openapi: 3.1.0 info: title: Managed Database for PostgreSQL and MySQL Access Control List Certificate API description: "Managed Database for PostgreSQL and MySQL provides fully-managed relational Database Instances, with MySQL or PostgreSQL as database engines. The resource allows you to focus on development rather than administration or configuration. It comes with a high-availability mode, data replication, and automatic backups.\n\nCompared to traditional database management, which requires customers to provide their infrastructure and resources to manage their databases, Managed Database for PostgreSQL and MySQL Instance offers the user access to Database Instances without setting up the hardware or configuring the software. Scaleway handles the provisioning, manages the configuration, and provides useful features as high availability, automated backup, user management, and more.\n\n\n\n\n## Concepts\n\nRefer to our [dedicated concepts page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/concepts/) to find definitions of the different terms referring to Managed Database for PostgreSQL and MySQL.\n\n\n\n\n## Quickstart\n\n1. Configure your environment variables.\n \n This is an optional step that seeks to simplify your usage of the APIs.\n \n\n ```bash\n export SCW_ACCESS_KEY=\"\"\n export SCW_SECRET_KEY=\"\"\n export SCW_REGION=\"\"\n ```\n2. Edit the POST request payload you will use to create your Database Instance. Replace the parameters in the following example:\n ```json\n '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n\n | Parameter | Description |\n | :--------------- |:-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n | `project_id` | The ID of the Project you want to create your Database Instance in. To find your Project ID you can **[list the projects](/api/account/project-api/#path-projects-list-all-projects-of-an-organization)** or consult the **[Scaleway console](https://console.scaleway.com/project/settings)**. |\n | `engine` | **REQUIRED** Version ID of the database engine. To check the list of available engines you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/database-engines` |\n | `name` | Name of the Database Instance |\n | `node_type` | **REQUIRED** The node type. To check the list of available node types you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/node-types` |\n | `is_ha_cluster` | **BOOLEAN** Defines whether High Availability is enabled for the Database Instance |\n | `disable_backup` | **BOOLEAN** Defines whether automated backups are disabled for the Database Instance |\n | `tags` | The list of tags `[\"tag1\", \"tag2\", ...]` that will be associated with the Database Instance. Tags can be appended to the query of the [List Database Instances](#path-database-instances-list-database-instances) call to show results for only the Database Instances using a specific tag. You can also combine tags to list Database Instances that possess all the appended tags. |\n | `user_name` | **REQUIRED** Identifier of the default user, which is created concurrently with the Database Instance |\n | `password` | **REQUIRED** Password for the default user |\n | `volume_type` | Type of volume where data is stored. You can specify either local volume (`lssd`) or block volume (`bssd`, `sbs_5k` or `sbs_15k`). The default value is `lssd` |\n | `volume_size` | Volume size when volume_type is `bssd`, `sbs_5k` or `sbs_15k`. The value should be expressed in bytes. For example 30GB is expressed as 30000000000 |\n3. Create a Database Instance by running the following command. Make sure you include the payload you edited in the previous step.\n ```bash\n curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"Content-Type: application/json\" \\\n https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances \\\n -d '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n4. List your Database Instances.\n ```bash\n curl -X GET \\\n -H \"Content-Type: application/json\" \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances\n ```\n\n You should get a response like the following:\n\n \n This is a response example, the UUIDs and IP address displayed are not real.\n \n\n ```json\n {\n \"id\": \"f5122f66-fb50-4cef-aa02-487ef4fc1af0\",\n \"name\": \"myDB\",\n \"organization_id\": \"895693aa-3915-4896-8761-c2923b008be7\",\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"status\": \"ready\",\n \"engine\": \"PostgreSQL-15\",\n \"endpoint\": {\n \"ip\": \"198.51.100.0\",\n \"port\": 22245,\n \"name\": null\n },\n \"tags\": [\n \"donnerstag\"\n ],\n \"settings\": [],\n \"backup_schedule\": {\n \"frequency\": 24,\n \"retention\": 7,\n \"disabled\": true\n },\n \"is_ha_cluster\": true,\n \"read_replicas\": [],\n \"node_type\": \"db-pro2-xxs\",\n \"volume\": {\n \"type\": \"sbs_5k\",\n \"size\": 30000000000\n }\n \"created_at\": \"2019-04-19T16:24:52.591417Z\",\n \"region\": \"fr-par\"\n }\n ```\n5. Retrieve your Database Instance IP and port from the response.