Chapter 71. Common Object Reference
71.1. Common Object Reference Copy linkLink copied to clipboard!
71.1.1. Common object reference Copy linkLink copied to clipboard!
71.1.2. Models Copy linkLink copied to clipboard!
71.1.2.1. AdministrationEventResource Copy linkLink copied to clipboard!
Resource holds all information about the resource associated with the event.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | String | Resource type associated with the event. An event may refer to an underlying resource such as a particular image. In that case, the resource type will be filled here. | |||
| id | String | Resource ID associated with the event. If an event refers to an underlying resource, the resource ID identifies the underlying resource. The resource ID is not guaranteed to be set, depending on the context of the administration event. | |||
| name | String | Resource name associated with the event. If an event refers to an underlying resource, the resource name identifies the underlying resource. The resource name is not guaranteed to be set, depending on the context of the administration event. |
71.1.2.2. AlertDeploymentContainer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| image | |||||
| name | String |
71.1.2.3. AlertEnforcement Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| action | UNSET_ENFORCEMENT, SCALE_TO_ZERO_ENFORCEMENT, UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT, KILL_POD_ENFORCEMENT, FAIL_BUILD_ENFORCEMENT, FAIL_KUBE_REQUEST_ENFORCEMENT, FAIL_DEPLOYMENT_CREATE_ENFORCEMENT, FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT, | ||||
| message | String |
71.1.2.4. AlertEntityType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| DEPLOYMENT |
| CONTAINER_IMAGE |
| RESOURCE |
| NODE |
71.1.2.5. AlertGroupAlertCounts Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| count | String | int64 |
71.1.2.6. AlertNode Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterId | String | This field has to be duplicated in Alert for scope management and search. | |||
| clusterName | String | This field has to be duplicated in Alert for scope management and search. |
71.1.2.7. AlertProcessViolation Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| message | String | ||||
| processes | List of StorageProcessIndicator |
71.1.2.8. AlertResourceResourceType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| SECRETS |
| CONFIGMAPS |
| CLUSTER_ROLES |
| CLUSTER_ROLE_BINDINGS |
| NETWORK_POLICIES |
| SECURITY_CONTEXT_CONSTRAINTS |
| EGRESS_FIREWALLS |
71.1.2.9. AlertServiceResolveAlertBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| whitelist | Boolean | ||||
| addToBaseline | Boolean |
71.1.2.10. AlertViolation Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| message | String | ||||
| keyValueAttrs | |||||
| networkFlowInfo | |||||
| fileAccess | |||||
| type | GENERIC, K8S_EVENT, NETWORK_FLOW, NETWORK_POLICY, FILE_ACCESS, | ||||
| time | Date | Indicates violation time. This field differs from top-level field 'time' which represents last time the alert occurred in case of multiple occurrences of the policy alert. As of 55.0, this field is set only for kubernetes event violations, but may not be limited to it in future. | date-time |
71.1.2.11. AlertViolationType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| GENERIC |
| K8S_EVENT |
| NETWORK_FLOW |
| NETWORK_POLICY |
| FILE_ACCESS |
71.1.2.12. AuthMachineToMachineConfigMapping Copy linkLink copied to clipboard!
Mappings map an identity token’s claim values to a specific role within Central.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | A key within the identity token’s claim value to use. | |||
| valueExpression | String | A regular expression that will be evaluated against values of the identity token claim identified by the specified key. This regular expressions is in RE2 format, see more here: https://github.com/google/re2/wiki/Syntax. | |||
| role | String | The role which should be issued when the key and value match for a particular identity token. |
71.1.2.13. AuthProviderRequiredAttribute Copy linkLink copied to clipboard!
RequiredAttribute allows to specify a set of attributes which ALL are required to be returned by the auth provider. If any attribute is missing within the external claims of the token issued by Central, the authentication request to this IdP is considered failed.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| attributeKey | String | ||||
| attributeValue | String |
71.1.2.14. AuthProviderServicePutAuthProviderBody Copy linkLink copied to clipboard!
Next Tag: 15.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| uiEndpoint | String | ||||
| enabled | Boolean | ||||
| config |
Map of | Config holds auth provider specific configuration. Each configuration options are different based on the given auth provider type. OIDC:
OpenShift Auth: supports no extra configuration options. User PKI:
SAML:
IAP:
| |||
| loginUrl | String | The login URL will be provided by the backend, and may not be specified in a request. | |||
| validated | Boolean | ||||
| extraUiEndpoints |
List of |
UI endpoints which to allow in addition to | |||
| active | Boolean | ||||
| requiredAttributes | List of AuthProviderRequiredAttribute | ||||
| traits | |||||
| claimMappings |
Map of | Specifies claims from IdP token that will be copied to Rox token attributes. Each key in this map contains a path in IdP token we want to map. Path is separated by "." symbol. For example, if IdP token payload looks like:
then "a.b" would be a valid key and "a.z" is not. We support the following types of claims:
We do NOT support the following types of claims:
Each value in this map contains a Rox token attribute name we want to add claim to. If, for example, value is "groups", claim would be found in "external_user.Attributes.groups" in token. Note: we only support this feature for OIDC auth provider. | |||
| lastUpdated | Date | Last updated indicates the last time the auth provider has been updated. In case there have been tokens issued by an auth provider before this timestamp, they will be considered invalid. Subsequently, all clients will have to re-issue their tokens (either by refreshing or by an additional login attempt). | date-time |
71.1.2.15. AuthProviderServiceUpdateAuthProviderBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| enabled | Boolean |
71.1.2.16. AuthServiceUpdateAuthMachineToMachineConfigBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.17. AuthServiceUpdateAuthMachineToMachineConfigBodyConfig Copy linkLink copied to clipboard!
AuthMachineToMachineConfig determines rules for exchanging an identity token from a third party with a Central access token. The M2M stands for machine to machine, as this is the intended use-case for the config.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | GENERIC, GITHUB_ACTIONS, KUBE_SERVICE_ACCOUNT, | ||||
| tokenExpirationDuration | String | Sets the expiration of the token returned from the ExchangeAuthMachineToMachineToken API call. Possible valid time units are: s, m, h. The maximum allowed expiration duration is 24h. As an example: 2h45m. For additional information on the validation of the duration, see: https://pkg.go.dev/time#ParseDuration. | |||
| mappings | At least one mapping is required to resolve to a valid role for the access token to be successfully generated. | ||||
| issuer | String | The issuer of the related OIDC provider issuing the ID tokens to exchange. Must be non-empty string containing URL when type is GENERIC. In case of GitHub actions, this must be empty or set to https://token.actions.githubusercontent.com. Issuer is a unique key, therefore there may be at most one GITHUB_ACTIONS config, and each GENERIC config must have a distinct issuer. | |||
| traits |
71.1.2.18. AuthorizationTraceResponseResponseStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN_STATUS |
| SUCCESS |
| FAILURE |
71.1.2.19. AuthorizationTraceResponseTrace Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| scopeCheckerType | String | ||||
| builtIn |
71.1.2.20. AuthorizationTraceResponseUser Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| username | String | ||||
| friendlyName | String | ||||
| aggregatedPermissions | Map of StorageAccess | ||||
| roles | List of UserRole |
71.1.2.21. AvailableProviderTypesResponseAuthProviderType Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | String | ||||
| suggestedAttributes |
List of |
71.1.2.22. BannerConfigSize Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| SMALL |
| MEDIUM |
| LARGE |
71.1.2.23. BaseImageServiceV2UpdateBaseImageTagPatternBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| baseImageTagPattern | String |
71.1.2.24. CRSRevokeResponseCRSRevocationError Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| error | String |
71.1.2.25. CVEInfoReference Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| URI | String | ||||
| tags |
List of |
71.1.2.26. CVSSV2AccessComplexity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| ACCESS_HIGH |
| ACCESS_MEDIUM |
| ACCESS_LOW |
71.1.2.27. CVSSV2Authentication Copy linkLink copied to clipboard!
| Enum Values |
|---|
| AUTH_MULTIPLE |
| AUTH_SINGLE |
| AUTH_NONE |
71.1.2.28. CVSSV3AttackVector Copy linkLink copied to clipboard!
| Enum Values |
|---|
| ATTACK_LOCAL |
| ATTACK_ADJACENT |
| ATTACK_NETWORK |
| ATTACK_PHYSICAL |
71.1.2.29. CVSSV3Complexity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| COMPLEXITY_LOW |
| COMPLEXITY_HIGH |
71.1.2.30. CVSSV3Impact Copy linkLink copied to clipboard!
| Enum Values |
|---|
| IMPACT_NONE |
| IMPACT_LOW |
| IMPACT_HIGH |
71.1.2.31. CVSSV3Privileges Copy linkLink copied to clipboard!
| Enum Values |
|---|
| PRIVILEGE_NONE |
| PRIVILEGE_LOW |
| PRIVILEGE_HIGH |
71.1.2.32. CVSSV3Severity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| NONE |
| LOW |
| MEDIUM |
| HIGH |
| CRITICAL |
71.1.2.33. CVSSV3UserInteraction Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UI_NONE |
| UI_REQUIRED |
71.1.2.34. CentralServicesCapabilitiesCapabilityStatus Copy linkLink copied to clipboard!
- CapabilityAvailable: CapabilityAvailable means that UI and APIs should be available for users to use. This does not automatically mean that the functionality is 100% available and any calls to APIs will result in successful execution. Rather it means that users should be allowed to leverage the functionality as opposed to CapabilityDisabled when functionality should be blocked.
- CapabilityDisabled: CapabilityDisabled means the corresponding UI should be disabled and attempts to use related APIs should lead to errors.
| Enum Values |
|---|
| CapabilityAvailable |
| CapabilityDisabled |
71.1.2.35. CentralTelemetryConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| userId | String | ||||
| endpoint | String | ||||
| storageKeyV1 | String |
71.1.2.36. CloudSourceCredentials Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| secret | String | Used for single-valued authentication via long-lived tokens. | |||
| clientId | String | Used for client authentication in combination with client_secret. | |||
| clientSecret | String | Used for client authentication in combination with client_id. |
71.1.2.37. CloudSourcesServiceUpdateCloudSourceBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cloudSource | |||||
| updateCredentials | Boolean | If true, cloud_source must include valid credentials. If false, the resource must already exist and credentials in cloud_source are ignored. |
71.1.2.38. CloudSourcesServiceUpdateCloudSourceBodyCloudSource Copy linkLink copied to clipboard!
CloudSource is an integration which provides a source for discovered clusters.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | TYPE_UNSPECIFIED, TYPE_PALADIN_CLOUD, TYPE_OCM, | ||||
| credentials | |||||
| skipTestIntegration | Boolean | ||||
| paladinCloud | |||||
| ocm |
71.1.2.39. ClusterAlertsAlertEvents Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| events | List of V1AlertEvent |
71.1.2.40. ClusterHealthStatusHealthStatusLabel Copy linkLink copied to clipboard!
- UNAVAILABLE: Only collector can have unavailable status
| Enum Values |
|---|
| UNINITIALIZED |
| UNAVAILABLE |
| UNHEALTHY |
| DEGRADED |
| HEALTHY |
71.1.2.41. ClusterScanStatusSuiteStatus Copy linkLink copied to clipboard!
Additional scan status gathered from ComplianceSuite
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| phase | String | ||||
| result | String | ||||
| errorMessage | String | ||||
| lastTransitionTime | Date | date-time |
71.1.2.42. ClusterUpgradeStatusUpgradability Copy linkLink copied to clipboard!
- SENSOR_VERSION_HIGHER: SENSOR_VERSION_HIGHER occurs when we detect that the sensor is running a newer version than this Central. This is unexpected, but can occur depending on the patches a customer does. In this case, we will NOT automatically "upgrade" the sensor, since that would be a downgrade, even if the autoupgrade setting is on. The user will be allowed to manually trigger the upgrade, but they are strongly discouraged from doing so without upgrading Central first, since this is an unsupported configuration.
| Enum Values |
|---|
| UNSET |
| UP_TO_DATE |
| MANUAL_UPGRADE_REQUIRED |
| AUTO_UPGRADE_POSSIBLE |
| SENSOR_VERSION_HIGHER |
71.1.2.43. ClusterUpgradeStatusUpgradeProcessStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| active | Boolean | ||||
| id | String | ||||
| targetVersion | String | ||||
| upgraderImage | String | ||||
| initiatedAt | Date | date-time | |||
| progress | |||||
| type | UPGRADE, CERT_ROTATION, |
71.1.2.44. ClustersServicePutClusterBody Copy linkLink copied to clipboard!
Next tag: 33
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | GENERIC_CLUSTER, KUBERNETES_CLUSTER, OPENSHIFT_CLUSTER, OPENSHIFT4_CLUSTER, | ||||
| labels |
Map of | ||||
| mainImage | String | ||||
| collectorImage | String | ||||
| centralApiEndpoint | String | ||||
| runtimeSupport | Boolean | ||||
| collectionMethod | UNSET_COLLECTION, NO_COLLECTION, KERNEL_MODULE, EBPF, CORE_BPF, | ||||
| admissionController | Boolean | ||||
| admissionControllerUpdates | Boolean | ||||
| admissionControllerEvents | Boolean | ||||
| status | |||||
| dynamicConfig | |||||
| tolerationsConfig | |||||
| priority | String | int64 | |||
| healthStatus | |||||
| slimCollector | Boolean | ||||
| helmConfig | |||||
| mostRecentSensorId | |||||
| auditLogState | Map of StorageAuditLogFileState | For internal use only. | |||
| initBundleId | String | ||||
| managedBy | MANAGER_TYPE_UNKNOWN, MANAGER_TYPE_MANUAL, MANAGER_TYPE_HELM_CHART, MANAGER_TYPE_KUBERNETES_OPERATOR, | ||||
| sensorCapabilities |
List of | ||||
| admissionControllerFailOnError | Boolean |
71.1.2.45. CollectionServiceUpdateCollectionBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| description | String | ||||
| resourceSelectors | List of StorageResourceSelector | ||||
| embeddedCollectionIds |
List of |
71.1.2.46. ComplianceAggregationAggregationKey Copy linkLink copied to clipboard!
Next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| scope | UNKNOWN, STANDARD, CLUSTER, CATEGORY, CONTROL, NAMESPACE, NODE, DEPLOYMENT, CHECK, | ||||
| id | String |
71.1.2.47. ComplianceAggregationResult Copy linkLink copied to clipboard!
Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| aggregationKeys | |||||
| unit | UNKNOWN, STANDARD, CLUSTER, CATEGORY, CONTROL, NAMESPACE, NODE, DEPLOYMENT, CHECK, | ||||
| numPassing | Integer | int32 | |||
| numFailing | Integer | int32 | |||
| numSkipped | Integer | int32 |
71.1.2.48. ComplianceDomainCluster Copy linkLink copied to clipboard!
These must mirror the tags exactly in cluster.proto for backwards compatibility
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String |
71.1.2.49. ComplianceDomainDeployment Copy linkLink copied to clipboard!
This must mirror the tags exactly in deployment.proto for backwards compatibility
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| namespace | String | ||||
| namespaceId | String | ||||
| clusterId | String | ||||
| clusterName | String |
71.1.2.50. ComplianceDomainNode Copy linkLink copied to clipboard!
These must mirror the tags exactly in node.proto for backwards compatibility
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterId | String | ||||
| clusterName | String |
71.1.2.51. ComplianceResultValueEvidence Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| state | COMPLIANCE_STATE_UNKNOWN, COMPLIANCE_STATE_SKIP, COMPLIANCE_STATE_NOTE, COMPLIANCE_STATE_SUCCESS, COMPLIANCE_STATE_FAILURE, COMPLIANCE_STATE_ERROR, | ||||
| message | String | ||||
| messageId | Integer | int32 |
71.1.2.52. ComplianceRuleFix Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| platform | String | ||||
| disruption | String |
71.1.2.53. ComplianceRunResultsEntityResults Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| controlResults | Map of StorageComplianceResultValue |
71.1.2.54. ComplianceScanConfigurationServiceUpdateComplianceScanConfigurationBody Copy linkLink copied to clipboard!
Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| scanName | String | ||||
| scanConfig | |||||
| clusters |
List of |
71.1.2.55. ComplianceServiceUpdateComplianceStandardConfigBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| hideScanResults | Boolean |
71.1.2.56. ComputeEffectiveAccessScopeRequestDetail Copy linkLink copied to clipboard!
| Enum Values |
|---|
| STANDARD |
| MINIMAL |
| HIGH |
71.1.2.57. ComputeEffectiveAccessScopeRequestPayload Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| simpleRules |
71.1.2.58. ContainerConfigEnvironmentConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| value | String | ||||
| envVarSource | UNSET, RAW, SECRET_KEY, CONFIG_MAP_KEY, FIELD, RESOURCE_FIELD, UNKNOWN, |
71.1.2.59. ContainerNameAndBaselineStatusBaselineStatus Copy linkLink copied to clipboard!
- NOT_GENERATED: In current implementation, this is a temporary condition.
| Enum Values |
|---|
| INVALID |
| NOT_GENERATED |
| UNLOCKED |
| LOCKED |
71.1.2.60. CosignPublicKeyVerificationPublicKey Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| publicKeyPemEnc | String |
71.1.2.61. DBExportManifestEncodingType Copy linkLink copied to clipboard!
The encoding of the file data in the restore body, usually for compression purposes.
| Enum Values |
|---|
| UNKNOWN |
| UNCOMPREESSED |
| DEFLATED |
71.1.2.62. DBRestoreProcessStatusResumeInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| pos | String | int64 |
71.1.2.63. DBRestoreRequestHeaderLocalFileInfo Copy linkLink copied to clipboard!
LocalFileInfo provides information about the file on the local machine of the user initiating the restore process, in order to provide information to other users about ongoing restore processes.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| path | String | The full path of the file. | |||
| bytesSize | String | The size of the file, in bytes. 0 if unknown. | int64 |
71.1.2.64. DatabaseStatusDatabaseType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| Hidden |
| RocksDB |
| PostgresDB |
71.1.2.65. DeclarativeConfigHealthResourceType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| CONFIG_MAP |
| ACCESS_SCOPE |
| PERMISSION_SET |
| ROLE |
| AUTH_PROVIDER |
| GROUP |
| NOTIFIER |
| AUTH_MACHINE_TO_MACHINE_CONFIG |
71.1.2.66. DelegatedRegistryConfigDelegatedRegistry Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| path | String | ||||
| clusterId | String |
71.1.2.67. DelegatedRegistryConfigEnabledFor Copy linkLink copied to clipboard!
-
NONE: Scan all images via central services except for images from the OCP integrated registry - ALL: Scan all images via the secured clusters - SPECIFIC: Scan images that match
registriesor are from the OCP integrated registry via the secured clusters otherwise scan via central services
| Enum Values |
|---|
| NONE |
| ALL |
| SPECIFIC |
71.1.2.68. DeployDetectionResponseRun Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| alerts | List of StorageAlert |
71.1.2.69. DeploymentContainer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| image | |||||
| name | String |
71.1.2.70. DeploymentLabelsResponseLabelValues Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| values |
List of |
71.1.2.71. DeploymentListenPort Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| port | Long | int64 | |||
| l4protocol | L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY, |
71.1.2.72. DiscoveredClusterMetadataType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSPECIFIED |
| AKS |
| ARO |
| EKS |
| GKE |
| OCP |
| OSD |
| ROSA |
71.1.2.73. DryRunResponseAlert Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployment | String | ||||
| violations |
List of |
71.1.2.74. DynamicClusterConfigProcessIndicatorsConfig Copy linkLink copied to clipboard!
Configure per-namespace persistence for ProcessIndicators
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| noPersistence | Boolean | Specifies whether to persist process indicators independently from other configuratons. If true, the filters above are ignored, and no process indicators are persisted. If false (the protobuf default for booleans), process indicators are persisted according to namespace_filter and exclude_openshift_ns. | |||
| excludeNamespaceFilter | String | A regex specifying to not persist process indicators from specified namespaces. E.g. namespace_filter: "test-.*" will instruct Central to not persist any process indicator coming from the "test-filtering" namespace. | |||
| excludeOpenshiftNs | Boolean | A short-cut to not persist process indicators from openshift namespaces. Equivalent to namespace_filter: "openshift-.*". |
71.1.2.75. ECRConfigAuthorizationData Copy linkLink copied to clipboard!
An authorization data represents the IAM authentication credentials and can be used to access any Amazon ECR registry that the IAM principal has access to.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| username | String | ||||
| password | String | ||||
| expiresAt | Date | date-time |
71.1.2.76. EffectiveAccessScopeCluster Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| state | UNKNOWN, INCLUDED, EXCLUDED, PARTIAL, | ||||
| labels |
Map of | ||||
| namespaces |
71.1.2.77. EmailAuthMethod Copy linkLink copied to clipboard!
| Enum Values |
|---|
| DISABLED |
| PLAIN |
| LOGIN |
71.1.2.78. EmbeddedImageScanComponentExecutable Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| path | String | ||||
| dependencies |
List of |
71.1.2.79. EmbeddedVulnerabilityScoreVersion Copy linkLink copied to clipboard!
ScoreVersion can be deprecated ROX-26066
- V2: No unset for automatic backwards compatibility
| Enum Values |
|---|
| V2 |
| V3 |
71.1.2.80. EmbeddedVulnerabilityVulnerabilityType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN_VULNERABILITY |
| IMAGE_VULNERABILITY |
| K8S_VULNERABILITY |
| ISTIO_VULNERABILITY |
| NODE_VULNERABILITY |
| OPENSHIFT_VULNERABILITY |
71.1.2.81. EnvironmentConfigEnvVarSource Copy linkLink copied to clipboard!
For any update to EnvVarSource, please also update 'ui/src/messages/common.js'
| Enum Values |
|---|
| UNSET |
| RAW |
| SECRET_KEY |
| CONFIG_MAP_KEY |
| FIELD |
| RESOURCE_FIELD |
| UNKNOWN |
71.1.2.82. ExceptionExpiryExpiryType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| TIME |
| ALL_CVE_FIXABLE |
| ANY_CVE_FIXABLE |
71.1.2.83. ExclusionDeployment Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| scope |
71.1.2.84. ExclusionImage Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.85. ExternalBackupServicePutExternalBackupBody Copy linkLink copied to clipboard!
Next available tag: 10
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| schedule | |||||
| backupsToKeep | Integer | int32 | |||
| s3 | |||||
| gcs | |||||
| s3compatible | |||||
| includeCertificates | Boolean |
71.1.2.86. ExternalBackupServiceUpdateExternalBackupBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| externalBackup | |||||
| updatePassword | Boolean | When false, use the stored credentials of an existing external backup configuration given its ID. |
71.1.2.87. FileAccessFileMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| uid | Long | int64 | |||
| gid | Long | int64 | |||
| mode | Long | int64 | |||
| username | String | ||||
| group | String |
71.1.2.88. FileAccessOperation Copy linkLink copied to clipboard!
| Enum Values |
|---|
| CREATE |
| UNLINK |
| RENAME |
| PERMISSION_CHANGE |
| OWNERSHIP_CHANGE |
| OPEN |
71.1.2.89. GenerateNetworkPoliciesRequestDeleteExistingPoliciesMode Copy linkLink copied to clipboard!
- NONE: Do not delete any existing network policies.
- GENERATED_ONLY: Delete any existing auto-generated network policies.
