Incus network-acls API

The network-acls API from Incus — 4 operation(s) for network-acls.

Operations 9

GET /1.0/network-acls Get the network ACLs #
POST /1.0/network-acls Add a network ACL #
DELETE /1.0/network-acls/{name} Delete the network ACL #
GET /1.0/network-acls/{name} Get the network ACL #
PATCH /1.0/network-acls/{name} Partially update the network ACL #
POST /1.0/network-acls/{name} Rename the network ACL #
PUT /1.0/network-acls/{name} Update the network ACL #
GET /1.0/network-acls/{name}/log Get the network ACL log #
GET /1.0/network-acls?recursion=1 Get the network ACLs #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/incus-network-acls-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

incus-network-acls-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: lxc-devel@lists.linuxcontainers.org
    name: Incus upstream
    url: https://github.com/lxc/incus
  description: 'This is the REST API used by all Incus clients.

    Internal endpoints aren''t included in this documentation.


    The Incus API is available over both a local unix+http and remote https API.

    Authentication for local users relies on group membership and access to the unix socket.

    For remote users, the default authentication method is TLS client

    certificates.'
  license:
    name: Apache-2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
  title: Incus external REST certificates Network Acls API
  version: '1.0'
tags:
- name: network-acls
paths:
  /1.0/network-acls:
    get:
      description: Returns a list of network ACLs (URLs).
      operationId: network_acls_get
      parameters:
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      - description: Retrieve network ACLs from all projects
        example: true
        in: query
        name: all-projects
        schema:
          type: boolean
      - description: Collection filter
        example: default
        in: query
        name: filter
        schema:
          type: string
      responses:
        '200':
          description: API endpoints
          content:
            application/json:
              schema:
                description: Sync response
                properties:
                  metadata:
                    description: List of endpoints
                    example: "[\n  \"/1.0/network-acls/foo\",\n  \"/1.0/network-acls/bar\"\n]"
                    items:
                      type: string
                    type: array
                  status:
                    description: Status description
                    example: Success
                    type: string
                  status_code:
                    description: Status code
                    example: 200
                    type: integer
                  type:
                    description: Response type
                    example: sync
                    type: string
                type: object
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the network ACLs
      tags:
      - network-acls
    post:
      description: Creates a new network ACL.
      operationId: network_acls_post
      parameters:
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Add a network ACL
      tags:
      - network-acls
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkACLsPost'
        description: ACL
        required: true
  /1.0/network-acls/{name}:
    delete:
      description: Removes the network ACL.
      operationId: network_acl_delete
      parameters:
      - description: ACL name
        in: path
        name: name
        required: true
        schema:
          type: string
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Delete the network ACL
      tags:
      - network-acls
    get:
      description: Gets a specific network ACL.
      operationId: network_acl_get
      parameters:
      - description: ACL name
        in: path
        name: name
        required: true
        schema:
          type: string
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          description: ACL
          content:
            application/json:
              schema:
                description: Sync response
                properties:
                  metadata:
                    $ref: '#/components/schemas/NetworkACL'
                  status:
                    description: Status description
                    example: Success
                    type: string
                  status_code:
                    description: Status code
                    example: 200
                    type: integer
                  type:
                    description: Response type
                    example: sync
                    type: string
                type: object
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the network ACL
      tags:
      - network-acls
    patch:
      description: Updates a subset of the network ACL configuration.
      operationId: network_acl_patch
      parameters:
      - description: ACL name
        in: path
        name: name
        required: true
        schema:
          type: string
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '412':
          $ref: '#/components/responses/PreconditionFailed'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Partially update the network ACL
      tags:
      - network-acls
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkACLPut'
        description: ACL configuration
        required: true
    post:
      description: Renames an existing network ACL.
      operationId: network_acl_post
      parameters:
      - description: ACL name
        in: path
        name: name
        required: true
        schema:
          type: string
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Rename the network ACL
      tags:
      - network-acls
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkACLPost'
        description: ACL rename request
        required: true
    put:
      description: Updates the entire network ACL configuration.
      operationId: network_acl_put
      parameters:
      - description: ACL name
        in: path
        name: name
        required: true
        schema:
          type: string
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          $ref: '#/components/responses/EmptySyncResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Forbidden'
        '412':
          $ref: '#/components/responses/PreconditionFailed'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Update the network ACL
      tags:
      - network-acls
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkACLPut'
        description: ACL configuration
        required: true
  /1.0/network-acls/{name}/log:
    get:
      description: Gets a specific network ACL log entries.
      operationId: network_acl_log_get
      parameters:
      - description: ACL name
        in: path
        name: name
        required: true
        schema:
          type: string
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      responses:
        '200':
          description: Raw log file
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the network ACL log
      tags:
      - network-acls
  /1.0/network-acls?recursion=1:
    get:
      description: Returns a list of network ACLs (structs).
      operationId: network_acls_get_recursion1
      parameters:
      - description: Project name
        example: default
        in: query
        name: project
        schema:
          type: string
      - description: Retrieve network ACLs from all projects
        example: true
        in: query
        name: all-projects
        schema:
          type: boolean
      - description: Collection filter
        example: default
        in: query
        name: filter
        schema:
          type: string
      responses:
        '200':
          description: API endpoints
          content:
            application/json:
              schema:
                description: Sync response
                properties:
                  metadata:
                    description: List of network ACLs
                    items:
                      $ref: '#/components/schemas/NetworkACL'
                    type: array
