed",
        "isolate-in-progress",
        "isolate-complete",
        "restore-in-progress"
      ]
    },
    "IpamResourceDiscoveryId":{"type":"string"},
    "IpamResourceDiscoverySet":{
      "type":"list",
      "member":{
        "shape":"IpamResourceDiscovery",
        "locationName":"item"
      }
    },
    "IpamResourceDiscoveryState":{
      "type":"string",
      "enum":[
        "create-in-progress",
        "create-complete",
        "create-failed",
        "modify-in-progress",
        "modify-complete",
        "modify-failed",
        "delete-in-progress",
        "delete-complete",
        "delete-failed",
        "isolate-in-progress",
        "isolate-complete",
        "restore-in-progress"
      ]
    },
    "IpamResourceTag":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "documentation":"<p>The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p>",
          "locationName":"key"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The value of the tag.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>"
    },
    "IpamResourceTagList":{
      "type":"list",
      "member":{
        "shape":"IpamResourceTag",
        "locationName":"item"
      }
    },
    "IpamResourceType":{
      "type":"string",
      "enum":[
        "vpc",
        "subnet",
        "eip",
        "public-ipv4-pool",
        "ipv6-pool"
      ]
    },
    "IpamScope":{
      "type":"structure",
      "members":{
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the scope.</p>",
          "locationName":"ownerId"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the scope.</p>",
          "locationName":"ipamScopeId"
        },
        "IpamScopeArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the scope.</p>",
          "locationName":"ipamScopeArn"
        },
        "IpamArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The ARN of the IPAM.</p>",
          "locationName":"ipamArn"
        },
        "IpamRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region of the IPAM scope.</p>",
          "locationName":"ipamRegion"
        },
        "IpamScopeType":{
          "shape":"IpamScopeType",
          "documentation":"<p>The type of the scope.</p>",
          "locationName":"ipamScopeType"
        },
        "IsDefault":{
          "shape":"Boolean",
          "documentation":"<p>Defines if the scope is the default scope or not.</p>",
          "locationName":"isDefault"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the scope.</p>",
          "locationName":"description"
        },
        "PoolCount":{
          "shape":"Integer",
          "documentation":"<p>The number of pools in the scope.</p>",
          "locationName":"poolCount"
        },
        "State":{
          "shape":"IpamScopeState",
          "documentation":"<p>The state of the IPAM scope.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The key/value combination of a tag assigned to the resource. Use the tag key in the filter name and the tag value as the filter value. For example, to find all resources that have a tag with the key <code>Owner</code> and the value <code>TeamA</code>, specify <code>tag:Owner</code> for the filter name and <code>TeamA</code> for the filter value.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>In IPAM, a scope is the highest-level container within IPAM. An IPAM contains two default scopes. Each scope represents the IP space for a single network. The private scope is intended for all private IP address space. The public scope is intended for all public IP address space. Scopes enable you to reuse IP addresses across multiple unconnected networks without causing IP address overlap or conflict.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/how-it-works-ipam.html\">How IPAM works</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>"
    },
    "IpamScopeId":{"type":"string"},
    "IpamScopeSet":{
      "type":"list",
      "member":{
        "shape":"IpamScope",
        "locationName":"item"
      }
    },
    "IpamScopeState":{
      "type":"string",
      "enum":[
        "create-in-progress",
        "create-complete",
        "create-failed",
        "modify-in-progress",
        "modify-complete",
        "modify-failed",
        "delete-in-progress",
        "delete-complete",
        "delete-failed",
        "isolate-in-progress",
        "isolate-complete",
        "restore-in-progress"
      ]
    },
    "IpamScopeType":{
      "type":"string",
      "enum":[
        "public",
        "private"
      ]
    },
    "IpamSet":{
      "type":"list",
      "member":{
        "shape":"Ipam",
        "locationName":"item"
      }
    },
    "IpamState":{
      "type":"string",
      "enum":[
        "create-in-progress",
        "create-complete",
        "create-failed",
        "modify-in-progress",
        "modify-complete",
        "modify-failed",
        "delete-in-progress",
        "delete-complete",
        "delete-failed",
        "isolate-in-progress",
        "isolate-complete",
        "restore-in-progress"
      ]
    },
    "Ipv4PoolCoipId":{"type":"string"},
    "Ipv4PoolEc2Id":{"type":"string"},
    "Ipv4PrefixList":{
      "type":"list",
      "member":{
        "shape":"Ipv4PrefixSpecificationRequest",
        "locationName":"item"
      }
    },
    "Ipv4PrefixListResponse":{
      "type":"list",
      "member":{
        "shape":"Ipv4PrefixSpecificationResponse",
        "locationName":"item"
      }
    },
    "Ipv4PrefixSpecification":{
      "type":"structure",
      "members":{
        "Ipv4Prefix":{
          "shape":"String",
          "documentation":"<p>The IPv4 prefix. For information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-prefix-eni.html\"> Assigning prefixes to Amazon EC2 network interfaces</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"ipv4Prefix"
        }
      },
      "documentation":"<p>Describes an IPv4 prefix.</p>"
    },
    "Ipv4PrefixSpecificationRequest":{
      "type":"structure",
      "members":{
        "Ipv4Prefix":{
          "shape":"String",
          "documentation":"<p>The IPv4 prefix. For information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-prefix-eni.html\"> Assigning prefixes to Amazon EC2 network interfaces</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        }
      },
      "documentation":"<p>Describes the IPv4 prefix option for a network interface.</p>"
    },
    "Ipv4PrefixSpecificationResponse":{
      "type":"structure",
      "members":{
        "Ipv4Prefix":{
          "shape":"String",
          "documentation":"<p>The IPv4 delegated prefixes assigned to the network interface.</p>",
          "locationName":"ipv4Prefix"
        }
      },
      "documentation":"<p>Information about the IPv4 delegated prefixes assigned to a network interface.</p>"
    },
    "Ipv4PrefixesList":{
      "type":"list",
      "member":{
        "shape":"Ipv4PrefixSpecification",
        "locationName":"item"
      }
    },
    "Ipv6Address":{"type":"string"},
    "Ipv6AddressList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "Ipv6CidrAssociation":{
      "type":"structure",
      "members":{
        "Ipv6Cidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block.</p>",
          "locationName":"ipv6Cidr"
        },
        "AssociatedResource":{
          "shape":"String",
          "documentation":"<p>The resource that's associated with the IPv6 CIDR block.</p>",
          "locationName":"associatedResource"
        }
      },
      "documentation":"<p>Describes an IPv6 CIDR block association.</p>"
    },
    "Ipv6CidrAssociationSet":{
      "type":"list",
      "member":{
        "shape":"Ipv6CidrAssociation",
        "locationName":"item"
      }
    },
    "Ipv6CidrBlock":{
      "type":"structure",
      "members":{
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block.</p>",
          "locationName":"ipv6CidrBlock"
        }
      },
      "documentation":"<p>Describes an IPv6 CIDR block.</p>"
    },
    "Ipv6CidrBlockSet":{
      "type":"list",
      "member":{
        "shape":"Ipv6CidrBlock",
        "locationName":"item"
      }
    },
    "Ipv6Flag":{"type":"boolean"},
    "Ipv6Pool":{
      "type":"structure",
      "members":{
        "PoolId":{
          "shape":"String",
          "documentation":"<p>The ID of the address pool.</p>",
          "locationName":"poolId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the address pool.</p>",
          "locationName":"description"
        },
        "PoolCidrBlocks":{
          "shape":"PoolCidrBlocksSet",
          "documentation":"<p>The CIDR blocks for the address pool.</p>",
          "locationName":"poolCidrBlockSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags for the address pool.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an IPv6 address pool.</p>"
    },
    "Ipv6PoolEc2Id":{"type":"string"},
    "Ipv6PoolIdList":{
      "type":"list",
      "member":{
        "shape":"Ipv6PoolEc2Id",
        "locationName":"item"
      }
    },
    "Ipv6PoolMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "Ipv6PoolSet":{
      "type":"list",
      "member":{
        "shape":"Ipv6Pool",
        "locationName":"item"
      }
    },
    "Ipv6PrefixList":{
      "type":"list",
      "member":{
        "shape":"Ipv6PrefixSpecificationRequest",
        "locationName":"item"
      }
    },
    "Ipv6PrefixListResponse":{
      "type":"list",
      "member":{
        "shape":"Ipv6PrefixSpecificationResponse",
        "locationName":"item"
      }
    },
    "Ipv6PrefixSpecification":{
      "type":"structure",
      "members":{
        "Ipv6Prefix":{
          "shape":"String",
          "documentation":"<p>The IPv6 prefix.</p>",
          "locationName":"ipv6Prefix"
        }
      },
      "documentation":"<p>Describes the IPv6 prefix.</p>"
    },
    "Ipv6PrefixSpecificationRequest":{
      "type":"structure",
      "members":{
        "Ipv6Prefix":{
          "shape":"String",
          "documentation":"<p>The IPv6 prefix.</p>"
        }
      },
      "documentation":"<p>Describes the IPv4 prefix option for a network interface.</p>"
    },
    "Ipv6PrefixSpecificationResponse":{
      "type":"structure",
      "members":{
        "Ipv6Prefix":{
          "shape":"String",
          "documentation":"<p>The IPv6 delegated prefixes assigned to the network interface.</p>",
          "locationName":"ipv6Prefix"
        }
      },
      "documentation":"<p>Information about the IPv6 delegated prefixes assigned to a network interface.</p>"
    },
    "Ipv6PrefixesList":{
      "type":"list",
      "member":{
        "shape":"Ipv6PrefixSpecification",
        "locationName":"item"
      }
    },
    "Ipv6Range":{
      "type":"structure",
      "members":{
        "CidrIpv6":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR range. You can either specify a CIDR range or a source security group, not both. To specify a single IPv6 address, use the /128 prefix length.</p>",
          "locationName":"cidrIpv6"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the security group rule that references this IPv6 address range.</p> <p>Constraints: Up to 255 characters in length. Allowed characters are a-z, A-Z, 0-9, spaces, and ._-:/()#,@[]+=&;{}!$*</p>",
          "locationName":"description"
        }
      },
      "documentation":"<p>[EC2-VPC only] Describes an IPv6 range.</p>"
    },
    "Ipv6RangeList":{
      "type":"list",
      "member":{
        "shape":"Ipv6Range",
        "locationName":"item"
      }
    },
    "Ipv6SupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "KernelId":{"type":"string"},
    "KeyFormat":{
      "type":"string",
      "enum":[
        "pem",
        "ppk"
      ]
    },
    "KeyNameStringList":{
      "type":"list",
      "member":{
        "shape":"KeyPairName",
        "locationName":"KeyName"
      }
    },
    "KeyPair":{
      "type":"structure",
      "members":{
        "KeyFingerprint":{
          "shape":"String",
          "documentation":"<ul> <li> <p>For RSA key pairs, the key fingerprint is the SHA-1 digest of the DER encoded private key.</p> </li> <li> <p>For ED25519 key pairs, the key fingerprint is the base64-encoded SHA-256 digest, which is the default for OpenSSH, starting with OpenSSH 6.8.</p> </li> </ul>",
          "locationName":"keyFingerprint"
        },
        "KeyMaterial":{
          "shape":"SensitiveUserData",
          "documentation":"<p>An unencrypted PEM encoded RSA or ED25519 private key.</p>",
          "locationName":"keyMaterial"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>The name of the key pair.</p>",
          "locationName":"keyName"
        },
        "KeyPairId":{
          "shape":"String",
          "documentation":"<p>The ID of the key pair.</p>",
          "locationName":"keyPairId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags applied to the key pair.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a key pair.</p>"
    },
    "KeyPairId":{"type":"string"},
    "KeyPairIdStringList":{
      "type":"list",
      "member":{
        "shape":"KeyPairId",
        "locationName":"KeyPairId"
      }
    },
    "KeyPairInfo":{
      "type":"structure",
      "members":{
        "KeyPairId":{
          "shape":"String",
          "documentation":"<p>The ID of the key pair.</p>",
          "locationName":"keyPairId"
        },
        "KeyFingerprint":{
          "shape":"String",
          "documentation":"<p>If you used <a>CreateKeyPair</a> to create the key pair:</p> <ul> <li> <p>For RSA key pairs, the key fingerprint is the SHA-1 digest of the DER encoded private key.</p> </li> <li> <p>For ED25519 key pairs, the key fingerprint is the base64-encoded SHA-256 digest, which is the default for OpenSSH, starting with <a href=\"http://www.openssh.com/txt/release-6.8\">OpenSSH 6.8</a>.</p> </li> </ul> <p>If you used <a>ImportKeyPair</a> to provide Amazon Web Services the public key:</p> <ul> <li> <p>For RSA key pairs, the key fingerprint is the MD5 public key fingerprint as specified in section 4 of RFC4716.</p> </li> <li> <p>For ED25519 key pairs, the key fingerprint is the base64-encoded SHA-256 digest, which is the default for OpenSSH, starting with <a href=\"http://www.openssh.com/txt/release-6.8\">OpenSSH 6.8</a>.</p> </li> </ul>",
          "locationName":"keyFingerprint"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>The name of the key pair.</p>",
          "locationName":"keyName"
        },
        "KeyType":{
          "shape":"KeyType",
          "documentation":"<p>The type of key pair.</p>",
          "locationName":"keyType"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags applied to the key pair.</p>",
          "locationName":"tagSet"
        },
        "PublicKey":{
          "shape":"String",
          "documentation":"<p>The public key material.</p>",
          "locationName":"publicKey"
        },
        "CreateTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>If you used Amazon EC2 to create the key pair, this is the date and time when the key was created, in <a href=\"https://www.iso.org/iso-8601-date-and-time-format.html\">ISO 8601 date-time format</a>, in the UTC time zone.</p> <p>If you imported an existing key pair to Amazon EC2, this is the date and time the key was imported, in <a href=\"https://www.iso.org/iso-8601-date-and-time-format.html\">ISO 8601 date-time format</a>, in the UTC time zone.</p>",
          "locationName":"createTime"
        }
      },
      "documentation":"<p>Describes a key pair.</p>"
    },
    "KeyPairList":{
      "type":"list",
      "member":{
        "shape":"KeyPairInfo",
        "locationName":"item"
      }
    },
    "KeyPairName":{"type":"string"},
    "KeyType":{
      "type":"string",
      "enum":[
        "rsa",
        "ed25519"
      ]
    },
    "KmsKeyId":{"type":"string"},
    "LastError":{
      "type":"structure",
      "members":{
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message for the VPC endpoint error.</p>",
          "locationName":"message"
        },
        "Code":{
          "shape":"String",
          "documentation":"<p>The error code for the VPC endpoint error.</p>",
          "locationName":"code"
        }
      },
      "documentation":"<p>The last error that occurred for a VPC endpoint.</p>"
    },
    "LaunchPermission":{
      "type":"structure",
      "members":{
        "Group":{
          "shape":"PermissionGroup",
          "documentation":"<p>The name of the group.</p>",
          "locationName":"group"
        },
        "UserId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p> <p>Constraints: Up to 10 000 account IDs can be specified in a single request.</p>",
          "locationName":"userId"
        },
        "OrganizationArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of an organization.</p>",
          "locationName":"organizationArn"
        },
        "OrganizationalUnitArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of an organizational unit (OU).</p>",
          "locationName":"organizationalUnitArn"
        }
      },
      "documentation":"<p>Describes a launch permission.</p>"
    },
    "LaunchPermissionList":{
      "type":"list",
      "member":{
        "shape":"LaunchPermission",
        "locationName":"item"
      }
    },
    "LaunchPermissionModifications":{
      "type":"structure",
      "members":{
        "Add":{
          "shape":"LaunchPermissionList",
          "documentation":"<p>The Amazon Web Services account ID, organization ARN, or OU ARN to add to the list of launch permissions for the AMI.</p>"
        },
        "Remove":{
          "shape":"LaunchPermissionList",
          "documentation":"<p>The Amazon Web Services account ID, organization ARN, or OU ARN to remove from the list of launch permissions for the AMI.</p>"
        }
      },
      "documentation":"<p>Describes a launch permission modification.</p>"
    },
    "LaunchSpecification":{
      "type":"structure",
      "members":{
        "UserData":{
          "shape":"SensitiveUserData",
          "documentation":"<p>The Base64-encoded user data for the instance.</p>",
          "locationName":"userData"
        },
        "SecurityGroups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>One or more security groups. When requesting instances in a VPC, you must specify the IDs of the security groups. When requesting instances in EC2-Classic, you can specify the names or the IDs of the security groups.</p>",
          "locationName":"groupSet"
        },
        "AddressingType":{
          "shape":"String",
          "documentation":"<p>Deprecated.</p>",
          "locationName":"addressingType"
        },
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingList",
          "documentation":"<p>One or more block device mapping entries.</p>",
          "locationName":"blockDeviceMapping"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is optimized for EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS Optimized instance.</p> <p>Default: <code>false</code> </p>",
          "locationName":"ebsOptimized"
        },
        "IamInstanceProfile":{
          "shape":"IamInstanceProfileSpecification",
          "documentation":"<p>The IAM instance profile.</p>",
          "locationName":"iamInstanceProfile"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI.</p>",
          "locationName":"imageId"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. Only one instance type can be specified.</p>",
          "locationName":"instanceType"
        },
        "KernelId":{
          "shape":"String",
          "documentation":"<p>The ID of the kernel.</p>",
          "locationName":"kernelId"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>The name of the key pair.</p>",
          "locationName":"keyName"
        },
        "NetworkInterfaces":{
          "shape":"InstanceNetworkInterfaceSpecificationList",
          "documentation":"<p>One or more network interfaces. If you specify a network interface, you must specify subnet IDs and security group IDs using the network interface.</p>",
          "locationName":"networkInterfaceSet"
        },
        "Placement":{
          "shape":"SpotPlacement",
          "documentation":"<p>The placement information for the instance.</p>",
          "locationName":"placement"
        },
        "RamdiskId":{
          "shape":"String",
          "documentation":"<p>The ID of the RAM disk.</p>",
          "locationName":"ramdiskId"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet in which to launch the instance.</p>",
          "locationName":"subnetId"
        },
        "Monitoring":{
          "shape":"RunInstancesMonitoringEnabled",
          "locationName":"monitoring"
        }
      },
      "documentation":"<p>Describes the launch specification for an instance.</p>"
    },
    "LaunchSpecsList":{
      "type":"list",
      "member":{
        "shape":"SpotFleetLaunchSpecification",
        "locationName":"item"
      }
    },
    "LaunchTemplate":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"String",
          "documentation":"<p>The ID of the launch template.</p>",
          "locationName":"launchTemplateId"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p>",
          "locationName":"launchTemplateName"
        },
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The time launch template was created.</p>",
          "locationName":"createTime"
        },
        "CreatedBy":{
          "shape":"String",
          "documentation":"<p>The principal that created the launch template. </p>",
          "locationName":"createdBy"
        },
        "DefaultVersionNumber":{
          "shape":"Long",
          "documentation":"<p>The version number of the default version of the launch template.</p>",
          "locationName":"defaultVersionNumber"
        },
        "LatestVersionNumber":{
          "shape":"Long",
          "documentation":"<p>The version number of the latest version of the launch template.</p>",
          "locationName":"latestVersionNumber"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the launch template.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a launch template.</p>"
    },
    "LaunchTemplateAndOverridesResponse":{
      "type":"structure",
      "members":{
        "LaunchTemplateSpecification":{
          "shape":"FleetLaunchTemplateSpecification",
          "documentation":"<p>The launch template.</p>",
          "locationName":"launchTemplateSpecification"
        },
        "Overrides":{
          "shape":"FleetLaunchTemplateOverrides",
          "documentation":"<p>Any parameters that you specify override the same parameters in the launch template.</p>",
          "locationName":"overrides"
        }
      },
      "documentation":"<p>Describes a launch template and overrides.</p>"
    },
    "LaunchTemplateAutoRecoveryState":{
      "type":"string",
      "enum":[
        "default",
        "disabled"
      ]
    },
    "LaunchTemplateBlockDeviceMapping":{
      "type":"structure",
      "members":{
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The device name.</p>",
          "locationName":"deviceName"
        },
        "VirtualName":{
          "shape":"String",
          "documentation":"<p>The virtual device name (ephemeralN).</p>",
          "locationName":"virtualName"
        },
        "Ebs":{
          "shape":"LaunchTemplateEbsBlockDevice",
          "documentation":"<p>Information about the block device for an EBS volume.</p>",
          "locationName":"ebs"
        },
        "NoDevice":{
          "shape":"String",
          "documentation":"<p>To omit the device from the block device mapping, specify an empty string.</p>",
          "locationName":"noDevice"
        }
      },
      "documentation":"<p>Describes a block device mapping.</p>"
    },
    "LaunchTemplateBlockDeviceMappingList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateBlockDeviceMapping",
        "locationName":"item"
      }
    },
    "LaunchTemplateBlockDeviceMappingRequest":{
      "type":"structure",
      "members":{
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The device name (for example, /dev/sdh or xvdh).</p>"
        },
        "VirtualName":{
          "shape":"String",
          "documentation":"<p>The virtual device name (ephemeralN). Instance store volumes are numbered starting from 0. An instance type with 2 available instance store volumes can specify mappings for ephemeral0 and ephemeral1. The number of available instance store volumes depends on the instance type. After you connect to the instance, you must mount the volume.</p>"
        },
        "Ebs":{
          "shape":"LaunchTemplateEbsBlockDeviceRequest",
          "documentation":"<p>Parameters used to automatically set up EBS volumes when the instance is launched.</p>"
        },
        "NoDevice":{
          "shape":"String",
          "documentation":"<p>To omit the device from the block device mapping, specify an empty string.</p>"
        }
      },
      "documentation":"<p>Describes a block device mapping.</p>"
    },
    "LaunchTemplateBlockDeviceMappingRequestList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateBlockDeviceMappingRequest",
        "locationName":"BlockDeviceMapping"
      }
    },
    "LaunchTemplateCapacityReservationSpecificationRequest":{
      "type":"structure",
      "members":{
        "CapacityReservationPreference":{
          "shape":"CapacityReservationPreference",
          "documentation":"<p>Indicates the instance's Capacity Reservation preferences. Possible preferences include:</p> <ul> <li> <p> <code>open</code> - The instance can run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone).</p> </li> <li> <p> <code>none</code> - The instance avoids running in a Capacity Reservation even if one is available. The instance runs in On-Demand capacity.</p> </li> </ul>"
        },
        "CapacityReservationTarget":{
          "shape":"CapacityReservationTarget",
          "documentation":"<p>Information about the target Capacity Reservation or Capacity Reservation group.</p>"
        }
      },
      "documentation":"<p>Describes an instance's Capacity Reservation targeting option. You can specify only one option at a time. Use the <code>CapacityReservationPreference</code> parameter to configure the instance to run in On-Demand capacity or to run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone). Use the <code>CapacityReservationTarget</code> parameter to explicitly target a specific Capacity Reservation or a Capacity Reservation group.</p>"
    },
    "LaunchTemplateCapacityReservationSpecificationResponse":{
      "type":"structure",
      "members":{
        "CapacityReservationPreference":{
          "shape":"CapacityReservationPreference",
          "documentation":"<p>Indicates the instance's Capacity Reservation preferences. Possible preferences include:</p> <ul> <li> <p> <code>open</code> - The instance can run in any <code>open</code> Capacity Reservation that has matching attributes (instance type, platform, Availability Zone).</p> </li> <li> <p> <code>none</code> - The instance avoids running in a Capacity Reservation even if one is available. The instance runs in On-Demand capacity.</p> </li> </ul>",
          "locationName":"capacityReservationPreference"
        },
        "CapacityReservationTarget":{
          "shape":"CapacityReservationTargetResponse",
          "documentation":"<p>Information about the target Capacity Reservation or Capacity Reservation group.</p>",
          "locationName":"capacityReservationTarget"
        }
      },
      "documentation":"<p>Information about the Capacity Reservation targeting option.</p>"
    },
    "LaunchTemplateConfig":{
      "type":"structure",
      "members":{
        "LaunchTemplateSpecification":{
          "shape":"FleetLaunchTemplateSpecification",
          "documentation":"<p>The launch template.</p>",
          "locationName":"launchTemplateSpecification"
        },
        "Overrides":{
          "shape":"LaunchTemplateOverridesList",
          "documentation":"<p>Any parameters that you specify override the same parameters in the launch template.</p>",
          "locationName":"overrides"
        }
      },
      "documentation":"<p>Describes a launch template and overrides.</p>"
    },
    "LaunchTemplateConfigList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateConfig",
        "locationName":"item"
      }
    },
    "LaunchTemplateCpuOptions":{
      "type":"structure",
      "members":{
        "CoreCount":{
          "shape":"Integer",
          "documentation":"<p>The number of CPU cores for the instance.</p>",
          "locationName":"coreCount"
        },
        "ThreadsPerCore":{
          "shape":"Integer",
          "documentation":"<p>The number of threads per CPU core.</p>",
          "locationName":"threadsPerCore"
        }
      },
      "documentation":"<p>The CPU options for the instance.</p>"
    },
    "LaunchTemplateCpuOptionsRequest":{
      "type":"structure",
      "members":{
        "CoreCount":{
          "shape":"Integer",
          "documentation":"<p>The number of CPU cores for the instance.</p>"
        },
        "ThreadsPerCore":{
          "shape":"Integer",
          "documentation":"<p>The number of threads per CPU core. To disable multithreading for the instance, specify a value of <code>1</code>. Otherwise, specify the default value of <code>2</code>.</p>"
        }
      },
      "documentation":"<p>The CPU options for the instance. Both the core count and threads per core must be specified in the request.</p>"
    },
    "LaunchTemplateEbsBlockDevice":{
      "type":"structure",
      "members":{
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the EBS volume is encrypted.</p>",
          "locationName":"encrypted"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the EBS volume is deleted on instance termination.</p>",
          "locationName":"deleteOnTermination"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The number of I/O operations per second (IOPS) that the volume supports. </p>",
          "locationName":"iops"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The ARN of the Key Management Service (KMS) CMK used for encryption.</p>",
          "locationName":"kmsKeyId"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiB.</p>",
          "locationName":"volumeSize"
        },
        "VolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The volume type.</p>",
          "locationName":"volumeType"
        },
        "Throughput":{
          "shape":"Integer",
          "documentation":"<p>The throughput that the volume supports, in MiB/s.</p>",
          "locationName":"throughput"
        }
      },
      "documentation":"<p>Describes a block device for an EBS volume.</p>"
    },
    "LaunchTemplateEbsBlockDeviceRequest":{
      "type":"structure",
      "members":{
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the EBS volume is encrypted. Encrypted volumes can only be attached to instances that support Amazon EBS encryption. If you are creating a volume from a snapshot, you can't specify an encryption value.</p>"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the EBS volume is deleted on instance termination.</p>"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The number of I/O operations per second (IOPS). For <code>gp3</code>, <code>io1</code>, and <code>io2</code> volumes, this represents the number of IOPS that are provisioned for the volume. For <code>gp2</code> volumes, this represents the baseline performance of the volume and the rate at which the volume accumulates I/O credits for bursting.</p> <p>The following are the supported values for each volume type:</p> <ul> <li> <p> <code>gp3</code>: 3,000-16,000 IOPS</p> </li> <li> <p> <code>io1</code>: 100-64,000 IOPS</p> </li> <li> <p> <code>io2</code>: 100-64,000 IOPS</p> </li> </ul> <p>For <code>io1</code> and <code>io2</code> volumes, we guarantee 64,000 IOPS only for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">Instances built on the Nitro System</a>. Other instance families guarantee performance up to 32,000 IOPS.</p> <p>This parameter is supported for <code>io1</code>, <code>io2</code>, and <code>gp3</code> volumes only. This parameter is not supported for <code>gp2</code>, <code>st1</code>, <code>sc1</code>, or <code>standard</code> volumes.</p>"
        },
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The ARN of the symmetric Key Management Service (KMS) CMK used for encryption.</p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiBs. You must specify either a snapshot ID or a volume size. The following are the supported volumes sizes for each volume type:</p> <ul> <li> <p> <code>gp2</code> and <code>gp3</code>: 1-16,384</p> </li> <li> <p> <code>io1</code> and <code>io2</code>: 4-16,384</p> </li> <li> <p> <code>st1</code> and <code>sc1</code>: 125-16,384</p> </li> <li> <p> <code>standard</code>: 1-1,024</p> </li> </ul>"
        },
        "VolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The volume type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html\">Amazon EBS volume types</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "Throughput":{
          "shape":"Integer",
          "documentation":"<p>The throughput to provision for a <code>gp3</code> volume, with a maximum of 1,000 MiB/s.</p> <p>Valid Range: Minimum value of 125. Maximum value of 1000.</p>"
        }
      },
      "documentation":"<p>The parameters for a block device for an EBS volume.</p>"
    },
    "LaunchTemplateElasticInferenceAccelerator":{
      "type":"structure",
      "required":["Type"],
      "members":{
        "Type":{
          "shape":"String",
          "documentation":"<p> The type of elastic inference accelerator. The possible values are eia1.medium, eia1.large, and eia1.xlarge. </p>"
        },
        "Count":{
          "shape":"LaunchTemplateElasticInferenceAcceleratorCount",
          "documentation":"<p> The number of elastic inference accelerators to attach to the instance. </p> <p>Default: 1</p>"
        }
      },
      "documentation":"<p> Describes an elastic inference accelerator. </p>"
    },
    "LaunchTemplateElasticInferenceAcceleratorCount":{
      "type":"integer",
      "min":1
    },
    "LaunchTemplateElasticInferenceAcceleratorList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateElasticInferenceAccelerator",
        "locationName":"item"
      }
    },
    "LaunchTemplateElasticInferenceAcceleratorResponse":{
      "type":"structure",
      "members":{
        "Type":{
          "shape":"String",
          "documentation":"<p> The type of elastic inference accelerator. The possible values are eia1.medium, eia1.large, and eia1.xlarge. </p>",
          "locationName":"type"
        },
        "Count":{
          "shape":"Integer",
          "documentation":"<p> The number of elastic inference accelerators to attach to the instance. </p> <p>Default: 1</p>",
          "locationName":"count"
        }
      },
      "documentation":"<p> Describes an elastic inference accelerator. </p>"
    },
    "LaunchTemplateElasticInferenceAcceleratorResponseList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateElasticInferenceAcceleratorResponse",
        "locationName":"item"
      }
    },
    "LaunchTemplateEnclaveOptions":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>If this parameter is set to <code>true</code>, the instance is enabled for Amazon Web Services Nitro Enclaves; otherwise, it is not enabled for Amazon Web Services Nitro Enclaves.</p>",
          "locationName":"enabled"
        }
      },
      "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves.</p>"
    },
    "LaunchTemplateEnclaveOptionsRequest":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>To enable the instance for Amazon Web Services Nitro Enclaves, set this parameter to <code>true</code>.</p>"
        }
      },
      "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves. For more information, see <a href=\"https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html\">What is Amazon Web Services Nitro Enclaves?</a> in the <i>Amazon Web Services Nitro Enclaves User Guide</i>.</p>"
    },
    "LaunchTemplateErrorCode":{
      "type":"string",
      "enum":[
        "launchTemplateIdDoesNotExist",
        "launchTemplateIdMalformed",
        "launchTemplateNameDoesNotExist",
        "launchTemplateNameMalformed",
        "launchTemplateVersionDoesNotExist",
        "unexpectedError"
      ]
    },
    "LaunchTemplateHibernationOptions":{
      "type":"structure",
      "members":{
        "Configured":{
          "shape":"Boolean",
          "documentation":"<p>If this parameter is set to <code>true</code>, the instance is enabled for hibernation; otherwise, it is not enabled for hibernation.</p>",
          "locationName":"configured"
        }
      },
      "documentation":"<p>Indicates whether an instance is configured for hibernation.</p>"
    },
    "LaunchTemplateHibernationOptionsRequest":{
      "type":"structure",
      "members":{
        "Configured":{
          "shape":"Boolean",
          "documentation":"<p>If you set this parameter to <code>true</code>, the instance is enabled for hibernation.</p> <p>Default: <code>false</code> </p>"
        }
      },
      "documentation":"<p>Indicates whether the instance is configured for hibernation. This parameter is valid only if the instance meets the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/hibernating-prerequisites.html\">hibernation prerequisites</a>.</p>"
    },
    "LaunchTemplateHttpTokensState":{
      "type":"string",
      "enum":[
        "optional",
        "required"
      ]
    },
    "LaunchTemplateIamInstanceProfileSpecification":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the instance profile.</p>",
          "locationName":"arn"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the instance profile.</p>",
          "locationName":"name"
        }
      },
      "documentation":"<p>Describes an IAM instance profile.</p>"
    },
    "LaunchTemplateIamInstanceProfileSpecificationRequest":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the instance profile.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the instance profile.</p>"
        }
      },
      "documentation":"<p>An IAM instance profile.</p>"
    },
    "LaunchTemplateId":{"type":"string"},
    "LaunchTemplateIdStringList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateId",
        "locationName":"item"
      }
    },
    "LaunchTemplateInstanceMaintenanceOptions":{
      "type":"structure",
      "members":{
        "AutoRecovery":{
          "shape":"LaunchTemplateAutoRecoveryState",
          "documentation":"<p>Disables the automatic recovery behavior of your instance or sets it to default.</p>",
          "locationName":"autoRecovery"
        }
      },
      "documentation":"<p>The maintenance options of your instance.</p>"
    },
    "LaunchTemplateInstanceMaintenanceOptionsRequest":{
      "type":"structure",
      "members":{
        "AutoRecovery":{
          "shape":"LaunchTemplateAutoRecoveryState",
          "documentation":"<p>Disables the automatic recovery behavior of your instance or sets it to default. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-recover.html#instance-configuration-recovery\">Simplified automatic recovery</a>.</p>"
        }
      },
      "documentation":"<p>The maintenance options of your instance.</p>"
    },
    "LaunchTemplateInstanceMarketOptions":{
      "type":"structure",
      "members":{
        "MarketType":{
          "shape":"MarketType",
          "documentation":"<p>The market type.</p>",
          "locationName":"marketType"
        },
        "SpotOptions":{
          "shape":"LaunchTemplateSpotMarketOptions",
          "documentation":"<p>The options for Spot Instances.</p>",
          "locationName":"spotOptions"
        }
      },
      "documentation":"<p>The market (purchasing) option for the instances.</p>"
    },
    "LaunchTemplateInstanceMarketOptionsRequest":{
      "type":"structure",
      "members":{
        "MarketType":{
          "shape":"MarketType",
          "documentation":"<p>The market type.</p>"
        },
        "SpotOptions":{
          "shape":"LaunchTemplateSpotMarketOptionsRequest",
          "documentation":"<p>The options for Spot Instances.</p>"
        }
      },
      "documentation":"<p>The market (purchasing) option for the instances.</p>"
    },
    "LaunchTemplateInstanceMetadataEndpointState":{
      "type":"string",
      "enum":[
        "disabled",
        "enabled"
      ]
    },
    "LaunchTemplateInstanceMetadataOptions":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"LaunchTemplateInstanceMetadataOptionsState",
          "documentation":"<p>The state of the metadata option changes.</p> <p> <code>pending</code> - The metadata options are being updated and the instance is not ready to process metadata traffic with the new selection.</p> <p> <code>applied</code> - The metadata options have been successfully applied on the instance.</p>",
          "locationName":"state"
        },
        "HttpTokens":{
          "shape":"LaunchTemplateHttpTokensState",
          "documentation":"<p>Indicates whether IMDSv2 is <code>optional</code> or <code>required</code>.</p> <p> <code>optional</code> - When IMDSv2 is optional, you can choose to retrieve instance metadata with or without a session token in your request. If you retrieve the IAM role credentials without a token, the IMDSv1 role credentials are returned. If you retrieve the IAM role credentials using a valid session token, the IMDSv2 role credentials are returned.</p> <p> <code>required</code> - When IMDSv2 is required, you must send a session token with any instance metadata retrieval requests. In this state, retrieving the IAM role credentials always returns IMDSv2 credentials; IMDSv1 credentials are not available.</p> <p>Default: <code>optional</code> </p>",
          "locationName":"httpTokens"
        },
        "HttpPutResponseHopLimit":{
          "shape":"Integer",
          "documentation":"<p>The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel.</p> <p>Default: 1</p> <p>Possible values: Integers from 1 to 64</p>",
          "locationName":"httpPutResponseHopLimit"
        },
        "HttpEndpoint":{
          "shape":"LaunchTemplateInstanceMetadataEndpointState",
          "documentation":"<p>Enables or disables the HTTP metadata endpoint on your instances. If the parameter is not specified, the default state is <code>enabled</code>.</p> <note> <p>If you specify a value of <code>disabled</code>, you will not be able to access your instance metadata. </p> </note>",
          "locationName":"httpEndpoint"
        },
        "HttpProtocolIpv6":{
          "shape":"LaunchTemplateInstanceMetadataProtocolIpv6",
          "documentation":"<p>Enables or disables the IPv6 endpoint for the instance metadata service.</p> <p>Default: <code>disabled</code> </p>",
          "locationName":"httpProtocolIpv6"
        },
        "InstanceMetadataTags":{
          "shape":"LaunchTemplateInstanceMetadataTagsState",
          "documentation":"<p>Set to <code>enabled</code> to allow access to instance tags from the instance metadata. Set to <code>disabled</code> to turn off access to instance tags from the instance metadata. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#work-with-tags-in-IMDS\">Work with instance tags using the instance metadata</a>.</p> <p>Default: <code>disabled</code> </p>",
          "locationName":"instanceMetadataTags"
        }
      },
      "documentation":"<p>The metadata options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">Instance metadata and user data</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "LaunchTemplateInstanceMetadataOptionsRequest":{
      "type":"structure",
      "members":{
        "HttpTokens":{
          "shape":"LaunchTemplateHttpTokensState",
          "documentation":"<p>IMDSv2 uses token-backed sessions. Set the use of HTTP tokens to <code>optional</code> (in other words, set the use of IMDSv2 to <code>optional</code>) or <code>required</code> (in other words, set the use of IMDSv2 to <code>required</code>).</p> <ul> <li> <p> <code>optional</code> - When IMDSv2 is optional, you can choose to retrieve instance metadata with or without a session token in your request. If you retrieve the IAM role credentials without a token, the IMDSv1 role credentials are returned. If you retrieve the IAM role credentials using a valid session token, the IMDSv2 role credentials are returned.</p> </li> <li> <p> <code>required</code> - When IMDSv2 is required, you must send a session token with any instance metadata retrieval requests. In this state, retrieving the IAM role credentials always returns IMDSv2 credentials; IMDSv1 credentials are not available.</p> </li> </ul> <p>Default: <code>optional</code> </p>"
        },
        "HttpPutResponseHopLimit":{
          "shape":"Integer",
          "documentation":"<p>The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel.</p> <p>Default: <code>1</code> </p> <p>Possible values: Integers from 1 to 64</p>"
        },
        "HttpEndpoint":{
          "shape":"LaunchTemplateInstanceMetadataEndpointState",
          "documentation":"<p>Enables or disables the HTTP metadata endpoint on your instances. If the parameter is not specified, the default state is <code>enabled</code>.</p> <note> <p>If you specify a value of <code>disabled</code>, you will not be able to access your instance metadata. </p> </note>"
        },
        "HttpProtocolIpv6":{
          "shape":"LaunchTemplateInstanceMetadataProtocolIpv6",
          "documentation":"<p>Enables or disables the IPv6 endpoint for the instance metadata service.</p> <p>Default: <code>disabled</code> </p>"
        },
        "InstanceMetadataTags":{
          "shape":"LaunchTemplateInstanceMetadataTagsState",
          "documentation":"<p>Set to <code>enabled</code> to allow access to instance tags from the instance metadata. Set to <code>disabled</code> to turn off access to instance tags from the instance metadata. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#work-with-tags-in-IMDS\">Work with instance tags using the instance metadata</a>.</p> <p>Default: <code>disabled</code> </p>"
        }
      },
      "documentation":"<p>The metadata options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">Instance metadata and user data</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
    },
    "LaunchTemplateInstanceMetadataOptionsState":{
      "type":"string",
      "enum":[
        "pending",
        "applied"
      ]
    },
    "LaunchTemplateInstanceMetadataProtocolIpv6":{
      "type":"string",
      "enum":[
        "disabled",
        "enabled"
      ]
    },
    "LaunchTemplateInstanceMetadataTagsState":{
      "type":"string",
      "enum":[
        "disabled",
        "enabled"
      ]
    },
    "LaunchTemplateInstanceNetworkInterfaceSpecification":{
      "type":"structure",
      "members":{
        "AssociateCarrierIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to associate a Carrier IP address with eth0 for a new network interface.</p> <p>Use this option when you launch an instance in a Wavelength Zone and want to associate a Carrier IP address with the network interface. For more information about Carrier IP addresses, see <a href=\"https://docs.aws.amazon.com/wavelength/latest/developerguide/how-wavelengths-work.html#provider-owned-ip\">Carrier IP addresses</a> in the <i>Wavelength Developer Guide</i>.</p>",
          "locationName":"associateCarrierIpAddress"
        },
        "AssociatePublicIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to associate a public IPv4 address with eth0 for a new network interface.</p>",
          "locationName":"associatePublicIpAddress"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the network interface is deleted when the instance is terminated.</p>",
          "locationName":"deleteOnTermination"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the network interface.</p>",
          "locationName":"description"
        },
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The device index for the network interface attachment.</p>",
          "locationName":"deviceIndex"
        },
        "Groups":{
          "shape":"GroupIdStringList",
          "documentation":"<p>The IDs of one or more security groups.</p>",
          "locationName":"groupSet"
        },
        "InterfaceType":{
          "shape":"String",
          "documentation":"<p>The type of network interface.</p>",
          "locationName":"interfaceType"
        },
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 addresses for the network interface.</p>",
          "locationName":"ipv6AddressCount"
        },
        "Ipv6Addresses":{
          "shape":"InstanceIpv6AddressList",
          "documentation":"<p>The IPv6 addresses for the network interface.</p>",
          "locationName":"ipv6AddressesSet"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The primary private IPv4 address of the network interface.</p>",
          "locationName":"privateIpAddress"
        },
        "PrivateIpAddresses":{
          "shape":"PrivateIpAddressSpecificationList",
          "documentation":"<p>One or more private IPv4 addresses.</p>",
          "locationName":"privateIpAddressesSet"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of secondary private IPv4 addresses for the network interface.</p>",
          "locationName":"secondaryPrivateIpAddressCount"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet for the network interface.</p>",
          "locationName":"subnetId"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card.</p>",
          "locationName":"networkCardIndex"
        },
        "Ipv4Prefixes":{
          "shape":"Ipv4PrefixListResponse",
          "documentation":"<p>One or more IPv4 prefixes assigned to the network interface.</p>",
          "locationName":"ipv4PrefixSet"
        },
        "Ipv4PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv4 prefixes that Amazon Web Services automatically assigned to the network interface.</p>",
          "locationName":"ipv4PrefixCount"
        },
        "Ipv6Prefixes":{
          "shape":"Ipv6PrefixListResponse",
          "documentation":"<p>One or more IPv6 prefixes assigned to the network interface.</p>",
          "locationName":"ipv6PrefixSet"
        },
        "Ipv6PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 prefixes that Amazon Web Services automatically assigned to the network interface.</p>",
          "locationName":"ipv6PrefixCount"
        }
      },
      "documentation":"<p>Describes a network interface.</p>"
    },
    "LaunchTemplateInstanceNetworkInterfaceSpecificationList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateInstanceNetworkInterfaceSpecification",
        "locationName":"item"
      }
    },
    "LaunchTemplateInstanceNetworkInterfaceSpecificationRequest":{
      "type":"structure",
      "members":{
        "AssociateCarrierIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Associates a Carrier IP address with eth0 for a new network interface.</p> <p>Use this option when you launch an instance in a Wavelength Zone and want to associate a Carrier IP address with the network interface. For more information about Carrier IP addresses, see <a href=\"https://docs.aws.amazon.com/wavelength/latest/developerguide/how-wavelengths-work.html#provider-owned-ip\">Carrier IP addresses</a> in the <i>Wavelength Developer Guide</i>.</p>"
        },
        "AssociatePublicIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Associates a public IPv4 address with eth0 for a new network interface.</p>"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the network interface is deleted when the instance is terminated.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the network interface.</p>"
        },
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The device index for the network interface attachment.</p>"
        },
        "Groups":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>The IDs of one or more security groups.</p>",
          "locationName":"SecurityGroupId"
        },
        "InterfaceType":{
          "shape":"String",
          "documentation":"<p>The type of network interface. To create an Elastic Fabric Adapter (EFA), specify <code>efa</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/efa.html\">Elastic Fabric Adapter</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>If you are not creating an EFA, specify <code>interface</code> or omit this parameter.</p> <p>Valid values: <code>interface</code> | <code>efa</code> </p>"
        },
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 addresses to assign to a network interface. Amazon EC2 automatically selects the IPv6 addresses from the subnet range. You can't use this option if specifying specific IPv6 addresses.</p>"
        },
        "Ipv6Addresses":{
          "shape":"InstanceIpv6AddressListRequest",
          "documentation":"<p>One or more specific IPv6 addresses from the IPv6 CIDR block range of your subnet. You can't use this option if you're specifying a number of IPv6 addresses.</p>"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The primary private IPv4 address of the network interface.</p>"
        },
        "PrivateIpAddresses":{
          "shape":"PrivateIpAddressSpecificationList",
          "documentation":"<p>One or more private IPv4 addresses.</p>"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of secondary private IPv4 addresses to assign to a network interface.</p>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet for the network interface.</p>"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card. Some instance types support multiple network cards. The primary network interface must be assigned to network card index 0. The default is network card index 0.</p>"
        },
        "Ipv4Prefixes":{
          "shape":"Ipv4PrefixList",
          "documentation":"<p>One or more IPv4 prefixes to be assigned to the network interface. You cannot use this option if you use the <code>Ipv4PrefixCount</code> option.</p>",
          "locationName":"Ipv4Prefix"
        },
        "Ipv4PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv4 prefixes to be automatically assigned to the network interface. You cannot use this option if you use the <code>Ipv4Prefix</code> option.</p>"
        },
        "Ipv6Prefixes":{
          "shape":"Ipv6PrefixList",
          "documentation":"<p>One or more IPv6 prefixes to be assigned to the network interface. You cannot use this option if you use the <code>Ipv6PrefixCount</code> option.</p>",
          "locationName":"Ipv6Prefix"
        },
        "Ipv6PrefixCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 prefixes to be automatically assigned to the network interface. You cannot use this option if you use the <code>Ipv6Prefix</code> option.</p>"
        }
      },
      "documentation":"<p>The parameters for a network interface.</p>"
    },
    "LaunchTemplateInstanceNetworkInterfaceSpecificationRequestList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateInstanceNetworkInterfaceSpecificationRequest",
        "locationName":"InstanceNetworkInterfaceSpecification"
      }
    },
    "LaunchTemplateLicenseConfiguration":{
      "type":"structure",
      "members":{
        "LicenseConfigurationArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the license configuration.</p>",
          "locationName":"licenseConfigurationArn"
        }
      },
      "documentation":"<p>Describes a license configuration.</p>"
    },
    "LaunchTemplateLicenseConfigurationRequest":{
      "type":"structure",
      "members":{
        "LicenseConfigurationArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the license configuration.</p>"
        }
      },
      "documentation":"<p>Describes a license configuration.</p>"
    },
    "LaunchTemplateLicenseList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateLicenseConfiguration",
        "locationName":"item"
      }
    },
    "LaunchTemplateLicenseSpecificationListRequest":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateLicenseConfigurationRequest",
        "locationName":"item"
      }
    },
    "LaunchTemplateName":{
      "type":"string",
      "max":128,
      "min":3,
      "pattern":"[a-zA-Z0-9\\(\\)\\.\\-/_]+"
    },
    "LaunchTemplateNameStringList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateName",
        "locationName":"item"
      }
    },
    "LaunchTemplateOverrides":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "SpotPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"spotPrice"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet in which to launch the instances.</p>",
          "locationName":"subnetId"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which to launch the instances.</p>",
          "locationName":"availabilityZone"
        },
        "WeightedCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units provided by the specified instance type.</p>",
          "locationName":"weightedCapacity"
        },
        "Priority":{
          "shape":"Double",
          "documentation":"<p>The priority for the launch template override. The highest priority is launched first.</p> <p>If <code>OnDemandAllocationStrategy</code> is set to <code>prioritized</code>, Spot Fleet uses priority to determine which launch template override to use first in fulfilling On-Demand capacity.</p> <p>If the Spot <code>AllocationStrategy</code> is set to <code>capacityOptimizedPrioritized</code>, Spot Fleet uses priority on a best-effort basis to determine which launch template override to use in fulfilling Spot capacity, but optimizes for capacity first.</p> <p>Valid values are whole numbers starting at <code>0</code>. The lower the number, the higher the priority. If no number is set, the launch template override has the lowest priority. You can set the same priority for different launch template overrides.</p>",
          "locationName":"priority"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirements",
          "documentation":"<p>The instance requirements. When you specify instance requirements, Amazon EC2 will identify instance types with the provided requirements, and then use your On-Demand and Spot allocation strategies to launch instances from these instance types, in the same way as when you specify a list of instance types.</p> <note> <p>If you specify <code>InstanceRequirements</code>, you can't specify <code>InstanceType</code>.</p> </note>",
          "locationName":"instanceRequirements"
        }
      },
      "documentation":"<p>Describes overrides for a launch template.</p>"
    },
    "LaunchTemplateOverridesList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateOverrides",
        "locationName":"item"
      }
    },
    "LaunchTemplatePlacement":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone of the instance.</p>",
          "locationName":"availabilityZone"
        },
        "Affinity":{
          "shape":"String",
          "documentation":"<p>The affinity setting for the instance on the Dedicated Host.</p>",
          "locationName":"affinity"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the placement group for the instance.</p>",
          "locationName":"groupName"
        },
        "HostId":{
          "shape":"String",
          "documentation":"<p>The ID of the Dedicated Host for the instance.</p>",
          "locationName":"hostId"
        },
        "Tenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instance (if the instance is running in a VPC). An instance with a tenancy of <code>dedicated</code> runs on single-tenant hardware. </p>",
          "locationName":"tenancy"
        },
        "SpreadDomain":{
          "shape":"String",
          "documentation":"<p>Reserved for future use.</p>",
          "locationName":"spreadDomain"
        },
        "HostResourceGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the host resource group in which to launch the instances. </p>",
          "locationName":"hostResourceGroupArn"
        },
        "PartitionNumber":{
          "shape":"Integer",
          "documentation":"<p>The number of the partition the instance should launch in. Valid only if the placement group strategy is set to <code>partition</code>.</p>",
          "locationName":"partitionNumber"
        },
        "GroupId":{
          "shape":"PlacementGroupId",
          "documentation":"<p>The Group ID of the placement group. You must specify the Placement Group <b>Group ID</b> to launch an instance in a shared placement group.</p>",
          "locationName":"groupId"
        }
      },
      "documentation":"<p>Describes the placement of an instance.</p>"
    },
    "LaunchTemplatePlacementRequest":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone for the instance.</p>"
        },
        "Affinity":{
          "shape":"String",
          "documentation":"<p>The affinity setting for an instance on a Dedicated Host.</p>"
        },
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group for the instance.</p>"
        },
        "HostId":{
          "shape":"DedicatedHostId",
          "documentation":"<p>The ID of the Dedicated Host for the instance.</p>"
        },
        "Tenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instance (if the instance is running in a VPC). An instance with a tenancy of dedicated runs on single-tenant hardware.</p>"
        },
        "SpreadDomain":{
          "shape":"String",
          "documentation":"<p>Reserved for future use.</p>"
        },
        "HostResourceGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the host resource group in which to launch the instances. If you specify a host resource group ARN, omit the <b>Tenancy</b> parameter or set it to <code>host</code>.</p>"
        },
        "PartitionNumber":{
          "shape":"Integer",
          "documentation":"<p>The number of the partition the instance should launch in. Valid only if the placement group strategy is set to <code>partition</code>.</p>"
        },
        "GroupId":{
          "shape":"PlacementGroupId",
          "documentation":"<p>The Group Id of a placement group. You must specify the Placement Group <b>Group Id</b> to launch an instance in a shared placement group.</p>"
        }
      },
      "documentation":"<p>Describes the placement of an instance.</p>"
    },
    "LaunchTemplatePrivateDnsNameOptions":{
      "type":"structure",
      "members":{
        "HostnameType":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname to assign to an instance.</p>",
          "locationName":"hostnameType"
        },
        "EnableResourceNameDnsARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>",
          "locationName":"enableResourceNameDnsARecord"
        },
        "EnableResourceNameDnsAAAARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p>",
          "locationName":"enableResourceNameDnsAAAARecord"
        }
      },
      "documentation":"<p>Describes the options for instance hostnames.</p>"
    },
    "LaunchTemplatePrivateDnsNameOptionsRequest":{
      "type":"structure",
      "members":{
        "HostnameType":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname for Amazon EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 native subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID.</p>"
        },
        "EnableResourceNameDnsARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>"
        },
        "EnableResourceNameDnsAAAARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p>"
        }
      },
      "documentation":"<p>Describes the options for instance hostnames.</p>"
    },
    "LaunchTemplateSet":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplate",
        "locationName":"item"
      }
    },
    "LaunchTemplateSpecification":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>"
        },
        "LaunchTemplateName":{
          "shape":"String",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>"
        },
        "Version":{
          "shape":"String",
          "documentation":"<p>The launch template version number, <code>$Latest</code>, or <code>$Default</code>.</p> <p>If the value is <code>$Latest</code>, Amazon EC2 uses the latest version of the launch template.</p> <p>If the value is <code>$Default</code>, Amazon EC2 uses the default version of the launch template.</p> <p>Default: The default version of the launch template.</p>"
        }
      },
      "documentation":"<p>The launch template to use. You must specify either the launch template ID or launch template name in the request, but not both.</p>"
    },
    "LaunchTemplateSpotMarketOptions":{
      "type":"structure",
      "members":{
        "MaxPrice":{
          "shape":"String",
          "documentation":"<p>The maximum hourly price you're willing to pay for the Spot Instances. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your Spot Instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"maxPrice"
        },
        "SpotInstanceType":{
          "shape":"SpotInstanceType",
          "documentation":"<p>The Spot Instance request type.</p>",
          "locationName":"spotInstanceType"
        },
        "BlockDurationMinutes":{
          "shape":"Integer",
          "documentation":"<p>The required duration for the Spot Instances (also known as Spot blocks), in minutes. This value must be a multiple of 60 (60, 120, 180, 240, 300, or 360).</p>",
          "locationName":"blockDurationMinutes"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date of the request. For a one-time request, the request remains active until all instances launch, the request is canceled, or this date is reached. If the request is persistent, it remains active until it is canceled or this date and time is reached.</p>",
          "locationName":"validUntil"
        },
        "InstanceInterruptionBehavior":{
          "shape":"InstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted.</p>",
          "locationName":"instanceInterruptionBehavior"
        }
      },
      "documentation":"<p>The options for Spot Instances.</p>"
    },
    "LaunchTemplateSpotMarketOptionsRequest":{
      "type":"structure",
      "members":{
        "MaxPrice":{
          "shape":"String",
          "documentation":"<p>The maximum hourly price you're willing to pay for the Spot Instances. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your Spot Instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>"
        },
        "SpotInstanceType":{
          "shape":"SpotInstanceType",
          "documentation":"<p>The Spot Instance request type.</p>"
        },
        "BlockDurationMinutes":{
          "shape":"Integer",
          "documentation":"<p>Deprecated.</p>"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date of the request, in UTC format (<i>YYYY-MM-DD</i>T<i>HH:MM:SS</i>Z). Supported only for persistent requests.</p> <ul> <li> <p>For a persistent request, the request remains active until the <code>ValidUntil</code> date and time is reached. Otherwise, the request remains active until you cancel it.</p> </li> <li> <p>For a one-time request, <code>ValidUntil</code> is not supported. The request remains active until all instances launch or you cancel the request.</p> </li> </ul> <p>Default: 7 days from the current date</p>"
        },
        "InstanceInterruptionBehavior":{
          "shape":"InstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted. The default is <code>terminate</code>.</p>"
        }
      },
      "documentation":"<p>The options for Spot Instances.</p>"
    },
    "LaunchTemplateTagSpecification":{
      "type":"structure",
      "members":{
        "ResourceType":{
          "shape":"ResourceType",
          "documentation":"<p>The type of resource to tag.</p>",
          "locationName":"resourceType"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the resource.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>The tags specification for the launch template.</p>"
    },
    "LaunchTemplateTagSpecificationList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateTagSpecification",
        "locationName":"item"
      }
    },
    "LaunchTemplateTagSpecificationRequest":{
      "type":"structure",
      "members":{
        "ResourceType":{
          "shape":"ResourceType",
          "documentation":"<p>The type of resource to tag.</p> <p>The <code>Valid Values</code> are all the resource types that can be tagged. However, when creating a launch template, you can specify tags for the following resource types only: <code>instance</code> | <code>volume</code> | <code>elastic-gpu</code> | <code>network-interface</code> | <code>spot-instances-request</code> </p> <p>To tag a resource after it has been created, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html\">CreateTags</a>.</p>"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags to apply to the resource.</p>",
          "locationName":"Tag"
        }
      },
      "documentation":"<p>The tags specification for the resources that are created during instance launch.</p>"
    },
    "LaunchTemplateTagSpecificationRequestList":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateTagSpecificationRequest",
        "locationName":"LaunchTemplateTagSpecificationRequest"
      }
    },
    "LaunchTemplateVersion":{
      "type":"structure",
      "members":{
        "LaunchTemplateId":{
          "shape":"String",
          "documentation":"<p>The ID of the launch template.</p>",
          "locationName":"launchTemplateId"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p>",
          "locationName":"launchTemplateName"
        },
        "VersionNumber":{
          "shape":"Long",
          "documentation":"<p>The version number.</p>",
          "locationName":"versionNumber"
        },
        "VersionDescription":{
          "shape":"VersionDescription",
          "documentation":"<p>The description for the version.</p>",
          "locationName":"versionDescription"
        },
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The time the version was created.</p>",
          "locationName":"createTime"
        },
        "CreatedBy":{
          "shape":"String",
          "documentation":"<p>The principal that created the version.</p>",
          "locationName":"createdBy"
        },
        "DefaultVersion":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the version is the default version.</p>",
          "locationName":"defaultVersion"
        },
        "LaunchTemplateData":{
          "shape":"ResponseLaunchTemplateData",
          "documentation":"<p>Information about the launch template.</p>",
          "locationName":"launchTemplateData"
        }
      },
      "documentation":"<p>Describes a launch template version.</p>"
    },
    "LaunchTemplateVersionSet":{
      "type":"list",
      "member":{
        "shape":"LaunchTemplateVersion",
        "locationName":"item"
      }
    },
    "LaunchTemplatesMonitoring":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether detailed monitoring is enabled. Otherwise, basic monitoring is enabled.</p>",
          "locationName":"enabled"
        }
      },
      "documentation":"<p>Describes the monitoring for the instance.</p>"
    },
    "LaunchTemplatesMonitoringRequest":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Specify <code>true</code> to enable detailed monitoring. Otherwise, basic monitoring is enabled.</p>"
        }
      },
      "documentation":"<p>Describes the monitoring for the instance.</p>"
    },
    "LicenseConfiguration":{
      "type":"structure",
      "members":{
        "LicenseConfigurationArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the license configuration.</p>",
          "locationName":"licenseConfigurationArn"
        }
      },
      "documentation":"<p>Describes a license configuration.</p>"
    },
    "LicenseConfigurationRequest":{
      "type":"structure",
      "members":{
        "LicenseConfigurationArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the license configuration.</p>"
        }
      },
      "documentation":"<p>Describes a license configuration.</p>"
    },
    "LicenseList":{
      "type":"list",
      "member":{
        "shape":"LicenseConfiguration",
        "locationName":"item"
      }
    },
    "LicenseSpecificationListRequest":{
      "type":"list",
      "member":{
        "shape":"LicenseConfigurationRequest",
        "locationName":"item"
      }
    },
    "ListImagesInRecycleBinMaxResults":{
      "type":"integer",
      "max":1000,
      "min":1
    },
    "ListImagesInRecycleBinRequest":{
      "type":"structure",
      "members":{
        "ImageIds":{
          "shape":"ImageIdStringList",
          "documentation":"<p>The IDs of the AMIs to list. Omit this parameter to list all of the AMIs that are in the Recycle Bin. You can specify up to 20 IDs in a single request.</p>",
          "locationName":"ImageId"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "MaxResults":{
          "shape":"ListImagesInRecycleBinMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p> <p>If you do not specify a value for <i>MaxResults</i>, the request returns 1,000 items per page by default. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\"> Pagination</a>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ListImagesInRecycleBinResult":{
      "type":"structure",
      "members":{
        "Images":{
          "shape":"ImageRecycleBinInfoList",
          "documentation":"<p>Information about the AMIs.</p>",
          "locationName":"imageSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "ListSnapshotsInRecycleBinMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "ListSnapshotsInRecycleBinRequest":{
      "type":"structure",
      "members":{
        "MaxResults":{
          "shape":"ListSnapshotsInRecycleBinMaxResults",
          "documentation":"<p>The maximum number of items to return for this request. To get the next page of items, make another request with the token returned in the output. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Query-Requests.html#api-pagination\">Pagination</a>.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token returned from a previous paginated request. Pagination continues from the end of the items returned by the previous request.</p>"
        },
        "SnapshotIds":{
          "shape":"SnapshotIdStringList",
          "documentation":"<p>The IDs of the snapshots to list. Omit this parameter to list all of the snapshots that are in the Recycle Bin.</p>",
          "locationName":"SnapshotId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ListSnapshotsInRecycleBinResult":{
      "type":"structure",
      "members":{
        "Snapshots":{
          "shape":"SnapshotRecycleBinInfoList",
          "documentation":"<p>Information about the snapshots.</p>",
          "locationName":"snapshotSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to include in another request to get the next page of items. This value is <code>null</code> when there are no more items to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "ListingState":{
      "type":"string",
      "enum":[
        "available",
        "sold",
        "cancelled",
        "pending"
      ]
    },
    "ListingStatus":{
      "type":"string",
      "enum":[
        "active",
        "pending",
        "cancelled",
        "closed"
      ]
    },
    "LoadBalancerArn":{"type":"string"},
    "LoadBalancersConfig":{
      "type":"structure",
      "members":{
        "ClassicLoadBalancersConfig":{
          "shape":"ClassicLoadBalancersConfig",
          "documentation":"<p>The Classic Load Balancers.</p>",
          "locationName":"classicLoadBalancersConfig"
        },
        "TargetGroupsConfig":{
          "shape":"TargetGroupsConfig",
          "documentation":"<p>The target groups.</p>",
          "locationName":"targetGroupsConfig"
        }
      },
      "documentation":"<p>Describes the Classic Load Balancers and target groups to attach to a Spot Fleet request.</p>"
    },
    "LoadPermission":{
      "type":"structure",
      "members":{
        "UserId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p>",
          "locationName":"userId"
        },
        "Group":{
          "shape":"PermissionGroup",
          "documentation":"<p>The name of the group.</p>",
          "locationName":"group"
        }
      },
      "documentation":"<p>Describes a load permission.</p>"
    },
    "LoadPermissionList":{
      "type":"list",
      "member":{
        "shape":"LoadPermission",
        "locationName":"item"
      }
    },
    "LoadPermissionListRequest":{
      "type":"list",
      "member":{
        "shape":"LoadPermissionRequest",
        "locationName":"item"
      }
    },
    "LoadPermissionModifications":{
      "type":"structure",
      "members":{
        "Add":{
          "shape":"LoadPermissionListRequest",
          "documentation":"<p>The load permissions to add.</p>"
        },
        "Remove":{
          "shape":"LoadPermissionListRequest",
          "documentation":"<p>The load permissions to remove.</p>"
        }
      },
      "documentation":"<p>Describes modifications to the load permissions of an Amazon FPGA image (AFI).</p>"
    },
    "LoadPermissionRequest":{
      "type":"structure",
      "members":{
        "Group":{
          "shape":"PermissionGroup",
          "documentation":"<p>The name of the group.</p>"
        },
        "UserId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p>"
        }
      },
      "documentation":"<p>Describes a load permission.</p>"
    },
    "LocalGateway":{
      "type":"structure",
      "members":{
        "LocalGatewayId":{
          "shape":"LocalGatewayId",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state of the local gateway.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the local gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a local gateway.</p>"
    },
    "LocalGatewayId":{"type":"string"},
    "LocalGatewayIdSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayId",
        "locationName":"item"
      }
    },
    "LocalGatewayMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "LocalGatewayRoute":{
      "type":"structure",
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR block used for destination matches.</p>",
          "locationName":"destinationCidrBlock"
        },
        "LocalGatewayVirtualInterfaceGroupId":{
          "shape":"LocalGatewayVirtualInterfaceGroupId",
          "documentation":"<p>The ID of the virtual interface group.</p>",
          "locationName":"localGatewayVirtualInterfaceGroupId"
        },
        "Type":{
          "shape":"LocalGatewayRouteType",
          "documentation":"<p>The route type.</p>",
          "locationName":"type"
        },
        "State":{
          "shape":"LocalGatewayRouteState",
          "documentation":"<p>The state of the route.</p>",
          "locationName":"state"
        },
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableId"
        },
        "LocalGatewayRouteTableArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway route.</p>",
          "locationName":"ownerId"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "CoipPoolId":{
          "shape":"CoipPoolId",
          "documentation":"<p>The ID of the customer-owned address pool.</p>",
          "locationName":"coipPoolId"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p> The ID of the prefix list. </p>",
          "locationName":"destinationPrefixListId"
        }
      },
      "documentation":"<p>Describes a route for a local gateway route table.</p>"
    },
    "LocalGatewayRouteList":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRoute",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteState":{
      "type":"string",
      "enum":[
        "pending",
        "active",
        "blackhole",
        "deleting",
        "deleted"
      ]
    },
    "LocalGatewayRouteTable":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableId"
        },
        "LocalGatewayRouteTableArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableArn"
        },
        "LocalGatewayId":{
          "shape":"LocalGatewayId",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway route table.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state of the local gateway route table.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the local gateway route table.</p>",
          "locationName":"tagSet"
        },
        "Mode":{
          "shape":"LocalGatewayRouteTableMode",
          "documentation":"<p>The mode of the local gateway route table.</p>",
          "locationName":"mode"
        },
        "StateReason":{
          "shape":"StateReason",
          "documentation":"<p>Information about the state change.</p>",
          "locationName":"stateReason"
        }
      },
      "documentation":"<p>Describes a local gateway route table.</p>"
    },
    "LocalGatewayRouteTableIdSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRoutetableId",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteTableMode":{
      "type":"string",
      "enum":[
        "direct-vpc-routing",
        "coip"
      ]
    },
    "LocalGatewayRouteTableSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRouteTable",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteTableVirtualInterfaceGroupAssociation":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVirtualInterfaceGroupAssociationId":{
          "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociationId",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"localGatewayRouteTableVirtualInterfaceGroupAssociationId"
        },
        "LocalGatewayVirtualInterfaceGroupId":{
          "shape":"LocalGatewayVirtualInterfaceGroupId",
          "documentation":"<p>The ID of the virtual interface group.</p>",
          "locationName":"localGatewayVirtualInterfaceGroupId"
        },
        "LocalGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayId",
          "documentation":"<p>The ID of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableId"
        },
        "LocalGatewayRouteTableArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the local gateway route table for the virtual interface group.</p>",
          "locationName":"localGatewayRouteTableArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway virtual interface group association.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the association.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an association between a local gateway route table and a virtual interface group.</p>"
    },
    "LocalGatewayRouteTableVirtualInterfaceGroupAssociationId":{"type":"string"},
    "LocalGatewayRouteTableVirtualInterfaceGroupAssociationIdSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociationId",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteTableVirtualInterfaceGroupAssociationSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRouteTableVirtualInterfaceGroupAssociation",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteTableVpcAssociation":{
      "type":"structure",
      "members":{
        "LocalGatewayRouteTableVpcAssociationId":{
          "shape":"LocalGatewayRouteTableVpcAssociationId",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"localGatewayRouteTableVpcAssociationId"
        },
        "LocalGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway route table.</p>",
          "locationName":"localGatewayRouteTableId"
        },
        "LocalGatewayRouteTableArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the local gateway route table for the association.</p>",
          "locationName":"localGatewayRouteTableArn"
        },
        "LocalGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway route table for the association.</p>",
          "locationName":"ownerId"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the association.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an association between a local gateway route table and a VPC.</p>"
    },
    "LocalGatewayRouteTableVpcAssociationId":{"type":"string"},
    "LocalGatewayRouteTableVpcAssociationIdSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRouteTableVpcAssociationId",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteTableVpcAssociationSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayRouteTableVpcAssociation",
        "locationName":"item"
      }
    },
    "LocalGatewayRouteType":{
      "type":"string",
      "enum":[
        "static",
        "propagated"
      ]
    },
    "LocalGatewayRoutetableId":{"type":"string"},
    "LocalGatewaySet":{
      "type":"list",
      "member":{
        "shape":"LocalGateway",
        "locationName":"item"
      }
    },
    "LocalGatewayVirtualInterface":{
      "type":"structure",
      "members":{
        "LocalGatewayVirtualInterfaceId":{
          "shape":"LocalGatewayVirtualInterfaceId",
          "documentation":"<p>The ID of the virtual interface.</p>",
          "locationName":"localGatewayVirtualInterfaceId"
        },
        "LocalGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "Vlan":{
          "shape":"Integer",
          "documentation":"<p>The ID of the VLAN.</p>",
          "locationName":"vlan"
        },
        "LocalAddress":{
          "shape":"String",
          "documentation":"<p>The local address.</p>",
          "locationName":"localAddress"
        },
        "PeerAddress":{
          "shape":"String",
          "documentation":"<p>The peer address.</p>",
          "locationName":"peerAddress"
        },
        "LocalBgpAsn":{
          "shape":"Integer",
          "documentation":"<p>The Border Gateway Protocol (BGP) Autonomous System Number (ASN) of the local gateway.</p>",
          "locationName":"localBgpAsn"
        },
        "PeerBgpAsn":{
          "shape":"Integer",
          "documentation":"<p>The peer BGP ASN.</p>",
          "locationName":"peerBgpAsn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway virtual interface.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the virtual interface.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a local gateway virtual interface.</p>"
    },
    "LocalGatewayVirtualInterfaceGroup":{
      "type":"structure",
      "members":{
        "LocalGatewayVirtualInterfaceGroupId":{
          "shape":"LocalGatewayVirtualInterfaceGroupId",
          "documentation":"<p>The ID of the virtual interface group.</p>",
          "locationName":"localGatewayVirtualInterfaceGroupId"
        },
        "LocalGatewayVirtualInterfaceIds":{
          "shape":"LocalGatewayVirtualInterfaceIdSet",
          "documentation":"<p>The IDs of the virtual interfaces.</p>",
          "locationName":"localGatewayVirtualInterfaceIdSet"
        },
        "LocalGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the local gateway virtual interface group.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the virtual interface group.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a local gateway virtual interface group.</p>"
    },
    "LocalGatewayVirtualInterfaceGroupId":{"type":"string"},
    "LocalGatewayVirtualInterfaceGroupIdSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayVirtualInterfaceGroupId",
        "locationName":"item"
      }
    },
    "LocalGatewayVirtualInterfaceGroupSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayVirtualInterfaceGroup",
        "locationName":"item"
      }
    },
    "LocalGatewayVirtualInterfaceId":{"type":"string"},
    "LocalGatewayVirtualInterfaceIdSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayVirtualInterfaceId",
        "locationName":"item"
      }
    },
    "LocalGatewayVirtualInterfaceSet":{
      "type":"list",
      "member":{
        "shape":"LocalGatewayVirtualInterface",
        "locationName":"item"
      }
    },
    "LocalStorage":{
      "type":"string",
      "enum":[
        "included",
        "required",
        "excluded"
      ]
    },
    "LocalStorageType":{
      "type":"string",
      "enum":[
        "hdd",
        "ssd"
      ]
    },
    "LocalStorageTypeSet":{
      "type":"list",
      "member":{
        "shape":"LocalStorageType",
        "locationName":"item"
      }
    },
    "Location":{"type":"string"},
    "LocationType":{
      "type":"string",
      "enum":[
        "region",
        "availability-zone",
        "availability-zone-id"
      ]
    },
    "LogDestinationType":{
      "type":"string",
      "enum":[
        "cloud-watch-logs",
        "s3",
        "kinesis-data-firehose"
      ]
    },
    "Long":{"type":"long"},
    "ManagedPrefixList":{
      "type":"structure",
      "members":{
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>",
          "locationName":"prefixListId"
        },
        "AddressFamily":{
          "shape":"String",
          "documentation":"<p>The IP address version.</p>",
          "locationName":"addressFamily"
        },
        "State":{
          "shape":"PrefixListState",
          "documentation":"<p>The current state of the prefix list.</p>",
          "locationName":"state"
        },
        "StateMessage":{
          "shape":"String",
          "documentation":"<p>The state message.</p>",
          "locationName":"stateMessage"
        },
        "PrefixListArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) for the prefix list.</p>",
          "locationName":"prefixListArn"
        },
        "PrefixListName":{
          "shape":"String",
          "documentation":"<p>The name of the prefix list.</p>",
          "locationName":"prefixListName"
        },
        "MaxEntries":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of entries for the prefix list.</p>",
          "locationName":"maxEntries"
        },
        "Version":{
          "shape":"Long",
          "documentation":"<p>The version of the prefix list.</p>",
          "locationName":"version"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the prefix list.</p>",
          "locationName":"tagSet"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the owner of the prefix list.</p>",
          "locationName":"ownerId"
        }
      },
      "documentation":"<p>Describes a managed prefix list.</p>"
    },
    "ManagedPrefixListSet":{
      "type":"list",
      "member":{
        "shape":"ManagedPrefixList",
        "locationName":"item"
      }
    },
    "MarketType":{
      "type":"string",
      "enum":["spot"]
    },
    "MaxIpv4AddrPerInterface":{"type":"integer"},
    "MaxIpv6AddrPerInterface":{"type":"integer"},
    "MaxNetworkInterfaces":{"type":"integer"},
    "MaxResults":{"type":"integer"},
    "MaxResultsParam":{
      "type":"integer",
      "max":100,
      "min":0
    },
    "MaximumBandwidthInMbps":{"type":"integer"},
    "MaximumEfaInterfaces":{"type":"integer"},
    "MaximumIops":{"type":"integer"},
    "MaximumNetworkCards":{"type":"integer"},
    "MaximumThroughputInMBps":{"type":"double"},
    "MembershipType":{
      "type":"string",
      "enum":[
        "static",
        "igmp"
      ]
    },
    "MemoryGiBPerVCpu":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Double",
          "documentation":"<p>The minimum amount of memory per vCPU, in GiB. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Double",
          "documentation":"<p>The maximum amount of memory per vCPU, in GiB. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum amount of memory per vCPU, in GiB.</p> <p/>"
    },
    "MemoryGiBPerVCpuRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Double",
          "documentation":"<p>The minimum amount of memory per vCPU, in GiB. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Double",
          "documentation":"<p>The maximum amount of memory per vCPU, in GiB. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum amount of memory per vCPU, in GiB.</p>"
    },
    "MemoryInfo":{
      "type":"structure",
      "members":{
        "SizeInMiB":{
          "shape":"MemorySize",
          "documentation":"<p>The size of the memory, in MiB.</p>",
          "locationName":"sizeInMiB"
        }
      },
      "documentation":"<p>Describes the memory for the instance type.</p>"
    },
    "MemoryMiB":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum amount of memory, in MiB. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum amount of memory, in MiB. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum amount of memory, in MiB.</p>"
    },
    "MemoryMiBRequest":{
      "type":"structure",
      "required":["Min"],
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum amount of memory, in MiB. To specify no minimum limit, specify <code>0</code>.</p>"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum amount of memory, in MiB. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum amount of memory, in MiB.</p>"
    },
    "MemorySize":{"type":"long"},
    "MetricPoint":{
      "type":"structure",
      "members":{
        "StartDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The start date for the metric point. The starting date for the metric point. The starting time must be formatted as <code>yyyy-mm-ddThh:mm:ss</code>. For example, <code>2022-06-10T12:00:00.000Z</code>.</p>",
          "locationName":"startDate"
        },
        "EndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The end date for the metric point. The ending time must be formatted as <code>yyyy-mm-ddThh:mm:ss</code>. For example, <code>2022-06-12T12:00:00.000Z</code>.</p>",
