openapi: 3.1.0
info:
title: Managed Database for PostgreSQL and MySQL Access Control List Security Groups API
description: "Managed Database for PostgreSQL and MySQL provides fully-managed relational Database Instances, with MySQL or PostgreSQL as database engines. The resource allows you to focus on development rather than administration or configuration. It comes with a high-availability mode, data replication, and automatic backups.\n\nCompared to traditional database management, which requires customers to provide their infrastructure and resources to manage their databases, Managed Database for PostgreSQL and MySQL Instance offers the user access to Database Instances without setting up the hardware or configuring the software. Scaleway handles the provisioning, manages the configuration, and provides useful features as high availability, automated backup, user management, and more.\n\n\n\n\n## Concepts\n\nRefer to our [dedicated concepts page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/concepts/) to find definitions of the different terms referring to Managed Database for PostgreSQL and MySQL.\n\n\n\n\n## Quickstart\n\n1. Configure your environment variables.\n <Message type=\"note\">\n This is an optional step that seeks to simplify your usage of the APIs.\n </Message>\n\n ```bash\n export SCW_ACCESS_KEY=\"<API access key>\"\n export SCW_SECRET_KEY=\"<API secret key>\"\n export SCW_REGION=\"<Scaleway region>\"\n ```\n2. Edit the POST request payload you will use to create your Database Instance. Replace the parameters in the following example:\n ```json\n '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n\n | Parameter | Description |\n | :--------------- |:-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n | `project_id` | The ID of the Project you want to create your Database Instance in. To find your Project ID you can **[list the projects](/api/account/project-api/#path-projects-list-all-projects-of-an-organization)** or consult the **[Scaleway console](https://console.scaleway.com/project/settings)**. |\n | `engine` | **REQUIRED** Version ID of the database engine. To check the list of available engines you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/database-engines` |\n | `name` | Name of the Database Instance |\n | `node_type` | **REQUIRED** The node type. To check the list of available node types you can use the following endpoint: `https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/node-types` |\n | `is_ha_cluster` | **BOOLEAN** Defines whether High Availability is enabled for the Database Instance |\n | `disable_backup` | **BOOLEAN** Defines whether automated backups are disabled for the Database Instance |\n | `tags` | The list of tags `[\"tag1\", \"tag2\", ...]` that will be associated with the Database Instance. Tags can be appended to the query of the [List Database Instances](#path-database-instances-list-database-instances) call to show results for only the Database Instances using a specific tag. You can also combine tags to list Database Instances that possess all the appended tags. |\n | `user_name` | **REQUIRED** Identifier of the default user, which is created concurrently with the Database Instance |\n | `password` | **REQUIRED** Password for the default user |\n | `volume_type` | Type of volume where data is stored. You can specify either local volume (`lssd`) or block volume (`bssd`, `sbs_5k` or `sbs_15k`). The default value is `lssd` |\n | `volume_size` | Volume size when volume_type is `bssd`, `sbs_5k` or `sbs_15k`. The value should be expressed in bytes. For example 30GB is expressed as 30000000000 |\n3. Create a Database Instance by running the following command. Make sure you include the payload you edited in the previous step.\n ```bash\n curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"Content-Type: application/json\" \\\n https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances \\\n -d '{\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"name\": \"myDB\",\n \"engine\": \"PostgreSQL-15\",\n \"tags\": [\"donnerstag\"],\n \"is_ha_cluster\": true,\n \"node_type\": \"db-pro2-xxs\",\n \"disable_backup\": false,\n \"user_name\": \"my_initial_user\",\n \"password\": \"thiZ_is_v0ry_s3cret\",\n \"volume_type\": \"sbs_5k\",\n \"volume_size\": \"30000000000\"\n }'\n ```\n4. List your Database Instances.