- ALL: Delete all existing network policies in the respective namespace.
| Enum Values |
|---|
| UNKNOWN |
| NONE |
| GENERATED_ONLY |
| ALL |
71.1.2.90. GetAlertTimeseriesResponseClusterAlerts Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster | String | ||||
| severities | List of ClusterAlertsAlertEvents |
71.1.2.91. GetAlertsCountsRequestRequestGroup Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| CATEGORY |
| CLUSTER |
71.1.2.92. GetAlertsCountsResponseAlertGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| group | String | ||||
| counts | List of AlertGroupAlertCounts |
71.1.2.93. GetLoginAuthProvidersResponseLoginAuthProvider Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| loginUrl | String |
71.1.2.94. GetSensorUpgradeConfigResponseSensorAutoUpgradeFeatureStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| NOT_SUPPORTED |
| SUPPORTED |
71.1.2.95. GetSensorUpgradeConfigResponseUpgradeConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enableAutoUpgrade | Boolean | ||||
| autoUpgradeFeature | GetSensorUpgradeConfigResponseSensorAutoUpgradeFeatureStatus | NOT_SUPPORTED, SUPPORTED, |
71.1.2.96. GoogleRpcStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| code | Integer | int32 | |||
| message | String | ||||
| details | List of ProtobufAny |
71.1.2.97. GooglerpcStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| code | Integer | int32 | |||
| message | String |
71.1.2.98. GroupLabels Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| labels |
List of | A list of labels to aggregate on. The complete list of labels for the given metric group can be found in the documentation, or in the API error message, returned when an invalid label is attempted to be added. | |||
| includeFilters |
Map of | A map of label name to a filter regular expression for this label value. See the RE2 syntax reference: https://github.com/google/re2/wiki/Syntax. If include_filters are specified, a metric record is only counted if all label values match the according label expression. Patterns are full-match only (automatically wrapped with ^ and $). | |||
| excludeFilters |
Map of | A map of label name to a filter regular expression for this label value. See the RE2 syntax reference: https://github.com/google/re2/wiki/Syntax. If exclude_filters are specified, a metric record is dropped if any label value matches the according label expression. Patterns are full-match only (automatically wrapped with ^ and $). Exclude filters are applied after include filters. |
71.1.2.99. ImageIntegrationServicePutImageIntegrationBody Copy linkLink copied to clipboard!
Next Tag: 25
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| categories | List of StorageImageIntegrationCategory | ||||
| clairify | |||||
| scannerV4 | |||||
| docker | |||||
| quay | |||||
| ecr | |||||
| | |||||
| clair | |||||
| clairV4 | |||||
| ibm | |||||
| azure | |||||
| autogenerated | Boolean | ||||
| clusterId | String | ||||
| skipTestIntegration | Boolean | ||||
| source |
71.1.2.100. ImageIntegrationServiceUpdateImageIntegrationBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config | |||||
| updatePassword | Boolean | When false, use the stored credentials of an existing image integration given its ID. |
71.1.2.101. ImagePullSecretRegistry Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| username | String |
71.1.2.102. ImageSBOMRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster | String | Cluster to delegate scan to, may be the cluster’s name or ID. | |||
| namespace | String | Namespace on the secured cluster from which to read context information when delegating image scans, specifically pull secrets to access the image registry. | |||
| imageName | X | String | Image name and reference. (e.g. nginx:latest or nginx@sha256:…) | ||
| force | Boolean | Bypass Central’s cache for the image and force a new pull from the Scanner | |||
| digest | String | Image digest if not already part of image name |
71.1.2.103. InitBundleMetaImpactedCluster Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| id | String |
71.1.2.104. InitBundleRevokeResponseInitBundleRevocationError Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| error | String | ||||
| impactedClusters | List of InitBundleMetaImpactedCluster |
71.1.2.105. JiraPriorityMapping Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| priorityName | String |
71.1.2.106. KeyValueAttrsKeyValueAttr Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| value | String |
71.1.2.107. LabelSelectorOperator Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| IN |
| NOT_IN |
| EXISTS |
| NOT_EXISTS |
71.1.2.108. LabelSelectorRequirement Copy linkLink copied to clipboard!
Next available tag: 4
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| op | UNKNOWN, IN, NOT_IN, EXISTS, NOT_EXISTS, | ||||
| values |
List of |
71.1.2.109. ListAlertCommonEntityInfo Copy linkLink copied to clipboard!
Fields common to all entities that an alert might belong to.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterName | String | ||||
| namespace | String | ||||
| clusterId | String | ||||
| namespaceId | String | ||||
| resourceType | DEPLOYMENT, SECRETS, CONFIGMAPS, CLUSTER_ROLES, CLUSTER_ROLE_BINDINGS, NETWORK_POLICIES, SECURITY_CONTEXT_CONSTRAINTS, EGRESS_FIREWALLS, NODE, |
71.1.2.110. ListAlertNodeEntity Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.111. ListAlertPolicyDevFields Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| SORTName | String |
71.1.2.112. ListAlertResourceEntity Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.113. ListDeploymentsWithProcessInfoResponseDeploymentWithProcessInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployment | |||||
| baselineStatuses |
71.1.2.114. MetadataLicenseStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| NONE |
| INVALID |
| EXPIRED |
| RESTARTING |
| VALID |
71.1.2.115. MetadataProviderType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| PROVIDER_TYPE_UNSPECIFIED |
| PROVIDER_TYPE_AWS |
| PROVIDER_TYPE_GCP |
| PROVIDER_TYPE_AZURE |
71.1.2.116. MicrosoftSentinelClientCertAuthConfig Copy linkLink copied to clipboard!
client certificate which is used for authentication
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clientCert | String | PEM encoded ASN.1 DER format. | |||
| privateKey | String | PEM encoded PKCS #8, ASN.1 DER format. |
71.1.2.117. MicrosoftSentinelDataCollectionRuleConfig Copy linkLink copied to clipboard!
DataCollectionRuleConfig contains information about the data collection rule which is a config per notifier type.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| streamName | String | ||||
| dataCollectionRuleId | String | ||||
| enabled | Boolean |
71.1.2.118. NetworkBaselineServiceGetNetworkBaselineStatusForFlowsBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| peers | List of V1NetworkBaselineStatusPeer |
71.1.2.119. NetworkBaselineServiceModifyBaselineStatusForPeersBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| peers | List of V1NetworkBaselinePeerStatus |
71.1.2.120. NetworkEntityInfoDeployment Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| namespace | String | ||||
| cluster | String | ||||
| listenPorts | List of DeploymentListenPort |
71.1.2.121. NetworkEntityInfoExternalSource Copy linkLink copied to clipboard!
Update normalizeDupNameExtSrcs(…) in central/networkgraph/aggregator/aggregator.go whenever this message is updated.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| cidr | String | ||||
| default | Boolean |
| |||
| discovered | Boolean |
|
71.1.2.122. NetworkFlowInfoEntity Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| entityType | UNKNOWN_TYPE, DEPLOYMENT, INTERNET, LISTEN_ENDPOINT, EXTERNAL_SOURCE, INTERNAL_ENTITIES, | ||||
| deploymentNamespace | String | ||||
| deploymentType | String | ||||
| port | Integer | int32 |
71.1.2.123. NetworkGraphServiceCreateExternalNetworkEntityBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity |
71.1.2.124. NetworkGraphServicePatchExternalNetworkEntityBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.125. NetworkPolicyServiceApplyNetworkPolicyYamlForDeploymentBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| modification |
71.1.2.126. NetworkPolicyServiceGetBaselineGeneratedNetworkPolicyForDeploymentBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deleteExisting | UNKNOWN, NONE, GENERATED_ONLY, ALL, | ||||
| includePorts | Boolean |
71.1.2.127. NextAvailableTag10 Copy linkLink copied to clipboard!
Next available tag: 10
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| schedule | |||||
| backupsToKeep | Integer | int32 | |||
| s3 | |||||
| gcs | |||||
| s3compatible | |||||
| includeCertificates | Boolean |
71.1.2.128. NextTag21 Copy linkLink copied to clipboard!
Next Tag: 21
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| uiEndpoint | String | ||||
| labelKey | String | ||||
| labelDefault | String | ||||
| jira | |||||
| | |||||
| cscc | |||||
| splunk | |||||
| pagerduty | |||||
| generic | |||||
| sumologic | |||||
| awsSecurityHub | |||||
| syslog | |||||
| microsoftSentinel | |||||
| notifierSecret | String | ||||
| traits |
71.1.2.129. NextTag25 Copy linkLink copied to clipboard!
Next Tag: 25
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| categories | List of StorageImageIntegrationCategory | ||||
| clairify | |||||
| scannerV4 | |||||
| docker | |||||
| quay | |||||
| ecr | |||||
| | |||||
| clair | |||||
| clairV4 | |||||
| ibm | |||||
| azure | |||||
| autogenerated | Boolean | ||||
| clusterId | String | ||||
| skipTestIntegration | Boolean | ||||
| source |
71.1.2.130. NodeScanScanner Copy linkLink copied to clipboard!
| Enum Values |
|---|
| SCANNER |
| SCANNER_V4 |
71.1.2.131. NotifierServicePutNotifierBody Copy linkLink copied to clipboard!
Next Tag: 21
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| uiEndpoint | String | ||||
| labelKey | String | ||||
| labelDefault | String | ||||
| jira | |||||
| | |||||
| cscc | |||||
| splunk | |||||
| pagerduty | |||||
| generic | |||||
| sumologic | |||||
| awsSecurityHub | |||||
| syslog | |||||
| microsoftSentinel | |||||
| notifierSecret | String | ||||
| traits |
71.1.2.132. NotifierServiceUpdateNotifierBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| notifier | |||||
| updatePassword | Boolean | When false, use the stored credentials of an existing notifier configuration given its ID. |
71.1.2.133. PlatformComponentConfigRule Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| namespaceRule |
71.1.2.134. PodContainerInstanceList Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| instances | List of StorageContainerInstance |
71.1.2.135. PolicyMitreAttackVectors Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| tactic | String | ||||
| techniques |
List of |
71.1.2.136. PolicyServiceEnableDisablePolicyNotificationBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| notifierIds |
List of | ||||
| disable | Boolean |
71.1.2.137. PolicyServicePatchPolicyBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| disabled | Boolean |
71.1.2.138. PolicyServicePutPolicyBody Copy linkLink copied to clipboard!
Next tag: 28
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | Name of the policy. Must be unique. | |||
| description | String | Free-form text description of this policy. | |||
| rationale | String | ||||
| remediation | String | Describes how to remediate a violation of this policy. | |||
| disabled | Boolean | Toggles whether or not this policy will be executing and actively firing alerts. | |||
| categories |
List of | List of categories that this policy falls under. Category names must already exist in Central. | |||
| lifecycleStages | List of StorageLifecycleStage | Describes which policy lifecylce stages this policy applies to. Choices are DEPLOY, BUILD, and RUNTIME. | |||
| eventSource | NOT_APPLICABLE, DEPLOYMENT_EVENT, AUDIT_LOG_EVENT, NODE_EVENT, | ||||
| exclusions | List of StorageExclusion | Define deployments or images that should be excluded from this policy. | |||
| scope | List of StorageScope | Defines clusters, namespaces, and deployments that should be included in this policy. No scopes defined includes everything. | |||
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| enforcementActions | List of StorageEnforcementAction | FAIL_DEPLOYMENT_CREATE_ENFORCEMENT takes effect only if admission control webhook is configured to enforce on object creates/updates. FAIL_KUBE_REQUEST_ENFORCEMENT takes effect only if admission control webhook is enabled to listen on exec and port-forward events. FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT takes effect only if admission control webhook is configured to enforce on object updates. Lists the enforcement actions to take when a violation from this policy is identified. Possible value are UNSET_ENFORCEMENT, SCALE_TO_ZERO_ENFORCEMENT, UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT, KILL_POD_ENFORCEMENT, FAIL_BUILD_ENFORCEMENT, FAIL_KUBE_REQUEST_ENFORCEMENT, FAIL_DEPLOYMENT_CREATE_ENFORCEMENT, and. FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT. | |||
| notifiers |
List of | List of IDs of the notifiers that should be triggered when a violation from this policy is identified. IDs should be in the form of a UUID and are found through the Central API. | |||
| lastUpdated | Date | date-time | |||
| SORTName | String | For internal use only. | |||
| SORTLifecycleStage | String | For internal use only. | |||
| SORTEnforcement | Boolean | For internal use only. | |||
| policyVersion | String | ||||
| policySections | List of StoragePolicySection | PolicySections define the violation criteria for this policy. | |||
| mitreAttackVectors | List of PolicyMitreAttackVectors | ||||
| criteriaLocked | Boolean | Read-only field. If true, the policy’s criteria fields are rendered read-only. | |||
| mitreVectorsLocked | Boolean | Read-only field. If true, the policy’s MITRE ATT&CK fields are rendered read-only. | |||
| isDefault | Boolean | Read-only field. Indicates the policy is a default policy if true and a custom policy if false. | |||
| source | IMPERATIVE, DECLARATIVE, |
71.1.2.139. PortConfigExposureInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| level | UNSET, EXTERNAL, NODE, INTERNAL, HOST, ROUTE, | ||||
| serviceName | String | ||||
| serviceId | String | ||||
| serviceClusterIp | String | ||||
| servicePort | Integer | int32 | |||
| nodePort | Integer | int32 | |||
| externalIps |
List of | ||||
| externalHostnames |
List of |
71.1.2.140. PortConfigExposureLevel Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| EXTERNAL |
| NODE |
| INTERNAL |
| HOST |
| ROUTE |
71.1.2.141. ProcessListeningOnPortEndpoint Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| port | Long | int64 | |||
| protocol | L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY, |
71.1.2.142. ProcessSignalLineageInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| parentUid | Long | int64 | |||
| parentExecFilePath | String |
71.1.2.143. PrometheusMetricsGroup Copy linkLink copied to clipboard!
A group is a collection of metrics that are computed by the same aggregator. Metrics in a group may use different subsets of a complete list of labels supported by the aggregator.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| gatheringPeriodMinutes | Long | The gathering period for periodically gathered metrics. If set to zero, gathering is disabled. | int64 | ||
| descriptors | Map of GroupLabels | Metric descriptors is a map of metric names to the list of allowed labels. |
71.1.2.144. ProtobufAny Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| @type | String |
71.1.2.145. QuayConfigRobotAccount Copy linkLink copied to clipboard!
Robot account is Quay’s named tokens that can be granted permissions on multiple repositories under an organization. It’s Quay’s recommended authentication model when possible (i.e. registry integration)
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| username | String | ||||
| password | String | The server will mask the value of this password in responses and logs. |
71.1.2.146. ReportConfigurationReportType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| VULNERABILITY |
71.1.2.147. ReportConfigurationServiceUpdateReportConfigurationBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| reportConfig |
71.1.2.148. ReportLastRunStatusRunStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| SUCCESS |
| FAILURE |
71.1.2.149. ReportServiceUpdateReportConfigurationBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| description | String | ||||
| type | VULNERABILITY, | ||||
| vulnReportFilters | |||||
| schedule | |||||
| resourceScope | |||||
| notifiers | List of V2NotifierConfiguration |
71.1.2.150. ResourceCollectionEmbeddedResourceCollection Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String |
71.1.2.151. ResourceResourceType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| SECRETS |
| CONFIGMAPS |
| CLUSTER_ROLES |
| CLUSTER_ROLE_BINDINGS |
| NETWORK_POLICIES |
| SECURITY_CONTEXT_CONSTRAINTS |
| EGRESS_FIREWALLS |
71.1.2.152. ResultFactor Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| message | String | ||||
| url | String |
71.1.2.153. RiskResult Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| factors | List of ResultFactor | ||||
| score | Float | float |
71.1.2.154. RoleServicePutPermissionSetBody Copy linkLink copied to clipboard!
This encodes a set of permissions for StackRox resources.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
| |||
| description | String | ||||
| resourceToAccess | Map of StorageAccess | ||||
| traits |
71.1.2.155. RoleServicePutSimpleAccessScopeBody Copy linkLink copied to clipboard!
Simple access scope is a (simple) selection criteria for scoped resources. It does not allow multi-component AND-rules nor set operations on names.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
| |||
| description | String | ||||
| rules | |||||
| traits |
71.1.2.156. RoleServiceUpdateRoleBody Copy linkLink copied to clipboard!
A role specifies which actions are allowed for which subset of cluster objects. Permissions be can either specified directly via setting resource_to_access together with global_access or by referencing a permission set by its id in permission_set_name.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| description | String | ||||
| permissionSetId | String | The associated PermissionSet and AccessScope for this Role. | |||
| accessScopeId | String | ||||
| globalAccess | NO_ACCESS, READ_ACCESS, READ_WRITE_ACCESS, | ||||
| resourceToAccess | Map of StorageAccess |
Deprecated 2021-04-20 in favor of | |||
| traits |
71.1.2.157. RpcStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| code | Integer | int32 | |||
| message | String | ||||
| details | List of ProtobufAny |
71.1.2.158. RuleNamespaceRule Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| regex | String |
71.1.2.159. SBOMSPDX23Document Copy linkLink copied to clipboard!
SPDX 2.3 document, refer to https://spdx.github.io/spdx-spec/v2.3/ for more details.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| spdxVersion | String | ||||
| dataLicense | String | ||||
| SPDXID | String | ||||
| name | String | ||||
| documentNamespace | String | ||||
| creationInfo | |||||
| packages | List of SBOMSPDX23DocumentPackagesInner | ||||
| relationships |
71.1.2.160. SBOMSPDX23DocumentCreationInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| created | String | ||||
| creators |
List of |
71.1.2.161. SBOMSPDX23DocumentPackagesInner Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| SPDXID | Object | ||||
| name | String | ||||
| versionInfo | String | ||||
| packageFileName | String | ||||
| downloadLocation | String | ||||
| filesAnalyzed | Boolean | ||||
| primaryPackagePurpose | String |
71.1.2.162. SBOMSPDX23DocumentRelationshipsInner Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| spdxElementId | String | ||||
| relatedSpdxElement | String | ||||
| relationshipType | String |
71.1.2.163. ScheduleDaysOfMonth Copy linkLink copied to clipboard!
1 for 1st, 2 for 2nd …. 31 for 31st
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| days |
List of | int32 |
71.1.2.164. ScheduleDaysOfWeek Copy linkLink copied to clipboard!
Sunday = 0, Monday = 1, …. Saturday = 6
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| days |
List of | int32 |
71.1.2.165. ScheduleIntervalType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| DAILY |
| WEEKLY |
| MONTHLY |
71.1.2.166. ScheduleWeeklyInterval Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| day | Integer | int32 |
71.1.2.167. ScopeImage Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| registry | String | ||||
| remote | String | ||||
| tag | String |
71.1.2.168. SearchResponseCount Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| category | SEARCH_UNSET, ALERTS, IMAGES, IMAGE_COMPONENTS, IMAGE_VULN_EDGE, IMAGE_COMPONENT_EDGE, POLICIES, DEPLOYMENTS, PODS, SECRETS, PROCESS_INDICATORS, COMPLIANCE, CLUSTERS, NAMESPACES, NODES, NODE_COMPONENTS, NODE_VULN_EDGE, NODE_COMPONENT_EDGE, NODE_COMPONENT_CVE_EDGE, COMPLIANCE_STANDARD, COMPLIANCE_CONTROL_GROUP, COMPLIANCE_CONTROL, SERVICE_ACCOUNTS, ROLES, ROLEBINDINGS, REPORT_CONFIGURATIONS, PROCESS_BASELINES, SUBJECTS, RISKS, VULNERABILITIES, CLUSTER_VULNERABILITIES, IMAGE_VULNERABILITIES, NODE_VULNERABILITIES, COMPONENT_VULN_EDGE, CLUSTER_VULN_EDGE, NETWORK_ENTITY, VULN_REQUEST, NETWORK_BASELINE, NETWORK_POLICIES, PROCESS_BASELINE_RESULTS, COMPLIANCE_METADATA, COMPLIANCE_RESULTS, COMPLIANCE_DOMAIN, CLUSTER_HEALTH, POLICY_CATEGORIES, IMAGE_INTEGRATIONS, COLLECTIONS, POLICY_CATEGORY_EDGE, PROCESS_LISTENING_ON_PORT, API_TOKEN, REPORT_METADATA, REPORT_SNAPSHOT, COMPLIANCE_INTEGRATIONS, COMPLIANCE_SCAN_CONFIG, COMPLIANCE_SCAN, COMPLIANCE_CHECK_RESULTS, BLOB, ADMINISTRATION_EVENTS, COMPLIANCE_SCAN_CONFIG_STATUS, ADMINISTRATION_USAGE, COMPLIANCE_PROFILES, COMPLIANCE_RULES, COMPLIANCE_SCAN_SETTING_BINDINGS, COMPLIANCE_SUITES, CLOUD_SOURCES, DISCOVERED_CLUSTERS, COMPLIANCE_REMEDIATIONS, COMPLIANCE_BENCHMARKS, AUTH_PROVIDERS, COMPLIANCE_REPORT_SNAPSHOT, IMAGE_COMPONENTS_V2, IMAGE_VULNERABILITIES_V2, IMAGES_V2, VIRTUAL_MACHINES, BASE_IMAGES, BASE_IMAGE_LAYERS, VIRTUAL_MACHINES_V2, VIRTUAL_MACHINE_SCANS_V2, VIRTUAL_MACHINE_COMPONENTS_V2, VIRTUAL_MACHINE_VULNERABILITIES_V2, IMAGE_CVE_INFOS, | ||||
| count | String | int64 |
71.1.2.169. SearchResultMatches Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| values |
List of |
71.1.2.170. SeccompProfileProfileType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNCONFINED |
| RUNTIME_DEFAULT |
| LOCALHOST |
71.1.2.171. SecurityContextSELinux Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| user | String | ||||
| role | String | ||||
| type | String | ||||
| level | String |
71.1.2.172. SecurityContextSeccompProfile Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | UNCONFINED, RUNTIME_DEFAULT, LOCALHOST, | ||||
| localhostProfile | String |
71.1.2.173. SetBasedLabelSelectorOperator Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| IN |
| NOT_IN |
| EXISTS |
| NOT_EXISTS |
71.1.2.174. SetBasedLabelSelectorRequirement Copy linkLink copied to clipboard!
Next available tag: 4
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| op | UNKNOWN, IN, NOT_IN, EXISTS, NOT_EXISTS, | ||||
| values |
List of |
71.1.2.175. SignatureIntegrationServicePutSignatureIntegrationBody Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| cosign | |||||
| cosignCertificates | |||||
| transparencyLog | |||||
| traits |
71.1.2.176. SimpleAccessScopeRules Copy linkLink copied to clipboard!
Each element of any repeated field is an individual rule. Rules are joined by logical OR: if there exists a rule allowing resource x, x is in the access scope.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| includedClusterIds |
List of | included_cluster_ids contains a list of clusters to which full access is granted, identified by their IDs. | |||
| includedClusters |
List of | included_clusters contains a list of clusters to which full access is granted, identified by their names. | |||
| includedNamespaces | List of SimpleAccessScopeRulesNamespace | ||||
| clusterLabelSelectors | List of StorageSetBasedLabelSelector | ||||
| namespaceLabelSelectors | List of StorageSetBasedLabelSelector |
71.1.2.177. SimpleAccessScopeRulesNamespace Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | The namespace field and at least one cluster field must be set. The cluster ID takes precedence over the cluster name when a cluster with that ID exists. | |||
| clusterName | String | ||||
| namespaceName | String |
71.1.2.178. StorageAWSProviderMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| accountId | String |
71.1.2.179. StorageAWSSecurityHub Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| region | String | ||||
| credentials | |||||
| accountId | String |
71.1.2.180. StorageAWSSecurityHubCredentials Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| accessKeyId | String | ||||
| secretAccessKey | String | ||||
| stsEnabled | Boolean |
71.1.2.181. StorageAccess Copy linkLink copied to clipboard!
| Enum Values |
|---|
| NO_ACCESS |
| READ_ACCESS |
| READ_WRITE_ACCESS |
71.1.2.182. StorageAdministrationEventsConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| retentionDurationDays | Long | int64 |
71.1.2.183. StorageAdmissionControlHealthInfo Copy linkLink copied to clipboard!
AdmissionControlHealthInfo carries data about admission control deployment but does not include admission control health status derived from this data. Aggregated admission control health status is not included because it is derived in central and not in the component that first reports AdmissionControlHealthInfo (sensor).
The following fields are made optional/nullable because there can be errors when trying to obtain them and the default value of 0 might be confusing with the actual value 0. In case an error happens when trying to obtain a certain field, it will be absent (instead of having the default value).
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| totalDesiredPods | Integer | int32 | |||
| totalReadyPods | Integer | int32 | |||
| statusErrors |
List of | Collection of errors that occurred while trying to obtain admission control health info. |
71.1.2.184. StorageAdmissionControllerConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean | ||||
| timeoutSeconds | Integer | int32 | |||
| scanInline | Boolean | ||||
| disableBypass | Boolean | ||||
| enforceOnUpdates | Boolean |
71.1.2.185. StorageAdvisory Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| link | String |
71.1.2.186. StorageAlert Copy linkLink copied to clipboard!
Next available tag: 26
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| policy | |||||
| lifecycleStage | DEPLOY, BUILD, RUNTIME, | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| namespace | String | ||||
| namespaceId | String | ||||
| deployment | |||||
| image | |||||
| resource | |||||
| node | |||||
| violations | List of AlertViolation | For run-time phase alert, a maximum of 40 violations are retained. | |||
| processViolation | |||||
| enforcement | |||||
| time | Date | date-time | |||
| firstOccurred | Date | date-time | |||
| resolvedAt | Date | The time at which the alert was resolved. Only set if ViolationState is RESOLVED. | date-time | ||
| state | ACTIVE, RESOLVED, ATTEMPTED, | ||||
| platformComponent | Boolean | ||||
| entityType | UNSET, DEPLOYMENT, CONTAINER_IMAGE, RESOURCE, NODE, | ||||
| enforcementCount | Integer | Cached enforcement count, computed on upsert. For RUNTIME+KILL_POD alerts this is the number of unique pods killed. For DEPLOY alerts with enforcement this is 1. Avoids deserializing the full alert blob for ListAlert queries. | int32 |
71.1.2.187. StorageAlertDeployment Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| namespace | String | This field has to be duplicated in Alert for scope management and search. | |||
| namespaceId | String | This field has to be duplicated in Alert for scope management and search. | |||
| labels |
Map of | ||||
| clusterId | String | This field has to be duplicated in Alert for scope management and search. | |||
| clusterName | String | This field has to be duplicated in Alert for scope management and search. | |||
| containers | List of AlertDeploymentContainer | ||||
| annotations |
Map of | ||||
| inactive | Boolean |
71.1.2.188. StorageAlertResource Copy linkLink copied to clipboard!
Represents an alert on a kubernetes resource other than a deployment (configmaps, secrets, etc.)
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| resourceType | UNKNOWN, SECRETS, CONFIGMAPS, CLUSTER_ROLES, CLUSTER_ROLE_BINDINGS, NETWORK_POLICIES, SECURITY_CONTEXT_CONSTRAINTS, EGRESS_FIREWALLS, | ||||
| name | String | ||||
| clusterId | String | This field has to be duplicated in Alert for scope management and search. | |||
| clusterName | String | This field has to be duplicated in Alert for scope management and search. | |||
| namespace | String | This field has to be duplicated in Alert for scope management and search. | |||
| namespaceId | String | This field has to be duplicated in Alert for scope management and search. |
71.1.2.189. StorageAlertRetentionConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| resolvedDeployRetentionDurationDays | Integer | int32 | |||
| deletedRuntimeRetentionDurationDays | Integer |
This runtime alert retention configuration takes precedence after | int32 | ||
| allRuntimeRetentionDurationDays | Integer | This runtime alert retention configuration has highest precedence. All runtime alerts, including attempted alerts and deleted deployment alerts, are deleted even if respective retention is longer. | int32 | ||
| attemptedDeployRetentionDurationDays | Integer | int32 | |||
| attemptedRuntimeRetentionDurationDays | Integer | This runtime alert retention configuration has lowest precedence. | int32 |
71.1.2.190. StorageAuditLogFileState Copy linkLink copied to clipboard!
AuditLogFileState tracks the last audit log event timestamp and ID that was collected by Compliance For internal use only
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collectLogsSince | Date | date-time | |||
| lastAuditId | String |
71.1.2.191. StorageAuthProvider Copy linkLink copied to clipboard!
Next Tag: 15.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| uiEndpoint | String | ||||
| enabled | Boolean | ||||
| config |
Map of | Config holds auth provider specific configuration. Each configuration options are different based on the given auth provider type. OIDC:
OpenShift Auth: supports no extra configuration options. User PKI:
SAML:
IAP:
| |||
| loginUrl | String | The login URL will be provided by the backend, and may not be specified in a request. | |||
| validated | Boolean | ||||
| extraUiEndpoints |
List of |
UI endpoints which to allow in addition to | |||
| active | Boolean | ||||
| requiredAttributes | List of AuthProviderRequiredAttribute | ||||
| traits | |||||
| claimMappings |
Map of | Specifies claims from IdP token that will be copied to Rox token attributes. Each key in this map contains a path in IdP token we want to map. Path is separated by "." symbol. For example, if IdP token payload looks like:
then "a.b" would be a valid key and "a.z" is not. We support the following types of claims:
We do NOT support the following types of claims:
Each value in this map contains a Rox token attribute name we want to add claim to. If, for example, value is "groups", claim would be found in "external_user.Attributes.groups" in token. Note: we only support this feature for OIDC auth provider. | |||
| lastUpdated | Date | Last updated indicates the last time the auth provider has been updated. In case there have been tokens issued by an auth provider before this timestamp, they will be considered invalid. Subsequently, all clients will have to re-issue their tokens (either by refreshing or by an additional login attempt). | date-time |
71.1.2.192. StorageAutoLockProcessBaselinesConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean |
71.1.2.193. StorageAzureConfig Copy linkLink copied to clipboard!
Azure container registry configuration. Used by integrations of type "azure".
