# Create or Update Storage instance

> Media API · Storage

```http
PUT https://app.mk.io/api/v1/projects/{project_name}/media/storage/{storage_name}
```

Create or update a Storage instance.
Only the description, credentials and privateLinkServiceConnection details are updatable.

RBAC Capability Required: `infra.storage.create` or `infra.storage.update`

## Authentication

- `Authorization` header — Bearer authentication of the form `Bearer <token>`.

## Path parameters

| Name           | Type   | Required | Description |
|----------------|--------|----------|-------------|
| `project_name` | string | Yes      | —           |
| `storage_name` | string | Yes      | —           |

## Request body

Content type: `application/json`

- `spec` · object · **Required** — The specification of the storage instance.
  - One of the following variants, selected by `type`:
    - **Microsoft.Storage** (object)
      - `credential` · object · Optional — The credential for the Azure Storage Account
        - `sasToken` · string · **Required** · _pattern: ^\\?([a-z]+=[^&]+)(&[a-z]+=[^&]+)+$_ — SAS Token for Azure Storage Account, including leading ?
      - `description` · string or null · Optional — Description of the storage.
      - `privateLinkServiceConnection` · object or null · Optional — Optional settings for a Private Link. Set it to null to remove the Private Link.
        - `requestMessage` · string · **Required** · _0-140 characters_ — A message passed to the owner of the remote resource with this connection request. This field cannot be modified, only set during creation.
        - `resourceGroupName` · string · **Required** · _1-90 characters_ — The name of the resource group containing the storage account This field cannot be modified, only set during creation.
        - `storageAccountName` · string · **Required** · _3-24 characters_ — The name of the storage account. The full Azure ID would be '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Storage/storageAccounts/{storageAccountName}' This field cannot be modified, only set during creation.
        - `subscriptionId` · string · **Required** · _format: uuid_ — The ID of the Azure subscription containing the storage account This field cannot be modified, only set during creation.
      - `type` · enum · **Required** — The type of storage. This field cannot be modified, only set during creation.
        - Allowed values: `Microsoft.Storage`, `AWS.S3`, `Google.Storage`
      - `url` · string · **Required** — HTTP(S) URL required for access to the storage. This field cannot be modified, only set during creation.
    - **AWS.S3** (object)
      - `bucketName` · string · **Required** · _pattern: ^(?!.*\\.\\.)[a-z0-9][-a-z0-9.]{1,61}[a-z0-9]$_ — The name of the AWS S3 bucket. This field cannot be modified, only set during creation.
      - `credential` · object · Optional — The credential for the AWS S3 bucket. Required at creation.
        - `accessKeyId` · string · **Required** · _pattern: ^A[KS]IA[0-9A-Z]{16}$_ — The access key ID for the bucket.
        - `secretAccessKey` · string · **Required** · _pattern: ^[A-Za-z0-9+/=]{40}$_ — The secret access key for the bucket.
      - `description` · string or null · Optional — Description of the storage.
      - `type` · enum · **Required** — The type of storage. This field cannot be modified, only set during creation.
        - Allowed values: `Microsoft.Storage`, `AWS.S3`, `Google.Storage`
    - **Google.Storage** (object)
      - `bucketName` · string · **Required** · _2-256 characters_ — The name of the Google Storage bucket. This field cannot be modified, only set during creation.
      - `credential` · object · Optional — The credential for the Google Storage bucket. Required at creation.
        - `gac` · map from strings to string · **Required** — Google Application Credentials in JSON format. You can generate this from the command line with `gcloud iam service-accounts keys create key.json --iam-account=<service_account>@<project>.iam.gserviceaccount.com` Or download it from the GCP console.
          - `[any key]` · string — map of additional properties
      - `description` · string or null · Optional — Description of the storage.
      - `type` · enum · **Required** — The type of storage. This field cannot be modified, only set during creation.
        - Allowed values: `Microsoft.Storage`, `AWS.S3`, `Google.Storage`

## Example request

```bash
curl -X PUT "https://app.mk.io/api/v1/projects/{project_name}/media/storage/{storage_name}" \
  -H "Authorization: Bearer <token>" \
  -H "Content-Type: application/json" \
  -d '{
  "spec": {
    "bucketName": "my-aws-bucket",
    "credential": {
      "accessKeyId": "AKIAEXAMPLE123456789",
      "secretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
    },
    "description": "Input media files for processing.",
    "type": "AWS.S3"
  }
}'
```

