CLI Command Reference
Key Lifecycle Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Creating a Key | hcloud KMS CreateKey | This API is used to create a CMK, which can be symmetric or asymmetric. | |
| Enabling a Key | hcloud KMS EnableKey | ||
| Disabling a Key | hcloud KMS DisableKey | ||
| Scheduling Key Deletion | hcloud KMS DeleteKey | ||
| Canceling Scheduled Key Deletion | hcloud KMS CancelKeyDeletion | ||
| Modifying a Key Alias | hcloud KMS UpdateKeyAlias | ||
| Modifying Key Description | hcloud KMS UpdateKeyDescription |
DEK Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Generating a Random Number | hcloud KMS CreateRandom | ||
| Creating a DEK | hcloud KMS CreateDatakey | ||
| Creating a Plaintext-free DEK | hcloud KMS CreateDatakeyWithoutPlaintext | ||
| Create a data key pair for rsa algorithm. | hcloud KMS CreateRsaDatakeyPair | ||
| Create a data key pair for ec algorithm. | hcloud KMS CreateEcDatakeyPair | ||
| Creating a PIN | hcloud KMS CreatePin | This API is used to create a PIN, which is used to create and encrypt a DEK in the level-4 cryptography testing scenario. | |
| Encrypting a DEK | hcloud KMS EncryptDatakey | ||
| Decrypting a DEK | hcloud KMS DecryptDatakey |
Key Import Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Obtaining Key Import Parameters | hcloud KMS CreateParametersForImport | ||
| Importing Key Materials | hcloud KMS ImportKeyMaterial | ||
| Deleting Key Materials | hcloud KMS DeleteImportedKeyMaterial | ||
| On-demand Key Rotation | hcloud KMS RotateOnDemand | This API is used to import key materials for external keys. You need to import the key materials before performing rotation. |
Key Authorization Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Creating a Grant | hcloud KMS CreateGrant | ||
| Revoking a Grant | hcloud KMS CancelGrant | ||
| Retiring a Grant | hcloud KMS CancelSelfGrant | ||
| Querying the Grant List | hcloud KMS ListGrants | ||
| Querying Retirable Grants | hcloud KMS ListRetirableGrants |
Small-size Data Encryption and Decryption
Signature and Verification
| API Name | Command | Description | Operation |
|---|---|---|---|
| Signing Data | hcloud KMS Sign | ||
| Authenticating a Signature | hcloud KMS ValidateSignature |
Key Agreement
| API Name | Command | Description | Operation |
|---|---|---|---|
| Deriving a Shared Key | hcloud KMS DeriveSharedSecret |
Key Rotation Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Enabling Key Rotation | hcloud KMS EnableKeyRotation | ||
| Disabling Key Rotation | hcloud KMS DisableKeyRotation | ||
| Modifying the Key Rotation Interval | hcloud KMS UpdateKeyRotationInterval | ||
| Querying Key Rotation Status | hcloud KMS ShowKeyRotationStatus |
Key Tag Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying Key Instances | hcloud KMS ListKmsByTags | ||
| Querying Key Tags | hcloud KMS ShowKmsTags | ||
| Adding Tags to a Key | hcloud KMS CreateKmsTag | ||
| Querying Project Tags | hcloud KMS ListKmsTags | ||
| Batch Adding or Deleting Key Tags | hcloud KMS BatchCreateKmsTags | ||
| Deleting Key Tags | hcloud KMS DeleteTag |
Key Query
| API Name | Command | Description | Operation |
|---|---|---|---|
| Querying the Key List | hcloud KMS ListKeys | ||
| Querying Key Details | hcloud KMS ListKeyDetail | ||
| Querying a Public Key | hcloud KMS ShowPublicKey | ||
| Querying the Instance Quantity | hcloud KMS ShowUserInstances | ||
| Querying Quota | hcloud KMS ShowUserQuotas |
Key API Version Query
Dedicated Keystore Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Creating a Dedicated Keystore | hcloud KMS CreateKeyStore | ||
| Obtaining the Dedicated Keystore List | hcloud KMS ListKeyStores | This API is used to query a user's dedicated keystore list. | |
| Obtaining a Dedicated Keystore | hcloud KMS ShowKeyStore | This API is used to obtain a dedicated keystore. | |
| Deleting a Dedicated Keystore | hcloud KMS DeleteKeyStore | This API is used to delete a dedicated keystore. | |
| Enabling a Dedicated Keystore | hcloud KMS EnableKeyStore | This API is used to enable a dedicated keystore. | |
| Disabling a Dedicated Keystore | hcloud KMS DisableKeyStore | This API is used to disable a dedicated keystore. |
Mutil-Region keys
| API Name | Command | Description | Operation |
|---|---|---|---|
| Update the primary region of a key. | hcloud KMS UpdatePrimaryRegion | Update the primary region to which the key belongs. After the changing, the current region becomes a replica region. | |
| Replicating a key to a specified region | hcloud KMS ReplicateKey | Replicating a key to a specified region. | |
| Querying the regions supported by the mutil-region key function. | hcloud KMS ListSupportRegions | Querying the regions supported by the mutil-region key function. |
Message Authentication Code
Alias Management
| API Name | Command | Description | Operation |
|---|---|---|---|
| Associating Key Alias | hcloud KMS AssociateAlias | Associate an alias. | |
| Querying the Alias Associated with a Key | hcloud KMS ListAliases | Obtain all aliases associated to a key. | |
| Creating a Key Alias | hcloud KMS CreateAlias | Create an alias. | |
| Deleting a Key Alias | hcloud KMS DeleteAlias | Delete an alias. |
Key Space
| API Name | Command | Description | Operation |
|---|---|---|---|
| Creating an Access Point | hcloud KMS CreateAccessPoint | This API is used to create an access point. | |
| Obtaining the Access Point List | hcloud KMS ListAccessPoint | This API is used to query an access point. | |
| Enabling an Access Point | hcloud KMS EnableAccessPoint | This API is used to enable an access point. | |
| Disabling an Access Point | hcloud KMS DisableAccessPoint | This API is used to disable an access point. | |
| Deleting an Access Point | hcloud KMS DeleteAccessPoint | This API is used to delete an access point. | |
| Downloading an custom access point private key | hcloud KMS DownloadAccessPointPrivateKey | This API is used to download an custom access point private key | |
| Creating a Key Policy | hcloud KMS CreateKeyPolicy | This API is used to create a key policy. | |
| Obtaining the Key Policy List | hcloud KMS ListKeyPolicy | This API is used to obtain the key policy list. | |
| Querying a Key Policy | hcloud KMS ShowKeyPolicy | This API is used to query a key policy. | |
| Deleting a Key Policy | hcloud KMS DeleteKeyPolicy | This API is used to delete a key policy. | |
| Updating a Key Policy | hcloud KMS UpdateKeyPolicy | This API is used to update a key policy. | |
| Creating a Key Capsule | hcloud KMS CreateDatakeyCapsule | This API is used to create a key capsule. | |
| Decrypting a Key Capsule | hcloud KMS DecryptDatakeyCapsule | This API is used to decrypt a key capsule. |
Small-size data encryption and decryption
| API Name | Command | Description | Operation |
|---|---|---|---|
| Re-encryption | hcloud KMS ReEncrypt | Decrypt the ciphertext using the source key and then use a specified key for encryption. |
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot