private_endpoints
Creates, updates, deletes, gets or lists a private_endpoints resource.
Overview​
| Name | private_endpoints |
| Type | Resource |
| Id | oci.object_storage.private_endpoints |
Fields​
The following fields are returned by SELECT queries:
- get
- list
A private endpoint representation for the requested private endpoint.
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/Content/General/Concepts/identifiers.htm) of the PrivateEndpoint. |
name | string | This name associated with the endpoint. Valid characters are uppercase or lowercase letters, numbers, hyphens, underscores, and periods. Example: my-new-private-endpoint1 |
accessTargets | array | A list of targets that can be accessed by the private endpoint. At least one or more access targets is required for a private endpoint. |
additionalPrefixes | array | A list of additional prefix that you can provide along with any other prefix. These resulting endpointFqdn's are added to the customer VCN's DNS record. |
compartmentId | string | The compartment which is associated with the Private Endpoint. |
createdBy | string | The [OCID](/Content/General/Concepts/identifiers.htm) of the user who created the Private Endpoint. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
etag | string | The entity tag (ETag) for the Private Endpoint. |
fqdns | object | The object representing FQDN details formed using prefix and additionalPrefixes. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
lifecycleState | string | The Private Endpoint's lifecycle state. (CREATING, ACTIVE, INACTIVE, UPDATING, DELETING, DELETED, FAILED) |
namespace | string | The Object Storage namespace associated with the private enpoint. |
nsgIds | array | A list of the OCIDs of the network security groups (NSGs) to add the private endpoint's VNIC to. For more information about NSGs, see [NetworkSecurityGroup](#/en/iaas/latest/NetworkSecurityGroup/). |
prefix | string | A prefix to use for the private endpoint. The customer VCN's DNS records are updated with this prefix. The prefix input from the customer will be the first sub-domain in the endpointFqdn. Example: If the prefix chosen is "abc", then the endpointFqdn will be 'abc.private.objectstorage.<region>.oraclecloud.com' |
privateEndpointIp | string | The private IP address to assign to this private endpoint. If you provide a value, it must be an available IP address in the customer's subnet. If it's not available, an error is returned. If you do not provide a value, an available IP address in the subnet is automatically chosen. |
securityAttributes | object | Security attributes for Private Endpoint resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Oracle-ZPR": {"MaxEgressCount": {"value": "42", "mode": "enforce"}}} |
subnetId | string | The OCID of the customer's subnet where the private endpoint VNIC will reside. |
timeCreated | string (date-time) | The date and time the Private Endpoint was created, as described in [RFC 2616](https:​//tools.ietf.org/html/rfc2616#section-14.29). |
timeModified | string (date-time) | The date and time the Private Endpoint was updated, as described in [RFC 2616](https:​//tools.ietf.org/html/rfc2616#section-14.29). |
To use any of the API operations, you must be authorized in an IAM policy. If you are not authorized,<br />talk to an administrator. If you are an administrator who needs to write policies to give users access, see<br />[Getting Started with Policies](/Content/Identity/Concepts/policygetstarted.htm).<br />
| Name | Datatype | Description |
|---|---|---|
name | string | The name given to the Private Endpoint. Avoid entering confidential information. Example: my-new-pe1 |
compartmentId | string | The compartment ID in which the Private Endpoint is authorized. |
createdBy | string | The [OCID](/Content/General/Concepts/identifiers.htm) of the user who created the Private Endpoint. |
etag | string | The entity tag for the Private Endpoint. |
fqdns | object | The object representing FQDN details formed using prefix and additionalPrefixes. |
lifecycleState | string | The summaries of Private Endpoints' lifecycle state. (x-obmcs-enumref: #/definitions/PrivateEndpoint/lifecycleState) |
namespace | string | The Object Storage namespace with which the Private Endpoint is associated. |
prefix | string | A prefix to use for the private endpoint. The customer VCN's DNS records are updated with this prefix. The prefix input from the customer will be the first sub-domain in the endpointFqdn. Example: If the prefix chosen is "abc", then the endpointFqdn will be 'abc.private.objectstorage.<region>.oraclecloud.com' |
timeCreated | string (date-time) | The date and time the Private Endpoint was created, as described in [RFC 2616](https:​//tools.ietf.org/html/rfc2616#section-14.29). |
timeModified | string (date-time) | The date and time the Private Endpoint was updated, as described in [RFC 2616](https:​//tools.ietf.org/html/rfc2616#section-14.29). |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | namespaceName, peName, region | if-match, if-none-match, opc-client-request-id | Gets the current representation of the given Private Endpoint in the given Object Storage namespace.<br /> |
