Global InfraGlobal Infra Cloud

Assets

Asset reference for Cassandra.

Edit

This page documents the following assets:

  • Application Role — A role used to control access to a cluster. A role can hold permissions of its own (see grants), inherit the permissions of other roles (see role memberships), and optionally be used by an application to connect. Roles that can connect get a generated password stored in Vault.
  • Cluster — A managed database cluster that hosts your keyspaces, roles and grants. Clusters are provisioned for you and cannot be created, changed or deleted through this service.
  • Grant — A permission given to a role on a resource such as a keyspace or a table. A grant carries exactly one permission on one resource, so create one grant per permission you want to give.
  • Human Role — A named person’s access to a cluster. A human role holds read-only access to every keyspace of its tenant, and can be granted write access for a limited period through the elevate action. Its permissions are not configurable: they follow from the role being a human role. The password is generated and stored in Vault, and password_location tells you where to read it.
  • Keyspace — A keyspace: the top-level container that holds your tables inside a cluster. Deleting a keyspace permanently destroys every table and row it contains.
  • Role — A role used to control access to a cluster. A role can hold permissions of its own (see grants), inherit the permissions of other roles (see role memberships), and optionally be used by an application to connect. Roles that can connect get a generated password stored in Vault.
  • Role Grants Exclusive — Takes exclusive ownership of the permissions held directly by a role. Every permission the role holds directly and that is absent from grant_ids is removed. This does not give permissions: list here the permissions the role is allowed to keep, and create each of them as a grant. Deleting this releases the ownership, it does not remove any permission.
  • Role Membership — The inheritance of one role’s permissions by another role. The role named by role_id receives every permission held by the role named by member_of_role_id. Create one role membership per inherited role.

Application Role

A role used to control access to a cluster. A role can hold permissions of its own (see grants), inherit the permissions of other roles (see role memberships), and optionally be used by an application to connect. Roles that can connect get a generated password stored in Vault.

Schema

The following properties describe a Application Role:

PropertyTypeDescription
cluster_id
Required
stringThe identifier of the cluster this role belongs to. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01
effective_grants
Computed
list(object)Every permission this role currently holds, including permissions inherited from other roles. Read-only.
login
Default
booleanWhether an application can connect to the cluster with this role. When true, a password is generated and stored in Vault, and password_location tells you where to read it. When false (the default), the role is only a container for permissions that other roles inherit through a role membership.
name
RequiredForceNew
stringThe name of the role, unique within the cluster. Must start with a lowercase letter and may contain only lowercase letters, digits and underscores, up to 48 characters. Cannot be changed after creation.
Examples:keyspace_readerapp_user
password_last_rotated_at
Computed
stringWhen the password of this role was last set through this service. Absent for a role that cannot connect, since it has no password.
password_location
Computed
stringThe Vault UI URL where the password of this role is stored. Only returned when login is true.

Examples


Cluster

A managed database cluster that hosts your keyspaces, roles and grants. Clusters are provisioned for you and cannot be created, changed or deleted through this service.

Schema

The following properties describe a Cluster:

PropertyTypeDescription
endpoints
Computed
list(string)The host addresses your applications use to reach the cluster. Configure all of them in your client so it can fail over between nodes.
model
DefaultForceNew
stringThe service profile of the cluster: 'efficiency' is optimised for storage cost, 'performance' for throughput and latency.
name
RequiredForceNew
stringThe name of the cluster, unique within your tenant.
Examples:welcome_cluster01
port
Computed
integerThe network port your applications use to reach the cluster.
size_gb
Required
integerThe usable storage capacity of the cluster, in gigabytes. Replicas are not counted.
Examples:502000

Examples


Grant

A permission given to a role on a resource such as a keyspace or a table. A grant carries exactly one permission on one resource, so create one grant per permission you want to give.

Schema

The following properties describe a Grant:

PropertyTypeDescription
permission
RequiredForceNew
stringThe permission given on the target resource. SELECT allows reading data, MODIFY allows writing and deleting data. A grant carries exactly one permission: to give several permissions, create several grants. The full list also contains permissions that can only be reported for grants already present on the cluster: those cannot be requested here, but they remain visible and removable.
Examples:SELECTMODIFY
resource_kind
RequiredForceNew
stringThe kind of resource the permission applies to, for example a single keyspace or a single table. The full list also contains kinds that can only be reported for grants already present on the cluster: those cannot be requested here, but they remain visible and removable.
Examples:KEYSPACETABLE
resource_name
ForceNew
stringThe name of the resource the permission applies to. Required when resource_kind targets a named resource (KEYSPACE, TABLE, FUNCTION, ROLE, MBEAN, MBEANS) and when it targets everything inside a keyspace (ALL TABLES IN KEYSPACE, ALL FUNCTIONS IN KEYSPACE), in which case give the keyspace name. Must be left empty for the cluster-wide kinds ALL KEYSPACES, ALL FUNCTIONS, ALL ROLES and ALL MBEANS. Cannot be changed after creation.
Examples:my_keyspacemy_keyspace.my_table
role_id
Required
stringThe role that receives the permission. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01/app_user

Examples


Human Role

A named person’s access to a cluster. A human role holds read-only access to every keyspace of its tenant, and can be granted write access for a limited period through the elevate action. Its permissions are not configurable: they follow from the role being a human role. The password is generated and stored in Vault, and password_location tells you where to read it.

