RDBMS‐Management‐Guide - cloud-barista/cb-spider GitHub Wiki
RDBMS Management Guide
※ CB-Spider Database Infrastructure Overview
- CB-Spider provides a unified interface for controlling managed Database services across multiple clouds.
- CB-Spider's Database (DB) is divided into RDBMS and NoSQL:
- RDBMS: MySQL, MariaDB, PostgreSQL, etc. — selected via the
DBEnginefield on the RDBMS deployment API - NoSQL: MongoDB, Redis, Cassandra, etc. — planned for future support
- RDBMS: MySQL, MariaDB, PostgreSQL, etc. — selected via the
- DBSpec (Database Spec): provides the instance spec list and info (vCPU, Memory, etc.) required to create a DB instance, regardless of DB type.
- Details: see the DB Spec Info Guide
1. CB-Spider RDBMS Overview
- CB-Spider provides a unified interface for controlling managed RDBMS services across multiple CSPs.
- CB-Spider provides both MySQL (
DBEngine=mysql) and MariaDB (DBEngine=mariadb) as RDBMS engines. - This guide primarily describes the following features centered on the MySQL engine (
DBEngine=mysql):- Retrieve RDBMS meta information such as supported versions, storage options, and capabilities
- Create, get, list, and delete RDBMS instances
- Create, list, and delete databases inside an RDBMS instance
- Register, unregister, and directly delete existing CSP RDBMS instances
- ※ Because some CSPs don't provide standard SQL-based internal database management, CB-Spider inevitably provides an abstracted internal database management API
1.1 Terminology
- DBEngine: A value identifying which DB engine (
mysql,mariadb) CB-Spider supports; most APIs — RDBMS meta information, DBSpec, instances, and more — use this value to identify the target engine. - DBSpec: The DB instance spec information CB-Spider provides per CSP/Region/DBEngine. (e.g.
db.t3.medium) See the DB Spec Info Guide for details such as VCpu, Memory, and Storage size range. - RDBMS instance: A managed database server unit provisioned on a CSP.
- Database: A logical database unit created and managed inside an RDBMS instance.
- RDBMS meta information: CSP-specific capability data used before creating an RDBMS instance, such as supported versions, specs, storage options, and network requirements.
1.2 Target Service and Console per CSP
The actual managed-DB service name and Console link for each CSP that CB-Spider abstracts. For some CSPs the Console varies by project/region context and has no fixed deep link, in which case the login URL plus in-console menu path is shown instead.
| CSP | MySQL | MariaDB | Console |
|---|---|---|---|
| AWS | Amazon RDS (MySQL) | Amazon RDS (MariaDB) | console.aws.amazon.com/rds Databases menu |
| Azure | Azure Database for MySQL – Flexible Server | Not supported | Log in at portal.azure.com and search for "Azure Database for MySQL flexible servers" |
| GCP | Cloud SQL for MySQL | Not supported | console.cloud.google.com/sql/instances |
| Alibaba | ApsaraDB RDS (MySQL) | ApsaraDB RDS (MariaDB) | rdsnext.console.aliyun.com (region-specific path) |
| Tencent | TencentDB for MySQL | TencentDB for MariaDB (not currently supported by CB-Spider) | console.tencentcloud.com/cdb |
| IBM | IBM Cloud Databases for MySQL (Gen1) | Not supported | cloud.ibm.com/databases-overview/resources |
| OpenStack | Horizon Database (MySQL) | Horizon Database (MariaDB) | Horizon: accessible via the Project → Database → Instances menu |
| NCP | Cloud DB for MySQL | Not supported | Log in at console.ncloud.com then Services → Database → Cloud DB for MySQL |
| NHN | RDS for MySQL | RDS for MariaDB | Log in at console.nhncloud.com, select a Project, then Database → RDS for MySQL / Database → RDS for MariaDB |
2. CB-Spider RDBMS Configuration
- RDBMS Pre-check: Verify that the managed RDBMS service is enabled and permissions are configured in the CSP Console
- NHN:
RDS for MySQLandRDS for MariaDBare separate services and must each be activated per project
- NHN:
- RDBMS Credentials: Obtain the required credentials for each CSP
- Most CSPs share the same credentials used for VM/network management (no extra step needed)
- NHN: Separate RDS-specific credentials are required
- RDBMS Credential Registration: RDBMS credentials must be added to CB-Spider Connection's Credential information
-
CSPs where existing Credentials are identical and no additional RDBMS credentials are needed
[AWS/Azure/GCP/Alibaba/Tencent/IBM/OpenStack/NCP] -
