
Huawei Invoke
CertifiedSynchronously invoke a Huawei Cloud FunctionGraph function
Huawei Invoke
Synchronously invoke a Huawei Cloud FunctionGraph function
Invokes a FunctionGraph function synchronously and captures its response. The function output
is stored in Kestra internal storage and accessible via {{ outputs.<taskId>.uri }}.
Authentication uses AK/SK request signing. Provide accessKeyId and secretAccessKey via
{{ secret('NAME') }}, or configure temporaryCredentials for inline IAM credential exchange.
Set fetchLogs: true to also capture the last ~4 KB of the function's execution logs in the
logs output; for full, durable logs use LTS.
If the function runtime reports an error (a non-2xx function execution status),
the task throws FunctionGraphInvokeException with a message pointing to the LTS logs.
HTTP-level failures (4xx/5xx) are also surfaced as FunctionGraphInvokeException.
type: io.kestra.plugin.huawei.functiongraph.InvokeExamples
Invoke a FunctionGraph function with a payload.
id: functiongraph_invoke
namespace: company.team
tasks:
- id: invoke
type: io.kestra.plugin.huawei.functiongraph.Invoke
accessKeyId: "{{ secret('HUAWEI_AK') }}"
secretAccessKey: "{{ secret('HUAWEI_SK') }}"
region: eu-west-101
functionUrn: "urn:fss:eu-west-101:abc123:function:default:my-fn:latest"
functionPayload:
key: value
date: "2024-01-01"
Invoke a function using the European sovereign cloud endpoint suffix.
id: functiongraph_invoke_eu
namespace: company.team
tasks:
- id: invoke
type: io.kestra.plugin.huawei.functiongraph.Invoke
accessKeyId: "{{ secret('HUAWEI_AK') }}"
secretAccessKey: "{{ secret('HUAWEI_SK') }}"
region: eu-west-101
endpointSuffix: myhuaweicloud.eu
functionUrn: "urn:fss:eu-west-101:abc123:function:default:my-fn:latest"
Properties
functionUrn *Requiredstring
Full URN of the function to invoke
The function URN uniquely identifies the function and version to invoke. Format:
urn: fss: <region>: <project_id>: function: <pkg>: <name>: <qualifier>
Example: urn: fss: eu-west-101: abc123: function: default: my-fn: latest
Find the URN in the FunctionGraph console under the function's Configuration tab.
accessKeyId string
Access Key (AK) used to authenticate with Huawei Cloud
Huawei Cloud access key used together with secretAccessKey to sign API requests. Required for AK/SK-based authentication; not required when providing a pre-obtained securityToken. Sensitive — always provide via {{ secret('NAME') }}.
domainId string
Huawei Cloud Account Domain ID
Identifies the Huawei Cloud account (domain). Required when authenticating against global services such as IAM, or when requesting a domain-scoped IAM token.
endpointOverride string
FunctionGraph endpoint URL override
Overrides the default endpoint derived from region and endpointSuffix. Use this for
private endpoints, non-standard deployments, or tests. When set, endpointSuffix is
ignored.
Format: https://functiongraph.<region>.myhuaweicloud.com (without trailing slash).
endpointSuffix string
Huawei Cloud domain suffix
Controls the top-level domain used when deriving the FunctionGraph endpoint from region.
Defaults to myhuaweicloud.com. Set to myhuaweicloud.eu for the Huawei Cloud European
sovereign cloud.
Ignored when endpointOverride is set.
fetchLogs booleanstring
falseCapture the function's execution logs
When true, requests the last ~4 KB of the function's execution logs (stdout/stderr)
via the X-Cff-Log-Type: tail header. The logs are emitted to the task logs at INFO
level and exposed in the logs output. For full, durable logs use LTS instead.