## Responses

### 200 — Storage instance successfully updated

- `kind` · string · Optional — The kind of record.
- `metadata` · object · **Required** — Metadata about the storage instance.
  - `created` · string · Optional · _format: date-time_ — The time when the resource was created
  - `createdBy` · string · Optional · _format: uuid_ — ID of the user who created the resource
  - `createdByEmail` · string · Optional — Email of the user who created the resource
  - `id` · string · **Required** · _format: uuid_ — The ID of the resource
  - `name` · string · Optional — The name of the resource
  - `updated` · string · Optional · _format: date-time_ — The time when the resource was last updated
  - `updatedBy` · string · Optional · _format: uuid_ — ID of the user who last updated the resource
  - `updatedByEmail` · string · Optional — Email of the user who last updated the resource
- `spec` · object · **Required** — The specification of the storage instance.
  - One of the following variants, selected by `type`:
    - **Microsoft.Storage** (object)
      - `credential` · object · Optional — The credential for the Azure Storage Account
        - `sasToken` · string · **Required** · _pattern: ^\\?([a-z]+=[^&]+)(&[a-z]+=[^&]+)+$_ — SAS Token for Azure Storage Account, including leading ?
        - `signedExpiry` · string · **Required** · _format: date-time_ — The expiry time of the token.
        - `signedStart` · string or null · **Required** · _format: date-time_ — The start time of the token.
      - `description` · string or null · **Required** — Description of the storage.
      - `privateLinkServiceConnection` · object or null · Optional — Optional settings for a Private Link. Set it to null to remove the Private Link.
        - `requestMessage` · string · **Required** · _0-140 characters_ — A message passed to the owner of the remote resource with this connection request. This field cannot be modified, only set during creation.
        - `resourceGroupName` · string · **Required** · _1-90 characters_ — The name of the resource group containing the storage account This field cannot be modified, only set during creation.
        - `storageAccountName` · string · **Required** · _3-24 characters_ — The name of the storage account. The full Azure ID would be '/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Storage/storageAccounts/{storageAccountName}' This field cannot be modified, only set during creation.
        - `subscriptionId` · string · **Required** · _format: uuid_ — The ID of the Azure subscription containing the storage account This field cannot be modified, only set during creation.
      - `region` · string or null · **Required** — Storage region.
      - `type` · enum · **Required** — The type of storage. This field cannot be modified, only set during creation.
        - Allowed values: `Microsoft.Storage`, `AWS.S3`, `Google.Storage`
      - `url` · string · **Required** — HTTP(S) URL required for access to the storage. This field cannot be modified, only set during creation.
    - **AWS.S3** (object)
      - `bucketName` · string · **Required** · _pattern: ^(?!.*\\.\\.)[a-z0-9][-a-z0-9.]{1,61}[a-z0-9]$_ — The name of the AWS S3 bucket. This field cannot be modified, only set during creation.
      - `credential` · object · Optional — The credential for the AWS S3 bucket. Required at creation.
        - `accessKeyId` · string · **Required** · _pattern: ^A[KS]IA[0-9A-Z]{16}$_ — The access key ID for the bucket.
        - `secretAccessKey` · string · **Required** · _pattern: ^[A-Za-z0-9+/=]{40}$_ — The secret access key for the bucket.
      - `description` · string or null · **Required** — Description of the storage.
      - `region` · string or null · **Required** — Storage region.
      - `type` · enum · **Required** — The type of storage. This field cannot be modified, only set during creation.
        - Allowed values: `Microsoft.Storage`, `AWS.S3`, `Google.Storage`
      - `url` · string · **Required** — The URL of the S3 bucket
    - **Google.Storage** (object)
      - `bucketName` · string · **Required** · _2-256 characters_ — The name of the Google Storage bucket. This field cannot be modified, only set during creation.
      - `credential` · object · Optional — The credential for the Google Storage bucket. Required at creation.
        - `gac` · map from strings to string · **Required** — Google Application Credentials in JSON format. You can generate this from the command line with `gcloud iam service-accounts keys create key.json --iam-account=<service_account>@<project>.iam.gserviceaccount.com` Or download it from the GCP console.
          - `[any key]` · string — map of additional properties
      - `description` · string or null · **Required** — Description of the storage.
      - `region` · string or null · **Required** — Storage region.
      - `type` · enum · **Required** — The type of storage. This field cannot be modified, only set during creation.
        - Allowed values: `Microsoft.Storage`, `AWS.S3`, `Google.Storage`
- `status` · object · Optional — Additional status information regarding the storage instance.
  - `activeCredentialId` · string or null · **Required** · _format: uuid_ — The ID of the active credential for this storage.
  - `privateLinkServiceConnectionStatus` · enum · Optional — The state of the Azure Private Connection, if enabled.
    - Allowed values: `Creating`, `Pending`, `Ready`, `Running`, `Deleting`, `Deleted`

### 201 — Storage instance successfully created

- `error` · object · **Required** — Pertinent information about the error
  - `code` · string · **Required** — The error code.
  - `detail` · string · **Required** — The error message.
  - `extraDetail` · map from strings to any · Optional — Extra information regarding this error.
    - `[any key]` · any — map of additional properties
- `ref` · string · **Required** — A reference to the request that caused the error.
- `status` · integer · **Required** — The HTTP status code

### 401 — Unauthorized

### 403 — Forbidden

### 404 — Not Found

### 429 — Too Many Requests

### 500 — Internal Server Error

---

Source spec: `media-api` · operationId: `[put]_/api/v1/projects/{project_name}/media/storage/{storage_name}`
