# List Relational databases

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/relationaldatabases/list/

`GET /unified/cloud-infrastructure/relational_databases`

Resource: **RelationalDatabases** · API: **Unified Cloud Infrastructure API**

## Supported integrations

Amazon Web Services

## Query parameters

- **`integrated_account_id`** _(string, required)_
  The ID of the integrated account to use for the request.
- **`truto_response_format`** _(string)_
  The format of the response. - `unified` returns the response with unified mappings applied. - `raw` returns the unprocessed, raw response from the remote API. - `normalized` applies the unified mappings and returns the data in a normalized format. - `stream` returns the response as a stream, which is ideal for transmitting large datasets, files, or binary data. Using streaming mode helps to efficiently handle large payloads or real-time data flows without requiring the entire data to be buffered in memory. - `debug` returns the final unified result alongside raw remote fetch information. The response is an envelope containing `result` (identical to unified mode output) and `debug` (with `requestUrl`, `requestOptions`, `data`, `responseHeaders`, and for list operations: `nextCursor`, `isLooping`, `isEmptyResult`, `resultCount`). When the upstream body exceeds 1 MiB, `data` is replaced by `{ truto_truncated: true, truto_max_bytes, truto_excerpt }`. `debug` is `null` for static responses or when `truto_skip_api_call=true`. Defaults to `unified`.
  Allowed: `unified`, `raw`, `normalized`, `stream`, `debug`
- **`truto_key_by`** _(string)_
  By default the `result` attribute is an array of objects. This parameter allows you to specify a field in each `result` objects to use as key, which transforms the `result` array into an object with the array items keyed by the field. This is useful for when you want to use the result as a lookup table.
- **`truto_ignore_limit`** _(boolean)_
  Ignores the `limit` query parameter.
- **`truto_ignore_remote_data`** _(boolean)_
  Excludes the `remote_data` attribute from the response.
- **`truto_exclude_fields`** _(array<string>)_
  Array of fields to exclude from the response.
- **`remote_query`** _(object)_
  Query parameters to pass to the underlying API without any transformations. Refer [this guide](https://truto.one/docs/api-reference/overview/querying#remote-query-parameters) to see how to structure the query parameters.
- **`topology`** _(string)_
  Which RDS API to read: 'instance' (default) or 'cluster'. Call both for a complete inventory, as neither returns the other's rows. Instances belonging to a cluster are suppressed on the instance route.
  Allowed: `cluster`, `instance`, `unknown`
- **`region`** _(string)_
  AWS region to read. One call reads one region; the caller drives any multi-region loop.