CSPs where additional RDBMS credentials need to be added to existing Credentials
[NHN][NHN] ... existing Credential information ... {"Key": "User Access Key", "Value": "WWWW"}, {"Key": "Secret Access Key", "Value": "XXXX"}, {"Key": "mysqlAppKey", "Value": "YYYY"}, {"Key": "mariadbAppKey", "Value": "ZZZZ"}
-
3. RDBMS Configuration Components
-
The main input fields for creating an RDBMS instance are:
- Basic identity: Name, ConnectionName
- Engine:
DBEngine=mysql|mariadb, DBEngineVersion (format differs per CSP) - Spec and storage: DBSpec, StorageSize, StorageType (optional)
- Network: VPCName, SubnetNames (required by some CSPs), SecurityGroupNames (requirement and behavior differ by CSP — see 10.5)
- Authentication: MasterUserName, MasterUserPassword
- Access and operation options: PublicAccess, HighAvailability, DeletionProtection, BackupRetentionDays
-
RDBMS status values (RDBMSStatus):
- Creating, Available, Deleting, Stopped, Error
3.1 Looking up DBSpec information
- The
DBSpecvalue (e.g.db.t3.medium) is provided per CSP/Region/DBEngine through CB-Spider's dedicated DB Spec lookup API (GET /spider/dbspec,GET /spider/dbspec/{Name}), which also exposes each DB Spec's VCpu (Count/ClockGHz), MemSizeMiB, and StorageSizeRangeGB (the storage size range you may request when creating an instance with that spec). - Before creating an RDBMS instance, it's recommended to first query this API to see which DBSpecs are available for the target CSP/Region/DBEngine and what resources each one provides.
- For details (API specification, response fields, examples), see the DB Spec Info Guide.
4. MySQL Coverage and Validation Status
4.1 Core Functionality Validation (based on test/rdbms-mysql-test)
- The MySQL create/get/delete workflow is validated through the multi-CSP test scripts in
test/rdbms-mysql-test. - Default test instance name:
cb-spider-mysql-test - For detailed test procedures and environment setup, see: rdbms-mysql-test README
| CSP | MySQL Version | Example Spec | Example Storage | Network Note |
|---|---|---|---|---|
| AWS | 8.0 | db.t3.medium | 100GB | Requires 2 subnets in different AZs, Security Group required |
| Azure | 8.0.21 | Standard_B1ms | 20GB | Subnet not used when PublicAccess=true (default), required when false — see 10.7 |
| GCP | 8.0 | db-custom-2-8192 | 20GB | Subnet not used |
| Alibaba | 8.0 | mysql.n4.large.1 | 20GB | Subnet required |
| Tencent | 8.0 | 8000 (MB) | 50GB | Subnet required, SecurityGroup optional |
| IBM | 8.4 | multitenant | 30GB | Subnet not used |
| OpenStack | 5.7.29 | m1.small | 20GB | Subnet not used |
| NCP | 8.0.36 | SVR.VDBAS... | CSP-managed | Subnet required |
| NHN | MYSQL_V8408 | m2.c2m4 | 20GB | Subnet required |
4.2 Per-CSP StorageType Validation (based on test/storage-type-test)
- A parallel test suite that validates each CSP-specific
StorageTypevalue by actually creating an instance with it. - Azure, IBM, and NCP are excluded (SKIP) since all three have
SupportsStorageTypeSelection=false. - For detailed test procedures and environment setup, see: storage-type-test README
| CSP | Validated StorageType values | Notes |
|---|---|---|
| AWS | gp2, gp3, io1, io2, standard | io1/io2 require the Iops field (min. 3000) and a minimum StorageSize of 100GB |
| GCP | PD_SSD, PD_HDD, HYPERDISK_BALANCED | Determined automatically by machine series (N2/C4A/N4, etc.), not specified directly |
| Alibaba | cloud_auto, cloud_essd, cloud_essd2, cloud_essd3, local_ssd | essd2/3 require a minimum of 500GB/1500GB and a different spec; local_ssd is only for the rds.mysql.* spec family |
| Tencent | local_ssd, CLOUD_HSSD, CLOUD_SSD, CLOUD_PREMIUM | - |
| OpenStack | __DEFAULT__, RBD | StorageType isn't exposed via the API after creation (validated by reaching Available instead) |
| NHN | General HDD, General SSD | - |
| Azure | (not selectable) | SupportsStorageTypeSelection=false — storageSku is set automatically by Azure (read-only) |
| IBM | (not selectable) | SupportsStorageTypeSelection=false — IBM Cloud Databases has no storage type/media selection at all; only StorageSize and DBSpec (host_flavor) are configurable |
| NCP | (not selectable) | SupportsStorageTypeSelection=false — G3 always applies SSD automatically |
4.3 Database Management inside RDBMS Instance (based on test/database-test)
- A parallel test suite that validates CreateDatabase / ListDatabases / DeleteDatabase inside a running RDBMS instance across all 9 CSPs.