\n ```bash\n curl -X GET \\\n -H \"Content-Type: application/json\" \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances\n ```\n\n You should get a response like the following:\n\n <Message type=\"note\">\n This is a response example, the UUIDs and IP address displayed are not real.\n </Message>\n\n ```json\n {\n \"id\": \"f5122f66-fb50-4cef-aa02-487ef4fc1af0\",\n \"name\": \"myDB\",\n \"organization_id\": \"895693aa-3915-4896-8761-c2923b008be7\",\n \"project_id\": \"d8e65f2b-cce9-40b7-80fc-6a2902db6826\",\n \"status\": \"ready\",\n \"engine\": \"PostgreSQL-15\",\n \"endpoint\": {\n \"ip\": \"198.51.100.0\",\n \"port\": 22245,\n \"name\": null\n },\n \"tags\": [\n \"donnerstag\"\n ],\n \"settings\": [],\n \"backup_schedule\": {\n \"frequency\": 24,\n \"retention\": 7,\n \"disabled\": true\n },\n \"is_ha_cluster\": true,\n \"read_replicas\": [],\n \"node_type\": \"db-pro2-xxs\",\n \"volume\": {\n \"type\": \"sbs_5k\",\n \"size\": 30000000000\n }\n \"created_at\": \"2019-04-19T16:24:52.591417Z\",\n \"region\": \"fr-par\"\n }\n ```\n5. Retrieve your Database Instance IP and port from the response.\n <Message type=\"note\">\n In the example above, the IP and port are `198.51.100.0` and `22245`, respectively.\n </Message>\n6. Connect to your Database Instance with the database client of the engine you selected.\n For MySQL, run the following command:\n ```bash\n mysql -h <ip-address> --port <port> -p -u <user_name>\n ```\n\n For PostgreSQL, run:\n ```bash\n psql -h <ip-address> -p <port> -U <username> -d rdb\n ```\n\n For the recurring example, the command would look like:\n\n ```bash\n psql -h 198.51.100.0 -p 22245 -U my_initial_user -d rdb\n ```\n7. Enter the database password that you defined upon creation.\n\nYou are now connected to your Managed Database.\n\n\n<Message type=\"requirement\">\nTo perform the following steps, you must first ensure that:\n - you have an account and are logged into the [Scaleway console](https://console.scaleway.com/organization)\n - you have created an [API key](https://www.scaleway.com/en/docs/iam/how-to/create-api-keys/) and that the API key has sufficient [IAM permissions](https://www.scaleway.com/en/docs/iam/reference-content/permission-sets/) to perform the actions described on this page.\n - you have [installed `curl`](https://curl.se/download.html)\n</Message>\n\n\n## Technical Information\n\n### Regions\n\nScaleway's infrastructure is spread across different [regions and Availability Zones](https://www.scaleway.com/en/docs/account/reference-content/products-availability/).\n\nManaged Database for PostgreSQL and MySQL is available in the Paris, Amsterdam and Warsaw regions, which are represented by the following path parameters:\n\n- `fr-par`\n- `nl-ams`\n- `pl-waw`\n\n### PostgreSQL specifications\n\n#### Versions\n\nScaleway Database for PostgreSQL supports PostgreSQL versions 11, 12, 13, 14 and 15.\n\n#### System\n\nDifferent modules are available for installation, including TimescaleDB and PostGIS. Refer to the [Managed Database for PostgreSQL and MySQL FAQ page](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/#which-postgresql-extensions-are-available) for an extensive list of PostgreSQL extensions.\n\n#### Database Management\n\nYou can create logical databases through the Scaleway console, the Scaleway APIs or SQL.\n\n- databases created using the Scaleway console or the API are owned by an internal system user. These are called \"managed databases\".\n- databases created using SQL will be owned by the creator. These are called \"unmanaged databases\".\n\n### MySQL specifications\n\n#### Versions\n\nScaleway Database for MySQL supports MySQL 8.\n\n#### System\n\n- only the [InnoDB engine](https://dev.mysql.com/doc/refman/8.0/en/innodb-storage-engine.html) is supported\n- the [Global Transaction Identifier (GTID)](https://dev.mysql.com/doc/refman/8.0/en/replication-gtids-concepts.html) is enabled.\n- [`mysql_native_password`](https://dev.mysql.com/doc/refman/8.0/en/native-pluggable-authentication.html) (default) and [`caching_sha2_password`](https://dev.mysql.com/doc/refman/8.0/en/caching-sha2-pluggable-authentication.html) authentication are supported.\n\n#### User Management\n\n- users with an `admin` role have access to all logical databases and can create new ones.\n- users created via the API are authenticated using the default authentication plugin, which can be changed in the settings.\n\n## Technical Limitations\n\n### PostgreSQL\n\n#### User Management\n\n- users with an `admin` role have `CREATEROLE` and `CREATEDB` privileges.