
Huawei Upload
CertifiedUpload a file from Kestra internal storage to Huawei OBS
Huawei Upload
Upload a file from Kestra internal storage to Huawei OBS
Reads a file from Kestra internal storage (identified by a kestra:// URI) and uploads it to
the specified OBS bucket. Content length is always set explicitly so the upload works against both
real OBS and S3-compatible endpoints (which require Content-Length for streaming uploads).
type: io.kestra.plugin.huawei.obs.UploadExamples
id: obs_upload
namespace: company.team
tasks:
- id: upload
type: io.kestra.plugin.huawei.obs.Upload
accessKeyId: "{{ secret('HUAWEI_AK') }}"
secretAccessKey: "{{ secret('HUAWEI_SK') }}"
region: "eu-west-101"
bucket: "my-bucket"
from: "{{ inputs.file }}"
key: "uploads/data.csv"
contentType: "text/csv"
Properties
bucket *Requiredstring
OBS bucket name
Name of the OBS bucket to operate on. The bucket must already exist.
from *Requiredstring
Kestra internal storage URI of the file to upload
The URI of a file stored in Kestra internal storage (e.g. from a previous task output). Must be a kestra:// URI.
Pebble expression referencing an Internal Storage URI e.g. {{ outputs.mytask.uri }}.
key *Requiredstring
OBS object key (path within the bucket)
The key under which the object will be stored in the bucket, e.g. data/2024/file.csv.
accessKeyId string
Access Key (AK) used to authenticate with Huawei Cloud
Huawei Cloud access key used together with secretAccessKey to sign API requests. Required for AK/SK-based authentication; not required when providing a pre-obtained securityToken. Sensitive — always provide via {{ secret('NAME') }}.
authType string
OBSV2V4Request signing algorithm
Controls how OBS client signs each request:
OBS— native Huawei OBS signing (default; use for real OBS endpoints).V2— S3 v2 HMAC signing; required for MinIO and other S3-compatible endpoints.V4— S3 v4 signing; not compatible with MinIO via the OBS SDK due to a date-format mismatch. Do not useV4with S3-compatible endpoints.
contentType string
MIME content type of the uploaded object
Set to the appropriate MIME type (e.g. text/csv, application/json). OBS uses this value when serving the object.
domainId string
Huawei Cloud Account Domain ID
Identifies the Huawei Cloud account (domain). Required when authenticating against global services such as IAM, or when requesting a domain-scoped IAM token.
endpointOverride string
Override for the OBS endpoint URL
Full URL of the OBS endpoint to connect to instead of the region-derived default
(https://obs.<region>.myhuaweicloud.com). Required when using S3-compatible endpoints
such as MinIO (e.g. http://localhost: 9000). Trailing slashes are stripped automatically.
endpointSuffix string
myhuaweicloud.comDomain suffix for the region-derived OBS endpoint
Suffix appended to build https://obs.<region>.<endpointSuffix> when no endpointOverride
is set. Defaults to myhuaweicloud.com. Set to myhuaweicloud.eu for the European sovereign
region (e.g. eu-west-101). Ignored when endpointOverride is set.
metadata object
User-defined metadata to attach to the object
Key/value pairs stored as object metadata. Keys must be bare names without any prefix —
the OBS SDK prepends x-obs-meta- automatically. Values are stored as ASCII strings; any
non-string value (number, boolean) is converted via its string form.
Example: { "author": "kestra", "env": "prod" }.
pathStyleAccess booleanstring
Use path-style access for object keys
When true, the bucket name is placed in the URL path (http://host/bucket/key) instead of
the virtual-hosted style (http://bucket.host/key). Required for MinIO and most
S3-compatible endpoints. Default is false (virtual-hosted style, as used by real OBS).
