vault_replicas
Creates, updates, deletes, gets or lists a vault_replicas resource.
Overview​
| Name | vault_replicas |
| Type | Resource |
| Id | oci.kms.vault_replicas |
Fields​
The following fields are returned by SELECT queries:
- list
Summary of vault replicas
| Name | Datatype | Description |
|---|---|---|
cryptoEndpoint | string | The vault replica's crypto endpoint |
managementEndpoint | string | The vault replica's management endpoint |
region | string | Region to which vault is replicated to |
status | string | Status of the Vault (CREATING, CREATED, DELETING, DELETED) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | vaultId, region | if-match, limit, page, opc-request-id, opc-retry-token, sortBy, sortOrder | Lists the replicas for a vault<br /><br />As a provisioning operation, this call is subject to a Key Management limit that applies to<br />the total number of requests across all provisioning write operations. Key Management might<br />throttle this call to reject an otherwise valid request when the total rate of provisioning<br />write operations exceeds 10 requests per second for a given tenancy.<br /> |
create | insert | vaultId, region, replicaRegion | if-match, opc-request-id, opc-retry-token | Creates a replica for the vault in another region in the same realm<br /><br />The API is a no-op if called for same region that a vault is already replicated to.<br />409 if called on a vault that is already replicated to a different region. Users need to delete<br />existing replica first before calling it with a different region.<br /><br />As a provisioning operation, this call is subject to a Key Management limit that applies to<br />the total number of requests across all provisioning write operations. Key Management might<br />throttle this call to reject an otherwise valid request when the total rate of provisioning<br />write operations exceeds 10 requests per second for a given tenancy.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
vaultId | string | The OCID of the vault. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
opc-request-id | string | Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
sortBy | string | The field to sort by. You can specify only one sort order. The default order for TIMECREATED is descending. The default order for DISPLAYNAME is ascending. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). |
SELECT examples​
- list
Lists the replicas for a vault<br /><br />As a provisioning operation, this call is subject to a Key Management limit that applies to<br />the total number of requests across all provisioning write operations. Key Management might<br />throttle this call to reject an otherwise valid request when the total rate of provisioning<br />write operations exceeds 10 requests per second for a given tenancy.<br />
SELECT
cryptoEndpoint,
managementEndpoint,
region,
status
FROM oci.kms.vault_replicas
WHERE vaultId = '{{ vaultId }}' -- required
AND region = '{{ region }}' -- required
AND if-match = '{{ if-match }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND opc-request-id = '{{ opc-request-id }}'
AND opc-retry-token = '{{ opc-retry-token }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
;
INSERT examples​
- create
- Manifest
Creates a replica for the vault in another region in the same realm<br /><br />The API is a no-op if called for same region that a vault is already replicated to.<br />409 if called on a vault that is already replicated to a different region. Users need to delete<br />existing replica first before calling it with a different region.<br /><br />As a provisioning operation, this call is subject to a Key Management limit that applies to<br />the total number of requests across all provisioning write operations. Key Management might<br />throttle this call to reject an otherwise valid request when the total rate of provisioning<br />write operations exceeds 10 requests per second for a given tenancy.<br />
INSERT INTO oci.kms.vault_replicas (
replicaRegion,
replicaVaultMetadata,
vaultId,
region,
if-match,
opc-request-id,
opc-retry-token
)
SELECT
'{{ replicaRegion }}' /* required */,
'{{ replicaVaultMetadata }}',
'{{ vaultId }}',
'{{ region }}',
'{{ if-match }}',
'{{ opc-request-id }}',
'{{ opc-retry-token }}'
;
# Description fields are for documentation purposes
- name: vault_replicas
props:
- name: vaultId
value: "{{ vaultId }}"
description: Required parameter for the vault_replicas resource.
- name: region
value: "{{ region }}"
description: Required parameter for the vault_replicas resource.
- name: replicaRegion
value: "{{ replicaRegion }}"
description: |
The region in the realm to which the vault need to be replicated to
- name: replicaVaultMetadata
description: |
Metadata for the replica vault, needed if different from primary vault
value:
vaultType: "{{ vaultType }}"
- name: if-match
value: "{{ if-match }}"
description: For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
description: For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
- name: opc-request-id
value: "{{ opc-request-id }}"
description: Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
description: Unique identifier for the request. If provided, the returned request ID will include this value. Otherwise, a random request ID will be generated by the service.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).