CloudQuery rbac API
The rbac API from CloudQuery — 4 operation(s) for rbac.
The rbac API from CloudQuery — 4 operation(s) for rbac.
openapi: 3.1.0
info:
contact:
email: support@cloudquery.io
name: CloudQuery Support Team
url: https://cloudquery.io
description: 'Welcome to the CloudQuery Platform API documentation! This API can be used to interact with the CloudQuery platform. As a user, the API allows you to search the CloudQuery asset inventory, run SQL queries against the data warehouse, save and load searches, and much more. As an administrator, it allows you to manage your teams, syncs, and other objects.
### Authentication
The API is secured using bearer tokens. To get started, you can generate an API key for your Platform deployment from your platform dashboard. For a step-by-step guide, see: https://www.cloudquery.io/docs/cli/managing-cloudquery/deployments/generate-api-key.
The base URL for the API depends on where your CloudQuery Platform is hosted. If running locally, this is usually http://localhost:3000/api. In a production deployment it should be an HTTPS URL. For purposes of illustration, we will assume the platform instance is available at https://cloudquery.mycompany.com. In this case, the base API endpoint will be https://cloudquery.mycompany.com/api.
### Example Request
To test your connection to the API, we can use the `/plugins` endpoint. For example:
`curl -v -H "Authorization: Bearer $CLOUDQUERY_API_KEY" \ https://cloudquery.mycompany.com/api/plugins`
'
license:
name: MIT
url: https://spdx.org/licenses/MIT
termsOfService: https://www.cloudquery.io/terms
title: CloudQuery Platform OpenAPI Spec admin rbac API
version: 1.0.0
security:
- bearerAuth: []
- cookieAuth: []
tags:
- name: rbac
paths:
/rbac/permissions:
get:
description: List all permissions
operationId: PlatformListAllRBACPermissions
parameters:
- $ref: '#/components/parameters/platform_per_page'
- $ref: '#/components/parameters/platform_page'
- $ref: '#/components/parameters/platform_rbac_permissions_sort_bys'
- $ref: '#/components/parameters/platform_rbac_permissions_sort_dirs'
- name: search_term
in: query
schema:
type: string
description: Filter permissions by name or description.
responses:
'200':
description: Response
content:
application/json:
schema:
required:
- items
- metadata
properties:
items:
items:
$ref: '#/components/schemas/PlatformRBACPermission'
type: array
metadata:
$ref: '#/components/schemas/PlatformListMetadata'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
post:
description: Create a permission
operationId: PlatformCreateRBACPermission
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACPermissionCreate'
responses:
'201':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACPermission'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
/rbac/permissions/{permission_id}:
get:
description: Get a permission
operationId: PlatformGetRBACPermission
parameters:
- $ref: '#/components/parameters/platform_rbac_permission_id'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACPermission'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
patch:
description: Update a permission
operationId: PlatformUpdateRBACPermission
parameters:
- $ref: '#/components/parameters/platform_rbac_permission_id'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACPermissionUpdate'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACPermission'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
delete:
description: Delete a permission
operationId: PlatformDeleteRBACPermission
parameters:
- $ref: '#/components/parameters/platform_rbac_permission_id'
responses:
'204':
description: Success
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
/rbac/roles:
get:
description: List all roles
operationId: PlatformListAllRBACRoles
parameters:
- $ref: '#/components/parameters/platform_per_page'
- $ref: '#/components/parameters/platform_page'
- $ref: '#/components/parameters/platform_rbac_roles_sort_bys'
- $ref: '#/components/parameters/platform_rbac_roles_sort_dirs'
- name: search_term
in: query
schema:
type: string
description: Filter roles by name or description.