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| username | String | ||||
| password | String | The password for the integration. The server will mask the value of this credential in responses and logs. | |||
| wifEnabled | Boolean | Enables authentication with short-lived tokens using Azure managed identities or Azure workload identities. |
71.1.2.194. StorageAzureProviderMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| subscriptionId | String |
71.1.2.195. StorageBackupInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| backupLastRunAt | Date | date-time | |||
| status | FAIL, PASS, | ||||
| requestor |
71.1.2.196. StorageBannerConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean | ||||
| text | String | ||||
| size | UNSET, SMALL, MEDIUM, LARGE, | ||||
| color | String | ||||
| backgroundColor | String |
71.1.2.197. StorageBaseImageInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| baseImageId | String | ||||
| baseImageFullName | String | ||||
| baseImageDigest | String | ||||
| created | Date | date-time | |||
| maxLayerIndex | Integer | Index of the last base image layer, taking into account "empty layers" (aka. metadata history without SHA). | int32 |
71.1.2.198. StorageBaselineElement Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| element | |||||
| auto | Boolean |
71.1.2.199. StorageBaselineItem Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| processName | String |
71.1.2.200. StorageBooleanOperator Copy linkLink copied to clipboard!
| Enum Values |
|---|
| OR |
| AND |
71.1.2.201. StorageCSCC Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| serviceAccount | String | The service account for the integration. The server will mask the value of this credential in responses and logs. | |||
| sourceId | String | ||||
| wifEnabled | Boolean |
71.1.2.202. StorageCVEInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cve | String | ||||
| summary | String | ||||
| link | String | ||||
| publishedOn | Date | This indicates the timestamp when the cve was first published in the cve feeds. | date-time | ||
| createdAt | Date | Time when the CVE was first seen in the system. | date-time | ||
| lastModified | Date | date-time | |||
| scoreVersion | V2, V3, UNKNOWN, | ||||
| cvssV2 | |||||
| cvssV3 | |||||
| references | List of CVEInfoReference | ||||
| cvssMetrics | List of StorageCVSSScore | ||||
| epss |
71.1.2.203. StorageCVEInfoScoreVersion Copy linkLink copied to clipboard!
ScoreVersion can be deprecated ROX-26066
- V2: No unset for automatic backwards compatibility
| Enum Values |
|---|
| V2 |
| V3 |
| UNKNOWN |
71.1.2.204. StorageCVSSScore Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| source | SOURCE_UNKNOWN, SOURCE_RED_HAT, SOURCE_OSV, SOURCE_NVD, | ||||
| url | String | ||||
| cvssv2 | |||||
| cvssv3 |
71.1.2.205. StorageCVSSV2 Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| vector | String | ||||
| attackVector | ATTACK_LOCAL, ATTACK_ADJACENT, ATTACK_NETWORK, | ||||
| accessComplexity | ACCESS_HIGH, ACCESS_MEDIUM, ACCESS_LOW, | ||||
| authentication | AUTH_MULTIPLE, AUTH_SINGLE, AUTH_NONE, | ||||
| confidentiality | IMPACT_NONE, IMPACT_PARTIAL, IMPACT_COMPLETE, | ||||
| integrity | IMPACT_NONE, IMPACT_PARTIAL, IMPACT_COMPLETE, | ||||
| availability | IMPACT_NONE, IMPACT_PARTIAL, IMPACT_COMPLETE, | ||||
| exploitabilityScore | Float | float | |||
| impactScore | Float | float | |||
| score | Float | float | |||
| severity | UNKNOWN, LOW, MEDIUM, HIGH, |
71.1.2.206. StorageCVSSV2AttackVector Copy linkLink copied to clipboard!
| Enum Values |
|---|
| ATTACK_LOCAL |
| ATTACK_ADJACENT |
| ATTACK_NETWORK |
71.1.2.207. StorageCVSSV2Impact Copy linkLink copied to clipboard!
| Enum Values |
|---|
| IMPACT_NONE |
| IMPACT_PARTIAL |
| IMPACT_COMPLETE |
71.1.2.208. StorageCVSSV2Severity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| LOW |
| MEDIUM |
| HIGH |
71.1.2.209. StorageCVSSV3 Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| vector | String | ||||
| exploitabilityScore | Float | float | |||
| impactScore | Float | float | |||
| attackVector | ATTACK_LOCAL, ATTACK_ADJACENT, ATTACK_NETWORK, ATTACK_PHYSICAL, | ||||
| attackComplexity | COMPLEXITY_LOW, COMPLEXITY_HIGH, | ||||
| privilegesRequired | PRIVILEGE_NONE, PRIVILEGE_LOW, PRIVILEGE_HIGH, | ||||
| userInteraction | UI_NONE, UI_REQUIRED, | ||||
| scope | UNCHANGED, CHANGED, | ||||
| confidentiality | IMPACT_NONE, IMPACT_LOW, IMPACT_HIGH, | ||||
| integrity | IMPACT_NONE, IMPACT_LOW, IMPACT_HIGH, | ||||
| availability | IMPACT_NONE, IMPACT_LOW, IMPACT_HIGH, | ||||
| score | Float | float | |||
| severity | UNKNOWN, NONE, LOW, MEDIUM, HIGH, CRITICAL, |
71.1.2.210. StorageCVSSV3AttackVector Copy linkLink copied to clipboard!
| Enum Values |
|---|
| ATTACK_LOCAL |
| ATTACK_ADJACENT |
| ATTACK_NETWORK |
| ATTACK_PHYSICAL |
71.1.2.211. StorageCVSSV3Impact Copy linkLink copied to clipboard!
| Enum Values |
|---|
| IMPACT_NONE |
| IMPACT_LOW |
| IMPACT_HIGH |
71.1.2.212. StorageCVSSV3Scope Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNCHANGED |
| CHANGED |
71.1.2.213. StorageCVSSV3Severity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| NONE |
| LOW |
| MEDIUM |
| HIGH |
| CRITICAL |
71.1.2.214. StorageCert Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| subject | |||||
| issuer | |||||
| sans |
List of | ||||
| startDate | Date | date-time | |||
| endDate | Date | date-time | |||
| algorithm | String |
71.1.2.215. StorageCertName Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| commonName | String | ||||
| country | String | ||||
| organization | String | ||||
| organizationUnit | String | ||||
| locality | String | ||||
| province | String | ||||
| streetAddress | String | ||||
| postalCode | String | ||||
| names |
List of |
71.1.2.216. StorageCertificateTransparencyLogVerification Copy linkLink copied to clipboard!
Validate that the signature certificate contains a signed certificate timestamp as proof of inclusion into the certificate transparency log.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean | Validate the inclusion of certificates into a certificate transparency log. Disables validation if not enabled. | |||
| publicKeyPemEnc | String | PEM encoded public key used to validate the proof of inclusion into the certificate transparency log. Defaults to the key of the public Sigstore instance if left empty. |
71.1.2.217. StorageClairConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| insecure | Boolean |
71.1.2.218. StorageClairV4Config Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| insecure | Boolean |
71.1.2.219. StorageClairifyConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| grpcEndpoint | String | ||||
| numConcurrentScans | Integer | int32 |
71.1.2.220. StorageCluster Copy linkLink copied to clipboard!
Next tag: 33
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | GENERIC_CLUSTER, KUBERNETES_CLUSTER, OPENSHIFT_CLUSTER, OPENSHIFT4_CLUSTER, | ||||
| labels |
Map of | ||||
| mainImage | String | ||||
| collectorImage | String | ||||
| centralApiEndpoint | String | ||||
| runtimeSupport | Boolean | ||||
| collectionMethod | UNSET_COLLECTION, NO_COLLECTION, KERNEL_MODULE, EBPF, CORE_BPF, | ||||
| admissionController | Boolean | ||||
| admissionControllerUpdates | Boolean | ||||
| admissionControllerEvents | Boolean | ||||
| status | |||||
| dynamicConfig | |||||
| tolerationsConfig | |||||
| priority | String | int64 | |||
| healthStatus | |||||
| slimCollector | Boolean | ||||
| helmConfig | |||||
| mostRecentSensorId | |||||
| auditLogState | Map of StorageAuditLogFileState | For internal use only. | |||
| initBundleId | String | ||||
| managedBy | MANAGER_TYPE_UNKNOWN, MANAGER_TYPE_MANUAL, MANAGER_TYPE_HELM_CHART, MANAGER_TYPE_KUBERNETES_OPERATOR, | ||||
| sensorCapabilities |
List of | ||||
| admissionControllerFailOnError | Boolean |
71.1.2.221. StorageClusterCertExpiryStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| sensorCertExpiry | Date | date-time | |||
| sensorCertNotBefore | Date | date-time |
71.1.2.222. StorageClusterHealthStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| collectorHealthInfo | |||||
| admissionControlHealthInfo | |||||
| scannerHealthInfo | |||||
| sensorHealthStatus | UNINITIALIZED, UNAVAILABLE, UNHEALTHY, DEGRADED, HEALTHY, | ||||
| collectorHealthStatus | UNINITIALIZED, UNAVAILABLE, UNHEALTHY, DEGRADED, HEALTHY, | ||||
| overallHealthStatus | UNINITIALIZED, UNAVAILABLE, UNHEALTHY, DEGRADED, HEALTHY, | ||||
| admissionControlHealthStatus | UNINITIALIZED, UNAVAILABLE, UNHEALTHY, DEGRADED, HEALTHY, | ||||
| scannerHealthStatus | UNINITIALIZED, UNAVAILABLE, UNHEALTHY, DEGRADED, HEALTHY, | ||||
| lastContact | Date | For sensors not having health capability, this will be filled with gRPC connection poll. Otherwise, this timestamp will be updated by central pipeline when message is processed. Note: we use this setting to guard against a specific attack vector during CRS-based cluster registration. Assuming that a CRS was used to register a cluster A and the CRS is leaked, an attacker shall not be able to re-run the CRS-flow which would then equip the attacker with a certificate & key issued to the cluster A. As countermeasure we only allow re-running the CRS-flow only as long as the last_contact field is empty, indicating that the legit cluster A’s sensor has not yet connected with the CRS-issued service certificates. | date-time | ||
| healthInfoComplete | Boolean |
71.1.2.223. StorageClusterMetadata Copy linkLink copied to clipboard!
ClusterMetadata contains metadata information about the cluster infrastructure.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | UNSPECIFIED, AKS, ARO, EKS, GKE, OCP, OSD, ROSA, | ||||
| name | String | Name represents the name under which the cluster is registered with the cloud provider. In case of self managed OpenShift it is the name chosen by the OpenShift installer. | |||
| id | String |
Id represents a unique ID under which the cluster is registered with the cloud provider. Not all cluster types have an id. For all OpenShift clusters, this is the Red Hat |
71.1.2.224. StorageClusterMetadataType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSPECIFIED |
| AKS |
| ARO |
| EKS |
| GKE |
| OCP |
| OSD |
| ROSA |
71.1.2.225. StorageClusterStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| sensorVersion | String | ||||
| DEPRECATEDLastContact | Date | This field has been deprecated starting release 49.0. Use healthStatus.lastContact instead. | date-time | ||
| providerMetadata | |||||
| orchestratorMetadata | |||||
| upgradeStatus | |||||
| certExpiryStatus |
71.1.2.226. StorageClusterType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| GENERIC_CLUSTER |
| KUBERNETES_CLUSTER |
| OPENSHIFT_CLUSTER |
| OPENSHIFT4_CLUSTER |
71.1.2.227. StorageClusterUpgradeStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| upgradability | UNSET, UP_TO_DATE, MANUAL_UPGRADE_REQUIRED, AUTO_UPGRADE_POSSIBLE, SENSOR_VERSION_HIGHER, | ||||
| upgradabilityStatusReason | String | ||||
| mostRecentProcess |
71.1.2.228. StorageCollectionMethod Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET_COLLECTION |
| NO_COLLECTION |
| KERNEL_MODULE |
| EBPF |
| CORE_BPF |
71.1.2.229. StorageCollectorHealthInfo Copy linkLink copied to clipboard!
CollectorHealthInfo carries data about collector deployment but does not include collector health status derived from this data. Aggregated collector health status is not included because it is derived in central and not in the component that first reports CollectorHealthInfo (sensor).
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| version | String | ||||
| totalDesiredPods | Integer | int32 | |||
| totalReadyPods | Integer | int32 | |||
| totalRegisteredNodes | Integer | int32 | |||
| statusErrors |
List of | Collection of errors that occurred while trying to obtain collector health info. |
71.1.2.230. StorageCompleteClusterConfig Copy linkLink copied to clipboard!
Encodes a complete cluster configuration minus ID/Name identifiers including static and dynamic settings.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| dynamicConfig | |||||
| staticConfig | |||||
| configFingerprint | String | ||||
| clusterLabels |
Map of |
71.1.2.231. StorageComplianceAggregationResponse Copy linkLink copied to clipboard!
Next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| results | List of ComplianceAggregationResult | ||||
| sources | |||||
| errorMessage | String |
71.1.2.232. StorageComplianceAggregationScope Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| STANDARD |
| CLUSTER |
| CATEGORY |
| CONTROL |
| NAMESPACE |
| NODE |
| DEPLOYMENT |
| CHECK |
71.1.2.233. StorageComplianceAggregationSource Copy linkLink copied to clipboard!
Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | ||||
| standardId | String | ||||
| successfulRun | |||||
| failedRuns | List of StorageComplianceRunMetadata |
71.1.2.234. StorageComplianceDomain Copy linkLink copied to clipboard!
Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| cluster | |||||
| nodes | Map of ComplianceDomainNode | ||||
| deployments | Map of ComplianceDomainDeployment |
71.1.2.235. StorageComplianceResultValue Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| evidence | List of ComplianceResultValueEvidence | ||||
| overallState | COMPLIANCE_STATE_UNKNOWN, COMPLIANCE_STATE_SKIP, COMPLIANCE_STATE_NOTE, COMPLIANCE_STATE_SUCCESS, COMPLIANCE_STATE_FAILURE, COMPLIANCE_STATE_ERROR, |
71.1.2.236. StorageComplianceRunMetadata Copy linkLink copied to clipboard!
Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| runId | String | ||||
| standardId | String | ||||
| clusterId | String | ||||
| startTimestamp | Date | date-time | |||
| finishTimestamp | Date | date-time | |||
| success | Boolean | ||||
| errorMessage | String | ||||
| domainId | String |
71.1.2.237. StorageComplianceRunResults Copy linkLink copied to clipboard!
Next available tag: 6
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| domain | |||||
| runMetadata | |||||
| clusterResults | |||||
| nodeResults | |||||
| deploymentResults | |||||
| machineConfigResults |
71.1.2.238. StorageComplianceState Copy linkLink copied to clipboard!
| Enum Values |
|---|
| COMPLIANCE_STATE_UNKNOWN |
| COMPLIANCE_STATE_SKIP |
| COMPLIANCE_STATE_NOTE |
| COMPLIANCE_STATE_SUCCESS |
| COMPLIANCE_STATE_FAILURE |
| COMPLIANCE_STATE_ERROR |
71.1.2.239. StorageConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| publicConfig | |||||
| privateConfig | |||||
| platformComponentConfig |
71.1.2.240. StorageContainer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| config | |||||
| image | |||||
| securityContext | |||||
| volumes | List of StorageVolume | ||||
| ports | List of StoragePortConfig | ||||
| secrets | List of StorageEmbeddedSecret | ||||
| resources | |||||
| name | String | ||||
| livenessProbe | |||||
| readinessProbe | |||||
| type | REGULAR, INIT, |
71.1.2.241. StorageContainerConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| env | List of ContainerConfigEnvironmentConfig | ||||
| command |
List of | ||||
| args |
List of | ||||
| directory | String | ||||
| user | String | ||||
| uid | String | int64 | |||
| appArmorProfile | String |
71.1.2.242. StorageContainerImage Copy linkLink copied to clipboard!
Next tag: 13
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | |||||
| notPullable | Boolean | ||||
| isClusterLocal | Boolean | ||||
| idV2 | String |
71.1.2.243. StorageContainerInstance Copy linkLink copied to clipboard!
ContainerInstanceID allows to uniquely identify a container within a cluster.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| instanceId | |||||
| containingPodId | String | The pod containing this container instance (kubernetes only). | |||
| containerName | String | Container name. | |||
| containerIps |
List of | The IP addresses of this container. | |||
| started | Date | date-time | |||
| imageDigest | String | ||||
| finished | Date | The finish time of the container, if it finished. | date-time | ||
| exitCode | Integer | The exit code of the container. Only valid when finished is populated. | int32 | ||
| terminationReason | String | The reason for the container’s termination, if it finished. |
71.1.2.244. StorageContainerInstanceID Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| containerRuntime | UNKNOWN_CONTAINER_RUNTIME, DOCKER_CONTAINER_RUNTIME, CRIO_CONTAINER_RUNTIME, | ||||
| id | String | The ID of the container, specific to the given runtime. | |||
| node | String | The node on which this container runs. |
71.1.2.245. StorageContainerNameAndBaselineStatus Copy linkLink copied to clipboard!
ContainerNameAndBaselineStatus represents a cached result of process evaluation on a specific container name.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| containerName | String | ||||
| baselineStatus | INVALID, NOT_GENERATED, UNLOCKED, LOCKED, | ||||
| anomalousProcessesExecuted | Boolean |
71.1.2.246. StorageContainerRuntime Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN_CONTAINER_RUNTIME |
| DOCKER_CONTAINER_RUNTIME |
| CRIO_CONTAINER_RUNTIME |
71.1.2.247. StorageContainerRuntimeInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | UNKNOWN_CONTAINER_RUNTIME, DOCKER_CONTAINER_RUNTIME, CRIO_CONTAINER_RUNTIME, | ||||
| version | String |
71.1.2.248. StorageContainerType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| REGULAR |
| INIT |
71.1.2.249. StorageCosignCertificateVerification Copy linkLink copied to clipboard!
Holds all verification data for verifying certificates attached to cosign signatures. If only the certificate is given, the Fulcio trusted root chain will be assumed and verified against. If only the chain is given, this will be used over the Fulcio trusted root chain for verification. If no certificate or chain is given, the Fulcio trusted root chain will be assumed and verified against.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| certificatePemEnc | String | PEM encoded certificate to use for verification. Leave empty when using short-lived certificates as issued by Fulcio. | |||
| certificateChainPemEnc | String | PEM encoded certificate chain to use for verification. Defaults to the root certificate authority of the public Sigstore instance if left empty. | |||
| certificateOidcIssuer | String | Certificate OIDC issuer to verify against. This supports regular expressions following the RE2 syntax: https://github.com/google/re2/wiki/Syntax. In case the certificate does not specify an OIDC issuer, you may use '.*' as the OIDC issuer. However, it is recommended to use Fulcio compatible certificates according to the specification: https://github.com/sigstore/fulcio/blob/main/docs/certificate-specification.md. | |||
| certificateIdentity | String | Certificate identity to verify against. This supports regular expressions following the RE2 syntax: https://github.com/google/re2/wiki/Syntax. In case the certificate does not specify an identity, you may use '.*' as the identity. However, it is recommended to use Fulcio compatible certificates according to the specification: https://github.com/sigstore/fulcio/blob/main/docs/certificate-specification.md. | |||
| certificateTransparencyLog |
71.1.2.250. StorageCosignPublicKeyVerification Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| publicKeys |
71.1.2.251. StorageCosignSignature Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| rawSignature | byte[] | byte | |||
| signaturePayload | byte[] | byte | |||
| certPem | byte[] | byte | |||
| certChainPem | byte[] | byte | |||
| rekorBundle | byte[] | byte |
71.1.2.252. StorageDataSource Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| mirror | String |
71.1.2.253. StorageDayOption Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numDays | Long | int64 | |||
| enabled | Boolean |
71.1.2.254. StorageDeclarativeConfigHealth Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| status | UNHEALTHY, HEALTHY, | ||||
| errorMessage | String | ||||
| resourceName | String | ||||
| resourceType | CONFIG_MAP, ACCESS_SCOPE, PERMISSION_SET, ROLE, AUTH_PROVIDER, GROUP, NOTIFIER, AUTH_MACHINE_TO_MACHINE_CONFIG, | ||||
| lastTimestamp | Date | Timestamp when the current status was set. | date-time |
71.1.2.255. StorageDeclarativeConfigHealthStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNHEALTHY |
| HEALTHY |
71.1.2.256. StorageDecommissionedClusterRetentionConfig Copy linkLink copied to clipboard!
next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| retentionDurationDays | Integer | int32 | |||
| ignoreClusterLabels |
Map of | ||||
| lastUpdated | Date | date-time | |||
| createdAt | Date | date-time |
71.1.2.257. StorageDeployment Copy linkLink copied to clipboard!
Next available tag: 36
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| hash | String | uint64 | |||
| type | String | ||||
| namespace | String | ||||
| namespaceId | String | ||||
| orchestratorComponent | Boolean | ||||
| replicas | String | int64 | |||
| labels |
Map of | ||||
| podLabels |
Map of | ||||
| labelSelector | |||||
| created | Date | date-time | |||
| clusterId | String | ||||
| clusterName | String | ||||
| containers | List of StorageContainer | ||||
| annotations |
Map of | ||||
| priority | String | int64 | |||
| inactive | Boolean | ||||
| imagePullSecrets |
List of | ||||
| serviceAccount | String | ||||
| serviceAccountPermissionLevel | UNSET, NONE, DEFAULT, ELEVATED_IN_NAMESPACE, ELEVATED_CLUSTER_WIDE, CLUSTER_ADMIN, | ||||
| automountServiceAccountToken | Boolean | ||||
| hostNetwork | Boolean | ||||
| hostPid | Boolean | ||||
| hostIpc | Boolean | ||||
| runtimeClass | String | ||||
| tolerations | List of StorageToleration | ||||
| ports | List of StoragePortConfig | ||||
| stateTimestamp | String | int64 | |||
| riskScore | Float | float | |||
| platformComponent | Boolean |
71.1.2.258. StorageDockerConfig Copy linkLink copied to clipboard!
Docker registry configuration. Used by integrations of type "docker" and other docker compliant registries without dedicated configuration type.
Use of type "azure" with DockerConfig has been deprecated in 4.7. Use AzureConfig instead.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| username | String | ||||
| password | String | The password for the integration. The server will mask the value of this credential in responses and logs. | |||
| insecure | Boolean |
71.1.2.259. StorageDynamicClusterConfig Copy linkLink copied to clipboard!
The difference between Static and Dynamic cluster config is that Dynamic values are sent over the Central to Sensor gRPC connection. This has the benefit of allowing for "hot reloading" of values without restarting Secured cluster components.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| admissionControllerConfig | |||||
| registryOverride | String | ||||
| disableAuditLogs | Boolean | ||||
| autoLockProcessBaselinesConfig | |||||
| processIndicators |
71.1.2.260. StorageECRConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| registryId | String | ||||
| accessKeyId | String | The access key ID for the integration. The server will mask the value of this credential in responses and logs. | |||
| secretAccessKey | String | The secret access key for the integration. The server will mask the value of this credential in responses and logs. | |||
| region | String | ||||
| useIam | Boolean | ||||
| endpoint | String | ||||
| useAssumeRole | Boolean | ||||
| assumeRoleId | String | ||||
| assumeRoleExternalId | String | ||||
| authorizationData |
71.1.2.261. StorageEPSS Copy linkLink copied to clipboard!
EPSS Score stores two epss metrics returned by scanner - epss probability and epss percentile
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| epssProbability | Float | float | |||
| epssPercentile | Float | float |
71.1.2.262. StorageEffectiveAccessScope Copy linkLink copied to clipboard!
EffectiveAccessScope describes which clusters and namespaces are "in scope" given current state. Basically, if AccessScope is applied to the currently known clusters and namespaces, the result is EffectiveAccessScope.