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
projectId string
Huawei Cloud Project ID
Identifies the region-scoped project against which most regional services authenticate. Mutually exclusive with domainId for global services such as IAM.
region string
Huawei Cloud region
Region identifier such as eu-west-101, ap-southeast-1, or cn-north-4.
secretAccessKey string
Secret Key (SK) used to authenticate with Huawei Cloud
Huawei Cloud secret key paired with accessKeyId. Required for AK/SK-based authentication. Sensitive — always provide via {{ secret('NAME') }}.
securityToken string
Pre-obtained Huawei Cloud IAM token used as bearer credential for downstream API calls
When set, downstream Huawei tasks send this value in the X-Auth-Token header instead of signing requests with AK/SK. Sensitive.
storageClass string
STANDARDWARMCOLDDEEP_ARCHIVEINTELLIGENT_TIERINGHIGH_PERFORMANCEOBS storage class for the uploaded object
Controls the storage tier:
STANDARD— frequently accessed data (default when unset).WARM— infrequently accessed data; lower storage cost, retrieval fee applies.COLD— archival data; lowest cost, higher retrieval latency.DEEP_ARCHIVE— long-term archival.INTELLIGENT_TIERING— automatic tier transitions based on access patterns.
temporaryCredentials string
Inline IAM credential exchange
When set, the connection layer calls the Huawei IAM STS API once per task execution and
uses the returned temporary AK/SK + security token instead of the static accessKeyId
and secretAccessKey properties.
Configure once via pluginDefaults to apply transparently to every task in a namespace
without per-task credential wiring:
pluginDefaults:
- type: io.kestra.plugin.huawei.obs
values:
region: eu-west-101
temporaryCredentials:
authMethod: PASSWORD
username: my-iam-user
password: "{{ secret('HUAWEI_IAM_PASSWORD') }}"
domainName: my-account-domain
durationSeconds: 3600
**Long-running tasks: ** the exchange runs once at execution start. For RealtimeTrigger
or long-running Consume tasks that outlive durationSeconds, credentials will expire
mid-run. Use long-lived AK/SK properties or refresh externally in that case.
io.kestra.plugin.huawei.TemporaryCredentialsConfig
PASSWORDPASSWORDTOKENAuthentication method
Controls which credentials are used to obtain the session token before exchanging for temporary STS credentials.
PASSWORD(default): provideusername,password, anddomainName.TOKEN: provide an existingiamToken(X-Auth-Token).
Account domain name (PASSWORD method only)
The Huawei Cloud account name (domain name) that owns the IAM user.
Required when authMethod is PASSWORD. Visible in the Huawei Cloud console under
My Credentials → Domain Name.
900Lifetime of the temporary credentials in seconds
How long the returned temporary AK/SK/security-token should remain valid. Huawei Cloud accepts values between 900 (15 minutes) and 86400 (24 hours). Defaults to 900 seconds.
myhuaweicloud.comHuawei Cloud IAM endpoint suffix
Domain suffix used to build the IAM endpoint URL when no explicit endpoint override is set.
Defaults to myhuaweicloud.com. Set to myhuaweicloud.eu for the European sovereign cloud
(region eu-west-101 / EU-Dublin).
IAM token to exchange (TOKEN method only)
An existing Huawei Cloud X-Auth-Token to exchange for temporary STS credentials.
Required when authMethod is TOKEN. Sensitive — always provide via {{ secret('NAME') }}.
IAM password (PASSWORD method only)
Password for the IAM user identified by username.
Required when authMethod is PASSWORD.
Sensitive — always provide via {{ secret('NAME') }}.
Project name for project-scoped tokens (PASSWORD method only)
Overrides the project name used for scope=PROJECT token requests.
Defaults to the task's region value when omitted, which is correct for most regions.
PROJECTPROJECTDOMAINToken scope (PASSWORD method only)
Scope of the session token obtained during password authentication.
PROJECT(default): token is scoped to the project matchingprojectName(or the task'sregionwhenprojectNameis omitted). Use for most downstream tasks.DOMAIN: token is scoped to the domain.
IAM username (PASSWORD method only)
Huawei Cloud IAM username. Required when authMethod is PASSWORD.
Outputs
bucket string
Bucket the object was uploaded to
eTag string
ETag assigned by OBS after a successful upload
key string
Key of the uploaded object
versionId string
Version ID of the uploaded object
Non-null only when bucket versioning is enabled.