- Runs against the instance created by
run-all-csp-rdbms-tests.sh. Each test createsspidertestdb, verifies it appears in the list, then deletes it and verifies removal. - For detailed test procedures and environment setup, see: database-test README
| CSP | Implementation | Notes |
|---|---|---|
| AWS | SQL fallback | Direct SQL (CREATE/DROP DATABASE) via MasterUserPassword |
| Azure | CSP-native API | Azure MySQL Flexible Server SDK |
| GCP | CSP-native API | Google Cloud SQL Admin API |
| Alibaba | CSP-native API | Alibaba Cloud RDS SDK |
| Tencent | CSP-native API | Tencent Cloud MySQL SDK |
| IBM | SQL fallback | Direct SQL via MasterUserPassword |
| OpenStack | CSP-native API | OpenStack Trove API |
| NCP | CSP-native API | NCP Cloud MySQL/PostgreSQL API |
| NHN | CSP-native API | NHN Cloud RDS API |
4.4 RDBMS Tag Management (based on test/tag-test)
- A parallel test suite that validates AddTag / ListTag / GetTag / RemoveTag on RDBMS instances.
- Only CSPs where
RDBMSMetaInfo.SupportsTag=trueare included; the remaining 3 CSPs are excluded. - For detailed test procedures and environment setup, see: tag-test README
| CSP | SupportsTag | Notes |
|---|---|---|
| AWS | true |
✅ included |
| Azure | true |
✅ included |
| GCP | true |
✅ included |
| Alibaba | true |
✅ included |
| Tencent | true |
✅ included |
| IBM | true |
✅ included |
| OpenStack | false |
excluded |
| NCP | false |
excluded |
| NHN | false |
excluded |
5. MariaDB Coverage and Validation Status
- MariaDB-supported CSPs: AWS, Alibaba, OpenStack, NHN
- Tencent: Tencent's own documentation lists a MariaDB offering, but API calls return a "not supported" error (needs re-verification)
- MariaDB-unsupported CSPs: Azure, GCP, IBM, NCP
5.1 Core Functionality Validation (based on test/rdbms-mariadb-test)
- The MariaDB create/get/delete workflow is validated through the multi-CSP test scripts in
test/rdbms-mariadb-test. - Default test instance name:
cb-spider-mariadb-test - For detailed test procedures and environment setup, see: rdbms-mariadb-test README
| CSP | MariaDB Version | Example Spec | Example Storage | Network Note |
|---|---|---|---|---|
| AWS | 10.6 (returned as 10.6.27) | db.t3.medium | 100GB | Requires 2 subnets in different AZs, Security Group required |
| Alibaba | 10.6 | mariadb.n2.medium.2c (queried dynamically from MetaInfo; falls back to rds.mariadb.s4.large if the query fails) | 20GB | Subnet required |
| OpenStack | 10.4 | m1.small | 20GB | Subnet not used |
| NHN | MARIADB_V101118 |
m2.c2m4 | 20GB | Subnet required |
5.2 Per-CSP StorageType Validation (based on test/rdbms-mariadb-test/storage-type-test)
- A parallel test suite that validates each CSP-specific
StorageTypevalue by actually creating an instance with it. - For detailed test procedures and environment setup, see: storage-type-test README
| CSP | Validated StorageType values | Notes |
|---|---|---|
| AWS | gp2, gp3, io1, io2 | io1/io2 require the Iops field (min. 3000) — same constraint as MySQL |
| Alibaba | cloud_essd, cloud_essd2, cloud_essd3 | essd2/essd3 require a minimum StorageSize of 500GB/1500GB respectively |
| OpenStack | __DEFAULT__, RBD | Trove does not expose StorageType after creation (judged as PASS when Available) |
| NHN | General HDD, General SSD | - |
5.3 Database Management inside RDBMS Instance (based on test/rdbms-mariadb-test/database-test)
- A parallel test suite that validates CreateDatabase / ListDatabases / DeleteDatabase inside a running MariaDB instance.