Schema

The following properties describe a Human Role:

PropertyTypeDescription
access_level
Default
stringWhether this person may request write access. read_only, the default, means read access at all times and no more. read_write means the same read access, plus the ability to obtain write access for a limited period through the elevate action.
Examples:read_only
cluster_id
Required
stringThe identifier of the cluster this role belongs to. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01
effective_grants
Computed
list(object)Every permission this role currently holds. Read-only.
enabled
Computed
booleanWhether the person can currently connect. Set to false by the disable action when the password has not been changed for three months, and back to true by rotate_password. Rotating the password is the only way to re-enable an account.
name
Computed
stringThe name of the role, derived from the person's platform nickname and unique within the cluster. Use it as the username when connecting.
Examples:h_flastname
password_last_rotated_at
Computed
stringWhen the password of this role was last set through this service. A password older than three months is disabled.
password_location
Computed
stringThe Vault UI URL where the password of this role is stored.
user_id
RequiredForceNew
stringThe identifier of the person this role belongs to, which is their email address. The person must be a real user of the platform; the role is named after them and cannot be created for an account that is not a person. Cannot be changed after creation.
Examples:firstname.lastname@worldline.com

Examples


Keyspace

A keyspace: the top-level container that holds your tables inside a cluster. Deleting a keyspace permanently destroys every table and row it contains.

Schema

The following properties describe a Keyspace:

PropertyTypeDescription
cluster_id
Required
stringThe identifier of the cluster that hosts this keyspace. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01
name
RequiredForceNew
stringThe name of the keyspace, unique within the cluster. Must start with a lowercase letter and may contain only lowercase letters, digits and underscores, up to 48 characters. Cannot be changed after creation.
Examples:my_keyspace

Examples


Role

A role used to control access to a cluster. A role can hold permissions of its own (see grants), inherit the permissions of other roles (see role memberships), and optionally be used by an application to connect. Roles that can connect get a generated password stored in Vault.

Schema

The following properties describe a Role:

PropertyTypeDescription
cluster_id
Required
stringThe identifier of the cluster this role belongs to. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01
effective_grants
Computed
list(object)Every permission this role currently holds, including permissions inherited from other roles. Read-only.
login
Default
booleanWhether an application can connect to the cluster with this role. When true, a password is generated and stored in Vault, and password_location tells you where to read it. When false (the default), the role is only a container for permissions that other roles inherit through a role membership.
name
RequiredForceNew
stringThe name of the role, unique within the cluster. Must start with a lowercase letter and may contain only lowercase letters, digits and underscores, up to 48 characters. Cannot be changed after creation.
Examples:keyspace_readerapp_user
password_location
Computed
stringThe Vault UI URL where the password of this role is stored. Only returned when login is true.

Examples


Role Grants Exclusive

Takes exclusive ownership of the permissions held directly by a role. Every permission the role holds directly and that is absent from grant_ids is removed. This does not give permissions: list here the permissions the role is allowed to keep, and create each of them as a grant. Deleting this releases the ownership, it does not remove any permission.

Schema

The following properties describe a Role Grants Exclusive:

PropertyTypeDescription
grant_ids
Required
list(string)The complete set of permissions the role is allowed to hold directly. Every permission held by the role and absent from this list is removed. Each entry is the identifier of a grant. Permissions inherited through a role membership are not concerned.
Examples:emea/sandbox/welcome/welcome_cluster01/app_user/select/all-tables-in-keyspace/my_keyspace
role_id
Required
stringThe role whose permissions are owned exclusively. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01/app_user

Examples


Role Membership

The inheritance of one role’s permissions by another role. The role named by role_id receives every permission held by the role named by member_of_role_id. Create one role membership per inherited role.

Schema

The following properties describe a Role Membership:

PropertyTypeDescription
member_of_role_id
Required
stringThe role whose permissions are inherited. Must name a role on the same cluster as role_id, and cannot be role_id itself or be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01/keyspace_reader
role_id
Required
stringThe role that receives the permissions of the role named by member_of_role_id. Cannot be changed after creation.
Examples:emea/sandbox/welcome/welcome_cluster01/app_user

Examples

On this page