## Response body

- **`result`** _(array<object>)_
  List of Relational databases
  - **`id`** _(string, required)_
    Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
  - **`provider_id`** _(string)_
    The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
  - **`provider`** _(string)_
    Which cloud this object was read from.
    Allowed: `aws`, `azure`, `gcp`
  - **`account`** _(string)_
    The account, subscription or project this object belongs to.
  - **`region`** _(string)_
    Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
  - **`native_type`** _(string)_
    The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
  - **`tags`** _(object)_
    Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
  - **`collected_at`** _(string)_
    When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
  - **`updated_at`** _(string)_
    When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
  - **`created_at`** _(string)_
    When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
  - **`unreadable_fields`** _(array<object>)_
    Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
    - **`field`** _(string)_
      The property on this resource that could not be read.
    - **`reason`** _(string)_
      Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
      Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
    - **`detail`** _(string)_
      Explanation of the reason, where one adds anything.
  - **`remote_data`** _(object)_
    Raw data returned from the remote API call.
  - **`db_id`** _(string)_
    The provider's own identifier for the database.
  - **`topology`** _(string)_
    Whether this row represents a cluster or a standalone instance.
    Allowed: `cluster`, `instance`, `unknown`
  - **`engine`** _(string)_
    The database engine, as the provider names it.
  - **`engine_version`** _(string)_
    The database engine version currently running.
  - **`engine_lifecycle_support`** _(string)_
    The provider's support status for this engine version, where exposed.
  - **`location`** _(string)_
    Where the database sits.
  - **`public_network_access`** _(boolean)_
    The provider's public-network-access flag, not proven reachability: true doesn't mean reachable, and false doesn't mean safe — actual exposure also depends on routing.
  - **`allowed_networks`** _(array<object>)_
    Ingress rules that reach this database.
    - **`source_id`** _(string)_
      The source range or security group allowed in.
    - **`protocol`** _(string)_
      The protocol allowed.
    - **`from_port`** _(integer)_
      Lowest port allowed.
    - **`to_port`** _(integer)_
      Highest port allowed.
  - **`allow_all_ingress`** _(boolean)_
    Whether any allowed network rule permits the whole internet.
  - **`attached_rule_sets`** _(array<object>)_
    The firewall rule sets attached to this database.
    - **`id`** _(string)_
      The target's `id`.
  - **`encryption_at_rest`** _(boolean)_
    Whether storage is encrypted at rest.
  - **`encryption_key_type`** _(string)_
    Who manages the storage encryption key. AWS merges provider-managed and customer-managed into one value (only provider-owned is distinguishable); resolving further may yield permission_denied.
    Allowed: `provider_managed`, `provider_owned`, `customer_managed`, `none`, `unknown`
  - **`encryption_key`** _(object)_
    The key protecting the database at rest.
    - **`id`** _(string)_
      The target's `id`.
  - **`storage_encryption_type`** _(string)_
    The provider's own storage encryption type string, verbatim.
  - **`backup_retention_days`** _(integer)_
    How many days of backups are retained.
  - **`point_in_time_recovery`** _(boolean)_
    Whether point-in-time restore is available. AWS has no such flag; this is derived from backup retention and cross-checked against latest_restorable_time.
  - **`latest_restorable_time`** _(string)_
    The most recent point the database could be restored to.
  - **`deletion_protection`** _(boolean)_
    Whether the database is protected against deletion.
  - **`high_availability_mode`** _(string)_
    The database's high-availability topology, distinguishing standby, multi-AZ, and multi-region configurations.
    Allowed: `none`, `single_standby`, `multi_az_cluster`, `multi_region`, `zone_redundant`, `unknown`
  - **`min_tls_version`** _(string)_
    Minimum TLS version accepted. Often not derivable on AWS: some engines have no true minimum, only an allow-list or independent toggles, and an absent parameter isn't the same as off.
  - **`tls_enforced`** _(boolean)_
    Whether TLS is required for connections, independent of any minimum version floor.
  - **`audit_log_destinations`** _(array<object>)_
    Where audit and error logs are delivered. AWS creates the destination on first write, so a row here can name a log group that does not exist yet.
    - **`id`** _(string)_
      The target's `id`.
  - **`replica_locations`** _(array<string>)_
    Regions holding replicas of this database.
  - **`replicas`** _(array<object>)_
    The replica databases themselves.
    - **`id`** _(string)_
      The target's `id`.
  - **`global_cluster_id`** _(string)_
    The global cluster this database belongs to, where it is part of one.
  - **`is_writer`** _(boolean)_
    Whether this row is the writer of its cluster or global cluster.
- **`next_cursor`** _(string)_
  The cursor to use for the next page of results. Pass this value as `next_cursor` in the query parameter in the next request to get the next page of results.
- **`debug`** _(object)_
  Present only when `truto_response_format=debug`. Contains raw fetch details: `requestUrl`, `requestOptions`, `data`, `responseHeaders`, `nextCursor`, `isLooping`, `isEmptyResult`, `resultCount`. `data` is the parsed upstream body; when its JSON form exceeds 1 MiB it is replaced by `{ truto_truncated: true, truto_max_bytes, truto_excerpt }`, where `truto_excerpt` is the leading bytes of that body. The same applies to a string `requestOptions.body`. `null` for static responses or when `truto_skip_api_call=true`.
  - **`requestUrl`** _(string)_
  - **`requestOptions`** _(object)_
  - **`data`** _(unknown)_
  - **`responseHeaders`** _(object)_
  - **`nextCursor`** _(string)_
  - **`isLooping`** _(boolean)_
  - **`isEmptyResult`** _(boolean)_
  - **`resultCount`** _(number)_

## Code examples

### Truto CLI

```bash
truto unified cloud-infrastructure relationaldatabases \
  -a '<integrated_account_id>' \
  -o json
```

### Truto TS SDK

```typescript
import Truto from '@truto/truto-ts-sdk';

const truto = new Truto({
  token: '<your_api_token>',
});

const result = await truto.unifiedApi.list(
  'cloud-infrastructure',
  'relationaldatabases',
  { integrated_account_id: '<integrated_account_id>' }
);

console.log(result);
```

### Truto Python SDK

```python
import asyncio
from truto_python_sdk import TrutoApi

truto_api = TrutoApi(token="<your_api_token>")

async def main():
    async for item in truto_api.unified_api.list(
        "cloud-infrastructure",
        "relationaldatabases",
        {"integrated_account_id": "<integrated_account_id>"}
    ):
        print(item)

asyncio.run(main())
```

### curl

```bash
curl -X GET 'https://api.truto.one/unified/cloud-infrastructure/relational_databases?integrated_account_id=<integrated_account_id>' \
  -H 'Authorization: Bearer <your_api_token>' \
  -H 'Content-Type: application/json'
```

### JavaScript

```javascript
const integratedAccountId = '<integrated_account_id>';

const response = await fetch(`https://api.truto.one/unified/cloud-infrastructure/relational_databases?integrated_account_id=${integratedAccountId}`, {
  method: 'GET',
  headers: {
    'Authorization': 'Bearer <your_api_token>',
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
```

### Python

```python
import requests

url = "https://api.truto.one/unified/cloud-infrastructure/relational_databases"
headers = {
    "Authorization": "Bearer <your_api_token>",
    "Content-Type": "application/json",
}
params = {
    "integrated_account_id": "<integrated_account_id>"
}

response = requests.get(url, headers=headers, params=params)
print(response.json())
```
