DataSnapshots Object
Relationships
graph LR
DataSnapshots -->|"account"| Accounts
DataSnapshots -->|"encryption_key"| ManagedKeys
Properties
Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
When the snapshot was taken.
Whether the snapshot is encrypted.
The key protecting the snapshot, where it is encrypted.
The target's id.
Whether the snapshot is readable by any account on the provider.
Where the snapshot currently sits (not its origin — a cross-region copy reports its current location). AWS returns no location for block-volume snapshots, so the queried region is used instead.
The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
Which cloud this object was read from.
awsazuregcp
The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
The account-and-region-wide snapshot sharing posture. Under a block-all-sharing setting, an already-public snapshot (is_public true) is effectively private and not actually exposed.
Raw data returned from the remote API call.
Accounts this snapshot has been explicitly shared with. Empty means shared with nobody; null means the sharing attribute could not be read.
Whether the per-snapshot sharing attribute was actually read. False means shared_with_accounts and is_public are inferred, not confirmed.
Which snapshot service this came from — block volume, database instance, database cluster, or disk. Encryption and sharing fields have different semantics per family.
block_volumedatabase_instancedatabase_clusterdiskother
The provider's own identifier for the snapshot.
Whether the snapshot was taken manually or by automated backup. Automated snapshots can't be shared, so their sharing fields are set by construction, not read per-snapshot.
manualautomatedunknown
The account that owns the source. On AWS this is parsed from the ARN, since neither database snapshot type carries an owner field.
The database or volume this snapshot was taken from.
The provider's own status string for the snapshot, verbatim.
Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
Explanation of the reason, where one adds anything.
The property on this resource that could not be read.
Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.