3 =================================================================
4 radosgw-admin -- rados REST gateway user administration utility
5 =================================================================
7 .. program:: radosgw-admin
12 | **radosgw-admin** *command* [ *options* *...* ]
18 :program:`radosgw-admin` is a RADOS gateway user administration utility. It
19 allows creating and modifying users.
25 :program:`radosgw-admin` utility uses many commands for administration purpose
28 :command:`user create`
31 :command:`user modify`
35 Display information of a user, and any potentially available
38 :command:`user rename`
44 :command:`user suspend`
47 :command:`user enable`
48 Re-enable user after suspension.
54 Show user stats as accounted by quota subsystem.
60 Add user capabilities.
63 Remove user capabilities.
65 :command:`subuser create`
66 Create a new subuser (primarily useful for clients using the Swift API).
68 :command:`subuser modify`
80 :command:`bucket list`
81 List buckets, or, if bucket specified with --bucket=<bucket>,
82 list its objects. If bucket specified adding --allow-unordered
83 removes ordering requirement, possibly generating results more
84 quickly in buckets with large number of objects.
86 :command:`bucket limit check`
87 Show bucket sharding stats.
89 :command:`bucket link`
90 Link bucket to specified user.
92 :command:`bucket unlink`
93 Unlink bucket from specified user.
95 :command:`bucket chown`
96 Link bucket to specified user and update object ACLs.
97 Use --marker to resume if command gets interrupted.
99 :command:`bucket stats`
100 Returns bucket statistics.
105 :command:`bucket check`
108 :command:`bucket rewrite`
109 Rewrite all objects in the specified bucket.
111 :command:`bucket radoslist`
112 List the rados objects that contain the data for all objects is
113 the designated bucket, if --bucket=<bucket> is specified, or
114 otherwise all buckets.
