REST Resource: recoverableSnapshots

Resource: RecoverableSnapshot

Represents a RecoverableSnapshot resource.

A RecoverableSnapshot represents a snapshot in recycle bin.

JSON representation
{
  "kind": string,
  "id": string,
  "name": string,
  "description": string,
  "creationTimestamp": string,
  "purgeTimestamp": string,
  "status": enum,
  "originalResource": {
    "deletionTimestamp": string,
    "id": string,
    "creationTimestamp": string,
    "name": string,
    "description": string,
    "sourceDisk": string,
    "sourceDiskId": string,
    "diskSizeGb": string,
    "storageBytes": string,
    "storageBytesStatus": enum,
    "licenses": [
      string
    ],
    "snapshotEncryptionKey": {
      "sha256": string,
      "kmsKeyServiceAccount": string,

      
      "rawKey": string,
      "rsaEncryptedKey": string,
      "kmsKeyName": string
      
    },
    "sourceDiskEncryptionKey": {
      "sha256": string,
      "kmsKeyServiceAccount": string,

      
      "rawKey": string,
      "rsaEncryptedKey": string,
      "kmsKeyName": string
      
    },
    "selfLink": string,
    "selfLinkWithId": string,
    "labels": {
      string: string,
      ...
    },
    "labelFingerprint": string,
    "licenseCodes": [
      string
    ],
    "storageLocations": [
      string
    ],
    "autoCreated": boolean,
    "guestOsFeatures": [
      {
        "type": enum
      }
    ],
    "downloadBytes": string,
    "chainName": string,
    "satisfiesPzs": boolean,
    "sourceSnapshotSchedulePolicy": string,
    "sourceSnapshotSchedulePolicyId": string,
    "sourceInstantSnapshot": string,
    "sourceInstantSnapshotId": string,
    "architecture": enum,
    "snapshotType": enum,
    "creationSizeBytes": string,
    "maxRetentionDays": integer,
    "enableConfidentialCompute": boolean,
    "sourceDiskForRecoveryCheckpoint": string,
    "sourceInstantSnapshotEncryptionKey": {
      "sha256": string,
      "kmsKeyServiceAccount": string,

      
      "rawKey": string,
      "rsaEncryptedKey": string,
      "kmsKeyName": string
      
    },
    "region": string,
    "satisfiesPzi": boolean,
    "snapshotGroupName": string,
    "snapshotGroupId": string
  },
  "satisfiesPzs": boolean,
  "satisfiesPzi": boolean,
  "selfLink": string,
  "selfLinkWithId": string
}
Fields
kind

string

Output only. Type of the resource. Always compute#recoverableSnapshot for RecoverableSnapshot resources.

id

string (uint64 format)

Output only. The unique identifier for the resource. This identifier is defined by the server.

name

string

Output only. Identifier. Name of the recoverable snapshot generated on the deletion of the snapshot. The name will be 1-63 characters long, and comply with RFC1035. Specifically, the name will be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character will be a lowercase letter, and all following characters can be a dash, lowercase letter, or digit, except the last character, which cannot be a dash.

description

string

Optional. An optional description of this resource.

creationTimestamp

string

Output only. Creation timestamp in RFC3339 text format.

purgeTimestamp

string

Output only. Purge timestamp of recoverable snapshot in RFC3339 text format.

status

enum

Output only. Status of the recoverable snapshot.

originalResource

object

Output only. Output Only] The original snapshot resource.

originalResource.deletionTimestamp

string

Output only. Deletion timestamp of snapshot in RFC3339 text format.

originalResource.id

string (uint64 format)

Output only. The unique identifier for the original snapshot. This identifier is defined by the server.

originalResource.creationTimestamp

string

Output only. Creation timestamp in RFC3339 text format.

originalResource.name

string

Name of the original snapshot provided by the client. The name must be 1-63 characters long, and comply with RFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash.

originalResource.description

string

An optional description of this resource.

originalResource.sourceDisk

string

The source disk used to create this snapshot.

originalResource.sourceDiskId

string

Output only. The ID value of the disk used to create this snapshot

originalResource.diskSizeGb

string (int64 format)

Output only. Size of the source disk, specified in GB.

originalResource.storageBytes

string (int64 format)

Output only. A size of the storage used by the snapshot.

originalResource.storageBytesStatus

enum

Output only. [Deprecated] Instead, check the storageBytes field. After snapshot creation, the storageBytesStatus field is always UP_TO_DATE. Output only. An indicator whether storageBytes is in a stable state or it is being adjusted as a result of shared storage reallocation. This status can either be unset, meaning the snapshot is being created, or UP_TO_DATE, meaning the size of the snapshot is up-to-date.

originalResource.licenses[]

string

Output only. A list of public visible licenses that apply to this snapshot.

originalResource.snapshotEncryptionKey

object

Encrypts the snapshot using a customer-supplied encryption key.

