Skip to main content

api_management_service

Creates, updates, deletes, gets or lists an api_management_service resource.

Overview

Nameapi_management_service
TypeResource
Idazure.api_management.api_management_service

Fields

The following fields are returned by SELECT queries:

NameDatatypeDescription
idstringFully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}.
namestringThe name of the resource.
additionalLocationsarrayAdditional datacenter locations of the API Management service.
apiVersionConstraintobjectControl Plane Apis version constraint for the API Management service.
certificatesarrayList of Certificates that need to be installed in the API Management service. Max supported certificates that can be installed is 10.
configurationApiobjectConfiguration API configuration of the API Management service.
createdAtUtcstring (date-time)Creation UTC date of the API Management service.The date conforms to the following format: yyyy-MM-ddTHH:mm:ssZ as specified by the ISO 8601 standard.
customPropertiesobjectCustom properties of the API Management service.Setting Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TripleDes168 will disable the cipher TLS_RSA_WITH_3DES_EDE_CBC_SHA for all TLS(1.0, 1.1 and 1.2).Setting Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls11 can be used to disable just TLS 1.1.Setting Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Protocols.Tls10 can be used to disable TLS 1.0 on an API Management service.Setting Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls11 can be used to disable just TLS 1.1 for communications with backends.Setting Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Backend.Protocols.Tls10 can be used to disable TLS 1.0 for communications with backends.Setting Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2 can be used to enable HTTP2 protocol on an API Management service.Not specifying any of these properties on PATCH operation will reset omitted properties' values to their defaults. For all the settings except Http2 the default value is True if the service was created on or before April 1, 2018 and False otherwise. Http2 setting's default value is False.You can disable any of the following ciphers by using settings Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.[cipher_name]: TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_GCM_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA. For example, Microsoft.WindowsAzure.ApiManagement.Gateway.Security.Ciphers.TLS_RSA_WITH_AES_128_CBC_SHA256:false. The default value is true for them. Note: The following ciphers can't be disabled since they are required by internal platform components: TLS_AES_256_GCM_SHA384,TLS_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384,TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256.
developerPortalStatusstringStatus of developer portal in this API Management service. Known values are: "Enabled" and "Disabled". (Enabled, Disabled)
developerPortalUrlstringDEveloper Portal endpoint URL of the API Management service.
disableGatewaybooleanProperty only valid for an Api Management service deployed in multiple locations. This can be used to disable the gateway in master region.
enableClientCertificatebooleanProperty only meant to be used for Consumption SKU Service. This enforces a client certificate to be presented on each request to the gateway. This also enables the ability to authenticate the certificate in the policy on the gateway.
etagstringETag of the resource.
gatewayRegionalUrlstringGateway URL of the API Management service in the Default Region.
gatewayUrlstringGateway URL of the API Management service.
hostnameConfigurationsarrayCustom hostname configuration of the API Management service.
identityobjectManaged service identity of the Api Management service.
legacyPortalStatusstringStatus of legacy portal in the API Management service. Known values are: "Enabled" and "Disabled". (Enabled, Disabled)
locationstringThe geo-location where the resource lives. Required.
managementApiUrlstringManagement API endpoint URL of the API Management service.
natGatewayStatestringProperty can be used to enable NAT Gateway for this API Management service. Known values are: "Enabled" and "Disabled". (Enabled, Disabled)
notificationSenderEmailstringEmail address from which the notification will be sent.
outboundPublicIPAddressesarrayOutbound public IPV4 address prefixes associated with NAT Gateway deployed service. Available only for Premium SKU on stv2 platform.
platformVersionstringCompute Platform Version running the service in this location. Known values are: "undetermined", "stv1", "stv2", "mtv1", and "stv2.1". (undetermined, stv1, stv2, mtv1, stv2.1)
portalUrlstringPublisher portal endpoint Url of the API Management service.
privateEndpointConnectionsarrayList of Private Endpoint Connections of this service.
privateIPAddressesarrayPrivate Static Load Balanced IP addresses of the API Management service in Primary region which is deployed in an Internal Virtual Network. Available only for Basic, Standard, Premium and Isolated SKU.
provisioningStatestringThe current provisioning state of the API Management service which can be one of the following: Created/Activating/Succeeded/Updating/Failed/Stopped/Terminating/TerminationFailed/Deleted.
publicIPAddressesarrayPublic Static Load Balanced IP addresses of the API Management service in Primary region. Available only for Basic, Standard, Premium and Isolated SKU.
publicIpAddressIdstringPublic Standard SKU IP V4 based IP address to be associated with Virtual Network deployed service in the region. Supported only for Developer and Premium SKU being deployed in Virtual Network.
publicNetworkAccessstringWhether or not public endpoint access is allowed for this API Management service. Value is optional but if passed in, must be 'Enabled' or 'Disabled'. If 'Disabled', private endpoints are the exclusive access method. Default value is 'Enabled'. Known values are: "Enabled" and "Disabled". (Enabled, Disabled)
publisherEmailstringPublisher email. Required.
publisherNamestringPublisher name. Required.
releaseChannelstringRelease Channel of this API Management service. Known values are: "Preview", "Default", and "Stable". (Preview, Default, Stable)
restorebooleanUndelete Api Management Service if it was previously soft-deleted. If this flag is specified and set to True all other properties will be ignored.
scmUrlstringSCM endpoint URL of the API Management service.
skuobjectSKU properties of the API Management service. Required.
systemDataobjectAzure Resource Manager metadata containing createdBy and modifiedBy information.
tagsobjectResource tags.
targetProvisioningStatestringThe provisioning state of the API Management service, which is targeted by the long running operation started on the service.
typestringThe type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts".
virtualNetworkConfigurationobjectVirtual network configuration of the API Management service.
virtualNetworkTypestringThe type of VPN in which API Management service needs to be configured in. None (Default Value) means the API Management service is not part of any Virtual Network, External means the API Management deployment is set up inside a Virtual Network having an Internet Facing Endpoint, and Internal means that API Management deployment is setup inside a Virtual Network having an Intranet Facing Endpoint only. Known values are: "None", "External", and "Internal". (None, External, Internal)
zoneRedundantbooleanZone Redundant Requirement when creating StandardV2 and PremiumV2. If this flag is set to True, will return a APIM service with Zone redundant or fail the request if any underneath component cannot be zone redundant.
zonesarrayThe availability zones.

