import * as outputs from "../types/output"; export interface AccountAuthenticationSamlFieldMapping { /** * Field name for user email */ email?: string; /** * Field name for user's first name */ firstName?: string; /** * Field name for user's identity. This field must always exist in responses, and must be immutable and unique. Contents of this field are used to identify the user. Using user ID (such as unix user id) is highly recommended, as email address may change, requiring relinking user to Aiven user. */ identity?: string; /** * Field name for user's last name */ lastName?: string; /** * Field name for user's full name. If specified, first*name and last*name mappings are ignored */ realName?: string; } export interface AwsOrgVpcPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface AwsPrivatelinkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface AzureOrgVpcPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface AzurePrivatelinkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface BillingGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ByocAwsEntityContactEmail { /** * User email address. Maximum length: `254`. */ email: string; /** * User real name. Maximum length: `256`. */ realName?: string; /** * Role of this user. Maximum length: `256`. */ role?: string; } export interface ByocAwsEntityTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ByocAwsProvisionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ByocPermissionsTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ClickhouseClickhouse { /** * ClickHouse server URIs. */ uris: string[]; } export interface ClickhouseClickhouseUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Example: `3`. */ backupHour?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Example: `30`. */ backupMinute?: number; /** * Enum: `25.3`, `25.8`, `26.3`, and newer. ClickHouse major version. */ clickhouseVersion?: string; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.ClickhouseClickhouseUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.ClickhouseClickhouseUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.ClickhouseClickhouseUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.ClickhouseClickhouseUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * ClickHouse server settings, which can be found in the `system.server_settings` table */ serverSettings?: outputs.ClickhouseClickhouseUserConfigServerSettings; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * ClickHouse session settings, which can be found in the `system.settings` table */ sessionSettings?: outputs.ClickhouseClickhouseUserConfigSessionSettings; /** * Use static public IP addresses. */ staticIps?: boolean; /** * The percentage of free disk space required on local storage before data is moved to object storage. A value of 0.2 means data is moved when local storage has less than 20% free space. Default: `0.2`. */ tieredStorageMoveFactor?: number; } export interface ClickhouseClickhouseUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface ClickhouseClickhouseUserConfigPrivateAccess { /** * Allow clients to connect to clickhouse with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouse?: boolean; /** * Allow clients to connect to clickhouseArrowflight with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouseArrowflight?: boolean; /** * Allow clients to connect to clickhouseHttps with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouseHttps?: boolean; /** * Allow clients to connect to clickhouseMysql with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouseMysql?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface ClickhouseClickhouseUserConfigPrivatelinkAccess { /** * Enable clickhouse. */ clickhouse?: boolean; /** * Enable clickhouse_arrowflight. */ clickhouseArrowflight?: boolean; /** * Enable clickhouse_https. */ clickhouseHttps?: boolean; /** * Enable clickhouse_mysql. */ clickhouseMysql?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface ClickhouseClickhouseUserConfigPublicAccess { /** * Allow clients to connect to clickhouse from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouse?: boolean; /** * Allow clients to connect to clickhouseArrowflight from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouseArrowflight?: boolean; /** * Allow clients to connect to clickhouseHttps from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouseHttps?: boolean; /** * Allow clients to connect to clickhouseMysql from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouseMysql?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface ClickhouseClickhouseUserConfigServerSettings { /** * Fraction of total server memory allocated to the vector similarity index cache. 0 disables the cache. Default is 0.07 (7% of server memory). Only effective on ClickHouse 25.8+. Default: `0.07`. */ vectorSimilarityIndexCacheSize?: number; } export interface ClickhouseClickhouseUserConfigSessionSettings { /** * When set, ClickHouse applies backward-compatible behavior from the specified version. Automatically set to the previous version on major version upgrade. Set to null to disable compatibility mode once all incompatibilities have been resolved. Takes effect after the next service restart/upgrade. */ compatibility?: string; } export interface ClickhouseComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface ClickhouseDatabaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ClickhouseGrantPrivilegeGrant { /** * The column to grant access to. Changing this property forces recreation of the resource. */ column?: string; /** * The database to grant access to. To set up proper dependencies please refer to this variable as a reference. Changing this property forces recreation of the resource. */ database: string; /** * The privileges to grant. For example: `INSERT`, `SELECT`, `CREATE TABLE`. A complete list is available in the [ClickHouse documentation](https://clickhouse.com/docs/en/sql-reference/statements/grant). Changing this property forces recreation of the resource. */ privilege?: string; /** * The table to grant access to. Changing this property forces recreation of the resource. */ table?: string; /** * Allow grantees to grant their privileges to other grantees. Changing this property forces recreation of the resource. */ withGrant?: boolean; } export interface ClickhouseGrantRoleGrant { /** * The roles to grant. To set up proper dependencies please refer to this variable as a reference. Changing this property forces recreation of the resource. */ role?: string; } export interface ClickhouseServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface ClickhouseTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface ClickhouseTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface ClickhouseUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface CmkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ConnectionPoolTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface DragonflyComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface DragonflyDragonfly { /** * Dragonfly password. */ password: string; /** * Dragonfly replica server URI. */ replicaUri: string; /** * Dragonfly slave server URIs. */ slaveUris: string[]; /** * Dragonfly server URIs. */ uris: string[]; } export interface DragonflyDragonflyUserConfig { /** * Evict entries when getting close to maxmemory limit. Default: `false`. */ cacheMode?: boolean; /** * Enum: `dfs`, `off`, `rdb`. When persistence is `rdb` or `dfs`, Dragonfly does RDB or DFS dumps every 10 minutes. Dumps are done according to the backup schedule for backup purposes. When persistence is `off`, no RDB/DFS dumps or backups are done, so data can be lost at any moment if the service is restarted for any reason, or if the service is powered off. Also, the service can't be forked. */ dragonflyPersistence?: string; /** * Require SSL to access Dragonfly. Default: `true`. */ dragonflySsl?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.DragonflyDragonflyUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.DragonflyDragonflyUserConfigMigration; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.DragonflyDragonflyUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.DragonflyDragonflyUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.DragonflyDragonflyUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface DragonflyDragonflyUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface DragonflyDragonflyUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface DragonflyDragonflyUserConfigPrivateAccess { /** * Allow clients to connect to dragonfly with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ dragonfly?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface DragonflyDragonflyUserConfigPrivatelinkAccess { /** * Enable dragonfly. */ dragonfly?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface DragonflyDragonflyUserConfigPublicAccess { /** * Allow clients to connect to dragonfly from the public internet for service nodes that are in a project VPC or another type of private network. */ dragonfly?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface DragonflyServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface DragonflyTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface DragonflyTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface FlinkApplicationDeploymentTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface FlinkApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface FlinkApplicationVersionSink { /** * The CREATE TABLE statement */ createTable: string; /** * The integration ID */ integrationId?: string; } export interface FlinkApplicationVersionSource { /** * The CREATE TABLE statement */ createTable: string; /** * The integration ID */ integrationId?: string; } export interface FlinkComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface FlinkFlink { /** * The host and port of a Flink server. */ hostPorts: string[]; } export interface FlinkFlinkUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Enable to upload Custom JARs for Flink applications. */ customCode?: boolean; /** * Enum: `1.16`, `1.19`, `1.20`, and newer. Flink major version. */ flinkVersion?: string; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.FlinkFlinkUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Task slots per node. For a 3 node plan, total number of task slots is 3x this value. Example: `1`. */ numberOfTaskSlots?: number; /** * Timeout in seconds used for all futures and blocking Pekko requests. Example: `10`. */ pekkoAskTimeoutS?: number; /** * Maximum size in bytes for messages exchanged between the JobManager and the TaskManagers. */ pekkoFramesizeB?: number; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.FlinkFlinkUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.FlinkFlinkUserConfigPublicAccess; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface FlinkFlinkUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface FlinkFlinkUserConfigPrivatelinkAccess { /** * Enable flink. */ flink?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface FlinkFlinkUserConfigPublicAccess { /** * Allow clients to connect to flink from the public internet for service nodes that are in a project VPC or another type of private network. */ flink?: boolean; } export interface FlinkJarApplicationApplicationVersion { /** * The creation timestamp of this entity in ISO 8601 format, always in UTC. */ createdAt: string; /** * The creator of this entity. */ createdBy: string; /** * Flink JarApplicationVersion FileInfo. */ fileInfos: outputs.FlinkJarApplicationApplicationVersionFileInfo[]; /** * ApplicationVersion ID. */ id: string; /** * Version number. */ version: number; } export interface FlinkJarApplicationApplicationVersionFileInfo { /** * sha256 of the file if known. */ fileSha256: string; /** * The size of the file in bytes. */ fileSize: number; /** * Indicates whether the uploaded .jar file has been verified by the system and deployment ready. The possible values are `FAILED`, `INITIAL` and `READY`. */ fileStatus: string; /** * The pre-signed url of the bucket where the .jar file is uploaded. Becomes null when the JarApplicationVersion is ready or failed. */ url: string; /** * In the case fileStatus is FAILED, the error code of the failure. The possible values are `1`, `2`, `3` and `4`. */ verifyErrorCode: number; /** * In the case fileStatus is FAILED, may contain details about the failure. */ verifyErrorMessage: string; } export interface FlinkJarApplicationCurrentDeployment { /** * The creation timestamp of this entity in ISO 8601 format, always in UTC. */ createdAt: string; /** * The creator of this entity. */ createdBy: string; /** * The fully qualified name of the entry class to pass during Flink job submission through the entryClass parameter. */ entryClass: string; /** * Error message describing what caused deployment to fail. */ errorMsg: string; /** * Deployment ID. */ id: string; /** * Job ID. */ jobId: string; /** * Job savepoint. */ lastSavepoint: string; /** * Reading of Flink parallel execution documentation is recommended before setting this value to other than 1. Please do not set this value higher than (total number of nodes x number*of*task_slots), or every new job created will fail. */ parallelism: number; /** * Arguments to pass during Flink job submission through the programArgsList parameter. */ programArgs: string[]; /** * Job savepoint. */ startingSavepoint: string; /** * Deployment status. The possible values are `CANCELED`, `CANCELLING`, `CANCELLING_REQUESTED`, `CREATED`, `DELETE_REQUESTED`, `DELETING`, `FAILED`, `FAILING`, `FINISHED`, `INITIALIZING`, `RECONCILING`, `RESTARTING`, `RUNNING`, `SAVING`, `SAVING_AND_STOP`, `SAVING_AND_STOP_REQUESTED` and `SUSPENDED`. */ status: string; /** * ApplicationVersion ID. */ versionId: string; } export interface FlinkJarApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface FlinkJarApplicationVersionFileInfo { /** * sha256 of the file if known. */ fileSha256: string; /** * The size of the file in bytes. */ fileSize: number; /** * Indicates whether the uploaded .jar file has been verified by the system and deployment ready. The possible values are `FAILED`, `INITIAL` and `READY`. */ fileStatus: string; /** * The pre-signed url of the bucket where the .jar file is uploaded. Becomes null when the JarApplicationVersion is ready or failed. */ url: string; /** * In the case fileStatus is FAILED, the error code of the failure. The possible values are `1`, `2` and `3`. */ verifyErrorCode: number; /** * In the case fileStatus is FAILED, may contain details about the failure. */ verifyErrorMessage: string; } export interface FlinkServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface FlinkTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface FlinkTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GcpOrgVpcPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface GcpPrivatelinkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface GetAccountAuthenticationSamlFieldMapping { /** * Field name for user email */ email?: string; /** * Field name for user's first name */ firstName?: string; /** * Field name for user's identity. This field must always exist in responses, and must be immutable and unique. Contents of this field are used to identify the user. Using user ID (such as unix user id) is highly recommended, as email address may change, requiring relinking user to Aiven user. */ identity?: string; /** * Field name for user's last name */ lastName?: string; /** * Field name for user's full name. If specified, firstName and lastName mappings are ignored */ realName?: string; } export interface GetAwsOrgVpcPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetAwsPrivatelinkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetAzureOrgVpcPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetAzurePrivatelinkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetBillingGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetClickhouseClickhouse { /** * ClickHouse server URIs. */ uris: string[]; } export interface GetClickhouseClickhouseUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Example: `3`. */ backupHour?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Example: `30`. */ backupMinute?: number; /** * Enum: `25.3`, `25.8`, `26.3`, and newer. ClickHouse major version. */ clickhouseVersion?: string; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetClickhouseClickhouseUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetClickhouseClickhouseUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetClickhouseClickhouseUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetClickhouseClickhouseUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * ClickHouse server settings, which can be found in the `system.server_settings` table */ serverSettings?: outputs.GetClickhouseClickhouseUserConfigServerSettings; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * ClickHouse session settings, which can be found in the `system.settings` table */ sessionSettings?: outputs.GetClickhouseClickhouseUserConfigSessionSettings; /** * Use static public IP addresses. */ staticIps?: boolean; /** * The percentage of free disk space required on local storage before data is moved to object storage. A value of 0.2 means data is moved when local storage has less than 20% free space. Default: `0.2`. */ tieredStorageMoveFactor?: number; } export interface GetClickhouseClickhouseUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetClickhouseClickhouseUserConfigPrivateAccess { /** * Allow clients to connect to clickhouse with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouse?: boolean; /** * Allow clients to connect to clickhouseArrowflight with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouseArrowflight?: boolean; /** * Allow clients to connect to clickhouseHttps with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouseHttps?: boolean; /** * Allow clients to connect to clickhouseMysql with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ clickhouseMysql?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface GetClickhouseClickhouseUserConfigPrivatelinkAccess { /** * Enable clickhouse. */ clickhouse?: boolean; /** * Enable clickhouse_arrowflight. */ clickhouseArrowflight?: boolean; /** * Enable clickhouse_https. */ clickhouseHttps?: boolean; /** * Enable clickhouse_mysql. */ clickhouseMysql?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetClickhouseClickhouseUserConfigPublicAccess { /** * Allow clients to connect to clickhouse from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouse?: boolean; /** * Allow clients to connect to clickhouseArrowflight from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouseArrowflight?: boolean; /** * Allow clients to connect to clickhouseHttps from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouseHttps?: boolean; /** * Allow clients to connect to clickhouseMysql from the public internet for service nodes that are in a project VPC or another type of private network. */ clickhouseMysql?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface GetClickhouseClickhouseUserConfigServerSettings { /** * Fraction of total server memory allocated to the vector similarity index cache. 0 disables the cache. Default is 0.07 (7% of server memory). Only effective on ClickHouse 25.8+. Default: `0.07`. */ vectorSimilarityIndexCacheSize?: number; } export interface GetClickhouseClickhouseUserConfigSessionSettings { /** * When set, ClickHouse applies backward-compatible behavior from the specified version. Automatically set to the previous version on major version upgrade. Set to null to disable compatibility mode once all incompatibilities have been resolved. Takes effect after the next service restart/upgrade. */ compatibility?: string; } export interface GetClickhouseComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetClickhouseDatabaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetClickhouseServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetClickhouseTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetClickhouseTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetClickhouseUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetCmkAccessorAwsTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetCmkAccessorAzureTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetCmkAccessorGcpTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetCmkAccessorOciTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetConnectionPoolTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetDragonflyComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetDragonflyDragonfly { /** * Dragonfly password. */ password: string; /** * Dragonfly replica server URI. */ replicaUri: string; /** * Dragonfly slave server URIs. */ slaveUris: string[]; /** * Dragonfly server URIs. */ uris: string[]; } export interface GetDragonflyDragonflyUserConfig { /** * Evict entries when getting close to maxmemory limit. Default: `false`. */ cacheMode?: boolean; /** * Enum: `dfs`, `off`, `rdb`. When persistence is `rdb` or `dfs`, Dragonfly does RDB or DFS dumps every 10 minutes. Dumps are done according to the backup schedule for backup purposes. When persistence is `off`, no RDB/DFS dumps or backups are done, so data can be lost at any moment if the service is restarted for any reason, or if the service is powered off. Also, the service can't be forked. */ dragonflyPersistence?: string; /** * Require SSL to access Dragonfly. Default: `true`. */ dragonflySsl?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetDragonflyDragonflyUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.GetDragonflyDragonflyUserConfigMigration; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetDragonflyDragonflyUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetDragonflyDragonflyUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetDragonflyDragonflyUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface GetDragonflyDragonflyUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetDragonflyDragonflyUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface GetDragonflyDragonflyUserConfigPrivateAccess { /** * Allow clients to connect to dragonfly with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ dragonfly?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface GetDragonflyDragonflyUserConfigPrivatelinkAccess { /** * Enable dragonfly. */ dragonfly?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetDragonflyDragonflyUserConfigPublicAccess { /** * Allow clients to connect to dragonfly from the public internet for service nodes that are in a project VPC or another type of private network. */ dragonfly?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface GetDragonflyServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetDragonflyTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetDragonflyTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetFlinkApplicationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetFlinkApplicationVersionSink { /** * The CREATE TABLE statement */ createTable: string; /** * The integration ID */ integrationId?: string; } export interface GetFlinkApplicationVersionSource { /** * The CREATE TABLE statement */ createTable: string; /** * The integration ID */ integrationId?: string; } export interface GetFlinkComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetFlinkFlink { /** * The host and port of a Flink server. */ hostPorts: string[]; } export interface GetFlinkFlinkUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Enable to upload Custom JARs for Flink applications. */ customCode?: boolean; /** * Enum: `1.16`, `1.19`, `1.20`, and newer. Flink major version. */ flinkVersion?: string; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetFlinkFlinkUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Task slots per node. For a 3 node plan, total number of task slots is 3x this value. Example: `1`. */ numberOfTaskSlots?: number; /** * Timeout in seconds used for all futures and blocking Pekko requests. Example: `10`. */ pekkoAskTimeoutS?: number; /** * Maximum size in bytes for messages exchanged between the JobManager and the TaskManagers. */ pekkoFramesizeB?: number; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetFlinkFlinkUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetFlinkFlinkUserConfigPublicAccess; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface GetFlinkFlinkUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetFlinkFlinkUserConfigPrivatelinkAccess { /** * Enable flink. */ flink?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetFlinkFlinkUserConfigPublicAccess { /** * Allow clients to connect to flink from the public internet for service nodes that are in a project VPC or another type of private network. */ flink?: boolean; } export interface GetFlinkServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetFlinkTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetFlinkTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetGcpOrgVpcPeeringConnectionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetGcpPrivatelinkTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetGrafanaComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetGrafanaGrafana { /** * Grafana server URIs. */ uris: string[]; } export interface GetGrafanaGrafanaUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Setting has no effect with Grafana 11 and onward. Enable or disable Grafana legacy alerting functionality. This should not be enabled with unified_alerting_enabled. */ alertingEnabled?: boolean; /** * Enum: `alerting`, `keepState`. Default error or timeout setting for new alerting rules. */ alertingErrorOrTimeout?: string; /** * Max number of alert annotations that Grafana stores. 0 (default) keeps all alert annotations. Example: `0`. */ alertingMaxAnnotationsToKeep?: number; /** * Enum: `alerting`, `keepState`, `noData`, `ok`. Default value for 'no data or null values' for new alerting rules. */ alertingNodataOrNullvalues?: string; /** * Allow embedding Grafana dashboards with iframe/frame/object/embed tags. Disabled by default to limit impact of clickjacking. */ allowEmbedding?: boolean; /** * Azure AD OAuth integration */ authAzuread?: outputs.GetGrafanaGrafanaUserConfigAuthAzuread; /** * Enable or disable basic authentication form, used by Grafana built-in login. */ authBasicEnabled?: boolean; /** * Generic OAuth integration */ authGenericOauth?: outputs.GetGrafanaGrafanaUserConfigAuthGenericOauth; /** * Github Auth integration */ authGithub?: outputs.GetGrafanaGrafanaUserConfigAuthGithub; /** * GitLab Auth integration */ authGitlab?: outputs.GetGrafanaGrafanaUserConfigAuthGitlab; /** * Google Auth integration */ authGoogle?: outputs.GetGrafanaGrafanaUserConfigAuthGoogle; /** * Enum: `lax`, `none`, `strict`. Cookie SameSite attribute: `strict` prevents sending cookie for cross-site requests, effectively disabling direct linking from other sites to Grafana. `lax` is the default value. */ cookieSamesite?: string; /** * Serve the web frontend using a custom CNAME pointing to the Aiven DNS name. When you set a custom domain for a service deployed in a VPC, the service certificate is only created for the public-* hostname and the custom domain. Example: `grafana.example.org`. */ customDomain?: string; /** * Enable browsing of dashboards in grid (pictures) mode. This feature is new in Grafana 9 and is quite resource intensive. It may cause low-end plans to work more slowly while the dashboard previews are rendering. */ dashboardPreviewsEnabled?: boolean; /** * Enable use of the Grafana Scenes Library as the dashboard engine. i.e. the `dashboardScene` feature flag. Upstream blog post at https://grafana.com/blog/2024/10/31/grafana-dashboards-are-now-powered-by-scenes-big-changes-same-ui/. */ dashboardScenesEnabled?: boolean; /** * Signed sequence of decimal numbers, followed by a unit suffix (ms, s, m, h, d), e.g. 30s, 1h. Example: `5s`. */ dashboardsMinRefreshInterval?: string; /** * Dashboard versions to keep per dashboard. Example: `20`. */ dashboardsVersionsToKeep?: number; /** * Send `X-Grafana-User` header to data source. */ dataproxySendUserHeader?: boolean; /** * Timeout for data proxy requests in seconds. Example: `30`. */ dataproxyTimeout?: number; /** * Grafana date format specifications */ dateFormats?: outputs.GetGrafanaGrafanaUserConfigDateFormats; /** * Set to true to disable gravatar. Defaults to false (gravatar is enabled). */ disableGravatar?: boolean; /** * Editors can manage folders, teams and dashboards created by them. */ editorsCanAdmin?: boolean; /** * External image store settings */ externalImageStorage?: outputs.GetGrafanaGrafanaUserConfigExternalImageStorage; /** * Google Analytics ID. Example: `UA-123456-4`. */ googleAnalyticsUaId?: string; /** * Enum: `11`, and newer. Grafana major version. */ grafanaVersion?: string; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetGrafanaGrafanaUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Enable Grafana's /metrics endpoint. */ metricsEnabled?: boolean; /** * Enforce user lookup based on email instead of the unique ID provided by the IdP. This setup introduces significant security risks, such as potential phishing, spoofing, and other data breaches. */ oauthAllowInsecureEmailLookup?: boolean; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetGrafanaGrafanaUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetGrafanaGrafanaUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetGrafanaGrafanaUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * SMTP server settings */ smtpServer?: outputs.GetGrafanaGrafanaUserConfigSmtpServer; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Enable or disable Grafana unified alerting functionality. By default this is enabled and any legacy alerts will be migrated on upgrade to Grafana 9+. To stay on legacy alerting, set unifiedAlertingEnabled to false and alertingEnabled to true. See https://grafana.com/docs/grafana/latest/alerting/ for more details. */ unifiedAlertingEnabled?: boolean; /** * Auto-assign new users on signup to main organization. Defaults to false. */ userAutoAssignOrg?: boolean; /** * Enum: `Admin`, `Editor`, `Viewer`. Set role for new signups. Defaults to Viewer. */ userAutoAssignOrgRole?: string; /** * Users with view-only permission can edit but not save dashboards. */ viewersCanEdit?: boolean; /** * Setting to enable/disable Write-Ahead Logging. The default value is false (disabled). */ wal?: boolean; } export interface GetGrafanaGrafanaUserConfigAuthAzuread { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Allowed domains. */ allowedDomains?: string[]; /** * Require users to belong to one of given groups. */ allowedGroups?: string[]; /** * Authorization URL. Example: `https://login.microsoftonline.com//oauth2/v2.0/authorize`. */ authUrl: string; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * Token URL. Example: `https://login.microsoftonline.com//oauth2/v2.0/token`. */ tokenUrl: string; } export interface GetGrafanaGrafanaUserConfigAuthGenericOauth { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Allowed domains. */ allowedDomains?: string[]; /** * Require user to be member of one of the listed organizations. */ allowedOrganizations?: string[]; /** * API URL. Example: `https://yourprovider.com/api`. */ apiUrl: string; /** * Authorization URL. Example: `https://yourprovider.com/oauth/authorize`. */ authUrl: string; /** * Allow users to bypass the login screen and automatically log in. */ autoLogin?: boolean; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * Name of the OAuth integration. Example: `My authentication`. */ name?: string; /** * OAuth scopes. */ scopes?: string[]; /** * Token URL. Example: `https://yourprovider.com/oauth/token`. */ tokenUrl: string; /** * Set to true to use refresh token and check access token expiration. */ useRefreshToken?: boolean; } export interface GetGrafanaGrafanaUserConfigAuthGithub { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Require users to belong to one of given organizations. */ allowedOrganizations?: string[]; /** * Allow users to bypass the login screen and automatically log in. */ autoLogin?: boolean; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * Stop automatically syncing user roles. */ skipOrgRoleSync?: boolean; /** * Require users to belong to one of given team IDs. */ teamIds?: number[]; } export interface GetGrafanaGrafanaUserConfigAuthGitlab { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Require users to belong to one of given groups. */ allowedGroups: string[]; /** * This only needs to be set when using self hosted GitLab. Example: `https://gitlab.com/api/v4`. */ apiUrl?: string; /** * This only needs to be set when using self hosted GitLab. Example: `https://gitlab.com/oauth/authorize`. */ authUrl?: string; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * This only needs to be set when using self hosted GitLab. Example: `https://gitlab.com/oauth/token`. */ tokenUrl?: string; } export interface GetGrafanaGrafanaUserConfigAuthGoogle { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Domains allowed to sign-in to this Grafana. */ allowedDomains: string[]; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; } export interface GetGrafanaGrafanaUserConfigDateFormats { /** * Default time zone for user preferences. Value `browser` uses browser local time zone. Example: `Europe/Helsinki`. */ defaultTimezone?: string; /** * Moment.js style format string for cases where full date is shown. Example: `YYYY MM DD`. */ fullDate?: string; /** * Moment.js style format string used when a time requiring day accuracy is shown. Example: `MM/DD`. */ intervalDay?: string; /** * Moment.js style format string used when a time requiring hour accuracy is shown. Example: `MM/DD HH:mm`. */ intervalHour?: string; /** * Moment.js style format string used when a time requiring minute accuracy is shown. Example: `HH:mm`. */ intervalMinute?: string; /** * Moment.js style format string used when a time requiring month accuracy is shown. Example: `YYYY-MM`. */ intervalMonth?: string; /** * Moment.js style format string used when a time requiring second accuracy is shown. Example: `HH:mm:ss`. */ intervalSecond?: string; /** * Moment.js style format string used when a time requiring year accuracy is shown. Example: `YYYY`. */ intervalYear?: string; } export interface GetGrafanaGrafanaUserConfigExternalImageStorage { /** * S3 access key. Requires permissions to the S3 bucket for the s3:PutObject and s3:PutObjectAcl actions. Example: `AAAAAAAAAAAAAAAAAAA`. */ accessKey: string; /** * Bucket URL for S3. Example: `https://grafana.s3-ap-southeast-2.amazonaws.com/`. */ bucketUrl: string; /** * Enum: `s3`. External image store provider. */ provider: string; /** * S3 secret key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretKey: string; } export interface GetGrafanaGrafanaUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetGrafanaGrafanaUserConfigPrivateAccess { /** * Allow clients to connect to grafana with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ grafana?: boolean; } export interface GetGrafanaGrafanaUserConfigPrivatelinkAccess { /** * Enable grafana. */ grafana?: boolean; } export interface GetGrafanaGrafanaUserConfigPublicAccess { /** * Allow clients to connect to grafana from the public internet for service nodes that are in a project VPC or another type of private network. */ grafana?: boolean; } export interface GetGrafanaGrafanaUserConfigSmtpServer { /** * Address used for sending emails. Example: `yourgrafanauser@yourdomain.example.com`. */ fromAddress: string; /** * Name used in outgoing emails, defaults to Grafana. */ fromName?: string; /** * Server hostname or IP. Example: `smtp.example.com`. */ host: string; /** * Password for SMTP authentication. Example: `ein0eemeev5eeth3Ahfu`. */ password?: string; /** * SMTP server port. Example: `25`. */ port: number; /** * Skip verifying server certificate. Defaults to false. */ skipVerify?: boolean; /** * Enum: `MandatoryStartTLS`, `NoStartTLS`, `OpportunisticStartTLS`. Either OpportunisticStartTLS, MandatoryStartTLS or NoStartTLS. Default is OpportunisticStartTLS. */ starttlsPolicy?: string; /** * Username for SMTP authentication. Example: `smtpuser`. */ username?: string; } export interface GetGrafanaServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetGrafanaTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetGrafanaTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetKafkaAclTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetKafkaComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetKafkaConnectComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetKafkaConnectKafkaConnectUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Allow-list of HTTPS URLs used to validate GCP credentialSource requests for Kafka Connect. */ gcpAuthAllowedUrls?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetKafkaConnectKafkaConnectUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Kafka Connect configuration values */ kafkaConnect?: outputs.GetKafkaConnectKafkaConnectUserConfigKafkaConnect; /** * The plugin selected by the user */ pluginVersions?: outputs.GetKafkaConnectKafkaConnectUserConfigPluginVersion[]; /** * List of preferred zone IDs for service node placement. Nodes will be placed in these zones when available. If a specified zone is unavailable (e.g., due to capacity constraints), nodes will be placed in other available zones to maintain the configured number of zones for availability. Invalid zone IDs are rejected at configuration time. Zone IDs are cloud-specific: AWS uses zone IDs like `euc1-az1`, GCP uses zone names like `europe-west1-a`, and Azure uses `location/zone` format like `germanywestcentral/1`. If singleZone is enabled with an availability_zone, that setting takes precedence over preferred_zones. Changes take effect on next node recreation (e.g., maintenance or plan change). For eligible plans, nodes outside preferred zones are automatically rebalanced once per day. */ preferredZones?: string[]; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetKafkaConnectKafkaConnectUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetKafkaConnectKafkaConnectUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetKafkaConnectKafkaConnectUserConfigPublicAccess; /** * List of allowed URLs for SASL OAUTHBEARER authentication. Only HTTPS URLs are allowed for security reasons. */ saslOauthbearerAllowedUrls?: string[]; /** * Configure external secret providers in order to reference external secrets in connector configuration. Currently Hashicorp Vault (provider: vault, auth_method: token) and AWS Secrets Manager (provider: aws, auth_method: credentials) are supported. Secrets can be referenced in connector config with ${::} */ secretProviders?: outputs.GetKafkaConnectKafkaConnectUserConfigSecretProvider[]; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface GetKafkaConnectKafkaConnectUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetKafkaConnectKafkaConnectUserConfigKafkaConnect { /** * Enum: `All`, `None`. Defines what client configurations can be overridden by the connector. Default is None. */ connectorClientConfigOverridePolicy?: string; /** * Enum: `earliest`, `latest`. What to do when there is no initial offset in Kafka or if the current offset does not exist any more on the server. Default is earliest. */ consumerAutoOffsetReset?: string; /** * Records are fetched in batches by the consumer, and if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that the consumer can make progress. As such, this is not a absolute maximum. */ consumerFetchMaxBytes?: number; /** * Enum: `readCommitted`, `readUncommitted`. Transaction read isolation level. readUncommitted is the default, but readCommitted can be used if consume-exactly-once behavior is desired. */ consumerIsolationLevel?: string; /** * Records are fetched in batches by the consumer.If the first record batch in the first non-empty partition of the fetch is larger than this limit, the batch will still be returned to ensure that the consumer can make progress. */ consumerMaxPartitionFetchBytes?: number; /** * The maximum delay in milliseconds between invocations of poll() when using consumer group management (defaults to 300000). */ consumerMaxPollIntervalMs?: number; /** * The maximum number of records returned in a single call to poll() (defaults to 500). */ consumerMaxPollRecords?: number; /** * The interval at which to try committing offsets for tasks (defaults to 60000). */ offsetFlushIntervalMs?: number; /** * Maximum number of milliseconds to wait for records to flush and partition offset data to be committed to offset storage before cancelling the process and restoring the offset data to be committed in a future attempt (defaults to 5000). */ offsetFlushTimeoutMs?: number; /** * When enabled, connectors will automatically resolve IPv6 addresses from external server names configured with dual-stack. Default: `false`. */ preferIpv6AddressEnable?: boolean; /** * This setting gives the upper bound of the batch size to be sent. If there are fewer than this many bytes accumulated for this partition, the producer will `linger` for the linger.ms time waiting for more records to show up. A batch size of zero will disable batching entirely (defaults to 16384). */ producerBatchSize?: number; /** * The total bytes of memory the producer can use to buffer records waiting to be sent to the broker (defaults to 33554432). */ producerBufferMemory?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * This setting gives the upper bound on the delay for batching: once there is batch.size worth of records for a partition it will be sent immediately regardless of this setting, however if there are fewer than this many bytes accumulated for this partition the producer will `linger` for the specified time waiting for more records to show up. Defaults to 0. */ producerLingerMs?: number; /** * This setting will limit the number of record batches the producer will send in a single request to avoid sending huge requests. */ producerMaxRequestSize?: number; /** * The maximum delay that is scheduled in order to wait for the return of one or more departed workers before rebalancing and reassigning their connectors and tasks to the group. During this period the connectors and tasks of the departed workers remain unassigned. Defaults to 5 minutes. */ scheduledRebalanceMaxDelayMs?: number; /** * The timeout in milliseconds used to detect failures when using Kafka’s group management facilities (defaults to 10000). */ sessionTimeoutMs?: number; } export interface GetKafkaConnectKafkaConnectUserConfigPluginVersion { /** * The name of the plugin. Example: `debezium-connector`. */ pluginName: string; /** * The version of the plugin. Example: `2.5.0`. */ version: string; } export interface GetKafkaConnectKafkaConnectUserConfigPrivateAccess { /** * Allow clients to connect to kafkaConnect with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafkaConnect?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface GetKafkaConnectKafkaConnectUserConfigPrivatelinkAccess { /** * Enable jolokia. */ jolokia?: boolean; /** * Enable kafka_connect. */ kafkaConnect?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetKafkaConnectKafkaConnectUserConfigPublicAccess { /** * Allow clients to connect to kafkaConnect from the public internet for service nodes that are in a project VPC or another type of private network. */ kafkaConnect?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface GetKafkaConnectKafkaConnectUserConfigSecretProvider { /** * AWS secret provider configuration */ aws?: outputs.GetKafkaConnectKafkaConnectUserConfigSecretProviderAws; /** * Azure KeyVault secret provider configuration */ azure?: outputs.GetKafkaConnectKafkaConnectUserConfigSecretProviderAzure; /** * ENV secret provider configuration */ env?: outputs.GetKafkaConnectKafkaConnectUserConfigSecretProviderEnv; /** * Name of the secret provider. Used to reference secrets in connector config. */ name: string; /** * Vault secret provider configuration */ vault?: outputs.GetKafkaConnectKafkaConnectUserConfigSecretProviderVault; } export interface GetKafkaConnectKafkaConnectUserConfigSecretProviderAws { /** * Access key used to authenticate with aws. */ accessKey?: string; /** * Enum: `credentials`. Auth method of the vault secret provider. */ authMethod: string; /** * Region used to lookup secrets with AWS SecretManager. */ region: string; /** * Secret key used to authenticate with aws. */ secretKey?: string; } export interface GetKafkaConnectKafkaConnectUserConfigSecretProviderAzure { /** * Enum: `credentials`. Auth method of the Azure KeyVault secret provider. */ authMethod: string; /** * Azure client ID for the service principal. */ clientId?: string; /** * Azure client secret for the service principal. */ secret?: string; /** * Azure tenant ID for the service principal. */ tenantId?: string; } export interface GetKafkaConnectKafkaConnectUserConfigSecretProviderEnv { /** * Key/value map of secrets for ENV secret provider. */ secrets: { [key: string]: string; }; } export interface GetKafkaConnectKafkaConnectUserConfigSecretProviderVault { /** * Address of the Vault server. */ address: string; /** * Enum: `token`. Auth method of the vault secret provider. */ authMethod: string; /** * Enum: `1`, `2`, and newer. KV Secrets Engine version of the Vault server instance. */ engineVersion?: number; /** * Prefix path depth of the secrets Engine. Default is 1. If the secrets engine path has more than one segment it has to be increased to the number of segments. */ prefixPathDepth?: number; /** * PEM encoded certificate of the Vault server. Required if the vault server uses a self-signed certificate. */ serverPem?: string; /** * Token used to authenticate with vault and auth method `token`. */ token?: string; } export interface GetKafkaConnectServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetKafkaConnectTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetKafkaConnectTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetKafkaConnectorTask { /** * The name of the related connector. */ connector: string; /** * The task ID of the task. */ task: number; } export interface GetKafkaKafka { /** * The Kafka client certificate. */ accessCert: string; /** * The Kafka client certificate key. */ accessKey: string; /** * The Kafka Connect URI. */ connectUri: string; /** * The Kafka REST URI. */ restUri: string; /** * The Schema Registry URI. */ schemaRegistryUri: string; /** * Kafka server URIs. */ uris: string[]; } export interface GetKafkaKafkaUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Allow access to read Kafka topic messages in the Aiven Console and REST API. */ aivenKafkaTopicMessages?: boolean; /** * Enum: `12`, `24`, `3`, `4`, `6`, `8`. Interval in hours between automatic backups. Minimum value is 3 hours. Must be a divisor of 24 (3, 4, 6, 8, 12, 24). (Applicable to ACU plans only). */ backupIntervalHours?: number; /** * Number of days to retain automatic backups. Backups older than this value will be automatically deleted. (Applicable to ACU plans only). Example: `7`. */ backupRetentionDays?: number; /** * Serve the web frontend using a custom CNAME pointing to the Aiven DNS name. When you set a custom domain for a service deployed in a VPC, the service certificate is only created for the public-* hostname and the custom domain. Example: `grafana.example.org`. */ customDomain?: string; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * Enable follower fetching */ followerFetching?: outputs.GetKafkaKafkaUserConfigFollowerFetching; /** * Allow-list of HTTPS URLs used to validate GCP credentialSource requests for Kafka Connect. */ gcpAuthAllowedUrls?: string[]; /** * Inkless configuration values */ inkless?: outputs.GetKafkaKafkaUserConfigInkless; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetKafkaKafkaUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Kafka broker configuration values */ kafka?: outputs.GetKafkaKafkaUserConfigKafka; /** * Kafka authentication methods */ kafkaAuthenticationMethods?: outputs.GetKafkaKafkaUserConfigKafkaAuthenticationMethods; /** * Enable Kafka Connect service. Default: `false`. */ kafkaConnect?: boolean; /** * Kafka Connect configuration values */ kafkaConnectConfig?: outputs.GetKafkaKafkaUserConfigKafkaConnectConfig; /** * The plugin selected by the user */ kafkaConnectPluginVersions?: outputs.GetKafkaKafkaUserConfigKafkaConnectPluginVersion[]; /** * Configure external secret providers in order to reference external secrets in connector configuration. Currently Hashicorp Vault (provider: vault, auth_method: token) and AWS Secrets Manager (provider: aws, auth_method: credentials) are supported. Secrets can be referenced in connector config with ${::} */ kafkaConnectSecretProviders?: outputs.GetKafkaKafkaUserConfigKafkaConnectSecretProvider[]; /** * Kafka Diskless configuration values */ kafkaDiskless?: outputs.GetKafkaKafkaUserConfigKafkaDiskless; /** * Enable Kafka-REST service. Default: `false`. */ kafkaRest?: boolean; /** * Enable authorization in Kafka-REST service. */ kafkaRestAuthorization?: boolean; /** * Kafka REST configuration */ kafkaRestConfig?: outputs.GetKafkaKafkaUserConfigKafkaRestConfig; /** * Kafka SASL mechanisms */ kafkaSaslMechanisms?: outputs.GetKafkaKafkaUserConfigKafkaSaslMechanisms; /** * Enum: `3.1`, `3.2`, `3.3`, `3.4`, `3.5`, `3.6`, `3.7`, `3.8`, `3.9`, `4.0`, `4.1`, `4.2`, and newer. Kafka major version. */ kafkaVersion?: string; /** * Pin a specific installed Karapace version on this service. Leave null/unset to auto-follow the newest installed version. */ karapaceVersion?: string; /** * Use a Let's Encrypt certificate authority (CA) for Kafka SASL authentication. (Default: False). */ letsencryptSasl?: boolean; /** * Use a Let's Encrypt certificate authority (CA) for Kafka SASL authentication via Privatelink. (Default: False). */ letsencryptSaslPrivatelink?: boolean; /** * List of preferred zone IDs for service node placement. Nodes will be placed in these zones when available. If a specified zone is unavailable (e.g., due to capacity constraints), nodes will be placed in other available zones to maintain the configured number of zones for availability. Invalid zone IDs are rejected at configuration time. Zone IDs are cloud-specific: AWS uses zone IDs like `euc1-az1`, GCP uses zone names like `europe-west1-a`, and Azure uses `location/zone` format like `germanywestcentral/1`. If singleZone is enabled with an availability_zone, that setting takes precedence over preferred_zones. Changes take effect on next node recreation (e.g., maintenance or plan change). For eligible plans, nodes outside preferred zones are automatically rebalanced once per day. */ preferredZones?: string[]; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetKafkaKafkaUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetKafkaKafkaUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetKafkaKafkaUserConfigPublicAccess; /** * List of allowed URLs for SASL OAUTHBEARER authentication. Only HTTPS URLs are allowed for security reasons. */ saslOauthbearerAllowedUrls?: string[]; /** * Enable Schema-Registry service. Default: `false`. */ schemaRegistry?: boolean; /** * Schema Registry configuration */ schemaRegistryConfig?: outputs.GetKafkaKafkaUserConfigSchemaRegistryConfig; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Single-zone configuration */ singleZone?: outputs.GetKafkaKafkaUserConfigSingleZone; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Tiered storage configuration */ tieredStorage?: outputs.GetKafkaKafkaUserConfigTieredStorage; } export interface GetKafkaKafkaUserConfigFollowerFetching { /** * Whether to enable the follower fetching functionality. */ enabled?: boolean; } export interface GetKafkaKafkaUserConfigInkless { /** * Whether to enable the Inkless functionality. */ enabled: boolean; } export interface GetKafkaKafkaUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetKafkaKafkaUserConfigKafka { /** * Enable Kafka audit logging by providing this object. Removing it disables the feature. Enabling, updating, or disabling audit logging causes a rolling restart of all Kafka brokers */ auditLog?: outputs.GetKafkaKafkaUserConfigKafkaAuditLog; /** * Enable auto-creation of topics. (Default: false). */ autoCreateTopicsEnable?: boolean; /** * Enum: `gzip`, `lz4`, `producer`, `snappy`, `uncompressed`, `zstd`. Specify the final compression type for a given topic. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `uncompressed` which is equivalent to no compression; and `producer` which means retain the original compression codec set by the producer.