diff --git a/package-lock.json b/package-lock.json index affbd8e..837aa8a 100644 --- a/package-lock.json +++ b/package-lock.json @@ -9683,9 +9683,9 @@ "license": "MIT" }, "node_modules/undici": { - "version": "8.10.0", - "resolved": "https://registry.npmjs.org/undici/-/undici-8.10.0.tgz", - "integrity": "sha512-HvltHd7avK13QIw/oLe4qoOLyoVSoafqJ2jYOrtMRBkbYT31eiBQ8O0ehRKZiEZCMEyLFQNIADpgCWC5fALvYQ==", + "version": "8.11.2", + "resolved": "https://registry.npmjs.org/undici/-/undici-8.11.2.tgz", + "integrity": "sha512-u4UB2/IrKdU6lFxumHmmo1a3fCQO5tzQllRorfoRS63txhrB7xTpSn1PftwC4qEHkOaqP95fCWW4lJzwErwzhQ==", "license": "MIT", "engines": { "node": ">=22.19.0" diff --git a/site/dolt/src/content/products/hosted/api/v1/README.md b/site/dolt/src/content/products/hosted/api/v1/README.md index b13761d..6e99dbd 100644 --- a/site/dolt/src/content/products/hosted/api/v1/README.md +++ b/site/dolt/src/content/products/hosted/api/v1/README.md @@ -61,6 +61,10 @@ See [Authentication](/products/hosted/api/v1/authentication) for how to create a | **POST** | `/api/v1/deployments/{owner}/{deployment}/backups` | [Take a backup of a deployment](/products/hosted/api/v1/deployment#createDeploymentBackup) | | **GET** | `/api/v1/deployments/{owner}/{deployment}/database-version` | [List the versions a deployment can run](/products/hosted/api/v1/deployment#listDeploymentDatabaseVersions) | | **POST** | `/api/v1/deployments/{owner}/{deployment}/database-version` | [Roll a deployment's database engine to another version](/products/hosted/api/v1/deployment#updateDeploymentDatabaseVersion) | +| **GET** | `/api/v1/deployments/{owner}/{deployment}/dolt-credentials` | [Read a deployment's Dolt credentials](/products/hosted/api/v1/deployment#getDeploymentDoltCredentials) | +| **POST** | `/api/v1/deployments/{owner}/{deployment}/dolt-credentials` | [Issue Dolt credentials for a deployment](/products/hosted/api/v1/deployment#createDeploymentDoltCredentials) | +| **DELETE** | `/api/v1/deployments/{owner}/{deployment}/dolt-credentials` | [Remove a deployment's Dolt credentials](/products/hosted/api/v1/deployment#deleteDeploymentDoltCredentials) | +| **POST** | `/api/v1/deployments/{owner}/{deployment}/dolt-credentials/reroll` | [Replace a deployment's Dolt credentials](/products/hosted/api/v1/deployment#rerollDeploymentDoltCredentials) | | **POST** | `/api/v1/deployments/{owner}/{deployment}/disable` | [Disable a deployment](/products/hosted/api/v1/deployment#disableDeployment) | ### Pull request @@ -135,6 +139,8 @@ Instance changes are also `202`, but there is no per-instance `state` field to p [Taking a backup](/products/hosted/api/v1/deployment#createDeploymentBackup), [rolling the database version](/products/hosted/api/v1/deployment#updateDeploymentDatabaseVersion), and [rebooting an instance](/products/hosted/api/v1/deployment#rebootDeploymentInstance) return `202` with an [OperationRef](/products/hosted/api/v1/models#model-operationref). Follow its `href`, or pass its `id` to [Get an operation](/products/hosted/api/v1/operation#getOperation), and poll with a delay until `status` is `succeeded` or `failed`. Completion means different things for each action: a version roll waits for every instance to report the requested version, backup completion is inferred from successful backup timestamps, and a reboot succeeds when the platform accepts the request, before the database is necessarily ready. A failed operation does not imply rollback, and a transient HTTP error while polling is not a reason to submit the action again. +[Issuing](/products/hosted/api/v1/deployment#createDeploymentDoltCredentials), [removing](/products/hosted/api/v1/deployment#deleteDeploymentDoltCredentials), or [replacing Dolt credentials](/products/hosted/api/v1/deployment#rerollDeploymentDoltCredentials) also returns `202` with an OperationRef to poll. These credentials let the deployment access private databases on DoltHub. After issuing or replacing them succeeds, [read the public key](/products/hosted/api/v1/deployment#getDeploymentDoltCredentials) and add it to the appropriate DoltHub account. After removal succeeds, that read returns `404`. Replacement can temporarily leave instances with different credentials, and a failed operation does not roll back changes. + Deployment names are unique within an owner, which makes creates idempotent by name: retrying after an ambiguous failure returns `409 Conflict` rather than provisioning a second deployment. > **Creating a deployment incurs cost.