openapi: 3.1.0 info: title: Managed Database for PostgreSQL and MySQL Access Control List Secrets API description: "Managed Database for PostgreSQL and MySQL provides fully-managed relational Database Instances, with MySQL or PostgreSQL as database engines. The resource allows you to focus on development rather than administration or configuration. It comes with a high-availability mode, data replication, and automatic backups.\n\nCompared to traditional database management, which requires customers to provide their infrastructure and resources to manage their databases, Managed Database for PostgreSQL and MySQL Instance offers the user access to Database Instances without setting up the hardware or configuring the software. Scaleway handles the provisioning, manages the configuration, and provides useful features as high availability, automated backup, user management, and more.\n\n\n\n\n## Concepts\n\nRefer to our [dedicated concepts page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/concepts/) to find definitions of the different terms referring to Managed Database for PostgreSQL and MySQL.\n\n\n\n\n## Quickstart\n\n1. Configure your environment variables.\n \n This is an optional step that seeks to simplify your usage of the APIs.\n \n\n ```bash\n export SCW_ACCESS_KEY=\"\"\n export SCW_SECRET_KEY=\"\"\n export SCW_REGION=\"\"\n ```\n2. Edit the POST request payload you will use to create your Database Instance. Replace the parameters in the following example:\n ```json\n '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n\n | Parameter | Description |\n | :--------------- |:-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n | `project_id` | The ID of the Project you want to create your Database Instance in. To find your Project ID you can **[list the projects](/api/account/project-api/#path-projects-list-all-projects-of-an-organization)** or consult the **[Scaleway console](https://console.scaleway.com/project/settings)**. |\n | `engine` | **REQUIRED** Version ID of the database engine. To check the list of available engines you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/database-engines` |\n | `name` | Name of the Database Instance |\n | `node_type` | **REQUIRED** The node type. To check the list of available node types you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/node-types` |\n | `is_ha_cluster` | **BOOLEAN** Defines whether High Availability is enabled for the Database Instance |\n | `disable_backup` | **BOOLEAN** Defines whether automated backups are disabled for the Database Instance |\n | `tags` | The list of tags `[\"tag1\", \"tag2\", ...]` that will be associated with the Database Instance. Tags can be appended to the query of the [List Database Instances](#path-database-instances-list-database-instances) call to show results for only the Database Instances using a specific tag. You can also combine tags to list Database Instances that possess all the appended tags. |\n | `user_name` | **REQUIRED** Identifier of the default user, which is created concurrently with the Database Instance |\n | `password` | **REQUIRED** Password for the default user |\n | `volume_type` | Type of volume where data is stored. You can specify either local volume (`lssd`) or block volume (`bssd`, `sbs_5k` or `sbs_15k`). The default value is `lssd` |\n | `volume_size` | Volume size when volume_type is `bssd`, `sbs_5k` or `sbs_15k`. The value should be expressed in bytes. For example 30GB is expressed as 30000000000 |\n3. Create a Database Instance by running the following command. Make sure you include the payload you edited in the previous step.\n ```bash\n curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"Content-Type: application/json\" \\\n https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances \\\n -d '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n4. List your Database Instances.\n ```bash\n curl -X GET \\\n -H \"Content-Type: application/json\" \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances\n ```\n\n You should get a response like the following:\n\n \n This is a response example, the UUIDs and IP address displayed are not real.\n \n\n ```json\n {\n \"id\": \"f5122f66-fb50-4cef-aa02-487ef4fc1af0\",\n \"name\": \"myDB\",\n \"organization_id\": \"895693aa-3915-4896-8761-c2923b008be7\",\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"status\": \"ready\",\n \"engine\": \"PostgreSQL-15\",\n \"endpoint\": {\n \"ip\": \"198.51.100.0\",\n \"port\": 22245,\n \"name\": null\n },\n \"tags\": [\n \"donnerstag\"\n ],\n \"settings\": [],\n \"backup_schedule\": {\n \"frequency\": 24,\n \"retention\": 7,\n \"disabled\": true\n },\n \"is_ha_cluster\": true,\n \"read_replicas\": [],\n \"node_type\": \"db-pro2-xxs\",\n \"volume\": {\n \"type\": \"sbs_5k\",\n \"size\": 30000000000\n }\n \"created_at\": \"2019-04-19T16:24:52.591417Z\",\n \"region\": \"fr-par\"\n }\n ```\n5. Retrieve your Database Instance IP and port from the response.\n \n In the example above, the IP and port are `198.51.100.0` and `22245`, respectively.\n \n6. Connect to your Database Instance with the database client of the engine you selected.