\n- users do NOT have `SUPERUSER` nor `REPLICATION` privileges.\n- permission management through the Scaleway console or API is only possible for the \"managed databases\".\n\n#### Backup and restoration\n\nDatabases that have been backed up and then restored retain the user permission settings in use at the time of backup. If you delete users after backup and then restore your backup in the same database, or if you restore a backup to a different database with different or no users, the permissions configured for them continue to exist, but with no associated owner. This error will put a stop to the restoration process.\n\nTo avoid this issue, we recommend you re-create the users you deleted. In the occasion you restore the backup to a new database, you must create new users with the same names.\n\n## Going Further\n\nFor more information about Managed Database for PostgreSQL and MySQL, you can check out the following pages:\n\n* [Managed Database for PostgreSQL and MySQL Documentation](https://www.scaleway.com/en/docs/managed-databases/postgresql-and-mysql/)\n* [Managed Database for PostgreSQL and MySQL FAQ](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/faq/)\n* [Scaleway Slack Community](https://scaleway-community.slack.com/) join the #database channel\n* [Contact our support team](https://console.scaleway.com/support/tickets)\n\n### How to migrate a database\n\nIf you wish to migrate existing databases to a Managed Database for PostgreSQL or MySQL, you can refer to the [Migrating existing databases to a Database Instance](https://www.scaleway.com/en/docs/tutorials/migrate-databases-instance/) tutorial page.\n\n### Troubleshoooting\n\n#### Disk full status\n\nIf your Database Instance uses local storage, your local volume might eventually approach full capacity and shift to `disk_full` mode. This mode grants you enough space to either [upgrade your node type](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/how-to/upgrade-version/#how-to-change-the-node-type) or [clear out space in your volume](https://www.scaleway.com/en/docs/managed-databases-for-postgresql-and-mysql/troubleshooting/disk-full/)."
version: v1
servers:
- url: https://api.scaleway.com
tags:
- name: Security Groups
description: 'A security group is a set of firewall rules on a set of Instances.
Security groups enable you to create rules that either drop or allow incoming traffic from certain ports of your Instances.
Security groups are stateful by default which means return traffic is automatically allowed, regardless of any rules.
As a contrary, you have to switch in a stateless mode to define explicitly allowed.
'
paths:
/instance/v1/zones/{zone}/security_groups:
get:
tags:
- Security Groups
operationId: ListSecurityGroups
summary: List security groups
description: List all existing security groups.
parameters:
- in: path
name: zone
description: The zone you want to target
required: true
schema:
type: string
enum:
- fr-par-1
- fr-par-2
- fr-par-3
- nl-ams-1
- nl-ams-2
- nl-ams-3
- pl-waw-1
- pl-waw-2
- pl-waw-3
- it-mil-1
- in: query
name: name
description: Name of the security group.
schema:
type: string
- in: query
name: organization
description: Security group Organization ID.
schema:
type: string
- in: query
name: project
description: Security group Project ID.
schema:
type: string
- in: query
name: tags
description: List security groups with these exact tags (to filter with several tags, use commas to separate them).
schema:
type: string
- in: query
name: project_default
description: Filter security groups with this value for project_default.
schema:
type: boolean
- in: query
name: per_page
description: A positive integer lower or equal to 100 to select the number of items to return.
schema:
type: integer
format: uint32
- in: query
name: page
description: A positive integer to choose the page to return.
schema:
type: integer
format: int32
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/scaleway.instance.v1.ListSecurityGroupsResponse'
security:
- scaleway: []
x-codeSamples:
- lang: cURL
source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups\""
- lang: HTTPie
source: "http GET \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups\" \\\n X-Auth-Token:$SCW_SECRET_KEY"
post:
tags:
- Security Groups
operationId: CreateSecurityGroup
summary: Create a security group
description: Create a security group with a specified name and description.