116 :command:`bucket reshard`
119 :command:`bucket sync disable`
122 :command:`bucket sync enable`
126 Retrieve bucket index object entries.
129 Store bucket index object entries.
132 List raw bucket index entries.
135 Purge bucket index entries.
140 :command:`object stat`
141 Stat an object for its metadata.
143 :command:`object unlink`
144 Unlink object from bucket index.
146 :command:`object rewrite`
147 Rewrite the specified object.
149 :command:`objects expire`
150 Run expired objects cleanup.
155 :command:`period get`
158 :command:`period get-current`
159 Get the current period info.
161 :command:`period pull`
164 :command:`period push`
167 :command:`period list`
170 :command:`period update`
171 Update the staging period.
173 :command:`period commit`
174 Commit the staging period.
179 :command:`quota enable`
182 :command:`quota disable`
185 :command:`global quota get`
186 View global quota parameters.
188 :command:`global quota set`
189 Set global quota parameters.
191 :command:`global quota enable`
192 Enable a global quota.
194 :command:`global quota disable`
195 Disable a global quota.
197 :command:`realm create`
206 :command:`realm get-default`
207 Get the default realm name.
209 :command:`realm list`
212 :command:`realm list-periods`
213 List all realm periods.
215 :command:`realm rename`
219 Set the realm info (requires infile).
221 :command:`realm default`
222 Set the realm as default.
224 :command:`realm pull`
225 Pull a realm and its current period.
227 :command:`zonegroup add`
228 Add a zone to a zonegroup.
230 :command:`zonegroup create`
231 Create a new zone group info.
233 :command:`zonegroup default`
234 Set the default zone group.
236 :command:`zonegroup rm`
237 Remove a zone group info.
239 :command:`zonegroup get`
240 Show the zone group info.
242 :command:`zonegroup modify`
243 Modify an existing zonegroup.
245 :command:`zonegroup set`
246 Set the zone group info (requires infile).
248 :command:`zonegroup remove`
249 Remove a zone from a zonegroup.
251 :command:`zonegroup rename`
254 :command:`zonegroup list`
255 List all zone groups set on this cluster.
257 :command:`zonegroup placement list`
258 List zonegroup's placement targets.
260 :command:`zonegroup placement add`
261 Add a placement target id to a zonegroup.
263 :command:`zonegroup placement modify`
264 Modify a placement target of a specific zonegroup.
266 :command:`zonegroup placement rm`
267 Remove a placement target from a zonegroup.
269 :command:`zonegroup placement default`
270 Set a zonegroup's default placement target.
272 :command:`zone create`
279 Show zone cluster params.
282 Set zone cluster params (requires infile).
284 :command:`zone modify`
285 Modify an existing zone.
288 List all zones set on this cluster.
290 :command:`metadata sync status`
291 Get metadata sync status.
293 :command:`metadata sync init`
296 :command:`metadata sync run`
299 :command:`data sync status`
300 Get data sync status of the specified source zone.
302 :command:`data sync init`
303 Init data sync for the specified source zone.
305 :command:`data sync run`
306 Run data sync for the specified source zone.
308 :command:`sync error list`
311 :command:`sync error trim`
314 :command:`zone rename`
317 :command:`zone placement list`
318 List zone's placement targets.
320 :command:`zone placement add`
321 Add a zone placement target.
323 :command:`zone placement modify`
324 Modify a zone placement target.
326 :command:`zone placement rm`
327 Remove a zone placement target.
330 Add an existing pool for data placement.
333 Remove an existing pool from data placement set.
335 :command:`pools list`
336 List placement active set.
339 Display bucket/object policy.
345 Dump a log from specific object or (bucket + date + bucket-id).
346 (NOTE: required to specify formatting of date to "YYYY-MM-DD-hh")
351 :command:`usage show`
352 Show the usage information (with optional user and date range).
354 :command:`usage trim`
355 Trim usage information (with optional user and date range).
358 Dump expired garbage collection objects (specify --include-all to list all
359 entries, including unexpired).
361 :command:`gc process`
362 Manually process garbage.
365 List all bucket lifecycle progress.
367 :command:`lc process`
368 Manually process lifecycle. If a bucket is specified (e.g., via
369 --bucket_id or via --bucket and optional --tenant), only that bucket
372 :command:`metadata get`
375 :command:`metadata put`
378 :command:`metadata rm`
379 Remove metadata info.
381 :command:`metadata list`
384 :command:`mdlog list`
385 List metadata log which is needed for multi-site deployments.
387 :command:`mdlog trim`
388 Trim metadata log manually instead of relying on RGWs integrated log sync.
389 Before trimming, compare the listings and make sure the last sync was
390 complete, otherwise it can reinitiate a sync.
392 :command:`mdlog status`
393 Read metadata log status.
395 :command:`bilog list`
396 List bucket index log which is needed for multi-site deployments.
398 :command:`bilog trim`
399 Trim bucket index log (use start-marker, end-marker) manually instead
400 of relying on RGWs integrated log sync.
401 Before trimming, compare the listings and make sure the last sync was
402 complete, otherwise it can reinitiate a sync.
404 :command:`datalog list`
405 List data log which is needed for multi-site deployments.
407 :command:`datalog trim`
408 Trim data log manually instead of relying on RGWs integrated log sync.
409 Before trimming, compare the listings and make sure the last sync was
410 complete, otherwise it can reinitiate a sync.
412 :command:`datalog status`
413 Read data log status.
415 :command:`orphans find`
416 Init and run search for leaked rados objects.
417 DEPRECATED. See the "rgw-orphan-list" tool.
419 :command:`orphans finish`
420 Clean up search for leaked rados objects.
421 DEPRECATED. See the "rgw-orphan-list" tool.
423 :command:`orphans list-jobs`
424 List the current job-ids for the orphans search.
425 DEPRECATED. See the "rgw-orphan-list" tool.
427 :command:`role create`
428 create a new AWS role for use with STS.