          "locationName":"endDate"
        },
        "Value":{
          "shape":"Float",
          "locationName":"value"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The status of the metric point.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Indicates whether the network was healthy or degraded at a particular point. The value is aggregated from the <code>startDate</code> to the <code>endDate</code>. Currently only <code>five_minutes</code> is supported.</p>"
    },
    "MetricPoints":{
      "type":"list",
      "member":{
        "shape":"MetricPoint",
        "locationName":"item"
      }
    },
    "MetricType":{
      "type":"string",
      "enum":["aggregate-latency"]
    },
    "MillisecondDateTime":{"type":"timestamp"},
    "ModifyAddressAttributeRequest":{
      "type":"structure",
      "required":["AllocationId"],
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>[EC2-VPC] The allocation ID.</p>"
        },
        "DomainName":{
          "shape":"String",
          "documentation":"<p>The domain name to modify for the IP address.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyAddressAttributeResult":{
      "type":"structure",
      "members":{
        "Address":{
          "shape":"AddressAttribute",
          "documentation":"<p>Information about the Elastic IP address.</p>",
          "locationName":"address"
        }
      }
    },
    "ModifyAvailabilityZoneGroupRequest":{
      "type":"structure",
      "required":[
        "GroupName",
        "OptInStatus"
      ],
      "members":{
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the Availability Zone group, Local Zone group, or Wavelength Zone group.</p>"
        },
        "OptInStatus":{
          "shape":"ModifyAvailabilityZoneOptInStatus",
          "documentation":"<p>Indicates whether you are opted in to the Local Zone group or Wavelength Zone group. The only valid value is <code>opted-in</code>. You must contact <a href=\"https://console.aws.amazon.com/support/home#/case/create%3FissueType=customer-service%26serviceCode=general-info%26getting-started%26categoryCode=using-aws%26services\">Amazon Web Services Support</a> to opt out of a Local Zone or Wavelength Zone group.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyAvailabilityZoneGroupResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Is <code>true</code> if the request succeeds, and an error otherwise.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyAvailabilityZoneOptInStatus":{
      "type":"string",
      "enum":[
        "opted-in",
        "not-opted-in"
      ]
    },
    "ModifyCapacityReservationFleetRequest":{
      "type":"structure",
      "required":["CapacityReservationFleetId"],
      "members":{
        "CapacityReservationFleetId":{
          "shape":"CapacityReservationFleetId",
          "documentation":"<p>The ID of the Capacity Reservation Fleet to modify.</p>"
        },
        "TotalTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The total number of capacity units to be reserved by the Capacity Reservation Fleet. This value, together with the instance type weights that you assign to each instance type used by the Fleet determine the number of instances for which the Fleet reserves capacity. Both values are based on units that make sense for your workload. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#target-capacity\">Total target capacity</a> in the Amazon EC2 User Guide.</p>"
        },
        "EndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation Fleet expires. When the Capacity Reservation Fleet expires, its state changes to <code>expired</code> and all of the Capacity Reservations in the Fleet expire.</p> <p>The Capacity Reservation Fleet expires within an hour after the specified time. For example, if you specify <code>5/31/2019</code>, <code>13:30:55</code>, the Capacity Reservation Fleet is guaranteed to expire between <code>13:30:55</code> and <code>14:30:55</code> on <code>5/31/2019</code>.</p> <p>You can't specify <b>EndDate</b> and <b> RemoveEndDate</b> in the same request.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "RemoveEndDate":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to remove the end date from the Capacity Reservation Fleet. If you remove the end date, the Capacity Reservation Fleet does not expire and it remains active until you explicitly cancel it using the <b>CancelCapacityReservationFleet</b> action.</p> <p>You can't specify <b>RemoveEndDate</b> and <b> EndDate</b> in the same request.</p>"
        }
      }
    },
    "ModifyCapacityReservationFleetResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyCapacityReservationRequest":{
      "type":"structure",
      "required":["CapacityReservationId"],
      "members":{
        "CapacityReservationId":{
          "shape":"CapacityReservationId",
          "documentation":"<p>The ID of the Capacity Reservation.</p>"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances for which to reserve capacity. The number of instances can't be increased or decreased by more than <code>1000</code> in a single request.</p>"
        },
        "EndDate":{
          "shape":"DateTime",
          "documentation":"<p>The date and time at which the Capacity Reservation expires. When a Capacity Reservation expires, the reserved capacity is released and you can no longer launch instances into it. The Capacity Reservation's state changes to <code>expired</code> when it reaches its end date and time.</p> <p>The Capacity Reservation is cancelled within an hour from the specified time. For example, if you specify 5/31/2019, 13:30:55, the Capacity Reservation is guaranteed to end between 13:30:55 and 14:30:55 on 5/31/2019.</p> <p>You must provide an <code>EndDate</code> value if <code>EndDateType</code> is <code>limited</code>. Omit <code>EndDate</code> if <code>EndDateType</code> is <code>unlimited</code>.</p>"
        },
        "EndDateType":{
          "shape":"EndDateType",
          "documentation":"<p>Indicates the way in which the Capacity Reservation ends. A Capacity Reservation can have one of the following end types:</p> <ul> <li> <p> <code>unlimited</code> - The Capacity Reservation remains active until you explicitly cancel it. Do not provide an <code>EndDate</code> value if <code>EndDateType</code> is <code>unlimited</code>.</p> </li> <li> <p> <code>limited</code> - The Capacity Reservation expires automatically at a specified date and time. You must provide an <code>EndDate</code> value if <code>EndDateType</code> is <code>limited</code>.</p> </li> </ul>"
        },
        "Accept":{
          "shape":"Boolean",
          "documentation":"<p>Reserved. Capacity Reservations you have created are accepted by default.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "AdditionalInfo":{
          "shape":"String",
          "documentation":"<p>Reserved for future use.</p>"
        }
      }
    },
    "ModifyCapacityReservationResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyClientVpnEndpointRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint to modify.</p>"
        },
        "ServerCertificateArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the server certificate to be used. The server certificate must be provisioned in Certificate Manager (ACM).</p>"
        },
        "ConnectionLogOptions":{
          "shape":"ConnectionLogOptions",
          "documentation":"<p>Information about the client connection logging options.</p> <p>If you enable client connection logging, data about client connections is sent to a Cloudwatch Logs log stream. The following information is logged:</p> <ul> <li> <p>Client connection requests</p> </li> <li> <p>Client connection results (successful and unsuccessful)</p> </li> <li> <p>Reasons for unsuccessful client connection requests</p> </li> <li> <p>Client connection termination time</p> </li> </ul>"
        },
        "DnsServers":{
          "shape":"DnsServersOptionsModifyStructure",
          "documentation":"<p>Information about the DNS servers to be used by Client VPN connections. A Client VPN endpoint can have up to two DNS servers.</p>"
        },
        "VpnPort":{
          "shape":"Integer",
          "documentation":"<p>The port number to assign to the Client VPN endpoint for TCP and UDP traffic.</p> <p>Valid Values: <code>443</code> | <code>1194</code> </p> <p>Default Value: <code>443</code> </p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A brief description of the Client VPN endpoint.</p>"
        },
        "SplitTunnel":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the VPN is split-tunnel.</p> <p>For information about split-tunnel VPN endpoints, see <a href=\"https://docs.aws.amazon.com/vpn/latest/clientvpn-admin/split-tunnel-vpn.html\">Split-tunnel Client VPN endpoint</a> in the <i>Client VPN Administrator Guide</i>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "SecurityGroupIds":{
          "shape":"ClientVpnSecurityGroupIdSet",
          "documentation":"<p>The IDs of one or more security groups to apply to the target network.</p>",
          "locationName":"SecurityGroupId"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC to associate with the Client VPN endpoint.</p>"
        },
        "SelfServicePortal":{
          "shape":"SelfServicePortal",
          "documentation":"<p>Specify whether to enable the self-service portal for the Client VPN endpoint.</p>"
        },
        "ClientConnectOptions":{
          "shape":"ClientConnectOptions",
          "documentation":"<p>The options for managing connection authorization for new client connections.</p>"
        },
        "SessionTimeoutHours":{
          "shape":"Integer",
          "documentation":"<p>The maximum VPN session duration time in hours.</p> <p>Valid values: <code>8 | 10 | 12 | 24</code> </p> <p>Default value: <code>24</code> </p>"
        },
        "ClientLoginBannerOptions":{
          "shape":"ClientLoginBannerOptions",
          "documentation":"<p>Options for enabling a customizable text banner that will be displayed on Amazon Web Services provided clients when a VPN session is established.</p>"
        }
      }
    },
    "ModifyClientVpnEndpointResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyDefaultCreditSpecificationRequest":{
      "type":"structure",
      "required":[
        "InstanceFamily",
        "CpuCredits"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceFamily":{
          "shape":"UnlimitedSupportedInstanceFamily",
          "documentation":"<p>The instance family.</p>"
        },
        "CpuCredits":{
          "shape":"String",
          "documentation":"<p>The credit option for CPU usage of the instance family.</p> <p>Valid Values: <code>standard</code> | <code>unlimited</code> </p>"
        }
      }
    },
    "ModifyDefaultCreditSpecificationResult":{
      "type":"structure",
      "members":{
        "InstanceFamilyCreditSpecification":{
          "shape":"InstanceFamilyCreditSpecification",
          "documentation":"<p>The default credit option for CPU usage of the instance family.</p>",
          "locationName":"instanceFamilyCreditSpecification"
        }
      }
    },
    "ModifyEbsDefaultKmsKeyIdRequest":{
      "type":"structure",
      "required":["KmsKeyId"],
      "members":{
        "KmsKeyId":{
          "shape":"KmsKeyId",
          "documentation":"<p>The identifier of the Key Management Service (KMS) KMS key to use for Amazon EBS encryption. If this parameter is not specified, your KMS key for Amazon EBS is used. If <code>KmsKeyId</code> is specified, the encrypted state must be <code>true</code>.</p> <p>You can specify the KMS key using any of the following:</p> <ul> <li> <p>Key ID. For example, 1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Key alias. For example, alias/ExampleAlias.</p> </li> <li> <p>Key ARN. For example, arn:aws:kms:us-east-1:012345678910:key/1234abcd-12ab-34cd-56ef-1234567890ab.</p> </li> <li> <p>Alias ARN. For example, arn:aws:kms:us-east-1:012345678910:alias/ExampleAlias.</p> </li> </ul> <p>Amazon Web Services authenticates the KMS key asynchronously. Therefore, if you specify an ID, alias, or ARN that is not valid, the action can appear to complete, but eventually fails.</p> <p>Amazon EBS does not support asymmetric KMS keys.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyEbsDefaultKmsKeyIdResult":{
      "type":"structure",
      "members":{
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the default KMS key for encryption by default.</p>",
          "locationName":"kmsKeyId"
        }
      }
    },
    "ModifyFleetRequest":{
      "type":"structure",
      "required":["FleetId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ExcessCapacityTerminationPolicy":{
          "shape":"FleetExcessCapacityTerminationPolicy",
          "documentation":"<p>Indicates whether running instances should be terminated if the total target capacity of the EC2 Fleet is decreased below the current size of the EC2 Fleet.</p> <p>Supported only for fleets of type <code>maintain</code>.</p>"
        },
        "LaunchTemplateConfigs":{
          "shape":"FleetLaunchTemplateConfigListRequest",
          "documentation":"<p>The launch template and overrides.</p>",
          "locationName":"LaunchTemplateConfig"
        },
        "FleetId":{
          "shape":"FleetId",
          "documentation":"<p>The ID of the EC2 Fleet.</p>"
        },
        "TargetCapacitySpecification":{
          "shape":"TargetCapacitySpecificationRequest",
          "documentation":"<p>The size of the EC2 Fleet.</p>"
        },
        "Context":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>"
        }
      }
    },
    "ModifyFleetResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>If the request succeeds, the response returns <code>true</code>. If the request fails, no response is returned, and instead an error message is returned.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyFpgaImageAttributeRequest":{
      "type":"structure",
      "required":["FpgaImageId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FpgaImageId":{
          "shape":"FpgaImageId",
          "documentation":"<p>The ID of the AFI.</p>"
        },
        "Attribute":{
          "shape":"FpgaImageAttributeName",
          "documentation":"<p>The name of the attribute.</p>"
        },
        "OperationType":{
          "shape":"OperationType",
          "documentation":"<p>The operation type.</p>"
        },
        "UserIds":{
          "shape":"UserIdStringList",
          "documentation":"<p>The Amazon Web Services account IDs. This parameter is valid only when modifying the <code>loadPermission</code> attribute.</p>",
          "locationName":"UserId"
        },
        "UserGroups":{
          "shape":"UserGroupStringList",
          "documentation":"<p>The user groups. This parameter is valid only when modifying the <code>loadPermission</code> attribute.</p>",
          "locationName":"UserGroup"
        },
        "ProductCodes":{
          "shape":"ProductCodeStringList",
          "documentation":"<p>The product codes. After you add a product code to an AFI, it can't be removed. This parameter is valid only when modifying the <code>productCodes</code> attribute.</p>",
          "locationName":"ProductCode"
        },
        "LoadPermission":{
          "shape":"LoadPermissionModifications",
          "documentation":"<p>The load permission for the AFI.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the AFI.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>A name for the AFI.</p>"
        }
      }
    },
    "ModifyFpgaImageAttributeResult":{
      "type":"structure",
      "members":{
        "FpgaImageAttribute":{
          "shape":"FpgaImageAttribute",
          "documentation":"<p>Information about the attribute.</p>",
          "locationName":"fpgaImageAttribute"
        }
      }
    },
    "ModifyHostsRequest":{
      "type":"structure",
      "required":["HostIds"],
      "members":{
        "AutoPlacement":{
          "shape":"AutoPlacement",
          "documentation":"<p>Specify whether to enable or disable auto-placement.</p>",
          "locationName":"autoPlacement"
        },
        "HostIds":{
          "shape":"RequestHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts to modify.</p>",
          "locationName":"hostId"
        },
        "HostRecovery":{
          "shape":"HostRecovery",
          "documentation":"<p>Indicates whether to enable or disable host recovery for the Dedicated Host. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-recovery.html\"> Host recovery</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>Specifies the instance type to be supported by the Dedicated Host. Specify this parameter to modify a Dedicated Host to support only a specific instance type.</p> <p>If you want to modify a Dedicated Host to support multiple instance types in its current instance family, omit this parameter and specify <b>InstanceFamily</b> instead. You cannot specify <b>InstanceType</b> and <b>InstanceFamily</b> in the same request.</p>"
        },
        "InstanceFamily":{
          "shape":"String",
          "documentation":"<p>Specifies the instance family to be supported by the Dedicated Host. Specify this parameter to modify a Dedicated Host to support multiple instance types within its current instance family.</p> <p>If you want to modify a Dedicated Host to support a specific instance type only, omit this parameter and specify <b>InstanceType</b> instead. You cannot specify <b>InstanceFamily</b> and <b>InstanceType</b> in the same request.</p>"
        },
        "HostMaintenance":{
          "shape":"HostMaintenance",
          "documentation":"<p>Indicates whether to enable or disable host maintenance for the Dedicated Host. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/dedicated-hosts-maintenance.html\"> Host maintenance</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        }
      }
    },
    "ModifyHostsResult":{
      "type":"structure",
      "members":{
        "Successful":{
          "shape":"ResponseHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts that were successfully modified.</p>",
          "locationName":"successful"
        },
        "Unsuccessful":{
          "shape":"UnsuccessfulItemList",
          "documentation":"<p>The IDs of the Dedicated Hosts that could not be modified. Check whether the setting you requested can be used.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "ModifyIdFormatRequest":{
      "type":"structure",
      "required":[
        "Resource",
        "UseLongIds"
      ],
      "members":{
        "Resource":{
          "shape":"String",
          "documentation":"<p>The type of resource: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>.</p> <p>Alternatively, use the <code>all-current</code> option to include all resource types that are currently within their opt-in period for longer IDs.</p>"
        },
        "UseLongIds":{
          "shape":"Boolean",
          "documentation":"<p>Indicate whether the resource should use longer IDs (17-character IDs).</p>"
        }
      }
    },
    "ModifyIdentityIdFormatRequest":{
      "type":"structure",
      "required":[
        "PrincipalArn",
        "Resource",
        "UseLongIds"
      ],
      "members":{
        "PrincipalArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the principal, which can be an IAM user, IAM role, or the root user. Specify <code>all</code> to modify the ID format for all IAM users, IAM roles, and the root user of the account.</p>",
          "locationName":"principalArn"
        },
        "Resource":{
          "shape":"String",
          "documentation":"<p>The type of resource: <code>bundle</code> | <code>conversion-task</code> | <code>customer-gateway</code> | <code>dhcp-options</code> | <code>elastic-ip-allocation</code> | <code>elastic-ip-association</code> | <code>export-task</code> | <code>flow-log</code> | <code>image</code> | <code>import-task</code> | <code>internet-gateway</code> | <code>network-acl</code> | <code>network-acl-association</code> | <code>network-interface</code> | <code>network-interface-attachment</code> | <code>prefix-list</code> | <code>route-table</code> | <code>route-table-association</code> | <code>security-group</code> | <code>subnet</code> | <code>subnet-cidr-block-association</code> | <code>vpc</code> | <code>vpc-cidr-block-association</code> | <code>vpc-endpoint</code> | <code>vpc-peering-connection</code> | <code>vpn-connection</code> | <code>vpn-gateway</code>.</p> <p>Alternatively, use the <code>all-current</code> option to include all resource types that are currently within their opt-in period for longer IDs.</p>",
          "locationName":"resource"
        },
        "UseLongIds":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the resource should use longer IDs (17-character IDs)</p>",
          "locationName":"useLongIds"
        }
      }
    },
    "ModifyImageAttributeRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "Attribute":{
          "shape":"String",
          "documentation":"<p>The name of the attribute to modify.</p> <p>Valid values: <code>description</code> | <code>launchPermission</code> </p>"
        },
        "Description":{
          "shape":"AttributeValue",
          "documentation":"<p>A new description for the AMI.</p>"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "LaunchPermission":{
          "shape":"LaunchPermissionModifications",
          "documentation":"<p>A new launch permission for the AMI.</p>"
        },
        "OperationType":{
          "shape":"OperationType",
          "documentation":"<p>The operation type. This parameter can be used only when the <code>Attribute</code> parameter is <code>launchPermission</code>.</p>"
        },
        "ProductCodes":{
          "shape":"ProductCodeStringList",
          "documentation":"<p>Not supported.</p>",
          "locationName":"ProductCode"
        },
        "UserGroups":{
          "shape":"UserGroupStringList",
          "documentation":"<p>The user groups. This parameter can be used only when the <code>Attribute</code> parameter is <code>launchPermission</code>.</p>",
          "locationName":"UserGroup"
        },
        "UserIds":{
          "shape":"UserIdStringList",
          "documentation":"<p>The Amazon Web Services account IDs. This parameter can be used only when the <code>Attribute</code> parameter is <code>launchPermission</code>.</p>",
          "locationName":"UserId"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The value of the attribute being modified. This parameter can be used only when the <code>Attribute</code> parameter is <code>description</code>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "OrganizationArns":{
          "shape":"OrganizationArnStringList",
          "documentation":"<p>The Amazon Resource Name (ARN) of an organization. This parameter can be used only when the <code>Attribute</code> parameter is <code>launchPermission</code>.</p>",
          "locationName":"OrganizationArn"
        },
        "OrganizationalUnitArns":{
          "shape":"OrganizationalUnitArnStringList",
          "documentation":"<p>The Amazon Resource Name (ARN) of an organizational unit (OU). This parameter can be used only when the <code>Attribute</code> parameter is <code>launchPermission</code>.</p>",
          "locationName":"OrganizationalUnitArn"
        }
      },
      "documentation":"<p>Contains the parameters for ModifyImageAttribute.</p>"
    },
    "ModifyInstanceAttributeRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "SourceDestCheck":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Enable or disable source/destination checks, which ensure that the instance is either the source or the destination of any traffic that it receives. If the value is <code>true</code>, source/destination checks are enabled; otherwise, they are disabled. The default value is <code>true</code>. You must disable source/destination checks if the instance runs services such as network address translation, routing, or firewalls.</p>"
        },
        "Attribute":{
          "shape":"InstanceAttributeName",
          "documentation":"<p>The name of the attribute to modify.</p> <important> <p>You can modify the following attributes only: <code>disableApiTermination</code> | <code>instanceType</code> | <code>kernel</code> | <code>ramdisk</code> | <code>instanceInitiatedShutdownBehavior</code> | <code>blockDeviceMapping</code> | <code>userData</code> | <code>sourceDestCheck</code> | <code>groupSet</code> | <code>ebsOptimized</code> | <code>sriovNetSupport</code> | <code>enaSupport</code> | <code>nvmeSupport</code> | <code>disableApiStop</code> | <code>enclaveOptions</code> </p> </important>",
          "locationName":"attribute"
        },
        "BlockDeviceMappings":{
          "shape":"InstanceBlockDeviceMappingSpecificationList",
          "documentation":"<p>Modifies the <code>DeleteOnTermination</code> attribute for volumes that are currently attached. The volume must be owned by the caller. If no value is specified for <code>DeleteOnTermination</code>, the default is <code>true</code> and the volume is deleted when the instance is terminated.</p> <p>To add instance store volumes to an Amazon EBS-backed instance, you must add them when you launch the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/block-device-mapping-concepts.html#Using_OverridingAMIBDM\">Update the block device mapping when launching an instance</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"blockDeviceMapping"
        },
        "DisableApiTermination":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>If the value is <code>true</code>, you can't terminate the instance using the Amazon EC2 console, CLI, or API; otherwise, you can. You cannot use this parameter for Spot Instances.</p>",
          "locationName":"disableApiTermination"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "EbsOptimized":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Specifies whether the instance is optimized for Amazon EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS Optimized instance.</p>",
          "locationName":"ebsOptimized"
        },
        "EnaSupport":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Set to <code>true</code> to enable enhanced networking with ENA for the instance.</p> <p>This option is supported only for HVM instances. Specifying this option with a PV instance can make it unreachable.</p>",
          "locationName":"enaSupport"
        },
        "Groups":{
          "shape":"GroupIdStringList",
          "documentation":"<p>[EC2-VPC] Replaces the security groups of the instance with the specified security groups. You must specify at least one security group, even if it's just the default security group for the VPC. You must specify the security group ID, not the security group name.</p>",
          "locationName":"GroupId"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceInitiatedShutdownBehavior":{
          "shape":"AttributeValue",
          "documentation":"<p>Specifies whether an instance stops or terminates when you initiate shutdown from the instance (using the operating system command for system shutdown).</p>",
          "locationName":"instanceInitiatedShutdownBehavior"
        },
        "InstanceType":{
          "shape":"AttributeValue",
          "documentation":"<p>Changes the instance type to the specified value. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>. If the instance type is not valid, the error returned is <code>InvalidInstanceAttributeValue</code>.</p>",
          "locationName":"instanceType"
        },
        "Kernel":{
          "shape":"AttributeValue",
          "documentation":"<p>Changes the instance's kernel to the specified value. We recommend that you use PV-GRUB instead of kernels and RAM disks. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/UserProvidedKernels.html\">PV-GRUB</a>.</p>",
          "locationName":"kernel"
        },
        "Ramdisk":{
          "shape":"AttributeValue",
          "documentation":"<p>Changes the instance's RAM disk to the specified value. We recommend that you use PV-GRUB instead of kernels and RAM disks. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/UserProvidedKernels.html\">PV-GRUB</a>.</p>",
          "locationName":"ramdisk"
        },
        "SriovNetSupport":{
          "shape":"AttributeValue",
          "documentation":"<p>Set to <code>simple</code> to enable enhanced networking with the Intel 82599 Virtual Function interface for the instance.</p> <p>There is no way to disable enhanced networking with the Intel 82599 Virtual Function interface at this time.</p> <p>This option is supported only for HVM instances. Specifying this option with a PV instance can make it unreachable.</p>",
          "locationName":"sriovNetSupport"
        },
        "UserData":{
          "shape":"BlobAttributeValue",
          "documentation":"<p>Changes the instance's user data to the specified value. If you are using an Amazon Web Services SDK or command line tool, base64-encoding is performed for you, and you can load the text from a file. Otherwise, you must provide base64-encoded text.</p>",
          "locationName":"userData"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>A new value for the attribute. Use only with the <code>kernel</code>, <code>ramdisk</code>, <code>userData</code>, <code>disableApiTermination</code>, or <code>instanceInitiatedShutdownBehavior</code> attribute.</p>",
          "locationName":"value"
        },
        "DisableApiStop":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether an instance is enabled for stop protection. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Stop_Start.html#Using_StopProtection\">Stop Protection</a>.</p> <p/>"
        }
      }
    },
    "ModifyInstanceCapacityReservationAttributesRequest":{
      "type":"structure",
      "required":[
        "InstanceId",
        "CapacityReservationSpecification"
      ],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance to be modified.</p>"
        },
        "CapacityReservationSpecification":{
          "shape":"CapacityReservationSpecification",
          "documentation":"<p>Information about the Capacity Reservation targeting option.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyInstanceCapacityReservationAttributesResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyInstanceCreditSpecificationRequest":{
      "type":"structure",
      "required":["InstanceCreditSpecifications"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>"
        },
        "InstanceCreditSpecifications":{
          "shape":"InstanceCreditSpecificationListRequest",
          "documentation":"<p>Information about the credit option for CPU usage.</p>",
          "locationName":"InstanceCreditSpecification"
        }
      }
    },
    "ModifyInstanceCreditSpecificationResult":{
      "type":"structure",
      "members":{
        "SuccessfulInstanceCreditSpecifications":{
          "shape":"SuccessfulInstanceCreditSpecificationSet",
          "documentation":"<p>Information about the instances whose credit option for CPU usage was successfully modified.</p>",
          "locationName":"successfulInstanceCreditSpecificationSet"
        },
        "UnsuccessfulInstanceCreditSpecifications":{
          "shape":"UnsuccessfulInstanceCreditSpecificationSet",
          "documentation":"<p>Information about the instances whose credit option for CPU usage was not modified.</p>",
          "locationName":"unsuccessfulInstanceCreditSpecificationSet"
        }
      }
    },
    "ModifyInstanceEventStartTimeRequest":{
      "type":"structure",
      "required":[
        "InstanceId",
        "InstanceEventId",
        "NotBefore"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance with the scheduled event.</p>"
        },
        "InstanceEventId":{
          "shape":"String",
          "documentation":"<p>The ID of the event whose date and time you are modifying.</p>"
        },
        "NotBefore":{
          "shape":"DateTime",
          "documentation":"<p>The new date and time when the event will take place.</p>"
        }
      }
    },
    "ModifyInstanceEventStartTimeResult":{
      "type":"structure",
      "members":{
        "Event":{
          "shape":"InstanceStatusEvent",
          "documentation":"<p>Information about the event.</p>",
          "locationName":"event"
        }
      }
    },
    "ModifyInstanceEventWindowRequest":{
      "type":"structure",
      "required":["InstanceEventWindowId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the event window.</p>"
        },
        "InstanceEventWindowId":{
          "shape":"InstanceEventWindowId",
          "documentation":"<p>The ID of the event window.</p>"
        },
        "TimeRanges":{
          "shape":"InstanceEventWindowTimeRangeRequestSet",
          "documentation":"<p>The time ranges of the event window.</p>",
          "locationName":"TimeRange"
        },
        "CronExpression":{
          "shape":"InstanceEventWindowCronExpression",
          "documentation":"<p>The cron expression of the event window, for example, <code>* 0-4,20-23 * * 1,5</code>.</p> <p>Constraints:</p> <ul> <li> <p>Only hour and day of the week values are supported.</p> </li> <li> <p>For day of the week values, you can specify either integers <code>0</code> through <code>6</code>, or alternative single values <code>SUN</code> through <code>SAT</code>.</p> </li> <li> <p>The minute, month, and year must be specified by <code>*</code>.</p> </li> <li> <p>The hour value must be one or a multiple range, for example, <code>0-4</code> or <code>0-4,20-23</code>.</p> </li> <li> <p>Each hour range must be >= 2 hours, for example, <code>0-2</code> or <code>20-23</code>.</p> </li> <li> <p>The event window must be >= 4 hours. The combined total time ranges in the event window must be >= 4 hours.</p> </li> </ul> <p>For more information about cron expressions, see <a href=\"https://en.wikipedia.org/wiki/Cron\">cron</a> on the <i>Wikipedia website</i>.</p>"
        }
      }
    },
    "ModifyInstanceEventWindowResult":{
      "type":"structure",
      "members":{
        "InstanceEventWindow":{
          "shape":"InstanceEventWindow",
          "documentation":"<p>Information about the event window.</p>",
          "locationName":"instanceEventWindow"
        }
      }
    },
    "ModifyInstanceMaintenanceOptionsRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "AutoRecovery":{
          "shape":"InstanceAutoRecoveryState",
          "documentation":"<p>Disables the automatic recovery behavior of your instance or sets it to default.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyInstanceMaintenanceOptionsResult":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "AutoRecovery":{
          "shape":"InstanceAutoRecoveryState",
          "documentation":"<p>Provides information on the current automatic recovery behavior of your instance.</p>",
          "locationName":"autoRecovery"
        }
      }
    },
    "ModifyInstanceMetadataOptionsRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "HttpTokens":{
          "shape":"HttpTokensState",
          "documentation":"<p>IMDSv2 uses token-backed sessions. Set the use of HTTP tokens to <code>optional</code> (in other words, set the use of IMDSv2 to <code>optional</code>) or <code>required</code> (in other words, set the use of IMDSv2 to <code>required</code>).</p> <ul> <li> <p> <code>optional</code> - When IMDSv2 is optional, you can choose to retrieve instance metadata with or without a session token in your request. If you retrieve the IAM role credentials without a token, the IMDSv1 role credentials are returned. If you retrieve the IAM role credentials using a valid session token, the IMDSv2 role credentials are returned.</p> </li> <li> <p> <code>required</code> - When IMDSv2 is required, you must send a session token with any instance metadata retrieval requests. In this state, retrieving the IAM role credentials always returns IMDSv2 credentials; IMDSv1 credentials are not available.</p> </li> </ul> <p>Default: <code>optional</code> </p>"
        },
        "HttpPutResponseHopLimit":{
          "shape":"Integer",
          "documentation":"<p>The desired HTTP PUT response hop limit for instance metadata requests. The larger the number, the further instance metadata requests can travel. If no parameter is specified, the existing state is maintained.</p> <p>Possible values: Integers from 1 to 64</p>"
        },
        "HttpEndpoint":{
          "shape":"InstanceMetadataEndpointState",
          "documentation":"<p>Enables or disables the HTTP metadata endpoint on your instances. If this parameter is not specified, the existing state is maintained.</p> <p>If you specify a value of <code>disabled</code>, you cannot access your instance metadata.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "HttpProtocolIpv6":{
          "shape":"InstanceMetadataProtocolState",
          "documentation":"<p>Enables or disables the IPv6 endpoint for the instance metadata service. This setting applies only if you have enabled the HTTP metadata endpoint.</p>"
        },
        "InstanceMetadataTags":{
          "shape":"InstanceMetadataTagsState",
          "documentation":"<p>Set to <code>enabled</code> to allow access to instance tags from the instance metadata. Set to <code>disabled</code> to turn off access to instance tags from the instance metadata. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#work-with-tags-in-IMDS\">Work with instance tags using the instance metadata</a>.</p> <p>Default: <code>disabled</code> </p>"
        }
      }
    },
    "ModifyInstanceMetadataOptionsResult":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceMetadataOptions":{
          "shape":"InstanceMetadataOptionsResponse",
          "documentation":"<p>The metadata options for the instance.</p>",
          "locationName":"instanceMetadataOptions"
        }
      }
    },
    "ModifyInstancePlacementRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "Affinity":{
          "shape":"Affinity",
          "documentation":"<p>The affinity setting for the instance.</p>",
          "locationName":"affinity"
        },
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group in which to place the instance. For spread placement groups, the instance must have a tenancy of <code>default</code>. For cluster and partition placement groups, the instance must have a tenancy of <code>default</code> or <code>dedicated</code>.</p> <p>To remove an instance from a placement group, specify an empty string (\"\").</p>"
        },
        "HostId":{
          "shape":"DedicatedHostId",
          "documentation":"<p>The ID of the Dedicated Host with which to associate the instance.</p>",
          "locationName":"hostId"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance that you are modifying.</p>",
          "locationName":"instanceId"
        },
        "Tenancy":{
          "shape":"HostTenancy",
          "documentation":"<p>The tenancy for the instance.</p> <note> <p>For T3 instances, you can't change the tenancy from <code>dedicated</code> to <code>host</code>, or from <code>host</code> to <code>dedicated</code>. Attempting to make one of these unsupported tenancy changes results in the <code>InvalidTenancy</code> error code.</p> </note>",
          "locationName":"tenancy"
        },
        "PartitionNumber":{
          "shape":"Integer",
          "documentation":"<p>The number of the partition in which to place the instance. Valid only if the placement group strategy is set to <code>partition</code>.</p>"
        },
        "HostResourceGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the host resource group in which to place the instance.</p>"
        },
        "GroupId":{
          "shape":"PlacementGroupId",
          "documentation":"<p>The Group Id of a placement group. You must specify the Placement Group <b>Group Id</b> to launch an instance in a shared placement group.</p>"
        }
      }
    },
    "ModifyInstancePlacementResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Is <code>true</code> if the request succeeds, and an error otherwise.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyIpamPoolRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool you want to modify.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the IPAM pool you want to modify.</p>"
        },
        "AutoImport":{
          "shape":"Boolean",
          "documentation":"<p>If true, IPAM will continuously look for resources within the CIDR range of this pool and automatically import them as allocations into your IPAM. The CIDRs that will be allocated for these resources must not already be allocated to other resources in order for the import to succeed. IPAM will import a CIDR regardless of its compliance with the pool's allocation rules, so a resource might be imported and subsequently marked as noncompliant. If IPAM discovers multiple CIDRs that overlap, IPAM will import the largest CIDR only. If IPAM discovers multiple CIDRs with matching CIDRs, IPAM will randomly import one of them only. </p> <p>A locale must be set on the pool for this feature to work.</p>"
        },
        "AllocationMinNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The minimum netmask length required for CIDR allocations in this IPAM pool to be compliant. Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128. The minimum netmask length must be less than the maximum netmask length.</p>"
        },
        "AllocationMaxNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The maximum netmask length possible for CIDR allocations in this IPAM pool to be compliant. Possible netmask lengths for IPv4 addresses are 0 - 32. Possible netmask lengths for IPv6 addresses are 0 - 128.The maximum netmask length must be greater than the minimum netmask length.</p>"
        },
        "AllocationDefaultNetmaskLength":{
          "shape":"IpamNetmaskLength",
          "documentation":"<p>The default netmask length for allocations added to this pool. If, for example, the CIDR assigned to this pool is 10.0.0.0/8 and you enter 16 here, new allocations will default to 10.0.0.0/16.</p>"
        },
        "ClearAllocationDefaultNetmaskLength":{
          "shape":"Boolean",
          "documentation":"<p>Clear the default netmask length allocation rule for this pool.</p>"
        },
        "AddAllocationResourceTags":{
          "shape":"RequestIpamResourceTagList",
          "documentation":"<p>Add tag allocation rules to a pool. For more information about allocation rules, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-top-ipam.html\">Create a top-level pool</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"AddAllocationResourceTag"
        },
        "RemoveAllocationResourceTags":{
          "shape":"RequestIpamResourceTagList",
          "documentation":"<p>Remove tag allocation rules from a pool.</p>",
          "locationName":"RemoveAllocationResourceTag"
        }
      }
    },
    "ModifyIpamPoolResult":{
      "type":"structure",
      "members":{
        "IpamPool":{
          "shape":"IpamPool",
          "documentation":"<p>The results of the modification.</p>",
          "locationName":"ipamPool"
        }
      }
    },
    "ModifyIpamRequest":{
      "type":"structure",
      "required":["IpamId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamId":{
          "shape":"IpamId",
          "documentation":"<p>The ID of the IPAM you want to modify.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the IPAM you want to modify.</p>"
        },
        "AddOperatingRegions":{
          "shape":"AddIpamOperatingRegionSet",
          "documentation":"<p>Choose the operating Regions for the IPAM. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p> <p>For more information about operating Regions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i>.</p>",
          "locationName":"AddOperatingRegion"
        },
        "RemoveOperatingRegions":{
          "shape":"RemoveIpamOperatingRegionSet",
          "documentation":"<p>The operating Regions to remove.</p>",
          "locationName":"RemoveOperatingRegion"
        }
      }
    },
    "ModifyIpamResourceCidrRequest":{
      "type":"structure",
      "required":[
        "ResourceId",
        "ResourceCidr",
        "ResourceRegion",
        "CurrentIpamScopeId",
        "Monitored"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource you want to modify.</p>"
        },
        "ResourceCidr":{
          "shape":"String",
          "documentation":"<p>The CIDR of the resource you want to modify.</p>"
        },
        "ResourceRegion":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Region of the resource you want to modify.</p>"
        },
        "CurrentIpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the current scope that the resource CIDR is in.</p>"
        },
        "DestinationIpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the scope you want to transfer the resource CIDR to.</p>"
        },
        "Monitored":{
          "shape":"Boolean",
          "documentation":"<p>Determines if the resource is monitored by IPAM. If a resource is monitored, the resource is discovered by IPAM and you can view details about the resource’s CIDR.</p>"
        }
      }
    },
    "ModifyIpamResourceCidrResult":{
      "type":"structure",
      "members":{
        "IpamResourceCidr":{
          "shape":"IpamResourceCidr",
          "documentation":"<p>The CIDR of the resource.</p>",
          "locationName":"ipamResourceCidr"
        }
      }
    },
    "ModifyIpamResourceDiscoveryRequest":{
      "type":"structure",
      "required":["IpamResourceDiscoveryId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamResourceDiscoveryId":{
          "shape":"IpamResourceDiscoveryId",
          "documentation":"<p>A resource discovery ID.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A resource discovery description.</p>"
        },
        "AddOperatingRegions":{
          "shape":"AddIpamOperatingRegionSet",
          "documentation":"<p>Add operating Regions to the resource discovery. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p>",
          "locationName":"AddOperatingRegion"
        },
        "RemoveOperatingRegions":{
          "shape":"RemoveIpamOperatingRegionSet",
          "documentation":"<p>Remove operating Regions.</p>",
          "locationName":"RemoveOperatingRegion"
        }
      }
    },
    "ModifyIpamResourceDiscoveryResult":{
      "type":"structure",
      "members":{
        "IpamResourceDiscovery":{
          "shape":"IpamResourceDiscovery",
          "documentation":"<p>A resource discovery.</p>",
          "locationName":"ipamResourceDiscovery"
        }
      }
    },
    "ModifyIpamResult":{
      "type":"structure",
      "members":{
        "Ipam":{
          "shape":"Ipam",
          "documentation":"<p>The results of the modification.</p>",
          "locationName":"ipam"
        }
      }
    },
    "ModifyIpamScopeRequest":{
      "type":"structure",
      "required":["IpamScopeId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamScopeId":{
          "shape":"IpamScopeId",
          "documentation":"<p>The ID of the scope you want to modify.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the scope you want to modify.</p>"
        }
      }
    },
    "ModifyIpamScopeResult":{
      "type":"structure",
      "members":{
        "IpamScope":{
          "shape":"IpamScope",
          "documentation":"<p>The results of the modification.</p>",
          "locationName":"ipamScope"
        }
      }
    },
    "ModifyLaunchTemplateRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring idempotency</a>.</p> <p>Constraint: Maximum 128 ASCII characters.</p>"
        },
        "LaunchTemplateId":{
          "shape":"LaunchTemplateId",
          "documentation":"<p>The ID of the launch template.</p> <p>You must specify either the <code>LaunchTemplateId</code> or the <code>LaunchTemplateName</code>, but not both.</p>"
        },
        "LaunchTemplateName":{
          "shape":"LaunchTemplateName",
          "documentation":"<p>The name of the launch template.</p> <p>You must specify either the <code>LaunchTemplateName</code> or the <code>LaunchTemplateId</code>, but not both.</p>"
        },
        "DefaultVersion":{
          "shape":"String",
          "documentation":"<p>The version number of the launch template to set as the default version.</p>",
          "locationName":"SetDefaultVersion"
        }
      }
    },
    "ModifyLaunchTemplateResult":{
      "type":"structure",
      "members":{
        "LaunchTemplate":{
          "shape":"LaunchTemplate",
          "documentation":"<p>Information about the launch template.</p>",
          "locationName":"launchTemplate"
        }
      }
    },
    "ModifyLocalGatewayRouteRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableId"],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR block used for destination matches. The value that you provide must match the CIDR of an existing route in the table.</p>"
        },
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>"
        },
        "LocalGatewayVirtualInterfaceGroupId":{
          "shape":"LocalGatewayVirtualInterfaceGroupId",
          "documentation":"<p> The ID of the virtual interface group. </p>"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p> The ID of the prefix list. Use a prefix list in place of <code>DestinationCidrBlock</code>. You cannot use <code>DestinationPrefixListId</code> and <code>DestinationCidrBlock</code> in the same request. </p>"
        }
      }
    },
    "ModifyLocalGatewayRouteResult":{
      "type":"structure",
      "members":{
        "Route":{
          "shape":"LocalGatewayRoute",
          "documentation":"<p>Information about the local gateway route table.</p>",
          "locationName":"route"
        }
      }
    },
    "ModifyManagedPrefixListRequest":{
      "type":"structure",
      "required":["PrefixListId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "CurrentVersion":{
          "shape":"Long",
          "documentation":"<p>The current version of the prefix list.</p>"
        },
        "PrefixListName":{
          "shape":"String",
          "documentation":"<p>A name for the prefix list.</p>"
        },
        "AddEntries":{
          "shape":"AddPrefixListEntries",
          "documentation":"<p>One or more entries to add to the prefix list.</p>",
          "locationName":"AddEntry"
        },
        "RemoveEntries":{
          "shape":"RemovePrefixListEntries",
          "documentation":"<p>One or more entries to remove from the prefix list.</p>",
          "locationName":"RemoveEntry"
        },
        "MaxEntries":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of entries for the prefix list. You cannot modify the entries of a prefix list and modify the size of a prefix list at the same time.</p> <p>If any of the resources that reference the prefix list cannot support the new maximum size, the modify operation fails. Check the state message for the IDs of the first ten resources that do not support the new maximum size.</p>"
        }
      }
    },
    "ModifyManagedPrefixListResult":{
      "type":"structure",
      "members":{
        "PrefixList":{
          "shape":"ManagedPrefixList",
          "documentation":"<p>Information about the prefix list.</p>",
          "locationName":"prefixList"
        }
      }
    },
    "ModifyNetworkInterfaceAttributeRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "Attachment":{
          "shape":"NetworkInterfaceAttachmentChanges",
          "documentation":"<p>Information about the interface attachment. If modifying the <code>delete on termination</code> attribute, you must specify the ID of the interface attachment.</p>",
          "locationName":"attachment"
        },
        "Description":{
          "shape":"AttributeValue",
          "documentation":"<p>A description for the network interface.</p>",
          "locationName":"description"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Groups":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>Changes the security groups for the network interface. The new set of groups you specify replaces the current set. You must specify at least one group, even if it's just the default security group in the VPC. You must specify the ID of the security group, not the name.</p>",
          "locationName":"SecurityGroupId"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "SourceDestCheck":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Enable or disable source/destination checks, which ensure that the instance is either the source or the destination of any traffic that it receives. If the value is <code>true</code>, source/destination checks are enabled; otherwise, they are disabled. The default value is <code>true</code>. You must disable source/destination checks if the instance runs services such as network address translation, routing, or firewalls.</p>",
          "locationName":"sourceDestCheck"
        },
        "EnaSrdSpecification":{
          "shape":"EnaSrdSpecification",
          "documentation":"<p>Updates the ENA Express configuration for the network interface that’s attached to the instance.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for ModifyNetworkInterfaceAttribute.</p>"
    },
    "ModifyPrivateDnsNameOptionsRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "PrivateDnsHostnameType":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname for EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 only subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID.</p>"
        },
        "EnableResourceNameDnsARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>"
        },
        "EnableResourceNameDnsAAAARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p>"
        }
      }
    },
    "ModifyPrivateDnsNameOptionsResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyReservedInstancesRequest":{
      "type":"structure",
      "required":[
        "ReservedInstancesIds",
        "TargetConfigurations"
      ],
      "members":{
        "ReservedInstancesIds":{
          "shape":"ReservedInstancesIdStringList",
          "documentation":"<p>The IDs of the Reserved Instances to modify.</p>",
          "locationName":"ReservedInstancesId"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "TargetConfigurations":{
          "shape":"ReservedInstancesConfigurationList",
          "documentation":"<p>The configuration settings for the Reserved Instances to modify.</p>",
          "locationName":"ReservedInstancesConfigurationSetItemType"
        }
      },
      "documentation":"<p>Contains the parameters for ModifyReservedInstances.</p>"
    },
    "ModifyReservedInstancesResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesModificationId":{
          "shape":"String",
          "documentation":"<p>The ID for the modification.</p>",
          "locationName":"reservedInstancesModificationId"
        }
      },
      "documentation":"<p>Contains the output of ModifyReservedInstances.</p>"
    },
    "ModifySecurityGroupRulesRequest":{
      "type":"structure",
      "required":[
        "GroupId",
        "SecurityGroupRules"
      ],
      "members":{
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group.</p>"
        },
        "SecurityGroupRules":{
          "shape":"SecurityGroupRuleUpdateList",
          "documentation":"<p>Information about the security group properties to update.</p>",
          "locationName":"SecurityGroupRule"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifySecurityGroupRulesResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifySnapshotAttributeRequest":{
      "type":"structure",
      "required":["SnapshotId"],
      "members":{
        "Attribute":{
          "shape":"SnapshotAttributeName",
          "documentation":"<p>The snapshot attribute to modify. Only volume creation permissions can be modified.</p>"
        },
        "CreateVolumePermission":{
          "shape":"CreateVolumePermissionModifications",
          "documentation":"<p>A JSON representation of the snapshot attribute modification.</p>"
        },
        "GroupNames":{
          "shape":"GroupNameStringList",
          "documentation":"<p>The group to modify for the snapshot.</p>",
          "locationName":"UserGroup"
        },
        "OperationType":{
          "shape":"OperationType",
          "documentation":"<p>The type of operation to perform to the attribute.</p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>"
        },
        "UserIds":{
          "shape":"UserIdStringList",
          "documentation":"<p>The account ID to modify for the snapshot.</p>",
          "locationName":"UserId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "ModifySnapshotTierRequest":{
      "type":"structure",
      "required":["SnapshotId"],
      "members":{
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>"
        },
        "StorageTier":{
          "shape":"TargetStorageTier",
          "documentation":"<p>The name of the storage tier. You must specify <code>archive</code>.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifySnapshotTierResult":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "TieringStartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the archive process was started.</p>",
          "locationName":"tieringStartTime"
        }
      }
    },
    "ModifySpotFleetRequestRequest":{
      "type":"structure",
      "required":["SpotFleetRequestId"],
      "members":{
        "ExcessCapacityTerminationPolicy":{
          "shape":"ExcessCapacityTerminationPolicy",
          "documentation":"<p>Indicates whether running instances should be terminated if the target capacity of the Spot Fleet request is decreased below the current size of the Spot Fleet.</p> <p>Supported only for fleets of type <code>maintain</code>.</p>",
          "locationName":"excessCapacityTerminationPolicy"
        },
        "LaunchTemplateConfigs":{
          "shape":"LaunchTemplateConfigList",
          "documentation":"<p>The launch template and overrides. You can only use this parameter if you specified a launch template (<code>LaunchTemplateConfigs</code>) in your Spot Fleet request. If you specified <code>LaunchSpecifications</code> in your Spot Fleet request, then omit this parameter.</p>",
          "locationName":"LaunchTemplateConfig"
        },
        "SpotFleetRequestId":{
          "shape":"SpotFleetRequestId",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        },
        "TargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The size of the fleet.</p>",
          "locationName":"targetCapacity"
        },
        "OnDemandTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of On-Demand Instances in the fleet.</p>"
        },
        "Context":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for ModifySpotFleetRequest.</p>"
    },
    "ModifySpotFleetRequestResponse":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>If the request succeeds, the response returns <code>true</code>. If the request fails, no response is returned, and instead an error message is returned.</p>",
          "locationName":"return"
        }
      },
      "documentation":"<p>Contains the output of ModifySpotFleetRequest.</p>"
    },
    "ModifySubnetAttributeRequest":{
      "type":"structure",
      "required":["SubnetId"],
      "members":{
        "AssignIpv6AddressOnCreation":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Specify <code>true</code> to indicate that network interfaces created in the specified subnet should be assigned an IPv6 address. This includes a network interface that's created when launching an instance into the subnet (the instance therefore receives an IPv6 address). </p> <p>If you enable the IPv6 addressing feature for your subnet, your network interface or instance only receives an IPv6 address if it's created using version <code>2016-11-15</code> or later of the Amazon EC2 API.</p>"
        },
        "MapPublicIpOnLaunch":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Specify <code>true</code> to indicate that network interfaces attached to instances created in the specified subnet should be assigned a public IPv4 address.</p>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "MapCustomerOwnedIpOnLaunch":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Specify <code>true</code> to indicate that network interfaces attached to instances created in the specified subnet should be assigned a customer-owned IPv4 address.</p> <p>When this value is <code>true</code>, you must specify the customer-owned IP pool using <code>CustomerOwnedIpv4Pool</code>.</p>"
        },
        "CustomerOwnedIpv4Pool":{
          "shape":"CoipPoolId",
          "documentation":"<p>The customer-owned IPv4 address pool associated with the subnet.</p> <p>You must set this value when you specify <code>true</code> for <code>MapCustomerOwnedIpOnLaunch</code>.</p>"
        },
        "EnableDns64":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether DNS queries made to the Amazon-provided DNS Resolver in this subnet should return synthetic IPv6 addresses for IPv4-only destinations.</p>"
        },
        "PrivateDnsHostnameTypeOnLaunch":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname to assign to instances in the subnet at launch. For IPv4-only and dual-stack (IPv4 and IPv6) subnets, an instance DNS name can be based on the instance IPv4 address (ip-name) or the instance ID (resource-name). For IPv6 only subnets, an instance DNS name must be based on the instance ID (resource-name).</p>"
        },
        "EnableResourceNameDnsARecordOnLaunch":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>"
        },
        "EnableResourceNameDnsAAAARecordOnLaunch":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p>"
        },
        "EnableLniAtDeviceIndex":{
          "shape":"Integer",
          "documentation":"<p> Indicates the device position for local network interfaces in this subnet. For example, <code>1</code> indicates local network interfaces in this subnet are the secondary network interface (eth1). A local network interface cannot be the primary network interface (eth0). </p>"
        },
        "DisableLniAtDeviceIndex":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p> Specify <code>true</code> to indicate that local network interfaces at the current position should be disabled. </p>"
        }
      }
    },
    "ModifyTrafficMirrorFilterNetworkServicesRequest":{
      "type":"structure",
      "required":["TrafficMirrorFilterId"],
      "members":{
        "TrafficMirrorFilterId":{
          "shape":"TrafficMirrorFilterId",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>"
        },
        "AddNetworkServices":{
          "shape":"TrafficMirrorNetworkServiceList",
          "documentation":"<p>The network service, for example Amazon DNS, that you want to mirror.</p>",
          "locationName":"AddNetworkService"
        },
        "RemoveNetworkServices":{
          "shape":"TrafficMirrorNetworkServiceList",
          "documentation":"<p>The network service, for example Amazon DNS, that you no longer want to mirror.</p>",
          "locationName":"RemoveNetworkService"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyTrafficMirrorFilterNetworkServicesResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilter":{
          "shape":"TrafficMirrorFilter",
          "documentation":"<p>The Traffic Mirror filter that the network service is associated with.</p>",
          "locationName":"trafficMirrorFilter"
        }
      }
    },
    "ModifyTrafficMirrorFilterRuleRequest":{
      "type":"structure",
      "required":["TrafficMirrorFilterRuleId"],
      "members":{
        "TrafficMirrorFilterRuleId":{
          "shape":"TrafficMirrorFilterRuleIdWithResolver",
          "documentation":"<p>The ID of the Traffic Mirror rule.</p>"
        },
        "TrafficDirection":{
          "shape":"TrafficDirection",
          "documentation":"<p>The type of traffic to assign to the rule.</p>"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The number of the Traffic Mirror rule. This number must be unique for each Traffic Mirror rule in a given direction. The rules are processed in ascending order by rule number.</p>"
        },
        "RuleAction":{
          "shape":"TrafficMirrorRuleAction",
          "documentation":"<p>The action to assign to the rule.</p>"
        },
        "DestinationPortRange":{
          "shape":"TrafficMirrorPortRangeRequest",
          "documentation":"<p>The destination ports that are associated with the Traffic Mirror rule.</p>"
        },
        "SourcePortRange":{
          "shape":"TrafficMirrorPortRangeRequest",
          "documentation":"<p>The port range to assign to the Traffic Mirror rule.</p>"
        },
        "Protocol":{
          "shape":"Integer",
          "documentation":"<p>The protocol, for example TCP, to assign to the Traffic Mirror rule.</p>"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The destination CIDR block to assign to the Traffic Mirror rule.</p>"
        },
        "SourceCidrBlock":{
          "shape":"String",
          "documentation":"<p>The source CIDR block to assign to the Traffic Mirror rule.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description to assign to the Traffic Mirror rule.</p>"
        },
        "RemoveFields":{
          "shape":"TrafficMirrorFilterRuleFieldList",
          "documentation":"<p>The properties that you want to remove from the Traffic Mirror filter rule.</p> <p>When you remove a property from a Traffic Mirror filter rule, the property is set to the default.</p>",
          "locationName":"RemoveField"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyTrafficMirrorFilterRuleResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterRule":{
          "shape":"TrafficMirrorFilterRule",
          "documentation":"<p>Modifies a Traffic Mirror rule.</p>",
          "locationName":"trafficMirrorFilterRule"
        }
      }
    },
    "ModifyTrafficMirrorSessionRequest":{
      "type":"structure",
      "required":["TrafficMirrorSessionId"],
      "members":{
        "TrafficMirrorSessionId":{
          "shape":"TrafficMirrorSessionId",
          "documentation":"<p>The ID of the Traffic Mirror session.</p>"
        },
        "TrafficMirrorTargetId":{
          "shape":"TrafficMirrorTargetId",
          "documentation":"<p>The Traffic Mirror target. The target must be in the same VPC as the source, or have a VPC peering connection with the source.</p>"
        },
        "TrafficMirrorFilterId":{
          "shape":"TrafficMirrorFilterId",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>"
        },
        "PacketLength":{
          "shape":"Integer",
          "documentation":"<p>The number of bytes in each packet to mirror. These are bytes after the VXLAN header. To mirror a subset, set this to the length (in bytes) to mirror. For example, if you set this value to 100, then the first 100 bytes that meet the filter criteria are copied to the target. Do not specify this parameter when you want to mirror the entire packet.</p>"
        },
        "SessionNumber":{
          "shape":"Integer",
          "documentation":"<p>The session number determines the order in which sessions are evaluated when an interface is used by multiple sessions. The first session with a matching filter is the one that mirrors the packets.</p> <p>Valid values are 1-32766.</p>"
        },
        "VirtualNetworkId":{
          "shape":"Integer",
          "documentation":"<p>The virtual network ID of the Traffic Mirror session.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description to assign to the Traffic Mirror session.</p>"
        },
        "RemoveFields":{
          "shape":"TrafficMirrorSessionFieldList",
          "documentation":"<p>The properties that you want to remove from the Traffic Mirror session.</p> <p>When you remove a property from a Traffic Mirror session, the property is set to the default.</p>",
          "locationName":"RemoveField"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyTrafficMirrorSessionResult":{
      "type":"structure",
      "members":{
        "TrafficMirrorSession":{
          "shape":"TrafficMirrorSession",
          "documentation":"<p>Information about the Traffic Mirror session.</p>",
          "locationName":"trafficMirrorSession"
        }
      }
    },
    "ModifyTransitGatewayOptions":{
      "type":"structure",
      "members":{
        "AddTransitGatewayCidrBlocks":{
          "shape":"TransitGatewayCidrBlockStringList",
          "documentation":"<p>Adds IPv4 or IPv6 CIDR blocks for the transit gateway. Must be a size /24 CIDR block or larger for IPv4, or a size /64 CIDR block or larger for IPv6.</p>"
        },
        "RemoveTransitGatewayCidrBlocks":{
          "shape":"TransitGatewayCidrBlockStringList",
          "documentation":"<p>Removes CIDR blocks for the transit gateway.</p>"
        },
        "VpnEcmpSupport":{
          "shape":"VpnEcmpSupportValue",
          "documentation":"<p>Enable or disable Equal Cost Multipath Protocol support.</p>"
        },
        "DnsSupport":{
          "shape":"DnsSupportValue",
          "documentation":"<p>Enable or disable DNS support.</p>"
        },
        "AutoAcceptSharedAttachments":{
          "shape":"AutoAcceptSharedAttachmentsValue",
          "documentation":"<p>Enable or disable automatic acceptance of attachment requests.</p>"
        },
        "DefaultRouteTableAssociation":{
          "shape":"DefaultRouteTableAssociationValue",
          "documentation":"<p>Enable or disable automatic association with the default association route table.</p>"
        },
        "AssociationDefaultRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the default association route table.</p>"
        },
        "DefaultRouteTablePropagation":{
          "shape":"DefaultRouteTablePropagationValue",
          "documentation":"<p>Enable or disable automatic propagation of routes to the default propagation route table.</p>"
        },
        "PropagationDefaultRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the default propagation route table.</p>"
        },
        "AmazonSideAsn":{
          "shape":"Long",
          "documentation":"<p>A private Autonomous System Number (ASN) for the Amazon side of a BGP session. The range is 64512 to 65534 for 16-bit ASNs and 4200000000 to 4294967294 for 32-bit ASNs.</p> <p>The modify ASN operation is not allowed on a transit gateway with active BGP sessions. You must first delete all transit gateway attachments that have BGP configured prior to modifying the ASN on the transit gateway.</p>"
        }
      },
      "documentation":"<p>The transit gateway options.</p>"
    },
    "ModifyTransitGatewayPrefixListReferenceRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "PrefixListId"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment to which traffic is routed.</p>"
        },
        "Blackhole":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to drop traffic that matches this route.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyTransitGatewayPrefixListReferenceResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPrefixListReference":{
          "shape":"TransitGatewayPrefixListReference",
          "documentation":"<p>Information about the prefix list reference.</p>",
          "locationName":"transitGatewayPrefixListReference"
        }
      }
    },
    "ModifyTransitGatewayRequest":{
      "type":"structure",
      "required":["TransitGatewayId"],
      "members":{
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the transit gateway.</p>"
        },
        "Options":{
          "shape":"ModifyTransitGatewayOptions",
          "documentation":"<p>The options to modify.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyTransitGatewayResult":{
      "type":"structure",
      "members":{
        "TransitGateway":{
          "shape":"TransitGateway",
          "documentation":"<p>Information about the transit gateway.</p>",
          "locationName":"transitGateway"
        }
      }
    },
    "ModifyTransitGatewayVpcAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "AddSubnetIds":{
          "shape":"TransitGatewaySubnetIdList",
          "documentation":"<p>The IDs of one or more subnets to add. You can specify at most one subnet per Availability Zone.</p>"
        },
        "RemoveSubnetIds":{
          "shape":"TransitGatewaySubnetIdList",
          "documentation":"<p>The IDs of one or more subnets to remove.</p>"
        },
        "Options":{
          "shape":"ModifyTransitGatewayVpcAttachmentRequestOptions",
          "documentation":"<p>The new VPC attachment options.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyTransitGatewayVpcAttachmentRequestOptions":{
      "type":"structure",
      "members":{
        "DnsSupport":{
          "shape":"DnsSupportValue",
          "documentation":"<p>Enable or disable DNS support. The default is <code>enable</code>.</p>"
        },
        "Ipv6Support":{
          "shape":"Ipv6SupportValue",
          "documentation":"<p>Enable or disable IPv6 support. The default is <code>enable</code>.</p>"
        },
        "ApplianceModeSupport":{
          "shape":"ApplianceModeSupportValue",
          "documentation":"<p>Enable or disable support for appliance mode. If enabled, a traffic flow between a source and destination uses the same Availability Zone for the VPC attachment for the lifetime of that flow. The default is <code>disable</code>.</p>"
        }
      },
      "documentation":"<p>Describes the options for a VPC attachment.</p>"
    },
    "ModifyTransitGatewayVpcAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayVpcAttachment":{
          "shape":"TransitGatewayVpcAttachment",
          "documentation":"<p>Information about the modified attachment.</p>",
          "locationName":"transitGatewayVpcAttachment"
        }
      }
    },
    "ModifyVerifiedAccessEndpointEniOptions":{
      "type":"structure",
      "members":{
        "Protocol":{
          "shape":"VerifiedAccessEndpointProtocol",
          "documentation":"<p>The IP protocol.</p>"
        },
        "Port":{
          "shape":"VerifiedAccessEndpointPortNumber",
          "documentation":"<p>The IP port number.</p>"
        }
      },
      "documentation":"<p>Options for a network-interface type Verified Access endpoint.</p>"
    },
    "ModifyVerifiedAccessEndpointLoadBalancerOptions":{
      "type":"structure",
      "members":{
        "SubnetIds":{
          "shape":"ModifyVerifiedAccessEndpointSubnetIdList",
          "documentation":"<p>The IDs of the subnets.</p>",
          "locationName":"SubnetId"
        },
        "Protocol":{
          "shape":"VerifiedAccessEndpointProtocol",
          "documentation":"<p>The IP protocol.</p>"
        },
        "Port":{
          "shape":"VerifiedAccessEndpointPortNumber",
          "documentation":"<p>The IP port number.</p>"
        }
      },
      "documentation":"<p>Describes a load balancer when creating an Amazon Web Services Verified Access endpoint using the <code>load-balancer</code> type.</p>"
    },
    "ModifyVerifiedAccessEndpointPolicyRequest":{
      "type":"structure",
      "required":[
        "VerifiedAccessEndpointId",
        "PolicyEnabled"
      ],
      "members":{
        "VerifiedAccessEndpointId":{
          "shape":"VerifiedAccessEndpointId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>"
        },
        "PolicyEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The status of the Verified Access policy.</p>"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVerifiedAccessEndpointPolicyResult":{
      "type":"structure",
      "members":{
        "PolicyEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The status of the Verified Access policy.</p>",
          "locationName":"policyEnabled"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>",
          "locationName":"policyDocument"
        }
      }
    },
    "ModifyVerifiedAccessEndpointRequest":{
      "type":"structure",
      "required":["VerifiedAccessEndpointId"],
      "members":{
        "VerifiedAccessEndpointId":{
          "shape":"VerifiedAccessEndpointId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>"
        },
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>"
        },
        "LoadBalancerOptions":{
          "shape":"ModifyVerifiedAccessEndpointLoadBalancerOptions",
          "documentation":"<p>The load balancer details if creating the Amazon Web Services Verified Access endpoint as <code>load-balancer</code>type.</p>"
        },
        "NetworkInterfaceOptions":{
          "shape":"ModifyVerifiedAccessEndpointEniOptions",
          "documentation":"<p>The network interface options.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access endpoint.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVerifiedAccessEndpointResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessEndpoint":{
          "shape":"VerifiedAccessEndpoint",
          "documentation":"<p>The Amazon Web Services Verified Access endpoint details.</p>",
          "locationName":"verifiedAccessEndpoint"
        }
      }
    },
    "ModifyVerifiedAccessEndpointSubnetIdList":{
      "type":"list",
      "member":{
        "shape":"SubnetId",
        "locationName":"item"
      }
    },
    "ModifyVerifiedAccessGroupPolicyRequest":{
      "type":"structure",
      "required":[
        "VerifiedAccessGroupId",
        "PolicyEnabled"
      ],
      "members":{
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>"
        },
        "PolicyEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The status of the Verified Access policy.</p>"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVerifiedAccessGroupPolicyResult":{
      "type":"structure",
      "members":{
        "PolicyEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The status of the Verified Access policy.</p>",
          "locationName":"policyEnabled"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services Verified Access policy document.</p>",
          "locationName":"policyDocument"
        }
      }
    },
    "ModifyVerifiedAccessGroupRequest":{
      "type":"structure",
      "required":["VerifiedAccessGroupId"],
      "members":{
        "VerifiedAccessGroupId":{
          "shape":"VerifiedAccessGroupId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>"
        },
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access group.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVerifiedAccessGroupResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessGroup":{
          "shape":"VerifiedAccessGroup",
          "documentation":"<p>Details of Amazon Web Services Verified Access group.</p>",
          "locationName":"verifiedAccessGroup"
        }
      }
    },
    "ModifyVerifiedAccessInstanceLoggingConfigurationRequest":{
      "type":"structure",
      "required":[
        "VerifiedAccessInstanceId",
        "AccessLogs"
      ],
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "AccessLogs":{
          "shape":"VerifiedAccessLogOptions",
          "documentation":"<p>The configuration options for Amazon Web Services Verified Access instances.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "ModifyVerifiedAccessInstanceLoggingConfigurationResult":{
      "type":"structure",
      "members":{
        "LoggingConfiguration":{
          "shape":"VerifiedAccessInstanceLoggingConfiguration",
          "documentation":"<p>The logging configuration for Amazon Web Services Verified Access instance.</p>",
          "locationName":"loggingConfiguration"
        }
      }
    },
    "ModifyVerifiedAccessInstanceRequest":{
      "type":"structure",
      "required":["VerifiedAccessInstanceId"],
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"VerifiedAccessInstanceId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access instance.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "ModifyVerifiedAccessInstanceResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstance":{
          "shape":"VerifiedAccessInstance",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstance"
        }
      }
    },
    "ModifyVerifiedAccessTrustProviderOidcOptions":{
      "type":"structure",
      "members":{
        "Scope":{
          "shape":"String",
          "documentation":"<p>OpenID Connect (OIDC) scopes are used by an application during authentication to authorize access to a user's details. Each scope returns a specific set of user attributes.</p>"
        }
      },
      "documentation":"<p>OpenID Connect options for an <code>oidc</code>-type, user-identity based trust provider.</p>"
    },
    "ModifyVerifiedAccessTrustProviderRequest":{
      "type":"structure",
      "required":["VerifiedAccessTrustProviderId"],
      "members":{
        "VerifiedAccessTrustProviderId":{
          "shape":"VerifiedAccessTrustProviderId",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>"
        },
        "OidcOptions":{
          "shape":"ModifyVerifiedAccessTrustProviderOidcOptions",
          "documentation":"<p>The OpenID Connect details for an <code>oidc</code>-type, user-identity based trust provider.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access trust provider.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "ModifyVerifiedAccessTrustProviderResult":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProvider":{
          "shape":"VerifiedAccessTrustProvider",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"verifiedAccessTrustProvider"
        }
      }
    },
    "ModifyVolumeAttributeRequest":{
      "type":"structure",
      "required":["VolumeId"],
      "members":{
        "AutoEnableIO":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether the volume should be auto-enabled for I/O operations.</p>"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the volume.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "ModifyVolumeRequest":{
      "type":"structure",
      "required":["VolumeId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the volume.</p>"
        },
        "Size":{
          "shape":"Integer",
          "documentation":"<p>The target size of the volume, in GiB. The target volume size must be greater than or equal to the existing size of the volume.</p> <p>The following are the supported volumes sizes for each volume type:</p> <ul> <li> <p> <code>gp2</code> and <code>gp3</code>: 1-16,384</p> </li> <li> <p> <code>io1</code> and <code>io2</code>: 4-16,384</p> </li> <li> <p> <code>st1</code> and <code>sc1</code>: 125-16,384</p> </li> <li> <p> <code>standard</code>: 1-1,024</p> </li> </ul> <p>Default: The existing size is retained.</p>"
        },
        "VolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The target EBS volume type of the volume. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html\">Amazon EBS volume types</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>Default: The existing type is retained.</p>"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The target IOPS rate of the volume. This parameter is valid only for <code>gp3</code>, <code>io1</code>, and <code>io2</code> volumes.</p> <p>The following are the supported values for each volume type:</p> <ul> <li> <p> <code>gp3</code>: 3,000-16,000 IOPS</p> </li> <li> <p> <code>io1</code>: 100-64,000 IOPS</p> </li> <li> <p> <code>io2</code>: 100-64,000 IOPS</p> </li> </ul> <p>Default: The existing value is retained if you keep the same volume type. If you change the volume type to <code>io1</code>, <code>io2</code>, or <code>gp3</code>, the default is 3,000.</p>"
        },
        "Throughput":{
          "shape":"Integer",
          "documentation":"<p>The target throughput of the volume, in MiB/s. This parameter is valid only for <code>gp3</code> volumes. The maximum value is 1,000.</p> <p>Default: The existing value is retained if the source and target volume type is <code>gp3</code>. Otherwise, the default value is 125.</p> <p>Valid Range: Minimum value of 125. Maximum value of 1000.</p>"
        },
        "MultiAttachEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether to enable Amazon EBS Multi-Attach. If you enable Multi-Attach, you can attach the volume to up to 16 <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\"> Nitro-based instances</a> in the same Availability Zone. This parameter is supported with <code>io1</code> and <code>io2</code> volumes only. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volumes-multi.html\"> Amazon EBS Multi-Attach</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        }
      }
    },
    "ModifyVolumeResult":{
      "type":"structure",
      "members":{
        "VolumeModification":{
          "shape":"VolumeModification",
          "documentation":"<p>Information about the volume modification.</p>",
          "locationName":"volumeModification"
        }
      }
    },
    "ModifyVpcAttributeRequest":{
      "type":"structure",
      "required":["VpcId"],
      "members":{
        "EnableDnsHostnames":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether the instances launched in the VPC get DNS hostnames. If enabled, instances in the VPC get DNS hostnames; otherwise, they do not.</p> <p>You cannot modify the DNS resolution and DNS hostnames attributes in the same request. Use separate requests for each attribute. You can only enable DNS hostnames if you've enabled DNS support.</p>"
        },
        "EnableDnsSupport":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether the DNS resolution is supported for the VPC. If enabled, queries to the Amazon provided DNS server at the 169.254.169.253 IP address, or the reserved IP address at the base of the VPC network range \"plus two\" succeed. If disabled, the Amazon provided DNS service in the VPC that resolves public DNS hostnames to IP addresses is not enabled.</p> <p>You cannot modify the DNS resolution and DNS hostnames attributes in the same request. Use separate requests for each attribute.</p>"
        },
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "EnableNetworkAddressUsageMetrics":{
          "shape":"AttributeBooleanValue",
          "documentation":"<p>Indicates whether Network Address Usage metrics are enabled for your VPC.</p>"
        }
      }
    },
    "ModifyVpcEndpointConnectionNotificationRequest":{
      "type":"structure",
      "required":["ConnectionNotificationId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ConnectionNotificationId":{
          "shape":"ConnectionNotificationId",
          "documentation":"<p>The ID of the notification.</p>"
        },
        "ConnectionNotificationArn":{
          "shape":"String",
          "documentation":"<p>The ARN for the SNS topic for the notification.</p>"
        },
        "ConnectionEvents":{
          "shape":"ValueStringList",
          "documentation":"<p>The events for the endpoint. Valid values are <code>Accept</code>, <code>Connect</code>, <code>Delete</code>, and <code>Reject</code>.</p>"
        }
      }
    },
    "ModifyVpcEndpointConnectionNotificationResult":{
      "type":"structure",
      "members":{
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyVpcEndpointRequest":{
      "type":"structure",
      "required":["VpcEndpointId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "VpcEndpointId":{
          "shape":"VpcEndpointId",
          "documentation":"<p>The ID of the endpoint.</p>"
        },
        "ResetPolicy":{
          "shape":"Boolean",
          "documentation":"<p>(Gateway endpoint) Specify <code>true</code> to reset the policy document to the default policy. The default policy allows full access to the service.</p>"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>(Interface and gateway endpoints) A policy to attach to the endpoint that controls access to the service. The policy must be in valid JSON format.</p>"
        },
        "AddRouteTableIds":{
          "shape":"VpcEndpointRouteTableIdList",
          "documentation":"<p>(Gateway endpoint) The IDs of the route tables to associate with the endpoint.</p>",
          "locationName":"AddRouteTableId"
        },
        "RemoveRouteTableIds":{
          "shape":"VpcEndpointRouteTableIdList",
          "documentation":"<p>(Gateway endpoint) The IDs of the route tables to disassociate from the endpoint.</p>",
          "locationName":"RemoveRouteTableId"
        },
        "AddSubnetIds":{
          "shape":"VpcEndpointSubnetIdList",
          "documentation":"<p>(Interface and Gateway Load Balancer endpoints) The IDs of the subnets in which to serve the endpoint. For a Gateway Load Balancer endpoint, you can specify only one subnet.</p>",
          "locationName":"AddSubnetId"
        },
        "RemoveSubnetIds":{
          "shape":"VpcEndpointSubnetIdList",
          "documentation":"<p>(Interface endpoint) The IDs of the subnets from which to remove the endpoint.</p>",
          "locationName":"RemoveSubnetId"
        },
        "AddSecurityGroupIds":{
          "shape":"VpcEndpointSecurityGroupIdList",
          "documentation":"<p>(Interface endpoint) The IDs of the security groups to associate with the network interface.</p>",
          "locationName":"AddSecurityGroupId"
        },
        "RemoveSecurityGroupIds":{
          "shape":"VpcEndpointSecurityGroupIdList",
          "documentation":"<p>(Interface endpoint) The IDs of the security groups to disassociate from the network interface.</p>",
          "locationName":"RemoveSecurityGroupId"
        },
        "IpAddressType":{
          "shape":"IpAddressType",
          "documentation":"<p>The IP address type for the endpoint.</p>"
        },
        "DnsOptions":{
          "shape":"DnsOptionsSpecification",
          "documentation":"<p>The DNS options for the endpoint.</p>"
        },
        "PrivateDnsEnabled":{
          "shape":"Boolean",
          "documentation":"<p>(Interface endpoint) Indicates whether a private hosted zone is associated with the VPC.</p>"
        }
      }
    },
    "ModifyVpcEndpointResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyVpcEndpointServiceConfigurationRequest":{
      "type":"structure",
      "required":["ServiceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the service.</p>"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>(Interface endpoint configuration) The private DNS name to assign to the endpoint service.</p>"
        },
        "RemovePrivateDnsName":{
          "shape":"Boolean",
          "documentation":"<p>(Interface endpoint configuration) Removes the private DNS name of the endpoint service.</p>"
        },
        "AcceptanceRequired":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether requests to create an endpoint to your service must be accepted.</p>"
        },
        "AddNetworkLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of Network Load Balancers to add to your service configuration.</p>",
          "locationName":"AddNetworkLoadBalancerArn"
        },
        "RemoveNetworkLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of Network Load Balancers to remove from your service configuration.</p>",
          "locationName":"RemoveNetworkLoadBalancerArn"
        },
        "AddGatewayLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of Gateway Load Balancers to add to your service configuration.</p>",
          "locationName":"AddGatewayLoadBalancerArn"
        },
        "RemoveGatewayLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of Gateway Load Balancers to remove from your service configuration.</p>",
          "locationName":"RemoveGatewayLoadBalancerArn"
        },
        "AddSupportedIpAddressTypes":{
          "shape":"ValueStringList",
          "documentation":"<p>The IP address types to add to your service configuration.</p>",
          "locationName":"AddSupportedIpAddressType"
        },
        "RemoveSupportedIpAddressTypes":{
          "shape":"ValueStringList",
          "documentation":"<p>The IP address types to remove from your service configuration.</p>",
          "locationName":"RemoveSupportedIpAddressType"
        }
      }
    },
    "ModifyVpcEndpointServiceConfigurationResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyVpcEndpointServicePayerResponsibilityRequest":{
      "type":"structure",
      "required":[
        "ServiceId",
        "PayerResponsibility"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the service.</p>"
        },
        "PayerResponsibility":{
          "shape":"PayerResponsibility",
          "documentation":"<p>The entity that is responsible for the endpoint costs. The default is the endpoint owner. If you set the payer responsibility to the service owner, you cannot set it back to the endpoint owner.</p>"
        }
      }
    },
    "ModifyVpcEndpointServicePayerResponsibilityResult":{
      "type":"structure",
      "members":{
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyVpcEndpointServicePermissionsRequest":{
      "type":"structure",
      "required":["ServiceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the service.</p>"
        },
        "AddAllowedPrincipals":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARN) of the principals. Permissions are granted to the principals in this list. To grant permissions to all principals, specify an asterisk (*).</p>"
        },