EffectiveAccessScope represents a tree with nodes marked as included and excluded. If a node is included, all its child nodes are included.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusters | List of EffectiveAccessScopeCluster |
71.1.2.263. StorageEffectiveAccessScopeNamespace Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| state | UNKNOWN, INCLUDED, EXCLUDED, PARTIAL, | ||||
| labels |
Map of |
71.1.2.264. StorageEffectiveAccessScopeState Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| INCLUDED |
| EXCLUDED |
| PARTIAL |
71.1.2.265. StorageEmail Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| server | String | ||||
| sender | String | ||||
| username | String | ||||
| password | String | The password for the integration. The server will mask the value of this credential in responses and logs. | |||
| disableTLS | Boolean | ||||
| DEPRECATEDUseStartTLS | Boolean | ||||
| from | String | ||||
| startTLSAuthMethod | DISABLED, PLAIN, LOGIN, | ||||
| allowUnauthenticatedSmtp | Boolean | ||||
| skipTLSVerify | Boolean | ||||
| hostnameHeloEhlo | String |
71.1.2.266. StorageEmailNotifierConfiguration Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| notifierId | String | ||||
| mailingLists |
List of | ||||
| customSubject | String | ||||
| customBody | String |
71.1.2.267. StorageEmbeddedImageScanComponent Copy linkLink copied to clipboard!
Next Tag: 14
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| version | String | ||||
| license | |||||
| vulns | List of StorageEmbeddedVulnerability | ||||
| layerIndex | Integer | int32 | |||
| priority | String | int64 | |||
| source | OS, PYTHON, JAVA, RUBY, NODEJS, GO, DOTNETCORERUNTIME, INFRASTRUCTURE, | ||||
| location | String | ||||
| topCvss | Float | float | |||
| riskScore | Float | float | |||
| fixedBy | String | Component version that fixes all the fixable vulnerabilities in this component. | |||
| executables | |||||
| architecture | String |
71.1.2.268. StorageEmbeddedImageScanComponentExecutable Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| path | String | ||||
| dependencies |
List of |
71.1.2.269. StorageEmbeddedNodeScanComponent Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| version | String | ||||
| vulns | List of StorageEmbeddedVulnerability | ||||
| vulnerabilities | List of StorageNodeVulnerability | ||||
| priority | String | int64 | |||
| topCvss | Float | float | |||
| riskScore | Float | float |
71.1.2.270. StorageEmbeddedSecret Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| path | String |
71.1.2.271. StorageEmbeddedVulnerability Copy linkLink copied to clipboard!
Next Tag: 27
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cve | String | ||||
| advisory | |||||
| cvss | Float | float | |||
| summary | String | ||||
| link | String | ||||
| fixedBy | String | ||||
| scoreVersion | V2, V3, | ||||
| cvssV2 | |||||
| cvssV3 | |||||
| publishedOn | Date | date-time | |||
| lastModified | Date | date-time | |||
| vulnerabilityType | UNKNOWN_VULNERABILITY, IMAGE_VULNERABILITY, K8S_VULNERABILITY, ISTIO_VULNERABILITY, NODE_VULNERABILITY, OPENSHIFT_VULNERABILITY, | ||||
| vulnerabilityTypes | |||||
| suppressed | Boolean | ||||
| suppressActivation | Date | date-time | |||
| suppressExpiry | Date | date-time | |||
| firstSystemOccurrence | Date | Time when the CVE was first seen, for this specific distro, in the system. | date-time | ||
| firstImageOccurrence | Date | Time when the CVE was first seen in this image. | date-time | ||
| fixAvailableTimestamp | Date | Timestamp when the fix for this CVE was made available according to the sources or the timestamp of the first scan after this field was introduced which discovered this CVE as fixable, if it is. | date-time | ||
| severity | UNKNOWN_VULNERABILITY_SEVERITY, LOW_VULNERABILITY_SEVERITY, MODERATE_VULNERABILITY_SEVERITY, IMPORTANT_VULNERABILITY_SEVERITY, CRITICAL_VULNERABILITY_SEVERITY, | ||||
| state | OBSERVED, DEFERRED, FALSE_POSITIVE, | ||||
| cvssMetrics | List of StorageCVSSScore | ||||
| nvdCvss | Float | float | |||
| epss | |||||
| datasource | String |
71.1.2.272. StorageEmbeddedVulnerabilityScoreVersion Copy linkLink copied to clipboard!
ScoreVersion can be deprecated ROX-26066
- V2: No unset for automatic backwards compatibility
| Enum Values |
|---|
| V2 |
| V3 |
71.1.2.273. StorageEnforcementAction Copy linkLink copied to clipboard!
- FAIL_KUBE_REQUEST_ENFORCEMENT: FAIL_KUBE_REQUEST_ENFORCEMENT takes effect only if admission control webhook is enabled to listen on exec and port-forward events.
- FAIL_DEPLOYMENT_CREATE_ENFORCEMENT: FAIL_DEPLOYMENT_CREATE_ENFORCEMENT takes effect only if admission control webhook is configured to enforce on object creates.
- FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT: FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT takes effect only if admission control webhook is configured to enforce on object updates.
| Enum Values |
|---|
| UNSET_ENFORCEMENT |
| SCALE_TO_ZERO_ENFORCEMENT |
| UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT |
| KILL_POD_ENFORCEMENT |
| FAIL_BUILD_ENFORCEMENT |
| FAIL_KUBE_REQUEST_ENFORCEMENT |
| FAIL_DEPLOYMENT_CREATE_ENFORCEMENT |
| FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT |
71.1.2.274. StorageEntityField Copy linkLink copied to clipboard!
| Enum Values |
|---|
| FIELD_UNSET |
| FIELD_ID |
| FIELD_NAME |
| FIELD_LABEL |
| FIELD_ANNOTATION |
71.1.2.275. StorageEntityScope Copy linkLink copied to clipboard!
EntityScope is a new scoping method using ns,deployments,clusters filters introduced in 4.11
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| rules | List of StorageEntityScopeRule |
71.1.2.276. StorageEntityScopeRule Copy linkLink copied to clipboard!
EntityScopeRule stores the filter as an entity field pair along with a list of values
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | ENTITY_TYPE_UNSET, ENTITY_TYPE_DEPLOYMENT, ENTITY_TYPE_NAMESPACE, ENTITY_TYPE_CLUSTER, | ||||
| field | FIELD_UNSET, FIELD_ID, FIELD_NAME, FIELD_LABEL, FIELD_ANNOTATION, | ||||
| values | List of StorageRuleValue |
71.1.2.277. StorageEntityType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| ENTITY_TYPE_UNSET |
| ENTITY_TYPE_DEPLOYMENT |
| ENTITY_TYPE_NAMESPACE |
| ENTITY_TYPE_CLUSTER |
71.1.2.278. StorageEventSource Copy linkLink copied to clipboard!
| Enum Values |
|---|
| NOT_APPLICABLE |
| DEPLOYMENT_EVENT |
| AUDIT_LOG_EVENT |
| NODE_EVENT |
71.1.2.279. StorageExclusion Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| deployment | |||||
| image | |||||
| expiration | Date | date-time |
71.1.2.280. StorageExclusionDeployment Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| scope |
71.1.2.281. StorageExportPoliciesResponse Copy linkLink copied to clipboard!
ExportPoliciesResponse is used by the API but it is defined in storage because we expect customers to store them. We do backwards-compatibility checks on objects in the storge folder and those checks should be applied to this object
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policies | List of StoragePolicy |
71.1.2.282. StorageExternalBackup Copy linkLink copied to clipboard!
Next available tag: 10
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| schedule | |||||
| backupsToKeep | Integer | int32 | |||
| s3 | |||||
| gcs | |||||
| s3compatible | |||||
| includeCertificates | Boolean |
71.1.2.283. StorageFileAccess Copy linkLink copied to clipboard!
FileAccess contains fields related to arbitrary file accesses performed by a given process. This activity can come from k8s, or directly on a node.
It is currently intended to be used in Sensor and for detection, but will only be stored embedded in an Alert. As a result, it does not currently define a primary key.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| file | |||||
| operation | CREATE, UNLINK, RENAME, PERMISSION_CHANGE, OWNERSHIP_CHANGE, OPEN, | ||||
| moved | |||||
| timestamp | Date | date-time | |||
| process | |||||
| hostname | String |
71.1.2.284. StorageFileAccessFile Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| effectivePath | String | ||||
| actualPath | String | ||||
| meta |
71.1.2.285. StorageGCSConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| bucket | String | ||||
| serviceAccount | String | The service account for the storage integration. The server will mask the value of this credential in responses and logs. | |||
| objectPrefix | String | ||||
| useWorkloadId | Boolean |
71.1.2.286. StorageGeneric Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| skipTLSVerify | Boolean | ||||
| caCert | String | ||||
| username | String | ||||
| password | String | The password for the integration. The server will mask the value of this credential in responses and logs. | |||
| headers | List of StorageKeyValuePair | ||||
| extraFields | List of StorageKeyValuePair | ||||
| auditLoggingEnabled | Boolean |
71.1.2.287. StorageGoogleConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| serviceAccount | String | The service account for the integration. The server will mask the value of this credential in responses and logs. | |||
| project | String | ||||
| wifEnabled | Boolean |
71.1.2.288. StorageGoogleProviderMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| project | String | ||||
| clusterName | String | Deprecated in favor of providerMetadata.cluster.name. |
71.1.2.289. StorageGroup Copy linkLink copied to clipboard!
Group is a GroupProperties : Role mapping.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| props | |||||
| roleName | String | This is the name of the role that will apply to users in this group. |
71.1.2.290. StorageGroupProperties Copy linkLink copied to clipboard!
GroupProperties defines the properties of a group. Groups apply to users when their properties match. For instance: - If GroupProperties has only an auth_provider_id, then that group applies to all users logged in with that auth provider. - If GroupProperties in addition has a claim key, then it applies to all users with that auth provider and the claim key, etc. Note: Changes to GroupProperties may require changes to v1.DeleteGroupRequest.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | Unique identifier for group properties and respectively the group. | |||
| traits | |||||
| authProviderId | String | ||||
| key | String | ||||
| value | String |
71.1.2.291. StorageIBMRegistryConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| apiKey | String | The API key for the integration. The server will mask the value of this credential in responses and logs. |
71.1.2.292. StorageIPBlock Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cidr | String | ||||
| except |
List of |
71.1.2.293. StorageImage Copy linkLink copied to clipboard!
This proto is deprecated and replaced by ImageV2. Next Tag: 19
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | |||||
| names | List of StorageImageName | This should deprecate the ImageName field long-term, allowing images with the same digest to be associated with different locations. TODO(dhaus): For now, this message will be without search tags due to duplicated search tags otherwise. | |||
| metadata | |||||
| scan | |||||
| signatureVerificationData | |||||
| signature | |||||
| components | Integer | int32 | |||
| cves | Integer | int32 | |||
| fixableCves | Integer | int32 | |||
| lastUpdated | Date | date-time | |||
| notPullable | Boolean | ||||
| isClusterLocal | Boolean | ||||
| priority | String | int64 | |||
| riskScore | Float | float | |||
| topCvss | Float | float | |||
| notes | List of StorageImageNote | ||||
| baseImageInfo | List of StorageBaseImageInfo |
71.1.2.294. StorageImageIntegration Copy linkLink copied to clipboard!
Next Tag: 25
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| categories | List of StorageImageIntegrationCategory | ||||
| clairify | |||||
| scannerV4 | |||||
| docker | |||||
| quay | |||||
| ecr | |||||
| | |||||
| clair | |||||
| clairV4 | |||||
| ibm | |||||
| azure | |||||
| autogenerated | Boolean | ||||
| clusterId | String | ||||
| skipTestIntegration | Boolean | ||||
| source |
71.1.2.295. StorageImageIntegrationCategory Copy linkLink copied to clipboard!
- NODE_SCANNER: Image and Node integrations are currently done on the same form in the UI so the image integration is also currently used for node integrations. This decision was made because we currently only support one node scanner (our scanner).
| Enum Values |
|---|
| REGISTRY |
| SCANNER |
| NODE_SCANNER |
71.1.2.296. StorageImageIntegrationSource Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | ||||
| namespace | String | ||||
| imagePullSecretName | String |
71.1.2.297. StorageImageLayer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| instruction | String | ||||
| value | String | ||||
| created | Date | date-time | |||
| author | String | ||||
| empty | Boolean |
71.1.2.298. StorageImageMetadata Copy linkLink copied to clipboard!
If any fields of ImageMetadata are modified including subfields, please check pkg/images/enricher/metadata.go to ensure that those changes will be automatically picked up Next Tag: 6
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| v1 | |||||
| v2 | |||||
| layerShas |
List of | ||||
| dataSource | |||||
| version | String | uint64 |
71.1.2.299. StorageImageName Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| registry | String | ||||
| remote | String | ||||
| tag | String | ||||
| fullName | String |
71.1.2.300. StorageImageNote Copy linkLink copied to clipboard!
| Enum Values |
|---|
| MISSING_METADATA |
| MISSING_SCAN_DATA |
| MISSING_SIGNATURE |
| MISSING_SIGNATURE_VERIFICATION_DATA |
71.1.2.301. StorageImagePullSecret Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| registries | List of ImagePullSecretRegistry |
71.1.2.302. StorageImageScan Copy linkLink copied to clipboard!
Next tag: 8
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| scannerVersion | String | ||||
| scanTime | Date | date-time | |||
| components | |||||
| operatingSystem | String | ||||
| dataSource | |||||
| notes | List of StorageImageScanNote | ||||
| hash | String | uint64 |
71.1.2.303. StorageImageScanNote Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| OS_UNAVAILABLE |
| PARTIAL_SCAN_DATA |
| OS_CVES_UNAVAILABLE |
| OS_CVES_STALE |
| LANGUAGE_CVES_UNAVAILABLE |
| CERTIFIED_RHEL_SCAN_UNAVAILABLE |
71.1.2.304. StorageImageSignature Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| signatures | List of StorageSignature | ||||
| fetched | Date | date-time |
71.1.2.305. StorageImageSignatureVerificationData Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| results |
71.1.2.306. StorageImageSignatureVerificationResult Copy linkLink copied to clipboard!
Next Tag: 7
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| verificationTime | Date | date-time | |||
| verifierId | String | verifier_id correlates to the ID of the signature integration used to verify the signature. | |||
| status | UNSET, VERIFIED, FAILED_VERIFICATION, INVALID_SIGNATURE_ALGO, CORRUPTED_SIGNATURE, GENERIC_ERROR, | ||||
| description | String | description is set in the case of an error with the specific error’s message. Otherwise, this will not be set. | |||
| verifiedImageReferences |
List of | The full image names that are verified by this specific signature integration ID. | |||
| verifierName | String |
verifier_name is the name of the signature integration associated with |
71.1.2.307. StorageImageSignatureVerificationResultStatus Copy linkLink copied to clipboard!
Status represents the status of the result.
- VERIFIED: VERIFIED is set when the signature’s verification was successful.
- FAILED_VERIFICATION: FAILED_VERIFICATION is set when the signature’s verification failed.
- INVALID_SIGNATURE_ALGO: INVALID_SIGNATURE_ALGO is set when the signature’s algorithm is invalid and unsupported.
- CORRUPTED_SIGNATURE: CORRUPTED_SIGNATURE is set when the raw signature is corrupted, i.e. wrong base64 encoding.
- GENERIC_ERROR: GENERIC_ERROR is set when an error occurred during verification that cannot be associated with a specific status.
| Enum Values |
|---|
| UNSET |
| VERIFIED |
| FAILED_VERIFICATION |
| INVALID_SIGNATURE_ALGO |
| CORRUPTED_SIGNATURE |
| GENERIC_ERROR |
71.1.2.308. StorageIntegrationHealth Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | UNKNOWN, IMAGE_INTEGRATION, NOTIFIER, BACKUP, DECLARATIVE_CONFIG, | ||||
| status | UNINITIALIZED, UNHEALTHY, HEALTHY, | ||||
| errorMessage | String | ||||
| lastTimestamp | Date | date-time |
71.1.2.309. StorageIntegrationHealthStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNINITIALIZED |
| UNHEALTHY |
| HEALTHY |
71.1.2.310. StorageIntegrationHealthType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| IMAGE_INTEGRATION |
| NOTIFIER |
| BACKUP |
| DECLARATIVE_CONFIG |
71.1.2.311. StorageJira Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| url | String | ||||
| username | String | ||||
| password | String | The password for the integration. The server will mask the value of this credential in responses and logs. | |||
| issueType | String | ||||
| priorityMappings | List of JiraPriorityMapping | ||||
| defaultFieldsJson | String | ||||
| disablePriority | Boolean |
71.1.2.312. StorageK8sRole Copy linkLink copied to clipboard!
Properties of an individual k8s Role or ClusterRole. ////////////////////////////////////////
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| namespace | String | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| clusterRole | Boolean | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| createdAt | Date | date-time | |||
| rules | List of StoragePolicyRule |
71.1.2.313. StorageK8sRoleBinding Copy linkLink copied to clipboard!
Properties of an individual k8s RoleBinding or ClusterRoleBinding. ////////////////////////////////////////
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| namespace | String | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| clusterRole | Boolean | ClusterRole specifies whether the binding binds a cluster role. However, it cannot be used to determine whether the binding is a cluster role binding. This can be done in conjunction with the namespace. If the namespace is empty and cluster role is true, the binding is a cluster role binding. | |||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| createdAt | Date | date-time | |||
| subjects | List of StorageSubject | ||||
| roleId | String |
71.1.2.314. StorageKeyValuePair Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| value | String |
71.1.2.315. StorageL4Protocol Copy linkLink copied to clipboard!
| Enum Values |
|---|
| L4_PROTOCOL_UNKNOWN |
| L4_PROTOCOL_TCP |
| L4_PROTOCOL_UDP |
| L4_PROTOCOL_ICMP |
| L4_PROTOCOL_RAW |
| L4_PROTOCOL_SCTP |
| L4_PROTOCOL_ANY |
71.1.2.316. StorageLabelSelector Copy linkLink copied to clipboard!
Label selector components are joined with logical AND, see https://kubernetes.io/docs/concepts/overview/working-with-objects/labels/
Next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| matchLabels |
Map of | This is actually a oneof, but we can’t make it one due to backwards compatibility constraints. | |||
| requirements | List of LabelSelectorRequirement |
71.1.2.317. StorageLabelSelectorOperator Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| IN |
| NOT_IN |
| EXISTS |
| NOT_EXISTS |
71.1.2.318. StorageLicense Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | String | ||||
| url | String |
71.1.2.319. StorageLifecycleStage Copy linkLink copied to clipboard!
| Enum Values |
|---|
| DEPLOY |
| BUILD |
| RUNTIME |
71.1.2.320. StorageListAlert Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| lifecycleStage | DEPLOY, BUILD, RUNTIME, | ||||
| time | Date | date-time | |||
| policy | |||||
| state | ACTIVE, RESOLVED, ATTEMPTED, | ||||
| enforcementCount | Integer | int32 | |||
| enforcementAction | UNSET_ENFORCEMENT, SCALE_TO_ZERO_ENFORCEMENT, UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT, KILL_POD_ENFORCEMENT, FAIL_BUILD_ENFORCEMENT, FAIL_KUBE_REQUEST_ENFORCEMENT, FAIL_DEPLOYMENT_CREATE_ENFORCEMENT, FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT, | ||||
| commonEntityInfo | |||||
| deployment | |||||
| resource | |||||
| node |
71.1.2.321. StorageListAlertDeployment Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterName | String | This field is deprecated and can be found in CommonEntityInfo. It will be removed from here in a future release. This field has moved to CommonEntityInfo | |||
| namespace | String | This field is deprecated and can be found in CommonEntityInfo. It will be removed from here in a future release. This field has moved to CommonEntityInfo | |||
| clusterId | String | This field is deprecated and can be found in CommonEntityInfo. It will be removed from here in a future release. This field has moved to CommonEntityInfo | |||
| inactive | Boolean | ||||
| namespaceId | String | This field is deprecated and can be found in CommonEntityInfo. It will be removed from here in a future release. This field has moved to CommonEntityInfo | |||
| deploymentType | String |
71.1.2.322. StorageListAlertPolicy Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| description | String | ||||
| categories |
List of | ||||
| developerInternalFields |
71.1.2.323. StorageListAlertResourceType Copy linkLink copied to clipboard!
A special ListAlert-only enumeration of all resource types. Unlike Alert.Resource.ResourceType this also includes deployment and node as types This must be kept in sync with Alert.Resource.ResourceType (excluding the deployment and node values)
| Enum Values |
|---|
| DEPLOYMENT |
| SECRETS |
| CONFIGMAPS |
| CLUSTER_ROLES |
| CLUSTER_ROLE_BINDINGS |
| NETWORK_POLICIES |
| SECURITY_CONTEXT_CONSTRAINTS |
| EGRESS_FIREWALLS |
| NODE |
71.1.2.324. StorageListDeployment Copy linkLink copied to clipboard!
Next available tag: 9
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| hash | String | uint64 | |||
| name | String | ||||
| cluster | String | ||||
| clusterId | String | ||||
| namespace | String | ||||
| created | Date | date-time | |||
| priority | String | int64 |
71.1.2.325. StorageListImage Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| components | Integer | int32 | |||
| cves | Integer | int32 | |||
| fixableCves | Integer | int32 | |||
| created | Date | date-time | |||
| lastUpdated | Date | date-time | |||
| priority | String | int64 |
71.1.2.326. StorageListPolicy Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| description | String | ||||
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| disabled | Boolean | ||||
| lifecycleStages | List of StorageLifecycleStage | ||||
| notifiers |
List of | ||||
| lastUpdated | Date | date-time | |||
| eventSource | NOT_APPLICABLE, DEPLOYMENT_EVENT, AUDIT_LOG_EVENT, NODE_EVENT, | ||||
| isDefault | Boolean | ||||
| source | IMPERATIVE, DECLARATIVE, |
71.1.2.327. StorageListSecret Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| namespace | String | ||||
| types | List of StorageSecretType | ||||
| createdAt | Date | date-time |
71.1.2.328. StorageLivenessProbe Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| defined | Boolean |
71.1.2.329. StorageLoginNotice Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean | ||||
| text | String |
71.1.2.330. StorageManagerType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| MANAGER_TYPE_UNKNOWN |
| MANAGER_TYPE_MANUAL |
| MANAGER_TYPE_HELM_CHART |
| MANAGER_TYPE_KUBERNETES_OPERATOR |
71.1.2.331. StorageMatchType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| EXACT |
| REGEX |
71.1.2.332. StorageMicrosoftSentinel Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| logIngestionEndpoint | String | log_ingestion_endpoint is the log ingestion endpoint. | |||
| directoryTenantId | String | directory_tenant_id contains the ID of the Microsoft Directory ID of the selected tenant. | |||
| applicationClientId | String | application_client_id contains the ID of the application ID of the service principal. | |||
| secret | String | secret contains the client secret. | |||
| alertDcrConfig | |||||
| auditLogDcrConfig | |||||
| clientCertAuthConfig | |||||
| wifEnabled | Boolean | Enables authentication with short-lived tokens using Azure managed identities or Azure workload identities. The toggle exists to make the use of Azure default credentials explicit rather than always using them as a fallback. The explicit behavior is more consistent with other integrations. |
71.1.2.333. StorageMitreAttackVector Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| tactic | |||||
| techniques | List of StorageMitreTechnique |
71.1.2.334. StorageMitreTactic Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| description | String |
71.1.2.335. StorageMitreTechnique Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| description | String |
71.1.2.336. StorageNamespaceMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| labels |
Map of | ||||
| creationTime | Date | date-time | |||
| priority | String | int64 | |||
| annotations |
Map of |
71.1.2.337. StorageNetworkBaseline Copy linkLink copied to clipboard!
NetworkBaseline represents a network baseline of a deployment. It contains all the baseline peers and their respective connections. next available tag: 8
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deploymentId | String | This is the ID of the baseline. | |||
| clusterId | String | ||||
| namespace | String | ||||
| peers | List of StorageNetworkBaselinePeer | ||||
| forbiddenPeers | List of StorageNetworkBaselinePeer | A list of peers that will never be added to the baseline. For now, this contains peers that the user has manually removed. This is used to ensure we don’t add it back in the event we see the flow again. | |||
| observationPeriodEnd | Date | date-time | |||
| locked | Boolean | ||||
| deploymentName | String |
71.1.2.338. StorageNetworkBaselineConnectionProperties Copy linkLink copied to clipboard!
NetworkBaselineConnectionProperties represents information about a baseline connection next available tag: 4
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| ingress | Boolean | ||||
| port | Long | int64 | |||
| protocol | L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY, |
71.1.2.339. StorageNetworkBaselinePeer Copy linkLink copied to clipboard!
NetworkBaselinePeer represents a baseline peer. next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| properties |
71.1.2.340. StorageNetworkEntity Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| info | |||||
| scope |
71.1.2.341. StorageNetworkEntityInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | UNKNOWN_TYPE, DEPLOYMENT, INTERNET, LISTEN_ENDPOINT, EXTERNAL_SOURCE, INTERNAL_ENTITIES, | ||||
| id | String | ||||
| deployment | |||||
| externalSource |
71.1.2.342. StorageNetworkEntityInfoType Copy linkLink copied to clipboard!
- INTERNAL_ENTITIES: INTERNAL_ENTITIES is for grouping all internal entities under a single network graph node
| Enum Values |
|---|
| UNKNOWN_TYPE |
| DEPLOYMENT |
| INTERNET |
| LISTEN_ENDPOINT |
| EXTERNAL_SOURCE |
| INTERNAL_ENTITIES |
71.1.2.343. StorageNetworkEntityScope Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String |
71.1.2.344. StorageNetworkFlow Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| props | |||||
| lastSeenTimestamp | Date | date-time | |||
| clusterId | String | ||||
| updatedAt | Date | date-time |
71.1.2.345. StorageNetworkFlowProperties Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| srcEntity | |||||
| dstEntity | |||||
| dstPort | Long | may be 0 if not applicable (e.g., icmp). | int64 | ||
| l4protocol | L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY, |
71.1.2.346. StorageNetworkGraphConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| hideDefaultExternalSrcs | Boolean |
71.1.2.347. StorageNetworkPolicy Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| namespace | String | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| spec | |||||
| yaml | String | ||||
| apiVersion | String | ||||
| created | Date | date-time |
71.1.2.348. StorageNetworkPolicyApplicationUndoRecord Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | ||||
| user | String | ||||
| applyTimestamp | Date | date-time | |||
| originalModification | |||||
| undoModification |
71.1.2.349. StorageNetworkPolicyEgressRule Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| ports | List of StorageNetworkPolicyPort | ||||
| to | List of StorageNetworkPolicyPeer |
71.1.2.350. StorageNetworkPolicyIngressRule Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| ports | List of StorageNetworkPolicyPort | ||||
| from | List of StorageNetworkPolicyPeer |
71.1.2.351. StorageNetworkPolicyModification Copy linkLink copied to clipboard!
Next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| applyYaml | String | ||||
| toDelete | List of StorageNetworkPolicyReference |
71.1.2.352. StorageNetworkPolicyPeer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| podSelector | |||||
| namespaceSelector | |||||
| ipBlock |
71.1.2.353. StorageNetworkPolicyPort Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| protocol | UNSET_PROTOCOL, TCP_PROTOCOL, UDP_PROTOCOL, SCTP_PROTOCOL, | ||||
| port | Integer | int32 | |||
| portName | String |
71.1.2.354. StorageNetworkPolicyReference Copy linkLink copied to clipboard!
Next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| namespace | String | ||||