parameters:
- in: path
name: zone
description: The zone you want to target
required: true
schema:
type: string
enum:
- fr-par-1
- fr-par-2
- fr-par-3
- nl-ams-1
- nl-ams-2
- nl-ams-3
- pl-waw-1
- pl-waw-2
- pl-waw-3
- it-mil-1
responses:
'201':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/scaleway.instance.v1.CreateSecurityGroupResponse'
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
description: Name of the security group.
description:
type: string
description: Description of the security group.
organization:
type: string
description: Organization ID the security group belongs to.
deprecated: true
nullable: true
x-one-of: ProjectIdentifier
project:
type: string
description: Project ID the security group belong to.
nullable: true
x-one-of: ProjectIdentifier
tags:
type: array
description: Tags of the security group.
items:
type: string
organization_default:
type: boolean
description: Defines whether this security group becomes the default security group for new Instances.
deprecated: true
nullable: true
x-one-of: DefaultIdentifier
project_default:
type: boolean
description: Whether this security group becomes the default security group for new Instances.
nullable: true
x-one-of: DefaultIdentifier
stateful:
type: boolean
description: Whether the security group is stateful or not.
inbound_default_policy:
type: string
description: Default policy for inbound rules.
enum:
- unknown_policy
- accept
- drop
default: unknown_policy
outbound_default_policy:
type: string
description: Default policy for outbound rules.
enum:
- unknown_policy
- accept
- drop
default: unknown_policy
enable_default_security:
type: boolean
description: True to block SMTP on IPv4 and IPv6. This feature is read only, please open a support ticket if you need to make it configurable.
nullable: true
required:
- name
x-properties-order:
- name
- description
- organization
- project
- tags
- organization_default
- project_default
- stateful
- inbound_default_policy
- outbound_default_policy
- enable_default_security
security:
- scaleway: []
x-codeSamples:
- lang: cURL
source: "curl -X POST \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"description\": \"string\",\n \"name\": \"string\",\n \"stateful\": false\n }' \\\n \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups\""
- lang: HTTPie
source: "http POST \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n description=\"string\" \\\n name=\"string\" \\\n stateful:=false"
/instance/v1/zones/{zone}/security_groups/{id}:
put:
tags:
- Security Groups
operationId: SetSecurityGroup
summary: Update a security group
description: Replace all security group properties with a security group message.
parameters:
- in: path
name: zone
description: The zone you want to target
required: true
schema:
type: string
enum:
- fr-par-1
- fr-par-2
- fr-par-3
- nl-ams-1
- nl-ams-2
- nl-ams-3
- pl-waw-1
- pl-waw-2
- pl-waw-3
- it-mil-1
- in: path
name: id
description: UUID of the security group.
required: true
schema:
type: string
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/scaleway.instance.v1.SetSecurityGroupResponse'
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
description: Name of the security group.
tags:
type: array
description: Tags of the security group.
nullable: true
items:
type: string
creation_date:
type: string
description: Creation date of the security group (will be ignored). (RFC 3339 format)
format: date-time
example: '2022-03-22T12:34:56.123456Z'
nullable: true
modification_date:
type: string
description: Modification date of the security group (will be ignored). (RFC 3339 format)
format: date-time
example: '2022-03-22T12:34:56.123456Z'
nullable: true
description:
type: string
description: Description of the security group.
enable_default_security:
type: boolean
description: True to block SMTP on IPv4 and IPv6. This feature is read only, please open a support ticket if you need to make it configurable.
inbound_default_policy:
type: string
description: Default inbound policy.
enum:
- unknown_policy
- accept
- drop
default: unknown_policy
outbound_default_policy:
type: string
description: Default outbound policy.
enum:
- unknown_policy
- accept
- drop
default: unknown_policy
organization:
type: string
description: Security groups Organization ID.
project:
type: string
description: Security group Project ID.
organization_default:
type: boolean
description: Please use project_default instead.
deprecated: true
project_default:
type: boolean
description: True use this security group for future Instances created in this project.
servers:
type: array
description: Instances attached to this security group.