** Disabling one tears down its instances and their storage — [take a backup first](/products/hosted/api/v1/deployment#createDeploymentBackup) and confirm completion if you want the data. diff --git a/site/dolt/src/content/products/hosted/api/v1/deployment.md b/site/dolt/src/content/products/hosted/api/v1/deployment.md index aa520ee..fcccd21 100644 --- a/site/dolt/src/content/products/hosted/api/v1/deployment.md +++ b/site/dolt/src/content/products/hosted/api/v1/deployment.md @@ -879,6 +879,220 @@ curl -X POST 'https://hosted.doltdb.com/api/v1/deployments/{owner}/{deployment}/ --- +## Read a deployment's Dolt credentials {#getDeploymentDoltCredentials} +GET /api/v1/deployments/{owner}/{deployment}/dolt-credentials + +Returns the public half of the Dolt credentials the deployment uses to authenticate to DoltHub, so it can clone from and push to private databases. The private key is held by the deployment's instances and is never returned here. + +These are not the deployment's SQL username and password, and not a way to connect to the deployment. They are a `dolt creds` key pair belonging to the deployment itself, and the public key is what you add to a DoltHub account to let the deployment in. + +`404` when the deployment has no credentials, which is the state it starts in. + +Requires admin on the deployment. + + +**Parameters** + +| Name | In | Type | Required | Description | +|------|----|------|----------|-------------| +| `owner` | path | string | yes | The user or organization that owns the deployment. 3–32 characters of letters, digits, hyphens, and underscores. | +| `deployment` | path | string | yes | The deployment name, unique within the owner. 3–32 characters of letters, digits, hyphens, and underscores. | + +**Example request** + +```sh +curl -X GET 'https://hosted.doltdb.com/api/v1/deployments/{owner}/{deployment}/dolt-credentials' \ + -H 'Authorization: Bearer YOUR_TOKEN' +``` + +**Responses** + +| Status | Description | Schema | +|--------|-------------|--------| +| `200` | The deployment's Dolt credentials. | [`DoltCredentials`](/products/hosted/api/v1/models#model-doltcredentials) | +| `400` | The request was malformed or failed input validation. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `401` | Authentication credentials were missing or invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `403` | Authenticated, but not permitted to perform this action. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `404` | The requested resource does not exist. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `405` | The HTTP method is not supported for this resource. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `422` | The request was well-formed but semantically invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `500` | An unexpected server error occurred. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `503` | The service is temporarily unavailable. | [`Problem`](/products/hosted/api/v1/models#model-problem) | + +**Example response `200`** + +```json +{ + "data": { + "key_id": "qi54ma4nlm0dvvhbrgv2p0lqmgs1kgnd", + "public_key": "7pnjqfqgqgqfhs5rgkcbhjqgxzqfnkqfhs5rgkcbhjqgxzqfnkqa" + } +} +``` + +--- + +## Issue Dolt credentials for a deployment {#createDeploymentDoltCredentials} +POST /api/v1/deployments/{owner}/{deployment}/dolt-credentials + +Generates a `dolt creds` key pair, hands the private half to the deployment's instances, and records the public half. Use it once; to replace an existing key pair use `POST .../dolt-credentials/reroll`, which removes the old key in the same pass. + +The work is queued, so this returns `202` with an operation to poll. The operation does not carry the key: read `GET .../dolt-credentials` once it succeeds. + + +Requires admin on the deployment, which must be `started`. + + +**Parameters** + +| Name | In | Type | Required | Description | +|------|----|------|----------|-------------| +| `owner` | path | string | yes | The user or organization that owns the deployment. 