# RelationalDatabases Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/relationaldatabases/

Schema for the `RelationalDatabases` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`db_id`** _(string)_
  The provider's own identifier for the database.
- **`topology`** _(string)_
  Whether this row represents a cluster or a standalone instance.
  Allowed: `cluster`, `instance`, `unknown`
- **`engine`** _(string)_
  The database engine, as the provider names it.
- **`engine_version`** _(string)_
  The database engine version currently running.
- **`engine_lifecycle_support`** _(string)_
  The provider's support status for this engine version, where exposed.
- **`location`** _(string)_
  Where the database sits.
- **`public_network_access`** _(boolean)_
  The provider's public-network-access flag, not proven reachability: true doesn't mean reachable, and false doesn't mean safe — actual exposure also depends on routing.
- **`allowed_networks`** _(array<object>)_
  Ingress rules that reach this database.
  - **`source_id`** _(string)_
    The source range or security group allowed in.
  - **`protocol`** _(string)_
    The protocol allowed.
  - **`from_port`** _(integer)_
    Lowest port allowed.
  - **`to_port`** _(integer)_
    Highest port allowed.
- **`allow_all_ingress`** _(boolean)_
  Whether any allowed network rule permits the whole internet.
- **`attached_rule_sets`** _(array<object>)_
  The firewall rule sets attached to this database.
  - **`id`** _(string)_
    The target's `id`.
- **`encryption_at_rest`** _(boolean)_
  Whether storage is encrypted at rest.
- **`encryption_key_type`** _(string)_
  Who manages the storage encryption key. AWS merges provider-managed and customer-managed into one value (only provider-owned is distinguishable); resolving further may yield permission_denied.
  Allowed: `provider_managed`, `provider_owned`, `customer_managed`, `none`, `unknown`
- **`encryption_key`** _(object)_
  The key protecting the database at rest.
  - **`id`** _(string)_
    The target's `id`.
- **`storage_encryption_type`** _(string)_
  The provider's own storage encryption type string, verbatim.
- **`backup_retention_days`** _(integer)_
  How many days of backups are retained.
- **`point_in_time_recovery`** _(boolean)_
  Whether point-in-time restore is available. AWS has no such flag; this is derived from backup retention and cross-checked against latest_restorable_time.
- **`latest_restorable_time`** _(string)_
  The most recent point the database could be restored to.
- **`deletion_protection`** _(boolean)_
  Whether the database is protected against deletion.
- **`high_availability_mode`** _(string)_
  The database's high-availability topology, distinguishing standby, multi-AZ, and multi-region configurations.
  Allowed: `none`, `single_standby`, `multi_az_cluster`, `multi_region`, `zone_redundant`, `unknown`
- **`min_tls_version`** _(string)_
  Minimum TLS version accepted. Often not derivable on AWS: some engines have no true minimum, only an allow-list or independent toggles, and an absent parameter isn't the same as off.
- **`tls_enforced`** _(boolean)_
  Whether TLS is required for connections, independent of any minimum version floor.
- **`audit_log_destinations`** _(array<object>)_
  Where audit and error logs are delivered. AWS creates the destination on first write, so a row here can name a log group that does not exist yet.
  - **`id`** _(string)_
    The target's `id`.
- **`replica_locations`** _(array<string>)_
  Regions holding replicas of this database.
- **`replicas`** _(array<object>)_
  The replica databases themselves.
  - **`id`** _(string)_
    The target's `id`.
- **`global_cluster_id`** _(string)_
  The global cluster this database belongs to, where it is part of one.
- **`is_writer`** _(boolean)_
  Whether this row is the writer of its cluster or global cluster.

## Methods

- [GET /unified/cloud-infrastructure/relational_databases](/docs/api-reference/unified-cloud-infrastructure-api/relationaldatabases/list) — List Relational databases