| name | String |
71.1.2.355. StorageNetworkPolicySpec Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| podSelector | |||||
| ingress | List of StorageNetworkPolicyIngressRule | ||||
| egress | List of StorageNetworkPolicyEgressRule | ||||
| policyTypes | List of StorageNetworkPolicyType |
71.1.2.356. StorageNetworkPolicyType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET_NETWORK_POLICY_TYPE |
| INGRESS_NETWORK_POLICY_TYPE |
| EGRESS_NETWORK_POLICY_TYPE |
71.1.2.357. StorageNode Copy linkLink copied to clipboard!
Node represents information about a node in the cluster. next available tag: 28
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | A unique ID identifying this node. | |||
| name | String | The (host)name of the node. Might or might not be the same as ID. | |||
| taints | List of StorageTaint | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| joinedAt | Date | date-time | |||
| internalIpAddresses |
List of | ||||
| externalIpAddresses |
List of | ||||
| containerRuntimeVersion | String | Use container_runtime.version | |||
| containerRuntime | |||||
| kernelVersion | String | ||||
| operatingSystem | String | From NodeInfo. Operating system reported by the node (ex: linux). | |||
| osImage | String | From NodeInfo. OS image reported by the node from /etc/os-release. | |||
| kubeletVersion | String | ||||
| kubeProxyVersion | String | ||||
| lastUpdated | Date | date-time | |||
| k8sUpdated | Date | Time we received an update from Kubernetes. | date-time | ||
| scan | |||||
| components | Integer | int32 | |||
| cves | Integer | int32 | |||
| fixableCves | Integer | int32 | |||
| priority | String | int64 | |||
| riskScore | Float | float | |||
| topCvss | Float | float | |||
| notes | List of StorageNodeNote |
71.1.2.358. StorageNodeNote Copy linkLink copied to clipboard!
| Enum Values |
|---|
| MISSING_SCAN_DATA |
71.1.2.359. StorageNodeScan Copy linkLink copied to clipboard!
Next tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| scanTime | Date | date-time | |||
| operatingSystem | String | ||||
| components | List of StorageEmbeddedNodeScanComponent | ||||
| notes | List of StorageNodeScanNote | ||||
| scannerVersion | SCANNER, SCANNER_V4, |
71.1.2.360. StorageNodeScanNote Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| UNSUPPORTED |
| KERNEL_UNSUPPORTED |
| CERTIFIED_RHEL_CVES_UNAVAILABLE |
71.1.2.361. StorageNodeVulnerability Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cveBaseInfo | |||||
| cvss | Float | float | |||
| severity | UNKNOWN_VULNERABILITY_SEVERITY, LOW_VULNERABILITY_SEVERITY, MODERATE_VULNERABILITY_SEVERITY, IMPORTANT_VULNERABILITY_SEVERITY, CRITICAL_VULNERABILITY_SEVERITY, | ||||
| fixedBy | String | ||||
| snoozed | Boolean | ||||
| snoozeStart | Date | date-time | |||
| snoozeExpiry | Date | date-time |
71.1.2.362. StorageNotifier Copy linkLink copied to clipboard!
Next Tag: 21
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | String | ||||
| uiEndpoint | String | ||||
| labelKey | String | ||||
| labelDefault | String | ||||
| jira | |||||
| | |||||
| cscc | |||||
| splunk | |||||
| pagerduty | |||||
| generic | |||||
| sumologic | |||||
| awsSecurityHub | |||||
| syslog | |||||
| microsoftSentinel | |||||
| notifierSecret | String | ||||
| traits |
71.1.2.363. StorageNotifierConfiguration Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| emailConfig | |||||
| id | String |
71.1.2.364. StorageOperationStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| FAIL |
| PASS |
71.1.2.365. StorageOrchestratorMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| version | String | ||||
| openshiftVersion | String | ||||
| buildDate | Date | date-time | |||
| apiVersions |
List of |
71.1.2.366. StoragePagerDuty Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| apiKey | String | The API key for the integration. The server will mask the value of this credential in responses and logs. |
71.1.2.367. StoragePermissionLevel Copy linkLink copied to clipboard!
For any update to PermissionLevel, also update: - pkg/searchbasedpolicies/builders/k8s_rbac.go - ui/src/messages/common.js
| Enum Values |
|---|
| UNSET |
| NONE |
| DEFAULT |
| ELEVATED_IN_NAMESPACE |
| ELEVATED_CLUSTER_WIDE |
| CLUSTER_ADMIN |
71.1.2.368. StoragePermissionSet Copy linkLink copied to clipboard!
This encodes a set of permissions for StackRox resources.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | id is generated and cannot be changed. | |||
| name | String |
| |||
| description | String | ||||
| resourceToAccess | Map of StorageAccess | ||||
| traits |
71.1.2.369. StoragePlatformComponentConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| rules | List of PlatformComponentConfigRule | ||||
| needsReevaluation | Boolean |
71.1.2.370. StoragePod Copy linkLink copied to clipboard!
Pod represents information for a currently running pod or deleted pod in an active deployment.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| deploymentId | String | ||||
| namespace | String | ||||
| clusterId | String | ||||
| liveInstances | List of StorageContainerInstance | ||||
| terminatedInstances | List of PodContainerInstanceList | Must be a list of lists, so we can perform search queries (does not work for maps that aren’t <string, string>) There is one bucket (list) per container name. | |||
| started | Date | Time Kubernetes reports the pod was created. | date-time |
71.1.2.371. StoragePolicy Copy linkLink copied to clipboard!
Next tag: 28
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | Name of the policy. Must be unique. | |||
| description | String | Free-form text description of this policy. | |||
| rationale | String | ||||
| remediation | String | Describes how to remediate a violation of this policy. | |||
| disabled | Boolean | Toggles whether or not this policy will be executing and actively firing alerts. | |||
| categories |
List of | List of categories that this policy falls under. Category names must already exist in Central. | |||
| lifecycleStages | List of StorageLifecycleStage | Describes which policy lifecylce stages this policy applies to. Choices are DEPLOY, BUILD, and RUNTIME. | |||
| eventSource | NOT_APPLICABLE, DEPLOYMENT_EVENT, AUDIT_LOG_EVENT, NODE_EVENT, | ||||
| exclusions | List of StorageExclusion | Define deployments or images that should be excluded from this policy. | |||
| scope | List of StorageScope | Defines clusters, namespaces, and deployments that should be included in this policy. No scopes defined includes everything. | |||
| severity | UNSET_SEVERITY, LOW_SEVERITY, MEDIUM_SEVERITY, HIGH_SEVERITY, CRITICAL_SEVERITY, | ||||
| enforcementActions | List of StorageEnforcementAction | FAIL_DEPLOYMENT_CREATE_ENFORCEMENT takes effect only if admission control webhook is configured to enforce on object creates/updates. FAIL_KUBE_REQUEST_ENFORCEMENT takes effect only if admission control webhook is enabled to listen on exec and port-forward events. FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT takes effect only if admission control webhook is configured to enforce on object updates. Lists the enforcement actions to take when a violation from this policy is identified. Possible value are UNSET_ENFORCEMENT, SCALE_TO_ZERO_ENFORCEMENT, UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT, KILL_POD_ENFORCEMENT, FAIL_BUILD_ENFORCEMENT, FAIL_KUBE_REQUEST_ENFORCEMENT, FAIL_DEPLOYMENT_CREATE_ENFORCEMENT, and. FAIL_DEPLOYMENT_UPDATE_ENFORCEMENT. | |||
| notifiers |
List of | List of IDs of the notifiers that should be triggered when a violation from this policy is identified. IDs should be in the form of a UUID and are found through the Central API. | |||
| lastUpdated | Date | date-time | |||
| SORTName | String | For internal use only. | |||
| SORTLifecycleStage | String | For internal use only. | |||
| SORTEnforcement | Boolean | For internal use only. | |||
| policyVersion | String | ||||
| policySections | List of StoragePolicySection | PolicySections define the violation criteria for this policy. | |||
| mitreAttackVectors | List of PolicyMitreAttackVectors | ||||
| criteriaLocked | Boolean | Read-only field. If true, the policy’s criteria fields are rendered read-only. | |||
| mitreVectorsLocked | Boolean | Read-only field. If true, the policy’s MITRE ATT&CK fields are rendered read-only. | |||
| isDefault | Boolean | Read-only field. Indicates the policy is a default policy if true and a custom policy if false. | |||
| source | IMPERATIVE, DECLARATIVE, |
71.1.2.372. StoragePolicyGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| fieldName | String | Defines which field on a deployment or image this PolicyGroup evaluates. See https://docs.openshift.com/acs/operating/manage-security-policies.html#policy-criteria_manage-security-policies for a complete list of possible values. | |||
| booleanOperator | OR, AND, | ||||
| negate | Boolean | Determines if the evaluation of this PolicyGroup is negated. Default to false. | |||
| values | List of StoragePolicyValue |
71.1.2.373. StoragePolicyRule Copy linkLink copied to clipboard!
Properties of an individual rules that grant permissions to resources. ////////////////////////////////////////
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| verbs |
List of | ||||
| apiGroups |
List of | ||||
| resources |
List of | ||||
| nonResourceUrls |
List of | ||||
| resourceNames |
List of |
71.1.2.374. StoragePolicySection Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| sectionName | String | ||||
| policyGroups | List of StoragePolicyGroup | The set of policies groups that make up this section. Each group can be considered an individual criterion. |
71.1.2.375. StoragePolicySource Copy linkLink copied to clipboard!
| Enum Values |
|---|
| IMPERATIVE |
| DECLARATIVE |
71.1.2.376. StoragePolicyValue Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| value | String |
71.1.2.377. StoragePortConfig Copy linkLink copied to clipboard!
Next Available Tag: 6
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| containerPort | Integer | int32 | |||
| protocol | String | ||||
| exposure | UNSET, EXTERNAL, NODE, INTERNAL, HOST, ROUTE, | ||||
| exposedPort | Integer | int32 | |||
| exposureInfos | List of PortConfigExposureInfo |
71.1.2.378. StoragePrivateConfig Copy linkLink copied to clipboard!
next available tag: 10
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| DEPRECATEDAlertRetentionDurationDays | Integer | int32 | |||
| alertConfig | |||||
| imageRetentionDurationDays | Integer | int32 | |||
| expiredVulnReqRetentionDurationDays | Integer | int32 | |||
| decommissionedClusterRetention | |||||
| reportRetentionConfig | |||||
| vulnerabilityExceptionConfig | |||||
| administrationEventsConfig | |||||
| metrics |
71.1.2.379. StorageProcessBaseline Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| key | |||||
| elements | List of StorageBaselineElement | ||||
| elementGraveyard | List of StorageBaselineElement | ||||
| created | Date | date-time | |||
| userLockedTimestamp | Date | date-time | |||
| stackRoxLockedTimestamp | Date | date-time | |||
| lastUpdate | Date | date-time |
71.1.2.380. StorageProcessBaselineKey Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deploymentId | String | The idea is for the keys to be flexible. Only certain combinations of these will be supported. | |||
| containerName | String | ||||
| clusterId | String | ||||
| namespace | String |
71.1.2.381. StorageProcessIndicator Copy linkLink copied to clipboard!
Next available tag: 13
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| deploymentId | String | ||||
| containerName | String | ||||
| podId | String | ||||
| podUid | String | ||||
| signal | |||||
| clusterId | String | ||||
| namespace | String | ||||
| containerStartTime | Date | date-time | |||
| imageId | String |
71.1.2.382. StorageProcessListeningOnPort Copy linkLink copied to clipboard!
The API returns an array of these
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | |||||
| deploymentId | String | ||||
| containerName | String | ||||
| podId | String | ||||
| podUid | String | ||||
| signal | |||||
| clusterId | String | ||||
| namespace | String | ||||
| containerStartTime | Date | date-time | |||
| imageId | String |
71.1.2.383. StorageProcessSignal Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | A unique UUID for identifying the message We have this here instead of at the top level because we want to have each message to be self contained. | |||
| containerId | String | ||||
| time | Date | date-time | |||
| name | String | ||||
| args | String | ||||
| execFilePath | String | ||||
| pid | Long | int64 | |||
| uid | Long | int64 | |||
| gid | Long | int64 | |||
| lineage |
List of | ||||
| scraped | Boolean | ||||
| lineageInfo | List of ProcessSignalLineageInfo |
71.1.2.384. StoragePrometheusMetrics Copy linkLink copied to clipboard!
next available tag: 4
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| imageVulnerabilities | |||||
| policyViolations | |||||
| nodeVulnerabilities |
71.1.2.385. StorageProtocol Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET_PROTOCOL |
| TCP_PROTOCOL |
| UDP_PROTOCOL |
| SCTP_PROTOCOL |
71.1.2.386. StorageProviderMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| region | String | ||||
| zone | String | ||||
| | |||||
| aws | |||||
| azure | |||||
| verified | Boolean | ||||
| cluster |
71.1.2.387. StoragePublicConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| loginNotice | |||||
| header | |||||
| footer | |||||
| telemetry |
71.1.2.388. StorageQuayConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| oauthToken | String | The OAuth token for the integration. Required if this is a scanner integration. The server will mask the value of this credential in responses and logs. | |||
| insecure | Boolean | ||||
| registryRobotCredentials |
71.1.2.389. StorageReadinessProbe Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| defined | Boolean |
71.1.2.390. StorageReportConfiguration Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| description | String | ||||
| type | VULNERABILITY, | ||||
| vulnReportFilters | |||||
| scopeId | String | ||||
| emailConfig | |||||
| schedule | |||||
| lastRunStatus | |||||
| lastSuccessfulRunTime | Date | date-time | |||
| resourceScope | |||||
| notifiers | List of StorageNotifierConfiguration | ||||
| creator | |||||
| version | Integer | int32 |
71.1.2.391. StorageReportLastRunStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| reportStatus | SUCCESS, FAILURE, | ||||
| lastRunTime | Date | date-time | |||
| errorMsg | String |
71.1.2.392. StorageReportRetentionConfig Copy linkLink copied to clipboard!
next available tag: 4
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| historyRetentionDurationDays | Long | int64 | |||
| downloadableReportRetentionDays | Long | int64 | |||
| downloadableReportGlobalRetentionBytes | Long | int64 |
71.1.2.393. StorageResourceCollection Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| description | String | ||||
| createdAt | Date | date-time | |||
| lastUpdated | Date | date-time | |||
| createdBy | |||||
| updatedBy | |||||
| resourceSelectors | List of StorageResourceSelector |
| |||
| embeddedCollections |
71.1.2.394. StorageResourceScope Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collectionId | String | ||||
| entityScope |
71.1.2.395. StorageResourceSelector Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| rules | List of StorageSelectorRule |
|
71.1.2.396. StorageResources Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cpuCoresRequest | Float | float | |||
| cpuCoresLimit | Float | float | |||
| memoryMbRequest | Float | float | |||
| memoryMbLimit | Float | float |
71.1.2.397. StorageRisk Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| subject | |||||
| score | Float | float | |||
| results | List of RiskResult |
71.1.2.398. StorageRiskSubject Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| namespace | String | ||||
| clusterId | String | ||||
| type | UNKNOWN, DEPLOYMENT, NAMESPACE, CLUSTER, NODE, NODE_COMPONENT, IMAGE, IMAGE_COMPONENT, SERVICEACCOUNT, |
71.1.2.399. StorageRiskSubjectType Copy linkLink copied to clipboard!
Next tag: 9
| Enum Values |
|---|
| UNKNOWN |
| DEPLOYMENT |
| NAMESPACE |
| CLUSTER |
| NODE |
| NODE_COMPONENT |
| IMAGE |
| IMAGE_COMPONENT |
| SERVICEACCOUNT |
71.1.2.400. StorageRole Copy linkLink copied to clipboard!
A role specifies which actions are allowed for which subset of cluster objects. Permissions be can either specified directly via setting resource_to_access together with global_access or by referencing a permission set by its id in permission_set_name.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
| |||
| description | String | ||||
| permissionSetId | String | The associated PermissionSet and AccessScope for this Role. | |||
| accessScopeId | String | ||||
| globalAccess | NO_ACCESS, READ_ACCESS, READ_WRITE_ACCESS, | ||||
| resourceToAccess | Map of StorageAccess |
Deprecated 2021-04-20 in favor of | |||
| traits |
71.1.2.401. StorageRuleValue Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| value | String | ||||
| matchType | EXACT, REGEX, |
71.1.2.402. StorageS3Compatible Copy linkLink copied to clipboard!
S3Compatible configures the backup integration with an S3 compatible storage provider. S3 compatible is intended for non-AWS providers. For AWS S3 use S3Config.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| bucket | String | ||||
| accessKeyId | String | The access key ID to use. The server will mask the value of this credential in responses and logs. | |||
| secretAccessKey | String | The secret access key to use. The server will mask the value of this credential in responses and logs. | |||
| region | String | ||||
| objectPrefix | String | ||||
| endpoint | String | ||||
| urlStyle | S3_URL_STYLE_UNSPECIFIED, S3_URL_STYLE_VIRTUAL_HOSTED, S3_URL_STYLE_PATH, |
71.1.2.403. StorageS3Config Copy linkLink copied to clipboard!
S3Config configures the backup integration with AWS S3.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| bucket | String | ||||
| useIam | Boolean | ||||
| accessKeyId | String | The access key ID for the storage integration. The server will mask the value of this credential in responses and logs. | |||
| secretAccessKey | String | The secret access key for the storage integration. The server will mask the value of this credential in responses and logs. | |||
| region | String | ||||
| objectPrefix | String | ||||
| endpoint | String |
71.1.2.404. StorageS3URLStyle Copy linkLink copied to clipboard!
| Enum Values |
|---|
| S3_URL_STYLE_UNSPECIFIED |
| S3_URL_STYLE_VIRTUAL_HOSTED |
| S3_URL_STYLE_PATH |
71.1.2.405. StorageScannerHealthInfo Copy linkLink copied to clipboard!
ScannerHealthInfo represents health info of a scanner instance that is deployed on a secured cluster (so called "local scanner"). When the scanner is deployed on a central cluster, the following message is NOT used. ScannerHealthInfo carries data about scanner deployment but does not include scanner health status derived from this data. Aggregated scanner health status is not included because it is derived in central and not in the component that first reports ScannerHealthInfo (sensor).
The following fields are made optional/nullable because there can be errors when trying to obtain them and the default value of 0 might be confusing with the actual value 0. In case an error happens when trying to obtain a certain field, it will be absent (instead of having the default value).
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| totalDesiredAnalyzerPods | Integer | int32 | |||
| totalReadyAnalyzerPods | Integer | int32 | |||
| totalDesiredDbPods | Integer | int32 | |||
| totalReadyDbPods | Integer | int32 | |||
| statusErrors |
List of | Collection of errors that occurred while trying to obtain scanner health info. |
71.1.2.406. StorageScannerV4Config Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numConcurrentScans | Integer | int32 | |||
| indexerEndpoint | String | ||||
| matcherEndpoint | String |
71.1.2.407. StorageSchedule Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| intervalType | UNSET, DAILY, WEEKLY, MONTHLY, | ||||
| hour | Integer | int32 | |||
| minute | Integer | int32 | |||
| weekly | |||||
| daysOfWeek | |||||
| daysOfMonth |
71.1.2.408. StorageScope Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster | String | ||||
| namespace | String | ||||
| label | |||||
| clusterLabel | |||||
| namespaceLabel |
71.1.2.409. StorageScopeLabel Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| value | String |
71.1.2.410. StorageSecret Copy linkLink copied to clipboard!
Flat secret object. Any properties of an individual secret. (regardless of time, scope, or context) ////////////////////////////////////////
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| clusterId | String | ||||
| clusterName | String | ||||
| namespace | String | ||||
| type | String | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| createdAt | Date | date-time | |||
| files | List of StorageSecretDataFile | Metadata about the secrets. The secret need not be a file, but rather may be an arbitrary value. | |||
| relationship |
71.1.2.411. StorageSecretContainerRelationship Copy linkLink copied to clipboard!
Secrets can be mounted in a path in a container. Next Tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | Id of the container the secret is mounted in. | |||
| path | String | Path is a container specific mounting directory. |
71.1.2.412. StorageSecretDataFile Copy linkLink copied to clipboard!
Metadata about secret. Additional information is presented for a certificate file and imagePullSecret, but the "file" may also represent some arbitrary value.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| type | UNDETERMINED, PUBLIC_CERTIFICATE, CERTIFICATE_REQUEST, PRIVACY_ENHANCED_MESSAGE, OPENSSH_PRIVATE_KEY, PGP_PRIVATE_KEY, EC_PRIVATE_KEY, RSA_PRIVATE_KEY, DSA_PRIVATE_KEY, CERT_PRIVATE_KEY, ENCRYPTED_PRIVATE_KEY, IMAGE_PULL_SECRET, | ||||
| cert | |||||
| imagePullSecret |
71.1.2.413. StorageSecretDeploymentRelationship Copy linkLink copied to clipboard!
Secrets can be used by a deployment. Next Tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | Id of the deployment using the secret within a container. | |||
| name | String | Name of the deployment. |
71.1.2.414. StorageSecretRelationship Copy linkLink copied to clipboard!
The combined relationships that belong to the secret. Next Tag: 6
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| containerRelationships | |||||
| deploymentRelationships | Deployment id to relationship. |
71.1.2.415. StorageSecretType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNDETERMINED |
| PUBLIC_CERTIFICATE |
| CERTIFICATE_REQUEST |
| PRIVACY_ENHANCED_MESSAGE |
| OPENSSH_PRIVATE_KEY |
| PGP_PRIVATE_KEY |
| EC_PRIVATE_KEY |
| RSA_PRIVATE_KEY |
| DSA_PRIVATE_KEY |
| CERT_PRIVATE_KEY |
| ENCRYPTED_PRIVATE_KEY |
| IMAGE_PULL_SECRET |
71.1.2.416. StorageSecurityContext Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| privileged | Boolean | ||||
| selinux | |||||
| dropCapabilities |
List of | ||||
| addCapabilities |
List of | ||||
| readOnlyRootFilesystem | Boolean | ||||
| seccompProfile | |||||
| allowPrivilegeEscalation | Boolean |
71.1.2.417. StorageSelectorRule Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| fieldName | String | ||||
| operator | OR, AND, | ||||
| values | List of StorageRuleValue |
|
71.1.2.418. StorageSensorDeploymentIdentification Copy linkLink copied to clipboard!
StackRoxDeploymentIdentification aims at uniquely identifying a StackRox Sensor deployment. It is used to determine whether a sensor connection comes from a sensor pod that has restarted or was recreated (possibly after a network partition), or from a deployment in a different namespace or cluster.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| systemNamespaceId | String | ||||
| defaultNamespaceId | String | ||||
| appNamespace | String | ||||
| appNamespaceId | String | ||||
| appServiceaccountId | String | ||||
| k8sNodeName | String |
71.1.2.419. StorageSensorUpgradeConfig Copy linkLink copied to clipboard!
SensorUpgradeConfig encapsulates configuration relevant to sensor auto-upgrades.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enableAutoUpgrade | Boolean | Whether to automatically trigger upgrades for out-of-date sensors. |
71.1.2.420. StorageServiceAccount Copy linkLink copied to clipboard!
Any properties of an individual service account. (regardless of time, scope, or context) ////////////////////////////////////////
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| namespace | String | ||||
| clusterName | String | ||||
| clusterId | String | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| createdAt | Date | date-time | |||
| automountToken | Boolean | ||||
| secrets |
List of | ||||
| imagePullSecrets |
List of |
71.1.2.421. StorageServiceIdentity Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| serialStr | String | ||||
| serial | String | int64 | |||
| id | String | ||||
| type | UNKNOWN_SERVICE, SENSOR_SERVICE, CENTRAL_SERVICE, CENTRAL_DB_SERVICE, REMOTE_SERVICE, COLLECTOR_SERVICE, MONITORING_UI_SERVICE, MONITORING_DB_SERVICE, MONITORING_CLIENT_SERVICE, BENCHMARK_SERVICE, SCANNER_SERVICE, SCANNER_DB_SERVICE, ADMISSION_CONTROL_SERVICE, SCANNER_V4_INDEXER_SERVICE, SCANNER_V4_MATCHER_SERVICE, SCANNER_V4_DB_SERVICE, SCANNER_V4_SERVICE, REGISTRANT_SERVICE, | ||||
| initBundleId | String |
71.1.2.422. StorageServiceType Copy linkLink copied to clipboard!
Next available tag: 18
- SCANNER_V4_SERVICE: This is used when Scanner V4 is run in combo-mode.
| Enum Values |
|---|
| UNKNOWN_SERVICE |
| SENSOR_SERVICE |
| CENTRAL_SERVICE |
| CENTRAL_DB_SERVICE |
| REMOTE_SERVICE |
| COLLECTOR_SERVICE |
| MONITORING_UI_SERVICE |
| MONITORING_DB_SERVICE |
| MONITORING_CLIENT_SERVICE |
| BENCHMARK_SERVICE |
| SCANNER_SERVICE |
| SCANNER_DB_SERVICE |
| ADMISSION_CONTROL_SERVICE |
| SCANNER_V4_INDEXER_SERVICE |
| SCANNER_V4_MATCHER_SERVICE |
| SCANNER_V4_DB_SERVICE |
| SCANNER_V4_SERVICE |
| REGISTRANT_SERVICE |
71.1.2.423. StorageSetBasedLabelSelector Copy linkLink copied to clipboard!
SetBasedLabelSelector only allows set-based label requirements.
