Skip to main content

volume_kms_keys

Creates, updates, deletes, gets or lists a volume_kms_keys resource.

Overview​

Namevolume_kms_keys
TypeResource
Idoci.block_storage.volume_kms_keys

Fields​

The following fields are returned by SELECT queries:

The OCID of the Vault service master encryption key associated with this volume.

NameDatatypeDescription
kmsKeyIdstringThe OCID of the Vault service key assigned to this volume. If the volume is not using Vault service, then the kmsKeyId will be a null string.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectvolumeId, regionif-matchGets the Vault service encryption key assigned to the specified volume.<br />
updateupdatevolumeId, regionif-matchUpdates the specified volume with a new Key Management master encryption key.<br />
deletedeletevolumeId, regionif-matchRemoves the specified volume's assigned Vault service encryption key.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
volumeIdstringThe OCID of the volume.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.

SELECT examples​

Gets the Vault service encryption key assigned to the specified volume.<br />

SELECT
kmsKeyId
FROM oci.block_storage.volume_kms_keys
WHERE volumeId = '{{ volumeId }}' -- required
AND region = '{{ region }}' -- required
AND if-match = '{{ if-match }}'
;

UPDATE examples​

Updates the specified volume with a new Key Management master encryption key.<br />

UPDATE oci.block_storage.volume_kms_keys
SET
kmsKeyId = '{{ kmsKeyId }}'
WHERE
volumeId = '{{ volumeId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
kmsKeyId;

DELETE examples​

Removes the specified volume's assigned Vault service encryption key.<br />

DELETE FROM oci.block_storage.volume_kms_keys
WHERE volumeId = '{{ volumeId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;