Ceph CreateUser

Ceph CreateUser

Certified

Create an RGW user

Calls POST /api/rgw/user and returns the resulting user, including the generated S3 access keys. The secret key is returned only at creation time and is encrypted in the outputs.

yaml
type: io.kestra.plugin.ceph.rgw.CreateUser

Create an RGW user

yaml
id: create_rgw_user
namespace: company.team

tasks:
  - id: create_user
    type: io.kestra.plugin.ceph.rgw.CreateUser
    host: "ceph-mgr.internal"
    username: "admin"
    password: "{{ secret('CEPH_DASHBOARD_PASSWORD') }}"
    uid: "svc-backups"
    displayName: "Backup service account"
    email: "backups@company.team"
Properties

Display name

Human-readable name for the user.

Ceph Dashboard host

Hostname or IP address of the Ceph Manager Dashboard. Must be reachable from the Kestra worker.

User ID

Unique identifier for the new RGW user.

Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.

Definitions
assetFailureBehaviorstring
Possible Values
IGNOREFAILWARN

Asset failure behavior

Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.

enableAutobooleanstring

Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.

inputsarray

The assets consumed as inputs.

id*string
Min length1
typestring
outputs

The assets produced as outputs.

id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*string
Min length1

Custom asset type

descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150

Email

Optional contact email for the user.

Password

Password for the Ceph Dashboard account. Never logged. Required unless token is set; ignored otherwise.

Default8443

Ceph Dashboard port

TCP port of the Ceph Manager Dashboard REST API. Defaults to 8443.

Defaultfalse

Skip TLS certificate verification

When true, disables TLS certificate verification. Useful when the Ceph Manager Dashboard uses a self-signed certificate, which is the default on most Ceph deployments. Defaults to false (secure): enable it explicitly and only for trusted networks.

Pre-obtained JWT

A JWT obtained from POST /api/auth, used directly instead of username/password. Reused as-is for every request in the execution. It expires (Ceph default 8h TTL) and is NOT auto-renewed, so do not use it in triggers or scheduled flows; use username/password there instead. Mutually exclusive with password: when set, username/password are ignored.

Username

Ceph Dashboard account used to obtain a session token from POST /api/auth. Required unless token is set.

Display name

Human-readable name of the user.

Email

Contact email of the user, if set.

S3 access keys

S3 credentials Ceph generated for the user. Creating the user is the only point at which the secret key is returned.

Definitions
accessKeystring

Access key

S3 access key ID for the user.

secretKeystring

Secret key

S3 secret access key, encrypted in the outputs. Reference it directly to feed another task, or store it in a secret; avoid logging it.

User ID

Unique identifier of the RGW user.