- name: type
in: query
schema:
type: string
description: Filter roles by type.
responses:
'200':
description: Response
content:
application/json:
schema:
required:
- items
- metadata
properties:
items:
items:
$ref: '#/components/schemas/PlatformRole'
type: array
metadata:
$ref: '#/components/schemas/PlatformListMetadata'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
post:
description: Create a role
operationId: PlatformCreateRBACRole
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACRoleCreate'
responses:
'201':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRole'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
/rbac/roles/{role_id}:
get:
description: Get a role
operationId: PlatformGetRBACRole
parameters:
- $ref: '#/components/parameters/platform_rbac_role_id'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRole'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
patch:
description: Update a role (custom roles only)
operationId: PlatformUpdateRBACRole
parameters:
- $ref: '#/components/parameters/platform_rbac_role_id'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRBACRoleUpdate'
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformRole'
'400':
$ref: '#/components/responses/PlatformBadRequest'
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
delete:
description: Delete a role
operationId: PlatformDeleteRBACRole
parameters:
- $ref: '#/components/parameters/platform_rbac_role_id'
responses:
'204':
description: Success
'401':
$ref: '#/components/responses/PlatformRequiresAuthentication'
'403':
$ref: '#/components/responses/PlatformForbidden'
'404':
$ref: '#/components/responses/PlatformNotFound'
'422':
$ref: '#/components/responses/PlatformUnprocessableEntity'
'500':
$ref: '#/components/responses/PlatformInternalError'
tags:
- rbac
components:
schemas:
PlatformListMetadata:
required:
- page_size
properties:
total_count:
type: integer
last_page:
type: integer
page_size:
type: integer
time_ms:
type: integer
PlatformFieldError:
allOf:
- $ref: '#/components/schemas/PlatformBasicError'
- properties:
errors:
items:
type: string
type: array
field_errors:
additionalProperties:
type: string
type: object
type: object
PlatformRoleID:
description: The unique ID for the role.
type: string
format: uuid
x-go-name: RoleID
PlatformRole:
type: object
description: Role
required:
- id
- name
- description
- permissions
- created_by
- created_at
- updated_at
- type
properties:
id:
description: The unique ID for the role.
type: string
format: uuid
x-go-name: ID
name:
type: string
description:
type: string
permissions:
type: array
items:
$ref: '#/components/schemas/PlatformRBACPermission'
created_by:
$ref: '#/components/schemas/PlatformCreatedBy'
created_at:
example: '2017-07-14T16:53:42Z'
format: date-time
type: string
updated_at:
example: '2017-07-14T16:53:42Z'
format: date-time
type: string
type:
$ref: '#/components/schemas/PlatformRoleType'
PlatformRBACPermissionID:
description: The unique ID for the data permission.
type: string
format: uuid
x-go-name: RBACPermissionID
PlatformRBACRoleSortDirection:
title: RBACRoleSortDirection
type: string
enum:
- asc
- desc
default: asc
PlatformRBACPermissionSortDirection:
title: RBACPermissionSortDirection
type: string
enum:
- asc
- desc
default: asc
PlatformUserName:
description: The unique name for the user.
minLength: 1
maxLength: 255
pattern: ^[a-zA-Z\p{L}][a-zA-Z\p{L} \-']*$
x-pattern-message: can contain only letters, spaces, hyphens, and apostrophes, starting with a letter
type: string
example: Sarah O'Connor
PlatformRBACPermission:
type: object
required:
- id
- name
- description
- query
- created_by
- created_at
- updated_at
- number_of_affected_roles
- number_of_affected_users
properties:
id:
$ref: '#/components/schemas/PlatformRBACPermissionID'
name:
type: string
description:
type: string
query:
type: string
created_by:
$ref: '#/components/schemas/PlatformCreatedBy'
created_at:
example: '2017-07-14T16:53:42Z'
format: date-time
type: string
updated_at:
example: '2017-07-14T16:53:42Z'
format: date-time
type: string
number_of_affected_roles:
type: integer
number_of_affected_users:
type: integer
PlatformRBACPermissionUpdate:
type: object
properties:
name:
type: string
description:
type: string
query:
type: string