437 List the roles with specified path prefix.
439 :command:`role modify`
440 Modify the assume role policy of an existing role.
442 :command:`role-policy put`
443 Add/update permission policy to role.
445 :command:`role-policy list`
446 List the policies attached to a role.
448 :command:`role-policy get`
449 Get the specified inline policy document embedded with the given role.
451 :command:`role-policy rm`
452 Remove the policy attached to a role
454 :command:`reshard add`
455 Schedule a resharding of a bucket
457 :command:`reshard list`
458 List all bucket resharding or scheduled to be resharded
460 :command:`reshard process`
461 Process of scheduled reshard jobs
463 :command:`reshard status`
464 Resharding status of a bucket
466 :command:`reshard cancel`
467 Cancel resharding a bucket
469 :command:`topic list`
470 List bucket notifications/pubsub topics
473 Get a bucket notifications/pubsub topic
476 Remove a bucket notifications/pubsub topic
478 :command:`subscription get`
479 Get a pubsub subscription definition
481 :command:`subscription rm`
482 Remove a pubsub subscription
484 :command:`subscription pull`
485 Show events in a pubsub subscription
487 :command:`subscription ack`
488 Ack (remove) an events in a pubsub subscription
494 .. option:: -c ceph.conf, --conf=ceph.conf
496 Use ``ceph.conf`` configuration file instead of the default
497 ``/etc/ceph/ceph.conf`` to determine monitor addresses during
500 .. option:: -m monaddress[:port]
502 Connect to specified monitor (instead of looking through ceph.conf).
504 .. option:: --tenant=<tenant>
508 .. option:: --uid=uid
512 .. option:: --new-uid=uid
514 ID of the new user. Used with 'user rename' command.
516 .. option:: --subuser=<name>
520 .. option:: --access-key=<key>
524 .. option:: --email=email
526 The e-mail address of the user.
528 .. option:: --secret/--secret-key=<key>
532 .. option:: --gen-access-key
534 Generate random access key (for S3).
536 .. option:: --gen-secret
538 Generate random secret key.
540 .. option:: --key-type=<type>
542 key type, options are: swift, s3.
544 .. option:: --temp-url-key[-2]=<key>
548 .. option:: --max-buckets
550 max number of buckets for a user (0 for no limit, negative value to disable bucket creation).
553 .. option:: --access=<access>
555 Set the access permissions for the sub-user.
556 Available access permissions are read, write, readwrite and full.
558 .. option:: --display-name=<name>
560 The display name of the user.
564 Set the admin flag on the user.
568 Set the system flag on the user.
570 .. option:: --bucket=[tenant-id/]bucket
572 Specify the bucket name. If tenant-id is not specified, the tenant-id
573 of the user (--uid) is used.
575 .. option:: --pool=<pool>
577 Specify the pool name.
578 Also used with `orphans find` as data pool to scan for leaked rados objects.
580 .. option:: --object=object
582 Specify the object name.
584 .. option:: --date=yyyy-mm-dd
586 The date in the format yyyy-mm-dd.
588 .. option:: --start-date=yyyy-mm-dd
590 The start date in the format yyyy-mm-dd.
592 .. option:: --end-date=yyyy-mm-dd
594 The end date in the format yyyy-mm-dd.
596 .. option:: --bucket-id=<bucket-id>
598 Specify the bucket id.
600 .. option:: --bucket-new-name=[tenant-id/]<bucket>
602 Optional for `bucket link`; use to rename a bucket.
603 While tenant-id/ can be specified, this is never
604 necessary for normal operation.
606 .. option:: --shard-id=<shard-id>
608 Optional for mdlog list, bi list, data sync status. Required for ``mdlog trim``.
610 .. option:: --max-entries=<entries>
612 Optional for listing operations to specify the max entries.
614 .. option:: --purge-data
616 When specified, user removal will also purge all the user data.
618 .. option:: --purge-keys
620 When specified, subuser removal will also purge all the subuser keys.
622 .. option:: --purge-objects
624 When specified, the bucket removal will also purge all objects in it.
626 .. option:: --metadata-key=<key>
628 Key to retrieve metadata from with ``metadata get``.
630 .. option:: --remote=<remote>
632 Zone or zonegroup id of remote gateway.
634 .. option:: --period=<id>
638 .. option:: --url=<url>
640 url for pushing/pulling period or realm.
