openapi: 3.1.0 info: title: Managed Database for PostgreSQL and MySQL Access Control List Policies API description: "Managed Database for PostgreSQL and MySQL provides fully-managed relational Database Instances, with MySQL or PostgreSQL as database engines. The resource allows you to focus on development rather than administration or configuration. It comes with a high-availability mode, data replication, and automatic backups.\n\nCompared to traditional database management, which requires customers to provide their infrastructure and resources to manage their databases, Managed Database for PostgreSQL and MySQL Instance offers the user access to Database Instances without setting up the hardware or configuring the software. Scaleway handles the provisioning, manages the configuration, and provides useful features as high availability, automated backup, user management, and more.\n\n\n\n\n## Concepts\n\nRefer to our [dedicated concepts page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/concepts/) to find definitions of the different terms referring to Managed Database for PostgreSQL and MySQL.\n\n\n\n\n## Quickstart\n\n1. Configure your environment variables.\n \n This is an optional step that seeks to simplify your usage of the APIs.\n \n\n ```bash\n export SCW_ACCESS_KEY=\"\"\n export SCW_SECRET_KEY=\"\"\n export SCW_REGION=\"\"\n ```\n2. Edit the POST request payload you will use to create your Database Instance. Replace the parameters in the following example:\n ```json\n '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n\n | Parameter | Description |\n | :--------------- |:-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n | `project_id` | The ID of the Project you want to create your Database Instance in. To find your Project ID you can **[list the projects](/api/account/project-api/#path-projects-list-all-projects-of-an-organization)** or consult the **[Scaleway console](https://console.scaleway.com/project/settings)**. |\n | `engine` | **REQUIRED** Version ID of the database engine. To check the list of available engines you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/database-engines` |\n | `name` | Name of the Database Instance |\n | `node_type` | **REQUIRED** The node type. To check the list of available node types you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/node-types` |\n | `is_ha_cluster` | **BOOLEAN** Defines whether High Availability is enabled for the Database Instance |\n | `disable_backup` | **BOOLEAN** Defines whether automated backups are disabled for the Database Instance |\n | `tags` | The list of tags `[\"tag1\", \"tag2\", ...]` that will be associated with the Database Instance. Tags can be appended to the query of the [List Database Instances](#path-database-instances-list-database-instances) call to show results for only the Database Instances using a specific tag. You can also combine tags to list Database Instances that possess all the appended tags. |\n | `user_name` | **REQUIRED** Identifier of the default user, which is created concurrently with the Database Instance |\n | `password` | **REQUIRED** Password for the default user |\n | `volume_type` | Type of volume where data is stored. You can specify either local volume (`lssd`) or block volume (`bssd`, `sbs_5k` or `sbs_15k`). The default value is `lssd` |\n | `volume_size` | Volume size when volume_type is `bssd`, `sbs_5k` or `sbs_15k`. The value should be expressed in bytes. For example 30GB is expressed as 30000000000 |\n3. Create a Database Instance by running the following command. Make sure you include the payload you edited in the previous step.\n ```bash\n curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"Content-Type: application/json\" \\\n https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances \\\n -d '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n4. List your Database Instances.\n ```bash\n curl -X GET \\\n -H \"Content-Type: application/json\" \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances\n ```\n\n You should get a response like the following:\n\n \n This is a response example, the UUIDs and IP address displayed are not real.\n \n\n ```json\n {\n \"id\": \"f5122f66-fb50-4cef-aa02-487ef4fc1af0\",\n \"name\": \"myDB\",\n \"organization_id\": \"895693aa-3915-4896-8761-c2923b008be7\",\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"status\": \"ready\",\n \"engine\": \"PostgreSQL-15\",\n \"endpoint\": {\n \"ip\": \"198.51.100.0\",\n \"port\": 22245,\n \"name\": null\n },\n \"tags\": [\n \"donnerstag\"\n ],\n \"settings\": [],\n \"backup_schedule\": {\n \"frequency\": 24,\n \"retention\": 7,\n \"disabled\": true\n },\n \"is_ha_cluster\": true,\n \"read_replicas\": [],\n \"node_type\": \"db-pro2-xxs\",\n \"volume\": {\n \"type\": \"sbs_5k\",\n \"size\": 30000000000\n }\n \"created_at\": \"2019-04-19T16:24:52.591417Z\",\n \"region\": \"fr-par\"\n }\n ```\n5. Retrieve your Database Instance IP and port from the response.\n \n In the example above, the IP and port are `198.51.100.0` and `22245`, respectively.\n \n6. Connect to your Database Instance with the database client of the engine you selected.\n For MySQL, run the following command:\n ```bash\n mysql -h --port -p -u \n ```\n\n For PostgreSQL, run:\n ```bash\n psql -h -p -U -d rdb\n ```\n\n For the recurring example, the command would look like:\n\n ```bash\n psql -h 198.51.100.0 -p 22245 -U my_initial_user -d rdb\n ```\n7. Enter the database password that you defined upon creation.