        "RemoveAllowedPrincipals":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARN) of the principals. Permissions are revoked for principals in this list.</p>"
        }
      }
    },
    "ModifyVpcEndpointServicePermissionsResult":{
      "type":"structure",
      "members":{
        "AddedPrincipals":{
          "shape":"AddedPrincipalSet",
          "documentation":"<p>Information about the added principals.</p>",
          "locationName":"addedPrincipalSet"
        },
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyVpcPeeringConnectionOptionsRequest":{
      "type":"structure",
      "required":["VpcPeeringConnectionId"],
      "members":{
        "AccepterPeeringConnectionOptions":{
          "shape":"PeeringConnectionOptionsRequest",
          "documentation":"<p>The VPC peering connection options for the accepter VPC.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "RequesterPeeringConnectionOptions":{
          "shape":"PeeringConnectionOptionsRequest",
          "documentation":"<p>The VPC peering connection options for the requester VPC.</p>"
        },
        "VpcPeeringConnectionId":{
          "shape":"VpcPeeringConnectionId",
          "documentation":"<p>The ID of the VPC peering connection.</p>"
        }
      }
    },
    "ModifyVpcPeeringConnectionOptionsResult":{
      "type":"structure",
      "members":{
        "AccepterPeeringConnectionOptions":{
          "shape":"PeeringConnectionOptions",
          "documentation":"<p>Information about the VPC peering connection options for the accepter VPC.</p>",
          "locationName":"accepterPeeringConnectionOptions"
        },
        "RequesterPeeringConnectionOptions":{
          "shape":"PeeringConnectionOptions",
          "documentation":"<p>Information about the VPC peering connection options for the requester VPC.</p>",
          "locationName":"requesterPeeringConnectionOptions"
        }
      }
    },
    "ModifyVpcTenancyRequest":{
      "type":"structure",
      "required":[
        "VpcId",
        "InstanceTenancy"
      ],
      "members":{
        "VpcId":{
          "shape":"VpcId",
          "documentation":"<p>The ID of the VPC.</p>"
        },
        "InstanceTenancy":{
          "shape":"VpcTenancy",
          "documentation":"<p>The instance tenancy attribute for the VPC. </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVpcTenancyResult":{
      "type":"structure",
      "members":{
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ModifyVpnConnectionOptionsRequest":{
      "type":"structure",
      "required":["VpnConnectionId"],
      "members":{
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the Site-to-Site VPN connection. </p>"
        },
        "LocalIpv4NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR on the customer gateway (on-premises) side of the VPN connection.</p> <p>Default: <code>0.0.0.0/0</code> </p>"
        },
        "RemoteIpv4NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR on the Amazon Web Services side of the VPN connection.</p> <p>Default: <code>0.0.0.0/0</code> </p>"
        },
        "LocalIpv6NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR on the customer gateway (on-premises) side of the VPN connection.</p> <p>Default: <code>::/0</code> </p>"
        },
        "RemoteIpv6NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR on the Amazon Web Services side of the VPN connection.</p> <p>Default: <code>::/0</code> </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVpnConnectionOptionsResult":{
      "type":"structure",
      "members":{
        "VpnConnection":{
          "shape":"VpnConnection",
          "documentation":"<p>Information about the VPN connection.</p>",
          "locationName":"vpnConnection"
        }
      }
    },
    "ModifyVpnConnectionRequest":{
      "type":"structure",
      "required":["VpnConnectionId"],
      "members":{
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the VPN connection.</p>"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>"
        },
        "CustomerGatewayId":{
          "shape":"CustomerGatewayId",
          "documentation":"<p>The ID of the customer gateway at your end of the VPN connection.</p>"
        },
        "VpnGatewayId":{
          "shape":"VpnGatewayId",
          "documentation":"<p>The ID of the virtual private gateway at the Amazon Web Services side of the VPN connection.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVpnConnectionResult":{
      "type":"structure",
      "members":{
        "VpnConnection":{
          "shape":"VpnConnection",
          "documentation":"<p>Information about the VPN connection.</p>",
          "locationName":"vpnConnection"
        }
      }
    },
    "ModifyVpnTunnelCertificateRequest":{
      "type":"structure",
      "required":[
        "VpnConnectionId",
        "VpnTunnelOutsideIpAddress"
      ],
      "members":{
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the Amazon Web Services Site-to-Site VPN connection.</p>"
        },
        "VpnTunnelOutsideIpAddress":{
          "shape":"String",
          "documentation":"<p>The external IP address of the VPN tunnel.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVpnTunnelCertificateResult":{
      "type":"structure",
      "members":{
        "VpnConnection":{
          "shape":"VpnConnection",
          "documentation":"<p>Information about the VPN connection.</p>",
          "locationName":"vpnConnection"
        }
      }
    },
    "ModifyVpnTunnelOptionsRequest":{
      "type":"structure",
      "required":[
        "VpnConnectionId",
        "VpnTunnelOutsideIpAddress",
        "TunnelOptions"
      ],
      "members":{
        "VpnConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the Amazon Web Services Site-to-Site VPN connection.</p>"
        },
        "VpnTunnelOutsideIpAddress":{
          "shape":"String",
          "documentation":"<p>The external IP address of the VPN tunnel.</p>"
        },
        "TunnelOptions":{
          "shape":"ModifyVpnTunnelOptionsSpecification",
          "documentation":"<p>The tunnel options to modify.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ModifyVpnTunnelOptionsResult":{
      "type":"structure",
      "members":{
        "VpnConnection":{
          "shape":"VpnConnection",
          "documentation":"<p>Information about the VPN connection.</p>",
          "locationName":"vpnConnection"
        }
      }
    },
    "ModifyVpnTunnelOptionsSpecification":{
      "type":"structure",
      "members":{
        "TunnelInsideCidr":{
          "shape":"String",
          "documentation":"<p>The range of inside IPv4 addresses for the tunnel. Any specified CIDR blocks must be unique across all VPN connections that use the same virtual private gateway. </p> <p>Constraints: A size /30 CIDR block from the <code>169.254.0.0/16</code> range. The following CIDR blocks are reserved and cannot be used:</p> <ul> <li> <p> <code>169.254.0.0/30</code> </p> </li> <li> <p> <code>169.254.1.0/30</code> </p> </li> <li> <p> <code>169.254.2.0/30</code> </p> </li> <li> <p> <code>169.254.3.0/30</code> </p> </li> <li> <p> <code>169.254.4.0/30</code> </p> </li> <li> <p> <code>169.254.5.0/30</code> </p> </li> <li> <p> <code>169.254.169.252/30</code> </p> </li> </ul>"
        },
        "TunnelInsideIpv6Cidr":{
          "shape":"String",
          "documentation":"<p>The range of inside IPv6 addresses for the tunnel. Any specified CIDR blocks must be unique across all VPN connections that use the same transit gateway.</p> <p>Constraints: A size /126 CIDR block from the local <code>fd00::/8</code> range.</p>"
        },
        "PreSharedKey":{
          "shape":"String",
          "documentation":"<p>The pre-shared key (PSK) to establish initial authentication between the virtual private gateway and the customer gateway.</p> <p>Constraints: Allowed characters are alphanumeric characters, periods (.), and underscores (_). Must be between 8 and 64 characters in length and cannot start with zero (0).</p>"
        },
        "Phase1LifetimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The lifetime for phase 1 of the IKE negotiation, in seconds.</p> <p>Constraints: A value between 900 and 28,800.</p> <p>Default: <code>28800</code> </p>"
        },
        "Phase2LifetimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The lifetime for phase 2 of the IKE negotiation, in seconds.</p> <p>Constraints: A value between 900 and 3,600. The value must be less than the value for <code>Phase1LifetimeSeconds</code>.</p> <p>Default: <code>3600</code> </p>"
        },
        "RekeyMarginTimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The margin time, in seconds, before the phase 2 lifetime expires, during which the Amazon Web Services side of the VPN connection performs an IKE rekey. The exact time of the rekey is randomly selected based on the value for <code>RekeyFuzzPercentage</code>.</p> <p>Constraints: A value between 60 and half of <code>Phase2LifetimeSeconds</code>.</p> <p>Default: <code>540</code> </p>"
        },
        "RekeyFuzzPercentage":{
          "shape":"Integer",
          "documentation":"<p>The percentage of the rekey window (determined by <code>RekeyMarginTimeSeconds</code>) during which the rekey time is randomly selected.</p> <p>Constraints: A value between 0 and 100.</p> <p>Default: <code>100</code> </p>"
        },
        "ReplayWindowSize":{
          "shape":"Integer",
          "documentation":"<p>The number of packets in an IKE replay window.</p> <p>Constraints: A value between 64 and 2048.</p> <p>Default: <code>1024</code> </p>"
        },
        "DPDTimeoutSeconds":{
          "shape":"Integer",
          "documentation":"<p>The number of seconds after which a DPD timeout occurs.</p> <p>Constraints: A value greater than or equal to 30.</p> <p>Default: <code>30</code> </p>"
        },
        "DPDTimeoutAction":{
          "shape":"String",
          "documentation":"<p>The action to take after DPD timeout occurs. Specify <code>restart</code> to restart the IKE initiation. Specify <code>clear</code> to end the IKE session.</p> <p>Valid Values: <code>clear</code> | <code>none</code> | <code>restart</code> </p> <p>Default: <code>clear</code> </p>"
        },
        "Phase1EncryptionAlgorithms":{
          "shape":"Phase1EncryptionAlgorithmsRequestList",
          "documentation":"<p>One or more encryption algorithms that are permitted for the VPN tunnel for phase 1 IKE negotiations.</p> <p>Valid values: <code>AES128</code> | <code>AES256</code> | <code>AES128-GCM-16</code> | <code>AES256-GCM-16</code> </p>",
          "locationName":"Phase1EncryptionAlgorithm"
        },
        "Phase2EncryptionAlgorithms":{
          "shape":"Phase2EncryptionAlgorithmsRequestList",
          "documentation":"<p>One or more encryption algorithms that are permitted for the VPN tunnel for phase 2 IKE negotiations.</p> <p>Valid values: <code>AES128</code> | <code>AES256</code> | <code>AES128-GCM-16</code> | <code>AES256-GCM-16</code> </p>",
          "locationName":"Phase2EncryptionAlgorithm"
        },
        "Phase1IntegrityAlgorithms":{
          "shape":"Phase1IntegrityAlgorithmsRequestList",
          "documentation":"<p>One or more integrity algorithms that are permitted for the VPN tunnel for phase 1 IKE negotiations.</p> <p>Valid values: <code>SHA1</code> | <code>SHA2-256</code> | <code>SHA2-384</code> | <code>SHA2-512</code> </p>",
          "locationName":"Phase1IntegrityAlgorithm"
        },
        "Phase2IntegrityAlgorithms":{
          "shape":"Phase2IntegrityAlgorithmsRequestList",
          "documentation":"<p>One or more integrity algorithms that are permitted for the VPN tunnel for phase 2 IKE negotiations.</p> <p>Valid values: <code>SHA1</code> | <code>SHA2-256</code> | <code>SHA2-384</code> | <code>SHA2-512</code> </p>",
          "locationName":"Phase2IntegrityAlgorithm"
        },
        "Phase1DHGroupNumbers":{
          "shape":"Phase1DHGroupNumbersRequestList",
          "documentation":"<p>One or more Diffie-Hellman group numbers that are permitted for the VPN tunnel for phase 1 IKE negotiations.</p> <p>Valid values: <code>2</code> | <code>14</code> | <code>15</code> | <code>16</code> | <code>17</code> | <code>18</code> | <code>19</code> | <code>20</code> | <code>21</code> | <code>22</code> | <code>23</code> | <code>24</code> </p>",
          "locationName":"Phase1DHGroupNumber"
        },
        "Phase2DHGroupNumbers":{
          "shape":"Phase2DHGroupNumbersRequestList",
          "documentation":"<p>One or more Diffie-Hellman group numbers that are permitted for the VPN tunnel for phase 2 IKE negotiations.</p> <p>Valid values: <code>2</code> | <code>5</code> | <code>14</code> | <code>15</code> | <code>16</code> | <code>17</code> | <code>18</code> | <code>19</code> | <code>20</code> | <code>21</code> | <code>22</code> | <code>23</code> | <code>24</code> </p>",
          "locationName":"Phase2DHGroupNumber"
        },
        "IKEVersions":{
          "shape":"IKEVersionsRequestList",
          "documentation":"<p>The IKE versions that are permitted for the VPN tunnel.</p> <p>Valid values: <code>ikev1</code> | <code>ikev2</code> </p>",
          "locationName":"IKEVersion"
        },
        "StartupAction":{
          "shape":"String",
          "documentation":"<p>The action to take when the establishing the tunnel for the VPN connection. By default, your customer gateway device must initiate the IKE negotiation and bring up the tunnel. Specify <code>start</code> for Amazon Web Services to initiate the IKE negotiation.</p> <p>Valid Values: <code>add</code> | <code>start</code> </p> <p>Default: <code>add</code> </p>"
        },
        "LogOptions":{
          "shape":"VpnTunnelLogOptionsSpecification",
          "documentation":"<p>Options for logging VPN tunnel activity.</p>"
        }
      },
      "documentation":"<p>The Amazon Web Services Site-to-Site VPN tunnel options to modify.</p>"
    },
    "MonitorInstancesRequest":{
      "type":"structure",
      "required":["InstanceIds"],
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The IDs of the instances.</p>",
          "locationName":"InstanceId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "MonitorInstancesResult":{
      "type":"structure",
      "members":{
        "InstanceMonitorings":{
          "shape":"InstanceMonitoringList",
          "documentation":"<p>The monitoring information.</p>",
          "locationName":"instancesSet"
        }
      }
    },
    "Monitoring":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"MonitoringState",
          "documentation":"<p>Indicates whether detailed monitoring is enabled. Otherwise, basic monitoring is enabled.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes the monitoring of an instance.</p>"
    },
    "MonitoringState":{
      "type":"string",
      "enum":[
        "disabled",
        "disabling",
        "enabled",
        "pending"
      ]
    },
    "MoveAddressToVpcRequest":{
      "type":"structure",
      "required":["PublicIp"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address.</p>",
          "locationName":"publicIp"
        }
      }
    },
    "MoveAddressToVpcResult":{
      "type":"structure",
      "members":{
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>The allocation ID for the Elastic IP address.</p>",
          "locationName":"allocationId"
        },
        "Status":{
          "shape":"Status",
          "documentation":"<p>The status of the move of the IP address.</p>",
          "locationName":"status"
        }
      }
    },
    "MoveByoipCidrToIpamRequest":{
      "type":"structure",
      "required":[
        "Cidr",
        "IpamPoolId",
        "IpamPoolOwner"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The BYOIP CIDR.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The IPAM pool ID.</p>"
        },
        "IpamPoolOwner":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the IPAM pool.</p>"
        }
      }
    },
    "MoveByoipCidrToIpamResult":{
      "type":"structure",
      "members":{
        "ByoipCidr":{
          "shape":"ByoipCidr",
          "documentation":"<p>The BYOIP CIDR.</p>",
          "locationName":"byoipCidr"
        }
      }
    },
    "MoveStatus":{
      "type":"string",
      "enum":[
        "movingToVpc",
        "restoringToClassic"
      ]
    },
    "MovingAddressStatus":{
      "type":"structure",
      "members":{
        "MoveStatus":{
          "shape":"MoveStatus",
          "documentation":"<p>The status of the Elastic IP address that's being moved to the EC2-VPC platform, or restored to the EC2-Classic platform.</p>",
          "locationName":"moveStatus"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address.</p>",
          "locationName":"publicIp"
        }
      },
      "documentation":"<p>Describes the status of a moving Elastic IP address.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "MovingAddressStatusSet":{
      "type":"list",
      "member":{
        "shape":"MovingAddressStatus",
        "locationName":"item"
      }
    },
    "MulticastSupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "NatGateway":{
      "type":"structure",
      "members":{
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time the NAT gateway was created.</p>",
          "locationName":"createTime"
        },
        "DeleteTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time the NAT gateway was deleted, if applicable.</p>",
          "locationName":"deleteTime"
        },
        "FailureCode":{
          "shape":"String",
          "documentation":"<p>If the NAT gateway could not be created, specifies the error code for the failure. (<code>InsufficientFreeAddressesInSubnet</code> | <code>Gateway.NotAttached</code> | <code>InvalidAllocationID.NotFound</code> | <code>Resource.AlreadyAssociated</code> | <code>InternalError</code> | <code>InvalidSubnetID.NotFound</code>)</p>",
          "locationName":"failureCode"
        },
        "FailureMessage":{
          "shape":"String",
          "documentation":"<p>If the NAT gateway could not be created, specifies the error message for the failure, that corresponds to the error code.</p> <ul> <li> <p>For InsufficientFreeAddressesInSubnet: \"Subnet has insufficient free addresses to create this NAT gateway\"</p> </li> <li> <p>For Gateway.NotAttached: \"Network vpc-xxxxxxxx has no Internet gateway attached\"</p> </li> <li> <p>For InvalidAllocationID.NotFound: \"Elastic IP address eipalloc-xxxxxxxx could not be associated with this NAT gateway\"</p> </li> <li> <p>For Resource.AlreadyAssociated: \"Elastic IP address eipalloc-xxxxxxxx is already associated\"</p> </li> <li> <p>For InternalError: \"Network interface eni-xxxxxxxx, created and used internally by this NAT gateway is in an invalid state. Please try again.\"</p> </li> <li> <p>For InvalidSubnetID.NotFound: \"The specified subnet subnet-xxxxxxxx does not exist or could not be found.\"</p> </li> </ul>",
          "locationName":"failureMessage"
        },
        "NatGatewayAddresses":{
          "shape":"NatGatewayAddressList",
          "documentation":"<p>Information about the IP addresses and network interface associated with the NAT gateway.</p>",
          "locationName":"natGatewayAddressSet"
        },
        "NatGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the NAT gateway.</p>",
          "locationName":"natGatewayId"
        },
        "ProvisionedBandwidth":{
          "shape":"ProvisionedBandwidth",
          "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>",
          "locationName":"provisionedBandwidth"
        },
        "State":{
          "shape":"NatGatewayState",
          "documentation":"<p>The state of the NAT gateway.</p> <ul> <li> <p> <code>pending</code>: The NAT gateway is being created and is not ready to process traffic.</p> </li> <li> <p> <code>failed</code>: The NAT gateway could not be created. Check the <code>failureCode</code> and <code>failureMessage</code> fields for the reason.</p> </li> <li> <p> <code>available</code>: The NAT gateway is able to process traffic. This status remains until you delete the NAT gateway, and does not indicate the health of the NAT gateway.</p> </li> <li> <p> <code>deleting</code>: The NAT gateway is in the process of being terminated and may still be processing traffic.</p> </li> <li> <p> <code>deleted</code>: The NAT gateway has been terminated and is no longer processing traffic.</p> </li> </ul>",
          "locationName":"state"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet in which the NAT gateway is located.</p>",
          "locationName":"subnetId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC in which the NAT gateway is located.</p>",
          "locationName":"vpcId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the NAT gateway.</p>",
          "locationName":"tagSet"
        },
        "ConnectivityType":{
          "shape":"ConnectivityType",
          "documentation":"<p>Indicates whether the NAT gateway supports public or private connectivity.</p>",
          "locationName":"connectivityType"
        }
      },
      "documentation":"<p>Describes a NAT gateway.</p>"
    },
    "NatGatewayAddress":{
      "type":"structure",
      "members":{
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>[Public NAT gateway only] The allocation ID of the Elastic IP address that's associated with the NAT gateway.</p>",
          "locationName":"allocationId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface associated with the NAT gateway.</p>",
          "locationName":"networkInterfaceId"
        },
        "PrivateIp":{
          "shape":"String",
          "documentation":"<p>The private IP address associated with the NAT gateway.</p>",
          "locationName":"privateIp"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>[Public NAT gateway only] The Elastic IP address associated with the NAT gateway.</p>",
          "locationName":"publicIp"
        },
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>[Public NAT gateway only] The association ID of the Elastic IP address that's associated with the NAT gateway.</p>",
          "locationName":"associationId"
        },
        "IsPrimary":{
          "shape":"Boolean",
          "documentation":"<p>Defines if the IP address is the primary address.</p>",
          "locationName":"isPrimary"
        },
        "FailureMessage":{
          "shape":"String",
          "documentation":"<p>The address failure message.</p>",
          "locationName":"failureMessage"
        },
        "Status":{
          "shape":"NatGatewayAddressStatus",
          "documentation":"<p>The address status.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Describes the IP addresses and network interface associated with a NAT gateway.</p>"
    },
    "NatGatewayAddressList":{
      "type":"list",
      "member":{
        "shape":"NatGatewayAddress",
        "locationName":"item"
      }
    },
    "NatGatewayAddressStatus":{
      "type":"string",
      "enum":[
        "assigning",
        "unassigning",
        "associating",
        "disassociating",
        "succeeded",
        "failed"
      ]
    },
    "NatGatewayId":{"type":"string"},
    "NatGatewayIdStringList":{
      "type":"list",
      "member":{
        "shape":"NatGatewayId",
        "locationName":"item"
      }
    },
    "NatGatewayList":{
      "type":"list",
      "member":{
        "shape":"NatGateway",
        "locationName":"item"
      }
    },
    "NatGatewayState":{
      "type":"string",
      "enum":[
        "pending",
        "failed",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "NetmaskLength":{"type":"integer"},
    "NetworkAcl":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"NetworkAclAssociationList",
          "documentation":"<p>Any associations between the network ACL and one or more subnets</p>",
          "locationName":"associationSet"
        },
        "Entries":{
          "shape":"NetworkAclEntryList",
          "documentation":"<p>One or more entries (rules) in the network ACL.</p>",
          "locationName":"entrySet"
        },
        "IsDefault":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is the default network ACL for the VPC.</p>",
          "locationName":"default"
        },
        "NetworkAclId":{
          "shape":"String",
          "documentation":"<p>The ID of the network ACL.</p>",
          "locationName":"networkAclId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the network ACL.</p>",
          "locationName":"tagSet"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC for the network ACL.</p>",
          "locationName":"vpcId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the network ACL.</p>",
          "locationName":"ownerId"
        }
      },
      "documentation":"<p>Describes a network ACL.</p>"
    },
    "NetworkAclAssociation":{
      "type":"structure",
      "members":{
        "NetworkAclAssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the association between a network ACL and a subnet.</p>",
          "locationName":"networkAclAssociationId"
        },
        "NetworkAclId":{
          "shape":"String",
          "documentation":"<p>The ID of the network ACL.</p>",
          "locationName":"networkAclId"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        }
      },
      "documentation":"<p>Describes an association between a network ACL and a subnet.</p>"
    },
    "NetworkAclAssociationId":{"type":"string"},
    "NetworkAclAssociationList":{
      "type":"list",
      "member":{
        "shape":"NetworkAclAssociation",
        "locationName":"item"
      }
    },
    "NetworkAclEntry":{
      "type":"structure",
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 network range to allow or deny, in CIDR notation.</p>",
          "locationName":"cidrBlock"
        },
        "Egress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the rule is an egress rule (applied to traffic leaving the subnet).</p>",
          "locationName":"egress"
        },
        "IcmpTypeCode":{
          "shape":"IcmpTypeCode",
          "documentation":"<p>ICMP protocol: The ICMP type and code.</p>",
          "locationName":"icmpTypeCode"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 network range to allow or deny, in CIDR notation.</p>",
          "locationName":"ipv6CidrBlock"
        },
        "PortRange":{
          "shape":"PortRange",
          "documentation":"<p>TCP or UDP protocols: The range of ports the rule applies to.</p>",
          "locationName":"portRange"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol number. A value of \"-1\" means all protocols.</p>",
          "locationName":"protocol"
        },
        "RuleAction":{
          "shape":"RuleAction",
          "documentation":"<p>Indicates whether to allow or deny the traffic that matches the rule.</p>",
          "locationName":"ruleAction"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The rule number for the entry. ACL entries are processed in ascending order by rule number.</p>",
          "locationName":"ruleNumber"
        }
      },
      "documentation":"<p>Describes an entry in a network ACL.</p>"
    },
    "NetworkAclEntryList":{
      "type":"list",
      "member":{
        "shape":"NetworkAclEntry",
        "locationName":"item"
      }
    },
    "NetworkAclId":{"type":"string"},
    "NetworkAclIdStringList":{
      "type":"list",
      "member":{
        "shape":"NetworkAclId",
        "locationName":"item"
      }
    },
    "NetworkAclList":{
      "type":"list",
      "member":{
        "shape":"NetworkAcl",
        "locationName":"item"
      }
    },
    "NetworkBandwidthGbps":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Double",
          "documentation":"<p>The minimum amount of network bandwidth, in Gbps. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Double",
          "documentation":"<p>The maximum amount of network bandwidth, in Gbps. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum amount of network bandwidth, in gigabits per second (Gbps).</p> <note> <p>Setting the minimum bandwidth does not guarantee that your instance will achieve the minimum bandwidth. Amazon EC2 will identify instance types that support the specified minimum bandwidth, but the actual bandwidth of your instance might go below the specified minimum at times. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-network-bandwidth.html#available-instance-bandwidth\">Available instance bandwidth</a> in the <i>Amazon EC2 User Guide</i>.</p> </note>"
    },
    "NetworkBandwidthGbpsRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Double",
          "documentation":"<p>The minimum amount of network bandwidth, in Gbps. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Double",
          "documentation":"<p>The maximum amount of network bandwidth, in Gbps. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum amount of network bandwidth, in gigabits per second (Gbps).</p> <note> <p>Setting the minimum bandwidth does not guarantee that your instance will achieve the minimum bandwidth. Amazon EC2 will identify instance types that support the specified minimum bandwidth, but the actual bandwidth of your instance might go below the specified minimum at times. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-network-bandwidth.html#available-instance-bandwidth\">Available instance bandwidth</a> in the <i>Amazon EC2 User Guide</i>.</p> </note>"
    },
    "NetworkCardIndex":{"type":"integer"},
    "NetworkCardInfo":{
      "type":"structure",
      "members":{
        "NetworkCardIndex":{
          "shape":"NetworkCardIndex",
          "documentation":"<p>The index of the network card.</p>",
          "locationName":"networkCardIndex"
        },
        "NetworkPerformance":{
          "shape":"NetworkPerformance",
          "documentation":"<p>The network performance of the network card.</p>",
          "locationName":"networkPerformance"
        },
        "MaximumNetworkInterfaces":{
          "shape":"MaxNetworkInterfaces",
          "documentation":"<p>The maximum number of network interfaces for the network card.</p>",
          "locationName":"maximumNetworkInterfaces"
        }
      },
      "documentation":"<p>Describes the network card support of the instance type.</p>"
    },
    "NetworkCardInfoList":{
      "type":"list",
      "member":{
        "shape":"NetworkCardInfo",
        "locationName":"item"
      }
    },
    "NetworkInfo":{
      "type":"structure",
      "members":{
        "NetworkPerformance":{
          "shape":"NetworkPerformance",
          "documentation":"<p>The network performance.</p>",
          "locationName":"networkPerformance"
        },
        "MaximumNetworkInterfaces":{
          "shape":"MaxNetworkInterfaces",
          "documentation":"<p>The maximum number of network interfaces for the instance type.</p>",
          "locationName":"maximumNetworkInterfaces"
        },
        "MaximumNetworkCards":{
          "shape":"MaximumNetworkCards",
          "documentation":"<p>The maximum number of physical network cards that can be allocated to the instance.</p>",
          "locationName":"maximumNetworkCards"
        },
        "DefaultNetworkCardIndex":{
          "shape":"DefaultNetworkCardIndex",
          "documentation":"<p>The index of the default network card, starting at 0.</p>",
          "locationName":"defaultNetworkCardIndex"
        },
        "NetworkCards":{
          "shape":"NetworkCardInfoList",
          "documentation":"<p>Describes the network cards for the instance type.</p>",
          "locationName":"networkCards"
        },
        "Ipv4AddressesPerInterface":{
          "shape":"MaxIpv4AddrPerInterface",
          "documentation":"<p>The maximum number of IPv4 addresses per network interface.</p>",
          "locationName":"ipv4AddressesPerInterface"
        },
        "Ipv6AddressesPerInterface":{
          "shape":"MaxIpv6AddrPerInterface",
          "documentation":"<p>The maximum number of IPv6 addresses per network interface.</p>",
          "locationName":"ipv6AddressesPerInterface"
        },
        "Ipv6Supported":{
          "shape":"Ipv6Flag",
          "documentation":"<p>Indicates whether IPv6 is supported.</p>",
          "locationName":"ipv6Supported"
        },
        "EnaSupport":{
          "shape":"EnaSupport",
          "documentation":"<p>Indicates whether Elastic Network Adapter (ENA) is supported.</p>",
          "locationName":"enaSupport"
        },
        "EfaSupported":{
          "shape":"EfaSupportedFlag",
          "documentation":"<p>Indicates whether Elastic Fabric Adapter (EFA) is supported.</p>",
          "locationName":"efaSupported"
        },
        "EfaInfo":{
          "shape":"EfaInfo",
          "documentation":"<p>Describes the Elastic Fabric Adapters for the instance type.</p>",
          "locationName":"efaInfo"
        },
        "EncryptionInTransitSupported":{
          "shape":"EncryptionInTransitSupported",
          "documentation":"<p>Indicates whether the instance type automatically encrypts in-transit traffic between instances.</p>",
          "locationName":"encryptionInTransitSupported"
        },
        "EnaSrdSupported":{
          "shape":"EnaSrdSupported",
          "documentation":"<p>Indicates whether the instance type supports ENA Express. ENA Express uses Amazon Web Services Scalable Reliable Datagram (SRD) technology to increase the maximum bandwidth used per stream and minimize tail latency of network traffic between EC2 instances.</p>",
          "locationName":"enaSrdSupported"
        }
      },
      "documentation":"<p>Describes the networking features of the instance type.</p>"
    },
    "NetworkInsightsAccessScope":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScopeId"
        },
        "NetworkInsightsAccessScopeArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScopeArn"
        },
        "CreatedDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The creation date.</p>",
          "locationName":"createdDate"
        },
        "UpdatedDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The last updated date.</p>",
          "locationName":"updatedDate"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Network Access Scope.</p>"
    },
    "NetworkInsightsAccessScopeAnalysis":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalysisId":{
          "shape":"NetworkInsightsAccessScopeAnalysisId",
          "documentation":"<p>The ID of the Network Access Scope analysis.</p>",
          "locationName":"networkInsightsAccessScopeAnalysisId"
        },
        "NetworkInsightsAccessScopeAnalysisArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Network Access Scope analysis.</p>",
          "locationName":"networkInsightsAccessScopeAnalysisArn"
        },
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScopeId"
        },
        "Status":{
          "shape":"AnalysisStatus",
          "documentation":"<p>The status.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message.</p>",
          "locationName":"statusMessage"
        },
        "WarningMessage":{
          "shape":"String",
          "documentation":"<p>The warning message.</p>",
          "locationName":"warningMessage"
        },
        "StartDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The analysis start date.</p>",
          "locationName":"startDate"
        },
        "EndDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The analysis end date.</p>",
          "locationName":"endDate"
        },
        "FindingsFound":{
          "shape":"FindingsFound",
          "documentation":"<p>Indicates whether there are findings.</p>",
          "locationName":"findingsFound"
        },
        "AnalyzedEniCount":{
          "shape":"Integer",
          "documentation":"<p>The number of network interfaces analyzed.</p>",
          "locationName":"analyzedEniCount"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Network Access Scope analysis.</p>"
    },
    "NetworkInsightsAccessScopeAnalysisId":{"type":"string"},
    "NetworkInsightsAccessScopeAnalysisIdList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsAccessScopeAnalysisId",
        "locationName":"item"
      }
    },
    "NetworkInsightsAccessScopeAnalysisList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsAccessScopeAnalysis",
        "locationName":"item"
      }
    },
    "NetworkInsightsAccessScopeContent":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>",
          "locationName":"networkInsightsAccessScopeId"
        },
        "MatchPaths":{
          "shape":"AccessScopePathList",
          "documentation":"<p>The paths to match.</p>",
          "locationName":"matchPathSet"
        },
        "ExcludePaths":{
          "shape":"AccessScopePathList",
          "documentation":"<p>The paths to exclude.</p>",
          "locationName":"excludePathSet"
        }
      },
      "documentation":"<p>Describes the Network Access Scope content.</p>"
    },
    "NetworkInsightsAccessScopeId":{"type":"string"},
    "NetworkInsightsAccessScopeIdList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsAccessScopeId",
        "locationName":"item"
      }
    },
    "NetworkInsightsAccessScopeList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsAccessScope",
        "locationName":"item"
      }
    },
    "NetworkInsightsAnalysis":{
      "type":"structure",
      "members":{
        "NetworkInsightsAnalysisId":{
          "shape":"NetworkInsightsAnalysisId",
          "documentation":"<p>The ID of the network insights analysis.</p>",
          "locationName":"networkInsightsAnalysisId"
        },
        "NetworkInsightsAnalysisArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the network insights analysis.</p>",
          "locationName":"networkInsightsAnalysisArn"
        },
        "NetworkInsightsPathId":{
          "shape":"NetworkInsightsPathId",
          "documentation":"<p>The ID of the path.</p>",
          "locationName":"networkInsightsPathId"
        },
        "AdditionalAccounts":{
          "shape":"ValueStringList",
          "documentation":"<p>The member accounts that contain resources that the path can traverse.</p>",
          "locationName":"additionalAccountSet"
        },
        "FilterInArns":{
          "shape":"ArnList",
          "documentation":"<p>The Amazon Resource Names (ARN) of the Amazon Web Services resources that the path must traverse.</p>",
          "locationName":"filterInArnSet"
        },
        "StartDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time the analysis started.</p>",
          "locationName":"startDate"
        },
        "Status":{
          "shape":"AnalysisStatus",
          "documentation":"<p>The status of the network insights analysis.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message, if the status is <code>failed</code>.</p>",
          "locationName":"statusMessage"
        },
        "WarningMessage":{
          "shape":"String",
          "documentation":"<p>The warning message.</p>",
          "locationName":"warningMessage"
        },
        "NetworkPathFound":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the destination is reachable from the source.</p>",
          "locationName":"networkPathFound"
        },
        "ForwardPathComponents":{
          "shape":"PathComponentList",
          "documentation":"<p>The components in the path from source to destination.</p>",
          "locationName":"forwardPathComponentSet"
        },
        "ReturnPathComponents":{
          "shape":"PathComponentList",
          "documentation":"<p>The components in the path from destination to source.</p>",
          "locationName":"returnPathComponentSet"
        },
        "Explanations":{
          "shape":"ExplanationList",
          "documentation":"<p>The explanations. For more information, see <a href=\"https://docs.aws.amazon.com/vpc/latest/reachability/explanation-codes.html\">Reachability Analyzer explanation codes</a>.</p>",
          "locationName":"explanationSet"
        },
        "AlternatePathHints":{
          "shape":"AlternatePathHintList",
          "documentation":"<p>Potential intermediate components.</p>",
          "locationName":"alternatePathHintSet"
        },
        "SuggestedAccounts":{
          "shape":"ValueStringList",
          "documentation":"<p>Potential intermediate accounts.</p>",
          "locationName":"suggestedAccountSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a network insights analysis.</p>"
    },
    "NetworkInsightsAnalysisId":{"type":"string"},
    "NetworkInsightsAnalysisIdList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsAnalysisId",
        "locationName":"item"
      }
    },
    "NetworkInsightsAnalysisList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsAnalysis",
        "locationName":"item"
      }
    },
    "NetworkInsightsMaxResults":{
      "type":"integer",
      "max":100,
      "min":1
    },
    "NetworkInsightsPath":{
      "type":"structure",
      "members":{
        "NetworkInsightsPathId":{
          "shape":"NetworkInsightsPathId",
          "documentation":"<p>The ID of the path.</p>",
          "locationName":"networkInsightsPathId"
        },
        "NetworkInsightsPathArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the path.</p>",
          "locationName":"networkInsightsPathArn"
        },
        "CreatedDate":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time stamp when the path was created.</p>",
          "locationName":"createdDate"
        },
        "Source":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services resource that is the source of the path.</p>",
          "locationName":"source"
        },
        "Destination":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services resource that is the destination of the path.</p>",
          "locationName":"destination"
        },
        "SourceArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the source.</p>",
          "locationName":"sourceArn"
        },
        "DestinationArn":{
          "shape":"ResourceArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the destination.</p>",
          "locationName":"destinationArn"
        },
        "SourceIp":{
          "shape":"IpAddress",
          "documentation":"<p>The IP address of the Amazon Web Services resource that is the source of the path.</p>",
          "locationName":"sourceIp"
        },
        "DestinationIp":{
          "shape":"IpAddress",
          "documentation":"<p>The IP address of the Amazon Web Services resource that is the destination of the path.</p>",
          "locationName":"destinationIp"
        },
        "Protocol":{
          "shape":"Protocol",
          "documentation":"<p>The protocol.</p>",
          "locationName":"protocol"
        },
        "DestinationPort":{
          "shape":"Integer",
          "documentation":"<p>The destination port.</p>",
          "locationName":"destinationPort"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags associated with the path.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a path.</p>"
    },
    "NetworkInsightsPathId":{"type":"string"},
    "NetworkInsightsPathIdList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsPathId",
        "locationName":"item"
      }
    },
    "NetworkInsightsPathList":{
      "type":"list",
      "member":{
        "shape":"NetworkInsightsPath",
        "locationName":"item"
      }
    },
    "NetworkInsightsResourceId":{"type":"string"},
    "NetworkInterface":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"NetworkInterfaceAssociation",
          "documentation":"<p>The association information for an Elastic IP address (IPv4) associated with the network interface.</p>",
          "locationName":"association"
        },
        "Attachment":{
          "shape":"NetworkInterfaceAttachment",
          "documentation":"<p>The network interface attachment.</p>",
          "locationName":"attachment"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description.</p>",
          "locationName":"description"
        },
        "Groups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>Any security groups for the network interface.</p>",
          "locationName":"groupSet"
        },
        "InterfaceType":{
          "shape":"NetworkInterfaceType",
          "documentation":"<p>The type of network interface.</p>",
          "locationName":"interfaceType"
        },
        "Ipv6Addresses":{
          "shape":"NetworkInterfaceIpv6AddressesList",
          "documentation":"<p>The IPv6 addresses associated with the network interface.</p>",
          "locationName":"ipv6AddressesSet"
        },
        "MacAddress":{
          "shape":"String",
          "documentation":"<p>The MAC address.</p>",
          "locationName":"macAddress"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the network interface.</p>",
          "locationName":"ownerId"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private DNS name.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The IPv4 address of the network interface within the subnet.</p>",
          "locationName":"privateIpAddress"
        },
        "PrivateIpAddresses":{
          "shape":"NetworkInterfacePrivateIpAddressList",
          "documentation":"<p>The private IPv4 addresses associated with the network interface.</p>",
          "locationName":"privateIpAddressesSet"
        },
        "Ipv4Prefixes":{
          "shape":"Ipv4PrefixesList",
          "documentation":"<p>The IPv4 prefixes that are assigned to the network interface.</p>",
          "locationName":"ipv4PrefixSet"
        },
        "Ipv6Prefixes":{
          "shape":"Ipv6PrefixesList",
          "documentation":"<p>The IPv6 prefixes that are assigned to the network interface.</p>",
          "locationName":"ipv6PrefixSet"
        },
        "RequesterId":{
          "shape":"String",
          "documentation":"<p>The alias or Amazon Web Services account ID of the principal or service that created the network interface.</p>",
          "locationName":"requesterId"
        },
        "RequesterManaged":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the network interface is being managed by Amazon Web Services.</p>",
          "locationName":"requesterManaged"
        },
        "SourceDestCheck":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether source/destination checking is enabled.</p>",
          "locationName":"sourceDestCheck"
        },
        "Status":{
          "shape":"NetworkInterfaceStatus",
          "documentation":"<p>The status of the network interface.</p>",
          "locationName":"status"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "TagSet":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the network interface.</p>",
          "locationName":"tagSet"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "DenyAllIgwTraffic":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether a network interface with an IPv6 address is unreachable from the public internet. If the value is <code>true</code>, inbound traffic from the internet is dropped and you cannot assign an elastic IP address to the network interface. The network interface is reachable from peered VPCs and resources connected through a transit gateway, including on-premises networks.</p>",
          "locationName":"denyAllIgwTraffic"
        },
        "Ipv6Native":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is an IPv6 only network interface.</p>",
          "locationName":"ipv6Native"
        },
        "Ipv6Address":{
          "shape":"String",
          "documentation":"<p>The IPv6 globally unique address associated with the network interface.</p>",
          "locationName":"ipv6Address"
        }
      },
      "documentation":"<p>Describes a network interface.</p>"
    },
    "NetworkInterfaceAssociation":{
      "type":"structure",
      "members":{
        "AllocationId":{
          "shape":"String",
          "documentation":"<p>The allocation ID.</p>",
          "locationName":"allocationId"
        },
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The association ID.</p>",
          "locationName":"associationId"
        },
        "IpOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Elastic IP address owner.</p>",
          "locationName":"ipOwnerId"
        },
        "PublicDnsName":{
          "shape":"String",
          "documentation":"<p>The public DNS name.</p>",
          "locationName":"publicDnsName"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The address of the Elastic IP address bound to the network interface.</p>",
          "locationName":"publicIp"
        },
        "CustomerOwnedIp":{
          "shape":"String",
          "documentation":"<p>The customer-owned IP address associated with the network interface.</p>",
          "locationName":"customerOwnedIp"
        },
        "CarrierIp":{
          "shape":"String",
          "documentation":"<p>The carrier IP address associated with the network interface.</p> <p>This option is only available when the network interface is in a subnet which is associated with a Wavelength Zone.</p>",
          "locationName":"carrierIp"
        }
      },
      "documentation":"<p>Describes association information for an Elastic IP address (IPv4 only), or a Carrier IP address (for a network interface which resides in a subnet in a Wavelength Zone).</p>"
    },
    "NetworkInterfaceAttachment":{
      "type":"structure",
      "members":{
        "AttachTime":{
          "shape":"DateTime",
          "documentation":"<p>The timestamp indicating when the attachment initiated.</p>",
          "locationName":"attachTime"
        },
        "AttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface attachment.</p>",
          "locationName":"attachmentId"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the network interface is deleted when the instance is terminated.</p>",
          "locationName":"deleteOnTermination"
        },
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The device index of the network interface attachment on the instance.</p>",
          "locationName":"deviceIndex"
        },
        "NetworkCardIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the network card.</p>",
          "locationName":"networkCardIndex"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "InstanceOwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the instance.</p>",
          "locationName":"instanceOwnerId"
        },
        "Status":{
          "shape":"AttachmentStatus",
          "documentation":"<p>The attachment state.</p>",
          "locationName":"status"
        },
        "EnaSrdSpecification":{
          "shape":"AttachmentEnaSrdSpecification",
          "documentation":"<p>Configures ENA Express for the network interface that this action attaches to the instance.</p>",
          "locationName":"enaSrdSpecification"
        }
      },
      "documentation":"<p>Describes a network interface attachment.</p>"
    },
    "NetworkInterfaceAttachmentChanges":{
      "type":"structure",
      "members":{
        "AttachmentId":{
          "shape":"NetworkInterfaceAttachmentId",
          "documentation":"<p>The ID of the network interface attachment.</p>",
          "locationName":"attachmentId"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the network interface is deleted when the instance is terminated.</p>",
          "locationName":"deleteOnTermination"
        }
      },
      "documentation":"<p>Describes an attachment change.</p>"
    },
    "NetworkInterfaceAttachmentId":{"type":"string"},
    "NetworkInterfaceAttribute":{
      "type":"string",
      "enum":[
        "description",
        "groupSet",
        "sourceDestCheck",
        "attachment"
      ]
    },
    "NetworkInterfaceCount":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of network interfaces. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of network interfaces. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum number of network interfaces.</p>"
    },
    "NetworkInterfaceCountRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of network interfaces. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of network interfaces. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum number of network interfaces.</p>"
    },
    "NetworkInterfaceCreationType":{
      "type":"string",
      "enum":[
        "efa",
        "branch",
        "trunk"
      ]
    },
    "NetworkInterfaceId":{"type":"string"},
    "NetworkInterfaceIdList":{
      "type":"list",
      "member":{
        "shape":"NetworkInterfaceId",
        "locationName":"item"
      }
    },
    "NetworkInterfaceIpv6Address":{
      "type":"structure",
      "members":{
        "Ipv6Address":{
          "shape":"String",
          "documentation":"<p>The IPv6 address.</p>",
          "locationName":"ipv6Address"
        }
      },
      "documentation":"<p>Describes an IPv6 address associated with a network interface.</p>"
    },
    "NetworkInterfaceIpv6AddressesList":{
      "type":"list",
      "member":{
        "shape":"NetworkInterfaceIpv6Address",
        "locationName":"item"
      }
    },
    "NetworkInterfaceList":{
      "type":"list",
      "member":{
        "shape":"NetworkInterface",
        "locationName":"item"
      }
    },
    "NetworkInterfacePermission":{
      "type":"structure",
      "members":{
        "NetworkInterfacePermissionId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface permission.</p>",
          "locationName":"networkInterfacePermissionId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "AwsAccountId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p>",
          "locationName":"awsAccountId"
        },
        "AwsService":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Service.</p>",
          "locationName":"awsService"
        },
        "Permission":{
          "shape":"InterfacePermissionType",
          "documentation":"<p>The type of permission.</p>",
          "locationName":"permission"
        },
        "PermissionState":{
          "shape":"NetworkInterfacePermissionState",
          "documentation":"<p>Information about the state of the permission.</p>",
          "locationName":"permissionState"
        }
      },
      "documentation":"<p>Describes a permission for a network interface.</p>"
    },
    "NetworkInterfacePermissionId":{"type":"string"},
    "NetworkInterfacePermissionIdList":{
      "type":"list",
      "member":{"shape":"NetworkInterfacePermissionId"}
    },
    "NetworkInterfacePermissionList":{
      "type":"list",
      "member":{
        "shape":"NetworkInterfacePermission",
        "locationName":"item"
      }
    },
    "NetworkInterfacePermissionState":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"NetworkInterfacePermissionStateCode",
          "documentation":"<p>The state of the permission.</p>",
          "locationName":"state"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A status message, if applicable.</p>",
          "locationName":"statusMessage"
        }
      },
      "documentation":"<p>Describes the state of a network interface permission.</p>"
    },
    "NetworkInterfacePermissionStateCode":{
      "type":"string",
      "enum":[
        "pending",
        "granted",
        "revoking",
        "revoked"
      ]
    },
    "NetworkInterfacePrivateIpAddress":{
      "type":"structure",
      "members":{
        "Association":{
          "shape":"NetworkInterfaceAssociation",
          "documentation":"<p>The association information for an Elastic IP address (IPv4) associated with the network interface.</p>",
          "locationName":"association"
        },
        "Primary":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this IPv4 address is the primary private IPv4 address of the network interface.</p>",
          "locationName":"primary"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private DNS name.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IPv4 address.</p>",
          "locationName":"privateIpAddress"
        }
      },
      "documentation":"<p>Describes the private IPv4 address of a network interface.</p>"
    },
    "NetworkInterfacePrivateIpAddressList":{
      "type":"list",
      "member":{
        "shape":"NetworkInterfacePrivateIpAddress",
        "locationName":"item"
      }
    },
    "NetworkInterfaceStatus":{
      "type":"string",
      "enum":[
        "available",
        "associated",
        "attaching",
        "in-use",
        "detaching"
      ]
    },
    "NetworkInterfaceType":{
      "type":"string",
      "enum":[
        "interface",
        "natGateway",
        "efa",
        "trunk",
        "load_balancer",
        "network_load_balancer",
        "vpc_endpoint",
        "branch",
        "transit_gateway",
        "lambda",
        "quicksight",
        "global_accelerator_managed",
        "api_gateway_managed",
        "gateway_load_balancer",
        "gateway_load_balancer_endpoint",
        "iot_rules_managed",
        "aws_codestar_connections_managed"
      ]
    },
    "NetworkPerformance":{"type":"string"},
    "NewDhcpConfiguration":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "locationName":"key"
        },
        "Values":{
          "shape":"ValueStringList",
          "locationName":"Value"
        }
      }
    },
    "NewDhcpConfigurationList":{
      "type":"list",
      "member":{
        "shape":"NewDhcpConfiguration",
        "locationName":"item"
      }
    },
    "NextToken":{"type":"string"},
    "OccurrenceDayRequestSet":{
      "type":"list",
      "member":{
        "shape":"Integer",
        "locationName":"OccurenceDay"
      }
    },
    "OccurrenceDaySet":{
      "type":"list",
      "member":{
        "shape":"Integer",
        "locationName":"item"
      }
    },
    "OfferingClassType":{
      "type":"string",
      "enum":[
        "standard",
        "convertible"
      ]
    },
    "OfferingId":{"type":"string"},
    "OfferingTypeValues":{
      "type":"string",
      "enum":[
        "Heavy Utilization",
        "Medium Utilization",
        "Light Utilization",
        "No Upfront",
        "Partial Upfront",
        "All Upfront"
      ]
    },
    "OidcOptions":{
      "type":"structure",
      "members":{
        "Issuer":{
          "shape":"String",
          "documentation":"<p>The OIDC issuer.</p>",
          "locationName":"issuer"
        },
        "AuthorizationEndpoint":{
          "shape":"String",
          "documentation":"<p>The OIDC authorization endpoint.</p>",
          "locationName":"authorizationEndpoint"
        },
        "TokenEndpoint":{
          "shape":"String",
          "documentation":"<p>The OIDC token endpoint.</p>",
          "locationName":"tokenEndpoint"
        },
        "UserInfoEndpoint":{
          "shape":"String",
          "documentation":"<p>The OIDC user info endpoint.</p>",
          "locationName":"userInfoEndpoint"
        },
        "ClientId":{
          "shape":"String",
          "documentation":"<p>The client identifier.</p>",
          "locationName":"clientId"
        },
        "ClientSecret":{
          "shape":"String",
          "documentation":"<p>The client secret.</p>",
          "locationName":"clientSecret"
        },
        "Scope":{
          "shape":"String",
          "documentation":"<p>The OpenID Connect (OIDC) scope specified.</p>",
          "locationName":"scope"
        }
      },
      "documentation":"<p>Options for OIDC-based, user-identity type trust provider.</p>"
    },
    "OnDemandAllocationStrategy":{
      "type":"string",
      "enum":[
        "lowestPrice",
        "prioritized"
      ]
    },
    "OnDemandOptions":{
      "type":"structure",
      "members":{
        "AllocationStrategy":{
          "shape":"FleetOnDemandAllocationStrategy",
          "documentation":"<p>The strategy that determines the order of the launch template overrides to use in fulfilling On-Demand capacity.</p> <p> <code>lowest-price</code> - EC2 Fleet uses price to determine the order, launching the lowest price first.</p> <p> <code>prioritized</code> - EC2 Fleet uses the priority that you assigned to each launch template override, launching the highest priority first.</p> <p>Default: <code>lowest-price</code> </p>",
          "locationName":"allocationStrategy"
        },
        "CapacityReservationOptions":{
          "shape":"CapacityReservationOptions",
          "documentation":"<p>The strategy for using unused Capacity Reservations for fulfilling On-Demand capacity.</p> <p>Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"capacityReservationOptions"
        },
        "SingleInstanceType":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet uses a single instance type to launch all On-Demand Instances in the fleet.</p> <p>Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"singleInstanceType"
        },
        "SingleAvailabilityZone":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet launches all On-Demand Instances into a single Availability Zone.</p> <p>Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"singleAvailabilityZone"
        },
        "MinTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The minimum target capacity for On-Demand Instances in the fleet. If the minimum target capacity is not reached, the fleet launches no instances.</p> <p>Supported only for fleets of type <code>instant</code>.</p> <p>At least one of the following must be specified: <code>SingleAvailabilityZone</code> | <code>SingleInstanceType</code> </p>",
          "locationName":"minTargetCapacity"
        },
        "MaxTotalPrice":{
          "shape":"String",
          "documentation":"<p>The maximum amount per hour for On-Demand Instances that you're willing to pay.</p>",
          "locationName":"maxTotalPrice"
        }
      },
      "documentation":"<p>Describes the configuration of On-Demand Instances in an EC2 Fleet.</p>"
    },
    "OnDemandOptionsRequest":{
      "type":"structure",
      "members":{
        "AllocationStrategy":{
          "shape":"FleetOnDemandAllocationStrategy",
          "documentation":"<p>The strategy that determines the order of the launch template overrides to use in fulfilling On-Demand capacity.</p> <p> <code>lowest-price</code> - EC2 Fleet uses price to determine the order, launching the lowest price first.</p> <p> <code>prioritized</code> - EC2 Fleet uses the priority that you assigned to each launch template override, launching the highest priority first.</p> <p>Default: <code>lowest-price</code> </p>"
        },
        "CapacityReservationOptions":{
          "shape":"CapacityReservationOptionsRequest",
          "documentation":"<p>The strategy for using unused Capacity Reservations for fulfilling On-Demand capacity.</p> <p>Supported only for fleets of type <code>instant</code>.</p>"
        },
        "SingleInstanceType":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet uses a single instance type to launch all On-Demand Instances in the fleet.</p> <p>Supported only for fleets of type <code>instant</code>.</p>"
        },
        "SingleAvailabilityZone":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet launches all On-Demand Instances into a single Availability Zone.</p> <p>Supported only for fleets of type <code>instant</code>.</p>"
        },
        "MinTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The minimum target capacity for On-Demand Instances in the fleet. If the minimum target capacity is not reached, the fleet launches no instances.</p> <p>Supported only for fleets of type <code>instant</code>.</p> <p>At least one of the following must be specified: <code>SingleAvailabilityZone</code> | <code>SingleInstanceType</code> </p>"
        },
        "MaxTotalPrice":{
          "shape":"String",
          "documentation":"<p>The maximum amount per hour for On-Demand Instances that you're willing to pay.</p>"
        }
      },
      "documentation":"<p>Describes the configuration of On-Demand Instances in an EC2 Fleet.</p>"
    },
    "OperationType":{
      "type":"string",
      "enum":[
        "add",
        "remove"
      ]
    },
    "OrganizationArnStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"OrganizationArn"
      }
    },
    "OrganizationalUnitArnStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"OrganizationalUnitArn"
      }
    },
    "OutpostArn":{
      "type":"string",
      "pattern":"^arn:aws([a-z-]+)?:outposts:[a-z\\d-]+:\\d{12}:outpost/op-[a-f0-9]{17}$"
    },
    "OwnerStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"Owner"
      }
    },
    "PacketHeaderStatement":{
      "type":"structure",
      "members":{
        "SourceAddresses":{
          "shape":"ValueStringList",
          "documentation":"<p>The source addresses.</p>",
          "locationName":"sourceAddressSet"
        },
        "DestinationAddresses":{
          "shape":"ValueStringList",
          "documentation":"<p>The destination addresses.</p>",
          "locationName":"destinationAddressSet"
        },
        "SourcePorts":{
          "shape":"ValueStringList",
          "documentation":"<p>The source ports.</p>",
          "locationName":"sourcePortSet"
        },
        "DestinationPorts":{
          "shape":"ValueStringList",
          "documentation":"<p>The destination ports.</p>",
          "locationName":"destinationPortSet"
        },
        "SourcePrefixLists":{
          "shape":"ValueStringList",
          "documentation":"<p>The source prefix lists.</p>",
          "locationName":"sourcePrefixListSet"
        },
        "DestinationPrefixLists":{
          "shape":"ValueStringList",
          "documentation":"<p>The destination prefix lists.</p>",
          "locationName":"destinationPrefixListSet"
        },
        "Protocols":{
          "shape":"ProtocolList",
          "documentation":"<p>The protocols.</p>",
          "locationName":"protocolSet"
        }
      },
      "documentation":"<p>Describes a packet header statement.</p>"
    },
    "PacketHeaderStatementRequest":{
      "type":"structure",
      "members":{
        "SourceAddresses":{
          "shape":"ValueStringList",
          "documentation":"<p>The source addresses.</p>",
          "locationName":"SourceAddress"
        },
        "DestinationAddresses":{
          "shape":"ValueStringList",
          "documentation":"<p>The destination addresses.</p>",
          "locationName":"DestinationAddress"
        },
        "SourcePorts":{
          "shape":"ValueStringList",
          "documentation":"<p>The source ports.</p>",
          "locationName":"SourcePort"
        },
        "DestinationPorts":{
          "shape":"ValueStringList",
          "documentation":"<p>The destination ports.</p>",
          "locationName":"DestinationPort"
        },
        "SourcePrefixLists":{
          "shape":"ValueStringList",
          "documentation":"<p>The source prefix lists.</p>",
          "locationName":"SourcePrefixList"
        },
        "DestinationPrefixLists":{
          "shape":"ValueStringList",
          "documentation":"<p>The destination prefix lists.</p>",
          "locationName":"DestinationPrefixList"
        },
        "Protocols":{
          "shape":"ProtocolList",
          "documentation":"<p>The protocols.</p>",
          "locationName":"Protocol"
        }
      },
      "documentation":"<p>Describes a packet header statement.</p>"
    },
    "PartitionLoadFrequency":{
      "type":"string",
      "enum":[
        "none",
        "daily",
        "weekly",
        "monthly"
      ]
    },
    "PathComponent":{
      "type":"structure",
      "members":{
        "SequenceNumber":{
          "shape":"Integer",
          "documentation":"<p>The sequence number.</p>",
          "locationName":"sequenceNumber"
        },
        "AclRule":{
          "shape":"AnalysisAclRule",
          "documentation":"<p>The network ACL rule.</p>",
          "locationName":"aclRule"
        },
        "AttachedTo":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The resource to which the path component is attached.</p>",
          "locationName":"attachedTo"
        },
        "Component":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The component.</p>",
          "locationName":"component"
        },
        "DestinationVpc":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The destination VPC.</p>",
          "locationName":"destinationVpc"
        },
        "OutboundHeader":{
          "shape":"AnalysisPacketHeader",
          "documentation":"<p>The outbound header.</p>",
          "locationName":"outboundHeader"
        },
        "InboundHeader":{
          "shape":"AnalysisPacketHeader",
          "documentation":"<p>The inbound header.</p>",
          "locationName":"inboundHeader"
        },
        "RouteTableRoute":{
          "shape":"AnalysisRouteTableRoute",
          "documentation":"<p>The route table route.</p>",
          "locationName":"routeTableRoute"
        },
        "SecurityGroupRule":{
          "shape":"AnalysisSecurityGroupRule",
          "documentation":"<p>The security group rule.</p>",
          "locationName":"securityGroupRule"
        },
        "SourceVpc":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The source VPC.</p>",
          "locationName":"sourceVpc"
        },
        "Subnet":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The subnet.</p>",
          "locationName":"subnet"
        },
        "Vpc":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The component VPC.</p>",
          "locationName":"vpc"
        },
        "AdditionalDetails":{
          "shape":"AdditionalDetailList",
          "documentation":"<p>The additional details.</p>",
          "locationName":"additionalDetailSet"
        },
        "TransitGateway":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The transit gateway.</p>",
          "locationName":"transitGateway"
        },
        "TransitGatewayRouteTableRoute":{
          "shape":"TransitGatewayRouteTableRoute",
          "documentation":"<p>The route in a transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableRoute"
        },
        "Explanations":{
          "shape":"ExplanationList",
          "documentation":"<p>The explanation codes.</p>",
          "locationName":"explanationSet"
        },
        "ElasticLoadBalancerListener":{
          "shape":"AnalysisComponent",
          "documentation":"<p>The load balancer listener.</p>",
          "locationName":"elasticLoadBalancerListener"
        }
      },
      "documentation":"<p>Describes a path component.</p>"
    },
    "PathComponentList":{
      "type":"list",
      "member":{
        "shape":"PathComponent",
        "locationName":"item"
      }
    },
    "PathStatement":{
      "type":"structure",
      "members":{
        "PacketHeaderStatement":{
          "shape":"PacketHeaderStatement",
          "documentation":"<p>The packet header statement.</p>",
          "locationName":"packetHeaderStatement"
        },
        "ResourceStatement":{
          "shape":"ResourceStatement",
          "documentation":"<p>The resource statement.</p>",
          "locationName":"resourceStatement"
        }
      },
      "documentation":"<p>Describes a path statement.</p>"
    },
    "PathStatementRequest":{
      "type":"structure",
      "members":{
        "PacketHeaderStatement":{
          "shape":"PacketHeaderStatementRequest",
          "documentation":"<p>The packet header statement.</p>"
        },
        "ResourceStatement":{
          "shape":"ResourceStatementRequest",
          "documentation":"<p>The resource statement.</p>"
        }
      },
      "documentation":"<p>Describes a path statement.</p>"
    },
    "PayerResponsibility":{
      "type":"string",
      "enum":["ServiceOwner"]
    },
    "PaymentOption":{
      "type":"string",
      "enum":[
        "AllUpfront",
        "PartialUpfront",
        "NoUpfront"
      ]
    },
    "PciId":{
      "type":"structure",
      "members":{
        "DeviceId":{
          "shape":"String",
          "documentation":"<p>The ID of the device.</p>"
        },
        "VendorId":{
          "shape":"String",
          "documentation":"<p>The ID of the vendor.</p>"
        },
        "SubsystemId":{
          "shape":"String",
          "documentation":"<p>The ID of the subsystem.</p>"
        },
        "SubsystemVendorId":{
          "shape":"String",
          "documentation":"<p>The ID of the vendor for the subsystem.</p>"
        }
      },
      "documentation":"<p>Describes the data that identifies an Amazon FPGA image (AFI) on the PCI bus.</p>"
    },
    "PeeringAttachmentStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The status code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The status message, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>The status of the transit gateway peering attachment.</p>"
    },
    "PeeringConnectionOptions":{
      "type":"structure",
      "members":{
        "AllowDnsResolutionFromRemoteVpc":{
          "shape":"Boolean",
          "documentation":"<p>If true, the public DNS hostnames of instances in the specified VPC resolve to private IP addresses when queried from instances in the peer VPC.</p>",
          "locationName":"allowDnsResolutionFromRemoteVpc"
        },
        "AllowEgressFromLocalClassicLinkToRemoteVpc":{
          "shape":"Boolean",
          "documentation":"<p>If true, enables outbound communication from an EC2-Classic instance that's linked to a local VPC using ClassicLink to instances in a peer VPC.</p>",
          "locationName":"allowEgressFromLocalClassicLinkToRemoteVpc"
        },
        "AllowEgressFromLocalVpcToRemoteClassicLink":{
          "shape":"Boolean",
          "documentation":"<p>If true, enables outbound communication from instances in a local VPC to an EC2-Classic instance that's linked to a peer VPC using ClassicLink.</p>",
          "locationName":"allowEgressFromLocalVpcToRemoteClassicLink"
        }
      },
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Describes the VPC peering connection options.</p>"
    },
    "PeeringConnectionOptionsRequest":{
      "type":"structure",
      "members":{
        "AllowDnsResolutionFromRemoteVpc":{
          "shape":"Boolean",
          "documentation":"<p>If true, enables a local VPC to resolve public DNS hostnames to private IP addresses when queried from instances in the peer VPC.</p>"
        },
        "AllowEgressFromLocalClassicLinkToRemoteVpc":{
          "shape":"Boolean",
          "documentation":"<p>If true, enables outbound communication from an EC2-Classic instance that's linked to a local VPC using ClassicLink to instances in a peer VPC.</p>"
        },
        "AllowEgressFromLocalVpcToRemoteClassicLink":{
          "shape":"Boolean",
          "documentation":"<p>If true, enables outbound communication from instances in a local VPC to an EC2-Classic instance that's linked to a peer VPC using ClassicLink.</p>"
        }
      },
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>The VPC peering connection options.</p>"
    },
    "PeeringTgwInfo":{
      "type":"structure",
      "members":{
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "CoreNetworkId":{
          "shape":"String",
          "documentation":"<p>The ID of the core network where the transit gateway peer is located.</p>",
          "locationName":"coreNetworkId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the transit gateway.</p>",
          "locationName":"ownerId"
        },
        "Region":{
          "shape":"String",
          "documentation":"<p>The Region of the transit gateway.</p>",
          "locationName":"region"
        }
      },
      "documentation":"<p>Information about the transit gateway in the peering attachment.</p>"
    },
    "PeriodType":{
      "type":"string",
      "enum":[
        "five-minutes",
        "fifteen-minutes",
        "one-hour",
        "three-hours",
        "one-day",
        "one-week"
      ]
    },
    "PermissionGroup":{
      "type":"string",
      "enum":["all"]
    },
    "Phase1DHGroupNumbersList":{
      "type":"list",
      "member":{
        "shape":"Phase1DHGroupNumbersListValue",
        "locationName":"item"
      }
    },
    "Phase1DHGroupNumbersListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"Integer",
          "documentation":"<p>The Diffie-Hellmann group number.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The Diffie-Hellmann group number for phase 1 IKE negotiations.</p>"
    },
    "Phase1DHGroupNumbersRequestList":{
      "type":"list",
      "member":{
        "shape":"Phase1DHGroupNumbersRequestListValue",
        "locationName":"item"
      }
    },
    "Phase1DHGroupNumbersRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"Integer",
          "documentation":"<p>The Diffie-Hellmann group number.</p>"
        }
      },
      "documentation":"<p>Specifies a Diffie-Hellman group number for the VPN tunnel for phase 1 IKE negotiations.</p>"
    },
    "Phase1EncryptionAlgorithmsList":{
      "type":"list",
      "member":{
        "shape":"Phase1EncryptionAlgorithmsListValue",
        "locationName":"item"
      }
    },
    "Phase1EncryptionAlgorithmsListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The value for the encryption algorithm.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The encryption algorithm for phase 1 IKE negotiations.</p>"
    },
    "Phase1EncryptionAlgorithmsRequestList":{
      "type":"list",
      "member":{
        "shape":"Phase1EncryptionAlgorithmsRequestListValue",
        "locationName":"item"
      }
    },
    "Phase1EncryptionAlgorithmsRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The value for the encryption algorithm.</p>"
        }
      },
      "documentation":"<p>Specifies the encryption algorithm for the VPN tunnel for phase 1 IKE negotiations.</p>"
    },
    "Phase1IntegrityAlgorithmsList":{
      "type":"list",
      "member":{
        "shape":"Phase1IntegrityAlgorithmsListValue",
        "locationName":"item"
      }
    },
    "Phase1IntegrityAlgorithmsListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The value for the integrity algorithm.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The integrity algorithm for phase 1 IKE negotiations.</p>"
    },
    "Phase1IntegrityAlgorithmsRequestList":{
      "type":"list",
      "member":{
        "shape":"Phase1IntegrityAlgorithmsRequestListValue",
        "locationName":"item"
      }
    },
    "Phase1IntegrityAlgorithmsRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The value for the integrity algorithm.</p>"
        }
      },
      "documentation":"<p>Specifies the integrity algorithm for the VPN tunnel for phase 1 IKE negotiations.</p>"
    },
    "Phase2DHGroupNumbersList":{
      "type":"list",
      "member":{
        "shape":"Phase2DHGroupNumbersListValue",
        "locationName":"item"
      }
    },
    "Phase2DHGroupNumbersListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"Integer",
          "documentation":"<p>The Diffie-Hellmann group number.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The Diffie-Hellmann group number for phase 2 IKE negotiations.</p>"
    },
    "Phase2DHGroupNumbersRequestList":{
      "type":"list",
      "member":{
        "shape":"Phase2DHGroupNumbersRequestListValue",
        "locationName":"item"
      }
    },
    "Phase2DHGroupNumbersRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"Integer",
          "documentation":"<p>The Diffie-Hellmann group number.</p>"
        }
      },
      "documentation":"<p>Specifies a Diffie-Hellman group number for the VPN tunnel for phase 2 IKE negotiations.</p>"
    },
    "Phase2EncryptionAlgorithmsList":{
      "type":"list",
      "member":{
        "shape":"Phase2EncryptionAlgorithmsListValue",
        "locationName":"item"
      }
    },
    "Phase2EncryptionAlgorithmsListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The encryption algorithm.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The encryption algorithm for phase 2 IKE negotiations.</p>"
    },
    "Phase2EncryptionAlgorithmsRequestList":{
      "type":"list",
      "member":{
        "shape":"Phase2EncryptionAlgorithmsRequestListValue",
        "locationName":"item"
      }
    },
    "Phase2EncryptionAlgorithmsRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The encryption algorithm.</p>"
        }
      },
      "documentation":"<p>Specifies the encryption algorithm for the VPN tunnel for phase 2 IKE negotiations.</p>"
    },
    "Phase2IntegrityAlgorithmsList":{
      "type":"list",
      "member":{
        "shape":"Phase2IntegrityAlgorithmsListValue",
        "locationName":"item"
      }
    },
    "Phase2IntegrityAlgorithmsListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The integrity algorithm.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>The integrity algorithm for phase 2 IKE negotiations.</p>"
    },
    "Phase2IntegrityAlgorithmsRequestList":{
      "type":"list",
      "member":{
        "shape":"Phase2IntegrityAlgorithmsRequestListValue",
        "locationName":"item"
      }
    },
    "Phase2IntegrityAlgorithmsRequestListValue":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The integrity algorithm.</p>"
        }
      },
      "documentation":"<p>Specifies the integrity algorithm for the VPN tunnel for phase 2 IKE negotiations.</p>"
    },
    "Placement":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone of the instance.</p> <p>If not specified, an Availability Zone will be automatically chosen for you based on the load balancing criteria for the Region.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet\">CreateFleet</a>.</p>",
          "locationName":"availabilityZone"
        },
        "Affinity":{
          "shape":"String",
          "documentation":"<p>The affinity setting for the instance on the Dedicated Host.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet\">CreateFleet</a> or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportInstance.html\">ImportInstance</a>.</p>",
          "locationName":"affinity"
        },
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group that the instance is in. If you specify <code>GroupName</code>, you can't specify <code>GroupId</code>.</p>",
          "locationName":"groupName"
        },
        "PartitionNumber":{
          "shape":"Integer",
          "documentation":"<p>The number of the partition that the instance is in. Valid only if the placement group strategy is set to <code>partition</code>.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet\">CreateFleet</a>.</p>",
          "locationName":"partitionNumber"
        },
        "HostId":{
          "shape":"String",
          "documentation":"<p>The ID of the Dedicated Host on which the instance resides.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet\">CreateFleet</a> or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportInstance.html\">ImportInstance</a>.</p>",
          "locationName":"hostId"
        },
        "Tenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instance (if the instance is running in a VPC). An instance with a tenancy of <code>dedicated</code> runs on single-tenant hardware.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet\">CreateFleet</a>. The <code>host</code> tenancy is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportInstance.html\">ImportInstance</a> or for T3 instances that are configured for the <code>unlimited</code> CPU credit option.</p>",
          "locationName":"tenancy"
        },
        "SpreadDomain":{
          "shape":"String",
          "documentation":"<p>Reserved for future use.</p>",
          "locationName":"spreadDomain"
        },
        "HostResourceGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the host resource group in which to launch the instances.</p> <p>If you specify this parameter, either omit the <b>Tenancy</b> parameter or set it to <code>host</code>.</p> <p>This parameter is not supported for <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateFleet\">CreateFleet</a>.</p>",
          "locationName":"hostResourceGroupArn"
        },
        "GroupId":{
          "shape":"PlacementGroupId",
          "documentation":"<p>The ID of the placement group that the instance is in. If you specify <code>GroupId</code>, you can't specify <code>GroupName</code>.</p>",
          "locationName":"groupId"
        }
      },
      "documentation":"<p>Describes the placement of an instance.</p>"
    },
    "PlacementGroup":{
      "type":"structure",
      "members":{
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the placement group.</p>",
          "locationName":"groupName"
        },
        "State":{
          "shape":"PlacementGroupState",
          "documentation":"<p>The state of the placement group.</p>",
          "locationName":"state"
        },
        "Strategy":{
          "shape":"PlacementStrategy",
          "documentation":"<p>The placement strategy.</p>",
          "locationName":"strategy"
        },
        "PartitionCount":{
          "shape":"Integer",
          "documentation":"<p>The number of partitions. Valid only if <b>strategy</b> is set to <code>partition</code>.</p>",
          "locationName":"partitionCount"
        },
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the placement group.</p>",
          "locationName":"groupId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags applied to the placement group.</p>",
          "locationName":"tagSet"
        },
        "GroupArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the placement group.</p>",
          "locationName":"groupArn"
        },
        "SpreadLevel":{
          "shape":"SpreadLevel",
          "documentation":"<p>The spread level for the placement group. <i>Only</i> Outpost placement groups can be spread across hosts.</p>",
          "locationName":"spreadLevel"
        }
      },
      "documentation":"<p>Describes a placement group.</p>"
    },
    "PlacementGroupArn":{
      "type":"string",
      "pattern":"^arn:aws([a-z-]+)?:ec2:[a-z\\d-]+:\\d{12}:placement-group/([^\\s].+[^\\s]){1,255}$"
    },
    "PlacementGroupId":{"type":"string"},
    "PlacementGroupIdStringList":{
      "type":"list",
      "member":{
        "shape":"PlacementGroupId",
        "locationName":"GroupId"
      }
    },
    "PlacementGroupInfo":{
      "type":"structure",
      "members":{
        "SupportedStrategies":{
          "shape":"PlacementGroupStrategyList",
          "documentation":"<p>The supported placement group types.</p>",
          "locationName":"supportedStrategies"
        }
      },
      "documentation":"<p>Describes the placement group support of the instance type.</p>"
    },
    "PlacementGroupList":{
      "type":"list",
      "member":{
        "shape":"PlacementGroup",
        "locationName":"item"
      }
    },
    "PlacementGroupName":{"type":"string"},
    "PlacementGroupState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "PlacementGroupStrategy":{
      "type":"string",
      "enum":[
        "cluster",
        "partition",
        "spread"
      ]
    },
    "PlacementGroupStrategyList":{
      "type":"list",
      "member":{
        "shape":"PlacementGroupStrategy",
        "locationName":"item"
      }
    },
    "PlacementGroupStringList":{
      "type":"list",
      "member":{"shape":"PlacementGroupName"}
    },
    "PlacementResponse":{
      "type":"structure",
      "members":{
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group that the instance is in.</p>",
          "locationName":"groupName"
        }
      },
      "documentation":"<p>Describes the placement of an instance.</p>"
    },
    "PlacementStrategy":{
      "type":"string",
      "enum":[
        "cluster",
        "spread",
        "partition"
      ]
    },
    "PlatformValues":{
      "type":"string",
      "enum":["Windows"]
    },
    "PoolCidrBlock":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR block.</p>",
          "locationName":"poolCidrBlock"
        }
      },
      "documentation":"<p>Describes a CIDR block for an address pool.</p>"
    },
    "PoolCidrBlocksSet":{
      "type":"list",
      "member":{
        "shape":"PoolCidrBlock",
        "locationName":"item"
      }
    },
    "PoolMaxResults":{
      "type":"integer",
      "max":10,
      "min":1
    },
    "Port":{
      "type":"integer",
      "max":65535,
      "min":0
    },
    "PortRange":{
      "type":"structure",
      "members":{
        "From":{
          "shape":"Integer",
          "documentation":"<p>The first port in the range.</p>",
          "locationName":"from"
        },
        "To":{
          "shape":"Integer",
          "documentation":"<p>The last port in the range.</p>",
          "locationName":"to"
        }
      },
      "documentation":"<p>Describes a range of ports.</p>"
    },
    "PortRangeList":{
      "type":"list",
      "member":{
        "shape":"PortRange",
        "locationName":"item"
      }
    },
    "PrefixList":{
      "type":"structure",
      "members":{
        "Cidrs":{
          "shape":"ValueStringList",
          "documentation":"<p>The IP address range of the Amazon Web Service.</p>",
          "locationName":"cidrSet"
        },
        "PrefixListId":{
          "shape":"String",
          "documentation":"<p>The ID of the prefix.</p>",
          "locationName":"prefixListId"
        },
        "PrefixListName":{
          "shape":"String",
          "documentation":"<p>The name of the prefix.</p>",
          "locationName":"prefixListName"
        }
      },
      "documentation":"<p>Describes prefixes for Amazon Web Services services.</p>"
    },
    "PrefixListAssociation":{
      "type":"structure",
      "members":{
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceOwner":{
          "shape":"String",
          "documentation":"<p>The owner of the resource.</p>",
          "locationName":"resourceOwner"
        }
      },
      "documentation":"<p>Describes the resource with which a prefix list is associated.</p>"
    },
    "PrefixListAssociationSet":{
      "type":"list",
      "member":{
        "shape":"PrefixListAssociation",
        "locationName":"item"
      }
    },
    "PrefixListEntry":{
      "type":"structure",
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR block.</p>",
          "locationName":"cidr"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description.</p>",
          "locationName":"description"
        }
      },
      "documentation":"<p>Describes a prefix list entry.</p>"
    },
    "PrefixListEntrySet":{
      "type":"list",
      "member":{
        "shape":"PrefixListEntry",
        "locationName":"item"
      }
    },
    "PrefixListId":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the security group rule that references this prefix list ID.</p> <p>Constraints: Up to 255 characters in length. Allowed characters are a-z, A-Z, 0-9, spaces, and ._-:/()#,@[]+=;{}!$*</p>",
          "locationName":"description"
        },
        "PrefixListId":{
          "shape":"String",
          "documentation":"<p>The ID of the prefix.</p>",
          "locationName":"prefixListId"
        }
      },
      "documentation":"<p>Describes a prefix list ID.</p>"
    },
    "PrefixListIdList":{
      "type":"list",
      "member":{
        "shape":"PrefixListId",
        "locationName":"item"
      }
    },
    "PrefixListIdSet":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "PrefixListMaxResults":{
      "type":"integer",
      "max":100,
      "min":1
    },
    "PrefixListResourceId":{"type":"string"},
    "PrefixListResourceIdStringList":{
      "type":"list",
      "member":{
        "shape":"PrefixListResourceId",
        "locationName":"item"
      }
    },
    "PrefixListSet":{
      "type":"list",
      "member":{
        "shape":"PrefixList",
        "locationName":"item"
      }
    },
    "PrefixListState":{
      "type":"string",
      "enum":[
        "create-in-progress",
        "create-complete",
        "create-failed",
        "modify-in-progress",
        "modify-complete",
        "modify-failed",
        "restore-in-progress",
        "restore-complete",
        "restore-failed",
        "delete-in-progress",
        "delete-complete",
        "delete-failed"
      ]
    },
    "PriceSchedule":{
      "type":"structure",
      "members":{
        "Active":{
          "shape":"Boolean",
          "documentation":"<p>The current price schedule, as determined by the term remaining for the Reserved Instance in the listing.</p> <p>A specific price schedule is always in effect, but only one price schedule can be active at any time. Take, for example, a Reserved Instance listing that has five months remaining in its term. When you specify price schedules for five months and two months, this means that schedule 1, covering the first three months of the remaining term, will be active during months 5, 4, and 3. Then schedule 2, covering the last two months of the term, will be active for months 2 and 1.</p>",
          "locationName":"active"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency for transacting the Reserved Instance resale. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "Price":{
          "shape":"Double",
          "documentation":"<p>The fixed price for the term.</p>",
          "locationName":"price"
        },
        "Term":{
          "shape":"Long",
          "documentation":"<p>The number of months remaining in the reservation. For example, 2 is the second to the last month before the capacity reservation expires.</p>",
          "locationName":"term"
        }
      },
