Huawei DeleteItem

Huawei DeleteItem

Certified

Delete a GeminiDB (DynamoDB-compatible) item by key

Deletes a single item using the provided primary key; no condition expression is applied.

Authenticate with the instance's database account — accessKeyId: rwuser and the instance admin password as secretAccessKey. Huawei IAM AK/SK credentials are not accepted by the DynamoDB-compatible data plane.

yaml
type: io.kestra.plugin.huawei.geminidb.DeleteItem

Delete an item by its key

yaml
id: geminidb_delete_item
namespace: company.team

tasks:
  - id: delete_item
    type: io.kestra.plugin.huawei.geminidb.DeleteItem
    accessKeyId: rwuser
    secretAccessKey: "{{ secret('GEMINIDB_ADMIN_PASSWORD') }}"
    endpoint: "http://192.168.0.10:8000"
    tableName: persons
    key:
      id: "1"
Properties

GeminiDB instance connection address

The DynamoDB-compatible API endpoint of the GeminiDB for NoSQL instance, e.g. http://192.168.0.10: 8000. Find it under Connections on the instance's console page. Unlike other Huawei Cloud services, this address is per-instance and cannot be derived from region.

The data-plane port is 8000 and is fixed: it cannot be chosen at creation or changed afterwards (a high-availability port 80 is also documented). Do not use 8635 — that is the Cassandra/CQL port of the underlying kernel and does not speak the DynamoDB protocol.

region is used only for SigV4 request signing and does not affect routing — GeminiDB routes solely by this endpoint property; leave region at its default unless signing requires a specific value.

Item key

Full primary key map (partition key, plus sort key when the table defines one).

Table name

Target GeminiDB (DynamoDB-compatible) table for the operation.

GeminiDB database account username

The DynamoDB-compatible data plane authenticates against the instance's own database account, not Huawei IAM — set this to the fixed database username rwuser. Sensitive — always provide via {{ secret('NAME') }}.

Huawei Cloud Account Domain ID

Identifies the Huawei Cloud account (domain). Required when authenticating against global services such as IAM, or when requesting a domain-scoped IAM token.

Reference (ref) of the pluginDefaults to apply to this task.

Huawei Cloud Project ID

Identifies the region-scoped project against which most regional services authenticate. Mutually exclusive with domainId for global services such as IAM.

Huawei Cloud region

Region identifier such as eu-west-101, ap-southeast-1, or cn-north-4.

GeminiDB database account password

The instance admin password set when the GeminiDB instance was purchased — it cannot be retrieved later, only reset. Paired with accessKeyId: rwuser. Sensitive — always provide via {{ secret('NAME') }}.

Not supported by GeminiDB

GeminiDB's DynamoDB-compatible data plane never consults Huawei IAM, so a security token (or an inline temporaryCredentials exchange) has nothing to authenticate against. Setting either causes the task to fail fast with an actionable error instead of the opaque AccessDeniedException: auth failed a real GeminiDB instance would otherwise return. Use accessKeyId/secretAccessKey instead.

Inline IAM credential exchange

When set, the connection layer calls the Huawei IAM STS API once per task execution and uses the returned temporary AK/SK + security token instead of the static accessKeyId and secretAccessKey properties.

Configure once via pluginDefaults to apply transparently to every task in a namespace without per-task credential wiring:

pluginDefaults: 
  - type: io.kestra.plugin.huawei.obs
    values: 
      region: eu-west-101
      temporaryCredentials: 
        authMethod: PASSWORD
        username: my-iam-user
        password: "{{ secret('HUAWEI_IAM_PASSWORD') }}"
        domainName: my-account-domain
        durationSeconds: 3600

**Long-running tasks: ** the exchange runs once at execution start. For RealtimeTrigger or long-running Consume tasks that outlive durationSeconds, credentials will expire mid-run. Use long-lived AK/SK properties or refresh externally in that case.

Definitions
authMethodstring
DefaultPASSWORD
Possible Values
PASSWORDTOKEN

Authentication method

Controls which credentials are used to obtain the session token before exchanging for temporary STS credentials.

  • PASSWORD (default): provide username, password, and domainName.
  • TOKEN: provide an existing iamToken (X-Auth-Token).
domainNamestring

Account domain name (PASSWORD method only)

The Huawei Cloud account name (domain name) that owns the IAM user. Required when authMethod is PASSWORD. Visible in the Huawei Cloud console under My Credentials → Domain Name.

durationSecondsintegerstring
Default900

Lifetime of the temporary credentials in seconds

How long the returned temporary AK/SK/security-token should remain valid. Huawei Cloud accepts values between 900 (15 minutes) and 86400 (24 hours). Defaults to 900 seconds.

endpointSuffixstring
Defaultmyhuaweicloud.com

Huawei Cloud IAM endpoint suffix

Domain suffix used to build the IAM endpoint URL when no explicit endpoint override is set. Defaults to myhuaweicloud.com. Set to myhuaweicloud.eu for the European sovereign cloud (region eu-west-101 / EU-Dublin).

iamTokenstring

IAM token to exchange (TOKEN method only)

An existing Huawei Cloud X-Auth-Token to exchange for temporary STS credentials. Required when authMethod is TOKEN. Sensitive — always provide via {{ secret('NAME') }}.

passwordstring

IAM password (PASSWORD method only)

Password for the IAM user identified by username. Required when authMethod is PASSWORD. Sensitive — always provide via {{ secret('NAME') }}.

projectNamestring

Project name for project-scoped tokens (PASSWORD method only)

Overrides the project name used for scope=PROJECT token requests. Defaults to the task's region value when omitted, which is correct for most regions.

scopestring
DefaultPROJECT
Possible Values
PROJECTDOMAIN

Token scope (PASSWORD method only)

Scope of the session token obtained during password authentication.

  • PROJECT (default): token is scoped to the project matching projectName (or the task's region when projectName is omitted). Use for most downstream tasks.
  • DOMAIN: token is scoped to the domain.
usernamestring

IAM username (PASSWORD method only)

Huawei Cloud IAM username. Required when authMethod is PASSWORD.