3–32 characters of letters, digits, hyphens, and underscores. | +| `deployment` | path | string | yes | The deployment name, unique within the owner. 3–32 characters of letters, digits, hyphens, and underscores. | + +**Example request** + +```sh +curl -X POST 'https://hosted.doltdb.com/api/v1/deployments/{owner}/{deployment}/dolt-credentials' \ + -H 'Authorization: Bearer YOUR_TOKEN' \ + -H 'Content-Type: application/json' +``` + +**Responses** + +| Status | Description | Schema | +|--------|-------------|--------| +| `202` | The request to issue credentials was accepted and queued. | [`OperationRef`](/products/hosted/api/v1/models#model-operationref) | +| `400` | The request was malformed or failed input validation. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `401` | Authentication credentials were missing or invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `403` | Authenticated, but not permitted to perform this action. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `404` | The requested resource does not exist. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `405` | The HTTP method is not supported for this resource. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `409` | The request conflicts with the current state of the resource (e.g. it already exists). | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `422` | The request was well-formed but semantically invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `500` | An unexpected server error occurred. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `503` | The service is temporarily unavailable. | [`Problem`](/products/hosted/api/v1/models#model-problem) | + +**Example response `202`** + +```json +{ + "data": { + "id": "3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72", + "href": "https://hosted.doltdb.com/api/v1/operations/3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72" + } +} +``` + +--- + +## Remove a deployment's Dolt credentials {#deleteDeploymentDoltCredentials} +DELETE /api/v1/deployments/{owner}/{deployment}/dolt-credentials + +Removes the key pair from the deployment's instances and clears the recorded public key. Anything on DoltHub that trusted that public key stops letting the deployment in. + +The work is queued, so this returns `202` with an operation to poll rather than `204`. `GET .../dolt-credentials` answers `404` once it succeeds. + + +`404` when the deployment has no credentials to remove. Requires admin on the deployment. + + +**Parameters** + +| Name | In | Type | Required | Description | +|------|----|------|----------|-------------| +| `owner` | path | string | yes | The user or organization that owns the deployment. 3–32 characters of letters, digits, hyphens, and underscores. | +| `deployment` | path | string | yes | The deployment name, unique within the owner. 3–32 characters of letters, digits, hyphens, and underscores. | + +**Example request** + +```sh +curl -X DELETE 'https://hosted.doltdb.com/api/v1/deployments/{owner}/{deployment}/dolt-credentials' \ + -H 'Authorization: Bearer YOUR_TOKEN' +``` + +**Responses** + +| Status | Description | Schema | +|--------|-------------|--------| +| `202` | The removal was queued. | [`OperationRef`](/products/hosted/api/v1/models#model-operationref) | +| `400` | The request was malformed or failed input validation. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `401` | Authentication credentials were missing or invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `403` | Authenticated, but not permitted to perform this action. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `404` | The requested resource does not exist. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `405` | The HTTP method is not supported for this resource. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `422` | The request was well-formed but semantically invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `500` | An unexpected server error occurred. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `503` | The service is temporarily unavailable. | [`Problem`](/products/hosted/api/v1/models#model-problem) | + +**Example response `202`** + +```json +{ + "data": { + "id": "3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72", + "href": "https://hosted.doltdb.com/api/v1/operations/3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72" + } +} +``` + +--- + +## Replace a deployment's Dolt credentials {#rerollDeploymentDoltCredentials} +POST /api/v1/deployments/{owner}/{deployment}/dolt-credentials/reroll + +Issues a new `dolt creds` key pair and requests removal of the old one in the same per-instance update. This is not an atomic change across the deployment: instances can temporarily disagree, and a failed operation does not roll back changes. + +The new public key has to be added to DoltHub before the deployment can reach private databases again, so expect a gap between this succeeding and access being restored. + +The work is queued, so this returns `202` with an operation to poll. Read `GET .../dolt-credentials` once it succeeds for the new public key. + + +`404` when the deployment has no credentials to replace; use `POST` to issue the first pair. Requires admin on the deployment. + + +**Parameters** + +| Name | In | Type | Required | Description | +|------|----|------|----------|-------------| +| `owner` | path | string | yes | The user or organization that owns the deployment. 3–32 characters of letters, digits, hyphens, and underscores. | +| `deployment` | path | string | yes | The deployment name, unique within the owner. 3–32 characters of letters, digits, hyphens, and underscores. | + +**Example request** + +```sh +curl -X POST 'https://hosted.doltdb.com/api/v1/deployments/{owner}/{deployment}/dolt-credentials/reroll' \ + -H 'Authorization: Bearer YOUR_TOKEN' \ + -H 'Content-Type: application/json' +``` + +**Responses** + +| Status | Description | Schema | +|--------|-------------|--------| +| `202` | The replacement was queued. | [`OperationRef`](/products/hosted/api/v1/models#model-operationref) | +| `400` | The request was malformed or failed input validation. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `401` | Authentication credentials were missing or invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `403` | Authenticated, but not permitted to perform this action. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `404` | The requested resource does not exist. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `405` | The HTTP method is not supported for this resource. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `422` | The request was well-formed but semantically invalid. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `500` | An unexpected server error occurred. | [`Problem`](/products/hosted/api/v1/models#model-problem) | +| `503` | The service is temporarily unavailable. | [`Problem`](/products/hosted/api/v1/models#model-problem) | + +**Example response `202`** + +```json +{ + "data": { + "id": "3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72", + "href": "https://hosted.doltdb.com/api/v1/operations/3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72" + } +} +``` + +--- + ## Read a deployment's logs {#getDeploymentLogs} GET /api/v1/deployments/{owner}/{deployment}/logs diff --git a/site/dolt/src/content/products/hosted/api/v1/models.md b/site/dolt/src/content/products/hosted/api/v1/models.md index 12c182b..443b9e8 100644 --- a/site/dolt/src/content/products/hosted/api/v1/models.md +++ b/site/dolt/src/content/products/hosted/api/v1/models.md @@ -370,6 +370,16 @@ What a deployment's database engine is running and the versions it can be upgrad --- +## DoltCredentials {#model-doltcredentials} +The public half of the `dolt creds` key pair a deployment authenticates to DoltHub with. The private half lives on the deployment's instances and is never returned. + +| Field | Type | Required | Description | +|-------|------|----------|-------------| +| `key_id` | `string` | yes | The key pair's identifier, which is what DoltHub lists the credential under. | +| `public_key` | `string` | yes | The public key, to be added to the DoltHub account whose private databases the deployment should reach. | + +--- + ## UpdateDatabaseVersionRequest {#model-updatedatabaseversionrequest} The version to roll the deployment's database engine to. diff --git a/site/dolt/src/content/reference/sql/benchmarks/correctness.md