642 .. option:: --epoch=<number>
648 Commit the period during 'period update'.
650 .. option:: --staging
652 Get the staging period info.
658 .. option:: --master-zone=<id>
662 .. option:: --rgw-realm=<name>
666 .. option:: --realm-id=<id>
670 .. option:: --realm-new-name=<name>
674 .. option:: --rgw-zonegroup=<name>
678 .. option:: --zonegroup-id=<id>
682 .. option:: --zonegroup-new-name=<name>
684 The new name of the zonegroup.
686 .. option:: --rgw-zone=<zone>
688 Zone in which radosgw is running.
690 .. option:: --zone-id=<id>
694 .. option:: --zone-new-name=<name>
696 The new name of the zone.
698 .. option:: --source-zone
700 The source zone for data sync.
702 .. option:: --default
704 Set the entity (realm, zonegroup, zone) as default.
706 .. option:: --read-only
708 Set the zone as read-only when adding to the zonegroup.
710 .. option:: --placement-id
712 Placement id for the zonegroup placement commands.
714 .. option:: --tags=<list>
716 The list of tags for zonegroup placement add and modify commands.
718 .. option:: --tags-add=<list>
720 The list of tags to add for zonegroup placement modify command.
722 .. option:: --tags-rm=<list>
724 The list of tags to remove for zonegroup placement modify command.
726 .. option:: --endpoints=<list>
730 .. option:: --index-pool=<pool>
732 The placement target index pool.
734 .. option:: --data-pool=<pool>
736 The placement target data pool.
738 .. option:: --data-extra-pool=<pool>
740 The placement target data extra (non-ec) pool.
742 .. option:: --placement-index-type=<type>
744 The placement target index type (normal, indexless, or #id).
746 .. option:: --tier-type=<type>
750 .. option:: --tier-config=<k>=<v>[,...]
752 Set zone tier config keys, values.
754 .. option:: --tier-config-rm=<k>[,...]
756 Unset zone tier config keys.
758 .. option:: --sync-from-all[=false]
760 Set/reset whether zone syncs from all zonegroup peers.
762 .. option:: --sync-from=[zone-name][,...]
764 Set the list of zones to sync from.
766 .. option:: --sync-from-rm=[zone-name][,...]
768 Remove the zones from list of zones to sync from.
770 .. option:: --bucket-index-max-shards
772 Override a zone's or zonegroup's default number of bucket index shards. This
773 option is accepted by the 'zone create', 'zone modify', 'zonegroup add',
774 and 'zonegroup modify' commands, and applies to buckets that are created
775 after the zone/zonegroup changes take effect.
779 Besides checking bucket index, will also fix it.
781 .. option:: --check-objects
783 bucket check: Rebuilds bucket index according to actual objects state.
785 .. option:: --format=<format>
787 Specify output format for certain operations. Supported formats: xml, json.
789 .. option:: --sync-stats
791 Option for 'user stats' command. When specified, it will update user stats with
792 the current stats reported by user's buckets indexes.
794 .. option:: --show-config
798 .. option:: --show-log-entries=<flag>
800 Enable/disable dump of log entries on log show.
802 .. option:: --show-log-sum=<flag>
804 Enable/disable dump of log summation on log show.
806 .. option:: --skip-zero-entries
808 Log show only dumps entries that don't have zero value in one of the numeric
813 Specify a file to read in when setting data.
815 .. option:: --categories=<list>
817 Comma separated list of categories, used in usage show.
819 .. option:: --caps=<caps>
821 List of caps (e.g., "usage=read, write; user=read").
823 .. option:: --compression=<compression-algorithm>
825 Placement target compression algorithm (lz4|snappy|zlib|zstd)
827 .. option:: --yes-i-really-mean-it
829 Required for certain operations.
831 .. option:: --min-rewrite-size
833 Specify the min object size for bucket rewrite (default 4M).
835 .. option:: --max-rewrite-size
837 Specify the max object size for bucket rewrite (default ULLONG_MAX).
839 .. option:: --min-rewrite-stripe-size
841 Specify the min stripe size for object rewrite (default 0). If the value
842 is set to 0, then the specified object will always be
843 rewritten for restriping.
845 .. option:: --warnings-only
847 When specified with bucket limit check,
848 list only buckets nearing or over the current max objects per shard value.