\n\nYou are now connected to your Managed Database.\n\n\n\nTo perform the following steps, you must first ensure that:\n - you have an account and are logged into the [Scaleway console](https://console.scaleway.com/organization)\n - you have created an [API key](https://www.scaleway.com/en/docs/iam/how-to/create-api-keys/) and that the API key has sufficient [IAM permissions](https://www.scaleway.com/en/docs/iam/reference-content/permission-sets/) to perform the actions described on this page.\n - you have [installed `curl`](https://curl.se/download.html)\n\n\n\n## Technical Information\n\n### Regions\n\nScaleway's infrastructure is spread across different [regions and Availability Zones](https://www.scaleway.com/en/docs/account/reference-content/products-availability/).\n\nManaged Database for PostgreSQL and MySQL is available in the Paris, Amsterdam and Warsaw regions, which are represented by the following path parameters:\n\n- `fr-par`\n- `nl-ams`\n- `pl-waw`\n\n### PostgreSQL specifications\n\n#### Versions\n\nScaleway Database for PostgreSQL supports PostgreSQL versions 11, 12, 13, 14 and 15.\n\n#### System\n\nDifferent modules are available for installation, including TimescaleDB and PostGIS. Refer to the [Managed Database for PostgreSQL and MySQL FAQ page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/#which-postgresql-extensions-are-available) for an extensive list of PostgreSQL extensions.\n\n#### Database Management\n\nYou can create logical databases through the Scaleway console, the Scaleway APIs or SQL.\n\n- databases created using the Scaleway console or the API are owned by an internal system user. These are called \"managed databases\".\n- databases created using SQL will be owned by the creator. These are called \"unmanaged databases\".\n\n### MySQL specifications\n\n#### Versions\n\nScaleway Database for MySQL supports MySQL 8.\n\n#### System\n\n- only the [InnoDB engine](https://dev.mysql.com/doc/refman/8.0/en/innodb-storage-engine.html) is supported\n- the [Global Transaction Identifier (GTID)](https://dev.mysql.com/doc/refman/8.0/en/replication-gtids-concepts.html) is enabled.\n- [`mysql_native_password`](https://dev.mysql.com/doc/refman/8.0/en/native-pluggable-authentication.html) (default) and [`caching_sha2_password`](https://dev.mysql.com/doc/refman/8.0/en/caching-sha2-pluggable-authentication.html) authentication are supported.\n\n#### User Management\n\n- users with an `admin` role have access to all logical databases and can create new ones.\n- users created via the API are authenticated using the default authentication plugin, which can be changed in the settings.\n\n## Technical Limitations\n\n### PostgreSQL\n\n#### User Management\n\n- users with an `admin` role have `CREATEROLE` and `CREATEDB` privileges.\n- users do NOT have `SUPERUSER` nor `REPLICATION` privileges.\n- permission management through the Scaleway console or API is only possible for the \"managed databases\".\n\n#### Backup and restoration\n\nDatabases that have been backed up and then restored retain the user permission settings in use at the time of backup. If you delete users after backup and then restore your backup in the same database, or if you restore a backup to a different database with different or no users, the permissions configured for them continue to exist, but with no associated owner. This error will put a stop to the restoration process.\n\nTo avoid this issue, we recommend you re-create the users you deleted. In the occasion you restore the backup to a new database, you must create new users with the same names.\n\n## Going Further\n\nFor more information about Managed Database for PostgreSQL and MySQL, you can check out the following pages:\n\n* [Managed Database for PostgreSQL and MySQL Documentation](https://www.scaleway.com/en/docs/managed-databases/postgresql-and-mysql/)\n* [Managed Database for PostgreSQL and MySQL FAQ](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/)\n* [Scaleway Slack Community](https://scaleway-community.slack.com/) join the #database channel\n* [Contact our support team](https://console.scaleway.com/support/tickets)\n\n### How to migrate a database\n\nIf you wish to migrate existing databases to a Managed Database for PostgreSQL or MySQL, you can refer to the [Migrating existing databases to a Database Instance](https://www.scaleway.com/en/docs/tutorials/migrate-databases-instance/) tutorial page.\n\n### Troubleshoooting\n\n#### Disk full status\n\nIf your Database Instance uses local storage, your local volume might eventually approach full capacity and shift to `disk_full` mode. This mode grants you enough space to either [upgrade your node type](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/how-to/upgrade-version/#how-to-change-the-node-type) or [clear out space in your volume](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/troubleshooting/disk-full/)." version: v1 servers: - url: https://api.scaleway.com tags: - name: Policies description: 'Policies control user rights, by defining one or more rules to apply to the attached principals (users, groups or applications). A policy rule has two parts:\ permission set and scope. For each policy rule, you specify one or more permission sets (eg. “list all Instances”) and their scope (eg. “on Project A only”). This therefore defines