(Default: producer). */ compressionType?: string; /** * Idle connections timeout: the server socket processor threads close the connections that idle for longer than this. (Default: 600000 ms (10 minutes)). Example: `540000`. */ connectionsMaxIdleMs?: number; /** * Replication factor for auto-created topics (Default: 3). */ defaultReplicationFactor?: number; /** * Enum: `classic`, `classic,consumer`, `classic,consumer,share`, `classic,consumer,share,streams`, `classic,consumer,streams`, `classic,share`, `classic,streams`. The enabled consumer group rebalance protocols. Use consumer, classic, share, streams to enable Kafka share groups. */ groupCoordinatorRebalanceProtocols?: string; /** * The amount of time, in milliseconds, the group coordinator will wait for more consumers to join a new group before performing the first rebalance. A longer delay means potentially fewer rebalances, but increases the time until processing begins. The default value for this is 3 seconds. During development and testing it might be desirable to set this to 0 in order to not delay test execution time. (Default: 3000 ms (3 seconds)). Example: `3000`. */ groupInitialRebalanceDelayMs?: number; /** * The maximum allowed session timeout for registered consumers. Longer timeouts give consumers more time to process messages in between heartbeats at the cost of a longer time to detect failures. Default: 1800000 ms (30 minutes). */ groupMaxSessionTimeoutMs?: number; /** * The minimum allowed session timeout for registered consumers. Longer timeouts give consumers more time to process messages in between heartbeats at the cost of a longer time to detect failures. (Default: 6000 ms (6 seconds)). Example: `6000`. */ groupMinSessionTimeoutMs?: number; /** * The maximum delivery attempts for a share-group record. Example: `5`. */ groupShareDeliveryCountLimit?: number; /** * The heartbeat interval used by share group members. Example: `5000`. */ groupShareHeartbeatIntervalMs?: number; /** * The maximum number of share groups allowed on the broker. */ groupShareMaxGroups?: number; /** * The maximum heartbeat interval allowed for share group members. Example: `15000`. */ groupShareMaxHeartbeatIntervalMs?: number; /** * The maximum record lock duration allowed for share groups. Example: `60000`. */ groupShareMaxRecordLockDurationMs?: number; /** * The maximum session timeout allowed for share group members. Example: `60000`. */ groupShareMaxSessionTimeoutMs?: number; /** * The maximum number of members allowed in a share group. Example: `200`. */ groupShareMaxSize?: number; /** * The minimum heartbeat interval allowed for share group members. Example: `5000`. */ groupShareMinHeartbeatIntervalMs?: number; /** * The minimum record lock duration allowed for share groups. Example: `15000`. */ groupShareMinRecordLockDurationMs?: number; /** * The minimum session timeout allowed for share group members. Example: `45000`. */ groupShareMinSessionTimeoutMs?: number; /** * The maximum number of record locks allowed per share group partition. Example: `2000`. */ groupSharePartitionMaxRecordLocks?: number; /** * The duration for which a fetched share-group record is locked. Example: `30000`. */ groupShareRecordLockDurationMs?: number; /** * The timeout used to detect share group member failures. Example: `45000`. */ groupShareSessionTimeoutMs?: number; /** * How long are delete records retained? (Default: 86400000 (1 day)). */ logCleanerDeleteRetentionMs?: number; /** * The maximum amount of time message will remain uncompacted. Only applicable for logs that are being compacted. (Default: 9223372036854775807 ms (Long.MAX_VALUE)). */ logCleanerMaxCompactionLagMs?: number; /** * Controls log compactor frequency. Larger value means more frequent compactions but also more space wasted for logs. Consider setting log.cleaner.max.compaction.lag.ms to enforce compactions sooner, instead of setting a very high value for this option. (Default: 0.5). Example: `0.5`. */ logCleanerMinCleanableRatio?: number; /** * The minimum time a message will remain uncompacted in the log. Only applicable for logs that are being compacted. (Default: 0 ms). */ logCleanerMinCompactionLagMs?: number; /** * Enum: `compact`, `compact,delete`, `delete`. The default cleanup policy for segments beyond the retention window (Default: delete). */ logCleanupPolicy?: string; /** * The number of messages accumulated on a log partition before messages are flushed to disk (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logFlushIntervalMessages?: number; /** * The maximum time in ms that a message in any topic is kept in memory (page-cache) before flushed to disk. If not set, the value in log.flush.scheduler.interval.ms is used (Default: null). */ logFlushIntervalMs?: number; /** * The interval with which Kafka adds an entry to the offset index (Default: 4096 bytes (4 kibibytes)). Example: `4096`. */ logIndexIntervalBytes?: number; /** * The maximum size in bytes of the offset index (Default: 10485760 (10 mebibytes)). */ logIndexSizeMaxBytes?: number; /** * The maximum size of local log segments that can grow for a partition before it gets eligible for deletion. If set to -2, the value of log.retention.bytes is used. The effective value should always be less than or equal to log.retention.bytes value. (Default: -2). */ logLocalRetentionBytes?: number; /** * The number of milliseconds to keep the local log segments before it gets eligible for deletion. If set to -2, the value of log.retention.ms is used. The effective value should always be less than or equal to log.retention.ms value. (Default: -2). */ logLocalRetentionMs?: number; /** * This configuration controls whether down-conversion of message formats is enabled to satisfy consume requests. (Default: true). */ logMessageDownconversionEnable?: boolean; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps later than the broker's timestamp. (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logMessageTimestampAfterMaxMs?: number; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps earlier than the broker's timestamp. (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logMessageTimestampBeforeMaxMs?: number; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logMessageTimestampDifferenceMaxMs?: number; /** * Enum: `CreateTime`, `LogAppendTime`. Define whether the timestamp in the message is message create time or log append time. (Default: CreateTime). */ logMessageTimestampType?: string; /** * Should pre allocate file when create new segment? (Default: false). */ logPreallocate?: boolean; /** * The maximum size of the log before deleting messages (Default: -1). */ logRetentionBytes?: number; /** * The number of hours to keep a log file before deleting it. Use -1 for unlimited retention or 1 or higher. Setting 0 is invalid and prevents Kafka from starting. (Default: 168 hours, or 1 week). */ logRetentionHours?: number; /** * The number of milliseconds to keep a log file before deleting it (in milliseconds), If not set, the value in log.retention.minutes is used. If set to -1, no time limit is applied. (Default: null, log.retention.hours applies). */ logRetentionMs?: number; /** * The maximum jitter to subtract from logRollTimeMillis (in milliseconds). If not set, the value in log.roll.jitter.hours is used (Default: null). */ logRollJitterMs?: number; /** * The maximum time before a new log segment is rolled out (in milliseconds). (Default: null, log.roll.hours applies (Default: 168, 7 days)). */ logRollMs?: number; /** * The maximum size of a single log file (Default: 1073741824 bytes (1 gibibyte)). */ logSegmentBytes?: number; /** * The amount of time to wait before deleting a file from the filesystem (Default: 60000 ms (1 minute)). Example: `60000`. */ logSegmentDeleteDelayMs?: number; /** * The maximum number of connections allowed from each ip address (Default: 2147483647). */ maxConnectionsPerIp?: number; /** * The maximum number of incremental fetch sessions that the broker will maintain. (Default: 1000). Example: `1000`. */ maxIncrementalFetchSessionCacheSlots?: number; /** * The maximum size of message that the server can receive. (Default: 1048588 bytes (1 mebibyte + 12 bytes)). */ messageMaxBytes?: number; /** * When a producer sets acks to `all` (or `-1`), min.insync.replicas specifies the minimum number of replicas that must acknowledge a write for the write to be considered successful. (Default: 1). Example: `1`. */ minInsyncReplicas?: number; /** * Number of partitions for auto-created topics (Default: 1). */ numPartitions?: number; /** * Log retention window in minutes for offsets topic (Default: 10080 minutes (7 days)). Example: `10080`. */ offsetsRetentionMinutes?: number; /** * The purge interval (in number of requests) of the producer request purgatory (Default: 1000). */ producerPurgatoryPurgeIntervalRequests?: number; /** * The number of bytes of messages to attempt to fetch for each partition . This is not an absolute maximum, if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that progress can be made. (Default: 1048576 bytes (1 mebibytes)). */ replicaFetchMaxBytes?: number; /** * Maximum bytes expected for the entire fetch response. Records are fetched in batches, and if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that progress can be made. As such, this is not an absolute maximum. (Default: 10485760 bytes (10 mebibytes)). */ replicaFetchResponseMaxBytes?: number; /** * The (optional) comma-delimited setting for the broker to use to verify that the JWT was issued for one of the expected audiences. (Default: null). */ saslOauthbearerExpectedAudience?: string; /** * Optional setting for the broker to use to verify that the JWT was created by the expected issuer.(Default: null). */ saslOauthbearerExpectedIssuer?: string; /** * OIDC JWKS endpoint URL. By setting this the SASL SSL OAuth2/OIDC authentication is enabled. See also other options for SASL OAuth2/OIDC. (Default: null). */ saslOauthbearerJwksEndpointUrl?: string; /** * Name of the scope from which to extract the subject claim from the JWT.(Default: sub). */ saslOauthbearerSubClaimName?: string; /** * The maximum number of bytes in a socket request (Default: 104857600 bytes). */ socketRequestMaxBytes?: number; /** * Enable verification that checks that the partition has been added to the transaction before writing transactional records to the partition. (Default: true). */ transactionPartitionVerificationEnable?: boolean; /** * The interval at which to remove transactions that have expired due to transactional.id.expiration.ms passing (Default: 3600000 ms (1 hour)). */ transactionRemoveExpiredTransactionCleanupIntervalMs?: number; /** * The transaction topic segment bytes should be kept relatively small in order to facilitate faster log compaction and cache loads (Default: 104857600 bytes (100 mebibytes)). */ transactionStateLogSegmentBytes?: number; } export interface GetKafkaKafkaUserConfigKafkaAuditLog { /** * Aggregation period in seconds over which audit log entries are batched before being emitted. Default: `300`. */ aggregationPeriodSec?: number; /** * Enum: `user`, `userAndIp`. Group audit log entries by user or by user and IP address. Only valid when recordType is user_operations. Default: `userAndIp`. */ groupBy?: string; /** * Whether to include denied authorization attempts in the audit log. Default: `false`. */ includeDenials?: boolean; /** * Enum: `userActivity`, `userOperations`. userOperations records individual Kafka API calls (produce, fetch, etc.). userActivity records higher-level user actions. Default: `userOperations`. */ recordType?: string; } export interface GetKafkaKafkaUserConfigKafkaAuthenticationMethods { /** * Enable certificate/SSL authentication. Default: `true`. */ certificate?: boolean; /** * Enable SASL authentication. Default: `false`. */ sasl?: boolean; } export interface GetKafkaKafkaUserConfigKafkaConnectConfig { /** * Enum: `All`, `None`. Defines what client configurations can be overridden by the connector. Default is None. */ connectorClientConfigOverridePolicy?: string; /** * Enum: `earliest`, `latest`. What to do when there is no initial offset in Kafka or if the current offset does not exist any more on the server. Default is earliest. */ consumerAutoOffsetReset?: string; /** * Records are fetched in batches by the consumer, and if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that the consumer can make progress. As such, this is not a absolute maximum. */ consumerFetchMaxBytes?: number; /** * Enum: `readCommitted`, `readUncommitted`. Transaction read isolation level. readUncommitted is the default, but readCommitted can be used if consume-exactly-once behavior is desired. */ consumerIsolationLevel?: string; /** * Records are fetched in batches by the consumer.If the first record batch in the first non-empty partition of the fetch is larger than this limit, the batch will still be returned to ensure that the consumer can make progress. */ consumerMaxPartitionFetchBytes?: number; /** * The maximum delay in milliseconds between invocations of poll() when using consumer group management (defaults to 300000). */ consumerMaxPollIntervalMs?: number; /** * The maximum number of records returned in a single call to poll() (defaults to 500). */ consumerMaxPollRecords?: number; /** * The interval at which to try committing offsets for tasks (defaults to 60000). */ offsetFlushIntervalMs?: number; /** * Maximum number of milliseconds to wait for records to flush and partition offset data to be committed to offset storage before cancelling the process and restoring the offset data to be committed in a future attempt (defaults to 5000). */ offsetFlushTimeoutMs?: number; /** * When enabled, connectors will automatically resolve IPv6 addresses from external server names configured with dual-stack. Default: `false`. */ preferIpv6AddressEnable?: boolean; /** * This setting gives the upper bound of the batch size to be sent. If there are fewer than this many bytes accumulated for this partition, the producer will `linger` for the linger.ms time waiting for more records to show up. A batch size of zero will disable batching entirely (defaults to 16384). */ producerBatchSize?: number; /** * The total bytes of memory the producer can use to buffer records waiting to be sent to the broker (defaults to 33554432). */ producerBufferMemory?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * This setting gives the upper bound on the delay for batching: once there is batch.size worth of records for a partition it will be sent immediately regardless of this setting, however if there are fewer than this many bytes accumulated for this partition the producer will `linger` for the specified time waiting for more records to show up. Defaults to 0. */ producerLingerMs?: number; /** * This setting will limit the number of record batches the producer will send in a single request to avoid sending huge requests. */ producerMaxRequestSize?: number; /** * The maximum delay that is scheduled in order to wait for the return of one or more departed workers before rebalancing and reassigning their connectors and tasks to the group. During this period the connectors and tasks of the departed workers remain unassigned. Defaults to 5 minutes. */ scheduledRebalanceMaxDelayMs?: number; /** * The timeout in milliseconds used to detect failures when using Kafka’s group management facilities (defaults to 10000). */ sessionTimeoutMs?: number; } export interface GetKafkaKafkaUserConfigKafkaConnectPluginVersion { /** * The name of the plugin. Example: `debezium-connector`. */ pluginName: string; /** * The version of the plugin. Example: `2.5.0`. */ version: string; } export interface GetKafkaKafkaUserConfigKafkaConnectSecretProvider { /** * AWS secret provider configuration */ aws?: outputs.GetKafkaKafkaUserConfigKafkaConnectSecretProviderAws; /** * Azure KeyVault secret provider configuration */ azure?: outputs.GetKafkaKafkaUserConfigKafkaConnectSecretProviderAzure; /** * ENV secret provider configuration */ env?: outputs.GetKafkaKafkaUserConfigKafkaConnectSecretProviderEnv; /** * Name of the secret provider. Used to reference secrets in connector config. */ name: string; /** * Vault secret provider configuration */ vault?: outputs.GetKafkaKafkaUserConfigKafkaConnectSecretProviderVault; } export interface GetKafkaKafkaUserConfigKafkaConnectSecretProviderAws { /** * Access key used to authenticate with aws. */ accessKey?: string; /** * Enum: `credentials`. Auth method of the vault secret provider. */ authMethod: string; /** * Region used to lookup secrets with AWS SecretManager. */ region: string; /** * Secret key used to authenticate with aws. */ secretKey?: string; } export interface GetKafkaKafkaUserConfigKafkaConnectSecretProviderAzure { /** * Enum: `credentials`. Auth method of the Azure KeyVault secret provider. */ authMethod: string; /** * Azure client ID for the service principal. */ clientId?: string; /** * Azure client secret for the service principal. */ secret?: string; /** * Azure tenant ID for the service principal. */ tenantId?: string; } export interface GetKafkaKafkaUserConfigKafkaConnectSecretProviderEnv { /** * Key/value map of secrets for ENV secret provider. */ secrets: { [key: string]: string; }; } export interface GetKafkaKafkaUserConfigKafkaConnectSecretProviderVault { /** * Address of the Vault server. */ address: string; /** * Enum: `token`. Auth method of the vault secret provider. */ authMethod: string; /** * Enum: `1`, `2`, and newer. KV Secrets Engine version of the Vault server instance. */ engineVersion?: number; /** * Prefix path depth of the secrets Engine. Default is 1. If the secrets engine path has more than one segment it has to be increased to the number of segments. */ prefixPathDepth?: number; /** * PEM encoded certificate of the Vault server. Required if the vault server uses a self-signed certificate. */ serverPem?: string; /** * Token used to authenticate with vault and auth method `token`. */ token?: string; } export interface GetKafkaKafkaUserConfigKafkaDiskless { /** * The regexes of topics to auto enable diskless. Topics matching any of the regexes will be created as diskless topics. */ autoDisklessTopicRegexes?: string[]; /** * Whether to enable the Diskless functionality. */ enabled: boolean; } export interface GetKafkaKafkaUserConfigKafkaRestConfig { /** * If true the consumer's offset will be periodically committed to Kafka in the background. Default: `true`. */ consumerEnableAutoCommit?: boolean; /** * Specifies the maximum duration (in seconds) a client can remain idle before it is deleted. If a consumer is inactive, it will exit the consumer group, and its state will be discarded. A value of 0 (default) indicates that the consumer will not be disconnected automatically due to inactivity. Default: `0`. */ consumerIdleDisconnectTimeout?: number; /** * Maximum number of bytes in unencoded message keys and values by a single request. */ consumerRequestMaxBytes?: number; /** * Enum: `1000`, `15000`, `30000`. The maximum total time to wait for messages for a request if the maximum number of messages has not yet been reached. Default: `1000`. */ consumerRequestTimeoutMs?: number; /** * Enum: `recordName`, `topicName`, `topicRecordName`. Name strategy to use when selecting subject for storing schemas. Default: `topicName`. */ nameStrategy?: string; /** * If true, validate that given schema is registered under expected subject name by the used name strategy when producing messages. Default: `true`. */ nameStrategyValidation?: boolean; /** * Enum: `-1`, `0`, `1`, `all`. The number of acknowledgments the producer requires the leader to have received before considering a request complete. If set to `all` or `-1`, the leader will wait for the full set of in-sync replicas to acknowledge the record. Default: `1`. */ producerAcks?: string; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * Wait for up to the given delay to allow batching records together. Default: `0`. */ producerLingerMs?: number; /** * The maximum size of a request in bytes. Note that Kafka broker can also cap the record batch size. */ producerMaxRequestSize?: number; /** * Maximum number of SimpleConsumers that can be instantiated per broker. Default: `25`. */ simpleconsumerPoolSizeMax?: number; } export interface GetKafkaKafkaUserConfigKafkaSaslMechanisms { /** * Enable PLAIN mechanism. Default: `true`. */ plain?: boolean; /** * Enable SCRAM-SHA-256 mechanism. Default: `true`. */ scramSha256?: boolean; /** * Enable SCRAM-SHA-512 mechanism. Default: `true`. */ scramSha512?: boolean; } export interface GetKafkaKafkaUserConfigPrivateAccess { /** * Allow clients to connect to kafka with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafka?: boolean; /** * Allow clients to connect to kafkaConnect with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafkaConnect?: boolean; /** * Allow clients to connect to kafkaRest with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafkaRest?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; /** * Allow clients to connect to schemaRegistry with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ schemaRegistry?: boolean; } export interface GetKafkaKafkaUserConfigPrivatelinkAccess { /** * Enable jolokia. */ jolokia?: boolean; /** * Enable kafka. */ kafka?: boolean; /** * Enable kafka_connect. */ kafkaConnect?: boolean; /** * Enable kafka_rest. */ kafkaRest?: boolean; /** * Enable prometheus. */ prometheus?: boolean; /** * Enable schema_registry. */ schemaRegistry?: boolean; } export interface GetKafkaKafkaUserConfigPublicAccess { /** * Allow clients to connect to kafka from the public internet for service nodes that are in a project VPC or another type of private network. */ kafka?: boolean; /** * Allow clients to connect to kafkaConnect from the public internet for service nodes that are in a project VPC or another type of private network. */ kafkaConnect?: boolean; /** * Allow clients to connect to kafkaRest from the public internet for service nodes that are in a project VPC or another type of private network. */ kafkaRest?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; /** * Allow clients to connect to schemaRegistry from the public internet for service nodes that are in a project VPC or another type of private network. */ schemaRegistry?: boolean; } export interface GetKafkaKafkaUserConfigSchemaRegistryConfig { /** * If true, Karapace / Schema Registry on the service nodes can participate in leader election. It might be needed to disable this when the schemas topic is replicated to a secondary cluster and Karapace / Schema Registry there must not participate in leader election. Defaults to `true`. */ leaderEligibility?: boolean; /** * If enabled, kafka errors which can be retried or custom errors specified for the service will not be raised, instead, a warning log is emitted. This will denoise issue tracking systems, i.e. sentry. Defaults to `true`. */ retriableErrorsSilenced?: boolean; /** * If enabled, the Schema Registry validates OAuth2/OIDC JWT bearer tokens on incoming requests. Requires the OIDC provider settings under the `kafka` configuration (`saslOauthbearerJwksEndpointUrl` and related). Defaults to `false`. */ saslOauthbearerAuthenticationEnabled?: boolean; /** * If enabled, the Schema Registry enforces role-based authorization derived from the JWT roles claim. Requires `saslOauthbearerAuthenticationEnabled` to be enabled. Defaults to `false`. */ saslOauthbearerAuthorizationEnabled?: boolean; /** * JSON object mapping HTTP methods to the list of roles allowed to perform them on the Schema Registry, provided as a JSON-encoded string. Role names use the `karapace.` prefix, e.g. `karapace.schema:read`. Defaults to `{"GET": ["karapace.schema:read", "karapace.subject:read"], "POST": [], "PUT": [], "DELETE": []}`. */ saslOauthbearerMethodRoles?: string; /** * JSON path used to extract the roles claim from the JWT for Schema Registry authorization. Defaults to `resource_access.karapace.roles`. */ saslOauthbearerRolesClaimPath?: string; /** * If enabled, causes the Karapace schema-registry service to shutdown when there are invalid schema records in the `_schemas` topic. Defaults to `false`. */ schemaReaderStrictMode?: boolean; /** * The durable single partition topic that acts as the durable log for the data. This topic must be compacted to avoid losing data due to retention policy. Please note that changing this configuration in an existing Schema Registry / Karapace setup leads to previous schemas being inaccessible, data encoded with them potentially unreadable and schema ID sequence put out of order. It's only possible to do the switch while Schema Registry / Karapace is disabled. Defaults to `_schemas`. */ topicName?: string; } export interface GetKafkaKafkaUserConfigSingleZone { /** * The availability zone to use for the service. This is only used when enabled is set to true. If not set the service will be allocated in random AZ.The AZ is not guaranteed, and the service may be allocated in a different AZ if the selected AZ is not available. Zones will not be validated and invalid zones will be ignored, falling back to random AZ selection. Common availability zones include: AWS (euc1-az1, euc1-az2, euc1-az3), GCP (europe-west1-a, europe-west1-b, europe-west1-c), Azure (germanywestcentral/1, germanywestcentral/2, germanywestcentral/3). Example: `euc1-az1`. */ availabilityZone?: string; /** * Whether to allocate nodes on the same Availability Zone or spread across zones available. By default service nodes are spread across different AZs. The single AZ support is best-effort and may temporarily allocate nodes in different AZs e.g. in case of capacity limitations in one AZ. */ enabled?: boolean; } export interface GetKafkaKafkaUserConfigTieredStorage { /** * Whether to enable the tiered storage functionality. */ enabled?: boolean; /** * Local cache configuration * * @deprecated This property is deprecated. */ localCache?: outputs.GetKafkaKafkaUserConfigTieredStorageLocalCache; } export interface GetKafkaKafkaUserConfigTieredStorageLocalCache { /** * Local cache size in bytes. Example: `1073741824`. * * @deprecated This property is deprecated. */ size?: number; } export interface GetKafkaMirrorMakerComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetKafkaMirrorMakerKafkaMirrormakerUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetKafkaMirrorMakerKafkaMirrormakerUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Kafka MirrorMaker configuration values */ kafkaMirrormaker?: outputs.GetKafkaMirrorMakerKafkaMirrormakerUserConfigKafkaMirrormaker; /** * List of preferred zone IDs for service node placement. Nodes will be placed in these zones when available. If a specified zone is unavailable (e.g., due to capacity constraints), nodes will be placed in other available zones to maintain the configured number of zones for availability. Invalid zone IDs are rejected at configuration time. Zone IDs are cloud-specific: AWS uses zone IDs like `euc1-az1`, GCP uses zone names like `europe-west1-a`, and Azure uses `location/zone` format like `germanywestcentral/1`. If singleZone is enabled with an availability_zone, that setting takes precedence over preferred_zones. Changes take effect on next node recreation (e.g., maintenance or plan change). For eligible plans, nodes outside preferred zones are automatically rebalanced once per day. */ preferredZones?: string[]; /** * List of allowed URLs for SASL OAUTHBEARER authentication. Only HTTPS URLs are allowed for security reasons. */ saslOauthbearerAllowedUrls?: string[]; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface GetKafkaMirrorMakerKafkaMirrormakerUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetKafkaMirrorMakerKafkaMirrormakerUserConfigKafkaMirrormaker { /** * Timeout for administrative tasks, e.g. detecting new topics, loading of consumer group and offsets. Defaults to 60000 milliseconds (1 minute). */ adminTimeoutMs?: number; /** * Whether to emit consumer group offset checkpoints to target cluster periodically (default: true). */ emitCheckpointsEnabled?: boolean; /** * Frequency at which consumer group offset checkpoints are emitted (default: 60, every minute). Example: `60`. */ emitCheckpointsIntervalSeconds?: number; /** * Consumer groups to replicate. Supports comma-separated group IDs and regexes. Example: `.*`. */ groups?: string; /** * Exclude groups. Supports comma-separated group IDs and regexes. Excludes take precedence over includes. Example: `console-consumer-.*,connect-.*,__.*`. */ groupsExclude?: string; /** * How out-of-sync a remote partition can be before it is resynced. Example: `100`. */ offsetLagMax?: number; /** * Whether to periodically check for new consumer groups. Defaults to `true`. */ refreshGroupsEnabled?: boolean; /** * Frequency of consumer group refresh in seconds. Defaults to 600 seconds (10 minutes). */ refreshGroupsIntervalSeconds?: number; /** * Whether to periodically check for new topics and partitions. Defaults to `true`. */ refreshTopicsEnabled?: boolean; /** * Frequency of topic and partitions refresh in seconds. Defaults to 600 seconds (10 minutes). */ refreshTopicsIntervalSeconds?: number; /** * Whether to periodically write the translated offsets of replicated consumer groups (in the source cluster) to __consumer_offsets topic in target cluster, as long as no active consumers in that group are connected to the target cluster. */ syncGroupOffsetsEnabled?: boolean; /** * Frequency at which consumer group offsets are synced (default: 60, every minute). Example: `60`. */ syncGroupOffsetsIntervalSeconds?: number; /** * Whether to periodically configure remote topics to match their corresponding upstream topics. */ syncTopicConfigsEnabled?: boolean; /** * `tasks.max` is set to this multiplied by the number of CPUs in the service. Default: `1`. */ tasksMaxPerCpu?: number; } export interface GetKafkaMirrorMakerServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetKafkaMirrorMakerTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetKafkaMirrorMakerTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetKafkaSchemaConfigurationReference { /** * The name used to reference the provided subject and version. Maximum length: `1024`. */ name: string; /** * Subject. Maximum length: `1024`. */ subject: string; /** * Version. */ version: number; } export interface GetKafkaSchemaReference { /** * The name used to reference the provided subject and version. Maximum length: `1024`. */ name: string; /** * Subject. Maximum length: `1024`. */ subject: string; /** * Version. */ version: number; } export interface GetKafkaSchemaRegistryAclTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetKafkaServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetKafkaTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetKafkaTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetKafkaTopicConfig { /** * The retention policy to use on old segments. Possible values include 'delete', 'compact', or a comma-separated list of them. The default policy ('delete') will discard old segments when their retention time or size limit has been reached. The 'compact' setting will enable log compaction on the topic. The possible values are `compact`, `compact,delete` and `delete`. */ cleanupPolicy: string; /** * Specify the final compression type for a given topic. This configuration accepts the standard compression codecs ('gzip', 'snappy', 'lz4', 'zstd'). It additionally accepts 'uncompressed' which is equivalent to no compression; and 'producer' which means retain the original compression codec set by the producer. The possible values are `gzip`, `lz4`, `producer`, `snappy`, `uncompressed` and `zstd`. */ compressionType: string; /** * The amount of time to retain delete tombstone markers for log compacted topics. This setting also gives a bound on the time in which a consumer must complete a read if they begin from offset 0 to ensure that they get a valid snapshot of the final stage (otherwise delete tombstones may be collected before they complete their scan). */ deleteRetentionMs: string; /** * Indicates whether diskless should be enabled. This is only available for BYOC services with Diskless feature enabled. */ disklessEnable: boolean; /** * The time to wait before deleting a file from the filesystem. */ fileDeleteDelayMs: string; /** * This setting allows specifying an interval at which we will force an fsync of data written to the log. For example if this was set to 1 we would fsync after every message; if it were 5 we would fsync after every five messages. In general we recommend you not set this and use replication for durability and allow the operating system's background flush capabilities as it is more efficient. */ flushMessages: string; /** * This setting allows specifying a time interval at which we will force an fsync of data written to the log. For example if this was set to 1000 we would fsync after 1000 ms had passed. In general we recommend you not set this and use replication for durability and allow the operating system's background flush capabilities as it is more efficient. */ flushMs: string; /** * This setting controls how frequently Kafka adds an index entry to its offset index. The default setting ensures that we index a message roughly every 4096 bytes. More indexing allows reads to jump closer to the exact position in the log but makes the index larger. You probably don't need to change this. */ indexIntervalBytes: string; /** * This configuration controls the maximum bytes tiered storage will retain segment files locally before it will discard old log segments to free up space. If set to -2, the limit is equal to overall retention time. If set to -1, no limit is applied but it's possible only if overall retention is also -1. The field is required with `retentionBytes`. */ localRetentionBytes: string; /** * This configuration controls the maximum time tiered storage will retain segment files locally before it will discard old log segments to free up space. If set to -2, the time limit is equal to overall retention time. If set to -1, no time limit is applied but it's possible only if overall retention is also -1. The field is required with `retentionMs`. */ localRetentionMs: string; /** * The maximum time a message will remain ineligible for compaction in the log. Only applicable for logs that are being compacted. */ maxCompactionLagMs: string; /** * The largest record batch size allowed by Kafka (after compression if compression is enabled). If this is increased and there are consumers older than 0.10.2, the consumers' fetch size must also be increased so that the they can fetch record batches this large. In the latest message format version, records are always grouped into batches for efficiency. In previous message format versions, uncompressed records are not grouped into batches and this limit only applies to a single record in that case. */ maxMessageBytes: string; /** * This configuration controls whether down-conversion of message formats is enabled to satisfy consume requests. When set to false, broker will not perform down-conversion for consumers expecting an older message format. The broker responds with UNSUPPORTED_VERSION error for consume requests from such older clients. This configuration does not apply to any message format conversion that might be required for replication to followers. */ messageDownconversionEnable: boolean; /** * Specify the message format version the broker will use to append messages to the logs. The value should be a valid ApiVersion. Some examples are: 0.8.2, 0.9.0.0, 0.10.0, check ApiVersion for more details. By setting a particular message format version, the user is certifying that all the existing messages on disk are smaller or equal than the specified version. Setting this value incorrectly will cause consumers with older versions to break as they will receive messages with a format that they don't understand. Deprecated in Kafka 4.0+: this configuration is removed and any supplied value will be ignored; for services upgraded to 4.0+, the returned value may be 'None'. The possible values are `0.10.0`, `0.10.0-IV0`, `0.10.0-IV1`, `0.10.1`, `0.10.1-IV0`, `0.10.1-IV1`, `0.10.1-IV2`, `0.10.2`, `0.10.2-IV0`, `0.11.0`, `0.11.0-IV0`, `0.11.0-IV1`, `0.11.0-IV2`, `0.8.0`, `0.8.1`, `0.8.2`, `0.9.0`, `1.0`, `1.0-IV0`, `1.1`, `1.1-IV0`, `2.0`, `2.0-IV0`, `2.0-IV1`, `2.1`, `2.1-IV0`, `2.1-IV1`, `2.1-IV2`, `2.2`, `2.2-IV0`, `2.2-IV1`, `2.3`, `2.3-IV0`, `2.3-IV1`, `2.4`, `2.4-IV0`, `2.4-IV1`, `2.5`, `2.5-IV0`, `2.6`, `2.6-IV0`, `2.7`, `2.7-IV0`, `2.7-IV1`, `2.7-IV2`, `2.8`, `2.8-IV0`, `2.8-IV1`, `3.0`, `3.0-IV0`, `3.0-IV1`, `3.1`, `3.1-IV0`, `3.2`, `3.2-IV0`, `3.3`, `3.3-IV0`, `3.3-IV1`, `3.3-IV2`, `3.3-IV3`, `3.4`, `3.4-IV0`, `3.5`, `3.5-IV0`, `3.5-IV1`, `3.5-IV2`, `3.6`, `3.6-IV0`, `3.6-IV1`, `3.6-IV2`, `3.7`, `3.7-IV0`, `3.7-IV1`, `3.7-IV2`, `3.7-IV3`, `3.7-IV4`, `3.8`, `3.8-IV0`, `3.9`, `3.9-IV0`, `3.9-IV1`, `4.0`, `4.0-IV0`, `4.1`, `4.1-IV0`, `4.2` and `4.2-IV0`. */ messageFormatVersion: string; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps later than the broker's timestamp. */ messageTimestampAfterMaxMs: string; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps earlier than the broker's timestamp. */ messageTimestampBeforeMaxMs: string; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. This configuration is ignored if message.timestamp.type=LogAppendTime. */ messageTimestampDifferenceMaxMs: string; /** * Define whether the timestamp in the message is message create time or log append time. The possible values are `CreateTime` and `LogAppendTime`. */ messageTimestampType: string; /** * This configuration controls how frequently the log compactor will attempt to clean the log (assuming log compaction is enabled). By default we will avoid cleaning a log where more than 50% of the log has been compacted. This ratio bounds the maximum space wasted in the log by duplicates (at 50% at most 50% of the log could be duplicates). A higher ratio will mean fewer, more efficient cleanings but will mean more wasted space in the log. If the max.compaction.lag.ms or the min.compaction.lag.ms configurations are also specified, then the log compactor considers the log to be eligible for compaction as soon as either: (i) the dirty ratio threshold has been met and the log has had dirty (uncompacted) records for at least the min.compaction.lag.ms duration, or (ii) if the log has had dirty (uncompacted) records for at most the max.compaction.lag.ms period. */ minCleanableDirtyRatio: number; /** * The minimum time a message will remain uncompacted in the log. Only applicable for logs that are being compacted. */ minCompactionLagMs: string; /** * When a producer sets acks to 'all' (or '-1'), this configuration specifies the minimum number of replicas that must acknowledge a write for the write to be considered successful. If this minimum cannot be met, then the producer will raise an exception (either NotEnoughReplicas or NotEnoughReplicasAfterAppend). When used together, min.insync.replicas and acks allow you to enforce greater durability guarantees. A typical scenario would be to create a topic with a replication factor of 3, set min.insync.replicas to 2, and produce with acks of 'all'. This will ensure that the producer raises an exception if a majority of replicas do not receive a write. */ minInsyncReplicas: string; /** * True if we should preallocate the file on disk when creating a new log segment. */ preallocate: boolean; /** * Indicates whether tiered storage should be enabled. This is only available for services with Tiered Storage feature enabled. */ remoteStorageEnable: boolean; /** * This configuration controls the maximum size a partition (which consists of log segments) can grow to before we will discard old log segments to free up space if we are using the 'delete' retention policy. By default there is no size limit only a time limit. Since this limit is enforced at the partition level, multiply it by the number of partitions to compute the topic retention in bytes. */ retentionBytes: string; /** * This configuration controls the maximum time we will retain a log before we will discard old log segments to free up space if we are using the 'delete' retention policy. This represents an SLA on how soon consumers must read their data. If set to -1, no time limit is applied. */ retentionMs: string; /** * This configuration controls the segment file size for the log. Retention and cleaning is always done a file at a time so a larger segment size means fewer files but less granular control over retention. Setting this to a very low value has consequences, and the Aiven management plane ignores values less than 10 megabytes. */ segmentBytes: string; /** * This configuration controls the size of the index that maps offsets to file positions. We preallocate this index file and shrink it only after log rolls. You generally should not need to change this setting. */ segmentIndexBytes: string; /** * The maximum random jitter subtracted from the scheduled segment roll time to avoid thundering herds of segment rolling. */ segmentJitterMs: string; /** * This configuration controls the period of time after which Kafka will force the log to roll even if the segment file isn't full to ensure that retention can delete or compact old data. Setting this to a very low value has consequences, and the Aiven management plane ignores values less than 10 seconds. */ segmentMs: string; /** * Indicates whether to enable replicas not in the ISR set to be elected as leader as a last resort, even though doing so may result in data loss. */ uncleanLeaderElectionEnable: boolean; } export interface GetKafkaTopicListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetKafkaTopicListTopic { /** * The retention policy to use on old segments. Possible values include 'delete', 'compact', or a comma-separated list of them. The default policy ('delete') will discard old segments when their retention time or size limit has been reached. The 'compact' setting will enable log compaction on the topic. */ cleanupPolicy: string; /** * Indicates whether diskless should be enabled. This is only available for BYOC services with Diskless feature enabled. */ disklessEnable: boolean; /** * When a producer sets acks to 'all' (or '-1'), this configuration specifies the minimum number of replicas that must acknowledge a write for the write to be considered successful. If this minimum cannot be met, then the producer will raise an exception (either NotEnoughReplicas or NotEnoughReplicasAfterAppend). When used together, min.insync.replicas and acks allow you to enforce greater durability guarantees. A typical scenario would be to create a topic with a replication factor of 3, set min.insync.replicas to 2, and produce with acks of 'all'. This will ensure that the producer raises an exception if a majority of replicas do not receive a write. */ minInsyncReplicas: number; /** * The user group that owns this topic. */ ownerUserGroupId: string; /** * Number of partitions. */ partitions: number; /** * Indicates whether tiered storage should be enabled. This is only available for services with Tiered Storage feature enabled. */ remoteStorageEnable: boolean; /** * Number of replicas. */ replication: number; /** * This configuration controls the maximum size a partition (which consists of log segments) can grow to before we will discard old log segments to free up space if we are using the 'delete' retention policy. By default there is no size limit only a time limit. Since this limit is enforced at the partition level, multiply it by the number of partitions to compute the topic retention in bytes. */ retentionBytes: number; /** * Retention period (hours). */ retentionHours: number; /** * Topic state. The possible values are `ACTIVE`, `CONFIGURING` and `DELETING`. */ state: string; /** * Topic tags. */ tags?: outputs.GetKafkaTopicListTopicTag[]; /** * Topic description. */ topicDescription: string; /** * Topic name. */ topicName: string; } export interface GetKafkaTopicListTopicTag { /** * Tag key. */ key: string; /** * Tag value. */ value: string; } export interface GetKafkaTopicTag { /** * Tag key. */ key: string; /** * Tag value. */ value: string; } export interface GetKafkaTopicTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetKafkaUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetMirrorMakerReplicationFlowTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetMySqlComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetMySqlMysql { /** * MySQL connection parameters. */ params: outputs.GetMySqlMysqlParam[]; /** * MySQL replica URI for services with a replica. */ replicaUri: string; /** * MySQL standby connection URIs. */ standbyUris: string[]; /** * MySQL syncing connection URIs. */ syncingUris: string[]; /** * MySQL connection URIs. */ uris: string[]; } export interface GetMySqlMysqlParam { /** * Thr name of the primary MySQL database. */ databaseName: string; /** * MySQL host IP or name. */ host: string; /** * The password for the admin service user. */ password: string; /** * MySQL port. */ port: number; /** * MySQL SSL mode setting. Always set to "require". */ sslmode: string; /** * The username for the admin service user. */ user: string; } export interface GetMySqlMysqlUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Custom password for admin user. Defaults to random string. This must be set only when a new service is being created. */ adminPassword?: string; /** * Custom username for admin user. This must be set only when a new service is being created. Example: `avnadmin`. */ adminUsername?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Default: `0`. */ backupHour?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Default: `0`. */ backupMinute?: number; /** * Warning: reducing this value can make a large batch of binary logs eligible for purge at once. Depending on the volume, this can sometimes stall the MySQL commit path and block writes until the purge completes. To stay on the safe side, prefer lowering the value gradually in small decrements during a low-traffic window rather than dropping it drastically in one step. Example: `600`. */ binlogRetentionPeriod?: number; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetMySqlMysqlUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.GetMySqlMysqlUserConfigMigration; /** * mysql.conf configuration values */ mysql?: outputs.GetMySqlMysqlUserConfigMysql; /** * MySQL incremental backup configuration */ mysqlIncrementalBackup?: outputs.GetMySqlMysqlUserConfigMysqlIncrementalBackup; /** * Enum: `8`, `8.4`, and newer. MySQL major version. */ mysqlVersion?: string; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetMySqlMysqlUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetMySqlMysqlUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetMySqlMysqlUserConfigPublicAccess; /** * Recovery target time when forking a service. This has effect only when a new service is being created. Example: `2019-01-01 23:34:45`. */ recoveryTargetTime?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface GetMySqlMysqlUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetMySqlMysqlUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Enum: `mydumper`, `mysqldump`. Experimental! Tool to use for database dump and restore during migration. Default: mysqldump. */ dumpTool?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * Skip dump-restore part and start replication. Default: `false`. */ reestablishReplication?: boolean; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface GetMySqlMysqlUserConfigMysql { /** * When enabled, the server automatically grants the EXECUTE and ALTER ROUTINE privileges to the creator of a stored routine and drops them when the routine is dropped. */ automaticSpPrivileges?: boolean; /** * The number of seconds that the mysqld server waits for a connect packet before responding with Bad handshake. Example: `10`. */ connectTimeout?: number; /** * Default server time zone as an offset from UTC (from -12:00 to +12:00), a time zone name, or `SYSTEM` to use the MySQL server default. Example: `+03:00`. */ defaultTimeZone?: string; /** * Number of digits by which to increase the scale of the result of division operations performed with the / operator. Default is 4. Example: `6`. */ divPrecisionIncrement?: number; /** * Whether optimizer JSON output such as EXPLAIN FORMAT=JSON adds end markers that repeat a structure's key near its closing bracket, making large JSON structures easier to read. */ endMarkersInJson?: boolean; /** * The number of equality ranges in a query at or above which the optimizer switches from index dives to index statistics when estimating the number of qualifying rows. 0 means always use index dives. Default is 200. Example: `100`. */ eqRangeIndexDiveLimit?: number; /** * The maximum permitted result length in bytes for the GROUP_CONCAT() function. Example: `1024`. */ groupConcatMaxLen?: number; /** * The time, in seconds, before cached statistics expire. Example: `86400`. */ informationSchemaStatsExpiry?: number; /** * Whether InnoDB adaptive hash indexing is enabled. The optimal setting is workload-dependent: it speeds up lookups for some workloads but its internal latch can become a contention point under high concurrency, in which case disabling it can improve throughput. */ innodbAdaptiveHashIndex?: boolean; /** * Maximum size for the InnoDB change buffer, as a percentage of the total size of the buffer pool. Default is 25. Example: `30`. */ innodbChangeBufferMaxSize?: number; /** * Specifies whether flushing a page from the InnoDB buffer pool also flushes other dirty pages in the same extent (default is 1): 0 - dirty pages in the same extent are not flushed, 1 - flush contiguous dirty pages in the same extent, 2 - flush dirty pages in the same extent. Example: `0`. */ innodbFlushNeighbors?: number; /** * Whether stopword processing is applied when creating or rebuilding an InnoDB FULLTEXT index. Enabled by default. */ innodbFtEnableStopword?: boolean; /** * Maximum length of words that are stored in an InnoDB FULLTEXT index. Changing this parameter will lead to a restart of the MySQL service. Example: `60`. */ innodbFtMaxTokenSize?: number; /** * Minimum length of words that are stored in an InnoDB FULLTEXT index. Changing this parameter will lead to a restart of the MySQL service. Example: `3`. */ innodbFtMinTokenSize?: number; /** * Number of words processed during each OPTIMIZE TABLE operation on an InnoDB FULLTEXT index. Default is 2000. Example: `4000`. */ innodbFtNumWordOptimize?: number; /** * Maximum memory in bytes used per query for the InnoDB FULLTEXT search query result cache. Aiven sizes this automatically based on the service plan's memory; setting a value overrides the calculated default. */ innodbFtResultCacheLimit?: number; /** * This option is used to specify your own InnoDB FULLTEXT index stopword list for all InnoDB tables. Example: `db_name/table_name`. */ innodbFtServerStopwordTable?: string; /** * This option is used to specify your own InnoDB FULLTEXT index stopword list for specific InnoDB tables. Example: `db_name/table_name`. */ innodbFtUserStopwordTable?: string; /** * The number of I/O operations per second (IOPS) available to InnoDB background tasks, such as flushing pages from the buffer pool and merging data from the change buffer. Set this to a value appropriate for the underlying storage; it must not exceed innodb_io_capacity_max. Example: `2000`. */ innodbIoCapacity?: number; /** * The maximum number of I/O operations per second (IOPS) that InnoDB background tasks may perform when flushing falls behind. Defaults to twice innodbIoCapacity (minimum 2000). This must be greater than or equal to innodb_io_capacity. */ innodbIoCapacityMax?: number; /** * The length of time in seconds an InnoDB transaction waits for a row lock before giving up. Default is 120. Example: `50`. */ innodbLockWaitTimeout?: number; /** * The size in bytes of the buffer that InnoDB uses to write to the log files on disk. */ innodbLogBufferSize?: number; /** * The upper limit in bytes on the size of the temporary log files used during online DDL operations for InnoDB tables. */ innodbOnlineAlterLogMaxSize?: number; /** * When enabled, OPTIMIZE TABLE on InnoDB tables only updates the FULLTEXT index instead of rebuilding the table. Intended to be enabled temporarily during FULLTEXT index maintenance and disabled afterwards; while enabled, OPTIMIZE TABLE does not reclaim table space. */ innodbOptimizeFulltextOnly?: boolean; /** * When enabled, information about all deadlocks in InnoDB user transactions is recorded in the error log. Disabled by default. */ innodbPrintAllDeadlocks?: boolean; /** * The number of I/O threads for read operations in InnoDB. Default is 4. Changing this parameter will lead to a restart of the MySQL service. Example: `10`. */ innodbReadIoThreads?: number; /** * When enabled a transaction timeout causes InnoDB to abort and roll back the entire transaction. Changing this parameter will lead to a restart of the MySQL service. */ innodbRollbackOnTimeout?: boolean; /** * Defines the maximum number of threads permitted inside of InnoDB. Default is 0 (infinite concurrency - no limit). Example: `10`. */ innodbThreadConcurrency?: number; /** * The number of I/O threads for write operations in InnoDB. Default is 4. Changing this parameter will lead to a restart of the MySQL service. Example: `10`. */ innodbWriteIoThreads?: number; /** * The number of seconds the server waits for activity on an interactive connection before closing it. Example: `3600`. */ interactiveTimeout?: number; /** * Enum: `MEMORY`, `TempTable`. The storage engine for in-memory internal temporary tables. */ internalTmpMemStorageEngine?: string; /** * Enum: `INSIGHTS`, `INSIGHTS,TABLE`, `NONE`, `TABLE`. The slow log output destination when slowQueryLog is ON. To enable MySQL AI Insights, choose INSIGHTS. To use MySQL AI Insights and the mysql.slow_log table at the same time, choose INSIGHTS,TABLE. To only use the mysql.slow_log table, choose TABLE. To silence slow logs, choose NONE. */ logOutput?: string; /** * The slowQueryLogs work as SQL statements that take more than longQueryTime seconds to execute. Example: `10`. */ longQueryTime?: number; /** * Enum: `0`, `1`. Sets how table and database names are stored and compared. 0 = case-sensitive (default), 1 = names stored lowercase, comparisons are case-insensitive. This option can only be set when creating the service and cannot be changed later. See https://dev.mysql.com/doc/refman/8.0/en/identifier-case-sensitivity.html for details. */ lowerCaseTableNames?: number; /** * Size of the largest message in bytes that can be received by the server. Default is 67108864 (64M). */ maxAllowedPacket?: number; /** * The maximum permitted number of simultaneous client connections. Lower this to reserve memory for other work. The value cannot exceed the limit provided by your service plan. Upgrading the plan does not raise a value you have set explicitly, so increase it yourself after an upgrade. Example: `200`. */ maxConnections?: number; /** * Execution timeout in milliseconds for read-only top-level SELECT statements. 0 (the default) means no timeout. Example: `15000`. */ maxExecutionTime?: number; /** * Limits the size of internal in-memory tables. Also set tmp_table_size. Default is 16777216 (16M). */ maxHeapTableSize?: number; /** * Limit on the assumed maximum number of index seeks when looking up rows based on a key. Lowering this value causes the optimizer to prefer index lookups over table scans. Example: `100`. */ maxSeeksForKey?: number; /** * The maximum number of simultaneous connections permitted to any single user account. 0, the default, means no per-account limit. Any other value must be at least 10 below max_connections, so that monitoring and your own admin sessions can still connect when an application saturates its own limit. Aiven's replication and management connections are unaffected however low you set this. Example: `50`. */ maxUserConnections?: number; /** * Start sizes of connection buffer and result buffer. Default is 16384 (16K). Changing this parameter will lead to a restart of the MySQL service. Example: `16384`. */ netBufferLength?: number; /** * The number of seconds to wait for more data from a connection before aborting the read. Example: `30`. */ netReadTimeout?: number; /** * The number of seconds to wait for a block to be written to a connection before aborting the write. Example: `30`. */ netWriteTimeout?: number; /** * Controls the heuristics applied during query optimization to prune less-promising partial plans from the optimizer search space. 0 disables heuristics (exhaustive search); 1 prunes plans based on the number of rows retrieved. Example: `1`. */ optimizerPruneLevel?: number; /** * Maximum depth of search performed by the query optimizer when choosing a join order. Larger values produce better plans for joins over many tables but take longer to compile; 0 lets the optimizer choose the depth automatically. Example: `62`. */ optimizerSearchDepth?: number; /** * Comma-separated list of optimizer flag assignments in the form flag=on|off|default, or the single value `default` to reset all flags. Flags not listed keep their current values. Controls query optimizer behaviors such as index merge, hash join and semijoin strategies. Example: `batched_key_access=on,mrr_cost_based=off`. */ optimizerSwitch?: string; /** * The number of rows per thread in the eventsStatementsHistory table. Changing this parameter will lead to a restart of the MySQL service. */ performanceSchemaEventsStatementsHistorySize?: number; /** * The maximum amount of space in bytes to use for all relay logs while replicating from an external migration source. When the limit is reached, the replication I/O thread stops fetching relay log events until the SQL thread has caught up. Raise this to give a large migration a bigger relay-log budget; ensure the service disk is sized accordingly. The setting applies only on the node replicating from the external source; standby nodes always use the Aiven-managed default (the smaller of 5 GiB and 30% of the service disk), which is also used when this option is left unset. Changing this parameter will lead to a restart of the MySQL service. */ relayLogSpaceLimit?: number; /** * Slow query log enables capturing of slow queries. Setting slowQueryLog to false also truncates the mysql.slow_log table. */ slowQueryLog?: boolean; /** * Sort buffer size in bytes for ORDER BY optimization. Default is 262144 (256K). Example: `262144`. */ sortBufferSize?: number; /** * Global SQL mode. Set to empty to use MySQL server defaults. When creating a new service and not setting this field Aiven default SQL mode (strict, SQL standard compliant) will be assigned. Example: `ANSI,TRADITIONAL`. */ sqlMode?: string; /** * Require primary key to be defined for new tables or old tables modified with ALTER TABLE and fail if missing. It is recommended to always have primary keys because various functionality may break if any large table is missing them. */ sqlRequirePrimaryKey?: boolean; /** * Limits the size of internal in-memory tables. Also set max_heap_table_size. Default is 16777216 (16M). */ tmpTableSize?: number; /** * The number of seconds the server waits for activity on a noninteractive connection before closing it. Example: `28800`. */ waitTimeout?: number; /** * Whether window functions are computed to high precision. Disabling this trades exactness for speed in window function evaluation. */ windowingUseHighPrecision?: boolean; } export interface GetMySqlMysqlUserConfigMysqlIncrementalBackup { /** * Enable periodic incremental backups. When enabled, fullBackupWeekSchedule must be set. Incremental backups only store changes since the last backup, making them faster and more storage-efficient than full backups. This is particularly useful for large databases where daily full backups would be too time-consuming or expensive. */ enabled: boolean; /** * Comma-separated list of days of the week when full backups should be created. Valid values: mon, tue, wed, thu, fri, sat, sun. Example: `sun,wed`. */ fullBackupWeekSchedule?: string; } export interface GetMySqlMysqlUserConfigPrivateAccess { /** * Allow clients to connect to mysql with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ mysql?: boolean; /** * Allow clients to connect to mysqlx with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ mysqlx?