Skip to main content

bs

Creates, updates, deletes, gets or lists a bs resource.

Overview​

Namebs
TypeResource
Idoci.object_storage.bs

Fields​

The following fields are returned by SELECT queries:

SELECT not supported for this resource, use SHOW METHODS to view available operations for the resource.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
batch_delete_objectsexecnamespaceName, bucketName, region, objectsopc-client-request-idDeletes a batch of objects.
copy_objectexecnamespaceName, bucketName, region, sourceObjectName, destinationRegion, destinationNamespace, destinationBucket, destinationObjectNameopc-client-request-id, opc-sse-customer-algorithm, opc-sse-customer-key, opc-sse-customer-key-sha256, opc-source-sse-customer-algorithm, opc-source-sse-customer-key, opc-source-sse-customer-key-sha256, opc-sse-kms-key-idCreates a request to copy an object within a region or to another region.<br /><br />See [Object Names](/Content/Object/Tasks/managingobjects.htm#namerequirements)<br />for object naming requirements.<br />
make_bucket_writableexecnamespaceName, bucketName, regionopc-client-request-idStops replication to the destination bucket and removes the replication policy. When the replication<br />policy was created, this destination bucket became read-only except for new and changed objects replicated<br />automatically from the source bucket. MakeBucketWritable removes the replication policy. This bucket is no<br />longer the target for replication and is now writable, allowing users to make changes to bucket contents.<br />
reencrypt_bucketexecnamespaceName, bucketName, regionisReencryptBucketKeyOnly, opc-client-request-idRe-encrypts the unique data encryption key that encrypts each object written to the bucket by using the most recent <br />version of the master encryption key assigned to the bucket. (All data encryption keys are encrypted by a master <br />encryption key. Master encryption keys are assigned to buckets and managed by Oracle by default, but you can assign <br />a key that you created and control through the Oracle Cloud Infrastructure Key Management service.) The kmsKeyId property <br />of the bucket determines which master encryption key is assigned to the bucket. If you assigned a different Key Management <br />master encryption key to the bucket, you can call this API to re-encrypt all data encryption keys with the newly <br />assigned key. Similarly, you might want to re-encrypt all data encryption keys if the assigned key has been rotated to <br />a new key version since objects were last added to the bucket. If you call this API and there is no kmsKeyId associated <br />with the bucket, the call will fail. <br />Also, if you set isBucketKeyEnabled, you might want to re-encrypt all data encryption keys<br />using the bucket key. This will help reduce calls to OCI Vault KMS when older objects are downloaded.<br /><br />Calling this API starts a work request task to re-encrypt the data encryption key of all objects in the bucket. Only <br />objects created before the time of the API call will be re-encrypted. The call can take a long time, depending on how many <br />objects are in the bucket and how big they are. This API returns a work request ID that you can use to retrieve the status <br />of the work request task.<br />All the versions of objects will be re-encrypted whether versioning is enabled or suspended at the bucket.<br />
reencrypt_objectexecnamespaceName, bucketName, objectName, regionversionId, opc-client-request-idRe-encrypts the data encryption keys that encrypt the object and its chunks. By default, when you create a bucket, the Object Storage<br />service manages the master encryption key used to encrypt each object's data encryption keys. The encryption mechanism that you specify for<br />the bucket applies to the objects it contains.<br /><br />You can alternatively employ one of these encryption strategies for an object:<br /><br />- You can assign a key that you created and control through the Oracle Cloud Infrastructure Vault service.<br /><br />- You can encrypt an object using your own encryption key. The key you supply is known as a customer-provided encryption key (SSE-C).<br />
rename_objectexecnamespaceName, bucketName, region, sourceName, newNameopc-client-request-idRename an object in the given Object Storage namespace.<br /><br />See [Object Names](/Content/Object/Tasks/managingobjects.htm#namerequirements)<br />for object naming requirements.<br />
restore_objectsexecnamespaceName, bucketName, region, objectNameopc-client-request-idRestores the object specified by the objectName parameter.<br />By default object will be restored for 24 hours. Duration can be configured using the hours parameter.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
bucketNamestringThe name of the bucket. Avoid entering confidential information. Example: my-new-bucket1
namespaceNamestringThe Object Storage namespace used for the request.
objectNamestringThe name of the object. Avoid entering confidential information. Example: test/object1.log
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
isReencryptBucketKeyOnlybooleanIf true, reencrypt only the intermediate bucket keys and skip everything else in the bucket.
opc-client-request-idstringThe client request ID for tracing.
opc-source-sse-customer-algorithmstringThe optional header that specifies "AES256" as the encryption algorithm to use to decrypt the source object. For more information, see [Using Your Own Keys for Server-Side Encryption](/Content/Object/Tasks/usingyourencryptionkeys.htm).
opc-source-sse-customer-keystringThe optional header that specifies the base64-encoded 256-bit encryption key to use to decrypt the source object. For more information, see [Using Your Own Keys for Server-Side Encryption](/Content/Object/Tasks/usingyourencryptionkeys.htm).
opc-source-sse-customer-key-sha256stringThe optional header that specifies the base64-encoded SHA256 hash of the encryption key used to decrypt the source object. This value is used to check the integrity of the encryption key. For more information, see [Using Your Own Keys for Server-Side Encryption](/Content/Object/Tasks/usingyourencryptionkeys.htm).
opc-sse-customer-algorithmstringThe optional header that specifies "AES256" as the encryption algorithm. For more information, see [Using Your Own Keys for Server-Side Encryption](/Content/Object/Tasks/usingyourencryptionkeys.htm).
opc-sse-customer-keystringThe optional header that specifies the base64-encoded 256-bit encryption key to use to encrypt or decrypt the data. For more information, see [Using Your Own Keys for Server-Side Encryption](/Content/Object/Tasks/usingyourencryptionkeys.htm).
opc-sse-customer-key-sha256stringThe optional header that specifies the base64-encoded SHA256 hash of the encryption key. This value is used to check the integrity of the encryption key. For more information, see [Using Your Own Keys for Server-Side Encryption](/Content/Object/Tasks/usingyourencryptionkeys.htm).
opc-sse-kms-key-idstringThe [OCID](/Content/General/Concepts/identifiers.htm) of a master encryption key used to call the Key Management service to generate a data encryption key or to encrypt or decrypt a data encryption key.
versionIdstringVersionId used to identify a particular version of the object

Lifecycle Methods​

Deletes a batch of objects.

EXEC oci.object_storage.bs.batch_delete_objects
@namespaceName='{{ namespaceName }}' --required,
@bucketName='{{ bucketName }}' --required,
@region='{{ region }}' --required,
@opc-client-request-id='{{ opc-client-request-id }}'
@@json=
'{
"isSkipDeletedResult": {{ isSkipDeletedResult }},
"objects": "{{ objects }}"
}'
;