customer_secret_keys
Creates, updates, deletes, gets or lists a customer_secret_keys resource.
Overview​
| Name | customer_secret_keys |
| Type | Resource |
| Id | oci.identity.customer_secret_keys |
Fields​
The following fields are returned by SELECT queries:
- list
As the name suggests, a CustomerSecretKeySummary object contains information about a CustomerSecretKey.<br />A CustomerSecretKey is an Oracle-provided key for using the Object Storage Service's Amazon S3 compatible API.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the secret key. |
displayName | string | The displayName you assign to the secret key. Does not have to be unique, and it's changeable. |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The secret key's current state. After creating a secret key, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
timeCreated | string (date-time) | Date and time the CustomerSecretKey object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
timeExpires | string (date-time) | Date and time when this password will expire, in the format defined by RFC3339. Null if it never expires. Example: 2016-08-25T21:10:29.600Z |
userId | string | The OCID of the user the password belongs to. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | userId, region | Lists the secret keys for the specified user. The returned object contains the secret key's OCID, but not<br />the secret key itself. The actual secret key is returned only upon creation.<br /> | |
create | insert | userId, region, displayName | opc-retry-token | Creates a new secret key for the specified user. Secret keys are used for authentication with the Object Storage Service's Amazon S3<br />compatible API. The secret key consists of an Access Key/Secret Key pair. For information, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the secret key (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateCustomerSecretKey](#/en/identity/20160918/CustomerSecretKeySummary/UpdateCustomerSecretKey).<br /><br />Every user has permission to create a secret key for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create a secret key for any user, including themselves.<br /> |
update | update | userId, customerSecretKeyId, region | if-match | Updates the specified secret key's description.<br /> |
delete | delete | userId, customerSecretKeyId, region | if-match | Deletes the specified secret key for the specified user.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
customerSecretKeyId | string | The access token of the secret key. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
userId | string | The OCID of the user. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
SELECT examples​
- list
Lists the secret keys for the specified user. The returned object contains the secret key's OCID, but not<br />the secret key itself. The actual secret key is returned only upon creation.<br />
SELECT
id,
displayName,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
userId
FROM oci.identity.customer_secret_keys
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
;
INSERT examples​
- create
- Manifest
Creates a new secret key for the specified user. Secret keys are used for authentication with the Object Storage Service's Amazon S3<br />compatible API. The secret key consists of an Access Key/Secret Key pair. For information, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the secret key (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateCustomerSecretKey](#/en/identity/20160918/CustomerSecretKeySummary/UpdateCustomerSecretKey).<br /><br />Every user has permission to create a secret key for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create a secret key for any user, including themselves.<br />
INSERT INTO oci.identity.customer_secret_keys (
displayName,
userId,
region,
opc-retry-token
)
SELECT
'{{ displayName }}' /* required */,
'{{ userId }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
displayName,
inactiveStatus,
key,
lifecycleState,
timeCreated,
timeExpires,
userId
;
# Description fields are for documentation purposes
- name: customer_secret_keys
props:
- name: userId
value: "{{ userId }}"
description: Required parameter for the customer_secret_keys resource.
- name: region
value: "{{ region }}"
description: Required parameter for the customer_secret_keys resource.
- name: displayName
value: "{{ displayName }}"
description: |
The name you assign to the secret key during creation. Does not have to be unique, and it's changeable.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the specified secret key's description.<br />
UPDATE oci.identity.customer_secret_keys
SET
displayName = '{{ displayName }}'
WHERE
userId = '{{ userId }}' --required
AND customerSecretKeyId = '{{ customerSecretKeyId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
displayName,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
userId;
DELETE examples​
- delete
Deletes the specified secret key for the specified user.<br />
DELETE FROM oci.identity.customer_secret_keys
WHERE userId = '{{ userId }}' --required
AND customerSecretKeyId = '{{ customerSecretKeyId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;