Kong System Accounts - Roles API

The System Accounts - Roles API from Kong — 2 operation(s) for system accounts - roles.

OpenAPI Specification

kong-system-accounts-roles-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API.


    You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com).

    Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.'
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: Kong Enterprise Admin ACLs System Accounts - Roles API
  version: 3.14.0
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
security:
- adminToken: []
tags:
- name: System Accounts - Roles
paths:
  /v3/system-accounts/{accountId}/assigned-roles:
    parameters:
    - name: accountId
      in: path
      description: ID of the system account.
      required: true
      schema:
        type: string
    get:
      operationId: get-system-accounts-accountId-assigned-roles
      summary: List Assigned Roles for System Account
      description: Lists the roles belonging to a system account. Returns 400 if any filter parameters are invalid.
      parameters:
      - name: filter
        in: query
        description: Filter roles returned in the response.
        required: false
        schema:
          type: object
          properties:
            entity_id:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
            role_name:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
            entity_type_name:
              $ref: '#/components/schemas/StringFieldEqualsFilter'
        style: deepObject
      responses:
        '200':
          $ref: '#/components/responses/AssignedRoleCollection'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - System Accounts - Roles
    post:
      x-speakeasy-entity-operation:
        terraform-resource: SystemAccountRole#create
        terraform-datasource: null
      operationId: post-system-accounts-accountId-assigned-roles
      summary: Create Assigned Role for System Account
      description: Assigns a role to a system account. Returns 409 if role is already assigned.
      requestBody:
        $ref: '#/components/requestBodies/AssignRole'
      responses:
        '201':
          $ref: '#/components/responses/AssignedRoleSingle'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
        '409':
          $ref: '#/components/responses/IdentityConflict'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - System Accounts - Roles
  /v3/system-accounts/{accountId}/assigned-roles/{roleId}:
    parameters:
    - name: accountId
      in: path
      description: ID of the system account.
      required: true
      schema:
        type: string
    - name: roleId
      in: path
      description: ID of the role.
      required: true
      schema:
        type: string
      x-speakeasy-match: id
    get:
      x-speakeasy-entity-operation:
        terraform-resource: SystemAccountRole#read
        terraform-datasource: null
      operationId: get-system-account-role
      summary: Get System Account Role
      description: Returns the assigned role for the specified ID.
      responses:
        '200':
          $ref: '#/components/responses/AssignedRoleSingle'
        '400':
          $ref: '#/components/responses/IdentityBadRequest'
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/IdentityPermissionDenied'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - System Accounts - Roles
    delete:
      x-speakeasy-entity-operation:
        terraform-resource: SystemAccountRole#delete
        terraform-datasource: null
      operationId: delete-system-accounts-accountId-assigned-roles-roleId
      summary: Delete Assigned Role from System Account
      description: Removes an assigned role from a system account. Returns 404 if the system account or assigned role were not found.
      responses:
        '204':
          description: No Content
        '401':
          $ref: '#/components/responses/IdentityUnauthenticated'
        '403':
          $ref: '#/components/responses/Unauthorized'
        '404':
          $ref: '#/components/responses/IdentityNotFound'
      servers:
      - url: https://global.api.konghq.com/
      tags:
      - System Accounts - Roles
components:
  schemas:
    InvalidParameterMinimumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - min_length
          - min_digits
          - min_lowercase
          - min_uppercase
          - min_symbols
          - min_items
          - min
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - minimum
    StringFieldEqualsFilter:
      description: Filters on the given string field value by exact match.
      properties:
        eq:
          type: string
      title: StringFieldEqualsFilter
    InvalidParameterChoiceItem:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - enum
          nullable: false
          readOnly: true
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          items: {}
          minItems: 1
          nullable: false
          readOnly: true
          uniqueItems: true
        source:
          type: string
          example: body
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - choices
    ConflictError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 409
          title:
            example: Conflict
          type:
            example: https://httpstatuses.com/409
          instance:
            example: kong:trace:1234567890
          detail:
            example: Conflict
    InvalidParameterMaximumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - max_length
          - max_items
          - max
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - maximum
    ForbiddenError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 403
          title:
            example: Forbidden
          type:
            example: https://httpstatuses.com/403
          instance:
            example: kong:trace:1234567890
          detail:
            example: Forbidden
    UnauthorizedError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 401
          title:
            example: Unauthorized
          type:
            example: https://httpstatuses.com/401
          instance:
            example: kong:trace:1234567890
          detail:
            example: Invalid credentials
    PaginatedMeta:
      description: returns the pagination information
      type: object
      properties:
        page:
          $ref: '#/components/schemas/PageMeta'
      required:
      - page
      title: PaginatedMeta
      x-speakeasy-terraform-ignore: true
    BaseError:
      description: standard error
      type: object
      properties:
        status:
          description: 'The HTTP status code of the error. Useful when passing the response

            body to child properties in a frontend UI. Must be returned as an integer.