Next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| requirements | List of SetBasedLabelSelectorRequirement |
71.1.2.424. StorageSeverity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET_SEVERITY |
| LOW_SEVERITY |
| MEDIUM_SEVERITY |
| HIGH_SEVERITY |
| CRITICAL_SEVERITY |
71.1.2.425. StorageSignature Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cosign |
71.1.2.426. StorageSignatureIntegration Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| cosign | |||||
| cosignCertificates | |||||
| transparencyLog | |||||
| traits |
71.1.2.427. StorageSimpleAccessScope Copy linkLink copied to clipboard!
Simple access scope is a (simple) selection criteria for scoped resources. It does not allow multi-component AND-rules nor set operations on names.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String |
| |||
| name | String |
| |||
| description | String | ||||
| rules | |||||
| traits |
71.1.2.428. StorageSlimUser Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String |
71.1.2.429. StorageSource Copy linkLink copied to clipboard!
| Enum Values |
|---|
| SOURCE_UNKNOWN |
| SOURCE_RED_HAT |
| SOURCE_OSV |
| SOURCE_NVD |
71.1.2.430. StorageSourceType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| OS |
| PYTHON |
| JAVA |
| RUBY |
| NODEJS |
| GO |
| DOTNETCORERUNTIME |
| INFRASTRUCTURE |
71.1.2.431. StorageSplunk Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| httpToken | String | The HTTP token for the integration. The server will mask the value of this credential in responses and logs. | |||
| httpEndpoint | String | ||||
| insecure | Boolean | ||||
| truncate | String | int64 | |||
| auditLoggingEnabled | Boolean | ||||
| derivedSourceType | Boolean | ||||
| sourceTypes |
Map of |
71.1.2.432. StorageStaticClusterConfig Copy linkLink copied to clipboard!
The difference between Static and Dynamic cluster config is that Static values are not sent over the Central to Sensor gRPC connection. They are used, for example, to generate manifests that can be used to set up the Secured Cluster’s k8s components. They are not dynamically reloaded.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| type | GENERIC_CLUSTER, KUBERNETES_CLUSTER, OPENSHIFT_CLUSTER, OPENSHIFT4_CLUSTER, | ||||
| mainImage | String | ||||
| centralApiEndpoint | String | ||||
| collectionMethod | UNSET_COLLECTION, NO_COLLECTION, KERNEL_MODULE, EBPF, CORE_BPF, | ||||
| collectorImage | String | ||||
| admissionController | Boolean | ||||
| admissionControllerUpdates | Boolean | ||||
| tolerationsConfig | |||||
| slimCollector | Boolean | ||||
| admissionControllerEvents | Boolean | ||||
| admissionControllerFailOnError | Boolean |
71.1.2.433. StorageSubject Copy linkLink copied to clipboard!
Properties of an individual subjects who are granted roles via role bindings. ////////////////////////////////////////
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| kind | UNSET_KIND, SERVICE_ACCOUNT, USER, GROUP, | ||||
| name | String | ||||
| namespace | String | ||||
| clusterId | String | ||||
| clusterName | String |
71.1.2.434. StorageSubjectKind Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET_KIND |
| SERVICE_ACCOUNT |
| USER |
| GROUP |
71.1.2.435. StorageSumoLogic Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| httpSourceAddress | String | ||||
| skipTLSVerify | Boolean |
71.1.2.436. StorageSyslog Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| localFacility | LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7, | ||||
| tcpConfig | |||||
| extraFields | List of StorageKeyValuePair | ||||
| messageFormat | LEGACY, CEF, | ||||
| maxMessageSize | Integer | int32 |
71.1.2.437. StorageTaint Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| value | String | ||||
| taintEffect | UNKNOWN_TAINT_EFFECT, NO_SCHEDULE_TAINT_EFFECT, PREFER_NO_SCHEDULE_TAINT_EFFECT, NO_EXECUTE_TAINT_EFFECT, |
71.1.2.438. StorageTaintEffect Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN_TAINT_EFFECT |
| NO_SCHEDULE_TAINT_EFFECT |
| PREFER_NO_SCHEDULE_TAINT_EFFECT |
| NO_EXECUTE_TAINT_EFFECT |
71.1.2.439. StorageTelemetryConfiguration Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean | ||||
| lastSetTime | Date | date-time |
71.1.2.440. StorageTokenMetadata Copy linkLink copied to clipboard!
Next available tag: 8
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| roles |
List of | ||||
| issuedAt | Date | date-time | |||
| expiration | Date | date-time | |||
| revoked | Boolean | ||||
| role | String |
71.1.2.441. StorageToleration Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| operator | TOLERATION_OPERATION_UNKNOWN, TOLERATION_OPERATOR_EXISTS, TOLERATION_OPERATOR_EQUAL, | ||||
| value | String | ||||
| taintEffect | UNKNOWN_TAINT_EFFECT, NO_SCHEDULE_TAINT_EFFECT, PREFER_NO_SCHEDULE_TAINT_EFFECT, NO_EXECUTE_TAINT_EFFECT, |
71.1.2.442. StorageTolerationOperator Copy linkLink copied to clipboard!
| Enum Values |
|---|
| TOLERATION_OPERATION_UNKNOWN |
| TOLERATION_OPERATOR_EXISTS |
| TOLERATION_OPERATOR_EQUAL |
71.1.2.443. StorageTolerationsConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| disabled | Boolean |
71.1.2.444. StorageTraits Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| mutabilityMode | ALLOW_MUTATE, ALLOW_MUTATE_FORCED, | ||||
| visibility | VISIBLE, HIDDEN, | ||||
| origin | IMPERATIVE, DEFAULT, DECLARATIVE, DECLARATIVE_ORPHANED, EPHEMERAL, | ||||
| expiresAt | Date | expires_at specifies when this object should be considered expired and eligible for pruning. This field is optional. Objects without an expires_at value are never pruned based on expiry. Currently used for dynamically created RBAC objects (roles, permission sets, access scopes) that are generated by the internal token API for sensors. | date-time |
71.1.2.445. StorageTraitsMutabilityMode Copy linkLink copied to clipboard!
EXPERIMENTAL. NOTE: Please refer from using MutabilityMode for the time being. It will be replaced in the future (ROX-14276). MutabilityMode specifies whether and how an object can be modified. Default is ALLOW_MUTATE and means there are no modification restrictions; this is equivalent to the absence of MutabilityMode specification. ALLOW_MUTATE_FORCED forbids all modifying operations except object removal with force bit on.
Be careful when changing the state of this field. For example, modifying an object from ALLOW_MUTATE to ALLOW_MUTATE_FORCED is allowed but will prohibit any further changes to it, including modifying it back to ALLOW_MUTATE.
| Enum Values |
|---|
| ALLOW_MUTATE |
| ALLOW_MUTATE_FORCED |
71.1.2.446. StorageTraitsOrigin Copy linkLink copied to clipboard!
Origin specifies the origin of an object. Objects can have five different origins: - IMPERATIVE: the object was created via the API. This is assumed by default. - DEFAULT: the object is a default object, such as default roles, access scopes etc. - DECLARATIVE: the object is created via declarative configuration. - DECLARATIVE_ORPHANED: the object is created via declarative configuration and then unsuccessfully deleted(for example, because it is referenced by another object) - EPHEMERAL: the object is created via an internal API, generated on the fly and meant to be ephemeral. Based on the origin, different rules apply to the objects. Objects with the DECLARATIVE origin are not allowed to be modified via API, only via declarative configuration. Additionally, they may not reference objects with the IMPERATIVE or EPHEMERAL origin. Objects with the DEFAULT origin are not allowed to be modified via either API or declarative configuration. They may be referenced by all other objects. Objects with the IMPERATIVE origin are allowed to be modified via API, not via declarative configuration. They may reference all other objects. Objects with the EPHEMERAL origin are neither allowed to be modified via API, nor via declarative configuration. They may reference all other objects. Objects with the DECLARATIVE_ORPHANED origin are not allowed to be modified via either API or declarative configuration. DECLARATIVE_ORPHANED resource can become DECLARATIVE again if it is redefined in declarative configuration. Objects with this origin will be cleaned up from the system immediately after they are not referenced by other resources anymore. They may be referenced by all other objects.
| Enum Values |
|---|
| IMPERATIVE |
| DEFAULT |
| DECLARATIVE |
| DECLARATIVE_ORPHANED |
| EPHEMERAL |
71.1.2.447. StorageTraitsVisibility Copy linkLink copied to clipboard!
EXPERIMENTAL. visibility allows to specify whether the object should be visible for certain APIs.
| Enum Values |
|---|
| VISIBLE |
| HIDDEN |
71.1.2.448. StorageTransparencyLogVerification Copy linkLink copied to clipboard!
Validate the inclusion of signature signing events into a transparency log.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean | Validate the inclusion of signatures into a transparency log. Disables validation if not enabled. | |||
| url | String |
The URL of the transparency log. Required for online confirmation of inclusion into the transparency log. Defaults to the Sigstore instance | |||
| validateOffline | Boolean | Force offline validation of the signature proof of inclusion into the transparency log. Do not fall back to request confirmation from the transparency log over network. | |||
| publicKeyPemEnc | String | PEM encoded public key used to validate the proof of inclusion into the transparency log. Defaults to the key of the public Sigstore instance if left empty. |
71.1.2.449. StorageUpgradeProgress Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| upgradeState | UPGRADE_INITIALIZING, UPGRADER_LAUNCHING, UPGRADER_LAUNCHED, PRE_FLIGHT_CHECKS_COMPLETE, UPGRADE_OPERATIONS_DONE, UPGRADE_COMPLETE, UPGRADE_INITIALIZATION_ERROR, PRE_FLIGHT_CHECKS_FAILED, UPGRADE_ERROR_ROLLING_BACK, UPGRADE_ERROR_ROLLED_BACK, UPGRADE_ERROR_ROLLBACK_FAILED, UPGRADE_ERROR_UNKNOWN, UPGRADE_TIMED_OUT, | ||||
| upgradeStatusDetail | String | ||||
| since | Date | date-time |
71.1.2.450. StorageUser Copy linkLink copied to clipboard!
User is an object that allows us to track the roles a user is tied to, and how they logged in.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| authProviderId | String | ||||
| attributes | List of StorageUserAttribute | ||||
| idpToken | String |
71.1.2.451. StorageUserAttribute Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| value | String |
71.1.2.452. StorageUserInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| username | String | ||||
| friendlyName | String | ||||
| permissions | |||||
| roles | List of StorageUserInfoRole |
71.1.2.453. StorageUserInfoRole Copy linkLink copied to clipboard!
Role is wire compatible with the old format of storage.Role and hence only includes role name and associated permissions.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| resourceToAccess | Map of StorageAccess |
71.1.2.454. StorageV1Metadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| digest | String | ||||
| created | Date | date-time | |||
| author | String | ||||
| layers | List of StorageImageLayer | ||||
| user | String | ||||
| command |
List of | ||||
| entrypoint |
List of | ||||
| volumes |
List of | ||||
| labels |
Map of |
71.1.2.455. StorageV2Metadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| digest | String |
71.1.2.456. StorageViolationState Copy linkLink copied to clipboard!
| Enum Values |
|---|
| ACTIVE |
| RESOLVED |
| ATTEMPTED |
71.1.2.457. StorageVolume Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| source | String | ||||
| destination | String | ||||
| readOnly | Boolean | ||||
| type | String | ||||
| mountPropagation | NONE, HOST_TO_CONTAINER, BIDIRECTIONAL, |
71.1.2.458. StorageVulnerabilityExceptionConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| expiryOptions |
71.1.2.459. StorageVulnerabilityExceptionConfigExpiryOptions Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| dayOptions | List of StorageDayOption | ||||
| fixableCveOptions | |||||
| customDate | Boolean | ||||
| indefinite | Boolean |
71.1.2.460. StorageVulnerabilityExceptionConfigFixableCVEOptions Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| allFixable | Boolean | ||||
| anyFixable | Boolean |
71.1.2.461. StorageVulnerabilityReportFilters Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| fixability | BOTH, FIXABLE, NOT_FIXABLE, | ||||
| sinceLastReport | Boolean | ||||
| severities | List of StorageVulnerabilitySeverity | ||||
| imageTypes | |||||
| allVuln | Boolean | ||||
| sinceLastSentScheduledReport | Boolean | ||||
| sinceStartDate | Date | date-time | |||
| accessScopeRules | List of SimpleAccessScopeRules | ||||
| includeNvdCvss | Boolean | ||||
| includeEpssProbability | Boolean | ||||
| includeAdvisory | Boolean | ||||
| query | String |
71.1.2.462. StorageVulnerabilitySeverity Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN_VULNERABILITY_SEVERITY |
| LOW_VULNERABILITY_SEVERITY |
| MODERATE_VULNERABILITY_SEVERITY |
| IMPORTANT_VULNERABILITY_SEVERITY |
| CRITICAL_VULNERABILITY_SEVERITY |
71.1.2.463. StorageVulnerabilityState Copy linkLink copied to clipboard!
VulnerabilityState indicates if vulnerability is being observed or deferred(/suppressed). By default, it vulnerabilities are observed.
- OBSERVED: [Default state]
| Enum Values |
|---|
| OBSERVED |
| DEFERRED |
| FALSE_POSITIVE |
71.1.2.464. StorageWatchedImage Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.465. SyslogLocalFacility Copy linkLink copied to clipboard!
| Enum Values |
|---|
| LOCAL0 |
| LOCAL1 |
| LOCAL2 |
| LOCAL3 |
| LOCAL4 |
| LOCAL5 |
| LOCAL6 |
| LOCAL7 |
71.1.2.466. SyslogMessageFormat Copy linkLink copied to clipboard!
| Enum Values |
|---|
| LEGACY |
| CEF |
71.1.2.467. SyslogTCPConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| hostname | String | ||||
| port | Integer | int32 | |||
| skipTlsVerify | Boolean | ||||
| useTls | Boolean |
71.1.2.468. TraceBuiltInAuthorizer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clustersTotalNum | Integer | int32 | |||
| namespacesTotalNum | Integer | int32 | |||
| deniedAuthzDecisions |
Map of | int32 | |||
| allowedAuthzDecisions |
Map of | int32 | |||
| effectiveAccessScopes |
Map of |
71.1.2.469. UpgradeProcessStatusUpgradeProcessType Copy linkLink copied to clipboard!
- UPGRADE: UPGRADE represents a sensor version upgrade.
- CERT_ROTATION: CERT_ROTATION represents an upgrade process that only rotates the TLS certs used by the cluster, without changing anything else.
| Enum Values |
|---|
| UPGRADE |
| CERT_ROTATION |
71.1.2.470. UpgradeProgressUpgradeState Copy linkLink copied to clipboard!
- UPGRADER_LAUNCHING: In-progress states.
- UPGRADE_COMPLETE: The success state. PLEASE NUMBER ALL IN-PROGRESS STATES ABOVE THIS AND ALL ERROR STATES BELOW THIS.
- UPGRADE_INITIALIZATION_ERROR: Error states.
| Enum Values |
|---|
| UPGRADE_INITIALIZING |
| UPGRADER_LAUNCHING |
| UPGRADER_LAUNCHED |
| PRE_FLIGHT_CHECKS_COMPLETE |
| UPGRADE_OPERATIONS_DONE |
| UPGRADE_COMPLETE |
| UPGRADE_INITIALIZATION_ERROR |
| PRE_FLIGHT_CHECKS_FAILED |
| UPGRADE_ERROR_ROLLING_BACK |
| UPGRADE_ERROR_ROLLED_BACK |
| UPGRADE_ERROR_ROLLBACK_FAILED |
| UPGRADE_ERROR_UNKNOWN |
| UPGRADE_TIMED_OUT |
71.1.2.471. UserInfoResourceToAccess Copy linkLink copied to clipboard!
ResourceToAccess represents a collection of permissions. It is wire compatible with the old format of storage.Role and replaces it in places where only aggregated permissions are required.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| resourceToAccess | Map of StorageAccess |
71.1.2.472. UserRole Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| permissions | Map of StorageAccess | ||||
| accessScopeName | String | ||||
| accessScope |
71.1.2.473. V1AddAuthMachineToMachineConfigRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.474. V1AddAuthMachineToMachineConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.475. V1AdministrationEvent Copy linkLink copied to clipboard!
AdministrationEvents are administrative events emitted by Central. They are used to create transparency for users for asynchronous, background tasks. Events are part of Central’s system health view.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | UUID of the event. | |||
| type | ADMINISTRATION_EVENT_TYPE_UNKNOWN, ADMINISTRATION_EVENT_TYPE_GENERIC, ADMINISTRATION_EVENT_TYPE_LOG_MESSAGE, | ||||
| level | ADMINISTRATION_EVENT_LEVEL_UNKNOWN, ADMINISTRATION_EVENT_LEVEL_INFO, ADMINISTRATION_EVENT_LEVEL_SUCCESS, ADMINISTRATION_EVENT_LEVEL_WARNING, ADMINISTRATION_EVENT_LEVEL_ERROR, | ||||
| message | String | Message associated with the event. The message may include detailed information for this particular event. | |||
| hint | String | Hint associated with the event. The hint may include different information based on the type of event. It can include instructions to resolve an event, or informational hints. | |||
| domain | String | Domain associated with the event. An event’s domain outlines the feature domain where the event was created from. As an example, this might be "Image Scanning". In case of events that cannot be tied to a specific domain, this will be "General". | |||
| resource | |||||
| numOccurrences | String | Occurrences associated with the event. When events may occur multiple times, the occurrences track the amount. | int64 | ||
| lastOccurredAt | Date | Specifies the time when the event has last occurred. | date-time | ||
| createdAt | Date | Specifies the time when the event has been created. | date-time |
71.1.2.476. V1AdministrationEventLevel Copy linkLink copied to clipboard!
AdministrationEventLevel exposes the different levels of events.
| Enum Values |
|---|
| ADMINISTRATION_EVENT_LEVEL_UNKNOWN |
| ADMINISTRATION_EVENT_LEVEL_INFO |
| ADMINISTRATION_EVENT_LEVEL_SUCCESS |
| ADMINISTRATION_EVENT_LEVEL_WARNING |
| ADMINISTRATION_EVENT_LEVEL_ERROR |
71.1.2.477. V1AdministrationEventType Copy linkLink copied to clipboard!
AdministrationEventType exposes the different types of events.
| Enum Values |
|---|
| ADMINISTRATION_EVENT_TYPE_UNKNOWN |
| ADMINISTRATION_EVENT_TYPE_GENERIC |
| ADMINISTRATION_EVENT_TYPE_LOG_MESSAGE |
71.1.2.478. V1AdministrationEventsFilter Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| from | Date | Matches events with last_occurred_at after a specific timestamp, i.e. the lower boundary. | date-time | ||
| until | Date | Matches events with last_occurred_at before a specific timestamp, i.e. the upper boundary. | date-time | ||
| domain |
List of | Matches events from a specific domain. | |||
| resourceType |
List of | Matches events associated with a specific resource type. | |||
| type | List of V1AdministrationEventType | Matches events based on their type. | |||
| level | List of V1AdministrationEventLevel | Matches events based on their level. |
71.1.2.479. V1AggregateBy Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| aggrFunc | UNSET, COUNT, MIN, MAX, | ||||
| distinct | Boolean |
71.1.2.480. V1Aggregation Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| COUNT |
| MIN |
| MAX |
71.1.2.481. V1AlertEvent Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| time | String | int64 | |||
| type | CREATED, REMOVED, | ||||
| id | String |
71.1.2.482. V1AuthMachineToMachineConfig Copy linkLink copied to clipboard!
AuthMachineToMachineConfig determines rules for exchanging an identity token from a third party with a Central access token. The M2M stands for machine to machine, as this is the intended use-case for the config.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | UUID of the config. Note that when adding a machine to machine config, this field should not be set. | |||
| type | GENERIC, GITHUB_ACTIONS, KUBE_SERVICE_ACCOUNT, | ||||
| tokenExpirationDuration | String | Sets the expiration of the token returned from the ExchangeAuthMachineToMachineToken API call. Possible valid time units are: s, m, h. The maximum allowed expiration duration is 24h. As an example: 2h45m. For additional information on the validation of the duration, see: https://pkg.go.dev/time#ParseDuration. | |||
| mappings | At least one mapping is required to resolve to a valid role for the access token to be successfully generated. | ||||
| issuer | String | The issuer of the related OIDC provider issuing the ID tokens to exchange. Must be non-empty string containing URL when type is GENERIC. In case of GitHub actions, this must be empty or set to https://token.actions.githubusercontent.com. Issuer is a unique key, therefore there may be at most one GITHUB_ACTIONS config, and each GENERIC config must have a distinct issuer. | |||
| traits |
71.1.2.483. V1AuthMachineToMachineConfigType Copy linkLink copied to clipboard!
The type of the auth machine to machine config. Currently supports GitHub actions or any other generic OIDC provider to use for verifying and exchanging the token.
| Enum Values |
|---|
| GENERIC |
| GITHUB_ACTIONS |
| KUBE_SERVICE_ACCOUNT |
71.1.2.484. V1AuthStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| userId | String | ||||
| serviceId | |||||
| expires | Date | date-time | |||
| refreshUrl | String | ||||
| authProvider | |||||
| userInfo | |||||
| userAttributes | List of V1UserAttribute | ||||
| idpToken | String | Token returned to ACS by the underlying identity provider. This field is set only in a few, specific contexts. Do not rely on this field being present in the response. |
71.1.2.485. V1Authorities Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| authorities | List of V1Authority |
71.1.2.486. V1Authority Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| certificatePem | byte[] | byte |
71.1.2.487. V1AuthorizationTraceResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| arrivedAt | Date | date-time | |||
| processedAt | Date | date-time | |||
| request | |||||
| response | |||||
| user | |||||
| trace |
71.1.2.488. V1AuthorizationTraceResponseRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String | ||||
| method | String |
71.1.2.489. V1AuthorizationTraceResponseResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| status | UNKNOWN_STATUS, SUCCESS, FAILURE, | ||||
| error | String |
71.1.2.490. V1AutocompleteResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| values |
List of |
71.1.2.491. V1AvailableProviderTypesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| authProviderTypes |
71.1.2.492. V1BuildDetectionRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| image | |||||
| imageName | String | ||||
| noExternalMetadata | Boolean | ||||
| sendNotifications | Boolean | ||||
| force | Boolean | ||||
| policyCategories |
List of | ||||
| cluster | String | Cluster to delegate scan to, may be the cluster’s name or ID. | |||
| namespace | String | Namespace on the secured cluster from which to read context information when delegating image scans, specifically pull secrets to access the image registry. |
71.1.2.493. V1BuildDetectionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| alerts | List of StorageAlert |
71.1.2.494. V1BulkProcessBaselinesRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | ||||
| namespaces |
List of |
71.1.2.495. V1BulkUpdateProcessBaselinesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| success | Boolean |
71.1.2.496. V1CRSGenRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.497. V1CRSGenRequestExtended Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| validUntil | Date | date-time | |||
| validFor | String | ||||
| maxRegistrations | String | uint64 |
71.1.2.498. V1CRSGenResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| meta | |||||
| crs | byte[] | byte |
71.1.2.499. V1CRSMeta Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| createdAt | Date | date-time | |||
| createdBy | |||||
| expiresAt | Date | date-time | |||
| maxRegistrations | String | uint64 | |||
| registrationsInitiated |
List of | ||||
| registrationsCompleted |
List of |
71.1.2.500. V1CRSMetasResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| items | List of V1CRSMeta |
71.1.2.501. V1CRSRevokeRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| ids |
List of |
71.1.2.502. V1CRSRevokeResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| crsRevocationErrors | |||||
| revokedIds |
List of |
71.1.2.503. V1CentralServicesCapabilities Copy linkLink copied to clipboard!
Provides availability of certain functionality of Central Services in the current configuration. The initial intended use is to disable certain functionality that does not make sense in the Cloud Service context.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| centralScanningCanUseContainerIamRoleForEcr | CapabilityAvailable, CapabilityDisabled, | ||||
| centralCanUseCloudBackupIntegrations | CapabilityAvailable, CapabilityDisabled, | ||||
| centralCanDisplayDeclarativeConfigHealth | CapabilityAvailable, CapabilityDisabled, | ||||
| centralCanUpdateCert | CapabilityAvailable, CapabilityDisabled, | ||||
| centralCanUseAcscsEmailIntegration | CapabilityAvailable, CapabilityDisabled, |
71.1.2.504. V1CentralUpgradeStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| version | String | ||||
| forceRollbackTo | String | The version of previous clone in Central. This is the version we can force rollback to. | |||
| canRollbackAfterUpgrade | Boolean | If true, we can rollback to the current version if an upgrade failed. | |||
| spaceRequiredForRollbackAfterUpgrade | String | int64 | |||
| spaceAvailableForRollbackAfterUpgrade | String | int64 |
71.1.2.505. V1CloudSource Copy linkLink copied to clipboard!
CloudSource is an integration which provides a source for discovered clusters.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| type | TYPE_UNSPECIFIED, TYPE_PALADIN_CLOUD, TYPE_OCM, | ||||
| credentials | |||||
| skipTestIntegration | Boolean | ||||
| paladinCloud | |||||
| ocm |
71.1.2.506. V1CloudSourceType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| TYPE_UNSPECIFIED |
| TYPE_PALADIN_CLOUD |
| TYPE_OCM |
71.1.2.507. V1CloudSourcesFilter Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| names |
List of | Matches cloud sources based on their name. | |||
| types | List of V1CloudSourceType | Matches cloud sources based on their type. |
71.1.2.508. V1ClusterDefaultsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| mainImageRepository | String | ||||
| collectorImageRepository | String | ||||
| kernelSupportAvailable | Boolean |
71.1.2.509. V1ClusterResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster | |||||
| clusterRetentionInfo |
71.1.2.510. V1ClustersList Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusters | List of StorageCluster | ||||
| clusterIdToRetentionInfo |
71.1.2.511. V1CollectionDeploymentMatchOptions Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| withMatches | Boolean | ||||
| filterQuery |
71.1.2.512. V1ComplianceControl Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| standardId | String | ||||
| groupId | String | ||||
| name | String | ||||
| description | String | ||||
| implemented | Boolean | ||||
| interpretationText | String |
71.1.2.513. V1ComplianceControlGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| standardId | String | ||||
| name | String | ||||
| description | String | ||||
| numImplementedChecks | Integer | int32 |
71.1.2.514. V1ComplianceRun Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| clusterId | String | ||||
| standardId | String | ||||
| startTime | Date | date-time | |||
| finishTime | Date | date-time | |||
| state | INVALID, READY, STARTED, WAIT_FOR_DATA, EVALUTING_CHECKS, FINISHED, | ||||
| errorMessage | String |
71.1.2.515. V1ComplianceRunSelection Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | The ID of the cluster. "*" means "all clusters". | |||
| standardId | String | The ID of the compliance standard. "*" means "all standards". |
71.1.2.516. V1ComplianceRunState Copy linkLink copied to clipboard!
| Enum Values |
|---|
| INVALID |
| READY |
| STARTED |
| WAIT_FOR_DATA |
| EVALUTING_CHECKS |
| FINISHED |
71.1.2.517. V1ComplianceStandard Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| metadata | |||||
| groups | List of V1ComplianceControlGroup | ||||
| controls | List of V1ComplianceControl |
71.1.2.518. V1ComplianceStandardMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| description | String | ||||
| numImplementedChecks | Integer | int32 | |||
| scopes | |||||
| dynamic | Boolean | ||||
| hideScanResults | Boolean |
71.1.2.519. V1ComplianceStandardMetadataScope Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| CLUSTER |
| NAMESPACE |
| DEPLOYMENT |
| NODE |
71.1.2.520. V1ConfigureTelemetryRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabled | Boolean |
71.1.2.521. V1CountAdministrationEventsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | The total number of events after filtering and deduplication. | int32 |
71.1.2.522. V1CountAlertsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.523. V1CountCloudSourcesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.524. V1CountDeploymentsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.525. V1CountDiscoveredClustersResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.526. V1CountImagesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.527. V1CountProcessesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.528. V1CountReportConfigurationsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.529. V1CountSecretsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.530. V1CreateCloudSourceRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cloudSource |
71.1.2.531. V1CreateCloudSourceResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cloudSource |
71.1.2.532. V1CreateCollectionRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| description | String | ||||
| resourceSelectors | List of StorageResourceSelector | ||||
| embeddedCollectionIds |
List of |
71.1.2.533. V1CreateCollectionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collection |
71.1.2.534. V1CreateServiceIdentityRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| type | UNKNOWN_SERVICE, SENSOR_SERVICE, CENTRAL_SERVICE, CENTRAL_DB_SERVICE, REMOTE_SERVICE, COLLECTOR_SERVICE, MONITORING_UI_SERVICE, MONITORING_DB_SERVICE, MONITORING_CLIENT_SERVICE, BENCHMARK_SERVICE, SCANNER_SERVICE, SCANNER_DB_SERVICE, ADMISSION_CONTROL_SERVICE, SCANNER_V4_INDEXER_SERVICE, SCANNER_V4_MATCHER_SERVICE, SCANNER_V4_DB_SERVICE, SCANNER_V4_SERVICE, REGISTRANT_SERVICE, |
71.1.2.535. V1CreateServiceIdentityResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| identity | |||||
| certificatePem | byte[] | byte | |||
| privateKeyPem | byte[] | byte |
71.1.2.536. V1DBExportFormat Copy linkLink copied to clipboard!
DBExportFormat describes a format (= a collection of files) for the database export.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| formatName | String | ||||
| files | List of V1DBExportFormatFile |
71.1.2.537. V1DBExportFormatFile Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| optional | Boolean |
71.1.2.538. V1DBExportManifest Copy linkLink copied to clipboard!
A DB export manifest describes the file contents of a restore request. To prevent data loss, a manifest is always interpreted as binding, i.e., the server must ensure that it will read and make use of every file listed in the manifest, otherwise it must reject the request.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| files | List of V1DBExportManifestFile |
71.1.2.539. V1DBExportManifestFile Copy linkLink copied to clipboard!
A single file in the restore body.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | The name of the file. This may or may not be a (relative) file path and up to the server to interpret. For databases exported as ZIP files, this is the path relative to the root of the archive. | |||
| encoding | UNKNOWN, UNCOMPREESSED, DEFLATED, | ||||
| encodedSize | String | int64 | |||
| decodedSize | String | int64 | |||
| decodedCrc32 | Long | The CRC32 (IEEE) checksum of the decoded(!) data. | int64 |
71.1.2.540. V1DBRestoreProcessMetadata Copy linkLink copied to clipboard!
The metadata of an ongoing or completed restore process. This is the static metadata, which will not change (i.e., it is not a status).