                  status:
                    description: Status description
                    example: Success
                    type: string
                  status_code:
                    description: Status code
                    example: 200
                    type: integer
                  type:
                    description: Response type
                    example: sync
                    type: string
                type: object
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      summary: Get the network ACLs
      tags:
      - network-acls
components:
  responses:
    PreconditionFailed:
      description: Precondition Failed
      content:
        application/json:
          schema:
            properties:
              error:
                example: precondition failed
                type: string
                x-go-name: Error
              error_code:
                example: 412
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            properties:
              error:
                example: not authorized
                type: string
                x-go-name: Error
              error_code:
                example: 403
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object
    InternalServerError:
      description: Internal Server Error
      content:
        application/json:
          schema:
            properties:
              error:
                example: internal server error
                type: string
                x-go-name: Error
              error_code:
                example: 500
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object
    BadRequest:
      description: Bad Request
      content:
        application/json:
          schema:
            properties:
              error:
                example: bad request
                type: string
                x-go-name: Error
              error_code:
                example: 400
                format: int64
                type: integer
                x-go-name: ErrorCode
              type:
                example: error
                type: string
                x-go-name: Type
            type: object
    EmptySyncResponse:
      description: Empty sync response
      content:
        application/json:
          schema:
            properties:
              status:
                example: Success
                type: string
                x-go-name: Status
              status_code:
                example: 200
                format: int64
                type: integer
                x-go-name: StatusCode
              type:
                example: sync
                type: string
                x-go-name: Type
            type: object
  schemas:
    NetworkACLPost:
      properties:
        name:
          description: The new name for the ACL
          example: bar
          type: string
          x-go-name: Name
      title: NetworkACLPost used for renaming an ACL.
      type: object
      x-go-package: github.com/lxc/incus/v7/shared/api
    NetworkACL:
      properties:
        config:
          description: ACL configuration map (refer to doc/network-acls.md)
          example:
            user.mykey: foo
          type: object
          x-go-name: Config
        description:
          description: Description of the ACL
          example: Web servers
          type: string
          x-go-name: Description
        egress:
          description: List of egress rules (order independent)
          items:
            $ref: '#/components/schemas/NetworkACLRule'
          type: array
          x-go-name: Egress
        ingress:
          description: List of ingress rules (order independent)
          items:
            $ref: '#/components/schemas/NetworkACLRule'
          type: array
          x-go-name: Ingress
        name:
          description: The new name for the ACL
          example: bar
          type: string
          x-go-name: Name
        project:
          description: Project name
          example: project1
          type: string
          x-go-name: Project
        used_by:
          description: List of URLs of objects using this profile
          example:
          - /1.0/instances/c1
          - /1.0/instances/v1
          - /1.0/networks/mybr0
          items:
            type: string
          readOnly: true
          type: array
          x-go-name: UsedBy
      title: NetworkACL used for displaying an ACL.
      type: object
      x-go-package: github.com/lxc/incus/v7/shared/api
    NetworkACLRule:
      description: Refer to doc/network-acls.md for details.
      properties:
        action:
          description: Action to perform on rule match
          example: allow
          type: string
          x-go-name: Action
        description:
          description: Description of the rule
          example: Allow DNS queries to Google DNS
          type: string
          x-go-name: Description
        destination:
          description: Destination address
          example: 8.8.8.8/32,8.8.4.4/32
          type: string
          x-go-name: Destination
        destination_port:
          description: Destination port
          example: '53'
          type: string
          x-go-name: DestinationPort
        icmp_code:
          description: ICMP message code (for ICMP protocol)
          example: '0'
          type: string
          x-go-name: ICMPCode
        icmp_type:
          description: Type of ICMP message (for ICMP protocol)
          example: '8'
          type: string
          x-go-name: ICMPType
        protocol:
          description: Protocol
          example: udp
          type: string
          x-go-name: Protocol
        source:
          description: Source address
          example: '@internal'
          type: string
          x-go-name: Source
        source_port:
          description: Source port
          example: '1234'
          type: string
          x-go-name: SourcePort
        state:
          description: State of the rule
          example: enabled
          type: string
          x-go-name: State
      title: NetworkACLRule represents a single rule in an ACL ruleset.
      type: object
      x-go-package: github.com/lxc/incus/v7/shared/api
    NetworkACLPut:
      properties:
        config:
          description: ACL configuration map (refer to doc/network-acls.md)
          example:
            user.mykey: foo
          type: object
          x-go-name: Config
        description:
          description: Description of the ACL
          example: Web servers
          type: string
          x-go-name: Description
        egress:
          description: List of egress rules (order independent)
          items:
            $ref: '#/components/schemas/NetworkACLRule'
          type: array
          x-go-name: Egress
        ingress:
          description: List of ingress rules (order independent)
          items:
            $ref: '#/components/schemas/NetworkACLRule'
          type: array
          x-go-name: Ingress
      title: NetworkACLPut used for updating an ACL.
      type: object
      x-go-package: github.com/lxc/incus/v7/shared/api
    NetworkACLsPost:
      properties:
        config:
          description: ACL configuration map (refer to doc/network-acls.md)
          example:
            user.mykey: foo
          type: object
          x-go-name: Config
        description:
          description: Description of the ACL
          example: Web servers
          type: string
          x-go-name: Description
        egress:
          description: List of egress rules (order independent)
          items:
            $ref: '#/components/schemas/NetworkACLRule'
          type: array
          x-go-name: Egress
        ingress:
          description: List of ingress rules (order independent)
          items:
            $ref: '#/components/schemas/NetworkACLRule'
          type: array
          x-go-name: Ingress
        name:
          description: The new name for the ACL
          example: bar
          type: string
          x-go-name: Name
      title: NetworkACLsPost used for creating an ACL.
      type: object
      x-go-package: github.com/lxc/incus/v7/shared/api