After you encrypt a snapshot using a customer-supplied key, you must provide the same key if you use the snapshot later. For example, you must provide the encryption key when you create a disk from the encrypted snapshot in a future request.

Customer-supplied encryption keys do not protect access to metadata of the snapshot.

If you do not provide an encryption key when creating the snapshot, then the snapshot will be encrypted using an automatically generated key and you do not need to provide a key to use the snapshot later.

originalResource.snapshotEncryptionKey.rawKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies a 256-bit customer-supplied encryption key, encoded in RFC 4648 base64 to either encrypt or decrypt this resource. You can provide either the rawKey or the rsaEncryptedKey. For example:

"rawKey": "SGVsbG8gZnJvbSBHb29nbGUgQ2xvdWQgUGxhdGZvcm0=" 

originalResource.snapshotEncryptionKey.rsaEncryptedKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies an RFC 4648 base64 encoded, RSA-wrapped 2048-bit customer-supplied encryption key to either encrypt or decrypt this resource. You can provide either the rawKey or the rsaEncryptedKey. For example:

"rsaEncryptedKey": "ieCx/NcW06PcT7Ep1X6LUTc/hLvUDYyzSZPPVCVPTVEohpeHASqC8uw5TzyO9U+Fka9JFH z0mBibXUInrC/jEk014kCK/NPjYgEMOyssZ4ZINPKxlUh2zn1bV+MCaTICrdmuSBTWlUUiFoD D6PYznLwh8ZNdaheCeZ8ewEXgFQ8V+sDroLaN3Xs3MDTXQEMMoNUXMCZEIpg9Vtp9x2oe==" 
The key must meet the following requirements before you can provide it to Compute Engine:
  1. The key is wrapped using a RSA public key certificate provided by Google.
  2. After being wrapped, the key must be encoded in RFC 4648 base64 encoding.
Gets the RSA public key certificate provided by Google at:
 https://cloud-certs.storage.googleapis.com/google-cloud-csek-ingress.pem

originalResource.snapshotEncryptionKey.kmsKeyName

string

The name of the encryption key that is stored in Google Cloud KMS. For example:

"kmsKeyName": "projects/ kms_project_id/locations/ region/keyRings/ key_region/cryptoKeys/key 
The fully-qualifed key name may be returned for resource GET requests. For example:
"kmsKeyName": "projects/ kms_project_id/locations/ region/keyRings/ key_region/cryptoKeys/key /cryptoKeyVersions/1

originalResource.snapshotEncryptionKey.sha256
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Output only. The RFC 4648 base64 encoded SHA-256 hash of the customer-supplied encryption key that protects this resource.

originalResource.snapshotEncryptionKey.kmsKeyServiceAccount

string

The service account being used for the encryption request for the given KMS key. If absent, the Compute Engine default service account is used. For example:

"kmsKeyServiceAccount": "name@ projectId.iam.gserviceaccount.com/ 

originalResource.sourceDiskEncryptionKey

object

The customer-supplied encryption key of the source disk. Required if the source disk is protected by a customer-supplied encryption key.

originalResource.sourceDiskEncryptionKey.rawKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies a 256-bit customer-supplied encryption key, encoded in RFC 4648 base64 to either encrypt or decrypt this resource. You can provide either the rawKey or the rsaEncryptedKey. For example:

"rawKey": "SGVsbG8gZnJvbSBHb29nbGUgQ2xvdWQgUGxhdGZvcm0=" 

originalResource.sourceDiskEncryptionKey.rsaEncryptedKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies an RFC 4648 base64 encoded, RSA-wrapped 2048-bit customer-supplied encryption key to either encrypt or decrypt this resource. You can provide either the rawKey or the rsaEncryptedKey. For example:

"rsaEncryptedKey": "ieCx/NcW06PcT7Ep1X6LUTc/hLvUDYyzSZPPVCVPTVEohpeHASqC8uw5TzyO9U+Fka9JFH z0mBibXUInrC/jEk014kCK/NPjYgEMOyssZ4ZINPKxlUh2zn1bV+MCaTICrdmuSBTWlUUiFoD D6PYznLwh8ZNdaheCeZ8ewEXgFQ8V+sDroLaN3Xs3MDTXQEMMoNUXMCZEIpg9Vtp9x2oe==" 
The key must meet the following requirements before you can provide it to Compute Engine:
  1. The key is wrapped using a RSA public key certificate provided by Google.
  2. After being wrapped, the key must be encoded in RFC 4648 base64 encoding.
Gets the RSA public key certificate provided by Google at:
 https://cloud-certs.storage.googleapis.com/google-cloud-csek-ingress.pem

originalResource.sourceDiskEncryptionKey.kmsKeyName

string

The name of the encryption key that is stored in Google Cloud KMS. For example:

"kmsKeyName": "projects/ kms_project_id/locations/ region/keyRings/ key_region/cryptoKeys/key 
The fully-qualifed key name may be returned for resource GET requests. For example:
"kmsKeyName": "projects/ kms_project_id/locations/ region/keyRings/ key_region/cryptoKeys/key /cryptoKeyVersions/1

originalResource.sourceDiskEncryptionKey.sha256
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Output only. The RFC 4648 base64 encoded SHA-256 hash of the customer-supplied encryption key that protects this resource.

originalResource.sourceDiskEncryptionKey.kmsKeyServiceAccount

string

The service account being used for the encryption request for the given KMS key. If absent, the Compute Engine default service account is used. For example:

"kmsKeyServiceAccount": "name@ projectId.iam.gserviceaccount.com/ 

originalResource.selfLink

string

Output only. Server-defined URL for the resource.

originalResource.selfLinkWithId

string

Output only. Server-defined URL for this resource's resource id.

originalResource.labels

map (key: string, value: string)

Labels to apply to this snapshot. These can be later modified by the setLabels method. Label values may be empty.

originalResource.labelFingerprint

string (bytes format)

A fingerprint for the labels being applied to this snapshot, which is essentially a hash of the labels set used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update labels. You must always provide an up-to-date fingerprint hash in order to update or change labels, otherwise the request will fail with error 412 conditionNotMet.

To see the latest fingerprint, make a get() request to retrieve a snapshot.

A base64-encoded string.

originalResource.licenseCodes[]

string (int64 format)

Output only. Integer license codes indicating which licenses are attached to this snapshot.

originalResource.storageLocations[]

string

Cloud Storage bucket storage location of the snapshot (regional or multi-regional).

originalResource.autoCreated

boolean

Output only. Set to true if snapshots are automatically created by applying resource policy on the target disk.

originalResource.guestOsFeatures[]

object

Output only. A list of features to enable on the guest operating system. Applicable only for bootable images. Read Enabling guest operating system features to see a list of available options.

originalResource.guestOsFeatures[].type

enum

The ID of a supported feature. To add multiple values, use commas to separate values. Set to one or more of the following values:

  • VIRTIO_SCSI_MULTIQUEUE
  • WINDOWS
  • MULTI_IP_SUBNET
  • UEFI_COMPATIBLE
  • GVNIC
  • SEV_CAPABLE
  • SUSPEND_RESUME_COMPATIBLE
  • SEV_LIVE_MIGRATABLE_V2
  • SEV_SNP_CAPABLE
  • TDX_CAPABLE
  • IDPF
  • SNP_SVSM_CAPABLE
  • CCA_CAPABLE
  • SUSPEND_SAFE_FPR
For more information, see Enabling guest operating system features.

originalResource.downloadBytes

string (int64 format)

Output only. Number of bytes downloaded to restore a snapshot to a disk.

originalResource.chainName

string

Creates the new snapshot in the snapshot chain labeled with the specified name. The chain name must be 1-63 characters long and comply with RFC1035. This is an uncommon option only for advanced service owners who needs to create separate snapshot chains, for example, for chargeback tracking. When you describe your snapshot resource, this field is visible only if it has a non-empty value.

originalResource.satisfiesPzs

boolean

Output only. Reserved for future use.

originalResource.sourceSnapshotSchedulePolicy

string

Output only. URL of the resource policy which created this scheduled snapshot.

originalResource.sourceSnapshotSchedulePolicyId

string

Output only. ID of the resource policy which created this scheduled snapshot.

originalResource.sourceInstantSnapshot

string

The source instant snapshot used to create this snapshot.

originalResource.sourceInstantSnapshotId

string

Output only. The unique ID of the instant snapshot used to create this snapshot. This value identifies the exact instant snapshot that was used to create this persistent disk. For example, if you created the persistent disk from an instant snapshot that was later deleted and recreated under the same name, the source instant snapshot ID would identify the exact instant snapshot that was used.