\n \n In the example above, the IP and port are `198.51.100.0` and `22245`, respectively.\n \n6. Connect to your Database Instance with the database client of the engine you selected.\n For MySQL, run the following command:\n ```bash\n mysql -h --port -p -u \n ```\n\n For PostgreSQL, run:\n ```bash\n psql -h -p -U -d rdb\n ```\n\n For the recurring example, the command would look like:\n\n ```bash\n psql -h 198.51.100.0 -p 22245 -U my_initial_user -d rdb\n ```\n7. Enter the database password that you defined upon creation.\n\nYou are now connected to your Managed Database.\n\n\n\nTo perform the following steps, you must first ensure that:\n - you have an account and are logged into the [Scaleway console](https://console.scaleway.com/organization)\n - you have created an [API key](https://www.scaleway.com/en/docs/iam/how-to/create-api-keys/) and that the API key has sufficient [IAM permissions](https://www.scaleway.com/en/docs/iam/reference-content/permission-sets/) to perform the actions described on this page.\n - you have [installed `curl`](https://curl.se/download.html)\n\n\n\n## Technical Information\n\n### Regions\n\nScaleway's infrastructure is spread across different [regions and Availability Zones](https://www.scaleway.com/en/docs/account/reference-content/products-availability/).\n\nManaged Database for PostgreSQL and MySQL is available in the Paris, Amsterdam and Warsaw regions, which are represented by the following path parameters:\n\n- `fr-par`\n- `nl-ams`\n- `pl-waw`\n\n### PostgreSQL specifications\n\n#### Versions\n\nScaleway Database for PostgreSQL supports PostgreSQL versions 11, 12, 13, 14 and 15.\n\n#### System\n\nDifferent modules are available for installation, including TimescaleDB and PostGIS. Refer to the [Managed Database for PostgreSQL and MySQL FAQ page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/#which-postgresql-extensions-are-available) for an extensive list of PostgreSQL extensions.\n\n#### Database Management\n\nYou can create logical databases through the Scaleway console, the Scaleway APIs or SQL.\n\n- databases created using the Scaleway console or the API are owned by an internal system user. These are called \"managed databases\".\n- databases created using SQL will be owned by the creator. These are called \"unmanaged databases\".\n\n### MySQL specifications\n\n#### Versions\n\nScaleway Database for MySQL supports MySQL 8.\n\n#### System\n\n- only the [InnoDB engine](https://dev.mysql.com/doc/refman/8.0/en/innodb-storage-engine.html) is supported\n- the [Global Transaction Identifier (GTID)](https://dev.mysql.com/doc/refman/8.0/en/replication-gtids-concepts.html) is enabled.\n- [`mysql_native_password`](https://dev.mysql.com/doc/refman/8.0/en/native-pluggable-authentication.html) (default) and [`caching_sha2_password`](https://dev.mysql.com/doc/refman/8.0/en/caching-sha2-pluggable-authentication.html) authentication are supported.\n\n#### User Management\n\n- users with an `admin` role have access to all logical databases and can create new ones.\n- users created via the API are authenticated using the default authentication plugin, which can be changed in the settings.\n\n## Technical Limitations\n\n### PostgreSQL\n\n#### User Management\n\n- users with an `admin` role have `CREATEROLE` and `CREATEDB` privileges.\n- users do NOT have `SUPERUSER` nor `REPLICATION` privileges.\n- permission management through the Scaleway console or API is only possible for the \"managed databases\".\n\n#### Backup and restoration\n\nDatabases that have been backed up and then restored retain the user permission settings in use at the time of backup. If you delete users after backup and then restore your backup in the same database, or if you restore a backup to a different database with different or no users, the permissions configured for them continue to exist, but with no associated owner. This error will put a stop to the restoration process.\n\nTo avoid this issue, we recommend you re-create the users you deleted. In the occasion you restore the backup to a new database, you must create new users with the same names.\n\n## Going Further\n\nFor more information about Managed Database for PostgreSQL and MySQL, you can check out the following pages:\n\n* [Managed Database for PostgreSQL and MySQL Documentation](https://www.scaleway.com/en/docs/managed-databases/postgresql-and-mysql/)\n* [Managed Database for PostgreSQL and MySQL FAQ](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/)\n* [Scaleway Slack Community](https://scaleway-community.slack.com/) join the #database channel\n* [Contact our support team](https://console.scaleway.com/support/tickets)\n\n### How to migrate a database\n\nIf you wish to migrate existing databases to a Managed Database for PostgreSQL or MySQL, you can refer to the [Migrating existing databases to a Database Instance](https://www.scaleway.com/en/docs/tutorials/migrate-databases-instance/) tutorial page.