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface GetMySqlMysqlUserConfigPrivatelinkAccess { /** * Enable mysql. */ mysql?: boolean; /** * Enable mysqlx. */ mysqlx?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetMySqlMysqlUserConfigPublicAccess { /** * Allow clients to connect to mysql from the public internet for service nodes that are in a project VPC or another type of private network. */ mysql?: boolean; /** * Allow clients to connect to mysqlx from the public internet for service nodes that are in a project VPC or another type of private network. */ mysqlx?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface GetMySqlServiceIntegration { /** * Type of the service integration. The possible value is `readReplica`. */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetMySqlTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetMySqlTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetMysqlDatabaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetMysqlUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOpenSearchComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetOpenSearchOpensearch { /** * URI for Kibana dashboard frontend. * * @deprecated This field was added by mistake and has never worked. It will be removed in future versions. */ kibanaUri: string; /** * URI for OpenSearch dashboard frontend. */ opensearchDashboardsUri: string; /** * OpenSearch password. */ password: string; /** * OpenSearch server URIs. */ uris: string[]; /** * OpenSearch username. */ username: string; } export interface GetOpenSearchOpensearchUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Azure migration settings */ azureMigration?: outputs.GetOpenSearchOpensearchUserConfigAzureMigration; /** * Serve the web frontend using a custom CNAME pointing to the Aiven DNS name. When you set a custom domain for a service deployed in a VPC, the service certificate is only created for the public-* hostname and the custom domain. Example: `grafana.example.org`. */ customDomain?: string; /** * Disable automatic replication factor adjustment for multi-node services. By default, Aiven ensures all indexes are replicated at least to two nodes. Note: Due to potential data loss in case of losing a service node, this setting can not be activated unless specifically allowed for the project. */ disableReplicationFactorAdjustment?: boolean; /** * Google Cloud Storage migration settings */ gcsMigration?: outputs.GetOpenSearchOpensearchUserConfigGcsMigration; /** * Index patterns */ indexPatterns?: outputs.GetOpenSearchOpensearchUserConfigIndexPattern[]; /** * Index rollup settings */ indexRollup?: outputs.GetOpenSearchOpensearchUserConfigIndexRollup; /** * Template settings for all new indexes */ indexTemplate?: outputs.GetOpenSearchOpensearchUserConfigIndexTemplate; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetOpenSearchOpensearchUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * OpenSearch JWT Configuration */ jwt?: outputs.GetOpenSearchOpensearchUserConfigJwt; /** * Aiven automation resets index.refresh_interval to default value for every index to be sure that indices are always visible to search. If it doesn't fit your case, you can disable this by setting up this flag to true. */ keepIndexRefreshInterval?: boolean; /** * Use indexPatterns instead. Default: `0`. */ maxIndexCount?: number; /** * OpenSearch OpenID Connect Configuration */ openid?: outputs.GetOpenSearchOpensearchUserConfigOpenid; /** * OpenSearch settings */ opensearch?: outputs.GetOpenSearchOpensearchUserConfigOpensearch; /** * OpenSearch Dashboards settings */ opensearchDashboards?: outputs.GetOpenSearchOpensearchUserConfigOpensearchDashboards; /** * Enum: `1`, `2`, `2.19`, `3.3`, `3.6`, and newer. OpenSearch version. */ opensearchVersion?: string; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetOpenSearchOpensearchUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetOpenSearchOpensearchUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetOpenSearchOpensearchUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * AWS S3 / AWS S3 compatible migration settings */ s3Migration?: outputs.GetOpenSearchOpensearchUserConfigS3Migration; /** * OpenSearch SAML configuration */ saml?: outputs.GetOpenSearchOpensearchUserConfigSaml; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface GetOpenSearchOpensearchUserConfigAzureMigration { /** * Account name. */ account: string; /** * The path to the repository data within its container. The value of this setting should not start or end with a /. */ basePath: string; /** * Big files can be broken down into chunks during snapshotting if needed. Should be the same as for the 3rd party repository. */ chunkSize?: string; /** * When set to true metadata files are stored in compressed format. */ compress?: boolean; /** * Azure container name. */ container: string; /** * Defines the DNS suffix for Azure Storage endpoints. */ endpointSuffix?: string; /** * Whether to restore aliases alongside their associated indexes. Default is true. */ includeAliases?: boolean; /** * A comma-delimited list of indices to restore from the snapshot. Multi-index syntax is supported. Example: `metrics*,logs*,data-20240823`. */ indices: string; /** * Azure account secret key. One of key or sasToken should be specified. */ key?: string; /** * Throttles the restore rate per node. Defaults to unlimited. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxRestoreBytesPerSec?: string; /** * Throttles the snapshot rate per node. Defaults to 40mb. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxSnapshotBytesPerSec?: string; /** * Whether the repository is read-only. Default: `true`. */ readonly?: boolean; /** * If true, restore the cluster state. Defaults to false. */ restoreGlobalState?: boolean; /** * A shared access signatures (SAS) token. One of key or sasToken should be specified. */ sasToken?: string; /** * The snapshot name to restore from. */ snapshotName: string; } export interface GetOpenSearchOpensearchUserConfigGcsMigration { /** * The path to the repository data within its container. The value of this setting should not start or end with a /. */ basePath: string; /** * The path to the repository data within its container. */ bucket: string; /** * Big files can be broken down into chunks during snapshotting if needed. Should be the same as for the 3rd party repository. */ chunkSize?: string; /** * When set to true metadata files are stored in compressed format. */ compress?: boolean; /** * Google Cloud Storage credentials file content. */ credentials: string; /** * Whether to restore aliases alongside their associated indexes. Default is true. */ includeAliases?: boolean; /** * A comma-delimited list of indices to restore from the snapshot. Multi-index syntax is supported. Example: `metrics*,logs*,data-20240823`. */ indices: string; /** * Throttles the restore rate per node. Defaults to unlimited. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxRestoreBytesPerSec?: string; /** * Throttles the snapshot rate per node. Defaults to 40mb. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxSnapshotBytesPerSec?: string; /** * Whether the repository is read-only. Default: `true`. */ readonly?: boolean; /** * If true, restore the cluster state. Defaults to false. */ restoreGlobalState?: boolean; /** * The snapshot name to restore from. */ snapshotName: string; } export interface GetOpenSearchOpensearchUserConfigIndexPattern { /** * Maximum number of indexes to keep. Example: `3`. */ maxIndexCount: number; /** * fnmatch pattern. Example: `logs_*_foo_*`. */ pattern: string; /** * Enum: `alphabetical`, `creationDate`. Deletion sorting algorithm. Default: `creationDate`. */ sortingAlgorithm?: string; } export interface GetOpenSearchOpensearchUserConfigIndexRollup { /** * Whether rollups are enabled in OpenSearch Dashboards. Defaults to true. */ rollupDashboardsEnabled?: boolean; /** * Whether the rollup plugin is enabled. Defaults to true. */ rollupEnabled?: boolean; /** * How many retries the plugin should attempt for failed rollup jobs. Defaults to 5. */ rollupSearchBackoffCount?: number; /** * The backoff time between retries for failed rollup jobs. Defaults to 1000ms. */ rollupSearchBackoffMillis?: number; /** * Whether OpenSearch should return all jobs that match all specified search terms. If disabled, OpenSearch returns just one, as opposed to all, of the jobs that matches the search terms. Defaults to false. */ rollupSearchSearchAllJobs?: boolean; } export interface GetOpenSearchOpensearchUserConfigIndexTemplate { /** * The maximum number of nested JSON objects that a single document can contain across all nested types. This limit helps to prevent out of memory errors when a document contains too many nested objects. Default is 10000. Deprecated, use an index template instead. Example: `10000`. */ mappingNestedObjectsLimit?: number; /** * The number of replicas each primary shard has. Deprecated, use an index template instead. Example: `1`. */ numberOfReplicas?: number; /** * The number of primary shards that an index should have. Deprecated, use an index template instead. Example: `1`. */ numberOfShards?: number; } export interface GetOpenSearchOpensearchUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetOpenSearchOpensearchUserConfigJwt { /** * Enables or disables JWT-based authentication for OpenSearch. When enabled, users can authenticate using JWT tokens. Default: `false`. */ enabled: boolean; /** * The maximum allowed time difference in seconds between the JWT issuer's clock and the OpenSearch server's clock. This helps prevent token validation failures due to minor time synchronization issues. Default: `20`. */ jwtClockSkewToleranceSeconds?: number; /** * The HTTP header name where the JWT token is transmitted. Typically `Authorization` for Bearer tokens. Default: `Authorization`. */ jwtHeader?: string; /** * If the JWT token is transmitted as a URL parameter instead of an HTTP header, specify the parameter name here. Example: `token`. */ jwtUrlParameter?: string; /** * If specified, the JWT must contain an `aud` claim that matches this value. This provides additional security by ensuring the JWT was issued for the expected audience. Example: `https://myapp.example.com`. */ requiredAudience?: string; /** * If specified, the JWT must contain an `iss` claim that matches this value. This provides additional security by ensuring the JWT was issued by the expected issuer. Example: `https://auth.example.com`. */ requiredIssuer?: string; /** * The key in the JWT payload that contains the user's roles. If specified, roles will be extracted from the JWT for authorization. Example: `roles`. */ rolesKey?: string; /** * The secret key used to sign and verify JWT tokens. This should be a secure, randomly generated key HMAC key or public RSA/ECDSA key. Example: `MrJiimVjKgjRKCSk0s6rcEuCz17v5ZyFRqKARfZbuZE= (HMAC) or -----BEGIN PUBLIC KEY----- * MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA... * -----END PUBLIC KEY----- (PEM)`. */ signingKey: string; /** * The key in the JWT payload that contains the user's subject identifier. If not specified, the `sub` claim is used by default. Example: `sub`. */ subjectKey?: string; } export interface GetOpenSearchOpensearchUserConfigOpenid { /** * The ID of the OpenID Connect client configured in your IdP. Required. */ clientId: string; /** * The client secret of the OpenID Connect client configured in your IdP. Required. */ clientSecret: string; /** * The URL of your IdP where the Security plugin can find the OpenID Connect metadata/configuration settings. Example: `https://test-account.okta.com/app/exk491jujcVc83LEX697/sso/saml/metadata`. */ connectUrl: string; /** * Enables or disables OpenID Connect authentication for OpenSearch. When enabled, users can authenticate using OpenID Connect with an Identity Provider. Default: `true`. */ enabled: boolean; /** * HTTP header name of the JWT token. Optional. Default is Authorization. Default: `Authorization`. */ header?: string; /** * The HTTP header that stores the token. Typically the Authorization header with the Bearer schema: Authorization: Bearer . Optional. Default is Authorization. Example: `preferredUsername`. */ jwtHeader?: string; /** * If the token is not transmitted in the HTTP header, but as an URL parameter, define the name of the parameter here. Optional. Example: `preferredUsername`. */ jwtUrlParameter?: string; /** * The maximum number of unknown key IDs in the time frame. Default is 10. Optional. Default: `10`. */ refreshRateLimitCount?: number; /** * The time frame to use when checking the maximum number of unknown key IDs, in milliseconds. Optional.Default is 10000 (10 seconds). Default: `10000`. */ refreshRateLimitTimeWindowMs?: number; /** * The key in the JSON payload that stores the user’s roles. The value of this key must be a comma-separated list of roles. Required only if you want to use roles in the JWT. Example: `roles`. */ rolesKey?: string; /** * The scope of the identity token issued by the IdP. Optional. Default is openid profile email address phone. */ scope?: string; /** * The key in the JSON payload that stores the user’s name. If not defined, the subject registered claim is used. Most IdP providers use the preferredUsername claim. Optional. Example: `preferredUsername`. */ subjectKey?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearch { /** * Explicitly allow or block automatic creation of indices. Defaults to true. */ actionAutoCreateIndexEnabled?: boolean; /** * Require explicit index names when deleting. */ actionDestructiveRequiresName?: boolean; /** * Opensearch Security Plugin Settings */ authFailureListeners?: outputs.GetOpenSearchOpensearchUserConfigOpensearchAuthFailureListeners; /** * Defines a limit of how much total remote data can be referenced as a ratio of the size of the disk reserved for the file cache. This is designed to be a safeguard to prevent oversubscribing a cluster. Defaults to 0. */ clusterFilecacheRemoteDataRatio?: number; /** * Controls the number of shards allowed in the cluster per data node. Example: `1000`. */ clusterMaxShardsPerNode?: number; clusterRemoteStore?: outputs.GetOpenSearchOpensearchUserConfigOpensearchClusterRemoteStore; /** * When set to true, OpenSearch attempts to evenly distribute the primary shards between the cluster nodes. Enabling this setting does not always guarantee an equal number of primary shards on each node, especially in the event of a failover. Changing this setting to false after it was set to true does not invoke redistribution of primary shards. Default is false. */ clusterRoutingAllocationBalancePreferPrimary?: boolean; /** * How many concurrent incoming/outgoing shard recoveries (normally replicas) are allowed to happen on a node. Defaults to node cpu count * 2. */ clusterRoutingAllocationNodeConcurrentRecoveries?: number; clusterSearchRequestSlowlog?: outputs.GetOpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlog; /** * Watermark settings */ diskWatermarks?: outputs.GetOpenSearchOpensearchUserConfigOpensearchDiskWatermarks; /** * Sender name placeholder to be used in Opensearch Dashboards and Opensearch keystore. Example: `alert-sender`. */ emailSenderName?: string; /** * Sender password for Opensearch alerts to authenticate with SMTP server. Example: `very-secure-mail-password`. */ emailSenderPassword?: string; /** * Sender username for Opensearch alerts. Example: `jane@example.com`. */ emailSenderUsername?: string; /** * Enable remote-backed storage. */ enableRemoteBackedStorage?: boolean; /** * Enable searchable snapshots. */ enableSearchableSnapshots?: boolean; /** * Enable/Disable security audit. */ enableSecurityAudit?: boolean; /** * Enable/Disable snapshot API for custom repositories, this requires security management to be enabled. */ enableSnapshotApi?: boolean; /** * Maximum content length for HTTP requests to the OpenSearch HTTP API, in bytes. */ httpMaxContentLength?: number; /** * The max size of allowed headers, in bytes. Example: `8192`. */ httpMaxHeaderSize?: number; /** * The max length of an HTTP URL, in bytes. Example: `4096`. */ httpMaxInitialLineLength?: number; /** * Relative amount. Maximum amount of heap memory used for field data cache. This is an expert setting; decreasing the value too much will increase overhead of loading field data; too much memory used for field data cache will decrease amount of heap available for other operations. */ indicesFielddataCacheSize?: number; /** * Percentage value. Default is 10%. Total amount of heap used for indexing buffer, before writing segments to disk. This is an expert setting. Too low value will slow down indexing; too high value will increase indexing performance but causes performance issues for query performance. */ indicesMemoryIndexBufferSize?: number; /** * Absolute value. Default is unbound. Doesn't work without indices.memory.index_buffer_size. Maximum amount of heap used for query cache, an absolute indices.memory.index_buffer_size maximum hard limit. */ indicesMemoryMaxIndexBufferSize?: number; /** * Absolute value. Default is 48mb. Doesn't work without indices.memory.index_buffer_size. Minimum amount of heap used for query cache, an absolute indices.memory.index_buffer_size minimal hard limit. */ indicesMemoryMinIndexBufferSize?: number; /** * Percentage value. Default is 10%. Maximum amount of heap used for query cache. This is an expert setting. Too low value will decrease query performance and increase performance for other operations; too high value will cause issues with other OpenSearch functionality. */ indicesQueriesCacheSize?: number; /** * Maximum number of clauses Lucene BooleanQuery can have. The default value (1024) is relatively high, and increasing it may cause performance issues. Investigate other approaches first before increasing this value. */ indicesQueryBoolMaxClauseCount?: number; /** * Limits total inbound and outbound recovery traffic for each node. Applies to both peer recoveries as well as snapshot recoveries (i.e., restores from a snapshot). Defaults to 40mb. */ indicesRecoveryMaxBytesPerSec?: number; /** * Number of file chunks sent in parallel for each recovery. Defaults to 2. */ indicesRecoveryMaxConcurrentFileChunks?: number; /** * Specifies whether ISM is enabled or not. */ ismEnabled?: boolean; /** * Specifies whether audit history is enabled or not. The logs from ISM are automatically indexed to a logs document. */ ismHistoryEnabled?: boolean; /** * The maximum age before rolling over the audit history index in hours. Example: `24`. */ ismHistoryMaxAge?: number; /** * The maximum number of documents before rolling over the audit history index. */ ismHistoryMaxDocs?: number; /** * The time between rollover checks for the audit history index in hours. Example: `8`. */ ismHistoryRolloverCheckPeriod?: number; /** * How long audit history indices are kept in days. Example: `30`. */ ismHistoryRolloverRetentionPeriod?: number; /** * Enable or disable KNN memory circuit breaker. Defaults to true. */ knnMemoryCircuitBreakerEnabled?: boolean; /** * Maximum amount of memory in percentage that can be used for the KNN index. Defaults to 50% of the JVM heap size. 0 is used to set it to null which can be used to invalidate caches. */ knnMemoryCircuitBreakerLimit?: number; /** * When set to true, the setting allows admins to control access and permissions to the connector API using backend_roles. Defaults to false. */ mlCommonsConnectorAccessControlEnabled?: boolean; /** * Enable or disable model access control for ML Commons. When enabled, access to ML models is controlled by security permissions. Defaults to false. */ mlCommonsModelAccessControlEnabled?: boolean; /** * Native memory threshold percentage for ML Commons. Controls the maximum percentage of native memory that can be used by ML Commons operations. Defaults to 90%. */ mlCommonsNativeMemoryThreshold?: number; /** * Enable or disable running ML Commons tasks only on ML nodes. When enabled, ML tasks will only execute on nodes designated as ML nodes. Defaults to true. */ mlCommonsOnlyRunOnMlNode?: boolean; /** * Adds the trusted endpoints to the cluster settings. Supports Java regex expressions. */ mlCommonsTrustedConnectorEndpointsRegexes?: string[]; /** * Defines a limit of how much total remote data can be referenced as a ratio of the size of the disk reserved for the file cache. This is designed to be a safeguard to prevent oversubscribing a cluster. Defaults to 5gb. Requires restarting all OpenSearch nodes. */ nodeSearchCacheSize?: string; /** * Compatibility mode sets OpenSearch to report its version as 7.10 so clients continue to work. Default is false. Deprecated and ignored for service version 3.3 and higher. */ overrideMainResponseVersion?: boolean; /** * Enable or disable filtering of alerting by backend roles. Requires Security plugin. Defaults to false. */ pluginsAlertingFilterByBackendRoles?: boolean; /** * Whitelisted addresses for reindexing. Changing this value will cause all OpenSearch instances to restart. */ reindexRemoteWhitelists?: string[]; remoteStore?: outputs.GetOpenSearchOpensearchUserConfigOpensearchRemoteStore; /** * Script compilation circuit breaker limits the number of inline script compilations within a period of time. Default is use-context. Example: `75/5m`. */ scriptMaxCompilationsRate?: string; /** * Search Backpressure Settings */ searchBackpressure?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressure; searchInsightsTopQueries?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueries; /** * Maximum number of aggregation buckets allowed in a single response. OpenSearch default value is used when this is not defined. Example: `10000`. */ searchMaxBuckets?: number; /** * Segment Replication Backpressure Settings */ segrep?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSegrep; /** * Shard indexing back pressure settings */ shardIndexingPressure?: outputs.GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressure; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolAnalyzeQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolAnalyzeSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolForceMergeSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolGetQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolGetSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolSearchQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolSearchSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolSearchThrottledQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolSearchThrottledSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolWriteQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolWriteSize?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchAuthFailureListeners { internalAuthenticationBackendLimiting?: outputs.GetOpenSearchOpensearchUserConfigOpensearchAuthFailureListenersInternalAuthenticationBackendLimiting; /** * IP address rate limiting settings * * @deprecated This property is deprecated. */ ipRateLimiting?: outputs.GetOpenSearchOpensearchUserConfigOpensearchAuthFailureListenersIpRateLimiting; } export interface GetOpenSearchOpensearchUserConfigOpensearchAuthFailureListenersInternalAuthenticationBackendLimiting { /** * The number of login attempts allowed before login is blocked. Example: `10`. */ allowedTries?: number; /** * Enum: `internal`. internal_authentication_backend_limiting.authentication_backend. */ authenticationBackend?: string; /** * The duration of time that login remains blocked after a failed login. Example: `600`. */ blockExpirySeconds?: number; /** * internal_authentication_backend_limiting.max_blocked_clients. Example: `100000`. */ maxBlockedClients?: number; /** * The maximum number of tracked IP addresses that have failed login. Example: `100000`. */ maxTrackedClients?: number; /** * The window of time in which the value for `allowedTries` is enforced. Example: `3600`. */ timeWindowSeconds?: number; /** * Enum: `username`. internal_authentication_backend_limiting.type. */ type?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchAuthFailureListenersIpRateLimiting { /** * The number of login attempts allowed before login is blocked. Example: `10`. */ allowedTries?: number; /** * The duration of time that login remains blocked after a failed login. Example: `600`. */ blockExpirySeconds?: number; /** * The maximum number of blocked IP addresses. Example: `100000`. */ maxBlockedClients?: number; /** * The maximum number of tracked IP addresses that have failed login. Example: `100000`. */ maxTrackedClients?: number; /** * The window of time in which the value for `allowedTries` is enforced. Example: `3600`. */ timeWindowSeconds?: number; /** * Enum: `ip`. The type of rate limiting. */ type?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchClusterRemoteStore { /** * The amount of time to wait for the cluster state upload to complete. Defaults to 20s. */ stateGlobalMetadataUploadTimeout?: string; /** * The amount of time to wait for the manifest file upload to complete. The manifest file contains the details of each of the files uploaded for a single cluster state, both index metadata files and global metadata files. Defaults to 20s. */ stateMetadataManifestUploadTimeout?: string; /** * The default value of the translog buffer interval used when performing periodic translog updates. This setting is only effective when the index setting `index.remote_store.translog.buffer_interval` is not present. Defaults to 650ms. */ translogBufferInterval?: string; /** * Sets the maximum number of open translog files for remote-backed indexes. This limits the total number of translog files per shard. After reaching this limit, the remote store flushes the translog files. Default is 1000. The minimum required is 100. Example: `1000`. */ translogMaxReaders?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlog { /** * Enum: `debug`, `info`, `trace`, `warn`. Log level. Default: `trace`. */ level?: string; threshold?: outputs.GetOpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlogThreshold; } export interface GetOpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlogThreshold { /** * Debug threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ debug?: string; /** * Info threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ info?: string; /** * Trace threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ trace?: string; /** * Warning threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ warn?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchDashboards { /** * Enable or disable OpenSearch Dashboards. Default: `true`. */ enabled?: boolean; /** * Limits the maximum amount of memory (in MiB) the OpenSearch Dashboards process can use. This sets the maxOldSpaceSize option of the nodejs running the OpenSearch Dashboards. Note: the memory reserved by OpenSearch Dashboards is not available for OpenSearch. Default: `128`. */ maxOldSpaceSize?: number; /** * Enable or disable multiple data sources in OpenSearch Dashboards. Default: `true`. */ multipleDataSourceEnabled?: boolean; /** * Timeout in milliseconds for requests made by OpenSearch Dashboards towards OpenSearch. Default: `30000`. */ opensearchRequestTimeout?: number; /** * Determines whether the session TTL resets (is “kept alive”) on each user activity. Optional. Default is true. Default: `true`. */ sessionKeepalive?: boolean; /** * Defines the time-to-live (TTL) for user sessions. The value should be a time value with unit, e.g. 1m, 5s, 1h, 3d, 100ms. Default is 1 hour. Default: `1h`. */ sessionTtl?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchDiskWatermarks { /** * The flood stage watermark for disk usage. Example: `95`. */ floodStage: number; /** * The high watermark for disk usage. Example: `90`. */ high: number; /** * The low watermark for disk usage. Example: `85`. */ low: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchRemoteStore { /** * The variance factor that is used together with the moving average to calculate the dynamic bytes lag threshold for activating remote segment backpressure. Defaults to 10. */ segmentPressureBytesLagVarianceFactor?: number; /** * The minimum consecutive failure count for activating remote segment backpressure. Defaults to 5. */ segmentPressureConsecutiveFailuresLimit?: number; /** * Enables remote segment backpressure. Default is `true`. */ segmentPressureEnabled?: boolean; /** * The variance factor that is used together with the moving average to calculate the dynamic time lag threshold for activating remote segment backpressure. Defaults to 10. */ segmentPressureTimeLagVarianceFactor?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressure { /** * Enum: `disabled`, `enforced`, `monitorOnly`. The search backpressure mode. Valid values are monitor_only, enforced, or disabled. Default is monitor_only. */ mode?: string; /** * Node duress settings */ nodeDuress?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressureNodeDuress; /** * Search shard settings */ searchShardTask?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchShardTask; /** * Search task settings */ searchTask?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchTask; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressureNodeDuress { /** * The CPU usage threshold (as a percentage) required for a node to be considered to be under duress. Default is 0.9. */ cpuThreshold?: number; /** * The heap usage threshold (as a percentage) required for a node to be considered to be under duress. Default is 0.7. */ heapThreshold?: number; /** * The number of successive limit breaches after which the node is considered to be under duress. Default is 3. */ numSuccessiveBreaches?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchShardTask { /** * The maximum number of search tasks to cancel in a single iteration of the observer thread. Default is 10.0. */ cancellationBurst?: number; /** * The maximum number of tasks to cancel per millisecond of elapsed time. Default is 0.003. */ cancellationRate?: number; /** * The maximum number of tasks to cancel, as a percentage of successful task completions. Default is 0.1. */ cancellationRatio?: number; /** * The CPU usage threshold (in milliseconds) required for a single search shard task before it is considered for cancellation. Default is 15000. */ cpuTimeMillisThreshold?: number; /** * The elapsed time threshold (in milliseconds) required for a single search shard task before it is considered for cancellation. Default is 30000. */ elapsedTimeMillisThreshold?: number; /** * The number of previously completed search shard tasks to consider when calculating the rolling average of heap usage. Default is 100. */ heapMovingAverageWindowSize?: number; /** * The heap usage threshold (as a percentage) required for a single search shard task before it is considered for cancellation. Default is 0.5. */ heapPercentThreshold?: number; /** * The minimum variance required for a single search shard task’s heap usage compared to the rolling average of previously completed tasks before it is considered for cancellation. Default is 2.0. */ heapVariance?: number; /** * The heap usage threshold (as a percentage) required for the sum of heap usages of all search shard tasks before cancellation is applied. Default is 0.5. */ totalHeapPercentThreshold?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchTask { /** * The maximum number of search tasks to cancel in a single iteration of the observer thread. Default is 5.0. */ cancellationBurst?: number; /** * The maximum number of search tasks to cancel per millisecond of elapsed time. Default is 0.003. */ cancellationRate?: number; /** * The maximum number of search tasks to cancel, as a percentage of successful search task completions. Default is 0.1. */ cancellationRatio?: number; /** * The CPU usage threshold (in milliseconds) required for an individual parent task before it is considered for cancellation. Default is 30000. */ cpuTimeMillisThreshold?: number; /** * The elapsed time threshold (in milliseconds) required for an individual parent task before it is considered for cancellation. Default is 45000. */ elapsedTimeMillisThreshold?: number; /** * The window size used to calculate the rolling average of the heap usage for the completed parent tasks. Default is 10. */ heapMovingAverageWindowSize?: number; /** * The heap usage threshold (as a percentage) required for an individual parent task before it is considered for cancellation. Default is 0.2. */ heapPercentThreshold?: number; /** * The heap usage variance required for an individual parent task before it is considered for cancellation. A task is considered for cancellation when taskHeapUsage is greater than or equal to heapUsageMovingAverage * variance. Default is 2.0. */ heapVariance?: number; /** * The heap usage threshold (as a percentage) required for the sum of heap usages of all search tasks before cancellation is applied. Default is 0.5. */ totalHeapPercentThreshold?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueries { /** * Top N queries monitoring by CPU */ cpu?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesCpu; /** * Top N queries monitoring by latency */ latency?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesLatency; /** * Top N queries monitoring by memory */ memory?: outputs.GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesMemory; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesCpu { /** * Enable or disable top N query monitoring by the metric. Default: `false`. */ enabled?: boolean; /** * Specify the value of N for the top N queries by the metric. */ topNSize?: number; /** * Configure the window size of the top N queries. The value should be a time value with unit, e.g. 1m, 5s, 1h. */ windowSize?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesLatency { /** * Enable or disable top N query monitoring by the metric. Default: `false`. */ enabled?: boolean; /** * Specify the value of N for the top N queries by the metric. */ topNSize?: number; /** * Configure the window size of the top N queries. The value should be a time value with unit, e.g. 1m, 5s, 1h. */ windowSize?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesMemory { /** * Enable or disable top N query monitoring by the metric. Default: `false`. */ enabled?: boolean; /** * Specify the value of N for the top N queries by the metric. */ topNSize?: number; /** * Configure the window size of the top N queries. The value should be a time value with unit, e.g. 1m, 5s, 1h. */ windowSize?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchSegrep { /** * The maximum number of indexing checkpoints that a replica shard can fall behind when copying from primary. Once `segrep.pressure.checkpoint.limit` is breached along with `segrep.pressure.time.limit`, the segment replication backpressure mechanism is initiated. Default is 4 checkpoints. Default: `4`. */ pressureCheckpointLimit?: number; /** * Enables the segment replication backpressure mechanism. Default is false. Default: `false`. */ pressureEnabled?: boolean; /** * The maximum number of stale replica shards that can exist in a replication group. Once `segrep.pressure.replica.stale.limit` is breached, the segment replication backpressure mechanism is initiated. Default is .5, which is 50% of a replication group. Default: `0.5`. */ pressureReplicaStaleLimit?: number; /** * The maximum amount of time that a replica shard can take to copy from the primary shard. Once segrep.pressure.time.limit is breached along with segrep.pressure.checkpoint.limit, the segment replication backpressure mechanism is initiated. Default is 5 minutes. Default: `5m`. */ pressureTimeLimit?: string; } export interface GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressure { /** * Enable or disable shard indexing backpressure. Default is false. */ enabled?: boolean; /** * Run shard indexing backpressure in shadow mode or enforced mode. In shadow mode (value set as false), shard indexing backpressure tracks all granular-level metrics, but it doesn’t actually reject any indexing requests. In enforced mode (value set as true), shard indexing backpressure rejects any requests to the cluster that might cause a dip in its performance. Default is false. */ enforced?: boolean; /** * Operating factor */ operatingFactor?: outputs.GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressureOperatingFactor; /** * Primary parameter */ primaryParameter?: outputs.GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameter; } export interface GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressureOperatingFactor { /** * Specify the lower occupancy limit of the allocated quota of memory for the shard. If the total memory usage of a shard is below this limit, shard indexing backpressure decreases the current allocated memory for that shard. Default is 0.75. */ lower?: number; /** * Specify the optimal occupancy of the allocated quota of memory for the shard. If the total memory usage of a shard is at this level, shard indexing backpressure doesn’t change the current allocated memory for that shard. Default is 0.85. */ optimal?: number; /** * Specify the upper occupancy limit of the allocated quota of memory for the shard. If the total memory usage of a shard is above this limit, shard indexing backpressure increases the current allocated memory for that shard. Default is 0.95. */ upper?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameter { node?: outputs.GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterNode; shard?: outputs.GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterShard; } export interface GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterNode { /** * Define the percentage of the node-level memory threshold that acts as a soft indicator for strain on a node. Default is 0.7. */ softLimit?: number; } export interface GetOpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterShard { /** * Specify the minimum assigned quota for a new shard in any role (coordinator, primary, or replica). Shard indexing backpressure increases or decreases this allocated quota based on the inflow of traffic for the shard. Default is 0.001. */ minLimit?: number; } export interface GetOpenSearchOpensearchUserConfigPrivateAccess { /** * Allow clients to connect to opensearch with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ opensearch?: boolean; /** * Allow clients to connect to opensearchDashboards with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ opensearchDashboards?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface GetOpenSearchOpensearchUserConfigPrivatelinkAccess { /** * Enable opensearch. */ opensearch?: boolean; /** * Enable opensearch_dashboards. */ opensearchDashboards?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetOpenSearchOpensearchUserConfigPublicAccess { /** * Allow clients to connect to opensearch from the public internet for service nodes that are in a project VPC or another type of private network. */ opensearch?: boolean; /** * Allow clients to connect to opensearchDashboards from the public internet for service nodes that are in a project VPC or another type of private network. */ opensearchDashboards?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface GetOpenSearchOpensearchUserConfigS3Migration { /** * AWS Access key. */ accessKey: string; /** * The path to the repository data within its container. The value of this setting should not start or end with a /. */ basePath: string; /** * S3 bucket name. */ bucket: string; /** * Big files can be broken down into chunks during snapshotting if needed. Should be the same as for the 3rd party repository. */ chunkSize?: string; /** * When set to true metadata files are stored in compressed format. */ compress?: boolean; /** * The S3 service endpoint to connect to. If you are using an S3-compatible service then you should set this to the service’s endpoint. */ endpoint?: string; /** * Whether to restore aliases alongside their associated indexes. Default is true. */ includeAliases?: boolean; /** * A comma-delimited list of indices to restore from the snapshot. Multi-index syntax is supported. Example: `metrics*,logs*,data-20240823`. */ indices: string; /** * Throttles the restore rate per node. Defaults to unlimited. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxRestoreBytesPerSec?: string; /** * Throttles the snapshot rate per node. Defaults to 40mb. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxSnapshotBytesPerSec?: string; /** * Whether the repository is read-only. Default: `true`. */ readonly?: boolean; /** * S3 region. */ region: string; /** * If true, restore the cluster state. Defaults to false. */ restoreGlobalState?: boolean; /** * AWS secret key. */ secretKey: string; /** * When set to true files are encrypted on server side. */ serverSideEncryption?: boolean; /** * The snapshot name to restore from. */ snapshotName: string; } export interface GetOpenSearchOpensearchUserConfigSaml { /** * Enables or disables SAML-based authentication for OpenSearch. When enabled, users can authenticate using SAML with an Identity Provider. Default: `true`. */ enabled: boolean; /** * The unique identifier for the Identity Provider (IdP) entity that is used for SAML authentication. This value is typically provided by the IdP. Example: `test-idp-entity-id`. */ idpEntityId: string; /** * The URL of the SAML metadata for the Identity Provider (IdP). This is used to configure SAML-based authentication with the IdP. Example: `https://test-account.okta.com/app/exk491jujcVc83LEX697/sso/saml/metadata`. */ idpMetadataUrl: string; /** * This parameter specifies the PEM-encoded root certificate authority (CA) content for the SAML identity provider (IdP) server verification. The root CA content is used to verify the SSL/TLS certificate presented by the server. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ idpPemtrustedcasContent?: string; /** * Optional. Specifies the attribute in the SAML response where role information is stored, if available. Role attributes are not required for SAML authentication, but can be included in SAML assertions by most Identity Providers (IdPs) to determine user access levels or permissions. Example: `RoleName`. */ rolesKey?: string; /** * The unique identifier for the Service Provider (SP) entity that is used for SAML authentication. This value is typically provided by the SP. Example: `test-sp-entity-id`. */ spEntityId: string; /** * Optional. Specifies the attribute in the SAML response where the subject identifier is stored. If not configured, the NameID attribute is used by default. Example: `NameID`. */ subjectKey?: string; } export interface GetOpenSearchServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetOpenSearchTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetOpenSearchTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetOpensearchSecurityPluginConfigTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOpensearchUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationAddressTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationApplicationUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationBillingGroupBillingContactEmail { /** * Email. */ email: string; } export interface GetOrganizationBillingGroupBillingEmail { /** * Email. */ email: string; } export interface GetOrganizationBillingGroupListBillingGroup { /** * Billing address ID. */ billingAddressId: string; /** * List of billing contact emails. */ billingContactEmails?: outputs.GetOrganizationBillingGroupListBillingGroupBillingContactEmail[]; /** * List of billing contact emails. */ billingEmails?: outputs.GetOrganizationBillingGroupListBillingGroupBillingEmail[]; /** * Billing group ID. */ billingGroupId: string; /** * Billing Group Name. */ billingGroupName: string; /** * The date when this billing group was created. */ createTime: string; /** * Extra billing text. */ customInvoiceText: string; /** * Organization ID. */ organizationId: string; /** * Payment method. */ paymentMethods?: outputs.GetOrganizationBillingGroupListBillingGroupPaymentMethod[]; /** * Shipping address ID. */ shippingAddressId: string; /** * VAT ID. */ vatId: string; } export interface GetOrganizationBillingGroupListBillingGroupBillingContactEmail { /** * Email. */ email: string; } export interface GetOrganizationBillingGroupListBillingGroupBillingEmail { /** * Email. */ email: string; } export interface GetOrganizationBillingGroupListBillingGroupPaymentMethod { /** * Payment method ID. */ paymentMethodId: string; /** * An enumeration. The possible values are `awsSubscription`, `azureSubscription`, `bankTransfer`, `creditCard`, `custom` and `gcpSubscription`. */ paymentMethodType: string; } export interface GetOrganizationBillingGroupListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationBillingGroupPaymentMethod { /** * Payment method ID. */ paymentMethodId: string; /** * An enumeration. The possible values are `awsSubscription`, `azureSubscription`, `bankTransfer`, `creditCard`, `custom` and `gcpSubscription`. */ paymentMethodType: string; } export interface GetOrganizationBillingGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationPaymentMethodListPaymentMethod { /** * Payment method ID. */ paymentMethodId: string; /** * An enumeration. The possible values are `awsSubscription`, `azureSubscription`, `bankTransfer`, `creditCard`, `custom` and `gcpSubscription`. */ paymentMethodType: string; } export interface GetOrganizationPaymentMethodListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationProjectTag { /** * Project tag key. */ key: string; /** * Project tag value. */ value: string; } export interface GetOrganizationProjectTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationUserGroupListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationUserGroupListUserGroup { /** * User group creation time. */ createTime: string; /** * Description. */ description: string; /** * Managed By Scim. */ managedByScim: boolean; /** * Member Count. */ memberCount: number; /** * User group last update time. */ updateTime: string; /** * User Group ID. */ userGroupId: string; /** * User Group Name. */ userGroupName: string; } export interface GetOrganizationUserGroupMemberListMember { /** * Last Activity Time. */ lastActivityTime: string; /** * User ID. */ userId: string; /** * OrganizationUserInfo. */ userInfos?: outputs.GetOrganizationUserGroupMemberListMemberUserInfo[]; } export interface GetOrganizationUserGroupMemberListMemberUserInfo { /** * City. */ city: string; /** * Country. */ country: string; /** * Creation time. */ createTime: string; /** * Department. */ department: string; /** * Is Application User. */ isApplicationUser: boolean; /** * Job Title. */ jobTitle: string; /** * Managed By Scim. */ managedByScim: boolean; /** * Managing Organization ID. */ managingOrganizationId: string; /** * Real Name. */ realName: string; /** * State. */ state: string; /** * User Email. */ userEmail: string; } export interface GetOrganizationUserGroupMemberListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationUserGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationUserListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationUserListUser { /** * Super admin state of the organization user. */ isSuperAdmin: boolean; /** * Join time. */ joinTime: string; /** * Last activity time. */ lastActivityTime: string; /** * User ID. */ userId: string; /** * OrganizationUserInfo. */ userInfos?: outputs.GetOrganizationUserListUserUserInfo[]; } export interface GetOrganizationUserListUserUserInfo { /** * City. */ city: string; /** * Country. */ country: string; /** * Creation time. */ createTime: string; /** * Department. */ department: string; /** * Is Application User. */ isApplicationUser: boolean; /** * Job Title. */ jobTitle: string; /** * Managed By Scim. */ managedByScim: boolean; /** * Managing Organization ID. */ managingOrganizationId: string; /** * Real Name. */ realName: string; /** * State. */ state: string; /** * User Email. */ userEmail: string; } export interface GetOrganizationVpcTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetOrganizationalUnitTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetPgComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetPgDatabaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetPgPg { /** * PgBouncer connection details for [connection pooling](https://aiven.io/docs/products/postgresql/concepts/pg-connection-pooling). * * @deprecated This field was added by mistake and has never worked. It will be removed in future versions. */ bouncer: string; /** * Primary PostgreSQL database name. */ dbname: string; /** * PostgreSQL primary node host IP or name. */ host: string; /** * The [number of allowed connections](https://aiven.io/docs/products/postgresql/reference/pg-connection-limits). Varies based on the service plan. */ maxConnections: number; /** * PostgreSQL connection parameters. */ params: outputs.GetPgPgParam[]; /** * PostgreSQL admin user password. */ password: string; /** * PostgreSQL port. */ port: number; /** * PostgreSQL replica URI for services with a replica. */ replicaUri: string; /** * PostgreSQL SSL mode setting. */ sslmode: string; /** * PostgreSQL standby connection URIs. */ standbyUris: string[]; /** * PostgreSQL syncing connection URIs. */ syncingUris: string[]; /** * PostgreSQL primary connection URI. */ uri: string; /** * PostgreSQL primary connection URIs. */ uris: string[]; /** * PostgreSQL admin user name. */ user: string; } export interface GetPgPgParam { /** * Primary PostgreSQL database name. */ databaseName: string; /** * PostgreSQL host IP or name. */ host: string; /** * PostgreSQL admin user password. */ password: string; /** * PostgreSQL port. */ port: number; /** * PostgreSQL SSL mode setting. */ sslmode: string; /** * PostgreSQL admin user name. */ user: string; } export interface GetPgPgUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Custom password for admin user. Defaults to random string. This must be set only when a new service is being created. */ adminPassword?: string; /** * Custom username for admin user. This must be set only when a new service is being created. Example: `avnadmin`. */ adminUsername?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Example: `3`. */ backupHour?: number; /** * Enum: `12`, `24`, `3`, `4`, `6`, `8`. Interval in hours between automatic backups. Minimum value is 3 hours. Must be a divisor of 24 (3, 4, 6, 8, 12, 24). (Applicable to ACU plans only). */ backupIntervalHours?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Example: `30`. */ backupMinute?: number; /** * Number of days to retain automatic backups. Backups older than this value will be automatically deleted. (Applicable to ACU plans only). Example: `7`. */ backupRetentionDays?: number; /** * Creates a dedicated read-only DNS that automatically falls back to the primary if standby nodes are unavailable. It switches back when a standby recovers. Default: `false`. */ enableHaReplicaDns?: boolean; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetPgPgUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.GetPgPgUserConfigMigration; /** * Number of nodes for the service. Example: `3`. */ nodeCount?: number; /** * postgresql.conf configuration values */ pg?: outputs.GetPgPgUserConfigPg; /** * System-wide settings for the pgQualstats extension * * @deprecated This property is deprecated. */ pgQualstats?: outputs.GetPgPgUserConfigPgQualstats; /** * Should the service which is being forked be a read replica (deprecated, use readReplica service integration instead). */ pgReadReplica?: boolean; /** * Name of the PG Service from which to fork (deprecated, use service_to_fork_from). This has effect only when a new service is being created. Example: `anotherservicename`. */ pgServiceToForkFrom?: string; /** * Enable the pgStatMonitor extension. Changing this parameter causes a service restart. When this extension is enabled, pgStatStatements results for utility commands are unreliable. Default: `false`. */ pgStatMonitorEnable?: boolean; /** * Enable the pgStatPlans extension. Changing this parameter causes a service restart. Tracks execution plans for SQL queries. Default: `false`. */ pgStatPlansEnable?: boolean; /** * Enum: `10`, `11`, `12`, `13`, `14`, `15`, `16`, `17`, `18`, and newer. PostgreSQL major version. */ pgVersion?: string; /** * System-wide settings for the pgaudit extension */ pgaudit?: outputs.GetPgPgUserConfigPgaudit; /** * PGBouncer connection pooling settings */ pgbouncer?: outputs.GetPgPgUserConfigPgbouncer; /** * System-wide settings for pglookout */ pglookout?: outputs.GetPgPgUserConfigPglookout; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetPgPgUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetPgPgUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetPgPgUserConfigPublicAccess; /** * Recovery target time when forking a service. This has effect only when a new service is being created. Example: `2019-01-01 23:34:45`. */ recoveryTargetTime?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Percentage of total RAM that the database server uses for shared memory buffers. Valid range is 20-60 (float), which corresponds to 20% - 60%. This setting adjusts the sharedBuffers configuration value. Changing this parameter causes a service restart. Example: `41.5`. */ sharedBuffersPercentage?: number; /** * Use static public IP addresses. */ staticIps?: boolean; switchoverWindows?: outputs.GetPgPgUserConfigSwitchoverWindow[]; /** * Enum: `off`, `quorum`. Use synchronousCommit instead. Any change to this setting will automatically update synchronous_commit. Setting the value to quorum changes synchronousCommit to remote_write, while setting it to off changes synchronousCommit to off. */ synchronousReplication?: string; /** * System-wide settings for the timescaledb extension */ timescaledb?: outputs.GetPgPgUserConfigTimescaledb; /** * Enum: `aiven`, `timescale`. Variant of the PostgreSQL service, may affect the features that are exposed by default. */ variant?: string; /** * Sets the maximum amount of memory to be used by a query operation (such as a sort or hash table) before writing to temporary disk files, in MB. The default is 1MB + 0.075% of total RAM (up to 32MB). Example: `4`. */ workMem?: number; } export interface GetPgPgUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetPgPgUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface GetPgPgUserConfigPg { /** * Specifies a fraction of the table size to add to autovacuumAnalyzeThreshold when deciding whether to trigger an ANALYZE (e.g. `0.2` for 20% of the table size). The default is `0.2`. */ autovacuumAnalyzeScaleFactor?: number; /** * Specifies the minimum number of inserted, updated or deleted tuples needed to trigger an ANALYZE in any one table. The default is `50`. */ autovacuumAnalyzeThreshold?: number; /** * Specifies the maximum age (in transactions) that a table's pg_class.relfrozenxid field can attain before a VACUUM operation is forced to prevent transaction ID wraparound within the table. The system launches autovacuum processes to prevent wraparound even when autovacuum is otherwise disabled. Changing this parameter causes a service restart. */ autovacuumFreezeMaxAge?: number; /** * Specifies the maximum number of autovacuum processes (other than the autovacuum launcher) that may be running at any one time. The default is `3`. Changing this parameter causes a service restart. */ autovacuumMaxWorkers?: number; /** * Specifies the minimum delay between autovacuum runs on any given database. The delay is measured in seconds. The default is `60`. */ autovacuumNaptime?: number; /** * Specifies the cost delay value that will be used in automatic VACUUM operations. If `-1` is specified, the regular vacuumCostDelay value will be used. The default is `2` (upstream default). */ autovacuumVacuumCostDelay?: number; /** * Specifies the cost limit value that will be used in automatic VACUUM operations. If `-1` is specified, the regular vacuumCostLimit value will be used. The default is `-1` (upstream default). */ autovacuumVacuumCostLimit?: number; /** * Specifies a fraction of the table size to add to autovacuumVacuumThreshold when deciding whether to trigger a VACUUM (e.g. `0.2` for 20% of the table size). The default is `0.2`. */ autovacuumVacuumScaleFactor?: number; /** * Specifies the minimum number of updated or deleted tuples needed to trigger a VACUUM in any one table. The default is `50`. */ autovacuumVacuumThreshold?: number; /** * Specifies the delay between activity rounds for the background writer in milliseconds. The default is `200`. Example: `200`. */ bgwriterDelay?: number; /** * Whenever more than bgwriterFlushAfter bytes have been written by the background writer, attempt to force the OS to issue these writes to the underlying storage. Specified in kilobytes. Setting of 0 disables forced writeback. The default is `512`. Example: `512`. */ bgwriterFlushAfter?: number; /** * In each round, no more than this many buffers will be written by the background writer. Setting this to zero disables background writing. The default is `100`. Example: `100`. */ bgwriterLruMaxpages?: number; /** * The average recent need for new buffers is multiplied by bgwriterLruMultiplier to arrive at an estimate of the number that will be needed during the next round, (up to bgwriter_lru_maxpages). 