- For detailed test procedures and environment setup, see: database-test README
| CSP | Implementation | Notes |
|---|---|---|
| AWS | SQL fallback | Direct SQL (CREATE/DROP DATABASE) via MasterUserPassword |
| Alibaba | CSP-native API | Alibaba Cloud RDS SDK |
| OpenStack | CSP-native API | OpenStack Trove API |
| NHN | CSP-native API | Same as MySQL |
5.4 RDBMS Tag Management (based on test/rdbms-mariadb-test/tag-test)
- A parallel test suite that validates AddTag / ListTag / GetTag / RemoveTag on MariaDB instances.
- Only CSPs where
SupportsTag=trueand MariaDB is supported are included. - For detailed test procedures and environment setup, see: tag-test README
| CSP | MariaDB Support | SupportsTag | Included in Tag Test |
|---|---|---|---|
| AWS | ✅ | true |
✅ |
| Alibaba | ✅ | true |
✅ |
| OpenStack | ⚠️ (not provisioned / not tested) | false |
❌ (excluded by SupportsTag) |
| NHN | ✅ | false |
❌ (excluded by SupportsTag) |
6. CB-Spider RDBMS Instance Management API
- The following APIs are used under the
/spiderbase path and apply to bothmysqlandmariadb, — simply set theDBEnginevalue accordingly in the request. - Reference: Swagger guide (Swagger-Guide)
6.1 RDBMS Meta Information
GET /spider/rdbmsmetainfo - Get RDBMS MetaInfo (ConnectionName, DBEngine)
6.2 Basic RDBMS Instance Management
POST /spider/rdbms - Create RDBMS
GET /spider/rdbms?ConnectionName={conn} - List RDBMS
GET /spider/rdbms/{Name}?ConnectionName={conn} - Get RDBMS
DELETE /spider/rdbms/{Name} - Delete RDBMS (requires ConnectionName in body)
6.3 Database Management Inside an RDBMS Instance
GET /spider/rdbms/{Name}/databases - List Databases
POST /spider/rdbms/{Name}/databases - Create Database
DELETE /spider/rdbms/{Name}/databases/{DBName} - Delete Database
6.4 Registration and Extended Management for Existing RDBMS
POST /spider/regrdbms - Register existing CSP RDBMS
DELETE /spider/regrdbms/{Name} - Unregister RDBMS
DELETE /spider/csprdbms/{Id} - Delete CSP RDBMS directly
GET /spider/getrdbmsowner - Get owner VPC by CSP RDBMS ID
GET /spider/allrdbms - List all RDBMS (CB-Spider/CSP/mapped)
GET /spider/allrdbmsinfo - List all RDBMS info
GET /spider/countrdbms - Count all RDBMS
GET /spider/countrdbms/{ConnectionName} - Count RDBMS by connection
6.5 Checking Client-Side Secure (TLS) Connection
GET /spider/rdbms/{Name}/secure-transport - Get secure transport status (require_secure_transport, TLS in use, CA certificate)
- Reports the target instance's
require_secure_transportsetting, whether TLS is actually in use, and a live-captured CA certificate. - Also checks the server certificate's Subject Alternative Name (SAN) presence and reports the strongest usable SSL mode directly via
RecommendedSSLMode(DISABLED/VERIFY_CA/VERIFY_IDENTITY). - For how to connect safely from the
mysqlCLI or an application using this certificate (VERIFY_CA/VERIFY_IDENTITYmodes), see the Guide to Secure Connection to CB-Spider RDBMS.
