Exoscale template API
Templates contain the OS and the initial setup of a Compute instance.
Templates contain the OS and the initial setup of a Compute instance.
openapi: 3.0.0
info:
version: 2.0.0
termsOfService: https://exoscale.com/terms
contact:
email: support@exoscale.com
name: Exoscale Support
url: https://portal.exoscale.com/tickets
title: Exoscale ai-api-key template API
description: Infrastructure automation API, allowing programmatic access to all Exoscale products and services.
servers:
- url: https://api-{zone}.exoscale.com/v2
variables:
zone:
default: ch-gva-2
enum:
- ch-gva-2
- ch-dk-2
- de-fra-1
- de-muc-1
- at-vie-1
- at-vie-2
- bg-sof-1
- hr-zag-1
tags:
- description: "Templates contain the OS and the initial setup of a\n Compute instance."
parent: compute
externalDocs:
description: Read more
url: https://www.exoscale.com/templates/
name: template
x-display-name: Template
x-weight: 140
x-icon: exo-template
paths:
/template/{id}:
delete:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
$ref: '#/components/schemas/operation'
description: ''
parameters:
- in: path
required: true
name: id
schema:
type: string
format: uuid
summary: Delete a Template
operationId: delete-template
post:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
$ref: '#/components/schemas/operation'
description: ''
parameters:
- in: path
required: true
name: id
schema:
type: string
format: uuid
summary: Copy a Template from a zone to another
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
target-zone:
$ref: '#/components/schemas/zone'
description: Target Zone name
required:
- target-zone
operationId: copy-template
put:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
$ref: '#/components/schemas/operation'
description: ''
parameters:
- in: path
required: true
name: id
schema:
type: string
format: uuid
summary: Update template attributes
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
maxLength: 255
minLength: 1
description: Template name
description:
type: string
maxLength: 255
description: Template Description
operationId: update-template
get:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
$ref: '#/components/schemas/template'
description: ''
parameters:
- in: path
required: true
name: id
schema:
type: string
format: uuid
summary: Retrieve Template details
operationId: get-template
/snapshot/{id}:promote:
post:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
$ref: '#/components/schemas/operation'
description: ''
parameters:
- in: path
required: true
name: id
schema:
type: string
format: uuid
summary: Promote a Snapshot to a Template
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
maxLength: 255
minLength: 1
description: Template name
description:
type: string
maxLength: 4096
description: Template description
default-user:
type: string
maxLength: 255
minLength: 1
description: Template default user
ssh-key-enabled:
type: boolean
description: Enable SSH key-based login in the template
password-enabled:
type: boolean
description: Enable password-based login in the template
required:
- name
operationId: promote-snapshot-to-template
/template:
get:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
type: object
properties:
templates:
type: array
items:
$ref: '#/components/schemas/template'
description: ''
parameters:
- in: query
required: false
name: visibility
schema:
type: string
enum:
- private
- public
- in: query
required: false
name: family
schema:
type: string
summary: List Templates
operationId: list-templates
post:
tags:
- template
responses:
'200':
description: '200'
content:
application/json:
schema:
$ref: '#/components/schemas/operation'
description: ''
parameters: []
summary: Register a Template
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
application-consistent-snapshot-enabled:
type: boolean
description: Template with support for Application Consistent Snapshots
maintainer:
type: string
maxLength: 255
minLength: 1
description: Template maintainer
description:
type: string
maxLength: 255
description: Template description
ssh-key-enabled:
type: boolean
description: Enable SSH key-based login
name:
type: string
maxLength: 255
minLength: 1
description: Template name
default-user:
type: string
maxLength: 255
minLength: 1
description: Template default user
size:
type: integer
format: int64
minimum: 0
exclusiveMinimum: true
description: Template size
password-enabled:
type: boolean
description: Enable password-based login
build:
type: string
maxLength: 255
minLength: 1
description: Template build
checksum:
type: string
minLength: 1
description: Template MD5 checksum
boot-mode:
type: string
enum:
- legacy
- uefi
description: 'Boot mode (default: legacy)'
url:
type: string
minLength: 1
description: Template source URL
version:
type: string
maxLength: 255
minLength: 1
description: Template version
required:
- name
- url
- checksum
- ssh-key-enabled
- password-enabled
operationId: register-template
components:
schemas:
zone-name:
type: string
enum:
- ch-dk-2
- de-muc-1
- ch-gva-2
- at-vie-1
- de-fra-1
- bg-sof-1
- at-vie-2
- hr-zag-1
template:
type: object
properties:
application-consistent-snapshot-enabled:
type: boolean
description: Template with Qemu Guest Agent installed for application consistent snapshot
maintainer:
type: string
readOnly: true
description: Template maintainer
description:
type: string
maxLength: 255
description: Template description
ssh-key-enabled:
type: boolean
description: Enable SSH key-based login
family:
type: string