b/site/dolt/src/content/reference/sql/benchmarks/correctness.md index 8be4b5a..485eb10 100644 --- a/site/dolt/src/content/reference/sql/benchmarks/correctness.md +++ b/site/dolt/src/content/reference/sql/benchmarks/correctness.md @@ -55,7 +55,7 @@ AND col3 IN (3,9,0))))) OR col4 <= 4.25 OR ((col3 = 5))) OR (((col0 > 0)) AND col0 > 6 AND (col4 >= 6.56))) ``` -Here are Dolt's sqllogictest results for version `2.3.5`. Tests that +Here are Dolt's sqllogictest results for version `2.4.0`. Tests that did not run could not complete due to a timeout earlier in the run. | Results | Count | diff --git a/site/dolt/src/content/reference/sql/benchmarks/latency.md b/site/dolt/src/content/reference/sql/benchmarks/latency.md index 71fe778..3d1c235 100644 --- a/site/dolt/src/content/reference/sql/benchmarks/latency.md +++ b/site/dolt/src/content/reference/sql/benchmarks/latency.md @@ -33,41 +33,41 @@ attempt to run as many queries as possible in a fixed 2 minute time window. The `Dolt` and `MySQL` columns show the median latency in milliseconds (ms) of each query during that 2 minute time window. -The Dolt version is `2.3.5`. +The Dolt version is `2.4.0`. | Read Tests | MySQL | Dolt | Multiple | |:-----------------------:|:------:|:------:|:--------:| -| covering\_index\_scan | 16.71 | 2.3 | 0.14 | -| groupby\_scan | 134.9 | 65.65 | 0.49 | -| index\_join | 3.43 | 1.93 | 0.56 | -| index\_join\_scan | 4.25 | 1.32 | 0.31 | -| index\_scan | 344.08 | 204.11 | 0.59 | +| covering\_index\_scan | 16.71 | 2.35 | 0.14 | +| groupby\_scan | 134.9 | 64.47 | 0.48 | +| index\_join | 3.36 | 1.96 | 0.58 | +| index\_join\_scan | 4.25 | 1.37 | 0.32 | +| index\_scan | 344.08 | 200.47 | 0.58 | | oltp\_point\_select | 0.19 | 0.26 | 1.37 | | oltp\_read\_only | 3.68 | 5.09 | 1.38 | | select\_random\_points | 0.36 | 0.52 | 1.44 | -| select\_random\_ranges | 0.38 | 0.65 | 1.71 | +| select\_random\_ranges | 0.39 | 0.67 | 1.72 | | table\_scan | 344.08 | 204.11 | 0.59 | -| types\_table\_scan | 759.88 | 467.3 | 0.61 | +| types\_table\_scan | 759.88 | 458.96 | 0.6 | | reads\_mean\_multiplier | | | 0.84 | | Write Tests | MySQL | Dolt | Multiple | |:------------------------:|:-----:|:-----:|:--------:| -| oltp\_delete\_insert | 7.84 | 6.21 | 0.79 | -| oltp\_insert | 4.1 | 3.13 | 0.76 | -| oltp\_read\_write | 8.9 | 11.24 | 1.26 | -| oltp\_update\_index | 4.33 | 3.3 | 0.76 | -| oltp\_update\_non\_index | 4.1 | 3.02 | 0.74 | +| oltp\_delete\_insert | 8.28 | 6.21 | 0.75 | +| oltp\_insert | 4.18 | 3.19 | 0.76 | +| oltp\_read\_write | 9.06 | 11.45 | 1.26 | +| oltp\_update\_index | 4.41 | 3.36 | 0.76 | +| oltp\_update\_non\_index | 4.18 | 3.07 | 0.73 | | oltp\_write\_only | 5.18 | 6.32 | 1.22 | -| types\_delete\_insert | 8.28 | 6.79 | 0.82 | -| writes\_mean\_multiplier | | | 0.91 | +| types\_delete\_insert | 8.58 | 6.79 | 0.79 | +| writes\_mean\_multiplier | | | 0.9 | | TPC-C TPS Tests | MySQL | Dolt | Multiple | |:---------------------:|:-----:|:-----:|:--------:| -| tpcc-scale-factor-1 | 96.87 | 52.38 | 1.85 | -| tpcc\_tps\_multiplier | | | 1.85 | +| tpcc-scale-factor-1 | 96.45 | 53.18 | 1.81 | +| tpcc\_tps\_multiplier | | | 1.81 | -| Overall Mean Multiple | 1.20 | +| Overall Mean Multiple | 1.18 | |:---------------------:|:----:|
diff --git a/specs/hosted-v1.yaml b/specs/hosted-v1.yaml index 075ef1b..b1497a7 100644 --- a/specs/hosted-v1.yaml +++ b/specs/hosted-v1.yaml @@ -1357,6 +1357,302 @@ paths: "503": $ref: "#/components/responses/ServiceUnavailable" + /api/v1/deployments/{owner}/{deployment}/dolt-credentials: + parameters: + - name: owner + in: path + required: true + description: >- + The user or organization that owns the deployment. 3–32 characters of letters, + digits, hyphens, and underscores. + schema: + type: string + pattern: "^[-a-zA-Z0-9_]{3,32}$" + example: acme + - name: deployment + in: path + required: true + description: >- + The deployment name, unique within the owner. 