1.0 represents a “just in time” policy of writing exactly the number of buffers predicted to be needed. Larger values provide some cushion against spikes in demand, while smaller values intentionally leave writes to be done by server processes. The default is `2.0`. Example: `2`. */ bgwriterLruMultiplier?: number; /** * This is the amount of time, in milliseconds, to wait on a lock before checking to see if there is a deadlock condition. The default is `1000` (upstream default). Example: `1000`. */ deadlockTimeout?: number; /** * Enum: `lz4`, `pglz`. Specifies the default TOAST compression method for values of compressible columns. The default is `lz4`. Only available for PostgreSQL 14+. */ defaultToastCompression?: string; /** * Time out sessions with open transactions after this number of milliseconds. */ idleInTransactionSessionTimeout?: number; /** * EXPERIMENTAL: Controls the largest I/O size in operations that combine I/O in 8kB units. Version 17 and up only. Default: `16`. */ ioCombineLimit?: number; /** * EXPERIMENTAL: Controls the largest I/O size in operations that combine I/O in 8kB units, and silently limits the user-settable parameter io_combine_limit. Version 18 and up only. Changing this parameter causes a service restart. Default: `16`. */ ioMaxCombineLimit?: number; /** * EXPERIMENTAL: Controls the maximum number of I/O operations that one process can execute simultaneously. Version 18 and up only. Changing this parameter causes a service restart. Default: `-1`. */ ioMaxConcurrency?: number; /** * Enum: `ioUring`, `sync`, `worker`. EXPERIMENTAL: Controls the maximum number of I/O operations that one process can execute simultaneously. Version 18 and up only. Changing this parameter causes a service restart. Default: `worker`. */ ioMethod?: string; /** * EXPERIMENTAL: Number of IO worker processes, for io_method=worker. Version 18 and up only. */ ioWorkers?: number; /** * Controls system-wide use of Just-in-Time Compilation (JIT). */ jit?: boolean; /** * Causes each action executed by autovacuum to be logged if it ran for at least the specified number of milliseconds. Setting this to zero logs all autovacuum actions. Minus-one disables logging autovacuum actions. The default is `1000`. */ logAutovacuumMinDuration?: number; /** * Enum: `DEFAULT`, `TERSE`, `VERBOSE`. Controls the amount of detail written in the server log for each message that is logged. */ logErrorVerbosity?: string; /** * Enum: `'%m [%p] %q[user=%u,db=%d,app=%a] '`, `'%t [%p]: [%l-1] user=%u,db=%d,app=%a,client=%h '`, `'pid=%p,user=%u,db=%d,app=%a,client=%h '`, `'pid=%p,user=%u,db=%d,app=%a,client=%h,txid=%x,qid=%Q '`. Choose from one of the available log formats. */ logLinePrefix?: string; /** * Log statements that take more than this number of milliseconds to run, -1 disables. */ logMinDurationStatement?: number; /** * Log statements for each temporary file created larger than this number of kilobytes, -1 disables. */ logTempFiles?: number; /** * Sets the PostgreSQL maximum number of concurrent connections to the database server. For services with a read replica, first increase the read replica's value. After the change is applied to the replica, you can increase the primary service's value. Changing this parameter causes a service restart. */ maxConnections?: number; /** * PostgreSQL maximum number of files that can be open per process. The default is `1000` (upstream default). Changing this parameter causes a service restart. */ maxFilesPerProcess?: number; /** * PostgreSQL maximum locks per transaction. Changing this parameter causes a service restart. */ maxLocksPerTransaction?: number; /** * PostgreSQL maximum logical replication workers (taken from the pool defined by max_worker_processes). The default is `4` (upstream default). Changing this parameter causes a service restart. */ maxLogicalReplicationWorkers?: number; /** * Sets the maximum number of workers that the system can support for parallel queries. The default is `8` (upstream default). */ maxParallelWorkers?: number; /** * Sets the maximum number of workers that can be started by a single Gather or Gather Merge node. The default is `2` (upstream default). */ maxParallelWorkersPerGather?: number; /** * PostgreSQL maximum predicate locks per transaction. The default is `64` (upstream default). Changing this parameter causes a service restart. */ maxPredLocksPerTransaction?: number; /** * PostgreSQL maximum prepared transactions. The default is `0`. Changing this parameter causes a service restart. */ maxPreparedTransactions?: number; /** * PostgreSQL maximum replication slots. The default is `20`. Changing this parameter causes a service restart. */ maxReplicationSlots?: number; /** * PostgreSQL maximum WAL size (MB) reserved for replication slots. If `-1` is specified, replication slots may retain an unlimited amount of WAL files. The default is `-1` (upstream default). walKeepSize minimum WAL size setting takes precedence over this. */ maxSlotWalKeepSize?: number; /** * Maximum depth of the stack in bytes. The default is `2097152` (upstream default). */ maxStackDepth?: number; /** * Max standby archive delay in milliseconds. The default is `30000` (upstream default). */ maxStandbyArchiveDelay?: number; /** * Max standby streaming delay in milliseconds. The default is `30000` (upstream default). */ maxStandbyStreamingDelay?: number; /** * Maximum number of synchronization workers per subscription. The default is `2`. */ maxSyncWorkersPerSubscription?: number; /** * PostgreSQL maximum WAL senders. The default is `20`. Changing this parameter causes a service restart. */ maxWalSenders?: number; /** * Sets the maximum number of background processes that the system can support. The default is `8`. Changing this parameter causes a service restart. */ maxWorkerProcesses?: number; /** * Enum: `md5`, `scram-sha-256`. Chooses the algorithm for encrypting passwords. */ passwordEncryption?: string; /** * Sets the time interval in seconds to run pg_partman's scheduled tasks. The default is `3600`. Example: `3600`. */ pgPartmanBgwDotInterval?: number; /** * Controls which role to use for pg_partman's scheduled background tasks. Example: `myrolename`. */ pgPartmanBgwDotRole?: string; /** * Enables or disables query plan monitoring. Only available for PostgreSQL 13+. */ pgStatMonitorDotPgsmEnableQueryPlan?: boolean; /** * Sets the maximum number of buckets. Changing this parameter causes a service restart. Only available for PostgreSQL 13+. Example: `10`. */ pgStatMonitorDotPgsmMaxBuckets?: number; /** * Enum: `all`, `none`, `top`. Controls which statements' plans are tracked. Specify top to track top-level statements (those issued directly by clients), all to also track nested statements (such as statements invoked within functions), or none to disable plan tracking. The default is `top`. */ pgStatPlansDotTrack?: string; /** * Enum: `all`, `none`, `top`. Controls which statements are counted. Specify top to track top-level statements (those issued directly by clients), all to also track nested statements (such as statements invoked within functions), or none to disable statement statistics collection. The default is `top`. */ pgStatStatementsDotTrack?: string; /** * Enum: `local`, `off`, `on`, `remoteApply`, `remoteWrite`. Sets the current transaction's synchronization level. The default is `off`. This setting takes precedence over `synchronousReplication`. */ synchronousCommit?: string; /** * PostgreSQL temporary file limit in KiB, -1 for unlimited. */ tempFileLimit?: number; /** * PostgreSQL service timezone. Example: `Europe/Helsinki`. */ timezone?: string; /** * Specifies the number of bytes reserved to track the currently executing command for each active session. Changing this parameter causes a service restart. Example: `1024`. */ trackActivityQuerySize?: number; /** * Enum: `off`, `on`. Record commit time of transactions. Changing this parameter causes a service restart. */ trackCommitTimestamp?: string; /** * Enum: `all`, `none`, `pl`. Enables tracking of function call counts and time used. */ trackFunctions?: string; /** * Enum: `off`, `on`. Enables timing of database I/O calls. The default is `off`. When on, it will repeatedly query the operating system for the current time, which may cause significant overhead on some platforms. */ trackIoTiming?: string; /** * Terminate replication connections that are inactive for longer than this amount of time, in milliseconds. Setting this value to zero disables the timeout. Example: `60000`. */ walSenderTimeout?: number; /** * WAL flush interval in milliseconds. The default is `200`. Setting this parameter to a lower value may negatively impact performance. Example: `50`. */ walWriterDelay?: number; } export interface GetPgPgUserConfigPgQualstats { /** * Enable / Disable pg_qualstats. Default: `false`. * * @deprecated This property is deprecated. */ enabled?: boolean; /** * Error estimation num threshold to save quals. Default: `0`. * * @deprecated This property is deprecated. */ minErrEstimateNum?: number; /** * Error estimation ratio threshold to save quals. Default: `0`. * * @deprecated This property is deprecated. */ minErrEstimateRatio?: number; /** * Enable / Disable pgQualstats constants tracking. Default: `true`. * * @deprecated This property is deprecated. */ trackConstants?: boolean; /** * Track quals on system catalogs too. Default: `false`. * * @deprecated This property is deprecated. */ trackPgCatalog?: boolean; } export interface GetPgPgUserConfigPgaudit { /** * Enable pgaudit extension. When enabled, pgaudit extension will be automatically installed.Otherwise, extension will be uninstalled but auditing configurations will be preserved. Default: `false`. */ featureEnabled?: boolean; /** * Specifies that session logging should be enabled in the case where all relations in a statement are in pg_catalog. Default: `true`. */ logCatalog?: boolean; /** * Specifies whether log messages will be visible to a client process such as psql. Default: `false`. */ logClient?: boolean; /** * Enum: `debug1`, `debug2`, `debug3`, `debug4`, `debug5`, `info`, `log`, `notice`, `warning`. Specifies the log level that will be used for log entries. Default: `log`. */ logLevel?: string; /** * Crop parameters representation and whole statements if they exceed this threshold. A (default) value of -1 disable the truncation. Default: `-1`. */ logMaxStringLength?: number; /** * This GUC allows to turn off logging nested statements, that is, statements that are executed as part of another ExecutorRun. Default: `true`. */ logNestedStatements?: boolean; /** * Specifies that audit logging should include the parameters that were passed with the statement. Default: `false`. */ logParameter?: boolean; /** * Specifies that parameter values longer than this setting (in bytes) should not be logged, but replaced with . Default: `0`. */ logParameterMaxSize?: number; /** * Specifies whether session audit logging should create a separate log entry for each relation (TABLE, VIEW, etc.) referenced in a SELECT or DML statement. Default: `false`. */ logRelation?: boolean; /** * Log Rows. Default: `false`. */ logRows?: boolean; /** * Specifies whether logging will include the statement text and parameters (if enabled). Default: `true`. */ logStatement?: boolean; /** * Specifies whether logging will include the statement text and parameters with the first log entry for a statement/substatement combination or with every entry. Default: `false`. */ logStatementOnce?: boolean; /** * Specifies which classes of statements will be logged by session audit logging. */ logs?: string[]; /** * Specifies the master role to use for object audit logging. */ role?: string; } export interface GetPgPgUserConfigPgbouncer { /** * If the automatically created database pools have been unused this many seconds, they are freed. If 0 then timeout is disabled. (seconds). Default: `3600`. */ autodbIdleTimeout?: number; /** * Do not allow more than this many server connections per database (regardless of user). Setting it to 0 means unlimited. Example: `0`. */ autodbMaxDbConnections?: number; /** * Enum: `session`, `statement`, `transaction`. PGBouncer pool mode. Default: `transaction`. */ autodbPoolMode?: string; /** * If non-zero then create automatically a pool of that size per user when a pool doesn't exist. Default: `0`. */ autodbPoolSize?: number; /** * List of parameters to ignore when given in startup packet. */ ignoreStartupParameters?: string[]; /** * PgBouncer tracks protocol-level named prepared statements related commands sent by the client in transaction and statement pooling modes when maxPreparedStatements is set to a non-zero value. Setting it to 0 disables prepared statements. maxPreparedStatements defaults to 100, and its maximum is 3000. Default: `100`. */ maxPreparedStatements?: number; /** * Add more server connections to pool if below this number. Improves behavior when usual load comes suddenly back after period of total inactivity. The value is effectively capped at the pool size. Default: `0`. */ minPoolSize?: number; /** * If connection and login don’t finish in this amount of time, the connection will be closed. (seconds). */ serverConnectTimeout?: number; /** * If a server connection has been idle more than this many seconds it will be dropped. If 0 then timeout is disabled. (seconds). Default: `600`. */ serverIdleTimeout?: number; /** * The pooler will close an unused server connection that has been connected longer than this. (seconds). Default: `3600`. */ serverLifetime?: number; /** * If login to the server failed, because of failure to connect or from authentication, the pooler waits this much before retrying to connect. During the waiting interval, new clients trying to connect to the failing server will get an error immediately without another connection attempt. (seconds). */ serverLoginRetry?: number; /** * Run serverResetQuery (DISCARD ALL) in all pooling modes. Default: `false`. */ serverResetQueryAlways?: boolean; } export interface GetPgPgUserConfigPglookout { /** * Number of seconds of master unavailability before triggering database failover to standby. Default: `60`. */ maxFailoverReplicationTimeLag?: number; } export interface GetPgPgUserConfigPrivateAccess { /** * Allow clients to connect to pg with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ pg?: boolean; /** * Allow clients to connect to pgbouncer with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ pgbouncer?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface GetPgPgUserConfigPrivatelinkAccess { /** * Enable pg. */ pg?: boolean; /** * Enable pgbouncer. */ pgbouncer?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface GetPgPgUserConfigPublicAccess { /** * Allow clients to connect to pg from the public internet for service nodes that are in a project VPC or another type of private network. */ pg?: boolean; /** * Allow clients to connect to pgbouncer from the public internet for service nodes that are in a project VPC or another type of private network. */ pgbouncer?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface GetPgPgUserConfigSwitchoverWindow { /** * Enum: `friday`, `monday`, `saturday`, `sunday`, `thursday`, `tuesday`, `wednesday`. */ dow: string; /** * Example: `12:30:00`. */ endTime: string; /** * Example: `12:30:00`. */ startTime: string; } export interface GetPgPgUserConfigTimescaledb { /** * The number of background workers for timescaledb operations. You should configure this setting to the sum of your number of databases and the total number of concurrent background workers you want running at any given point in time. Changing this parameter causes a service restart. Default: `16`. */ maxBackgroundWorkers?: number; } export interface GetPgServiceIntegration { /** * Type of the service integration. The possible values are `readReplica` and `disasterRecovery`. */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetPgTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetPgTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetPgUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetProjectTag { /** * Project tag key. */ key: string; /** * Project tag value. */ value: string; } export interface GetProjectVpcTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetServiceIntegrationClickhouseCredentialsUserConfig { /** * Grants to assign */ grants?: outputs.GetServiceIntegrationClickhouseCredentialsUserConfigGrant[]; } export interface GetServiceIntegrationClickhouseCredentialsUserConfigGrant { /** * User or role to assign the grant to. Example: `alice`. */ user: string; } export interface GetServiceIntegrationClickhouseKafkaUserConfig { /** * Array of table configurations that define how Kafka topics are mapped to ClickHouse tables. Each table configuration specifies the table structure, associated Kafka topics, and read/write settings */ tables?: outputs.GetServiceIntegrationClickhouseKafkaUserConfigTable[]; } export interface GetServiceIntegrationClickhouseKafkaUserConfigTable { /** * Enum: `beginning`, `earliest`, `end`, `largest`, `latest`, `smallest`. Determines where to start reading from Kafka when no offset is stored or the stored offset is out of range. `earliest` starts from the beginning, `latest` starts from the end. Default: `earliest`. */ autoOffsetReset?: string; /** * When set to a non-zero value and there are no committed offsets, the consumer starts from the offset corresponding to (now - auto_offset_reset_by_duration_ms). This overrides autoOffsetReset when set. Requires ClickHouse >= 25.8. Default: `0`. */ autoOffsetResetByDurationMs?: number; /** * Array of column definitions that specify the structure of the ClickHouse table. Each column maps to a field in the Kafka messages */ columns: outputs.GetServiceIntegrationClickhouseKafkaUserConfigTableColumn[]; /** * Enum: `Avro`, `AvroConfluent`, `CSV`, `JSONAsString`, `JSONCompactEachRow`, `JSONCompactStringsEachRow`, `JSONEachRow`, `JSONStringsEachRow`, `MsgPack`, `Parquet`, `RawBLOB`, `TSKV`, `TSV`, `TabSeparated`. The format of the messages in the Kafka topics. Determines how ClickHouse parses and serializes the data (e.g., JSON, CSV, Avro). Default: `JSONEachRow`. */ dataFormat: string; /** * Enum: `basic`, `bestEffort`, `bestEffortUs`. Specifies how ClickHouse should parse DateTime values from text-based input formats. `basic` uses simple parsing, `bestEffort` attempts more flexible parsing. Default: `basic`. */ dateTimeInputFormat?: string; /** * The Kafka consumer group name. Multiple consumers with the same group name will share the workload and maintain offset positions. Default: `clickhouse`. */ groupName: string; /** * Enum: `deadLetterQueue`, `default`, `stream`. Defines how ClickHouse should handle errors when processing Kafka messages. `default` stops on errors, `stream` continues processing and logs errors, `deadLetterQueue` saves error data to system.dead_letter_queue (requires ClickHouse 25.8+). Default: `default`. */ handleErrorMode?: string; /** * Optional materialized view that persists data from the Kafka engine table into a MergeTree-family table. When specified, a ClickHouse materialized view is created that automatically reads from the Kafka table and inserts into a durable target table */ materializedView?: outputs.GetServiceIntegrationClickhouseKafkaUserConfigTableMaterializedView; /** * Maximum number of rows to collect before flushing data between Kafka and ClickHouse. Default: `0`. */ maxBlockSize?: number; /** * Maximum number of rows that can be processed from a single Kafka message for row-based formats. Useful for controlling memory usage. Default: `1`. */ maxRowsPerMessage?: number; /** * The name of the ClickHouse table to be created. This table can consume data from and write data to the specified Kafka topics. Example: `events`. */ name: string; /** * Number of Kafka consumers to run per table per replica. Increasing this can improve throughput but may increase resource usage. Default: `1`. */ numConsumers?: number; /** * Maximum number of messages to fetch in a single Kafka poll operation for reading. Default: `0`. */ pollMaxBatchSize?: number; /** * Timeout in milliseconds for a single poll from Kafka. Takes the value of the streamFlushIntervalMs server setting by default (500ms). Default: `0`. */ pollMaxTimeoutMs?: number; /** * The maximum number of messages in a batch sent to Kafka. If the number of messages exceeds this value, the batch is sent. Default: `10000`. */ producerBatchNumMessages?: number; /** * The maximum size in bytes of a batch of messages sent to Kafka. If the batch size is exceeded, the batch is sent. */ producerBatchSize?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. The compression codec to use when sending a batch of messages to Kafka. Default: `none`. */ producerCompressionCodec?: string; /** * The compression level to use when sending a batch of messages to Kafka. Usable range is algorithm-dependent: [0-9] for gzip; [0-12] for lz4; only 0 for snappy; -1 = codec-dependent default compression level. Default: `-1`. */ producerCompressionLevel?: number; /** * The time in milliseconds to wait for additional messages before sending a batch. If the time is exceeded, the batch is sent. Default: `5`. */ producerLingerMs?: number; /** * The maximum size of the buffer in kilobytes before sending. */ producerQueueBufferingMaxKbytes?: number; /** * The maximum number of messages to buffer before sending. Default: `100000`. */ producerQueueBufferingMaxMessages?: number; /** * The number of acknowledgements the leader broker must receive from ISR brokers before responding to the request: 0=Broker does not send any response/ack to client, -1 will block until message is committed by all in sync replicas (ISRs). Default: `-1`. */ producerRequestRequiredAcks?: number; /** * Number of broken messages to skip before stopping processing when reading from Kafka. Useful for handling corrupted data without failing the entire integration. Default: `0`. */ skipBrokenMessages?: number; /** * When enabled, each consumer runs in its own thread, providing better isolation and potentially better performance for high-throughput scenarios. Default: `false`. */ threadPerConsumer?: boolean; /** * Array of Kafka topics that this table will read data from or write data to. Messages from all specified topics will be inserted into this table, and data inserted into this table will be published to the topics */ topics: outputs.GetServiceIntegrationClickhouseKafkaUserConfigTableTopic[]; } export interface GetServiceIntegrationClickhouseKafkaUserConfigTableColumn { /** * The name of the column in the ClickHouse table. This should match the field names in your Kafka message format. Example: `key`. */ name: string; /** * The ClickHouse data type for this column. Must be a valid ClickHouse data type that can handle the data format. Example: `UInt64`. */ type: string; } export interface GetServiceIntegrationClickhouseKafkaUserConfigTableMaterializedView { /** * The database to create the materialized view in. Must not be the Kafka integration database as it is not replicated and may be dropped. Default: `default`. */ databaseName?: string; /** * Enum: `AggregatingMergeTree`, `CollapsingMergeTree`, `MergeTree`, `ReplacingMergeTree`, `SummingMergeTree`, `VersionedCollapsingMergeTree`. The MergeTree-family engine for the materialized view's target table. Default: `MergeTree`. */ engine?: string; /** * Column names passed as engine arguments, e.g. the sign column for CollapsingMergeTree or the sign and version columns for VersionedCollapsingMergeTree. */ engineParams?: string[]; /** * Number of days after which data is moved from local disk to remote storage (tiered storage). Must be specified together with ttl_column. Example: `7`. */ localDiskTtlDays?: number; /** * Columns for the ORDER BY clause of the target table. Determines the sort order and primary index. */ orderBies: string[]; /** * Date or DateTime column used for both row deletion TTL and local disk tiered storage TTL. Must be specified when ttlDays or localDiskTtlDays is set. Example: `createdAt`. */ ttlColumn?: string; /** * Number of days after which rows are deleted, calculated from the TTL column value. Must be specified together with ttl_column. Example: `30`. */ ttlDays?: number; /** * The name of the materialized view to create. Example: `eventsMv`. */ viewName: string; } export interface GetServiceIntegrationClickhouseKafkaUserConfigTableTopic { /** * The name of the Kafka topic to read messages from or write messages to. The topic must exist in the Kafka cluster. Example: `topicName`. */ name: string; } export interface GetServiceIntegrationClickhousePostgresqlUserConfig { /** * Databases to expose */ databases?: outputs.GetServiceIntegrationClickhousePostgresqlUserConfigDatabase[]; } export interface GetServiceIntegrationClickhousePostgresqlUserConfigDatabase { /** * PostgreSQL database to expose. Default: `defaultdb`. */ database?: string; /** * PostgreSQL schema to expose. Default: `public`. */ schema?: string; } export interface GetServiceIntegrationDatadogUserConfig { /** * Enable Datadog Database Monitoring. */ datadogDbmEnabled?: boolean; /** * Enable collection of PL/pgSQL function metrics from pg_stat_user_functions. Requires `trackFunctions` to be set to `pl` or `all` in the service configuration. */ datadogFunctionMetricsEnabled?: boolean; /** * Relations to collect PostgreSQL relation metrics for, such as table size, index statistics, row counts, vacuum ages and locks. No relation metrics are collected when unset */ datadogPgRelations?: outputs.GetServiceIntegrationDatadogUserConfigDatadogPgRelation[]; /** * Enable Datadog PgBouncer Metric Tracking. */ datadogPgbouncerEnabled?: boolean; /** * Custom tags provided by user */ datadogTags?: outputs.GetServiceIntegrationDatadogUserConfigDatadogTag[]; /** * List of custom metrics. */ excludeConsumerGroups?: string[]; /** * List of topics to exclude. */ excludeTopics?: string[]; /** * List of custom metrics. */ includeConsumerGroups?: string[]; /** * List of topics to include. */ includeTopics?: string[]; /** * List of custom metrics. */ kafkaCustomMetrics?: string[]; /** * Maximum number of JMX metrics to send. Example: `2000`. */ maxJmxMetrics?: number; /** * List of custom metrics. */ mirrormakerCustomMetrics?: string[]; /** * Datadog Opensearch Options */ opensearch?: outputs.GetServiceIntegrationDatadogUserConfigOpensearch; /** * Datadog Redis Options */ redis?: outputs.GetServiceIntegrationDatadogUserConfigRedis; } export interface GetServiceIntegrationDatadogUserConfigDatadogPgRelation { /** * Name of a single relation to collect metrics for. Example: `orders`. */ relationName?: string; /** * Regular expression matching the names of the relations to collect metrics for. Example: `^orders_.*`. */ relationRegex?: string; /** * Only collect lock metrics for these relation kinds. Applies to ordinary tables when unset. Accepted values are the `relkind` values of `pgClass`: `r` (ordinary table), `i` (index), `S` (sequence), `t` (TOAST table), `m` (materialized view), `c` (composite type), `f` (foreign table), `p` (partitioned table). */ relkinds?: string[]; /** * Only collect metrics for relations in these schemas. Applies to all schemas when unset. */ schemas?: string[]; } export interface GetServiceIntegrationDatadogUserConfigDatadogTag { /** * Optional tag explanation. Example: `Used to tag primary replica metrics`. */ comment?: string; /** * Tag format and usage are described here: https://docs.datadoghq.com/getting_started/tagging. Tags with prefix `aiven-` are reserved for Aiven. Example: `replica:primary`. */ tag: string; } export interface GetServiceIntegrationDatadogUserConfigOpensearch { /** * Enable Datadog Opensearch Cluster Monitoring. */ clusterStatsEnabled?: boolean; /** * Enable Datadog Opensearch Index Monitoring. */ indexStatsEnabled?: boolean; /** * Enable Datadog Opensearch Pending Task Monitoring. */ pendingTaskStatsEnabled?: boolean; /** * Enable Datadog Opensearch Primary Shard Monitoring. */ pshardStatsEnabled?: boolean; } export interface GetServiceIntegrationDatadogUserConfigRedis { /** * Enable commandStats option in the agent's configuration. Default: `false`. */ commandStatsEnabled?: boolean; } export interface GetServiceIntegrationEndpointAutoscalerUserConfig { /** * Configure autoscaling thresholds for a service */ autoscalings: outputs.GetServiceIntegrationEndpointAutoscalerUserConfigAutoscaling[]; } export interface GetServiceIntegrationEndpointAutoscalerUserConfigAutoscaling { /** * The maximum total disk size (in gb) to allow autoscaler to scale up to. Example: `300`. */ capGb: number; /** * Enum: `autoscaleDisk`. Type of autoscale event. */ type: string; } export interface GetServiceIntegrationEndpointDatadogUserConfig { /** * Datadog API key. Example: `848f30907c15c55d601fe45487cce9b6`. */ datadogApiKey: string; /** * Custom tags provided by user */ datadogTags?: outputs.GetServiceIntegrationEndpointDatadogUserConfigDatadogTag[]; /** * Disable consumer group metrics. */ disableConsumerStats?: boolean; /** * Extra tags prefix. Defaults to aiven. */ extraTagsPrefix?: string; /** * Number of separate instances to fetch kafka consumer statistics with. Example: `8`. */ kafkaConsumerCheckInstances?: number; /** * Number of seconds that datadog will wait to get consumer statistics from brokers. Example: `60`. */ kafkaConsumerStatsTimeout?: number; /** * Maximum number of partition contexts to send. Example: `32000`. */ maxPartitionContexts?: number; /** * Enum: `ap1.datadoghq.com`, `ap2.datadoghq.com`, `datadoghq.com`, `datadoghq.eu`, `ddog-gov.com`, `us2.ddog-gov.com`, `us3.datadoghq.com`, `us5.datadoghq.com`. Datadog intake site. Defaults to datadoghq.com. */ site?: string; } export interface GetServiceIntegrationEndpointDatadogUserConfigDatadogTag { /** * Optional tag explanation. Example: `Used to tag primary replica metrics`. */ comment?: string; /** * Tag format and usage are described here: https://docs.datadoghq.com/getting_started/tagging. Tags with prefix `aiven-` are reserved for Aiven. Example: `replica:primary`. */ tag: string; } export interface GetServiceIntegrationEndpointExternalAwsCloudwatchLogsUserConfig { /** * AWS access key. Required permissions are logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents and logs:DescribeLogStreams. Example: `AAAAAAAAAAAAAAAAAAAA`. */ accessKey: string; /** * AWS CloudWatch log group name. Example: `my-log-group`. */ logGroupName?: string; /** * AWS region. Example: `us-east-1`. */ region: string; /** * AWS secret key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretKey: string; } export interface GetServiceIntegrationEndpointExternalAwsCloudwatchMetricsUserConfig { /** * AWS access key. Required permissions are cloudwatch:PutMetricData. Example: `AAAAAAAAAAAAAAAAAAAA`. */ accessKey: string; /** * AWS CloudWatch Metrics Namespace. Example: `my-metrics-namespace`. */ namespace: string; /** * AWS region. Example: `us-east-1`. */ region: string; /** * AWS secret key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretKey: string; } export interface GetServiceIntegrationEndpointExternalAwsS3UserConfig { /** * Access Key Id. Example: `AAAAAAAAAAAAAAAAAAA`. */ accessKeyId: string; /** * Secret Access Key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretAccessKey: string; /** * S3-compatible bucket URL. Example: `https://mybucket.s3-myregion.amazonaws.com/mydataset/`. */ url: string; } export interface GetServiceIntegrationEndpointExternalAzureBlobStorageUserConfig { /** * Blob path. Example: `path/to/blob/file.csv`. */ blobPath?: string; /** * Azure Blob Storage connection string. Example: `AccountName=IDENT;AccountKey=SECRET`. */ connectionString: string; /** * Container. Example: `container-dev`. */ container: string; } export interface GetServiceIntegrationEndpointExternalClickhouseUserConfig { /** * Hostname or IP address of the server. Example: `my.server.com`. */ host: string; /** * Password. Example: `jjKk45Nnd`. */ password: string; /** * Secure TCP server port. Example: `9440`. */ port: number; /** * User name. Example: `default`. */ username: string; } export interface GetServiceIntegrationEndpointExternalElasticsearchLogsUserConfig { /** * PEM encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ ca?: string; /** * Maximum number of days of logs to keep. Default: `3`. */ indexDaysMax?: number; /** * Elasticsearch index prefix. Default: `logs`. */ indexPrefix: string; /** * Elasticsearch request timeout limit. Default: `10`. */ timeout?: number; /** * Elasticsearch connection URL. Example: `https://user:passwd@logs.example.com/`. */ url: string; } export interface GetServiceIntegrationEndpointExternalGoogleCloudBigquery { /** * GCP project id. Example: `snappy-photon-12345`. */ projectId: string; /** * This is a JSON object with the fields documented in https://cloud.google.com/iam/docs/creating-managing-service-account-keys. Example: `{"type": "serviceAccount", ...`. */ serviceAccountCredentials: string; } export interface GetServiceIntegrationEndpointExternalGoogleCloudLoggingUserConfig { /** * Google Cloud Logging log id. Example: `syslog`. */ logId: string; /** * GCP project id. Example: `snappy-photon-12345`. */ projectId: string; /** * This is a JSON object with the fields documented in https://cloud.google.com/iam/docs/creating-managing-service-account-keys. Example: `{"type": "serviceAccount", ...`. */ serviceAccountCredentials: string; } export interface GetServiceIntegrationEndpointExternalKafkaUserConfig { /** * Bootstrap servers. Example: `10.0.0.1:9092,10.0.0.2:9092`. */ bootstrapServers: string; /** * Enum: `PLAIN`, `SCRAM-SHA-256`, `SCRAM-SHA-512`. SASL mechanism used for connections to the Kafka server. */ saslMechanism?: string; /** * Password for SASL PLAIN mechanism in the Kafka server. Example: `admin`. */ saslPlainPassword?: string; /** * Username for SASL PLAIN mechanism in the Kafka server. Example: `admin`. */ saslPlainUsername?: string; /** * Enum: `PLAINTEXT`, `SASL_PLAINTEXT`, `SASL_SSL`, `SSL`. Security protocol. */ securityProtocol: string; /** * PEM-encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslCaCert?: string; /** * PEM-encoded client certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslClientCert?: string; /** * PEM-encoded client key. Example: `-----BEGIN PRIVATE KEY----- * ... * -----END PRIVATE KEY----- * `. */ sslClientKey?: string; /** * Enum: `https`. The endpoint identification algorithm to validate server hostname using server certificate. */ sslEndpointIdentificationAlgorithm?: string; } export interface GetServiceIntegrationEndpointExternalMysqlUserConfig { /** * Hostname or IP address of the server. Example: `my.server.com`. */ host: string; /** * Password. Example: `jjKk45Nnd`. */ password: string; /** * Port number of the server. Example: `5432`. */ port: number; /** * Enum: `verify-full`. SSL Mode. Default: `verify-full`. */ sslMode?: string; /** * SSL Root Cert. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslRootCert?: string; /** * User name. Example: `myname`. */ username: string; } export interface GetServiceIntegrationEndpointExternalObjectStorageConfigUserConfig { /** * Azure account secret key (Azure only). Example: `YWNjb3VudCBrZXkgZXhhbXBsZQ==`. */ accountKey?: string; /** * Azure account name (Azure only). Example: `myazureaccount`. */ accountName?: string; /** * AWS access key ID (S3 only). Example: `AKIAIOSFODNN7EXAMPLE`. */ awsAccessKeyId?: string; /** * AWS secret access key (S3 only). Example: `wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY`. */ awsSecretAccessKey?: string; /** * Bucket name. Example: `my-thanos-bucket`. */ bucketName?: string; /** * Google service account credentials JSON (Google Cloud Storage only). Example: `{"type": "serviceAccount", ...`. */ credentials?: string; /** * S3-compatible endpoint host (S3 only). Example: `s3.eu-west-1.amazonaws.com`. */ host?: string; /** * S3-compatible endpoint port (S3 only). Example: `443`. */ port?: number; /** * Object storage prefix / path. Example: `thanos-data/`. */ prefix?: string; /** * GCP project ID (Google Cloud Storage only). Example: `my-gcp-project`. */ projectId?: string; /** * AWS S3 region (S3 only). Example: `eu-west-1`. */ region?: string; /** * Enum: `azure`, `google`, `s3`. Object storage type. */ storageType: string; } export interface GetServiceIntegrationEndpointExternalOpensearchLogsUserConfig { /** * PEM encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ ca?: string; /** * Maximum number of days of logs to keep. Default: `3`. */ indexDaysMax?: number; /** * OpenSearch index prefix. Default: `logs`. */ indexPrefix: string; /** * OpenSearch request timeout limit. Default: `10`. */ timeout?: number; /** * OpenSearch connection URL. Example: `https://user:passwd@logs.example.com/`. */ url: string; } export interface GetServiceIntegrationEndpointExternalPostgresql { /** * Default database. Example: `testdb`. */ defaultDatabase?: string; /** * Hostname or IP address of the server. Example: `my.server.com`. */ host: string; /** * Password. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server. Example: `5432`. */ port: number; /** * Client certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslClientCertificate?: string; /** * Client key. Example: `-----BEGIN PRIVATE KEY----- * ... * -----END PRIVATE KEY-----`. */ sslClientKey?: string; /** * Enum: `allow`, `disable`, `prefer`, `require`, `verify-ca`, `verify-full`. SSL mode to use for the connection. Please note that Aiven requires TLS for all connections to external PostgreSQL services. Default: `verify-full`. */ sslMode?: string; /** * SSL Root Cert. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslRootCert?: string; /** * User name. Example: `myname`. */ username: string; } export interface GetServiceIntegrationEndpointExternalPrometheusUserConfig { /** * Prometheus basic authentication password. Example: `fhyFNBjj3R`. */ basicAuthPassword?: string; /** * Prometheus basic authentication username. Example: `prom4851`. */ basicAuthUsername?: string; /** * Prometheus enabled write endpoint. Example: `https://write.example.com/`. */ serviceUri?: string; } export interface GetServiceIntegrationEndpointExternalSchemaRegistryUserConfig { /** * Enum: `basic`, `none`. Authentication method. */ authentication: string; /** * Basic authentication password. Example: `Zm9vYg==`. */ basicAuthPassword?: string; /** * Basic authentication user name. Example: `avnadmin`. */ basicAuthUsername?: string; /** * Schema Registry URL. Example: `https://schema-registry.kafka.company.com:28419`. */ url: string; } export interface GetServiceIntegrationEndpointJolokiaUserConfig { /** * Jolokia basic authentication password. Example: `yhfBNFii4C`. */ basicAuthPassword?: string; /** * Jolokia basic authentication username. Example: `jol48k51`. */ basicAuthUsername?: string; } export interface GetServiceIntegrationEndpointOpentelemetryUserConfig { /** * Resource attributes to attach to every exported metric. */ attributes?: { [key: string]: string; }; /** * Enum: `gzip`, `none`. Payload compression. */ compression: string; /** * Enum: `json`, `protobuf`. Encoding used for exported metrics. Leave unset to use telegraf's default. */ encodingType?: string; /** * Additional gRPC metadata headers sent with every export request. */ headers?: { [key: string]: string; }; /** * Either a bare `host:port` (OTLP/gRPC, no URL scheme) or an `http://`/`https://` URL (OTLP/HTTP). Example: `otel-collector.example.avns.net:4317`. */ serviceAddress: string; /** * Connection timeout in seconds. Example: `10`. */ timeout: number; } export interface GetServiceIntegrationEndpointPrometheusUserConfig { /** * Prometheus basic authentication password. Example: `fhyFNBjj3R`. */ basicAuthPassword?: string; /** * Prometheus basic authentication username. Example: `prom4851`. */ basicAuthUsername?: string; } export interface GetServiceIntegrationEndpointRsyslogUserConfig { /** * PEM encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ ca?: string; /** * PEM encoded client certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ cert?: string; /** * When true, embedded newlines in a log message are escaped so a multi-line record (e.g. a stack trace) is delivered as one complete log entry. Useful for newline-delimited cloud log intakes that drop continuation lines. Default: `false`. */ escapeNewlines?: boolean; /** * Enum: `custom`, `rfc3164`, `rfc5424`. Message format. Default: `rfc5424`. */ format: string; /** * PEM encoded client key. Example: `-----BEGIN PRIVATE KEY----- * ... * -----END PRIVATE KEY----- * `. */ key?: string; /** * Custom syslog message format. Example: `<%pri%>%timestamp:::date-rfc3339% %HOSTNAME% %app-name% %msg%`. */ logline?: string; /** * Rsyslog max message size. Default: `8192`. */ maxMessageSize?: number; /** * Rsyslog server port. Default: `514`. */ port: number; /** * Structured data block for log message. Example: `TOKEN tag="LiteralValue"`. */ sd?: string; /** * Rsyslog server IP address or hostname. Example: `logs.example.com`. */ server: string; /** * Require TLS. Default: `true`. */ tls: boolean; } export interface GetServiceIntegrationExternalAwsCloudwatchLogsUserConfig { /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface GetServiceIntegrationExternalAwsCloudwatchMetricsUserConfig { /** * Metrics to not send to AWS CloudWatch (takes precedence over extra_metrics) */ droppedMetrics?: outputs.GetServiceIntegrationExternalAwsCloudwatchMetricsUserConfigDroppedMetric[]; /** * Metrics to allow through to AWS CloudWatch (in addition to default metrics) */ extraMetrics?: outputs.GetServiceIntegrationExternalAwsCloudwatchMetricsUserConfigExtraMetric[]; } export interface GetServiceIntegrationExternalAwsCloudwatchMetricsUserConfigDroppedMetric { /** * Identifier of a value in the metric. Example: `used`. */ field: string; /** * Identifier of the metric. Example: `java.lang:Memory`. */ metric: string; } export interface GetServiceIntegrationExternalAwsCloudwatchMetricsUserConfigExtraMetric { /** * Identifier of a value in the metric. Example: `used`. */ field: string; /** * Identifier of the metric. Example: `java.lang:Memory`. */ metric: string; } export interface GetServiceIntegrationExternalElasticsearchLogsUserConfig { /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface GetServiceIntegrationExternalOpensearchLogsUserConfig { /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface GetServiceIntegrationFlinkExternalPostgresqlUserConfig { /** * Enum: `unspecified`. If stringtype is set to unspecified, parameters will be sent to the server as untyped values. */ stringtype?: string; } export interface GetServiceIntegrationKafkaConnectUserConfig { /** * Kafka Connect service configuration values */ kafkaConnect?: outputs.GetServiceIntegrationKafkaConnectUserConfigKafkaConnect; } export interface GetServiceIntegrationKafkaConnectUserConfigKafkaConnect { /** * The name of the topic where connector and task configuration data are stored.This must be the same for all workers with the same group_id. Example: `__connect_configs`. */ configStorageTopic?: string; /** * A unique string that identifies the Connect cluster group this worker belongs to. Example: `connect`. */ groupId?: string; /** * The name of the topic where connector and task configuration offsets are stored.This must be the same for all workers with the same group_id. Example: `__connect_offsets`. */ offsetStorageTopic?: string; /** * The name of the topic where connector and task configuration status updates are stored.This must be the same for all workers with the same group_id. Example: `__connect_status`. */ statusStorageTopic?: string; } export interface GetServiceIntegrationKafkaLogsUserConfig { /** * Topic name. Example: `mytopic`. */ kafkaTopic: string; /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface GetServiceIntegrationKafkaMirrormakerUserConfig { /** * The alias under which the Kafka cluster is known to MirrorMaker. Can contain the following symbols: ASCII alphanumerics, `.`, `_`, and `-`. Example: `kafka-abc`. */ clusterAlias?: string; /** * Kafka MirrorMaker configuration values */ kafkaMirrormaker?: outputs.GetServiceIntegrationKafkaMirrormakerUserConfigKafkaMirrormaker; } export interface GetServiceIntegrationKafkaMirrormakerUserConfigKafkaMirrormaker { /** * Enum: `earliest`, `latest`. Set where consumer starts to consume data. Value `earliest`: Start replication from the earliest offset. Value `latest`: Start replication from the latest offset. Default is `earliest`. */ consumerAutoOffsetReset?: string; /** * The maximum amount of data the server should return for a fetch request. Default is `52428800` (50MiB). */ consumerFetchMaxBytes?: number; /** * The maximum amount of time the server will block before answering the fetch request if there isn't sufficient data to immediately satisfy `consumerFetchMinBytes`. Default is `500`. */ consumerFetchMaxWaitMs?: number; /** * The minimum amount of data the server should return for a fetch request. Default is `1`. Example: `1024`. */ consumerFetchMinBytes?: number; /** * The maximum amount of data per partition the server will return. Default is `1048576` (1MiB). */ consumerMaxPartitionFetchBytes?: number; /** * Set consumer max.poll.records. Default is `500`. */ consumerMaxPollRecords?: number; /** * The size of the TCP receive buffer (SO_RCVBUF) to use when reading data. Default is `65536` (64KiB). `-1` uses the OS default. */ consumerReceiveBufferBytes?: number; /** * The maximum time the client will wait for a response to a request. Default is `30000` (30s). */ consumerRequestTimeoutMs?: number; /** * The batch size in bytes producer will attempt to collect before publishing to broker. Default is `16384` (16KiB). */ producerBatchSize?: number; /** * The amount of bytes producer can use for buffering data before publishing to broker. Default is `33554432` (32MiB). */ producerBufferMemory?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * The linger time (ms) for waiting new data to arrive for publishing. Default is `0`. Example: `100`. */ producerLingerMs?: number; /** * The maximum request size in bytes. Default is `1048576` (1MiB). */ producerMaxRequestSize?: number; /** * The maximum time the client will wait for a response to a request. Default is `30000` (30s). */ producerRequestTimeoutMs?: number; /** * The size of the TCP send buffer (SO_SNDBUF) to use when sending data. Default is `131072` (128KiB). `-1` uses the OS default. */ producerSendBufferBytes?: number; } export interface GetServiceIntegrationLogsUserConfig { /** * Elasticsearch index retention limit. Default: `3`. */ elasticsearchIndexDaysMax?: number; /** * Elasticsearch index prefix. Default: `logs`. */ elasticsearchIndexPrefix?: string; /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface GetServiceIntegrationMetricsUserConfig { /** * Name of the database where to store metric datapoints. Only affects PostgreSQL destinations. Defaults to `metrics`. Note that this must be the same for all metrics integrations that write data to the same PostgreSQL service. */ database?: string; /** * Number of days to keep old metrics. Only affects PostgreSQL destinations. Set to 0 for no automatic cleanup. Defaults to 30 days. */ retentionDays?: number; /** * Name of a user that can be used to read metrics. This will be used for Grafana integration (if enabled) to prevent Grafana users from making undesired changes. Only affects PostgreSQL destinations. Defaults to `metricsReader`. Note that this must be the same for all metrics integrations that write data to the same PostgreSQL service. */ roUsername?: string; /** * Configuration options for metrics where source service is MySQL */ sourceMysql?: outputs.GetServiceIntegrationMetricsUserConfigSourceMysql; /** * Name of the user used to write metrics. Only affects PostgreSQL destinations. Defaults to `metricsWriter`. Note that this must be the same for all metrics integrations that write data to the same PostgreSQL service. */ username?: string; } export interface GetServiceIntegrationMetricsUserConfigSourceMysql { /** * Configuration options for Telegraf MySQL input plugin */ telegraf?: outputs.GetServiceIntegrationMetricsUserConfigSourceMysqlTelegraf; } export interface GetServiceIntegrationMetricsUserConfigSourceMysqlTelegraf { /** * Gather metrics from PERFORMANCE_SCHEMA.EVENT_WAITS. */ gatherEventWaits?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.FILE_SUMMARY_BY_EVENT_NAME. */ gatherFileEventsStats?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.TABLE_IO_WAITS_SUMMARY_BY_INDEX_USAGE. */ gatherIndexIoWaits?: boolean; /** * Gather autoIncrement columns and max values from information schema. */ gatherInfoSchemaAutoInc?: boolean; /** * Gather metrics from INFORMATION_SCHEMA.INNODB_METRICS. */ gatherInnodbMetrics?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.EVENTS_STATEMENTS_SUMMARY_BY_DIGEST. */ gatherPerfEventsStatements?: boolean; /** * Gather thread state counts from INFORMATION_SCHEMA.PROCESSLIST. */ gatherProcessList?: boolean; /** * Gather metrics from SHOW REPLICA STATUS command output. */ gatherReplicaStatus?: boolean; /** * Gather metrics from SHOW SLAVE STATUS command output. */ gatherSlaveStatus?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.TABLE_IO_WAITS_SUMMARY_BY_TABLE. */ gatherTableIoWaits?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.TABLE_LOCK_WAITS. */ gatherTableLockWaits?: boolean; /** * Gather metrics from INFORMATION_SCHEMA.TABLES. */ gatherTableSchema?: boolean; /** * Truncates digest text from perfEventsStatements into this many characters. Example: `120`. */ perfEventsStatementsDigestTextLimit?: number; /** * Limits metrics from perf_events_statements. Example: `250`. */ perfEventsStatementsLimit?: number; /** * Only include perfEventsStatements whose last seen is less than this many seconds. Example: `86400`. */ perfEventsStatementsTimeLimit?: number; } export interface GetServiceIntegrationPrometheusUserConfig { /** * Configuration options for metrics where source service is MySQL */ sourceMysql?: outputs.GetServiceIntegrationPrometheusUserConfigSourceMysql; } export interface GetServiceIntegrationPrometheusUserConfigSourceMysql { /** * Configuration options for Telegraf MySQL input plugin */ telegraf?: outputs.GetServiceIntegrationPrometheusUserConfigSourceMysqlTelegraf; } export interface GetServiceIntegrationPrometheusUserConfigSourceMysqlTelegraf { /** * Gather metrics from PERFORMANCE_SCHEMA.EVENT_WAITS. */ gatherEventWaits?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.FILE_SUMMARY_BY_EVENT_NAME. */ gatherFileEventsStats?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.TABLE_IO_WAITS_SUMMARY_BY_INDEX_USAGE. */ gatherIndexIoWaits?: boolean; /** * Gather autoIncrement columns and max values from information schema. */ gatherInfoSchemaAutoInc?: boolean; /** * Gather metrics from INFORMATION_SCHEMA.INNODB_METRICS. */ gatherInnodbMetrics?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.EVENTS_STATEMENTS_SUMMARY_BY_DIGEST. */ gatherPerfEventsStatements?: boolean; /** * Gather thread state counts from INFORMATION_SCHEMA.PROCESSLIST. */ gatherProcessList?: boolean; /** * Gather metrics from SHOW REPLICA STATUS command output. */ gatherReplicaStatus?: boolean; /** * Gather metrics from SHOW SLAVE STATUS command output. */ gatherSlaveStatus?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.TABLE_IO_WAITS_SUMMARY_BY_TABLE. */ gatherTableIoWaits?: boolean; /** * Gather metrics from PERFORMANCE_SCHEMA.TABLE_LOCK_WAITS. */ gatherTableLockWaits?: boolean; /** * Gather metrics from INFORMATION_SCHEMA.TABLES. */ gatherTableSchema?: boolean; /** * Truncates digest text from perfEventsStatements into this many characters. Example: `120`. */ perfEventsStatementsDigestTextLimit?: number; /** * Limits metrics from perf_events_statements. Example: `250`. */ perfEventsStatementsLimit?: number; /** * Only include perfEventsStatements whose last seen is less than this many seconds. Example: `86400`. */ perfEventsStatementsTimeLimit?: number; } export interface GetServiceIntegrationRsyslogUserConfig { /** * Per-service override for escaping embedded newlines in log messages. When set, it overrides the rsyslog endpoint setting for this service. When unset, the endpoint setting applies. */ escapeNewlines?: boolean; } export interface GetServiceListService { /** * Cloud provider and location. */ cloudDescription: string; /** * Target cloud. */ cloudName: string; /** * Active Customer Managed Key identifier (CMK ID). */ cmkId: string; /** * Service creation timestamp (ISO 8601). */ createTime: string; /** * Megabytes of disk space for data storage. */ diskSpaceMb: number; /** * True when the service uses a cluster plan with dedicated node groups. */ isClusterPlan: boolean; /** * Number of service nodes in the active plan. */ nodeCount: number; /** * Number of CPUs for each node. */ nodeCpuCount: number; /** * Megabytes of memory for each node. */ nodeMemoryMb: number; /** * Subscription plan. */ plan: string; /** * Project VPC ID. */ projectVpcId: string; /** * Service name. */ serviceName: string; /** * Service type code. */ serviceType: string; /** * Single line description of the service. */ serviceTypeDescription: string; /** * URI for connecting to the service (may be null). */ serviceUri: string; /** * State of the service. The possible values are `POWEROFF`, `REBALANCING`, `REBUILDING` and `RUNNING`. */ state: string; /** * Service is protected against termination and powering off. */ terminationProtection: boolean; /** * Service last update timestamp (ISO 8601). */ updateTime: string; } export interface GetServiceListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetServicePlanBackupConfig { /** * Interval of taking a frequent backup in service types supporting different backup schedules. */ frequentIntervalMinutes: number; /** * Maximum age of the oldest frequent backup in service types supporting different backup schedules. */ frequentOldestAgeMinutes: number; /** * Interval of taking an infrequent backup in service types supporting different backup schedules. */ infrequentIntervalMinutes: number; /** * Maximum age of the oldest infrequent backup in service types supporting different backup schedules. */ infrequentOldestAgeMinutes: number; /** * The interval, in hours, at which backups are generated. For some services, like PostgreSQL, this is the interval at which full snapshots are taken and continuous incremental backup stream is maintained in addition to that. */ interval: number; /** * Maximum number of backups to keep. Zero when no backups are created. */ maxCount: number; /** * Mechanism how backups can be restored. 