Initialize a tunnel client
A tunnel client, which is a client for Tunnel Service, provides a variety of methods for callers to perform operations on tunnels and consume data. To use Tunnel Service to consume data in a table, you must initialize a tunnel client.
Preparations
Before you initialize a Tablestore client, you must obtain information about the Tablestore instance that you want to access, install Tablestore SDK for Go, and configure access credentials.
Obtain your instance information
Region ID: The ID of the region in which the instance resides. For example, the region ID of China (Hangzhou) is cn-hangzhou.
Instance name and endpoint: Each Tablestore instance has an endpoint. You must specify the endpoint in your application to perform operations on tables and data. You can obtain the instance name and endpoint as follows.
Log on to the Tablestore console.
In the top navigation bar, select a resource group and a region.
On the Overview page, click the instance alias or click Manage Instance in the Actions column.
On the Instance Details tab, view the name and endpoint of the instance.
ImportantBy default, Internet access is disabled for new instances. To access resources in an instance over the Internet, you must enable Internet access for the instance.
Install the Tablestore SDK for Go
Run the go mod init <DIRNAME> command in the project directory to generate the go.mo d file. Then, run the following command to install Tablestore SDK for Go:
<DIRNAME> indicates the project directory path. Replace <DIRNAME> with the actual project directory path.
go get github.com/aliyun/aliyun-tablestore-go-sdk/tablestore
For more information, see Installing the Tablestore SDK.
Configure access credentials
You need to create an AccessKey for an Alibaba Cloud account or a RAM user and configure the AccessKey in the environment variables as follows.
After you complete the configuration, restart or refresh your compilation and runtime environment, including IDEs, command-line interfaces, other desktop applications, and background services, to ensure that the latest system environment variables are loaded successfully. For more information about configuring access credentials, see Configure access credentials.
Linux
Run the following commands in the command-line interface to append environment variable settings to the
~/.bashrcfile.echo "export TABLESTORE_ACCESS_KEY_ID='YOUR_ACCESS_KEY_ID'" >> ~/.bashrc echo "export TABLESTORE_ACCESS_KEY_SECRET='YOUR_ACCESS_KEY_SECRET'" >> ~/.bashrcRun the following command to allow the changes to take effect:
source ~/.bashrcRun the following commands to check whether the environment variables take effect:
echo $TABLESTORE_ACCESS_KEY_ID echo $TABLESTORE_ACCESS_KEY_SECRET
macOS
Run the following command in the terminal to check the default Shell type.
echo $SHELLPerform operations based on the default Shell type.
Zsh
Run the following commands to append environment variable settings to the
~/.zshrcfile.echo "export TABLESTORE_ACCESS_KEY_ID='YOUR_ACCESS_KEY_ID'" >> ~/.zshrc echo "export TABLESTORE_ACCESS_KEY_SECRET='YOUR_ACCESS_KEY_SECRET'" >> ~/.zshrcRun the following command to allow the changes to take effect:
source ~/.zshrcRun the following commands to check whether the environment variables take effect:
echo $TABLESTORE_ACCESS_KEY_ID echo $TABLESTORE_ACCESS_KEY_SECRET
Bash
Run the following commands to append environment variable settings to the
~/.bash_profilefile.echo "export TABLESTORE_ACCESS_KEY_ID='YOUR_ACCESS_KEY_ID'" >> ~/.bash_profile echo "export TABLESTORE_ACCESS_KEY_SECRET='YOUR_ACCESS_KEY_SECRET'" >> ~/.bash_profileRun the following command to allow the changes to take effect:
source ~/.bash_profileRun the following commands to check whether the environment variables take effect:
echo $TABLESTORE_ACCESS_KEY_ID echo $TABLESTORE_ACCESS_KEY_SECRET
Windows
CMD
Run the following commands in CMD to set environment variables.
setx TABLESTORE_ACCESS_KEY_ID "YOUR_ACCESS_KEY_ID" setx TABLESTORE_ACCESS_KEY_SECRET "YOUR_ACCESS_KEY_SECRET"After restarting CMD, run the following commands to check whether the environment variables take effect:
echo %TABLESTORE_ACCESS_KEY_ID% echo %TABLESTORE_ACCESS_KEY_SECRET%
PowerShell
Run the following command in PowerShell:
[Environment]::SetEnvironmentVariable("TABLESTORE_ACCESS_KEY_ID", "YOUR_ACCESS_KEY_ID", [EnvironmentVariableTarget]::User) [Environment]::SetEnvironmentVariable("TABLESTORE_ACCESS_KEY_SECRET", "YOUR_ACCESS_KEY_SECRET", [EnvironmentVariableTarget]::User)Run the following commands to check whether the environment variables take effect:
[Environment]::GetEnvironmentVariable("TABLESTORE_ACCESS_KEY_ID", [EnvironmentVariableTarget]::User) [Environment]::GetEnvironmentVariable("TABLESTORE_ACCESS_KEY_SECRET", [EnvironmentVariableTarget]::User)
Initialize a tunnel client
Initialize a tunnel client by using a method that best suits your business requirements.
-
Use the AccessKey pair of your Alibaba Cloud account or a RAM user to initialize a tunnel client
ImportantFor security purposes, we recommend that you use the AccessKey pair of a RAM user to access Tablestore. You can create a RAM user, attach the
AliyunOTSFullAccesspolicy to the RAM user to grant the RAM user the permissions to manage Tablestore, and create an AccessKey pair for the RAM user. For more information, see Access Tablestore with a RAM user's AccessKey pair.The following sample code provides an example on how to use the AccessKey ID and AccessKey secret that you obtained to initialize a tunnel client:
// Specify the name of the instance. // Specify the endpoint of the instance. Example: https://instance.cn-hangzhou.ots.aliyun.com. // Specify the AccessKey ID and AccessKey secret of your Alibaba Cloud account or a RAM user. instanceName := "yourInstanceName" endPoint := "yourEndpoint" accessKeyId := os.Getenv("TABLESTORE_ACCESS_KEY_ID") accessKeySecret := os.Getenv("TABLESTORE_ACCESS_KEY_SECRET") tunnelClient := tunnel.NewTunnelClient(endPoint, instanceName, accessKeyId, accessKeySecret) -
Use the temporary access credentials that you obtained from STS to initialize a tunnel client
If you want to authorize temporary access, you can use this method to initialize a tunnel client.
NoteFor information about how to obtain temporary access credentials from STS, see Use STS temporary credentials to access Tablestore.
A tunnel client provides the NewTunnelClientWithToken operation that you can call to initialize a tunnel client based on temporary access credentials.