\n For MySQL, run the following command:\n ```bash\n mysql -h --port -p -u \n ```\n\n For PostgreSQL, run:\n ```bash\n psql -h -p -U -d rdb\n ```\n\n For the recurring example, the command would look like:\n\n ```bash\n psql -h 198.51.100.0 -p 22245 -U my_initial_user -d rdb\n ```\n7. Enter the database password that you defined upon creation.\n\nYou are now connected to your Managed Database.\n\n\n\nTo perform the following steps, you must first ensure that:\n - you have an account and are logged into the [Scaleway console](https://console.scaleway.com/organization)\n - you have created an [API key](https://www.scaleway.com/en/docs/iam/how-to/create-api-keys/) and that the API key has sufficient [IAM permissions](https://www.scaleway.com/en/docs/iam/reference-content/permission-sets/) to perform the actions described on this page.\n - you have [installed `curl`](https://curl.se/download.html)\n\n\n\n## Technical Information\n\n### Regions\n\nScaleway's infrastructure is spread across different [regions and Availability Zones](https://www.scaleway.com/en/docs/account/reference-content/products-availability/).\n\nManaged Database for PostgreSQL and MySQL is available in the Paris, Amsterdam and Warsaw regions, which are represented by the following path parameters:\n\n- `fr-par`\n- `nl-ams`\n- `pl-waw`\n\n### PostgreSQL specifications\n\n#### Versions\n\nScaleway Database for PostgreSQL supports PostgreSQL versions 11, 12, 13, 14 and 15.\n\n#### System\n\nDifferent modules are available for installation, including TimescaleDB and PostGIS. Refer to the [Managed Database for PostgreSQL and MySQL FAQ page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/#which-postgresql-extensions-are-available) for an extensive list of PostgreSQL extensions.\n\n#### Database Management\n\nYou can create logical databases through the Scaleway console, the Scaleway APIs or SQL.\n\n- databases created using the Scaleway console or the API are owned by an internal system user. These are called \"managed databases\".\n- databases created using SQL will be owned by the creator. These are called \"unmanaged databases\".\n\n### MySQL specifications\n\n#### Versions\n\nScaleway Database for MySQL supports MySQL 8.\n\n#### System\n\n- only the [InnoDB engine](https://dev.mysql.com/doc/refman/8.0/en/innodb-storage-engine.html) is supported\n- the [Global Transaction Identifier (GTID)](https://dev.mysql.com/doc/refman/8.0/en/replication-gtids-concepts.html) is enabled.\n- [`mysql_native_password`](https://dev.mysql.com/doc/refman/8.0/en/native-pluggable-authentication.html) (default) and [`caching_sha2_password`](https://dev.mysql.com/doc/refman/8.0/en/caching-sha2-pluggable-authentication.html) authentication are supported.\n\n#### User Management\n\n- users with an `admin` role have access to all logical databases and can create new ones.\n- users created via the API are authenticated using the default authentication plugin, which can be changed in the settings.\n\n## Technical Limitations\n\n### PostgreSQL\n\n#### User Management\n\n- users with an `admin` role have `CREATEROLE` and `CREATEDB` privileges.\n- users do NOT have `SUPERUSER` nor `REPLICATION` privileges.\n- permission management through the Scaleway console or API is only possible for the \"managed databases\".\n\n#### Backup and restoration\n\nDatabases that have been backed up and then restored retain the user permission settings in use at the time of backup. If you delete users after backup and then restore your backup in the same database, or if you restore a backup to a different database with different or no users, the permissions configured for them continue to exist, but with no associated owner. This error will put a stop to the restoration process.\n\nTo avoid this issue, we recommend you re-create the users you deleted. In the occasion you restore the backup to a new database, you must create new users with the same names.\n\n## Going Further\n\nFor more information about Managed Database for PostgreSQL and MySQL, you can check out the following pages:\n\n* [Managed Database for PostgreSQL and MySQL Documentation](https://www.scaleway.com/en/docs/managed-databases/postgresql-and-mysql/)\n* [Managed Database for PostgreSQL and MySQL FAQ](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/)\n* [Scaleway Slack Community](https://scaleway-community.slack.com/) join the #database channel\n* [Contact our support team](https://console.scaleway.com/support/tickets)\n\n### How to migrate a database\n\nIf you wish to migrate existing databases to a Managed Database for PostgreSQL or MySQL, you can refer to the [Migrating existing databases to a Database Instance](https://www.scaleway.com/en/docs/tutorials/migrate-databases-instance/) tutorial page.\n\n### Troubleshoooting\n\n#### Disk full status\n\nIf your Database Instance uses local storage, your local volume might eventually approach full capacity and shift to `disk_full` mode. This mode grants you enough space to either [upgrade your node type](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/how-to/upgrade-version/#how-to-change-the-node-type) or [clear out space in your volume](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/troubleshooting/disk-full/)." version: v1 servers: - url: https://api.scaleway.com tags: - name: Secrets description: Secrets are logical containers made up of zero or more immutable versions, that contain sensitive data paths: /secret-manager/v1beta1/regions/{region}/secrets: get: tags: - Secrets operationId: ListSecrets summary: List secrets description: Retrieve the list of secrets created within an Organization and/or Project. You must specify either the `organization_id` or the `project_id` and the `region`. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: query name: organization_id description: Filter by Organization ID (optional). (UUID format) schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d - in: query name: project_id description: Filter by Project ID (optional). (UUID format) schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d - in: query name: order_by schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.ListSecretsRequest.OrderBy' - in: query name: page schema: $ref: '#/components/schemas/google.protobuf.Int32Value' - in: query name: page_size schema: type: integer format: uint32 - in: query name: tags description: List of tags to filter on (optional). schema: type: array items: type: string - in: query name: name description: Filter by secret name (optional). schema: type: string - in: query name: path description: Filter by exact path (optional). schema: type: string - in: query name: ephemeral description: Filter by ephemeral / not ephemeral (optional). schema: type: boolean - in: query name: type description: Filter by secret type (optional). schema: type: string enum: - unknown_type - opaque - certificate - key_value - basic_credentials - database_credentials - ssh_key x-enum-descriptions: values: opaque: Default type. certificate: List of concatenated PEM blocks. They can contain certificates, private keys or any other PEM block types. key_value: Flat JSON that allows you to set as many first level keys and scalar types as values (string, numeric, boolean) as you need. basic_credentials: Flat JSON that allows you to set a username and a password. database_credentials: Flat JSON that allows you to set an engine, username, password, host, database name, and port. ssh_key: Flat JSON that allows you to set an SSH key. default: unknown_type - in: query name: scheduled_for_deletion description: Filter by whether the secret was scheduled for deletion / not scheduled for deletion. By default, it will display only not scheduled for deletion secrets. required: true schema: type: boolean responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.ListSecretsResponse' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets?scheduled_for_deletion=false\"" - lang: HTTPie source: "http GET \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n scheduled_for_deletion==false" post: tags: - Secrets operationId: CreateSecret summary: Create a secret description: Create a secret in a given region specified by the `region` parameter. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' requestBody: required: true content: application/json: schema: type: object properties: project_id: type: string description: ID of the Project containing the secret. (UUID format) example: 6170692e-7363-616c-6577-61792e636f6d name: type: string description: Name of the secret. tags: type: array description: List of the secret's tags. items: type: string description: type: string description: Description of the secret. nullable: true type: type: string description: 'Type of the secret. (Optional.) See the `Secret.Type` enum for a description of values. If not specified, the type is `Opaque`.' enum: - unknown_type - opaque - certificate - key_value - basic_credentials - database_credentials - ssh_key x-enum-descriptions: values: opaque: Default type. certificate: List of concatenated PEM blocks. They can contain certificates, private keys or any other PEM block types. key_value: Flat JSON that allows you to set as many first level keys and scalar types as values (string, numeric, boolean) as you need. basic_credentials: Flat JSON that allows you to set a username and a password. database_credentials: Flat JSON that allows you to set an engine, username, password, host, database name, and port. ssh_key: Flat JSON that allows you to set an SSH key. default: unknown_type path: type: string description: 'Path of the secret. (Optional.) Location of the secret in the directory structure. If not specified, the path is `/`.' nullable: true ephemeral_policy: type: object description: 'Ephemeral policy of the secret. (Optional.) Policy that defines whether/when a secret''s versions expire. By default, the policy is applied to all the secret''s versions.' properties: time_to_live: type: string description: Time frame, from one second and up to one year, during which the secret's versions are valid. (in seconds) example: 2.5s nullable: true expires_once_accessed: type: boolean description: Returns `true` if the version expires after a single user access. nullable: true action: type: string description: 'Action to perform when the version of a secret expires. See the `EphemeralPolicy.Action` enum for a description of values.' enum: - unknown_action - delete - disable x-enum-descriptions: values: delete: The version is deleted once it expires. disable: The version is disabled once it expires. default: unknown_action