7. Key Request and Response Fields
7.1 Main Fields in the MetaInfo Response (RDBMSMetaInfo)
| Field | Description |
|---|---|
| DBEngine | Requested DB engine |
| SupportedVersions | List of supported engine versions |
| DBSpecOptions | List of available instance specs |
| StorageTypeOptions | List of available storage types |
| StorageSizeRangeGB | Storage size range (Min/Max) in decimal GB (10⁹ bytes). Converted from the CSP's native unit when it is objectively known to be binary (GiB) — see 10.2; left unconverted, with a DataSourceNotes caveat, when the native unit can't be confirmed |
| SupportsHighAvailability | Whether HA can be configured |
| SupportsBackup | Whether managed automatic backup is supported |
| BackupRetentionRange | Backup retention range configurable at creation time |
| SupportsPublicAccess | Whether public access can be toggled |
| SupportsDeletionProtection | Whether deletion protection can be configured |
| SupportsEncryption | Whether storage encryption is supported |
| SupportsStorageTypeSelection | Whether StorageType can be specified at creation |
| SupportsStorageSizeConfiguration | Whether StorageSize can be specified at creation |
| RequiresSubnet | Whether SubnetNames is required at creation |
| RequiresSecurityGroup | Whether SecurityGroupNames is required at creation — see 10.5 for actual per-CSP behavior |
| SupportsTag | Whether tagging is supported for RDBMS resources (true: AWS, Azure, GCP, Alibaba, Tencent, IBM / false: NCP, NHN, OpenStack). Fixed per CSP — the same value applies whether DBEngine is mysql or mariadb. |
| DataSource (optional) | Marked "Static" when the value's source is not a CSP API resultApplies to: SupportedVersions, DBSpecOptions, StorageTypeOptions, StorageSizeRangeGB, StorageSizeRangeGB.Min, StorageSizeRangeGB.Max |
| DataSourceNotes (optional) | Reason why DataSource is "Static" |
Example response (NCP, MySQL — some fields are Static)
{
"DBEngine": "mysql",
"SupportedVersions": ["8.0.36"],
"DBSpecOptions": ["SVR.VDBAS.AMD.STAND.C002.M008.NET.SSD.B050.G003"],
"StorageTypeOptions": ["NA"],
"StorageSizeRangeGB": { "Min": 10, "Max": 6000 },
"SupportsHighAvailability": true,
"SupportsBackup": true,
"SupportsPublicAccess": false,
"SupportsDeletionProtection": true,
"SupportsEncryption": false,
"SupportsStorageTypeSelection": false,
"SupportsStorageSizeConfiguration": false,
"RequiresSubnet": true,
"RequiresSecurityGroup": false,
"SupportsTag": false,
"DataSource": {
"StorageTypeOptions": "Static",
"StorageSizeRangeGB": "Static"
},
"DataSourceNotes": {
"StorageTypeOptions": "NCP G3 generation sets storage type (SSD) automatically; not user-selectable or queryable via API.",
"StorageSizeRangeGB": "NCP has no storage-size query API; range shown (10-6000GB) is a known approximation, not authoritative. No unit conversion is applied because the value is not derived from any CSP-reported unit."
}
}
In this example, SupportedVersions and DBSpecOptions have no entry in DataSource, so they are live API values, while StorageTypeOptions and StorageSizeRangeGB are "Static" reference values. See 10. CSP-Specific Notes for which fields go Static for which CSP, and why.
7.2 Main Fields in RDBMS Instance Create Request (RDBMSCreateRequest.ReqInfo)
| Field | Description | Example |
|---|---|---|
| Name | RDBMS instance name | cb-spider-mysql-test |
| VPCName | Target VPC name | vpc-01 |
| DBEngine | DB engine | mysql |
| DBEngineVersion | Engine version | 8.0 |
| DBSpec | Instance spec (see the DB Spec Info Guide for details) | db.t3.medium |
| StorageSize | Storage size (GB) | 100 |
| StorageType | Storage type (optional) | gp2 |
| SubnetNames | List of subnets (required by some CSPs; for Azure this depends on PublicAccess — see 10.7) | [subnet-01, subnet-02] |
| SecurityGroupNames | List of security groups (required by some CSPs; see 10.5 for actual per-CSP behavior) | [sg-01] |
| MasterUserName | Admin username | myadmin |
| MasterUserPassword | Admin password | Password123! |
| PublicAccess | Whether public access is enabled | true |
| NHNAutoOpenDBSecurityGroup | (NHN only, optional) when set together with PublicAccess=true, auto-creates and attaches a fully-open DB Security Group. See 10.6 |
false |
| HighAvailability | Whether HA is enabled | false |
| DeletionProtection | Whether deletion protection is enabled | false |
| BackupRetentionDays | Backup retention days (optional) | 7 |
| Iops | Provisioned IOPS (used by some storage types) | 3000 |
7.3 Main Fields in RDBMS Instance Get Response (RDBMSInfo)
| Field | Description |
|---|---|
| IId (NameId, SystemId) | User-defined name and CSP system ID |
| Status | Creating/Available/Deleting/Stopped/Error |
| Endpoint, Port | DB connection endpoint and port |
| DBEngine, DBEngineVersion | Engine and version |
| DBSpec | Instance spec (see the DB Spec Info Guide for details) |
| StorageSize, StorageType | Storage size and type |
| PublicAccess | Public access setting |
| VpcIID, SubnetIIDs, SecurityGroupIIDs | Network identity information |
| KeyValueList | CSP-specific extended information |
8. Recommended RDBMS Instance Operation Flow
This flow applies equally to both mysql and mariadb requests; only the CSP coverage differs.