PlatformRoleType:
type: string
enum:
- admin:write
- admin:read
- general:read
- general:write
- ci
- schema-only
- custom
x-enum-varnames:
- AdminWrite
- AdminRead
- GeneralRead
- GeneralWrite
- CI
- SchemaOnly
- Custom
PlatformUserID:
description: ID of the User
type: string
format: uuid
example: 12345678-1234-1234-1234-1234567890ab
x-go-name: UserID
PlatformRBACPermissionCreate:
type: object
required:
- name
- description
- query
properties:
name:
type: string
description:
type: string
query:
type: string
dry_run:
type: boolean
default: false
PlatformRBACRoleCreate:
type: object
required:
- name
- permissions
properties:
name:
type: string
description:
type: string
permissions:
type: array
items:
$ref: '#/components/schemas/PlatformRBACPermissionID'
PlatformRBACPermissionSortBy:
title: RBACPermissionSortBy
type: string
enum:
- id
- name
- description
- created_by
- created_at
- updated_at
PlatformRBACRoleUpdate:
type: object
properties:
name:
type: string
description:
type: string
permissions:
type: array
items:
$ref: '#/components/schemas/PlatformRBACPermissionID'
PlatformBasicError:
additionalProperties: false
description: Basic Error
required:
- message
- status
properties:
message:
type: string
status:
type: integer
title: Basic Error
type: object
PlatformRBACRoleSortBy:
title: RBACRoleSortBy
type: string
enum:
- id
- name
- description
- created_by
- created_at
- updated_at
PlatformCreatedBy:
type: object
required:
- id
- name
- email
properties:
id:
$ref: '#/components/schemas/PlatformUserID'
name:
$ref: '#/components/schemas/PlatformUserName'
email:
type: string
responses:
PlatformBadRequest:
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformFieldError'
description: Bad request
PlatformInternalError:
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformBasicError'
description: Internal Error
PlatformNotFound:
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformBasicError'
description: Resource not found
PlatformForbidden:
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformFieldError'
description: Forbidden
PlatformUnprocessableEntity:
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformFieldError'
description: UnprocessableEntity
PlatformRequiresAuthentication:
content:
application/json:
schema:
$ref: '#/components/schemas/PlatformBasicError'
description: Requires authentication
parameters:
platform_rbac_role_id:
in: path
name: role_id
required: true
schema:
$ref: '#/components/schemas/PlatformRoleID'
x-go-name: RoleID
platform_rbac_roles_sort_dirs:
name: sort_dir
in: query
description: Sort direction options
allowEmptyValue: true
explode: true
schema:
type: array
items:
$ref: '#/components/schemas/PlatformRBACRoleSortDirection'
x-go-type-skip-optional-pointer: true
x-go-name: RBACRoleSortDirections
platform_page:
description: Page number of the results to fetch
in: query
name: page
required: false
schema:
default: 1
minimum: 1
type: integer
format: int64
platform_rbac_permissions_sort_dirs:
name: sort_dir
in: query
description: Sort direction options
allowEmptyValue: true
explode: true
schema:
type: array
items:
$ref: '#/components/schemas/PlatformRBACPermissionSortDirection'
x-go-type-skip-optional-pointer: true
x-go-name: RBACPermissionSortDirections
platform_per_page:
description: The number of results per page (max 1000).
in: query
name: per_page
required: false
schema:
default: 100
maximum: 1000
minimum: 1
type: integer
format: int64
platform_rbac_permission_id:
in: path
name: permission_id
required: true
schema:
$ref: '#/components/schemas/PlatformRBACPermissionID'
x-go-name: RBACPermissionID
platform_rbac_roles_sort_bys:
name: sort_by
in: query
description: Sort by options
allowEmptyValue: true
explode: true
schema:
type: array
items:
$ref: '#/components/schemas/PlatformRBACRoleSortBy'
x-go-type-skip-optional-pointer: true
x-go-name: RBACRoleSortBys
platform_rbac_permissions_sort_bys:
name: sort_by
in: query
description: Sort by options
allowEmptyValue: true
explode: true
schema:
type: array
items:
$ref: '#/components/schemas/PlatformRBACPermissionSortBy'
x-go-type-skip-optional-pointer: true
x-go-name: RBACPermissionSortBys
securitySchemes:
bearerAuth:
scheme: bearer
type: http
basicAuth:
scheme: basic
type: http
cookieAuth:
scheme: cookie
type: http