\n\n### Troubleshoooting\n\n#### Disk full status\n\nIf your Database Instance uses local storage, your local volume might eventually approach full capacity and shift to `disk_full` mode. This mode grants you enough space to either [upgrade your node type](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/how-to/upgrade-version/#how-to-change-the-node-type) or [clear out space in your volume](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/troubleshooting/disk-full/)." version: v1 servers: - url: https://api.scaleway.com tags: - name: Certificate description: The Load Balancer certificate object. It represents an SSL/TLS certificate for your Load Balancer which can be used by a frontend to establish secure, encrypted connections for incoming traffic. Use this endpoint to create Let's Encrypt certificates or import custom certificates for your Load Balancer, and update, list, get and delete them as required. paths: /lb/v1/zones/{zone}/certificates/{certificate_id}: get: tags: - Certificate operationId: GetCertificate summary: Get an SSL/TLS certificate description: Get information for a particular SSL/TLS certificate, specified by its certificate ID. The response returns full details of the certificate, including its type, main domain name, and alternative domain names. parameters: - in: path name: zone description: The zone you want to target required: true schema: type: string enum: - fr-par-1 - fr-par-2 - nl-ams-1 - nl-ams-2 - nl-ams-3 - pl-waw-1 - pl-waw-2 - pl-waw-3 - in: path name: certificate_id description: Certificate ID. required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.lb.v1.Certificate' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/lb/v1/zones/{zone}/certificates/{certificate_id}\"" - lang: HTTPie source: "http GET \"https://api.scaleway.com/lb/v1/zones/{zone}/certificates/{certificate_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" put: tags: - Certificate operationId: UpdateCertificate summary: Update an SSL/TLS certificate description: Update the name of a particular SSL/TLS certificate, specified by its certificate ID. parameters: - in: path name: zone description: The zone you want to target required: true schema: type: string enum: - fr-par-1 - fr-par-2 - nl-ams-1 - nl-ams-2 - nl-ams-3 - pl-waw-1 - pl-waw-2 - pl-waw-3 - in: path name: certificate_id description: Certificate ID. required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.lb.v1.Certificate' requestBody: required: true content: application/json: schema: type: object properties: name: type: string description: Certificate name. required: - name x-properties-order: - name security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X PUT \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\"name\":\"string\"}' \\\n \"https://api.scaleway.com/lb/v1/zones/{zone}/certificates/{certificate_id}\"" - lang: HTTPie source: "http PUT \"https://api.scaleway.com/lb/v1/zones/{zone}/certificates/{certificate_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n name=\"string\"" delete: tags: - Certificate operationId: DeleteCertificate summary: Delete an SSL/TLS certificate description: Delete an SSL/TLS certificate, specified by its certificate ID. Deleting a certificate is irreversible and cannot be undone. parameters: - in: path name: zone description: The zone you want to target required: true schema: type: string enum: - fr-par-1 - fr-par-2 - nl-ams-1 - nl-ams-2 - nl-ams-3 - pl-waw-1 - pl-waw-2 - pl-waw-3 - in: path name: certificate_id description: Certificate ID. required: true schema: type: string responses: '204': description: '' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X DELETE \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/lb/v1/zones/{zone}/certificates/{certificate_id}\"" - lang: HTTPie source: "http DELETE \"https://api.scaleway.com/lb/v1/zones/{zone}/certificates/{certificate_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /lb/v1/zones/{zone}/lbs/{lb_id}/certificates: get: tags: - Certificate operationId: ListCertificates summary: List all SSL/TLS certificates on a given Load Balancer description: List all the SSL/TLS certificates on a given Load Balancer. The response is an array of certificate objects, which are by default listed in ascending order of creation date. parameters: - in: path name: zone description: The zone you want to target required: true schema: type: string enum: - fr-par-1 - fr-par-2 - nl-ams-1 - nl-ams-2 - nl-ams-3 - pl-waw-1 - pl-waw-2 - pl-waw-3 - in: path name: lb_id description: Load Balancer