list | select | namespaceName, compartmentId, region | limit, page, fields, opc-client-request-id, lifecycleState | Gets a list of all PrivateEndpointSummary in a compartment associated with a namespace.<br />To use this and other API operations, you must be authorized in an IAM policy. If you are not authorized,<br />talk to an administrator. If you are an administrator who needs to write policies to give users access, see<br />[Getting Started with Policies](/Content/Identity/Concepts/policygetstarted.htm).<br /> |
create | insert | namespaceName, region, name, compartmentId, subnetId, prefix, accessTargets | opc-client-request-id | Create a PrivateEndpoint.<br /> |
update | update | namespaceName, peName, region | opc-client-request-id, if-match | Performs a partial or full update of a user-defined data associated with the Private Endpoint.<br /><br />Use UpdatePrivateEndpoint to move a Private Endpoint from one compartment to another within the same tenancy. Supply the compartmentID<br />of the compartment that you want to move the Private Endpoint to. Or use it to update the name, subnetId, endpointFqdn or privateEndpointIp or accessTargets of the Private Endpoint.<br />For more information about moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /><br />This API follows replace semantics (rather than merge semantics). That means if the body provides values for <br />parameters and the resource has exisiting ones, this operation will replace those existing values. <br /> |
delete | delete | namespaceName, peName, region | if-match, opc-client-request-id | Deletes a Private Endpoint if it exists in the given namespace.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The ID of the compartment in which to list buckets. |
namespaceName | string | The Object Storage namespace used for the request. |
peName | string | The name of the private endpoint. Avoid entering confidential information. Example: my-new-pe-1 |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
fields | array | PrivateEndpoint summary in list of PrivateEndpoints includes the 'namespace', 'name', 'compartmentId', 'createdBy', 'timeCreated', 'timeModified' and 'etag' fields. This parameter can also include 'tags' (freeformTags and definedTags). The only supported value of this parameter is 'tags' for now. Example 'tags'. |
if-match | string | The entity tag (ETag) to match with the ETag of an existing resource. If the specified ETag matches the ETag of the existing resource, GET and HEAD requests will return the resource and PUT and POST requests will upload the resource. |
if-none-match | string | The entity tag (ETag) to avoid matching. Wildcards ('*') are not allowed. If the specified ETag does not match the ETag of the existing resource, the request returns the expected response. If the ETag matches the ETag of the existing resource, the request returns an HTTP 304 status without a response body. |
lifecycleState | string | The lifecycle state of the Private Endpoint |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
opc-client-request-id | string | The client request ID for tracing. |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
SELECT examples​
- get
- list
Gets the current representation of the given Private Endpoint in the given Object Storage namespace.<br />
SELECT
id,
name,
accessTargets,
additionalPrefixes,
compartmentId,
createdBy,
definedTags,
etag,
fqdns,
freeformTags,
lifecycleState,
namespace,
nsgIds,
prefix,
privateEndpointIp,
securityAttributes,
subnetId,
timeCreated,
timeModified
FROM oci.object_storage.private_endpoints
WHERE namespaceName = '{{ namespaceName }}' -- required
AND peName = '{{ peName }}' -- required
AND region = '{{ region }}' -- required
AND if-match = '{{ if-match }}'
AND if-none-match = '{{ if-none-match }}'
AND opc-client-request-id = '{{ opc-client-request-id }}'
;
Gets a list of all PrivateEndpointSummary in a compartment associated with a namespace.<br />To use this and other API operations, you must be authorized in an IAM policy. If you are not authorized,<br />talk to an administrator. If you are an administrator who needs to write policies to give users access, see<br />[Getting Started with Policies](/Content/Identity/Concepts/policygetstarted.htm).<br />
SELECT
name,
compartmentId,
createdBy,
etag,
fqdns,
lifecycleState,
namespace,
prefix,
timeCreated,
timeModified
FROM oci.object_storage.private_endpoints
WHERE namespaceName = '{{ namespaceName }}' -- required
AND compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND fields = '{{ fields }}'
AND opc-client-request-id = '{{ opc-client-request-id }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Create a PrivateEndpoint.<br />
INSERT INTO oci.object_storage.private_endpoints (
accessTargets,
additionalPrefixes,
compartmentId,
definedTags,
freeformTags,
name,
nsgIds,
prefix,
privateEndpointIp,
securityAttributes,
subnetId,
namespaceName,
region,
opc-client-request-id
)
SELECT
'{{ accessTargets }}' /* required */,
'{{ additionalPrefixes }}',
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ freeformTags }}',
'{{ name }}' /* required */,
'{{ nsgIds }}',
'{{ prefix }}' /* required */,
'{{ privateEndpointIp }}',
'{{ securityAttributes }}',
'{{ subnetId }}' /* required */,
'{{ namespaceName }}',
'{{ region }}',
'{{ opc-client-request-id }}'
;
# Description fields are for documentation purposes
- name: private_endpoints
props:
- name: namespaceName
value: "{{ namespaceName }}"
description: Required parameter for the private_endpoints resource.
