ekms_private_endpoints
Creates, updates, deletes, gets or lists an ekms_private_endpoints resource.
Overview​
| Name | ekms_private_endpoints |
| Type | Resource |
| Id | oci.kms.ekms_private_endpoints |
Fields​
The following fields are returned by SELECT queries:
- get
- list
Retrieves EKMS private endpoint with given id.
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier that is immutable |
caBundle | string | CABundle to validate TLS certificate of the external key manager system in PEM format |
compartmentId | string | Compartment Identifier. |
definedTags | object | Usage of predefined tag keys. These predefined keys are scoped to namespaces. Example: {"foo-namespace": {"bar-key": "value"}} |
displayName | string | EKMS Private Endpoint display name |
externalKeyManagerIp | string | Private IP of the external key manager system to connect to from the EKMS private endpoint |
freeformTags | object | Simple key-value pair that is applied without any predefined name, type, or scope. Exists for cross-compatibility only. Example: {"bar-key": "value"} |
lifecycleDetails | string | A message describing the current state in more detail. For example, can be used to provide actionable information for a resource in 'Failed' state. |
lifecycleState | string | The current state of the EKMS private endpoint resource. (CREATING, ACTIVE, DELETING, DELETED, FAILED) |
port | integer | The port of the external key manager system |
privateEndpointIp | string | The IP address in the customer's VCN for the EKMS private endpoint. This is taken from subnet |
subnetId | string | Subnet Identifier |
timeCreated | string (date-time) | The time the EKMS private endpoint was created. An [RFC3339](https:​//tools.ietf.org/html/rfc3339) formatted datetime string. |
timeUpdated | string (date-time) | The time the EKMS private endpoint was updated. An [RFC3339](https:​//tools.ietf.org/html/rfc3339) formatted datetime string. |
EKMS private endpoints summary
| Name | Datatype | Description |
|---|---|---|
id | string | Unique identifier that is immutable |
compartmentId | string | Identifier of the compartment this EKMS private endpoint belongs to |
definedTags | object | Usage of predefined tag keys. These predefined keys are scoped to namespaces. Example: {"foo-namespace": {"bar-key": "value"}} |
displayName | string | Mutable name of the EKMS private endpoint |
freeformTags | object | Simple key-value pair that is applied without any predefined name, type, or scope. Exists for cross-compatibility only. Example: {"bar-key": "value"} |
lifecycleState | string | The current state of the EKMS private endpoint resource. (CREATING, ACTIVE, DELETING, DELETED, FAILED) |
subnetId | string | Subnet Identifier |
timeCreated | string (date-time) | The time the EKMS private endpoint was created. An [RFC3339](https:​//tools.ietf.org/html/rfc3339) formatted datetime string. |
timeUpdated | string (date-time) | The time the EKMS private endpoint was updated. An [RFC3339](https:​//tools.ietf.org/html/rfc3339) formatted datetime string. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | ekmsPrivateEndpointId, region | opc-request-id | Gets a specific EKMS private by identifier. |
list | select | compartmentId, region | limit, page, sortOrder, sortBy, opc-request-id | Returns a list of all the EKMS private endpoints in the specified compartment.<br /> |
create | insert | region, subnetId, compartmentId, externalKeyManagerIp, caBundle, displayName | opc-request-id, opc-retry-token | Create a new EKMS private endpoint used to connect to external key manager system |
update | update | ekmsPrivateEndpointId, region | if-match, opc-request-id | Updates EKMS private endpoint. |
delete | delete | ekmsPrivateEndpointId, region | if-match, opc-request-id | Deletes EKMS private endpoint by identifier. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The OCID of the compartment. |
ekmsPrivateEndpointId | string | Unique EKMS private endpoint identifier. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
opc-request-id | string | Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
sortBy | string | The field to sort by. You can specify only one sort order. The default order for TIMECREATED is descending. The default order for DISPLAYNAME is ascending. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). |
SELECT examples​
- get
- list
Gets a specific EKMS private by identifier.