ID. required: true schema: type: string - in: query name: order_by description: Sort order of certificates in the response. schema: type: string enum: - created_at_asc - created_at_desc - name_asc - name_desc default: created_at_asc - in: query name: page description: The page number to return, from the paginated results. schema: type: integer format: int32 - in: query name: page_size description: Number of certificates to return. schema: type: integer format: uint32 - in: query name: name description: Certificate name to filter for, only certificates of this name will be returned. schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.lb.v1.ListCertificatesResponse' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/lb/v1/zones/{zone}/lbs/{lb_id}/certificates\"" - lang: HTTPie source: "http GET \"https://api.scaleway.com/lb/v1/zones/{zone}/lbs/{lb_id}/certificates\" \\\n X-Auth-Token:$SCW_SECRET_KEY" post: tags: - Certificate operationId: CreateCertificate summary: Create an SSL/TLS certificate description: Generate a new SSL/TLS certificate for a given Load Balancer. You can choose to create a Let's Encrypt certificate, or import a custom certificate. parameters: - in: path name: zone description: The zone you want to target required: true schema: type: string enum: - fr-par-1 - fr-par-2 - nl-ams-1 - nl-ams-2 - nl-ams-3 - pl-waw-1 - pl-waw-2 - pl-waw-3 - in: path name: lb_id description: Load Balancer ID. required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.lb.v1.Certificate' requestBody: required: true content: application/json: schema: type: object properties: name: type: string description: Name for the certificate. letsencrypt: type: object description: Object to define a new Let's Encrypt certificate to be generated. properties: common_name: type: string description: Main domain name of certificate (this domain must exist and resolve to your Load Balancer IP address). subject_alternative_name: type: array description: Alternative domain names (all domain names must exist and resolve to your Load Balancer IP address). items: type: string nullable: true required: - common_name x-properties-order: - common_name - subject_alternative_name x-one-of: type custom_certificate: type: object description: Object to define an existing custom certificate to be imported. properties: certificate_chain: type: string description: Full PEM-formatted certificate, consisting of the entire certificate chain including public key, private key, and (optionally) Certificate Authorities. nullable: true required: - certificate_chain x-properties-order: - certificate_chain x-one-of: type required: - name x-properties-order: - name - letsencrypt - custom_certificate security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\"name\":\"string\"}' \\\n \"https://api.scaleway.com/lb/v1/zones/{zone}/lbs/{lb_id}/certificates\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/lb/v1/zones/{zone}/lbs/{lb_id}/certificates\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n name=\"string\"" components: schemas: scaleway.lb.v1.Certificate: type: object properties: type: type: string description: Certificate type (Let's Encrypt or custom). enum: - letsencryt - custom - letsencrypt default: letsencryt id: type: string description: Certificate ID. common_name: type: string description: Main domain name of certificate. subject_alternative_name: type: array description: Alternative domain names. items: type: string fingerprint: type: string description: Identifier (SHA-1) of the certificate. not_valid_before: type: string description: Lower validity bound. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true not_valid_after: type: string description: Upper validity bound. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true status: type: string description: Certificate status. enum: - pending - ready - error default: pending lb: type: object description: Load Balancer object the certificate is attached to. properties: id: type: string description: Underlying Instance ID. name: type: string description: Load Balancer name. description: type: string description: Load Balancer description. status: type: string description: Load Balancer status. enum: - unknown - ready - pending - stopped - error - locked - migrating - to_create - creating - to_delete - deleting default: unknown instances: type: array description: List of underlying Instances. items: $ref: '#/components/schemas/scaleway.lb.v1.Instance' organization_id: type: string description: Scaleway Organization ID. project_id: type: string description: Scaleway Project ID. ip: type: array description: List of IP addresses attached to the Load Balancer. items: $ref: '#/components/schemas/scaleway.lb.v1.Ip' tags: type: array description: Load Balancer tags. items: type: string frontend_count: type: integer description: Number of frontends the Load Balancer has. format: int32 backend_count: type: integer description: Number of backends the Load Balancer has. format: int32 type: type: string description: Load Balancer offer type. subscriber: type: object description: Subscriber information. properties: id: type: string description: Subscriber ID. name: type: string description: Subscriber name. email_config: type: object description: Email address of subscriber. properties: email: type: string description: Email address to send alerts to. nullable: true x-properties-order: - email x-one-of: config webhook_config: type: object description: Webhook URI of subscriber. properties: uri: type: string description: URI to receive POST requests. nullable: true x-properties-order: - uri x-one-of: config x-properties-order: - id - name - email_config - webhook_config ssl_compatibility_level: type: string description: Determines the minimal SSL version which needs to be supported on client side. enum: - ssl_compatibility_level_unknown - ssl_compatibility_level_intermediate - ssl_compatibility_level_modern - ssl_compatibility_level_old default: ssl_compatibility_level_unknown created_at: type: string description: Date on which the Load Balancer was created. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true updated_at: type: string description: Date on which the Load Balancer was last updated. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true private_network_count: type: integer description: Number of Private Networks attached to the Load Balancer. format: int32 route_count: type: integer description: Number of routes configured on the Load Balancer. format: int32 region: type: string description: The region the Load Balancer is in. deprecated: true zone: type: string description: The zone the Load Balancer is in. x-properties-order: - id - name - description - status - instances - organization_id - project_id - ip - tags - frontend_count - backend_count - type - subscriber - ssl_compatibility_level - created_at - updated_at - private_network_count - route_count - region - zone name: type: string description: Certificate name. created_at: type: string description: Date on which the certificate was created. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true updated_at: type: string description: Date on which the certificate was last updated. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true status_details: type: string description: Additional information about the certificate status (useful in case of certificate generation failure, for example). nullable: true x-properties-order: - type - id - common_name - subject_alternative_name - fingerprint - not_valid_before - not_valid_after - status - lb - name - created_at - updated_at - status_details scaleway.lb.v1.Ip: type: object properties: id: type: string description: IP address ID. ip_address: type: string description: IP address. organization_id: type: string description: Organization ID of the Scaleway Organization the IP address is in. project_id: type: string description: Project ID of the Scaleway Project the IP address is in. lb_id: type: string description: Load Balancer ID. nullable: true reverse: type: string description: Reverse DNS (domain name) of the IP address. tags: type: array description: IP tags. items: type: string region: type: string description: The region the IP address is in. deprecated: true zone: type: string description: The zone the IP address is in. x-properties-order: - id - ip_address - organization_id - project_id - lb_id - reverse - tags - region - zone scaleway.lb.v1.Instance: type: object properties: id: type: string description: Underlying Instance ID. status: type: string description: Instance status. enum: - unknown - ready - pending - stopped - error - locked - migrating default: unknown ip_address: type: string description: Instance IP address. created_at: type: string description: Date on which the Instance was created. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true updated_at: type: string description: Date on which the Instance was last updated. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true region: type: string description: The region the Instance is in. deprecated: true zone: type: string description: The zone the Instance is in. x-properties-order: - id - status - ip_address - created_at - updated_at - region - zone scaleway.lb.v1.ListCertificatesResponse: type: object properties: certificates: type: array description: List of certificate objects. items: $ref: '#/components/schemas/scaleway.lb.v1.Certificate' total_count: type: integer description: The total number of objects. format: uint32 x-properties-order: - certificates - total_count securitySchemes: scaleway: in: header name: X-Auth-Token type: apiKey