            '
          type: integer
          readOnly: true
        title:
          description: 'A short, human-readable summary of the problem. It should not

            change between occurences of a problem, except for localization.

            Should be provided as "Sentence case" for direct use in the UI.

            '
          type: string
          readOnly: true
        type:
          description: The error type.
          type: string
          readOnly: true
        instance:
          description: 'Used to return the correlation ID back to the user, in the format

            kong:trace:<correlation_id>. This helps us find the relevant logs

            when a customer reports an issue.

            '
          type: string
          readOnly: true
        detail:
          description: 'A human readable explanation specific to this occurence of the problem.

            This field may contain request/entity data to help the user understand

            what went wrong. Enclose variable values in square brackets. Should be

            provided as "Sentence case" for direct use in the UI.

            '
          type: string
          readOnly: true
      required:
      - status
      - title
      - instance
      - detail
      title: Error
    InvalidParameterDependentItem:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - dependent_fields
          nullable: true
          readOnly: true
        reason:
          type: string
          example: is a required field
          readOnly: true
        dependents:
          type: array
          items: {}
          nullable: true
          readOnly: true
          uniqueItems: true
        source:
          type: string
          example: body
      additionalProperties: false
      required:
      - field
      - rule
      - reason
      - dependents
    InvalidRules:
      description: invalid parameters rules
      type: string
      enum:
      - required
      - is_array
      - is_base64
      - is_boolean
      - is_date_time
      - is_integer
      - is_null
      - is_number
      - is_object
      - is_string
      - is_uuid
      - is_fqdn
      - is_arn
      - unknown_property
      - missing_reference
      - is_label
      - matches_regex
      - invalid
      - is_supported_network_availability_zone_list
      - is_supported_network_cidr_block
      - is_supported_provider_region
      - type
      nullable: true
      readOnly: true
      x-speakeasy-unknown-values: allow
    InvalidParameters:
      description: invalid parameters
      type: array
      items:
        oneOf:
        - $ref: '#/components/schemas/InvalidParameterStandard'
        - $ref: '#/components/schemas/InvalidParameterMinimumLength'
        - $ref: '#/components/schemas/InvalidParameterMaximumLength'
        - $ref: '#/components/schemas/InvalidParameterChoiceItem'
        - $ref: '#/components/schemas/InvalidParameterDependentItem'
      minItems: 1
      nullable: false
      uniqueItems: true
    BadRequestError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        required:
        - invalid_parameters
        properties:
          invalid_parameters:
            $ref: '#/components/schemas/InvalidParameters'
    InvalidParameterStandard:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          $ref: '#/components/schemas/InvalidRules'
        source:
          type: string
          example: body
        reason:
          type: string
          example: is a required field
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
    PageMeta:
      description: Contains pagination query parameters and the total number of objects returned.
      type: object
      properties:
        number:
          type: number
          example: 1
          x-speakeasy-terraform-ignore: true
        size:
          type: number
          example: 10
          x-speakeasy-terraform-ignore: true
        total:
          type: number
          example: 100
          x-speakeasy-terraform-ignore: true
      required:
      - number
      - size
      - total
    NotFoundError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 404
          title:
            example: Not Found
          type:
            example: https://httpstatuses.com/404
          instance:
            example: kong:trace:1234567890
          detail:
            example: Not found
    AssignedRole:
      description: An assigned role is a role that has been assigned to a user or team.
      type: object
      properties:
        id:
          description: The ID of the role assignment.
          type: string
          format: uuid
          example: eaf7adf1-32c8-4bbf-b960-d1f8456afe67
        role_name:
          description: Name of the role being assigned.
          type: string
          example: Viewer
        entity_id:
          description: A RBAC entity ID.
          type: string
          format: uuid
          example: 817d0422-45c9-4d88-8d64-45aef05c1ae7
        entity_type_name:
          description: Name of the entity type the role is being assigned to.
          type: string
          example: Control Planes
        entity_region:
          description: Region of the entity.
          type: string
          example: eu
          enum:
          - us
          - eu
          - au
          - me
          - in
          - sg
          - '*'
          x-speakeasy-unknown-values: allow
      example:
        id: 54cc6168-ebb1-4300-8168-d62a0dd08fc8
        role_name: Viewer
        entity_id: 18ee2573-dec0-4b83-be99-fa7700bcdc61
        entity_type_name: Control Planes
