Global InfraGlobal Infra Cloud

Assets

Asset reference for DbaaS Postgres.

Edit

This page documents the following assets:

  • Cluster — Represents a logical database cluster within the DBaaS infrastructure.
  • Database — Represents a database provisioned through the DBaaS platform.
  • Database Client Certificate — Client certificate for authenticating to the database.
  • Database Feature — Database features to be installed on the database
  • Database Hba Conf — The full user-managed pg_hba.conf block for a database. Exactly one per database (identity is the parent database itself). Each non-blank, non-comment line in content is stored as a row in the CMDB infra.hba table tagged with rule_id ‘user’, then pg_hba.conf is regenerated from the CMDB and reloaded on every cluster node. Lines render verbatim in the exact order supplied (no internal sort) — the caller controls ordering. Coexists with database_hba_entry, whose list/get exclude the ‘user’ rows.
  • Database Hba Entry — Database HBA (Host-Based Authentication) entry that defines the authentication rules for connecting to a database. Each entry specifies the connection type, database, user, address, and authentication method.
  • Database Role — Role that can be assigned to database users. This is a logical role used for organizing permissions and does not necessarily correspond to a specific database role in the underlying database system.
  • Release — Represents an available PostgreSQL release from the CMDB.
  • Snapshot — Represents an available snapshot for a database provisioned through the DBaaS platform.

Cluster

Represents a logical database cluster within the DBaaS infrastructure.

Schema

The following properties describe a Cluster:

PropertyTypeDescription
arch
Required
integerCluster architecture (e.g., 64 for 64-bit).
boarding
stringOnboarding state of the cluster.
cluster
Required
stringName or identifier of the cluster.
nodes
Required
list(object)List of nodes in the cluster.
sgbd
Required
stringDatabase engine used by the cluster.
sync_state
stringSynchronization state of the cluster.
vip
stringVirtual IP address associated with the cluster.

Examples


Database

Represents a database provisioned through the DBaaS platform.

Schema

The following properties describe a Database:

PropertyTypeDescription
architecture
Computed
stringThe database architecture (e.g., v1, v2).
cluster
Computed
stringThe database cluster hosting the database. Assigned by the system.
communities
Default
list(string)List of tenant names (communities) that have access to this database.
Examples:["core","axis","ahub"]
connection_usage_percent
Computed
numberThe percentage of connection usage relative to its total capacity.
db_group
Default
booleanWhen true, creates nominative group roles specific to this database rather than tenant-scoped ones.
endpoint
Computed
stringThe endpoint of the database.
id
Computed
integerThe unique identifier of the database in the CMDB. Assigned by the system upon database creation.
instance
Computed
stringThe specific instance ID (db_iid) where the database runs.
last_backup_date
Computed
stringThe date of the last backup (snapshot) for the cluster hosting this database.
maintenance_windows
Default
list(object)Scheduled maintenance windows for the database.
Examples:[{"hour_end":"04:00","hour_start":"02:00"}][{"hour_end":"00:00","hour_start":"22:00"}]
major_release_version
RequiredDefault
integerThe PostgreSQL major version. Required; must be one of the available releases. On update it can only be increased, which triggers a major-version upgrade.
master_node_location
Computed
stringThe datacenter where the master node of the database is located.
max_connections
Default
integerThe maximum number of connections allowed for this database.
Examples:100500
minor_release_version
Computed
stringThe PostgreSQL minor version (e.g., 17.4). Must be in the list of available releases.
name
RequiredForceNew
stringThe name of the database. Must follow the pattern {tenant}_<name>.
Examples:axis_mydbcore_users
size
Default
integerThe maximum size of the database in gigabytes. Sizes above the service-configured limit require an admin approval gate.
Examples:1050
status
Computed
stringCurrent status of the database instance.
storage_usage_percent
Computed
numberThe percentage of storage usage relative to its total capacity.

Examples


Database Client Certificate

Client certificate for authenticating to the database.

Schema

The following properties describe a Database Client Certificate:

PropertyTypeDescription
ca_chain
Computed
stringThe CA chain content in PEM format, if applicable.
Examples:-----BEGIN CERTIFICATE----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ... -----END CERTIFICATE-----
certificate
Computed
stringThe client certificate content in PEM format.
Examples:-----BEGIN CERTIFICATE----- MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ... -----END CERTIFICATE-----
certificate_location
Computed
stringThe location within the Vault secret where the client certificate can be found.
csr
RequiredForceNew
stringThe Certificate Signing Request (CSR) content in PEM format used to generate the client certificate. It must be a RSA key of minimum 4096 bits.
Examples:-----BEGIN CERTIFICATE REQUEST----- MIIBVzCBuAIBADA7MQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExETAPBgNVBAcTCFNhbiBSYW1vbjEPMA0GA1UEChMGRXhhbXBsZTENMAsGA1UECxMEVGVzdDEWMBQGA1UEAxMNY2xpZW50LmV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ... -----END CERTIFICATE REQUEST-----
database_id
Required
stringAsset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time.
Examples:sb/eu/2/axis_mydbsb/eu/2/core_mydb
expiration_time
Computed
stringThe expiration time of the client certificate.
Examples:2024-12-31T23:59:59Z
role_id
Required
stringAsset ID of the parent database role. Used by the platform to register a parent relation and validate the role exists at creation time.
Examples:sb/eu/axis_mydb/axis_mydb_writersb/eu/core_mydb/core_mydb_reader
serial_number
Computed
stringThe serial number of the client certificate as reported by Vault PKI (colon-separated hex, e.g. "1a:2b:3c:…"). Used to revoke the certificate.
Examples:1a:2b:3c:4d:5e:6f
ttl
RequiredForceNew
stringTime to live for the client certificate. Accepts year shorthand (e.g. "1y"), day shorthand (e.g. "90d"), or Go duration format (e.g. "26280h"). Min: 1 month (720h). Max: 3 years.
Examples:3y90d26280h

