Class: KnoxCall::Resources::DynamicDb

Inherits:
Object
  • Object
show all
Includes:
UnwrapsEnvelope
Defined in:
lib/knoxcall/resources/dynamic_db.rb

Instance Method Summary collapse

Constructor Details

#initialize(client) ⇒ DynamicDb

Returns a new instance of DynamicDb.



6
# File 'lib/knoxcall/resources/dynamic_db.rb', line 6

def initialize(client) = @client = client

Instance Method Details

#create(**input) ⇒ Object



13
14
# File 'lib/knoxcall/resources/dynamic_db.rb', line 13

def create(**input) = unwrap(@client.request("POST", "/v1/dyn-db-credentials", body: input))
# Returns {"updated" => <name String>}.

#create_role(connection_name, **input) ⇒ Object



30
31
# File 'lib/knoxcall/resources/dynamic_db.rb', line 30

def create_role(connection_name, **input) = unwrap(@client.request("POST", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles", body: input))
# Returns {"updated" => <role String>}.

#delete(name) ⇒ Object

Returns => (NOT a boolean — server contract).



17
18
# File 'lib/knoxcall/resources/dynamic_db.rb', line 17

def delete(name) = unwrap(@client.request("DELETE", "/v1/dyn-db-credentials/#{encode(name)}"))
# Returns {"rotated", "fingerprint_updated"}.

#delete_role(connection_name, role) ⇒ Object

Returns => .



34
# File 'lib/knoxcall/resources/dynamic_db.rb', line 34

def delete_role(connection_name, role) = unwrap(@client.request("DELETE", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles/#{encode(role)}"))

#get(name) ⇒ Object



12
# File 'lib/knoxcall/resources/dynamic_db.rb', line 12

def get(name) = unwrap(@client.request("GET", "/v1/dyn-db-credentials/#{encode(name)}"))

#list ⇒ Object

Bare array — no pagination.



11
# File 'lib/knoxcall/resources/dynamic_db.rb', line 11

def list = unwrap(@client.request("GET", "/v1/dyn-db-credentials"))

#list_leases(limit: nil, offset: nil, connection: nil) ⇒ Object

Returns => [...], "total", "limit", "offset" — this list really is limit/offset (inside data), the one list on the API that is neither page/per_page nor a bare array.

Only LIVE leases are returned — status "active", "renewing" or "errored", i.e. every lease whose database user may still exist on your server. Expired and revoked leases have had their user dropped and are neither listed nor counted in "total". connection is an exact match on the connection's name, scoped to the caller's Live/Test space.

"errored" is included deliberately: renewal was abandoned after five consecutive failures, so nothing is refreshing or expiring that lease. It is also the set counted by the 409 "has N active credential lease(s)" a connection or role delete returns, so anything blocking a delete is listed here and can be revoked.



60
61
62
63
# File 'lib/knoxcall/resources/dynamic_db.rb', line 60

def list_leases(limit: nil, offset: nil, connection: nil)
  q = { limit: limit, offset: offset, connection: connection }.compact
  unwrap(@client.request("GET", "/v1/dyn-db-credentials/leases", query: q.empty? ? nil : q))
end

#list_roles(connection_name) ⇒ Object

Bare array — no pagination.



29
# File 'lib/knoxcall/resources/dynamic_db.rb', line 29

def list_roles(connection_name) = unwrap(@client.request("GET", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles"))

#mint(connection_name, role, ttl_seconds: nil) ⇒ Object

The response's "password" is shown exactly once — store it now. Returns "password", "expires_at", "lease_id" (Integer), "connection_name", "role_name".



41
42
43
44
# File 'lib/knoxcall/resources/dynamic_db.rb', line 41

def mint(connection_name, role, ttl_seconds: nil)
  body = ttl_seconds ? { ttl_seconds: ttl_seconds } : {}
  unwrap(@client.request("POST", "/v1/dyn-db-credentials/#{encode(connection_name)}/creds/#{encode(role)}", body: body))
end

#revoke_lease(lease_id) ⇒ Object

Returns => .



65
# File 'lib/knoxcall/resources/dynamic_db.rb', line 65

def revoke_lease(lease_id) = unwrap(@client.request("POST", "/v1/dyn-db-credentials/leases/#{encode(lease_id)}/revoke", body: {}))

#rotate_ssh_key(name, ssh_private_key:, ssh_passphrase: nil, ssh_host_fingerprint: nil) ⇒ Object

Returns "fingerprint_updated".



19
20
21
22
23
24
# File 'lib/knoxcall/resources/dynamic_db.rb', line 19

def rotate_ssh_key(name, ssh_private_key:, ssh_passphrase: nil, ssh_host_fingerprint: nil)
  body = { ssh_private_key: ssh_private_key }
  body[:ssh_passphrase] = ssh_passphrase if ssh_passphrase
  body[:ssh_host_fingerprint] = ssh_host_fingerprint if ssh_host_fingerprint
  unwrap(@client.request("POST", "/v1/dyn-db-credentials/#{encode(name)}/rotate-ssh-key", body: body))
end

#update(name, **input) ⇒ Object

Returns => .



15
16
# File 'lib/knoxcall/resources/dynamic_db.rb', line 15

def update(name, **input) = unwrap(@client.request("PATCH", "/v1/dyn-db-credentials/#{encode(name)}", body: input))
# Returns {"deleted" => <name String>} (NOT a boolean — server contract).

#update_role(connection_name, role, **input) ⇒ Object

Returns => .



32
33
# File 'lib/knoxcall/resources/dynamic_db.rb', line 32

def update_role(connection_name, role, **input) = unwrap(@client.request("PATCH", "/v1/dyn-db-credentials/#{encode(connection_name)}/roles/#{encode(role)}", body: input))
# Returns {"deleted" => <role String>}.