Assets
Asset reference for DbaaS Postgres.
This page documents the following assets:
- Cluster — Represents a logical database cluster within the DBaaS infrastructure.
- Database — Represents a database provisioned through the DBaaS platform.
- Database Client Certificate — Client certificate for authenticating to the database.
- Database Feature — Database features to be installed on the database
- Database Hba Conf — The full user-managed pg_hba.conf block for a database. Exactly one per database (identity is the parent database itself). Each non-blank, non-comment line in content is stored as a row in the CMDB infra.hba table tagged with rule_id ‘user’, then pg_hba.conf is regenerated from the CMDB and reloaded on every cluster node. Lines render verbatim in the exact order supplied (no internal sort) — the caller controls ordering. Coexists with database_hba_entry, whose list/get exclude the ‘user’ rows.
- Database Hba Entry — Database HBA (Host-Based Authentication) entry that defines the authentication rules for connecting to a database. Each entry specifies the connection type, database, user, address, and authentication method.
- Database Role — Role that can be assigned to database users. This is a logical role used for organizing permissions and does not necessarily correspond to a specific database role in the underlying database system.
- Release — Represents an available PostgreSQL release from the CMDB.
- Snapshot — Represents an available snapshot for a database provisioned through the DBaaS platform.
Cluster
Represents a logical database cluster within the DBaaS infrastructure.
Schema
The following properties describe a Cluster:
| Property | Type | Description |
|---|---|---|
arch Required | integer | Cluster architecture (e.g., 64 for 64-bit). |
boarding | string | Onboarding state of the cluster. |
cluster Required | string | Name or identifier of the cluster. |
nodes Required | list(object) | List of nodes in the cluster. |
sgbd Required | string | Database engine used by the cluster. |
sync_state | string | Synchronization state of the cluster. |
vip | string | Virtual IP address associated with the cluster. |
Examples
Database
Represents a database provisioned through the DBaaS platform.
Schema
The following properties describe a Database:
| Property | Type | Description |
|---|---|---|
architecture Computed | string | The database architecture (e.g., v1, v2). |
cluster Computed | string | The database cluster hosting the database. Assigned by the system. |
communities Default | list(string) | List of tenant names (communities) that have access to this database. Examples: ["core","axis","ahub"] |
connection_usage_percent Computed | number | The percentage of connection usage relative to its total capacity. |
db_group Default | boolean | When true, creates nominative group roles specific to this database rather than tenant-scoped ones. |
endpoint Computed | string | The endpoint of the database. |
id Computed | integer | The unique identifier of the database in the CMDB. Assigned by the system upon database creation. |
instance Computed | string | The specific instance ID (db_iid) where the database runs. |
last_backup_date Computed | string | The date of the last backup (snapshot) for the cluster hosting this database. |
maintenance_windows Default | list(object) | Scheduled maintenance windows for the database. Examples: [{"hour_end":"04:00","hour_start":"02:00"}][{"hour_end":"00:00","hour_start":"22:00"}] |
major_release_version RequiredDefault | integer | The PostgreSQL major version. Required; must be one of the available releases. On update it can only be increased, which triggers a major-version upgrade. |
master_node_location Computed | string | The datacenter where the master node of the database is located. |
max_connections Default | integer | The maximum number of connections allowed for this database. Examples: 100500 |
minor_release_version Computed | string | The PostgreSQL minor version (e.g., 17.4). Must be in the list of available releases. |
name RequiredForceNew | string | The name of the database. Must follow the pattern {tenant}_<name>. Examples: axis_mydbcore_users |
size Default | integer | The maximum size of the database in gigabytes. Sizes above the service-configured limit require an admin approval gate. Examples: 1050 |
status Computed | string | Current status of the database instance. |
storage_usage_percent Computed | number | The percentage of storage usage relative to its total capacity. |
Examples
Database Client Certificate
Client certificate for authenticating to the database.
Schema
The following properties describe a Database Client Certificate:
| Property | Type | Description |
|---|---|---|
ca_chain Computed | string | The CA chain content in PEM format, if applicable. Examples: -----BEGIN CERTIFICATE-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ...
-----END CERTIFICATE----- |
certificate Computed | string | The client certificate content in PEM format. Examples: -----BEGIN CERTIFICATE-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ...
-----END CERTIFICATE----- |
certificate_location Computed | string | The location within the Vault secret where the client certificate can be found. |
csr RequiredForceNew | string | The Certificate Signing Request (CSR) content in PEM format used to generate the client certificate. It must be a RSA key of minimum 4096 bits. Examples: -----BEGIN CERTIFICATE REQUEST-----
MIIBVzCBuAIBADA7MQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExETAPBgNVBAcTCFNhbiBSYW1vbjEPMA0GA1UEChMGRXhhbXBsZTENMAsGA1UECxMEVGVzdDEWMBQGA1UEAxMNY2xpZW50LmV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ...