'basic' means a backup is restored as is so that the system is restored to the state it was when the backup was generated. 'pitr' means point-in-time-recovery, which allows restoring the system to any state since the first available full snapshot. The possible values are `basic` and `pitr`. */ recoveryMode: string; } export interface GetServicePlanListServicePlan { /** * True when the plan is a cluster plan with dedicated node groups. */ isClusterPlan: boolean; /** * Maximum amount of system memory as a percentage (0-100) the service can actually use after taking into account management overhead. This is relevant for memory bound services for which some service management operations require allocating proportional amount of memory on top the basic load. */ maxMemoryPercent: number; /** * Number of nodes in this service plan. */ nodeCount: number; /** * Number of primary nodes in this Valkey cluster service plan. */ primaryCount: number; /** * Service plan hourly price per cloud region. */ regions: { [key: string]: outputs.GetServicePlanListServicePlanRegions; }; /** * Subscription plan. */ servicePlan: string; /** * Service type code. */ serviceType: string; /** * Number of shards in this service plan. */ shardCount: number; } export interface GetServicePlanListServicePlanRegions { /** * Maximum amount of disk space possible for the plan in the given region. */ diskSpaceCapMb: number; /** * Hourly additional disk space price per GiB in this region. */ diskSpaceGbPriceUsd: string; /** * Combined amount of service disk space of all service nodes in megabytes. */ diskSpaceMb: number; /** * Disk space change step size. */ diskSpaceStepMb: number; /** * Number of CPU cores on each service node. */ nodeCpuCount: number; /** * Amount of memory on each service node in megabytes. */ nodeMemoryMb: number; /** * Hourly object storage price per GiB in this region. */ objectStorageGbPriceUsd: string; /** * Hourly service price in this region. */ priceUsd: string; } export interface GetServicePlanListTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetServicePlanTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetThanosComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetThanosServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetThanosTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetThanosTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetThanosThano { /** * Query frontend URI. */ queryFrontendUri: string; /** * Query URI. */ queryUri: string; /** * Receiver remote write URI. */ receiverRemoteWriteUri: string; /** * Thanos server URIs. */ uris: string[]; } export interface GetThanosThanosUserConfig { /** * Configuration options for Thanos Compactor */ compactor?: outputs.GetThanosThanosUserConfigCompactor; /** * Environmental variables. * * @deprecated This property is deprecated. */ env?: { [key: string]: string; }; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetThanosThanosUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * After exceeding the limit a service alert is going to be raised (0 means not set). */ objectStorageUsageAlertThresholdGb?: number; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetThanosThanosUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetThanosThanosUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetThanosThanosUserConfigPublicAccess; /** * Configuration options for Thanos Query */ query?: outputs.GetThanosThanosUserConfigQuery; /** * Configuration options for Thanos Query Frontend */ queryFrontend?: outputs.GetThanosThanosUserConfigQueryFrontend; /** * Common configuration options for Thanos Receive. */ receiverIngesting?: { [key: string]: string; }; /** * Configuration options for Thanos Receive Routing. */ receiverRouting?: { [key: string]: string; }; /** * Configuration options for Thanos Ruler. */ ruler?: { [key: string]: string; }; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Configuration options for Thanos Store. */ store?: { [key: string]: string; }; } export interface GetThanosThanosUserConfigCompactor { /** * Retention time for data in days for each resolution (5m, 1h, raw). */ retentionDays?: number; } export interface GetThanosThanosUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetThanosThanosUserConfigPrivateAccess { /** * Allow clients to connect to queryFrontend with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ queryFrontend?: boolean; /** * Allow clients to connect to receiverRouting with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ receiverRouting?: boolean; } export interface GetThanosThanosUserConfigPrivatelinkAccess { /** * Enable query_frontend. */ queryFrontend?: boolean; /** * Enable receiver_routing. */ receiverRouting?: boolean; } export interface GetThanosThanosUserConfigPublicAccess { /** * Allow clients to connect to compactor from the public internet for service nodes that are in a project VPC or another type of private network. */ compactor?: boolean; /** * Allow clients to connect to query from the public internet for service nodes that are in a project VPC or another type of private network. */ query?: boolean; /** * Allow clients to connect to queryFrontend from the public internet for service nodes that are in a project VPC or another type of private network. */ queryFrontend?: boolean; /** * Allow clients to connect to receiverIngesting from the public internet for service nodes that are in a project VPC or another type of private network. */ receiverIngesting?: boolean; /** * Allow clients to connect to receiverRouting from the public internet for service nodes that are in a project VPC or another type of private network. */ receiverRouting?: boolean; /** * Allow clients to connect to ruler from the public internet for service nodes that are in a project VPC or another type of private network. */ ruler?: boolean; /** * Allow clients to connect to store from the public internet for service nodes that are in a project VPC or another type of private network. */ store?: boolean; } export interface GetThanosThanosUserConfigQuery { /** * Set the default evaluation interval for subqueries. Default: `1m`. */ queryDefaultEvaluationInterval?: string; /** * The maximum lookback duration for retrieving metrics during expression evaluations in PromQL. PromQL always evaluates the query for a certain timestamp, and it looks back for the given amount of time to get the latest sample. If it exceeds the maximum lookback delta, it assumes the series is stale and returns none (a gap). The lookback delta should be set to at least 2 times the slowest scrape interval. If unset, it will use the promql default of 5m. Default: `5m`. */ queryLookbackDelta?: string; /** * The default metadata time range duration for retrieving labels through Labels and Series API when the range parameters are not specified. The zero value means the range covers the time since the beginning. Default: `0s`. */ queryMetadataDefaultTimeRange?: string; /** * Maximum time to process a query by the query node. Default: `2m`. */ queryTimeout?: string; /** * The maximum samples allowed for a single Series request. The Series call fails if this limit is exceeded. Set to 0 for no limit. NOTE: For efficiency, the limit is internally implemented as 'chunks limit' considering each chunk contains a maximum of 120 samples. The default value is 100 * store.limits.request-series. Default: `0`. */ storeLimitsRequestSamples?: number; /** * The maximum series allowed for a single Series request. The Series call fails if this limit is exceeded. Set to 0 for no limit. The default value is 1000 * cpu_count. Default: `0`. */ storeLimitsRequestSeries?: number; } export interface GetThanosThanosUserConfigQueryFrontend { /** * Whether to align the query range boundaries with the step. If enabled, the query range boundaries will be aligned to the step, providing more accurate results for queries with high-resolution data. Default: `true`. */ queryRangeAlignRangeWithStep?: boolean; } export interface GetValkeyComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GetValkeyServiceIntegration { /** * Type of the service integration. The possible value is `readReplica`. */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GetValkeyTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GetValkeyTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface GetValkeyUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ read?: string; } export interface GetValkeyValkey { /** * Valkey password. */ password: string; /** * Valkey replica server URI. */ replicaUri: string; /** * Valkey slave server URIs. */ slaveUris: string[]; /** * Valkey server URIs. */ uris: string[]; } export interface GetValkeyValkeyUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Example: `3`. */ backupHour?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Example: `30`. */ backupMinute?: number; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * When enabled, Valkey will create frequent local RDB snapshots. When disabled, Valkey will only take RDB snapshots when a backup is created, based on the backup schedule. This setting is ignored when `valkeyPersistence` is set to `off`. Default: `true`. */ frequentSnapshots?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GetValkeyValkeyUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.GetValkeyValkeyUserConfigMigration; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GetValkeyValkeyUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GetValkeyValkeyUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GetValkeyValkeyUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Enum: `allchannels`, `resetchannels`. Determines default pub/sub channels' ACL for new users if ACL is not supplied. When this option is not defined, allChannels is assumed to keep backward compatibility. This option doesn't affect Valkey configuration acl-pubsub-default. */ valkeyAclChannelsDefault?: string; /** * Valkey reclaims expired keys both when accessed and in the background. The background process scans for expired keys to free memory. Increasing the active-expire-effort setting (default 1, max 10) uses more CPU to reclaim expired keys faster, reducing memory usage but potentially increasing latency. Default: `1`. */ valkeyActiveExpireEffort?: number; /** * Enable active memory defragmentation. When enabled, Valkey relocates objects off sparsely-used memory pages to reduce fragmentation and return memory to the operating system. Defragmentation runs on the main thread and consumes CPU, so it may increase latency under load. Default: `false`. */ valkeyActivedefrag?: boolean; /** * Set Valkey IO thread count. Changing this will cause a restart of the Valkey service. Example: `1`. */ valkeyIoThreads?: number; /** * LFU maxmemory-policy counter decay time in minutes. Default: `1`. */ valkeyLfuDecayTime?: number; /** * Counter logarithm factor for volatile-lfu and allkeys-lfu maxmemory-policies. Default: `10`. */ valkeyLfuLogFactor?: number; /** * Enum: `allkeys-lfu`, `allkeys-lru`, `allkeys-random`, `noeviction`, `volatile-lfu`, `volatile-lru`, `volatile-random`, `volatile-ttl`. Valkey maxmemory-policy. Default: `noeviction`. */ valkeyMaxmemoryPolicy?: string; /** * Set notify-keyspace-events option. */ valkeyNotifyKeyspaceEvents?: string; /** * Set number of Valkey databases. Changing this will cause a restart of the Valkey service. Example: `16`. */ valkeyNumberOfDatabases?: number; /** * Enum: `off`, `rdb`. When persistence is `rdb`, Valkey does RDB dumps each 10 minutes if any key is changed. Also RDB dumps are done according to backup schedule for backup purposes. When persistence is `off`, no RDB dumps and backups are done, so data can be lost at any moment if service is restarted for any reason, or if service is powered off. Also service can't be forked. */ valkeyPersistence?: string; /** * Set output buffer limit for pub / sub clients in MB. The value is the hard limit, the soft limit is 1/4 of the hard limit. When setting the limit, be mindful of the available memory in the selected service plan. Example: `64`. */ valkeyPubsubClientOutputBufferLimit?: number; /** * Require SSL to access Valkey. Default: `true`. */ valkeySsl?: boolean; /** * Valkey idle connection timeout in seconds. Default: `300`. */ valkeyTimeout?: number; /** * Enum: `8.1`, `9.0`, `9.1`, and newer. Valkey major version. */ valkeyVersion?: string; } export interface GetValkeyValkeyUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GetValkeyValkeyUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface GetValkeyValkeyUserConfigPrivateAccess { /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; /** * Allow clients to connect to valkey with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ valkey?: boolean; } export interface GetValkeyValkeyUserConfigPrivatelinkAccess { /** * Enable prometheus. */ prometheus?: boolean; /** * Enable valkey. */ valkey?: boolean; } export interface GetValkeyValkeyUserConfigPublicAccess { /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; /** * Allow clients to connect to valkey from the public internet for service nodes that are in a project VPC or another type of private network. */ valkey?: boolean; } export interface GovernanceAccessAccessData { /** * Acls. Changing this property forces recreation of the resource. */ acls: outputs.GovernanceAccessAccessDataAcl[]; /** * Project name. Changing this property forces recreation of the resource. */ projectName: string; /** * Service name. Changing this property forces recreation of the resource. */ serviceName: string; /** * The service username assigned to the access. Changing this property forces recreation of the resource. */ username: string; } export interface GovernanceAccessAccessDataAcl { /** * The IP address from which a principal is allowed or denied access to the resource. Use `*` for all hosts. Maximum length: `256`. Changing this property forces recreation of the resource. */ host: string; /** * Acl ID. */ id: string; /** * An enumeration. The possible values are `Read` and `Write`. Changing this property forces recreation of the resource. */ operation: string; /** * An enumeration. The possible value is `LITERAL`. */ patternType: string; /** * An enumeration. The possible value is `ALLOW`. Changing this property forces recreation of the resource. */ permissionType: string; /** * Acl principal. */ principal: string; /** * Acl resource name. Maximum length: `256`. Changing this property forces recreation of the resource. */ resourceName: string; /** * An enumeration. The possible value is `Topic`. Changing this property forces recreation of the resource. */ resourceType: string; } export interface GovernanceAccessTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface GrafanaComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface GrafanaGrafana { /** * Grafana server URIs. */ uris: string[]; } export interface GrafanaGrafanaUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Setting has no effect with Grafana 11 and onward. Enable or disable Grafana legacy alerting functionality. This should not be enabled with unified*alerting*enabled. */ alertingEnabled?: boolean; /** * Enum: `alerting`, `keepState`. Default error or timeout setting for new alerting rules. */ alertingErrorOrTimeout?: string; /** * Max number of alert annotations that Grafana stores. 0 (default) keeps all alert annotations. Example: `0`. */ alertingMaxAnnotationsToKeep?: number; /** * Enum: `alerting`, `keepState`, `noData`, `ok`. Default value for 'no data or null values' for new alerting rules. */ alertingNodataOrNullvalues?: string; /** * Allow embedding Grafana dashboards with iframe/frame/object/embed tags. Disabled by default to limit impact of clickjacking. */ allowEmbedding?: boolean; /** * Azure AD OAuth integration */ authAzuread?: outputs.GrafanaGrafanaUserConfigAuthAzuread; /** * Enable or disable basic authentication form, used by Grafana built-in login. */ authBasicEnabled?: boolean; /** * Generic OAuth integration */ authGenericOauth?: outputs.GrafanaGrafanaUserConfigAuthGenericOauth; /** * Github Auth integration */ authGithub?: outputs.GrafanaGrafanaUserConfigAuthGithub; /** * GitLab Auth integration */ authGitlab?: outputs.GrafanaGrafanaUserConfigAuthGitlab; /** * Google Auth integration */ authGoogle?: outputs.GrafanaGrafanaUserConfigAuthGoogle; /** * Enum: `lax`, `none`, `strict`. Cookie SameSite attribute: `strict` prevents sending cookie for cross-site requests, effectively disabling direct linking from other sites to Grafana. `lax` is the default value. */ cookieSamesite?: string; /** * Serve the web frontend using a custom CNAME pointing to the Aiven DNS name. When you set a custom domain for a service deployed in a VPC, the service certificate is only created for the public-* hostname and the custom domain. Example: `grafana.example.org`. */ customDomain?: string; /** * Enable browsing of dashboards in grid (pictures) mode. This feature is new in Grafana 9 and is quite resource intensive. It may cause low-end plans to work more slowly while the dashboard previews are rendering. */ dashboardPreviewsEnabled?: boolean; /** * Enable use of the Grafana Scenes Library as the dashboard engine. i.e. the `dashboardScene` feature flag. Upstream blog post at https://grafana.com/blog/2024/10/31/grafana-dashboards-are-now-powered-by-scenes-big-changes-same-ui/. */ dashboardScenesEnabled?: boolean; /** * Signed sequence of decimal numbers, followed by a unit suffix (ms, s, m, h, d), e.g. 30s, 1h. Example: `5s`. */ dashboardsMinRefreshInterval?: string; /** * Dashboard versions to keep per dashboard. Example: `20`. */ dashboardsVersionsToKeep?: number; /** * Send `X-Grafana-User` header to data source. */ dataproxySendUserHeader?: boolean; /** * Timeout for data proxy requests in seconds. Example: `30`. */ dataproxyTimeout?: number; /** * Grafana date format specifications */ dateFormats?: outputs.GrafanaGrafanaUserConfigDateFormats; /** * Set to true to disable gravatar. Defaults to false (gravatar is enabled). */ disableGravatar?: boolean; /** * Editors can manage folders, teams and dashboards created by them. */ editorsCanAdmin?: boolean; /** * External image store settings */ externalImageStorage?: outputs.GrafanaGrafanaUserConfigExternalImageStorage; /** * Google Analytics ID. Example: `UA-123456-4`. */ googleAnalyticsUaId?: string; /** * Enum: `11`, and newer. Grafana major version. */ grafanaVersion?: string; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.GrafanaGrafanaUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Enable Grafana's /metrics endpoint. */ metricsEnabled?: boolean; /** * Enforce user lookup based on email instead of the unique ID provided by the IdP. This setup introduces significant security risks, such as potential phishing, spoofing, and other data breaches. */ oauthAllowInsecureEmailLookup?: boolean; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.GrafanaGrafanaUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.GrafanaGrafanaUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.GrafanaGrafanaUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * SMTP server settings */ smtpServer?: outputs.GrafanaGrafanaUserConfigSmtpServer; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Enable or disable Grafana unified alerting functionality. By default this is enabled and any legacy alerts will be migrated on upgrade to Grafana 9+. To stay on legacy alerting, set unified*alerting*enabled to false and alertingEnabled to true. See https://grafana.com/docs/grafana/latest/alerting/ for more details. */ unifiedAlertingEnabled?: boolean; /** * Auto-assign new users on signup to main organization. Defaults to false. */ userAutoAssignOrg?: boolean; /** * Enum: `Admin`, `Editor`, `Viewer`. Set role for new signups. Defaults to Viewer. */ userAutoAssignOrgRole?: string; /** * Users with view-only permission can edit but not save dashboards. */ viewersCanEdit?: boolean; /** * Setting to enable/disable Write-Ahead Logging. The default value is false (disabled). */ wal?: boolean; } export interface GrafanaGrafanaUserConfigAuthAzuread { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Allowed domains. */ allowedDomains?: string[]; /** * Require users to belong to one of given groups. */ allowedGroups?: string[]; /** * Authorization URL. Example: `https://login.microsoftonline.com//oauth2/v2.0/authorize`. */ authUrl: string; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * Token URL. Example: `https://login.microsoftonline.com//oauth2/v2.0/token`. */ tokenUrl: string; } export interface GrafanaGrafanaUserConfigAuthGenericOauth { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Allowed domains. */ allowedDomains?: string[]; /** * Require user to be member of one of the listed organizations. */ allowedOrganizations?: string[]; /** * API URL. Example: `https://yourprovider.com/api`. */ apiUrl: string; /** * Authorization URL. Example: `https://yourprovider.com/oauth/authorize`. */ authUrl: string; /** * Allow users to bypass the login screen and automatically log in. */ autoLogin?: boolean; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * Name of the OAuth integration. Example: `My authentication`. */ name?: string; /** * OAuth scopes. */ scopes?: string[]; /** * Token URL. Example: `https://yourprovider.com/oauth/token`. */ tokenUrl: string; /** * Set to true to use refresh token and check access token expiration. */ useRefreshToken?: boolean; } export interface GrafanaGrafanaUserConfigAuthGithub { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Require users to belong to one of given organizations. */ allowedOrganizations?: string[]; /** * Allow users to bypass the login screen and automatically log in. */ autoLogin?: boolean; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * Stop automatically syncing user roles. */ skipOrgRoleSync?: boolean; /** * Require users to belong to one of given team IDs. */ teamIds?: number[]; } export interface GrafanaGrafanaUserConfigAuthGitlab { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Require users to belong to one of given groups. */ allowedGroups: string[]; /** * This only needs to be set when using self hosted GitLab. Example: `https://gitlab.com/api/v4`. */ apiUrl?: string; /** * This only needs to be set when using self hosted GitLab. Example: `https://gitlab.com/oauth/authorize`. */ authUrl?: string; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; /** * This only needs to be set when using self hosted GitLab. Example: `https://gitlab.com/oauth/token`. */ tokenUrl?: string; } export interface GrafanaGrafanaUserConfigAuthGoogle { /** * Automatically sign-up users on successful sign-in. */ allowSignUp?: boolean; /** * Domains allowed to sign-in to this Grafana. */ allowedDomains: string[]; /** * Client ID from provider. Example: `b1ba0bf54a4c2c0a1c29`. */ clientId: string; /** * Client secret from provider. Example: `bfa6gea4f129076761dcba8ce5e1e406bd83af7b`. */ clientSecret: string; } export interface GrafanaGrafanaUserConfigDateFormats { /** * Default time zone for user preferences. Value `browser` uses browser local time zone. Example: `Europe/Helsinki`. */ defaultTimezone?: string; /** * Moment.js style format string for cases where full date is shown. Example: `YYYY MM DD`. */ fullDate?: string; /** * Moment.js style format string used when a time requiring day accuracy is shown. Example: `MM/DD`. */ intervalDay?: string; /** * Moment.js style format string used when a time requiring hour accuracy is shown. Example: `MM/DD HH:mm`. */ intervalHour?: string; /** * Moment.js style format string used when a time requiring minute accuracy is shown. Example: `HH:mm`. */ intervalMinute?: string; /** * Moment.js style format string used when a time requiring month accuracy is shown. Example: `YYYY-MM`. */ intervalMonth?: string; /** * Moment.js style format string used when a time requiring second accuracy is shown. Example: `HH:mm:ss`. */ intervalSecond?: string; /** * Moment.js style format string used when a time requiring year accuracy is shown. Example: `YYYY`. */ intervalYear?: string; } export interface GrafanaGrafanaUserConfigExternalImageStorage { /** * S3 access key. Requires permissions to the S3 bucket for the s3:PutObject and s3:PutObjectAcl actions. Example: `AAAAAAAAAAAAAAAAAAA`. */ accessKey: string; /** * Bucket URL for S3. Example: `https://grafana.s3-ap-southeast-2.amazonaws.com/`. */ bucketUrl: string; /** * Enum: `s3`. External image store provider. */ provider: string; /** * S3 secret key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretKey: string; } export interface GrafanaGrafanaUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface GrafanaGrafanaUserConfigPrivateAccess { /** * Allow clients to connect to grafana with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ grafana?: boolean; } export interface GrafanaGrafanaUserConfigPrivatelinkAccess { /** * Enable grafana. */ grafana?: boolean; } export interface GrafanaGrafanaUserConfigPublicAccess { /** * Allow clients to connect to grafana from the public internet for service nodes that are in a project VPC or another type of private network. */ grafana?: boolean; } export interface GrafanaGrafanaUserConfigSmtpServer { /** * Address used for sending emails. Example: `yourgrafanauser@yourdomain.example.com`. */ fromAddress: string; /** * Name used in outgoing emails, defaults to Grafana. */ fromName?: string; /** * Server hostname or IP. Example: `smtp.example.com`. */ host: string; /** * Password for SMTP authentication. Example: `ein0eemeev5eeth3Ahfu`. */ password?: string; /** * SMTP server port. Example: `25`. */ port: number; /** * Skip verifying server certificate. Defaults to false. */ skipVerify?: boolean; /** * Enum: `MandatoryStartTLS`, `NoStartTLS`, `OpportunisticStartTLS`. Either OpportunisticStartTLS, MandatoryStartTLS or NoStartTLS. Default is OpportunisticStartTLS. */ starttlsPolicy?: string; /** * Username for SMTP authentication. Example: `smtpuser`. */ username?: string; } export interface GrafanaServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface GrafanaTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface GrafanaTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface KafkaAclTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface KafkaComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface KafkaConnectComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface KafkaConnectKafkaConnectUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Allow-list of HTTPS URLs used to validate GCP credentialSource requests for Kafka Connect. */ gcpAuthAllowedUrls?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.KafkaConnectKafkaConnectUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Kafka Connect configuration values */ kafkaConnect?: outputs.KafkaConnectKafkaConnectUserConfigKafkaConnect; /** * The plugin selected by the user */ pluginVersions?: outputs.KafkaConnectKafkaConnectUserConfigPluginVersion[]; /** * List of preferred zone IDs for service node placement. Nodes will be placed in these zones when available. If a specified zone is unavailable (e.g., due to capacity constraints), nodes will be placed in other available zones to maintain the configured number of zones for availability. Invalid zone IDs are rejected at configuration time. Zone IDs are cloud-specific: AWS uses zone IDs like `euc1-az1`, GCP uses zone names like `europe-west1-a`, and Azure uses `location/zone` format like `germanywestcentral/1`. If single*zone is enabled with an availability*zone, that setting takes precedence over preferred_zones. Changes take effect on next node recreation (e.g., maintenance or plan change). For eligible plans, nodes outside preferred zones are automatically rebalanced once per day. */ preferredZones?: string[]; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.KafkaConnectKafkaConnectUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.KafkaConnectKafkaConnectUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.KafkaConnectKafkaConnectUserConfigPublicAccess; /** * List of allowed URLs for SASL OAUTHBEARER authentication. Only HTTPS URLs are allowed for security reasons. */ saslOauthbearerAllowedUrls?: string[]; /** * Configure external secret providers in order to reference external secrets in connector configuration. Currently Hashicorp Vault (provider: vault, auth*method: token) and AWS Secrets Manager (provider: aws, auth*method: credentials) are supported. Secrets can be referenced in connector config with ${\n\n:\n\n:\n\n} */ secretProviders?: outputs.KafkaConnectKafkaConnectUserConfigSecretProvider[]; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface KafkaConnectKafkaConnectUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface KafkaConnectKafkaConnectUserConfigKafkaConnect { /** * Enum: `All`, `None`. Defines what client configurations can be overridden by the connector. Default is None. */ connectorClientConfigOverridePolicy?: string; /** * Enum: `earliest`, `latest`. What to do when there is no initial offset in Kafka or if the current offset does not exist any more on the server. Default is earliest. */ consumerAutoOffsetReset?: string; /** * Records are fetched in batches by the consumer, and if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that the consumer can make progress. As such, this is not a absolute maximum. */ consumerFetchMaxBytes?: number; /** * Enum: `readCommitted`, `readUncommitted`. Transaction read isolation level. read*uncommitted is the default, but read*committed can be used if consume-exactly-once behavior is desired. */ consumerIsolationLevel?: string; /** * Records are fetched in batches by the consumer.If the first record batch in the first non-empty partition of the fetch is larger than this limit, the batch will still be returned to ensure that the consumer can make progress. */ consumerMaxPartitionFetchBytes?: number; /** * The maximum delay in milliseconds between invocations of poll() when using consumer group management (defaults to 300000). */ consumerMaxPollIntervalMs?: number; /** * The maximum number of records returned in a single call to poll() (defaults to 500). */ consumerMaxPollRecords?: number; /** * The interval at which to try committing offsets for tasks (defaults to 60000). */ offsetFlushIntervalMs?: number; /** * Maximum number of milliseconds to wait for records to flush and partition offset data to be committed to offset storage before cancelling the process and restoring the offset data to be committed in a future attempt (defaults to 5000). */ offsetFlushTimeoutMs?: number; /** * When enabled, connectors will automatically resolve IPv6 addresses from external server names configured with dual-stack. Default: `false`. */ preferIpv6AddressEnable?: boolean; /** * This setting gives the upper bound of the batch size to be sent. If there are fewer than this many bytes accumulated for this partition, the producer will `linger` for the linger.ms time waiting for more records to show up. A batch size of zero will disable batching entirely (defaults to 16384). */ producerBatchSize?: number; /** * The total bytes of memory the producer can use to buffer records waiting to be sent to the broker (defaults to 33554432). */ producerBufferMemory?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * This setting gives the upper bound on the delay for batching: once there is batch.size worth of records for a partition it will be sent immediately regardless of this setting, however if there are fewer than this many bytes accumulated for this partition the producer will `linger` for the specified time waiting for more records to show up. Defaults to 0. */ producerLingerMs?: number; /** * This setting will limit the number of record batches the producer will send in a single request to avoid sending huge requests. */ producerMaxRequestSize?: number; /** * The maximum delay that is scheduled in order to wait for the return of one or more departed workers before rebalancing and reassigning their connectors and tasks to the group. During this period the connectors and tasks of the departed workers remain unassigned. Defaults to 5 minutes. */ scheduledRebalanceMaxDelayMs?: number; /** * The timeout in milliseconds used to detect failures when using Kafka’s group management facilities (defaults to 10000). */ sessionTimeoutMs?: number; } export interface KafkaConnectKafkaConnectUserConfigPluginVersion { /** * The name of the plugin. Example: `debezium-connector`. */ pluginName: string; /** * The version of the plugin. Example: `2.5.0`. */ version: string; } export interface KafkaConnectKafkaConnectUserConfigPrivateAccess { /** * Allow clients to connect to kafkaConnect with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafkaConnect?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface KafkaConnectKafkaConnectUserConfigPrivatelinkAccess { /** * Enable jolokia. */ jolokia?: boolean; /** * Enable kafka_connect. */ kafkaConnect?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface KafkaConnectKafkaConnectUserConfigPublicAccess { /** * Allow clients to connect to kafkaConnect from the public internet for service nodes that are in a project VPC or another type of private network. */ kafkaConnect?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface KafkaConnectKafkaConnectUserConfigSecretProvider { /** * AWS secret provider configuration */ aws?: outputs.KafkaConnectKafkaConnectUserConfigSecretProviderAws; /** * Azure KeyVault secret provider configuration */ azure?: outputs.KafkaConnectKafkaConnectUserConfigSecretProviderAzure; /** * ENV secret provider configuration */ env?: outputs.KafkaConnectKafkaConnectUserConfigSecretProviderEnv; /** * Name of the secret provider. Used to reference secrets in connector config. */ name: string; /** * Vault secret provider configuration */ vault?: outputs.KafkaConnectKafkaConnectUserConfigSecretProviderVault; } export interface KafkaConnectKafkaConnectUserConfigSecretProviderAws { /** * Access key used to authenticate with aws. */ accessKey?: string; /** * Enum: `credentials`. Auth method of the vault secret provider. */ authMethod: string; /** * Region used to lookup secrets with AWS SecretManager. */ region: string; /** * Secret key used to authenticate with aws. */ secretKey?: string; } export interface KafkaConnectKafkaConnectUserConfigSecretProviderAzure { /** * Enum: `credentials`. Auth method of the Azure KeyVault secret provider. */ authMethod: string; /** * Azure client ID for the service principal. */ clientId?: string; /** * Azure client secret for the service principal. */ secret?: string; /** * Azure tenant ID for the service principal. */ tenantId?: string; } export interface KafkaConnectKafkaConnectUserConfigSecretProviderEnv { /** * Key/value map of secrets for ENV secret provider. */ secrets: { [key: string]: string; }; } export interface KafkaConnectKafkaConnectUserConfigSecretProviderVault { /** * Address of the Vault server. */ address: string; /** * Enum: `token`. Auth method of the vault secret provider. */ authMethod: string; /** * Enum: `1`, `2`, and newer. KV Secrets Engine version of the Vault server instance. */ engineVersion?: number; /** * Prefix path depth of the secrets Engine. Default is 1. If the secrets engine path has more than one segment it has to be increased to the number of segments. */ prefixPathDepth?: number; /** * PEM encoded certificate of the Vault server. Required if the vault server uses a self-signed certificate. */ serverPem?: string; /** * Token used to authenticate with vault and auth method `token`. */ token?: string; } export interface KafkaConnectServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface KafkaConnectTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface KafkaConnectTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface KafkaConnectorTask { /** * The name of the related connector. */ connector: string; /** * The task ID of the task. */ task: number; } export interface KafkaKafka { /** * The Kafka client certificate. */ accessCert: string; /** * The Kafka client certificate key. */ accessKey: string; /** * The Kafka Connect URI. */ connectUri: string; /** * The Kafka REST URI. */ restUri: string; /** * The Schema Registry URI. */ schemaRegistryUri: string; /** * Kafka server URIs. */ uris: string[]; } export interface KafkaKafkaUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Allow access to read Kafka topic messages in the Aiven Console and REST API. */ aivenKafkaTopicMessages?: boolean; /** * Enum: `12`, `24`, `3`, `4`, `6`, `8`. Interval in hours between automatic backups. Minimum value is 3 hours. Must be a divisor of 24 (3, 4, 6, 8, 12, 24). (Applicable to ACU plans only). */ backupIntervalHours?: number; /** * Number of days to retain automatic backups. Backups older than this value will be automatically deleted. (Applicable to ACU plans only). Example: `7`. */ backupRetentionDays?: number; /** * Serve the web frontend using a custom CNAME pointing to the Aiven DNS name. When you set a custom domain for a service deployed in a VPC, the service certificate is only created for the public-* hostname and the custom domain. Example: `grafana.example.org`. */ customDomain?: string; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * Enable follower fetching */ followerFetching?: outputs.KafkaKafkaUserConfigFollowerFetching; /** * Allow-list of HTTPS URLs used to validate GCP credentialSource requests for Kafka Connect. */ gcpAuthAllowedUrls?: string[]; /** * Inkless configuration values */ inkless?: outputs.KafkaKafkaUserConfigInkless; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.KafkaKafkaUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Kafka broker configuration values */ kafka?: outputs.KafkaKafkaUserConfigKafka; /** * Kafka authentication methods */ kafkaAuthenticationMethods?: outputs.KafkaKafkaUserConfigKafkaAuthenticationMethods; /** * Enable Kafka Connect service. Default: `false`. */ kafkaConnect?: boolean; /** * Kafka Connect configuration values */ kafkaConnectConfig?: outputs.KafkaKafkaUserConfigKafkaConnectConfig; /** * The plugin selected by the user */ kafkaConnectPluginVersions?: outputs.KafkaKafkaUserConfigKafkaConnectPluginVersion[]; /** * Configure external secret providers in order to reference external secrets in connector configuration. Currently Hashicorp Vault (provider: vault, auth*method: token) and AWS Secrets Manager (provider: aws, auth*method: credentials) are supported. Secrets can be referenced in connector config with ${\n\n:\n\n:\n\n} */ kafkaConnectSecretProviders?: outputs.KafkaKafkaUserConfigKafkaConnectSecretProvider[]; /** * Kafka Diskless configuration values */ kafkaDiskless?: outputs.KafkaKafkaUserConfigKafkaDiskless; /** * Enable Kafka-REST service. Default: `false`. */ kafkaRest?: boolean; /** * Enable authorization in Kafka-REST service. */ kafkaRestAuthorization?: boolean; /** * Kafka REST configuration */ kafkaRestConfig?: outputs.KafkaKafkaUserConfigKafkaRestConfig; /** * Kafka SASL mechanisms */ kafkaSaslMechanisms?: outputs.KafkaKafkaUserConfigKafkaSaslMechanisms; /** * Enum: `3.1`, `3.2`, `3.3`, `3.4`, `3.5`, `3.6`, `3.7`, `3.8`, `3.9`, `4.0`, `4.1`, `4.2`, and newer. Kafka major version. */ kafkaVersion?: string; /** * Pin a specific installed Karapace version on this service. Leave null/unset to auto-follow the newest installed version. */ karapaceVersion?: string; /** * Use a Let's Encrypt certificate authority (CA) for Kafka SASL authentication. (Default: False). */ letsencryptSasl?: boolean; /** * Use a Let's Encrypt certificate authority (CA) for Kafka SASL authentication via Privatelink. (Default: False). */ letsencryptSaslPrivatelink?: boolean; /** * List of preferred zone IDs for service node placement. Nodes will be placed in these zones when available. If a specified zone is unavailable (e.g., due to capacity constraints), nodes will be placed in other available zones to maintain the configured number of zones for availability. Invalid zone IDs are rejected at configuration time. Zone IDs are cloud-specific: AWS uses zone IDs like `euc1-az1`, GCP uses zone names like `europe-west1-a`, and Azure uses `location/zone` format like `germanywestcentral/1`. If single*zone is enabled with an availability*zone, that setting takes precedence over preferred_zones. Changes take effect on next node recreation (e.g., maintenance or plan change). For eligible plans, nodes outside preferred zones are automatically rebalanced once per day. */ preferredZones?: string[]; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.KafkaKafkaUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.KafkaKafkaUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.KafkaKafkaUserConfigPublicAccess; /** * List of allowed URLs for SASL OAUTHBEARER authentication. Only HTTPS URLs are allowed for security reasons. */ saslOauthbearerAllowedUrls?: string[]; /** * Enable Schema-Registry service. Default: `false`. */ schemaRegistry?: boolean; /** * Schema Registry configuration */ schemaRegistryConfig?: outputs.KafkaKafkaUserConfigSchemaRegistryConfig; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Single-zone configuration */ singleZone?: outputs.KafkaKafkaUserConfigSingleZone; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Tiered storage configuration */ tieredStorage?: outputs.KafkaKafkaUserConfigTieredStorage; } export interface KafkaKafkaUserConfigFollowerFetching { /** * Whether to enable the follower fetching functionality. */ enabled?: boolean; } export interface KafkaKafkaUserConfigInkless { /** * Whether to enable the Inkless functionality. */ enabled: boolean; } export interface KafkaKafkaUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface KafkaKafkaUserConfigKafka { /** * Enable Kafka audit logging by providing this object. Removing it disables the feature. Enabling, updating, or disabling audit logging causes a rolling restart of all Kafka brokers */ auditLog?: outputs.KafkaKafkaUserConfigKafkaAuditLog; /** * Enable auto-creation of topics. (Default: false). */ autoCreateTopicsEnable?: boolean; /** * Enum: `gzip`, `lz4`, `producer`, `snappy`, `uncompressed`, `zstd`. Specify the final compression type for a given topic. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `uncompressed` which is equivalent to no compression; and `producer` which means retain the original compression codec set by the producer.(Default: producer). */ compressionType?: string; /** * Idle connections timeout: the server socket processor threads close the connections that idle for longer than this. (Default: 600000 ms (10 minutes)). Example: `540000`. */ connectionsMaxIdleMs?: number; /** * Replication factor for auto-created topics (Default: 3). */ defaultReplicationFactor?: number; /** * Enum: `classic`, `classic,consumer`, `classic,consumer,share`, `classic,consumer,share,streams`, `classic,consumer,streams`, `classic,share`, `classic,streams`. The enabled consumer group rebalance protocols. Use consumer, classic, share, streams to enable Kafka share groups. */ groupCoordinatorRebalanceProtocols?: string; /** * The amount of time, in milliseconds, the group coordinator will wait for more consumers to join a new group before performing the first rebalance. A longer delay means potentially fewer rebalances, but increases the time until processing begins. The default value for this is 3 seconds. During development and testing it might be desirable to set this to 0 in order to not delay test execution time. (Default: 3000 ms (3 seconds)). Example: `3000`. */ groupInitialRebalanceDelayMs?: number; /** * The maximum allowed session timeout for registered consumers. Longer timeouts give consumers more time to process messages in between heartbeats at the cost of a longer time to detect failures. Default: 1800000 ms (30 minutes). */ groupMaxSessionTimeoutMs?: number; /** * The minimum allowed session timeout for registered consumers. Longer timeouts give consumers more time to process messages in between heartbeats at the cost of a longer time to detect failures. (Default: 6000 ms (6 seconds)). Example: `6000`. */ groupMinSessionTimeoutMs?: number; /** * The maximum delivery attempts for a share-group record. Example: `5`. */ groupShareDeliveryCountLimit?: number; /** * The heartbeat interval used by share group members. Example: `5000`. */ groupShareHeartbeatIntervalMs?: number; /** * The maximum number of share groups allowed on the broker. */ groupShareMaxGroups?: number; /** * The maximum heartbeat interval allowed for share group members. Example: `15000`. */ groupShareMaxHeartbeatIntervalMs?: number; /** * The maximum record lock duration allowed for share groups. Example: `60000`. */ groupShareMaxRecordLockDurationMs?: number; /** * The maximum session timeout allowed for share group members. Example: `60000`. */ groupShareMaxSessionTimeoutMs?: number; /** * The maximum number of members allowed in a share group. Example: `200`. */ groupShareMaxSize?: number; /** * The minimum heartbeat interval allowed for share group members. Example: `5000`. */ groupShareMinHeartbeatIntervalMs?: number; /** * The minimum record lock duration allowed for share groups. Example: `15000`. */ groupShareMinRecordLockDurationMs?: number; /** * The minimum session timeout allowed for share group members. Example: `45000`. */ groupShareMinSessionTimeoutMs?: number; /** * The maximum number of record locks allowed per share group partition. Example: `2000`. */ groupSharePartitionMaxRecordLocks?: number; /** * The duration for which a fetched share-group record is locked. Example: `30000`. */ groupShareRecordLockDurationMs?: number; /** * The timeout used to detect share group member failures. Example: `45000`. */ groupShareSessionTimeoutMs?: number; /** * How long are delete records retained? (Default: 86400000 (1 day)). */ logCleanerDeleteRetentionMs?: number; /** * The maximum amount of time message will remain uncompacted. Only applicable for logs that are being compacted. (Default: 9223372036854775807 ms (Long.MAX_VALUE)). */ logCleanerMaxCompactionLagMs?: number; /** * Controls log compactor frequency. Larger value means more frequent compactions but also more space wasted for logs. Consider setting log.cleaner.max.compaction.lag.ms to enforce compactions sooner, instead of setting a very high value for this option. (Default: 0.5). Example: `0.5`. */ logCleanerMinCleanableRatio?: number; /** * The minimum time a message will remain uncompacted in the log. Only applicable for logs that are being compacted. (Default: 0 ms). */ logCleanerMinCompactionLagMs?: number; /** * Enum: `compact`, `compact,delete`, `delete`. The default cleanup policy for segments beyond the retention window (Default: delete). */ logCleanupPolicy?: string; /** * The number of messages accumulated on a log partition before messages are flushed to disk (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logFlushIntervalMessages?: number; /** * The maximum time in ms that a message in any topic is kept in memory (page-cache) before flushed to disk. If not set, the value in log.flush.scheduler.interval.ms is used (Default: null). */ logFlushIntervalMs?: number; /** * The interval with which Kafka adds an entry to the offset index (Default: 4096 bytes (4 kibibytes)). Example: `4096`. */ logIndexIntervalBytes?: number; /** * The maximum size in bytes of the offset index (Default: 10485760 (10 mebibytes)). */ logIndexSizeMaxBytes?: number; /** * The maximum size of local log segments that can grow for a partition before it gets eligible for deletion. If set to -2, the value of log.retention.bytes is used. The effective value should always be less than or equal to log.retention.bytes value. (Default: -2). */ logLocalRetentionBytes?: number; /** * The number of milliseconds to keep the local log segments before it gets eligible for deletion. If set to -2, the value of log.retention.ms is used. The effective value should always be less than or equal to log.retention.ms value. (Default: -2). */ logLocalRetentionMs?: number; /** * This configuration controls whether down-conversion of message formats is enabled to satisfy consume requests. (Default: true). */ logMessageDownconversionEnable?: boolean; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps later than the broker's timestamp. (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logMessageTimestampAfterMaxMs?: number; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps earlier than the broker's timestamp. (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logMessageTimestampBeforeMaxMs?: number; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message (Default: 9223372036854775807 (Long.MAX_VALUE)). */ logMessageTimestampDifferenceMaxMs?: number; /** * Enum: `CreateTime`, `LogAppendTime`. Define whether the timestamp in the message is message create time or log append time. (Default: CreateTime). */ logMessageTimestampType?: string; /** * Should pre allocate file when create new segment? (Default: false). */ logPreallocate?: boolean; /** * The maximum size of the log before deleting messages (Default: -1). */ logRetentionBytes?: number; /** * The number of hours to keep a log file before deleting it. Use -1 for unlimited retention or 1 or higher. Setting 0 is invalid and prevents Kafka from starting. (Default: 168 hours, or 1 week). */ logRetentionHours?: number; /** * The number of milliseconds to keep a log file before deleting it (in milliseconds), If not set, the value in log.retention.minutes is used. If set to -1, no time limit is applied. (Default: null, log.retention.hours applies). */ logRetentionMs?: number; /** * The maximum jitter to subtract from logRollTimeMillis (in milliseconds). If not set, the value in log.roll.jitter.hours is used (Default: null). */ logRollJitterMs?: number; /** * The maximum time before a new log segment is rolled out (in milliseconds). (Default: null, log.roll.hours applies (Default: 168, 7 days)). */ logRollMs?: number; /** * The maximum size of a single log file (Default: 1073741824 bytes (1 gibibyte)). */ logSegmentBytes?: number; /** * The amount of time to wait before deleting a file from the filesystem (Default: 60000 ms (1 minute)). Example: `60000`. */ logSegmentDeleteDelayMs?: number; /** * The maximum number of connections allowed from each ip address (Default: 2147483647). */ maxConnectionsPerIp?: number; /** * The maximum number of incremental fetch sessions that the broker will maintain. (Default: 1000). Example: `1000`. */ maxIncrementalFetchSessionCacheSlots?: number; /** * The maximum size of message that the server can receive. (Default: 1048588 bytes (1 mebibyte + 12 bytes)). */ messageMaxBytes?: number; /** * When a producer sets acks to `all` (or `-1`), min.insync.replicas specifies the minimum number of replicas that must acknowledge a write for the write to be considered successful. (Default: 1). Example: `1`. */ minInsyncReplicas?: number; /** * Number of partitions for auto-created topics (Default: 1). */ numPartitions?: number; /** * Log retention window in minutes for offsets topic (Default: 10080 minutes (7 days)). Example: `10080`. */ offsetsRetentionMinutes?: number; /** * The purge interval (in number of requests) of the producer request purgatory (Default: 1000). */ producerPurgatoryPurgeIntervalRequests?: number; /** * The number of bytes of messages to attempt to fetch for each partition . This is not an absolute maximum, if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that progress can be made. (Default: 1048576 bytes (1 mebibytes)). */ replicaFetchMaxBytes?: number; /** * Maximum bytes expected for the entire fetch response. Records are fetched in batches, and if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that progress can be made. As such, this is not an absolute maximum. (Default: 10485760 bytes (10 mebibytes)). */ replicaFetchResponseMaxBytes?: number; /** * The (optional) comma-delimited setting for the broker to use to verify that the JWT was issued for one of the expected audiences. (Default: null). */ saslOauthbearerExpectedAudience?: string; /** * Optional setting for the broker to use to verify that the JWT was created by the expected issuer.(Default: null). */ saslOauthbearerExpectedIssuer?: string; /** * OIDC JWKS endpoint URL. By setting this the SASL SSL OAuth2/OIDC authentication is enabled. See also other options for SASL OAuth2/OIDC. (Default: null). */ saslOauthbearerJwksEndpointUrl?: string; /** * Name of the scope from which to extract the subject claim from the JWT.(Default: sub). */ saslOauthbearerSubClaimName?: string; /** * The maximum number of bytes in a socket request (Default: 104857600 bytes). */ socketRequestMaxBytes?: number; /** * Enable verification that checks that the partition has been added to the transaction before writing transactional records to the partition. (Default: true). */ transactionPartitionVerificationEnable?: boolean; /** * The interval at which to remove transactions that have expired due to transactional.id.expiration.ms passing (Default: 3600000 ms (1 hour)). */ transactionRemoveExpiredTransactionCleanupIntervalMs?: number; /** * The transaction topic segment bytes should be kept relatively small in order to facilitate faster log compaction and cache loads (Default: 104857600 bytes (100 mebibytes)). */ transactionStateLogSegmentBytes?: number; } export interface KafkaKafkaUserConfigKafkaAuditLog { /** * Aggregation period in seconds over which audit log entries are batched before being emitted. Default: `300`. */ aggregationPeriodSec?: number; /** * Enum: `user`, `userAndIp`. Group audit log entries by user or by user and IP address. Only valid when record*type is user*operations. Default: `userAndIp`. */ groupBy?: string; /** * Whether to include denied authorization attempts in the audit log. Default: `false`. */ includeDenials?: boolean; /** * Enum: `userActivity`, `userOperations`. user*operations records individual Kafka API calls (produce, fetch, etc.). user*activity records higher-level user actions. Default: `userOperations`. */ recordType?: string; } export interface KafkaKafkaUserConfigKafkaAuthenticationMethods { /** * Enable certificate/SSL authentication. Default: `true`. */ certificate?: boolean; /** * Enable SASL authentication. Default: `false`. */ sasl?: boolean; } export interface KafkaKafkaUserConfigKafkaConnectConfig { /** * Enum: `All`, `None`. Defines what client configurations can be overridden by the connector. Default is None. */ connectorClientConfigOverridePolicy?: string; /** * Enum: `earliest`, `latest`. What to do when there is no initial offset in Kafka or if the current offset does not exist any more on the server. Default is earliest. */ consumerAutoOffsetReset?: string; /** * Records are fetched in batches by the consumer, and if the first record batch in the first non-empty partition of the fetch is larger than this value, the record batch will still be returned to ensure that the consumer can make progress. As such, this is not a absolute maximum. */ consumerFetchMaxBytes?: number; /** * Enum: `readCommitted`, `readUncommitted`. Transaction read isolation level. read*uncommitted is the default, but read*committed can be used if consume-exactly-once behavior is desired. */ consumerIsolationLevel?: string; /** * Records are fetched in batches by the consumer.If the first record batch in the first non-empty partition of the fetch is larger than this limit, the batch will still be returned to ensure that the consumer can make progress. */ consumerMaxPartitionFetchBytes?: number; /** * The maximum delay in milliseconds between invocations of poll() when using consumer group management (defaults to 300000). */ consumerMaxPollIntervalMs?: number; /** * The maximum number of records returned in a single call to poll() (defaults to 500). */ consumerMaxPollRecords?: number; /** * The interval at which to try committing offsets for tasks (defaults to 60000). */ offsetFlushIntervalMs?: number; /** * Maximum number of milliseconds to wait for records to flush and partition offset data to be committed to offset storage before cancelling the process and restoring the offset data to be committed in a future attempt (defaults to 5000). */ offsetFlushTimeoutMs?: number; /** * When enabled, connectors will automatically resolve IPv6 addresses from external server names configured with dual-stack. Default: `false`. */ preferIpv6AddressEnable?: boolean; /** * This setting gives the upper bound of the batch size to be sent. If there are fewer than this many bytes accumulated for this partition, the producer will `linger` for the linger.ms time waiting for more records to show up. A batch size of zero will disable batching entirely (defaults to 16384). */ producerBatchSize?: number; /** * The total bytes of memory the producer can use to buffer records waiting to be sent to the broker (defaults to 33554432). */ producerBufferMemory?