originalResource.architecture

enum

Output only. The architecture of the snapshot. Valid values are ARM64 or X86_64.

originalResource.snapshotType

enum

Indicates the type of the snapshot.

originalResource.creationSizeBytes

string (int64 format)

Output only. Size in bytes of the snapshot at creation time.

originalResource.maxRetentionDays

integer

Number of days the snapshot should be retained before being deleted automatically.

originalResource.enableConfidentialCompute

boolean

Output only. Whether this snapshot is created from a confidential compute mode disk. Output only.: This field is not set by user, but from source disk.

originalResource.sourceDiskForRecoveryCheckpoint

string

The source disk whose recovery checkpoint will be used to create this snapshot.

originalResource.sourceInstantSnapshotEncryptionKey

object

Customer provided encryption key when creating Snapshot from Instant Snapshot.

originalResource.sourceInstantSnapshotEncryptionKey.rawKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies a 256-bit customer-supplied encryption key, encoded in RFC 4648 base64 to either encrypt or decrypt this resource. You can provide either the rawKey or the rsaEncryptedKey. For example:

"rawKey": "SGVsbG8gZnJvbSBHb29nbGUgQ2xvdWQgUGxhdGZvcm0=" 

originalResource.sourceInstantSnapshotEncryptionKey.rsaEncryptedKey
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Specifies an RFC 4648 base64 encoded, RSA-wrapped 2048-bit customer-supplied encryption key to either encrypt or decrypt this resource. You can provide either the rawKey or the rsaEncryptedKey. For example:

"rsaEncryptedKey": "ieCx/NcW06PcT7Ep1X6LUTc/hLvUDYyzSZPPVCVPTVEohpeHASqC8uw5TzyO9U+Fka9JFH z0mBibXUInrC/jEk014kCK/NPjYgEMOyssZ4ZINPKxlUh2zn1bV+MCaTICrdmuSBTWlUUiFoD D6PYznLwh8ZNdaheCeZ8ewEXgFQ8V+sDroLaN3Xs3MDTXQEMMoNUXMCZEIpg9Vtp9x2oe==" 
The key must meet the following requirements before you can provide it to Compute Engine:
  1. The key is wrapped using a RSA public key certificate provided by Google.
  2. After being wrapped, the key must be encoded in RFC 4648 base64 encoding.
Gets the RSA public key certificate provided by Google at:
 https://cloud-certs.storage.googleapis.com/google-cloud-csek-ingress.pem

originalResource.sourceInstantSnapshotEncryptionKey.kmsKeyName

string

The name of the encryption key that is stored in Google Cloud KMS. For example:

"kmsKeyName": "projects/ kms_project_id/locations/ region/keyRings/ key_region/cryptoKeys/key 
The fully-qualifed key name may be returned for resource GET requests. For example:
"kmsKeyName": "projects/ kms_project_id/locations/ region/keyRings/ key_region/cryptoKeys/key /cryptoKeyVersions/1

originalResource.sourceInstantSnapshotEncryptionKey.sha256
(deprecated)

string

[DEPRECATED] CSEK is no longer supported. Use CMEK instead. Output only. The RFC 4648 base64 encoded SHA-256 hash of the customer-supplied encryption key that protects this resource.

originalResource.sourceInstantSnapshotEncryptionKey.kmsKeyServiceAccount

string

The service account being used for the encryption request for the given KMS key. If absent, the Compute Engine default service account is used. For example:

"kmsKeyServiceAccount": "name@ projectId.iam.gserviceaccount.com/ 

originalResource.region

string

Output only. URL of the region where the snapshot resides. Only applicable for regional snapshots.

originalResource.satisfiesPzi

boolean

Output only. Reserved for future use.

originalResource.snapshotGroupName

string

Output only. The snapshot group that this snapshot belongs to. The usage of snapshot group feature is restricted.

originalResource.snapshotGroupId

string

Output only. The unique ID of the snapshot group that this snapshot belongs to. The usage of snapshot group feature is restricted.

satisfiesPzs

boolean

Output only. Reserved for future use.

satisfiesPzi

boolean

Output only. Reserved for future use.

Methods

delete

Deletes the specified RecoverableSnapshot.

get

Returns the specified RecoverableSnapshot resource.

getIamPolicy

Gets the access control policy for a resource.

list

Retrieves a list of all of the RecoverableSnapshots in your project.

recover

Recovers the specified RecoverableSnapshot.

setIamPolicy

Sets the access control policy on the specified resource.

testIamPermissions

Returns permissions that a caller has on the specified resource.