Initialize a tunnel client

Updated at:

A tunnel client, which is a client for Tunnel Service, provides a variety of methods for callers to perform operations on tunnels and consume data. To use Tunnel Service to consume data in a table, you must initialize a tunnel client.

Preparations

Before you initialize a Tablestore client, you must obtain information about the Tablestore instance that you want to access, install Tablestore SDK for Go, and configure access credentials.

Obtain your instance information

  • Region ID: The ID of the region in which the instance resides. For example, the region ID of China (Hangzhou) is cn-hangzhou.

  • Instance name and endpoint: Each Tablestore instance has an endpoint. You must specify the endpoint in your application to perform operations on tables and data. You can obtain the instance name and endpoint as follows.

    1. Log on to the Tablestore console.

    2. In the top navigation bar, select a resource group and a region.

    3. On the Overview page, click the instance alias or click Manage Instance in the Actions column.

    4. On the Instance Details tab, view the name and endpoint of the instance.

      Important

      By default, Internet access is disabled for new instances. To access resources in an instance over the Internet, you must enable Internet access for the instance.

Install the Tablestore SDK for Go

Run the go mod init <DIRNAME> command in the project directory to generate the go.mo d file. Then, run the following command to install Tablestore SDK for Go:

Note

<DIRNAME> indicates the project directory path. Replace <DIRNAME> with the actual project directory path.

go get github.com/aliyun/aliyun-tablestore-go-sdk/tablestore

For more information, see Installing the Tablestore SDK.

Configure access credentials

You need to create an AccessKey for an Alibaba Cloud account or a RAM user and configure the AccessKey in the environment variables as follows.

Note

After you complete the configuration, restart or refresh your compilation and runtime environment, including IDEs, command-line interfaces, other desktop applications, and background services, to ensure that the latest system environment variables are loaded successfully. For more information about configuring access credentials, see Configure access credentials.

Linux

  1. Run the following commands in the command-line interface to append environment variable settings to the ~/.bashrc file.

    echo "export TABLESTORE_ACCESS_KEY_ID='YOUR_ACCESS_KEY_ID'" >> ~/.bashrc
    echo "export TABLESTORE_ACCESS_KEY_SECRET='YOUR_ACCESS_KEY_SECRET'" >> ~/.bashrc
  2. Run the following command to allow the changes to take effect:

    source ~/.bashrc
  3. Run the following commands to check whether the environment variables take effect:

    echo $TABLESTORE_ACCESS_KEY_ID
    echo $TABLESTORE_ACCESS_KEY_SECRET

macOS

  1. Run the following command in the terminal to check the default Shell type.

    echo $SHELL
  2. Perform operations based on the default Shell type.

    Zsh
    1. Run the following commands to append environment variable settings to the ~/.zshrc file.

      echo "export TABLESTORE_ACCESS_KEY_ID='YOUR_ACCESS_KEY_ID'" >> ~/.zshrc
      echo "export TABLESTORE_ACCESS_KEY_SECRET='YOUR_ACCESS_KEY_SECRET'" >> ~/.zshrc
    2. Run the following command to allow the changes to take effect:

      source ~/.zshrc
    3. Run the following commands to check whether the environment variables take effect:

      echo $TABLESTORE_ACCESS_KEY_ID
      echo $TABLESTORE_ACCESS_KEY_SECRET
    Bash
    1. Run the following commands to append environment variable settings to the ~/.bash_profile file.

      echo "export TABLESTORE_ACCESS_KEY_ID='YOUR_ACCESS_KEY_ID'" >> ~/.bash_profile
      echo "export TABLESTORE_ACCESS_KEY_SECRET='YOUR_ACCESS_KEY_SECRET'" >> ~/.bash_profile
    2. Run the following command to allow the changes to take effect:

      source ~/.bash_profile
    3. Run the following commands to check whether the environment variables take effect:

      echo $TABLESTORE_ACCESS_KEY_ID
      echo $TABLESTORE_ACCESS_KEY_SECRET

Windows

CMD
  1. Run the following commands in CMD to set environment variables.

    setx TABLESTORE_ACCESS_KEY_ID "YOUR_ACCESS_KEY_ID"
    setx TABLESTORE_ACCESS_KEY_SECRET "YOUR_ACCESS_KEY_SECRET"
  2. After restarting CMD, run the following commands to check whether the environment variables take effect:

    echo %TABLESTORE_ACCESS_KEY_ID%
    echo %TABLESTORE_ACCESS_KEY_SECRET%
PowerShell
  1. Run the following command in PowerShell:

    [Environment]::SetEnvironmentVariable("TABLESTORE_ACCESS_KEY_ID", "YOUR_ACCESS_KEY_ID", [EnvironmentVariableTarget]::User)
    [Environment]::SetEnvironmentVariable("TABLESTORE_ACCESS_KEY_SECRET", "YOUR_ACCESS_KEY_SECRET", [EnvironmentVariableTarget]::User)
  2. Run the following commands to check whether the environment variables take effect:

    [Environment]::GetEnvironmentVariable("TABLESTORE_ACCESS_KEY_ID", [EnvironmentVariableTarget]::User)
    [Environment]::GetEnvironmentVariable("TABLESTORE_ACCESS_KEY_SECRET", [EnvironmentVariableTarget]::User)

Initialize a tunnel client

Initialize a tunnel client by using a method that best suits your business requirements.

  • Use the AccessKey pair of your Alibaba Cloud account or a RAM user to initialize a tunnel client

    Important

    For security purposes, we recommend that you use the AccessKey pair of a RAM user to access Tablestore. You can create a RAM user, attach the AliyunOTSFullAccess policy to the RAM user to grant the RAM user the permissions to manage Tablestore, and create an AccessKey pair for the RAM user. For more information, see Access Tablestore with a RAM user's AccessKey pair.

    The following sample code provides an example on how to use the AccessKey ID and AccessKey secret that you obtained to initialize a tunnel client:

    // Specify the name of the instance. 
    // Specify the endpoint of the instance. Example: https://instance.cn-hangzhou.ots.aliyun.com. 
    // Specify the AccessKey ID and AccessKey secret of your Alibaba Cloud account or a RAM user. 
    instanceName := "yourInstanceName"
    endPoint := "yourEndpoint"
    accessKeyId := os.Getenv("TABLESTORE_ACCESS_KEY_ID")
    accessKeySecret := os.Getenv("TABLESTORE_ACCESS_KEY_SECRET")
    tunnelClient := tunnel.NewTunnelClient(endPoint, instanceName, accessKeyId, accessKeySecret)                    
  • Use the temporary access credentials that you obtained from STS to initialize a tunnel client

    If you want to authorize temporary access, you can use this method to initialize a tunnel client.

    Note

    For information about how to obtain temporary access credentials from STS, see Use STS temporary credentials to access Tablestore.

    A tunnel client provides the NewTunnelClientWithToken operation that you can call to initialize a tunnel client based on temporary access credentials.