- name: region
value: "{{ region }}"
description: Required parameter for the private_endpoints resource.
- name: accessTargets
description: |
A list of targets that can be accessed by the private endpoint.
value:
- bucket: "{{ bucket }}"
compartmentId: "{{ compartmentId }}"
namespace: "{{ namespace }}"
- name: additionalPrefixes
value:
- "{{ additionalPrefixes }}"
description: |
A list of additional prefix that you can provide along with any other prefix. These resulting endpointFqdn's are added to the
customer VCN's DNS record.
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The ID of the compartment in which to create the Private Endpoint.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: name
value: "{{ name }}"
description: |
This name associated with the endpoint. Valid characters are uppercase or lowercase letters, numbers, hyphens,
underscores, and periods.
Example: my-new-private-endpoint1
- name: nsgIds
value:
- "{{ nsgIds }}"
description: |
A list of the OCIDs of the network security groups (NSGs) to add the private endpoint's VNIC to.
For more information about NSGs, see
[NetworkSecurityGroup](#/en/iaas/latest/NetworkSecurityGroup/).
- name: prefix
value: "{{ prefix }}"
description: |
A prefix to use for the private endpoint. The customer VCN's DNS records are
updated with this prefix. The prefix input from the customer will be the first sub-domain in the endpointFqdn.
Example: If the prefix chosen is "abc", then the endpointFqdn will be 'abc.private.objectstorage.<region>.oraclecloud.com'
- name: privateEndpointIp
value: "{{ privateEndpointIp }}"
description: |
The private IP address to assign to this private endpoint. If you provide a value,
it must be an available IP address in the customer's subnet. If it's not available, an error
is returned.
If you do not provide a value, an available IP address in the subnet is automatically chosen.
- name: securityAttributes
value: "{{ securityAttributes }}"
description: |
Security attributes for Private Endpoint resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Oracle-ZPR": {"MaxEgressCount": {"value": "42", "mode": "enforce"}}}`
- name: subnetId
value: "{{ subnetId }}"
description: |
The OCID of the customer's subnet where the private endpoint VNIC will reside.
- name: opc-client-request-id
value: "{{ opc-client-request-id }}"
description: The client request ID for tracing.
description: The client request ID for tracing.
UPDATE examples​
- update
Performs a partial or full update of a user-defined data associated with the Private Endpoint.<br /><br />Use UpdatePrivateEndpoint to move a Private Endpoint from one compartment to another within the same tenancy. Supply the compartmentID<br />of the compartment that you want to move the Private Endpoint to. Or use it to update the name, subnetId, endpointFqdn or privateEndpointIp or accessTargets of the Private Endpoint.<br />For more information about moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /><br />This API follows replace semantics (rather than merge semantics). That means if the body provides values for <br />parameters and the resource has exisiting ones, this operation will replace those existing values. <br />
UPDATE oci.object_storage.private_endpoints
SET
accessTargets = '{{ accessTargets }}',
definedTags = '{{ definedTags }}',
freeformTags = '{{ freeformTags }}',
name = '{{ name }}',
namespace = '{{ namespace }}',
securityAttributes = '{{ securityAttributes }}'
WHERE
namespaceName = '{{ namespaceName }}' --required
AND peName = '{{ peName }}' --required
AND region = '{{ region }}' --required
AND opc-client-request-id = '{{ opc-client-request-id}}'
AND if-match = '{{ if-match}}';
DELETE examples​
- delete
Deletes a Private Endpoint if it exists in the given namespace.<br />
DELETE FROM oci.object_storage.private_endpoints
WHERE namespaceName = '{{ namespaceName }}' --required
AND peName = '{{ peName }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
AND opc-client-request-id = '{{ opc-client-request-id }}'
;