Defaults to false to keep the common invocation path lean.
functionPayload object
Input payload passed to the function
JSON-serializable map sent as the event body to the function. The function receives it as
its event parameter. When omitted, an empty body is sent.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
projectId string
Huawei Cloud Project ID
Identifies the region-scoped project against which most regional services authenticate. Mutually exclusive with domainId for global services such as IAM.
region string
Huawei Cloud region
Region identifier such as eu-west-101, ap-southeast-1, or cn-north-4.
secretAccessKey string
Secret Key (SK) used to authenticate with Huawei Cloud
Huawei Cloud secret key paired with accessKeyId. Required for AK/SK-based authentication. Sensitive — always provide via {{ secret('NAME') }}.
securityToken string
Pre-obtained Huawei Cloud IAM token used as bearer credential for downstream API calls
When set, downstream Huawei tasks send this value in the X-Auth-Token header instead of signing requests with AK/SK. Sensitive.
temporaryCredentials string
Inline IAM credential exchange
When set, the connection layer calls the Huawei IAM STS API once per task execution and
uses the returned temporary AK/SK + security token instead of the static accessKeyId
and secretAccessKey properties.
Configure once via pluginDefaults to apply transparently to every task in a namespace
without per-task credential wiring:
pluginDefaults:
- type: io.kestra.plugin.huawei.obs
values:
region: eu-west-101
temporaryCredentials:
authMethod: PASSWORD
username: my-iam-user
password: "{{ secret('HUAWEI_IAM_PASSWORD') }}"
domainName: my-account-domain
durationSeconds: 3600
**Long-running tasks: ** the exchange runs once at execution start. For RealtimeTrigger
or long-running Consume tasks that outlive durationSeconds, credentials will expire
mid-run. Use long-lived AK/SK properties or refresh externally in that case.
io.kestra.plugin.huawei.TemporaryCredentialsConfig
PASSWORDPASSWORDTOKENAuthentication method
Controls which credentials are used to obtain the session token before exchanging for temporary STS credentials.
PASSWORD(default): provideusername,password, anddomainName.TOKEN: provide an existingiamToken(X-Auth-Token).
Account domain name (PASSWORD method only)
The Huawei Cloud account name (domain name) that owns the IAM user.
Required when authMethod is PASSWORD. Visible in the Huawei Cloud console under
My Credentials → Domain Name.
900Lifetime of the temporary credentials in seconds
How long the returned temporary AK/SK/security-token should remain valid. Huawei Cloud accepts values between 900 (15 minutes) and 86400 (24 hours). Defaults to 900 seconds.
myhuaweicloud.comHuawei Cloud IAM endpoint suffix
Domain suffix used to build the IAM endpoint URL when no explicit endpoint override is set.
Defaults to myhuaweicloud.com. Set to myhuaweicloud.eu for the European sovereign cloud
(region eu-west-101 / EU-Dublin).
IAM token to exchange (TOKEN method only)
An existing Huawei Cloud X-Auth-Token to exchange for temporary STS credentials.
Required when authMethod is TOKEN. Sensitive — always provide via {{ secret('NAME') }}.
IAM password (PASSWORD method only)
Password for the IAM user identified by username.
Required when authMethod is PASSWORD.
Sensitive — always provide via {{ secret('NAME') }}.
Project name for project-scoped tokens (PASSWORD method only)
Overrides the project name used for scope=PROJECT token requests.
Defaults to the task's region value when omitted, which is correct for most regions.
PROJECTPROJECTDOMAINToken scope (PASSWORD method only)
Scope of the session token obtained during password authentication.
PROJECT(default): token is scoped to the project matchingprojectName(or the task'sregionwhenprojectNameis omitted). Use for most downstream tasks.DOMAIN: token is scoped to the domain.
IAM username (PASSWORD method only)
Huawei Cloud IAM username. Required when authMethod is PASSWORD.
Outputs
contentLength integer
Size of the function response in bytes
logs string
Tail of the function's execution logs
The last ~4 KB of stdout/stderr, populated only when fetchLogs is true; otherwise null.
requestId string
FunctionGraph request ID (X-Cff-Request-Id header value)
statusCode integer
HTTP status code returned by the FunctionGraph invocation API
uri string
uriURI of the function response stored in Kestra internal storage