Class: KnoxCall::Resources::DynamicDb
- Inherits:
-
Object
- Object
- KnoxCall::Resources::DynamicDb
- Includes:
- UnwrapsEnvelope
- Defined in:
- lib/knoxcall/resources/dynamic_db.rb
Instance Method Summary collapse
- #create(**input) ⇒ Object
- #create_role(connection_name, **input) ⇒ Object
-
#delete(name) ⇒ Object
Returns =>
(NOT a boolean — server contract). -
#delete_role(connection_name, role) ⇒ Object
Returns =>
. - #get(name) ⇒ Object
-
#initialize(client) ⇒ DynamicDb
constructor
A new instance of DynamicDb.
-
#list ⇒ Object
Bare array — no pagination.
-
#list_leases(limit: nil, offset: nil, connection: nil) ⇒ Object
Returns => [...], "total", "limit", "offset" — this list really is limit/offset (inside data), the one list on the API that is neither page/per_page nor a bare array.
-
#list_roles(connection_name) ⇒ Object
Bare array — no pagination.
-
#mint(connection_name, role, ttl_seconds: nil) ⇒ Object
The response's "password" is shown exactly once — store it now.
-
#revoke_lease(lease_id) ⇒ Object
Returns =>
. -
#rotate_ssh_key(name, ssh_private_key:, ssh_passphrase: nil, ssh_host_fingerprint: nil) ⇒ Object
Returns "fingerprint_updated".
-
#update(name, **input) ⇒ Object
Returns =>
. -
#update_role(connection_name, role, **input) ⇒ Object
Returns =>
.
Constructor Details
#initialize(client) ⇒ DynamicDb
Returns a new instance of DynamicDb.
6 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 6 def initialize(client) = @client = client |
Instance Method Details
#create(**input) ⇒ Object
13 14 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 13 def create(**input) = unwrap(@client.request("POST", "/v1/dyn-db-credentials", body: input)) # Returns {"updated" => <name String>}. |
#create_role(connection_name, **input) ⇒ Object
30 31 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 30 def create_role(connection_name, **input) = unwrap(@client.request("POST", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles", body: input)) # Returns {"updated" => <role String>}. |
#delete(name) ⇒ Object
Returns =>
17 18 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 17 def delete(name) = unwrap(@client.request("DELETE", "/v1/dyn-db-credentials/#{encode(name)}")) # Returns {"rotated", "fingerprint_updated"}. |
#delete_role(connection_name, role) ⇒ Object
Returns =>
34 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 34 def delete_role(connection_name, role) = unwrap(@client.request("DELETE", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles/#{encode(role)}")) |
#get(name) ⇒ Object
12 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 12 def get(name) = unwrap(@client.request("GET", "/v1/dyn-db-credentials/#{encode(name)}")) |
#list ⇒ Object
Bare array — no pagination.
11 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 11 def list = unwrap(@client.request("GET", "/v1/dyn-db-credentials")) |
#list_leases(limit: nil, offset: nil, connection: nil) ⇒ Object
Returns => [...], "total", "limit", "offset" — this list really is limit/offset (inside data), the one list on the API that is neither page/per_page nor a bare array.
Only LIVE leases are returned — status "active", "renewing" or
"errored", i.e. every lease whose database user may still exist on your
server. Expired and revoked leases have had their user dropped and are
neither listed nor counted in "total". connection is an exact match on
the connection's name, scoped to the caller's Live/Test space.
"errored" is included deliberately: renewal was abandoned after five consecutive failures, so nothing is refreshing or expiring that lease. It is also the set counted by the 409 "has N active credential lease(s)" a connection or role delete returns, so anything blocking a delete is listed here and can be revoked.
60 61 62 63 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 60 def list_leases(limit: nil, offset: nil, connection: nil) q = { limit: limit, offset: offset, connection: connection }.compact unwrap(@client.request("GET", "/v1/dyn-db-credentials/leases", query: q.empty? ? nil : q)) end |
#list_roles(connection_name) ⇒ Object
Bare array — no pagination.
29 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 29 def list_roles(connection_name) = unwrap(@client.request("GET", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles")) |
#mint(connection_name, role, ttl_seconds: nil) ⇒ Object
The response's "password" is shown exactly once — store it now. Returns "password", "expires_at", "lease_id" (Integer), "connection_name", "role_name".
41 42 43 44 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 41 def mint(connection_name, role, ttl_seconds: nil) body = ttl_seconds ? { ttl_seconds: ttl_seconds } : {} unwrap(@client.request("POST", "/v1/dyn-db-credentials/#{encode(connection_name)}/creds/#{encode(role)}", body: body)) end |
#revoke_lease(lease_id) ⇒ Object
Returns =>
65 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 65 def revoke_lease(lease_id) = unwrap(@client.request("POST", "/v1/dyn-db-credentials/leases/#{encode(lease_id)}/revoke", body: {})) |
#rotate_ssh_key(name, ssh_private_key:, ssh_passphrase: nil, ssh_host_fingerprint: nil) ⇒ Object
Returns "fingerprint_updated".
19 20 21 22 23 24 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 19 def rotate_ssh_key(name, ssh_private_key:, ssh_passphrase: nil, ssh_host_fingerprint: nil) body = { ssh_private_key: ssh_private_key } body[:ssh_passphrase] = ssh_passphrase if ssh_passphrase body[:ssh_host_fingerprint] = ssh_host_fingerprint if ssh_host_fingerprint unwrap(@client.request("POST", "/v1/dyn-db-credentials/#{encode(name)}/rotate-ssh-key", body: body)) end |
#update(name, **input) ⇒ Object
Returns =>
15 16 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 15 def update(name, **input) = unwrap(@client.request("PATCH", "/v1/dyn-db-credentials/#{encode(name)}", body: input)) # Returns {"deleted" => <name String>} (NOT a boolean — server contract). |
#update_role(connection_name, role, **input) ⇒ Object
Returns =>
32 33 |
# File 'lib/knoxcall/resources/dynamic_db.rb', line 32 def update_role(connection_name, role, **input) = unwrap(@client.request("PATCH", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles/#{encode(role)}", body: input)) # Returns {"deleted" => <role String>}. |