CloudQuery rbac API

The rbac API from CloudQuery — 4 operation(s) for rbac.

OpenAPI Specification

cloudquery-rbac-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: support@cloudquery.io
    name: CloudQuery Support Team
    url: https://cloudquery.io
  description: 'Welcome to the CloudQuery Platform API documentation! This API can be used to interact with the CloudQuery platform. As a user, the API allows you to search the CloudQuery asset inventory, run SQL queries against the data warehouse, save and load searches, and much more. As an administrator, it allows you to manage your teams, syncs, and other objects.

    ### Authentication

    The API is secured using bearer tokens. To get started, you can generate an API key for your Platform deployment from your platform dashboard. For a step-by-step guide, see: https://www.cloudquery.io/docs/cli/managing-cloudquery/deployments/generate-api-key.

    The base URL for the API depends on where your CloudQuery Platform is hosted. If running locally, this is usually http://localhost:3000/api. In a production deployment it should be an HTTPS URL. For purposes of illustration, we will assume the platform instance is available at https://cloudquery.mycompany.com. In this case, the base API endpoint will be https://cloudquery.mycompany.com/api.

    ### Example Request

    To test your connection to the API, we can use the `/plugins` endpoint. For example:

    `curl -v -H "Authorization: Bearer $CLOUDQUERY_API_KEY" \ https://cloudquery.mycompany.com/api/plugins`