- Retrieve RDBMS Meta Information
- Use
/spider/rdbmsmetainfoto check supported versions,StorageTypeOptions,RequiresSubnet, andRequiresSecurityGroupfor the target CSP. - Do not include
StorageType/StorageSizein the create request for a CSP whereSupportsStorageTypeSelection/SupportsStorageSizeConfigurationisfalse. - A field marked
"Static"inDataSourceis a reference/fixed value, not a live CSP value — re-check the CSP console/CLI if you need the current authoritative number.
- Build the Create Request
- Set the required fields in
ReqInfo:Name,DBEngine,DBEngineVersion,DBSpec,MasterUserName,MasterUserPassword,StorageSize, andVPCName. - Add
SubnetNamesandSecurityGroupNamesif required by the CSP.
- Create and Poll Status
- Call
POST /spider/rdbms, then repeatedly callGET /spider/rdbms/{Name}?ConnectionName=.... - Wait until the instance reaches the abstracted CB-Spider status
Available.
- Get or List Instances
- Get one:
GET /spider/rdbms/{Name}?ConnectionName=... - List all in a connection:
GET /spider/rdbms?ConnectionName=...
- Manage Databases Inside the RDBMS
- Use the database list/create/delete APIs.
- Depending on the CSP/driver implementation path,
MasterUserPasswordmay additionally be required — Create/Delete (POST/DELETE) take it in the request body, List (GET) takes it via theX-Master-User-Passwordheader.
- Delete the Instance
- Call
DELETE /spider/rdbms/{Name}withConnectionNamein the request body. - Poll until the instance is fully removed.
9. API Examples (RDBMS instance)
9.1 Get MetaInfo
curl -u admin:your-secure-password -sX GET \
"http://localhost:1024/spider/rdbmsmetainfo?ConnectionName=aws-config01&DBEngine=mysql" | jq
9.2 Create MySQL (AWS example)
curl -u admin:your-secure-password -sX POST http://localhost:1024/spider/rdbms \
-H 'Content-Type: application/json' \
-d '{
"ConnectionName": "aws-config01",
"ReqInfo": {
"Name": "cb-spider-mysql-test",
"VPCName": "vpc-01",
"DBEngine": "mysql",
"DBEngineVersion": "8.0",
"DBSpec": "db.t3.medium",
"StorageSize": "100",
"SubnetNames": ["subnet-01", "subnet-02"],
"SecurityGroupNames": ["sg-01"],
"MasterUserName": "myadmin",
"MasterUserPassword": "Password123!",
"PublicAccess": true
}
}' | jq
9.3 Create MariaDB (AWS example)
curl -u admin:your-secure-password -sX POST http://localhost:1024/spider/rdbms \
-H 'Content-Type: application/json' \
-d '{
"ConnectionName": "aws-config01",
"ReqInfo": {
"Name": "cb-spider-mariadb-test",
"VPCName": "vpc-01",
"DBEngine": "mariadb",
"DBEngineVersion": "10.6",
"DBSpec": "db.t3.medium",
"StorageSize": "100",
"SubnetNames": ["subnet-01", "subnet-02"],
"SecurityGroupNames": ["sg-01"],
"MasterUserName": "myadmin",
"MasterUserPassword": "Password123!",
"PublicAccess": true
}
}' | jq
9.4 Get RDBMS Instance
curl -u admin:your-secure-password -sX GET \
"http://localhost:1024/spider/rdbms/cb-spider-mysql-test?ConnectionName=aws-config01" | jq
9.5 Create, List, and Delete a Database
# Create Database
curl -u admin:your-secure-password -sX POST \
http://localhost:1024/spider/rdbms/cb-spider-mysql-test/databases \
-H 'Content-Type: application/json' \
-d '{
"ConnectionName": "aws-config01",
"DatabaseName": "mydb",
"MasterUserPassword": "Password123!"