      "documentation":"<p>Describes the price for a Reserved Instance.</p>"
    },
    "PriceScheduleList":{
      "type":"list",
      "member":{
        "shape":"PriceSchedule",
        "locationName":"item"
      }
    },
    "PriceScheduleSpecification":{
      "type":"structure",
      "members":{
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency for transacting the Reserved Instance resale. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "Price":{
          "shape":"Double",
          "documentation":"<p>The fixed price for the term.</p>",
          "locationName":"price"
        },
        "Term":{
          "shape":"Long",
          "documentation":"<p>The number of months remaining in the reservation. For example, 2 is the second to the last month before the capacity reservation expires.</p>",
          "locationName":"term"
        }
      },
      "documentation":"<p>Describes the price for a Reserved Instance.</p>"
    },
    "PriceScheduleSpecificationList":{
      "type":"list",
      "member":{
        "shape":"PriceScheduleSpecification",
        "locationName":"item"
      }
    },
    "PricingDetail":{
      "type":"structure",
      "members":{
        "Count":{
          "shape":"Integer",
          "documentation":"<p>The number of reservations available for the price.</p>",
          "locationName":"count"
        },
        "Price":{
          "shape":"Double",
          "documentation":"<p>The price per instance.</p>",
          "locationName":"price"
        }
      },
      "documentation":"<p>Describes a Reserved Instance offering.</p>"
    },
    "PricingDetailsList":{
      "type":"list",
      "member":{
        "shape":"PricingDetail",
        "locationName":"item"
      }
    },
    "PrincipalIdFormat":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>PrincipalIdFormatARN description</p>",
          "locationName":"arn"
        },
        "Statuses":{
          "shape":"IdFormatList",
          "documentation":"<p>PrincipalIdFormatStatuses description</p>",
          "locationName":"statusSet"
        }
      },
      "documentation":"<p>PrincipalIdFormat description</p>"
    },
    "PrincipalIdFormatList":{
      "type":"list",
      "member":{
        "shape":"PrincipalIdFormat",
        "locationName":"item"
      }
    },
    "PrincipalType":{
      "type":"string",
      "enum":[
        "All",
        "Service",
        "OrganizationUnit",
        "Account",
        "User",
        "Role"
      ]
    },
    "PrivateDnsDetails":{
      "type":"structure",
      "members":{
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private DNS name assigned to the VPC endpoint service.</p>",
          "locationName":"privateDnsName"
        }
      },
      "documentation":"<p>Information about the Private DNS name for interface endpoints.</p>"
    },
    "PrivateDnsDetailsSet":{
      "type":"list",
      "member":{
        "shape":"PrivateDnsDetails",
        "locationName":"item"
      }
    },
    "PrivateDnsNameConfiguration":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"DnsNameState",
          "documentation":"<p>The verification state of the VPC endpoint service.</p> <p>>Consumers of the endpoint service can use the private name only when the state is <code>verified</code>.</p>",
          "locationName":"state"
        },
        "Type":{
          "shape":"String",
          "documentation":"<p>The endpoint service verification type, for example TXT.</p>",
          "locationName":"type"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The value the service provider adds to the private DNS name domain record before verification.</p>",
          "locationName":"value"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name of the record subdomain the service provider needs to create. The service provider adds the <code>value</code> text to the <code>name</code>.</p>",
          "locationName":"name"
        }
      },
      "documentation":"<p>Information about the private DNS name for the service endpoint.</p>"
    },
    "PrivateDnsNameOptionsOnLaunch":{
      "type":"structure",
      "members":{
        "HostnameType":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname for EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 only subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID.</p>",
          "locationName":"hostnameType"
        },
        "EnableResourceNameDnsARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>",
          "locationName":"enableResourceNameDnsARecord"
        },
        "EnableResourceNameDnsAAAARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostname with DNS AAAA records.</p>",
          "locationName":"enableResourceNameDnsAAAARecord"
        }
      },
      "documentation":"<p>Describes the options for instance hostnames.</p>"
    },
    "PrivateDnsNameOptionsRequest":{
      "type":"structure",
      "members":{
        "HostnameType":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname for EC2 instances. For IPv4 only subnets, an instance DNS name must be based on the instance IPv4 address. For IPv6 only subnets, an instance DNS name must be based on the instance ID. For dual-stack subnets, you can specify whether DNS names use the instance IPv4 address or the instance ID.</p>"
        },
        "EnableResourceNameDnsARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>"
        },
        "EnableResourceNameDnsAAAARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p>"
        }
      },
      "documentation":"<p>Describes the options for instance hostnames.</p>"
    },
    "PrivateDnsNameOptionsResponse":{
      "type":"structure",
      "members":{
        "HostnameType":{
          "shape":"HostnameType",
          "documentation":"<p>The type of hostname to assign to an instance.</p>",
          "locationName":"hostnameType"
        },
        "EnableResourceNameDnsARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS A records.</p>",
          "locationName":"enableResourceNameDnsARecord"
        },
        "EnableResourceNameDnsAAAARecord":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to respond to DNS queries for instance hostnames with DNS AAAA records.</p>",
          "locationName":"enableResourceNameDnsAAAARecord"
        }
      },
      "documentation":"<p>Describes the options for instance hostnames.</p>"
    },
    "PrivateIpAddressConfigSet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstancesPrivateIpAddressConfig",
        "locationName":"PrivateIpAddressConfigSet"
      }
    },
    "PrivateIpAddressCount":{
      "type":"integer",
      "max":7,
      "min":1
    },
    "PrivateIpAddressSpecification":{
      "type":"structure",
      "members":{
        "Primary":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the private IPv4 address is the primary private IPv4 address. Only one IPv4 address can be designated as primary.</p>",
          "locationName":"primary"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The private IPv4 address.</p>",
          "locationName":"privateIpAddress"
        }
      },
      "documentation":"<p>Describes a secondary private IPv4 address for a network interface.</p>"
    },
    "PrivateIpAddressSpecificationList":{
      "type":"list",
      "member":{
        "shape":"PrivateIpAddressSpecification",
        "locationName":"item"
      }
    },
    "PrivateIpAddressStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"PrivateIpAddress"
      }
    },
    "ProcessorInfo":{
      "type":"structure",
      "members":{
        "SupportedArchitectures":{
          "shape":"ArchitectureTypeList",
          "documentation":"<p>The architectures supported by the instance type.</p>",
          "locationName":"supportedArchitectures"
        },
        "SustainedClockSpeedInGhz":{
          "shape":"ProcessorSustainedClockSpeed",
          "documentation":"<p>The speed of the processor, in GHz.</p>",
          "locationName":"sustainedClockSpeedInGhz"
        }
      },
      "documentation":"<p>Describes the processor used by the instance type.</p>"
    },
    "ProcessorSustainedClockSpeed":{"type":"double"},
    "ProductCode":{
      "type":"structure",
      "members":{
        "ProductCodeId":{
          "shape":"String",
          "documentation":"<p>The product code.</p>",
          "locationName":"productCode"
        },
        "ProductCodeType":{
          "shape":"ProductCodeValues",
          "documentation":"<p>The type of product code.</p>",
          "locationName":"type"
        }
      },
      "documentation":"<p>Describes a product code.</p>"
    },
    "ProductCodeList":{
      "type":"list",
      "member":{
        "shape":"ProductCode",
        "locationName":"item"
      }
    },
    "ProductCodeStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"ProductCode"
      }
    },
    "ProductCodeValues":{
      "type":"string",
      "enum":[
        "devpay",
        "marketplace"
      ]
    },
    "ProductDescriptionList":{
      "type":"list",
      "member":{"shape":"String"}
    },
    "PropagatingVgw":{
      "type":"structure",
      "members":{
        "GatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the virtual private gateway.</p>",
          "locationName":"gatewayId"
        }
      },
      "documentation":"<p>Describes a virtual private gateway propagating route.</p>"
    },
    "PropagatingVgwList":{
      "type":"list",
      "member":{
        "shape":"PropagatingVgw",
        "locationName":"item"
      }
    },
    "Protocol":{
      "type":"string",
      "enum":[
        "tcp",
        "udp"
      ]
    },
    "ProtocolList":{
      "type":"list",
      "member":{
        "shape":"Protocol",
        "locationName":"item"
      }
    },
    "ProtocolValue":{
      "type":"string",
      "enum":["gre"]
    },
    "ProvisionByoipCidrRequest":{
      "type":"structure",
      "required":["Cidr"],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The public IPv4 or IPv6 address range, in CIDR notation. The most specific IPv4 prefix that you can specify is /24. The most specific IPv6 prefix you can specify is /56. The address range cannot overlap with another address range that you've brought to this or another Region.</p>"
        },
        "CidrAuthorizationContext":{
          "shape":"CidrAuthorizationContext",
          "documentation":"<p>A signed document that proves that you are authorized to bring the specified IP address range to Amazon using BYOIP.</p>"
        },
        "PubliclyAdvertisable":{
          "shape":"Boolean",
          "documentation":"<p>(IPv6 only) Indicate whether the address range will be publicly advertised to the internet.</p> <p>Default: true</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the address range and the address pool.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PoolTagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the address pool.</p>",
          "locationName":"PoolTagSpecification"
        },
        "MultiRegion":{
          "shape":"Boolean",
          "documentation":"<p>Reserved.</p>"
        }
      }
    },
    "ProvisionByoipCidrResult":{
      "type":"structure",
      "members":{
        "ByoipCidr":{
          "shape":"ByoipCidr",
          "documentation":"<p>Information about the address range.</p>",
          "locationName":"byoipCidr"
        }
      }
    },
    "ProvisionIpamPoolCidrRequest":{
      "type":"structure",
      "required":["IpamPoolId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool to which you want to assign a CIDR.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR you want to assign to the IPAM pool. Either \"NetmaskLength\" or \"Cidr\" is required. This value will be null if you specify \"NetmaskLength\" and will be filled in during the provisioning process.</p>"
        },
        "CidrAuthorizationContext":{
          "shape":"IpamCidrAuthorizationContext",
          "documentation":"<p>A signed document that proves that you are authorized to bring a specified IP address range to Amazon using BYOIP. This option applies to public pools only.</p>"
        },
        "NetmaskLength":{
          "shape":"Integer",
          "documentation":"<p>The netmask length of the CIDR you'd like to provision to a pool. Can be used for provisioning Amazon-provided IPv6 CIDRs to top-level pools and for provisioning CIDRs to pools with source pools. Cannot be used to provision BYOIP CIDRs to top-level pools. Either \"NetmaskLength\" or \"Cidr\" is required.</p>"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "ProvisionIpamPoolCidrResult":{
      "type":"structure",
      "members":{
        "IpamPoolCidr":{
          "shape":"IpamPoolCidr",
          "documentation":"<p>Information about the provisioned CIDR.</p>",
          "locationName":"ipamPoolCidr"
        }
      }
    },
    "ProvisionPublicIpv4PoolCidrRequest":{
      "type":"structure",
      "required":[
        "IpamPoolId",
        "PoolId",
        "NetmaskLength"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool you would like to use to allocate this CIDR.</p>"
        },
        "PoolId":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of the public IPv4 pool you would like to use for this CIDR.</p>"
        },
        "NetmaskLength":{
          "shape":"Integer",
          "documentation":"<p>The netmask length of the CIDR you would like to allocate to the public IPv4 pool.</p>"
        }
      }
    },
    "ProvisionPublicIpv4PoolCidrResult":{
      "type":"structure",
      "members":{
        "PoolId":{
          "shape":"Ipv4PoolEc2Id",
          "documentation":"<p>The ID of the pool that you want to provision the CIDR to.</p>",
          "locationName":"poolId"
        },
        "PoolAddressRange":{
          "shape":"PublicIpv4PoolRange",
          "documentation":"<p>Information about the address range of the public IPv4 pool.</p>",
          "locationName":"poolAddressRange"
        }
      }
    },
    "ProvisionedBandwidth":{
      "type":"structure",
      "members":{
        "ProvisionTime":{
          "shape":"DateTime",
          "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>",
          "locationName":"provisionTime"
        },
        "Provisioned":{
          "shape":"String",
          "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>",
          "locationName":"provisioned"
        },
        "RequestTime":{
          "shape":"DateTime",
          "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>",
          "locationName":"requestTime"
        },
        "Requested":{
          "shape":"String",
          "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>",
          "locationName":"requested"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Reserved. If you need to sustain traffic greater than the <a href=\"https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html\">documented limits</a>, contact us through the <a href=\"https://console.aws.amazon.com/support/home?\">Support Center</a>.</p>"
    },
    "PtrUpdateStatus":{
      "type":"structure",
      "members":{
        "Value":{
          "shape":"String",
          "documentation":"<p>The value for the PTR record update.</p>",
          "locationName":"value"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The status of the PTR record update.</p>",
          "locationName":"status"
        },
        "Reason":{
          "shape":"String",
          "documentation":"<p>The reason for the PTR record update.</p>",
          "locationName":"reason"
        }
      },
      "documentation":"<p>The status of an updated pointer (PTR) record for an Elastic IP address.</p>"
    },
    "PublicIpAddress":{"type":"string"},
    "PublicIpStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"PublicIp"
      }
    },
    "PublicIpv4Pool":{
      "type":"structure",
      "members":{
        "PoolId":{
          "shape":"String",
          "documentation":"<p>The ID of the address pool.</p>",
          "locationName":"poolId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the address pool.</p>",
          "locationName":"description"
        },
        "PoolAddressRanges":{
          "shape":"PublicIpv4PoolRangeSet",
          "documentation":"<p>The address ranges.</p>",
          "locationName":"poolAddressRangeSet"
        },
        "TotalAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The total number of addresses.</p>",
          "locationName":"totalAddressCount"
        },
        "TotalAvailableAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The total number of available addresses.</p>",
          "locationName":"totalAvailableAddressCount"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The name of the location from which the address pool is advertised. A network border group is a unique set of Availability Zones or Local Zones from where Amazon Web Services advertises public IP addresses.</p>",
          "locationName":"networkBorderGroup"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags for the address pool.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an IPv4 address pool.</p>"
    },
    "PublicIpv4PoolIdStringList":{
      "type":"list",
      "member":{
        "shape":"Ipv4PoolEc2Id",
        "locationName":"item"
      }
    },
    "PublicIpv4PoolRange":{
      "type":"structure",
      "members":{
        "FirstAddress":{
          "shape":"String",
          "documentation":"<p>The first IP address in the range.</p>",
          "locationName":"firstAddress"
        },
        "LastAddress":{
          "shape":"String",
          "documentation":"<p>The last IP address in the range.</p>",
          "locationName":"lastAddress"
        },
        "AddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of addresses in the range.</p>",
          "locationName":"addressCount"
        },
        "AvailableAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of available addresses in the range.</p>",
          "locationName":"availableAddressCount"
        }
      },
      "documentation":"<p>Describes an address range of an IPv4 address pool.</p>"
    },
    "PublicIpv4PoolRangeSet":{
      "type":"list",
      "member":{
        "shape":"PublicIpv4PoolRange",
        "locationName":"item"
      }
    },
    "PublicIpv4PoolSet":{
      "type":"list",
      "member":{
        "shape":"PublicIpv4Pool",
        "locationName":"item"
      }
    },
    "Purchase":{
      "type":"structure",
      "members":{
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency in which the <code>UpfrontPrice</code> and <code>HourlyPrice</code> amounts are specified. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "Duration":{
          "shape":"Integer",
          "documentation":"<p>The duration of the reservation's term in seconds.</p>",
          "locationName":"duration"
        },
        "HostIdSet":{
          "shape":"ResponseHostIdSet",
          "documentation":"<p>The IDs of the Dedicated Hosts associated with the reservation.</p>",
          "locationName":"hostIdSet"
        },
        "HostReservationId":{
          "shape":"HostReservationId",
          "documentation":"<p>The ID of the reservation.</p>",
          "locationName":"hostReservationId"
        },
        "HourlyPrice":{
          "shape":"String",
          "documentation":"<p>The hourly price of the reservation per hour.</p>",
          "locationName":"hourlyPrice"
        },
        "InstanceFamily":{
          "shape":"String",
          "documentation":"<p>The instance family on the Dedicated Host that the reservation can be associated with.</p>",
          "locationName":"instanceFamily"
        },
        "PaymentOption":{
          "shape":"PaymentOption",
          "documentation":"<p>The payment option for the reservation.</p>",
          "locationName":"paymentOption"
        },
        "UpfrontPrice":{
          "shape":"String",
          "documentation":"<p>The upfront price of the reservation.</p>",
          "locationName":"upfrontPrice"
        }
      },
      "documentation":"<p>Describes the result of the purchase.</p>"
    },
    "PurchaseHostReservationRequest":{
      "type":"structure",
      "required":[
        "HostIdSet",
        "OfferingId"
      ],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency in which the <code>totalUpfrontPrice</code>, <code>LimitPrice</code>, and <code>totalHourlyPrice</code> amounts are specified. At this time, the only supported currency is <code>USD</code>.</p>"
        },
        "HostIdSet":{
          "shape":"RequestHostIdSet",
          "documentation":"<p>The IDs of the Dedicated Hosts with which the reservation will be associated.</p>"
        },
        "LimitPrice":{
          "shape":"String",
          "documentation":"<p>The specified limit is checked against the total upfront cost of the reservation (calculated as the offering's upfront cost multiplied by the host count). If the total upfront cost is greater than the specified price limit, the request fails. This is used to ensure that the purchase does not exceed the expected upfront cost of the purchase. At this time, the only supported currency is <code>USD</code>. For example, to indicate a limit price of USD 100, specify 100.00.</p>"
        },
        "OfferingId":{
          "shape":"OfferingId",
          "documentation":"<p>The ID of the offering.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the Dedicated Host Reservation during purchase.</p>",
          "locationName":"TagSpecification"
        }
      }
    },
    "PurchaseHostReservationResult":{
      "type":"structure",
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency in which the <code>totalUpfrontPrice</code> and <code>totalHourlyPrice</code> amounts are specified. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "Purchase":{
          "shape":"PurchaseSet",
          "documentation":"<p>Describes the details of the purchase.</p>",
          "locationName":"purchase"
        },
        "TotalHourlyPrice":{
          "shape":"String",
          "documentation":"<p>The total hourly price of the reservation calculated per hour.</p>",
          "locationName":"totalHourlyPrice"
        },
        "TotalUpfrontPrice":{
          "shape":"String",
          "documentation":"<p>The total amount charged to your account when you purchase the reservation.</p>",
          "locationName":"totalUpfrontPrice"
        }
      }
    },
    "PurchaseRequest":{
      "type":"structure",
      "required":[
        "InstanceCount",
        "PurchaseToken"
      ],
      "members":{
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances.</p>"
        },
        "PurchaseToken":{
          "shape":"String",
          "documentation":"<p>The purchase token.</p>"
        }
      },
      "documentation":"<p>Describes a request to purchase Scheduled Instances.</p>"
    },
    "PurchaseRequestSet":{
      "type":"list",
      "member":{
        "shape":"PurchaseRequest",
        "locationName":"PurchaseRequest"
      },
      "min":1
    },
    "PurchaseReservedInstancesOfferingRequest":{
      "type":"structure",
      "required":[
        "InstanceCount",
        "ReservedInstancesOfferingId"
      ],
      "members":{
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of Reserved Instances to purchase.</p>"
        },
        "ReservedInstancesOfferingId":{
          "shape":"ReservedInstancesOfferingId",
          "documentation":"<p>The ID of the Reserved Instance offering to purchase.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "LimitPrice":{
          "shape":"ReservedInstanceLimitPrice",
          "documentation":"<p>Specified for Reserved Instance Marketplace offerings to limit the total order and ensure that the Reserved Instances are not purchased at unexpected prices.</p>",
          "locationName":"limitPrice"
        },
        "PurchaseTime":{
          "shape":"DateTime",
          "documentation":"<p>The time at which to purchase the Reserved Instance, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>"
        }
      },
      "documentation":"<p>Contains the parameters for PurchaseReservedInstancesOffering.</p>"
    },
    "PurchaseReservedInstancesOfferingResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The IDs of the purchased Reserved Instances. If your purchase crosses into a discounted pricing tier, the final Reserved Instances IDs might change. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/concepts-reserved-instances-application.html#crossing-pricing-tiers\">Crossing pricing tiers</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"reservedInstancesId"
        }
      },
      "documentation":"<p>Contains the output of PurchaseReservedInstancesOffering.</p>"
    },
    "PurchaseScheduledInstancesRequest":{
      "type":"structure",
      "required":["PurchaseRequests"],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that ensures the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PurchaseRequests":{
          "shape":"PurchaseRequestSet",
          "documentation":"<p>The purchase requests.</p>",
          "locationName":"PurchaseRequest"
        }
      },
      "documentation":"<p>Contains the parameters for PurchaseScheduledInstances.</p>"
    },
    "PurchaseScheduledInstancesResult":{
      "type":"structure",
      "members":{
        "ScheduledInstanceSet":{
          "shape":"PurchasedScheduledInstanceSet",
          "documentation":"<p>Information about the Scheduled Instances.</p>",
          "locationName":"scheduledInstanceSet"
        }
      },
      "documentation":"<p>Contains the output of PurchaseScheduledInstances.</p>"
    },
    "PurchaseSet":{
      "type":"list",
      "member":{
        "shape":"Purchase",
        "locationName":"item"
      }
    },
    "PurchasedScheduledInstanceSet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstance",
        "locationName":"item"
      }
    },
    "RIProductDescription":{
      "type":"string",
      "enum":[
        "Linux/UNIX",
        "Linux/UNIX (Amazon VPC)",
        "Windows",
        "Windows (Amazon VPC)"
      ]
    },
    "RamdiskId":{"type":"string"},
    "ReasonCodesList":{
      "type":"list",
      "member":{
        "shape":"ReportInstanceReasonCodes",
        "locationName":"item"
      }
    },
    "RebootInstancesRequest":{
      "type":"structure",
      "required":["InstanceIds"],
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The instance IDs.</p>",
          "locationName":"InstanceId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "RecurringCharge":{
      "type":"structure",
      "members":{
        "Amount":{
          "shape":"Double",
          "documentation":"<p>The amount of the recurring charge.</p>",
          "locationName":"amount"
        },
        "Frequency":{
          "shape":"RecurringChargeFrequency",
          "documentation":"<p>The frequency of the recurring charge.</p>",
          "locationName":"frequency"
        }
      },
      "documentation":"<p>Describes a recurring charge.</p>"
    },
    "RecurringChargeFrequency":{
      "type":"string",
      "enum":["Hourly"]
    },
    "RecurringChargesList":{
      "type":"list",
      "member":{
        "shape":"RecurringCharge",
        "locationName":"item"
      }
    },
    "ReferencedSecurityGroup":{
      "type":"structure",
      "members":{
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "PeeringStatus":{
          "shape":"String",
          "documentation":"<p>The status of a VPC peering connection, if applicable.</p>",
          "locationName":"peeringStatus"
        },
        "UserId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID.</p>",
          "locationName":"userId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "VpcPeeringConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      },
      "documentation":"<p> Describes the security group that is referenced in the security group rule.</p>"
    },
    "Region":{
      "type":"structure",
      "members":{
        "Endpoint":{
          "shape":"String",
          "documentation":"<p>The Region service endpoint.</p>",
          "locationName":"regionEndpoint"
        },
        "RegionName":{
          "shape":"String",
          "documentation":"<p>The name of the Region.</p>",
          "locationName":"regionName"
        },
        "OptInStatus":{
          "shape":"String",
          "documentation":"<p>The Region opt-in status. The possible values are <code>opt-in-not-required</code>, <code>opted-in</code>, and <code>not-opted-in</code>.</p>",
          "locationName":"optInStatus"
        }
      },
      "documentation":"<p>Describes a Region.</p>"
    },
    "RegionList":{
      "type":"list",
      "member":{
        "shape":"Region",
        "locationName":"item"
      }
    },
    "RegionNameStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"RegionName"
      }
    },
    "RegionNames":{
      "type":"list",
      "member":{"shape":"String"},
      "max":10,
      "min":0
    },
    "RegisterImageRequest":{
      "type":"structure",
      "required":["Name"],
      "members":{
        "ImageLocation":{
          "shape":"String",
          "documentation":"<p>The full path to your AMI manifest in Amazon S3 storage. The specified bucket must have the <code>aws-exec-read</code> canned access control list (ACL) to ensure that it can be accessed by Amazon EC2. For more information, see <a href=\"https://docs.aws.amazon.com/AmazonS3/latest/dev/acl-overview.html#canned-acl\">Canned ACLs</a> in the <i>Amazon S3 Service Developer Guide</i>.</p>"
        },
        "Architecture":{
          "shape":"ArchitectureValues",
          "documentation":"<p>The architecture of the AMI.</p> <p>Default: For Amazon EBS-backed AMIs, <code>i386</code>. For instance store-backed AMIs, the architecture specified in the manifest file.</p>",
          "locationName":"architecture"
        },
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingRequestList",
          "documentation":"<p>The block device mapping entries.</p> <p>If you specify an Amazon EBS volume using the ID of an Amazon EBS snapshot, you can't specify the encryption state of the volume.</p> <p>If you create an AMI on an Outpost, then all backing snapshots must be on the same Outpost or in the Region of that Outpost. AMIs on an Outpost that include local snapshots can be used to launch instances on the same Outpost only. For more information, <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html#ami\">Amazon EBS local snapshots on Outposts</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"BlockDeviceMapping"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for your AMI.</p>",
          "locationName":"description"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "EnaSupport":{
          "shape":"Boolean",
          "documentation":"<p>Set to <code>true</code> to enable enhanced networking with ENA for the AMI and any instances that you launch from the AMI.</p> <p>This option is supported only for HVM AMIs. Specifying this option with a PV AMI can make instances launched from the AMI unreachable.</p>",
          "locationName":"enaSupport"
        },
        "KernelId":{
          "shape":"KernelId",
          "documentation":"<p>The ID of the kernel.</p>",
          "locationName":"kernelId"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>A name for your AMI.</p> <p>Constraints: 3-128 alphanumeric characters, parentheses (()), square brackets ([]), spaces ( ), periods (.), slashes (/), dashes (-), single quotes ('), at-signs (@), or underscores(_)</p>",
          "locationName":"name"
        },
        "BillingProducts":{
          "shape":"BillingProductList",
          "documentation":"<p>The billing product codes. Your account must be authorized to specify billing product codes.</p> <p>If your account is not authorized to specify billing product codes, you can publish AMIs that include billable software and list them on the Amazon Web Services Marketplace. You must first register as a seller on the Amazon Web Services Marketplace. For more information, see <a href=\"https://docs.aws.amazon.com/marketplace/latest/userguide/user-guide-for-sellers.html\">Getting started as a seller</a> and <a href=\"https://docs.aws.amazon.com/marketplace/latest/userguide/ami-products.html\">AMI-based products</a> in the <i>Amazon Web Services Marketplace Seller Guide</i>.</p>",
          "locationName":"BillingProduct"
        },
        "RamdiskId":{
          "shape":"RamdiskId",
          "documentation":"<p>The ID of the RAM disk.</p>",
          "locationName":"ramdiskId"
        },
        "RootDeviceName":{
          "shape":"String",
          "documentation":"<p>The device name of the root device volume (for example, <code>/dev/sda1</code>).</p>",
          "locationName":"rootDeviceName"
        },
        "SriovNetSupport":{
          "shape":"String",
          "documentation":"<p>Set to <code>simple</code> to enable enhanced networking with the Intel 82599 Virtual Function interface for the AMI and any instances that you launch from the AMI.</p> <p>There is no way to disable <code>sriovNetSupport</code> at this time.</p> <p>This option is supported only for HVM AMIs. Specifying this option with a PV AMI can make instances launched from the AMI unreachable.</p>",
          "locationName":"sriovNetSupport"
        },
        "VirtualizationType":{
          "shape":"String",
          "documentation":"<p>The type of virtualization (<code>hvm</code> | <code>paravirtual</code>).</p> <p>Default: <code>paravirtual</code> </p>",
          "locationName":"virtualizationType"
        },
        "BootMode":{
          "shape":"BootModeValues",
          "documentation":"<p>The boot mode of the AMI. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ami-boot.html\">Boot modes</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "TpmSupport":{
          "shape":"TpmSupportValues",
          "documentation":"<p>Set to <code>v2.0</code> to enable Trusted Platform Module (TPM) support. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/nitrotpm.html\">NitroTPM</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "UefiData":{
          "shape":"StringType",
          "documentation":"<p>Base64 representation of the non-volatile UEFI variable store. To retrieve the UEFI data, use the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_GetInstanceUefiData\">GetInstanceUefiData</a> command. You can inspect and modify the UEFI data by using the <a href=\"https://github.com/awslabs/python-uefivars\">python-uefivars tool</a> on GitHub. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/uefi-secure-boot.html\">UEFI Secure Boot</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "ImdsSupport":{
          "shape":"ImdsSupportValues",
          "documentation":"<p>Set to <code>v2.0</code> to indicate that IMDSv2 is specified in the AMI. Instances launched from this AMI will have <code>HttpTokens</code> automatically set to <code>required</code> so that, by default, the instance requires that IMDSv2 is used when requesting instance metadata. In addition, <code>HttpPutResponseHopLimit</code> is set to <code>2</code>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/configuring-IMDS-new-instances.html#configure-IMDS-new-instances-ami-configuration\">Configure the AMI</a> in the <i>Amazon EC2 User Guide</i>.</p> <note> <p>If you set the value to <code>v2.0</code>, make sure that your AMI software can support IMDSv2.</p> </note>"
        }
      },
      "documentation":"<p>Contains the parameters for RegisterImage.</p>"
    },
    "RegisterImageResult":{
      "type":"structure",
      "members":{
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the newly registered AMI.</p>",
          "locationName":"imageId"
        }
      },
      "documentation":"<p>Contains the output of RegisterImage.</p>"
    },
    "RegisterInstanceEventNotificationAttributesRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceTagAttribute":{
          "shape":"RegisterInstanceTagAttributeRequest",
          "documentation":"<p>Information about the tag keys to register.</p>"
        }
      }
    },
    "RegisterInstanceEventNotificationAttributesResult":{
      "type":"structure",
      "members":{
        "InstanceTagAttribute":{
          "shape":"InstanceTagNotificationAttribute",
          "documentation":"<p>The resulting set of tag keys.</p>",
          "locationName":"instanceTagAttribute"
        }
      }
    },
    "RegisterInstanceTagAttributeRequest":{
      "type":"structure",
      "members":{
        "IncludeAllTagsOfInstance":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to register all tag keys in the current Region. Specify <code>true</code> to register all tag keys.</p>"
        },
        "InstanceTagKeys":{
          "shape":"InstanceTagKeySet",
          "documentation":"<p>The tag keys to register.</p>",
          "locationName":"InstanceTagKey"
        }
      },
      "documentation":"<p>Information about the tag keys to register for the current Region. You can either specify individual tag keys or register all tag keys in the current Region. You must specify either <code>IncludeAllTagsOfInstance</code> or <code>InstanceTagKeys</code> in the request</p>"
    },
    "RegisterTransitGatewayMulticastGroupMembersRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayMulticastDomainId",
        "NetworkInterfaceIds"
      ],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>"
        },
        "NetworkInterfaceIds":{
          "shape":"TransitGatewayNetworkInterfaceIdList",
          "documentation":"<p>The group members' network interface IDs to register with the transit gateway multicast group.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RegisterTransitGatewayMulticastGroupMembersResult":{
      "type":"structure",
      "members":{
        "RegisteredMulticastGroupMembers":{
          "shape":"TransitGatewayMulticastRegisteredGroupMembers",
          "documentation":"<p>Information about the registered transit gateway multicast group members.</p>",
          "locationName":"registeredMulticastGroupMembers"
        }
      }
    },
    "RegisterTransitGatewayMulticastGroupSourcesRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayMulticastDomainId",
        "NetworkInterfaceIds"
      ],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>"
        },
        "NetworkInterfaceIds":{
          "shape":"TransitGatewayNetworkInterfaceIdList",
          "documentation":"<p>The group sources' network interface IDs to register with the transit gateway multicast group.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RegisterTransitGatewayMulticastGroupSourcesResult":{
      "type":"structure",
      "members":{
        "RegisteredMulticastGroupSources":{
          "shape":"TransitGatewayMulticastRegisteredGroupSources",
          "documentation":"<p>Information about the transit gateway multicast group sources.</p>",
          "locationName":"registeredMulticastGroupSources"
        }
      }
    },
    "RejectTransitGatewayMulticastDomainAssociationsRequest":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment.</p>"
        },
        "SubnetIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the subnets to associate with the transit gateway multicast domain.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RejectTransitGatewayMulticastDomainAssociationsResult":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"TransitGatewayMulticastDomainAssociations",
          "documentation":"<p>Information about the multicast domain associations.</p>",
          "locationName":"associations"
        }
      }
    },
    "RejectTransitGatewayPeeringAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway peering attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RejectTransitGatewayPeeringAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayPeeringAttachment":{
          "shape":"TransitGatewayPeeringAttachment",
          "documentation":"<p>The transit gateway peering attachment.</p>",
          "locationName":"transitGatewayPeeringAttachment"
        }
      }
    },
    "RejectTransitGatewayVpcAttachmentRequest":{
      "type":"structure",
      "required":["TransitGatewayAttachmentId"],
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RejectTransitGatewayVpcAttachmentResult":{
      "type":"structure",
      "members":{
        "TransitGatewayVpcAttachment":{
          "shape":"TransitGatewayVpcAttachment",
          "documentation":"<p>Information about the attachment.</p>",
          "locationName":"transitGatewayVpcAttachment"
        }
      }
    },
    "RejectVpcEndpointConnectionsRequest":{
      "type":"structure",
      "required":[
        "ServiceId",
        "VpcEndpointIds"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the service.</p>"
        },
        "VpcEndpointIds":{
          "shape":"VpcEndpointIdList",
          "documentation":"<p>The IDs of the VPC endpoints.</p>",
          "locationName":"VpcEndpointId"
        }
      }
    },
    "RejectVpcEndpointConnectionsResult":{
      "type":"structure",
      "members":{
        "Unsuccessful":{
          "shape":"UnsuccessfulItemSet",
          "documentation":"<p>Information about the endpoints that were not rejected, if applicable.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "RejectVpcPeeringConnectionRequest":{
      "type":"structure",
      "required":["VpcPeeringConnectionId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcPeeringConnectionId":{
          "shape":"VpcPeeringConnectionId",
          "documentation":"<p>The ID of the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      }
    },
    "RejectVpcPeeringConnectionResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "ReleaseAddressRequest":{
      "type":"structure",
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>[EC2-VPC] The allocation ID. Required for EC2-VPC.</p>"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>[EC2-Classic] The Elastic IP address. Required for EC2-Classic.</p>"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The set of Availability Zones, Local Zones, or Wavelength Zones from which Amazon Web Services advertises IP addresses.</p> <p>If you provide an incorrect network border group, you receive an <code>InvalidAddress.NotFound</code> error.</p> <p>You cannot use a network border group with EC2 Classic. If you attempt this operation on EC2 classic, you receive an <code>InvalidParameterCombination</code> error.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "ReleaseHostsRequest":{
      "type":"structure",
      "required":["HostIds"],
      "members":{
        "HostIds":{
          "shape":"RequestHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts to release.</p>",
          "locationName":"hostId"
        }
      }
    },
    "ReleaseHostsResult":{
      "type":"structure",
      "members":{
        "Successful":{
          "shape":"ResponseHostIdList",
          "documentation":"<p>The IDs of the Dedicated Hosts that were successfully released.</p>",
          "locationName":"successful"
        },
        "Unsuccessful":{
          "shape":"UnsuccessfulItemList",
          "documentation":"<p>The IDs of the Dedicated Hosts that could not be released, including an error message.</p>",
          "locationName":"unsuccessful"
        }
      }
    },
    "ReleaseIpamPoolAllocationRequest":{
      "type":"structure",
      "required":[
        "IpamPoolId",
        "Cidr",
        "IpamPoolAllocationId"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>A check for whether you have the required permissions for the action without actually making the request and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "IpamPoolId":{
          "shape":"IpamPoolId",
          "documentation":"<p>The ID of the IPAM pool which contains the allocation you want to release.</p>"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR of the allocation you want to release.</p>"
        },
        "IpamPoolAllocationId":{
          "shape":"IpamPoolAllocationId",
          "documentation":"<p>The ID of the allocation.</p>"
        }
      }
    },
    "ReleaseIpamPoolAllocationResult":{
      "type":"structure",
      "members":{
        "Success":{
          "shape":"Boolean",
          "documentation":"<p>Indicates if the release was successful.</p>",
          "locationName":"success"
        }
      }
    },
    "RemoveIpamOperatingRegion":{
      "type":"structure",
      "members":{
        "RegionName":{
          "shape":"String",
          "documentation":"<p>The name of the operating Region you want to remove.</p>"
        }
      },
      "documentation":"<p>Remove an operating Region from an IPAM. Operating Regions are Amazon Web Services Regions where the IPAM is allowed to manage IP address CIDRs. IPAM only discovers and monitors resources in the Amazon Web Services Regions you select as operating Regions.</p> <p>For more information about operating Regions, see <a href=\"https://docs.aws.amazon.com/vpc/latest/ipam/create-ipam.html\">Create an IPAM</a> in the <i>Amazon VPC IPAM User Guide</i> </p>"
    },
    "RemoveIpamOperatingRegionSet":{
      "type":"list",
      "member":{"shape":"RemoveIpamOperatingRegion"},
      "max":50,
      "min":0
    },
    "RemovePrefixListEntries":{
      "type":"list",
      "member":{"shape":"RemovePrefixListEntry"},
      "max":100,
      "min":0
    },
    "RemovePrefixListEntry":{
      "type":"structure",
      "required":["Cidr"],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR block.</p>"
        }
      },
      "documentation":"<p>An entry for a prefix list.</p>"
    },
    "ReplaceIamInstanceProfileAssociationRequest":{
      "type":"structure",
      "required":[
        "IamInstanceProfile",
        "AssociationId"
      ],
      "members":{
        "IamInstanceProfile":{
          "shape":"IamInstanceProfileSpecification",
          "documentation":"<p>The IAM instance profile.</p>"
        },
        "AssociationId":{
          "shape":"IamInstanceProfileAssociationId",
          "documentation":"<p>The ID of the existing IAM instance profile association.</p>"
        }
      }
    },
    "ReplaceIamInstanceProfileAssociationResult":{
      "type":"structure",
      "members":{
        "IamInstanceProfileAssociation":{
          "shape":"IamInstanceProfileAssociation",
          "documentation":"<p>Information about the IAM instance profile association.</p>",
          "locationName":"iamInstanceProfileAssociation"
        }
      }
    },
    "ReplaceNetworkAclAssociationRequest":{
      "type":"structure",
      "required":[
        "AssociationId",
        "NetworkAclId"
      ],
      "members":{
        "AssociationId":{
          "shape":"NetworkAclAssociationId",
          "documentation":"<p>The ID of the current association between the original network ACL and the subnet.</p>",
          "locationName":"associationId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkAclId":{
          "shape":"NetworkAclId",
          "documentation":"<p>The ID of the new network ACL to associate with the subnet.</p>",
          "locationName":"networkAclId"
        }
      }
    },
    "ReplaceNetworkAclAssociationResult":{
      "type":"structure",
      "members":{
        "NewAssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the new association.</p>",
          "locationName":"newAssociationId"
        }
      }
    },
    "ReplaceNetworkAclEntryRequest":{
      "type":"structure",
      "required":[
        "Egress",
        "NetworkAclId",
        "Protocol",
        "RuleAction",
        "RuleNumber"
      ],
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 network range to allow or deny, in CIDR notation (for example <code>172.16.0.0/24</code>).</p>",
          "locationName":"cidrBlock"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Egress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to replace the egress rule.</p> <p>Default: If no value is specified, we replace the ingress rule.</p>",
          "locationName":"egress"
        },
        "IcmpTypeCode":{
          "shape":"IcmpTypeCode",
          "documentation":"<p>ICMP protocol: The ICMP or ICMPv6 type and code. Required if specifying protocol 1 (ICMP) or protocol 58 (ICMPv6) with an IPv6 CIDR block.</p>",
          "locationName":"Icmp"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 network range to allow or deny, in CIDR notation (for example <code>2001:bd8:1234:1a00::/64</code>).</p>",
          "locationName":"ipv6CidrBlock"
        },
        "NetworkAclId":{
          "shape":"NetworkAclId",
          "documentation":"<p>The ID of the ACL.</p>",
          "locationName":"networkAclId"
        },
        "PortRange":{
          "shape":"PortRange",
          "documentation":"<p>TCP or UDP protocols: The range of ports the rule applies to. Required if specifying protocol 6 (TCP) or 17 (UDP).</p>",
          "locationName":"portRange"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol number. A value of \"-1\" means all protocols. If you specify \"-1\" or a protocol number other than \"6\" (TCP), \"17\" (UDP), or \"1\" (ICMP), traffic on all ports is allowed, regardless of any ports or ICMP types or codes that you specify. If you specify protocol \"58\" (ICMPv6) and specify an IPv4 CIDR block, traffic for all ICMP types and codes allowed, regardless of any that you specify. If you specify protocol \"58\" (ICMPv6) and specify an IPv6 CIDR block, you must specify an ICMP type and code.</p>",
          "locationName":"protocol"
        },
        "RuleAction":{
          "shape":"RuleAction",
          "documentation":"<p>Indicates whether to allow or deny the traffic that matches the rule.</p>",
          "locationName":"ruleAction"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The rule number of the entry to replace.</p>",
          "locationName":"ruleNumber"
        }
      }
    },
    "ReplaceRootVolumeTask":{
      "type":"structure",
      "members":{
        "ReplaceRootVolumeTaskId":{
          "shape":"ReplaceRootVolumeTaskId",
          "documentation":"<p>The ID of the root volume replacement task.</p>",
          "locationName":"replaceRootVolumeTaskId"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance for which the root volume replacement task was created.</p>",
          "locationName":"instanceId"
        },
        "TaskState":{
          "shape":"ReplaceRootVolumeTaskState",
          "documentation":"<p>The state of the task. The task can be in one of the following states:</p> <ul> <li> <p> <code>pending</code> - the replacement volume is being created.</p> </li> <li> <p> <code>in-progress</code> - the original volume is being detached and the replacement volume is being attached.</p> </li> <li> <p> <code>succeeded</code> - the replacement volume has been successfully attached to the instance and the instance is available.</p> </li> <li> <p> <code>failing</code> - the replacement task is in the process of failing.</p> </li> <li> <p> <code>failed</code> - the replacement task has failed but the original root volume is still attached.</p> </li> <li> <p> <code>failing-detached</code> - the replacement task is in the process of failing. The instance might have no root volume attached.</p> </li> <li> <p> <code>failed-detached</code> - the replacement task has failed and the instance has no root volume attached.</p> </li> </ul>",
          "locationName":"taskState"
        },
        "StartTime":{
          "shape":"String",
          "documentation":"<p>The time the task was started.</p>",
          "locationName":"startTime"
        },
        "CompleteTime":{
          "shape":"String",
          "documentation":"<p>The time the task completed.</p>",
          "locationName":"completeTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the task.</p>",
          "locationName":"tagSet"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI used to create the replacement root volume.</p>",
          "locationName":"imageId"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot used to create the replacement root volume.</p>",
          "locationName":"snapshotId"
        },
        "DeleteReplacedRootVolume":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the original root volume is to be deleted after the root volume replacement task completes.</p>",
          "locationName":"deleteReplacedRootVolume"
        }
      },
      "documentation":"<p>Information about a root volume replacement task.</p>"
    },
    "ReplaceRootVolumeTaskId":{"type":"string"},
    "ReplaceRootVolumeTaskIds":{
      "type":"list",
      "member":{
        "shape":"ReplaceRootVolumeTaskId",
        "locationName":"ReplaceRootVolumeTaskId"
      }
    },
    "ReplaceRootVolumeTaskState":{
      "type":"string",
      "enum":[
        "pending",
        "in-progress",
        "failing",
        "succeeded",
        "failed",
        "failed-detached"
      ]
    },
    "ReplaceRootVolumeTasks":{
      "type":"list",
      "member":{
        "shape":"ReplaceRootVolumeTask",
        "locationName":"item"
      }
    },
    "ReplaceRouteRequest":{
      "type":"structure",
      "required":["RouteTableId"],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR address block used for the destination match. The value that you provide must match the CIDR of an existing route in the table.</p>",
          "locationName":"destinationCidrBlock"
        },
        "DestinationIpv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR address block used for the destination match. The value that you provide must match the CIDR of an existing route in the table.</p>",
          "locationName":"destinationIpv6CidrBlock"
        },
        "DestinationPrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list for the route.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "VpcEndpointId":{
          "shape":"VpcEndpointId",
          "documentation":"<p>The ID of a VPC endpoint. Supported for Gateway Load Balancer endpoints only.</p>"
        },
        "EgressOnlyInternetGatewayId":{
          "shape":"EgressOnlyInternetGatewayId",
          "documentation":"<p>[IPv6 traffic only] The ID of an egress-only internet gateway.</p>",
          "locationName":"egressOnlyInternetGatewayId"
        },
        "GatewayId":{
          "shape":"RouteGatewayId",
          "documentation":"<p>The ID of an internet gateway or virtual private gateway.</p>",
          "locationName":"gatewayId"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of a NAT instance in your VPC.</p>",
          "locationName":"instanceId"
        },
        "LocalTarget":{
          "shape":"Boolean",
          "documentation":"<p>Specifies whether to reset the local route to its default target (<code>local</code>).</p>"
        },
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>[IPv4 traffic only] The ID of a NAT gateway.</p>",
          "locationName":"natGatewayId"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of a transit gateway.</p>"
        },
        "LocalGatewayId":{
          "shape":"LocalGatewayId",
          "documentation":"<p>The ID of the local gateway.</p>"
        },
        "CarrierGatewayId":{
          "shape":"CarrierGatewayId",
          "documentation":"<p>[IPv4 traffic only] The ID of a carrier gateway.</p>"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of a network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the route table.</p>",
          "locationName":"routeTableId"
        },
        "VpcPeeringConnectionId":{
          "shape":"VpcPeeringConnectionId",
          "documentation":"<p>The ID of a VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        },
        "CoreNetworkArn":{
          "shape":"CoreNetworkArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the core network.</p>"
        }
      }
    },
    "ReplaceRouteTableAssociationRequest":{
      "type":"structure",
      "required":[
        "AssociationId",
        "RouteTableId"
      ],
      "members":{
        "AssociationId":{
          "shape":"RouteTableAssociationId",
          "documentation":"<p>The association ID.</p>",
          "locationName":"associationId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "RouteTableId":{
          "shape":"RouteTableId",
          "documentation":"<p>The ID of the new route table to associate with the subnet.</p>",
          "locationName":"routeTableId"
        }
      }
    },
    "ReplaceRouteTableAssociationResult":{
      "type":"structure",
      "members":{
        "NewAssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the new association.</p>",
          "locationName":"newAssociationId"
        },
        "AssociationState":{
          "shape":"RouteTableAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"associationState"
        }
      }
    },
    "ReplaceTransitGatewayRouteRequest":{
      "type":"structure",
      "required":[
        "DestinationCidrBlock",
        "TransitGatewayRouteTableId"
      ],
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR range used for the destination match. Routing decisions are based on the most specific match.</p>"
        },
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the route table.</p>"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>"
        },
        "Blackhole":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether traffic matching this route is to be dropped.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ReplaceTransitGatewayRouteResult":{
      "type":"structure",
      "members":{
        "Route":{
          "shape":"TransitGatewayRoute",
          "documentation":"<p>Information about the modified route.</p>",
          "locationName":"route"
        }
      }
    },
    "ReplacementStrategy":{
      "type":"string",
      "enum":[
        "launch",
        "launch-before-terminate"
      ]
    },
    "ReportInstanceReasonCodes":{
      "type":"string",
      "enum":[
        "instance-stuck-in-state",
        "unresponsive",
        "not-accepting-credentials",
        "password-not-available",
        "performance-network",
        "performance-instance-store",
        "performance-ebs-volume",
        "performance-other",
        "other"
      ]
    },
    "ReportInstanceStatusRequest":{
      "type":"structure",
      "required":[
        "Instances",
        "ReasonCodes",
        "Status"
      ],
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>Descriptive text about the health state of your instance.</p>",
          "locationName":"description"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "EndTime":{
          "shape":"DateTime",
          "documentation":"<p>The time at which the reported instance health state ended.</p>",
          "locationName":"endTime"
        },
        "Instances":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The instances.</p>",
          "locationName":"instanceId"
        },
        "ReasonCodes":{
          "shape":"ReasonCodesList",
          "documentation":"<p>The reason codes that describe the health state of your instance.</p> <ul> <li> <p> <code>instance-stuck-in-state</code>: My instance is stuck in a state.</p> </li> <li> <p> <code>unresponsive</code>: My instance is unresponsive.</p> </li> <li> <p> <code>not-accepting-credentials</code>: My instance is not accepting my credentials.</p> </li> <li> <p> <code>password-not-available</code>: A password is not available for my instance.</p> </li> <li> <p> <code>performance-network</code>: My instance is experiencing performance problems that I believe are network related.</p> </li> <li> <p> <code>performance-instance-store</code>: My instance is experiencing performance problems that I believe are related to the instance stores.</p> </li> <li> <p> <code>performance-ebs-volume</code>: My instance is experiencing performance problems that I believe are related to an EBS volume.</p> </li> <li> <p> <code>performance-other</code>: My instance is experiencing performance problems.</p> </li> <li> <p> <code>other</code>: [explain using the description parameter]</p> </li> </ul>",
          "locationName":"reasonCode"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The time at which the reported instance health state began.</p>",
          "locationName":"startTime"
        },
        "Status":{
          "shape":"ReportStatusType",
          "documentation":"<p>The status of all instances listed.</p>",
          "locationName":"status"
        }
      }
    },
    "ReportStatusType":{
      "type":"string",
      "enum":[
        "ok",
        "impaired"
      ]
    },
    "RequestHostIdList":{
      "type":"list",
      "member":{
        "shape":"DedicatedHostId",
        "locationName":"item"
      }
    },
    "RequestHostIdSet":{
      "type":"list",
      "member":{
        "shape":"DedicatedHostId",
        "locationName":"item"
      }
    },
    "RequestInstanceTypeList":{
      "type":"list",
      "member":{"shape":"InstanceType"},
      "locationName":"InstanceType",
      "max":100,
      "min":0
    },
    "RequestIpamResourceTag":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "documentation":"<p>The key of a tag assigned to the resource. Use this filter to find all resources assigned a tag with a specific key, regardless of the tag value.</p>"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The value for the tag.</p>"
        }
      },
      "documentation":"<p>A tag on an IPAM resource.</p>"
    },
    "RequestIpamResourceTagList":{
      "type":"list",
      "member":{
        "shape":"RequestIpamResourceTag",
        "locationName":"item"
      }
    },
    "RequestLaunchTemplateData":{
      "type":"structure",
      "members":{
        "KernelId":{
          "shape":"KernelId",
          "documentation":"<p>The ID of the kernel.</p> <important> <p>We recommend that you use PV-GRUB instead of kernels and RAM disks. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/UserProvidedkernels.html\">User provided kernels</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </important>"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is optimized for Amazon EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal Amazon EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS-optimized instance.</p>"
        },
        "IamInstanceProfile":{
          "shape":"LaunchTemplateIamInstanceProfileSpecificationRequest",
          "documentation":"<p>The name or Amazon Resource Name (ARN) of an IAM instance profile.</p>"
        },
        "BlockDeviceMappings":{
          "shape":"LaunchTemplateBlockDeviceMappingRequestList",
          "documentation":"<p>The block device mapping.</p>",
          "locationName":"BlockDeviceMapping"
        },
        "NetworkInterfaces":{
          "shape":"LaunchTemplateInstanceNetworkInterfaceSpecificationRequestList",
          "documentation":"<p>One or more network interfaces. If you specify a network interface, you must specify any security groups and subnets as part of the network interface.</p>",
          "locationName":"NetworkInterface"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI. Alternatively, you can specify a Systems Manager parameter, which will resolve to an AMI ID on launch.</p> <p>Valid formats:</p> <ul> <li> <p> <code>ami-17characters00000</code> </p> </li> <li> <p> <code>resolve:ssm:parameter-name</code> </p> </li> <li> <p> <code>resolve:ssm:parameter-name:version-number</code> </p> </li> <li> <p> <code>resolve:ssm:parameter-name:label</code> </p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/finding-an-ami.html#using-systems-manager-parameter-to-find-AMI\">Use a Systems Manager parameter to find an AMI</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>If you specify <code>InstanceType</code>, you can't specify <code>InstanceRequirements</code>.</p>"
        },
        "KeyName":{
          "shape":"KeyPairName",
          "documentation":"<p>The name of the key pair. You can create a key pair using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateKeyPair.html\">CreateKeyPair</a> or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportKeyPair.html\">ImportKeyPair</a>.</p> <important> <p>If you do not specify a key pair, you can't connect to the instance unless you choose an AMI that is configured to allow users another way to log in.</p> </important>"
        },
        "Monitoring":{
          "shape":"LaunchTemplatesMonitoringRequest",
          "documentation":"<p>The monitoring for the instance.</p>"
        },
        "Placement":{
          "shape":"LaunchTemplatePlacementRequest",
          "documentation":"<p>The placement for the instance.</p>"
        },
        "RamDiskId":{
          "shape":"RamdiskId",
          "documentation":"<p>The ID of the RAM disk.</p> <important> <p>We recommend that you use PV-GRUB instead of kernels and RAM disks. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/UserProvidedkernels.html\">User provided kernels</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </important>"
        },
        "DisableApiTermination":{
          "shape":"Boolean",
          "documentation":"<p>If you set this parameter to <code>true</code>, you can't terminate the instance using the Amazon EC2 console, CLI, or API; otherwise, you can. To change this attribute after launch, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceAttribute.html\">ModifyInstanceAttribute</a>. Alternatively, if you set <code>InstanceInitiatedShutdownBehavior</code> to <code>terminate</code>, you can terminate the instance by running the shutdown command from the instance.</p>"
        },
        "InstanceInitiatedShutdownBehavior":{
          "shape":"ShutdownBehavior",
          "documentation":"<p>Indicates whether an instance stops or terminates when you initiate shutdown from the instance (using the operating system command for system shutdown).</p> <p>Default: <code>stop</code> </p>"
        },
        "UserData":{
          "shape":"String",
          "documentation":"<p>The user data to make available to the instance. You must provide base64-encoded text. User data is limited to 16 KB. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/user-data.html\">Run commands on your Linux instance at launch</a> (Linux) or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/instancedata-add-user-data.html\">Work with instance user data</a> (Windows) in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> <p>If you are creating the launch template for use with Batch, the user data must be provided in the <a href=\"https://cloudinit.readthedocs.io/en/latest/topics/format.html#mime-multi-part-archive\"> MIME multi-part archive format</a>. For more information, see <a href=\"https://docs.aws.amazon.com/batch/latest/userguide/launch-templates.html\">Amazon EC2 user data in launch templates</a> in the <i>Batch User Guide</i>.</p>"
        },
        "TagSpecifications":{
          "shape":"LaunchTemplateTagSpecificationRequestList",
          "documentation":"<p>The tags to apply to the resources that are created during instance launch.</p> <p>You can specify tags for the following resources only:</p> <ul> <li> <p>Instances</p> </li> <li> <p>Volumes</p> </li> <li> <p>Elastic graphics</p> </li> <li> <p>Spot Instance requests</p> </li> <li> <p>Network interfaces</p> </li> </ul> <p>To tag a resource after it has been created, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html\">CreateTags</a>.</p> <note> <p>To tag the launch template itself, you must use the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateLaunchTemplate.html\">TagSpecification</a> parameter.</p> </note>",
          "locationName":"TagSpecification"
        },
        "ElasticGpuSpecifications":{
          "shape":"ElasticGpuSpecificationList",
          "documentation":"<p>An elastic GPU to associate with the instance.</p>",
          "locationName":"ElasticGpuSpecification"
        },
        "ElasticInferenceAccelerators":{
          "shape":"LaunchTemplateElasticInferenceAcceleratorList",
          "documentation":"<p> The elastic inference accelerator for the instance. </p>",
          "locationName":"ElasticInferenceAccelerator"
        },
        "SecurityGroupIds":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>One or more security group IDs. You can create a security group using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecurityGroup.html\">CreateSecurityGroup</a>. You cannot specify both a security group ID and security name in the same request.</p>",
          "locationName":"SecurityGroupId"
        },
        "SecurityGroups":{
          "shape":"SecurityGroupStringList",
          "documentation":"<p>One or more security group names. For a nondefault VPC, you must use security group IDs instead. You cannot specify both a security group ID and security name in the same request.</p>",
          "locationName":"SecurityGroup"
        },
        "InstanceMarketOptions":{
          "shape":"LaunchTemplateInstanceMarketOptionsRequest",
          "documentation":"<p>The market (purchasing) option for the instances.</p>"
        },
        "CreditSpecification":{
          "shape":"CreditSpecificationRequest",
          "documentation":"<p>The credit option for CPU usage of the instance. Valid only for T instances.</p>"
        },
        "CpuOptions":{
          "shape":"LaunchTemplateCpuOptionsRequest",
          "documentation":"<p>The CPU options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html\">Optimizing CPU Options</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "CapacityReservationSpecification":{
          "shape":"LaunchTemplateCapacityReservationSpecificationRequest",
          "documentation":"<p>The Capacity Reservation targeting option. If you do not specify this parameter, the instance's Capacity Reservation preference defaults to <code>open</code>, which enables it to run in any open Capacity Reservation that has matching attributes (instance type, platform, Availability Zone).</p>"
        },
        "LicenseSpecifications":{
          "shape":"LaunchTemplateLicenseSpecificationListRequest",
          "documentation":"<p>The license configurations.</p>",
          "locationName":"LicenseSpecification"
        },
        "HibernationOptions":{
          "shape":"LaunchTemplateHibernationOptionsRequest",
          "documentation":"<p>Indicates whether an instance is enabled for hibernation. This parameter is valid only if the instance meets the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/hibernating-prerequisites.html\">hibernation prerequisites</a>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "MetadataOptions":{
          "shape":"LaunchTemplateInstanceMetadataOptionsRequest",
          "documentation":"<p>The metadata options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">Instance metadata and user data</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        },
        "EnclaveOptions":{
          "shape":"LaunchTemplateEnclaveOptionsRequest",
          "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves. For more information, see <a href=\"https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html\"> What is Amazon Web Services Nitro Enclaves?</a> in the <i>Amazon Web Services Nitro Enclaves User Guide</i>.</p> <p>You can't enable Amazon Web Services Nitro Enclaves and hibernation on the same instance.</p>"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirementsRequest",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with these attributes.</p> <p>If you specify <code>InstanceRequirements</code>, you can't specify <code>InstanceType</code>.</p>"
        },
        "PrivateDnsNameOptions":{
          "shape":"LaunchTemplatePrivateDnsNameOptionsRequest",
          "documentation":"<p>The options for the instance hostname. The default values are inherited from the subnet.</p>"
        },
        "MaintenanceOptions":{
          "shape":"LaunchTemplateInstanceMaintenanceOptionsRequest",
          "documentation":"<p>The maintenance options for the instance.</p>"
        },
        "DisableApiStop":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to enable the instance for stop protection. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Stop_Start.html#Using_StopProtection\">Stop protection</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>"
        }
      },
      "documentation":"<p>The information to include in the launch template.</p> <note> <p>You must specify at least one parameter for the launch template data.</p> </note>",
      "sensitive":true
    },
    "RequestSpotFleetRequest":{
      "type":"structure",
      "required":["SpotFleetRequestConfig"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "SpotFleetRequestConfig":{
          "shape":"SpotFleetRequestConfigData",
          "documentation":"<p>The configuration for the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestConfig"
        }
      },
      "documentation":"<p>Contains the parameters for RequestSpotFleet.</p>"
    },
    "RequestSpotFleetResponse":{
      "type":"structure",
      "members":{
        "SpotFleetRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        }
      },
      "documentation":"<p>Contains the output of RequestSpotFleet.</p>"
    },
    "RequestSpotInstancesRequest":{
      "type":"structure",
      "members":{
        "AvailabilityZoneGroup":{
          "shape":"String",
          "documentation":"<p>The user-specified name for a logical grouping of requests.</p> <p>When you specify an Availability Zone group in a Spot Instance request, all Spot Instances in the request are launched in the same Availability Zone. Instance proximity is maintained with this parameter, but the choice of Availability Zone is not. The group applies only to requests for Spot Instances of the same instance type. Any additional Spot Instance requests that are specified with the same Availability Zone group name are launched in that same Availability Zone, as long as at least one instance from the group is still active.</p> <p>If there is no active instance running in the Availability Zone group that you specify for a new Spot Instance request (all instances are terminated, the request is expired, or the maximum price you specified falls below current Spot price), then Amazon EC2 launches the instance in any Availability Zone where the constraint can be met. Consequently, the subsequent set of Spot Instances could be placed in a different zone from the original request, even if you specified the same Availability Zone group.</p> <p>Default: Instances are launched in any available Availability Zone.</p>",
          "locationName":"availabilityZoneGroup"
        },
        "BlockDurationMinutes":{
          "shape":"Integer",
          "documentation":"<p>Deprecated.</p>",
          "locationName":"blockDurationMinutes"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Run_Instance_Idempotency.html\">How to Ensure Idempotency</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>",
          "locationName":"clientToken"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of Spot Instances to launch.</p> <p>Default: 1</p>",
          "locationName":"instanceCount"
        },
        "LaunchGroup":{
          "shape":"String",
          "documentation":"<p>The instance launch group. Launch groups are Spot Instances that launch together and terminate together.</p> <p>Default: Instances are launched and terminated individually</p>",
          "locationName":"launchGroup"
        },
        "LaunchSpecification":{
          "shape":"RequestSpotLaunchSpecification",
          "documentation":"<p>The launch specification.</p>"
        },
        "SpotPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"spotPrice"
        },
        "Type":{
          "shape":"SpotInstanceType",
          "documentation":"<p>The Spot Instance request type.</p> <p>Default: <code>one-time</code> </p>",
          "locationName":"type"
        },
        "ValidFrom":{
          "shape":"DateTime",
          "documentation":"<p>The start date of the request. If this is a one-time request, the request becomes active at this date and time and remains active until all instances launch, the request expires, or the request is canceled. If the request is persistent, the request becomes active at this date and time and remains active until it expires or is canceled.</p> <p>The specified start date and time cannot be equal to the current date and time. You must specify a start date and time that occurs after the current date and time.</p>",
          "locationName":"validFrom"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date of the request, in UTC format (<i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p> <ul> <li> <p>For a persistent request, the request remains active until the <code>ValidUntil</code> date and time is reached. Otherwise, the request remains active until you cancel it. </p> </li> <li> <p>For a one-time request, the request remains active until all instances launch, the request is canceled, or the <code>ValidUntil</code> date and time is reached. By default, the request is valid for 7 days from the date the request was created.</p> </li> </ul>",
          "locationName":"validUntil"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key-value pair for tagging the Spot Instance request on creation. The value for <code>ResourceType</code> must be <code>spot-instances-request</code>, otherwise the Spot Instance request fails. To tag the Spot Instance request after it has been created, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html\">CreateTags</a>. </p>",
          "locationName":"TagSpecification"
        },
        "InstanceInterruptionBehavior":{
          "shape":"InstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted. The default is <code>terminate</code>.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for RequestSpotInstances.</p>"
    },
    "RequestSpotInstancesResult":{
      "type":"structure",
      "members":{
        "SpotInstanceRequests":{
          "shape":"SpotInstanceRequestList",
          "documentation":"<p>One or more Spot Instance requests.</p>",
          "locationName":"spotInstanceRequestSet"
        }
      },
      "documentation":"<p>Contains the output of RequestSpotInstances.</p>"
    },
    "RequestSpotLaunchSpecification":{
      "type":"structure",
      "members":{
        "SecurityGroupIds":{
          "shape":"RequestSpotLaunchSpecificationSecurityGroupIdList",
          "documentation":"<p>One or more security group IDs.</p>",
          "locationName":"SecurityGroupId"
        },
        "SecurityGroups":{
          "shape":"RequestSpotLaunchSpecificationSecurityGroupList",
          "documentation":"<p>One or more security groups. When requesting instances in a VPC, you must specify the IDs of the security groups. When requesting instances in EC2-Classic, you can specify the names or the IDs of the security groups.</p>",
          "locationName":"SecurityGroup"
        },
        "AddressingType":{
          "shape":"String",
          "documentation":"<p>Deprecated.</p>",
          "locationName":"addressingType"
        },
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingList",
          "documentation":"<p>One or more block device mapping entries. You can't specify both a snapshot ID and an encryption value. This is because only blank volumes can be encrypted on creation. If a snapshot is the basis for a volume, it is not blank and its encryption status is used for the volume encryption status.</p>",
          "locationName":"blockDeviceMapping"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is optimized for EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS Optimized instance.</p> <p>Default: <code>false</code> </p>",
          "locationName":"ebsOptimized"
        },
        "IamInstanceProfile":{
          "shape":"IamInstanceProfileSpecification",
          "documentation":"<p>The IAM instance profile.</p>",
          "locationName":"iamInstanceProfile"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>",
          "locationName":"imageId"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. Only one instance type can be specified.</p>",
          "locationName":"instanceType"
        },
        "KernelId":{
          "shape":"KernelId",
          "documentation":"<p>The ID of the kernel.</p>",
          "locationName":"kernelId"
        },
        "KeyName":{
          "shape":"KeyPairName",
          "documentation":"<p>The name of the key pair.</p>",
          "locationName":"keyName"
        },
        "Monitoring":{
          "shape":"RunInstancesMonitoringEnabled",
          "documentation":"<p>Indicates whether basic or detailed monitoring is enabled for the instance.</p> <p>Default: Disabled</p>",
          "locationName":"monitoring"
        },
        "NetworkInterfaces":{
          "shape":"InstanceNetworkInterfaceSpecificationList",
          "documentation":"<p>One or more network interfaces. If you specify a network interface, you must specify subnet IDs and security group IDs using the network interface.</p>",
          "locationName":"NetworkInterface"
        },
        "Placement":{
          "shape":"SpotPlacement",
          "documentation":"<p>The placement information for the instance.</p>",
          "locationName":"placement"
        },
        "RamdiskId":{
          "shape":"RamdiskId",
          "documentation":"<p>The ID of the RAM disk.</p>",
          "locationName":"ramdiskId"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet in which to launch the instance.</p>",
          "locationName":"subnetId"
        },
        "UserData":{
          "shape":"SensitiveUserData",
          "documentation":"<p>The Base64-encoded user data for the instance. User data is limited to 16 KB.</p>",
          "locationName":"userData"
        }
      },
      "documentation":"<p>Describes the launch specification for an instance.</p>"
    },
    "RequestSpotLaunchSpecificationSecurityGroupIdList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"item"
      }
    },
    "RequestSpotLaunchSpecificationSecurityGroupList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "Reservation":{
      "type":"structure",
      "members":{
        "Groups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>[EC2-Classic only] The security groups.</p>",
          "locationName":"groupSet"
        },
        "Instances":{
          "shape":"InstanceList",
          "documentation":"<p>The instances.</p>",
          "locationName":"instancesSet"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the reservation.</p>",
          "locationName":"ownerId"
        },
        "RequesterId":{
          "shape":"String",
          "documentation":"<p>The ID of the requester that launched the instances on your behalf (for example, Amazon Web Services Management Console or Auto Scaling).</p>",
          "locationName":"requesterId"
        },
        "ReservationId":{
          "shape":"String",
          "documentation":"<p>The ID of the reservation.</p>",
          "locationName":"reservationId"
        }
      },
      "documentation":"<p>Describes a launch request for one or more instances, and includes owner, requester, and security group information that applies to all instances in the launch request.</p>"
    },
    "ReservationFleetInstanceSpecification":{
      "type":"structure",
      "members":{
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type for which the Capacity Reservation Fleet reserves capacity.</p>"
        },
        "InstancePlatform":{
          "shape":"CapacityReservationInstancePlatform",
          "documentation":"<p>The type of operating system for which the Capacity Reservation Fleet reserves capacity.</p>"
        },
        "Weight":{
          "shape":"DoubleWithConstraints",
          "documentation":"<p>The number of capacity units provided by the specified instance type. This value, together with the total target capacity that you specify for the Fleet determine the number of instances for which the Fleet reserves capacity. Both values are based on units that make sense for your workload. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#target-capacity\">Total target capacity</a> in the Amazon EC2 User Guide.</p>"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the Capacity Reservation Fleet reserves the capacity. A Capacity Reservation Fleet can't span Availability Zones. All instance type specifications that you specify for the Fleet must use the same Availability Zone.</p>"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The ID of the Availability Zone in which the Capacity Reservation Fleet reserves the capacity. A Capacity Reservation Fleet can't span Availability Zones. All instance type specifications that you specify for the Fleet must use the same Availability Zone.</p>"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the Capacity Reservation Fleet supports EBS-optimized instances types. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using EBS-optimized instance types.</p>"
        },
        "Priority":{
          "shape":"IntegerWithConstraints",
          "documentation":"<p>The priority to assign to the instance type. This value is used to determine which of the instance types specified for the Fleet should be prioritized for use. A lower value indicates a high priority. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/crfleet-concepts.html#instance-priority\">Instance type priority</a> in the Amazon EC2 User Guide.</p>"
        }
      },
      "documentation":"<p>Information about an instance type to use in a Capacity Reservation Fleet.</p>"
    },
    "ReservationFleetInstanceSpecificationList":{
      "type":"list",
      "member":{"shape":"ReservationFleetInstanceSpecification"}
    },
    "ReservationId":{"type":"string"},
    "ReservationList":{
      "type":"list",
      "member":{
        "shape":"Reservation",
        "locationName":"item"
      }
    },
    "ReservationState":{
      "type":"string",
      "enum":[
        "payment-pending",
        "payment-failed",
        "active",
        "retired"
      ]
    },
    "ReservationValue":{
      "type":"structure",
      "members":{
        "HourlyPrice":{
          "shape":"String",
          "documentation":"<p>The hourly rate of the reservation.</p>",
          "locationName":"hourlyPrice"
        },
        "RemainingTotalValue":{
          "shape":"String",
          "documentation":"<p>The balance of the total value (the sum of remainingUpfrontValue + hourlyPrice * number of hours remaining).</p>",
          "locationName":"remainingTotalValue"
        },
        "RemainingUpfrontValue":{
          "shape":"String",
          "documentation":"<p>The remaining upfront cost of the reservation.</p>",
          "locationName":"remainingUpfrontValue"
        }
      },
      "documentation":"<p>The cost associated with the Reserved Instance.</p>"
    },
    "ReservedInstanceIdSet":{
      "type":"list",
      "member":{
        "shape":"ReservationId",
        "locationName":"ReservedInstanceId"
      }
    },
    "ReservedInstanceLimitPrice":{
      "type":"structure",
      "members":{
        "Amount":{
          "shape":"Double",
          "documentation":"<p>Used for Reserved Instance Marketplace offerings. Specifies the limit price on the total order (instanceCount * price).</p>",
          "locationName":"amount"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency in which the <code>limitPrice</code> amount is specified. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        }
      },
      "documentation":"<p>Describes the limit price of a Reserved Instance offering.</p>"
    },
    "ReservedInstanceReservationValue":{
      "type":"structure",
      "members":{
        "ReservationValue":{
          "shape":"ReservationValue",
          "documentation":"<p>The total value of the Convertible Reserved Instance that you are exchanging.</p>",
          "locationName":"reservationValue"
        },
        "ReservedInstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Convertible Reserved Instance that you are exchanging.</p>",
          "locationName":"reservedInstanceId"
        }
      },
      "documentation":"<p>The total value of the Convertible Reserved Instance.</p>"
    },
    "ReservedInstanceReservationValueSet":{
      "type":"list",
      "member":{
        "shape":"ReservedInstanceReservationValue",
        "locationName":"item"
      }
    },
    "ReservedInstanceState":{
      "type":"string",
      "enum":[
        "payment-pending",
        "active",
        "payment-failed",
        "retired",
        "queued",
        "queued-deleted"
      ]
    },
    "ReservedInstances":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the Reserved Instance can be used.</p>",
          "locationName":"availabilityZone"
        },
        "Duration":{
          "shape":"Long",
          "documentation":"<p>The duration of the Reserved Instance, in seconds.</p>",
          "locationName":"duration"
        },
        "End":{
          "shape":"DateTime",
          "documentation":"<p>The time when the Reserved Instance expires.</p>",
          "locationName":"end"
        },
        "FixedPrice":{
          "shape":"Float",
          "documentation":"<p>The purchase price of the Reserved Instance.</p>",
          "locationName":"fixedPrice"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of reservations purchased.</p>",
          "locationName":"instanceCount"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type on which the Reserved Instance can be used.</p>",
          "locationName":"instanceType"
        },
        "ProductDescription":{
          "shape":"RIProductDescription",
          "documentation":"<p>The Reserved Instance product platform description.</p>",
          "locationName":"productDescription"
        },
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance.</p>",
          "locationName":"reservedInstancesId"
        },
        "Start":{
          "shape":"DateTime",
          "documentation":"<p>The date and time the Reserved Instance started.</p>",
          "locationName":"start"
        },
        "State":{
          "shape":"ReservedInstanceState",
          "documentation":"<p>The state of the Reserved Instance purchase.</p>",
          "locationName":"state"
        },
        "UsagePrice":{
          "shape":"Float",
          "documentation":"<p>The usage price of the Reserved Instance, per hour.</p>",
          "locationName":"usagePrice"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency of the Reserved Instance. It's specified using ISO 4217 standard currency codes. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "InstanceTenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instance.</p>",
          "locationName":"instanceTenancy"
        },
        "OfferingClass":{
          "shape":"OfferingClassType",
          "documentation":"<p>The offering class of the Reserved Instance.</p>",
          "locationName":"offeringClass"
        },
        "OfferingType":{
          "shape":"OfferingTypeValues",
          "documentation":"<p>The Reserved Instance offering type.</p>",
          "locationName":"offeringType"
        },
        "RecurringCharges":{
          "shape":"RecurringChargesList",
          "documentation":"<p>The recurring charge tag assigned to the resource.</p>",
          "locationName":"recurringCharges"
        },
        "Scope":{
          "shape":"scope",
          "documentation":"<p>The scope of the Reserved Instance.</p>",
          "locationName":"scope"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the resource.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Reserved Instance.</p>"
    },
    "ReservedInstancesConfiguration":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone for the modified Reserved Instances.</p>",
          "locationName":"availabilityZone"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of modified Reserved Instances.</p> <note> <p>This is a required field for a request.</p> </note>",
          "locationName":"instanceCount"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type for the modified Reserved Instances.</p>",
          "locationName":"instanceType"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>The network platform of the modified Reserved Instances, which is either EC2-Classic or EC2-VPC.</p>",
          "locationName":"platform"
        },
        "Scope":{
          "shape":"scope",
          "documentation":"<p>Whether the Reserved Instance is applied to instances in a Region or instances in a specific Availability Zone.</p>",
          "locationName":"scope"
        }
      },
      "documentation":"<p>Describes the configuration settings for the modified Reserved Instances.</p>"
    },
    "ReservedInstancesConfigurationList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesConfiguration",
        "locationName":"item"
      }
    },
    "ReservedInstancesId":{
      "type":"structure",
      "members":{
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance.</p>",
          "locationName":"reservedInstancesId"
        }
      },
      "documentation":"<p>Describes the ID of a Reserved Instance.</p>"
    },
    "ReservedInstancesIdStringList":{
      "type":"list",
      "member":{
        "shape":"ReservationId",
        "locationName":"ReservedInstancesId"
      }
    },
    "ReservedInstancesList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstances",
        "locationName":"item"
      }
    },
    "ReservedInstancesListing":{
      "type":"structure",