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectresource_group_name, service_name, subscription_idGets an API Management service resource description.
list_by_resource_groupselectresource_group_name, subscription_idList all API Management services within a resource group.
check_name_availabilityselectsubscription_idChecks availability and correctness of a name for an API Management service.
listselectsubscription_idLists all API Management services within an Azure subscription.
create_or_updateinsertresource_group_name, service_name, subscription_id, location, properties, skuCreates or updates an API Management service. This is long running operation and could take several minutes to complete.
updateupdateresource_group_name, service_name, subscription_idUpdates an existing API Management service.
create_or_updatereplaceresource_group_name, service_name, subscription_id, location, properties, skuCreates or updates an API Management service. This is long running operation and could take several minutes to complete.
deletedeleteresource_group_name, service_name, subscription_idDeletes an existing API Management service.
get_sso_tokenexecresource_group_name, service_name, subscription_idGets the Single-Sign-On token for the API Management Service which is valid for 5 Minutes.
get_domain_ownership_identifierexecsubscription_idGet the custom domain ownership identifier for an API Management service.
restoreexecresource_group_name, service_name, subscription_id, storageAccount, containerName, backupNameRestores a backup of an API Management service created using the ApiManagementService_Backup operation on the current service. This is a long running operation and could take several minutes to complete.
backupexecresource_group_name, service_name, subscription_id, storageAccount, containerName, backupNameCreates a backup of the API Management service to the given Azure Storage Account. This is long running operation and could take several minutes to complete.
migrate_to_stv2execresource_group_name, service_name, subscription_idUpgrades an API Management service to the Stv2 platform. For details refer to https://aka.ms/apim-migrate-stv2 _. This change is not reversible. This is long running operation and could take several minutes to complete.
apply_network_configuration_updatesexecresource_group_name, service_name, subscription_idUpdates the Microsoft.ApiManagement resource running in the Virtual network to pick the updated DNS changes.
refresh_hostnamesexecresource_group_name, service_name, subscription_idForce Refresh the SSL certificate attached to the Custom Hostnames configured using secret from KeyVault on the Api Management service.