readOnly: true
description: Template family
name:
type: string
maxLength: 255
minLength: 1
description: Template name
default-user:
type: string
maxLength: 255
minLength: 1
description: Template default user
size:
type: integer
format: int64
minimum: 0
exclusiveMinimum: true
description: Template size
password-enabled:
type: boolean
description: Enable password-based login
build:
type: string
readOnly: true
description: Template build
checksum:
type: string
description: Template MD5 checksum
boot-mode:
type: string
enum:
- legacy
- uefi
description: 'Boot mode (default: legacy)'
id:
type: string
format: uuid
readOnly: true
description: Template ID
zones:
type: array
items:
$ref: '#/components/schemas/zone-name'
description: Zones availability
url:
type: string
description: Template source URL
version:
type: string
readOnly: true
description: Template version
created-at:
type: string
format: date-time
readOnly: true
description: Template creation date
visibility:
type: string
enum:
- private
- public
readOnly: true
description: Template visibility
description: Instance template
operation:
type: object
properties:
id:
type: string
format: uuid
readOnly: true
description: Operation ID
reason:
type: string
enum:
- incorrect
- unknown
- unavailable
- forbidden
- busy
- fault
- partial
- not-found
- interrupted
- unsupported
- conflict
readOnly: true
description: Operation failure reason
reference:
type: object
properties:
id:
type: string
format: uuid
description: Reference ID
link:
type: string
readOnly: true
description: Link to the referenced resource
command:
type: string
description: Command name
description: Related resource reference
readOnly: true
message:
type: string
readOnly: true
description: Operation message
state:
type: string
enum:
- failure
- pending
- success
- timeout
readOnly: true
description: Operation status
description: Operation
zone:
type: object
properties:
name:
$ref: '#/components/schemas/zone-name'
readOnly: true
x-go-findable: '1'
description: Zone short name
api-endpoint:
type: string
readOnly: true
x-go-type: Endpoint
x-go-findable: '2'
description: Zone API endpoint
sos-endpoint:
type: string
readOnly: true
x-go-type: Endpoint
description: Zone SOS endpoint
description: Zone
x-topics:
- title: API Request Signature
content: '
In order to authenticate legitimate users, the Exoscale API requires incoming requests to be signed using valid Exoscale API account credentials with the following mechanism.
## Signature Mechanism
The *message* (i.e. content) to sign contains several segments concatenated using a line return character (`\n`).
All segments must be included and in the described order. For cases where a segment doesn''t fit the context of the request (e.g. no request body) **an empty line must be used instead**.
* Request method and request URL (path only), separated by a space character
* Request body
* Request URL parameters (Query String) values, concatenated without separator. The matching parameter names have to be specified in the resulting signature header `signed-query-args=` pragma, separated by semicolons (e.g. `p1;p2;pN`).
* Request header values, concatenated without separator (none at the moment, leave empty)
* Request expiration date in UNIX timestamp format
Example *message* to sign for `GET /v2/resource/a02baf5a-a3e4-49a0-857b-8a08d276c1c0?p1=v1&p2=v2`:
```
GET /v2/resource/a02baf5a-a3e4-49a0-857b-8a08d276c1c0
v1v2
1599140767
```
The two blank lines above are due to the absence of a request body and signed headers.
Example *message* to [create a security group](https://community.exoscale.com/reference/api/compute/security-group/#create-security-group)
```
POST /v2/security-group
{"name": "my-security-group"}
1599140767
```
The two blank lines above are due to the absence of query parameters and signed headers.
The request signature consists of the base64-encoded [HMAC](https://en.wikipedia.org/wiki/HMAC) hash of the UTF-8 encoded *message* and the Exoscale API secret using the SHA265 function:
```
signature = BASE64_ENCODE(HMAC_SHA256(Exoscale API secret, message))
```
Finally, the computed signature must be added to the API request in a `Authorization` header such as:
```
Authorization: EXO2-HMAC-SHA256 credential=<Exoscale API key>,expires=<expiration date UNIX timestamp>,signature=<signature>
```
Example API query:
```
GET /v2/resource/a02baf5a-a3e4-49a0-857b-8a08d276c1c0?p1=v1&p2=v2 HTTP/1.1
Host: api-ch-gva-2.exoscale.com
Authorization: EXO2-HMAC-SHA256 credential=EXO29147e9f89102b7ac1e88514,signed-query-args=p1;p2,expires=1599140767,signature=2AOBQsbElQb4FpKT/FM/9T4NobjlmZkSGvvdUth/xlY=
```
## Reference Implementations
You can look up the following existing reference implementations:
* Go: [github.com/exoscale/egoscale/api/v2 > `SecurityProviderExoscale.signRequest`](https://github.com/exoscale/egoscale/blob/master/v2/api/security.go)
* Python: [requests-exoscale-auth > `ExoscaleV2Auth`](https://github.com/exoscale/requests-exoscale-auth/blob/master/exoscale_auth.py)
'
- title: Zone local resources
content: '
The API is deployed across all Exoscale zones. When performing a compute call, you should use the relevant zone for your resource.
For example: https://api-de-fra-1.exoscale.com/v2/instance would return only the instances from `de-fra-1`, https://api-ch-gva-2.exoscale.com/v2/instance from `ch-gva-2`.
To obtain a list of all instances across all zones, you would need to do the corresponding request for each zone.
'