SELECT
id,
caBundle,
compartmentId,
definedTags,
displayName,
externalKeyManagerIp,
freeformTags,
lifecycleDetails,
lifecycleState,
port,
privateEndpointIp,
subnetId,
timeCreated,
timeUpdated
FROM oci.kms.ekms_private_endpoints
WHERE ekmsPrivateEndpointId = '{{ ekmsPrivateEndpointId }}' -- required
AND region = '{{ region }}' -- required
AND opc-request-id = '{{ opc-request-id }}'
;
Returns a list of all the EKMS private endpoints in the specified compartment.<br />
SELECT
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
subnetId,
timeCreated,
timeUpdated
FROM oci.kms.ekms_private_endpoints
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND sortOrder = '{{ sortOrder }}'
AND sortBy = '{{ sortBy }}'
AND opc-request-id = '{{ opc-request-id }}'
;
INSERT examples​
- create
- Manifest
Create a new EKMS private endpoint used to connect to external key manager system
INSERT INTO oci.kms.ekms_private_endpoints (
caBundle,
compartmentId,
definedTags,
displayName,
externalKeyManagerIp,
freeformTags,
port,
subnetId,
region,
opc-request-id,
opc-retry-token
)
SELECT
'{{ caBundle }}' /* required */,
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ displayName }}' /* required */,
'{{ externalKeyManagerIp }}' /* required */,
'{{ freeformTags }}',
{{ port }},
'{{ subnetId }}' /* required */,
'{{ region }}',
'{{ opc-request-id }}',
'{{ opc-retry-token }}'
RETURNING
id,
caBundle,
compartmentId,
definedTags,
displayName,
externalKeyManagerIp,
freeformTags,
lifecycleDetails,
lifecycleState,
port,
privateEndpointIp,
subnetId,
timeCreated,
timeUpdated
;
# Description fields are for documentation purposes
- name: ekms_private_endpoints
props:
- name: region
value: "{{ region }}"
description: Required parameter for the ekms_private_endpoints resource.
- name: caBundle
value: "{{ caBundle }}"
description: |
CABundle to validate TLS certificate of the external key manager system in PEM format
- name: compartmentId
value: "{{ compartmentId }}"
description: |
Compartment identifier.
- name: definedTags
value: "{{ definedTags }}"
description: |
Usage of predefined tag keys. These predefined keys are scoped to namespaces.
Example: `{"foo-namespace": {"bar-key": "value"}}`
- name: displayName
value: "{{ displayName }}"
description: |
Display name of the EKMS private endpoint resource being created.
- name: externalKeyManagerIp
value: "{{ externalKeyManagerIp }}"
description: |
External private IP to connect to from this EKMS private endpoint
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Simple key-value pair that is applied without any predefined name, type, or scope. Exists for cross-compatibility only.
Example: `{"bar-key": "value"}`
- name: port
value: {{ port }}
description: |
The port of the external key manager system
- name: subnetId
value: "{{ subnetId }}"
description: |
The OCID of subnet in which the EKMS private endpoint is to be created
- name: opc-request-id
value: "{{ opc-request-id }}"
description: Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
description: Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates EKMS private endpoint.
UPDATE oci.kms.ekms_private_endpoints
SET
definedTags = '{{ definedTags }}',
displayName = '{{ displayName }}',
freeformTags = '{{ freeformTags }}'
WHERE
ekmsPrivateEndpointId = '{{ ekmsPrivateEndpointId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND opc-request-id = '{{ opc-request-id}}'
RETURNING
id,
caBundle,
compartmentId,
definedTags,
displayName,
externalKeyManagerIp,
freeformTags,
lifecycleDetails,
lifecycleState,
port,
privateEndpointIp,
subnetId,
timeCreated,
timeUpdated;
DELETE examples​
- delete
Deletes EKMS private endpoint by identifier.
DELETE FROM oci.kms.ekms_private_endpoints
WHERE ekmsPrivateEndpointId = '{{ ekmsPrivateEndpointId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
AND opc-request-id = '{{ opc-request-id }}'
;