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
resource_group_namestringThe name of the resource group. The name is case insensitive. Required.
service_namestringThe name of the API Management service. Required.
subscription_idstring

SELECT examples

Gets an API Management service resource description.

SELECT
id,
name,
additionalLocations,
apiVersionConstraint,
certificates,
configurationApi,
createdAtUtc,
customProperties,
developerPortalStatus,
developerPortalUrl,
disableGateway,
enableClientCertificate,
etag,
gatewayRegionalUrl,
gatewayUrl,
hostnameConfigurations,
identity,
legacyPortalStatus,
location,
managementApiUrl,
natGatewayState,
notificationSenderEmail,
outboundPublicIPAddresses,
platformVersion,
portalUrl,
privateEndpointConnections,
privateIPAddresses,
provisioningState,
publicIPAddresses,
publicIpAddressId,
publicNetworkAccess,
publisherEmail,
publisherName,
releaseChannel,
restore,
scmUrl,
sku,
systemData,
tags,
targetProvisioningState,
type,
virtualNetworkConfiguration,
virtualNetworkType,
zoneRedundant,
zones
FROM azure.api_management.api_management_service
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND service_name = '{{ service_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;

INSERT examples

Creates or updates an API Management service. This is long running operation and could take several minutes to complete.

INSERT INTO azure.api_management.api_management_service (
tags,
location,
properties,
sku,
identity,
zones,
resource_group_name,
service_name,
subscription_id
)
SELECT
'{{ tags }}',
'{{ location }}' /* required */,
'{{ properties }}' /* required */,
'{{ sku }}' /* required */,
'{{ identity }}',
'{{ zones }}',
'{{ resource_group_name }}',
'{{ service_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
etag,
identity,
location,
properties,
sku,
systemData,
tags,
type,
zones
;

UPDATE examples

Updates an existing API Management service.

UPDATE azure.api_management.api_management_service
SET
tags = '{{ tags }}',
properties = '{{ properties }}',
sku = '{{ sku }}',
identity = '{{ identity }}',
zones = '{{ zones }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND service_name = '{{ service_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
RETURNING
id,
name,
etag,
identity,
location,
properties,
sku,
systemData,
tags,
type,
zones;

REPLACE examples

Creates or updates an API Management service. This is long running operation and could take several minutes to complete.

REPLACE azure.api_management.api_management_service
SET
tags = '{{ tags }}',
location = '{{ location }}',
properties = '{{ properties }}',
sku = '{{ sku }}',
identity = '{{ identity }}',
zones = '{{ zones }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND service_name = '{{ service_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND location = '{{ location }}' --required
AND properties = '{{ properties }}' --required
AND sku = '{{ sku }}' --required
RETURNING
id,
name,
etag,
identity,
location,
properties,
sku,
systemData,
tags,
type,
zones;

DELETE examples

Deletes an existing API Management service.

DELETE FROM azure.api_management.api_management_service
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND service_name = '{{ service_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;

Lifecycle Methods

Gets the Single-Sign-On token for the API Management Service which is valid for 5 Minutes.

EXEC azure.api_management.api_management_service.get_sso_token 
@resource_group_name='{{ resource_group_name }}' --required,
@service_name='{{ service_name }}' --required,
@subscription_id='{{ subscription_id }}' --required
;