-----END CERTIFICATE REQUEST----- |
database_id Required | string | Asset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time. Examples: sb/eu/2/axis_mydbsb/eu/2/core_mydb |
expiration_time Computed | string | The expiration time of the client certificate. Examples: 2024-12-31T23:59:59Z |
role_id Required | string | Asset ID of the parent database role. Used by the platform to register a parent relation and validate the role exists at creation time. Examples: sb/eu/axis_mydb/axis_mydb_writersb/eu/core_mydb/core_mydb_reader |
serial_number Computed | string | The serial number of the client certificate as reported by Vault PKI (colon-separated hex, e.g. "1a:2b:3c:…"). Used to revoke the certificate. Examples: 1a:2b:3c:4d:5e:6f |
ttl RequiredForceNew | string | Time to live for the client certificate. Accepts year shorthand (e.g. "1y"), day shorthand (e.g. "90d"), or Go duration format (e.g. "26280h"). Min: 1 month (720h). Max: 3 years. Examples: 3y90d26280h |
Examples
Database Feature
Database features to be installed on the database
Schema
The following properties describe a Database Feature:
| Property | Type | Description |
|---|---|---|
database_id Required | string | Asset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time. Examples: sb/eu/2/axis_mydb |
name RequiredForceNew | string | Database feature name. Examples: pg_repackpg_stat_statements |
parameters Default | object | Feature-specific configuration. The set of keys and their types is determined by the feature named in `name`; refer to each feature's documentation for the supported parameters. |
Examples
Database Hba Conf
The full user-managed pg_hba.conf block for a database. Exactly one per database (identity is the parent database itself). Each non-blank, non-comment line in content is stored as a row in the CMDB infra.hba table tagged with rule_id ‘user’, then pg_hba.conf is regenerated from the CMDB and reloaded on every cluster node. Lines render verbatim in the exact order supplied (no internal sort) — the caller controls ordering. Coexists with database_hba_entry, whose list/get exclude the ‘user’ rows.
Schema
The following properties describe a Database Hba Conf:
| Property | Type | Description |
|---|---|---|
content RequiredDefault | string | Full user-managed pg_hba block. Each non-blank, non-comment line must be a valid pg_hba entry (host/hostssl only; the database column must equal the parent database name). Lines are applied in the given order. include/include_if_exists/include_dir directives are rejected. |
database_id Required | string | Asset ID of the parent database (platform/region/architecture/dbName). The database is the sole identity of the conf. Examples: sb/eu/2/axis_mydb |
Examples
Database Hba Entry
Database HBA (Host-Based Authentication) entry that defines the authentication rules for connecting to a database. Each entry specifies the connection type, database, user, address, and authentication method.
Schema
The following properties describe a Database Hba Entry:
| Property | Type | Description |
|---|---|---|
auth_method RequiredDefault | string | The authentication method to use for this HBA entry (e.g., cert, scram-sha-256, pam). When set to cert, connection_type must be hostssl. pam is only allowed when all users are group roles (prefixed with '+'). Examples: scram-sha-256cert |
auth_options | string | The authentication option based on provided method for this HBA entry. |
connection_type Default | string | The type of connection this HBA entry applies to (e.g., host, hostssl). Must be hostssl when auth_method is cert. Examples: hosthostssl |
database_id Required | string | Asset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time. Examples: sb/eu/2/axis_mydb |
rule_id Computed | string | Deprecated in favor of rule_name; echoes the rule_name value. Kept for backward compatibility during the transition. |
rule_name RequiredForceNew | string | Immutable caller-supplied name identifying this HBA rule. Forms the last segment of the asset ID and is unique per database; letters, digits, underscores, hyphens, and dots only. Examples: allow_app_readers |
source_addresses RequiredDefault | list(string) | List of client IP addresses or CIDR ranges this HBA entry applies to. Examples: ["10.133.84.2/32","10.135.84.2/32"] |
users Required | string | Comma-separated list of database users this HBA entry applies to. Examples: axis_myuser,core_readertenant_admin |
Examples
Database Role
Role that can be assigned to database users. This is a logical role used for organizing permissions and does not necessarily correspond to a specific database role in the underlying database system.
Schema
The following properties describe a Database Role:
| Property | Type | Description |
|---|---|---|
database_id Required | string | Asset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time. Examples: sb/eu/2/axis_mydb |
extra_roles_member Default | list(string) | Extra membership for the managed role. Examples: ["pg_monitor"]["pg_read_all_stats"] |
max_connections Default | integer | The maximum number of connections allowed for this role. Examples: 50100 |
name RequiredForceNew | string | Database role name. Examples: axis_mydb_writercore_mydb_reader |
password Default | string | Custom role password. |
password_location Computed | string | The Vault UI URL where the role password is stored. |
role_member RequiredDefault | string | Role standard membership. Linked to the IDM permission mapping in dbaas group. Examples: rorw |
role_parameters Default | object | Role-level parameters. |
Examples
Release
Represents an available PostgreSQL release from the CMDB.
Schema
The following properties describe a Release:
| Property | Type | Description |
|---|---|---|
name Required | string | The database engine name (e.g., PostgreSQL). |
release_version Required | string | The release version (e.g., 17.9). |
version Required | string | The PostgreSQL major version (e.g., 17). |
Examples
Snapshot
Represents an available snapshot for a database provisioned through the DBaaS platform.
Schema
The following properties describe a Snapshot:
| Property | Type | Description |
|---|---|---|
cluster Default | string | The name of the cluster the snapshot belongs to. |
database | string | The name of the database the snapshot belongs to. Examples: axis_mydbcore_users |
datetime Computed | string | The timestamp when the snapshot was created. |
name Computed | string | The name of the snapshot |
snapshot_id Computed | string | The unique identifier for the snapshot. |