Istio AuthorizationPolicy API

Fine-grained access control policies for workloads

Documentation

Specifications

Schemas & Data

Other Resources

OpenAPI Specification

istio-authorizationpolicy-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Istio Extensions AuthorizationPolicy API
  description: The Istio Extensions API (extensions.istio.io) provides configuration resources for extending the Istio service mesh with custom functionality. The WasmPlugin resource enables deploying WebAssembly (Wasm) modules as plugins to the Envoy sidecar proxies, allowing custom processing of network traffic at various phases of the request lifecycle. These resources are defined as Kubernetes Custom Resource Definitions (CRDs) and are accessed via the Kubernetes API server.
  version: v1alpha1
  contact:
    name: Istio
    url: https://istio.io/
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0
servers:
- url: https://{cluster}/apis/extensions.istio.io/v1alpha1
  description: Kubernetes API server endpoint for Istio Extensions v1alpha1
  variables:
    cluster:
      default: kubernetes.default.svc
      description: Kubernetes API server hostname
tags:
- name: AuthorizationPolicy
  description: Fine-grained access control policies for workloads
  externalDocs:
    url: https://istio.io/latest/docs/reference/config/security/authorization-policy/
paths:
  /namespaces/{namespace}/authorizationpolicies:
    get:
      operationId: listAuthorizationPolicies
      summary: Istio List AuthorizationPolicies
      description: List all AuthorizationPolicy resources in the specified namespace. An AuthorizationPolicy enables access control on workloads in the mesh, supporting ALLOW, DENY, AUDIT, and CUSTOM actions based on source, operation, and condition matching.
      tags:
      - AuthorizationPolicy
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/labelSelector'
      - $ref: '#/components/parameters/limit'
      - $ref: '#/components/parameters/continue'
      responses:
        '200':
          description: Successful response containing list of AuthorizationPolicies
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthorizationPolicyList'
        '401':
          description: Unauthorized
    post:
      operationId: createAuthorizationPolicy
      summary: Istio Create an AuthorizationPolicy
      description: Create a new AuthorizationPolicy resource in the specified namespace.
      tags:
      - AuthorizationPolicy
      parameters:
      - $ref: '#/components/parameters/namespace'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthorizationPolicy'
      responses:
        '201':
          description: AuthorizationPolicy created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthorizationPolicy'
        '401':
          description: Unauthorized
        '409':
          description: Conflict - resource already exists
  /namespaces/{namespace}/authorizationpolicies/{name}:
    get:
      operationId: getAuthorizationPolicy
      summary: Istio Get an AuthorizationPolicy
      description: Read the specified AuthorizationPolicy resource.
      tags:
      - AuthorizationPolicy
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/name'
      responses:
        '200':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthorizationPolicy'
        '401':
          description: Unauthorized
        '404':
          description: Not found
    put:
      operationId: replaceAuthorizationPolicy
      summary: Istio Replace an AuthorizationPolicy
      description: Replace the specified AuthorizationPolicy resource.
      tags:
      - AuthorizationPolicy
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/name'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AuthorizationPolicy'
      responses:
        '200':
          description: AuthorizationPolicy replaced
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthorizationPolicy'
        '401':
          description: Unauthorized
        '404':
          description: Not found
    delete:
      operationId: deleteAuthorizationPolicy
      summary: Istio Delete an AuthorizationPolicy
      description: Delete the specified AuthorizationPolicy resource.
      tags:
      - AuthorizationPolicy
      parameters:
      - $ref: '#/components/parameters/namespace'
      - $ref: '#/components/parameters/name'
      responses:
        '200':
          description: AuthorizationPolicy deleted
        '401':
          description: Unauthorized
        '404':
          description: Not found
components:
  parameters:
    labelSelector:
      name: labelSelector
      in: query
      description: A selector to restrict the list of returned objects by their labels
      schema:
        type: string
    continue:
      name: continue
      in: query
      description: Continue token for paginated list requests
      schema:
        type: string
    name:
      name: name
      in: path
      required: true
      description: The resource name
      schema:
        type: string
    namespace:
      name: namespace
      in: path
      required: true
      description: The Kubernetes namespace
      schema:
        type: string
    limit:
      name: limit
      in: query
      description: Maximum number of resources to return
      schema:
        type: integer
  schemas:
    AuthorizationPolicyList:
      type: object
      properties:
        apiVersion:
          type: string
        kind:
          type: string
          enum:
          - AuthorizationPolicyList
        metadata:
          $ref: '#/components/schemas/ListMeta'
        items:
          type: array
          items:
            $ref: '#/components/schemas/AuthorizationPolicy'
    ObjectMeta:
      type: object
      properties:
        name:
          type: string
          description: Name of the resource
        namespace:
          type: string
          description: Namespace of the resource
        labels:
          type: object
          additionalProperties:
            type: string
        annotations:
          type: object
          additionalProperties:
            type: string
        creationTimestamp:
          type: string
          format: date-time
        resourceVersion:
          type: string
    AuthorizationRule:
      type: object
      properties:
        from:
          type: array
          items:
            type: object
            properties:
              source:
                type: object
                properties:
                  principals:
                    type: array
                    items:
                      type: string
                    description: Peer identities derived from the peer certificate.
                  notPrincipals:
                    type: array
                    items:
                      type: string
                  requestPrincipals:
                    type: array
                    items:
                      type: string
                    description: Request identities derived from the JWT token.
                  notRequestPrincipals:
                    type: array
                    items:
                      type: string
                  namespaces:
                    type: array
                    items:
                      type: string
                    description: Namespaces derived from the peer certificate.
                  notNamespaces:
                    type: array
                    items:
                      type: string
                  ipBlocks:
                    type: array
                    items:
                      type: string
                    description: IP blocks in CIDR notation.
                  notIpBlocks:
                    type: array
                    items:
                      type: string
          description: Source identities (peers and request principals) to match.
        to:
          type: array
          items:
            type: object
            properties:
              operation:
                type: object
                properties:
                  hosts:
                    type: array
                    items:
                      type: string
                    description: The request host header values.
                  notHosts:
                    type: array
                    items:
                      type: string
                  ports:
                    type: array
                    items:
                      type: string
                    description: The request port values.
                  notPorts:
                    type: array
                    items:
                      type: string
                  methods:
                    type: array
                    items:
                      type: string
                    description: The request HTTP methods (GET, POST, etc.).
                  notMethods:
                    type: array
                    items:
                      type: string
                  paths:
                    type: array
                    items:
                      type: string
                    description: The request URL paths.
                  notPaths:
                    type: array
                    items:
                      type: string
          description: Operations (hosts, ports, methods, paths) to match.
        when:
          type: array
          items:
            type: object
            properties:
              key:
                type: string
                description: The name of an Istio attribute (e.g. request.headers[X-Custom]).
              values:
                type: array
                items:
                  type: string
              notValues:
                type: array
                items:
                  type: string
          description: Additional conditions to match.
    AuthorizationPolicy:
      type: object
      properties:
        apiVersion:
          type: string
          enum:
          - security.istio.io/v1
        kind:
          type: string
          enum:
          - AuthorizationPolicy
        metadata:
          $ref: '#/components/schemas/ObjectMeta'
        spec:
          type: object
          properties:
            selector:
              type: object
              properties:
                matchLabels:
                  type: object
                  additionalProperties:
                    type: string
              description: Workload selector to apply the policy to specific workloads.
            action:
              type: string
              enum:
              - ALLOW
              - DENY
              - AUDIT
              - CUSTOM
              description: The action to take when a request matches the policy rules.
            provider:
              type: object
              properties:
                name:
                  type: string
              description: Specifies the name of the extension provider. Required when action is CUSTOM.
            rules:
              type: array
              items:
                $ref: '#/components/schemas/AuthorizationRule'
              description: Rules to match for the policy. A match occurs when at least one rule is matched. An empty rule list means all requests are matched.
            targetRefs:
              type: array
              items:
                type: object
                properties:
                  kind:
                    type: string
                  group:
                    type: string
                  name:
                    type: string
              description: References to the target resources to which the policy applies.
    ListMeta:
      type: object
      properties:
        resourceVersion:
          type: string
        continue:
          type: string
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: Kubernetes API server bearer token authentication
externalDocs:
  description: Istio Extensions Configuration Reference
  url: https://istio.io/latest/docs/reference/config/