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | An ID identifying the restore process. Auto-assigned. | |||
| header | |||||
| startTime | Date | The time at which the restore process was started. | date-time | ||
| initiatingUserName | String | The user who initiated the database restore process. |
71.1.2.541. V1DBRestoreProcessStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| metadata | |||||
| attemptId | String | ||||
| state | UNKNOWN, NOT_STARTED, IN_PROGRESS, PAUSED, COMPLETED, | ||||
| resumeInfo | |||||
| error | String | ||||
| bytesRead | String | int64 | |||
| filesProcessed | String | int64 |
71.1.2.542. V1DBRestoreProcessStatusState Copy linkLink copied to clipboard!
- COMPLETED: successful if error is empty, unsuccessful otherwise
| Enum Values |
|---|
| UNKNOWN |
| NOT_STARTED |
| IN_PROGRESS |
| PAUSED |
| COMPLETED |
71.1.2.543. V1DBRestoreRequestHeader Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| formatName | String | The name of the database export format. Mandatory. | |||
| manifest | |||||
| localFile |
71.1.2.544. V1DatabaseBackupStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| backupInfo |
71.1.2.545. V1DatabaseStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| databaseAvailable | Boolean | ||||
| databaseType | Hidden, RocksDB, PostgresDB, | ||||
| databaseVersion | String | ||||
| databaseIsExternal | Boolean |
71.1.2.546. V1DayOption Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numDays | Long | int64 | |||
| enabled | Boolean |
71.1.2.547. V1DecommissionedClusterRetentionInfo Copy linkLink copied to clipboard!
next available tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| isExcluded | Boolean | ||||
| daysUntilDeletion | Integer | int32 |
71.1.2.548. V1DelegatedRegistryCluster Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| isValid | Boolean |
71.1.2.549. V1DelegatedRegistryClustersResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusters | List of V1DelegatedRegistryCluster |
71.1.2.550. V1DelegatedRegistryConfig Copy linkLink copied to clipboard!
DelegatedRegistryConfig determines if and where scan requests are delegated to, such as kept in central services or sent to particular secured clusters.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| enabledFor | NONE, ALL, SPECIFIC, | ||||
| defaultClusterId | String | ||||
| registries |
If |
71.1.2.551. V1DeleteAlertsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numDeleted | Long | int64 | |||
| dryRun | Boolean |
71.1.2.552. V1DeleteImagesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numDeleted | Long | int64 | |||
| dryRun | Boolean |
71.1.2.553. V1DeleteProcessBaselinesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numDeleted | Integer | int32 | |||
| dryRun | Boolean |
71.1.2.554. V1DeployDetectionRemark Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| permissionLevel | String | ||||
| appliedNetworkPolicies |
List of |
71.1.2.555. V1DeployDetectionRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployment | |||||
| noExternalMetadata | Boolean | ||||
| enforcementOnly | Boolean | ||||
| clusterId | String |
71.1.2.556. V1DeployDetectionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| runs | List of DeployDetectionResponseRun | ||||
| ignoredObjectRefs |
List of | The reference will be in the format: namespace/name[<group>/<version>, Kind=<kind>]. | |||
| remarks | List of V1DeployDetectionRemark |
71.1.2.557. V1DeployYAMLDetectionRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| yaml | String | ||||
| noExternalMetadata | Boolean | ||||
| enforcementOnly | Boolean | ||||
| force | Boolean | ||||
| policyCategories |
List of | ||||
| cluster | String | Cluster to delegate scan to, may be the cluster’s name or ID. | |||
| namespace | String |
71.1.2.558. V1DeploymentLabelsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| labels | |||||
| values |
List of |
71.1.2.559. V1DiscoveredCluster Copy linkLink copied to clipboard!
DiscoveredCluster represents a cluster discovered from a cloud source.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | UUIDv5 generated deterministically from the tuple (metadata.id, metadata.type, source.id). | |||
| metadata | |||||
| status | STATUS_UNSPECIFIED, STATUS_SECURED, STATUS_UNSECURED, | ||||
| source |
71.1.2.560. V1DiscoveredClusterCloudSource Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String |
71.1.2.561. V1DiscoveredClusterMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | Represents a unique ID under which the cluster is registered with the cloud provider. Matches storage.ClusterMetadata.id for secured clusters. | |||
| name | String | Represents the name under which the cluster is registered with the cloud provider. Matches storage.ClusterMetadata.name for secured clusters. | |||
| type | UNSPECIFIED, AKS, ARO, EKS, GKE, OCP, OSD, ROSA, | ||||
| providerType | PROVIDER_TYPE_UNSPECIFIED, PROVIDER_TYPE_AWS, PROVIDER_TYPE_GCP, PROVIDER_TYPE_AZURE, | ||||
| region | String | The region as reported by the cloud provider. | |||
| firstDiscoveredAt | Date | Timestamp at which the cluster was first discovered by the cloud source. | date-time |
71.1.2.562. V1DiscoveredClusterStatus Copy linkLink copied to clipboard!
- STATUS_UNSPECIFIED: The status of the cluster is unknown. May occur if a secured cluster is missing the metadata for a possible match.
- STATUS_SECURED: The discovered cluster was matched with a secured cluster.
- STATUS_UNSECURED: The discovered cluster was not matched with a secured cluster.
| Enum Values |
|---|
| STATUS_UNSPECIFIED |
| STATUS_SECURED |
| STATUS_UNSECURED |
71.1.2.563. V1DiscoveredClustersFilter Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| names |
List of | Matches discovered clusters of specific names. | |||
| types | List of DiscoveredClusterMetadataType | Matches discovered clusters of specific types. | |||
| statuses | List of V1DiscoveredClusterStatus | Matches discovered clusters of specific statuses. | |||
| sourceIds |
List of | Matches discovered clusters of specific cloud source IDs. |
71.1.2.564. V1DryRunCollectionRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| id | String | ||||
| description | String | ||||
| resourceSelectors | List of StorageResourceSelector | ||||
| embeddedCollectionIds |
List of | ||||
| options |
71.1.2.565. V1DryRunCollectionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployments | List of StorageListDeployment |
71.1.2.566. V1DryRunJobStatusResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| pending | Boolean | ||||
| result |
71.1.2.567. V1DryRunResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| alerts | List of DryRunResponseAlert |
71.1.2.568. V1ExchangeAuthMachineToMachineTokenRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| idToken | String | Identity token that is supposed to be exchanged. |
71.1.2.569. V1ExchangeAuthMachineToMachineTokenResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| accessToken | String | The exchanged access token. |
71.1.2.570. V1ExchangeTokenRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| externalToken | String | The external authentication token. The server will mask the value of this credential in responses and logs. | |||
| type | String | ||||
| state | String |
71.1.2.571. V1ExchangeTokenResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| token | String | ||||
| clientState | String | ||||
| test | Boolean | ||||
| user |
71.1.2.572. V1ExportDeploymentResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployment |
71.1.2.573. V1ExportImageResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| image |
71.1.2.574. V1ExportNodeResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| node |
71.1.2.575. V1ExportPodResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| pod |
71.1.2.576. V1ExportPoliciesRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policyIds |
List of |
71.1.2.577. V1ExternalNetworkFlowMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| flowsCount | Integer | int32 |
71.1.2.578. V1FeatureFlag Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| envVar | String | ||||
| enabled | Boolean |
71.1.2.579. V1GenerateNetworkPoliciesResponse Copy linkLink copied to clipboard!
Next available tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| modification |
71.1.2.580. V1GenerateTokenRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| role | String | ||||
| roles |
List of | ||||
| expiration | Date | date-time |
71.1.2.581. V1GenerateTokenResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| token | String | ||||
| metadata |
71.1.2.582. V1GetAPITokensResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| tokens | List of StorageTokenMetadata |
71.1.2.583. V1GetActiveDBRestoreProcessResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| activeStatus |
71.1.2.584. V1GetAdministrationEventResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| event |
71.1.2.585. V1GetAlertTimeseriesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusters |
71.1.2.586. V1GetAlertsCountsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| groups |
71.1.2.587. V1GetAlertsGroupResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| alertsByPolicies |
71.1.2.588. V1GetAlertsGroupResponsePolicyGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policy | |||||
| numAlerts | String | int64 |
71.1.2.589. V1GetAllowedPeersFromCurrentPolicyForDeploymentResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| allowedPeers | List of V1NetworkBaselineStatusPeer |
71.1.2.590. V1GetAuthMachineToMachineConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.591. V1GetAuthProvidersResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| authProviders | List of StorageAuthProvider |
71.1.2.592. V1GetBaselineGeneratedPolicyForDeploymentResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| modification |
71.1.2.593. V1GetCAConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| helmValuesBundle | byte[] | byte |
71.1.2.594. V1GetCertExpiryComponent Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNKNOWN |
| CENTRAL |
| SCANNER |
| SCANNER_V4 |
| CENTRAL_DB |
71.1.2.595. V1GetCertExpiryResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| expiry | Date | date-time |
71.1.2.596. V1GetCloudSourceResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cloudSource |
71.1.2.597. V1GetClustersForPermissionsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusters | List of V1ScopeObject |
71.1.2.598. V1GetCollectionCountResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 |
71.1.2.599. V1GetCollectionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collection | |||||
| deployments | List of StorageListDeployment |
71.1.2.600. V1GetComplianceRunResultsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| results | |||||
| failedRuns | List of StorageComplianceRunMetadata |
71.1.2.601. V1GetComplianceRunStatusesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| invalidRunIds |
List of | ||||
| runs | List of V1ComplianceRun |
71.1.2.602. V1GetComplianceStandardResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| standard |
71.1.2.603. V1GetComplianceStandardsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| standards | List of V1ComplianceStandardMetadata |
71.1.2.604. V1GetDBExportCapabilitiesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| formats | List of V1DBExportFormat | ||||
| supportedEncodings | List of DBExportManifestEncodingType |
71.1.2.605. V1GetDeclarativeConfigHealthsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| healths | List of StorageDeclarativeConfigHealth |
71.1.2.606. V1GetDefaultRedHatLayeredProductsRegexResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| regex | String |
71.1.2.607. V1GetDeploymentWithRiskResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployment | |||||
| risk |
71.1.2.608. V1GetDiffFlowsGroupedFlow Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| properties |
71.1.2.609. V1GetDiffFlowsReconciledFlow Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| added | |||||
| removed | |||||
| unchanged |
71.1.2.610. V1GetDiffFlowsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| added | List of V1GetDiffFlowsGroupedFlow | ||||
| removed | List of V1GetDiffFlowsGroupedFlow | ||||
| reconciled | List of V1GetDiffFlowsReconciledFlow |
71.1.2.611. V1GetDiscoveredClusterResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster |
71.1.2.612. V1GetExistingProbesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| existingFiles | List of V1ProbeUploadManifestFile |
71.1.2.613. V1GetExternalBackupsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| externalBackups | List of StorageExternalBackup |
71.1.2.614. V1GetExternalNetworkEntitiesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entities | List of StorageNetworkEntity |
71.1.2.615. V1GetExternalNetworkFlowsMetadataResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entities | List of V1ExternalNetworkFlowMetadata | ||||
| totalEntities | Integer | int32 |
71.1.2.616. V1GetExternalNetworkFlowsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| totalFlows | Integer | int32 | |||
| flows | List of StorageNetworkFlow |
71.1.2.617. V1GetFeatureFlagsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| featureFlags | List of V1FeatureFlag |
71.1.2.618. V1GetGroupedProcessesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| groups | List of V1ProcessNameGroup |
71.1.2.619. V1GetGroupedProcessesWithContainerResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| groups |
71.1.2.620. V1GetGroupsResponse Copy linkLink copied to clipboard!
API for updating Groups and getting users. Next Available Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| groups | List of StorageGroup |
71.1.2.621. V1GetImageIntegrationsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| integrations | List of StorageImageIntegration |
71.1.2.622. V1GetIntegrationHealthResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| integrationHealth | List of StorageIntegrationHealth |
71.1.2.623. V1GetLoginAuthProvidersResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| authProviders |
71.1.2.624. V1GetMitreVectorResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| mitreAttackVector |
71.1.2.625. V1GetNamespacesForClusterAndPermissionsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| namespaces | List of V1ScopeObject |
71.1.2.626. V1GetNamespacesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| namespaces | List of V1Namespace |
71.1.2.627. V1GetNotifiersResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| notifiers | List of StorageNotifier |
71.1.2.628. V1GetPermissionsResponse Copy linkLink copied to clipboard!
GetPermissionsResponse is wire-compatible with the old format of the Role message and represents a collection of aggregated permissions.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| resourceToAccess | Map of StorageAccess |
71.1.2.629. V1GetPolicyCategoriesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| categories | List of V1PolicyCategory |
71.1.2.630. V1GetPolicyMitreVectorsRequestOptions Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| excludePolicy | Boolean | If set to true, policy is excluded from the response. |
71.1.2.631. V1GetPolicyMitreVectorsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policy | |||||
| vectors | List of StorageMitreAttackVector |
71.1.2.632. V1GetProcessesListeningOnPortsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| listeningEndpoints | List of StorageProcessListeningOnPort | ||||
| totalListeningEndpoints | Integer | int32 |
71.1.2.633. V1GetProcessesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| processes | List of StorageProcessIndicator |
71.1.2.634. V1GetRecentComplianceRunsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| complianceRuns | List of V1ComplianceRun |
71.1.2.635. V1GetReportConfigurationResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| reportConfig |
71.1.2.636. V1GetReportConfigurationsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| reportConfigs | List of StorageReportConfiguration |
71.1.2.637. V1GetResourcesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| resources |
List of |
71.1.2.638. V1GetRoleBindingResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| binding |
71.1.2.639. V1GetRoleResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| role |
71.1.2.640. V1GetRolesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| roles | List of StorageRole |
71.1.2.641. V1GetSensorUpgradeConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.642. V1GetServiceAccountResponse Copy linkLink copied to clipboard!
One service account Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| saAndRole |
71.1.2.643. V1GetSubjectResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| subject | |||||
| clusterRoles | List of StorageK8sRole | ||||
| scopedRoles | List of V1ScopedRoles |
71.1.2.644. V1GetUndoModificationForDeploymentResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| undoRecord |
71.1.2.645. V1GetUndoModificationResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| undoRecord |
71.1.2.646. V1GetUpgradeStatusResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| upgradeStatus |
71.1.2.647. V1GetUsersAttributesResponse Copy linkLink copied to clipboard!
Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| usersAttributes | List of V1UserAttributeTuple |
71.1.2.648. V1GetUsersResponse Copy linkLink copied to clipboard!
Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| users | List of StorageUser |
71.1.2.649. V1GetVulnerabilityExceptionConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.650. V1GetWatchedImagesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| watchedImages | List of StorageWatchedImage |
71.1.2.651. V1GroupBatchUpdateRequest Copy linkLink copied to clipboard!
GroupBatchUpdateRequest is an in transaction batch update to the groups present. Next Available Tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| previousGroups | List of StorageGroup | Previous groups are the groups expected to be present in the store. Performs a diff on the GroupProperties present in previous_groups and required_groups: 1) if in previous_groups but not required_groups, it gets deleted. 2) if in previous_groups and required_groups, it gets updated. 3) if not in previous_groups but in required_groups, it gets added. | |||
| requiredGroups | List of StorageGroup | Required groups are the groups we want to mutate the previous groups into. | |||
| force | Boolean |
71.1.2.652. V1ImportPoliciesMetadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| overwrite | Boolean |
71.1.2.653. V1ImportPoliciesRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| metadata | |||||
| policies | List of StoragePolicy |
71.1.2.654. V1ImportPoliciesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| responses | List of V1ImportPolicyResponse | ||||
| allSucceeded | Boolean |
71.1.2.655. V1ImportPolicyError Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| message | String | ||||
| type | String | ||||
| duplicateName | String | ||||
| validationError | String |
71.1.2.656. V1ImportPolicyResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| succeeded | Boolean | ||||
| policy | |||||
| errors | List of V1ImportPolicyError |
71.1.2.657. V1InitBundleGenRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String |
71.1.2.658. V1InitBundleGenResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| meta | |||||
| helmValuesBundle | byte[] | byte | |||
| kubectlBundle | byte[] | byte |
71.1.2.659. V1InitBundleMeta Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| impactedClusters | List of InitBundleMetaImpactedCluster | ||||
| createdAt | Date | date-time | |||
| createdBy | |||||
| expiresAt | Date | date-time |
71.1.2.660. V1InitBundleMetasResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| items | List of V1InitBundleMeta |
71.1.2.661. V1InitBundleRevokeRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| ids |
List of | ||||
| confirmImpactedClustersIds |
List of |
71.1.2.662. V1InitBundleRevokeResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| initBundleRevocationErrors | |||||
| initBundleRevokedIds |
List of |
71.1.2.663. V1InterruptDBRestoreProcessResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| resumeInfo |
71.1.2.664. V1JobId Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| jobId | String |
71.1.2.665. V1KernelSupportAvailableResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| kernelSupportAvailable | Boolean |
71.1.2.666. V1ListAdministrationEventsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| events | List of V1AdministrationEvent |
71.1.2.667. V1ListAlertsRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| query | String | ||||
| pagination |
71.1.2.668. V1ListAlertsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| alerts | List of StorageListAlert |
71.1.2.669. V1ListAllowedTokenRolesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| roleNames |
List of |
71.1.2.670. V1ListAuthMachineToMachineConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| configs | List of V1AuthMachineToMachineConfig |
71.1.2.671. V1ListCloudSourcesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cloudSources | List of V1CloudSource |
71.1.2.672. V1ListCollectionSelectorsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| selectors |
List of |
71.1.2.673. V1ListCollectionsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collections | List of StorageResourceCollection |
71.1.2.674. V1ListDeploymentsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployments | List of StorageListDeployment |
71.1.2.675. V1ListDeploymentsWithProcessInfoResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployments | List of ListDeploymentsWithProcessInfoResponseDeploymentWithProcessInfo |
71.1.2.676. V1ListDiscoveredClustersResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusters | List of V1DiscoveredCluster |
71.1.2.677. V1ListImagesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| images | List of StorageListImage |
71.1.2.678. V1ListMitreAttackVectorsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| mitreAttackVectors | List of StorageMitreAttackVector |
71.1.2.679. V1ListNodesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| nodes | List of StorageNode |
71.1.2.680. V1ListPermissionSetsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| permissionSets | List of StoragePermissionSet |
71.1.2.681. V1ListPoliciesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policies | List of StorageListPolicy |
71.1.2.682. V1ListRoleBindingsResponse Copy linkLink copied to clipboard!
A list of k8s role bindings (free of scoped information) Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| bindings | List of StorageK8sRoleBinding |
71.1.2.683. V1ListRolesResponse Copy linkLink copied to clipboard!
A list of k8s roles (free of scoped information) Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| roles | List of StorageK8sRole |
71.1.2.684. V1ListSecretsResponse Copy linkLink copied to clipboard!
A list of secrets with their relationships. Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| secrets | List of StorageListSecret |
71.1.2.685. V1ListServiceAccountResponse Copy linkLink copied to clipboard!
A list of service accounts (free of scoped information) Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| saAndRoles | List of V1ServiceAccountAndRoles |
71.1.2.686. V1ListSignatureIntegrationsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| integrations | List of StorageSignatureIntegration |
71.1.2.687. V1ListSimpleAccessScopesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| accessScopes | List of StorageSimpleAccessScope |
71.1.2.688. V1ListSubjectsResponse Copy linkLink copied to clipboard!
A list of k8s subjects (users and groups only, for service accounts, try the service account service) Next Tag: 2
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| subjectAndRoles | List of V1SubjectAndRoles |
71.1.2.689. V1LockProcessBaselinesRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| keys | List of StorageProcessBaselineKey | ||||
| locked | Boolean |
71.1.2.690. V1LogLevelRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| level | String | ||||
| modules |
List of |
71.1.2.691. V1LogLevelResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| level | String | ||||
| moduleLevels | List of V1ModuleLevel |
71.1.2.692. V1MaxSecuredUnitsUsageResponse Copy linkLink copied to clipboard!
MaxSecuredUnitsUsageResponse holds the maximum values of the secured nodes and CPU Units (as reported by Kubernetes) with the time at which these values were aggregated, with the aggregation period accuracy (1h).