}' | jq
# List Databases
curl -u admin:your-secure-password -sX GET \
"http://localhost:1024/spider/rdbms/cb-spider-mysql-test/databases?ConnectionName=aws-config01" \
-H "X-Master-User-Password: Password123!" | jq
# Delete Database
curl -u admin:your-secure-password -sX DELETE \
http://localhost:1024/spider/rdbms/cb-spider-mysql-test/databases/mydb \
-H 'Content-Type: application/json' \
-d '{
"ConnectionName": "aws-config01",
"MasterUserPassword": "Password123!"
}' | jq
9.6 Delete RDBMS Instance
curl -u admin:your-secure-password -sX DELETE \
http://localhost:1024/spider/rdbms/cb-spider-mysql-test \
-H 'Content-Type: application/json' \
-d '{"ConnectionName": "aws-config01"}' | jq
10. CSP-Specific Notes (MetaInfo / Creation Caveats)
This section collects the issues that most often trip up API users when customizing an RDBMS create request per CSP. Always check /spider/rdbmsmetainfo for the target CSP before building a create request.
10.1 MetaInfo fields returned as fixed values (DataSource: "Static")
| CSP | Field | Notes |
|---|---|---|
| Azure | StorageTypeOptions | Always ["NA"] — Azure sets the storage type automatically; not queryable or selectable via API |
| GCP | StorageSizeRangeGB.Min | Always fixed at 10GB (only Max comes from the live Cloud SQL Tiers API) |
| Tencent | StorageTypeOptions | The live query result always has "local_ssd" added to it |
| IBM | DBSpecOptions | A statically maintained list of host_flavor IDs (no live query API exists) |
| IBM | StorageTypeOptions | Always ["NA"] — IBM Cloud Databases has no storage type/media selection via its API |
| NHN | StorageSizeRangeGB | Always fixed at 20-2048GB — applies to both mysql and mariadb requests |
| OpenStack | StorageSizeRangeGB.Min | Always fixed at 1GB |
| OpenStack | StorageSizeRangeGB.Max | Shown as -1 when the project has no configured Cinder volume quota (unlimited) — this is a sentinel, not a real numeric upper bound, so don't treat it as one |
| OpenStack, NCP | DBSpecOptions | May come back as an empty list ([]) if the spec-list API call fails |
| NCP | StorageTypeOptions, StorageSizeRangeGB | Always fixed (["NA"], 10-6000GB for reference only) |
Every other CSP/field combination is a live CSP API value.
10.2 Storage size unit conversion (StorageSizeRangeGB)
StorageSizeRangeGB is always expressed in decimal GB (10⁹ bytes). Since each CSP's underlying API reports storage limits in its own native unit, CB-Spider converts to decimal GB only when that native unit is objectively confirmed to be binary (GiB, 2³⁰ bytes), using a GiBToGB() helper; otherwise the value is passed through unconverted.
StorageSizeRangeGB values reported per CSP
- Based on RDBMS MetaInfo API runs, driver source analysis, and official CSP documentation
- ※
GB (unit unconfirmed, no conversion)cases are planned for further verification and improvement — related issue: #1820
| CSP | StorageSizeRangeGB (observed) | How obtained (source analysis) | Unit conversion (source analysis) | DataSource |
|---|---|---|---|---|
| AWS | Min: 5, Max: 70369 | API | GiB->GB | API |
| Azure | Min: 21, Max: 35184 | API | MiB->GB | API |
| GCP | Min: 10, Max: 70369 | Min: Static / Max: API | Min: GB (unit unconfirmed, no conversion) / Max: GiB->GB | StorageSizeRangeGB, .Min: Static |
| Alibaba | Min: 5, Max: 64000 | API | GB (unit unconfirmed, no conversion)⚠️ | API |
| Tencent | Min: 20, Max: 30000 | API | GB (unit unconfirmed, no conversion)⚠️ | API |
| IBM | Min: 32, Max: 13194 | API | MiB->GB | API |
| NCP | Min: 10, Max: 6000 | Static | GB (unit unconfirmed, no conversion) | StorageSizeRangeGB: Static |
| NHN | Min: 20, Max: 2048 | Static | GB (unit unconfirmed, no conversion) | StorageSizeRangeGB: Static |
| OpenStack | Min: 1, Max: -1 | Min: Static / Max: API | Min: GB (unit unconfirmed, no conversion) / Max: GB (unit unconfirmed, no conversion) | StorageSizeRangeGB: Min: Static / Max: API |
- Source baseline: CB-Spider v0.13.1-4
- DataSource: how the value returned by the Spider API was obtained
- Static: a fixed value CB-Spider hardcodes based on documentation analysis, since no API is available
- GB (unit unconfirmed, no conversion): the native unit (binary vs. decimal) could not be objectively confirmed
- ⚠️ Alibaba/Tencent: the RDS/CDB API documentation itself only states "GB," but both CSPs state elsewhere — for their other storage services (Alibaba OSS/Block Storage, Tencent's official Free Tier guide) — that "storage is measured in binary units." Since this isn't an explicit statement about RDS, CB-Spider currently exposes the value as-is, unconverted.