x-properties-order: - time_to_live - expires_once_accessed - action protected: type: boolean description: 'Returns `true` if secret protection is applied to a given secret. A protected secret cannot be deleted.' key_id: type: string description: 'ID of the Scaleway Key Manager key. (Optional.) The Scaleway Key Manager key ID will be used to encrypt and decrypt secret versions. If not specified, Secret Manager will use a Key Manager internal key. (UUID format)' example: 6170692e-7363-616c-6577-61792e636f6d nullable: true x-properties-order: - project_id - name - tags - description - type - path - ephemeral_policy - protected - key_id security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"name\": \"string\",\n \"project_id\": \"6170692e-7363-616c-6577-61792e636f6d\",\n \"protected\": false\n }' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n name=\"string\" \\\n project_id=\"6170692e-7363-616c-6577-61792e636f6d\" \\\n protected:=false" /secret-manager/v1beta1/regions/{region}/secrets/{secret_id}: get: tags: - Secrets operationId: GetSecret summary: Get metadata using the secret's ID description: Retrieve the metadata of a secret specified by the `region` and `secret_id` parameters. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: ID of the secret. (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}\"" - lang: HTTPie source: "http GET \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" patch: tags: - Secrets operationId: UpdateSecret summary: Update metadata of a secret description: Edit a secret's metadata such as name, tag(s), description and ephemeral policy. The secret to update is specified by the `secret_id` and `region` parameters. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: ID of the secret. (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' requestBody: required: true content: application/json: schema: type: object properties: name: type: string description: Secret's updated name (optional). nullable: true tags: type: array description: Secret's updated list of tags (optional). nullable: true items: type: string description: type: string description: Description of the secret. nullable: true path: type: string description: 'Path of the folder. (Optional.) Location of the folder in the directory structure. If not specified, the path is `/`.' nullable: true ephemeral_policy: type: object description: 'Ephemeral policy of the secret. (Optional.) Policy that defines whether/when a secret''s versions expire.' properties: time_to_live: type: string description: Time frame, from one second and up to one year, during which the secret's versions are valid. (in seconds) example: 2.5s nullable: true expires_once_accessed: type: boolean description: Returns `true` if the version expires after a single user access. nullable: true action: type: string description: 'Action to perform when the version of a secret expires. See the `EphemeralPolicy.Action` enum for a description of values.' enum: - unknown_action - delete - disable x-enum-descriptions: values: delete: The version is deleted once it expires. disable: The version is disabled once it expires. default: unknown_action x-properties-order: - time_to_live - expires_once_accessed - action x-properties-order: - name - tags - description - path - ephemeral_policy security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X PATCH \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}\"" - lang: HTTPie source: "http PATCH \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" delete: tags: - Secrets operationId: DeleteSecret summary: Delete a secret description: Delete a given secret specified by the `region` and `secret_id` parameters. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: ID of the secret. (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '204': description: '' security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X DELETE \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}\"" - lang: HTTPie source: "http DELETE \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/add-owner: post: tags: - Secrets operationId: AddSecretOwner summary: Allow a product to use the secret parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: ID of the secret. (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '204': description: '' requestBody: required: true content: application/json: schema: type: object properties: product: type: string description: 'ID of the product to add. See `Product` enum for description of values.' enum: - unknown_product - edge_services - s2s_vpn default: unknown_product x-properties-order: - product security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/add-owner\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/add-owner\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/protect: post: tags: - Secrets operationId: ProtectSecret summary: Enable secret protection description: Enable secret protection for a given secret specified by the `secret_id` parameter. Enabling secret protection means that your secret can be read and modified, but it cannot be deleted. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: ID of the secret to enable secret protection for. (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' requestBody: required: true content: application/json: schema: type: object security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/protect\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/protect\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/restore: post: tags: - Secrets operationId: RestoreSecret summary: Restore a secret description: Restore a secret and all its versions scheduled for deletion specified by the `region` and `secret_id` parameters. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' requestBody: required: true content: application/json: schema: type: object security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/restore\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/restore\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/unprotect: post: tags: - Secrets operationId: UnprotectSecret summary: Disable secret protection description: Disable secret protection for a given secret specified by the `secret_id` parameter. Disabling secret protection means that your secret can be read, modified and deleted. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: ID of the secret to disable secret protection for. (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' requestBody: required: true content: application/json: schema: type: object security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/unprotect\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/unprotect\" \\\n X-Auth-Token:$SCW_SECRET_KEY" /secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/versions/{revision}/restore: post: tags: - Secrets operationId: RestoreSecretVersion summary: Restore a version description: Restore a secret's version specified by the `region`, `secret_id` and `revision` parameters. parameters: - in: path name: region description: The region you want to target required: true schema: type: string enum: - fr-par - nl-ams - pl-waw - in: path name: secret_id description: (UUID format) required: true schema: type: string example: 6170692e-7363-616c-6577-61792e636f6d - in: path name: revision required: true schema: type: string responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.SecretVersion' requestBody: required: true content: application/json: schema: type: object security: - scaleway: [] x-codeSamples: - lang: cURL source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{}' \\\n \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/versions/{revision}/restore\"" - lang: HTTPie source: "http POST \"https://api.scaleway.com/secret-manager/v1beta1/regions/{region}/secrets/{secret_id}/versions/{revision}/restore\" \\\n X-Auth-Token:$SCW_SECRET_KEY" components: schemas: scaleway.secret_manager.v1beta1.Secret: type: object properties: id: type: string description: ID of the secret. (UUID format) example: 6170692e-7363-616c-6577-61792e636f6d project_id: type: string description: ID of the Project containing the secret. (UUID format) example: 6170692e-7363-616c-6577-61792e636f6d name: type: string description: Name of the secret. status: type: string description: 'Current status of the secret. * `ready`: the secret can be read, modified and deleted. * `locked`: no action can be performed on the secret. This status can only be applied and removed by Scaleway.' enum: - unknown_status - ready - locked default: unknown_status created_at: type: string description: Date and time of the secret's creation. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true updated_at: type: string description: Last update of the secret. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true tags: type: array description: List of the secret's tags. items: type: string version_count: type: integer description: Number of versions for this secret. format: uint32 description: type: string description: Updated description of the secret. nullable: true managed: type: boolean description: Returns `true` for secrets that are managed by another product. protected: type: boolean description: Returns `true` for protected secrets that cannot be deleted. type: type: string description: 'Type of the secret. See the `Secret.Type` enum for a description of values.' enum: - unknown_type - opaque - certificate - key_value - basic_credentials - database_credentials - ssh_key x-enum-descriptions: values: opaque: Default type. certificate: List of concatenated PEM blocks. They can contain certificates, private keys or any other PEM block types. key_value: Flat JSON that allows you to set as many first level keys and scalar types as values (string, numeric, boolean) as you need. basic_credentials: Flat JSON that allows you to set a username and a password. database_credentials: Flat JSON that allows you to set an engine, username, password, host, database name, and port. ssh_key: Flat JSON that allows you to set an SSH key. default: unknown_type path: type: string description: 'Path of the secret. Location of the secret in the directory structure.' ephemeral_policy: type: object description: 'Ephemeral policy of the secret. (Optional.) Policy that defines whether/when a secret''s versions expire. By default, the policy is applied to all the secret''s versions.' properties: time_to_live: type: string description: Time frame, from one second and up to one year, during which the