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * This setting gives the upper bound on the delay for batching: once there is batch.size worth of records for a partition it will be sent immediately regardless of this setting, however if there are fewer than this many bytes accumulated for this partition the producer will `linger` for the specified time waiting for more records to show up. Defaults to 0. */ producerLingerMs?: number; /** * This setting will limit the number of record batches the producer will send in a single request to avoid sending huge requests. */ producerMaxRequestSize?: number; /** * The maximum delay that is scheduled in order to wait for the return of one or more departed workers before rebalancing and reassigning their connectors and tasks to the group. During this period the connectors and tasks of the departed workers remain unassigned. Defaults to 5 minutes. */ scheduledRebalanceMaxDelayMs?: number; /** * The timeout in milliseconds used to detect failures when using Kafka’s group management facilities (defaults to 10000). */ sessionTimeoutMs?: number; } export interface KafkaKafkaUserConfigKafkaConnectPluginVersion { /** * The name of the plugin. Example: `debezium-connector`. */ pluginName: string; /** * The version of the plugin. Example: `2.5.0`. */ version: string; } export interface KafkaKafkaUserConfigKafkaConnectSecretProvider { /** * AWS secret provider configuration */ aws?: outputs.KafkaKafkaUserConfigKafkaConnectSecretProviderAws; /** * Azure KeyVault secret provider configuration */ azure?: outputs.KafkaKafkaUserConfigKafkaConnectSecretProviderAzure; /** * ENV secret provider configuration */ env?: outputs.KafkaKafkaUserConfigKafkaConnectSecretProviderEnv; /** * Name of the secret provider. Used to reference secrets in connector config. */ name: string; /** * Vault secret provider configuration */ vault?: outputs.KafkaKafkaUserConfigKafkaConnectSecretProviderVault; } export interface KafkaKafkaUserConfigKafkaConnectSecretProviderAws { /** * Access key used to authenticate with aws. */ accessKey?: string; /** * Enum: `credentials`. Auth method of the vault secret provider. */ authMethod: string; /** * Region used to lookup secrets with AWS SecretManager. */ region: string; /** * Secret key used to authenticate with aws. */ secretKey?: string; } export interface KafkaKafkaUserConfigKafkaConnectSecretProviderAzure { /** * Enum: `credentials`. Auth method of the Azure KeyVault secret provider. */ authMethod: string; /** * Azure client ID for the service principal. */ clientId?: string; /** * Azure client secret for the service principal. */ secret?: string; /** * Azure tenant ID for the service principal. */ tenantId?: string; } export interface KafkaKafkaUserConfigKafkaConnectSecretProviderEnv { /** * Key/value map of secrets for ENV secret provider. */ secrets: { [key: string]: string; }; } export interface KafkaKafkaUserConfigKafkaConnectSecretProviderVault { /** * Address of the Vault server. */ address: string; /** * Enum: `token`. Auth method of the vault secret provider. */ authMethod: string; /** * Enum: `1`, `2`, and newer. KV Secrets Engine version of the Vault server instance. */ engineVersion?: number; /** * Prefix path depth of the secrets Engine. Default is 1. If the secrets engine path has more than one segment it has to be increased to the number of segments. */ prefixPathDepth?: number; /** * PEM encoded certificate of the Vault server. Required if the vault server uses a self-signed certificate. */ serverPem?: string; /** * Token used to authenticate with vault and auth method `token`. */ token?: string; } export interface KafkaKafkaUserConfigKafkaDiskless { /** * The regexes of topics to auto enable diskless. Topics matching any of the regexes will be created as diskless topics. */ autoDisklessTopicRegexes?: string[]; /** * Whether to enable the Diskless functionality. */ enabled: boolean; } export interface KafkaKafkaUserConfigKafkaRestConfig { /** * If true the consumer's offset will be periodically committed to Kafka in the background. Default: `true`. */ consumerEnableAutoCommit?: boolean; /** * Specifies the maximum duration (in seconds) a client can remain idle before it is deleted. If a consumer is inactive, it will exit the consumer group, and its state will be discarded. A value of 0 (default) indicates that the consumer will not be disconnected automatically due to inactivity. Default: `0`. */ consumerIdleDisconnectTimeout?: number; /** * Maximum number of bytes in unencoded message keys and values by a single request. */ consumerRequestMaxBytes?: number; /** * Enum: `1000`, `15000`, `30000`. The maximum total time to wait for messages for a request if the maximum number of messages has not yet been reached. Default: `1000`. */ consumerRequestTimeoutMs?: number; /** * Enum: `recordName`, `topicName`, `topicRecordName`. Name strategy to use when selecting subject for storing schemas. Default: `topicName`. */ nameStrategy?: string; /** * If true, validate that given schema is registered under expected subject name by the used name strategy when producing messages. Default: `true`. */ nameStrategyValidation?: boolean; /** * Enum: `-1`, `0`, `1`, `all`. The number of acknowledgments the producer requires the leader to have received before considering a request complete. If set to `all` or `-1`, the leader will wait for the full set of in-sync replicas to acknowledge the record. Default: `1`. */ producerAcks?: string; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * Wait for up to the given delay to allow batching records together. Default: `0`. */ producerLingerMs?: number; /** * The maximum size of a request in bytes. Note that Kafka broker can also cap the record batch size. */ producerMaxRequestSize?: number; /** * Maximum number of SimpleConsumers that can be instantiated per broker. Default: `25`. */ simpleconsumerPoolSizeMax?: number; } export interface KafkaKafkaUserConfigKafkaSaslMechanisms { /** * Enable PLAIN mechanism. Default: `true`. */ plain?: boolean; /** * Enable SCRAM-SHA-256 mechanism. Default: `true`. */ scramSha256?: boolean; /** * Enable SCRAM-SHA-512 mechanism. Default: `true`. */ scramSha512?: boolean; } export interface KafkaKafkaUserConfigPrivateAccess { /** * Allow clients to connect to kafka with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafka?: boolean; /** * Allow clients to connect to kafkaConnect with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafkaConnect?: boolean; /** * Allow clients to connect to kafkaRest with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ kafkaRest?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; /** * Allow clients to connect to schemaRegistry with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ schemaRegistry?: boolean; } export interface KafkaKafkaUserConfigPrivatelinkAccess { /** * Enable jolokia. */ jolokia?: boolean; /** * Enable kafka. */ kafka?: boolean; /** * Enable kafka_connect. */ kafkaConnect?: boolean; /** * Enable kafka_rest. */ kafkaRest?: boolean; /** * Enable prometheus. */ prometheus?: boolean; /** * Enable schema_registry. */ schemaRegistry?: boolean; } export interface KafkaKafkaUserConfigPublicAccess { /** * Allow clients to connect to kafka from the public internet for service nodes that are in a project VPC or another type of private network. */ kafka?: boolean; /** * Allow clients to connect to kafkaConnect from the public internet for service nodes that are in a project VPC or another type of private network. */ kafkaConnect?: boolean; /** * Allow clients to connect to kafkaRest from the public internet for service nodes that are in a project VPC or another type of private network. */ kafkaRest?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; /** * Allow clients to connect to schemaRegistry from the public internet for service nodes that are in a project VPC or another type of private network. */ schemaRegistry?: boolean; } export interface KafkaKafkaUserConfigSchemaRegistryConfig { /** * If true, Karapace / Schema Registry on the service nodes can participate in leader election. It might be needed to disable this when the schemas topic is replicated to a secondary cluster and Karapace / Schema Registry there must not participate in leader election. Defaults to `true`. */ leaderEligibility?: boolean; /** * If enabled, kafka errors which can be retried or custom errors specified for the service will not be raised, instead, a warning log is emitted. This will denoise issue tracking systems, i.e. sentry. Defaults to `true`. */ retriableErrorsSilenced?: boolean; /** * If enabled, the Schema Registry validates OAuth2/OIDC JWT bearer tokens on incoming requests. Requires the OIDC provider settings under the `kafka` configuration (`saslOauthbearerJwksEndpointUrl` and related). Defaults to `false`. */ saslOauthbearerAuthenticationEnabled?: boolean; /** * If enabled, the Schema Registry enforces role-based authorization derived from the JWT roles claim. Requires `saslOauthbearerAuthenticationEnabled` to be enabled. Defaults to `false`. */ saslOauthbearerAuthorizationEnabled?: boolean; /** * JSON object mapping HTTP methods to the list of roles allowed to perform them on the Schema Registry, provided as a JSON-encoded string. Role names use the `karapace.` prefix, e.g. `karapace.schema:read`. Defaults to `{"GET": ["karapace.schema:read", "karapace.subject:read"], "POST": [], "PUT": [], "DELETE": []}`. */ saslOauthbearerMethodRoles?: string; /** * JSON path used to extract the roles claim from the JWT for Schema Registry authorization. Defaults to `resource_access.karapace.roles`. */ saslOauthbearerRolesClaimPath?: string; /** * If enabled, causes the Karapace schema-registry service to shutdown when there are invalid schema records in the `_schemas` topic. Defaults to `false`. */ schemaReaderStrictMode?: boolean; /** * The durable single partition topic that acts as the durable log for the data. This topic must be compacted to avoid losing data due to retention policy. Please note that changing this configuration in an existing Schema Registry / Karapace setup leads to previous schemas being inaccessible, data encoded with them potentially unreadable and schema ID sequence put out of order. It's only possible to do the switch while Schema Registry / Karapace is disabled. Defaults to `_schemas`. */ topicName?: string; } export interface KafkaKafkaUserConfigSingleZone { /** * The availability zone to use for the service. This is only used when enabled is set to true. If not set the service will be allocated in random AZ.The AZ is not guaranteed, and the service may be allocated in a different AZ if the selected AZ is not available. Zones will not be validated and invalid zones will be ignored, falling back to random AZ selection. Common availability zones include: AWS (euc1-az1, euc1-az2, euc1-az3), GCP (europe-west1-a, europe-west1-b, europe-west1-c), Azure (germanywestcentral/1, germanywestcentral/2, germanywestcentral/3). Example: `euc1-az1`. */ availabilityZone?: string; /** * Whether to allocate nodes on the same Availability Zone or spread across zones available. By default service nodes are spread across different AZs. The single AZ support is best-effort and may temporarily allocate nodes in different AZs e.g. in case of capacity limitations in one AZ. */ enabled?: boolean; } export interface KafkaKafkaUserConfigTieredStorage { /** * Whether to enable the tiered storage functionality. */ enabled?: boolean; /** * Local cache configuration * * @deprecated This property is deprecated. */ localCache?: outputs.KafkaKafkaUserConfigTieredStorageLocalCache; } export interface KafkaKafkaUserConfigTieredStorageLocalCache { /** * Local cache size in bytes. Example: `1073741824`. * * @deprecated This property is deprecated. */ size?: number; } export interface KafkaMirrorMakerComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface KafkaMirrorMakerKafkaMirrormakerUserConfig { /** * Additional Cloud Regions for Backup Replication. * * @deprecated This property is deprecated. */ additionalBackupRegions?: string; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.KafkaMirrorMakerKafkaMirrormakerUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Kafka MirrorMaker configuration values */ kafkaMirrormaker?: outputs.KafkaMirrorMakerKafkaMirrormakerUserConfigKafkaMirrormaker; /** * List of preferred zone IDs for service node placement. Nodes will be placed in these zones when available. If a specified zone is unavailable (e.g., due to capacity constraints), nodes will be placed in other available zones to maintain the configured number of zones for availability. Invalid zone IDs are rejected at configuration time. Zone IDs are cloud-specific: AWS uses zone IDs like `euc1-az1`, GCP uses zone names like `europe-west1-a`, and Azure uses `location/zone` format like `germanywestcentral/1`. If single*zone is enabled with an availability*zone, that setting takes precedence over preferred_zones. Changes take effect on next node recreation (e.g., maintenance or plan change). For eligible plans, nodes outside preferred zones are automatically rebalanced once per day. */ preferredZones?: string[]; /** * List of allowed URLs for SASL OAUTHBEARER authentication. Only HTTPS URLs are allowed for security reasons. */ saslOauthbearerAllowedUrls?: string[]; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface KafkaMirrorMakerKafkaMirrormakerUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface KafkaMirrorMakerKafkaMirrormakerUserConfigKafkaMirrormaker { /** * Timeout for administrative tasks, e.g. detecting new topics, loading of consumer group and offsets. Defaults to 60000 milliseconds (1 minute). */ adminTimeoutMs?: number; /** * Whether to emit consumer group offset checkpoints to target cluster periodically (default: true). */ emitCheckpointsEnabled?: boolean; /** * Frequency at which consumer group offset checkpoints are emitted (default: 60, every minute). Example: `60`. */ emitCheckpointsIntervalSeconds?: number; /** * Consumer groups to replicate. Supports comma-separated group IDs and regexes. Example: `.*`. */ groups?: string; /** * Exclude groups. Supports comma-separated group IDs and regexes. Excludes take precedence over includes. Example: `console-consumer-.*,connect-.*,__.*`. */ groupsExclude?: string; /** * How out-of-sync a remote partition can be before it is resynced. Example: `100`. */ offsetLagMax?: number; /** * Whether to periodically check for new consumer groups. Defaults to `true`. */ refreshGroupsEnabled?: boolean; /** * Frequency of consumer group refresh in seconds. Defaults to 600 seconds (10 minutes). */ refreshGroupsIntervalSeconds?: number; /** * Whether to periodically check for new topics and partitions. Defaults to `true`. */ refreshTopicsEnabled?: boolean; /** * Frequency of topic and partitions refresh in seconds. Defaults to 600 seconds (10 minutes). */ refreshTopicsIntervalSeconds?: number; /** * Whether to periodically write the translated offsets of replicated consumer groups (in the source cluster) to _*consumer*offsets topic in target cluster, as long as no active consumers in that group are connected to the target cluster. */ syncGroupOffsetsEnabled?: boolean; /** * Frequency at which consumer group offsets are synced (default: 60, every minute). Example: `60`. */ syncGroupOffsetsIntervalSeconds?: number; /** * Whether to periodically configure remote topics to match their corresponding upstream topics. */ syncTopicConfigsEnabled?: boolean; /** * `tasks.max` is set to this multiplied by the number of CPUs in the service. Default: `1`. */ tasksMaxPerCpu?: number; } export interface KafkaMirrorMakerServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface KafkaMirrorMakerTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface KafkaMirrorMakerTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface KafkaNativeAclTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface KafkaSchemaReference { /** * The name used to reference the provided subject and version. Maximum length: `1024`. */ name: string; /** * Subject. Maximum length: `1024`. */ subject: string; /** * Version. */ version: number; } export interface KafkaSchemaRegistryAclTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface KafkaServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface KafkaTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface KafkaTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface KafkaTopicConfig { /** * The retention policy to use on old segments. Possible values include 'delete', 'compact', or a comma-separated list of them. The default policy ('delete') will discard old segments when their retention time or size limit has been reached. The 'compact' setting will enable log compaction on the topic. The possible values are `compact`, `compact,delete` and `delete`. */ cleanupPolicy: string; /** * Specify the final compression type for a given topic. This configuration accepts the standard compression codecs ('gzip', 'snappy', 'lz4', 'zstd'). It additionally accepts 'uncompressed' which is equivalent to no compression; and 'producer' which means retain the original compression codec set by the producer. The possible values are `gzip`, `lz4`, `producer`, `snappy`, `uncompressed` and `zstd`. */ compressionType: string; /** * The amount of time to retain delete tombstone markers for log compacted topics. This setting also gives a bound on the time in which a consumer must complete a read if they begin from offset 0 to ensure that they get a valid snapshot of the final stage (otherwise delete tombstones may be collected before they complete their scan). */ deleteRetentionMs: string; /** * Indicates whether diskless should be enabled. This is only available for BYOC services with Diskless feature enabled. */ disklessEnable: boolean; /** * The time to wait before deleting a file from the filesystem. */ fileDeleteDelayMs: string; /** * This setting allows specifying an interval at which we will force an fsync of data written to the log. For example if this was set to 1 we would fsync after every message; if it were 5 we would fsync after every five messages. In general we recommend you not set this and use replication for durability and allow the operating system's background flush capabilities as it is more efficient. */ flushMessages: string; /** * This setting allows specifying a time interval at which we will force an fsync of data written to the log. For example if this was set to 1000 we would fsync after 1000 ms had passed. In general we recommend you not set this and use replication for durability and allow the operating system's background flush capabilities as it is more efficient. */ flushMs: string; /** * This setting controls how frequently Kafka adds an index entry to its offset index. The default setting ensures that we index a message roughly every 4096 bytes. More indexing allows reads to jump closer to the exact position in the log but makes the index larger. You probably don't need to change this. */ indexIntervalBytes: string; /** * This configuration controls the maximum bytes tiered storage will retain segment files locally before it will discard old log segments to free up space. If set to -2, the limit is equal to overall retention time. If set to -1, no limit is applied but it's possible only if overall retention is also -1. The field is required with `retentionBytes`. */ localRetentionBytes: string; /** * This configuration controls the maximum time tiered storage will retain segment files locally before it will discard old log segments to free up space. If set to -2, the time limit is equal to overall retention time. If set to -1, no time limit is applied but it's possible only if overall retention is also -1. The field is required with `retentionMs`. */ localRetentionMs: string; /** * The maximum time a message will remain ineligible for compaction in the log. Only applicable for logs that are being compacted. */ maxCompactionLagMs: string; /** * The largest record batch size allowed by Kafka (after compression if compression is enabled). If this is increased and there are consumers older than 0.10.2, the consumers' fetch size must also be increased so that the they can fetch record batches this large. In the latest message format version, records are always grouped into batches for efficiency. In previous message format versions, uncompressed records are not grouped into batches and this limit only applies to a single record in that case. */ maxMessageBytes: string; /** * This configuration controls whether down-conversion of message formats is enabled to satisfy consume requests. When set to false, broker will not perform down-conversion for consumers expecting an older message format. The broker responds with UNSUPPORTED_VERSION error for consume requests from such older clients. This configuration does not apply to any message format conversion that might be required for replication to followers. */ messageDownconversionEnable: boolean; /** * Specify the message format version the broker will use to append messages to the logs. The value should be a valid ApiVersion. Some examples are: 0.8.2, 0.9.0.0, 0.10.0, check ApiVersion for more details. By setting a particular message format version, the user is certifying that all the existing messages on disk are smaller or equal than the specified version. Setting this value incorrectly will cause consumers with older versions to break as they will receive messages with a format that they don't understand. Deprecated in Kafka 4.0+: this configuration is removed and any supplied value will be ignored; for services upgraded to 4.0+, the returned value may be 'None'. The possible values are `0.10.0`, `0.10.0-IV0`, `0.10.0-IV1`, `0.10.1`, `0.10.1-IV0`, `0.10.1-IV1`, `0.10.1-IV2`, `0.10.2`, `0.10.2-IV0`, `0.11.0`, `0.11.0-IV0`, `0.11.0-IV1`, `0.11.0-IV2`, `0.8.0`, `0.8.1`, `0.8.2`, `0.9.0`, `1.0`, `1.0-IV0`, `1.1`, `1.1-IV0`, `2.0`, `2.0-IV0`, `2.0-IV1`, `2.1`, `2.1-IV0`, `2.1-IV1`, `2.1-IV2`, `2.2`, `2.2-IV0`, `2.2-IV1`, `2.3`, `2.3-IV0`, `2.3-IV1`, `2.4`, `2.4-IV0`, `2.4-IV1`, `2.5`, `2.5-IV0`, `2.6`, `2.6-IV0`, `2.7`, `2.7-IV0`, `2.7-IV1`, `2.7-IV2`, `2.8`, `2.8-IV0`, `2.8-IV1`, `3.0`, `3.0-IV0`, `3.0-IV1`, `3.1`, `3.1-IV0`, `3.2`, `3.2-IV0`, `3.3`, `3.3-IV0`, `3.3-IV1`, `3.3-IV2`, `3.3-IV3`, `3.4`, `3.4-IV0`, `3.5`, `3.5-IV0`, `3.5-IV1`, `3.5-IV2`, `3.6`, `3.6-IV0`, `3.6-IV1`, `3.6-IV2`, `3.7`, `3.7-IV0`, `3.7-IV1`, `3.7-IV2`, `3.7-IV3`, `3.7-IV4`, `3.8`, `3.8-IV0`, `3.9`, `3.9-IV0`, `3.9-IV1`, `4.0`, `4.0-IV0`, `4.1`, `4.1-IV0`, `4.2` and `4.2-IV0`. */ messageFormatVersion: string; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps later than the broker's timestamp. */ messageTimestampAfterMaxMs: string; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. Applies only for messages with timestamps earlier than the broker's timestamp. */ messageTimestampBeforeMaxMs: string; /** * The maximum difference allowed between the timestamp when a broker receives a message and the timestamp specified in the message. If message.timestamp.type=CreateTime, a message will be rejected if the difference in timestamp exceeds this threshold. This configuration is ignored if message.timestamp.type=LogAppendTime. */ messageTimestampDifferenceMaxMs: string; /** * Define whether the timestamp in the message is message create time or log append time. The possible values are `CreateTime` and `LogAppendTime`. */ messageTimestampType: string; /** * This configuration controls how frequently the log compactor will attempt to clean the log (assuming log compaction is enabled). By default we will avoid cleaning a log where more than 50% of the log has been compacted. This ratio bounds the maximum space wasted in the log by duplicates (at 50% at most 50% of the log could be duplicates). A higher ratio will mean fewer, more efficient cleanings but will mean more wasted space in the log. If the max.compaction.lag.ms or the min.compaction.lag.ms configurations are also specified, then the log compactor considers the log to be eligible for compaction as soon as either: (i) the dirty ratio threshold has been met and the log has had dirty (uncompacted) records for at least the min.compaction.lag.ms duration, or (ii) if the log has had dirty (uncompacted) records for at most the max.compaction.lag.ms period. Maximum value: `1`. */ minCleanableDirtyRatio: number; /** * The minimum time a message will remain uncompacted in the log. Only applicable for logs that are being compacted. */ minCompactionLagMs: string; /** * When a producer sets acks to 'all' (or '-1'), this configuration specifies the minimum number of replicas that must acknowledge a write for the write to be considered successful. If this minimum cannot be met, then the producer will raise an exception (either NotEnoughReplicas or NotEnoughReplicasAfterAppend). When used together, min.insync.replicas and acks allow you to enforce greater durability guarantees. A typical scenario would be to create a topic with a replication factor of 3, set min.insync.replicas to 2, and produce with acks of 'all'. This will ensure that the producer raises an exception if a majority of replicas do not receive a write. Minimum value: `1`. */ minInsyncReplicas: string; /** * True if we should preallocate the file on disk when creating a new log segment. */ preallocate: boolean; /** * Indicates whether tiered storage should be enabled. This is only available for services with Tiered Storage feature enabled. */ remoteStorageEnable: boolean; /** * This configuration controls the maximum size a partition (which consists of log segments) can grow to before we will discard old log segments to free up space if we are using the 'delete' retention policy. By default there is no size limit only a time limit. Since this limit is enforced at the partition level, multiply it by the number of partitions to compute the topic retention in bytes. */ retentionBytes: string; /** * This configuration controls the maximum time we will retain a log before we will discard old log segments to free up space if we are using the 'delete' retention policy. This represents an SLA on how soon consumers must read their data. If set to -1, no time limit is applied. */ retentionMs: string; /** * This configuration controls the segment file size for the log. Retention and cleaning is always done a file at a time so a larger segment size means fewer files but less granular control over retention. Setting this to a very low value has consequences, and the Aiven management plane ignores values less than 10 megabytes. Minimum value: `14`. */ segmentBytes: string; /** * This configuration controls the size of the index that maps offsets to file positions. We preallocate this index file and shrink it only after log rolls. You generally should not need to change this setting. */ segmentIndexBytes: string; /** * The maximum random jitter subtracted from the scheduled segment roll time to avoid thundering herds of segment rolling. */ segmentJitterMs: string; /** * This configuration controls the period of time after which Kafka will force the log to roll even if the segment file isn't full to ensure that retention can delete or compact old data. Setting this to a very low value has consequences, and the Aiven management plane ignores values less than 10 seconds. Minimum value: `1`. */ segmentMs: string; /** * Indicates whether to enable replicas not in the ISR set to be elected as leader as a last resort, even though doing so may result in data loss. */ uncleanLeaderElectionEnable: boolean; } export interface KafkaTopicTag { /** * Tag key. Length must be between `1` and `64`. */ key: string; /** * Tag value. Maximum length: `256`. */ value?: string; } export interface KafkaTopicTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface KafkaUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface MirrorMakerReplicationFlowTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface MySqlComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface MySqlMysql { /** * MySQL connection parameters. */ params: outputs.MySqlMysqlParam[]; /** * MySQL replica URI for services with a replica. */ replicaUri: string; /** * MySQL standby connection URIs. */ standbyUris: string[]; /** * MySQL syncing connection URIs. */ syncingUris: string[]; /** * MySQL connection URIs. */ uris: string[]; } export interface MySqlMysqlParam { /** * Thr name of the primary MySQL database. */ databaseName: string; /** * MySQL host IP or name. */ host: string; /** * The password for the admin service user. */ password: string; /** * MySQL port. */ port: number; /** * MySQL SSL mode setting. Always set to "require". */ sslmode: string; /** * The username for the admin service user. */ user: string; } export interface MySqlMysqlUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Custom password for admin user. Defaults to random string. This must be set only when a new service is being created. */ adminPassword?: string; /** * Custom username for admin user. This must be set only when a new service is being created. Example: `avnadmin`. */ adminUsername?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Default: `0`. */ backupHour?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Default: `0`. */ backupMinute?: number; /** * Warning: reducing this value can make a large batch of binary logs eligible for purge at once. Depending on the volume, this can sometimes stall the MySQL commit path and block writes until the purge completes. To stay on the safe side, prefer lowering the value gradually in small decrements during a low-traffic window rather than dropping it drastically in one step. Example: `600`. */ binlogRetentionPeriod?: number; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.MySqlMysqlUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.MySqlMysqlUserConfigMigration; /** * mysql.conf configuration values */ mysql?: outputs.MySqlMysqlUserConfigMysql; /** * MySQL incremental backup configuration */ mysqlIncrementalBackup?: outputs.MySqlMysqlUserConfigMysqlIncrementalBackup; /** * Enum: `8`, `8.4`, and newer. MySQL major version. */ mysqlVersion?: string; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.MySqlMysqlUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.MySqlMysqlUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.MySqlMysqlUserConfigPublicAccess; /** * Recovery target time when forking a service. This has effect only when a new service is being created. Example: `2019-01-01 23:34:45`. */ recoveryTargetTime?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface MySqlMysqlUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface MySqlMysqlUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Enum: `mydumper`, `mysqldump`. Experimental! Tool to use for database dump and restore during migration. Default: mysqldump. */ dumpTool?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * Skip dump-restore part and start replication. Default: `false`. */ reestablishReplication?: boolean; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface MySqlMysqlUserConfigMysql { /** * When enabled, the server automatically grants the EXECUTE and ALTER ROUTINE privileges to the creator of a stored routine and drops them when the routine is dropped. */ automaticSpPrivileges?: boolean; /** * The number of seconds that the mysqld server waits for a connect packet before responding with Bad handshake. Example: `10`. */ connectTimeout?: number; /** * Default server time zone as an offset from UTC (from -12:00 to +12:00), a time zone name, or `SYSTEM` to use the MySQL server default. Example: `+03:00`. */ defaultTimeZone?: string; /** * Number of digits by which to increase the scale of the result of division operations performed with the / operator. Default is 4. Example: `6`. */ divPrecisionIncrement?: number; /** * Whether optimizer JSON output such as EXPLAIN FORMAT=JSON adds end markers that repeat a structure's key near its closing bracket, making large JSON structures easier to read. */ endMarkersInJson?: boolean; /** * The number of equality ranges in a query at or above which the optimizer switches from index dives to index statistics when estimating the number of qualifying rows. 0 means always use index dives. Default is 200. Example: `100`. */ eqRangeIndexDiveLimit?: number; /** * The maximum permitted result length in bytes for the GROUP_CONCAT() function. Example: `1024`. */ groupConcatMaxLen?: number; /** * The time, in seconds, before cached statistics expire. Example: `86400`. */ informationSchemaStatsExpiry?: number; /** * Whether InnoDB adaptive hash indexing is enabled. The optimal setting is workload-dependent: it speeds up lookups for some workloads but its internal latch can become a contention point under high concurrency, in which case disabling it can improve throughput. */ innodbAdaptiveHashIndex?: boolean; /** * Maximum size for the InnoDB change buffer, as a percentage of the total size of the buffer pool. Default is 25. Example: `30`. */ innodbChangeBufferMaxSize?: number; /** * Specifies whether flushing a page from the InnoDB buffer pool also flushes other dirty pages in the same extent (default is 1): 0 - dirty pages in the same extent are not flushed, 1 - flush contiguous dirty pages in the same extent, 2 - flush dirty pages in the same extent. Example: `0`. */ innodbFlushNeighbors?: number; /** * Whether stopword processing is applied when creating or rebuilding an InnoDB FULLTEXT index. Enabled by default. */ innodbFtEnableStopword?: boolean; /** * Maximum length of words that are stored in an InnoDB FULLTEXT index. Changing this parameter will lead to a restart of the MySQL service. Example: `60`. */ innodbFtMaxTokenSize?: number; /** * Minimum length of words that are stored in an InnoDB FULLTEXT index. Changing this parameter will lead to a restart of the MySQL service. Example: `3`. */ innodbFtMinTokenSize?: number; /** * Number of words processed during each OPTIMIZE TABLE operation on an InnoDB FULLTEXT index. Default is 2000. Example: `4000`. */ innodbFtNumWordOptimize?: number; /** * Maximum memory in bytes used per query for the InnoDB FULLTEXT search query result cache. Aiven sizes this automatically based on the service plan's memory; setting a value overrides the calculated default. */ innodbFtResultCacheLimit?: number; /** * This option is used to specify your own InnoDB FULLTEXT index stopword list for all InnoDB tables. Example: `db_name/table_name`. */ innodbFtServerStopwordTable?: string; /** * This option is used to specify your own InnoDB FULLTEXT index stopword list for specific InnoDB tables. Example: `db_name/table_name`. */ innodbFtUserStopwordTable?: string; /** * The number of I/O operations per second (IOPS) available to InnoDB background tasks, such as flushing pages from the buffer pool and merging data from the change buffer. Set this to a value appropriate for the underlying storage; it must not exceed innodb*io*capacity_max. Example: `2000`. */ innodbIoCapacity?: number; /** * The maximum number of I/O operations per second (IOPS) that InnoDB background tasks may perform when flushing falls behind. Defaults to twice innodb*io*capacity (minimum 2000). This must be greater than or equal to innodb*io*capacity. */ innodbIoCapacityMax?: number; /** * The length of time in seconds an InnoDB transaction waits for a row lock before giving up. Default is 120. Example: `50`. */ innodbLockWaitTimeout?: number; /** * The size in bytes of the buffer that InnoDB uses to write to the log files on disk. */ innodbLogBufferSize?: number; /** * The upper limit in bytes on the size of the temporary log files used during online DDL operations for InnoDB tables. */ innodbOnlineAlterLogMaxSize?: number; /** * When enabled, OPTIMIZE TABLE on InnoDB tables only updates the FULLTEXT index instead of rebuilding the table. Intended to be enabled temporarily during FULLTEXT index maintenance and disabled afterwards; while enabled, OPTIMIZE TABLE does not reclaim table space. */ innodbOptimizeFulltextOnly?: boolean; /** * When enabled, information about all deadlocks in InnoDB user transactions is recorded in the error log. Disabled by default. */ innodbPrintAllDeadlocks?: boolean; /** * The number of I/O threads for read operations in InnoDB. Default is 4. Changing this parameter will lead to a restart of the MySQL service. Example: `10`. */ innodbReadIoThreads?: number; /** * When enabled a transaction timeout causes InnoDB to abort and roll back the entire transaction. Changing this parameter will lead to a restart of the MySQL service. */ innodbRollbackOnTimeout?: boolean; /** * Defines the maximum number of threads permitted inside of InnoDB. Default is 0 (infinite concurrency - no limit). Example: `10`. */ innodbThreadConcurrency?: number; /** * The number of I/O threads for write operations in InnoDB. Default is 4. Changing this parameter will lead to a restart of the MySQL service. Example: `10`. */ innodbWriteIoThreads?: number; /** * The number of seconds the server waits for activity on an interactive connection before closing it. Example: `3600`. */ interactiveTimeout?: number; /** * Enum: `MEMORY`, `TempTable`. The storage engine for in-memory internal temporary tables. */ internalTmpMemStorageEngine?: string; /** * Enum: `INSIGHTS`, `INSIGHTS,TABLE`, `NONE`, `TABLE`. The slow log output destination when slow*query*log is ON. To enable MySQL AI Insights, choose INSIGHTS. To use MySQL AI Insights and the mysql.slow*log table at the same time, choose INSIGHTS,TABLE. To only use the mysql.slow*log table, choose TABLE. To silence slow logs, choose NONE. */ logOutput?: string; /** * The slow*query*logs work as SQL statements that take more than long*query*time seconds to execute. Example: `10`. */ longQueryTime?: number; /** * Enum: `0`, `1`. Sets how table and database names are stored and compared. 0 = case-sensitive (default), 1 = names stored lowercase, comparisons are case-insensitive. This option can only be set when creating the service and cannot be changed later. See https://dev.mysql.com/doc/refman/8.0/en/identifier-case-sensitivity.html for details. */ lowerCaseTableNames?: number; /** * Size of the largest message in bytes that can be received by the server. Default is 67108864 (64M). */ maxAllowedPacket?: number; /** * The maximum permitted number of simultaneous client connections. Lower this to reserve memory for other work. The value cannot exceed the limit provided by your service plan. Upgrading the plan does not raise a value you have set explicitly, so increase it yourself after an upgrade. Example: `200`. */ maxConnections?: number; /** * Execution timeout in milliseconds for read-only top-level SELECT statements. 0 (the default) means no timeout. Example: `15000`. */ maxExecutionTime?: number; /** * Limits the size of internal in-memory tables. Also set tmp*table*size. Default is 16777216 (16M). */ maxHeapTableSize?: number; /** * Limit on the assumed maximum number of index seeks when looking up rows based on a key. Lowering this value causes the optimizer to prefer index lookups over table scans. Example: `100`. */ maxSeeksForKey?: number; /** * The maximum number of simultaneous connections permitted to any single user account. 0, the default, means no per-account limit. Any other value must be at least 10 below max_connections, so that monitoring and your own admin sessions can still connect when an application saturates its own limit. Aiven's replication and management connections are unaffected however low you set this. Example: `50`. */ maxUserConnections?: number; /** * Start sizes of connection buffer and result buffer. Default is 16384 (16K). Changing this parameter will lead to a restart of the MySQL service. Example: `16384`. */ netBufferLength?: number; /** * The number of seconds to wait for more data from a connection before aborting the read. Example: `30`. */ netReadTimeout?: number; /** * The number of seconds to wait for a block to be written to a connection before aborting the write. Example: `30`. */ netWriteTimeout?: number; /** * Controls the heuristics applied during query optimization to prune less-promising partial plans from the optimizer search space. 0 disables heuristics (exhaustive search); 1 prunes plans based on the number of rows retrieved. Example: `1`. */ optimizerPruneLevel?: number; /** * Maximum depth of search performed by the query optimizer when choosing a join order. Larger values produce better plans for joins over many tables but take longer to compile; 0 lets the optimizer choose the depth automatically. Example: `62`. */ optimizerSearchDepth?: number; /** * Comma-separated list of optimizer flag assignments in the form flag=on|off|default, or the single value `default` to reset all flags. Flags not listed keep their current values. Controls query optimizer behaviors such as index merge, hash join and semijoin strategies. Example: `batched_key_access=on,mrr_cost_based=off`. */ optimizerSwitch?: string; /** * The number of rows per thread in the events*statements*history table. Changing this parameter will lead to a restart of the MySQL service. */ performanceSchemaEventsStatementsHistorySize?: number; /** * The maximum amount of space in bytes to use for all relay logs while replicating from an external migration source. When the limit is reached, the replication I/O thread stops fetching relay log events until the SQL thread has caught up. Raise this to give a large migration a bigger relay-log budget; ensure the service disk is sized accordingly. The setting applies only on the node replicating from the external source; standby nodes always use the Aiven-managed default (the smaller of 5 GiB and 30% of the service disk), which is also used when this option is left unset. Changing this parameter will lead to a restart of the MySQL service. */ relayLogSpaceLimit?: number; /** * Slow query log enables capturing of slow queries. Setting slow*query*log to false also truncates the mysql.slow_log table. */ slowQueryLog?: boolean; /** * Sort buffer size in bytes for ORDER BY optimization. Default is 262144 (256K). Example: `262144`. */ sortBufferSize?: number; /** * Global SQL mode. Set to empty to use MySQL server defaults. When creating a new service and not setting this field Aiven default SQL mode (strict, SQL standard compliant) will be assigned. Example: `ANSI,TRADITIONAL`. */ sqlMode?: string; /** * Require primary key to be defined for new tables or old tables modified with ALTER TABLE and fail if missing. It is recommended to always have primary keys because various functionality may break if any large table is missing them. */ sqlRequirePrimaryKey?: boolean; /** * Limits the size of internal in-memory tables. Also set max*heap*table_size. Default is 16777216 (16M). */ tmpTableSize?: number; /** * The number of seconds the server waits for activity on a noninteractive connection before closing it. Example: `28800`. */ waitTimeout?: number; /** * Whether window functions are computed to high precision. Disabling this trades exactness for speed in window function evaluation. */ windowingUseHighPrecision?: boolean; } export interface MySqlMysqlUserConfigMysqlIncrementalBackup { /** * Enable periodic incremental backups. When enabled, full*backup*week_schedule must be set. Incremental backups only store changes since the last backup, making them faster and more storage-efficient than full backups. This is particularly useful for large databases where daily full backups would be too time-consuming or expensive. */ enabled: boolean; /** * Comma-separated list of days of the week when full backups should be created. Valid values: mon, tue, wed, thu, fri, sat, sun. Example: `sun,wed`. */ fullBackupWeekSchedule?: string; } export interface MySqlMysqlUserConfigPrivateAccess { /** * Allow clients to connect to mysql with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ mysql?: boolean; /** * Allow clients to connect to mysqlx with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ mysqlx?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface MySqlMysqlUserConfigPrivatelinkAccess { /** * Enable mysql. */ mysql?: boolean; /** * Enable mysqlx. */ mysqlx?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface MySqlMysqlUserConfigPublicAccess { /** * Allow clients to connect to mysql from the public internet for service nodes that are in a project VPC or another type of private network. */ mysql?: boolean; /** * Allow clients to connect to mysqlx from the public internet for service nodes that are in a project VPC or another type of private network. */ mysqlx?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface MySqlServiceIntegration { /** * Type of the service integration. The possible value is `readReplica`. */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface MySqlTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface MySqlTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface MysqlDatabaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface MysqlUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OpenSearchComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface OpenSearchOpensearch { /** * URI for Kibana dashboard frontend. * * @deprecated This field was added by mistake and has never worked. It will be removed in future versions. */ kibanaUri: string; /** * URI for OpenSearch dashboard frontend. */ opensearchDashboardsUri: string; /** * OpenSearch password. */ password: string; /** * OpenSearch server URIs. */ uris: string[]; /** * OpenSearch username. */ username: string; } export interface OpenSearchOpensearchUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Azure migration settings */ azureMigration?: outputs.OpenSearchOpensearchUserConfigAzureMigration; /** * Serve the web frontend using a custom CNAME pointing to the Aiven DNS name. When you set a custom domain for a service deployed in a VPC, the service certificate is only created for the public-* hostname and the custom domain. Example: `grafana.example.org`. */ customDomain?: string; /** * Disable automatic replication factor adjustment for multi-node services. By default, Aiven ensures all indexes are replicated at least to two nodes. Note: Due to potential data loss in case of losing a service node, this setting can not be activated unless specifically allowed for the project. */ disableReplicationFactorAdjustment?: boolean; /** * Google Cloud Storage migration settings */ gcsMigration?: outputs.OpenSearchOpensearchUserConfigGcsMigration; /** * Index patterns */ indexPatterns?: outputs.OpenSearchOpensearchUserConfigIndexPattern[]; /** * Index rollup settings */ indexRollup?: outputs.OpenSearchOpensearchUserConfigIndexRollup; /** * Template settings for all new indexes */ indexTemplate?: outputs.OpenSearchOpensearchUserConfigIndexTemplate; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.OpenSearchOpensearchUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * OpenSearch JWT Configuration */ jwt?: outputs.OpenSearchOpensearchUserConfigJwt; /** * Aiven automation resets index.refresh_interval to default value for every index to be sure that indices are always visible to search. If it doesn't fit your case, you can disable this by setting up this flag to true. */ keepIndexRefreshInterval?: boolean; /** * Use indexPatterns instead. Default: `0`. */ maxIndexCount?: number; /** * OpenSearch OpenID Connect Configuration */ openid?: outputs.OpenSearchOpensearchUserConfigOpenid; /** * OpenSearch settings */ opensearch?: outputs.OpenSearchOpensearchUserConfigOpensearch; /** * OpenSearch Dashboards settings */ opensearchDashboards?: outputs.OpenSearchOpensearchUserConfigOpensearchDashboards; /** * Enum: `1`, `2`, `2.19`, `3.3`, `3.6`, and newer. OpenSearch version. */ opensearchVersion?: string; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.OpenSearchOpensearchUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.OpenSearchOpensearchUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.OpenSearchOpensearchUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * AWS S3 / AWS S3 compatible migration settings */ s3Migration?: outputs.OpenSearchOpensearchUserConfigS3Migration; /** * OpenSearch SAML configuration */ saml?: outputs.OpenSearchOpensearchUserConfigSaml; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; } export interface OpenSearchOpensearchUserConfigAzureMigration { /** * Account name. */ account: string; /** * The path to the repository data within its container. The value of this setting should not start or end with a /. */ basePath: string; /** * Big files can be broken down into chunks during snapshotting if needed. Should be the same as for the 3rd party repository. */ chunkSize?: string; /** * When set to true metadata files are stored in compressed format. */ compress?: boolean; /** * Azure container name. */ container: string; /** * Defines the DNS suffix for Azure Storage endpoints. */ endpointSuffix?: string; /** * Whether to restore aliases alongside their associated indexes. Default is true. */ includeAliases?: boolean; /** * A comma-delimited list of indices to restore from the snapshot. Multi-index syntax is supported. Example: `metrics*,logs*,data-20240823`. */ indices: string; /** * Azure account secret key. One of key or sasToken should be specified. */ key?: string; /** * Throttles the restore rate per node. Defaults to unlimited. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxRestoreBytesPerSec?: string; /** * Throttles the snapshot rate per node. Defaults to 40mb. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxSnapshotBytesPerSec?: string; /** * Whether the repository is read-only. Default: `true`. */ readonly?: boolean; /** * If true, restore the cluster state. Defaults to false. */ restoreGlobalState?: boolean; /** * A shared access signatures (SAS) token. One of key or sasToken should be specified. */ sasToken?: string; /** * The snapshot name to restore from. */ snapshotName: string; } export interface OpenSearchOpensearchUserConfigGcsMigration { /** * The path to the repository data within its container. The value of this setting should not start or end with a /. */ basePath: string; /** * The path to the repository data within its container. */ bucket: string; /** * Big files can be broken down into chunks during snapshotting if needed. Should be the same as for the 3rd party repository. */ chunkSize?: string; /** * When set to true metadata files are stored in compressed format. */ compress?: boolean; /** * Google Cloud Storage credentials file content. */ credentials: string; /** * Whether to restore aliases alongside their associated indexes. Default is true. */ includeAliases?: boolean; /** * A comma-delimited list of indices to restore from the snapshot. Multi-index syntax is supported. Example: `metrics*,logs*,data-20240823`. */ indices: string; /** * Throttles the restore rate per node. Defaults to unlimited. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxRestoreBytesPerSec?: string; /** * Throttles the snapshot rate per node. Defaults to 40mb. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxSnapshotBytesPerSec?: string; /** * Whether the repository is read-only. Default: `true`. */ readonly?: boolean; /** * If true, restore the cluster state. Defaults to false. */ restoreGlobalState?: boolean; /** * The snapshot name to restore from. */ snapshotName: string; } export interface OpenSearchOpensearchUserConfigIndexPattern { /** * Maximum number of indexes to keep. Example: `3`. */ maxIndexCount: number; /** * fnmatch pattern. Example: `logs_*_foo_*`. */ pattern: string; /** * Enum: `alphabetical`, `creationDate`. Deletion sorting algorithm. Default: `creationDate`. */ sortingAlgorithm?: string; } export interface OpenSearchOpensearchUserConfigIndexRollup { /** * Whether rollups are enabled in OpenSearch Dashboards. Defaults to true. */ rollupDashboardsEnabled?: boolean; /** * Whether the rollup plugin is enabled. Defaults to true. */ rollupEnabled?: boolean; /** * How many retries the plugin should attempt for failed rollup jobs. Defaults to 5. */ rollupSearchBackoffCount?: number; /** * The backoff time between retries for failed rollup jobs. Defaults to 1000ms. */ rollupSearchBackoffMillis?: number; /** * Whether OpenSearch should return all jobs that match all specified search terms. If disabled, OpenSearch returns just one, as opposed to all, of the jobs that matches the search terms. Defaults to false. */ rollupSearchSearchAllJobs?: boolean; } export interface OpenSearchOpensearchUserConfigIndexTemplate { /** * The maximum number of nested JSON objects that a single document can contain across all nested types. This limit helps to prevent out of memory errors when a document contains too many nested objects. Default is 10000. Deprecated, use an index template instead. Example: `10000`. */ mappingNestedObjectsLimit?: number; /** * The number of replicas each primary shard has. Deprecated, use an index template instead. Example: `1`. */ numberOfReplicas?: number; /** * The number of primary shards that an index should have. Deprecated, use an index template instead. Example: `1`. */ numberOfShards?: number; } export interface OpenSearchOpensearchUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface OpenSearchOpensearchUserConfigJwt { /** * Enables or disables JWT-based authentication for OpenSearch. When enabled, users can authenticate using JWT tokens. Default: `false`. */ enabled: boolean; /** * The maximum allowed time difference in seconds between the JWT issuer's clock and the OpenSearch server's clock. This helps prevent token validation failures due to minor time synchronization issues. Default: `20`. */ jwtClockSkewToleranceSeconds?: number; /** * The HTTP header name where the JWT token is transmitted. Typically `Authorization` for Bearer tokens. Default: `Authorization`. */ jwtHeader?: string; /** * If the JWT token is transmitted as a URL parameter instead of an HTTP header, specify the parameter name here. Example: `token`. */ jwtUrlParameter?: string; /** * If specified, the JWT must contain an `aud` claim that matches this value. This provides additional security by ensuring the JWT was issued for the expected audience. Example: `https://myapp.example.com`. */ requiredAudience?: string; /** * If specified, the JWT must contain an `iss` claim that matches this value. This provides additional security by ensuring the JWT was issued by the expected issuer. Example: `https://auth.example.com`. */ requiredIssuer?: string; /** * The key in the JWT payload that contains the user's roles. If specified, roles will be extracted from the JWT for authorization. Example: `roles`. */ rolesKey?: string; /** * The secret key used to sign and verify JWT tokens. This should be a secure, randomly generated key HMAC key or public RSA/ECDSA key. Example: `MrJiimVjKgjRKCSk0s6rcEuCz17v5ZyFRqKARfZbuZE= (HMAC) or -----BEGIN PUBLIC KEY----- * MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA... * -----END PUBLIC KEY----- (PEM)`. */ signingKey: string; /** * The key in the JWT payload that contains the user's subject identifier. If not specified, the `sub` claim is used by default. Example: `sub`. */ subjectKey?: string; } export interface OpenSearchOpensearchUserConfigOpenid { /** * The ID of the OpenID Connect client configured in your IdP. Required. */ clientId: string; /** * The client secret of the OpenID Connect client configured in your IdP. Required. */ clientSecret: string; /** * The URL of your IdP where the Security plugin can find the OpenID Connect metadata/configuration settings. Example: `https://test-account.okta.com/app/exk491jujcVc83LEX697/sso/saml/metadata`. */ connectUrl: string; /** * Enables or disables OpenID Connect authentication for OpenSearch. When enabled, users can authenticate using OpenID Connect with an Identity Provider. Default: `true`. */ enabled: boolean; /** * HTTP header name of the JWT token. Optional. Default is Authorization. Default: `Authorization`. */ header?: string; /** * The HTTP header that stores the token. Typically the Authorization header with the Bearer schema: Authorization: Bearer \n\n. Optional. Default is Authorization. Example: `preferredUsername`. */ jwtHeader?: string; /** * If the token is not transmitted in the HTTP header, but as an URL parameter, define the name of the parameter here. Optional. Example: `preferredUsername`. */ jwtUrlParameter?: string; /** * The maximum number of unknown key IDs in the time frame. Default is 10. Optional. Default: `10`. */ refreshRateLimitCount?: number; /** * The time frame to use when checking the maximum number of unknown key IDs, in milliseconds. Optional.Default is 10000 (10 seconds). Default: `10000`. */ refreshRateLimitTimeWindowMs?: number; /** * The key in the JSON payload that stores the user’s roles. The value of this key must be a comma-separated list of roles. Required only if you want to use roles in the JWT. Example: `roles`. */ rolesKey?: string; /** * The scope of the identity token issued by the IdP. Optional. Default is openid profile email address phone. */ scope?: string; /** * The key in the JSON payload that stores the user’s name. If not defined, the subject registered claim is used. Most IdP providers use the preferredUsername claim. Optional. Example: `preferredUsername`. */ subjectKey?: string; } export interface OpenSearchOpensearchUserConfigOpensearch { /** * Explicitly allow or block automatic creation of indices. Defaults to true. */ actionAutoCreateIndexEnabled?: boolean; /** * Require explicit index names when deleting. */ actionDestructiveRequiresName?: boolean; /** * Opensearch Security Plugin Settings */ authFailureListeners?: outputs.OpenSearchOpensearchUserConfigOpensearchAuthFailureListeners; /** * Defines a limit of how much total remote data can be referenced as a ratio of the size of the disk reserved for the file cache. This is designed to be a safeguard to prevent oversubscribing a cluster. Defaults to 0. */ clusterFilecacheRemoteDataRatio?: number; /** * Controls the number of shards allowed in the cluster per data node. Example: `1000`. */ clusterMaxShardsPerNode?: number; clusterRemoteStore?: outputs.OpenSearchOpensearchUserConfigOpensearchClusterRemoteStore; /** * When set to true, OpenSearch attempts to evenly distribute the primary shards between the cluster nodes. Enabling this setting does not always guarantee an equal number of primary shards on each node, especially in the event of a failover. Changing this setting to false after it was set to true does not invoke redistribution of primary shards. Default is false. */ clusterRoutingAllocationBalancePreferPrimary?: boolean; /** * How many concurrent incoming/outgoing shard recoveries (normally replicas) are allowed to happen on a node. Defaults to node cpu count * 2. */ clusterRoutingAllocationNodeConcurrentRecoveries?: number; clusterSearchRequestSlowlog?: outputs.OpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlog; /** * Watermark settings */ diskWatermarks?: outputs.OpenSearchOpensearchUserConfigOpensearchDiskWatermarks; /** * Sender name placeholder to be used in Opensearch Dashboards and Opensearch keystore. Example: `alert-sender`. */ emailSenderName?: string; /** * Sender password for Opensearch alerts to authenticate with SMTP server. Example: `very-secure-mail-password`. */ emailSenderPassword?: string; /** * Sender username for Opensearch alerts. Example: `jane@example.com`. */ emailSenderUsername?: string; /** * Enable remote-backed storage. */ enableRemoteBackedStorage?: boolean; /** * Enable searchable snapshots. */ enableSearchableSnapshots?: boolean; /** * Enable/Disable security audit. */ enableSecurityAudit?: boolean; /** * Enable/Disable snapshot API for custom repositories, this requires security management to be enabled. */ enableSnapshotApi?: boolean; /** * Maximum content length for HTTP requests to the OpenSearch HTTP API, in bytes. */ httpMaxContentLength?: number; /** * The max size of allowed headers, in bytes. Example: `8192`. */ httpMaxHeaderSize?: number; /** * The max length of an HTTP URL, in bytes. Example: `4096`. */ httpMaxInitialLineLength?: number; /** * Relative amount. Maximum amount of heap memory used for field data cache. This is an expert setting; decreasing the value too much will increase overhead of loading field data; too much memory used for field data cache will decrease amount of heap available for other operations. */ indicesFielddataCacheSize?: number; /** * Percentage value. Default is 10%. Total amount of heap used for indexing buffer, before writing segments to disk. This is an expert setting. Too low value will slow down indexing; too high value will increase indexing performance but causes performance issues for query performance. */ indicesMemoryIndexBufferSize?: number; /** * Absolute value. Default is unbound. Doesn't work without indices.memory.index*buffer*size. Maximum amount of heap used for query cache, an absolute indices.memory.index*buffer*size maximum hard limit. */ indicesMemoryMaxIndexBufferSize?: number; /** * Absolute value. Default is 48mb. Doesn't work without indices.memory.index*buffer*size. Minimum amount of heap used for query cache, an absolute indices.memory.index*buffer*size minimal hard limit. */ indicesMemoryMinIndexBufferSize?: number; /** * Percentage value. Default is 10%. Maximum amount of heap used for query cache. This is an expert setting. Too low value will decrease query performance and increase performance for other operations; too high value will cause issues with other OpenSearch functionality. */ indicesQueriesCacheSize?: number; /** * Maximum number of clauses Lucene BooleanQuery can have. The default value (1024) is relatively high, and increasing it may cause performance issues. Investigate other approaches first before increasing this value. */ indicesQueryBoolMaxClauseCount?: number; /** * Limits total inbound and outbound recovery traffic for each node. Applies to both peer recoveries as well as snapshot recoveries (i.e., restores from a snapshot). Defaults to 40mb. */ indicesRecoveryMaxBytesPerSec?: number; /** * Number of file chunks sent in parallel for each recovery. Defaults to 2. */ indicesRecoveryMaxConcurrentFileChunks?: number; /** * Specifies whether ISM is enabled or not. */ ismEnabled?: boolean; /** * Specifies whether audit history is enabled or not. The logs from ISM are automatically indexed to a logs document. */ ismHistoryEnabled?: boolean; /** * The maximum age before rolling over the audit history index in hours. Example: `24`. */ ismHistoryMaxAge?: number; /** * The maximum number of documents before rolling over the audit history index. */ ismHistoryMaxDocs?: number; /** * The time between rollover checks for the audit history index in hours. Example: `8`. */ ismHistoryRolloverCheckPeriod?: number; /** * How long audit history indices are kept in days. Example: `30`. */ ismHistoryRolloverRetentionPeriod?: number; /** * Enable or disable KNN memory circuit breaker. Defaults to true. */ knnMemoryCircuitBreakerEnabled?: boolean; /** * Maximum amount of memory in percentage that can be used for the KNN index. Defaults to 50% of the JVM heap size. 0 is used to set it to null which can be used to invalidate caches. */ knnMemoryCircuitBreakerLimit?: number; /** * When set to true, the setting allows admins to control access and permissions to the connector API using backend_roles. Defaults to false. */ mlCommonsConnectorAccessControlEnabled?: boolean; /** * Enable or disable model access control for ML Commons. When enabled, access to ML models is controlled by security permissions. Defaults to false. */ mlCommonsModelAccessControlEnabled?: boolean; /** * Native memory threshold percentage for ML Commons. Controls the maximum percentage of native memory that can be used by ML Commons operations. Defaults to 90%. */ mlCommonsNativeMemoryThreshold?: number; /** * Enable or disable running ML Commons tasks only on ML nodes. When enabled, ML tasks will only execute on nodes designated as ML nodes. Defaults to true. */ mlCommonsOnlyRunOnMlNode?: boolean; /** * Adds the trusted endpoints to the cluster settings. Supports Java regex expressions. */ mlCommonsTrustedConnectorEndpointsRegexes?: string[]; /** * Defines a limit of how much total remote data can be referenced as a ratio of the size of the disk reserved for the file cache. This is designed to be a safeguard to prevent oversubscribing a cluster. Defaults to 5gb. Requires restarting all OpenSearch nodes. */ nodeSearchCacheSize?: string; /** * Compatibility mode sets OpenSearch to report its version as 7.10 so clients continue to work. Default is false. Deprecated and ignored for service version 3.3 and higher. */ overrideMainResponseVersion?: boolean; /** * Enable or disable filtering of alerting by backend roles. Requires Security plugin. Defaults to false. */ pluginsAlertingFilterByBackendRoles?: boolean; /** * Whitelisted addresses for reindexing. Changing this value will cause all OpenSearch instances to restart. */ reindexRemoteWhitelists?: string[]; remoteStore?: outputs.OpenSearchOpensearchUserConfigOpensearchRemoteStore; /** * Script compilation circuit breaker limits the number of inline script compilations within a period of time. Default is use-context. Example: `75/5m`. */ scriptMaxCompilationsRate?: string; /** * Search Backpressure Settings */ searchBackpressure?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchBackpressure; searchInsightsTopQueries?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueries; /** * Maximum number of aggregation buckets allowed in a single response. OpenSearch default value is used when this is not defined. Example: `10000`. */ searchMaxBuckets?: number; /** * Segment Replication Backpressure Settings */ segrep?: outputs.OpenSearchOpensearchUserConfigOpensearchSegrep; /** * Shard indexing back pressure settings */ shardIndexingPressure?: outputs.OpenSearchOpensearchUserConfigOpensearchShardIndexingPressure; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolAnalyzeQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolAnalyzeSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolForceMergeSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolGetQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolGetSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolSearchQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolSearchSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolSearchThrottledQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolSearchThrottledSize?: number; /** * Size for the thread pool queue. See documentation for exact details. */ threadPoolWriteQueueSize?: number; /** * Size for the thread pool. See documentation for exact details. Do note this may have maximum value depending on CPU count - value is automatically lowered if set to higher than maximum value. */ threadPoolWriteSize?: number; } export interface OpenSearchOpensearchUserConfigOpensearchAuthFailureListeners { internalAuthenticationBackendLimiting?: outputs.OpenSearchOpensearchUserConfigOpensearchAuthFailureListenersInternalAuthenticationBackendLimiting; /** * IP address rate limiting settings * * @deprecated This property is deprecated. */ ipRateLimiting?: outputs.OpenSearchOpensearchUserConfigOpensearchAuthFailureListenersIpRateLimiting; } export interface OpenSearchOpensearchUserConfigOpensearchAuthFailureListenersInternalAuthenticationBackendLimiting { /** * The number of login attempts allowed before login is blocked. Example: `10`. */ allowedTries?: number; /** * Enum: `internal`. internal*authentication*backend*limiting.authentication*backend. */ authenticationBackend?: string; /** * The duration of time that login remains blocked after a failed login. Example: `600`. */ blockExpirySeconds?: number; /** * internal*authentication*backend*limiting.max*blocked_clients. Example: `100000`. */ maxBlockedClients?: number; /** * The maximum number of tracked IP addresses that have failed login. Example: `100000`. */ maxTrackedClients?: number; /** * The window of time in which the value for `allowedTries` is enforced. Example: `3600`. */ timeWindowSeconds?: number; /** * Enum: `username`. internal*authentication*backend_limiting.type. */ type?: string; } export interface OpenSearchOpensearchUserConfigOpensearchAuthFailureListenersIpRateLimiting { /** * The number of login attempts allowed before login is blocked. Example: `10`. */ allowedTries?: number; /** * The duration of time that login remains blocked after a failed login. Example: `600`. */ blockExpirySeconds?: number; /** * The maximum number of blocked IP addresses. Example: `100000`. */ maxBlockedClients?: number; /** * The maximum number of tracked IP addresses that have failed login. Example: `100000`. */ maxTrackedClients?: number; /** * The window of time in which the value for `allowedTries` is enforced. Example: `3600`. */ timeWindowSeconds?: number; /** * Enum: `ip`. The type of rate limiting. */ type?: string; } export interface OpenSearchOpensearchUserConfigOpensearchClusterRemoteStore { /** * The amount of time to wait for the cluster state upload to complete. Defaults to 20s. */ stateGlobalMetadataUploadTimeout?: string; /** * The amount of time to wait for the manifest file upload to complete. The manifest file contains the details of each of the files uploaded for a single cluster state, both index metadata files and global metadata files. Defaults to 20s. */ stateMetadataManifestUploadTimeout?: string; /** * The default value of the translog buffer interval used when performing periodic translog updates. This setting is only effective when the index setting `index.remote_store.translog.buffer_interval` is not present. Defaults to 650ms. */ translogBufferInterval?: string; /** * Sets the maximum number of open translog files for remote-backed indexes. This limits the total number of translog files per shard. After reaching this limit, the remote store flushes the translog files. Default is 1000. The minimum required is 100. Example: `1000`. */ translogMaxReaders?: number; } export interface OpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlog { /** * Enum: `debug`, `info`, `trace`, `warn`. Log level. Default: `trace`. */ level?: string; threshold?: outputs.OpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlogThreshold; } export interface OpenSearchOpensearchUserConfigOpensearchClusterSearchRequestSlowlogThreshold { /** * Debug threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ debug?: string; /** * Info threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ info?: string; /** * Trace threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ trace?: string; /** * Warning threshold for total request took time. The value should be in the form count and unit, where unit one of (s,m,h,d,nanos,ms,micros) or -1. Default is -1. */ warn?: string; } export interface OpenSearchOpensearchUserConfigOpensearchDashboards { /** * Enable or disable OpenSearch Dashboards. Default: `true`. */ enabled?: boolean; /** * Limits the maximum amount of memory (in MiB) the OpenSearch Dashboards process can use. This sets the max*old*space_size option of the nodejs running the OpenSearch Dashboards. Note: the memory reserved by OpenSearch Dashboards is not available for OpenSearch. Default: `128`. */ maxOldSpaceSize?: number; /** * Enable or disable multiple data sources in OpenSearch Dashboards. Default: `true`. */ multipleDataSourceEnabled?: boolean; /** * Timeout in milliseconds for requests made by OpenSearch Dashboards towards OpenSearch. Default: `30000`. */ opensearchRequestTimeout?: number; /** * Determines whether the session TTL resets (is “kept alive”) on each user activity. Optional. Default is true. Default: `true`. */ sessionKeepalive?: boolean; /** * Defines the time-to-live (TTL) for user sessions. The value should be a time value with unit, e.g. 1m, 5s, 1h, 3d, 100ms. Default is 1 hour. Default: `1h`. */ sessionTtl?: string; } export interface OpenSearchOpensearchUserConfigOpensearchDiskWatermarks { /** * The flood stage watermark for disk usage. Example: `95`. */ floodStage: number; /** * The high watermark for disk usage. Example: `90`. */ high: number; /** * The low watermark for disk usage. Example: `85`. */ low: number; } export interface OpenSearchOpensearchUserConfigOpensearchRemoteStore { /** * The variance factor that is used together with the moving average to calculate the dynamic bytes lag threshold for activating remote segment backpressure. Defaults to 10. */ segmentPressureBytesLagVarianceFactor?: number; /** * The minimum consecutive failure count for activating remote segment backpressure. Defaults to 5. */ segmentPressureConsecutiveFailuresLimit?: number; /** * Enables remote segment backpressure. Default is `true`. */ segmentPressureEnabled?: boolean; /** * The variance factor that is used together with the moving average to calculate the dynamic time lag threshold for activating remote segment backpressure. Defaults to 10. */ segmentPressureTimeLagVarianceFactor?: number; } export interface OpenSearchOpensearchUserConfigOpensearchSearchBackpressure { /** * Enum: `disabled`, `enforced`, `monitorOnly`. The search backpressure mode. Valid values are monitor*only, enforced, or disabled. Default is monitor*only. */ mode?: string; /** * Node duress settings */ nodeDuress?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchBackpressureNodeDuress; /** * Search shard settings */ searchShardTask?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchShardTask; /** * Search task settings */ searchTask?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchTask; } export interface OpenSearchOpensearchUserConfigOpensearchSearchBackpressureNodeDuress { /** * The CPU usage threshold (as a percentage) required for a node to be considered to be under duress. Default is 0.9. */ cpuThreshold?: number; /** * The heap usage threshold (as a percentage) required for a node to be considered to be under duress. Default is 0.7. */ heapThreshold?: number; /** * The number of successive limit breaches after which the node is considered to be under duress. Default is 3. */ numSuccessiveBreaches?: number; } export interface OpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchShardTask { /** * The maximum number of search tasks to cancel in a single iteration of the observer thread. Default is 10.0. */ cancellationBurst?: number; /** * The maximum number of tasks to cancel per millisecond of elapsed time. Default is 0.003. */ cancellationRate?: number; /** * The maximum number of tasks to cancel, as a percentage of successful task completions. Default is 0.1. */ cancellationRatio?: number; /** * The CPU usage threshold (in milliseconds) required for a single search shard task before it is considered for cancellation. Default is 15000. */ cpuTimeMillisThreshold?: number; /** * The elapsed time threshold (in milliseconds) required for a single search shard task before it is considered for cancellation. Default is 30000. */ elapsedTimeMillisThreshold?: number; /** * The number of previously completed search shard tasks to consider when calculating the rolling average of heap usage. Default is 100. */ heapMovingAverageWindowSize?: number; /** * The heap usage threshold (as a percentage) required for a single search shard task before it is considered for cancellation. Default is 0.5. */ heapPercentThreshold?: number; /** * The minimum variance required for a single search shard task’s heap usage compared to the rolling average of previously completed tasks before it is considered for cancellation. Default is 2.0. */ heapVariance?: number; /** * The heap usage threshold (as a percentage) required for the sum of heap usages of all search shard tasks before cancellation is applied. Default is 0.5. */ totalHeapPercentThreshold?: number; } export interface OpenSearchOpensearchUserConfigOpensearchSearchBackpressureSearchTask { /** * The maximum number of search tasks to cancel in a single iteration of the observer thread. Default is 5.0. */ cancellationBurst?: number; /** * The maximum number of search tasks to cancel per millisecond of elapsed time. Default is 0.003. */ cancellationRate?: number; /** * The maximum number of search tasks to cancel, as a percentage of successful search task completions. Default is 0.1. */ cancellationRatio?: number; /** * The CPU usage threshold (in milliseconds) required for an individual parent task before it is considered for cancellation. Default is 30000. */ cpuTimeMillisThreshold?: number; /** * The elapsed time threshold (in milliseconds) required for an individual parent task before it is considered for cancellation. Default is 45000. */ elapsedTimeMillisThreshold?: number; /** * The window size used to calculate the rolling average of the heap usage for the completed parent tasks. Default is 10. */ heapMovingAverageWindowSize?: number; /** * The heap usage threshold (as a percentage) required for an individual parent task before it is considered for cancellation. Default is 0.2. */ heapPercentThreshold?: number; /** * The heap usage variance required for an individual parent task before it is considered for cancellation. A task is considered for cancellation when taskHeapUsage is greater than or equal to heapUsageMovingAverage * variance. Default is 2.0. */ heapVariance?: number; /** * The heap usage threshold (as a percentage) required for the sum of heap usages of all search tasks before cancellation is applied. Default is 0.5. */ totalHeapPercentThreshold?: number; } export interface OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueries { /** * Top N queries monitoring by CPU */ cpu?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesCpu; /** * Top N queries monitoring by latency */ latency?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesLatency; /** * Top N queries monitoring by memory */ memory?: outputs.OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesMemory; } export interface OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesCpu { /** * Enable or disable top N query monitoring by the metric. Default: `false`. */ enabled?: boolean; /** * Specify the value of N for the top N queries by the metric. */ topNSize?: number; /** * Configure the window size of the top N queries. The value should be a time value with unit, e.g. 1m, 5s, 1h. */ windowSize?: string; } export interface OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesLatency { /** * Enable or disable top N query monitoring by the metric. Default: `false`. */ enabled?: boolean; /** * Specify the value of N for the top N queries by the metric. */ topNSize?: number; /** * Configure the window size of the top N queries. The value should be a time value with unit, e.g. 1m, 5s, 1h. */ windowSize?: string; } export interface OpenSearchOpensearchUserConfigOpensearchSearchInsightsTopQueriesMemory { /** * Enable or disable top N query monitoring by the metric. Default: `false`. */ enabled?: boolean; /** * Specify the value of N for the top N queries by the metric. */ topNSize?: number; /** * Configure the window size of the top N queries. The value should be a time value with unit, e.g. 1m, 5s, 1h. */ windowSize?: string; } export interface OpenSearchOpensearchUserConfigOpensearchSegrep { /** * The maximum number of indexing checkpoints that a replica shard can fall behind when copying from primary. Once `segrep.pressure.checkpoint.limit` is breached along with `segrep.pressure.time.limit`, the segment replication backpressure mechanism is initiated. Default is 4 checkpoints. Default: `4`. */ pressureCheckpointLimit?: number; /** * Enables the segment replication backpressure mechanism. Default is false. Default: `false`. */ pressureEnabled?: boolean; /** * The maximum number of stale replica shards that can exist in a replication group. Once `segrep.pressure.replica.stale.limit` is breached, the segment replication backpressure mechanism is initiated. Default is .5, which is 50% of a replication group. Default: `0.5`. */ pressureReplicaStaleLimit?: number; /** * The maximum amount of time that a replica shard can take to copy from the primary shard. Once segrep.pressure.time.limit is breached along with segrep.pressure.checkpoint.limit, the segment replication backpressure mechanism is initiated. Default is 5 minutes. Default: `5m`. */ pressureTimeLimit?: string; } export interface OpenSearchOpensearchUserConfigOpensearchShardIndexingPressure { /** * Enable or disable shard indexing backpressure. Default is false. */ enabled?: boolean; /** * Run shard indexing backpressure in shadow mode or enforced mode. In shadow mode (value set as false), shard indexing backpressure tracks all granular-level metrics, but it doesn’t actually reject any indexing requests. In enforced mode (value set as true), shard indexing backpressure rejects any requests to the cluster that might cause a dip in its performance. Default is false. */ enforced?: boolean; /** * Operating factor */ operatingFactor?: outputs.OpenSearchOpensearchUserConfigOpensearchShardIndexingPressureOperatingFactor; /** * Primary parameter */ primaryParameter?: outputs.OpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameter; } export interface OpenSearchOpensearchUserConfigOpensearchShardIndexingPressureOperatingFactor { /** * Specify the lower occupancy limit of the allocated quota of memory for the shard. If the total memory usage of a shard is below this limit, shard indexing backpressure decreases the current allocated memory for that shard. Default is 0.75. */ lower?: number; /** * Specify the optimal occupancy of the allocated quota of memory for the shard. If the total memory usage of a shard is at this level, shard indexing backpressure doesn’t change the current allocated memory for that shard. Default is 0.85. */ optimal?: number; /** * Specify the upper occupancy limit of the allocated quota of memory for the shard. If the total memory usage of a shard is above this limit, shard indexing backpressure increases the current allocated memory for that shard. Default is 0.95. */ upper?: number; } export interface OpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameter { node?: outputs.OpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterNode; shard?: outputs.OpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterShard; } export interface OpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterNode { /** * Define the percentage of the node-level memory threshold that acts as a soft indicator for strain on a node. Default is 0.7. */ softLimit?: number; } export interface OpenSearchOpensearchUserConfigOpensearchShardIndexingPressurePrimaryParameterShard { /** * Specify the minimum assigned quota for a new shard in any role (coordinator, primary, or replica). Shard indexing backpressure increases or decreases this allocated quota based on the inflow of traffic for the shard. Default is 0.001. */ minLimit?: number; } export interface OpenSearchOpensearchUserConfigPrivateAccess { /** * Allow clients to connect to opensearch with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ opensearch?: boolean; /** * Allow clients to connect to opensearchDashboards with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ opensearchDashboards?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface OpenSearchOpensearchUserConfigPrivatelinkAccess { /** * Enable opensearch. */ opensearch?: boolean; /** * Enable opensearch_dashboards. */ opensearchDashboards?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface OpenSearchOpensearchUserConfigPublicAccess { /** * Allow clients to connect to opensearch from the public internet for service nodes that are in a project VPC or another type of private network. */ opensearch?: boolean; /** * Allow clients to connect to opensearchDashboards from the public internet for service nodes that are in a project VPC or another type of private network. */ opensearchDashboards?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface OpenSearchOpensearchUserConfigS3Migration { /** * AWS Access key. */ accessKey: string; /** * The path to the repository data within its container. The value of this setting should not start or end with a /. */ basePath: string; /** * S3 bucket name. */ bucket: string; /** * Big files can be broken down into chunks during snapshotting if needed. Should be the same as for the 3rd party repository. */ chunkSize?: string; /** * When set to true metadata files are stored in compressed format. */ compress?: boolean; /** * The S3 service endpoint to connect to. If you are using an S3-compatible service then you should set this to the service’s endpoint. */ endpoint?: string; /** * Whether to restore aliases alongside their associated indexes. Default is true. */ includeAliases?: boolean; /** * A comma-delimited list of indices to restore from the snapshot. Multi-index syntax is supported. Example: `metrics*,logs*,data-20240823`. */ indices: string; /** * Throttles the restore rate per node. Defaults to unlimited. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxRestoreBytesPerSec?: string; /** * Throttles the snapshot rate per node. Defaults to 40mb. Note that if the recovery settings for managed services are set, this value is overridden by the recovery settings. Value should be a byte size with unit, e.g. 40mb, 100kb, 1gb. */ maxSnapshotBytesPerSec?: string; /** * Whether the repository is read-only. Default: `true`. */ readonly?: boolean; /** * S3 region. */ region: string; /** * If true, restore the cluster state. Defaults to false. */ restoreGlobalState?: boolean; /** * AWS secret key. */ secretKey: string; /** * When set to true files are encrypted on server side. */ serverSideEncryption?: boolean; /** * The snapshot name to restore from. */ snapshotName: string; } export interface OpenSearchOpensearchUserConfigSaml { /** * Enables or disables SAML-based authentication for OpenSearch. When enabled, users can authenticate using SAML with an Identity Provider. Default: `true`. */ enabled: boolean; /** * The unique identifier for the Identity Provider (IdP) entity that is used for SAML authentication. This value is typically provided by the IdP. Example: `test-idp-entity-id`. */ idpEntityId: string; /** * The URL of the SAML metadata for the Identity Provider (IdP). This is used to configure SAML-based authentication with the IdP. Example: `https://test-account.okta.com/app/exk491jujcVc83LEX697/sso/saml/metadata`. */ idpMetadataUrl: string; /** * This parameter specifies the PEM-encoded root certificate authority (CA) content for the SAML identity provider (IdP) server verification. The root CA content is used to verify the SSL/TLS certificate presented by the server. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ idpPemtrustedcasContent?: string; /** * Optional. Specifies the attribute in the SAML response where role information is stored, if available. Role attributes are not required for SAML authentication, but can be included in SAML assertions by most Identity Providers (IdPs) to determine user access levels or permissions. Example: `RoleName`. */ rolesKey?: string; /** * The unique identifier for the Service Provider (SP) entity that is used for SAML authentication. This value is typically provided by the SP. Example: `test-sp-entity-id`. */ spEntityId: string; /** * Optional. Specifies the attribute in the SAML response where the subject identifier is stored. If not configured, the NameID attribute is used by default. Example: `NameID`. */ subjectKey?: string; } export interface OpenSearchServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface OpenSearchTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface OpenSearchTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface OpensearchSecurityPluginConfigTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OpensearchUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationAddressTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationApplicationUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationApplicationUserTokenTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationBillingGroupBillingContactEmail { /** * Email. Maximum length: `254`. */ email: string; } export interface OrganizationBillingGroupBillingEmail { /** * Email. Maximum length: `254`. */ email: string; } export interface OrganizationBillingGroupPaymentMethod { /** * Payment method ID. Maximum length: `36`. */ paymentMethodId: string; /** * An enumeration. The possible values are `awsSubscription`, `azureSubscription`, `bankTransfer`, `creditCard`, `custom` and `gcpSubscription`. */ paymentMethodType: string; } export interface OrganizationBillingGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationGroupProjectTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationPermissionPermission { /** * Create Time. */ createTime: string; /** * List of [roles and permissions](https://aiven.io/docs/platform/concepts/permissions) to grant". The possible values are `admin`, `developer`, `operator`, `organization:app_users:write`, `organization:billing:read`, `organization:billing:write`, `organization:domains:write`, `organization:event_logs:read`, `organization:groups:write`, `organization:networking:read`, `organization:networking:write`, `organization:projects:write`, `organization:sustainability:read`, `organization:users:write`, `project:ai_gateway_keys:read`, `project:ai_gateway_keys:write`, `project:audit_logs:read`, `project:event_logs:read`, `project:integrations:read`, `project:integrations:write`, `project:networking:read`, `project:networking:write`, `project:permissions:read`, `project:services:read`, `project:services:write`, `readOnly`, `role:organization:admin`, `role:project:admin`, `role:project:read`, `role:services:maintenance`, `role:services:recover`, `service:configuration:write`, `service:data:write`, `service:logs:read`, `service:metrics:read`, `service:secrets:read` and `service:users:write`. */ permissions: string[]; /** * ID of the user or group to grant permissions to. Only active users who have accepted an [invite](https://aiven.io/docs/platform/howto/manage-org-users) to join the organization can be granted permissions. */ principalId: string; /** * An enumeration. The possible values are `user` and `userGroup`. */ principalType: string; /** * Update Time. */ updateTime: string; } export interface OrganizationPermissionTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationProjectTag { /** * Project tag key. */ key: string; /** * Project tag value. */ value: string; } export interface OrganizationProjectTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationUserGroupMemberTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationUserGroupTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationVpcTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface OrganizationalUnitTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface PgComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface PgDatabaseTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface PgPg { /** * PgBouncer connection details for [connection pooling](https://aiven.io/docs/products/postgresql/concepts/pg-connection-pooling). * * @deprecated This field was added by mistake and has never worked. It will be removed in future versions. */ bouncer: string; /** * Primary PostgreSQL database name. */ dbname: string; /** * PostgreSQL primary node host IP or name. */ host: string; /** * The [number of allowed connections](https://aiven.io/docs/products/postgresql/reference/pg-connection-limits). Varies based on the service plan. */ maxConnections: number; /** * PostgreSQL connection parameters. */ params: outputs.PgPgParam[]; /** * PostgreSQL admin user password. */ password: string; /** * PostgreSQL port. */ port: number; /** * PostgreSQL replica URI for services with a replica. */ replicaUri: string; /** * PostgreSQL SSL mode setting. */ sslmode: string; /** * PostgreSQL standby connection URIs. */ standbyUris: string[]; /** * PostgreSQL syncing connection URIs. */ syncingUris: string[]; /** * PostgreSQL primary connection URI. */ uri: string; /** * PostgreSQL primary connection URIs. */ uris: string[]; /** * PostgreSQL admin user name. */ user: string; } export interface PgPgParam { /** * Primary PostgreSQL database name. */ databaseName: string; /** * PostgreSQL host IP or name. */ host: string; /** * PostgreSQL admin user password. */ password: string; /** * PostgreSQL port. */ port: number; /** * PostgreSQL SSL mode setting. */ sslmode: string; /** * PostgreSQL admin user name. */ user: string; } export interface PgPgUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * Custom password for admin user. Defaults to random string. This must be set only when a new service is being created. */ adminPassword?: string; /** * Custom username for admin user. This must be set only when a new service is being created. Example: `avnadmin`. */ adminUsername?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Example: `3`. */ backupHour?: number; /** * Enum: `12`, `24`, `3`, `4`, `6`, `8`. Interval in hours between automatic backups. Minimum value is 3 hours. Must be a divisor of 24 (3, 4, 6, 8, 12, 24). (Applicable to ACU plans only). */ backupIntervalHours?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Example: `30`. */ backupMinute?: number; /** * Number of days to retain automatic backups. Backups older than this value will be automatically deleted. (Applicable to ACU plans only). Example: `7`. */ backupRetentionDays?: number; /** * Creates a dedicated read-only DNS that automatically falls back to the primary if standby nodes are unavailable. It switches back when a standby recovers. Default: `false`. */ enableHaReplicaDns?: boolean; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.PgPgUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.PgPgUserConfigMigration; /** * Number of nodes for the service. Example: `3`. */ nodeCount?: number; /** * postgresql.conf configuration values */ pg?: outputs.PgPgUserConfigPg; /** * System-wide settings for the pg*qualstats extension * * @deprecated This property is deprecated. */ pgQualstats?: outputs.PgPgUserConfigPgQualstats; /** * Should the service which is being forked be a read replica (deprecated, use readReplica service integration instead). */ pgReadReplica?: boolean; /** * Name of the PG Service from which to fork (deprecated, use service*to*fork_from). This has effect only when a new service is being created. Example: `anotherservicename`. */ pgServiceToForkFrom?: string; /** * Enable the pg*stat*monitor extension. Changing this parameter causes a service restart. When this extension is enabled, pg*stat*statements results for utility commands are unreliable. Default: `false`. */ pgStatMonitorEnable?: boolean; /** * Enable the pg*stat*plans extension. Changing this parameter causes a service restart. Tracks execution plans for SQL queries. Default: `false`. */ pgStatPlansEnable?: boolean; /** * Enum: `10`, `11`, `12`, `13`, `14`, `15`, `16`, `17`, `18`, and newer. PostgreSQL major version. */ pgVersion?: string; /** * System-wide settings for the pgaudit extension */ pgaudit?: outputs.PgPgUserConfigPgaudit; /** * PGBouncer connection pooling settings */ pgbouncer?: outputs.PgPgUserConfigPgbouncer; /** * System-wide settings for pglookout */ pglookout?: outputs.PgPgUserConfigPglookout; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.PgPgUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.PgPgUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.PgPgUserConfigPublicAccess; /** * Recovery target time when forking a service. This has effect only when a new service is being created. Example: `2019-01-01 23:34:45`. */ recoveryTargetTime?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Percentage of total RAM that the database server uses for shared memory buffers. Valid range is 20-60 (float), which corresponds to 20% - 60%. This setting adjusts the sharedBuffers configuration value. Changing this parameter causes a service restart. Example: `41.5`. */ sharedBuffersPercentage?: number; /** * Use static public IP addresses. */ staticIps?: boolean; switchoverWindows?: outputs.PgPgUserConfigSwitchoverWindow[]; /** * Enum: `off`, `quorum`. Use synchronous*commit instead. Any change to this setting will automatically update synchronous*commit. Setting the value to quorum changes synchronous*commit to remote*write, while setting it to off changes synchronousCommit to off. */ synchronousReplication?: string; /** * System-wide settings for the timescaledb extension */ timescaledb?: outputs.PgPgUserConfigTimescaledb; /** * Enum: `aiven`, `timescale`. Variant of the PostgreSQL service, may affect the features that are exposed by default. */ variant?: string; /** * Sets the maximum amount of memory to be used by a query operation (such as a sort or hash table) before writing to temporary disk files, in MB. The default is 1MB + 0.075% of total RAM (up to 32MB). Example: `4`. */ workMem?: number; } export interface PgPgUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface PgPgUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface PgPgUserConfigPg { /** * Specifies a fraction of the table size to add to autovacuum*analyze*threshold when deciding whether to trigger an ANALYZE (e.g. `0.2` for 20% of the table size). The default is `0.2`. */ autovacuumAnalyzeScaleFactor?: number; /** * Specifies the minimum number of inserted, updated or deleted tuples needed to trigger an ANALYZE in any one table. The default is `50`. */ autovacuumAnalyzeThreshold?: number; /** * Specifies the maximum age (in transactions) that a table's pg_class.relfrozenxid field can attain before a VACUUM operation is forced to prevent transaction ID wraparound within the table. The system launches autovacuum processes to prevent wraparound even when autovacuum is otherwise disabled. Changing this parameter causes a service restart. */ autovacuumFreezeMaxAge?: number; /** * Specifies the maximum number of autovacuum processes (other than the autovacuum launcher) that may be running at any one time. The default is `3`. Changing this parameter causes a service restart. */ autovacuumMaxWorkers?: number; /** * Specifies the minimum delay between autovacuum runs on any given database. The delay is measured in seconds. The default is `60`. */ autovacuumNaptime?: number; /** * Specifies the cost delay value that will be used in automatic VACUUM operations. If `-1` is specified, the regular vacuum*cost*delay value will be used. The default is `2` (upstream default). */ autovacuumVacuumCostDelay?: number; /** * Specifies the cost limit value that will be used in automatic VACUUM operations. If `-1` is specified, the regular vacuum*cost*limit value will be used. The default is `-1` (upstream default). */ autovacuumVacuumCostLimit?: number; /** * Specifies a fraction of the table size to add to autovacuum*vacuum*threshold when deciding whether to trigger a VACUUM (e.g. `0.2` for 20% of the table size). The default is `0.2`. */ autovacuumVacuumScaleFactor?: number; /** * Specifies the minimum number of updated or deleted tuples needed to trigger a VACUUM in any one table. The default is `50`. */ autovacuumVacuumThreshold?: number; /** * Specifies the delay between activity rounds for the background writer in milliseconds. The default is `200`. Example: `200`. */ bgwriterDelay?: number; /** * Whenever more than bgwriter*flush*after bytes have been written by the background writer, attempt to force the OS to issue these writes to the underlying storage. Specified in kilobytes. Setting of 0 disables forced writeback. The default is `512`. Example: `512`. */ bgwriterFlushAfter?: number; /** * In each round, no more than this many buffers will be written by the background writer. Setting this to zero disables background writing. The default is `100`. Example: `100`. */ bgwriterLruMaxpages?: number; /** * The average recent need for new buffers is multiplied by bgwriter*lru*multiplier to arrive at an estimate of the number that will be needed during the next round, (up to bgwriter*lru*maxpages). 1.0 represents a “just in time” policy of writing exactly the number of buffers predicted to be needed. Larger values provide some cushion against spikes in demand, while smaller values intentionally leave writes to be done by server processes. The default is `2.0`. Example: `2`. */ bgwriterLruMultiplier?: number; /** * This is the amount of time, in milliseconds, to wait on a lock before checking to see if there is a deadlock condition. The default is `1000` (upstream default). Example: `1000`. */ deadlockTimeout?: number; /** * Enum: `lz4`, `pglz`. Specifies the default TOAST compression method for values of compressible columns. The default is `lz4`. Only available for PostgreSQL 14+. */ defaultToastCompression?: string; /** * Time out sessions with open transactions after this number of milliseconds. */ idleInTransactionSessionTimeout?: number; /** * EXPERIMENTAL: Controls the largest I/O size in operations that combine I/O in 8kB units. Version 17 and up only. Default: `16`. */ ioCombineLimit?: number; /** * EXPERIMENTAL: Controls the largest I/O size in operations that combine I/O in 8kB units, and silently limits the user-settable parameter io*combine*limit. Version 18 and up only. Changing this parameter causes a service restart. Default: `16`. */ ioMaxCombineLimit?: number; /** * EXPERIMENTAL: Controls the maximum number of I/O operations that one process can execute simultaneously. Version 18 and up only. Changing this parameter causes a service restart. Default: `-1`. */ ioMaxConcurrency?: number; /** * Enum: `ioUring`, `sync`, `worker`. EXPERIMENTAL: Controls the maximum number of I/O operations that one process can execute simultaneously. Version 18 and up only. Changing this parameter causes a service restart. Default: `worker`. */ ioMethod?: string; /** * EXPERIMENTAL: Number of IO worker processes, for io_method=worker. Version 18 and up only. */ ioWorkers?: number; /** * Controls system-wide use of Just-in-Time Compilation (JIT). */ jit?: boolean; /** * Causes each action executed by autovacuum to be logged if it ran for at least the specified number of milliseconds. Setting this to zero logs all autovacuum actions. Minus-one disables logging autovacuum actions. The default is `1000`. */ logAutovacuumMinDuration?: number; /** * Enum: `DEFAULT`, `TERSE`, `VERBOSE`. Controls the amount of detail written in the server log for each message that is logged. */ logErrorVerbosity?: string; /** * Enum: `'%m [%p] %q[user=%u,db=%d,app=%a] '`, `'%t [%p]: [%l-1] user=%u,db=%d,app=%a,client=%h '`, `'pid=%p,user=%u,db=%d,app=%a,client=%h '`, `'pid=%p,user=%u,db=%d,app=%a,client=%h,txid=%x,qid=%Q '`. Choose from one of the available log formats. */ logLinePrefix?: string; /** * Log statements that take more than this number of milliseconds to run, -1 disables. */ logMinDurationStatement?: number; /** * Log statements for each temporary file created larger than this number of kilobytes, -1 disables. */ logTempFiles?: number; /** * Sets the PostgreSQL maximum number of concurrent connections to the database server. For services with a read replica, first increase the read replica's value. After the change is applied to the replica, you can increase the primary service's value. Changing this parameter causes a service restart. */ maxConnections?: number; /** * PostgreSQL maximum number of files that can be open per process. The default is `1000` (upstream default). Changing this parameter causes a service restart. */ maxFilesPerProcess?: number; /** * PostgreSQL maximum locks per transaction. Changing this parameter causes a service restart. */ maxLocksPerTransaction?: number; /** * PostgreSQL maximum logical replication workers (taken from the pool defined by max*worker*processes). The default is `4` (upstream default). Changing this parameter causes a service restart. */ maxLogicalReplicationWorkers?: number; /** * Sets the maximum number of workers that the system can support for parallel queries. The default is `8` (upstream default). */ maxParallelWorkers?: number; /** * Sets the maximum number of workers that can be started by a single Gather or Gather Merge node. The default is `2` (upstream default). */ maxParallelWorkersPerGather?: number; /** * PostgreSQL maximum predicate locks per transaction. The default is `64` (upstream default). Changing this parameter causes a service restart. */ maxPredLocksPerTransaction?: number; /** * PostgreSQL maximum prepared transactions. The default is `0`. Changing this parameter causes a service restart. */ maxPreparedTransactions?: number; /** * PostgreSQL maximum replication slots. The default is `20`. Changing this parameter causes a service restart. */ maxReplicationSlots?: number; /** * PostgreSQL maximum WAL size (MB) reserved for replication slots. If `-1` is specified, replication slots may retain an unlimited amount of WAL files. The default is `-1` (upstream default). wal*keep*size minimum WAL size setting takes precedence over this. */ maxSlotWalKeepSize?: number; /** * Maximum depth of the stack in bytes. The default is `2097152` (upstream default). */ maxStackDepth?: number; /** * Max standby archive delay in milliseconds. The default is `30000` (upstream default). */ maxStandbyArchiveDelay?: number; /** * Max standby streaming delay in milliseconds. The default is `30000` (upstream default). */ maxStandbyStreamingDelay?: number; /** * Maximum number of synchronization workers per subscription. The default is `2`. */ maxSyncWorkersPerSubscription?: number; /** * PostgreSQL maximum WAL senders. The default is `20`. Changing this parameter causes a service restart. */ maxWalSenders?: number; /** * Sets the maximum number of background processes that the system can support. The default is `8`. Changing this parameter causes a service restart. */ maxWorkerProcesses?: number; /** * Enum: `md5`, `scram-sha-256`. Chooses the algorithm for encrypting passwords. */ passwordEncryption?: string; /** * Sets the time interval in seconds to run pg_partman's scheduled tasks. The default is `3600`. Example: `3600`. */ pgPartmanBgwDotInterval?: number; /** * Controls which role to use for pg_partman's scheduled background tasks. Example: `myrolename`. */ pgPartmanBgwDotRole?: string; /** * Enables or disables query plan monitoring. Only available for PostgreSQL 13+. */ pgStatMonitorDotPgsmEnableQueryPlan?: boolean; /** * Sets the maximum number of buckets. Changing this parameter causes a service restart. Only available for PostgreSQL 13+. Example: `10`. */ pgStatMonitorDotPgsmMaxBuckets?: number; /** * Enum: `all`, `none`, `top`. Controls which statements' plans are tracked. Specify top to track top-level statements (those issued directly by clients), all to also track nested statements (such as statements invoked within functions), or none to disable plan tracking. The default is `top`. */ pgStatPlansDotTrack?: string; /** * Enum: `all`, `none`, `top`. Controls which statements are counted. Specify top to track top-level statements (those issued directly by clients), all to also track nested statements (such as statements invoked within functions), or none to disable statement statistics collection. The default is `top`. */ pgStatStatementsDotTrack?: string; /** * Enum: `local`, `off`, `on`, `remoteApply`, `remoteWrite`. Sets the current transaction's synchronization level. The default is `off`. This setting takes precedence over `synchronousReplication`. */ synchronousCommit?: string; /** * PostgreSQL temporary file limit in KiB, -1 for unlimited. */ tempFileLimit?: number; /** * PostgreSQL service timezone. Example: `Europe/Helsinki`. */ timezone?: string; /** * Specifies the number of bytes reserved to track the currently executing command for each active session. Changing this parameter causes a service restart. Example: `1024`. */ trackActivityQuerySize?: number; /** * Enum: `off`, `on`. Record commit time of transactions. Changing this parameter causes a service restart. */ trackCommitTimestamp?: string; /** * Enum: `all`, `none`, `pl`. Enables tracking of function call counts and time used. */ trackFunctions?: string; /** * Enum: `off`, `on`. Enables timing of database I/O calls. The default is `off`. When on, it will repeatedly query the operating system for the current time, which may cause significant overhead on some platforms. */ trackIoTiming?: string; /** * Terminate replication connections that are inactive for longer than this amount of time, in milliseconds. Setting this value to zero disables the timeout. Example: `60000`. */ walSenderTimeout?: number; /** * WAL flush interval in milliseconds. The default is `200`. Setting this parameter to a lower value may negatively impact performance. Example: `50`. */ walWriterDelay?: number; } export interface PgPgUserConfigPgQualstats { /** * Enable / Disable pg_qualstats. Default: `false`. * * @deprecated This property is deprecated. */ enabled?: boolean; /** * Error estimation num threshold to save quals. Default: `0`. * * @deprecated This property is deprecated. */ minErrEstimateNum?: number; /** * Error estimation ratio threshold to save quals. Default: `0`. * * @deprecated This property is deprecated. */ minErrEstimateRatio?: number; /** * Enable / Disable pgQualstats constants tracking. Default: `true`. * * @deprecated This property is deprecated. */ trackConstants?: boolean; /** * Track quals on system catalogs too. Default: `false`. * * @deprecated This property is deprecated. */ trackPgCatalog?: boolean; } export interface PgPgUserConfigPgaudit { /** * Enable pgaudit extension. When enabled, pgaudit extension will be automatically installed.Otherwise, extension will be uninstalled but auditing configurations will be preserved. Default: `false`. */ featureEnabled?: boolean; /** * Specifies that session logging should be enabled in the case where all relations in a statement are in pg_catalog. Default: `true`. */ logCatalog?: boolean; /** * Specifies whether log messages will be visible to a client process such as psql. Default: `false`. */ logClient?: boolean; /** * Enum: `debug1`, `debug2`, `debug3`, `debug4`, `debug5`, `info`, `log`, `notice`, `warning`. Specifies the log level that will be used for log entries. Default: `log`. */ logLevel?: string; /** * Crop parameters representation and whole statements if they exceed this threshold. A (default) value of -1 disable the truncation. Default: `-1`. */ logMaxStringLength?: number; /** * This GUC allows to turn off logging nested statements, that is, statements that are executed as part of another ExecutorRun. Default: `true`. */ logNestedStatements?: boolean; /** * Specifies that audit logging should include the parameters that were passed with the statement. Default: `false`. */ logParameter?: boolean; /** * Specifies that parameter values longer than this setting (in bytes) should not be logged, but replaced with \n\n. Default: `0`. */ logParameterMaxSize?: number; /** * Specifies whether session audit logging should create a separate log entry for each relation (TABLE, VIEW, etc.) referenced in a SELECT or DML statement. Default: `false`. */ logRelation?: boolean; /** * Log Rows. Default: `false`. */ logRows?: boolean; /** * Specifies whether logging will include the statement text and parameters (if enabled). Default: `true`. */ logStatement?: boolean; /** * Specifies whether logging will include the statement text and parameters with the first log entry for a statement/substatement combination or with every entry. Default: `false`. */ logStatementOnce?: boolean; /** * Specifies which classes of statements will be logged by session audit logging. */ logs?: string[]; /** * Specifies the master role to use for object audit logging. */ role?: string; } export interface PgPgUserConfigPgbouncer { /** * If the automatically created database pools have been unused this many seconds, they are freed. If 0 then timeout is disabled. (seconds). Default: `3600`. */ autodbIdleTimeout?: number; /** * Do not allow more than this many server connections per database (regardless of user). Setting it to 0 means unlimited. Example: `0`. */ autodbMaxDbConnections?: number; /** * Enum: `session`, `statement`, `transaction`. PGBouncer pool mode. Default: `transaction`. */ autodbPoolMode?: string; /** * If non-zero then create automatically a pool of that size per user when a pool doesn't exist. Default: `0`. */ autodbPoolSize?: number; /** * List of parameters to ignore when given in startup packet. */ ignoreStartupParameters?: string[]; /** * PgBouncer tracks protocol-level named prepared statements related commands sent by the client in transaction and statement pooling modes when max*prepared*statements is set to a non-zero value. Setting it to 0 disables prepared statements. max*prepared*statements defaults to 100, and its maximum is 3000. Default: `100`. */ maxPreparedStatements?: number; /** * Add more server connections to pool if below this number. Improves behavior when usual load comes suddenly back after period of total inactivity. The value is effectively capped at the pool size. Default: `0`. */ minPoolSize?: number; /** * If connection and login don’t finish in this amount of time, the connection will be closed. (seconds). */ serverConnectTimeout?: number; /** * If a server connection has been idle more than this many seconds it will be dropped. If 0 then timeout is disabled. (seconds). Default: `600`. */ serverIdleTimeout?: number; /** * The pooler will close an unused server connection that has been connected longer than this. (seconds). Default: `3600`. */ serverLifetime?: number; /** * If login to the server failed, because of failure to connect or from authentication, the pooler waits this much before retrying to connect. During the waiting interval, new clients trying to connect to the failing server will get an error immediately without another connection attempt. (seconds). */ serverLoginRetry?: number; /** * Run server*reset*query (DISCARD ALL) in all pooling modes. Default: `false`. */ serverResetQueryAlways?: boolean; } export interface PgPgUserConfigPglookout { /** * Number of seconds of master unavailability before triggering database failover to standby. Default: `60`. */ maxFailoverReplicationTimeLag?: number; } export interface PgPgUserConfigPrivateAccess { /** * Allow clients to connect to pg with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ pg?: boolean; /** * Allow clients to connect to pgbouncer with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ pgbouncer?: boolean; /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; } export interface PgPgUserConfigPrivatelinkAccess { /** * Enable pg. */ pg?: boolean; /** * Enable pgbouncer. */ pgbouncer?: boolean; /** * Enable prometheus. */ prometheus?: boolean; } export interface PgPgUserConfigPublicAccess { /** * Allow clients to connect to pg from the public internet for service nodes that are in a project VPC or another type of private network. */ pg?: boolean; /** * Allow clients to connect to pgbouncer from the public internet for service nodes that are in a project VPC or another type of private network. */ pgbouncer?: boolean; /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; } export interface PgPgUserConfigSwitchoverWindow { /** * Enum: `friday`, `monday`, `saturday`, `sunday`, `thursday`, `tuesday`, `wednesday`. */ dow: string; /** * Example: `12:30:00`. */ endTime: string; /** * Example: `12:30:00`. */ startTime: string; } export interface PgPgUserConfigTimescaledb { /** * The number of background workers for timescaledb operations. You should configure this setting to the sum of your number of databases and the total number of concurrent background workers you want running at any given point in time. Changing this parameter causes a service restart. Default: `16`. */ maxBackgroundWorkers?: number; } export interface PgServiceIntegration { /** * Type of the service integration. The possible values are `readReplica` and `disasterRecovery`. */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface PgTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface PgTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface PgUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ProjectTag { /** * Project tag key. */ key: string; /** * Project tag value. */ value: string; } export interface ProjectVpcTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ServiceIntegrationClickhouseCredentialsUserConfig { /** * Grants to assign */ grants?: outputs.ServiceIntegrationClickhouseCredentialsUserConfigGrant[]; } export interface ServiceIntegrationClickhouseCredentialsUserConfigGrant { /** * User or role to assign the grant to. Example: `alice`. */ user: string; } export interface ServiceIntegrationClickhouseKafkaUserConfig { /** * Array of table configurations that define how Kafka topics are mapped to ClickHouse tables. Each table configuration specifies the table structure, associated Kafka topics, and read/write settings */ tables?: outputs.ServiceIntegrationClickhouseKafkaUserConfigTable[]; } export interface ServiceIntegrationClickhouseKafkaUserConfigTable { /** * Enum: `beginning`, `earliest`, `end`, `largest`, `latest`, `smallest`. Determines where to start reading from Kafka when no offset is stored or the stored offset is out of range. `earliest` starts from the beginning, `latest` starts from the end. Default: `earliest`. */ autoOffsetReset?: string; /** * When set to a non-zero value and there are no committed offsets, the consumer starts from the offset corresponding to (now - auto*offset*reset*by*duration*ms). This overrides auto*offset_reset when set. Requires ClickHouse >= 25.8. Default: `0`. */ autoOffsetResetByDurationMs?: number; /** * Array of column definitions that specify the structure of the ClickHouse table. Each column maps to a field in the Kafka messages */ columns: outputs.ServiceIntegrationClickhouseKafkaUserConfigTableColumn[]; /** * Enum: `Avro`, `AvroConfluent`, `CSV`, `JSONAsString`, `JSONCompactEachRow`, `JSONCompactStringsEachRow`, `JSONEachRow`, `JSONStringsEachRow`, `MsgPack`, `Parquet`, `RawBLOB`, `TSKV`, `TSV`, `TabSeparated`. The format of the messages in the Kafka topics. Determines how ClickHouse parses and serializes the data (e.g., JSON, CSV, Avro). Default: `JSONEachRow`. */ dataFormat: string; /** * Enum: `basic`, `bestEffort`, `bestEffortUs`. Specifies how ClickHouse should parse DateTime values from text-based input formats. `basic` uses simple parsing, `bestEffort` attempts more flexible parsing. Default: `basic`. */ dateTimeInputFormat?: string; /** * The Kafka consumer group name. Multiple consumers with the same group name will share the workload and maintain offset positions. Default: `clickhouse`. */ groupName: string; /** * Enum: `deadLetterQueue`, `default`, `stream`. Defines how ClickHouse should handle errors when processing Kafka messages. `default` stops on errors, `stream` continues processing and logs errors, `deadLetterQueue` saves error data to system.dead*letter*queue (requires ClickHouse 25.8+). Default: `default`. */ handleErrorMode?: string; /** * Optional materialized view that persists data from the Kafka engine table into a MergeTree-family table. When specified, a ClickHouse materialized view is created that automatically reads from the Kafka table and inserts into a durable target table */ materializedView?: outputs.ServiceIntegrationClickhouseKafkaUserConfigTableMaterializedView; /** * Maximum number of rows to collect before flushing data between Kafka and ClickHouse. Default: `0`. */ maxBlockSize?: number; /** * Maximum number of rows that can be processed from a single Kafka message for row-based formats. Useful for controlling memory usage. Default: `1`. */ maxRowsPerMessage?: number; /** * The name of the ClickHouse table to be created. This table can consume data from and write data to the specified Kafka topics. Example: `events`. */ name: string; /** * Number of Kafka consumers to run per table per replica. Increasing this can improve throughput but may increase resource usage. Default: `1`. */ numConsumers?: number; /** * Maximum number of messages to fetch in a single Kafka poll operation for reading. Default: `0`. */ pollMaxBatchSize?: number; /** * Timeout in milliseconds for a single poll from Kafka. Takes the value of the stream*flush*interval_ms server setting by default (500ms). Default: `0`. */ pollMaxTimeoutMs?: number; /** * The maximum number of messages in a batch sent to Kafka. If the number of messages exceeds this value, the batch is sent. Default: `10000`. */ producerBatchNumMessages?: number; /** * The maximum size in bytes of a batch of messages sent to Kafka. If the batch size is exceeded, the batch is sent. */ producerBatchSize?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. The compression codec to use when sending a batch of messages to Kafka. Default: `none`. */ producerCompressionCodec?: string; /** * The compression level to use when sending a batch of messages to Kafka. Usable range is algorithm-dependent: [0-9] for gzip; [0-12] for lz4; only 0 for snappy; -1 = codec-dependent default compression level. Default: `-1`. */ producerCompressionLevel?: number; /** * The time in milliseconds to wait for additional messages before sending a batch. If the time is exceeded, the batch is sent. Default: `5`. */ producerLingerMs?: number; /** * The maximum size of the buffer in kilobytes before sending. */ producerQueueBufferingMaxKbytes?: number; /** * The maximum number of messages to buffer before sending. Default: `100000`. */ producerQueueBufferingMaxMessages?: number; /** * The number of acknowledgements the leader broker must receive from ISR brokers before responding to the request: 0=Broker does not send any response/ack to client, -1 will block until message is committed by all in sync replicas (ISRs). Default: `-1`. */ producerRequestRequiredAcks?: number; /** * Number of broken messages to skip before stopping processing when reading from Kafka. Useful for handling corrupted data without failing the entire integration. Default: `0`. */ skipBrokenMessages?: number; /** * When enabled, each consumer runs in its own thread, providing better isolation and potentially better performance for high-throughput scenarios. Default: `false`. */ threadPerConsumer?: boolean; /** * Array of Kafka topics that this table will read data from or write data to. Messages from all specified topics will be inserted into this table, and data inserted into this table will be published to the topics */ topics: outputs.ServiceIntegrationClickhouseKafkaUserConfigTableTopic[]; } export interface ServiceIntegrationClickhouseKafkaUserConfigTableColumn { /** * The name of the column in the ClickHouse table. This should match the field names in your Kafka message format. Example: `key`. */ name: string; /** * The ClickHouse data type for this column. Must be a valid ClickHouse data type that can handle the data format. Example: `UInt64`. */ type: string; } export interface ServiceIntegrationClickhouseKafkaUserConfigTableMaterializedView { /** * The database to create the materialized view in. Must not be the Kafka integration database as it is not replicated and may be dropped. Default: `default`. */ databaseName?: string; /** * Enum: `AggregatingMergeTree`, `CollapsingMergeTree`, `MergeTree`, `ReplacingMergeTree`, `SummingMergeTree`, `VersionedCollapsingMergeTree`. The MergeTree-family engine for the materialized view's target table. Default: `MergeTree`. */ engine?: string; /** * Column names passed as engine arguments, e.g. the sign column for CollapsingMergeTree or the sign and version columns for VersionedCollapsingMergeTree. */ engineParams?: string[]; /** * Number of days after which data is moved from local disk to remote storage (tiered storage). Must be specified together with ttl_column. Example: `7`. */ localDiskTtlDays?: number; /** * Columns for the ORDER BY clause of the target table. Determines the sort order and primary index. */ orderBies: string[]; /** * Date or DateTime column used for both row deletion TTL and local disk tiered storage TTL. Must be specified when ttl*days or local*disk*ttl*days is set. Example: `createdAt`. */ ttlColumn?: string; /** * Number of days after which rows are deleted, calculated from the TTL column value. Must be specified together with ttl_column. Example: `30`. */ ttlDays?: number; /** * The name of the materialized view to create. Example: `eventsMv`. */ viewName: string; } export interface ServiceIntegrationClickhouseKafkaUserConfigTableTopic { /** * The name of the Kafka topic to read messages from or write messages to. The topic must exist in the Kafka cluster. Example: `topicName`. */ name: string; } export interface ServiceIntegrationClickhousePostgresqlUserConfig { /** * Databases to expose */ databases?: outputs.ServiceIntegrationClickhousePostgresqlUserConfigDatabase[]; } export interface ServiceIntegrationClickhousePostgresqlUserConfigDatabase { /** * PostgreSQL database to expose. Default: `defaultdb`. */ database?: string; /** * PostgreSQL schema to expose. Default: `public`. */ schema?: string; } export interface ServiceIntegrationDatadogUserConfig { /** * Enable Datadog Database Monitoring. */ datadogDbmEnabled?: boolean; /** * Enable collection of PL/pgSQL function metrics from pg*stat*user_functions. Requires `trackFunctions` to be set to `pl` or `all` in the service configuration. */ datadogFunctionMetricsEnabled?: boolean; /** * Relations to collect PostgreSQL relation metrics for, such as table size, index statistics, row counts, vacuum ages and locks. No relation metrics are collected when unset */ datadogPgRelations?: outputs.ServiceIntegrationDatadogUserConfigDatadogPgRelation[]; /** * Enable Datadog PgBouncer Metric Tracking. */ datadogPgbouncerEnabled?: boolean; /** * Custom tags provided by user */ datadogTags?: outputs.ServiceIntegrationDatadogUserConfigDatadogTag[]; /** * List of custom metrics. */ excludeConsumerGroups?: string[]; /** * List of topics to exclude. */ excludeTopics?: string[]; /** * List of custom metrics. */ includeConsumerGroups?: string[]; /** * List of topics to include. */ includeTopics?: string[]; /** * List of custom metrics. */ kafkaCustomMetrics?: string[]; /** * Maximum number of JMX metrics to send. Example: `2000`. */ maxJmxMetrics?: number; /** * List of custom metrics. */ mirrormakerCustomMetrics?: string[]; /** * Datadog Opensearch Options */ opensearch?: outputs.ServiceIntegrationDatadogUserConfigOpensearch; /** * Datadog Redis Options */ redis?: outputs.ServiceIntegrationDatadogUserConfigRedis; } export interface ServiceIntegrationDatadogUserConfigDatadogPgRelation { /** * Name of a single relation to collect metrics for. Example: `orders`. */ relationName?: string; /** * Regular expression matching the names of the relations to collect metrics for. Example: `^orders_.*`. */ relationRegex?: string; /** * Only collect lock metrics for these relation kinds. Applies to ordinary tables when unset. Accepted values are the `relkind` values of `pgClass`: `r` (ordinary table), `i` (index), `S` (sequence), `t` (TOAST table), `m` (materialized view), `c` (composite type), `f` (foreign table), `p` (partitioned table). */ relkinds?: string[]; /** * Only collect metrics for relations in these schemas. Applies to all schemas when unset. */ schemas?: string[]; } export interface ServiceIntegrationDatadogUserConfigDatadogTag { /** * Optional tag explanation. Example: `Used to tag primary replica metrics`. */ comment?: string; /** * Tag format and usage are described here: https://docs.datadoghq.com/getting_started/tagging. Tags with prefix `aiven-` are reserved for Aiven. Example: `replica:primary`. */ tag: string; } export interface ServiceIntegrationDatadogUserConfigOpensearch { /** * Enable Datadog Opensearch Cluster Monitoring. */ clusterStatsEnabled?: boolean; /** * Enable Datadog Opensearch Index Monitoring. */ indexStatsEnabled?: boolean; /** * Enable Datadog Opensearch Pending Task Monitoring. */ pendingTaskStatsEnabled?: boolean; /** * Enable Datadog Opensearch Primary Shard Monitoring. */ pshardStatsEnabled?: boolean; } export interface ServiceIntegrationDatadogUserConfigRedis { /** * Enable commandStats option in the agent's configuration. Default: `false`. */ commandStatsEnabled?: boolean; } export interface ServiceIntegrationEndpointAutoscalerUserConfig { /** * Configure autoscaling thresholds for a service */ autoscalings: outputs.ServiceIntegrationEndpointAutoscalerUserConfigAutoscaling[]; } export interface ServiceIntegrationEndpointAutoscalerUserConfigAutoscaling { /** * The maximum total disk size (in gb) to allow autoscaler to scale up to. Example: `300`. */ capGb: number; /** * Enum: `autoscaleDisk`. Type of autoscale event. */ type: string; } export interface ServiceIntegrationEndpointDatadogUserConfig { /** * Datadog API key. Example: `848f30907c15c55d601fe45487cce9b6`. */ datadogApiKey: string; /** * Custom tags provided by user */ datadogTags?: outputs.ServiceIntegrationEndpointDatadogUserConfigDatadogTag[]; /** * Disable consumer group metrics. */ disableConsumerStats?: boolean; /** * Extra tags prefix. Defaults to aiven. */ extraTagsPrefix?: string; /** * Number of separate instances to fetch kafka consumer statistics with. Example: `8`. */ kafkaConsumerCheckInstances?: number; /** * Number of seconds that datadog will wait to get consumer statistics from brokers. Example: `60`. */ kafkaConsumerStatsTimeout?: number; /** * Maximum number of partition contexts to send. Example: `32000`. */ maxPartitionContexts?: number; /** * Enum: `ap1.datadoghq.com`, `ap2.datadoghq.com`, `datadoghq.com`, `datadoghq.eu`, `ddog-gov.com`, `us2.ddog-gov.com`, `us3.datadoghq.com`, `us5.datadoghq.com`. Datadog intake site. Defaults to datadoghq.com. */ site?: string; } export interface ServiceIntegrationEndpointDatadogUserConfigDatadogTag { /** * Optional tag explanation. Example: `Used to tag primary replica metrics`. */ comment?: string; /** * Tag format and usage are described here: https://docs.datadoghq.com/getting_started/tagging. Tags with prefix `aiven-` are reserved for Aiven. Example: `replica:primary`. */ tag: string; } export interface ServiceIntegrationEndpointExternalAwsCloudwatchLogsUserConfig { /** * AWS access key. Required permissions are logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents and logs:DescribeLogStreams. Example: `AAAAAAAAAAAAAAAAAAAA`. */ accessKey: string; /** * AWS CloudWatch log group name. Example: `my-log-group`. */ logGroupName?: string; /** * AWS region. Example: `us-east-1`. */ region: string; /** * AWS secret key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretKey: string; } export interface ServiceIntegrationEndpointExternalAwsCloudwatchMetricsUserConfig { /** * AWS access key. Required permissions are cloudwatch:PutMetricData. Example: `AAAAAAAAAAAAAAAAAAAA`. */ accessKey: string; /** * AWS CloudWatch Metrics Namespace. Example: `my-metrics-namespace`. */ namespace: string; /** * AWS region. Example: `us-east-1`. */ region: string; /** * AWS secret key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretKey: string; } export interface ServiceIntegrationEndpointExternalAwsS3UserConfig { /** * Access Key Id. Example: `AAAAAAAAAAAAAAAAAAA`. */ accessKeyId: string; /** * Secret Access Key. Example: `AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA`. */ secretAccessKey: string; /** * S3-compatible bucket URL. Example: `https://mybucket.s3-myregion.amazonaws.com/mydataset/`. */ url: string; } export interface ServiceIntegrationEndpointExternalAzureBlobStorageUserConfig { /** * Blob path. Example: `path/to/blob/file.csv`. */ blobPath?: string; /** * Azure Blob Storage connection string. Example: `AccountName=IDENT;AccountKey=SECRET`. */ connectionString: string; /** * Container. Example: `container-dev`. */ container: string; } export interface ServiceIntegrationEndpointExternalClickhouseUserConfig { /** * Hostname or IP address of the server. Example: `my.server.com`. */ host: string; /** * Password. Example: `jjKk45Nnd`. */ password: string; /** * Secure TCP server port. Example: `9440`. */ port: number; /** * User name. Example: `default`. */ username: string; } export interface ServiceIntegrationEndpointExternalElasticsearchLogsUserConfig { /** * PEM encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ ca?: string; /** * Maximum number of days of logs to keep. Default: `3`. */ indexDaysMax?: number; /** * Elasticsearch index prefix. Default: `logs`. */ indexPrefix: string; /** * Elasticsearch request timeout limit. Default: `10`. */ timeout?: number; /** * Elasticsearch connection URL. Example: `https://user:passwd@logs.example.com/`. */ url: string; } export interface ServiceIntegrationEndpointExternalGoogleCloudBigquery { /** * GCP project id. Example: `snappy-photon-12345`. */ projectId: string; /** * This is a JSON object with the fields documented in https://cloud.google.com/iam/docs/creating-managing-service-account-keys. Example: `{"type": "serviceAccount", ...`. */ serviceAccountCredentials: string; } export interface ServiceIntegrationEndpointExternalGoogleCloudLoggingUserConfig { /** * Google Cloud Logging log id. Example: `syslog`. */ logId: string; /** * GCP project id. Example: `snappy-photon-12345`. */ projectId: string; /** * This is a JSON object with the fields documented in https://cloud.google.com/iam/docs/creating-managing-service-account-keys. Example: `{"type": "serviceAccount", ...`. */ serviceAccountCredentials: string; } export interface ServiceIntegrationEndpointExternalKafkaUserConfig { /** * Bootstrap servers. Example: `10.0.0.1:9092,10.0.0.2:9092`. */ bootstrapServers: string; /** * Enum: `PLAIN`, `SCRAM-SHA-256`, `SCRAM-SHA-512`. SASL mechanism used for connections to the Kafka server. */ saslMechanism?: string; /** * Password for SASL PLAIN mechanism in the Kafka server. Example: `admin`. */ saslPlainPassword?: string; /** * Username for SASL PLAIN mechanism in the Kafka server. Example: `admin`. */ saslPlainUsername?: string; /** * Enum: `PLAINTEXT`, `SASL_PLAINTEXT`, `SASL_SSL`, `SSL`. Security protocol. */ securityProtocol: string; /** * PEM-encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslCaCert?: string; /** * PEM-encoded client certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslClientCert?: string; /** * PEM-encoded client key. Example: `-----BEGIN PRIVATE KEY----- * ... * -----END PRIVATE KEY----- * `. */ sslClientKey?: string; /** * Enum: `https`. The endpoint identification algorithm to validate server hostname using server certificate. */ sslEndpointIdentificationAlgorithm?: string; } export interface ServiceIntegrationEndpointExternalMysqlUserConfig { /** * Hostname or IP address of the server. Example: `my.server.com`. */ host: string; /** * Password. Example: `jjKk45Nnd`. */ password: string; /** * Port number of the server. Example: `5432`. */ port: number; /** * Enum: `verify-full`. SSL Mode. Default: `verify-full`. */ sslMode?: string; /** * SSL Root Cert. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslRootCert?: string; /** * User name. Example: `myname`. */ username: string; } export interface ServiceIntegrationEndpointExternalObjectStorageConfigUserConfig { /** * Azure account secret key (Azure only). Example: `YWNjb3VudCBrZXkgZXhhbXBsZQ==`. */ accountKey?: string; /** * Azure account name (Azure only). Example: `myazureaccount`. */ accountName?: string; /** * AWS access key ID (S3 only). Example: `AKIAIOSFODNN7EXAMPLE`. */ awsAccessKeyId?: string; /** * AWS secret access key (S3 only). Example: `wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY`. */ awsSecretAccessKey?: string; /** * Bucket name. Example: `my-thanos-bucket`. */ bucketName?: string; /** * Google service account credentials JSON (Google Cloud Storage only). Example: `{"type": "serviceAccount", ...`. */ credentials?: string; /** * S3-compatible endpoint host (S3 only). Example: `s3.eu-west-1.amazonaws.com`. */ host?: string; /** * S3-compatible endpoint port (S3 only). Example: `443`. */ port?: number; /** * Object storage prefix / path. Example: `thanos-data/`. */ prefix?: string; /** * GCP project ID (Google Cloud Storage only). Example: `my-gcp-project`. */ projectId?: string; /** * AWS S3 region (S3 only). Example: `eu-west-1`. */ region?: string; /** * Enum: `azure`, `google`, `s3`. Object storage type. */ storageType: string; } export interface ServiceIntegrationEndpointExternalOpensearchLogsUserConfig { /** * PEM encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ ca?: string; /** * Maximum number of days of logs to keep. Default: `3`. */ indexDaysMax?: number; /** * OpenSearch index prefix. Default: `logs`. */ indexPrefix: string; /** * OpenSearch request timeout limit. Default: `10`. */ timeout?: number; /** * OpenSearch connection URL. Example: `https://user:passwd@logs.example.com/`. */ url: string; } export interface ServiceIntegrationEndpointExternalPostgresql { /** * Default database. Example: `testdb`. */ defaultDatabase?: string; /** * Hostname or IP address of the server. Example: `my.server.com`. */ host: string; /** * Password. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server. Example: `5432`. */ port: number; /** * Client certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslClientCertificate?: string; /** * Client key. Example: `-----BEGIN PRIVATE KEY----- * ... * -----END PRIVATE KEY-----`. */ sslClientKey?: string; /** * Enum: `allow`, `disable`, `prefer`, `require`, `verify-ca`, `verify-full`. SSL mode to use for the connection. Please note that Aiven requires TLS for all connections to external PostgreSQL services. Default: `verify-full`. */ sslMode?: string; /** * SSL Root Cert. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ sslRootCert?: string; /** * User name. Example: `myname`. */ username: string; } export interface ServiceIntegrationEndpointExternalPrometheusUserConfig { /** * Prometheus basic authentication password. Example: `fhyFNBjj3R`. */ basicAuthPassword?: string; /** * Prometheus basic authentication username. Example: `prom4851`. */ basicAuthUsername?: string; /** * Prometheus enabled write endpoint. Example: `https://write.example.com/`. */ serviceUri?: string; } export interface ServiceIntegrationEndpointExternalSchemaRegistryUserConfig { /** * Enum: `basic`, `none`. Authentication method. */ authentication: string; /** * Basic authentication password. Example: `Zm9vYg==`. */ basicAuthPassword?: string; /** * Basic authentication user name. Example: `avnadmin`. */ basicAuthUsername?: string; /** * Schema Registry URL. Example: `https://schema-registry.kafka.company.com:28419`. */ url: string; } export interface ServiceIntegrationEndpointJolokiaUserConfig { /** * Jolokia basic authentication password. Example: `yhfBNFii4C`. */ basicAuthPassword?: string; /** * Jolokia basic authentication username. Example: `jol48k51`. */ basicAuthUsername?: string; } export interface ServiceIntegrationEndpointOpentelemetryUserConfig { /** * Resource attributes to attach to every exported metric. */ attributes?: { [key: string]: string; }; /** * Enum: `gzip`, `none`. Payload compression. */ compression: string; /** * Enum: `json`, `protobuf`. Encoding used for exported metrics. Leave unset to use telegraf's default. */ encodingType?: string; /** * Additional gRPC metadata headers sent with every export request. */ headers?: { [key: string]: string; }; /** * Either a bare `host:port` (OTLP/gRPC, no URL scheme) or an `http://`/`https://` URL (OTLP/HTTP). Example: `otel-collector.example.avns.net:4317`. */ serviceAddress: string; /** * Connection timeout in seconds. Example: `10`. */ timeout: number; } export interface ServiceIntegrationEndpointPrometheusUserConfig { /** * Prometheus basic authentication password. Example: `fhyFNBjj3R`. */ basicAuthPassword?: string; /** * Prometheus basic authentication username. Example: `prom4851`. */ basicAuthUsername?: string; } export interface ServiceIntegrationEndpointRsyslogUserConfig { /** * PEM encoded CA certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ ca?: string; /** * PEM encoded client certificate. Example: `-----BEGIN CERTIFICATE----- * ... * -----END CERTIFICATE----- * `. */ cert?: string; /** * When true, embedded newlines in a log message are escaped so a multi-line record (e.g. a stack trace) is delivered as one complete log entry. Useful for newline-delimited cloud log intakes that drop continuation lines. Default: `false`. */ escapeNewlines?: boolean; /** * Enum: `custom`, `rfc3164`, `rfc5424`. Message format. Default: `rfc5424`. */ format: string; /** * PEM encoded client key. Example: `-----BEGIN PRIVATE KEY----- * ... * -----END PRIVATE KEY----- * `. */ key?: string; /** * Custom syslog message format. Example: `<%pri%>%timestamp:::date-rfc3339% %HOSTNAME% %app-name% %msg%`. */ logline?: string; /** * Rsyslog max message size. Default: `8192`. */ maxMessageSize?: number; /** * Rsyslog server port. Default: `514`. */ port: number; /** * Structured data block for log message. Example: `TOKEN tag="LiteralValue"`. */ sd?: string; /** * Rsyslog server IP address or hostname. Example: `logs.example.com`. */ server: string; /** * Require TLS. Default: `true`. */ tls: boolean; } export interface ServiceIntegrationExternalAwsCloudwatchLogsUserConfig { /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface ServiceIntegrationExternalAwsCloudwatchMetricsUserConfig { /** * Metrics to not send to AWS CloudWatch (takes precedence over extra*metrics) */ droppedMetrics?: outputs.ServiceIntegrationExternalAwsCloudwatchMetricsUserConfigDroppedMetric[]; /** * Metrics to allow through to AWS CloudWatch (in addition to default metrics) */ extraMetrics?: outputs.ServiceIntegrationExternalAwsCloudwatchMetricsUserConfigExtraMetric[]; } export interface ServiceIntegrationExternalAwsCloudwatchMetricsUserConfigDroppedMetric { /** * Identifier of a value in the metric. Example: `used`. */ field: string; /** * Identifier of the metric. Example: `java.lang:Memory`. */ metric: string; } export interface ServiceIntegrationExternalAwsCloudwatchMetricsUserConfigExtraMetric { /** * Identifier of a value in the metric. Example: `used`. */ field: string; /** * Identifier of the metric. Example: `java.lang:Memory`. */ metric: string; } export interface ServiceIntegrationExternalElasticsearchLogsUserConfig { /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface ServiceIntegrationExternalOpensearchLogsUserConfig { /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface ServiceIntegrationFlinkExternalPostgresqlUserConfig { /** * Enum: `unspecified`. If stringtype is set to unspecified, parameters will be sent to the server as untyped values. */ stringtype?: string; } export interface ServiceIntegrationKafkaConnectUserConfig { /** * Kafka Connect service configuration values */ kafkaConnect?: outputs.ServiceIntegrationKafkaConnectUserConfigKafkaConnect; } export interface ServiceIntegrationKafkaConnectUserConfigKafkaConnect { /** * The name of the topic where connector and task configuration data are stored.This must be the same for all workers with the same group_id. Example: `__connect_configs`. */ configStorageTopic?: string; /** * A unique string that identifies the Connect cluster group this worker belongs to. Example: `connect`. */ groupId?: string; /** * The name of the topic where connector and task configuration offsets are stored.This must be the same for all workers with the same group_id. Example: `__connect_offsets`. */ offsetStorageTopic?: string; /** * The name of the topic where connector and task configuration status updates are stored.This must be the same for all workers with the same group_id. Example: `__connect_status`. */ statusStorageTopic?: string; } export interface ServiceIntegrationKafkaLogsUserConfig { /** * Topic name. Example: `mytopic`. */ kafkaTopic: string; /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface ServiceIntegrationKafkaMirrormakerUserConfig { /** * The alias under which the Kafka cluster is known to MirrorMaker. Can contain the following symbols: ASCII alphanumerics, `.`, `_`, and `-`. Example: `kafka-abc`. */ clusterAlias?: string; /** * Kafka MirrorMaker configuration values */ kafkaMirrormaker?: outputs.ServiceIntegrationKafkaMirrormakerUserConfigKafkaMirrormaker; } export interface ServiceIntegrationKafkaMirrormakerUserConfigKafkaMirrormaker { /** * Enum: `earliest`, `latest`. Set where consumer starts to consume data. Value `earliest`: Start replication from the earliest offset. Value `latest`: Start replication from the latest offset. Default is `earliest`. */ consumerAutoOffsetReset?: string; /** * The maximum amount of data the server should return for a fetch request. Default is `52428800` (50MiB). */ consumerFetchMaxBytes?: number; /** * The maximum amount of time the server will block before answering the fetch request if there isn't sufficient data to immediately satisfy `consumerFetchMinBytes`. Default is `500`. */ consumerFetchMaxWaitMs?: number; /** * The minimum amount of data the server should return for a fetch request. Default is `1`. Example: `1024`. */ consumerFetchMinBytes?: number; /** * The maximum amount of data per partition the server will return. Default is `1048576` (1MiB). */ consumerMaxPartitionFetchBytes?: number; /** * Set consumer max.poll.records. Default is `500`. */ consumerMaxPollRecords?: number; /** * The size of the TCP receive buffer (SO_RCVBUF) to use when reading data. Default is `65536` (64KiB). `-1` uses the OS default. */ consumerReceiveBufferBytes?: number; /** * The maximum time the client will wait for a response to a request. Default is `30000` (30s). */ consumerRequestTimeoutMs?: number; /** * The batch size in bytes producer will attempt to collect before publishing to broker. Default is `16384` (16KiB). */ producerBatchSize?: number; /** * The amount of bytes producer can use for buffering data before publishing to broker. Default is `33554432` (32MiB). */ producerBufferMemory?: number; /** * Enum: `gzip`, `lz4`, `none`, `snappy`, `zstd`. Specify the default compression type for producers. This configuration accepts the standard compression codecs (`gzip`, `snappy`, `lz4`, `zstd`). It additionally accepts `none` which is the default and equivalent to no compression. */ producerCompressionType?: string; /** * The linger time (ms) for waiting new data to arrive for publishing. Default is `0`. Example: `100`. */ producerLingerMs?: number; /** * The maximum request size in bytes. Default is `1048576` (1MiB). */ producerMaxRequestSize?: number; /** * The maximum time the client will wait for a response to a request. Default is `30000` (30s). */ producerRequestTimeoutMs?: number; /** * The size of the TCP send buffer (SO_SNDBUF) to use when sending data. Default is `131072` (128KiB). `-1` uses the OS default. */ producerSendBufferBytes?: number; } export interface ServiceIntegrationLogsUserConfig { /** * Elasticsearch index retention limit. Default: `3`. */ elasticsearchIndexDaysMax?: number; /** * Elasticsearch index prefix. Default: `logs`. */ elasticsearchIndexPrefix?: string; /** * The list of logging fields that will be sent to the integration logging service. The MESSAGE and timestamp fields are always sent. */ selectedLogFields?: string[]; } export interface ServiceIntegrationMetricsUserConfig { /** * Name of the database where to store metric datapoints. Only affects PostgreSQL destinations. Defaults to `metrics`. Note that this must be the same for all metrics integrations that write data to the same PostgreSQL service. */ database?: string; /** * Number of days to keep old metrics. Only affects PostgreSQL destinations. Set to 0 for no automatic cleanup. Defaults to 30 days. */ retentionDays?: number; /** * Name of a user that can be used to read metrics. This will be used for Grafana integration (if enabled) to prevent Grafana users from making undesired changes. Only affects PostgreSQL destinations. Defaults to `metricsReader`. Note that this must be the same for all metrics integrations that write data to the same PostgreSQL service. */ roUsername?: string; /** * Configuration options for metrics where source service is MySQL */ sourceMysql?: outputs.ServiceIntegrationMetricsUserConfigSourceMysql; /** * Name of the user used to write metrics. Only affects PostgreSQL destinations. Defaults to `metricsWriter`. Note that this must be the same for all metrics integrations that write data to the same PostgreSQL service. */ username?: string; } export interface ServiceIntegrationMetricsUserConfigSourceMysql { /** * Configuration options for Telegraf MySQL input plugin */ telegraf?: outputs.ServiceIntegrationMetricsUserConfigSourceMysqlTelegraf; } export interface ServiceIntegrationMetricsUserConfigSourceMysqlTelegraf { /** * Gather metrics from PERFORMANCE*SCHEMA.EVENT*WAITS. */ gatherEventWaits?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.FILE*SUMMARY*BY*EVENT_NAME. */ gatherFileEventsStats?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.TABLE*IO*WAITS*SUMMARY*BY*INDEX_USAGE. */ gatherIndexIoWaits?: boolean; /** * Gather autoIncrement columns and max values from information schema. */ gatherInfoSchemaAutoInc?: boolean; /** * Gather metrics from INFORMATION*SCHEMA.INNODB*METRICS. */ gatherInnodbMetrics?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.EVENTS*STATEMENTS*SUMMARY*BY_DIGEST. */ gatherPerfEventsStatements?: boolean; /** * Gather thread state counts from INFORMATION_SCHEMA.PROCESSLIST. */ gatherProcessList?: boolean; /** * Gather metrics from SHOW REPLICA STATUS command output. */ gatherReplicaStatus?: boolean; /** * Gather metrics from SHOW SLAVE STATUS command output. */ gatherSlaveStatus?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.TABLE*IO*WAITS*SUMMARY*BY*TABLE. */ gatherTableIoWaits?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.TABLE*LOCK_WAITS. */ gatherTableLockWaits?: boolean; /** * Gather metrics from INFORMATION_SCHEMA.TABLES. */ gatherTableSchema?: boolean; /** * Truncates digest text from perf*events*statements into this many characters. Example: `120`. */ perfEventsStatementsDigestTextLimit?: number; /** * Limits metrics from perf*events*statements. Example: `250`. */ perfEventsStatementsLimit?: number; /** * Only include perf*events*statements whose last seen is less than this many seconds. Example: `86400`. */ perfEventsStatementsTimeLimit?: number; } export interface ServiceIntegrationPrometheusUserConfig { /** * Configuration options for metrics where source service is MySQL */ sourceMysql?: outputs.ServiceIntegrationPrometheusUserConfigSourceMysql; } export interface ServiceIntegrationPrometheusUserConfigSourceMysql { /** * Configuration options for Telegraf MySQL input plugin */ telegraf?: outputs.ServiceIntegrationPrometheusUserConfigSourceMysqlTelegraf; } export interface ServiceIntegrationPrometheusUserConfigSourceMysqlTelegraf { /** * Gather metrics from PERFORMANCE*SCHEMA.EVENT*WAITS. */ gatherEventWaits?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.FILE*SUMMARY*BY*EVENT_NAME. */ gatherFileEventsStats?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.TABLE*IO*WAITS*SUMMARY*BY*INDEX_USAGE. */ gatherIndexIoWaits?: boolean; /** * Gather autoIncrement columns and max values from information schema. */ gatherInfoSchemaAutoInc?: boolean; /** * Gather metrics from INFORMATION*SCHEMA.INNODB*METRICS. */ gatherInnodbMetrics?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.EVENTS*STATEMENTS*SUMMARY*BY_DIGEST. */ gatherPerfEventsStatements?: boolean; /** * Gather thread state counts from INFORMATION_SCHEMA.PROCESSLIST. */ gatherProcessList?: boolean; /** * Gather metrics from SHOW REPLICA STATUS command output. */ gatherReplicaStatus?: boolean; /** * Gather metrics from SHOW SLAVE STATUS command output. */ gatherSlaveStatus?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.TABLE*IO*WAITS*SUMMARY*BY*TABLE. */ gatherTableIoWaits?: boolean; /** * Gather metrics from PERFORMANCE*SCHEMA.TABLE*LOCK_WAITS. */ gatherTableLockWaits?: boolean; /** * Gather metrics from INFORMATION_SCHEMA.TABLES. */ gatherTableSchema?: boolean; /** * Truncates digest text from perf*events*statements into this many characters. Example: `120`. */ perfEventsStatementsDigestTextLimit?: number; /** * Limits metrics from perf*events*statements. Example: `250`. */ perfEventsStatementsLimit?: number; /** * Only include perf*events*statements whose last seen is less than this many seconds. Example: `86400`. */ perfEventsStatementsTimeLimit?: number; } export interface ServiceIntegrationRsyslogUserConfig { /** * Per-service override for escaping embedded newlines in log messages. When set, it overrides the rsyslog endpoint setting for this service. When unset, the endpoint setting applies. */ escapeNewlines?: boolean; } export interface StaticIpTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ThanosComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface ThanosServiceIntegration { /** * Type of the service integration */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface ThanosTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface ThanosTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface ThanosThanos { /** * Query frontend URI. */ queryFrontendUri: string; /** * Query URI. */ queryUri: string; /** * Receiver remote write URI. */ receiverRemoteWriteUri: string; /** * Thanos server URIs. */ uris: string[]; } export interface ThanosThanosUserConfig { /** * Configuration options for Thanos Compactor */ compactor?: outputs.ThanosThanosUserConfigCompactor; /** * Environmental variables. * * @deprecated This property is deprecated. */ env?: { [key: string]: string; }; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.ThanosThanosUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * After exceeding the limit a service alert is going to be raised (0 means not set). */ objectStorageUsageAlertThresholdGb?: number; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.ThanosThanosUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.ThanosThanosUserConfigPrivatelinkAccess; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.ThanosThanosUserConfigPublicAccess; /** * Configuration options for Thanos Query */ query?: outputs.ThanosThanosUserConfigQuery; /** * Configuration options for Thanos Query Frontend */ queryFrontend?: outputs.ThanosThanosUserConfigQueryFrontend; /** * Common configuration options for Thanos Receive. */ receiverIngesting?: { [key: string]: string; }; /** * Configuration options for Thanos Receive Routing. */ receiverRouting?: { [key: string]: string; }; /** * Configuration options for Thanos Ruler. */ ruler?: { [key: string]: string; }; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Configuration options for Thanos Store. */ store?: { [key: string]: string; }; } export interface ThanosThanosUserConfigCompactor { /** * Retention time for data in days for each resolution (5m, 1h, raw). */ retentionDays?: number; } export interface ThanosThanosUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface ThanosThanosUserConfigPrivateAccess { /** * Allow clients to connect to queryFrontend with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ queryFrontend?: boolean; /** * Allow clients to connect to receiverRouting with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ receiverRouting?: boolean; } export interface ThanosThanosUserConfigPrivatelinkAccess { /** * Enable query_frontend. */ queryFrontend?: boolean; /** * Enable receiver_routing. */ receiverRouting?: boolean; } export interface ThanosThanosUserConfigPublicAccess { /** * Allow clients to connect to compactor from the public internet for service nodes that are in a project VPC or another type of private network. */ compactor?: boolean; /** * Allow clients to connect to query from the public internet for service nodes that are in a project VPC or another type of private network. */ query?: boolean; /** * Allow clients to connect to queryFrontend from the public internet for service nodes that are in a project VPC or another type of private network. */ queryFrontend?: boolean; /** * Allow clients to connect to receiverIngesting from the public internet for service nodes that are in a project VPC or another type of private network. */ receiverIngesting?: boolean; /** * Allow clients to connect to receiverRouting from the public internet for service nodes that are in a project VPC or another type of private network. */ receiverRouting?: boolean; /** * Allow clients to connect to ruler from the public internet for service nodes that are in a project VPC or another type of private network. */ ruler?: boolean; /** * Allow clients to connect to store from the public internet for service nodes that are in a project VPC or another type of private network. */ store?: boolean; } export interface ThanosThanosUserConfigQuery { /** * Set the default evaluation interval for subqueries. Default: `1m`. */ queryDefaultEvaluationInterval?: string; /** * The maximum lookback duration for retrieving metrics during expression evaluations in PromQL. PromQL always evaluates the query for a certain timestamp, and it looks back for the given amount of time to get the latest sample. If it exceeds the maximum lookback delta, it assumes the series is stale and returns none (a gap). The lookback delta should be set to at least 2 times the slowest scrape interval. If unset, it will use the promql default of 5m. Default: `5m`. */ queryLookbackDelta?: string; /** * The default metadata time range duration for retrieving labels through Labels and Series API when the range parameters are not specified. The zero value means the range covers the time since the beginning. Default: `0s`. */ queryMetadataDefaultTimeRange?: string; /** * Maximum time to process a query by the query node. Default: `2m`. */ queryTimeout?: string; /** * The maximum samples allowed for a single Series request. The Series call fails if this limit is exceeded. Set to 0 for no limit. NOTE: For efficiency, the limit is internally implemented as 'chunks limit' considering each chunk contains a maximum of 120 samples. The default value is 100 * store.limits.request-series. Default: `0`. */ storeLimitsRequestSamples?: number; /** * The maximum series allowed for a single Series request. The Series call fails if this limit is exceeded. Set to 0 for no limit. The default value is 1000 * cpu_count. Default: `0`. */ storeLimitsRequestSeries?: number; } export interface ThanosThanosUserConfigQueryFrontend { /** * Whether to align the query range boundaries with the step. If enabled, the query range boundaries will be aligned to the step, providing more accurate results for queries with high-resolution data. Default: `true`. */ queryRangeAlignRangeWithStep?: boolean; } export interface UpgradeStepTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ValkeyComponent { /** * Service component name */ component: string; /** * Connection info for connecting to the service component. This is a combination of host and port. */ connectionUri: string; /** * Host name for connecting to the service component */ host: string; /** * Kafka authentication method. This is a value specific to the 'kafka' service component */ kafkaAuthenticationMethod: string; /** * Kafka certificate used. The possible values are `letsencrypt` and `projectCa`. */ kafkaSslCa: string; /** * Port number for connecting to the service component */ port: number; /** * Privatelink connection ID */ privatelinkConnectionId: string; /** * Network access route */ route: string; /** * Whether the endpoint is encrypted or accepts plaintext. By default endpoints are always encrypted and this property is only included for service components they may disable encryption */ ssl: boolean; /** * DNS usage name */ usage: string; } export interface ValkeyServiceIntegration { /** * Type of the service integration. The possible value is `readReplica`. */ integrationType: string; /** * Name of the source service */ sourceServiceName: string; } export interface ValkeyTag { /** * Service tag key */ key: string; /** * Service tag value */ value: string; } export interface ValkeyTechEmail { /** * An email address to contact for technical issues */ email: string; } export interface ValkeyUserTimeouts { /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ create?: string; /** * Timeout for all operations. Deprecated, use operation-specific timeouts instead. * * @deprecated Use operation-specific timeouts instead. This field will be removed in the next major version. */ default?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs. */ delete?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled. */ read?: string; /** * A string that can be [parsed as a duration](https://pkg.go.dev/time#ParseDuration) consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). */ update?: string; } export interface ValkeyValkey { /** * Valkey password. */ password: string; /** * Valkey replica server URI. */ replicaUri: string; /** * Valkey slave server URIs. */ slaveUris: string[]; /** * Valkey server URIs. */ uris: string[]; } export interface ValkeyValkeyUserConfig { /** * Additional Cloud Regions for Backup Replication. */ additionalBackupRegions?: string; /** * The hour of day (in UTC) when backup for the service is started. New backup is only started if previous backup has already completed. Example: `3`. */ backupHour?: number; /** * The minute of an hour when backup for the service is started. New backup is only started if previous backup has already completed. Example: `30`. */ backupMinute?: number; /** * Register AAAA DNS records for the service, and allow IPv6 packets to service ports. */ enableIpv6?: boolean; /** * When enabled, Valkey will create frequent local RDB snapshots. When disabled, Valkey will only take RDB snapshots when a backup is created, based on the backup schedule. This setting is ignored when `valkeyPersistence` is set to `off`. Default: `true`. */ frequentSnapshots?: boolean; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16` */ ipFilterObjects?: outputs.ValkeyValkeyUserConfigIpFilterObject[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. */ ipFilterStrings?: string[]; /** * Allow incoming connections from CIDR address block, e.g. `10.20.0.0/16`. * * @deprecated Deprecated. Use `ipFilterString` instead. */ ipFilters?: string[]; /** * Migrate data from existing server */ migration?: outputs.ValkeyValkeyUserConfigMigration; /** * Allow access to selected service ports from private networks */ privateAccess?: outputs.ValkeyValkeyUserConfigPrivateAccess; /** * Allow access to selected service components through Privatelink */ privatelinkAccess?: outputs.ValkeyValkeyUserConfigPrivatelinkAccess; /** * Name of another project to fork a service from. This has effect only when a new service is being created. Example: `anotherprojectname`. */ projectToForkFrom?: string; /** * Allow access to selected service ports from the public Internet */ publicAccess?: outputs.ValkeyValkeyUserConfigPublicAccess; /** * Name of the basebackup to restore in forked service. Example: `backup-20191112t091354293891z`. */ recoveryBasebackupName?: string; /** * Store logs for the service so that they are available in the HTTP API and console. */ serviceLog?: boolean; /** * Name of another service to fork from. This has effect only when a new service is being created. Example: `anotherservicename`. */ serviceToForkFrom?: string; /** * Use static public IP addresses. */ staticIps?: boolean; /** * Enum: `allchannels`, `resetchannels`. Determines default pub/sub channels' ACL for new users if ACL is not supplied. When this option is not defined, allChannels is assumed to keep backward compatibility. This option doesn't affect Valkey configuration acl-pubsub-default. */ valkeyAclChannelsDefault?: string; /** * Valkey reclaims expired keys both when accessed and in the background. The background process scans for expired keys to free memory. Increasing the active-expire-effort setting (default 1, max 10) uses more CPU to reclaim expired keys faster, reducing memory usage but potentially increasing latency. Default: `1`. */ valkeyActiveExpireEffort?: number; /** * Enable active memory defragmentation. When enabled, Valkey relocates objects off sparsely-used memory pages to reduce fragmentation and return memory to the operating system. Defragmentation runs on the main thread and consumes CPU, so it may increase latency under load. Default: `false`. */ valkeyActivedefrag?: boolean; /** * Set Valkey IO thread count. Changing this will cause a restart of the Valkey service. Example: `1`. */ valkeyIoThreads?: number; /** * LFU maxmemory-policy counter decay time in minutes. Default: `1`. */ valkeyLfuDecayTime?: number; /** * Counter logarithm factor for volatile-lfu and allkeys-lfu maxmemory-policies. Default: `10`. */ valkeyLfuLogFactor?: number; /** * Enum: `allkeys-lfu`, `allkeys-lru`, `allkeys-random`, `noeviction`, `volatile-lfu`, `volatile-lru`, `volatile-random`, `volatile-ttl`. Valkey maxmemory-policy. Default: `noeviction`. */ valkeyMaxmemoryPolicy?: string; /** * Set notify-keyspace-events option. */ valkeyNotifyKeyspaceEvents?: string; /** * Set number of Valkey databases. Changing this will cause a restart of the Valkey service. Example: `16`. */ valkeyNumberOfDatabases?: number; /** * Enum: `off`, `rdb`. When persistence is `rdb`, Valkey does RDB dumps each 10 minutes if any key is changed. Also RDB dumps are done according to backup schedule for backup purposes. When persistence is `off`, no RDB dumps and backups are done, so data can be lost at any moment if service is restarted for any reason, or if service is powered off. Also service can't be forked. */ valkeyPersistence?: string; /** * Set output buffer limit for pub / sub clients in MB. The value is the hard limit, the soft limit is 1/4 of the hard limit. When setting the limit, be mindful of the available memory in the selected service plan. Example: `64`. */ valkeyPubsubClientOutputBufferLimit?: number; /** * Require SSL to access Valkey. Default: `true`. */ valkeySsl?: boolean; /** * Valkey idle connection timeout in seconds. Default: `300`. */ valkeyTimeout?: number; /** * Enum: `8.1`, `9.0`, `9.1`, and newer. Valkey major version. */ valkeyVersion?: string; } export interface ValkeyValkeyUserConfigIpFilterObject { /** * Description for IP filter list entry. Example: `Production service IP range`. */ description?: string; /** * CIDR address block. Example: `10.20.0.0/16`. */ network: string; } export interface ValkeyValkeyUserConfigMigration { /** * Database name for bootstrapping the initial connection. Example: `defaultdb`. */ dbname?: string; /** * Hostname or IP address of the server where to migrate data from. Example: `my.server.com`. */ host: string; /** * Comma-separated list of databases, which should be ignored during migration (supported by MySQL and PostgreSQL only at the moment). Example: `db1,db2`. */ ignoreDbs?: string; /** * Comma-separated list of database roles, which should be ignored during migration (supported by PostgreSQL only at the moment). Example: `role1,role2`. */ ignoreRoles?: string; /** * Enum: `dump`, `replication`. The migration method to be used (currently supported only by Redis, Dragonfly, MySQL and PostgreSQL service types). */ method?: string; /** * Password for authentication with the server where to migrate data from. Example: `jjKk45Nnd`. */ password?: string; /** * Port number of the server where to migrate data from. Example: `1234`. */ port: number; /** * The server where to migrate data from is secured with SSL. Default: `true`. */ ssl?: boolean; /** * User name for authentication with the server where to migrate data from. Example: `myname`. */ username?: string; } export interface ValkeyValkeyUserConfigPrivateAccess { /** * Allow clients to connect to prometheus with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ prometheus?: boolean; /** * Allow clients to connect to valkey with a DNS name that always resolves to the service's private IP addresses. Only available in certain network locations. */ valkey?: boolean; } export interface ValkeyValkeyUserConfigPrivatelinkAccess { /** * Enable prometheus. */ prometheus?: boolean; /** * Enable valkey. */ valkey?: boolean; } export interface ValkeyValkeyUserConfigPublicAccess { /** * Allow clients to connect to prometheus from the public internet for service nodes that are in a project VPC or another type of private network. */ prometheus?: boolean; /** * Allow clients to connect to valkey from the public internet for service nodes that are in a project VPC or another type of private network. */ valkey?: boolean; } //# sourceMappingURL=output.d.ts.map