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| maxNodesAt | Date | date-time | |||
| maxNodes | String | int64 | |||
| maxCpuUnitsAt | Date | date-time | |||
| maxCpuUnits | String | int64 |
71.1.2.693. V1Metadata Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| version | String | ||||
| buildFlavor | String | ||||
| releaseBuild | Boolean | ||||
| licenseStatus | NONE, INVALID, EXPIRED, RESTARTING, VALID, |
71.1.2.694. V1ModuleLevel Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| module | String | ||||
| level | String |
71.1.2.695. V1Namespace Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| metadata | |||||
| numDeployments | Integer | int32 | |||
| numSecrets | Integer | int32 | |||
| numNetworkPolicies | Integer | int32 |
71.1.2.696. V1NetworkBaselineExternalStatusResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| anomalous | List of V1NetworkBaselinePeerStatus | ||||
| totalAnomalous | Integer | int32 | |||
| baseline | List of V1NetworkBaselinePeerStatus | ||||
| totalBaseline | Integer | int32 |
71.1.2.697. V1NetworkBaselinePeerEntity Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| type | UNKNOWN_TYPE, DEPLOYMENT, INTERNET, LISTEN_ENDPOINT, EXTERNAL_SOURCE, INTERNAL_ENTITIES, | ||||
| name | String | ||||
| discovered | Boolean |
71.1.2.698. V1NetworkBaselinePeerStatus Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| peer | |||||
| status | BASELINE, ANOMALOUS, |
71.1.2.699. V1NetworkBaselinePeerStatusStatus Copy linkLink copied to clipboard!
Status of this peer connection. As of now we only have two statuses: - BASELINE: the connection is in the current deployment baseline - ANOMALOUS: the connection is not recognized by the current deployment baseline
| Enum Values |
|---|
| BASELINE |
| ANOMALOUS |
71.1.2.700. V1NetworkBaselineStatusPeer Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| port | Long | The port and protocol of the destination of the given connection. | int64 | ||
| protocol | L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY, | ||||
| ingress | Boolean | A boolean representing whether the query is for an ingress or egress connection. This is defined with respect to the current deployment. Thus: - If the connection in question is in the outEdges of the current deployment, this should be false. - If it is in the outEdges of the peer deployment, this should be true. |
71.1.2.701. V1NetworkBaselineStatusResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| statuses | List of V1NetworkBaselinePeerStatus |
71.1.2.702. V1NetworkEdgeProperties Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| port | Long | int64 | |||
| protocol | L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY, | ||||
| lastActiveTimestamp | Date | date-time |
71.1.2.703. V1NetworkEdgePropertiesBundle Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| properties | List of V1NetworkEdgeProperties |
71.1.2.704. V1NetworkGraph Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| epoch | Long | int64 | |||
| nodes | List of V1NetworkNode |
71.1.2.705. V1NetworkGraphDiff Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| DEPRECATEDNodeDiffs | Map of V1NetworkNodeDiff | ||||
| nodeDiffs | Map of V1NetworkNodeDiff |
71.1.2.706. V1NetworkGraphEpoch Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| epoch | Long | int64 |
71.1.2.707. V1NetworkGraphScope Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| query | String |
71.1.2.708. V1NetworkNode Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| entity | |||||
| internetAccess | Boolean | ||||
| policyIds |
List of | ||||
| nonIsolatedIngress | Boolean | ||||
| nonIsolatedEgress | Boolean | ||||
| queryMatch | Boolean | ||||
| outEdges |
71.1.2.709. V1NetworkNodeDiff Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policyIds |
List of | ||||
| DEPRECATEDOutEdges | |||||
| outEdges | |||||
| nonIsolatedIngress | Boolean | ||||
| nonIsolatedEgress | Boolean |
71.1.2.710. V1NetworkPoliciesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| networkPolicies | List of StorageNetworkPolicy |
71.1.2.711. V1NetworkPolicyInSimulation Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policy | |||||
| status | INVALID, UNCHANGED, MODIFIED, ADDED, DELETED, | ||||
| oldPolicy |
71.1.2.712. V1NetworkPolicyInSimulationStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| INVALID |
| UNCHANGED |
| MODIFIED |
| ADDED |
| DELETED |
71.1.2.713. V1OCMConfig Copy linkLink copied to clipboard!
OCMConfig provides information required to fetch discovered clusters from the OpenShift cluster manager.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String |
71.1.2.714. V1Pagination Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| limit | Integer | int32 | |||
| offset | Integer | int32 | |||
| sortOption | |||||
| sortOptions | List of V1SortOption | This field is under development. It is not supported on any REST APIs. |
71.1.2.715. V1PaladinCloudConfig Copy linkLink copied to clipboard!
PaladinCloudConfig provides information required to fetch discovered clusters from Paladin Cloud.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| endpoint | String |
71.1.2.716. V1PodsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| pods | List of StoragePod |
71.1.2.717. V1PolicyCategoriesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| categories |
List of |
71.1.2.718. V1PolicyCategory Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| isDefault | Boolean |
71.1.2.719. V1PolicyFromSearchRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| searchParams | String |
71.1.2.720. V1PolicyFromSearchResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| policy | |||||
| alteredSearchTerms |
List of | ||||
| hasNestedFields | Boolean |
71.1.2.721. V1PongMessage Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| status | String |
71.1.2.722. V1PostReportConfigurationRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| reportConfig |
71.1.2.723. V1PostReportConfigurationResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| reportConfig |
71.1.2.724. V1Preferences Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| maxGrpcReceiveSizeBytes | String | uint64 |
71.1.2.725. V1ProbeUploadManifestFile Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| size | String | int64 | |||
| crc32 | Long | int64 |
71.1.2.726. V1ProcessBaselineUpdateError Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| error | String | ||||
| key |
71.1.2.727. V1ProcessGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| args | String | ||||
| signals | List of StorageProcessIndicator |
71.1.2.728. V1ProcessNameAndContainerNameGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| containerName | String | ||||
| timesExecuted | Long | int64 | |||
| groups | List of V1ProcessGroup | ||||
| suspicious | Boolean |
71.1.2.729. V1ProcessNameGroup Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| timesExecuted | Long | int64 | |||
| groups | List of V1ProcessGroup |
71.1.2.730. V1PutConfigRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.731. V1PutNetworkGraphConfigRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.732. V1PutPlatformComponentConfigRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| rules | List of PlatformComponentConfigRule |
71.1.2.733. V1RawQuery Copy linkLink copied to clipboard!
RawQuery represents the search query string. The format of the query string is "<field name>:<value,value,…><field name>:<value, value,...>…" For example: To search for deployments named "central" and "sensor" in the namespace "stackrox", the query string would be "Deployment:central,sensor+Namespace:stackrox" RawQuery is used in ListAPIs to search for a particular object.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| query | String | ||||
| pagination |
71.1.2.734. V1RenamePolicyCategoryRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| newCategoryName | String |
71.1.2.735. V1ResolveAlertsRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| query | String |
71.1.2.736. V1SADeploymentRelationship Copy linkLink copied to clipboard!
Service accounts can be used by a deployment. Next Tag: 3
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | Name of the deployment. |
71.1.2.737. V1ScanImageRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| imageName | String | ||||
| force | Boolean | ||||
| includeSnoozed | Boolean | ||||
| cluster | String | Cluster to delegate scan to, may be the cluster’s name or ID. | |||
| namespace | String | Namespace on the secured cluster from which to read context information when delegating image scans, specifically pull secrets to access the image registry. |
71.1.2.738. V1ScopeObject Copy linkLink copied to clipboard!
ScopeObject represents an ID, name pair, which can apply to any entity that takes part in an access scope (so far Cluster and Namespace).
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String |
71.1.2.739. V1ScopedRoles Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| namespace | String | ||||
| roles | List of StorageK8sRole |
71.1.2.740. V1SearchCategory Copy linkLink copied to clipboard!
Next available tag: 85
| Enum Values |
|---|
| SEARCH_UNSET |
| ALERTS |
| IMAGES |
| IMAGE_COMPONENTS |
| IMAGE_VULN_EDGE |
| IMAGE_COMPONENT_EDGE |
| POLICIES |
| DEPLOYMENTS |
| PODS |
| SECRETS |
| PROCESS_INDICATORS |
| COMPLIANCE |
| CLUSTERS |
| NAMESPACES |
| NODES |
| NODE_COMPONENTS |
| NODE_VULN_EDGE |
| NODE_COMPONENT_EDGE |
| NODE_COMPONENT_CVE_EDGE |
| COMPLIANCE_STANDARD |
| COMPLIANCE_CONTROL_GROUP |
| COMPLIANCE_CONTROL |
| SERVICE_ACCOUNTS |
| ROLES |
| ROLEBINDINGS |
| REPORT_CONFIGURATIONS |
| PROCESS_BASELINES |
| SUBJECTS |
| RISKS |
| VULNERABILITIES |
| CLUSTER_VULNERABILITIES |
| IMAGE_VULNERABILITIES |
| NODE_VULNERABILITIES |
| COMPONENT_VULN_EDGE |
| CLUSTER_VULN_EDGE |
| NETWORK_ENTITY |
| VULN_REQUEST |
| NETWORK_BASELINE |
| NETWORK_POLICIES |
| PROCESS_BASELINE_RESULTS |
| COMPLIANCE_METADATA |
| COMPLIANCE_RESULTS |
| COMPLIANCE_DOMAIN |
| CLUSTER_HEALTH |
| POLICY_CATEGORIES |
| IMAGE_INTEGRATIONS |
| COLLECTIONS |
| POLICY_CATEGORY_EDGE |
| PROCESS_LISTENING_ON_PORT |
| API_TOKEN |
| REPORT_METADATA |
| REPORT_SNAPSHOT |
| COMPLIANCE_INTEGRATIONS |
| COMPLIANCE_SCAN_CONFIG |
| COMPLIANCE_SCAN |
| COMPLIANCE_CHECK_RESULTS |
| BLOB |
| ADMINISTRATION_EVENTS |
| COMPLIANCE_SCAN_CONFIG_STATUS |
| ADMINISTRATION_USAGE |
| COMPLIANCE_PROFILES |
| COMPLIANCE_RULES |
| COMPLIANCE_SCAN_SETTING_BINDINGS |
| COMPLIANCE_SUITES |
| CLOUD_SOURCES |
| DISCOVERED_CLUSTERS |
| COMPLIANCE_REMEDIATIONS |
| COMPLIANCE_BENCHMARKS |
| AUTH_PROVIDERS |
| COMPLIANCE_REPORT_SNAPSHOT |
| IMAGE_COMPONENTS_V2 |
| IMAGE_VULNERABILITIES_V2 |
| IMAGES_V2 |
| VIRTUAL_MACHINES |
| BASE_IMAGES |
| BASE_IMAGE_LAYERS |
| VIRTUAL_MACHINES_V2 |
| VIRTUAL_MACHINE_SCANS_V2 |
| VIRTUAL_MACHINE_COMPONENTS_V2 |
| VIRTUAL_MACHINE_VULNERABILITIES_V2 |
| IMAGE_CVE_INFOS |
71.1.2.741. V1SearchOptionsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| options |
List of |
71.1.2.742. V1SearchResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| results | List of V1SearchResult | ||||
| counts | List of SearchResponseCount |
71.1.2.743. V1SearchResult Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String | ||||
| category | SEARCH_UNSET, ALERTS, IMAGES, IMAGE_COMPONENTS, IMAGE_VULN_EDGE, IMAGE_COMPONENT_EDGE, POLICIES, DEPLOYMENTS, PODS, SECRETS, PROCESS_INDICATORS, COMPLIANCE, CLUSTERS, NAMESPACES, NODES, NODE_COMPONENTS, NODE_VULN_EDGE, NODE_COMPONENT_EDGE, NODE_COMPONENT_CVE_EDGE, COMPLIANCE_STANDARD, COMPLIANCE_CONTROL_GROUP, COMPLIANCE_CONTROL, SERVICE_ACCOUNTS, ROLES, ROLEBINDINGS, REPORT_CONFIGURATIONS, PROCESS_BASELINES, SUBJECTS, RISKS, VULNERABILITIES, CLUSTER_VULNERABILITIES, IMAGE_VULNERABILITIES, NODE_VULNERABILITIES, COMPONENT_VULN_EDGE, CLUSTER_VULN_EDGE, NETWORK_ENTITY, VULN_REQUEST, NETWORK_BASELINE, NETWORK_POLICIES, PROCESS_BASELINE_RESULTS, COMPLIANCE_METADATA, COMPLIANCE_RESULTS, COMPLIANCE_DOMAIN, CLUSTER_HEALTH, POLICY_CATEGORIES, IMAGE_INTEGRATIONS, COLLECTIONS, POLICY_CATEGORY_EDGE, PROCESS_LISTENING_ON_PORT, API_TOKEN, REPORT_METADATA, REPORT_SNAPSHOT, COMPLIANCE_INTEGRATIONS, COMPLIANCE_SCAN_CONFIG, COMPLIANCE_SCAN, COMPLIANCE_CHECK_RESULTS, BLOB, ADMINISTRATION_EVENTS, COMPLIANCE_SCAN_CONFIG_STATUS, ADMINISTRATION_USAGE, COMPLIANCE_PROFILES, COMPLIANCE_RULES, COMPLIANCE_SCAN_SETTING_BINDINGS, COMPLIANCE_SUITES, CLOUD_SOURCES, DISCOVERED_CLUSTERS, COMPLIANCE_REMEDIATIONS, COMPLIANCE_BENCHMARKS, AUTH_PROVIDERS, COMPLIANCE_REPORT_SNAPSHOT, IMAGE_COMPONENTS_V2, IMAGE_VULNERABILITIES_V2, IMAGES_V2, VIRTUAL_MACHINES, BASE_IMAGES, BASE_IMAGE_LAYERS, VIRTUAL_MACHINES_V2, VIRTUAL_MACHINE_SCANS_V2, VIRTUAL_MACHINE_COMPONENTS_V2, VIRTUAL_MACHINE_VULNERABILITIES_V2, IMAGE_CVE_INFOS, | ||||
| fieldToMatches | Map of SearchResultMatches | ||||
| score | Double | double | |||
| location | String | Location is intended to be a unique, yet human readable, identifier for the result. For example, for a deployment, the location will be "$cluster_name/$namespace/$deployment_name. It is displayed in the UI in the global search results, underneath the name for each result. |
71.1.2.744. V1SecuredUnitsUsageResponse Copy linkLink copied to clipboard!
SecuredUnitsUsageResponse holds the values of the currently observable administration usage metrics.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| numNodes | String | int64 | |||
| numCpuUnits | String | int64 |
71.1.2.745. V1ServiceAccountAndRoles Copy linkLink copied to clipboard!
A service account and the roles that reference it Next Tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| serviceAccount | |||||
| clusterRoles | List of StorageK8sRole | ||||
| scopedRoles | List of V1ScopedRoles | ||||
| deploymentRelationships | List of V1SADeploymentRelationship |
71.1.2.746. V1ServiceIdentityResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| identities | List of StorageServiceIdentity |
71.1.2.747. V1SimulateNetworkGraphResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| simulatedGraph | |||||
| policies | List of V1NetworkPolicyInSimulation | ||||
| added | |||||
| removed |
71.1.2.748. V1SortOption Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| field | String | ||||
| reversed | Boolean | ||||
| aggregateBy |
71.1.2.749. V1SubjectAndRoles Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| subject | |||||
| roles | List of StorageK8sRole |
71.1.2.750. V1SuppressCVERequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cves |
List of |
These are (NVD) vulnerability identifiers, | |||
| duration | String | In JSON format, the Duration type is encoded as a string rather than an object, where the string ends in the suffix "s" (indicating seconds) and is preceded by the number of seconds, with nanoseconds expressed as fractional seconds. For example, 3 seconds with 0 nanoseconds should be encoded in JSON format as "3s", while 3 seconds and 1 nanosecond should be expressed in JSON format as "3.000000001s", and 3 seconds and 1 microsecond should be expressed in JSON format as "3.000001s". |
71.1.2.751. V1TLSChallengeResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| trustInfoSerialized | byte[] | byte | |||
| signature | byte[] | byte | |||
| signatureSecondaryCa | byte[] | optional signature by key from TrustInfo.secondary_cert_chain[0]. | byte |
71.1.2.752. V1TestCloudSourceRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cloudSource | |||||
| updateCredentials | Boolean | If true, cloud_source must include valid credentials. If false, the resource must already exist and credentials in cloud_source are ignored. |
71.1.2.753. V1Traits Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| mutabilityMode | ALLOW_MUTATE, ALLOW_MUTATE_FORCED, | ||||
| visibility | VISIBLE, HIDDEN, | ||||
| origin | IMPERATIVE, DEFAULT, DECLARATIVE, DECLARATIVE_ORPHANED, |
71.1.2.754. V1TraitsMutabilityMode Copy linkLink copied to clipboard!
EXPERIMENTAL. NOTE: Please refer from using MutabilityMode for the time being. It will be replaced in the future (ROX-14276). MutabilityMode specifies whether and how an object can be modified. Default is ALLOW_MUTATE and means there are no modification restrictions; this is equivalent to the absence of MutabilityMode specification. ALLOW_MUTATE_FORCED forbids all modifying operations except object removal with force bit on.
Be careful when changing the state of this field. For example, modifying an object from ALLOW_MUTATE to ALLOW_MUTATE_FORCED is allowed but will prohibit any further changes to it, including modifying it back to ALLOW_MUTATE.
| Enum Values |
|---|
| ALLOW_MUTATE |
| ALLOW_MUTATE_FORCED |
71.1.2.755. V1TraitsOrigin Copy linkLink copied to clipboard!
Origin specifies the origin of an object. Objects can have four different origins: - IMPERATIVE: the object was created via the API. This is assumed by default. - DEFAULT: the object is a default object, such as default roles, access scopes etc. - DECLARATIVE: the object is created via declarative configuration. - DECLARATIVE_ORPHANED: the object is created via declarative configuration and then unsuccessfully deleted(for example, because it is referenced by another object) Based on the origin, different rules apply to the objects. Objects with the DECLARATIVE origin are not allowed to be modified via API, only via declarative configuration. Additionally, they may not reference objects with the IMPERATIVE origin. Objects with the DEFAULT origin are not allowed to be modified via either API or declarative configuration. They may be referenced by all other objects. Objects with the IMPERATIVE origin are allowed to be modified via API, not via declarative configuration. They may reference all other objects. Objects with the DECLARATIVE_ORPHANED origin are not allowed to be modified via either API or declarative configuration. DECLARATIVE_ORPHANED resource can become DECLARATIVE again if it is redefined in declarative configuration. Objects with this origin will be cleaned up from the system immediately after they are not referenced by other resources anymore. They may be referenced by all other objects.
| Enum Values |
|---|
| IMPERATIVE |
| DEFAULT |
| DECLARATIVE |
| DECLARATIVE_ORPHANED |
71.1.2.756. V1TraitsVisibility Copy linkLink copied to clipboard!
EXPERIMENTAL. visibility allows to specify whether the object should be visible for certain APIs.
| Enum Values |
|---|
| VISIBLE |
| HIDDEN |
71.1.2.757. V1TriggerComplianceRunsRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| selection |
71.1.2.758. V1TriggerComplianceRunsResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| startedRuns | List of V1ComplianceRun |
71.1.2.759. V1Type Copy linkLink copied to clipboard!
| Enum Values |
|---|
| CREATED |
| REMOVED |
71.1.2.760. V1UnsuppressCVERequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cves |
List of |
These are (NVD) vulnerability identifiers, |
71.1.2.761. V1UpdateCollectionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collection |
71.1.2.762. V1UpdateExternalBackupRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| externalBackup | |||||
| updatePassword | Boolean | When false, use the stored credentials of an existing external backup configuration given its ID. |
71.1.2.763. V1UpdateImageIntegrationRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config | |||||
| updatePassword | Boolean | When false, use the stored credentials of an existing image integration given its ID. |
71.1.2.764. V1UpdateNotifierRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| notifier | |||||
| updatePassword | Boolean | When false, use the stored credentials of an existing notifier configuration given its ID. |
71.1.2.765. V1UpdateProcessBaselinesRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| keys | List of StorageProcessBaselineKey | ||||
| addElements | List of StorageBaselineItem | ||||
| removeElements | List of StorageBaselineItem |
71.1.2.766. V1UpdateProcessBaselinesResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| baselines | List of StorageProcessBaseline | ||||
| errors | List of V1ProcessBaselineUpdateError |
71.1.2.767. V1UpdateSensorUpgradeConfigRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.768. V1UpdateVulnerabilityExceptionConfigRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.769. V1UpdateVulnerabilityExceptionConfigResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| config |
71.1.2.770. V1UserAttribute Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| key | String | ||||
| values |
List of |
71.1.2.771. V1UserAttributeTuple Copy linkLink copied to clipboard!
UserAttributeTuple descript the auth:key:value tuple that decides group membership. Next Tag: 4
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| authProviderId | String | ||||
| key | String | ||||
| value | String |
71.1.2.772. V1VulnDefinitionsInfo Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| lastUpdatedTimestamp | Date | date-time |
71.1.2.773. V1VulnDefinitionsInfoRequestComponent Copy linkLink copied to clipboard!
| Enum Values |
|---|
| SCANNER |
| SCANNER_V4 |
71.1.2.774. V1VulnMgmtExportWorkloadsResponse Copy linkLink copied to clipboard!
The workloads response contains the full image details including the vulnerability data.
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| deployment | |||||
| images | List of StorageImage | ||||
| livePods | Integer | int32 |
71.1.2.775. V1VulnerabilityExceptionConfig Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| expiryOptions |
71.1.2.776. V1VulnerabilityExceptionConfigExpiryOptions Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| dayOptions | List of V1DayOption | This allows users to set expiry interval based on number of days. | |||
| fixableCveOptions | |||||
| customDate | Boolean | This option, if true, allows UI to show a custom date picker for setting expiry date. | |||
| indefinite | Boolean |
71.1.2.777. V1VulnerabilityExceptionConfigFixableCVEOptions Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| allFixable | Boolean | This options allows users to expire the vulnerability deferral request if and only if all vulnerabilities in the requests become fixable. | |||
| anyFixable | Boolean | This options allows users to expire the vulnerability deferral request if any vulnerability in the requests become fixable. |
71.1.2.778. V1WatchImageRequest Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | The name of the image. This must be fully qualified, including a tag, but must NOT include a SHA. |
71.1.2.779. V1WatchImageResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| normalizedName | String | ||||
| errorType | NO_ERROR, INVALID_IMAGE_NAME, NO_VALID_INTEGRATION, SCAN_FAILED, | ||||
| errorMessage | String | Only set if error_type is NOT equal to "NO_ERROR". |
71.1.2.780. V2Advisory Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| link | String |
71.1.2.781. V2AgentStatus Copy linkLink copied to clipboard!
Agent status enriched from a separate data source (not on VirtualMachineV2 storage).
| Enum Values |
|---|
| AGENT_STATUS_UNKNOWN |
| AGENT_STATUS_ACTIVE |
71.1.2.782. V2AggregateBy Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| aggrFunc | UNSET, COUNT, MIN, MAX, | ||||
| distinct | Boolean |
71.1.2.783. V2Aggregation Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET |
| COUNT |
| MIN |
| MAX |
71.1.2.784. V2ApproveVulnerabilityExceptionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| exception |
71.1.2.785. V2BaseComplianceScanConfigurationSettings Copy linkLink copied to clipboard!
Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| oneTimeScan | Boolean | ||||
| profiles |
List of | ||||
| scanSchedule | |||||
| description | String | ||||
| notifiers | List of V2NotifierConfiguration |
71.1.2.786. V2BaseImageReference Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| baseImageRepoPath | String | ||||
| baseImageTagPattern | String | ||||
| user |
71.1.2.787. V2COStatus Copy linkLink copied to clipboard!
Represents the status of compliance operator
| Enum Values |
|---|
| HEALTHY |
| UNHEALTHY |
71.1.2.788. V2CVSSScore Copy linkLink copied to clipboard!
71.1.2.789. V2CVSSV3 Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| vector | String | ||||
| exploitabilityScore | Float | float | |||
| impactScore | Float | float | |||
| attackVector | ATTACK_LOCAL, ATTACK_ADJACENT, ATTACK_NETWORK, ATTACK_PHYSICAL, | ||||
| attackComplexity | COMPLEXITY_LOW, COMPLEXITY_HIGH, | ||||
| privilegesRequired | PRIVILEGE_NONE, PRIVILEGE_LOW, PRIVILEGE_HIGH, | ||||
| userInteraction | UI_NONE, UI_REQUIRED, | ||||
| scope | UNCHANGED, CHANGED, | ||||
| confidentiality | IMPACT_NONE, IMPACT_LOW, IMPACT_HIGH, | ||||
| integrity | IMPACT_NONE, IMPACT_LOW, IMPACT_HIGH, | ||||
| availability | IMPACT_NONE, IMPACT_LOW, IMPACT_HIGH, | ||||
| score | Float | float | |||
| severity | UNKNOWN, NONE, LOW, MEDIUM, HIGH, CRITICAL, |
71.1.2.790. V2CVSSV3Scope Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNCHANGED |
| CHANGED |
71.1.2.791. V2CancelVulnerabilityExceptionResponse Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| exception |
71.1.2.792. V2ClusterCheckStatus Copy linkLink copied to clipboard!
ClusterCheckStatus groups the result of the check by cluster
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster | |||||
| status | UNSET_CHECK_STATUS, PASS, FAIL, ERROR, INFO, MANUAL, NOT_APPLICABLE, INCONSISTENT, | ||||
| createdTime | Date | date-time | |||
| checkUid | String | ||||
| lastScanTime | Date | date-time |
71.1.2.793. V2ClusterPlatformType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| GENERIC_CLUSTER |
| KUBERNETES_CLUSTER |
| OPENSHIFT_CLUSTER |
| OPENSHIFT4_CLUSTER |
71.1.2.794. V2ClusterProviderType Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSPECIFIED |
| AKS |
| ARO |
| EKS |
| GKE |
| OCP |
| OSD |
| ROSA |
71.1.2.795. V2ClusterScanStatus Copy linkLink copied to clipboard!
ClusterScanStatus holds status based on cluster in the event that a scan configuration was successfully applied to some clusters but not others. Next available tag: 5
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | ||||
| errors |
List of | ||||
| clusterName | String | ||||
| suiteStatus |
71.1.2.796. V2CollectionReference Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| collectionId | String | ||||
| collectionName | String |
71.1.2.797. V2CollectionSnapshot Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| name | String |
71.1.2.798. V2Comment Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| id | String | ||||
| message | String | ||||
| user | |||||
| createdAt | Date | date-time |
71.1.2.799. V2ComplianceBenchmark Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| name | String | ||||
| version | String | ||||
| description | String | ||||
| provider | String | ||||
| shortName | String |
71.1.2.800. V2ComplianceCheckData Copy linkLink copied to clipboard!
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| clusterId | String | ||||
| scanName | String | ||||
| result |
71.1.2.801. V2ComplianceCheckResult Copy linkLink copied to clipboard!
ComplianceCheckResult details of an instance of a compliance check result
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| checkId | String | ||||
| checkName | String | ||||
| checkUid | String | ||||
| description | String | ||||
| instructions | String | ||||
| rationale | String | ||||
| valuesUsed |
List of | ||||
| warnings |
List of | ||||
| status | UNSET_CHECK_STATUS, PASS, FAIL, ERROR, INFO, MANUAL, NOT_APPLICABLE, INCONSISTENT, | ||||
| ruleName | String | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| controls | List of V2ComplianceControl |
71.1.2.802. V2ComplianceCheckResultStatusCount Copy linkLink copied to clipboard!
Group the number of occurrences by status
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| checkName | String | ||||
| rationale | String | ||||
| ruleName | String | ||||
| checkStats | List of V2ComplianceCheckStatusCount | ||||
| controls | List of V2ComplianceControl |
71.1.2.803. V2ComplianceCheckStatus Copy linkLink copied to clipboard!
| Enum Values |
|---|
| UNSET_CHECK_STATUS |
| PASS |
| FAIL |
| ERROR |
| INFO |
| MANUAL |
| NOT_APPLICABLE |
| INCONSISTENT |
71.1.2.804. V2ComplianceCheckStatusCount Copy linkLink copied to clipboard!
Group the number of occurrences by status
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| count | Integer | int32 | |||
| status | UNSET_CHECK_STATUS, PASS, FAIL, ERROR, INFO, MANUAL, NOT_APPLICABLE, INCONSISTENT, |
71.1.2.805. V2ComplianceClusterCheckStatus Copy linkLink copied to clipboard!
ComplianceClusterCheckStatus provides the status of a compliance check result across clusters
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| checkId | String | ||||
| checkName | String | ||||
| clusters | List of V2ClusterCheckStatus | ||||
| description | String | ||||
| instructions | String | ||||
| rationale | String | ||||
| valuesUsed |
List of | ||||
| warnings |
List of | ||||
| labels |
Map of | ||||
| annotations |
Map of | ||||
| controls | List of V2ComplianceControl |
71.1.2.806. V2ComplianceClusterOverallStats Copy linkLink copied to clipboard!
ComplianceClusterOverallStats provides overall stats for cluster
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| cluster | |||||
| checkStats | List of V2ComplianceCheckStatusCount | ||||
| clusterErrors |
List of | ||||
| lastScanTime | Date | date-time |
71.1.2.807. V2ComplianceClusterScanStats Copy linkLink copied to clipboard!
ComplianceClusterScanStats provides scan stats overview based on cluster
| Field Name | Required | Nullable | Type | Description | Format |
|---|---|---|---|---|---|
| scanStats | |||||
| cluster |