the actions that the principles can carry out on resources within the scope. ' paths: /iam/v1alpha1/policies: get: tags: - Policies operationId: ListPolicies summary: List policies of an Organization description: List the policies of an Organization. By default, the policies listed are ordered by creation date in ascending order. This can be modified via the `order_by` field. You must define the `organization_id` in the query path of your request. You can also define additional parameters to filter your query, such as `user_ids`, `groups_ids`, `application_ids`, and `policy_name`. parameters: - in: query name: order_by description: Criteria for sorting results. schema: type: string enum: - policy_name_asc - policy_name_desc - created_at_asc - created_at_desc x-enum-descriptions: values: policy_name_asc: Policy name ascending policy_name_desc: Policy name descending created_at_asc: Creation date ascending created_at_desc: Creation date descending default: policy_name_asc - in: query name: page_size description: Number of results per page. Value must be between 1 and 100. schema: type: integer format: uint32 - in: query name: page description: Page number. Value must be greater than 1. schema: type: integer format: int32 - in: query name: organization_id description: ID of the Organization to filter. schema: type: string - in: query name: editable description: Defines whether or not filter out editable policies. schema: type: boolean - in: query name: user_ids description: Defines whether or not to filter by list of user IDs. schema: type: array items: type: string - in: query name: group_ids description: Defines whether or not to filter by list of group IDs. schema: type: array items: type: string - in: query name: application_ids description: Filter by a list of application IDs. schema: type: array items: type: string - in: query name: no_principal description: Defines whether or not the policy is attributed to a principal. schema: type: boolean - in: query name: policy_name description: Name of the policy to fetch. schema: type: string - in: query name: tag description: Filter by tags containing a given string. schema: type: string - in: query name: policy_ids description: Filter by a list of IDs. schema: type: array items: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.iam.v1alpha1.ListPoliciesResponse' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/iam/v1alpha1/policies?organization_id=string\"" - lang: HTTPie source: "http GET \"https://api.scaleway.com/iam/v1alpha1/policies\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n organization_id==string" post: tags: - Policies operationId: CreatePolicy summary: Create a new policy description: Create a new application. You must define the `name` parameter in the request. You can specify parameters such as `user_id`, `groups_id`, `application_id`, `no_principal`, `rules` and its child attributes. responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy' requestBody: required: true content: application/json: schema: type: object properties: name: type: string description: Name of the policy to create (max length is 64 characters). description: type: string description: Description of the policy to create (max length is 200 characters). organization_id: type: string description: ID of the Organization. rules: type: array description: Rules of the policy to create. items: $ref: '#/components/schemas/scaleway.iam.v1alpha1.RuleSpecs' tags: type: array description: Tags associated with the policy (maximum of 10 tags). items: type: string user_id: type: string description: ID of user attributed to the policy. nullable: true x-one-of: principal group_id: type: string description: ID of group attributed to the policy. nullable: true x-one-of: principal application_id: type: string description: ID of application attributed to the policy. nullable: true x-one-of: principal no_principal: type: boolean description: Defines whether or not a policy is attributed to a principal. nullable: true x-one-of: principal required: - name x-properties-order: - name - description - organization_id - rules - tags - user_id - group_id - application_id - no_principal security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"description\": \"string\",\n \"name\": \"string\",\n \"organization_id\": \"string\"\n }' \\\n \"https://api.scaleway.com/iam/v1alpha1/policies\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/iam/v1alpha1/policies\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n description=\"string\" \\\n name=\"string\" \\\n organization_id=\"string\"" /iam/v1alpha1/policies/{policy_id}: get: tags: - Policies operationId: GetPolicy summary: Get an existing policy description: Retrieve information about a policy, specified by the `policy_id` parameter. The policy's full details, including `id`, `name`, `organization_id`, `nb_rules` and `nb_scopes`, `nb_permission_sets` are returned in the response. parameters: - in: path name: policy_id description: Id of policy to search. required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\"" - lang: HTTPie source: "http GET \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" patch: tags: - Policies operationId: UpdatePolicy summary: Update an existing policy description: Update the parameters of a policy, including `name`, `description`, `user_id`, `group_id`, `application_id` and `no_principal`. parameters: - in: path name: policy_id description: Id of policy to update. required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy' requestBody: required: true content: application/json: schema: type: object properties: name: type: string description: New name for the policy (max length is 64 characters). nullable: true description: type: string description: New description of policy (max length is 200 characters). nullable: true tags: type: array description: New tags for the policy (maximum of 10 tags). nullable: true items: type: string user_id: type: string description: New ID of user attributed to the policy. nullable: true x-one-of: principal group_id: type: string description: New ID of group attributed to the policy. nullable: true x-one-of: principal application_id: type: string description: New ID of application attributed to the policy. nullable: true x-one-of: principal no_principal: type: boolean description: Defines whether or not the policy is attributed to a principal. nullable: true x-one-of: principal x-properties-order: - name - description - tags - user_id - group_id - application_id - no_principal security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X PATCH \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\"" - lang: HTTPie source: "http PATCH \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" delete: tags: - Policies operationId: DeletePolicy summary: Delete a policy description: Delete a policy. You must define specify the `policy_id` parameter in your request. Note that when deleting a policy, all permissions it gives to its principal (user, group or application) will be revoked. parameters: - in: path name: policy_id description: Id of policy to delete. required: true schema: type: string responses: '204': description: '' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X DELETE \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\"" - lang: HTTPie source: "http DELETE \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /iam/v1alpha1/policies/{policy_id}/clone: post: tags: - Policies operationId: ClonePolicy summary: Clone a policy description: Clone a policy. You must define specify the `policy_id` parameter in your request. parameters: - in: path name: policy_id required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy' requestBody: required: true content: application/json: schema: type: object security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}/clone\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/iam/v1alpha1/policies/{policy_id}/clone\" \\\n X-Auth-Token:$SCW_SECRET_KEY" components: schemas: scaleway.iam.v1alpha1.RuleSpecs: type: object properties: permission_set_names: type: array description: Names of permission sets bound to the rule. nullable: true items: type: string condition: type: string description: Condition expression to evaluate. project_ids: type: array description: List of Project IDs the rule is scoped to. nullable: true x-one-of: scope items: type: string organization_id: type: string description: ID of Organization the rule is scoped to. nullable: true x-one-of: scope x-properties-order: - permission_set_names - condition - project_ids - organization_id scaleway.iam.v1alpha1.Policy: type: object properties: id: type: string description: Id of the policy. name: type: string description: Name of the policy. description: type: string description: Description of the policy. organization_id: type: string description: Organization ID of the policy. created_at: type: string description: Date and time of policy creation. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true updated_at: type: string description: Date and time of last policy update. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true editable: type: boolean description: Defines whether or not a policy is editable. deletable: type: boolean description: Defines whether or not a policy is deletable. managed: type: boolean description: Defines whether or not a policy is managed. nb_rules: type: integer description: Number of rules of the policy. format: uint32 nb_scopes: type: integer description: Number of policy scopes. format: uint32 nb_permission_sets: type: integer description: Number of permission sets of the policy. format: uint32 tags: type: array description: Tags associated with the policy. items: type: string user_id: type: string description: ID of the user attributed to the policy. nullable: true x-one-of: principal group_id: type: string description: ID of the group attributed to the policy. nullable: true x-one-of: principal application_id: type: string description: ID of the application attributed to the policy. nullable: true x-one-of: principal no_principal: type: boolean description: Defines whether or not a policy is attributed to a principal. nullable: true x-one-of: principal x-properties-order: - id - name - description - organization_id - created_at - updated_at - editable - deletable - managed - nb_rules - nb_scopes - nb_permission_sets - tags - user_id - group_id - application_id - no_principal scaleway.iam.v1alpha1.ListPoliciesResponse: type: object properties: policies: type: array description: List of policies. items: $ref: '#/components/schemas/scaleway.iam.v1alpha1.Policy' total_count: type: integer description: Total count of policies. format: uint32 x-properties-order: - policies - total_count securitySchemes: scaleway: in: header name: X-Auth-Token type: apiKey