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive key supplied by the client to ensure that the request is idempotent. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "CreateDate":{
          "shape":"DateTime",
          "documentation":"<p>The time the listing was created.</p>",
          "locationName":"createDate"
        },
        "InstanceCounts":{
          "shape":"InstanceCountList",
          "documentation":"<p>The number of instances in this state.</p>",
          "locationName":"instanceCounts"
        },
        "PriceSchedules":{
          "shape":"PriceScheduleList",
          "documentation":"<p>The price of the Reserved Instance listing.</p>",
          "locationName":"priceSchedules"
        },
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance.</p>",
          "locationName":"reservedInstancesId"
        },
        "ReservedInstancesListingId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance listing.</p>",
          "locationName":"reservedInstancesListingId"
        },
        "Status":{
          "shape":"ListingStatus",
          "documentation":"<p>The status of the Reserved Instance listing.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The reason for the current status of the Reserved Instance listing. The response can be blank.</p>",
          "locationName":"statusMessage"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the resource.</p>",
          "locationName":"tagSet"
        },
        "UpdateDate":{
          "shape":"DateTime",
          "documentation":"<p>The last modified timestamp of the listing.</p>",
          "locationName":"updateDate"
        }
      },
      "documentation":"<p>Describes a Reserved Instance listing.</p>"
    },
    "ReservedInstancesListingId":{"type":"string"},
    "ReservedInstancesListingList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesListing",
        "locationName":"item"
      }
    },
    "ReservedInstancesModification":{
      "type":"structure",
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive key supplied by the client to ensure that the request is idempotent. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "CreateDate":{
          "shape":"DateTime",
          "documentation":"<p>The time when the modification request was created.</p>",
          "locationName":"createDate"
        },
        "EffectiveDate":{
          "shape":"DateTime",
          "documentation":"<p>The time for the modification to become effective.</p>",
          "locationName":"effectiveDate"
        },
        "ModificationResults":{
          "shape":"ReservedInstancesModificationResultList",
          "documentation":"<p>Contains target configurations along with their corresponding new Reserved Instance IDs.</p>",
          "locationName":"modificationResultSet"
        },
        "ReservedInstancesIds":{
          "shape":"ReservedIntancesIds",
          "documentation":"<p>The IDs of one or more Reserved Instances.</p>",
          "locationName":"reservedInstancesSet"
        },
        "ReservedInstancesModificationId":{
          "shape":"String",
          "documentation":"<p>A unique ID for the Reserved Instance modification.</p>",
          "locationName":"reservedInstancesModificationId"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The status of the Reserved Instances modification request.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The reason for the status.</p>",
          "locationName":"statusMessage"
        },
        "UpdateDate":{
          "shape":"DateTime",
          "documentation":"<p>The time when the modification request was last updated.</p>",
          "locationName":"updateDate"
        }
      },
      "documentation":"<p>Describes a Reserved Instance modification.</p>"
    },
    "ReservedInstancesModificationId":{"type":"string"},
    "ReservedInstancesModificationIdStringList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesModificationId",
        "locationName":"ReservedInstancesModificationId"
      }
    },
    "ReservedInstancesModificationList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesModification",
        "locationName":"item"
      }
    },
    "ReservedInstancesModificationResult":{
      "type":"structure",
      "members":{
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The ID for the Reserved Instances that were created as part of the modification request. This field is only available when the modification is fulfilled.</p>",
          "locationName":"reservedInstancesId"
        },
        "TargetConfiguration":{
          "shape":"ReservedInstancesConfiguration",
          "documentation":"<p>The target Reserved Instances configurations supplied as part of the modification request.</p>",
          "locationName":"targetConfiguration"
        }
      },
      "documentation":"<p>Describes the modification request/s.</p>"
    },
    "ReservedInstancesModificationResultList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesModificationResult",
        "locationName":"item"
      }
    },
    "ReservedInstancesOffering":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the Reserved Instance can be used.</p>",
          "locationName":"availabilityZone"
        },
        "Duration":{
          "shape":"Long",
          "documentation":"<p>The duration of the Reserved Instance, in seconds.</p>",
          "locationName":"duration"
        },
        "FixedPrice":{
          "shape":"Float",
          "documentation":"<p>The purchase price of the Reserved Instance.</p>",
          "locationName":"fixedPrice"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type on which the Reserved Instance can be used.</p>",
          "locationName":"instanceType"
        },
        "ProductDescription":{
          "shape":"RIProductDescription",
          "documentation":"<p>The Reserved Instance product platform description.</p>",
          "locationName":"productDescription"
        },
        "ReservedInstancesOfferingId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance offering. This is the offering ID used in <a>GetReservedInstancesExchangeQuote</a> to confirm that an exchange can be made.</p>",
          "locationName":"reservedInstancesOfferingId"
        },
        "UsagePrice":{
          "shape":"Float",
          "documentation":"<p>The usage price of the Reserved Instance, per hour.</p>",
          "locationName":"usagePrice"
        },
        "CurrencyCode":{
          "shape":"CurrencyCodeValues",
          "documentation":"<p>The currency of the Reserved Instance offering you are purchasing. It's specified using ISO 4217 standard currency codes. At this time, the only supported currency is <code>USD</code>.</p>",
          "locationName":"currencyCode"
        },
        "InstanceTenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instance.</p>",
          "locationName":"instanceTenancy"
        },
        "Marketplace":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the offering is available through the Reserved Instance Marketplace (resale) or Amazon Web Services. If it's a Reserved Instance Marketplace offering, this is <code>true</code>.</p>",
          "locationName":"marketplace"
        },
        "OfferingClass":{
          "shape":"OfferingClassType",
          "documentation":"<p>If <code>convertible</code> it can be exchanged for Reserved Instances of the same or higher monetary value, with different configurations. If <code>standard</code>, it is not possible to perform an exchange.</p>",
          "locationName":"offeringClass"
        },
        "OfferingType":{
          "shape":"OfferingTypeValues",
          "documentation":"<p>The Reserved Instance offering type.</p>",
          "locationName":"offeringType"
        },
        "PricingDetails":{
          "shape":"PricingDetailsList",
          "documentation":"<p>The pricing details of the Reserved Instance offering.</p>",
          "locationName":"pricingDetailsSet"
        },
        "RecurringCharges":{
          "shape":"RecurringChargesList",
          "documentation":"<p>The recurring charge tag assigned to the resource.</p>",
          "locationName":"recurringCharges"
        },
        "Scope":{
          "shape":"scope",
          "documentation":"<p>Whether the Reserved Instance is applied to instances in a Region or an Availability Zone.</p>",
          "locationName":"scope"
        }
      },
      "documentation":"<p>Describes a Reserved Instance offering.</p>"
    },
    "ReservedInstancesOfferingId":{"type":"string"},
    "ReservedInstancesOfferingIdStringList":{
      "type":"list",
      "member":{"shape":"ReservedInstancesOfferingId"}
    },
    "ReservedInstancesOfferingList":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesOffering",
        "locationName":"item"
      }
    },
    "ReservedIntancesIds":{
      "type":"list",
      "member":{
        "shape":"ReservedInstancesId",
        "locationName":"item"
      }
    },
    "ResetAddressAttributeRequest":{
      "type":"structure",
      "required":[
        "AllocationId",
        "Attribute"
      ],
      "members":{
        "AllocationId":{
          "shape":"AllocationId",
          "documentation":"<p>[EC2-VPC] The allocation ID.</p>"
        },
        "Attribute":{
          "shape":"AddressAttributeName",
          "documentation":"<p>The attribute of the IP address.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ResetAddressAttributeResult":{
      "type":"structure",
      "members":{
        "Address":{
          "shape":"AddressAttribute",
          "documentation":"<p>Information about the IP address.</p>",
          "locationName":"address"
        }
      }
    },
    "ResetEbsDefaultKmsKeyIdRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "ResetEbsDefaultKmsKeyIdResult":{
      "type":"structure",
      "members":{
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the default KMS key for EBS encryption by default.</p>",
          "locationName":"kmsKeyId"
        }
      }
    },
    "ResetFpgaImageAttributeName":{
      "type":"string",
      "enum":["loadPermission"]
    },
    "ResetFpgaImageAttributeRequest":{
      "type":"structure",
      "required":["FpgaImageId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "FpgaImageId":{
          "shape":"FpgaImageId",
          "documentation":"<p>The ID of the AFI.</p>"
        },
        "Attribute":{
          "shape":"ResetFpgaImageAttributeName",
          "documentation":"<p>The attribute.</p>"
        }
      }
    },
    "ResetFpgaImageAttributeResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Is <code>true</code> if the request succeeds, and an error otherwise.</p>",
          "locationName":"return"
        }
      }
    },
    "ResetImageAttributeName":{
      "type":"string",
      "enum":["launchPermission"]
    },
    "ResetImageAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "ImageId"
      ],
      "members":{
        "Attribute":{
          "shape":"ResetImageAttributeName",
          "documentation":"<p>The attribute to reset (currently you can only reset the launch permission attribute).</p>"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      },
      "documentation":"<p>Contains the parameters for ResetImageAttribute.</p>"
    },
    "ResetInstanceAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "InstanceId"
      ],
      "members":{
        "Attribute":{
          "shape":"InstanceAttributeName",
          "documentation":"<p>The attribute to reset.</p> <important> <p>You can only reset the following attributes: <code>kernel</code> | <code>ramdisk</code> | <code>sourceDestCheck</code>.</p> </important>",
          "locationName":"attribute"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        }
      }
    },
    "ResetNetworkInterfaceAttributeRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "SourceDestCheck":{
          "shape":"String",
          "documentation":"<p>The source/destination checking attribute. Resets the value to <code>true</code>.</p>",
          "locationName":"sourceDestCheck"
        }
      },
      "documentation":"<p>Contains the parameters for ResetNetworkInterfaceAttribute.</p>"
    },
    "ResetSnapshotAttributeRequest":{
      "type":"structure",
      "required":[
        "Attribute",
        "SnapshotId"
      ],
      "members":{
        "Attribute":{
          "shape":"SnapshotAttributeName",
          "documentation":"<p>The attribute to reset. Currently, only the attribute for permission to create volumes can be reset.</p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "ResourceArn":{
      "type":"string",
      "max":1283,
      "min":1
    },
    "ResourceIdList":{
      "type":"list",
      "member":{"shape":"TaggableResourceId"}
    },
    "ResourceList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "ResourceStatement":{
      "type":"structure",
      "members":{
        "Resources":{
          "shape":"ValueStringList",
          "documentation":"<p>The resources.</p>",
          "locationName":"resourceSet"
        },
        "ResourceTypes":{
          "shape":"ValueStringList",
          "documentation":"<p>The resource types.</p>",
          "locationName":"resourceTypeSet"
        }
      },
      "documentation":"<p>Describes a resource statement.</p>"
    },
    "ResourceStatementRequest":{
      "type":"structure",
      "members":{
        "Resources":{
          "shape":"ValueStringList",
          "documentation":"<p>The resources.</p>",
          "locationName":"Resource"
        },
        "ResourceTypes":{
          "shape":"ValueStringList",
          "documentation":"<p>The resource types.</p>",
          "locationName":"ResourceType"
        }
      },
      "documentation":"<p>Describes a resource statement.</p>"
    },
    "ResourceType":{
      "type":"string",
      "enum":[
        "capacity-reservation",
        "client-vpn-endpoint",
        "customer-gateway",
        "carrier-gateway",
        "coip-pool",
        "dedicated-host",
        "dhcp-options",
        "egress-only-internet-gateway",
        "elastic-ip",
        "elastic-gpu",
        "export-image-task",
        "export-instance-task",
        "fleet",
        "fpga-image",
        "host-reservation",
        "image",
        "import-image-task",
        "import-snapshot-task",
        "instance",
        "instance-event-window",
        "internet-gateway",
        "ipam",
        "ipam-pool",
        "ipam-scope",
        "ipv4pool-ec2",
        "ipv6pool-ec2",
        "key-pair",
        "launch-template",
        "local-gateway",
        "local-gateway-route-table",
        "local-gateway-virtual-interface",
        "local-gateway-virtual-interface-group",
        "local-gateway-route-table-vpc-association",
        "local-gateway-route-table-virtual-interface-group-association",
        "natgateway",
        "network-acl",
        "network-interface",
        "network-insights-analysis",
        "network-insights-path",
        "network-insights-access-scope",
        "network-insights-access-scope-analysis",
        "placement-group",
        "prefix-list",
        "replace-root-volume-task",
        "reserved-instances",
        "route-table",
        "security-group",
        "security-group-rule",
        "snapshot",
        "spot-fleet-request",
        "spot-instances-request",
        "subnet",
        "subnet-cidr-reservation",
        "traffic-mirror-filter",
        "traffic-mirror-session",
        "traffic-mirror-target",
        "transit-gateway",
        "transit-gateway-attachment",
        "transit-gateway-connect-peer",
        "transit-gateway-multicast-domain",
        "transit-gateway-policy-table",
        "transit-gateway-route-table",
        "transit-gateway-route-table-announcement",
        "volume",
        "vpc",
        "vpc-endpoint",
        "vpc-endpoint-connection",
        "vpc-endpoint-service",
        "vpc-endpoint-service-permission",
        "vpc-peering-connection",
        "vpn-connection",
        "vpn-gateway",
        "vpc-flow-log",
        "capacity-reservation-fleet",
        "traffic-mirror-filter-rule",
        "vpc-endpoint-connection-device-type",
        "verified-access-instance",
        "verified-access-group",
        "verified-access-endpoint",
        "verified-access-policy",
        "verified-access-trust-provider",
        "vpn-connection-device-type",
        "vpc-block-public-access-exclusion",
        "ipam-resource-discovery",
        "ipam-resource-discovery-association"
      ]
    },
    "ResponseError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"LaunchTemplateErrorCode",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the error that's returned when you cannot delete a launch template version.</p>"
    },
    "ResponseHostIdList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "ResponseHostIdSet":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "ResponseLaunchTemplateData":{
      "type":"structure",
      "members":{
        "KernelId":{
          "shape":"String",
          "documentation":"<p>The ID of the kernel, if applicable.</p>",
          "locationName":"kernelId"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is optimized for Amazon EBS I/O. </p>",
          "locationName":"ebsOptimized"
        },
        "IamInstanceProfile":{
          "shape":"LaunchTemplateIamInstanceProfileSpecification",
          "documentation":"<p>The IAM instance profile.</p>",
          "locationName":"iamInstanceProfile"
        },
        "BlockDeviceMappings":{
          "shape":"LaunchTemplateBlockDeviceMappingList",
          "documentation":"<p>The block device mappings.</p>",
          "locationName":"blockDeviceMappingSet"
        },
        "NetworkInterfaces":{
          "shape":"LaunchTemplateInstanceNetworkInterfaceSpecificationList",
          "documentation":"<p>The network interfaces.</p>",
          "locationName":"networkInterfaceSet"
        },
        "ImageId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI or a Systems Manager parameter. The Systems Manager parameter will resolve to the ID of the AMI at instance launch.</p> <p>The value depends on what you specified in the request. The possible values are:</p> <ul> <li> <p>If an AMI ID was specified in the request, then this is the AMI ID.</p> </li> <li> <p>If a Systems Manager parameter was specified in the request, and <code>ResolveAlias</code> was configured as <code>true</code>, then this is the AMI ID that the parameter is mapped to in the Parameter Store.</p> </li> <li> <p>If a Systems Manager parameter was specified in the request, and <code>ResolveAlias</code> was configured as <code>false</code>, then this is the parameter value.</p> </li> </ul> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#use-an-ssm-parameter-instead-of-an-ami-id\">Use a Systems Manager parameter instead of an AMI ID</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"imageId"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "KeyName":{
          "shape":"String",
          "documentation":"<p>The name of the key pair.</p>",
          "locationName":"keyName"
        },
        "Monitoring":{
          "shape":"LaunchTemplatesMonitoring",
          "documentation":"<p>The monitoring for the instance.</p>",
          "locationName":"monitoring"
        },
        "Placement":{
          "shape":"LaunchTemplatePlacement",
          "documentation":"<p>The placement of the instance.</p>",
          "locationName":"placement"
        },
        "RamDiskId":{
          "shape":"String",
          "documentation":"<p>The ID of the RAM disk, if applicable.</p>",
          "locationName":"ramDiskId"
        },
        "DisableApiTermination":{
          "shape":"Boolean",
          "documentation":"<p>If set to <code>true</code>, indicates that the instance cannot be terminated using the Amazon EC2 console, command line tool, or API.</p>",
          "locationName":"disableApiTermination"
        },
        "InstanceInitiatedShutdownBehavior":{
          "shape":"ShutdownBehavior",
          "documentation":"<p>Indicates whether an instance stops or terminates when you initiate shutdown from the instance (using the operating system command for system shutdown).</p>",
          "locationName":"instanceInitiatedShutdownBehavior"
        },
        "UserData":{
          "shape":"SensitiveUserData",
          "documentation":"<p>The user data for the instance. </p>",
          "locationName":"userData"
        },
        "TagSpecifications":{
          "shape":"LaunchTemplateTagSpecificationList",
          "documentation":"<p>The tags that are applied to the resources that are created during instance launch.</p>",
          "locationName":"tagSpecificationSet"
        },
        "ElasticGpuSpecifications":{
          "shape":"ElasticGpuSpecificationResponseList",
          "documentation":"<p>The elastic GPU specification.</p>",
          "locationName":"elasticGpuSpecificationSet"
        },
        "ElasticInferenceAccelerators":{
          "shape":"LaunchTemplateElasticInferenceAcceleratorResponseList",
          "documentation":"<p> The elastic inference accelerator for the instance. </p>",
          "locationName":"elasticInferenceAcceleratorSet"
        },
        "SecurityGroupIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The security group IDs.</p>",
          "locationName":"securityGroupIdSet"
        },
        "SecurityGroups":{
          "shape":"ValueStringList",
          "documentation":"<p>The security group names.</p>",
          "locationName":"securityGroupSet"
        },
        "InstanceMarketOptions":{
          "shape":"LaunchTemplateInstanceMarketOptions",
          "documentation":"<p>The market (purchasing) option for the instances.</p>",
          "locationName":"instanceMarketOptions"
        },
        "CreditSpecification":{
          "shape":"CreditSpecification",
          "documentation":"<p>The credit option for CPU usage of the instance.</p>",
          "locationName":"creditSpecification"
        },
        "CpuOptions":{
          "shape":"LaunchTemplateCpuOptions",
          "documentation":"<p>The CPU options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html\">Optimizing CPU options</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"cpuOptions"
        },
        "CapacityReservationSpecification":{
          "shape":"LaunchTemplateCapacityReservationSpecificationResponse",
          "documentation":"<p>Information about the Capacity Reservation targeting option.</p>",
          "locationName":"capacityReservationSpecification"
        },
        "LicenseSpecifications":{
          "shape":"LaunchTemplateLicenseList",
          "documentation":"<p>The license configurations.</p>",
          "locationName":"licenseSet"
        },
        "HibernationOptions":{
          "shape":"LaunchTemplateHibernationOptions",
          "documentation":"<p>Indicates whether an instance is configured for hibernation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"hibernationOptions"
        },
        "MetadataOptions":{
          "shape":"LaunchTemplateInstanceMetadataOptions",
          "documentation":"<p>The metadata options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">Instance metadata and user data</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"metadataOptions"
        },
        "EnclaveOptions":{
          "shape":"LaunchTemplateEnclaveOptions",
          "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves.</p>",
          "locationName":"enclaveOptions"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirements",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with these attributes.</p> <p>If you specify <code>InstanceRequirements</code>, you can't specify <code>InstanceTypes</code>.</p>",
          "locationName":"instanceRequirements"
        },
        "PrivateDnsNameOptions":{
          "shape":"LaunchTemplatePrivateDnsNameOptions",
          "documentation":"<p>The options for the instance hostname.</p>",
          "locationName":"privateDnsNameOptions"
        },
        "MaintenanceOptions":{
          "shape":"LaunchTemplateInstanceMaintenanceOptions",
          "documentation":"<p>The maintenance options for your instance.</p>",
          "locationName":"maintenanceOptions"
        },
        "DisableApiStop":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is enabled for stop protection. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Stop_Start.html#Using_StopProtection\">Stop protection</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"disableApiStop"
        }
      },
      "documentation":"<p>The information for a launch template. </p>"
    },
    "RestorableByStringList":{
      "type":"list",
      "member":{"shape":"String"}
    },
    "RestoreAddressToClassicRequest":{
      "type":"structure",
      "required":["PublicIp"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address.</p>",
          "locationName":"publicIp"
        }
      }
    },
    "RestoreAddressToClassicResult":{
      "type":"structure",
      "members":{
        "PublicIp":{
          "shape":"String",
          "documentation":"<p>The Elastic IP address.</p>",
          "locationName":"publicIp"
        },
        "Status":{
          "shape":"Status",
          "documentation":"<p>The move status for the IP address.</p>",
          "locationName":"status"
        }
      }
    },
    "RestoreImageFromRecycleBinRequest":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI to restore.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RestoreImageFromRecycleBinResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "RestoreManagedPrefixListVersionRequest":{
      "type":"structure",
      "required":[
        "PrefixListId",
        "PreviousVersion",
        "CurrentVersion"
      ],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "PreviousVersion":{
          "shape":"Long",
          "documentation":"<p>The version to restore.</p>"
        },
        "CurrentVersion":{
          "shape":"Long",
          "documentation":"<p>The current version number for the prefix list.</p>"
        }
      }
    },
    "RestoreManagedPrefixListVersionResult":{
      "type":"structure",
      "members":{
        "PrefixList":{
          "shape":"ManagedPrefixList",
          "documentation":"<p>Information about the prefix list.</p>",
          "locationName":"prefixList"
        }
      }
    },
    "RestoreSnapshotFromRecycleBinRequest":{
      "type":"structure",
      "required":["SnapshotId"],
      "members":{
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot to restore.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RestoreSnapshotFromRecycleBinResult":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Outpost on which the snapshot is stored. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html\">Amazon EBS local snapshots on Outposts</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"outpostArn"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the snapshot.</p>",
          "locationName":"description"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the snapshot is encrypted.</p>",
          "locationName":"encrypted"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the EBS snapshot.</p>",
          "locationName":"ownerId"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The progress of the snapshot, as a percentage.</p>",
          "locationName":"progress"
        },
        "StartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time stamp when the snapshot was initiated.</p>",
          "locationName":"startTime"
        },
        "State":{
          "shape":"SnapshotState",
          "documentation":"<p>The state of the snapshot.</p>",
          "locationName":"status"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume that was used to create the snapshot.</p>",
          "locationName":"volumeId"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiB.</p>",
          "locationName":"volumeSize"
        }
      }
    },
    "RestoreSnapshotTierRequest":{
      "type":"structure",
      "required":["SnapshotId"],
      "members":{
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot to restore.</p>"
        },
        "TemporaryRestoreDays":{
          "shape":"RestoreSnapshotTierRequestTemporaryRestoreDays",
          "documentation":"<p>Specifies the number of days for which to temporarily restore an archived snapshot. Required for temporary restores only. The snapshot will be automatically re-archived after this period.</p> <p>To temporarily restore an archived snapshot, specify the number of days and omit the <b>PermanentRestore</b> parameter or set it to <code>false</code>.</p>"
        },
        "PermanentRestore":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to permanently restore an archived snapshot. To permanently restore an archived snapshot, specify <code>true</code> and omit the <b>RestoreSnapshotTierRequest$TemporaryRestoreDays</b> parameter.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RestoreSnapshotTierRequestTemporaryRestoreDays":{"type":"integer"},
    "RestoreSnapshotTierResult":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "RestoreStartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the snapshot restore process started.</p>",
          "locationName":"restoreStartTime"
        },
        "RestoreDuration":{
          "shape":"Integer",
          "documentation":"<p>For temporary restores only. The number of days for which the archived snapshot is temporarily restored.</p>",
          "locationName":"restoreDuration"
        },
        "IsPermanentRestore":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the snapshot is permanently restored. <code>true</code> indicates a permanent restore. <code>false</code> indicates a temporary restore.</p>",
          "locationName":"isPermanentRestore"
        }
      }
    },
    "ResultRange":{
      "type":"integer",
      "max":500,
      "min":20
    },
    "RevokeClientVpnIngressRequest":{
      "type":"structure",
      "required":[
        "ClientVpnEndpointId",
        "TargetNetworkCidr"
      ],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint with which the authorization rule is associated.</p>"
        },
        "TargetNetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 address range, in CIDR notation, of the network for which access is being removed.</p>"
        },
        "AccessGroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the Active Directory group for which to revoke access. </p>"
        },
        "RevokeAllGroups":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether access should be revoked for all clients.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "RevokeClientVpnIngressResult":{
      "type":"structure",
      "members":{
        "Status":{
          "shape":"ClientVpnAuthorizationRuleStatus",
          "documentation":"<p>The current state of the authorization rule.</p>",
          "locationName":"status"
        }
      }
    },
    "RevokeSecurityGroupEgressRequest":{
      "type":"structure",
      "required":["GroupId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The sets of IP permissions. You can't specify a destination security group and a CIDR IP address range in the same set of permissions.</p>",
          "locationName":"ipPermissions"
        },
        "SecurityGroupRuleIds":{
          "shape":"SecurityGroupRuleIdList",
          "documentation":"<p>The IDs of the security group rules.</p>",
          "locationName":"SecurityGroupRuleId"
        },
        "CidrIp":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the CIDR.</p>",
          "locationName":"cidrIp"
        },
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the port.</p>",
          "locationName":"fromPort"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the protocol name or number.</p>",
          "locationName":"ipProtocol"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify the port.</p>",
          "locationName":"toPort"
        },
        "SourceSecurityGroupName":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify a destination security group.</p>",
          "locationName":"sourceSecurityGroupName"
        },
        "SourceSecurityGroupOwnerId":{
          "shape":"String",
          "documentation":"<p>Not supported. Use a set of IP permissions to specify a destination security group.</p>",
          "locationName":"sourceSecurityGroupOwnerId"
        }
      }
    },
    "RevokeSecurityGroupEgressResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        },
        "UnknownIpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The outbound rules that were unknown to the service. In some cases, <code>unknownIpPermissionSet</code> might be in a different format from the request parameter. </p>",
          "locationName":"unknownIpPermissionSet"
        }
      }
    },
    "RevokeSecurityGroupIngressRequest":{
      "type":"structure",
      "members":{
        "CidrIp":{
          "shape":"String",
          "documentation":"<p>The CIDR IP address range. You can't specify this parameter when specifying a source security group.</p>"
        },
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the start of the port range. If the protocol is ICMP, this is the type number. A value of -1 indicates all ICMP types.</p>"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "GroupName":{
          "shape":"SecurityGroupName",
          "documentation":"<p>[EC2-Classic, default VPC] The name of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The sets of IP permissions. You can't specify a source security group and a CIDR IP address range in the same set of permissions.</p>"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>The IP protocol name (<code>tcp</code>, <code>udp</code>, <code>icmp</code>) or number (see <a href=\"http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers</a>). Use <code>-1</code> to specify all.</p>"
        },
        "SourceSecurityGroupName":{
          "shape":"String",
          "documentation":"<p>[EC2-Classic, default VPC] The name of the source security group. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the start of the port range, the IP protocol, and the end of the port range. For EC2-VPC, the source security group must be in the same VPC. To revoke a specific rule for an IP protocol and port range, use a set of IP permissions instead.</p>"
        },
        "SourceSecurityGroupOwnerId":{
          "shape":"String",
          "documentation":"<p>[EC2-Classic] The Amazon Web Services account ID of the source security group, if the source security group is in a different account. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the IP protocol, the start of the port range, and the end of the port range. To revoke a specific rule for an IP protocol and port range, use a set of IP permissions instead.</p>"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the end of the port range. If the protocol is ICMP, this is the code. A value of -1 indicates all ICMP codes.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "SecurityGroupRuleIds":{
          "shape":"SecurityGroupRuleIdList",
          "documentation":"<p>The IDs of the security group rules.</p>",
          "locationName":"SecurityGroupRuleId"
        }
      }
    },
    "RevokeSecurityGroupIngressResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        },
        "UnknownIpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The inbound rules that were unknown to the service. In some cases, <code>unknownIpPermissionSet</code> might be in a different format from the request parameter. </p>",
          "locationName":"unknownIpPermissionSet"
        }
      }
    },
    "RoleId":{"type":"string"},
    "RootDeviceType":{
      "type":"string",
      "enum":[
        "ebs",
        "instance-store"
      ]
    },
    "RootDeviceTypeList":{
      "type":"list",
      "member":{
        "shape":"RootDeviceType",
        "locationName":"item"
      }
    },
    "Route":{
      "type":"structure",
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR block used for the destination match.</p>",
          "locationName":"destinationCidrBlock"
        },
        "DestinationIpv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block used for the destination match.</p>",
          "locationName":"destinationIpv6CidrBlock"
        },
        "DestinationPrefixListId":{
          "shape":"String",
          "documentation":"<p>The prefix of the Amazon Web Service.</p>",
          "locationName":"destinationPrefixListId"
        },
        "EgressOnlyInternetGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the egress-only internet gateway.</p>",
          "locationName":"egressOnlyInternetGatewayId"
        },
        "GatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of a gateway attached to your VPC.</p>",
          "locationName":"gatewayId"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of a NAT instance in your VPC.</p>",
          "locationName":"instanceId"
        },
        "InstanceOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of Amazon Web Services account that owns the instance.</p>",
          "locationName":"instanceOwnerId"
        },
        "NatGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of a NAT gateway.</p>",
          "locationName":"natGatewayId"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of a transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "LocalGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the local gateway.</p>",
          "locationName":"localGatewayId"
        },
        "CarrierGatewayId":{
          "shape":"CarrierGatewayId",
          "documentation":"<p>The ID of the carrier gateway.</p>",
          "locationName":"carrierGatewayId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "Origin":{
          "shape":"RouteOrigin",
          "documentation":"<p>Describes how the route was created.</p> <ul> <li> <p> <code>CreateRouteTable</code> - The route was automatically created when the route table was created.</p> </li> <li> <p> <code>CreateRoute</code> - The route was manually added to the route table.</p> </li> <li> <p> <code>EnableVgwRoutePropagation</code> - The route was propagated by route propagation.</p> </li> </ul>",
          "locationName":"origin"
        },
        "State":{
          "shape":"RouteState",
          "documentation":"<p>The state of the route. The <code>blackhole</code> state indicates that the route's target isn't available (for example, the specified gateway isn't attached to the VPC, or the specified NAT instance has been terminated).</p>",
          "locationName":"state"
        },
        "VpcPeeringConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of a VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        },
        "CoreNetworkArn":{
          "shape":"CoreNetworkArn",
          "documentation":"<p>The Amazon Resource Name (ARN) of the core network.</p>",
          "locationName":"coreNetworkArn"
        }
      },
      "documentation":"<p>Describes a route in a route table.</p>"
    },
    "RouteGatewayId":{"type":"string"},
    "RouteList":{
      "type":"list",
      "member":{
        "shape":"Route",
        "locationName":"item"
      }
    },
    "RouteOrigin":{
      "type":"string",
      "enum":[
        "CreateRouteTable",
        "CreateRoute",
        "EnableVgwRoutePropagation"
      ]
    },
    "RouteState":{
      "type":"string",
      "enum":[
        "active",
        "blackhole"
      ]
    },
    "RouteTable":{
      "type":"structure",
      "members":{
        "Associations":{
          "shape":"RouteTableAssociationList",
          "documentation":"<p>The associations between the route table and one or more subnets or a gateway.</p>",
          "locationName":"associationSet"
        },
        "PropagatingVgws":{
          "shape":"PropagatingVgwList",
          "documentation":"<p>Any virtual private gateway (VGW) propagating routes.</p>",
          "locationName":"propagatingVgwSet"
        },
        "RouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the route table.</p>",
          "locationName":"routeTableId"
        },
        "Routes":{
          "shape":"RouteList",
          "documentation":"<p>The routes in the route table.</p>",
          "locationName":"routeSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the route table.</p>",
          "locationName":"tagSet"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the route table.</p>",
          "locationName":"ownerId"
        }
      },
      "documentation":"<p>Describes a route table.</p>"
    },
    "RouteTableAssociation":{
      "type":"structure",
      "members":{
        "Main":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is the main route table.</p>",
          "locationName":"main"
        },
        "RouteTableAssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"routeTableAssociationId"
        },
        "RouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the route table.</p>",
          "locationName":"routeTableId"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet. A subnet ID is not returned for an implicit association.</p>",
          "locationName":"subnetId"
        },
        "GatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the internet gateway or virtual private gateway.</p>",
          "locationName":"gatewayId"
        },
        "AssociationState":{
          "shape":"RouteTableAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"associationState"
        }
      },
      "documentation":"<p>Describes an association between a route table and a subnet or gateway.</p>"
    },
    "RouteTableAssociationId":{"type":"string"},
    "RouteTableAssociationList":{
      "type":"list",
      "member":{
        "shape":"RouteTableAssociation",
        "locationName":"item"
      }
    },
    "RouteTableAssociationState":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"RouteTableAssociationStateCode",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>The status message, if applicable.</p>",
          "locationName":"statusMessage"
        }
      },
      "documentation":"<p>Describes the state of an association between a route table and a subnet or gateway.</p>"
    },
    "RouteTableAssociationStateCode":{
      "type":"string",
      "enum":[
        "associating",
        "associated",
        "disassociating",
        "disassociated",
        "failed"
      ]
    },
    "RouteTableId":{"type":"string"},
    "RouteTableIdStringList":{
      "type":"list",
      "member":{
        "shape":"RouteTableId",
        "locationName":"item"
      }
    },
    "RouteTableList":{
      "type":"list",
      "member":{
        "shape":"RouteTable",
        "locationName":"item"
      }
    },
    "RuleAction":{
      "type":"string",
      "enum":[
        "allow",
        "deny"
      ]
    },
    "RunInstancesMonitoringEnabled":{
      "type":"structure",
      "required":["Enabled"],
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether detailed monitoring is enabled. Otherwise, basic monitoring is enabled.</p>",
          "locationName":"enabled"
        }
      },
      "documentation":"<p>Describes the monitoring of an instance.</p>"
    },
    "RunInstancesRequest":{
      "type":"structure",
      "required":[
        "MaxCount",
        "MinCount"
      ],
      "members":{
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingRequestList",
          "documentation":"<p>The block device mapping, which defines the EBS volumes and instance store volumes to attach to the instance at launch. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/block-device-mapping-concepts.html\">Block device mappings</a> in the <i>Amazon EC2 User Guide</i>.</p>",
          "locationName":"BlockDeviceMapping"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI. An AMI ID is required to launch an instance and must be specified here or in a launch template.</p>"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html\">Instance types</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: <code>m1.small</code> </p>"
        },
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>[EC2-VPC] The number of IPv6 addresses to associate with the primary network interface. Amazon EC2 chooses the IPv6 addresses from the range of your subnet. You cannot specify this option and the option to assign specific IPv6 addresses in the same request. You can specify this option if you've specified a minimum number of instances to launch.</p> <p>You cannot specify this option and the network interfaces option in the same request.</p>"
        },
        "Ipv6Addresses":{
          "shape":"InstanceIpv6AddressList",
          "documentation":"<p>[EC2-VPC] The IPv6 addresses from the range of the subnet to associate with the primary network interface. You cannot specify this option and the option to assign a number of IPv6 addresses in the same request. You cannot specify this option if you've specified a minimum number of instances to launch.</p> <p>You cannot specify this option and the network interfaces option in the same request.</p>",
          "locationName":"Ipv6Address"
        },
        "KernelId":{
          "shape":"KernelId",
          "documentation":"<p>The ID of the kernel.</p> <important> <p>We recommend that you use PV-GRUB instead of kernels and RAM disks. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/UserProvidedkernels.html\">PV-GRUB</a> in the <i>Amazon EC2 User Guide</i>.</p> </important>"
        },
        "KeyName":{
          "shape":"KeyPairName",
          "documentation":"<p>The name of the key pair. You can create a key pair using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateKeyPair.html\">CreateKeyPair</a> or <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ImportKeyPair.html\">ImportKeyPair</a>.</p> <important> <p>If you do not specify a key pair, you can't connect to the instance unless you choose an AMI that is configured to allow users another way to log in.</p> </important>"
        },
        "MaxCount":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of instances to launch. If you specify more instances than Amazon EC2 can launch in the target Availability Zone, Amazon EC2 launches the largest possible number of instances above <code>MinCount</code>.</p> <p>Constraints: Between 1 and the maximum number you're allowed for the specified instance type. For more information about the default limits, and how to request an increase, see <a href=\"http://aws.amazon.com/ec2/faqs/#How_many_instances_can_I_run_in_Amazon_EC2\">How many instances can I run in Amazon EC2</a> in the Amazon EC2 FAQ.</p>"
        },
        "MinCount":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of instances to launch. If you specify a minimum that is more instances than Amazon EC2 can launch in the target Availability Zone, Amazon EC2 launches no instances.</p> <p>Constraints: Between 1 and the maximum number you're allowed for the specified instance type. For more information about the default limits, and how to request an increase, see <a href=\"http://aws.amazon.com/ec2/faqs/#How_many_instances_can_I_run_in_Amazon_EC2\">How many instances can I run in Amazon EC2</a> in the Amazon EC2 General FAQ.</p>"
        },
        "Monitoring":{
          "shape":"RunInstancesMonitoringEnabled",
          "documentation":"<p>Specifies whether detailed monitoring is enabled for the instance.</p>"
        },
        "Placement":{
          "shape":"Placement",
          "documentation":"<p>The placement for the instance.</p>"
        },
        "RamdiskId":{
          "shape":"RamdiskId",
          "documentation":"<p>The ID of the RAM disk to select. Some kernels require additional drivers at launch. Check the kernel requirements for information about whether you need to specify a RAM disk. To find kernel requirements, go to the Amazon Web Services Resource Center and search for the kernel ID.</p> <important> <p>We recommend that you use PV-GRUB instead of kernels and RAM disks. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/UserProvidedkernels.html\">PV-GRUB</a> in the <i>Amazon EC2 User Guide</i>.</p> </important>"
        },
        "SecurityGroupIds":{
          "shape":"SecurityGroupIdStringList",
          "documentation":"<p>The IDs of the security groups. You can create a security group using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateSecurityGroup.html\">CreateSecurityGroup</a>.</p> <p>If you specify a network interface, you must specify any security groups as part of the network interface.</p>",
          "locationName":"SecurityGroupId"
        },
        "SecurityGroups":{
          "shape":"SecurityGroupStringList",
          "documentation":"<p>[EC2-Classic, default VPC] The names of the security groups.</p> <p>If you specify a network interface, you must specify any security groups as part of the network interface.</p> <p>Default: Amazon EC2 uses the default security group.</p>",
          "locationName":"SecurityGroup"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>[EC2-VPC] The ID of the subnet to launch the instance into.</p> <p>If you specify a network interface, you must specify any subnets as part of the network interface.</p>"
        },
        "UserData":{
          "shape":"RunInstancesUserData",
          "documentation":"<p>The user data script to make available to the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/user-data.html\">Run commands on your Linux instance at launch</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/ec2-windows-user-data.html\">Run commands on your Windows instance at launch</a>. If you are using a command line tool, base64-encoding is performed for you, and you can load the text from a file. Otherwise, you must provide base64-encoded text. User data is limited to 16 KB.</p>"
        },
        "AdditionalInfo":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>",
          "locationName":"additionalInfo"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier you provide to ensure the idempotency of the request. If you do not specify a client token, a randomly generated token is used for the request to ensure idempotency.</p> <p>For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p> <p>Constraints: Maximum 64 ASCII characters</p>",
          "idempotencyToken":true,
          "locationName":"clientToken"
        },
        "DisableApiTermination":{
          "shape":"Boolean",
          "documentation":"<p>If you set this parameter to <code>true</code>, you can't terminate the instance using the Amazon EC2 console, CLI, or API; otherwise, you can. To change this attribute after launch, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceAttribute.html\">ModifyInstanceAttribute</a>. Alternatively, if you set <code>InstanceInitiatedShutdownBehavior</code> to <code>terminate</code>, you can terminate the instance by running the shutdown command from the instance.</p> <p>Default: <code>false</code> </p>",
          "locationName":"disableApiTermination"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instance is optimized for Amazon EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal Amazon EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS-optimized instance.</p> <p>Default: <code>false</code> </p>",
          "locationName":"ebsOptimized"
        },
        "IamInstanceProfile":{
          "shape":"IamInstanceProfileSpecification",
          "documentation":"<p>The name or Amazon Resource Name (ARN) of an IAM instance profile.</p>",
          "locationName":"iamInstanceProfile"
        },
        "InstanceInitiatedShutdownBehavior":{
          "shape":"ShutdownBehavior",
          "documentation":"<p>Indicates whether an instance stops or terminates when you initiate shutdown from the instance (using the operating system command for system shutdown).</p> <p>Default: <code>stop</code> </p>",
          "locationName":"instanceInitiatedShutdownBehavior"
        },
        "NetworkInterfaces":{
          "shape":"InstanceNetworkInterfaceSpecificationList",
          "documentation":"<p>The network interfaces to associate with the instance. If you specify a network interface, you must specify any security groups and subnets as part of the network interface.</p>",
          "locationName":"networkInterface"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>[EC2-VPC] The primary IPv4 address. You must specify a value from the IPv4 address range of the subnet.</p> <p>Only one private IP address can be designated as primary. You can't specify this option if you've specified the option to designate a private IP address as the primary IP address in a network interface specification. You cannot specify this option if you're launching more than one instance in the request.</p> <p>You cannot specify this option and the network interfaces option in the same request.</p>",
          "locationName":"privateIpAddress"
        },
        "ElasticGpuSpecification":{
          "shape":"ElasticGpuSpecifications",
          "documentation":"<p>An elastic GPU to associate with the instance. An Elastic GPU is a GPU resource that you can attach to your Windows instance to accelerate the graphics performance of your applications. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/WindowsGuide/elastic-graphics.html\">Amazon EC2 Elastic GPUs</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "ElasticInferenceAccelerators":{
          "shape":"ElasticInferenceAccelerators",
          "documentation":"<p>An elastic inference accelerator to associate with the instance. Elastic inference accelerators are a resource you can attach to your Amazon EC2 instances to accelerate your Deep Learning (DL) inference workloads.</p> <p>You cannot specify accelerators from different generations in the same request.</p>",
          "locationName":"ElasticInferenceAccelerator"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply to the resources that are created during instance launch.</p> <p>You can specify tags for the following resources only:</p> <ul> <li> <p>Instances</p> </li> <li> <p>Volumes</p> </li> <li> <p>Elastic graphics</p> </li> <li> <p>Spot Instance requests</p> </li> <li> <p>Network interfaces</p> </li> </ul> <p>To tag a resource after it has been created, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CreateTags.html\">CreateTags</a>.</p>",
          "locationName":"TagSpecification"
        },
        "LaunchTemplate":{
          "shape":"LaunchTemplateSpecification",
          "documentation":"<p>The launch template to use to launch the instances. Any parameters that you specify in <a>RunInstances</a> override the same parameters in the launch template. You can specify either the name or ID of a launch template, but not both.</p>"
        },
        "InstanceMarketOptions":{
          "shape":"InstanceMarketOptionsRequest",
          "documentation":"<p>The market (purchasing) option for the instances.</p> <p>For <a>RunInstances</a>, persistent Spot Instance requests are only supported when <b>InstanceInterruptionBehavior</b> is set to either <code>hibernate</code> or <code>stop</code>.</p>"
        },
        "CreditSpecification":{
          "shape":"CreditSpecificationRequest",
          "documentation":"<p>The credit option for CPU usage of the burstable performance instance. Valid values are <code>standard</code> and <code>unlimited</code>. To change this attribute after launch, use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyInstanceCreditSpecification.html\"> ModifyInstanceCreditSpecification</a>. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/burstable-performance-instances.html\">Burstable performance instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>Default: <code>standard</code> (T2 instances) or <code>unlimited</code> (T3/T3a/T4g instances)</p> <p>For T3 instances with <code>host</code> tenancy, only <code>standard</code> is supported.</p>"
        },
        "CpuOptions":{
          "shape":"CpuOptionsRequest",
          "documentation":"<p>The CPU options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-optimize-cpu.html\">Optimize CPU options</a> in the <i>Amazon EC2 User Guide</i>.</p>"
        },
        "CapacityReservationSpecification":{
          "shape":"CapacityReservationSpecification",
          "documentation":"<p>Information about the Capacity Reservation targeting option. If you do not specify this parameter, the instance's Capacity Reservation preference defaults to <code>open</code>, which enables it to run in any open Capacity Reservation that has matching attributes (instance type, platform, Availability Zone).</p>"
        },
        "HibernationOptions":{
          "shape":"HibernationOptionsRequest",
          "documentation":"<p>Indicates whether an instance is enabled for hibernation. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>You can't enable hibernation and Amazon Web Services Nitro Enclaves on the same instance.</p>"
        },
        "LicenseSpecifications":{
          "shape":"LicenseSpecificationListRequest",
          "documentation":"<p>The license configurations.</p>",
          "locationName":"LicenseSpecification"
        },
        "MetadataOptions":{
          "shape":"InstanceMetadataOptionsRequest",
          "documentation":"<p>The metadata options for the instance. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html\">Instance metadata and user data</a>.</p>"
        },
        "EnclaveOptions":{
          "shape":"EnclaveOptionsRequest",
          "documentation":"<p>Indicates whether the instance is enabled for Amazon Web Services Nitro Enclaves. For more information, see <a href=\"https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave.html\"> What is Amazon Web Services Nitro Enclaves?</a> in the <i>Amazon Web Services Nitro Enclaves User Guide</i>.</p> <p>You can't enable Amazon Web Services Nitro Enclaves and hibernation on the same instance.</p>"
        },
        "PrivateDnsNameOptions":{
          "shape":"PrivateDnsNameOptionsRequest",
          "documentation":"<p>The options for the instance hostname. The default values are inherited from the subnet.</p>"
        },
        "MaintenanceOptions":{
          "shape":"InstanceMaintenanceOptionsRequest",
          "documentation":"<p>The maintenance and recovery options for the instance.</p>"
        },
        "DisableApiStop":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether an instance is enabled for stop protection. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Stop_Start.html#Using_StopProtection\">Stop protection</a>. </p>"
        }
      }
    },
    "RunInstancesUserData":{
      "type":"string",
      "sensitive":true
    },
    "RunScheduledInstancesRequest":{
      "type":"structure",
      "required":[
        "LaunchSpecification",
        "ScheduledInstanceId"
      ],
      "members":{
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that ensures the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "idempotencyToken":true
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances.</p> <p>Default: 1</p>"
        },
        "LaunchSpecification":{
          "shape":"ScheduledInstancesLaunchSpecification",
          "documentation":"<p>The launch specification. You must match the instance type, Availability Zone, network, and platform of the schedule that you purchased.</p>"
        },
        "ScheduledInstanceId":{
          "shape":"ScheduledInstanceId",
          "documentation":"<p>The Scheduled Instance ID.</p>"
        }
      },
      "documentation":"<p>Contains the parameters for RunScheduledInstances.</p>"
    },
    "RunScheduledInstancesResult":{
      "type":"structure",
      "members":{
        "InstanceIdSet":{
          "shape":"InstanceIdSet",
          "documentation":"<p>The IDs of the newly launched instances.</p>",
          "locationName":"instanceIdSet"
        }
      },
      "documentation":"<p>Contains the output of RunScheduledInstances.</p>"
    },
    "S3ObjectTag":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "documentation":"<p>The key of the tag.</p> <p>Constraints: Tag keys are case-sensitive and can be up to 128 Unicode characters in length. May not begin with <code>aws</code>:.</p>"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The value of the tag.</p> <p>Constraints: Tag values are case-sensitive and can be up to 256 Unicode characters in length.</p>"
        }
      },
      "documentation":"<p>The tags to apply to the AMI object that will be stored in the Amazon S3 bucket. For more information, see <a href=\"https://docs.aws.amazon.com/AmazonS3/latest/userguide/object-tagging.html\">Categorizing your storage using tags</a> in the <i>Amazon Simple Storage Service User Guide</i>.</p>"
    },
    "S3ObjectTagList":{
      "type":"list",
      "member":{
        "shape":"S3ObjectTag",
        "locationName":"item"
      }
    },
    "S3Storage":{
      "type":"structure",
      "members":{
        "AWSAccessKeyId":{
          "shape":"String",
          "documentation":"<p>The access key ID of the owner of the bucket. Before you specify a value for your access key ID, review and follow the guidance in <a href=\"https://docs.aws.amazon.com/accounts/latest/reference/best-practices.html\">Best Practices for Amazon Web Services accounts</a> in the <i>Account ManagementReference Guide</i>.</p>"
        },
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The bucket in which to store the AMI. You can specify a bucket that you already own or a new bucket that Amazon EC2 creates on your behalf. If you specify a bucket that belongs to someone else, Amazon EC2 returns an error.</p>",
          "locationName":"bucket"
        },
        "Prefix":{
          "shape":"String",
          "documentation":"<p>The beginning of the file name of the AMI.</p>",
          "locationName":"prefix"
        },
        "UploadPolicy":{
          "shape":"Blob",
          "documentation":"<p>An Amazon S3 upload policy that gives Amazon EC2 permission to upload items into Amazon S3 on your behalf.</p>",
          "locationName":"uploadPolicy"
        },
        "UploadPolicySignature":{
          "shape":"String",
          "documentation":"<p>The signature of the JSON document.</p>",
          "locationName":"uploadPolicySignature"
        }
      },
      "documentation":"<p>Describes the storage parameters for Amazon S3 and Amazon S3 buckets for an instance store-backed AMI.</p>"
    },
    "ScheduledInstance":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "CreateDate":{
          "shape":"DateTime",
          "documentation":"<p>The date when the Scheduled Instance was purchased.</p>",
          "locationName":"createDate"
        },
        "HourlyPrice":{
          "shape":"String",
          "documentation":"<p>The hourly price for a single instance.</p>",
          "locationName":"hourlyPrice"
        },
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances.</p>",
          "locationName":"instanceCount"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "NetworkPlatform":{
          "shape":"String",
          "documentation":"<p>The network platform (<code>EC2-Classic</code> or <code>EC2-VPC</code>).</p>",
          "locationName":"networkPlatform"
        },
        "NextSlotStartTime":{
          "shape":"DateTime",
          "documentation":"<p>The time for the next schedule to start.</p>",
          "locationName":"nextSlotStartTime"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>The platform (<code>Linux/UNIX</code> or <code>Windows</code>).</p>",
          "locationName":"platform"
        },
        "PreviousSlotEndTime":{
          "shape":"DateTime",
          "documentation":"<p>The time that the previous schedule ended or will end.</p>",
          "locationName":"previousSlotEndTime"
        },
        "Recurrence":{
          "shape":"ScheduledInstanceRecurrence",
          "documentation":"<p>The schedule recurrence.</p>",
          "locationName":"recurrence"
        },
        "ScheduledInstanceId":{
          "shape":"String",
          "documentation":"<p>The Scheduled Instance ID.</p>",
          "locationName":"scheduledInstanceId"
        },
        "SlotDurationInHours":{
          "shape":"Integer",
          "documentation":"<p>The number of hours in the schedule.</p>",
          "locationName":"slotDurationInHours"
        },
        "TermEndDate":{
          "shape":"DateTime",
          "documentation":"<p>The end date for the Scheduled Instance.</p>",
          "locationName":"termEndDate"
        },
        "TermStartDate":{
          "shape":"DateTime",
          "documentation":"<p>The start date for the Scheduled Instance.</p>",
          "locationName":"termStartDate"
        },
        "TotalScheduledInstanceHours":{
          "shape":"Integer",
          "documentation":"<p>The total number of hours for a single instance for the entire term.</p>",
          "locationName":"totalScheduledInstanceHours"
        }
      },
      "documentation":"<p>Describes a Scheduled Instance.</p>"
    },
    "ScheduledInstanceAvailability":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "AvailableInstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of available instances.</p>",
          "locationName":"availableInstanceCount"
        },
        "FirstSlotStartTime":{
          "shape":"DateTime",
          "documentation":"<p>The time period for the first schedule to start.</p>",
          "locationName":"firstSlotStartTime"
        },
        "HourlyPrice":{
          "shape":"String",
          "documentation":"<p>The hourly price for a single instance.</p>",
          "locationName":"hourlyPrice"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type. You can specify one of the C3, C4, M4, or R3 instance types.</p>",
          "locationName":"instanceType"
        },
        "MaxTermDurationInDays":{
          "shape":"Integer",
          "documentation":"<p>The maximum term. The only possible value is 365 days.</p>",
          "locationName":"maxTermDurationInDays"
        },
        "MinTermDurationInDays":{
          "shape":"Integer",
          "documentation":"<p>The minimum term. The only possible value is 365 days.</p>",
          "locationName":"minTermDurationInDays"
        },
        "NetworkPlatform":{
          "shape":"String",
          "documentation":"<p>The network platform (<code>EC2-Classic</code> or <code>EC2-VPC</code>).</p>",
          "locationName":"networkPlatform"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>The platform (<code>Linux/UNIX</code> or <code>Windows</code>).</p>",
          "locationName":"platform"
        },
        "PurchaseToken":{
          "shape":"String",
          "documentation":"<p>The purchase token. This token expires in two hours.</p>",
          "locationName":"purchaseToken"
        },
        "Recurrence":{
          "shape":"ScheduledInstanceRecurrence",
          "documentation":"<p>The schedule recurrence.</p>",
          "locationName":"recurrence"
        },
        "SlotDurationInHours":{
          "shape":"Integer",
          "documentation":"<p>The number of hours in the schedule.</p>",
          "locationName":"slotDurationInHours"
        },
        "TotalScheduledInstanceHours":{
          "shape":"Integer",
          "documentation":"<p>The total number of hours for a single instance for the entire term.</p>",
          "locationName":"totalScheduledInstanceHours"
        }
      },
      "documentation":"<p>Describes a schedule that is available for your Scheduled Instances.</p>"
    },
    "ScheduledInstanceAvailabilitySet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstanceAvailability",
        "locationName":"item"
      }
    },
    "ScheduledInstanceId":{"type":"string"},
    "ScheduledInstanceIdRequestSet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstanceId",
        "locationName":"ScheduledInstanceId"
      }
    },
    "ScheduledInstanceRecurrence":{
      "type":"structure",
      "members":{
        "Frequency":{
          "shape":"String",
          "documentation":"<p>The frequency (<code>Daily</code>, <code>Weekly</code>, or <code>Monthly</code>).</p>",
          "locationName":"frequency"
        },
        "Interval":{
          "shape":"Integer",
          "documentation":"<p>The interval quantity. The interval unit depends on the value of <code>frequency</code>. For example, every 2 weeks or every 2 months.</p>",
          "locationName":"interval"
        },
        "OccurrenceDaySet":{
          "shape":"OccurrenceDaySet",
          "documentation":"<p>The days. For a monthly schedule, this is one or more days of the month (1-31). For a weekly schedule, this is one or more days of the week (1-7, where 1 is Sunday).</p>",
          "locationName":"occurrenceDaySet"
        },
        "OccurrenceRelativeToEnd":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the occurrence is relative to the end of the specified week or month.</p>",
          "locationName":"occurrenceRelativeToEnd"
        },
        "OccurrenceUnit":{
          "shape":"String",
          "documentation":"<p>The unit for <code>occurrenceDaySet</code> (<code>DayOfWeek</code> or <code>DayOfMonth</code>).</p>",
          "locationName":"occurrenceUnit"
        }
      },
      "documentation":"<p>Describes the recurring schedule for a Scheduled Instance.</p>"
    },
    "ScheduledInstanceRecurrenceRequest":{
      "type":"structure",
      "members":{
        "Frequency":{
          "shape":"String",
          "documentation":"<p>The frequency (<code>Daily</code>, <code>Weekly</code>, or <code>Monthly</code>).</p>"
        },
        "Interval":{
          "shape":"Integer",
          "documentation":"<p>The interval quantity. The interval unit depends on the value of <code>Frequency</code>. For example, every 2 weeks or every 2 months.</p>"
        },
        "OccurrenceDays":{
          "shape":"OccurrenceDayRequestSet",
          "documentation":"<p>The days. For a monthly schedule, this is one or more days of the month (1-31). For a weekly schedule, this is one or more days of the week (1-7, where 1 is Sunday). You can't specify this value with a daily schedule. If the occurrence is relative to the end of the month, you can specify only a single day.</p>",
          "locationName":"OccurrenceDay"
        },
        "OccurrenceRelativeToEnd":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the occurrence is relative to the end of the specified week or month. You can't specify this value with a daily schedule.</p>"
        },
        "OccurrenceUnit":{
          "shape":"String",
          "documentation":"<p>The unit for <code>OccurrenceDays</code> (<code>DayOfWeek</code> or <code>DayOfMonth</code>). This value is required for a monthly schedule. You can't specify <code>DayOfWeek</code> with a weekly schedule. You can't specify this value with a daily schedule.</p>"
        }
      },
      "documentation":"<p>Describes the recurring schedule for a Scheduled Instance.</p>"
    },
    "ScheduledInstanceSet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstance",
        "locationName":"item"
      }
    },
    "ScheduledInstancesBlockDeviceMapping":{
      "type":"structure",
      "members":{
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The device name (for example, <code>/dev/sdh</code> or <code>xvdh</code>).</p>"
        },
        "Ebs":{
          "shape":"ScheduledInstancesEbs",
          "documentation":"<p>Parameters used to set up EBS volumes automatically when the instance is launched.</p>"
        },
        "NoDevice":{
          "shape":"String",
          "documentation":"<p>To omit the device from the block device mapping, specify an empty string.</p>"
        },
        "VirtualName":{
          "shape":"String",
          "documentation":"<p>The virtual device name (<code>ephemeral</code>N). Instance store volumes are numbered starting from 0. An instance type with two available instance store volumes can specify mappings for <code>ephemeral0</code> and <code>ephemeral1</code>. The number of available instance store volumes depends on the instance type. After you connect to the instance, you must mount the volume.</p> <p>Constraints: For M3 instances, you must specify instance store volumes in the block device mapping for the instance. When you launch an M3 instance, we ignore any instance store volumes specified in the block device mapping for the AMI.</p>"
        }
      },
      "documentation":"<p>Describes a block device mapping for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesBlockDeviceMappingSet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstancesBlockDeviceMapping",
        "locationName":"BlockDeviceMapping"
      }
    },
    "ScheduledInstancesEbs":{
      "type":"structure",
      "members":{
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume is deleted on instance termination.</p>"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume is encrypted. You can attached encrypted volumes only to instances that support them.</p>"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The number of I/O operations per second (IOPS) to provision for an <code>io1</code> or <code>io2</code> volume, with a maximum ratio of 50 IOPS/GiB for <code>io1</code>, and 500 IOPS/GiB for <code>io2</code>. Range is 100 to 64,000 IOPS for volumes in most Regions. Maximum IOPS of 64,000 is guaranteed only on <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/instance-types.html#ec2-nitro-instances\">instances built on the Nitro System</a>. Other instance families guarantee performance up to 32,000 IOPS. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/EBSVolumeTypes.html\">Amazon EBS volume types</a> in the <i>Amazon EC2 User Guide</i>.</p> <p>This parameter is valid only for Provisioned IOPS SSD (<code>io1</code> and <code>io2</code>) volumes.</p>"
        },
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiB.</p> <p>Default: If you're creating the volume from a snapshot and don't specify a volume size, the default is the snapshot size.</p>"
        },
        "VolumeType":{
          "shape":"String",
          "documentation":"<p>The volume type. <code>gp2</code> for General Purpose SSD, <code>io1</code> or <code> io2</code> for Provisioned IOPS SSD, Throughput Optimized HDD for <code>st1</code>, Cold HDD for <code>sc1</code>, or <code>standard</code> for Magnetic.</p> <p>Default: <code>gp2</code> </p>"
        }
      },
      "documentation":"<p>Describes an EBS volume for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesIamInstanceProfile":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN).</p>"
        },
        "Name":{
          "shape":"String",
          "documentation":"<p>The name.</p>"
        }
      },
      "documentation":"<p>Describes an IAM instance profile for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesIpv6Address":{
      "type":"structure",
      "members":{
        "Ipv6Address":{
          "shape":"Ipv6Address",
          "documentation":"<p>The IPv6 address.</p>"
        }
      },
      "documentation":"<p>Describes an IPv6 address.</p>"
    },
    "ScheduledInstancesIpv6AddressList":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstancesIpv6Address",
        "locationName":"Ipv6Address"
      }
    },
    "ScheduledInstancesLaunchSpecification":{
      "type":"structure",
      "required":["ImageId"],
      "members":{
        "BlockDeviceMappings":{
          "shape":"ScheduledInstancesBlockDeviceMappingSet",
          "documentation":"<p>The block device mapping entries.</p>",
          "locationName":"BlockDeviceMapping"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instances are optimized for EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS-optimized instance.</p> <p>Default: <code>false</code> </p>"
        },
        "IamInstanceProfile":{
          "shape":"ScheduledInstancesIamInstanceProfile",
          "documentation":"<p>The IAM instance profile.</p>"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the Amazon Machine Image (AMI).</p>"
        },
        "InstanceType":{
          "shape":"String",
          "documentation":"<p>The instance type.</p>"
        },
        "KernelId":{
          "shape":"KernelId",
          "documentation":"<p>The ID of the kernel.</p>"
        },
        "KeyName":{
          "shape":"KeyPairName",
          "documentation":"<p>The name of the key pair.</p>"
        },
        "Monitoring":{
          "shape":"ScheduledInstancesMonitoring",
          "documentation":"<p>Enable or disable monitoring for the instances.</p>"
        },
        "NetworkInterfaces":{
          "shape":"ScheduledInstancesNetworkInterfaceSet",
          "documentation":"<p>The network interfaces.</p>",
          "locationName":"NetworkInterface"
        },
        "Placement":{
          "shape":"ScheduledInstancesPlacement",
          "documentation":"<p>The placement information.</p>"
        },
        "RamdiskId":{
          "shape":"RamdiskId",
          "documentation":"<p>The ID of the RAM disk.</p>"
        },
        "SecurityGroupIds":{
          "shape":"ScheduledInstancesSecurityGroupIdSet",
          "documentation":"<p>The IDs of the security groups.</p>",
          "locationName":"SecurityGroupId"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet in which to launch the instances.</p>"
        },
        "UserData":{
          "shape":"String",
          "documentation":"<p>The base64-encoded MIME user data.</p>"
        }
      },
      "documentation":"<p>Describes the launch specification for a Scheduled Instance.</p> <p>If you are launching the Scheduled Instance in EC2-VPC, you must specify the ID of the subnet. You can specify the subnet using either <code>SubnetId</code> or <code>NetworkInterface</code>.</p>",
      "sensitive":true
    },
    "ScheduledInstancesMonitoring":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether monitoring is enabled.</p>"
        }
      },
      "documentation":"<p>Describes whether monitoring is enabled for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesNetworkInterface":{
      "type":"structure",
      "members":{
        "AssociatePublicIpAddress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to assign a public IPv4 address to instances launched in a VPC. The public IPv4 address can only be assigned to a network interface for eth0, and can only be assigned to a new network interface, not an existing one. You cannot specify more than one network interface in the request. If launching into a default subnet, the default value is <code>true</code>.</p>"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether to delete the interface when the instance is terminated.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description.</p>"
        },
        "DeviceIndex":{
          "shape":"Integer",
          "documentation":"<p>The index of the device for the network interface attachment.</p>"
        },
        "Groups":{
          "shape":"ScheduledInstancesSecurityGroupIdSet",
          "documentation":"<p>The IDs of the security groups.</p>",
          "locationName":"Group"
        },
        "Ipv6AddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of IPv6 addresses to assign to the network interface. The IPv6 addresses are automatically selected from the subnet range.</p>"
        },
        "Ipv6Addresses":{
          "shape":"ScheduledInstancesIpv6AddressList",
          "documentation":"<p>The specific IPv6 addresses from the subnet range.</p>",
          "locationName":"Ipv6Address"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The IPv4 address of the network interface within the subnet.</p>"
        },
        "PrivateIpAddressConfigs":{
          "shape":"PrivateIpAddressConfigSet",
          "documentation":"<p>The private IPv4 addresses.</p>",
          "locationName":"PrivateIpAddressConfig"
        },
        "SecondaryPrivateIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of secondary private IPv4 addresses.</p>"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>"
        }
      },
      "documentation":"<p>Describes a network interface for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesNetworkInterfaceSet":{
      "type":"list",
      "member":{
        "shape":"ScheduledInstancesNetworkInterface",
        "locationName":"NetworkInterface"
      }
    },
    "ScheduledInstancesPlacement":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>"
        },
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group.</p>"
        }
      },
      "documentation":"<p>Describes the placement for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesPrivateIpAddressConfig":{
      "type":"structure",
      "members":{
        "Primary":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is a primary IPv4 address. Otherwise, this is a secondary IPv4 address.</p>"
        },
        "PrivateIpAddress":{
          "shape":"String",
          "documentation":"<p>The IPv4 address.</p>"
        }
      },
      "documentation":"<p>Describes a private IPv4 address for a Scheduled Instance.</p>"
    },
    "ScheduledInstancesSecurityGroupIdSet":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"SecurityGroupId"
      }
    },
    "SearchLocalGatewayRoutesRequest":{
      "type":"structure",
      "required":["LocalGatewayRouteTableId"],
      "members":{
        "LocalGatewayRouteTableId":{
          "shape":"LocalGatewayRoutetableId",
          "documentation":"<p>The ID of the local gateway route table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters.</p> <ul> <li> <p> <code>prefix-list-id</code> - The ID of the prefix list.</p> </li> <li> <p> <code>route-search.exact-match</code> - The exact match of the specified filter.</p> </li> <li> <p> <code>route-search.longest-prefix-match</code> - The longest prefix that matches the route.</p> </li> <li> <p> <code>route-search.subnet-of-match</code> - The routes with a subnet that match the specified CIDR filter.</p> </li> <li> <p> <code>route-search.supernet-of-match</code> - The routes with a CIDR that encompass the CIDR filter. For example, if you have 10.0.1.0/29 and 10.0.1.0/31 routes in your route table and you specify <code>supernet-of-match</code> as 10.0.1.0/30, then the result returns 10.0.1.0/29.</p> </li> <li> <p> <code>state</code> - The state of the route.</p> </li> <li> <p> <code>type</code> - The route type.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"MaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "SearchLocalGatewayRoutesResult":{
      "type":"structure",
      "members":{
        "Routes":{
          "shape":"LocalGatewayRouteList",
          "documentation":"<p>Information about the routes.</p>",
          "locationName":"routeSet"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "SearchTransitGatewayMulticastGroupsRequest":{
      "type":"structure",
      "required":["TransitGatewayMulticastDomainId"],
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"TransitGatewayMulticastDomainId",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>group-ip-address</code> - The IP address of the transit gateway multicast group.</p> </li> <li> <p> <code>is-group-member</code> - The resource is a group member. Valid values are <code>true</code> | <code>false</code>.</p> </li> <li> <p> <code>is-group-source</code> - The resource is a group source. Valid values are <code>true</code> | <code>false</code>.</p> </li> <li> <p> <code>member-type</code> - The member type. Valid values are <code>igmp</code> | <code>static</code>.</p> </li> <li> <p> <code>resource-id</code> - The ID of the resource.</p> </li> <li> <p> <code>resource-type</code> - The type of resource. Valid values are <code>vpc</code> | <code>vpn</code> | <code>direct-connect-gateway</code> | <code>tgw-peering</code>.</p> </li> <li> <p> <code>source-type</code> - The source type. Valid values are <code>igmp</code> | <code>static</code>.</p> </li> <li> <p> <code>subnet-id</code> - The ID of the subnet.</p> </li> <li> <p> <code>transit-gateway-attachment-id</code> - The id of the transit gateway attachment.</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of results to return with a single call. To retrieve the remaining results, make another call with the returned <code>nextToken</code> value.</p>"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token for the next page of results.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "SearchTransitGatewayMulticastGroupsResult":{
      "type":"structure",
      "members":{
        "MulticastGroups":{
          "shape":"TransitGatewayMulticastGroupList",
          "documentation":"<p>Information about the transit gateway multicast group.</p>",
          "locationName":"multicastGroups"
        },
        "NextToken":{
          "shape":"String",
          "documentation":"<p>The token to use to retrieve the next page of results. This value is <code>null</code> when there are no more results to return.</p>",
          "locationName":"nextToken"
        }
      }
    },
    "SearchTransitGatewayRoutesRequest":{
      "type":"structure",
      "required":[
        "TransitGatewayRouteTableId",
        "Filters"
      ],
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>"
        },
        "Filters":{
          "shape":"FilterList",
          "documentation":"<p>One or more filters. The possible values are:</p> <ul> <li> <p> <code>attachment.transit-gateway-attachment-id</code>- The id of the transit gateway attachment.</p> </li> <li> <p> <code>attachment.resource-id</code> - The resource id of the transit gateway attachment.</p> </li> <li> <p> <code>attachment.resource-type</code> - The attachment resource type. Valid values are <code>vpc</code> | <code>vpn</code> | <code>direct-connect-gateway</code> | <code>peering</code> | <code>connect</code>.</p> </li> <li> <p> <code>prefix-list-id</code> - The ID of the prefix list.</p> </li> <li> <p> <code>route-search.exact-match</code> - The exact match of the specified filter.</p> </li> <li> <p> <code>route-search.longest-prefix-match</code> - The longest prefix that matches the route.</p> </li> <li> <p> <code>route-search.subnet-of-match</code> - The routes with a subnet that match the specified CIDR filter.</p> </li> <li> <p> <code>route-search.supernet-of-match</code> - The routes with a CIDR that encompass the CIDR filter. For example, if you have 10.0.1.0/29 and 10.0.1.0/31 routes in your route table and you specify supernet-of-match as 10.0.1.0/30, then the result returns 10.0.1.0/29.</p> </li> <li> <p> <code>state</code> - The state of the route (<code>active</code> | <code>blackhole</code>).</p> </li> <li> <p> <code>type</code> - The type of route (<code>propagated</code> | <code>static</code>).</p> </li> </ul>",
          "locationName":"Filter"
        },
        "MaxResults":{
          "shape":"TransitGatewayMaxResults",
          "documentation":"<p>The maximum number of routes to return.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "SearchTransitGatewayRoutesResult":{
      "type":"structure",
      "members":{
        "Routes":{
          "shape":"TransitGatewayRouteList",
          "documentation":"<p>Information about the routes.</p>",
          "locationName":"routeSet"
        },
        "AdditionalRoutesAvailable":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether there are additional routes available.</p>",
          "locationName":"additionalRoutesAvailable"
        }
      }
    },
    "SecurityGroup":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the security group.</p>",
          "locationName":"groupDescription"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the security group.</p>",
          "locationName":"groupName"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The inbound rules associated with the security group.</p>",
          "locationName":"ipPermissions"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the owner of the security group.</p>",
          "locationName":"ownerId"
        },
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "IpPermissionsEgress":{
          "shape":"IpPermissionList",
          "documentation":"<p>[VPC only] The outbound rules associated with the security group.</p>",
          "locationName":"ipPermissionsEgress"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the security group.</p>",
          "locationName":"tagSet"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>[VPC only] The ID of the VPC for the security group.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<p>Describes a security group.</p>"
    },
    "SecurityGroupId":{"type":"string"},
    "SecurityGroupIdList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"item"
      }
    },
    "SecurityGroupIdStringList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"SecurityGroupId"
      }
    },
    "SecurityGroupIdentifier":{
      "type":"structure",
      "members":{
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the security group.</p>",
          "locationName":"groupName"
        }
      },
      "documentation":"<p>Describes a security group.</p>"
    },
    "SecurityGroupList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroup",
        "locationName":"item"
      }
    },
    "SecurityGroupName":{"type":"string"},
    "SecurityGroupReference":{
      "type":"structure",
      "members":{
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of your security group.</p>",
          "locationName":"groupId"
        },
        "ReferencingVpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC with the referencing security group.</p>",
          "locationName":"referencingVpcId"
        },
        "VpcPeeringConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      },
      "documentation":"<p>Describes a VPC with a security group that references your security group.</p>"
    },
    "SecurityGroupReferences":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupReference",
        "locationName":"item"
      }
    },
    "SecurityGroupRule":{
      "type":"structure",
      "members":{
        "SecurityGroupRuleId":{
          "shape":"SecurityGroupRuleId",
          "documentation":"<p>The ID of the security group rule.</p>",
          "locationName":"securityGroupRuleId"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "GroupOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the security group. </p>",
          "locationName":"groupOwnerId"
        },
        "IsEgress":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the security group rule is an outbound rule.</p>",
          "locationName":"isEgress"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>The IP protocol name (<code>tcp</code>, <code>udp</code>, <code>icmp</code>, <code>icmpv6</code>) or number (see <a href=\"http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers</a>). </p> <p>Use <code>-1</code> to specify all protocols.</p>",
          "locationName":"ipProtocol"
        },
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the start of the port range. If the protocol is ICMP or ICMPv6, this is the type number. A value of -1 indicates all ICMP/ICMPv6 types. If you specify all ICMP/ICMPv6 types, you must specify all ICMP/ICMPv6 codes.</p>",
          "locationName":"fromPort"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the end of the port range. If the protocol is ICMP or ICMPv6, this is the type number. A value of -1 indicates all ICMP/ICMPv6 codes. If you specify all ICMP/ICMPv6 types, you must specify all ICMP/ICMPv6 codes.</p>",
          "locationName":"toPort"
        },
        "CidrIpv4":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR range.</p>",
          "locationName":"cidrIpv4"
        },
        "CidrIpv6":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR range.</p>",
          "locationName":"cidrIpv6"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>",
          "locationName":"prefixListId"
        },
        "ReferencedGroupInfo":{
          "shape":"ReferencedSecurityGroup",
          "documentation":"<p>Describes the security group that is referenced in the rule.</p>",
          "locationName":"referencedGroupInfo"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The security group rule description.</p>",
          "locationName":"description"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags applied to the security group rule.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a security group rule.</p>"
    },
    "SecurityGroupRuleDescription":{
      "type":"structure",
      "members":{
        "SecurityGroupRuleId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group rule.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the security group rule.</p>"
        }
      },
      "documentation":"<p>Describes the description of a security group rule.</p> <p>You can use this when you want to update the security group rule description for either an inbound or outbound rule.</p>"
    },
    "SecurityGroupRuleDescriptionList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupRuleDescription",
        "locationName":"item"
      }
    },
    "SecurityGroupRuleId":{"type":"string"},
    "SecurityGroupRuleIdList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "SecurityGroupRuleList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupRule",
        "locationName":"item"
      }
    },
    "SecurityGroupRuleRequest":{
      "type":"structure",
      "members":{