        entity_region: us
      title: AssignedRole
  responses:
    IdentityPermissionDenied:
      description: Permission denied
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ForbiddenError'
    IdentityConflict:
      description: Conflict
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/ConflictError'
    IdentityUnauthenticated:
      description: Unauthenticated
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/UnauthorizedError'
    AssignedRoleSingle:
      description: A get action response of a single assigned role.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/AssignedRole'
    Unauthorized:
      description: Unauthorized
      content:
        application/problem+json:
          schema:
            description: The error response object.
            type: object
            properties:
              status:
                description: The HTTP status code.
                type: integer
                example: 403
              title:
                description: The Error Response.
                type: string
                example: Unauthorized
              instance:
                description: The Konnect traceback code.
                type: string
                example: konnect:trace:952172606039454040
              detail:
                description: Details about the error response.
                type: string
                example: You do not have permission to perform this action
            $ref: '#/components/schemas/UnauthorizedError'
            title: Unauthorized Response
    AssignedRoleCollection:
      description: A paginated list response for a collection of assigned roles.
      content:
        application/json:
          schema:
            type: object
            properties:
              meta:
                $ref: '#/components/schemas/PaginatedMeta'
              data:
                description: An Array
                type: array
                items:
                  $ref: '#/components/schemas/AssignedRole'
            title: Assigned Role Collection Response
    IdentityBadRequest:
      description: Bad Request
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/BadRequestError'
    IdentityNotFound:
      description: Not Found
      content:
        application/problem+json:
          schema:
            $ref: '#/components/schemas/NotFoundError'
  requestBodies:
    AssignRole:
      content:
        application/json:
          schema:
            description: An assigned role is a role that has been assigned to a user or team.
            type: object
            properties:
              role_name:
                description: The desired role.
                type: string
                example: Viewer
                enum:
                - Admin
                - Appearance Maintainer
                - Application Registration
                - Certificate Admin
                - Cloud Gateway Cluster Admin
                - Cloud Gateway Cluster Viewer
                - Consumer Admin
                - Connector
                - Creator
                - Debug Session Creator
                - Deployer
                - Discovery Admin
                - Discovery Viewer
                - Editor
                - Gateway Service Admin
                - Integration Admin
                - Integration Viewer
                - Key Admin
                - Maintainer
                - Network Admin
                - Network Creator
                - Network Viewer
                - Plugin Admin
                - Plugins Admin
                - Product Publisher
                - Publisher
                - Route Admin
                - SNI Admin
                - Scorecard Admin
                - Scorecard Viewer
                - Service Admin
                - Service Creator
                - Service Viewer
                - Upstream Admin
                - Vault Admin
                - Viewer
                - Registration Approver
                - Content Editor
                - Add On Admin
                - Add On Viewer
                x-speakeasy-unknown-values: allow
              entity_id:
                description: The ID of the entity.
                type: string
                format: uuid
                example: e67490ce-44dc-4cbd-b65e-b52c746fc26a
              entity_type_name:
                description: The type of entity.
                type: string
                example: Control Planes
                enum:
                - Add Ons
                - APIs
                - API Products
                - Application Auth Strategies
                - Audit Logs
                - Control Planes
                - Dashboards
                - DCR Providers
                - Identity
                - Mesh Control Planes
                - Networks
                - Portals
                - Reports
                - Service Hub
                x-speakeasy-unknown-values: allow
              entity_region:
                description: Region of the team.
                type: string
                example: eu
                enum:
                - us
                - eu
                - au
                - me
                - in
                - sg
                - '*'
                x-speakeasy-unknown-values: allow
      description: The request schema for assigning a role.
  securitySchemes:
    adminToken:
      in: header
      name: Kong-Admin-Token
      type: apiKey
externalDocs:
  description: Documentation for Kong Gateway and its APIs
  url: https://developer.konghq.com