Endpoint

/v1/object-portal/bridges/

GET

Lists every bridge on the cluster with its full configuration. A bridge appears as soon as its creation commits, before the quorum restart that joins its filesystem. A cluster with no bridges answers with an empty list, whatever its license or storage layout. Bridges are listed in filesystem UUID order. The list is not paginated. A bridge whose configuration or mount point cannot be read fails the whole call with HTTP 500. No credential material is ever returned.

Parameters

This resource has no parameters.

Response

Codes

Code Description
200 Return value on success

Schema

{
  "description": "api_object_bridges",
  "type": "object",
  "properties": {
    "entries": {
      "type": "array",
      "items": {
        "description": "Every bridge on the cluster, in filesystem id order.",
        "type": "object",
        "properties": {
          "filesystem_uuid": {
            "description": "Filesystem UUID of the bridge",
            "type": "string"
          },
          "mount_path": {
            "description": "Absolute path in the primary filesystem where the bridge is mounted, written without a trailing slash.",
            "type": "string"
          },
          "bucket_uri": {
            "description": "Full URI of the bridge's bucket.",
            "type": "string"
          },
          "key_prefix": {
            "description": "Prefix inside the bucket the bridge serves. Absent when the bridge serves the whole bucket.",
            "type": "string"
          },
          "delimiter": {
            "description": "Object-key separator the bridge projects directories from.",
            "type": "string"
          },
          "key_vault_hostname": {
            "description": "Azure Key Vault hostname the bridge fetches SAS tokens from. Absent unless the bucket is reached through a key vault.",
            "type": "string"
          },
          "notification_queue_url": {
            "description": "Queue URL the bridge polls for bucket-side change notifications. Absent when the bridge has none.",
            "type": "string"
          },
          "protocol_access": {
            "type": "string",
            "enum": [
              "READ_WRITE_EXPORT",
              "READ_ONLY"
            ],
            "description": "Whether protocol front doors may change the bridge filesystem's data and namespace.:\n * `READ_ONLY` - BRIDGE_PROTOCOL_READ_ONLY,\n * `READ_WRITE_EXPORT` - BRIDGE_PROTOCOL_READ_WRITE_EXPORT"
          },
          "metadata_import": {
            "type": "string",
            "enum": [
              "OFF",
              "AUTO"
            ],
            "description": "Whether the bridge imports file-mover object metadata onto its inodes.:\n * `AUTO` - BRIDGE_METADATA_IMPORT_AUTO,\n * `OFF` - BRIDGE_METADATA_IMPORT_OFF"
          }
        }
      }
    }
  }
}

POST

Creates a bridge filesystem rooted at the given external bucket prefix. Requires a license whose `object_bridges` level permits the requested mode or, on a Qumulo-managed Azure cluster, a `key_vault_hostname` naming the cluster's own key vault, an arrangement Qumulo operations sets up. Without either the call returns HTTP 404; a license that permits only READ_ONLY bridges refuses a READ_WRITE_EXPORT one with HTTP 403. A bucket that holds one of the cluster's own object stores, or a Qumulo account's managed container reached through the cluster's vault, is refused with HTTP 409. A cluster that already holds `fs_bridge_max_count` bridges refuses the create with HTTP 409. The bridge sends no credentials of its own, or SAS tokens when `key_vault_hostname` names a vault.

Parameters

This resource has no parameters.

Request

Schema

{
  "description": "api_object_bridge_request",
  "type": "object",
  "properties": {
    "bucket_uri": {
      "description": "Full URI for the bucket. Examples: https://my-bucket.s3.us-west-2.amazonaws.com/ or https://myaccount.blob.core.windows.net/my-container",
      "type": "string"
    },
    "mount_path": {
      "description": "Absolute path in the primary filesystem where the bridge will be mounted. The parent directory must already exist; the basename is created during bridge creation and becomes the bridge's mount point.",
      "type": "string"
    },
    "key_prefix": {
      "description": "Optional prefix inside the bucket, matched against object keys as it is written. Must end with the delimiter. An empty prefix is refused; omit the field to bridge the whole bucket.",
      "type": "string"
    },
    "delimiter": {
      "description": "Object-key separator used to project bridge directories. Required and must be non-empty.",
      "type": "string"
    },
    "key_vault_hostname": {
      "description": "Azure Key Vault hostname (e.g. my-vault.vault.azure.net) from which to fetch SAS tokens for an Azure Blob bucket. Required for Azure buckets; omit for an AWS bucket.",
      "type": "string"
    },
    "notification_queue_url": {
      "description": "Optional SQS queue URL for bucket-side change notifications on an AWS S3 bucket. When set, qfsd long-polls this queue and routes events into the bridge fs. Refused unless it has the form https://sqs.<region>.amazonaws.com/<account>/<queue>.",
      "type": "string"
    },
    "protocol_access": {
      "type": "string",
      "enum": [
        "READ_WRITE_EXPORT",
        "READ_ONLY"
      ],
      "description": "READ_ONLY stops protocol front doors from changing the bridge filesystem's data or namespace; file attributes stay writable and internal convergence still writes. READ_WRITE_EXPORT leaves both writable and requires the backing bucket to have versioning enabled. Required; immutable after creation.:\n * `READ_ONLY` - BRIDGE_PROTOCOL_READ_ONLY,\n * `READ_WRITE_EXPORT` - BRIDGE_PROTOCOL_READ_WRITE_EXPORT"
    },
    "metadata_import": {
      "type": "string",
      "enum": [
        "OFF",
        "AUTO"
      ],
      "description": "Selects import of file-mover object metadata (ownership, permissions, ACLs, timestamps, DOS attributes) onto bridge inodes. AUTO translates each object matching a known mover dialect; OFF inherits everything from the parent directory with no per-object metadata reads. Required; immutable after creation.:\n * `AUTO` - BRIDGE_METADATA_IMPORT_AUTO,\n * `OFF` - BRIDGE_METADATA_IMPORT_OFF"
    }
  }
}

Response

Codes

Code Description
201 Return value on success