secret's versions are valid. (in seconds) example: 2.5s nullable: true expires_once_accessed: type: boolean description: Returns `true` if the version expires after a single user access. nullable: true action: type: string description: 'Action to perform when the version of a secret expires. See the `EphemeralPolicy.Action` enum for a description of values.' enum: - unknown_action - delete - disable x-enum-descriptions: values: delete: The version is deleted once it expires. disable: The version is disabled once it expires. default: unknown_action x-properties-order: - time_to_live - expires_once_accessed - action used_by: type: array description: List of Scaleway resources that can access and manage the secret. items: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Product' deletion_requested_at: type: string description: Returns the time at which deletion was requested. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true key_id: type: string description: 'ID of the Scaleway Key Manager key. (Optional.) The Scaleway Key Manager key ID used to encrypt and decrypt secret versions. (UUID format)' example: 6170692e-7363-616c-6577-61792e636f6d nullable: true region: type: string description: Region of the secret. x-properties-order: - id - project_id - name - status - created_at - updated_at - tags - version_count - description - managed - protected - type - path - ephemeral_policy - used_by - deletion_requested_at - key_id - region scaleway.secret_manager.v1beta1.SecretVersion: type: object properties: revision: type: integer description: 'Version number. The first version of the secret is numbered 1, and all subsequent revisions augment by 1.' format: uint32 secret_id: type: string description: ID of the secret. (UUID format) example: 6170692e-7363-616c-6577-61792e636f6d status: type: string description: 'Current status of the version. * `unknown_status`: the version is in an invalid state. * `enabled`: the version is accessible. * `disabled`: the version is not accessible but can be enabled. * `scheduled_for_deletion`: the version is scheduled for deletion. It will be deleted in 7 days. * `deleted`: the version is permanently deleted. It is not possible to recover it.' enum: - unknown_status - enabled - disabled - deleted - scheduled_for_deletion default: unknown_status created_at: type: string description: Date and time of the version's creation. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true updated_at: type: string description: Last update of the version. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true deleted_at: type: string description: Date and time of the version's deletion. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true description: type: string description: Description of the version. nullable: true latest: type: boolean description: Returns `true` if the version is the latest. ephemeral_properties: type: object description: 'Properties of the ephemeral version. Returns the version''s expiration date, whether it expires after being accessed once, and the action to perform (disable or delete) once the version expires.' properties: expires_at: type: string description: 'The version''s expiration date. (Optional.) If not specified, the version does not have an expiration date. (RFC 3339 format)' format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true expires_once_accessed: type: boolean description: 'Returns `true` if the version expires after a single user access. (Optional.) If not specified, the version can be accessed an unlimited amount of times.' nullable: true action: type: string description: 'Action to perform when the version of a secret expires. See `EphemeralPolicy.Action` enum for a description of values.' enum: - unknown_action - delete - disable x-enum-descriptions: values: delete: The version is deleted once it expires. disable: The version is disabled once it expires. default: unknown_action x-properties-order: - expires_at - expires_once_accessed - action deletion_requested_at: type: string description: Returns the time at which deletion was requested. (RFC 3339 format) format: date-time example: '2022-03-22T12:34:56.123456Z' nullable: true region: type: string description: Region of the version. x-properties-order: - revision - secret_id - status - created_at - updated_at - deleted_at - description - latest - ephemeral_properties - deletion_requested_at - region google.protobuf.Int32Value: type: integer format: int32 nullable: true scaleway.secret_manager.v1beta1.ListSecretsResponse: type: object properties: secrets: type: array description: Single page of secrets matching the requested criteria. items: $ref: '#/components/schemas/scaleway.secret_manager.v1beta1.Secret' total_count: type: integer description: Count of all secrets matching the requested criteria. format: uint64 x-properties-order: - secrets - total_count scaleway.secret_manager.v1beta1.ListSecretsRequest.OrderBy: type: string enum: - name_asc - name_desc - created_at_asc - created_at_desc - updated_at_asc - updated_at_desc default: name_asc scaleway.secret_manager.v1beta1.Product: type: string enum: - unknown_product - edge_services - s2s_vpn default: unknown_product securitySchemes: scaleway: in: header name: X-Auth-Token type: apiKey