Deploying a Stack
Function
DeployStack
This API deploys a created stack.
-
You can call this API to update the template and parameters and trigger a new deployment.
-
This API triggers deployment directly. If users want to confirm deployment details in advance, create an execution plan by calling CreateExecutionPlan and get the execution plan by calling GetExecutionPlan.
-
If resources defined in template (including imported resources) are deleted, the actual resources will be deleted when stack is deployed. It is recommended to use CreateExecutionPlan to ensure there is no unexpected operation to resources.
-
If automatic rollback is enabled, the stack rolls back once its deployment fails. If automatic rollback is disabled, the stack stays in the current status when the deployment fails.
-
If encrypt_kms_key_id is provided to enable template encryption, ensure that the stack agency role (if configured) or the current account identity has kms:dek:create(Create a data key) and kms:dek:decrypt(decrypt a data key) permissions to access the specified KMS master key.
URI
POST /v1/{project_id}/stacks/{stack_name}/deployments
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| project_id | Yes | String | A project ID is obtained by calling an API or from the console. Minimum: 3 Maximum: 64 |
| stack_name | Yes | String | A stack name is unique within its domain (domain_id), region, and project (project_id). It is case-sensitive and starts with a letter. Only letters, digits, underscores (_), and hyphens (-) are allowed. Minimum: 1 Maximum: 128 |
Request Parameters
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| Client-Request-Id | Yes | String | A unique request ID is specified by a user to locate a request. UUID is recommended. Minimum: 36 Maximum: 128 |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| template_body | No | String | HCL template. It describes the target status of a resource. RFS compares the differences between the statuses of this template and the current remote resources. Exactly one of template_body, template_uri, or private_template must be specified. In the CreateStack API, template_body, template_uri and private_template are optional. Note:
(If a variable is marked as sensitive in the template, its value will be masked in the vars_structure, vars_uri_content, and vars_body fields returned by the GetStackMetadata and GetExecutionPlanMetadata APIs.) Minimum: 0 Maximum: 51200 |
| template_uri | No | String | OBS address of an HCL template. The template describes the target status of a resource. RFS compares the differences between the statuses of this template and the current remote resources. Ensure that the OBS address is located in the same region as the RFS. The corresponding file must be a tf file or a zip package. A pure .tf file must end with .tf or .tf.json and comply with the HCL syntax. Currently, only the .zip package is supported. The file name extension must be .zip. The decompressed file cannot contain the .tfvars file and must be encoded in UTF8 format (the .tf.json file cannot contain the BOM header). The .zip package supports a maximum of 100 subfiles. Exactly one of template_body, template_uri and private_template must be specified. In the CreateStack API, template_body, template_uri and private_template are optional. Note:
(If a variable is marked as sensitive in the template, its value will be masked in the vars_structure, vars_uri_content, and vars_body fields returned by the GetStackMetadata and GetExecutionPlanMetadata APIs.) Minimum: 0 Maximum: 2048 |
| vars_structure | No | Array of VarsStructure objects | HCL variable structure. Transferring variables is supported by the HCL template. The same template can use different variables for different purposes.
Array Length: 0 - 100 |
| vars_body | No | String | Content of the HCL variable file. Transferring variables is supported by the HCL template. The same template can use different variables for different purposes.
Minimum: 0 Maximum: 51200 |
| vars_uri | No | String | OBS address of the HCL variable file. Transferring variables is supported by the HCL template. The same template can use different variables for different purposes. Ensure that the OBS address is located in the same region as the RFS.
Minimum: 0 Maximum: 2048 |
| encrypt_kms_key_id | No | String | The ID of the KMS customer master key (CMK) used to encrypt templates. Currently, only keys using the AES-256 algorithm are supported. If specified, RFS will use this key to encrypt your Terraform templates for storage. Please note that using your own CMK may incur KMS service charges. Important: Exercise caution when deleting this CMK. Deleting a key that is in use will render the associated stacks inaccessible, and you assume all risks associated with this action. Minimum: 36 Maximum: 36 |
| stack_id | No | String | Unique stack ID. It is a UUID generated by RFS when a stack is created. Stack names are unique at one specific time, so you can create a stack named HelloWorld and another stack with the same name after deleting the first one. For parallel development, team members may want to ensure that they are operating the stack they created, not one with the same name created by other members after deleting the previous one. To avoid this mismatch, check the ID, since RFS ensures each stack has a unique ID that does not change with updates. If the stack_id value differs from the current stack ID, 400 is returned. Minimum: 36 Maximum: 36 |
| private_template | No | PrivateTemplate object |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| var_key | Yes | String | Variable name. Minimum: 1 Maximum: 32 |
| var_value | Yes | String | Variable value. Variables must be in the form of a string. If a parameter is a number, it must also be in the form of a string, for example, '10'. For different types or complex structures, you can use vars_uri or vars_body. Minimum: 0 Maximum: 2048 |
| encryption | No | EncryptionStructure object | If a transferred var_value has been encrypted, you can declare this variable to require RFS to decrypt the var_value before using it. Currently, only KMS encryption and decryption are supported. |
| Parameter | Mandatory | Type | Description |
|---|---|---|---|
| kms | Yes | KmsStructure object | If an assigned var_value is encrypted by KMS, related encryption information can be transferred. RFS will help you decrypt the var_value by KMS. For more details about KMS encryption and its sample code, refer to KMS Application Scenarios. Note:
|
Response Parameters
Status code: 202
Status code: 400
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. |
| error_msg | String | Response message. |
Status code: 401
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. |
| error_msg | String | Response message. |
Status code: 403
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. |
| error_msg | String | Response message. |
Status code: 404
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. |
| error_msg | String | Response message. |
Status code: 409
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. |
| error_msg | String | Response message. |
Status code: 429
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. |
| error_msg | String | Response message. |
Status code: 500
| Parameter | Type | Description |
|---|---|---|
| error_code | String | Response code. Minimum: 11 Maximum: 11 |
| error_msg | String | Response message. |
| encoded_authorization_message | String | The message contains information about unauthorized requests. |
| details | Array of Detail objects | Detailed error messages returned by service when permission is denied. |
Example Requests
-
Transfer template and variable information using OBS signed URL.
POST https://{endpoint}/v1/ba2b9930c977f71edaeaa3a5e96a8ff1/stacks/my_hello_world_stack/deployments { "template_uri" : "https://my_hello_world_bucket.{region}.myhuaweicloud.com/my-hello-world-template.tf", "vars_uri" : "https://my_hello_world_bucket.{region}.myhuaweicloud.com/my-hello-world-vars.tfvars", "stack_id" : "1b15e005-bdbb-4bd7-8f9a-a09b6774b4b3" } -
Deploy a stack with private_template
POST https://{endpoint}/v1/ba2b9930c977f71edaeaa3a5e96a8ff1/stacks/my_hello_world_stack/deployments { "private_template" : { "template_id" : "69f8d5ea-eaa4-4a3b-a96d-bae9230e97c9", "template_version" : "V1" } }
Example Responses
Status code: 202
The request is accepted and processed asynchronously.
{
"deployment_id" : "3fef5d3e-27b6-44e8-9769-1d7262bd9430"
} Status Codes
| Status Code | Description |
|---|---|
| 202 | The request is accepted and processed asynchronously. |
| 400 | Invalid request. |
| 401 | Authentication failed. |
| 403 | |
| 404 | The stack does not exist. |
| 409 | Request conflict. Another request is being processed on the current stack. |
| 429 | Too frequent requests. |
| 500 | Internal server error. |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.