Skip to content

Replace Cloud Credentials.

PUT
/api/config/namespaces/{metadata.namespace}/cloud_credentialss/{metadata.name}
curl --request PUT \
--url https://example-corp.console.ves.volterra.io/api/v1/api/production/us-east-1/namespaces/default/api/config/namespaces/example/cloud_credentialss/example \
--header 'Authorization: <Authorization>' \
--header 'Content-Type: application/json' \
--data '{ "metadata": { "annotations": {}, "description": "example", "disable": true, "labels": {}, "name": "example", "namespace": "example" }, "spec": { "aws_assume_role": { "custom_external_id": "example", "duration_seconds": 1, "external_id_is_optional": {}, "external_id_is_tenant_id": {}, "role_arn": "example", "session_name": "example", "session_tags": {} }, "aws_secret_key": { "access_key": "example", "secret_key": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } }, "azure_client_secret": { "client_id": "example", "client_secret": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "subscription_id": "example", "tenant_id": "example" }, "azure_pfx_certificate": { "certificate_url": "example", "client_id": "example", "password": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } }, "subscription_id": "example", "tenant_id": "example" }, "gcp_cred_file": { "credential_file": { "blindfold_secret_info": { "decryption_provider": "example", "location": "example", "store_provider": "example" }, "clear_secret_info": { "provider": "example", "url": "https://example.com" } } } } }'

API to replace cloud_credentials object.

Examples of this operation.

metadata.namespace
required
string

Namespace This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

metadata.name
required
string

Name The configuration object to be replaced will be looked up by name.

Media typeapplication/json
ReplaceRequest is used to replace contents of a cloud_credentials

This is the input message of the ‘Replace’ RPC.

object
metadata
object
annotations
annotations

Annotations is an unstructured key value map stored with a resource that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects.

object
description
description

Human readable description for the object.

string
>= 21 characters <= 1200 characters
disable
disable

A value of true will administratively disable the object.

boolean format: boolean
labels
labels

Map of string keys and values that can be used to organize and categorize (scope and select) objects as chosen by the user. Values specified here will be used by selector expression.

object
name
name

This is the name of configuration object. It has to be unique within the namespace. It can only be specified during create API and cannot be changed during replace API. The value of name has to follow DNS-1035 format. Required: YES.

string
>= 6 characters <= 1024 characters
namespace
namespace

This defines the workspace within which each the configuration object is to be created. Must be a DNS_LABEL format. For a namespace object itself, namespace value will be ""

string
>= 6 characters <= 1024 characters
spec
object
aws_assume_role
object
custom_external_id
External ID is Custom ID

Exclusive with [external_id_is_optional external_id_is_tenant_id] External ID is Custom ID.

string
>= 2 characters <= 64 characters
duration_seconds
Role Session Duration Seconds

The duration, in seconds of the role session.

integer format: int64
external_id_is_optional
object
external_id_is_tenant_id
object
role_arn
IAM Role ARN

IAM Role ARN to assume the role Required: YES.

string
>= 20 characters <= 2048 characters
session_name
Role Session Name

Use the role session name to uniquely identify a session, which will be used for deploy, monitor from F5XC console Required: YES.

string
>= 2 characters <= 64 characters
session_tags
Role Session Tags

Session tags are key-value pair attributes that you pass when you assume an IAM role.

object
aws_secret_key
object
access_key
AWS Access Key ID

Access key ID for your AWS account Required: YES.

string
<= 128 characters
secret_key
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
azure_client_secret
object
client_id
Azure Client ID

Client ID for your Azure service principal Required: YES.

string
<= 64 characters
client_secret
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
subscription_id
Azure Subscription ID

Subscription ID for your Azure service principal Required: YES.

string
<= 64 characters
tenant_id
Azure Tenant ID

Tenant ID for your Azure service principal Required: YES.

string
<= 64 characters
azure_pfx_certificate
object
certificate_url
Azure client certificate

URL for Client Certificate in ‘.pfx’ or ‘.p12’ whose certificate is linked to service principal object Certificate URL can contain client certificate in string:/// format. Here is base64 of ‘.pfx’ or ‘.p12’ binary file Required: YES.

string
<= 8192 characters
client_id
Azure Client ID

Client ID for your Azure service principal Required: YES.

string
<= 64 characters
password
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
subscription_id
Azure Subscription ID

Subscription ID for your Azure service principal Required: YES.

string
<= 64 characters
tenant_id
Azure Tenant ID

Tenant ID for your Azure service principal Required: YES.

string
<= 64 characters
gcp_cred_file
object
credential_file
object
blindfold_secret_info
object
decryption_provider
Decryption Provider

Name of the Secret Management Access object that contains information about the backend Secret Management service.

string
<= 1024 characters
location
Location

Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location Required: YES.

string
>= 4 characters <= 1024 characters
store_provider
Store Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
<= 1024 characters
clear_secret_info
object
provider
Provider

Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///.

string
>= 3 characters <= 1024 characters
url
URL

URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding. Required: YES.

string format: uri
<= 131072 characters
Examplegenerated
{
"metadata": {
"annotations": {},
"description": "example",
"disable": true,
"labels": {},
"name": "example",
"namespace": "example"
},
"spec": {
"aws_assume_role": {
"custom_external_id": "example",
"duration_seconds": 1,
"external_id_is_optional": {},
"external_id_is_tenant_id": {},
"role_arn": "example",
"session_name": "example",
"session_tags": {}
},
"aws_secret_key": {
"access_key": "example",
"secret_key": {
"blindfold_secret_info": {
"decryption_provider": "example",
"location": "example",
"store_provider": "example"
},
"clear_secret_info": {
"provider": "example",
"url": "https://example.com"
}
}
},
"azure_client_secret": {
"client_id": "example",
"client_secret": {
"blindfold_secret_info": {
"decryption_provider": "example",
"location": "example",
"store_provider": "example"
},
"clear_secret_info": {
"provider": "example",
"url": "https://example.com"
}
},
"subscription_id": "example",
"tenant_id": "example"
},
"azure_pfx_certificate": {
"certificate_url": "example",
"client_id": "example",
"password": {
"blindfold_secret_info": {
"decryption_provider": "example",
"location": "example",
"store_provider": "example"
},
"clear_secret_info": {
"provider": "example",
"url": "https://example.com"
}
},
"subscription_id": "example",
"tenant_id": "example"
},
"gcp_cred_file": {
"credential_file": {
"blindfold_secret_info": {
"decryption_provider": "example",
"location": "example",
"store_provider": "example"
},
"clear_secret_info": {
"provider": "example",
"url": "https://example.com"
}
}
}
}
}

A successful response.

Media typeapplication/json
object
Examplegenerated
{}

Returned when operation is not authorized.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when there is no permission to access resource.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when resource is not found.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation on resource is conflicting with current value.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when operation has been rejected as it is happening too frequently.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server encountered an error in processing API.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when service is unavailable temporarily.

Media typeapplication/json
string format: string
Examplegenerated
example

Returned when server timed out processing request.

Media typeapplication/json
string format: string
Examplegenerated
example