- OpenStack's Max
DataSource="API"reflects the common case where a Cinder quota is actually configured. As in this run (openstack-config01), when no quota is configured, the driver returns-1(an "unlimited" sentinel) for.Max.
10.3 MasterUserPassword policy differs per CSP
For most CSPs, CB-Spider does not validate the password format itself — it passes the password straight through to the CSP API. Since each CSP enforces its own rules, check the error message (message field) returned on a failed create call and adjust the password accordingly.
Example: a password containing
!or@will fail on IBM, while NCP requires at least one special character.
10.4 IBM Cloud Databases: Gen1 / Gen2 platform
IBM Cloud Databases offers two separate infrastructure platforms per the IBM Cloud console: Gen1 (original platform, all regions, public + private endpoints) and Gen2 (newer platform, available only in select regions, private endpoints only). CB-Spider provisions Gen1 only.
10.5 CSP-Specific SecurityGroup Requirements and Behavior
Whether the create request's SecurityGroupNames field is required, and what it actually does, varies significantly by CSP. Check both the RequiresSecurityGroup MetaInfo field and the table below before creating an instance.
| CSP | RequiresSecurityGroup | Behavior |
|---|---|---|
| AWS | true |
Required. Shares the same VPC Security Group resource used by VMs (EC2) — the SG(s) named in SecurityGroupNames are attached to the RDS instance as-is. |
| Tencent | false |
Optional. If provided, shares the same VPC Security Group resource used by VMs (CVM) — the SG(s) named in SecurityGroupNames are attached to the RDS instance as-is. |
| Alibaba, Azure, GCP, IBM, NCP, OpenStack, NHN | false |
Ignored. The driver never reads this field, so any value in SecurityGroupNames is silently dropped with no error or log. There's no need to include it in the create request for these CSPs. |
Note on NHN: NHN Cloud RDS actually requires a separate "DB Security Group" (an RDS-only resource in its own API namespace, completely distinct from the VPC Security Group) for any external SQL access. This resource is not managed through CB-Spider's
SecurityGroupNamesfield — as the table above shows, it's always ignored. Instead, NHN Cloud offers a dedicated NHN-only field,NHNAutoOpenDBSecurityGroup, for this — see 10.6.
10.6 NHN NHNAutoOpenDBSecurityGroup option
RDBMSCreateRequest.ReqInfo.NHNAutoOpenDBSecurityGroup (bool, default false) is an NHN Cloud RDS-only convenience option.
true+PublicAccess=true: CB-Spider auto-creates a fully-open (0.0.0.0/0) DB Security Group at instance creation and attaches it to the instance. It is automatically deleted when the instance is deleted.true+PublicAccess=false: an invalid combination — the create request is rejected withNHNAutoOpenDBSecurityGroup requires PublicAccess=true.- Not set (default
false): no DB Security Group is created at all — the same "ignored" behavior described in 10.5. If you need external SQL access, create and attach a DB Security Group yourself via the NHN console/API.
"ReqInfo": {
...
"PublicAccess": true,
"NHNAutoOpenDBSecurityGroup": true
}
⚠️ Security note: a DB Security Group created via this option allows connections to the DB port from anywhere on the internet (
0.0.0.0/0) — anyone with the master credentials can connect. Use this only for quick tests/development; for production, configure a DB Security Group restricted to specific CIDRs yourself via the NHN console/API.
10.7 Azure's SubnetNames requirement depends on PublicAccess
Azure Database for MySQL Flexible Server does not use SubnetNames unconditionally — it only uses it when PublicAccess=false (VPC-private mode).
| PublicAccess | SubnetNames |
|---|---|
true (default) |
Ignored — has no effect even if provided |
false |
Required — omitting it causes the create request to be rejected |
A subnet supplied with PublicAccess=false gets delegated exclusively to the Azure MySQL Flexible Server and can no longer be shared with VMs or other resources.