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>The IP protocol name (<code>tcp</code>, <code>udp</code>, <code>icmp</code>, <code>icmpv6</code>) or number (see <a href=\"http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers</a>). </p> <p>Use <code>-1</code> to specify all protocols.</p>"
        },
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the start of the port range. If the protocol is ICMP or ICMPv6, this is the type number. A value of -1 indicates all ICMP/ICMPv6 types. If you specify all ICMP/ICMPv6 types, you must specify all ICMP/ICMPv6 codes.</p>"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>If the protocol is TCP or UDP, this is the end of the port range. If the protocol is ICMP or ICMPv6, this is the code. A value of -1 indicates all ICMP/ICMPv6 codes. If you specify all ICMP/ICMPv6 types, you must specify all ICMP/ICMPv6 codes.</p>"
        },
        "CidrIpv4":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR range. To specify a single IPv4 address, use the /32 prefix length. </p>"
        },
        "CidrIpv6":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR range. To specify a single IPv6 address, use the /128 prefix length.</p>"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>"
        },
        "ReferencedGroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group that is referenced in the security group rule.</p>"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the security group rule.</p>"
        }
      },
      "documentation":"<p>Describes a security group rule.</p> <p>You must specify exactly one of the following parameters, based on the rule type:</p> <ul> <li> <p>CidrIpv4</p> </li> <li> <p>CidrIpv6</p> </li> <li> <p>PrefixListId</p> </li> <li> <p>ReferencedGroupId</p> </li> </ul> <p>When you modify a rule, you cannot change the rule type. For example, if the rule uses an IPv4 address range, you must use <code>CidrIpv4</code> to specify a new IPv4 address range.</p>"
    },
    "SecurityGroupRuleUpdate":{
      "type":"structure",
      "required":["SecurityGroupRuleId"],
      "members":{
        "SecurityGroupRuleId":{
          "shape":"SecurityGroupRuleId",
          "documentation":"<p>The ID of the security group rule.</p>"
        },
        "SecurityGroupRule":{
          "shape":"SecurityGroupRuleRequest",
          "documentation":"<p>Information about the security group rule.</p>"
        }
      },
      "documentation":"<p>Describes an update to a security group rule.</p>"
    },
    "SecurityGroupRuleUpdateList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupRuleUpdate",
        "locationName":"item"
      }
    },
    "SecurityGroupStringList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupName",
        "locationName":"SecurityGroup"
      }
    },
    "SelfServicePortal":{
      "type":"string",
      "enum":[
        "enabled",
        "disabled"
      ]
    },
    "SendDiagnosticInterruptRequest":{
      "type":"structure",
      "required":["InstanceId"],
      "members":{
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The ID of the instance.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "SensitiveUserData":{
      "type":"string",
      "sensitive":true
    },
    "ServiceConfiguration":{
      "type":"structure",
      "members":{
        "ServiceType":{
          "shape":"ServiceTypeDetailSet",
          "documentation":"<p>The type of service.</p>",
          "locationName":"serviceType"
        },
        "ServiceId":{
          "shape":"String",
          "documentation":"<p>The ID of the service.</p>",
          "locationName":"serviceId"
        },
        "ServiceName":{
          "shape":"String",
          "documentation":"<p>The name of the service.</p>",
          "locationName":"serviceName"
        },
        "ServiceState":{
          "shape":"ServiceState",
          "documentation":"<p>The service state.</p>",
          "locationName":"serviceState"
        },
        "AvailabilityZones":{
          "shape":"ValueStringList",
          "documentation":"<p>The Availability Zones in which the service is available.</p>",
          "locationName":"availabilityZoneSet"
        },
        "AcceptanceRequired":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether requests from other Amazon Web Services accounts to create an endpoint to the service must first be accepted.</p>",
          "locationName":"acceptanceRequired"
        },
        "ManagesVpcEndpoints":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the service manages its VPC endpoints. Management of the service VPC endpoints using the VPC endpoint API is restricted.</p>",
          "locationName":"managesVpcEndpoints"
        },
        "NetworkLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of the Network Load Balancers for the service.</p>",
          "locationName":"networkLoadBalancerArnSet"
        },
        "GatewayLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of the Gateway Load Balancers for the service.</p>",
          "locationName":"gatewayLoadBalancerArnSet"
        },
        "SupportedIpAddressTypes":{
          "shape":"SupportedIpAddressTypes",
          "documentation":"<p>The supported IP address types.</p>",
          "locationName":"supportedIpAddressTypeSet"
        },
        "BaseEndpointDnsNames":{
          "shape":"ValueStringList",
          "documentation":"<p>The DNS names for the service.</p>",
          "locationName":"baseEndpointDnsNameSet"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private DNS name for the service.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateDnsNameConfiguration":{
          "shape":"PrivateDnsNameConfiguration",
          "documentation":"<p>Information about the endpoint service private DNS name configuration.</p>",
          "locationName":"privateDnsNameConfiguration"
        },
        "PayerResponsibility":{
          "shape":"PayerResponsibility",
          "documentation":"<p>The payer responsibility.</p>",
          "locationName":"payerResponsibility"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the service.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a service configuration for a VPC endpoint service.</p>"
    },
    "ServiceConfigurationSet":{
      "type":"list",
      "member":{
        "shape":"ServiceConfiguration",
        "locationName":"item"
      }
    },
    "ServiceConnectivityType":{
      "type":"string",
      "enum":[
        "ipv4",
        "ipv6"
      ]
    },
    "ServiceDetail":{
      "type":"structure",
      "members":{
        "ServiceName":{
          "shape":"String",
          "documentation":"<p>The name of the service.</p>",
          "locationName":"serviceName"
        },
        "ServiceId":{
          "shape":"String",
          "documentation":"<p>The ID of the endpoint service.</p>",
          "locationName":"serviceId"
        },
        "ServiceType":{
          "shape":"ServiceTypeDetailSet",
          "documentation":"<p>The type of service.</p>",
          "locationName":"serviceType"
        },
        "AvailabilityZones":{
          "shape":"ValueStringList",
          "documentation":"<p>The Availability Zones in which the service is available.</p>",
          "locationName":"availabilityZoneSet"
        },
        "Owner":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the service owner.</p>",
          "locationName":"owner"
        },
        "BaseEndpointDnsNames":{
          "shape":"ValueStringList",
          "documentation":"<p>The DNS names for the service.</p>",
          "locationName":"baseEndpointDnsNameSet"
        },
        "PrivateDnsName":{
          "shape":"String",
          "documentation":"<p>The private DNS name for the service.</p>",
          "locationName":"privateDnsName"
        },
        "PrivateDnsNames":{
          "shape":"PrivateDnsDetailsSet",
          "documentation":"<p>The private DNS names assigned to the VPC endpoint service.</p>",
          "locationName":"privateDnsNameSet"
        },
        "VpcEndpointPolicySupported":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the service supports endpoint policies.</p>",
          "locationName":"vpcEndpointPolicySupported"
        },
        "AcceptanceRequired":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether VPC endpoint connection requests to the service must be accepted by the service owner.</p>",
          "locationName":"acceptanceRequired"
        },
        "ManagesVpcEndpoints":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the service manages its VPC endpoints. Management of the service VPC endpoints using the VPC endpoint API is restricted.</p>",
          "locationName":"managesVpcEndpoints"
        },
        "PayerResponsibility":{
          "shape":"PayerResponsibility",
          "documentation":"<p>The payer responsibility.</p>",
          "locationName":"payerResponsibility"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the service.</p>",
          "locationName":"tagSet"
        },
        "PrivateDnsNameVerificationState":{
          "shape":"DnsNameState",
          "documentation":"<p>The verification state of the VPC endpoint service.</p> <p>Consumers of the endpoint service cannot use the private name when the state is not <code>verified</code>.</p>",
          "locationName":"privateDnsNameVerificationState"
        },
        "SupportedIpAddressTypes":{
          "shape":"SupportedIpAddressTypes",
          "documentation":"<p>The supported IP address types.</p>",
          "locationName":"supportedIpAddressTypeSet"
        }
      },
      "documentation":"<p>Describes a VPC endpoint service.</p>"
    },
    "ServiceDetailSet":{
      "type":"list",
      "member":{
        "shape":"ServiceDetail",
        "locationName":"item"
      }
    },
    "ServiceState":{
      "type":"string",
      "enum":[
        "Pending",
        "Available",
        "Deleting",
        "Deleted",
        "Failed"
      ]
    },
    "ServiceType":{
      "type":"string",
      "enum":[
        "Interface",
        "Gateway",
        "GatewayLoadBalancer"
      ]
    },
    "ServiceTypeDetail":{
      "type":"structure",
      "members":{
        "ServiceType":{
          "shape":"ServiceType",
          "documentation":"<p>The type of service.</p>",
          "locationName":"serviceType"
        }
      },
      "documentation":"<p>Describes the type of service for a VPC endpoint.</p>"
    },
    "ServiceTypeDetailSet":{
      "type":"list",
      "member":{
        "shape":"ServiceTypeDetail",
        "locationName":"item"
      }
    },
    "ShutdownBehavior":{
      "type":"string",
      "enum":[
        "stop",
        "terminate"
      ]
    },
    "SlotDateTimeRangeRequest":{
      "type":"structure",
      "required":[
        "EarliestTime",
        "LatestTime"
      ],
      "members":{
        "EarliestTime":{
          "shape":"DateTime",
          "documentation":"<p>The earliest date and time, in UTC, for the Scheduled Instance to start.</p>"
        },
        "LatestTime":{
          "shape":"DateTime",
          "documentation":"<p>The latest date and time, in UTC, for the Scheduled Instance to start. This value must be later than or equal to the earliest date and at most three months in the future.</p>"
        }
      },
      "documentation":"<p>Describes the time period for a Scheduled Instance to start its first schedule. The time period must span less than one day.</p>"
    },
    "SlotStartTimeRangeRequest":{
      "type":"structure",
      "members":{
        "EarliestTime":{
          "shape":"DateTime",
          "documentation":"<p>The earliest date and time, in UTC, for the Scheduled Instance to start.</p>"
        },
        "LatestTime":{
          "shape":"DateTime",
          "documentation":"<p>The latest date and time, in UTC, for the Scheduled Instance to start.</p>"
        }
      },
      "documentation":"<p>Describes the time period for a Scheduled Instance to start its first schedule.</p>"
    },
    "Snapshot":{
      "type":"structure",
      "members":{
        "DataEncryptionKeyId":{
          "shape":"String",
          "documentation":"<p>The data encryption key identifier for the snapshot. This value is a unique identifier that corresponds to the data encryption key that was used to encrypt the original volume or snapshot copy. Because data encryption keys are inherited by volumes created from snapshots, and vice versa, if snapshots share the same data encryption key identifier, then they belong to the same volume/snapshot lineage. This parameter is only returned by <a>DescribeSnapshots</a>.</p>",
          "locationName":"dataEncryptionKeyId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the snapshot.</p>",
          "locationName":"description"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the snapshot is encrypted.</p>",
          "locationName":"encrypted"
        },
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Key Management Service (KMS) KMS key that was used to protect the volume encryption key for the parent volume.</p>",
          "locationName":"kmsKeyId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the EBS snapshot.</p>",
          "locationName":"ownerId"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The progress of the snapshot, as a percentage.</p>",
          "locationName":"progress"
        },
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot. Each snapshot receives a unique identifier when it is created.</p>",
          "locationName":"snapshotId"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The time stamp when the snapshot was initiated.</p>",
          "locationName":"startTime"
        },
        "State":{
          "shape":"SnapshotState",
          "documentation":"<p>The snapshot state.</p>",
          "locationName":"status"
        },
        "StateMessage":{
          "shape":"String",
          "documentation":"<p>Encrypted Amazon EBS snapshots are copied asynchronously. If a snapshot copy operation fails (for example, if the proper Key Management Service (KMS) permissions are not obtained) this field displays error state details to help you diagnose why the error occurred. This parameter is only returned by <a>DescribeSnapshots</a>.</p>",
          "locationName":"statusMessage"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume that was used to create the snapshot. Snapshots created by the <a>CopySnapshot</a> action have an arbitrary volume ID that should not be used for any purpose.</p>",
          "locationName":"volumeId"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiB.</p>",
          "locationName":"volumeSize"
        },
        "OwnerAlias":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services owner alias, from an Amazon-maintained list (<code>amazon</code>). This is not the user-configured Amazon Web Services account alias set using the IAM console.</p>",
          "locationName":"ownerAlias"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Outpost on which the snapshot is stored. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html\">Amazon EBS local snapshots on Outposts</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"outpostArn"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the snapshot.</p>",
          "locationName":"tagSet"
        },
        "StorageTier":{
          "shape":"StorageTier",
          "documentation":"<p>The storage tier in which the snapshot is stored. <code>standard</code> indicates that the snapshot is stored in the standard snapshot storage tier and that it is ready for use. <code>archive</code> indicates that the snapshot is currently archived and that it must be restored before it can be used.</p>",
          "locationName":"storageTier"
        },
        "RestoreExpiryTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Only for archived snapshots that are temporarily restored. Indicates the date and time when a temporarily restored snapshot will be automatically re-archived.</p>",
          "locationName":"restoreExpiryTime"
        }
      },
      "documentation":"<p>Describes a snapshot.</p>"
    },
    "SnapshotAttributeName":{
      "type":"string",
      "enum":[
        "productCodes",
        "createVolumePermission"
      ]
    },
    "SnapshotDetail":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the snapshot.</p>",
          "locationName":"description"
        },
        "DeviceName":{
          "shape":"String",
          "documentation":"<p>The block device mapping for the snapshot.</p>",
          "locationName":"deviceName"
        },
        "DiskImageSize":{
          "shape":"Double",
          "documentation":"<p>The size of the disk in the snapshot, in GiB.</p>",
          "locationName":"diskImageSize"
        },
        "Format":{
          "shape":"String",
          "documentation":"<p>The format of the disk image from which the snapshot is created.</p>",
          "locationName":"format"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The percentage of progress for the task.</p>",
          "locationName":"progress"
        },
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The snapshot ID of the disk being imported.</p>",
          "locationName":"snapshotId"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>A brief status of the snapshot creation.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A detailed status message for the snapshot creation.</p>",
          "locationName":"statusMessage"
        },
        "Url":{
          "shape":"String",
          "documentation":"<p>The URL used to access the disk image.</p>",
          "locationName":"url"
        },
        "UserBucket":{
          "shape":"UserBucketDetails",
          "documentation":"<p>The Amazon S3 bucket for the disk image.</p>",
          "locationName":"userBucket"
        }
      },
      "documentation":"<p>Describes the snapshot created from the imported disk.</p>"
    },
    "SnapshotDetailList":{
      "type":"list",
      "member":{
        "shape":"SnapshotDetail",
        "locationName":"item"
      }
    },
    "SnapshotDiskContainer":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the disk image being imported.</p>"
        },
        "Format":{
          "shape":"String",
          "documentation":"<p>The format of the disk image being imported.</p> <p>Valid values: <code>VHD</code> | <code>VMDK</code> | <code>RAW</code> </p>"
        },
        "Url":{
          "shape":"String",
          "documentation":"<p>The URL to the Amazon S3-based disk image being imported. It can either be a https URL (https://..) or an Amazon S3 URL (s3://..).</p>"
        },
        "UserBucket":{
          "shape":"UserBucket",
          "documentation":"<p>The Amazon S3 bucket for the disk image.</p>"
        }
      },
      "documentation":"<p>The disk container object for the import snapshot request.</p>"
    },
    "SnapshotId":{"type":"string"},
    "SnapshotIdStringList":{
      "type":"list",
      "member":{
        "shape":"SnapshotId",
        "locationName":"SnapshotId"
      }
    },
    "SnapshotInfo":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>Description specified by the CreateSnapshotRequest that has been applied to all snapshots.</p>",
          "locationName":"description"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Tags associated with this snapshot.</p>",
          "locationName":"tagSet"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the snapshot is encrypted.</p>",
          "locationName":"encrypted"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>Source volume from which this snapshot was created.</p>",
          "locationName":"volumeId"
        },
        "State":{
          "shape":"SnapshotState",
          "documentation":"<p>Current state of the snapshot.</p>",
          "locationName":"state"
        },
        "VolumeSize":{
          "shape":"Integer",
          "documentation":"<p>Size of the volume from which this snapshot was created.</p>",
          "locationName":"volumeSize"
        },
        "StartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Time this snapshot was started. This is the same for all snapshots initiated by the same request.</p>",
          "locationName":"startTime"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>Progress this snapshot has made towards completing.</p>",
          "locationName":"progress"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>Account id used when creating this snapshot.</p>",
          "locationName":"ownerId"
        },
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>Snapshot id that can be used to describe this snapshot.</p>",
          "locationName":"snapshotId"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Outpost on which the snapshot is stored. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/snapshots-outposts.html\">Amazon EBS local snapshots on Outposts</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p>",
          "locationName":"outpostArn"
        }
      },
      "documentation":"<p>Information about a snapshot.</p>"
    },
    "SnapshotList":{
      "type":"list",
      "member":{
        "shape":"Snapshot",
        "locationName":"item"
      }
    },
    "SnapshotRecycleBinInfo":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "RecycleBinEnterTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the snaphsot entered the Recycle Bin.</p>",
          "locationName":"recycleBinEnterTime"
        },
        "RecycleBinExitTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the snapshot is to be permanently deleted from the Recycle Bin.</p>",
          "locationName":"recycleBinExitTime"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description for the snapshot.</p>",
          "locationName":"description"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume from which the snapshot was created.</p>",
          "locationName":"volumeId"
        }
      },
      "documentation":"<p>Information about a snapshot that is currently in the Recycle Bin.</p>"
    },
    "SnapshotRecycleBinInfoList":{
      "type":"list",
      "member":{
        "shape":"SnapshotRecycleBinInfo",
        "locationName":"item"
      }
    },
    "SnapshotSet":{
      "type":"list",
      "member":{
        "shape":"SnapshotInfo",
        "locationName":"item"
      }
    },
    "SnapshotState":{
      "type":"string",
      "enum":[
        "pending",
        "completed",
        "error",
        "recoverable",
        "recovering"
      ]
    },
    "SnapshotTaskDetail":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the snapshot.</p>",
          "locationName":"description"
        },
        "DiskImageSize":{
          "shape":"Double",
          "documentation":"<p>The size of the disk in the snapshot, in GiB.</p>",
          "locationName":"diskImageSize"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the snapshot is encrypted.</p>",
          "locationName":"encrypted"
        },
        "Format":{
          "shape":"String",
          "documentation":"<p>The format of the disk image from which the snapshot is created.</p>",
          "locationName":"format"
        },
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The identifier for the KMS key that was used to create the encrypted snapshot.</p>",
          "locationName":"kmsKeyId"
        },
        "Progress":{
          "shape":"String",
          "documentation":"<p>The percentage of completion for the import snapshot task.</p>",
          "locationName":"progress"
        },
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The snapshot ID of the disk being imported.</p>",
          "locationName":"snapshotId"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>A brief status for the import snapshot task.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A detailed status message for the import snapshot task.</p>",
          "locationName":"statusMessage"
        },
        "Url":{
          "shape":"String",
          "documentation":"<p>The URL of the disk image from which the snapshot is created.</p>",
          "locationName":"url"
        },
        "UserBucket":{
          "shape":"UserBucketDetails",
          "documentation":"<p>The Amazon S3 bucket for the disk image.</p>",
          "locationName":"userBucket"
        }
      },
      "documentation":"<p>Details about the import snapshot task.</p>"
    },
    "SnapshotTierStatus":{
      "type":"structure",
      "members":{
        "SnapshotId":{
          "shape":"SnapshotId",
          "documentation":"<p>The ID of the snapshot.</p>",
          "locationName":"snapshotId"
        },
        "VolumeId":{
          "shape":"VolumeId",
          "documentation":"<p>The ID of the volume from which the snapshot was created.</p>",
          "locationName":"volumeId"
        },
        "Status":{
          "shape":"SnapshotState",
          "documentation":"<p>The state of the snapshot.</p>",
          "locationName":"status"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the snapshot.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags that are assigned to the snapshot.</p>",
          "locationName":"tagSet"
        },
        "StorageTier":{
          "shape":"StorageTier",
          "documentation":"<p>The storage tier in which the snapshot is stored. <code>standard</code> indicates that the snapshot is stored in the standard snapshot storage tier and that it is ready for use. <code>archive</code> indicates that the snapshot is currently archived and that it must be restored before it can be used.</p>",
          "locationName":"storageTier"
        },
        "LastTieringStartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the last archive or restore process was started.</p>",
          "locationName":"lastTieringStartTime"
        },
        "LastTieringProgress":{
          "shape":"Integer",
          "documentation":"<p>The progress of the last archive or restore process, as a percentage.</p>",
          "locationName":"lastTieringProgress"
        },
        "LastTieringOperationStatus":{
          "shape":"TieringOperationStatus",
          "documentation":"<p>The status of the last archive or restore process.</p>",
          "locationName":"lastTieringOperationStatus"
        },
        "LastTieringOperationStatusDetail":{
          "shape":"String",
          "documentation":"<p>A message describing the status of the last archive or restore process.</p>",
          "locationName":"lastTieringOperationStatusDetail"
        },
        "ArchivalCompleteTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time when the last archive process was completed.</p>",
          "locationName":"archivalCompleteTime"
        },
        "RestoreExpiryTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>Only for archived snapshots that are temporarily restored. Indicates the date and time when a temporarily restored snapshot will be automatically re-archived.</p>",
          "locationName":"restoreExpiryTime"
        }
      },
      "documentation":"<p>Provides information about a snapshot's storage tier.</p>"
    },
    "SpotAllocationStrategy":{
      "type":"string",
      "enum":[
        "lowest-price",
        "diversified",
        "capacity-optimized",
        "capacity-optimized-prioritized",
        "price-capacity-optimized"
      ]
    },
    "SpotCapacityRebalance":{
      "type":"structure",
      "members":{
        "ReplacementStrategy":{
          "shape":"ReplacementStrategy",
          "documentation":"<p>The replacement strategy to use. Only available for fleets of type <code>maintain</code>.</p> <p> <code>launch</code> - Spot Fleet launches a new replacement Spot Instance when a rebalance notification is emitted for an existing Spot Instance in the fleet. Spot Fleet does not terminate the instances that receive a rebalance notification. You can terminate the old instances, or you can leave them running. You are charged for all instances while they are running. </p> <p> <code>launch-before-terminate</code> - Spot Fleet launches a new replacement Spot Instance when a rebalance notification is emitted for an existing Spot Instance in the fleet, and then, after a delay that you specify (in <code>TerminationDelay</code>), terminates the instances that received a rebalance notification.</p>",
          "locationName":"replacementStrategy"
        },
        "TerminationDelay":{
          "shape":"Integer",
          "documentation":"<p>The amount of time (in seconds) that Amazon EC2 waits before terminating the old Spot Instance after launching a new replacement Spot Instance.</p> <p>Required when <code>ReplacementStrategy</code> is set to <code>launch-before-terminate</code>.</p> <p>Not valid when <code>ReplacementStrategy</code> is set to <code>launch</code>.</p> <p>Valid values: Minimum value of <code>120</code> seconds. Maximum value of <code>7200</code> seconds.</p>",
          "locationName":"terminationDelay"
        }
      },
      "documentation":"<p>The Spot Instance replacement strategy to use when Amazon EC2 emits a signal that your Spot Instance is at an elevated risk of being interrupted. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-capacity-rebalance.html\">Capacity rebalancing</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>"
    },
    "SpotDatafeedSubscription":{
      "type":"structure",
      "members":{
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket where the Spot Instance data feed is located.</p>",
          "locationName":"bucket"
        },
        "Fault":{
          "shape":"SpotInstanceStateFault",
          "documentation":"<p>The fault codes for the Spot Instance request, if any.</p>",
          "locationName":"fault"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account ID of the account.</p>",
          "locationName":"ownerId"
        },
        "Prefix":{
          "shape":"String",
          "documentation":"<p>The prefix for the data feed files.</p>",
          "locationName":"prefix"
        },
        "State":{
          "shape":"DatafeedSubscriptionState",
          "documentation":"<p>The state of the Spot Instance data feed subscription.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes the data feed for a Spot Instance.</p>"
    },
    "SpotFleetLaunchSpecification":{
      "type":"structure",
      "members":{
        "SecurityGroups":{
          "shape":"GroupIdentifierList",
          "documentation":"<p>One or more security groups. When requesting instances in a VPC, you must specify the IDs of the security groups. When requesting instances in EC2-Classic, you can specify the names or the IDs of the security groups.</p>",
          "locationName":"groupSet"
        },
        "AddressingType":{
          "shape":"String",
          "documentation":"<p>Deprecated.</p>",
          "locationName":"addressingType"
        },
        "BlockDeviceMappings":{
          "shape":"BlockDeviceMappingList",
          "documentation":"<p>One or more block devices that are mapped to the Spot Instances. You can't specify both a snapshot ID and an encryption value. This is because only blank volumes can be encrypted on creation. If a snapshot is the basis for a volume, it is not blank and its encryption status is used for the volume encryption status.</p>",
          "locationName":"blockDeviceMapping"
        },
        "EbsOptimized":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the instances are optimized for EBS I/O. This optimization provides dedicated throughput to Amazon EBS and an optimized configuration stack to provide optimal EBS I/O performance. This optimization isn't available with all instance types. Additional usage charges apply when using an EBS Optimized instance.</p> <p>Default: <code>false</code> </p>",
          "locationName":"ebsOptimized"
        },
        "IamInstanceProfile":{
          "shape":"IamInstanceProfileSpecification",
          "documentation":"<p>The IAM instance profile.</p>",
          "locationName":"iamInstanceProfile"
        },
        "ImageId":{
          "shape":"ImageId",
          "documentation":"<p>The ID of the AMI.</p>",
          "locationName":"imageId"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "KernelId":{
          "shape":"String",
          "documentation":"<p>The ID of the kernel.</p>",
          "locationName":"kernelId"
        },
        "KeyName":{
          "shape":"KeyPairName",
          "documentation":"<p>The name of the key pair.</p>",
          "locationName":"keyName"
        },
        "Monitoring":{
          "shape":"SpotFleetMonitoring",
          "documentation":"<p>Enable or disable monitoring for the instances.</p>",
          "locationName":"monitoring"
        },
        "NetworkInterfaces":{
          "shape":"InstanceNetworkInterfaceSpecificationList",
          "documentation":"<p>One or more network interfaces. If you specify a network interface, you must specify subnet IDs and security group IDs using the network interface.</p> <note> <p> <code>SpotFleetLaunchSpecification</code> currently does not support Elastic Fabric Adapter (EFA). To specify an EFA, you must use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_LaunchTemplateConfig.html\">LaunchTemplateConfig</a>.</p> </note>",
          "locationName":"networkInterfaceSet"
        },
        "Placement":{
          "shape":"SpotPlacement",
          "documentation":"<p>The placement information.</p>",
          "locationName":"placement"
        },
        "RamdiskId":{
          "shape":"String",
          "documentation":"<p>The ID of the RAM disk. Some kernels require additional drivers at launch. Check the kernel requirements for information about whether you need to specify a RAM disk. To find kernel requirements, refer to the Amazon Web Services Resource Center and search for the kernel ID.</p>",
          "locationName":"ramdiskId"
        },
        "SpotPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"spotPrice"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The IDs of the subnets in which to launch the instances. To specify multiple subnets, separate them using commas; for example, \"subnet-1234abcdeexample1, subnet-0987cdef6example2\".</p>",
          "locationName":"subnetId"
        },
        "UserData":{
          "shape":"SensitiveUserData",
          "documentation":"<p>The Base64-encoded user data that instances use when starting up.</p>",
          "locationName":"userData"
        },
        "WeightedCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units provided by the specified instance type. These are the same units that you chose to set the target capacity in terms of instances, or a performance characteristic such as vCPUs, memory, or I/O.</p> <p>If the target capacity divided by this value is not a whole number, Amazon EC2 rounds the number of instances to the next whole number. If this value is not specified, the default is 1.</p>",
          "locationName":"weightedCapacity"
        },
        "TagSpecifications":{
          "shape":"SpotFleetTagSpecificationList",
          "documentation":"<p>The tags to apply during creation.</p>",
          "locationName":"tagSpecificationSet"
        },
        "InstanceRequirements":{
          "shape":"InstanceRequirements",
          "documentation":"<p>The attributes for the instance types. When you specify instance attributes, Amazon EC2 will identify instance types with those attributes.</p> <note> <p>If you specify <code>InstanceRequirements</code>, you can't specify <code>InstanceType</code>.</p> </note>",
          "locationName":"instanceRequirements"
        }
      },
      "documentation":"<p>Describes the launch specification for one or more Spot Instances. If you include On-Demand capacity in your fleet request or want to specify an EFA network device, you can't use <code>SpotFleetLaunchSpecification</code>; you must use <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_LaunchTemplateConfig.html\">LaunchTemplateConfig</a>.</p>"
    },
    "SpotFleetMonitoring":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Enables monitoring for the instance.</p> <p>Default: <code>false</code> </p>",
          "locationName":"enabled"
        }
      },
      "documentation":"<p>Describes whether monitoring is enabled.</p>"
    },
    "SpotFleetRequestConfig":{
      "type":"structure",
      "members":{
        "ActivityStatus":{
          "shape":"ActivityStatus",
          "documentation":"<p>The progress of the Spot Fleet request. If there is an error, the status is <code>error</code>. After all requests are placed, the status is <code>pending_fulfillment</code>. If the size of the fleet is equal to or greater than its target capacity, the status is <code>fulfilled</code>. If the size of the fleet is decreased, the status is <code>pending_termination</code> while Spot Instances are terminating.</p>",
          "locationName":"activityStatus"
        },
        "CreateTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The creation date and time of the request.</p>",
          "locationName":"createTime"
        },
        "SpotFleetRequestConfig":{
          "shape":"SpotFleetRequestConfigData",
          "documentation":"<p>The configuration of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestConfig"
        },
        "SpotFleetRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestId"
        },
        "SpotFleetRequestState":{
          "shape":"BatchState",
          "documentation":"<p>The state of the Spot Fleet request.</p>",
          "locationName":"spotFleetRequestState"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for a Spot Fleet resource.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Spot Fleet request.</p>"
    },
    "SpotFleetRequestConfigData":{
      "type":"structure",
      "required":[
        "IamFleetRole",
        "TargetCapacity"
      ],
      "members":{
        "AllocationStrategy":{
          "shape":"AllocationStrategy",
          "documentation":"<p>The strategy that determines how to allocate the target Spot Instance capacity across the Spot Instance pools specified by the Spot Fleet launch configuration. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-allocation-strategy.html\">Allocation strategies for Spot Instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <dl> <dt>priceCapacityOptimized (recommended)</dt> <dd> <p>Spot Fleet identifies the pools with the highest capacity availability for the number of instances that are launching. This means that we will request Spot Instances from the pools that we believe have the lowest chance of interruption in the near term. Spot Fleet then requests Spot Instances from the lowest priced of these pools.</p> </dd> <dt>capacityOptimized</dt> <dd> <p>Spot Fleet identifies the pools with the highest capacity availability for the number of instances that are launching. This means that we will request Spot Instances from the pools that we believe have the lowest chance of interruption in the near term. To give certain instance types a higher chance of launching first, use <code>capacityOptimizedPrioritized</code>. Set a priority for each instance type by using the <code>Priority</code> parameter for <code>LaunchTemplateOverrides</code>. You can assign the same priority to different <code>LaunchTemplateOverrides</code>. EC2 implements the priorities on a best-effort basis, but optimizes for capacity first. <code>capacityOptimizedPrioritized</code> is supported only if your Spot Fleet uses a launch template. Note that if the <code>OnDemandAllocationStrategy</code> is set to <code>prioritized</code>, the same priority is applied when fulfilling On-Demand capacity.</p> </dd> <dt>diversified</dt> <dd> <p>Spot Fleet requests instances from all of the Spot Instance pools that you specify.</p> </dd> <dt>lowestPrice</dt> <dd> <p>Spot Fleet requests instances from the lowest priced Spot Instance pool that has available capacity. If the lowest priced pool doesn't have available capacity, the Spot Instances come from the next lowest priced pool that has available capacity. If a pool runs out of capacity before fulfilling your desired capacity, Spot Fleet will continue to fulfill your request by drawing from the next lowest priced pool. To ensure that your desired capacity is met, you might receive Spot Instances from several pools. Because this strategy only considers instance price and not capacity availability, it might lead to high interruption rates.</p> </dd> </dl> <p>Default: <code>lowestPrice</code> </p>",
          "locationName":"allocationStrategy"
        },
        "OnDemandAllocationStrategy":{
          "shape":"OnDemandAllocationStrategy",
          "documentation":"<p>The order of the launch template overrides to use in fulfilling On-Demand capacity. If you specify <code>lowestPrice</code>, Spot Fleet uses price to determine the order, launching the lowest price first. If you specify <code>prioritized</code>, Spot Fleet uses the priority that you assign to each Spot Fleet launch template override, launching the highest priority first. If you do not specify a value, Spot Fleet defaults to <code>lowestPrice</code>.</p>",
          "locationName":"onDemandAllocationStrategy"
        },
        "SpotMaintenanceStrategies":{
          "shape":"SpotMaintenanceStrategies",
          "documentation":"<p>The strategies for managing your Spot Instances that are at an elevated risk of being interrupted.</p>",
          "locationName":"spotMaintenanceStrategies"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>A unique, case-sensitive identifier that you provide to ensure the idempotency of your listings. This helps to avoid duplicate listings. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">Ensuring Idempotency</a>.</p>",
          "locationName":"clientToken"
        },
        "ExcessCapacityTerminationPolicy":{
          "shape":"ExcessCapacityTerminationPolicy",
          "documentation":"<p>Indicates whether running instances should be terminated if you decrease the target capacity of the Spot Fleet request below the current size of the Spot Fleet.</p> <p>Supported only for fleets of type <code>maintain</code>.</p>",
          "locationName":"excessCapacityTerminationPolicy"
        },
        "FulfilledCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of units fulfilled by this request compared to the set target capacity. You cannot set this value.</p>",
          "locationName":"fulfilledCapacity"
        },
        "OnDemandFulfilledCapacity":{
          "shape":"Double",
          "documentation":"<p>The number of On-Demand units fulfilled by this request compared to the set target On-Demand capacity.</p>",
          "locationName":"onDemandFulfilledCapacity"
        },
        "IamFleetRole":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of an Identity and Access Management (IAM) role that grants the Spot Fleet the permission to request, launch, terminate, and tag instances on your behalf. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-requests.html#spot-fleet-prerequisites\">Spot Fleet prerequisites</a> in the <i>Amazon EC2 User Guide</i>. Spot Fleet can terminate Spot Instances on your behalf when you cancel its Spot Fleet request using <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_CancelSpotFleetRequests\">CancelSpotFleetRequests</a> or when the Spot Fleet request expires, if you set <code>TerminateInstancesWithExpiration</code>.</p>",
          "locationName":"iamFleetRole"
        },
        "LaunchSpecifications":{
          "shape":"LaunchSpecsList",
          "documentation":"<p>The launch specifications for the Spot Fleet request. If you specify <code>LaunchSpecifications</code>, you can't specify <code>LaunchTemplateConfigs</code>. If you include On-Demand capacity in your request, you must use <code>LaunchTemplateConfigs</code>.</p>",
          "locationName":"launchSpecifications"
        },
        "LaunchTemplateConfigs":{
          "shape":"LaunchTemplateConfigList",
          "documentation":"<p>The launch template and overrides. If you specify <code>LaunchTemplateConfigs</code>, you can't specify <code>LaunchSpecifications</code>. If you include On-Demand capacity in your request, you must use <code>LaunchTemplateConfigs</code>.</p>",
          "locationName":"launchTemplateConfigs"
        },
        "SpotPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"spotPrice"
        },
        "TargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of units to request for the Spot Fleet. You can choose to set the target capacity in terms of instances or a performance characteristic that is important to your application workload, such as vCPUs, memory, or I/O. If the request type is <code>maintain</code>, you can specify a target capacity of 0 and add capacity later.</p>",
          "locationName":"targetCapacity"
        },
        "OnDemandTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of On-Demand units to request. You can choose to set the target capacity in terms of instances or a performance characteristic that is important to your application workload, such as vCPUs, memory, or I/O. If the request type is <code>maintain</code>, you can specify a target capacity of 0 and add capacity later.</p>",
          "locationName":"onDemandTargetCapacity"
        },
        "OnDemandMaxTotalPrice":{
          "shape":"String",
          "documentation":"<p>The maximum amount per hour for On-Demand Instances that you're willing to pay. You can use the <code>onDemandMaxTotalPrice</code> parameter, the <code>spotMaxTotalPrice</code> parameter, or both parameters to ensure that your fleet cost does not exceed your budget. If you set a maximum price per hour for the On-Demand Instances and Spot Instances in your request, Spot Fleet will launch instances until it reaches the maximum amount you're willing to pay. When the maximum amount you're willing to pay is reached, the fleet stops launching instances even if it hasn’t met the target capacity.</p>",
          "locationName":"onDemandMaxTotalPrice"
        },
        "SpotMaxTotalPrice":{
          "shape":"String",
          "documentation":"<p>The maximum amount per hour for Spot Instances that you're willing to pay. You can use the <code>spotdMaxTotalPrice</code> parameter, the <code>onDemandMaxTotalPrice</code> parameter, or both parameters to ensure that your fleet cost does not exceed your budget. If you set a maximum price per hour for the On-Demand Instances and Spot Instances in your request, Spot Fleet will launch instances until it reaches the maximum amount you're willing to pay. When the maximum amount you're willing to pay is reached, the fleet stops launching instances even if it hasn’t met the target capacity.</p>",
          "locationName":"spotMaxTotalPrice"
        },
        "TerminateInstancesWithExpiration":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether running Spot Instances are terminated when the Spot Fleet request expires.</p>",
          "locationName":"terminateInstancesWithExpiration"
        },
        "Type":{
          "shape":"FleetType",
          "documentation":"<p>The type of request. Indicates whether the Spot Fleet only requests the target capacity or also attempts to maintain it. When this value is <code>request</code>, the Spot Fleet only places the required requests. It does not attempt to replenish Spot Instances if capacity is diminished, nor does it submit requests in alternative Spot pools if capacity is not available. When this value is <code>maintain</code>, the Spot Fleet maintains the target capacity. The Spot Fleet places the required requests to meet capacity and automatically replenishes any interrupted instances. Default: <code>maintain</code>. <code>instant</code> is listed but is not used by Spot Fleet.</p>",
          "locationName":"type"
        },
        "ValidFrom":{
          "shape":"DateTime",
          "documentation":"<p>The start date and time of the request, in UTC format (<i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). By default, Amazon EC2 starts fulfilling the request immediately.</p>",
          "locationName":"validFrom"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date and time of the request, in UTC format (<i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). After the end date and time, no new Spot Instance requests are placed or able to fulfill the request. If no value is specified, the Spot Fleet request remains until you cancel it.</p>",
          "locationName":"validUntil"
        },
        "ReplaceUnhealthyInstances":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether Spot Fleet should replace unhealthy instances.</p>",
          "locationName":"replaceUnhealthyInstances"
        },
        "InstanceInterruptionBehavior":{
          "shape":"InstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted. The default is <code>terminate</code>.</p>",
          "locationName":"instanceInterruptionBehavior"
        },
        "LoadBalancersConfig":{
          "shape":"LoadBalancersConfig",
          "documentation":"<p>One or more Classic Load Balancers and target groups to attach to the Spot Fleet request. Spot Fleet registers the running Spot Instances with the specified Classic Load Balancers and target groups.</p> <p>With Network Load Balancers, Spot Fleet cannot register instances that have the following instance types: C1, CC1, CC2, CG1, CG2, CR1, CS1, G1, G2, HI1, HS1, M1, M2, M3, and T1.</p>",
          "locationName":"loadBalancersConfig"
        },
        "InstancePoolsToUseCount":{
          "shape":"Integer",
          "documentation":"<p>The number of Spot pools across which to allocate your target Spot capacity. Valid only when Spot <b>AllocationStrategy</b> is set to <code>lowest-price</code>. Spot Fleet selects the cheapest Spot pools and evenly allocates your target Spot capacity across the number of Spot pools that you specify.</p> <p>Note that Spot Fleet attempts to draw Spot Instances from the number of pools that you specify on a best effort basis. If a pool runs out of Spot capacity before fulfilling your target capacity, Spot Fleet will continue to fulfill your request by drawing from the next cheapest pool. To ensure that your target capacity is met, you might receive Spot Instances from more than the number of pools that you specified. Similarly, if most of the pools have no Spot capacity, you might receive your full target capacity from fewer than the number of pools that you specified.</p>",
          "locationName":"instancePoolsToUseCount"
        },
        "Context":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>",
          "locationName":"context"
        },
        "TargetCapacityUnitType":{
          "shape":"TargetCapacityUnitType",
          "documentation":"<p>The unit for the target capacity. <code>TargetCapacityUnitType</code> can only be specified when <code>InstanceRequirements</code> is specified.</p> <p>Default: <code>units</code> (translates to number of instances)</p>",
          "locationName":"targetCapacityUnitType"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The key-value pair for tagging the Spot Fleet request on creation. The value for <code>ResourceType</code> must be <code>spot-fleet-request</code>, otherwise the Spot Fleet request fails. To tag instances at launch, specify the tags in the <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-launch-templates.html#create-launch-template\">launch template</a> (valid only if you use <code>LaunchTemplateConfigs</code>) or in the <code> <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SpotFleetTagSpecification.html\">SpotFleetTagSpecification</a> </code> (valid only if you use <code>LaunchSpecifications</code>). For information about tagging after launch, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Using_Tags.html#tag-resources\">Tagging Your Resources</a>.</p>",
          "locationName":"TagSpecification"
        }
      },
      "documentation":"<p>Describes the configuration of a Spot Fleet request.</p>"
    },
    "SpotFleetRequestConfigSet":{
      "type":"list",
      "member":{
        "shape":"SpotFleetRequestConfig",
        "locationName":"item"
      }
    },
    "SpotFleetRequestId":{"type":"string"},
    "SpotFleetRequestIdList":{
      "type":"list",
      "member":{
        "shape":"SpotFleetRequestId",
        "locationName":"item"
      }
    },
    "SpotFleetTagSpecification":{
      "type":"structure",
      "members":{
        "ResourceType":{
          "shape":"ResourceType",
          "documentation":"<p>The type of resource. Currently, the only resource type that is supported is <code>instance</code>. To tag the Spot Fleet request on creation, use the <code>TagSpecifications</code> parameter in <code> <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SpotFleetRequestConfigData.html\">SpotFleetRequestConfigData</a> </code>.</p>",
          "locationName":"resourceType"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tag"
        }
      },
      "documentation":"<p>The tags for a Spot Fleet resource.</p>"
    },
    "SpotFleetTagSpecificationList":{
      "type":"list",
      "member":{
        "shape":"SpotFleetTagSpecification",
        "locationName":"item"
      }
    },
    "SpotInstanceInterruptionBehavior":{
      "type":"string",
      "enum":[
        "hibernate",
        "stop",
        "terminate"
      ]
    },
    "SpotInstanceRequest":{
      "type":"structure",
      "members":{
        "ActualBlockHourlyPrice":{
          "shape":"String",
          "documentation":"<p>Deprecated.</p>",
          "locationName":"actualBlockHourlyPrice"
        },
        "AvailabilityZoneGroup":{
          "shape":"String",
          "documentation":"<p>The Availability Zone group. If you specify the same Availability Zone group for all Spot Instance requests, all Spot Instances are launched in the same Availability Zone.</p>",
          "locationName":"availabilityZoneGroup"
        },
        "BlockDurationMinutes":{
          "shape":"Integer",
          "documentation":"<p>Deprecated.</p>",
          "locationName":"blockDurationMinutes"
        },
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time when the Spot Instance request was created, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"createTime"
        },
        "Fault":{
          "shape":"SpotInstanceStateFault",
          "documentation":"<p>The fault codes for the Spot Instance request, if any.</p>",
          "locationName":"fault"
        },
        "InstanceId":{
          "shape":"InstanceId",
          "documentation":"<p>The instance ID, if an instance has been launched to fulfill the Spot Instance request.</p>",
          "locationName":"instanceId"
        },
        "LaunchGroup":{
          "shape":"String",
          "documentation":"<p>The instance launch group. Launch groups are Spot Instances that launch together and terminate together.</p>",
          "locationName":"launchGroup"
        },
        "LaunchSpecification":{
          "shape":"LaunchSpecification",
          "documentation":"<p>Additional information for launching instances.</p>",
          "locationName":"launchSpecification"
        },
        "LaunchedAvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone in which the request is launched.</p>",
          "locationName":"launchedAvailabilityZone"
        },
        "ProductDescription":{
          "shape":"RIProductDescription",
          "documentation":"<p>The product description associated with the Spot Instance.</p>",
          "locationName":"productDescription"
        },
        "SpotInstanceRequestId":{
          "shape":"String",
          "documentation":"<p>The ID of the Spot Instance request.</p>",
          "locationName":"spotInstanceRequestId"
        },
        "SpotPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"spotPrice"
        },
        "State":{
          "shape":"SpotInstanceState",
          "documentation":"<p>The state of the Spot Instance request. Spot request status information helps track your Spot Instance requests. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-request-status.html\">Spot request status</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>",
          "locationName":"state"
        },
        "Status":{
          "shape":"SpotInstanceStatus",
          "documentation":"<p>The status code and status message describing the Spot Instance request.</p>",
          "locationName":"status"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the resource.</p>",
          "locationName":"tagSet"
        },
        "Type":{
          "shape":"SpotInstanceType",
          "documentation":"<p>The Spot Instance request type.</p>",
          "locationName":"type"
        },
        "ValidFrom":{
          "shape":"DateTime",
          "documentation":"<p>The start date of the request, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). The request becomes active at this date and time.</p>",
          "locationName":"validFrom"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date of the request, in UTC format (<i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p> <ul> <li> <p>For a persistent request, the request remains active until the <code>validUntil</code> date and time is reached. Otherwise, the request remains active until you cancel it. </p> </li> <li> <p>For a one-time request, the request remains active until all instances launch, the request is canceled, or the <code>validUntil</code> date and time is reached. By default, the request is valid for 7 days from the date the request was created.</p> </li> </ul>",
          "locationName":"validUntil"
        },
        "InstanceInterruptionBehavior":{
          "shape":"InstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted.</p>",
          "locationName":"instanceInterruptionBehavior"
        }
      },
      "documentation":"<p>Describes a Spot Instance request.</p>"
    },
    "SpotInstanceRequestId":{"type":"string"},
    "SpotInstanceRequestIdList":{
      "type":"list",
      "member":{
        "shape":"SpotInstanceRequestId",
        "locationName":"SpotInstanceRequestId"
      }
    },
    "SpotInstanceRequestList":{
      "type":"list",
      "member":{
        "shape":"SpotInstanceRequest",
        "locationName":"item"
      }
    },
    "SpotInstanceState":{
      "type":"string",
      "enum":[
        "open",
        "active",
        "closed",
        "cancelled",
        "failed"
      ]
    },
    "SpotInstanceStateFault":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The reason code for the Spot Instance state change.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The message for the Spot Instance state change.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes a Spot Instance state change.</p>"
    },
    "SpotInstanceStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The status code. For a list of status codes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-request-status.html#spot-instance-request-status-understand\">Spot request status codes</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The description for the status code.</p>",
          "locationName":"message"
        },
        "UpdateTime":{
          "shape":"DateTime",
          "documentation":"<p>The date and time of the most recent status update, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"updateTime"
        }
      },
      "documentation":"<p>Describes the status of a Spot Instance request.</p>"
    },
    "SpotInstanceType":{
      "type":"string",
      "enum":[
        "one-time",
        "persistent"
      ]
    },
    "SpotMaintenanceStrategies":{
      "type":"structure",
      "members":{
        "CapacityRebalance":{
          "shape":"SpotCapacityRebalance",
          "documentation":"<p>The Spot Instance replacement strategy to use when Amazon EC2 emits a signal that your Spot Instance is at an elevated risk of being interrupted. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/spot-fleet-capacity-rebalance.html\">Capacity rebalancing</a> in the <i>Amazon EC2 User Guide for Linux Instances</i>.</p>",
          "locationName":"capacityRebalance"
        }
      },
      "documentation":"<p>The strategies for managing your Spot Instances that are at an elevated risk of being interrupted.</p>"
    },
    "SpotMarketOptions":{
      "type":"structure",
      "members":{
        "MaxPrice":{
          "shape":"String",
          "documentation":"<p>The maximum hourly price that you're willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your Spot Instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>"
        },
        "SpotInstanceType":{
          "shape":"SpotInstanceType",
          "documentation":"<p>The Spot Instance request type. For <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_RunInstances\">RunInstances</a>, persistent Spot Instance requests are only supported when the instance interruption behavior is either <code>hibernate</code> or <code>stop</code>.</p>"
        },
        "BlockDurationMinutes":{
          "shape":"Integer",
          "documentation":"<p>Deprecated.</p>"
        },
        "ValidUntil":{
          "shape":"DateTime",
          "documentation":"<p>The end date of the request, in UTC format (<i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z). Supported only for persistent requests.</p> <ul> <li> <p>For a persistent request, the request remains active until the <code>ValidUntil</code> date and time is reached. Otherwise, the request remains active until you cancel it.</p> </li> <li> <p>For a one-time request, <code>ValidUntil</code> is not supported. The request remains active until all instances launch or you cancel the request.</p> </li> </ul>"
        },
        "InstanceInterruptionBehavior":{
          "shape":"InstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted. The default is <code>terminate</code>.</p>"
        }
      },
      "documentation":"<p>The options for Spot Instances.</p>"
    },
    "SpotOptions":{
      "type":"structure",
      "members":{
        "AllocationStrategy":{
          "shape":"SpotAllocationStrategy",
          "documentation":"<p>The strategy that determines how to allocate the target Spot Instance capacity across the Spot Instance pools specified by the EC2 Fleet launch configuration. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-allocation-strategy.html\">Allocation strategies for Spot Instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <dl> <dt>price-capacity-optimized (recommended)</dt> <dd> <p>EC2 Fleet identifies the pools with the highest capacity availability for the number of instances that are launching. This means that we will request Spot Instances from the pools that we believe have the lowest chance of interruption in the near term. EC2 Fleet then requests Spot Instances from the lowest priced of these pools.</p> </dd> <dt>capacity-optimized</dt> <dd> <p>EC2 Fleet identifies the pools with the highest capacity availability for the number of instances that are launching. This means that we will request Spot Instances from the pools that we believe have the lowest chance of interruption in the near term. To give certain instance types a higher chance of launching first, use <code>capacity-optimized-prioritized</code>. Set a priority for each instance type by using the <code>Priority</code> parameter for <code>LaunchTemplateOverrides</code>. You can assign the same priority to different <code>LaunchTemplateOverrides</code>. EC2 implements the priorities on a best-effort basis, but optimizes for capacity first. <code>capacity-optimized-prioritized</code> is supported only if your EC2 Fleet uses a launch template. Note that if the On-Demand <code>AllocationStrategy</code> is set to <code>prioritized</code>, the same priority is applied when fulfilling On-Demand capacity.</p> </dd> <dt>diversified</dt> <dd> <p>EC2 Fleet requests instances from all of the Spot Instance pools that you specify.</p> </dd> <dt>lowest-price</dt> <dd> <p>EC2 Fleet requests instances from the lowest priced Spot Instance pool that has available capacity. If the lowest priced pool doesn't have available capacity, the Spot Instances come from the next lowest priced pool that has available capacity. If a pool runs out of capacity before fulfilling your desired capacity, EC2 Fleet will continue to fulfill your request by drawing from the next lowest priced pool. To ensure that your desired capacity is met, you might receive Spot Instances from several pools. Because this strategy only considers instance price and not capacity availability, it might lead to high interruption rates.</p> </dd> </dl> <p>Default: <code>lowest-price</code> </p>",
          "locationName":"allocationStrategy"
        },
        "MaintenanceStrategies":{
          "shape":"FleetSpotMaintenanceStrategies",
          "documentation":"<p>The strategies for managing your workloads on your Spot Instances that will be interrupted. Currently only the capacity rebalance strategy is available.</p>",
          "locationName":"maintenanceStrategies"
        },
        "InstanceInterruptionBehavior":{
          "shape":"SpotInstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted.</p> <p>Default: <code>terminate</code> </p>",
          "locationName":"instanceInterruptionBehavior"
        },
        "InstancePoolsToUseCount":{
          "shape":"Integer",
          "documentation":"<p>The number of Spot pools across which to allocate your target Spot capacity. Supported only when <code>AllocationStrategy</code> is set to <code>lowest-price</code>. EC2 Fleet selects the cheapest Spot pools and evenly allocates your target Spot capacity across the number of Spot pools that you specify.</p> <p>Note that EC2 Fleet attempts to draw Spot Instances from the number of pools that you specify on a best effort basis. If a pool runs out of Spot capacity before fulfilling your target capacity, EC2 Fleet will continue to fulfill your request by drawing from the next cheapest pool. To ensure that your target capacity is met, you might receive Spot Instances from more than the number of pools that you specified. Similarly, if most of the pools have no Spot capacity, you might receive your full target capacity from fewer than the number of pools that you specified.</p>",
          "locationName":"instancePoolsToUseCount"
        },
        "SingleInstanceType":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet uses a single instance type to launch all Spot Instances in the fleet.</p> <p>Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"singleInstanceType"
        },
        "SingleAvailabilityZone":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet launches all Spot Instances into a single Availability Zone.</p> <p>Supported only for fleets of type <code>instant</code>.</p>",
          "locationName":"singleAvailabilityZone"
        },
        "MinTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The minimum target capacity for Spot Instances in the fleet. If the minimum target capacity is not reached, the fleet launches no instances.</p> <p>Supported only for fleets of type <code>instant</code>.</p> <p>At least one of the following must be specified: <code>SingleAvailabilityZone</code> | <code>SingleInstanceType</code> </p>",
          "locationName":"minTargetCapacity"
        },
        "MaxTotalPrice":{
          "shape":"String",
          "documentation":"<p>The maximum amount per hour for Spot Instances that you're willing to pay. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your Spot Instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"maxTotalPrice"
        }
      },
      "documentation":"<p>Describes the configuration of Spot Instances in an EC2 Fleet.</p>"
    },
    "SpotOptionsRequest":{
      "type":"structure",
      "members":{
        "AllocationStrategy":{
          "shape":"SpotAllocationStrategy",
          "documentation":"<p>The strategy that determines how to allocate the target Spot Instance capacity across the Spot Instance pools specified by the EC2 Fleet launch configuration. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-fleet-allocation-strategy.html\">Allocation strategies for Spot Instances</a> in the <i>Amazon EC2 User Guide</i>.</p> <dl> <dt>price-capacity-optimized (recommended)</dt> <dd> <p>EC2 Fleet identifies the pools with the highest capacity availability for the number of instances that are launching. This means that we will request Spot Instances from the pools that we believe have the lowest chance of interruption in the near term. EC2 Fleet then requests Spot Instances from the lowest priced of these pools.</p> </dd> <dt>capacity-optimized</dt> <dd> <p>EC2 Fleet identifies the pools with the highest capacity availability for the number of instances that are launching. This means that we will request Spot Instances from the pools that we believe have the lowest chance of interruption in the near term. To give certain instance types a higher chance of launching first, use <code>capacity-optimized-prioritized</code>. Set a priority for each instance type by using the <code>Priority</code> parameter for <code>LaunchTemplateOverrides</code>. You can assign the same priority to different <code>LaunchTemplateOverrides</code>. EC2 implements the priorities on a best-effort basis, but optimizes for capacity first. <code>capacity-optimized-prioritized</code> is supported only if your EC2 Fleet uses a launch template. Note that if the On-Demand <code>AllocationStrategy</code> is set to <code>prioritized</code>, the same priority is applied when fulfilling On-Demand capacity.</p> </dd> <dt>diversified</dt> <dd> <p>EC2 Fleet requests instances from all of the Spot Instance pools that you specify.</p> </dd> <dt>lowest-price</dt> <dd> <p>EC2 Fleet requests instances from the lowest priced Spot Instance pool that has available capacity. If the lowest priced pool doesn't have available capacity, the Spot Instances come from the next lowest priced pool that has available capacity. If a pool runs out of capacity before fulfilling your desired capacity, EC2 Fleet will continue to fulfill your request by drawing from the next lowest priced pool. To ensure that your desired capacity is met, you might receive Spot Instances from several pools. Because this strategy only considers instance price and not capacity availability, it might lead to high interruption rates.</p> </dd> </dl> <p>Default: <code>lowest-price</code> </p>"
        },
        "MaintenanceStrategies":{
          "shape":"FleetSpotMaintenanceStrategiesRequest",
          "documentation":"<p>The strategies for managing your Spot Instances that are at an elevated risk of being interrupted.</p>"
        },
        "InstanceInterruptionBehavior":{
          "shape":"SpotInstanceInterruptionBehavior",
          "documentation":"<p>The behavior when a Spot Instance is interrupted.</p> <p>Default: <code>terminate</code> </p>"
        },
        "InstancePoolsToUseCount":{
          "shape":"Integer",
          "documentation":"<p>The number of Spot pools across which to allocate your target Spot capacity. Supported only when Spot <code>AllocationStrategy</code> is set to <code>lowest-price</code>. EC2 Fleet selects the cheapest Spot pools and evenly allocates your target Spot capacity across the number of Spot pools that you specify.</p> <p>Note that EC2 Fleet attempts to draw Spot Instances from the number of pools that you specify on a best effort basis. If a pool runs out of Spot capacity before fulfilling your target capacity, EC2 Fleet will continue to fulfill your request by drawing from the next cheapest pool. To ensure that your target capacity is met, you might receive Spot Instances from more than the number of pools that you specified. Similarly, if most of the pools have no Spot capacity, you might receive your full target capacity from fewer than the number of pools that you specified.</p>"
        },
        "SingleInstanceType":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet uses a single instance type to launch all Spot Instances in the fleet.</p> <p>Supported only for fleets of type <code>instant</code>.</p>"
        },
        "SingleAvailabilityZone":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the fleet launches all Spot Instances into a single Availability Zone.</p> <p>Supported only for fleets of type <code>instant</code>.</p>"
        },
        "MinTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The minimum target capacity for Spot Instances in the fleet. If the minimum target capacity is not reached, the fleet launches no instances.</p> <p>Supported only for fleets of type <code>instant</code>.</p> <p>At least one of the following must be specified: <code>SingleAvailabilityZone</code> | <code>SingleInstanceType</code> </p>"
        },
        "MaxTotalPrice":{
          "shape":"String",
          "documentation":"<p>The maximum amount per hour for Spot Instances that you're willing to pay. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your Spot Instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>"
        }
      },
      "documentation":"<p>Describes the configuration of Spot Instances in an EC2 Fleet request.</p>"
    },
    "SpotPlacement":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p> <p>[Spot Fleet only] To specify multiple Availability Zones, separate them using commas; for example, \"us-west-2a, us-west-2b\".</p>",
          "locationName":"availabilityZone"
        },
        "GroupName":{
          "shape":"PlacementGroupName",
          "documentation":"<p>The name of the placement group.</p>",
          "locationName":"groupName"
        },
        "Tenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The tenancy of the instance (if the instance is running in a VPC). An instance with a tenancy of <code>dedicated</code> runs on single-tenant hardware. The <code>host</code> tenancy is not supported for Spot Instances.</p>",
          "locationName":"tenancy"
        }
      },
      "documentation":"<p>Describes Spot Instance placement.</p>"
    },
    "SpotPlacementScore":{
      "type":"structure",
      "members":{
        "Region":{
          "shape":"String",
          "documentation":"<p>The Region.</p>",
          "locationName":"region"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZoneId"
        },
        "Score":{
          "shape":"Integer",
          "documentation":"<p>The placement score, on a scale from <code>1</code> to <code>10</code>. A score of <code>10</code> indicates that your Spot request is highly likely to succeed in this Region or Availability Zone. A score of <code>1</code> indicates that your Spot request is not likely to succeed. </p>",
          "locationName":"score"
        }
      },
      "documentation":"<p>The Spot placement score for this Region or Availability Zone. The score is calculated based on the assumption that the <code>capacity-optimized</code> allocation strategy is used and that all of the Availability Zones in the Region can be used.</p>"
    },
    "SpotPlacementScores":{
      "type":"list",
      "member":{
        "shape":"SpotPlacementScore",
        "locationName":"item"
      }
    },
    "SpotPlacementScoresMaxResults":{
      "type":"integer",
      "max":1000,
      "min":10
    },
    "SpotPlacementScoresTargetCapacity":{
      "type":"integer",
      "max":2000000000,
      "min":1
    },
    "SpotPrice":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone.</p>",
          "locationName":"availabilityZone"
        },
        "InstanceType":{
          "shape":"InstanceType",
          "documentation":"<p>The instance type.</p>",
          "locationName":"instanceType"
        },
        "ProductDescription":{
          "shape":"RIProductDescription",
          "documentation":"<p>A general description of the AMI.</p>",
          "locationName":"productDescription"
        },
        "SpotPrice":{
          "shape":"String",
          "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>",
          "locationName":"spotPrice"
        },
        "Timestamp":{
          "shape":"DateTime",
          "documentation":"<p>The date and time the request was created, in UTC format (for example, <i>YYYY</i>-<i>MM</i>-<i>DD</i>T<i>HH</i>:<i>MM</i>:<i>SS</i>Z).</p>",
          "locationName":"timestamp"
        }
      },
      "documentation":"<p>The maximum price per unit hour that you are willing to pay for a Spot Instance. We do not recommend using this parameter because it can lead to increased interruptions. If you do not specify this parameter, you will pay the current Spot price.</p> <important> <p>If you specify a maximum price, your instances will be interrupted more frequently than if you do not specify this parameter.</p> </important>"
    },
    "SpotPriceHistoryList":{
      "type":"list",
      "member":{
        "shape":"SpotPrice",
        "locationName":"item"
      }
    },
    "SpreadLevel":{
      "type":"string",
      "enum":[
        "host",
        "rack"
      ]
    },
    "StaleIpPermission":{
      "type":"structure",
      "members":{
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>The start of the port range for the TCP and UDP protocols, or an ICMP type number. A value of -1 indicates all ICMP types. </p>",
          "locationName":"fromPort"
        },
        "IpProtocol":{
          "shape":"String",
          "documentation":"<p>The IP protocol name (for <code>tcp</code>, <code>udp</code>, and <code>icmp</code>) or number (see <a href=\"http://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml\">Protocol Numbers)</a>.</p>",
          "locationName":"ipProtocol"
        },
        "IpRanges":{
          "shape":"IpRanges",
          "documentation":"<p>The IP ranges. Not applicable for stale security group rules.</p>",
          "locationName":"ipRanges"
        },
        "PrefixListIds":{
          "shape":"PrefixListIdSet",
          "documentation":"<p>The prefix list IDs. Not applicable for stale security group rules.</p>",
          "locationName":"prefixListIds"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>The end of the port range for the TCP and UDP protocols, or an ICMP type number. A value of <code>-1</code> indicates all ICMP types. </p>",
          "locationName":"toPort"
        },
        "UserIdGroupPairs":{
          "shape":"UserIdGroupPairSet",
          "documentation":"<p>The security group pairs. Returns the ID of the referenced security group and VPC, and the ID and status of the VPC peering connection.</p>",
          "locationName":"groups"
        }
      },
      "documentation":"<p>Describes a stale rule in a security group.</p>"
    },
    "StaleIpPermissionSet":{
      "type":"list",
      "member":{
        "shape":"StaleIpPermission",
        "locationName":"item"
      }
    },
    "StaleSecurityGroup":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the security group.</p>",
          "locationName":"description"
        },
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the security group.</p>",
          "locationName":"groupName"
        },
        "StaleIpPermissions":{
          "shape":"StaleIpPermissionSet",
          "documentation":"<p>Information about the stale inbound rules in the security group.</p>",
          "locationName":"staleIpPermissions"
        },
        "StaleIpPermissionsEgress":{
          "shape":"StaleIpPermissionSet",
          "documentation":"<p>Information about the stale outbound rules in the security group.</p>",
          "locationName":"staleIpPermissionsEgress"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC for the security group.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<p>Describes a stale security group (a security group that contains stale rules).</p>"
    },
    "StaleSecurityGroupSet":{
      "type":"list",
      "member":{
        "shape":"StaleSecurityGroup",
        "locationName":"item"
      }
    },
    "StartInstancesRequest":{
      "type":"structure",
      "required":["InstanceIds"],
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The IDs of the instances.</p>",
          "locationName":"InstanceId"
        },
        "AdditionalInfo":{
          "shape":"String",
          "documentation":"<p>Reserved.</p>",
          "locationName":"additionalInfo"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "StartInstancesResult":{
      "type":"structure",
      "members":{
        "StartingInstances":{
          "shape":"InstanceStateChangeList",
          "documentation":"<p>Information about the started instances.</p>",
          "locationName":"instancesSet"
        }
      }
    },
    "StartNetworkInsightsAccessScopeAnalysisRequest":{
      "type":"structure",
      "required":[
        "NetworkInsightsAccessScopeId",
        "ClientToken"
      ],
      "members":{
        "NetworkInsightsAccessScopeId":{
          "shape":"NetworkInsightsAccessScopeId",
          "documentation":"<p>The ID of the Network Access Scope.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "StartNetworkInsightsAccessScopeAnalysisResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAccessScopeAnalysis":{
          "shape":"NetworkInsightsAccessScopeAnalysis",
          "documentation":"<p>The Network Access Scope analysis.</p>",
          "locationName":"networkInsightsAccessScopeAnalysis"
        }
      }
    },
    "StartNetworkInsightsAnalysisRequest":{
      "type":"structure",
      "required":[
        "NetworkInsightsPathId",
        "ClientToken"
      ],
      "members":{
        "NetworkInsightsPathId":{
          "shape":"NetworkInsightsPathId",
          "documentation":"<p>The ID of the path.</p>"
        },
        "AdditionalAccounts":{
          "shape":"ValueStringList",
          "documentation":"<p>The member accounts that contain resources that the path can traverse.</p>",
          "locationName":"AdditionalAccount"
        },
        "FilterInArns":{
          "shape":"ArnList",
          "documentation":"<p>The Amazon Resource Names (ARN) of the resources that the path must traverse.</p>",
          "locationName":"FilterInArn"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "TagSpecifications":{
          "shape":"TagSpecificationList",
          "documentation":"<p>The tags to apply.</p>",
          "locationName":"TagSpecification"
        },
        "ClientToken":{
          "shape":"String",
          "documentation":"<p>Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html\">How to ensure idempotency</a>.</p>",
          "idempotencyToken":true
        }
      }
    },
    "StartNetworkInsightsAnalysisResult":{
      "type":"structure",
      "members":{
        "NetworkInsightsAnalysis":{
          "shape":"NetworkInsightsAnalysis",
          "documentation":"<p>Information about the network insights analysis.</p>",
          "locationName":"networkInsightsAnalysis"
        }
      }
    },
    "StartVpcEndpointServicePrivateDnsVerificationRequest":{
      "type":"structure",
      "required":["ServiceId"],
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "ServiceId":{
          "shape":"VpcEndpointServiceId",
          "documentation":"<p>The ID of the endpoint service.</p>"
        }
      }
    },
    "StartVpcEndpointServicePrivateDnsVerificationResult":{
      "type":"structure",
      "members":{
        "ReturnValue":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, it returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "State":{
      "type":"string",
      "enum":[
        "PendingAcceptance",
        "Pending",
        "Available",
        "Deleting",
        "Deleted",
        "Rejected",
        "Failed",
        "Expired"
      ]
    },
    "StateReason":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The reason code for the state change.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The message for the state change.</p> <ul> <li> <p> <code>Server.InsufficientInstanceCapacity</code>: There was insufficient capacity available to satisfy the launch request.</p> </li> <li> <p> <code>Server.InternalError</code>: An internal error caused the instance to terminate during launch.</p> </li> <li> <p> <code>Server.ScheduledStop</code>: The instance was stopped due to a scheduled retirement.</p> </li> <li> <p> <code>Server.SpotInstanceShutdown</code>: The instance was stopped because the number of Spot requests with a maximum price equal to or higher than the Spot price exceeded available capacity or because of an increase in the Spot price.</p> </li> <li> <p> <code>Server.SpotInstanceTermination</code>: The instance was terminated because the number of Spot requests with a maximum price equal to or higher than the Spot price exceeded available capacity or because of an increase in the Spot price.</p> </li> <li> <p> <code>Client.InstanceInitiatedShutdown</code>: The instance was shut down using the <code>shutdown -h</code> command from the instance.</p> </li> <li> <p> <code>Client.InstanceTerminated</code>: The instance was terminated or rebooted during AMI creation.</p> </li> <li> <p> <code>Client.InternalError</code>: A client error caused the instance to terminate during launch.</p> </li> <li> <p> <code>Client.InvalidSnapshot.NotFound</code>: The specified snapshot was not found.</p> </li> <li> <p> <code>Client.UserInitiatedHibernate</code>: Hibernation was initiated on the instance.</p> </li> <li> <p> <code>Client.UserInitiatedShutdown</code>: The instance was shut down using the Amazon EC2 API.</p> </li> <li> <p> <code>Client.VolumeLimitExceeded</code>: The limit on the number of EBS volumes or total storage was exceeded. Decrease usage or request an increase in your account limits.</p> </li> </ul>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes a state change.</p>"
    },
    "StaticSourcesSupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "StatisticType":{
      "type":"string",
      "enum":["p50"]
    },
    "Status":{
      "type":"string",
      "enum":[
        "MoveInProgress",
        "InVpc",
        "InClassic"
      ]
    },
    "StatusName":{
      "type":"string",
      "enum":["reachability"]
    },
    "StatusType":{
      "type":"string",
      "enum":[
        "passed",
        "failed",
        "insufficient-data",
        "initializing"
      ]
    },
    "StopInstancesRequest":{
      "type":"structure",
      "required":["InstanceIds"],
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The IDs of the instances.</p>",
          "locationName":"InstanceId"
        },
        "Hibernate":{
          "shape":"Boolean",
          "documentation":"<p>Hibernates the instance if the instance was enabled for hibernation at launch. If the instance cannot hibernate successfully, a normal shutdown occurs. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/Hibernate.html\">Hibernate your instance</a> in the <i>Amazon EC2 User Guide</i>.</p> <p> Default: <code>false</code> </p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        },
        "Force":{
          "shape":"Boolean",
          "documentation":"<p>Forces the instances to stop. The instances do not have an opportunity to flush file system caches or file system metadata. If you use this option, you must perform file system check and repair procedures. This option is not recommended for Windows instances.</p> <p>Default: <code>false</code> </p>",
          "locationName":"force"
        }
      }
    },
    "StopInstancesResult":{
      "type":"structure",
      "members":{
        "StoppingInstances":{
          "shape":"InstanceStateChangeList",
          "documentation":"<p>Information about the stopped instances.</p>",
          "locationName":"instancesSet"
        }
      }
    },
    "Storage":{
      "type":"structure",
      "members":{
        "S3":{
          "shape":"S3Storage",
          "documentation":"<p>An Amazon S3 storage location.</p>"
        }
      },
      "documentation":"<p>Describes the storage location for an instance store-backed AMI.</p>"
    },
    "StorageLocation":{
      "type":"structure",
      "members":{
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the S3 bucket.</p>"
        },
        "Key":{
          "shape":"String",
          "documentation":"<p>The key.</p>"
        }
      },
      "documentation":"<p>Describes a storage location in Amazon S3.</p>"
    },
    "StorageTier":{
      "type":"string",
      "enum":[
        "archive",
        "standard"
      ]
    },
    "StoreImageTaskResult":{
      "type":"structure",
      "members":{
        "AmiId":{
          "shape":"String",
          "documentation":"<p>The ID of the AMI that is being stored.</p>",
          "locationName":"amiId"
        },
        "TaskStartTime":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The time the task started.</p>",
          "locationName":"taskStartTime"
        },
        "Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket that contains the stored AMI object.</p>",
          "locationName":"bucket"
        },
        "S3objectKey":{
          "shape":"String",
          "documentation":"<p>The name of the stored AMI object in the bucket.</p>",
          "locationName":"s3objectKey"
        },
        "ProgressPercentage":{
          "shape":"Integer",
          "documentation":"<p>The progress of the task as a percentage.</p>",
          "locationName":"progressPercentage"
        },
        "StoreTaskState":{
          "shape":"String",
          "documentation":"<p>The state of the store task (<code>InProgress</code>, <code>Completed</code>, or <code>Failed</code>).</p>",
          "locationName":"storeTaskState"
        },
        "StoreTaskFailureReason":{
          "shape":"String",
          "documentation":"<p>If the tasks fails, the reason for the failure is returned. If the task succeeds, <code>null</code> is returned.</p>",
          "locationName":"storeTaskFailureReason"
        }
      },
      "documentation":"<p>The information about the AMI store task, including the progress of the task.</p>"
    },
    "StoreImageTaskResultSet":{
      "type":"list",
      "member":{
        "shape":"StoreImageTaskResult",
        "locationName":"item"
      }
    },
    "String":{"type":"string"},
    "StringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "StringType":{
      "type":"string",
      "max":64000,
      "min":0
    },
    "Subnet":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone of the subnet.</p>",
          "locationName":"availabilityZone"
        },
        "AvailabilityZoneId":{
          "shape":"String",
          "documentation":"<p>The AZ ID of the subnet.</p>",
          "locationName":"availabilityZoneId"
        },
        "AvailableIpAddressCount":{
          "shape":"Integer",
          "documentation":"<p>The number of unused private IPv4 addresses in the subnet. The IPv4 addresses for any stopped instances are considered unavailable.</p>",
          "locationName":"availableIpAddressCount"
        },
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR block assigned to the subnet.</p>",
          "locationName":"cidrBlock"
        },
        "DefaultForAz":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is the default subnet for the Availability Zone.</p>",
          "locationName":"defaultForAz"
        },
        "EnableLniAtDeviceIndex":{
          "shape":"Integer",
          "documentation":"<p> Indicates the device position for local network interfaces in this subnet. For example, <code>1</code> indicates local network interfaces in this subnet are the secondary network interface (eth1). </p>",
          "locationName":"enableLniAtDeviceIndex"
        },
        "MapPublicIpOnLaunch":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether instances launched in this subnet receive a public IPv4 address.</p>",
          "locationName":"mapPublicIpOnLaunch"
        },
        "MapCustomerOwnedIpOnLaunch":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether a network interface created in this subnet (including a network interface created by <a>RunInstances</a>) receives a customer-owned IPv4 address.</p>",
          "locationName":"mapCustomerOwnedIpOnLaunch"
        },
        "CustomerOwnedIpv4Pool":{
          "shape":"CoipPoolId",
          "documentation":"<p>The customer-owned IPv4 address pool associated with the subnet.</p>",
          "locationName":"customerOwnedIpv4Pool"
        },
        "State":{
          "shape":"SubnetState",
          "documentation":"<p>The current state of the subnet.</p>",
          "locationName":"state"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC the subnet is in.</p>",
          "locationName":"vpcId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the subnet.</p>",
          "locationName":"ownerId"
        },
        "AssignIpv6AddressOnCreation":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether a network interface created in this subnet (including a network interface created by <a>RunInstances</a>) receives an IPv6 address.</p>",
          "locationName":"assignIpv6AddressOnCreation"
        },
        "Ipv6CidrBlockAssociationSet":{
          "shape":"SubnetIpv6CidrBlockAssociationSet",
          "documentation":"<p>Information about the IPv6 CIDR blocks associated with the subnet.</p>",
          "locationName":"ipv6CidrBlockAssociationSet"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the subnet.</p>",
          "locationName":"tagSet"
        },
        "SubnetArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the subnet.</p>",
          "locationName":"subnetArn"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "EnableDns64":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether DNS queries made to the Amazon-provided DNS Resolver in this subnet should return synthetic IPv6 addresses for IPv4-only destinations.</p>",
          "locationName":"enableDns64"
        },
        "Ipv6Native":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is an IPv6 only subnet.</p>",
          "locationName":"ipv6Native"
        },
        "PrivateDnsNameOptionsOnLaunch":{
          "shape":"PrivateDnsNameOptionsOnLaunch",
          "documentation":"<p>The type of hostnames to assign to instances in the subnet at launch. An instance hostname is based on the IPv4 address or ID of the instance.</p>",
          "locationName":"privateDnsNameOptionsOnLaunch"
        }
      },
      "documentation":"<p>Describes a subnet.</p>"
    },
    "SubnetAssociation":{
      "type":"structure",
      "members":{
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "State":{
          "shape":"TransitGatewayMulitcastDomainAssociationState",
          "documentation":"<p>The state of the subnet association.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes the subnet association with the transit gateway multicast domain.</p>"
    },
    "SubnetAssociationList":{
      "type":"list",
      "member":{
        "shape":"SubnetAssociation",
        "locationName":"item"
      }
    },
    "SubnetCidrAssociationId":{"type":"string"},
    "SubnetCidrBlockState":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"SubnetCidrBlockStateCode",
          "documentation":"<p>The state of a CIDR block.</p>",
          "locationName":"state"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A message about the status of the CIDR block, if applicable.</p>",
          "locationName":"statusMessage"
        }
      },
      "documentation":"<p>Describes the state of a CIDR block.</p>"
    },
    "SubnetCidrBlockStateCode":{
      "type":"string",
      "enum":[
        "associating",
        "associated",
        "disassociating",
        "disassociated",
        "failing",
        "failed"
      ]
    },
    "SubnetCidrReservation":{
      "type":"structure",
      "members":{
        "SubnetCidrReservationId":{
          "shape":"SubnetCidrReservationId",
          "documentation":"<p>The ID of the subnet CIDR reservation.</p>",
          "locationName":"subnetCidrReservationId"
        },
        "SubnetId":{
          "shape":"SubnetId",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The CIDR that has been reserved.</p>",
          "locationName":"cidr"
        },
        "ReservationType":{
          "shape":"SubnetCidrReservationType",
          "documentation":"<p>The type of reservation. </p>",
          "locationName":"reservationType"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the account that owns the subnet CIDR reservation. </p>",
          "locationName":"ownerId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description assigned to the subnet CIDR reservation.</p>",
          "locationName":"description"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the subnet CIDR reservation.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a subnet CIDR reservation.</p>"
    },
    "SubnetCidrReservationId":{"type":"string"},
    "SubnetCidrReservationList":{
      "type":"list",
      "member":{
        "shape":"SubnetCidrReservation",
        "locationName":"item"
      }
    },
    "SubnetCidrReservationType":{
      "type":"string",
      "enum":[
        "prefix",
        "explicit"
      ]
    },
    "SubnetId":{"type":"string"},
    "SubnetIdStringList":{
      "type":"list",
      "member":{
        "shape":"SubnetId",
        "locationName":"SubnetId"
      }
    },
    "SubnetIpv6CidrBlockAssociation":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"SubnetCidrAssociationId",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"associationId"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block.</p>",
          "locationName":"ipv6CidrBlock"
        },
        "Ipv6CidrBlockState":{
          "shape":"SubnetCidrBlockState",
          "documentation":"<p>The state of the CIDR block.</p>",
          "locationName":"ipv6CidrBlockState"
        }
      },
      "documentation":"<p>Describes an association between a subnet and an IPv6 CIDR block.</p>"
    },
    "SubnetIpv6CidrBlockAssociationSet":{
      "type":"list",
      "member":{
        "shape":"SubnetIpv6CidrBlockAssociation",
        "locationName":"item"
      }
    },
    "SubnetList":{
      "type":"list",
      "member":{
        "shape":"Subnet",
        "locationName":"item"
      }
    },
    "SubnetState":{
      "type":"string",
      "enum":[
        "pending",
        "available"
      ]
    },
    "Subscription":{
      "type":"structure",
      "members":{
        "Source":{
          "shape":"String",
          "documentation":"<p>The Region or Availability Zone that's the source for the subscription. For example, <code>us-east-1</code>.</p>",
          "locationName":"source"
        },
        "Destination":{
          "shape":"String",
          "documentation":"<p>The Region or Availability Zone that's the target for the subscription. For example, <code>eu-west-1</code>.</p>",
          "locationName":"destination"
        },
        "Metric":{
          "shape":"MetricType",
          "documentation":"<p>The metric used for the subscription.</p>",
          "locationName":"metric"
        },
        "Statistic":{
          "shape":"StatisticType",
          "documentation":"<p>The statistic used for the subscription.</p>",
          "locationName":"statistic"
        },
        "Period":{
          "shape":"PeriodType",
          "documentation":"<p>The data aggregation time for the subscription.</p>",
          "locationName":"period"
        }
      },
      "documentation":"<p>Describes an Infrastructure Performance subscription.</p>"
    },
    "SubscriptionList":{
      "type":"list",
      "member":{
        "shape":"Subscription",
        "locationName":"item"
      }
    },
    "SuccessfulInstanceCreditSpecificationItem":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        }
      },
      "documentation":"<p>Describes the burstable performance instance whose credit option for CPU usage was successfully modified.</p>"
    },
    "SuccessfulInstanceCreditSpecificationSet":{
      "type":"list",
      "member":{
        "shape":"SuccessfulInstanceCreditSpecificationItem",
        "locationName":"item"
      }
    },
    "SuccessfulQueuedPurchaseDeletion":{
      "type":"structure",
      "members":{
        "ReservedInstancesId":{
          "shape":"String",
          "documentation":"<p>The ID of the Reserved Instance.</p>",
          "locationName":"reservedInstancesId"
        }
      },
      "documentation":"<p>Describes a Reserved Instance whose queued purchase was successfully deleted.</p>"
    },
    "SuccessfulQueuedPurchaseDeletionSet":{
      "type":"list",
      "member":{
        "shape":"SuccessfulQueuedPurchaseDeletion",
        "locationName":"item"
      }
    },
    "SummaryStatus":{
      "type":"string",
      "enum":[
        "ok",
        "impaired",
        "insufficient-data",
        "not-applicable",
        "initializing"
      ]
    },
    "SupportedIpAddressTypes":{
      "type":"list",
      "member":{
        "shape":"ServiceConnectivityType",
        "locationName":"item"
      },
      "max":2,
      "min":0
    },
    "Tag":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "documentation":"<p>The key of the tag.</p> <p>Constraints: Tag keys are case-sensitive and accept a maximum of 127 Unicode characters. May not begin with <code>aws:</code>.</p>",
          "locationName":"key"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The value of the tag.</p> <p>Constraints: Tag values are case-sensitive and accept a maximum of 256 Unicode characters.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>Describes a tag.</p>"
    },
    "TagDescription":{
      "type":"structure",
      "members":{
        "Key":{
          "shape":"String",
          "documentation":"<p>The tag key.</p>",
          "locationName":"key"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"ResourceType",
          "documentation":"<p>The resource type.</p>",
          "locationName":"resourceType"
        },
        "Value":{
          "shape":"String",
          "documentation":"<p>The tag value.</p>",
          "locationName":"value"
        }
      },
      "documentation":"<p>Describes a tag.</p>"
    },
    "TagDescriptionList":{
      "type":"list",
      "member":{
        "shape":"TagDescription",
        "locationName":"item"
      }
    },
    "TagList":{
      "type":"list",
      "member":{
        "shape":"Tag",
        "locationName":"item"
      }
    },
    "TagSpecification":{
      "type":"structure",
      "members":{
        "ResourceType":{
          "shape":"ResourceType",
          "documentation":"<p>The type of resource to tag on creation.</p>",
          "locationName":"resourceType"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags to apply to the resource.</p>",
          "locationName":"Tag"
        }
      },
      "documentation":"<p>The tags to apply to a resource when the resource is being created. When you specify a tag, you must specify the resource type to tag, otherwise the request will fail.</p> <note> <p>The <code>Valid Values</code> lists all the resource types that can be tagged. However, the action you're using might not support tagging all of these resource types. If you try to tag a resource type that is unsupported for the action you're using, you'll get an error.</p> </note>"
    },
    "TagSpecificationList":{
      "type":"list",
      "member":{
        "shape":"TagSpecification",
        "locationName":"item"
      }
    },
    "TaggableResourceId":{"type":"string"},
    "TargetCapacitySpecification":{
      "type":"structure",
      "members":{
        "TotalTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of units to request, filled using <code>DefaultTargetCapacityType</code>.</p>",
          "locationName":"totalTargetCapacity"
        },
        "OnDemandTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of On-Demand units to request. If you specify a target capacity for Spot units, you cannot specify a target capacity for On-Demand units.</p>",
          "locationName":"onDemandTargetCapacity"
        },
        "SpotTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of Spot units to launch. If you specify a target capacity for On-Demand units, you cannot specify a target capacity for Spot units.</p>",
          "locationName":"spotTargetCapacity"
        },
        "DefaultTargetCapacityType":{
          "shape":"DefaultTargetCapacityType",
          "documentation":"<p>The default <code>TotalTargetCapacity</code>, which is either <code>Spot</code> or <code>On-Demand</code>.</p>",
          "locationName":"defaultTargetCapacityType"
        },
        "TargetCapacityUnitType":{
          "shape":"TargetCapacityUnitType",
          "documentation":"<p>The unit for the target capacity. <code>TargetCapacityUnitType</code> can only be specified when <code>InstanceRequirements</code> is specified.</p> <p>Default: <code>units</code> (translates to number of instances)</p>",
          "locationName":"targetCapacityUnitType"
        }
      },
      "documentation":"<p>The number of units to request. You can choose to set the target capacity in terms of instances or a performance characteristic that is important to your application workload, such as vCPUs, memory, or I/O. If the request type is <code>maintain</code>, you can specify a target capacity of 0 and add capacity later.</p> <p>You can use the On-Demand Instance <code>MaxTotalPrice</code> parameter, the Spot Instance <code>MaxTotalPrice</code>, or both to ensure that your fleet cost does not exceed your budget. If you set a maximum price per hour for the On-Demand Instances and Spot Instances in your request, EC2 Fleet will launch instances until it reaches the maximum amount that you're willing to pay. When the maximum amount you're willing to pay is reached, the fleet stops launching instances even if it hasn’t met the target capacity. The <code>MaxTotalPrice</code> parameters are located in <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_OnDemandOptions.html\">OnDemandOptions</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SpotOptions\">SpotOptions</a>.</p>"
    },
    "TargetCapacitySpecificationRequest":{
      "type":"structure",
      "required":["TotalTargetCapacity"],
      "members":{
        "TotalTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of units to request, filled using <code>DefaultTargetCapacityType</code>.</p>"
        },
        "OnDemandTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of On-Demand units to request.</p>"
        },
        "SpotTargetCapacity":{
          "shape":"Integer",
          "documentation":"<p>The number of Spot units to request.</p>"
        },
        "DefaultTargetCapacityType":{
          "shape":"DefaultTargetCapacityType",
          "documentation":"<p>The default <code>TotalTargetCapacity</code>, which is either <code>Spot</code> or <code>On-Demand</code>.</p>"
        },
        "TargetCapacityUnitType":{
          "shape":"TargetCapacityUnitType",
          "documentation":"<p>The unit for the target capacity. <code>TargetCapacityUnitType</code> can only be specified when <code>InstanceRequirements</code> is specified.</p> <p>Default: <code>units</code> (translates to number of instances)</p>"
        }
      },
      "documentation":"<p>The number of units to request. You can choose to set the target capacity as the number of instances. Or you can set the target capacity to a performance characteristic that is important to your application workload, such as vCPUs, memory, or I/O. If the request type is <code>maintain</code>, you can specify a target capacity of 0 and add capacity later.</p> <p>You can use the On-Demand Instance <code>MaxTotalPrice</code> parameter, the Spot Instance <code>MaxTotalPrice</code> parameter, or both parameters to ensure that your fleet cost does not exceed your budget. If you set a maximum price per hour for the On-Demand Instances and Spot Instances in your request, EC2 Fleet will launch instances until it reaches the maximum amount that you're willing to pay. When the maximum amount you're willing to pay is reached, the fleet stops launching instances even if it hasn’t met the target capacity. The <code>MaxTotalPrice</code> parameters are located in <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_OnDemandOptionsRequest\">OnDemandOptionsRequest</a> and <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_SpotOptionsRequest\">SpotOptionsRequest</a>.</p>"
    },
    "TargetCapacityUnitType":{
      "type":"string",
      "enum":[
        "vcpu",
        "memory-mib",
        "units"
      ]
    },
    "TargetConfiguration":{
      "type":"structure",
      "members":{
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances the Convertible Reserved Instance offering can be applied to. This parameter is reserved and cannot be specified in a request</p>",
          "locationName":"instanceCount"
        },
        "OfferingId":{
          "shape":"String",
          "documentation":"<p>The ID of the Convertible Reserved Instance offering.</p>",
          "locationName":"offeringId"
        }
      },
      "documentation":"<p>Information about the Convertible Reserved Instance offering.</p>"
    },
    "TargetConfigurationRequest":{
      "type":"structure",
      "required":["OfferingId"],
      "members":{
        "InstanceCount":{
          "shape":"Integer",
          "documentation":"<p>The number of instances the Convertible Reserved Instance offering can be applied to. This parameter is reserved and cannot be specified in a request</p>"
        },
        "OfferingId":{
          "shape":"ReservedInstancesOfferingId",
          "documentation":"<p>The Convertible Reserved Instance offering ID.</p>"
        }
      },
      "documentation":"<p>Details about the target configuration.</p>"
    },
    "TargetConfigurationRequestSet":{
      "type":"list",
      "member":{
        "shape":"TargetConfigurationRequest",
        "locationName":"TargetConfigurationRequest"
      }
    },
    "TargetGroup":{
      "type":"structure",
      "members":{
        "Arn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the target group.</p>",
          "locationName":"arn"
        }
      },
      "documentation":"<p>Describes a load balancer target group.</p>"
    },
    "TargetGroups":{
      "type":"list",
      "member":{
        "shape":"TargetGroup",
        "locationName":"item"
      },
      "max":5,
      "min":1
    },
    "TargetGroupsConfig":{
      "type":"structure",
      "members":{
        "TargetGroups":{
          "shape":"TargetGroups",
          "documentation":"<p>One or more target groups.</p>",
          "locationName":"targetGroups"
        }
      },
      "documentation":"<p>Describes the target groups to attach to a Spot Fleet. Spot Fleet registers the running Spot Instances with these target groups.</p>"
    },
    "TargetNetwork":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"associationId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC in which the target network (subnet) is located.</p>",
          "locationName":"vpcId"
        },
        "TargetNetworkId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet specified as the target network.</p>",
          "locationName":"targetNetworkId"
        },
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint with which the target network is associated.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "Status":{
          "shape":"AssociationStatus",
          "documentation":"<p>The current state of the target network association.</p>",
          "locationName":"status"
        },
        "SecurityGroups":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the security groups applied to the target network association.</p>",
          "locationName":"securityGroups"
        }
      },
      "documentation":"<p>Describes a target network associated with a Client VPN endpoint.</p>"
    },
    "TargetNetworkSet":{
      "type":"list",
      "member":{
        "shape":"TargetNetwork",
        "locationName":"item"
      }
    },
    "TargetReservationValue":{
      "type":"structure",
      "members":{
        "ReservationValue":{
          "shape":"ReservationValue",
          "documentation":"<p>The total value of the Convertible Reserved Instances that make up the exchange. This is the sum of the list value, remaining upfront price, and additional upfront cost of the exchange.</p>",
          "locationName":"reservationValue"
        },
        "TargetConfiguration":{
          "shape":"TargetConfiguration",
          "documentation":"<p>The configuration of the Convertible Reserved Instances that make up the exchange.</p>",
          "locationName":"targetConfiguration"
        }
      },
      "documentation":"<p>The total value of the new Convertible Reserved Instances.</p>"
    },
    "TargetReservationValueSet":{
      "type":"list",
      "member":{
        "shape":"TargetReservationValue",
        "locationName":"item"
      }
    },
    "TargetStorageTier":{
      "type":"string",
      "enum":["archive"]
    },
    "TelemetryStatus":{
      "type":"string",
      "enum":[
        "UP",
        "DOWN"
      ]
    },
    "Tenancy":{
      "type":"string",
      "enum":[
        "default",
        "dedicated",
        "host"
      ]
    },
    "TerminateClientVpnConnectionsRequest":{
      "type":"structure",
      "required":["ClientVpnEndpointId"],
      "members":{
        "ClientVpnEndpointId":{
          "shape":"ClientVpnEndpointId",
          "documentation":"<p>The ID of the Client VPN endpoint to which the client is connected.</p>"
        },
        "ConnectionId":{
          "shape":"VpnConnectionId",
          "documentation":"<p>The ID of the client connection to be terminated.</p>"
        },
        "Username":{
          "shape":"String",
          "documentation":"<p>The name of the user who initiated the connection. Use this option to terminate all active connections for the specified user. This option can only be used if the user has established up to five connections.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "TerminateClientVpnConnectionsResult":{
      "type":"structure",
      "members":{
        "ClientVpnEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Client VPN endpoint.</p>",
          "locationName":"clientVpnEndpointId"
        },
        "Username":{
          "shape":"String",
          "documentation":"<p>The user who established the terminated client connections.</p>",
          "locationName":"username"
        },
        "ConnectionStatuses":{
          "shape":"TerminateConnectionStatusSet",
          "documentation":"<p>The current state of the client connections.</p>",
          "locationName":"connectionStatuses"
        }
      }
    },
    "TerminateConnectionStatus":{
      "type":"structure",
      "members":{
        "ConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the client connection.</p>",
          "locationName":"connectionId"
        },
        "PreviousStatus":{
          "shape":"ClientVpnConnectionStatus",
          "documentation":"<p>The state of the client connection.</p>",
          "locationName":"previousStatus"
        },
        "CurrentStatus":{
          "shape":"ClientVpnConnectionStatus",
          "documentation":"<p>A message about the status of the client connection, if applicable.</p>",
          "locationName":"currentStatus"
        }
      },
      "documentation":"<p>Information about a terminated Client VPN endpoint client connection.</p>"
    },
    "TerminateConnectionStatusSet":{
      "type":"list",
      "member":{
        "shape":"TerminateConnectionStatus",
        "locationName":"item"
      }
    },
    "TerminateInstancesRequest":{
      "type":"structure",
      "required":["InstanceIds"],
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The IDs of the instances.</p> <p>Constraints: Up to 1000 instance IDs. We recommend breaking up this request into smaller batches.</p>",
          "locationName":"InstanceId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "TerminateInstancesResult":{
      "type":"structure",
      "members":{
        "TerminatingInstances":{
          "shape":"InstanceStateChangeList",
          "documentation":"<p>Information about the terminated instances.</p>",
          "locationName":"instancesSet"
        }
      }
    },
    "ThreadsPerCore":{"type":"integer"},
    "ThreadsPerCoreList":{
      "type":"list",
      "member":{
        "shape":"ThreadsPerCore",
        "locationName":"item"
      }
    },
    "ThroughResourcesStatement":{
      "type":"structure",
      "members":{
        "ResourceStatement":{
          "shape":"ResourceStatement",
          "documentation":"<p>The resource statement.</p>",
          "locationName":"resourceStatement"
        }
      },
      "documentation":"<p>Describes a through resource statement.</p>"
    },
    "ThroughResourcesStatementList":{
      "type":"list",
      "member":{
        "shape":"ThroughResourcesStatement",
        "locationName":"item"
      }
    },
    "ThroughResourcesStatementRequest":{
      "type":"structure",
      "members":{
        "ResourceStatement":{
          "shape":"ResourceStatementRequest",
          "documentation":"<p>The resource statement.</p>"
        }
      },
      "documentation":"<p>Describes a through resource statement.</p>"
    },
    "ThroughResourcesStatementRequestList":{
      "type":"list",
      "member":{
        "shape":"ThroughResourcesStatementRequest",
        "locationName":"item"
      }
    },
    "TieringOperationStatus":{
      "type":"string",
      "enum":[
        "archival-in-progress",
        "archival-completed",
        "archival-failed",
        "temporary-restore-in-progress",
        "temporary-restore-completed",
        "temporary-restore-failed",
        "permanent-restore-in-progress",
        "permanent-restore-completed",
        "permanent-restore-failed"
      ]
    },
    "TotalLocalStorageGB":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Double",
          "documentation":"<p>The minimum amount of total local storage, in GB. If this parameter is not specified, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Double",
          "documentation":"<p>The maximum amount of total local storage, in GB. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum amount of total local storage, in GB.</p>"
    },
    "TotalLocalStorageGBRequest":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Double",
          "documentation":"<p>The minimum amount of total local storage, in GB. To specify no minimum limit, omit this parameter.</p>"
        },
        "Max":{
          "shape":"Double",
          "documentation":"<p>The maximum amount of total local storage, in GB. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum amount of total local storage, in GB.</p>"
    },
    "TpmSupportValues":{
      "type":"string",
      "enum":["v2.0"]
    },
    "TrafficDirection":{
      "type":"string",
      "enum":[
        "ingress",
        "egress"
      ]
    },
    "TrafficMirrorFilter":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>",
          "locationName":"trafficMirrorFilterId"
        },
        "IngressFilterRules":{
          "shape":"TrafficMirrorFilterRuleList",
          "documentation":"<p>Information about the ingress rules that are associated with the Traffic Mirror filter.</p>",
          "locationName":"ingressFilterRuleSet"
        },
        "EgressFilterRules":{
          "shape":"TrafficMirrorFilterRuleList",
          "documentation":"<p>Information about the egress rules that are associated with the Traffic Mirror filter.</p>",
          "locationName":"egressFilterRuleSet"
        },
        "NetworkServices":{
          "shape":"TrafficMirrorNetworkServiceList",
          "documentation":"<p>The network service traffic that is associated with the Traffic Mirror filter.</p>",
          "locationName":"networkServiceSet"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror filter.</p>",
          "locationName":"description"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the Traffic Mirror filter.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes the Traffic Mirror filter.</p>"
    },
    "TrafficMirrorFilterId":{"type":"string"},
    "TrafficMirrorFilterIdList":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorFilterId",
        "locationName":"item"
      }
    },
    "TrafficMirrorFilterRule":{
      "type":"structure",
      "members":{
        "TrafficMirrorFilterRuleId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror rule.</p>",
          "locationName":"trafficMirrorFilterRuleId"
        },
        "TrafficMirrorFilterId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror filter that the rule is associated with.</p>",
          "locationName":"trafficMirrorFilterId"
        },
        "TrafficDirection":{
          "shape":"TrafficDirection",
          "documentation":"<p>The traffic direction assigned to the Traffic Mirror rule.</p>",
          "locationName":"trafficDirection"
        },
        "RuleNumber":{
          "shape":"Integer",
          "documentation":"<p>The rule number of the Traffic Mirror rule.</p>",
          "locationName":"ruleNumber"
        },
        "RuleAction":{
          "shape":"TrafficMirrorRuleAction",
          "documentation":"<p>The action assigned to the Traffic Mirror rule.</p>",
          "locationName":"ruleAction"
        },
        "Protocol":{
          "shape":"Integer",
          "documentation":"<p>The protocol assigned to the Traffic Mirror rule.</p>",
          "locationName":"protocol"
        },
        "DestinationPortRange":{
          "shape":"TrafficMirrorPortRange",
          "documentation":"<p>The destination port range assigned to the Traffic Mirror rule.</p>",
          "locationName":"destinationPortRange"
        },
        "SourcePortRange":{
          "shape":"TrafficMirrorPortRange",
          "documentation":"<p>The source port range assigned to the Traffic Mirror rule.</p>",
          "locationName":"sourcePortRange"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The destination CIDR block assigned to the Traffic Mirror rule.</p>",
          "locationName":"destinationCidrBlock"
        },
        "SourceCidrBlock":{
          "shape":"String",
          "documentation":"<p>The source CIDR block assigned to the Traffic Mirror rule.</p>",
          "locationName":"sourceCidrBlock"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror rule.</p>",
          "locationName":"description"
        }
      },
      "documentation":"<p>Describes the Traffic Mirror rule.</p>"
    },
    "TrafficMirrorFilterRuleField":{
      "type":"string",
      "enum":[
        "destination-port-range",
        "source-port-range",
        "protocol",
        "description"
      ]
    },
    "TrafficMirrorFilterRuleFieldList":{
      "type":"list",
      "member":{"shape":"TrafficMirrorFilterRuleField"}
    },
    "TrafficMirrorFilterRuleIdWithResolver":{"type":"string"},
    "TrafficMirrorFilterRuleList":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorFilterRule",
        "locationName":"item"
      }
    },
    "TrafficMirrorFilterSet":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorFilter",
        "locationName":"item"
      }
    },
    "TrafficMirrorNetworkService":{
      "type":"string",
      "enum":["amazon-dns"]
    },
    "TrafficMirrorNetworkServiceList":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorNetworkService",
        "locationName":"item"
      }
    },
    "TrafficMirrorPortRange":{
      "type":"structure",
      "members":{
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>The start of the Traffic Mirror port range. This applies to the TCP and UDP protocols.</p>",
          "locationName":"fromPort"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>The end of the Traffic Mirror port range. This applies to the TCP and UDP protocols.</p>",
          "locationName":"toPort"
        }
      },
      "documentation":"<p>Describes the Traffic Mirror port range.</p>"
    },
    "TrafficMirrorPortRangeRequest":{
      "type":"structure",
      "members":{
        "FromPort":{
          "shape":"Integer",
          "documentation":"<p>The first port in the Traffic Mirror port range. This applies to the TCP and UDP protocols.</p>"
        },
        "ToPort":{
          "shape":"Integer",
          "documentation":"<p>The last port in the Traffic Mirror port range. This applies to the TCP and UDP protocols.</p>"
        }
      },
      "documentation":"<p>Information about the Traffic Mirror filter rule port range.</p>"
    },
    "TrafficMirrorRuleAction":{
      "type":"string",
      "enum":[
        "accept",
        "reject"
      ]
    },
    "TrafficMirrorSession":{
      "type":"structure",
      "members":{
        "TrafficMirrorSessionId":{
          "shape":"String",
          "documentation":"<p>The ID for the Traffic Mirror session.</p>",
          "locationName":"trafficMirrorSessionId"
        },
        "TrafficMirrorTargetId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror target.</p>",
          "locationName":"trafficMirrorTargetId"
        },
        "TrafficMirrorFilterId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror filter.</p>",
          "locationName":"trafficMirrorFilterId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror session's network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the account that owns the Traffic Mirror session.</p>",
          "locationName":"ownerId"
        },
        "PacketLength":{
          "shape":"Integer",
          "documentation":"<p>The number of bytes in each packet to mirror. These are the bytes after the VXLAN header. To mirror a subset, set this to the length (in bytes) to mirror. For example, if you set this value to 100, then the first 100 bytes that meet the filter criteria are copied to the target. Do not specify this parameter when you want to mirror the entire packet</p>",
          "locationName":"packetLength"
        },
        "SessionNumber":{
          "shape":"Integer",
          "documentation":"<p>The session number determines the order in which sessions are evaluated when an interface is used by multiple sessions. The first session with a matching filter is the one that mirrors the packets.</p> <p>Valid values are 1-32766.</p>",
          "locationName":"sessionNumber"
        },
        "VirtualNetworkId":{
          "shape":"Integer",
          "documentation":"<p>The virtual network ID associated with the Traffic Mirror session.</p>",
          "locationName":"virtualNetworkId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the Traffic Mirror session.</p>",
          "locationName":"description"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the Traffic Mirror session.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Traffic Mirror session.</p>"
    },
    "TrafficMirrorSessionField":{
      "type":"string",
      "enum":[
        "packet-length",
        "description",
        "virtual-network-id"
      ]
    },
    "TrafficMirrorSessionFieldList":{
      "type":"list",
      "member":{"shape":"TrafficMirrorSessionField"}
    },
    "TrafficMirrorSessionId":{"type":"string"},
    "TrafficMirrorSessionIdList":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorSessionId",
        "locationName":"item"
      }
    },
    "TrafficMirrorSessionSet":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorSession",
        "locationName":"item"
      }
    },
    "TrafficMirrorTarget":{
      "type":"structure",
      "members":{
        "TrafficMirrorTargetId":{
          "shape":"String",
          "documentation":"<p>The ID of the Traffic Mirror target.</p>",
          "locationName":"trafficMirrorTargetId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The network interface ID that is attached to the target.</p>",
          "locationName":"networkInterfaceId"
        },
        "NetworkLoadBalancerArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Network Load Balancer.</p>",
          "locationName":"networkLoadBalancerArn"
        },
        "Type":{
          "shape":"TrafficMirrorTargetType",
          "documentation":"<p>The type of Traffic Mirror target.</p>",
          "locationName":"type"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>Information about the Traffic Mirror target.</p>",
          "locationName":"description"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the account that owns the Traffic Mirror target.</p>",
          "locationName":"ownerId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the Traffic Mirror target.</p>",
          "locationName":"tagSet"
        },
        "GatewayLoadBalancerEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Gateway Load Balancer endpoint.</p>",
          "locationName":"gatewayLoadBalancerEndpointId"
        }
      },
      "documentation":"<p>Describes a Traffic Mirror target.</p>"
    },
    "TrafficMirrorTargetId":{"type":"string"},
    "TrafficMirrorTargetIdList":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorTargetId",
        "locationName":"item"
      }
    },
    "TrafficMirrorTargetSet":{
      "type":"list",
      "member":{
        "shape":"TrafficMirrorTarget",
        "locationName":"item"
      }
    },
    "TrafficMirrorTargetType":{
      "type":"string",
      "enum":[
        "network-interface",
        "network-load-balancer",
        "gateway-load-balancer-endpoint"
      ]
    },
    "TrafficMirroringMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "TrafficType":{
      "type":"string",
      "enum":[
        "ACCEPT",
        "REJECT",
        "ALL"
      ]
    },
    "TransitAssociationGatewayId":{"type":"string"},
    "TransitGateway":{
      "type":"structure",
      "members":{
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "TransitGatewayArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the transit gateway.</p>",
          "locationName":"transitGatewayArn"
        },
        "State":{
          "shape":"TransitGatewayState",
          "documentation":"<p>The state of the transit gateway.</p>",
          "locationName":"state"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the transit gateway.</p>",
          "locationName":"ownerId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of the transit gateway.</p>",
          "locationName":"description"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "Options":{
          "shape":"TransitGatewayOptions",
          "documentation":"<p>The transit gateway options.</p>",
          "locationName":"options"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the transit gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a transit gateway.</p>"
    },
    "TransitGatewayAssociation":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type. Note that the <code>tgw-peering</code> resource type has been deprecated.</p>",
          "locationName":"resourceType"
        },
        "State":{
          "shape":"TransitGatewayAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes an association between a resource attachment and a transit gateway route table.</p>"
    },
    "TransitGatewayAssociationState":{
      "type":"string",
      "enum":[
        "associating",
        "associated",
        "disassociating",
        "disassociated"
      ]
    },
    "TransitGatewayAttachment":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "TransitGatewayOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the transit gateway.</p>",
          "locationName":"transitGatewayOwnerId"
        },
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the resource.</p>",
          "locationName":"resourceOwnerId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type. Note that the <code>tgw-peering</code> resource type has been deprecated.</p>",
          "locationName":"resourceType"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "State":{
          "shape":"TransitGatewayAttachmentState",
          "documentation":"<p>The attachment state. Note that the <code>initiating</code> state has been deprecated.</p>",
          "locationName":"state"
        },
        "Association":{
          "shape":"TransitGatewayAttachmentAssociation",
          "documentation":"<p>The association.</p>",
          "locationName":"association"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the attachment.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes an attachment between a resource and a transit gateway.</p>"
    },
    "TransitGatewayAttachmentAssociation":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the route table for the transit gateway.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "State":{
          "shape":"TransitGatewayAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes an association.</p>"
    },
    "TransitGatewayAttachmentBgpConfiguration":{
      "type":"structure",
      "members":{
        "TransitGatewayAsn":{
          "shape":"Long",
          "documentation":"<p>The transit gateway Autonomous System Number (ASN).</p>",
          "locationName":"transitGatewayAsn"
        },
        "PeerAsn":{
          "shape":"Long",
          "documentation":"<p>The peer Autonomous System Number (ASN).</p>",
          "locationName":"peerAsn"
        },
        "TransitGatewayAddress":{
          "shape":"String",
          "documentation":"<p>The interior BGP peer IP address for the transit gateway.</p>",
          "locationName":"transitGatewayAddress"
        },
        "PeerAddress":{
          "shape":"String",
          "documentation":"<p>The interior BGP peer IP address for the appliance.</p>",
          "locationName":"peerAddress"
        },
        "BgpStatus":{
          "shape":"BgpStatus",
          "documentation":"<p>The BGP status.</p>",
          "locationName":"bgpStatus"
        }
      },
      "documentation":"<p>The BGP configuration information.</p>"
    },
    "TransitGatewayAttachmentBgpConfigurationList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayAttachmentBgpConfiguration",
        "locationName":"item"
      }
    },
    "TransitGatewayAttachmentId":{"type":"string"},
    "TransitGatewayAttachmentIdStringList":{
      "type":"list",
      "member":{"shape":"TransitGatewayAttachmentId"}
    },
    "TransitGatewayAttachmentList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayAttachment",
        "locationName":"item"
      }
    },
    "TransitGatewayAttachmentPropagation":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the propagation route table.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "State":{
          "shape":"TransitGatewayPropagationState",
          "documentation":"<p>The state of the propagation route table.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a propagation route table.</p>"
    },
    "TransitGatewayAttachmentPropagationList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayAttachmentPropagation",
        "locationName":"item"
      }
    },
    "TransitGatewayAttachmentResourceType":{
      "type":"string",
      "enum":[
        "vpc",
        "vpn",
        "direct-connect-gateway",
        "connect",
        "peering",
        "tgw-peering"
      ]
    },
    "TransitGatewayAttachmentState":{
      "type":"string",
      "enum":[
        "initiating",
        "initiatingRequest",
        "pendingAcceptance",
        "rollingBack",
        "pending",
        "available",
        "modifying",
        "deleting",
        "deleted",
        "failed",
        "rejected",
        "rejecting",
        "failing"
      ]
    },
    "TransitGatewayCidrBlockStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "TransitGatewayConnect":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the Connect attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "TransportTransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment from which the Connect attachment was created.</p>",
          "locationName":"transportTransitGatewayAttachmentId"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "State":{
          "shape":"TransitGatewayAttachmentState",
          "documentation":"<p>The state of the attachment.</p>",
          "locationName":"state"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "Options":{
          "shape":"TransitGatewayConnectOptions",
          "documentation":"<p>The Connect attachment options.</p>",
          "locationName":"options"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the attachment.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a transit gateway Connect attachment.</p>"
    },
    "TransitGatewayConnectList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayConnect",
        "locationName":"item"
      }
    },
    "TransitGatewayConnectOptions":{
      "type":"structure",
      "members":{
        "Protocol":{
          "shape":"ProtocolValue",
          "documentation":"<p>The tunnel protocol.</p>",
          "locationName":"protocol"
        }
      },
      "documentation":"<p>Describes the Connect attachment options.</p>"
    },
    "TransitGatewayConnectPeer":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the Connect attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "TransitGatewayConnectPeerId":{
          "shape":"TransitGatewayConnectPeerId",
          "documentation":"<p>The ID of the Connect peer.</p>",
          "locationName":"transitGatewayConnectPeerId"
        },
        "State":{
          "shape":"TransitGatewayConnectPeerState",
          "documentation":"<p>The state of the Connect peer.</p>",
          "locationName":"state"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "ConnectPeerConfiguration":{
          "shape":"TransitGatewayConnectPeerConfiguration",
          "documentation":"<p>The Connect peer details.</p>",
          "locationName":"connectPeerConfiguration"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the Connect peer.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a transit gateway Connect peer.</p>"
    },
    "TransitGatewayConnectPeerConfiguration":{
      "type":"structure",
      "members":{
        "TransitGatewayAddress":{
          "shape":"String",
          "documentation":"<p>The Connect peer IP address on the transit gateway side of the tunnel.</p>",
          "locationName":"transitGatewayAddress"
        },
        "PeerAddress":{
          "shape":"String",
          "documentation":"<p>The Connect peer IP address on the appliance side of the tunnel.</p>",
          "locationName":"peerAddress"
        },
        "InsideCidrBlocks":{
          "shape":"InsideCidrBlocksStringList",
          "documentation":"<p>The range of interior BGP peer IP addresses.</p>",
          "locationName":"insideCidrBlocks"
        },
        "Protocol":{
          "shape":"ProtocolValue",
          "documentation":"<p>The tunnel protocol.</p>",
          "locationName":"protocol"
        },
        "BgpConfigurations":{
          "shape":"TransitGatewayAttachmentBgpConfigurationList",
          "documentation":"<p>The BGP configuration details.</p>",
          "locationName":"bgpConfigurations"
        }
      },
      "documentation":"<p>Describes the Connect peer details.</p>"
    },
    "TransitGatewayConnectPeerId":{"type":"string"},
    "TransitGatewayConnectPeerIdStringList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayConnectPeerId",
        "locationName":"item"
      }
    },
    "TransitGatewayConnectPeerList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayConnectPeer",
        "locationName":"item"
      }
    },
    "TransitGatewayConnectPeerState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewayConnectRequestBgpOptions":{
      "type":"structure",
      "members":{
        "PeerAsn":{
          "shape":"Long",
          "documentation":"<p>The peer Autonomous System Number (ASN).</p>"
        }
      },
      "documentation":"<p>The BGP options for the Connect attachment.</p>"
    },
    "TransitGatewayId":{"type":"string"},
    "TransitGatewayIdStringList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayId",
        "locationName":"item"
      }
    },
    "TransitGatewayList":{
      "type":"list",
      "member":{
        "shape":"TransitGateway",
        "locationName":"item"
      }
    },
    "TransitGatewayMaxResults":{
      "type":"integer",
      "max":1000,
      "min":5
    },
    "TransitGatewayMulitcastDomainAssociationState":{
      "type":"string",
      "enum":[
        "pendingAcceptance",
        "associating",
        "associated",
        "disassociating",
        "disassociated",
        "rejected",
        "failed"
      ]
    },
    "TransitGatewayMulticastDeregisteredGroupMembers":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainId"
        },
        "DeregisteredNetworkInterfaceIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The network interface IDs of the deregistered members.</p>",
          "locationName":"deregisteredNetworkInterfaceIds"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>",
          "locationName":"groupIpAddress"
        }
      },
      "documentation":"<p>Describes the deregistered transit gateway multicast group members.</p>"
    },
    "TransitGatewayMulticastDeregisteredGroupSources":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainId"
        },
        "DeregisteredNetworkInterfaceIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The network interface IDs of the non-registered members.</p>",
          "locationName":"deregisteredNetworkInterfaceIds"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>",
          "locationName":"groupIpAddress"
        }
      },
      "documentation":"<p>Describes the deregistered transit gateway multicast group sources.</p>"
    },
    "TransitGatewayMulticastDomain":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainId"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "TransitGatewayMulticastDomainArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainArn"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p> The ID of the Amazon Web Services account that owns the transit gateway multicast domain.</p>",
          "locationName":"ownerId"
        },
        "Options":{
          "shape":"TransitGatewayMulticastDomainOptions",
          "documentation":"<p>The options for the transit gateway multicast domain.</p>",
          "locationName":"options"
        },
        "State":{
          "shape":"TransitGatewayMulticastDomainState",
          "documentation":"<p>The state of the transit gateway multicast domain.</p>",
          "locationName":"state"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The time the transit gateway multicast domain was created.</p>",
          "locationName":"creationTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the transit gateway multicast domain.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes the transit gateway multicast domain.</p>"
    },
    "TransitGatewayMulticastDomainAssociation":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The type of resource, for example a VPC attachment.</p>",
          "locationName":"resourceType"
        },
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p> The ID of the Amazon Web Services account that owns the transit gateway multicast domain association resource.</p>",
          "locationName":"resourceOwnerId"
        },
        "Subnet":{
          "shape":"SubnetAssociation",
          "documentation":"<p>The subnet associated with the transit gateway multicast domain.</p>",
          "locationName":"subnet"
        }
      },
      "documentation":"<p>Describes the resources associated with the transit gateway multicast domain.</p>"
    },
    "TransitGatewayMulticastDomainAssociationList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayMulticastDomainAssociation",
        "locationName":"item"
      }
    },
    "TransitGatewayMulticastDomainAssociations":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainId"
        },
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The type of resource, for example a VPC attachment.</p>",
          "locationName":"resourceType"
        },
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p> The ID of the Amazon Web Services account that owns the resource.</p>",
          "locationName":"resourceOwnerId"
        },
        "Subnets":{
          "shape":"SubnetAssociationList",
          "documentation":"<p>The subnets associated with the multicast domain.</p>",
          "locationName":"subnets"
        }
      },
      "documentation":"<p>Describes the multicast domain associations.</p>"
    },
    "TransitGatewayMulticastDomainId":{"type":"string"},
    "TransitGatewayMulticastDomainIdStringList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayMulticastDomainId",
        "locationName":"item"
      }
    },
    "TransitGatewayMulticastDomainList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayMulticastDomain",
        "locationName":"item"
      }
    },
    "TransitGatewayMulticastDomainOptions":{
      "type":"structure",
      "members":{
        "Igmpv2Support":{
          "shape":"Igmpv2SupportValue",
          "documentation":"<p>Indicates whether Internet Group Management Protocol (IGMP) version 2 is turned on for the transit gateway multicast domain.</p>",
          "locationName":"igmpv2Support"
        },
        "StaticSourcesSupport":{
          "shape":"StaticSourcesSupportValue",
          "documentation":"<p>Indicates whether support for statically configuring transit gateway multicast group sources is turned on.</p>",
          "locationName":"staticSourcesSupport"
        },
        "AutoAcceptSharedAssociations":{
          "shape":"AutoAcceptSharedAssociationsValue",
          "documentation":"<p>Indicates whether to automatically cross-account subnet associations that are associated with the transit gateway multicast domain.</p>",
          "locationName":"autoAcceptSharedAssociations"
        }
      },
      "documentation":"<p>Describes the options for a transit gateway multicast domain.</p>"
    },
    "TransitGatewayMulticastDomainState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewayMulticastGroup":{
      "type":"structure",
      "members":{
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>",
          "locationName":"groupIpAddress"
        },
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "SubnetId":{
          "shape":"String",
          "documentation":"<p>The ID of the subnet.</p>",
          "locationName":"subnetId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The type of resource, for example a VPC attachment.</p>",
          "locationName":"resourceType"
        },
        "ResourceOwnerId":{
          "shape":"String",
          "documentation":"<p> The ID of the Amazon Web Services account that owns the transit gateway multicast domain group resource.</p>",
          "locationName":"resourceOwnerId"
        },
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway attachment.</p>",
          "locationName":"networkInterfaceId"
        },
        "GroupMember":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the resource is a transit gateway multicast group member.</p>",
          "locationName":"groupMember"
        },
        "GroupSource":{
          "shape":"Boolean",
          "documentation":"<p>Indicates that the resource is a transit gateway multicast group member.</p>",
          "locationName":"groupSource"
        },
        "MemberType":{
          "shape":"MembershipType",
          "documentation":"<p>The member type (for example, <code>static</code>).</p>",
          "locationName":"memberType"
        },
        "SourceType":{
          "shape":"MembershipType",
          "documentation":"<p>The source type.</p>",
          "locationName":"sourceType"
        }
      },
      "documentation":"<p>Describes the transit gateway multicast group resources.</p>"
    },
    "TransitGatewayMulticastGroupList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayMulticastGroup",
        "locationName":"item"
      }
    },
    "TransitGatewayMulticastRegisteredGroupMembers":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainId"
        },
        "RegisteredNetworkInterfaceIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The ID of the registered network interfaces.</p>",
          "locationName":"registeredNetworkInterfaceIds"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>",
          "locationName":"groupIpAddress"
        }
      },
      "documentation":"<p>Describes the registered transit gateway multicast group members.</p>"
    },
    "TransitGatewayMulticastRegisteredGroupSources":{
      "type":"structure",
      "members":{
        "TransitGatewayMulticastDomainId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway multicast domain.</p>",
          "locationName":"transitGatewayMulticastDomainId"
        },
        "RegisteredNetworkInterfaceIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the network interfaces members registered with the transit gateway multicast group.</p>",
          "locationName":"registeredNetworkInterfaceIds"
        },
        "GroupIpAddress":{
          "shape":"String",
          "documentation":"<p>The IP address assigned to the transit gateway multicast group.</p>",
          "locationName":"groupIpAddress"
        }
      },
      "documentation":"<p>Describes the members registered with the transit gateway multicast group.</p>"
    },
    "TransitGatewayNetworkInterfaceIdList":{
      "type":"list",
      "member":{
        "shape":"NetworkInterfaceId",
        "locationName":"item"
      }
    },
    "TransitGatewayOptions":{
      "type":"structure",
      "members":{
        "AmazonSideAsn":{
          "shape":"Long",
          "documentation":"<p>A private Autonomous System Number (ASN) for the Amazon side of a BGP session. The range is 64512 to 65534 for 16-bit ASNs and 4200000000 to 4294967294 for 32-bit ASNs.</p>",
          "locationName":"amazonSideAsn"
        },
        "TransitGatewayCidrBlocks":{
          "shape":"ValueStringList",
          "documentation":"<p>The transit gateway CIDR blocks.</p>",
          "locationName":"transitGatewayCidrBlocks"
        },
        "AutoAcceptSharedAttachments":{
          "shape":"AutoAcceptSharedAttachmentsValue",
          "documentation":"<p>Indicates whether attachment requests are automatically accepted.</p>",
          "locationName":"autoAcceptSharedAttachments"
        },
        "DefaultRouteTableAssociation":{
          "shape":"DefaultRouteTableAssociationValue",
          "documentation":"<p>Indicates whether resource attachments are automatically associated with the default association route table.</p>",
          "locationName":"defaultRouteTableAssociation"
        },
        "AssociationDefaultRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the default association route table.</p>",
          "locationName":"associationDefaultRouteTableId"
        },
        "DefaultRouteTablePropagation":{
          "shape":"DefaultRouteTablePropagationValue",
          "documentation":"<p>Indicates whether resource attachments automatically propagate routes to the default propagation route table.</p>",
          "locationName":"defaultRouteTablePropagation"
        },
        "PropagationDefaultRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the default propagation route table.</p>",
          "locationName":"propagationDefaultRouteTableId"
        },
        "VpnEcmpSupport":{
          "shape":"VpnEcmpSupportValue",
          "documentation":"<p>Indicates whether Equal Cost Multipath Protocol support is enabled.</p>",
          "locationName":"vpnEcmpSupport"
        },
        "DnsSupport":{
          "shape":"DnsSupportValue",
          "documentation":"<p>Indicates whether DNS support is enabled.</p>",
          "locationName":"dnsSupport"
        },
        "MulticastSupport":{
          "shape":"MulticastSupportValue",
          "documentation":"<p>Indicates whether multicast is enabled on the transit gateway</p>",
          "locationName":"multicastSupport"
        }
      },
      "documentation":"<p>Describes the options for a transit gateway.</p>"
    },
    "TransitGatewayPeeringAttachment":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway peering attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "AccepterTransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the accepter transit gateway attachment.</p>",
          "locationName":"accepterTransitGatewayAttachmentId"
        },
        "RequesterTgwInfo":{
          "shape":"PeeringTgwInfo",
          "documentation":"<p>Information about the requester transit gateway.</p>",
          "locationName":"requesterTgwInfo"
        },
        "AccepterTgwInfo":{
          "shape":"PeeringTgwInfo",
          "documentation":"<p>Information about the accepter transit gateway.</p>",
          "locationName":"accepterTgwInfo"
        },
        "Options":{
          "shape":"TransitGatewayPeeringAttachmentOptions",
          "documentation":"<p>Details about the transit gateway peering attachment.</p>",
          "locationName":"options"
        },
        "Status":{
          "shape":"PeeringAttachmentStatus",
          "documentation":"<p>The status of the transit gateway peering attachment.</p>",
          "locationName":"status"
        },
        "State":{
          "shape":"TransitGatewayAttachmentState",
          "documentation":"<p>The state of the transit gateway peering attachment. Note that the <code>initiating</code> state has been deprecated.</p>",
          "locationName":"state"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The time the transit gateway peering attachment was created.</p>",
          "locationName":"creationTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the transit gateway peering attachment.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes the transit gateway peering attachment.</p>"
    },
    "TransitGatewayPeeringAttachmentList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayPeeringAttachment",
        "locationName":"item"
      }
    },
    "TransitGatewayPeeringAttachmentOptions":{
      "type":"structure",
      "members":{
        "DynamicRouting":{
          "shape":"DynamicRoutingValue",
          "documentation":"<p>Describes whether dynamic routing is enabled or disabled for the transit gateway peering attachment.</p>",
          "locationName":"dynamicRouting"
        }
      },
      "documentation":"<p>Describes dynamic routing for the transit gateway peering attachment.</p>"
    },
    "TransitGatewayPolicyRule":{
      "type":"structure",
      "members":{
        "SourceCidrBlock":{
          "shape":"String",
          "documentation":"<p>The source CIDR block for the transit gateway policy rule.</p>",
          "locationName":"sourceCidrBlock"
        },
        "SourcePortRange":{
          "shape":"String",
          "documentation":"<p>The port range for the transit gateway policy rule. Currently this is set to * (all).</p>",
          "locationName":"sourcePortRange"
        },
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The destination CIDR block for the transit gateway policy rule.</p>",
          "locationName":"destinationCidrBlock"
        },
        "DestinationPortRange":{
          "shape":"String",
          "documentation":"<p>The port range for the transit gateway policy rule. Currently this is set to * (all).</p>",
          "locationName":"destinationPortRange"
        },
        "Protocol":{
          "shape":"String",
          "documentation":"<p>The protocol used by the transit gateway policy rule.</p>",
          "locationName":"protocol"
        },
        "MetaData":{
          "shape":"TransitGatewayPolicyRuleMetaData",
          "documentation":"<p>The meta data tags used for the transit gateway policy rule.</p>",
          "locationName":"metaData"
        }
      },
      "documentation":"<p>Describes a rule associated with a transit gateway policy.</p>"
    },
    "TransitGatewayPolicyRuleMetaData":{
      "type":"structure",
      "members":{
        "MetaDataKey":{
          "shape":"String",
          "documentation":"<p>The key name for the transit gateway policy rule meta data tag.</p>",
          "locationName":"metaDataKey"
        },
        "MetaDataValue":{
          "shape":"String",
          "documentation":"<p>The value of the key for the transit gateway policy rule meta data tag.</p>",
          "locationName":"metaDataValue"
        }
      },
      "documentation":"<p>Describes the meta data tags associated with a transit gateway policy rule.</p>"
    },
    "TransitGatewayPolicyTable":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The ID of the transit gateway policy table.</p>",
          "locationName":"transitGatewayPolicyTableId"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "State":{
          "shape":"TransitGatewayPolicyTableState",
          "documentation":"<p>The state of the transit gateway policy table</p>",
          "locationName":"state"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The timestamp when the transit gateway policy table was created.</p>",
          "locationName":"creationTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>he key-value pairs associated with the transit gateway policy table.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a transit gateway policy table.</p>"
    },
    "TransitGatewayPolicyTableAssociation":{
      "type":"structure",
      "members":{
        "TransitGatewayPolicyTableId":{
          "shape":"TransitGatewayPolicyTableId",
          "documentation":"<p>The ID of the transit gateway policy table.</p>",
          "locationName":"transitGatewayPolicyTableId"
        },
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the transit gateway attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The resource ID of the transit gateway attachment.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type for the transit gateway policy table association.</p>",
          "locationName":"resourceType"
        },
        "State":{
          "shape":"TransitGatewayAssociationState",
          "documentation":"<p>The state of the transit gateway policy table association.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a transit gateway policy table association.</p>"
    },
    "TransitGatewayPolicyTableAssociationList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayPolicyTableAssociation",
        "locationName":"item"
      }
    },
    "TransitGatewayPolicyTableEntry":{
      "type":"structure",
      "members":{
        "PolicyRuleNumber":{
          "shape":"String",
          "documentation":"<p>The rule number for the transit gateway policy table entry.</p>",
          "locationName":"policyRuleNumber"
        },
        "PolicyRule":{
          "shape":"TransitGatewayPolicyRule",
          "documentation":"<p>The policy rule associated with the transit gateway policy table.</p>",
          "locationName":"policyRule"
        },
        "TargetRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the target route table.</p>",
          "locationName":"targetRouteTableId"
        }
      },
      "documentation":"<p>Describes a transit gateway policy table entry</p>"
    },
    "TransitGatewayPolicyTableEntryList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayPolicyTableEntry",
        "locationName":"item"
      }
    },
    "TransitGatewayPolicyTableId":{"type":"string"},
    "TransitGatewayPolicyTableIdStringList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayPolicyTableId",
        "locationName":"item"
      }
    },
    "TransitGatewayPolicyTableList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayPolicyTable",
        "locationName":"item"
      }
    },
    "TransitGatewayPolicyTableState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewayPrefixListAttachment":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type. Note that the <code>tgw-peering</code> resource type has been deprecated.</p>",
          "locationName":"resourceType"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        }
      },
      "documentation":"<p>Describes a transit gateway prefix list attachment.</p>"
    },
    "TransitGatewayPrefixListReference":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list.</p>",
          "locationName":"prefixListId"
        },
        "PrefixListOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the prefix list owner.</p>",
          "locationName":"prefixListOwnerId"
        },
        "State":{
          "shape":"TransitGatewayPrefixListReferenceState",
          "documentation":"<p>The state of the prefix list reference.</p>",
          "locationName":"state"
        },
        "Blackhole":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether traffic that matches this route is dropped.</p>",
          "locationName":"blackhole"
        },
        "TransitGatewayAttachment":{
          "shape":"TransitGatewayPrefixListAttachment",
          "documentation":"<p>Information about the transit gateway attachment.</p>",
          "locationName":"transitGatewayAttachment"
        }
      },
      "documentation":"<p>Describes a prefix list reference.</p>"
    },
    "TransitGatewayPrefixListReferenceSet":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayPrefixListReference",
        "locationName":"item"
      }
    },
    "TransitGatewayPrefixListReferenceState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "modifying",
        "deleting"
      ]
    },
    "TransitGatewayPropagation":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type. Note that the <code>tgw-peering</code> resource type has been deprecated.</p>",
          "locationName":"resourceType"
        },
        "TransitGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "State":{
          "shape":"TransitGatewayPropagationState",
          "documentation":"<p>The state.</p>",
          "locationName":"state"
        },
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The ID of the transit gateway route table announcement.</p>",
          "locationName":"transitGatewayRouteTableAnnouncementId"
        }
      },
      "documentation":"<p>Describes route propagation.</p>"
    },
    "TransitGatewayPropagationState":{
      "type":"string",
      "enum":[
        "enabling",
        "enabled",
        "disabling",
        "disabled"
      ]
    },
    "TransitGatewayRequestOptions":{
      "type":"structure",
      "members":{
        "AmazonSideAsn":{
          "shape":"Long",
          "documentation":"<p>A private Autonomous System Number (ASN) for the Amazon side of a BGP session. The range is 64512 to 65534 for 16-bit ASNs and 4200000000 to 4294967294 for 32-bit ASNs. The default is <code>64512</code>.</p>"
        },
        "AutoAcceptSharedAttachments":{
          "shape":"AutoAcceptSharedAttachmentsValue",
          "documentation":"<p>Enable or disable automatic acceptance of attachment requests. Disabled by default.</p>"
        },
        "DefaultRouteTableAssociation":{
          "shape":"DefaultRouteTableAssociationValue",
          "documentation":"<p>Enable or disable automatic association with the default association route table. Enabled by default.</p>"
        },
        "DefaultRouteTablePropagation":{
          "shape":"DefaultRouteTablePropagationValue",
          "documentation":"<p>Enable or disable automatic propagation of routes to the default propagation route table. Enabled by default.</p>"
        },
        "VpnEcmpSupport":{
          "shape":"VpnEcmpSupportValue",
          "documentation":"<p>Enable or disable Equal Cost Multipath Protocol support. Enabled by default.</p>"
        },
        "DnsSupport":{
          "shape":"DnsSupportValue",
          "documentation":"<p>Enable or disable DNS support. Enabled by default.</p>"
        },
        "MulticastSupport":{
          "shape":"MulticastSupportValue",
          "documentation":"<p>Indicates whether multicast is enabled on the transit gateway</p>"
        },
        "TransitGatewayCidrBlocks":{
          "shape":"TransitGatewayCidrBlockStringList",
          "documentation":"<p>One or more IPv4 or IPv6 CIDR blocks for the transit gateway. Must be a size /24 CIDR block or larger for IPv4, or a size /64 CIDR block or larger for IPv6.</p>"
        }
      },
      "documentation":"<p>Describes the options for a transit gateway.</p>"
    },
    "TransitGatewayRoute":{
      "type":"structure",
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR block used for destination matches.</p>",
          "locationName":"destinationCidrBlock"
        },
        "PrefixListId":{
          "shape":"PrefixListResourceId",
          "documentation":"<p>The ID of the prefix list used for destination matches.</p>",
          "locationName":"prefixListId"
        },
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The ID of the transit gateway route table announcement. </p>",
          "locationName":"transitGatewayRouteTableAnnouncementId"
        },
        "TransitGatewayAttachments":{
          "shape":"TransitGatewayRouteAttachmentList",
          "documentation":"<p>The attachments.</p>",
          "locationName":"transitGatewayAttachments"
        },
        "Type":{
          "shape":"TransitGatewayRouteType",
          "documentation":"<p>The route type.</p>",
          "locationName":"type"
        },
        "State":{
          "shape":"TransitGatewayRouteState",
          "documentation":"<p>The state of the route.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a route for a transit gateway route table.</p>"
    },
    "TransitGatewayRouteAttachment":{
      "type":"structure",
      "members":{
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type. Note that the <code>tgw-peering</code> resource type has been deprecated. </p>",
          "locationName":"resourceType"
        }
      },
      "documentation":"<p>Describes a route attachment.</p>"
    },
    "TransitGatewayRouteAttachmentList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteAttachment",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRoute",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteState":{
      "type":"string",
      "enum":[
        "pending",
        "active",
        "blackhole",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewayRouteTable":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "State":{
          "shape":"TransitGatewayRouteTableState",
          "documentation":"<p>The state of the transit gateway route table.</p>",
          "locationName":"state"
        },
        "DefaultAssociationRouteTable":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is the default association route table for the transit gateway.</p>",
          "locationName":"defaultAssociationRouteTable"
        },
        "DefaultPropagationRouteTable":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether this is the default propagation route table for the transit gateway.</p>",
          "locationName":"defaultPropagationRouteTable"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the route table.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a transit gateway route table.</p>"
    },
    "TransitGatewayRouteTableAnnouncement":{
      "type":"structure",
      "members":{
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The ID of the transit gateway route table announcement.</p>",
          "locationName":"transitGatewayRouteTableAnnouncementId"
        },
        "TransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "CoreNetworkId":{
          "shape":"String",
          "documentation":"<p>The ID of the core network for the transit gateway route table announcement.</p>",
          "locationName":"coreNetworkId"
        },
        "PeerTransitGatewayId":{
          "shape":"TransitGatewayId",
          "documentation":"<p>The ID of the peer transit gateway.</p>",
          "locationName":"peerTransitGatewayId"
        },
        "PeerCoreNetworkId":{
          "shape":"String",
          "documentation":"<p>The ID of the core network ID for the peer.</p>",
          "locationName":"peerCoreNetworkId"
        },
        "PeeringAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The ID of the peering attachment.</p>",
          "locationName":"peeringAttachmentId"
        },
        "AnnouncementDirection":{
          "shape":"TransitGatewayRouteTableAnnouncementDirection",
          "documentation":"<p>The direction for the route table announcement.</p>",
          "locationName":"announcementDirection"
        },
        "TransitGatewayRouteTableId":{
          "shape":"TransitGatewayRouteTableId",
          "documentation":"<p>The ID of the transit gateway route table.</p>",
          "locationName":"transitGatewayRouteTableId"
        },
        "State":{
          "shape":"TransitGatewayRouteTableAnnouncementState",
          "documentation":"<p>The state of the transit gateway announcement.</p>",
          "locationName":"state"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The timestamp when the transit gateway route table announcement was created.</p>",
          "locationName":"creationTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The key-value pairs associated with the route table announcement.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a transit gateway route table announcement.</p>"
    },
    "TransitGatewayRouteTableAnnouncementDirection":{
      "type":"string",
      "enum":[
        "outgoing",
        "incoming"
      ]
    },
    "TransitGatewayRouteTableAnnouncementId":{"type":"string"},
    "TransitGatewayRouteTableAnnouncementIdStringList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteTableAnnouncementId",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteTableAnnouncementList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteTableAnnouncement",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteTableAnnouncementState":{
      "type":"string",
      "enum":[
        "available",
        "pending",
        "failing",
        "failed",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewayRouteTableAssociation":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The resource type. Note that the <code>tgw-peering</code> resource type has been deprecated.</p>",
          "locationName":"resourceType"
        },
        "State":{
          "shape":"TransitGatewayAssociationState",
          "documentation":"<p>The state of the association.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes an association between a route table and a resource attachment.</p>"
    },
    "TransitGatewayRouteTableAssociationList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteTableAssociation",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteTableId":{"type":"string"},
    "TransitGatewayRouteTableIdStringList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteTableId",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteTableList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteTable",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteTablePropagation":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"TransitGatewayAttachmentResourceType",
          "documentation":"<p>The type of resource. Note that the <code>tgw-peering</code> resource type has been deprecated.</p>",
          "locationName":"resourceType"
        },
        "State":{
          "shape":"TransitGatewayPropagationState",
          "documentation":"<p>The state of the resource.</p>",
          "locationName":"state"
        },
        "TransitGatewayRouteTableAnnouncementId":{
          "shape":"TransitGatewayRouteTableAnnouncementId",
          "documentation":"<p>The ID of the transit gateway route table announcement.</p>",
          "locationName":"transitGatewayRouteTableAnnouncementId"
        }
      },
      "documentation":"<p>Describes a route table propagation.</p>"
    },
    "TransitGatewayRouteTablePropagationList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayRouteTablePropagation",
        "locationName":"item"
      }
    },
    "TransitGatewayRouteTableRoute":{
      "type":"structure",
      "members":{
        "DestinationCidr":{
          "shape":"String",
          "documentation":"<p>The CIDR block used for destination matches.</p>",
          "locationName":"destinationCidr"
        },
        "State":{
          "shape":"String",
          "documentation":"<p>The state of the route.</p>",
          "locationName":"state"
        },
        "RouteOrigin":{
          "shape":"String",
          "documentation":"<p>The route origin. The following are the possible values:</p> <ul> <li> <p>static</p> </li> <li> <p>propagated</p> </li> </ul>",
          "locationName":"routeOrigin"
        },
        "PrefixListId":{
          "shape":"String",
          "documentation":"<p>The ID of the prefix list.</p>",
          "locationName":"prefixListId"
        },
        "AttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the route attachment.</p>",
          "locationName":"attachmentId"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource for the route attachment.</p>",
          "locationName":"resourceId"
        },
        "ResourceType":{
          "shape":"String",
          "documentation":"<p>The resource type for the route attachment.</p>",
          "locationName":"resourceType"
        }
      },
      "documentation":"<p>Describes a route in a transit gateway route table.</p>"
    },
    "TransitGatewayRouteTableState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewayRouteType":{
      "type":"string",
      "enum":[
        "static",
        "propagated"
      ]
    },
    "TransitGatewayState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "modifying",
        "deleting",
        "deleted"
      ]
    },
    "TransitGatewaySubnetIdList":{
      "type":"list",
      "member":{
        "shape":"SubnetId",
        "locationName":"item"
      }
    },
    "TransitGatewayVpcAttachment":{
      "type":"structure",
      "members":{
        "TransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The ID of the attachment.</p>",
          "locationName":"transitGatewayAttachmentId"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway.</p>",
          "locationName":"transitGatewayId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "VpcOwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the VPC.</p>",
          "locationName":"vpcOwnerId"
        },
        "State":{
          "shape":"TransitGatewayAttachmentState",
          "documentation":"<p>The state of the VPC attachment. Note that the <code>initiating</code> state has been deprecated.</p>",
          "locationName":"state"
        },
        "SubnetIds":{
          "shape":"ValueStringList",
          "documentation":"<p>The IDs of the subnets.</p>",
          "locationName":"subnetIds"
        },
        "CreationTime":{
          "shape":"DateTime",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "Options":{
          "shape":"TransitGatewayVpcAttachmentOptions",
          "documentation":"<p>The VPC attachment options.</p>",
          "locationName":"options"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the VPC attachment.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a VPC attachment.</p>"
    },
    "TransitGatewayVpcAttachmentList":{
      "type":"list",
      "member":{
        "shape":"TransitGatewayVpcAttachment",
        "locationName":"item"
      }
    },
    "TransitGatewayVpcAttachmentOptions":{
      "type":"structure",
      "members":{
        "DnsSupport":{
          "shape":"DnsSupportValue",
          "documentation":"<p>Indicates whether DNS support is enabled.</p>",
          "locationName":"dnsSupport"
        },
        "Ipv6Support":{
          "shape":"Ipv6SupportValue",
          "documentation":"<p>Indicates whether IPv6 support is disabled.</p>",
          "locationName":"ipv6Support"
        },
        "ApplianceModeSupport":{
          "shape":"ApplianceModeSupportValue",
          "documentation":"<p>Indicates whether appliance mode support is enabled.</p>",
          "locationName":"applianceModeSupport"
        }
      },
      "documentation":"<p>Describes the VPC attachment options.</p>"
    },
    "TransportProtocol":{
      "type":"string",
      "enum":[
        "tcp",
        "udp"
      ]
    },
    "TrunkInterfaceAssociation":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"TrunkInterfaceAssociationId",
          "documentation":"<p>The ID of the association.</p>",
          "locationName":"associationId"
        },
        "BranchInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the branch network interface.</p>",
          "locationName":"branchInterfaceId"
        },
        "TrunkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the trunk network interface.</p>",
          "locationName":"trunkInterfaceId"
        },
        "InterfaceProtocol":{
          "shape":"InterfaceProtocolType",
          "documentation":"<p>The interface protocol. Valid values are <code>VLAN</code> and <code>GRE</code>.</p>",
          "locationName":"interfaceProtocol"
        },
        "VlanId":{
          "shape":"Integer",
          "documentation":"<p>The ID of the VLAN when you use the VLAN protocol.</p>",
          "locationName":"vlanId"
        },
        "GreKey":{
          "shape":"Integer",
          "documentation":"<p>The application key when you use the GRE protocol.</p>",
          "locationName":"greKey"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags for the trunk interface association.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<note> <p>Currently available in <b>limited preview only</b>. If you are interested in using this feature, contact your account manager.</p> </note> <p>Information about an association between a branch network interface with a trunk network interface.</p>"
    },
    "TrunkInterfaceAssociationId":{"type":"string"},
    "TrunkInterfaceAssociationIdList":{
      "type":"list",
      "member":{
        "shape":"TrunkInterfaceAssociationId",
        "locationName":"item"
      }
    },
    "TrunkInterfaceAssociationList":{
      "type":"list",
      "member":{
        "shape":"TrunkInterfaceAssociation",
        "locationName":"item"
      }
    },
    "TrustProviderType":{
      "type":"string",
      "enum":[
        "user",
        "device"
      ]
    },
    "TunnelInsideIpVersion":{
      "type":"string",
      "enum":[
        "ipv4",
        "ipv6"
      ]
    },
    "TunnelOption":{
      "type":"structure",
      "members":{
        "OutsideIpAddress":{
          "shape":"String",
          "documentation":"<p>The external IP address of the VPN tunnel.</p>",
          "locationName":"outsideIpAddress"
        },
        "TunnelInsideCidr":{
          "shape":"String",
          "documentation":"<p>The range of inside IPv4 addresses for the tunnel.</p>",
          "locationName":"tunnelInsideCidr"
        },
        "TunnelInsideIpv6Cidr":{
          "shape":"String",
          "documentation":"<p>The range of inside IPv6 addresses for the tunnel.</p>",
          "locationName":"tunnelInsideIpv6Cidr"
        },
        "PreSharedKey":{
          "shape":"String",
          "documentation":"<p>The pre-shared key (PSK) to establish initial authentication between the virtual private gateway and the customer gateway.</p>",
          "locationName":"preSharedKey"
        },
        "Phase1LifetimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The lifetime for phase 1 of the IKE negotiation, in seconds.</p>",
          "locationName":"phase1LifetimeSeconds"
        },
        "Phase2LifetimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The lifetime for phase 2 of the IKE negotiation, in seconds.</p>",
          "locationName":"phase2LifetimeSeconds"
        },
        "RekeyMarginTimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The margin time, in seconds, before the phase 2 lifetime expires, during which the Amazon Web Services side of the VPN connection performs an IKE rekey.</p>",
          "locationName":"rekeyMarginTimeSeconds"
        },
        "RekeyFuzzPercentage":{
          "shape":"Integer",
          "documentation":"<p>The percentage of the rekey window determined by <code>RekeyMarginTimeSeconds</code> during which the rekey time is randomly selected.</p>",
          "locationName":"rekeyFuzzPercentage"
        },
        "ReplayWindowSize":{
          "shape":"Integer",
          "documentation":"<p>The number of packets in an IKE replay window.</p>",
          "locationName":"replayWindowSize"
        },
        "DpdTimeoutSeconds":{
          "shape":"Integer",
          "documentation":"<p>The number of seconds after which a DPD timeout occurs.</p>",
          "locationName":"dpdTimeoutSeconds"
        },
        "DpdTimeoutAction":{
          "shape":"String",
          "documentation":"<p>The action to take after a DPD timeout occurs.</p>",
          "locationName":"dpdTimeoutAction"
        },
        "Phase1EncryptionAlgorithms":{
          "shape":"Phase1EncryptionAlgorithmsList",
          "documentation":"<p>The permitted encryption algorithms for the VPN tunnel for phase 1 IKE negotiations.</p>",
          "locationName":"phase1EncryptionAlgorithmSet"
        },
        "Phase2EncryptionAlgorithms":{
          "shape":"Phase2EncryptionAlgorithmsList",
          "documentation":"<p>The permitted encryption algorithms for the VPN tunnel for phase 2 IKE negotiations.</p>",
          "locationName":"phase2EncryptionAlgorithmSet"
        },
        "Phase1IntegrityAlgorithms":{
          "shape":"Phase1IntegrityAlgorithmsList",
          "documentation":"<p>The permitted integrity algorithms for the VPN tunnel for phase 1 IKE negotiations.</p>",
          "locationName":"phase1IntegrityAlgorithmSet"
        },
        "Phase2IntegrityAlgorithms":{
          "shape":"Phase2IntegrityAlgorithmsList",
          "documentation":"<p>The permitted integrity algorithms for the VPN tunnel for phase 2 IKE negotiations.</p>",
          "locationName":"phase2IntegrityAlgorithmSet"
        },
        "Phase1DHGroupNumbers":{
          "shape":"Phase1DHGroupNumbersList",
          "documentation":"<p>The permitted Diffie-Hellman group numbers for the VPN tunnel for phase 1 IKE negotiations.</p>",
          "locationName":"phase1DHGroupNumberSet"
        },
        "Phase2DHGroupNumbers":{
          "shape":"Phase2DHGroupNumbersList",
          "documentation":"<p>The permitted Diffie-Hellman group numbers for the VPN tunnel for phase 2 IKE negotiations.</p>",
          "locationName":"phase2DHGroupNumberSet"
        },
        "IkeVersions":{
          "shape":"IKEVersionsList",
          "documentation":"<p>The IKE versions that are permitted for the VPN tunnel.</p>",
          "locationName":"ikeVersionSet"
        },
        "StartupAction":{
          "shape":"String",
          "documentation":"<p>The action to take when the establishing the VPN tunnels for a VPN connection.</p>",
          "locationName":"startupAction"
        },
        "LogOptions":{
          "shape":"VpnTunnelLogOptions",
          "documentation":"<p>Options for logging VPN tunnel activity.</p>",
          "locationName":"logOptions"
        }
      },
      "documentation":"<p>The VPN tunnel options.</p>"
    },
    "TunnelOptionsList":{
      "type":"list",
      "member":{
        "shape":"TunnelOption",
        "locationName":"item"
      }
    },
    "UnassignIpv6AddressesRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "Ipv6Addresses":{
          "shape":"Ipv6AddressList",
          "documentation":"<p>The IPv6 addresses to unassign from the network interface.</p>",
          "locationName":"ipv6Addresses"
        },
        "Ipv6Prefixes":{
          "shape":"IpPrefixList",
          "documentation":"<p>The IPv6 prefixes to unassign from the network interface.</p>",
          "locationName":"Ipv6Prefix"
        },
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        }
      }
    },
    "UnassignIpv6AddressesResult":{
      "type":"structure",
      "members":{
        "NetworkInterfaceId":{
          "shape":"String",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "UnassignedIpv6Addresses":{
          "shape":"Ipv6AddressList",
          "documentation":"<p>The IPv6 addresses that have been unassigned from the network interface.</p>",
          "locationName":"unassignedIpv6Addresses"
        },
        "UnassignedIpv6Prefixes":{
          "shape":"IpPrefixList",
          "documentation":"<p>The IPv4 prefixes that have been unassigned from the network interface.</p>",
          "locationName":"unassignedIpv6PrefixSet"
        }
      }
    },
    "UnassignPrivateIpAddressesRequest":{
      "type":"structure",
      "required":["NetworkInterfaceId"],
      "members":{
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "PrivateIpAddresses":{
          "shape":"PrivateIpAddressStringList",
          "documentation":"<p>The secondary private IP addresses to unassign from the network interface. You can specify this option multiple times to unassign more than one IP address.</p>",
          "locationName":"privateIpAddress"
        },
        "Ipv4Prefixes":{
          "shape":"IpPrefixList",
          "documentation":"<p>The IPv4 prefixes to unassign from the network interface.</p>",
          "locationName":"Ipv4Prefix"
        }
      },
      "documentation":"<p>Contains the parameters for UnassignPrivateIpAddresses.</p>"
    },
    "UnassignPrivateNatGatewayAddressRequest":{
      "type":"structure",
      "required":[
        "NatGatewayId",
        "PrivateIpAddresses"
      ],
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>"
        },
        "PrivateIpAddresses":{
          "shape":"IpList",
          "documentation":"<p>The private IPv4 addresses you want to unassign.</p>",
          "locationName":"PrivateIpAddress"
        },
        "MaxDrainDurationSeconds":{
          "shape":"DrainSeconds",
          "documentation":"<p>The maximum amount of time to wait (in seconds) before forcibly releasing the IP addresses if connections are still in progress. Default value is 350 seconds.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "UnassignPrivateNatGatewayAddressResult":{
      "type":"structure",
      "members":{
        "NatGatewayId":{
          "shape":"NatGatewayId",
          "documentation":"<p>The NAT gateway ID.</p>",
          "locationName":"natGatewayId"
        },
        "NatGatewayAddresses":{
          "shape":"NatGatewayAddressList",
          "documentation":"<p>Information about the NAT gateway IP addresses.</p>",
          "locationName":"natGatewayAddressSet"
        }
      }
    },
    "UnlimitedSupportedInstanceFamily":{
      "type":"string",
      "enum":[
        "t2",
        "t3",
        "t3a",
        "t4g"
      ]
    },
    "UnmonitorInstancesRequest":{
      "type":"structure",
      "required":["InstanceIds"],
      "members":{
        "InstanceIds":{
          "shape":"InstanceIdStringList",
          "documentation":"<p>The IDs of the instances.</p>",
          "locationName":"InstanceId"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>",
          "locationName":"dryRun"
        }
      }
    },
    "UnmonitorInstancesResult":{