items:
$ref: '#/components/schemas/scaleway.instance.v1.ServerSummary'
stateful:
type: boolean
description: True to set the security group as stateful.
x-properties-order:
- name
- tags
- creation_date
- modification_date
- description
- enable_default_security
- inbound_default_policy
- outbound_default_policy
- organization
- project
- organization_default
- project_default
- servers
- stateful
security:
- scaleway: []
x-codeSamples:
- lang: cURL
source: "curl -X PUT \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n -H \"Content-Type: application/json\" \\\n -d '{\n \"description\": \"string\",\n \"enable_default_security\": false,\n \"name\": \"string\",\n \"organization\": \"string\",\n \"organization_default\": false,\n \"project\": \"string\",\n \"project_default\": false,\n \"stateful\": false\n }' \\\n \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups/{id}\""
- lang: HTTPie
source: "http PUT \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups/{id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY \\\n description=\"string\" \\\n enable_default_security:=false \\\n name=\"string\" \\\n organization=\"string\" \\\n organization_default:=false \\\n project=\"string\" \\\n project_default:=false \\\n stateful:=false"
/instance/v1/zones/{zone}/security_groups/{security_group_id}:
get:
tags:
- Security Groups
operationId: GetSecurityGroup
summary: Get a security group
description: Get the details of a security group with the specified ID.
parameters:
- in: path
name: zone
description: The zone you want to target
required: true
schema:
type: string
enum:
- fr-par-1
- fr-par-2
- fr-par-3
- nl-ams-1
- nl-ams-2
- nl-ams-3
- pl-waw-1
- pl-waw-2
- pl-waw-3
- it-mil-1
- in: path
name: security_group_id
description: UUID of the security group you want to get.
required: true
schema:
type: string
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/scaleway.instance.v1.GetSecurityGroupResponse'
security:
- scaleway: []
x-codeSamples:
- lang: cURL
source: "curl -X GET \\\n -H \"X-Auth-Token: $SCW_SECRET_KEY\" \\\n \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups/{security_group_id}\""
- lang: HTTPie
source: "http GET \"https://api.scaleway.com/instance/v1/zones/{zone}/security_groups/{security_group_id}\" \\\n X-Auth-Token:$SCW_SECRET_KEY"
patch:
tags:
- Security Groups
operationId: UpdateSecurityGroup
summary: Update a security group
description: Update the properties of security group.
parameters:
- in: path
name: zone
description: The zone you want to target
required: true
schema:
type: string
enum:
- fr-par-1
- fr-par-2
- fr-par-3
- nl-ams-1
- nl-ams-2
- nl-ams-3
- pl-waw-1
- pl-waw-2
- pl-waw-3
- it-mil-1
- in: path
name: security_group_id
description: UUID of the security group. (UUID format)
required: true
schema:
type: string
example: 6170692e-7363-616c-6577-61792e636f6d
responses:
'200':
description: ''
content:
application/json:
schema:
$ref: '#/components/schemas/scaleway.instance.v1.UpdateSecurityGroupResponse'
requestBody:
required: true
content:
application/json:
schema:
type: object
properties:
name:
type: string
description: Name of the security group.
nullable: true
description:
type: string
description: Description of the security group.
nullable: true
enable_default_security:
type: boolean
description: True to block SMTP on IPv4 and IPv6. This feature is read only, please open a support ticket if you need to make it configurable.
nullable: true
inbound_default_policy:
type: string
description: Default inbound policy.
enum:
- unknown_policy
- accept
- drop
default: unknown_policy
tags:
type: array
description: Tags of the security group.
nullable: true
items:
type: string
organization_default:
type: boolean
description: Please use project_default instead.
deprecated: true
nullable: true
project_default:
type: boolean
description: True use this security group for future Instances created in this project.
nullable: true
outbound_default_policy:
type: string
description: Default outbound policy.
enum:
- unknown_policy
- accept
- drop
default: unknown_policy
stateful:
type: boolean
description: True to set the security group as stateful.
nullable: true
x-properties-order:
- name
- description
- enable_default_security
- inbound_default_pol
# --- truncated at 32 KB (62 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/scaleway/refs/heads/main/openapi/scaleway-security-groups-api-openapi.yml