3–32 characters of letters, + digits, hyphens, and underscores. + schema: + type: string + pattern: "^[-a-zA-Z0-9_]{3,32}$" + example: analytics + get: + operationId: getDeploymentDoltCredentials + summary: Read a deployment's Dolt credentials. + description: >- + Returns the public half of the Dolt credentials the deployment uses to authenticate + to DoltHub, so it can clone from and push to private databases. The private key is + held by the deployment's instances and is never returned here. + + + These are not the deployment's SQL username and password, and not a way to connect + to the deployment. They are a `dolt creds` key pair belonging to the deployment + itself, and the public key is what you add to a DoltHub account to let the + deployment in. + + + `404` when the deployment has no credentials, which is the state it starts in. + + + Requires admin on the deployment. + tags: + - Deployment + security: + - apiToken: [] + responses: + "200": + description: The deployment's Dolt credentials. + headers: + x-request-id: + $ref: "#/components/headers/RequestId" + content: + application/json: + schema: + allOf: + - $ref: "#/components/schemas/Envelope" + - type: object + required: + - data + properties: + data: + $ref: "#/components/schemas/DoltCredentials" + examples: + default: + summary: A deployment with credentials. + value: + data: + key_id: qi54ma4nlm0dvvhbrgv2p0lqmgs1kgnd + public_key: 7pnjqfqgqgqfhs5rgkcbhjqgxzqfnkqfhs5rgkcbhjqgxzqfnkqa + "400": + $ref: "#/components/responses/BadRequest" + "401": + $ref: "#/components/responses/Unauthorized" + "403": + $ref: "#/components/responses/Forbidden" + "404": + $ref: "#/components/responses/NotFound" + "422": + $ref: "#/components/responses/UnprocessableEntity" + "405": + $ref: "#/components/responses/MethodNotAllowed" + "500": + $ref: "#/components/responses/InternalServerError" + "503": + $ref: "#/components/responses/ServiceUnavailable" + post: + operationId: createDeploymentDoltCredentials + summary: Issue Dolt credentials for a deployment. + description: >- + Generates a `dolt creds` key pair, hands the private half to the deployment's + instances, and records the public half. Use it once; to replace an existing key + pair use `POST .../dolt-credentials/reroll`, which removes the old key in the same + pass. + + + The work is queued, so this returns `202` with an operation to poll. The operation + does not carry the key: read `GET .../dolt-credentials` once it succeeds. + + + + Requires admin on the deployment, which must be `started`. + tags: + - Deployment + security: + - apiToken: [] + responses: + "202": + description: The request to issue credentials was accepted and queued. + headers: + x-request-id: + $ref: "#/components/headers/RequestId" + content: + application/json: + schema: + allOf: + - $ref: "#/components/schemas/Envelope" + - type: object + required: + - data + properties: + data: + $ref: "#/components/schemas/OperationRef" + examples: + default: + summary: Poll the operation, then retrieve the credentials. + value: + data: + id: 3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72 + href: https://hosted.doltdb.com/api/v1/operations/3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72 + "400": + $ref: "#/components/responses/BadRequest" + "401": + $ref: "#/components/responses/Unauthorized" + "403": + $ref: "#/components/responses/Forbidden" + "404": + $ref: "#/components/responses/NotFound" + "409": + $ref: "#/components/responses/Conflict" + "422": + $ref: "#/components/responses/UnprocessableEntity" + "405": + $ref: "#/components/responses/MethodNotAllowed" + "500": + $ref: "#/components/responses/InternalServerError" + "503": + $ref: "#/components/responses/ServiceUnavailable" + delete: + operationId: deleteDeploymentDoltCredentials + summary: Remove a deployment's Dolt credentials. + description: >- + Removes the key pair from the deployment's instances and clears the recorded public + key. Anything on DoltHub that trusted that public key stops letting the deployment + in. + + + The work is queued, so this returns `202` with an operation to poll rather than + `204`. `GET .../dolt-credentials` answers `404` once it succeeds. + + + + `404` when the deployment has no credentials to remove. Requires admin on the + deployment. + tags: + - Deployment + security: + - apiToken: [] + responses: + "202": + description: The removal was queued. + headers: + x-request-id: + $ref: "#/components/headers/RequestId" + content: + application/json: + schema: + allOf: + - $ref: "#/components/schemas/Envelope" + - type: object + required: + - data + properties: + data: + $ref: "#/components/schemas/OperationRef" + examples: + default: + summary: Poll the operation to confirm removal. + value: + data: + id: 3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72 + href: https://hosted.doltdb.com/api/v1/operations/3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72 + "400": + $ref: "#/components/responses/BadRequest" + "401": + $ref: "#/components/responses/Unauthorized" + "403": + $ref: "#/components/responses/Forbidden" + "404": + $ref: "#/components/responses/NotFound" + "422": + $ref: "#/components/responses/UnprocessableEntity" + "405": + $ref: "#/components/responses/MethodNotAllowed" + "500": + $ref: "#/components/responses/InternalServerError" + "503": + $ref: "#/components/responses/ServiceUnavailable" + + /api/v1/deployments/{owner}/{deployment}/dolt-credentials/reroll: + parameters: + - name: owner + in: path + required: true + description: >- + The user or organization that owns the deployment. 3–32 characters of letters, + digits, hyphens, and underscores. + schema: + type: string + pattern: "^[-a-zA-Z0-9_]{3,32}$" + example: acme + - name: deployment + in: path + required: true + description: >- + The deployment name, unique within the owner. 3–32 characters of letters, + digits, hyphens, and underscores. + schema: + type: string + pattern: "^[-a-zA-Z0-9_]{3,32}$" + example: analytics + post: + operationId: rerollDeploymentDoltCredentials + summary: Replace a deployment's Dolt credentials. + description: >- + Issues a new `dolt creds` key pair and requests removal of the old one in the same + per-instance update. This is not an atomic change across the deployment: instances + can temporarily disagree, and a failed operation does not roll back changes. + + + The new public key has to be added to DoltHub before the deployment can reach + private databases again, so expect a gap between this succeeding and access being + restored. + + + The work is queued, so this returns `202` with an operation to poll. Read + `GET .../dolt-credentials` once it succeeds for the new public key. + + + + `404` when the deployment has no credentials to replace; use `POST` to issue the + first pair. Requires admin on the deployment. + tags: + - Deployment + security: + - apiToken: [] + responses: + "202": + description: The replacement was queued. + headers: + x-request-id: + $ref: "#/components/headers/RequestId" + content: + application/json: + schema: + allOf: + - $ref: "#/components/schemas/Envelope" + - type: object + required: + - data + properties: + data: + $ref: "#/components/schemas/OperationRef" + examples: + default: + summary: Poll the operation, then retrieve the new credentials. + value: + data: + id: 3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72 + href: https://hosted.doltdb.com/api/v1/operations/3f2a9c14-8e7b-4d21-9a05-6c3e1b8f4d72 + "400": + $ref: "#/components/responses/BadRequest" + "401": + $ref: "#/components/responses/Unauthorized" + "403": + $ref: "#/components/responses/Forbidden" + "404": + $ref: "#/components/responses/NotFound" + "422": + $ref: "#/components/responses/UnprocessableEntity" + "405": + $ref: "#/components/responses/MethodNotAllowed" + "500": + $ref: "#/components/responses/InternalServerError" + "503": + $ref: "#/components/responses/ServiceUnavailable" + /api/v1/deployments/{owner}/{deployment}/logs: get: operationId: getDeploymentLogs @@ -3818,6 +4114,29 @@ components: type: string examples: - [1.60.0, 1.59.2, 1.59.1, 1.58.4, 1.58.3] + DoltCredentials: + type: object + title: DoltCredentials + description: >- + The public half of the `dolt creds` key pair a deployment authenticates to DoltHub + with. The private half lives on the deployment's instances and is never returned. + required: + - key_id + - public_key + properties: + key_id: + type: string + description: >- + The key pair's identifier, which is what DoltHub lists the credential under. + examples: + - qi54ma4nlm0dvvhbrgv2p0lqmgs1kgnd + public_key: + type: string + description: >- + The public key, to be added to the DoltHub account whose private databases the + deployment should reach. + examples: + - 7pnjqfqgqgqfhs5rgkcbhjqgxzqfnkqfhs5rgkcbhjqgxzqfnkqa UpdateDatabaseVersionRequest: type: object