    '
  license:
    name: MIT
    url: https://spdx.org/licenses/MIT
  termsOfService: https://www.cloudquery.io/terms
  title: CloudQuery Platform OpenAPI Spec admin rbac API
  version: 1.0.0
security:
- bearerAuth: []
- cookieAuth: []
tags:
- name: rbac
paths:
  /rbac/permissions:
    get:
      description: List all permissions
      operationId: PlatformListAllRBACPermissions
      parameters:
      - $ref: '#/components/parameters/platform_per_page'
      - $ref: '#/components/parameters/platform_page'
      - $ref: '#/components/parameters/platform_rbac_permissions_sort_bys'
      - $ref: '#/components/parameters/platform_rbac_permissions_sort_dirs'
      - name: search_term
        in: query
        schema:
          type: string
        description: Filter permissions by name or description.
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                required:
                - items
                - metadata
                properties:
                  items:
                    items:
                      $ref: '#/components/schemas/PlatformRBACPermission'
                    type: array
                  metadata:
                    $ref: '#/components/schemas/PlatformListMetadata'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
    post:
      description: Create a permission
      operationId: PlatformCreateRBACPermission
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlatformRBACPermissionCreate'
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformRBACPermission'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
  /rbac/permissions/{permission_id}:
    get:
      description: Get a permission
      operationId: PlatformGetRBACPermission
      parameters:
      - $ref: '#/components/parameters/platform_rbac_permission_id'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformRBACPermission'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
    patch:
      description: Update a permission
      operationId: PlatformUpdateRBACPermission
      parameters:
      - $ref: '#/components/parameters/platform_rbac_permission_id'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlatformRBACPermissionUpdate'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformRBACPermission'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
    delete:
      description: Delete a permission
      operationId: PlatformDeleteRBACPermission
      parameters:
      - $ref: '#/components/parameters/platform_rbac_permission_id'
      responses:
        '204':
          description: Success
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
  /rbac/roles:
    get:
      description: List all roles
      operationId: PlatformListAllRBACRoles
      parameters:
      - $ref: '#/components/parameters/platform_per_page'
      - $ref: '#/components/parameters/platform_page'
      - $ref: '#/components/parameters/platform_rbac_roles_sort_bys'
      - $ref: '#/components/parameters/platform_rbac_roles_sort_dirs'
      - name: search_term
        in: query
        schema:
          type: string
        description: Filter roles by name or description.
      - name: type
        in: query
        schema:
          type: string
        description: Filter roles by type.
      responses:
        '200':
          description: Response
          content:
            application/json:
              schema:
                required:
                - items
                - metadata
                properties:
                  items:
                    items:
                      $ref: '#/components/schemas/PlatformRole'
                    type: array
                  metadata:
                    $ref: '#/components/schemas/PlatformListMetadata'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
    post:
      description: Create a role
      operationId: PlatformCreateRBACRole
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlatformRBACRoleCreate'
      responses:
        '201':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformRole'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
  /rbac/roles/{role_id}:
    get:
      description: Get a role
      operationId: PlatformGetRBACRole
      parameters:
      - $ref: '#/components/parameters/platform_rbac_role_id'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformRole'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
    patch:
      description: Update a role (custom roles only)
      operationId: PlatformUpdateRBACRole
      parameters:
      - $ref: '#/components/parameters/platform_rbac_role_id'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PlatformRBACRoleUpdate'
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PlatformRole'
        '400':
          $ref: '#/components/responses/PlatformBadRequest'
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
    delete:
      description: Delete a role
      operationId: PlatformDeleteRBACRole
      parameters:
      - $ref: '#/components/parameters/platform_rbac_role_id'
      responses:
        '204':
          description: Success
        '401':
          $ref: '#/components/responses/PlatformRequiresAuthentication'
        '403':
          $ref: '#/components/responses/PlatformForbidden'
        '404':
          $ref: '#/components/responses/PlatformNotFound'
        '422':
          $ref: '#/components/responses/PlatformUnprocessableEntity'
        '500':
          $ref: '#/components/responses/PlatformInternalError'
      tags:
      - rbac
components:
  schemas:
    PlatformListMetadata:
      required:
      - page_size
      properties:
        total_count:
          type: integer
        last_page:
          type: integer
        page_size:
          type: integer
        time_ms:
          type: integer
    PlatformFieldError:
      allOf:
      - $ref: '#/components/schemas/PlatformBasicError'
      - properties:
          errors:
            items:
              type: string
            type: array
          field_errors:
            additionalProperties:
              type: string
            type: object
        type: object
    PlatformRoleID:
      description: The unique ID for the role.
      type: string
      format: uuid
      x-go-name: RoleID
    PlatformRole:
      type: object
      description: Role
      required:
      - id
      - name
      - description
      - permissions
      - created_by
      - created_at
      - updated_at
      - type
      properties:
        id:
          description: The unique ID for the role.
          type: string
          format: uuid
          x-go-name: ID
        name:
          type: string
        description:
          type: string
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/PlatformRBACPermission'
        created_by:
          $ref: '#/components/schemas/PlatformCreatedBy'
        created_at:
          example: '2017-07-14T16:53:42Z'
          format: date-time
          type: string
        updated_at:
          example: '2017-07-14T16:53:42Z'
          format: date-time
          type: string
        type:
          $ref: '#/components/schemas/PlatformRoleType'
    PlatformRBACPermissionID:
      description: The unique ID for the data permission.
      type: string
      format: uuid