850 .. option:: --bypass-gc
852 When specified with bucket deletion,
853 triggers object deletions by not involving GC.
855 .. option:: --inconsistent-index
857 When specified with bucket deletion and bypass-gc set to true,
858 ignores bucket index consistency.
860 .. option:: --max-concurrent-ios
862 Maximum concurrent ios for bucket operations. Affects operations that
863 scan the bucket index, e.g., listing, deletion, and all scan/search
864 operations such as finding orphans or checking the bucket index.
870 .. option:: --max-objects
872 Specify max objects (negative value to disable).
874 .. option:: --max-size
876 Specify max size (in B/K/M/G/T, negative value to disable).
878 .. option:: --quota-scope
880 The scope of quota (bucket, user).
883 Orphans Search Options
884 ======================
886 .. option:: --num-shards
888 Number of shards to use for keeping the temporary scan info
890 .. option:: --orphan-stale-secs
892 Number of seconds to wait before declaring an object to be an orphan.
893 Default is 86400 (24 hours).
897 Set the job id (for orphans find)
900 Orphans list-jobs options
901 =========================
903 .. option:: --extra-info
905 Provide extra info in the job list.
911 .. option:: --role-name
913 The name of the role to create.
917 The path to the role.
919 .. option:: --assume-role-policy-doc
921 The trust relationship policy document that grants an entity permission to
924 .. option:: --policy-name
926 The name of the policy document.
928 .. option:: --policy-doc
930 The permission policy document.
932 .. option:: --path-prefix
934 The path prefix for filtering the roles.
937 Bucket Notifications/PubSub Options
938 ===================================
941 The bucket notifications/pubsub topic name.
943 .. option:: --subscription
945 The pubsub subscription name.
947 .. option:: --event-id
949 The event id in a pubsub subscription.
955 Generate a new user::
957 $ radosgw-admin user create --display-name="johnny rotten" --uid=johnny
958 { "user_id": "johnny",
960 "display_name": "johnny rotten",
966 "access_key": "TCICW53D9BQ2VGC46I44",
967 "secret_key": "tfm9aHMI8X76L3UdgE+ZQaJag1vJQmE6HDb5Lbrz"}],
972 $ radosgw-admin user rm --uid=johnny
976 $ radosgw-admin user rename --uid=johny --new-uid=joe
978 Remove a user and all associated buckets with their contents::
980 $ radosgw-admin user rm --uid=johnny --purge-data
984 $ radosgw-admin bucket rm --bucket=foo
986 Link bucket to specified user::
988 $ radosgw-admin bucket link --bucket=foo --bucket_id=<bucket id> --uid=johnny
990 Unlink bucket from specified user::
992 $ radosgw-admin bucket unlink --bucket=foo --uid=johnny
996 $ radosgw-admin bucket link --bucket=foo --bucket-new-name=bar --uid=johnny
998 Move a bucket from the old global tenant space to a specified tenant::
1000 $ radosgw-admin bucket link --bucket=/foo --uid=12345678$12345678'
1002 Link bucket to specified user and change object ACLs::
1004 $ radosgw-admin bucket chown --bucket=/foo --uid=12345678$12345678'
1006 Show the logs of a bucket from April 1st, 2012::
1008 $ radosgw-admin log show --bucket=foo --date=2012-04-01-01 --bucket-id=default.14193.1
1010 Show usage information for user from March 1st to (but not including) April 1st, 2012::
1012 $ radosgw-admin usage show --uid=johnny \
1013 --start-date=2012-03-01 --end-date=2012-04-01
1015 Show only summary of usage information for all users::
1017 $ radosgw-admin usage show --show-log-entries=false
1019 Trim usage information for user until March 1st, 2012::
1021 $ radosgw-admin usage trim --uid=johnny --end-date=2012-04-01
1027 :program:`radosgw-admin` is part of Ceph, a massively scalable, open-source,
1028 distributed storage system. Please refer to the Ceph documentation at
1029 https://docs.ceph.com for more information.
1035 :doc:`ceph <ceph>`\(8)
1036 :doc:`radosgw <radosgw>`\(8)