      "type":"structure",
      "members":{
        "InstanceMonitorings":{
          "shape":"InstanceMonitoringList",
          "documentation":"<p>The monitoring information.</p>",
          "locationName":"instancesSet"
        }
      }
    },
    "UnsuccessfulInstanceCreditSpecificationErrorCode":{
      "type":"string",
      "enum":[
        "InvalidInstanceID.Malformed",
        "InvalidInstanceID.NotFound",
        "IncorrectInstanceState",
        "InstanceCreditSpecification.NotSupported"
      ]
    },
    "UnsuccessfulInstanceCreditSpecificationItem":{
      "type":"structure",
      "members":{
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "Error":{
          "shape":"UnsuccessfulInstanceCreditSpecificationItemError",
          "documentation":"<p>The applicable error for the burstable performance instance whose credit option for CPU usage was not modified.</p>",
          "locationName":"error"
        }
      },
      "documentation":"<p>Describes the burstable performance instance whose credit option for CPU usage was not modified.</p>"
    },
    "UnsuccessfulInstanceCreditSpecificationItemError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"UnsuccessfulInstanceCreditSpecificationErrorCode",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The applicable error message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Information about the error for the burstable performance instance whose credit option for CPU usage was not modified.</p>"
    },
    "UnsuccessfulInstanceCreditSpecificationSet":{
      "type":"list",
      "member":{
        "shape":"UnsuccessfulInstanceCreditSpecificationItem",
        "locationName":"item"
      }
    },
    "UnsuccessfulItem":{
      "type":"structure",
      "members":{
        "Error":{
          "shape":"UnsuccessfulItemError",
          "documentation":"<p>Information about the error.</p>",
          "locationName":"error"
        },
        "ResourceId":{
          "shape":"String",
          "documentation":"<p>The ID of the resource.</p>",
          "locationName":"resourceId"
        }
      },
      "documentation":"<p>Information about items that were not successfully processed in a batch call.</p>"
    },
    "UnsuccessfulItemError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The error code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message accompanying the error code.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Information about the error that occurred. For more information about errors, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html\">Error codes</a>.</p>"
    },
    "UnsuccessfulItemList":{
      "type":"list",
      "member":{
        "shape":"UnsuccessfulItem",
        "locationName":"item"
      }
    },
    "UnsuccessfulItemSet":{
      "type":"list",
      "member":{
        "shape":"UnsuccessfulItem",
        "locationName":"item"
      }
    },
    "UpdateSecurityGroupRuleDescriptionsEgressRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "GroupName":{
          "shape":"SecurityGroupName",
          "documentation":"<p>[Default VPC] The name of the security group. You must specify either the security group ID or the security group name in the request.</p>"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The IP permissions for the security group rule. You must specify either the IP permissions or the description.</p>"
        },
        "SecurityGroupRuleDescriptions":{
          "shape":"SecurityGroupRuleDescriptionList",
          "documentation":"<p>The description for the egress security group rules. You must specify either the description or the IP permissions.</p>",
          "locationName":"SecurityGroupRuleDescription"
        }
      }
    },
    "UpdateSecurityGroupRuleDescriptionsEgressResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "UpdateSecurityGroupRuleDescriptionsIngressRequest":{
      "type":"structure",
      "members":{
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        },
        "GroupId":{
          "shape":"SecurityGroupId",
          "documentation":"<p>The ID of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "GroupName":{
          "shape":"SecurityGroupName",
          "documentation":"<p>[EC2-Classic, default VPC] The name of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.</p>"
        },
        "IpPermissions":{
          "shape":"IpPermissionList",
          "documentation":"<p>The IP permissions for the security group rule. You must specify either IP permissions or a description.</p>"
        },
        "SecurityGroupRuleDescriptions":{
          "shape":"SecurityGroupRuleDescriptionList",
          "documentation":"<p>[VPC only] The description for the ingress security group rules. You must specify either a description or IP permissions.</p>",
          "locationName":"SecurityGroupRuleDescription"
        }
      }
    },
    "UpdateSecurityGroupRuleDescriptionsIngressResult":{
      "type":"structure",
      "members":{
        "Return":{
          "shape":"Boolean",
          "documentation":"<p>Returns <code>true</code> if the request succeeds; otherwise, returns an error.</p>",
          "locationName":"return"
        }
      }
    },
    "UsageClassType":{
      "type":"string",
      "enum":[
        "spot",
        "on-demand"
      ]
    },
    "UsageClassTypeList":{
      "type":"list",
      "member":{
        "shape":"UsageClassType",
        "locationName":"item"
      }
    },
    "UserBucket":{
      "type":"structure",
      "members":{
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The name of the Amazon S3 bucket where the disk image is located.</p>"
        },
        "S3Key":{
          "shape":"String",
          "documentation":"<p>The file name of the disk image.</p>"
        }
      },
      "documentation":"<p>Describes the Amazon S3 bucket for the disk image.</p>"
    },
    "UserBucketDetails":{
      "type":"structure",
      "members":{
        "S3Bucket":{
          "shape":"String",
          "documentation":"<p>The Amazon S3 bucket from which the disk image was created.</p>",
          "locationName":"s3Bucket"
        },
        "S3Key":{
          "shape":"String",
          "documentation":"<p>The file name of the disk image.</p>",
          "locationName":"s3Key"
        }
      },
      "documentation":"<p>Describes the Amazon S3 bucket for the disk image.</p>"
    },
    "UserData":{
      "type":"structure",
      "members":{
        "Data":{
          "shape":"String",
          "documentation":"<p>The user data. If you are using an Amazon Web Services SDK or command line tool, Base64-encoding is performed for you, and you can load the text from a file. Otherwise, you must provide Base64-encoded text.</p>",
          "locationName":"data"
        }
      },
      "documentation":"<p>Describes the user data for an instance.</p>",
      "sensitive":true
    },
    "UserGroupStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"UserGroup"
      }
    },
    "UserIdGroupPair":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the security group rule that references this user ID group pair.</p> <p>Constraints: Up to 255 characters in length. Allowed characters are a-z, A-Z, 0-9, spaces, and ._-:/()#,@[]+=;{}!$*</p>",
          "locationName":"description"
        },
        "GroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the security group.</p>",
          "locationName":"groupId"
        },
        "GroupName":{
          "shape":"String",
          "documentation":"<p>The name of the security group. In a request, use this parameter for a security group in EC2-Classic or a default VPC only. For a security group in a nondefault VPC, use the security group ID. </p> <p>For a referenced security group in another VPC, this value is not returned if the referenced security group is deleted.</p>",
          "locationName":"groupName"
        },
        "PeeringStatus":{
          "shape":"String",
          "documentation":"<p>The status of a VPC peering connection, if applicable.</p>",
          "locationName":"peeringStatus"
        },
        "UserId":{
          "shape":"String",
          "documentation":"<p>The ID of an Amazon Web Services account.</p> <p>For a referenced security group in another VPC, the account ID of the referenced security group is returned in the response. If the referenced security group is deleted, this value is not returned.</p> <p>[EC2-Classic] Required when adding or removing rules that reference a security group in another Amazon Web Services account.</p>",
          "locationName":"userId"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC for the referenced security group, if applicable.</p>",
          "locationName":"vpcId"
        },
        "VpcPeeringConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC peering connection, if applicable.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      },
      "documentation":"<p>Describes a security group and Amazon Web Services account ID pair.</p> <note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note>"
    },
    "UserIdGroupPairList":{
      "type":"list",
      "member":{
        "shape":"UserIdGroupPair",
        "locationName":"item"
      }
    },
    "UserIdGroupPairSet":{
      "type":"list",
      "member":{
        "shape":"UserIdGroupPair",
        "locationName":"item"
      }
    },
    "UserIdStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"UserId"
      }
    },
    "UserTrustProviderType":{
      "type":"string",
      "enum":[
        "iam-identity-center",
        "oidc"
      ]
    },
    "VCpuCount":{"type":"integer"},
    "VCpuCountRange":{
      "type":"structure",
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of vCPUs. If the value is <code>0</code>, there is no minimum limit.</p>",
          "locationName":"min"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of vCPUs. If this parameter is not specified, there is no maximum limit.</p>",
          "locationName":"max"
        }
      },
      "documentation":"<p>The minimum and maximum number of vCPUs.</p>"
    },
    "VCpuCountRangeRequest":{
      "type":"structure",
      "required":["Min"],
      "members":{
        "Min":{
          "shape":"Integer",
          "documentation":"<p>The minimum number of vCPUs. To specify no minimum limit, specify <code>0</code>.</p>"
        },
        "Max":{
          "shape":"Integer",
          "documentation":"<p>The maximum number of vCPUs. To specify no maximum limit, omit this parameter.</p>"
        }
      },
      "documentation":"<p>The minimum and maximum number of vCPUs.</p>"
    },
    "VCpuInfo":{
      "type":"structure",
      "members":{
        "DefaultVCpus":{
          "shape":"VCpuCount",
          "documentation":"<p>The default number of vCPUs for the instance type.</p>",
          "locationName":"defaultVCpus"
        },
        "DefaultCores":{
          "shape":"CoreCount",
          "documentation":"<p>The default number of cores for the instance type.</p>",
          "locationName":"defaultCores"
        },
        "DefaultThreadsPerCore":{
          "shape":"ThreadsPerCore",
          "documentation":"<p>The default number of threads per core for the instance type.</p>",
          "locationName":"defaultThreadsPerCore"
        },
        "ValidCores":{
          "shape":"CoreCountList",
          "documentation":"<p>The valid number of cores that can be configured for the instance type.</p>",
          "locationName":"validCores"
        },
        "ValidThreadsPerCore":{
          "shape":"ThreadsPerCoreList",
          "documentation":"<p>The valid number of threads per core that can be configured for the instance type.</p>",
          "locationName":"validThreadsPerCore"
        }
      },
      "documentation":"<p>Describes the vCPU configurations for the instance type.</p>"
    },
    "ValidationError":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The error code that indicates why the parameter or parameter combination is not valid. For more information about error codes, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html\">Error codes</a>.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The error message that describes why the parameter or parameter combination is not valid. For more information about error messages, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/APIReference/errors-overview.html\">Error codes</a>.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>The error code and error message that is returned for a parameter or parameter combination that is not valid when a new launch template or new version of a launch template is created.</p>"
    },
    "ValidationWarning":{
      "type":"structure",
      "members":{
        "Errors":{
          "shape":"ErrorSet",
          "documentation":"<p>The error codes and error messages.</p>",
          "locationName":"errorSet"
        }
      },
      "documentation":"<p>The error codes and error messages that are returned for the parameters or parameter combinations that are not valid when a new launch template or new version of a launch template is created.</p>"
    },
    "ValueStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "VerifiedAccessEndpoint":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstanceId"
        },
        "VerifiedAccessGroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access group.</p>",
          "locationName":"verifiedAccessGroupId"
        },
        "VerifiedAccessEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"verifiedAccessEndpointId"
        },
        "ApplicationDomain":{
          "shape":"String",
          "documentation":"<p>The DNS name for users to reach your application.</p>",
          "locationName":"applicationDomain"
        },
        "EndpointType":{
          "shape":"VerifiedAccessEndpointType",
          "documentation":"<p>The type of Amazon Web Services Verified Access endpoint. Incoming application requests will be sent to an IP address, load balancer or a network interface depending on the endpoint type specified.</p>",
          "locationName":"endpointType"
        },
        "AttachmentType":{
          "shape":"VerifiedAccessEndpointAttachmentType",
          "documentation":"<p>The type of attachment used to provide connectivity between the Amazon Web Services Verified Access endpoint and the application.</p>",
          "locationName":"attachmentType"
        },
        "DomainCertificateArn":{
          "shape":"String",
          "documentation":"<p>The ARN of a public TLS/SSL certificate imported into or created with ACM.</p>",
          "locationName":"domainCertificateArn"
        },
        "EndpointDomain":{
          "shape":"String",
          "documentation":"<p>A DNS name that is generated for the endpoint.</p>",
          "locationName":"endpointDomain"
        },
        "DeviceValidationDomain":{
          "shape":"String",
          "documentation":"<p>Returned if endpoint has a device trust provider attached.</p>",
          "locationName":"deviceValidationDomain"
        },
        "SecurityGroupIds":{
          "shape":"SecurityGroupIdList",
          "documentation":"<p>The IDs of the security groups for the endpoint.</p>",
          "locationName":"securityGroupIdSet"
        },
        "LoadBalancerOptions":{
          "shape":"VerifiedAccessEndpointLoadBalancerOptions",
          "documentation":"<p>The load balancer details if creating the Amazon Web Services Verified Access endpoint as <code>load-balancer</code>type.</p>",
          "locationName":"loadBalancerOptions"
        },
        "NetworkInterfaceOptions":{
          "shape":"VerifiedAccessEndpointEniOptions",
          "documentation":"<p>The options for network-interface type endpoint.</p>",
          "locationName":"networkInterfaceOptions"
        },
        "Status":{
          "shape":"VerifiedAccessEndpointStatus",
          "documentation":"<p>The endpoint status.</p>",
          "locationName":"status"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access endpoint.</p>",
          "locationName":"description"
        },
        "CreationTime":{
          "shape":"String",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "LastUpdatedTime":{
          "shape":"String",
          "documentation":"<p>The last updated time.</p>",
          "locationName":"lastUpdatedTime"
        },
        "DeletionTime":{
          "shape":"String",
          "documentation":"<p>The deletion time.</p>",
          "locationName":"deletionTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>An Amazon Web Services Verified Access endpoint specifies the application that Amazon Web Services Verified Access provides access to. It must be attached to an Amazon Web Services Verified Access group. An Amazon Web Services Verified Access endpoint must also have an attached access policy before you attached it to a group.</p>"
    },
    "VerifiedAccessEndpointAttachmentType":{
      "type":"string",
      "enum":["vpc"]
    },
    "VerifiedAccessEndpointEniOptions":{
      "type":"structure",
      "members":{
        "NetworkInterfaceId":{
          "shape":"NetworkInterfaceId",
          "documentation":"<p>The ID of the network interface.</p>",
          "locationName":"networkInterfaceId"
        },
        "Protocol":{
          "shape":"VerifiedAccessEndpointProtocol",
          "documentation":"<p>The IP protocol.</p>",
          "locationName":"protocol"
        },
        "Port":{
          "shape":"VerifiedAccessEndpointPortNumber",
          "documentation":"<p>The IP port number.</p>",
          "locationName":"port"
        }
      },
      "documentation":"<p>Options for a network-interface type endpoint.</p>"
    },
    "VerifiedAccessEndpointId":{"type":"string"},
    "VerifiedAccessEndpointIdList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessEndpointId",
        "locationName":"item"
      }
    },
    "VerifiedAccessEndpointList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessEndpoint",
        "locationName":"item"
      }
    },
    "VerifiedAccessEndpointLoadBalancerOptions":{
      "type":"structure",
      "members":{
        "Protocol":{
          "shape":"VerifiedAccessEndpointProtocol",
          "documentation":"<p>The IP protocol.</p>",
          "locationName":"protocol"
        },
        "Port":{
          "shape":"VerifiedAccessEndpointPortNumber",
          "documentation":"<p>The IP port number.</p>",
          "locationName":"port"
        },
        "LoadBalancerArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the load balancer.</p>",
          "locationName":"loadBalancerArn"
        },
        "SubnetIds":{
          "shape":"VerifiedAccessEndpointSubnetIdList",
          "documentation":"<p>The IDs of the subnets.</p>",
          "locationName":"subnetIdSet"
        }
      },
      "documentation":"<p>Describes a load balancer when creating an Amazon Web Services Verified Access endpoint using the <code>load-balancer</code> type.</p>"
    },
    "VerifiedAccessEndpointPortNumber":{
      "type":"integer",
      "max":65535,
      "min":1
    },
    "VerifiedAccessEndpointProtocol":{
      "type":"string",
      "enum":[
        "http",
        "https"
      ]
    },
    "VerifiedAccessEndpointStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"VerifiedAccessEndpointStatusCode",
          "documentation":"<p>The status code of the Verified Access endpoint.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The status message of the Verified Access endpoint.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the status of a Verified Access endpoint.</p>"
    },
    "VerifiedAccessEndpointStatusCode":{
      "type":"string",
      "enum":[
        "pending",
        "active",
        "updating",
        "deleting",
        "deleted"
      ]
    },
    "VerifiedAccessEndpointSubnetIdList":{
      "type":"list",
      "member":{
        "shape":"SubnetId",
        "locationName":"item"
      }
    },
    "VerifiedAccessEndpointType":{
      "type":"string",
      "enum":[
        "load-balancer",
        "network-interface"
      ]
    },
    "VerifiedAccessGroup":{
      "type":"structure",
      "members":{
        "VerifiedAccessGroupId":{
          "shape":"String",
          "documentation":"<p>The ID of the Verified Access group.</p>",
          "locationName":"verifiedAccessGroupId"
        },
        "VerifiedAccessInstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstanceId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access group.</p>",
          "locationName":"description"
        },
        "Owner":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account number that owns the group.</p>",
          "locationName":"owner"
        },
        "VerifiedAccessGroupArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the Verified Access group.</p>",
          "locationName":"verifiedAccessGroupArn"
        },
        "CreationTime":{
          "shape":"String",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "LastUpdatedTime":{
          "shape":"String",
          "documentation":"<p>The last updated time.</p>",
          "locationName":"lastUpdatedTime"
        },
        "DeletionTime":{
          "shape":"String",
          "documentation":"<p>The deletion time.</p>",
          "locationName":"deletionTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Verified Access group.</p>"
    },
    "VerifiedAccessGroupId":{"type":"string"},
    "VerifiedAccessGroupIdList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessGroupId",
        "locationName":"item"
      }
    },
    "VerifiedAccessGroupList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessGroup",
        "locationName":"item"
      }
    },
    "VerifiedAccessInstance":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstanceId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access instance.</p>",
          "locationName":"description"
        },
        "VerifiedAccessTrustProviders":{
          "shape":"VerifiedAccessTrustProviderCondensedList",
          "documentation":"<p>The IDs of the Amazon Web Services Verified Access trust providers.</p>",
          "locationName":"verifiedAccessTrustProviderSet"
        },
        "CreationTime":{
          "shape":"String",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "LastUpdatedTime":{
          "shape":"String",
          "documentation":"<p>The last updated time.</p>",
          "locationName":"lastUpdatedTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Verified Access instance.</p>"
    },
    "VerifiedAccessInstanceId":{"type":"string"},
    "VerifiedAccessInstanceIdList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessInstanceId",
        "locationName":"item"
      }
    },
    "VerifiedAccessInstanceList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessInstance",
        "locationName":"item"
      }
    },
    "VerifiedAccessInstanceLoggingConfiguration":{
      "type":"structure",
      "members":{
        "VerifiedAccessInstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access instance.</p>",
          "locationName":"verifiedAccessInstanceId"
        },
        "AccessLogs":{
          "shape":"VerifiedAccessLogs",
          "documentation":"<p>Details about the logging options.</p>",
          "locationName":"accessLogs"
        }
      },
      "documentation":"<p>Describes logging options for an Amazon Web Services Verified Access instance.</p>"
    },
    "VerifiedAccessInstanceLoggingConfigurationList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessInstanceLoggingConfiguration",
        "locationName":"item"
      }
    },
    "VerifiedAccessLogCloudWatchLogsDestination":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether logging is enabled.</p>",
          "locationName":"enabled"
        },
        "DeliveryStatus":{
          "shape":"VerifiedAccessLogDeliveryStatus",
          "documentation":"<p>The delivery status for access logs.</p>",
          "locationName":"deliveryStatus"
        },
        "LogGroup":{
          "shape":"String",
          "documentation":"<p>The ID of the CloudWatch Logs log group.</p>",
          "locationName":"logGroup"
        }
      },
      "documentation":"<p>Options for CloudWatch Logs as a logging destination.</p>"
    },
    "VerifiedAccessLogCloudWatchLogsDestinationOptions":{
      "type":"structure",
      "required":["Enabled"],
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether logging is enabled.</p>"
        },
        "LogGroup":{
          "shape":"String",
          "documentation":"<p>The ID of the CloudWatch Logs log group.</p>"
        }
      },
      "documentation":"<p>Options for CloudWatch Logs as a logging destination.</p>"
    },
    "VerifiedAccessLogDeliveryStatus":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"VerifiedAccessLogDeliveryStatusCode",
          "documentation":"<p>The status code.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>The status message.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes a log delivery status.</p>"
    },
    "VerifiedAccessLogDeliveryStatusCode":{
      "type":"string",
      "enum":[
        "success",
        "failed"
      ]
    },
    "VerifiedAccessLogKinesisDataFirehoseDestination":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether logging is enabled.</p>",
          "locationName":"enabled"
        },
        "DeliveryStatus":{
          "shape":"VerifiedAccessLogDeliveryStatus",
          "documentation":"<p>The delivery status.</p>",
          "locationName":"deliveryStatus"
        },
        "DeliveryStream":{
          "shape":"String",
          "documentation":"<p>The ID of the delivery stream.</p>",
          "locationName":"deliveryStream"
        }
      },
      "documentation":"<p>Options for Kinesis as a logging destination.</p>"
    },
    "VerifiedAccessLogKinesisDataFirehoseDestinationOptions":{
      "type":"structure",
      "required":["Enabled"],
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether logging is enabled.</p>"
        },
        "DeliveryStream":{
          "shape":"String",
          "documentation":"<p>The ID of the delivery stream.</p>"
        }
      },
      "documentation":"<p>Describes Amazon Kinesis Data Firehose logging options.</p>"
    },
    "VerifiedAccessLogOptions":{
      "type":"structure",
      "members":{
        "S3":{
          "shape":"VerifiedAccessLogS3DestinationOptions",
          "documentation":"<p>Sends Verified Access logs to Amazon S3.</p>"
        },
        "CloudWatchLogs":{
          "shape":"VerifiedAccessLogCloudWatchLogsDestinationOptions",
          "documentation":"<p>Sends Verified Access logs to CloudWatch Logs.</p>"
        },
        "KinesisDataFirehose":{
          "shape":"VerifiedAccessLogKinesisDataFirehoseDestinationOptions",
          "documentation":"<p>Sends Verified Access logs to Kinesis.</p>"
        }
      },
      "documentation":"<p>Describes the destinations for Verified Access logs.</p>"
    },
    "VerifiedAccessLogS3Destination":{
      "type":"structure",
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether logging is enabled.</p>",
          "locationName":"enabled"
        },
        "DeliveryStatus":{
          "shape":"VerifiedAccessLogDeliveryStatus",
          "documentation":"<p>The delivery status.</p>",
          "locationName":"deliveryStatus"
        },
        "BucketName":{
          "shape":"String",
          "documentation":"<p>The bucket name.</p>",
          "locationName":"bucketName"
        },
        "Prefix":{
          "shape":"String",
          "documentation":"<p>The bucket prefix.</p>",
          "locationName":"prefix"
        },
        "BucketOwner":{
          "shape":"String",
          "documentation":"<p>The Amazon Web Services account number that owns the bucket.</p>",
          "locationName":"bucketOwner"
        }
      },
      "documentation":"<p>Options for Amazon S3 as a logging destination.</p>"
    },
    "VerifiedAccessLogS3DestinationOptions":{
      "type":"structure",
      "required":["Enabled"],
      "members":{
        "Enabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether logging is enabled.</p>"
        },
        "BucketName":{
          "shape":"String",
          "documentation":"<p>The bucket name.</p>"
        },
        "Prefix":{
          "shape":"String",
          "documentation":"<p>The bucket prefix.</p>"
        },
        "BucketOwner":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the Amazon S3 bucket.</p>"
        }
      },
      "documentation":"<p>Options for Amazon S3 as a logging destination.</p>"
    },
    "VerifiedAccessLogs":{
      "type":"structure",
      "members":{
        "S3":{
          "shape":"VerifiedAccessLogS3Destination",
          "documentation":"<p>Amazon S3 logging options.</p>",
          "locationName":"s3"
        },
        "CloudWatchLogs":{
          "shape":"VerifiedAccessLogCloudWatchLogsDestination",
          "documentation":"<p>CloudWatch Logs logging destination.</p>",
          "locationName":"cloudWatchLogs"
        },
        "KinesisDataFirehose":{
          "shape":"VerifiedAccessLogKinesisDataFirehoseDestination",
          "documentation":"<p>Kinesis logging destination.</p>",
          "locationName":"kinesisDataFirehose"
        }
      },
      "documentation":"<p>Describes the destinations for Verified Access logs.</p>"
    },
    "VerifiedAccessTrustProvider":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProviderId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"verifiedAccessTrustProviderId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description for the Amazon Web Services Verified Access trust provider.</p>",
          "locationName":"description"
        },
        "TrustProviderType":{
          "shape":"TrustProviderType",
          "documentation":"<p>The type of Verified Access trust provider.</p>",
          "locationName":"trustProviderType"
        },
        "UserTrustProviderType":{
          "shape":"UserTrustProviderType",
          "documentation":"<p>The type of user-based trust provider.</p>",
          "locationName":"userTrustProviderType"
        },
        "DeviceTrustProviderType":{
          "shape":"DeviceTrustProviderType",
          "documentation":"<p>The type of device-based trust provider.</p>",
          "locationName":"deviceTrustProviderType"
        },
        "OidcOptions":{
          "shape":"OidcOptions",
          "documentation":"<p>The OpenID Connect details for an <code>oidc</code>-type, user-identity based trust provider.</p>",
          "locationName":"oidcOptions"
        },
        "DeviceOptions":{
          "shape":"DeviceOptions",
          "documentation":"<p>The options for device-identity type trust provider.</p>",
          "locationName":"deviceOptions"
        },
        "PolicyReferenceName":{
          "shape":"String",
          "documentation":"<p>The identifier to be used when working with policy rules.</p>",
          "locationName":"policyReferenceName"
        },
        "CreationTime":{
          "shape":"String",
          "documentation":"<p>The creation time.</p>",
          "locationName":"creationTime"
        },
        "LastUpdatedTime":{
          "shape":"String",
          "documentation":"<p>The last updated time.</p>",
          "locationName":"lastUpdatedTime"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a Verified Access trust provider.</p>"
    },
    "VerifiedAccessTrustProviderCondensed":{
      "type":"structure",
      "members":{
        "VerifiedAccessTrustProviderId":{
          "shape":"String",
          "documentation":"<p>The ID of the trust provider.</p>",
          "locationName":"verifiedAccessTrustProviderId"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>The description of trust provider.</p>",
          "locationName":"description"
        },
        "TrustProviderType":{
          "shape":"TrustProviderType",
          "documentation":"<p>The type of trust provider (user- or device-based).</p>",
          "locationName":"trustProviderType"
        },
        "UserTrustProviderType":{
          "shape":"UserTrustProviderType",
          "documentation":"<p>The type of user-based trust provider.</p>",
          "locationName":"userTrustProviderType"
        },
        "DeviceTrustProviderType":{
          "shape":"DeviceTrustProviderType",
          "documentation":"<p>The type of device-based trust provider.</p>",
          "locationName":"deviceTrustProviderType"
        }
      },
      "documentation":"<p>Condensed information about a trust provider.</p>"
    },
    "VerifiedAccessTrustProviderCondensedList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessTrustProviderCondensed",
        "locationName":"item"
      }
    },
    "VerifiedAccessTrustProviderId":{"type":"string"},
    "VerifiedAccessTrustProviderIdList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessTrustProviderId",
        "locationName":"item"
      }
    },
    "VerifiedAccessTrustProviderList":{
      "type":"list",
      "member":{
        "shape":"VerifiedAccessTrustProvider",
        "locationName":"item"
      }
    },
    "VersionDescription":{
      "type":"string",
      "max":255,
      "min":0
    },
    "VersionStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"item"
      }
    },
    "VgwTelemetry":{
      "type":"structure",
      "members":{
        "AcceptedRouteCount":{
          "shape":"Integer",
          "documentation":"<p>The number of accepted routes.</p>",
          "locationName":"acceptedRouteCount"
        },
        "LastStatusChange":{
          "shape":"DateTime",
          "documentation":"<p>The date and time of the last change in status.</p>",
          "locationName":"lastStatusChange"
        },
        "OutsideIpAddress":{
          "shape":"String",
          "documentation":"<p>The Internet-routable IP address of the virtual private gateway's outside interface.</p>",
          "locationName":"outsideIpAddress"
        },
        "Status":{
          "shape":"TelemetryStatus",
          "documentation":"<p>The status of the VPN tunnel.</p>",
          "locationName":"status"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>If an error occurs, a description of the error.</p>",
          "locationName":"statusMessage"
        },
        "CertificateArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the VPN tunnel endpoint certificate.</p>",
          "locationName":"certificateArn"
        }
      },
      "documentation":"<p>Describes telemetry for a VPN tunnel.</p>"
    },
    "VgwTelemetryList":{
      "type":"list",
      "member":{
        "shape":"VgwTelemetry",
        "locationName":"item"
      }
    },
    "VirtualizationType":{
      "type":"string",
      "enum":[
        "hvm",
        "paravirtual"
      ]
    },
    "VirtualizationTypeList":{
      "type":"list",
      "member":{
        "shape":"VirtualizationType",
        "locationName":"item"
      }
    },
    "VirtualizationTypeSet":{
      "type":"list",
      "member":{
        "shape":"VirtualizationType",
        "locationName":"item"
      },
      "max":2,
      "min":0
    },
    "Volume":{
      "type":"structure",
      "members":{
        "Attachments":{
          "shape":"VolumeAttachmentList",
          "documentation":"<p>Information about the volume attachments.</p>",
          "locationName":"attachmentSet"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone for the volume.</p>",
          "locationName":"availabilityZone"
        },
        "CreateTime":{
          "shape":"DateTime",
          "documentation":"<p>The time stamp when volume creation was initiated.</p>",
          "locationName":"createTime"
        },
        "Encrypted":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume is encrypted.</p>",
          "locationName":"encrypted"
        },
        "KmsKeyId":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Key Management Service (KMS) KMS key that was used to protect the volume encryption key for the volume.</p>",
          "locationName":"kmsKeyId"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "Size":{
          "shape":"Integer",
          "documentation":"<p>The size of the volume, in GiBs.</p>",
          "locationName":"size"
        },
        "SnapshotId":{
          "shape":"String",
          "documentation":"<p>The snapshot from which the volume was created, if applicable.</p>",
          "locationName":"snapshotId"
        },
        "State":{
          "shape":"VolumeState",
          "documentation":"<p>The volume state.</p>",
          "locationName":"status"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume.</p>",
          "locationName":"volumeId"
        },
        "Iops":{
          "shape":"Integer",
          "documentation":"<p>The number of I/O operations per second (IOPS). For <code>gp3</code>, <code>io1</code>, and <code>io2</code> volumes, this represents the number of IOPS that are provisioned for the volume. For <code>gp2</code> volumes, this represents the baseline performance of the volume and the rate at which the volume accumulates I/O credits for bursting.</p>",
          "locationName":"iops"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the volume.</p>",
          "locationName":"tagSet"
        },
        "VolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The volume type.</p>",
          "locationName":"volumeType"
        },
        "FastRestored":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the volume was created using fast snapshot restore.</p>",
          "locationName":"fastRestored"
        },
        "MultiAttachEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether Amazon EBS Multi-Attach is enabled.</p>",
          "locationName":"multiAttachEnabled"
        },
        "Throughput":{
          "shape":"Integer",
          "documentation":"<p>The throughput that the volume supports, in MiB/s.</p>",
          "locationName":"throughput"
        }
      },
      "documentation":"<p>Describes a volume.</p>"
    },
    "VolumeAttachment":{
      "type":"structure",
      "members":{
        "AttachTime":{
          "shape":"DateTime",
          "documentation":"<p>The time stamp when the attachment initiated.</p>",
          "locationName":"attachTime"
        },
        "Device":{
          "shape":"String",
          "documentation":"<p>The device name.</p>",
          "locationName":"device"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance.</p>",
          "locationName":"instanceId"
        },
        "State":{
          "shape":"VolumeAttachmentState",
          "documentation":"<p>The attachment state of the volume.</p>",
          "locationName":"status"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume.</p>",
          "locationName":"volumeId"
        },
        "DeleteOnTermination":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the EBS volume is deleted on instance termination.</p>",
          "locationName":"deleteOnTermination"
        }
      },
      "documentation":"<p>Describes volume attachment details.</p>"
    },
    "VolumeAttachmentList":{
      "type":"list",
      "member":{
        "shape":"VolumeAttachment",
        "locationName":"item"
      }
    },
    "VolumeAttachmentState":{
      "type":"string",
      "enum":[
        "attaching",
        "attached",
        "detaching",
        "detached",
        "busy"
      ]
    },
    "VolumeAttributeName":{
      "type":"string",
      "enum":[
        "autoEnableIO",
        "productCodes"
      ]
    },
    "VolumeDetail":{
      "type":"structure",
      "required":["Size"],
      "members":{
        "Size":{
          "shape":"Long",
          "documentation":"<p>The size of the volume, in GiB.</p>",
          "locationName":"size"
        }
      },
      "documentation":"<p>Describes an EBS volume.</p>"
    },
    "VolumeId":{"type":"string"},
    "VolumeIdStringList":{
      "type":"list",
      "member":{
        "shape":"VolumeId",
        "locationName":"VolumeId"
      }
    },
    "VolumeIdWithResolver":{"type":"string"},
    "VolumeList":{
      "type":"list",
      "member":{
        "shape":"Volume",
        "locationName":"item"
      }
    },
    "VolumeModification":{
      "type":"structure",
      "members":{
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The ID of the volume.</p>",
          "locationName":"volumeId"
        },
        "ModificationState":{
          "shape":"VolumeModificationState",
          "documentation":"<p>The current modification state. The modification state is null for unmodified volumes.</p>",
          "locationName":"modificationState"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A status message about the modification progress or failure.</p>",
          "locationName":"statusMessage"
        },
        "TargetSize":{
          "shape":"Integer",
          "documentation":"<p>The target size of the volume, in GiB.</p>",
          "locationName":"targetSize"
        },
        "TargetIops":{
          "shape":"Integer",
          "documentation":"<p>The target IOPS rate of the volume.</p>",
          "locationName":"targetIops"
        },
        "TargetVolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The target EBS volume type of the volume.</p>",
          "locationName":"targetVolumeType"
        },
        "TargetThroughput":{
          "shape":"Integer",
          "documentation":"<p>The target throughput of the volume, in MiB/s.</p>",
          "locationName":"targetThroughput"
        },
        "TargetMultiAttachEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The target setting for Amazon EBS Multi-Attach.</p>",
          "locationName":"targetMultiAttachEnabled"
        },
        "OriginalSize":{
          "shape":"Integer",
          "documentation":"<p>The original size of the volume, in GiB.</p>",
          "locationName":"originalSize"
        },
        "OriginalIops":{
          "shape":"Integer",
          "documentation":"<p>The original IOPS rate of the volume.</p>",
          "locationName":"originalIops"
        },
        "OriginalVolumeType":{
          "shape":"VolumeType",
          "documentation":"<p>The original EBS volume type of the volume.</p>",
          "locationName":"originalVolumeType"
        },
        "OriginalThroughput":{
          "shape":"Integer",
          "documentation":"<p>The original throughput of the volume, in MiB/s.</p>",
          "locationName":"originalThroughput"
        },
        "OriginalMultiAttachEnabled":{
          "shape":"Boolean",
          "documentation":"<p>The original setting for Amazon EBS Multi-Attach.</p>",
          "locationName":"originalMultiAttachEnabled"
        },
        "Progress":{
          "shape":"Long",
          "documentation":"<p>The modification progress, from 0 to 100 percent complete.</p>",
          "locationName":"progress"
        },
        "StartTime":{
          "shape":"DateTime",
          "documentation":"<p>The modification start time.</p>",
          "locationName":"startTime"
        },
        "EndTime":{
          "shape":"DateTime",
          "documentation":"<p>The modification completion or failure time.</p>",
          "locationName":"endTime"
        }
      },
      "documentation":"<p>Describes the modification status of an EBS volume.</p> <p>If the volume has never been modified, some element values will be null.</p>"
    },
    "VolumeModificationList":{
      "type":"list",
      "member":{
        "shape":"VolumeModification",
        "locationName":"item"
      }
    },
    "VolumeModificationState":{
      "type":"string",
      "enum":[
        "modifying",
        "optimizing",
        "completed",
        "failed"
      ]
    },
    "VolumeState":{
      "type":"string",
      "enum":[
        "creating",
        "available",
        "in-use",
        "deleting",
        "deleted",
        "error"
      ]
    },
    "VolumeStatusAction":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"String",
          "documentation":"<p>The code identifying the operation, for example, <code>enable-volume-io</code>.</p>",
          "locationName":"code"
        },
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the operation.</p>",
          "locationName":"description"
        },
        "EventId":{
          "shape":"String",
          "documentation":"<p>The ID of the event associated with this operation.</p>",
          "locationName":"eventId"
        },
        "EventType":{
          "shape":"String",
          "documentation":"<p>The event type associated with this operation.</p>",
          "locationName":"eventType"
        }
      },
      "documentation":"<p>Describes a volume status operation code.</p>"
    },
    "VolumeStatusActionsList":{
      "type":"list",
      "member":{
        "shape":"VolumeStatusAction",
        "locationName":"item"
      }
    },
    "VolumeStatusAttachmentStatus":{
      "type":"structure",
      "members":{
        "IoPerformance":{
          "shape":"String",
          "documentation":"<p>The maximum IOPS supported by the attached instance.</p>",
          "locationName":"ioPerformance"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the attached instance.</p>",
          "locationName":"instanceId"
        }
      },
      "documentation":"<p>Information about the instances to which the volume is attached.</p>"
    },
    "VolumeStatusAttachmentStatusList":{
      "type":"list",
      "member":{
        "shape":"VolumeStatusAttachmentStatus",
        "locationName":"item"
      }
    },
    "VolumeStatusDetails":{
      "type":"structure",
      "members":{
        "Name":{
          "shape":"VolumeStatusName",
          "documentation":"<p>The name of the volume status.</p>",
          "locationName":"name"
        },
        "Status":{
          "shape":"String",
          "documentation":"<p>The intended status of the volume status.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Describes a volume status.</p>"
    },
    "VolumeStatusDetailsList":{
      "type":"list",
      "member":{
        "shape":"VolumeStatusDetails",
        "locationName":"item"
      }
    },
    "VolumeStatusEvent":{
      "type":"structure",
      "members":{
        "Description":{
          "shape":"String",
          "documentation":"<p>A description of the event.</p>",
          "locationName":"description"
        },
        "EventId":{
          "shape":"String",
          "documentation":"<p>The ID of this event.</p>",
          "locationName":"eventId"
        },
        "EventType":{
          "shape":"String",
          "documentation":"<p>The type of this event.</p>",
          "locationName":"eventType"
        },
        "NotAfter":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The latest end time of the event.</p>",
          "locationName":"notAfter"
        },
        "NotBefore":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The earliest start time of the event.</p>",
          "locationName":"notBefore"
        },
        "InstanceId":{
          "shape":"String",
          "documentation":"<p>The ID of the instance associated with the event.</p>",
          "locationName":"instanceId"
        }
      },
      "documentation":"<p>Describes a volume status event.</p>"
    },
    "VolumeStatusEventsList":{
      "type":"list",
      "member":{
        "shape":"VolumeStatusEvent",
        "locationName":"item"
      }
    },
    "VolumeStatusInfo":{
      "type":"structure",
      "members":{
        "Details":{
          "shape":"VolumeStatusDetailsList",
          "documentation":"<p>The details of the volume status.</p>",
          "locationName":"details"
        },
        "Status":{
          "shape":"VolumeStatusInfoStatus",
          "documentation":"<p>The status of the volume.</p>",
          "locationName":"status"
        }
      },
      "documentation":"<p>Describes the status of a volume.</p>"
    },
    "VolumeStatusInfoStatus":{
      "type":"string",
      "enum":[
        "ok",
        "impaired",
        "insufficient-data"
      ]
    },
    "VolumeStatusItem":{
      "type":"structure",
      "members":{
        "Actions":{
          "shape":"VolumeStatusActionsList",
          "documentation":"<p>The details of the operation.</p>",
          "locationName":"actionsSet"
        },
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone of the volume.</p>",
          "locationName":"availabilityZone"
        },
        "OutpostArn":{
          "shape":"String",
          "documentation":"<p>The Amazon Resource Name (ARN) of the Outpost.</p>",
          "locationName":"outpostArn"
        },
        "Events":{
          "shape":"VolumeStatusEventsList",
          "documentation":"<p>A list of events associated with the volume.</p>",
          "locationName":"eventsSet"
        },
        "VolumeId":{
          "shape":"String",
          "documentation":"<p>The volume ID.</p>",
          "locationName":"volumeId"
        },
        "VolumeStatus":{
          "shape":"VolumeStatusInfo",
          "documentation":"<p>The volume status.</p>",
          "locationName":"volumeStatus"
        },
        "AttachmentStatuses":{
          "shape":"VolumeStatusAttachmentStatusList",
          "documentation":"<p>Information about the instances to which the volume is attached.</p>",
          "locationName":"attachmentStatuses"
        }
      },
      "documentation":"<p>Describes the volume status.</p>"
    },
    "VolumeStatusList":{
      "type":"list",
      "member":{
        "shape":"VolumeStatusItem",
        "locationName":"item"
      }
    },
    "VolumeStatusName":{
      "type":"string",
      "enum":[
        "io-enabled",
        "io-performance"
      ]
    },
    "VolumeType":{
      "type":"string",
      "enum":[
        "standard",
        "io1",
        "io2",
        "gp2",
        "sc1",
        "st1",
        "gp3"
      ]
    },
    "Vpc":{
      "type":"structure",
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The primary IPv4 CIDR block for the VPC.</p>",
          "locationName":"cidrBlock"
        },
        "DhcpOptionsId":{
          "shape":"String",
          "documentation":"<p>The ID of the set of DHCP options you've associated with the VPC.</p>",
          "locationName":"dhcpOptionsId"
        },
        "State":{
          "shape":"VpcState",
          "documentation":"<p>The current state of the VPC.</p>",
          "locationName":"state"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the VPC.</p>",
          "locationName":"ownerId"
        },
        "InstanceTenancy":{
          "shape":"Tenancy",
          "documentation":"<p>The allowed tenancy of instances launched into the VPC.</p>",
          "locationName":"instanceTenancy"
        },
        "Ipv6CidrBlockAssociationSet":{
          "shape":"VpcIpv6CidrBlockAssociationSet",
          "documentation":"<p>Information about the IPv6 CIDR blocks associated with the VPC.</p>",
          "locationName":"ipv6CidrBlockAssociationSet"
        },
        "CidrBlockAssociationSet":{
          "shape":"VpcCidrBlockAssociationSet",
          "documentation":"<p>Information about the IPv4 CIDR blocks associated with the VPC.</p>",
          "locationName":"cidrBlockAssociationSet"
        },
        "IsDefault":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the VPC is the default VPC.</p>",
          "locationName":"isDefault"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the VPC.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a VPC.</p>"
    },
    "VpcAttachment":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"AttachmentStatus",
          "documentation":"<p>The current state of the attachment.</p>",
          "locationName":"state"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<p>Describes an attachment between a virtual private gateway and a VPC.</p>"
    },
    "VpcAttachmentList":{
      "type":"list",
      "member":{
        "shape":"VpcAttachment",
        "locationName":"item"
      }
    },
    "VpcAttributeName":{
      "type":"string",
      "enum":[
        "enableDnsSupport",
        "enableDnsHostnames",
        "enableNetworkAddressUsageMetrics"
      ]
    },
    "VpcCidrAssociationId":{"type":"string"},
    "VpcCidrBlockAssociation":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The association ID for the IPv4 CIDR block.</p>",
          "locationName":"associationId"
        },
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR block.</p>",
          "locationName":"cidrBlock"
        },
        "CidrBlockState":{
          "shape":"VpcCidrBlockState",
          "documentation":"<p>Information about the state of the CIDR block.</p>",
          "locationName":"cidrBlockState"
        }
      },
      "documentation":"<p>Describes an IPv4 CIDR block associated with a VPC.</p>"
    },
    "VpcCidrBlockAssociationSet":{
      "type":"list",
      "member":{
        "shape":"VpcCidrBlockAssociation",
        "locationName":"item"
      }
    },
    "VpcCidrBlockState":{
      "type":"structure",
      "members":{
        "State":{
          "shape":"VpcCidrBlockStateCode",
          "documentation":"<p>The state of the CIDR block.</p>",
          "locationName":"state"
        },
        "StatusMessage":{
          "shape":"String",
          "documentation":"<p>A message about the status of the CIDR block, if applicable.</p>",
          "locationName":"statusMessage"
        }
      },
      "documentation":"<p>Describes the state of a CIDR block.</p>"
    },
    "VpcCidrBlockStateCode":{
      "type":"string",
      "enum":[
        "associating",
        "associated",
        "disassociating",
        "disassociated",
        "failing",
        "failed"
      ]
    },
    "VpcClassicLink":{
      "type":"structure",
      "members":{
        "ClassicLinkEnabled":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the VPC is enabled for ClassicLink.</p>",
          "locationName":"classicLinkEnabled"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the VPC.</p>",
          "locationName":"tagSet"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        }
      },
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Describes whether a VPC is enabled for ClassicLink.</p>"
    },
    "VpcClassicLinkIdList":{
      "type":"list",
      "member":{
        "shape":"VpcId",
        "locationName":"VpcId"
      }
    },
    "VpcClassicLinkList":{
      "type":"list",
      "member":{
        "shape":"VpcClassicLink",
        "locationName":"item"
      }
    },
    "VpcEndpoint":{
      "type":"structure",
      "members":{
        "VpcEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the endpoint.</p>",
          "locationName":"vpcEndpointId"
        },
        "VpcEndpointType":{
          "shape":"VpcEndpointType",
          "documentation":"<p>The type of endpoint.</p>",
          "locationName":"vpcEndpointType"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC to which the endpoint is associated.</p>",
          "locationName":"vpcId"
        },
        "ServiceName":{
          "shape":"String",
          "documentation":"<p>The name of the service to which the endpoint is associated.</p>",
          "locationName":"serviceName"
        },
        "State":{
          "shape":"State",
          "documentation":"<p>The state of the endpoint.</p>",
          "locationName":"state"
        },
        "PolicyDocument":{
          "shape":"String",
          "documentation":"<p>The policy document associated with the endpoint, if applicable.</p>",
          "locationName":"policyDocument"
        },
        "RouteTableIds":{
          "shape":"ValueStringList",
          "documentation":"<p>(Gateway endpoint) The IDs of the route tables associated with the endpoint.</p>",
          "locationName":"routeTableIdSet"
        },
        "SubnetIds":{
          "shape":"ValueStringList",
          "documentation":"<p>(Interface endpoint) The subnets for the endpoint.</p>",
          "locationName":"subnetIdSet"
        },
        "Groups":{
          "shape":"GroupIdentifierSet",
          "documentation":"<p>(Interface endpoint) Information about the security groups that are associated with the network interface.</p>",
          "locationName":"groupSet"
        },
        "IpAddressType":{
          "shape":"IpAddressType",
          "documentation":"<p>The IP address type for the endpoint.</p>",
          "locationName":"ipAddressType"
        },
        "DnsOptions":{
          "shape":"DnsOptions",
          "documentation":"<p>The DNS options for the endpoint.</p>",
          "locationName":"dnsOptions"
        },
        "PrivateDnsEnabled":{
          "shape":"Boolean",
          "documentation":"<p>(Interface endpoint) Indicates whether the VPC is associated with a private hosted zone.</p>",
          "locationName":"privateDnsEnabled"
        },
        "RequesterManaged":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the endpoint is being managed by its service.</p>",
          "locationName":"requesterManaged"
        },
        "NetworkInterfaceIds":{
          "shape":"ValueStringList",
          "documentation":"<p>(Interface endpoint) The network interfaces for the endpoint.</p>",
          "locationName":"networkInterfaceIdSet"
        },
        "DnsEntries":{
          "shape":"DnsEntrySet",
          "documentation":"<p>(Interface endpoint) The DNS entries for the endpoint.</p>",
          "locationName":"dnsEntrySet"
        },
        "CreationTimestamp":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time that the endpoint was created.</p>",
          "locationName":"creationTimestamp"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags assigned to the endpoint.</p>",
          "locationName":"tagSet"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the endpoint.</p>",
          "locationName":"ownerId"
        },
        "LastError":{
          "shape":"LastError",
          "documentation":"<p>The last error that occurred for endpoint.</p>",
          "locationName":"lastError"
        }
      },
      "documentation":"<p>Describes a VPC endpoint.</p>"
    },
    "VpcEndpointConnection":{
      "type":"structure",
      "members":{
        "ServiceId":{
          "shape":"String",
          "documentation":"<p>The ID of the service to which the endpoint is connected.</p>",
          "locationName":"serviceId"
        },
        "VpcEndpointId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC endpoint.</p>",
          "locationName":"vpcEndpointId"
        },
        "VpcEndpointOwner":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the VPC endpoint.</p>",
          "locationName":"vpcEndpointOwner"
        },
        "VpcEndpointState":{
          "shape":"State",
          "documentation":"<p>The state of the VPC endpoint.</p>",
          "locationName":"vpcEndpointState"
        },
        "CreationTimestamp":{
          "shape":"MillisecondDateTime",
          "documentation":"<p>The date and time that the VPC endpoint was created.</p>",
          "locationName":"creationTimestamp"
        },
        "DnsEntries":{
          "shape":"DnsEntrySet",
          "documentation":"<p>The DNS entries for the VPC endpoint.</p>",
          "locationName":"dnsEntrySet"
        },
        "NetworkLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of the network load balancers for the service.</p>",
          "locationName":"networkLoadBalancerArnSet"
        },
        "GatewayLoadBalancerArns":{
          "shape":"ValueStringList",
          "documentation":"<p>The Amazon Resource Names (ARNs) of the Gateway Load Balancers for the service.</p>",
          "locationName":"gatewayLoadBalancerArnSet"
        },
        "IpAddressType":{
          "shape":"IpAddressType",
          "documentation":"<p>The IP address type for the endpoint.</p>",
          "locationName":"ipAddressType"
        },
        "VpcEndpointConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC endpoint connection.</p>",
          "locationName":"vpcEndpointConnectionId"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>The tags.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a VPC endpoint connection to a service.</p>"
    },
    "VpcEndpointConnectionSet":{
      "type":"list",
      "member":{
        "shape":"VpcEndpointConnection",
        "locationName":"item"
      }
    },
    "VpcEndpointId":{"type":"string"},
    "VpcEndpointIdList":{
      "type":"list",
      "member":{
        "shape":"VpcEndpointId",
        "locationName":"item"
      }
    },
    "VpcEndpointRouteTableIdList":{
      "type":"list",
      "member":{
        "shape":"RouteTableId",
        "locationName":"item"
      }
    },
    "VpcEndpointSecurityGroupIdList":{
      "type":"list",
      "member":{
        "shape":"SecurityGroupId",
        "locationName":"item"
      }
    },
    "VpcEndpointServiceId":{"type":"string"},
    "VpcEndpointServiceIdList":{
      "type":"list",
      "member":{
        "shape":"VpcEndpointServiceId",
        "locationName":"item"
      }
    },
    "VpcEndpointSet":{
      "type":"list",
      "member":{
        "shape":"VpcEndpoint",
        "locationName":"item"
      }
    },
    "VpcEndpointSubnetIdList":{
      "type":"list",
      "member":{
        "shape":"SubnetId",
        "locationName":"item"
      }
    },
    "VpcEndpointType":{
      "type":"string",
      "enum":[
        "Interface",
        "Gateway",
        "GatewayLoadBalancer"
      ]
    },
    "VpcFlowLogId":{"type":"string"},
    "VpcId":{"type":"string"},
    "VpcIdStringList":{
      "type":"list",
      "member":{
        "shape":"VpcId",
        "locationName":"VpcId"
      }
    },
    "VpcIpv6CidrBlockAssociation":{
      "type":"structure",
      "members":{
        "AssociationId":{
          "shape":"String",
          "documentation":"<p>The association ID for the IPv6 CIDR block.</p>",
          "locationName":"associationId"
        },
        "Ipv6CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR block.</p>",
          "locationName":"ipv6CidrBlock"
        },
        "Ipv6CidrBlockState":{
          "shape":"VpcCidrBlockState",
          "documentation":"<p>Information about the state of the CIDR block.</p>",
          "locationName":"ipv6CidrBlockState"
        },
        "NetworkBorderGroup":{
          "shape":"String",
          "documentation":"<p>The name of the unique set of Availability Zones, Local Zones, or Wavelength Zones from which Amazon Web Services advertises IP addresses, for example, <code>us-east-1-wl1-bos-wlz-1</code>.</p>",
          "locationName":"networkBorderGroup"
        },
        "Ipv6Pool":{
          "shape":"String",
          "documentation":"<p>The ID of the IPv6 address pool from which the IPv6 CIDR block is allocated.</p>",
          "locationName":"ipv6Pool"
        }
      },
      "documentation":"<p>Describes an IPv6 CIDR block associated with a VPC.</p>"
    },
    "VpcIpv6CidrBlockAssociationSet":{
      "type":"list",
      "member":{
        "shape":"VpcIpv6CidrBlockAssociation",
        "locationName":"item"
      }
    },
    "VpcList":{
      "type":"list",
      "member":{
        "shape":"Vpc",
        "locationName":"item"
      }
    },
    "VpcPeeringConnection":{
      "type":"structure",
      "members":{
        "AccepterVpcInfo":{
          "shape":"VpcPeeringConnectionVpcInfo",
          "documentation":"<p>Information about the accepter VPC. CIDR block information is only returned when describing an active VPC peering connection.</p>",
          "locationName":"accepterVpcInfo"
        },
        "ExpirationTime":{
          "shape":"DateTime",
          "documentation":"<p>The time that an unaccepted VPC peering connection will expire.</p>",
          "locationName":"expirationTime"
        },
        "RequesterVpcInfo":{
          "shape":"VpcPeeringConnectionVpcInfo",
          "documentation":"<p>Information about the requester VPC. CIDR block information is only returned when describing an active VPC peering connection.</p>",
          "locationName":"requesterVpcInfo"
        },
        "Status":{
          "shape":"VpcPeeringConnectionStateReason",
          "documentation":"<p>The status of the VPC peering connection.</p>",
          "locationName":"status"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the resource.</p>",
          "locationName":"tagSet"
        },
        "VpcPeeringConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC peering connection.</p>",
          "locationName":"vpcPeeringConnectionId"
        }
      },
      "documentation":"<p>Describes a VPC peering connection.</p>"
    },
    "VpcPeeringConnectionId":{"type":"string"},
    "VpcPeeringConnectionIdList":{
      "type":"list",
      "member":{
        "shape":"VpcPeeringConnectionId",
        "locationName":"item"
      }
    },
    "VpcPeeringConnectionIdWithResolver":{"type":"string"},
    "VpcPeeringConnectionList":{
      "type":"list",
      "member":{
        "shape":"VpcPeeringConnection",
        "locationName":"item"
      }
    },
    "VpcPeeringConnectionOptionsDescription":{
      "type":"structure",
      "members":{
        "AllowDnsResolutionFromRemoteVpc":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether a local VPC can resolve public DNS hostnames to private IP addresses when queried from instances in a peer VPC.</p>",
          "locationName":"allowDnsResolutionFromRemoteVpc"
        },
        "AllowEgressFromLocalClassicLinkToRemoteVpc":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether a local ClassicLink connection can communicate with the peer VPC over the VPC peering connection.</p>",
          "locationName":"allowEgressFromLocalClassicLinkToRemoteVpc"
        },
        "AllowEgressFromLocalVpcToRemoteClassicLink":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether a local VPC can communicate with a ClassicLink connection in the peer VPC over the VPC peering connection.</p>",
          "locationName":"allowEgressFromLocalVpcToRemoteClassicLink"
        }
      },
      "documentation":"<note> <p>We are retiring EC2-Classic. We recommend that you migrate from EC2-Classic to a VPC. For more information, see <a href=\"https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/vpc-migrate.html\">Migrate from EC2-Classic to a VPC</a> in the <i>Amazon Elastic Compute Cloud User Guide</i>.</p> </note> <p>Describes the VPC peering connection options.</p>"
    },
    "VpcPeeringConnectionStateReason":{
      "type":"structure",
      "members":{
        "Code":{
          "shape":"VpcPeeringConnectionStateReasonCode",
          "documentation":"<p>The status of the VPC peering connection.</p>",
          "locationName":"code"
        },
        "Message":{
          "shape":"String",
          "documentation":"<p>A message that provides more information about the status, if applicable.</p>",
          "locationName":"message"
        }
      },
      "documentation":"<p>Describes the status of a VPC peering connection.</p>"
    },
    "VpcPeeringConnectionStateReasonCode":{
      "type":"string",
      "enum":[
        "initiating-request",
        "pending-acceptance",
        "active",
        "deleted",
        "rejected",
        "failed",
        "expired",
        "provisioning",
        "deleting"
      ]
    },
    "VpcPeeringConnectionVpcInfo":{
      "type":"structure",
      "members":{
        "CidrBlock":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR block for the VPC.</p>",
          "locationName":"cidrBlock"
        },
        "Ipv6CidrBlockSet":{
          "shape":"Ipv6CidrBlockSet",
          "documentation":"<p>The IPv6 CIDR block for the VPC.</p>",
          "locationName":"ipv6CidrBlockSet"
        },
        "CidrBlockSet":{
          "shape":"CidrBlockSet",
          "documentation":"<p>Information about the IPv4 CIDR blocks for the VPC.</p>",
          "locationName":"cidrBlockSet"
        },
        "OwnerId":{
          "shape":"String",
          "documentation":"<p>The ID of the Amazon Web Services account that owns the VPC.</p>",
          "locationName":"ownerId"
        },
        "PeeringOptions":{
          "shape":"VpcPeeringConnectionOptionsDescription",
          "documentation":"<p>Information about the VPC peering connection options for the accepter or requester VPC.</p>",
          "locationName":"peeringOptions"
        },
        "VpcId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPC.</p>",
          "locationName":"vpcId"
        },
        "Region":{
          "shape":"String",
          "documentation":"<p>The Region in which the VPC is located.</p>",
          "locationName":"region"
        }
      },
      "documentation":"<p>Describes a VPC in a VPC peering connection.</p>"
    },
    "VpcState":{
      "type":"string",
      "enum":[
        "pending",
        "available"
      ]
    },
    "VpcTenancy":{
      "type":"string",
      "enum":["default"]
    },
    "VpnConnection":{
      "type":"structure",
      "members":{
        "CustomerGatewayConfiguration":{
          "shape":"String",
          "documentation":"<p>The configuration information for the VPN connection's customer gateway (in the native XML format). This element is always present in the <a>CreateVpnConnection</a> response; however, it's present in the <a>DescribeVpnConnections</a> response only if the VPN connection is in the <code>pending</code> or <code>available</code> state.</p>",
          "locationName":"customerGatewayConfiguration"
        },
        "CustomerGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the customer gateway at your end of the VPN connection.</p>",
          "locationName":"customerGatewayId"
        },
        "Category":{
          "shape":"String",
          "documentation":"<p>The category of the VPN connection. A value of <code>VPN</code> indicates an Amazon Web Services VPN connection. A value of <code>VPN-Classic</code> indicates an Amazon Web Services Classic VPN connection.</p>",
          "locationName":"category"
        },
        "State":{
          "shape":"VpnState",
          "documentation":"<p>The current state of the VPN connection.</p>",
          "locationName":"state"
        },
        "Type":{
          "shape":"GatewayType",
          "documentation":"<p>The type of VPN connection.</p>",
          "locationName":"type"
        },
        "VpnConnectionId":{
          "shape":"String",
          "documentation":"<p>The ID of the VPN connection.</p>",
          "locationName":"vpnConnectionId"
        },
        "VpnGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the virtual private gateway at the Amazon Web Services side of the VPN connection.</p>",
          "locationName":"vpnGatewayId"
        },
        "TransitGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the transit gateway associated with the VPN connection.</p>",
          "locationName":"transitGatewayId"
        },
        "CoreNetworkArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the core network.</p>",
          "locationName":"coreNetworkArn"
        },
        "CoreNetworkAttachmentArn":{
          "shape":"String",
          "documentation":"<p>The ARN of the core network attachment.</p>",
          "locationName":"coreNetworkAttachmentArn"
        },
        "GatewayAssociationState":{
          "shape":"GatewayAssociationState",
          "documentation":"<p>The current state of the gateway association.</p>",
          "locationName":"gatewayAssociationState"
        },
        "Options":{
          "shape":"VpnConnectionOptions",
          "documentation":"<p>The VPN connection options.</p>",
          "locationName":"options"
        },
        "Routes":{
          "shape":"VpnStaticRouteList",
          "documentation":"<p>The static routes associated with the VPN connection.</p>",
          "locationName":"routes"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the VPN connection.</p>",
          "locationName":"tagSet"
        },
        "VgwTelemetry":{
          "shape":"VgwTelemetryList",
          "documentation":"<p>Information about the VPN tunnel.</p>",
          "locationName":"vgwTelemetry"
        }
      },
      "documentation":"<p>Describes a VPN connection.</p>"
    },
    "VpnConnectionDeviceSampleConfiguration":{
      "type":"string",
      "sensitive":true
    },
    "VpnConnectionDeviceType":{
      "type":"structure",
      "members":{
        "VpnConnectionDeviceTypeId":{
          "shape":"String",
          "documentation":"<p>Customer gateway device identifier.</p>",
          "locationName":"vpnConnectionDeviceTypeId"
        },
        "Vendor":{
          "shape":"String",
          "documentation":"<p>Customer gateway device vendor.</p>",
          "locationName":"vendor"
        },
        "Platform":{
          "shape":"String",
          "documentation":"<p>Customer gateway device platform.</p>",
          "locationName":"platform"
        },
        "Software":{
          "shape":"String",
          "documentation":"<p>Customer gateway device software version.</p>",
          "locationName":"software"
        }
      },
      "documentation":"<p>List of customer gateway devices that have a sample configuration file available for use. You can also see the list of device types with sample configuration files available under <a href=\"https://docs.aws.amazon.com/vpn/latest/s2svpn/your-cgw.html\">Your customer gateway device</a> in the <i>Amazon Web Services Site-to-Site VPN User Guide</i>.</p>"
    },
    "VpnConnectionDeviceTypeId":{"type":"string"},
    "VpnConnectionDeviceTypeList":{
      "type":"list",
      "member":{
        "shape":"VpnConnectionDeviceType",
        "locationName":"item"
      }
    },
    "VpnConnectionId":{"type":"string"},
    "VpnConnectionIdStringList":{
      "type":"list",
      "member":{
        "shape":"VpnConnectionId",
        "locationName":"VpnConnectionId"
      }
    },
    "VpnConnectionList":{
      "type":"list",
      "member":{
        "shape":"VpnConnection",
        "locationName":"item"
      }
    },
    "VpnConnectionOptions":{
      "type":"structure",
      "members":{
        "EnableAcceleration":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether acceleration is enabled for the VPN connection.</p>",
          "locationName":"enableAcceleration"
        },
        "StaticRoutesOnly":{
          "shape":"Boolean",
          "documentation":"<p>Indicates whether the VPN connection uses static routes only. Static routes must be used for devices that don't support BGP.</p>",
          "locationName":"staticRoutesOnly"
        },
        "LocalIpv4NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR on the customer gateway (on-premises) side of the VPN connection.</p>",
          "locationName":"localIpv4NetworkCidr"
        },
        "RemoteIpv4NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR on the Amazon Web Services side of the VPN connection.</p>",
          "locationName":"remoteIpv4NetworkCidr"
        },
        "LocalIpv6NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR on the customer gateway (on-premises) side of the VPN connection.</p>",
          "locationName":"localIpv6NetworkCidr"
        },
        "RemoteIpv6NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR on the Amazon Web Services side of the VPN connection.</p>",
          "locationName":"remoteIpv6NetworkCidr"
        },
        "OutsideIpAddressType":{
          "shape":"String",
          "documentation":"<p>The type of IPv4 address assigned to the outside interface of the customer gateway.</p> <p>Valid values: <code>PrivateIpv4</code> | <code>PublicIpv4</code> </p> <p>Default: <code>PublicIpv4</code> </p>",
          "locationName":"outsideIpAddressType"
        },
        "TransportTransitGatewayAttachmentId":{
          "shape":"String",
          "documentation":"<p>The transit gateway attachment ID in use for the VPN tunnel.</p>",
          "locationName":"transportTransitGatewayAttachmentId"
        },
        "TunnelInsideIpVersion":{
          "shape":"TunnelInsideIpVersion",
          "documentation":"<p>Indicates whether the VPN tunnels process IPv4 or IPv6 traffic.</p>",
          "locationName":"tunnelInsideIpVersion"
        },
        "TunnelOptions":{
          "shape":"TunnelOptionsList",
          "documentation":"<p>Indicates the VPN tunnel options.</p>",
          "locationName":"tunnelOptionSet"
        }
      },
      "documentation":"<p>Describes VPN connection options.</p>"
    },
    "VpnConnectionOptionsSpecification":{
      "type":"structure",
      "members":{
        "EnableAcceleration":{
          "shape":"Boolean",
          "documentation":"<p>Indicate whether to enable acceleration for the VPN connection.</p> <p>Default: <code>false</code> </p>"
        },
        "StaticRoutesOnly":{
          "shape":"Boolean",
          "documentation":"<p>Indicate whether the VPN connection uses static routes only. If you are creating a VPN connection for a device that does not support BGP, you must specify <code>true</code>. Use <a>CreateVpnConnectionRoute</a> to create a static route.</p> <p>Default: <code>false</code> </p>",
          "locationName":"staticRoutesOnly"
        },
        "TunnelInsideIpVersion":{
          "shape":"TunnelInsideIpVersion",
          "documentation":"<p>Indicate whether the VPN tunnels process IPv4 or IPv6 traffic.</p> <p>Default: <code>ipv4</code> </p>"
        },
        "TunnelOptions":{
          "shape":"VpnTunnelOptionsSpecificationsList",
          "documentation":"<p>The tunnel options for the VPN connection.</p>"
        },
        "LocalIpv4NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR on the customer gateway (on-premises) side of the VPN connection.</p> <p>Default: <code>0.0.0.0/0</code> </p>"
        },
        "RemoteIpv4NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv4 CIDR on the Amazon Web Services side of the VPN connection.</p> <p>Default: <code>0.0.0.0/0</code> </p>"
        },
        "LocalIpv6NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR on the customer gateway (on-premises) side of the VPN connection.</p> <p>Default: <code>::/0</code> </p>"
        },
        "RemoteIpv6NetworkCidr":{
          "shape":"String",
          "documentation":"<p>The IPv6 CIDR on the Amazon Web Services side of the VPN connection.</p> <p>Default: <code>::/0</code> </p>"
        },
        "OutsideIpAddressType":{
          "shape":"String",
          "documentation":"<p>The type of IPv4 address assigned to the outside interface of the customer gateway device.</p> <p>Valid values: <code>PrivateIpv4</code> | <code>PublicIpv4</code> </p> <p>Default: <code>PublicIpv4</code> </p>"
        },
        "TransportTransitGatewayAttachmentId":{
          "shape":"TransitGatewayAttachmentId",
          "documentation":"<p>The transit gateway attachment ID to use for the VPN tunnel.</p> <p>Required if <code>OutsideIpAddressType</code> is set to <code>PrivateIpv4</code>.</p>"
        }
      },
      "documentation":"<p>Describes VPN connection options.</p>"
    },
    "VpnEcmpSupportValue":{
      "type":"string",
      "enum":[
        "enable",
        "disable"
      ]
    },
    "VpnGateway":{
      "type":"structure",
      "members":{
        "AvailabilityZone":{
          "shape":"String",
          "documentation":"<p>The Availability Zone where the virtual private gateway was created, if applicable. This field may be empty or not returned.</p>",
          "locationName":"availabilityZone"
        },
        "State":{
          "shape":"VpnState",
          "documentation":"<p>The current state of the virtual private gateway.</p>",
          "locationName":"state"
        },
        "Type":{
          "shape":"GatewayType",
          "documentation":"<p>The type of VPN connection the virtual private gateway supports.</p>",
          "locationName":"type"
        },
        "VpcAttachments":{
          "shape":"VpcAttachmentList",
          "documentation":"<p>Any VPCs attached to the virtual private gateway.</p>",
          "locationName":"attachments"
        },
        "VpnGatewayId":{
          "shape":"String",
          "documentation":"<p>The ID of the virtual private gateway.</p>",
          "locationName":"vpnGatewayId"
        },
        "AmazonSideAsn":{
          "shape":"Long",
          "documentation":"<p>The private Autonomous System Number (ASN) for the Amazon side of a BGP session.</p>",
          "locationName":"amazonSideAsn"
        },
        "Tags":{
          "shape":"TagList",
          "documentation":"<p>Any tags assigned to the virtual private gateway.</p>",
          "locationName":"tagSet"
        }
      },
      "documentation":"<p>Describes a virtual private gateway.</p>"
    },
    "VpnGatewayId":{"type":"string"},
    "VpnGatewayIdStringList":{
      "type":"list",
      "member":{
        "shape":"VpnGatewayId",
        "locationName":"VpnGatewayId"
      }
    },
    "VpnGatewayList":{
      "type":"list",
      "member":{
        "shape":"VpnGateway",
        "locationName":"item"
      }
    },
    "VpnProtocol":{
      "type":"string",
      "enum":["openvpn"]
    },
    "VpnState":{
      "type":"string",
      "enum":[
        "pending",
        "available",
        "deleting",
        "deleted"
      ]
    },
    "VpnStaticRoute":{
      "type":"structure",
      "members":{
        "DestinationCidrBlock":{
          "shape":"String",
          "documentation":"<p>The CIDR block associated with the local subnet of the customer data center.</p>",
          "locationName":"destinationCidrBlock"
        },
        "Source":{
          "shape":"VpnStaticRouteSource",
          "documentation":"<p>Indicates how the routes were provided.</p>",
          "locationName":"source"
        },
        "State":{
          "shape":"VpnState",
          "documentation":"<p>The current state of the static route.</p>",
          "locationName":"state"
        }
      },
      "documentation":"<p>Describes a static route for a VPN connection.</p>"
    },
    "VpnStaticRouteList":{
      "type":"list",
      "member":{
        "shape":"VpnStaticRoute",
        "locationName":"item"
      }
    },
    "VpnStaticRouteSource":{
      "type":"string",
      "enum":["Static"]
    },
    "VpnTunnelLogOptions":{
      "type":"structure",
      "members":{
        "CloudWatchLogOptions":{
          "shape":"CloudWatchLogOptions",
          "documentation":"<p>Options for sending VPN tunnel logs to CloudWatch.</p>",
          "locationName":"cloudWatchLogOptions"
        }
      },
      "documentation":"<p>Options for logging VPN tunnel activity.</p>"
    },
    "VpnTunnelLogOptionsSpecification":{
      "type":"structure",
      "members":{
        "CloudWatchLogOptions":{
          "shape":"CloudWatchLogOptionsSpecification",
          "documentation":"<p>Options for sending VPN tunnel logs to CloudWatch.</p>"
        }
      },
      "documentation":"<p>Options for logging VPN tunnel activity.</p>"
    },
    "VpnTunnelOptionsSpecification":{
      "type":"structure",
      "members":{
        "TunnelInsideCidr":{
          "shape":"String",
          "documentation":"<p>The range of inside IPv4 addresses for the tunnel. Any specified CIDR blocks must be unique across all VPN connections that use the same virtual private gateway. </p> <p>Constraints: A size /30 CIDR block from the <code>169.254.0.0/16</code> range. The following CIDR blocks are reserved and cannot be used:</p> <ul> <li> <p> <code>169.254.0.0/30</code> </p> </li> <li> <p> <code>169.254.1.0/30</code> </p> </li> <li> <p> <code>169.254.2.0/30</code> </p> </li> <li> <p> <code>169.254.3.0/30</code> </p> </li> <li> <p> <code>169.254.4.0/30</code> </p> </li> <li> <p> <code>169.254.5.0/30</code> </p> </li> <li> <p> <code>169.254.169.252/30</code> </p> </li> </ul>"
        },
        "TunnelInsideIpv6Cidr":{
          "shape":"String",
          "documentation":"<p>The range of inside IPv6 addresses for the tunnel. Any specified CIDR blocks must be unique across all VPN connections that use the same transit gateway.</p> <p>Constraints: A size /126 CIDR block from the local <code>fd00::/8</code> range.</p>"
        },
        "PreSharedKey":{
          "shape":"String",
          "documentation":"<p>The pre-shared key (PSK) to establish initial authentication between the virtual private gateway and customer gateway.</p> <p>Constraints: Allowed characters are alphanumeric characters, periods (.), and underscores (_). Must be between 8 and 64 characters in length and cannot start with zero (0).</p>"
        },
        "Phase1LifetimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The lifetime for phase 1 of the IKE negotiation, in seconds.</p> <p>Constraints: A value between 900 and 28,800.</p> <p>Default: <code>28800</code> </p>"
        },
        "Phase2LifetimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The lifetime for phase 2 of the IKE negotiation, in seconds.</p> <p>Constraints: A value between 900 and 3,600. The value must be less than the value for <code>Phase1LifetimeSeconds</code>.</p> <p>Default: <code>3600</code> </p>"
        },
        "RekeyMarginTimeSeconds":{
          "shape":"Integer",
          "documentation":"<p>The margin time, in seconds, before the phase 2 lifetime expires, during which the Amazon Web Services side of the VPN connection performs an IKE rekey. The exact time of the rekey is randomly selected based on the value for <code>RekeyFuzzPercentage</code>.</p> <p>Constraints: A value between 60 and half of <code>Phase2LifetimeSeconds</code>.</p> <p>Default: <code>540</code> </p>"
        },
        "RekeyFuzzPercentage":{
          "shape":"Integer",
          "documentation":"<p>The percentage of the rekey window (determined by <code>RekeyMarginTimeSeconds</code>) during which the rekey time is randomly selected.</p> <p>Constraints: A value between 0 and 100.</p> <p>Default: <code>100</code> </p>"
        },
        "ReplayWindowSize":{
          "shape":"Integer",
          "documentation":"<p>The number of packets in an IKE replay window.</p> <p>Constraints: A value between 64 and 2048.</p> <p>Default: <code>1024</code> </p>"
        },
        "DPDTimeoutSeconds":{
          "shape":"Integer",
          "documentation":"<p>The number of seconds after which a DPD timeout occurs.</p> <p>Constraints: A value greater than or equal to 30.</p> <p>Default: <code>30</code> </p>"
        },
        "DPDTimeoutAction":{
          "shape":"String",
          "documentation":"<p>The action to take after DPD timeout occurs. Specify <code>restart</code> to restart the IKE initiation. Specify <code>clear</code> to end the IKE session.</p> <p>Valid Values: <code>clear</code> | <code>none</code> | <code>restart</code> </p> <p>Default: <code>clear</code> </p>"
        },
        "Phase1EncryptionAlgorithms":{
          "shape":"Phase1EncryptionAlgorithmsRequestList",
          "documentation":"<p>One or more encryption algorithms that are permitted for the VPN tunnel for phase 1 IKE negotiations.</p> <p>Valid values: <code>AES128</code> | <code>AES256</code> | <code>AES128-GCM-16</code> | <code>AES256-GCM-16</code> </p>",
          "locationName":"Phase1EncryptionAlgorithm"
        },
        "Phase2EncryptionAlgorithms":{
          "shape":"Phase2EncryptionAlgorithmsRequestList",
          "documentation":"<p>One or more encryption algorithms that are permitted for the VPN tunnel for phase 2 IKE negotiations.</p> <p>Valid values: <code>AES128</code> | <code>AES256</code> | <code>AES128-GCM-16</code> | <code>AES256-GCM-16</code> </p>",
          "locationName":"Phase2EncryptionAlgorithm"
        },
        "Phase1IntegrityAlgorithms":{
          "shape":"Phase1IntegrityAlgorithmsRequestList",
          "documentation":"<p>One or more integrity algorithms that are permitted for the VPN tunnel for phase 1 IKE negotiations.</p> <p>Valid values: <code>SHA1</code> | <code>SHA2-256</code> | <code>SHA2-384</code> | <code>SHA2-512</code> </p>",
          "locationName":"Phase1IntegrityAlgorithm"
        },
        "Phase2IntegrityAlgorithms":{
          "shape":"Phase2IntegrityAlgorithmsRequestList",
          "documentation":"<p>One or more integrity algorithms that are permitted for the VPN tunnel for phase 2 IKE negotiations.</p> <p>Valid values: <code>SHA1</code> | <code>SHA2-256</code> | <code>SHA2-384</code> | <code>SHA2-512</code> </p>",
          "locationName":"Phase2IntegrityAlgorithm"
        },
        "Phase1DHGroupNumbers":{
          "shape":"Phase1DHGroupNumbersRequestList",
          "documentation":"<p>One or more Diffie-Hellman group numbers that are permitted for the VPN tunnel for phase 1 IKE negotiations.</p> <p>Valid values: <code>2</code> | <code>14</code> | <code>15</code> | <code>16</code> | <code>17</code> | <code>18</code> | <code>19</code> | <code>20</code> | <code>21</code> | <code>22</code> | <code>23</code> | <code>24</code> </p>",
          "locationName":"Phase1DHGroupNumber"
        },
        "Phase2DHGroupNumbers":{
          "shape":"Phase2DHGroupNumbersRequestList",
          "documentation":"<p>One or more Diffie-Hellman group numbers that are permitted for the VPN tunnel for phase 2 IKE negotiations.</p> <p>Valid values: <code>2</code> | <code>5</code> | <code>14</code> | <code>15</code> | <code>16</code> | <code>17</code> | <code>18</code> | <code>19</code> | <code>20</code> | <code>21</code> | <code>22</code> | <code>23</code> | <code>24</code> </p>",
          "locationName":"Phase2DHGroupNumber"
        },
        "IKEVersions":{
          "shape":"IKEVersionsRequestList",
          "documentation":"<p>The IKE versions that are permitted for the VPN tunnel.</p> <p>Valid values: <code>ikev1</code> | <code>ikev2</code> </p>",
          "locationName":"IKEVersion"
        },
        "StartupAction":{
          "shape":"String",
          "documentation":"<p>The action to take when the establishing the tunnel for the VPN connection. By default, your customer gateway device must initiate the IKE negotiation and bring up the tunnel. Specify <code>start</code> for Amazon Web Services to initiate the IKE negotiation.</p> <p>Valid Values: <code>add</code> | <code>start</code> </p> <p>Default: <code>add</code> </p>"
        },
        "LogOptions":{
          "shape":"VpnTunnelLogOptionsSpecification",
          "documentation":"<p>Options for logging VPN tunnel activity.</p>"
        }
      },
      "documentation":"<p>The tunnel options for a single VPN tunnel.</p>"
    },
    "VpnTunnelOptionsSpecificationsList":{
      "type":"list",
      "member":{"shape":"VpnTunnelOptionsSpecification"}
    },
    "WeekDay":{
      "type":"string",
      "enum":[
        "sunday",
        "monday",
        "tuesday",
        "wednesday",
        "thursday",
        "friday",
        "saturday"
      ]
    },
    "WithdrawByoipCidrRequest":{
      "type":"structure",
      "required":["Cidr"],
      "members":{
        "Cidr":{
          "shape":"String",
          "documentation":"<p>The address range, in CIDR notation.</p>"
        },
        "DryRun":{
          "shape":"Boolean",
          "documentation":"<p>Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.</p>"
        }
      }
    },
    "WithdrawByoipCidrResult":{
      "type":"structure",
      "members":{
        "ByoipCidr":{
          "shape":"ByoipCidr",
          "documentation":"<p>Information about the address pool.</p>",
          "locationName":"byoipCidr"
        }
      }
    },
    "ZoneIdStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"ZoneId"
      }
    },
    "ZoneNameStringList":{
      "type":"list",
      "member":{
        "shape":"String",
        "locationName":"ZoneName"
      }
    },
    "scope":{
      "type":"string",
      "enum":[
        "Availability Zone",
        "Region"
      ]
    },
    "snapshotTierStatusSet":{
      "type":"list",
      "member":{
        "shape":"SnapshotTierStatus",
        "locationName":"item"
      }
    },
    "totalFpgaMemory":{"type":"integer"},
    "totalGpuMemory":{"type":"integer"}
  },
  "documentation":"<fullname>Amazon Elastic Compute Cloud</fullname> <p>Amazon Elastic Compute Cloud (Amazon EC2) provides secure and resizable computing capacity in the Amazon Web Services Cloud. Using Amazon EC2 eliminates the need to invest in hardware up front, so you can develop and deploy applications faster. Amazon Virtual Private Cloud (Amazon VPC) enables you to provision a logically isolated section of the Amazon Web Services Cloud where you can launch Amazon Web Services resources in a virtual network that you've defined. Amazon Elastic Block Store (Amazon EBS) provides block level storage volumes for use with EC2 instances. EBS volumes are highly available and reliable storage volumes that can be attached to any running instance and used like a hard drive.</p> <p>To learn more, see the following resources:</p> <ul> <li> <p>Amazon EC2: <a href=\"http://aws.amazon.com/ec2\">Amazon EC2 product page</a>, <a href=\"https://docs.aws.amazon.com/ec2/index.html\">Amazon EC2 documentation</a> </p> </li> <li> <p>Amazon EBS: <a href=\"http://aws.amazon.com/ebs\">Amazon EBS product page</a>, <a href=\"https://docs.aws.amazon.com/ebs/index.html\">Amazon EBS documentation</a> </p> </li> <li> <p>Amazon VPC: <a href=\"http://aws.amazon.com/vpc\">Amazon VPC product page</a>, <a href=\"https://docs.aws.amazon.com/vpc/index.html\">Amazon VPC documentation</a> </p> </li> <li> <p>VPN: <a href=\"http://aws.amazon.com/vpn\">VPN product page</a>, <a href=\"https://docs.aws.amazon.com/vpn/index.html\">VPN documentation</a> </p> </li> </ul>"
}