      x-go-name: RBACPermissionID
    PlatformRBACRoleSortDirection:
      title: RBACRoleSortDirection
      type: string
      enum:
      - asc
      - desc
      default: asc
    PlatformRBACPermissionSortDirection:
      title: RBACPermissionSortDirection
      type: string
      enum:
      - asc
      - desc
      default: asc
    PlatformUserName:
      description: The unique name for the user.
      minLength: 1
      maxLength: 255
      pattern: ^[a-zA-Z\p{L}][a-zA-Z\p{L} \-']*$
      x-pattern-message: can contain only letters, spaces, hyphens, and apostrophes, starting with a letter
      type: string
      example: Sarah O'Connor
    PlatformRBACPermission:
      type: object
      required:
      - id
      - name
      - description
      - query
      - created_by
      - created_at
      - updated_at
      - number_of_affected_roles
      - number_of_affected_users
      properties:
        id:
          $ref: '#/components/schemas/PlatformRBACPermissionID'
        name:
          type: string
        description:
          type: string
        query:
          type: string
        created_by:
          $ref: '#/components/schemas/PlatformCreatedBy'
        created_at:
          example: '2017-07-14T16:53:42Z'
          format: date-time
          type: string
        updated_at:
          example: '2017-07-14T16:53:42Z'
          format: date-time
          type: string
        number_of_affected_roles:
          type: integer
        number_of_affected_users:
          type: integer
    PlatformRBACPermissionUpdate:
      type: object
      properties:
        name:
          type: string
        description:
          type: string
        query:
          type: string
    PlatformRoleType:
      type: string
      enum:
      - admin:write
      - admin:read
      - general:read
      - general:write
      - ci
      - schema-only
      - custom
      x-enum-varnames:
      - AdminWrite
      - AdminRead
      - GeneralRead
      - GeneralWrite
      - CI
      - SchemaOnly
      - Custom
    PlatformUserID:
      description: ID of the User
      type: string
      format: uuid
      example: 12345678-1234-1234-1234-1234567890ab
      x-go-name: UserID
    PlatformRBACPermissionCreate:
      type: object
      required:
      - name
      - description
      - query
      properties:
        name:
          type: string
        description:
          type: string
        query:
          type: string
        dry_run:
          type: boolean
          default: false
    PlatformRBACRoleCreate:
      type: object
      required:
      - name
      - permissions
      properties:
        name:
          type: string
        description:
          type: string
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/PlatformRBACPermissionID'
    PlatformRBACPermissionSortBy:
      title: RBACPermissionSortBy
      type: string
      enum:
      - id
      - name
      - description
      - created_by
      - created_at
      - updated_at
    PlatformRBACRoleUpdate:
      type: object
      properties:
        name:
          type: string
        description:
          type: string
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/PlatformRBACPermissionID'
    PlatformBasicError:
      additionalProperties: false
      description: Basic Error
      required:
      - message
      - status
      properties:
        message:
          type: string
        status:
          type: integer
      title: Basic Error
      type: object
    PlatformRBACRoleSortBy:
      title: RBACRoleSortBy
      type: string
      enum:
      - id
      - name
      - description
      - created_by
      - created_at
      - updated_at
    PlatformCreatedBy:
      type: object
      required:
      - id
      - name
      - email
      properties:
        id:
          $ref: '#/components/schemas/PlatformUserID'
        name:
          $ref: '#/components/schemas/PlatformUserName'
        email:
          type: string
  responses:
    PlatformBadRequest:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformFieldError'
      description: Bad request
    PlatformInternalError:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformBasicError'
      description: Internal Error
    PlatformNotFound:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformBasicError'
      description: Resource not found
    PlatformForbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformFieldError'
      description: Forbidden
    PlatformUnprocessableEntity:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformFieldError'
      description: UnprocessableEntity
    PlatformRequiresAuthentication:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/PlatformBasicError'
      description: Requires authentication
  parameters:
    platform_rbac_role_id:
      in: path
      name: role_id
      required: true
      schema:
        $ref: '#/components/schemas/PlatformRoleID'
      x-go-name: RoleID
    platform_rbac_roles_sort_dirs:
      name: sort_dir
      in: query
      description: Sort direction options
      allowEmptyValue: true
      explode: true
      schema:
        type: array
        items:
          $ref: '#/components/schemas/PlatformRBACRoleSortDirection'
      x-go-type-skip-optional-pointer: true
      x-go-name: RBACRoleSortDirections
    platform_page:
      description: Page number of the results to fetch
      in: query
      name: page
      required: false
      schema:
        default: 1
        minimum: 1
        type: integer
        format: int64
    platform_rbac_permissions_sort_dirs:
      name: sort_dir
      in: query
      description: Sort direction options
      allowEmptyValue: true
      explode: true
      schema:
        type: array
        items:
          $ref: '#/components/schemas/PlatformRBACPermissionSortDirection'
      x-go-type-skip-optional-pointer: true
      x-go-name: RBACPermissionSortDirections
    platform_per_page:
      description: The number of results per page (max 1000).
      in: query
      name: per_page
      required: false
      schema:
        default: 100
        maximum: 1000
        minimum: 1
        type: integer
        format: int64
    platform_rbac_permission_id:
      in: path
      name: permission_id
      required: true
      schema:
        $ref: '#/components/schemas/PlatformRBACPermissionID'
      x-go-name: RBACPermissionID
    platform_rbac_roles_sort_bys:
      name: sort_by
      in: query
      description: Sort by options
      allowEmptyValue: true
      explode: true
      schema:
        type: array
        items:
          $ref: '#/components/schemas/PlatformRBACRoleSortBy'
      x-go-type-skip-optional-pointer: true
      x-go-name: RBACRoleSortBys
    platform_rbac_permissions_sort_bys:
      name: sort_by
      in: query
      description: Sort by options
      allowEmptyValue: true
      explode: true
      schema:
        type: array
        items:
          $ref: '#/components/schemas/PlatformRBACPermissionSortBy'
      x-go-type-skip-optional-pointer: true
      x-go-name: RBACPermissionSortBys
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http
    basicAuth:
      scheme: basic
      type: http
    cookieAuth:
      scheme: cookie
      type: http