Examples


Database Feature

Database features to be installed on the database

Schema

The following properties describe a Database Feature:

PropertyTypeDescription
database_id
Required
stringAsset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time.
Examples:sb/eu/2/axis_mydb
name
RequiredForceNew
stringDatabase feature name.
Examples:pg_repackpg_stat_statements
parameters
Default
objectFeature-specific configuration. The set of keys and their types is determined by the feature named in `name`; refer to each feature's documentation for the supported parameters.

Examples


Database Hba Conf

The full user-managed pg_hba.conf block for a database. Exactly one per database (identity is the parent database itself). Each non-blank, non-comment line in content is stored as a row in the CMDB infra.hba table tagged with rule_id ‘user’, then pg_hba.conf is regenerated from the CMDB and reloaded on every cluster node. Lines render verbatim in the exact order supplied (no internal sort) — the caller controls ordering. Coexists with database_hba_entry, whose list/get exclude the ‘user’ rows.

Schema

The following properties describe a Database Hba Conf:

PropertyTypeDescription
content
RequiredDefault
stringFull user-managed pg_hba block. Each non-blank, non-comment line must be a valid pg_hba entry (host/hostssl only; the database column must equal the parent database name). Lines are applied in the given order. include/include_if_exists/include_dir directives are rejected.
database_id
Required
stringAsset ID of the parent database (platform/region/architecture/dbName). The database is the sole identity of the conf.
Examples:sb/eu/2/axis_mydb

Examples


Database Hba Entry

Database HBA (Host-Based Authentication) entry that defines the authentication rules for connecting to a database. Each entry specifies the connection type, database, user, address, and authentication method.

Schema

The following properties describe a Database Hba Entry:

PropertyTypeDescription
auth_method
RequiredDefault
stringThe authentication method to use for this HBA entry (e.g., cert, scram-sha-256, pam). When set to cert, connection_type must be hostssl. pam is only allowed when all users are group roles (prefixed with '+').
Examples:scram-sha-256cert
auth_options
stringThe authentication option based on provided method for this HBA entry.
connection_type
Default
stringThe type of connection this HBA entry applies to (e.g., host, hostssl). Must be hostssl when auth_method is cert.
Examples:hosthostssl
database_id
Required
stringAsset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time.
Examples:sb/eu/2/axis_mydb
rule_id
Computed
stringDeprecated in favor of rule_name; echoes the rule_name value. Kept for backward compatibility during the transition.
rule_name
RequiredForceNew
stringImmutable caller-supplied name identifying this HBA rule. Forms the last segment of the asset ID and is unique per database; letters, digits, underscores, hyphens, and dots only.
Examples:allow_app_readers
source_addresses
RequiredDefault
list(string)List of client IP addresses or CIDR ranges this HBA entry applies to.
Examples:["10.133.84.2/32","10.135.84.2/32"]
users
Required
stringComma-separated list of database users this HBA entry applies to.
Examples:axis_myuser,core_readertenant_admin

Examples


Database Role

Role that can be assigned to database users. This is a logical role used for organizing permissions and does not necessarily correspond to a specific database role in the underlying database system.

Schema

The following properties describe a Database Role:

PropertyTypeDescription
database_id
Required
stringAsset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time.
Examples:sb/eu/2/axis_mydb
extra_roles_member
Default
list(string)Extra membership for the managed role.
Examples:["pg_monitor"]["pg_read_all_stats"]
max_connections
Default
integerThe maximum number of connections allowed for this role.
Examples:50100
name
RequiredForceNew
stringDatabase role name.
Examples:axis_mydb_writercore_mydb_reader
password
Default
stringCustom role password.
password_location
Computed
stringThe Vault UI URL where the role password is stored.
role_member
RequiredDefault
stringRole standard membership. Linked to the IDM permission mapping in dbaas group.
Examples:rorw
role_parameters
Default
objectRole-level parameters.

Examples


Release

Represents an available PostgreSQL release from the CMDB.

Schema

The following properties describe a Release:

PropertyTypeDescription
name
Required
stringThe database engine name (e.g., PostgreSQL).
release_version
Required
stringThe release version (e.g., 17.9).
version
Required
stringThe PostgreSQL major version (e.g., 17).

Examples


Snapshot

Represents an available snapshot for a database provisioned through the DBaaS platform.

Schema

The following properties describe a Snapshot:

PropertyTypeDescription
cluster
Default
stringThe name of the cluster the snapshot belongs to.
database
stringThe name of the database the snapshot belongs to.
Examples:axis_mydbcore_users
datetime
Computed
stringThe timestamp when the snapshot was created.
name
Computed
stringThe name of the snapshot
snapshot_id
Computed
stringThe unique identifier for the snapshot.

Examples

On this page