Kubernetes Config API

Configuration and storage resources including ConfigMaps, Secrets, PersistentVolumes, and PersistentVolumeClaims.

OpenAPI Specification

kubernetes-config-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Kubernetes Autoscaling Config API
  description: The Kubernetes API lets you query and manipulate the state of objects in Kubernetes. The core of Kubernetes control plane is the API server and the HTTP API that it exposes. Users, the different parts of your cluster, and external components all communicate with one another through the API server. The API is a resource-based (RESTful) programmatic interface provided via HTTP that supports retrieving, creating, updating, and deleting primary resources via the standard HTTP verbs (POST, PUT, PATCH, DELETE, GET).
  version: v1.32.0
  contact:
    name: Kubernetes Community
    url: https://kubernetes.io/community/
  termsOfService: https://www.apache.org/licenses/LICENSE-2.0
servers:
- url: https://kubernetes.default.svc
  description: In-cluster Kubernetes API Server
security:
- bearerAuth: []
- clientCertificate: []
tags:
- name: Config
  description: Configuration and storage resources including ConfigMaps, Secrets, PersistentVolumes, and PersistentVolumeClaims.
paths:
  /api/v1/namespaces/{namespace}/configmaps:
    get:
      operationId: listNamespacedConfigMaps
      summary: Kubernetes List ConfigMaps in a namespace
      description: Returns a list of all ConfigMaps in the specified namespace. ConfigMaps allow you to decouple configuration from pod images so that containerized applications can be made portable.
      tags:
      - Config
      parameters:
      - $ref: '#/components/parameters/NamespaceParam'
      - $ref: '#/components/parameters/LabelSelector'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Watch'
      responses:
        '200':
          description: List of ConfigMaps
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConfigMapList'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createNamespacedConfigMap
      summary: Kubernetes Create a ConfigMap
      description: Creates a new ConfigMap in the specified namespace. ConfigMaps store non-confidential data as key-value pairs that can be consumed as environment variables, command-line arguments, or configuration files.
      tags:
      - Config
      parameters:
      - $ref: '#/components/parameters/NamespaceParam'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ConfigMap'
      responses:
        '201':
          description: ConfigMap created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConfigMap'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
  /api/v1/namespaces/{namespace}/secrets:
    get:
      operationId: listNamespacedSecrets
      summary: Kubernetes List Secrets in a namespace
      description: Returns a list of Secrets in the specified namespace. Secrets store sensitive information such as passwords, OAuth tokens, and SSH keys, with access controlled via RBAC.
      tags:
      - Config
      parameters:
      - $ref: '#/components/parameters/NamespaceParam'
      - $ref: '#/components/parameters/LabelSelector'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Watch'
      responses:
        '200':
          description: List of Secrets
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecretList'
        '401':
          $ref: '#/components/responses/Unauthorized'
    post:
      operationId: createNamespacedSecret
      summary: Kubernetes Create a Secret
      description: Creates a new Secret in the specified namespace. Secret data is stored base64-encoded and can be mounted as files or exposed as environment variables in pods.
      tags:
      - Config
      parameters:
      - $ref: '#/components/parameters/NamespaceParam'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Secret'
      responses:
        '201':
          description: Secret created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Secret'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    ObjectMeta:
      type: object
      description: Standard Kubernetes object metadata included on all persistent resources. Contains identifying information, ownership references, and system-managed fields like resourceVersion and uid.
      properties:
        name:
          type: string
          description: Unique name of the object within a namespace or cluster scope.
        namespace:
          type: string
          description: Namespace that scopes the resource name. Not all resource types are namespaced.
        uid:
          type: string
          description: Unique identifier generated by the server for this object. Remains constant for the lifetime of the object.
        resourceVersion:
          type: string
          description: Opaque string that identifies an internal server version of the object. Used for optimistic concurrency control and watch operations.
        generation:
          type: integer
          description: Sequence number representing the generation of the desired state. Incremented by the server on spec changes.
        creationTimestamp:
          type: string
          format: date-time
          description: Timestamp when the object was created.
        deletionTimestamp:
          type: string
          format: date-time
          description: Time at which the object will be deleted. Set by the server when a delete is requested.
        labels:
          type: object
          additionalProperties:
            type: string
          description: Map of string keys and values to organize and select resources. Labels are queryable via label selectors.
        annotations:
          type: object
          additionalProperties:
            type: string
          description: Map of non-identifying metadata. Annotations may contain arbitrary data and are not queryable by the API.
        ownerReferences:
          type: array
          description: List of objects that own this object. Garbage collection will delete this object when all owners are deleted.
          items:
            $ref: '#/components/schemas/OwnerReference'
    OwnerReference:
      type: object
      description: Reference to an owning resource that manages this object's lifecycle via garbage collection.
      required:
      - apiVersion
      - kind
      - name
      - uid
      properties:
        apiVersion:
          type: string
          description: API version of the owner resource.
        kind:
          type: string
          description: Kind of the owner resource.
        name:
          type: string
          description: Name of the owner resource.
        uid:
          type: string
          description: UID of the owner resource.
        controller:
          type: boolean
          description: Whether this reference points to the managing controller.
    ConfigMap:
      type: object
      description: A ConfigMap holds non-confidential configuration data as key-value pairs. Pods can consume ConfigMaps as environment variables, command-line arguments, or configuration files in a volume.
      properties:
        apiVersion:
          type: string
          const: v1
        kind:
          type: string
          const: ConfigMap
        metadata:
          $ref: '#/components/schemas/ObjectMeta'
        data:
          type: object
          additionalProperties:
            type: string
          description: Map of UTF-8 string data. Use binaryData for binary content.
        binaryData:
          type: object
          additionalProperties:
            type: string
            format: byte
          description: Map of binary data. Keys must not overlap with data keys.
    Status:
      type: object
      description: Status is a return value for calls that don't return other objects. It is used to convey error messages, reasons, and codes for both success and failure responses.
      properties:
        apiVersion:
          type: string
        kind:
          type: string
          const: Status
        code:
          type: integer
          description: HTTP status code.
        message:
          type: string
          description: Human-readable description of the status.
        reason:
          type: string
          description: Machine-readable description of why the operation is in this status.
        status:
          type: string
          enum:
          - Success
          - Failure
          description: Outcome of the operation.
    Secret:
      type: object
      description: A Secret stores sensitive information such as passwords, OAuth tokens, and TLS certificates. Secret data is base64-encoded and access is controlled via RBAC.
      properties:
        apiVersion:
          type: string
          const: v1
        kind:
          type: string
          const: Secret
        metadata:
          $ref: '#/components/schemas/ObjectMeta'
        type:
          type: string
          description: 'Type of secret. Common types: Opaque (generic), kubernetes.io/tls, kubernetes.io/service-account-token, kubernetes.io/dockerconfigjson.'
          default: Opaque
        data:
          type: object
          additionalProperties:
            type: string
            format: byte
          description: Map of base64-encoded secret data.
        stringData:
          type: object
          additionalProperties:
            type: string
          description: Map of plain-text string data. Values are encoded to base64 before storage. Takes precedence over data for matching keys.
    ConfigMapList:
      type: object
      description: A list of ConfigMaps returned by list operations.
      required:
      - items
      properties:
        apiVersion:
          type: string
        kind:
          type: string
          const: ConfigMapList
        metadata:
          $ref: '#/components/schemas/ListMeta'
        items:
          type: array
          items:
            $ref: '#/components/schemas/ConfigMap'
    ListMeta:
      type: object
      description: Metadata that all list responses include, containing pagination state and the resource version of the list.
      properties:
        resourceVersion:
          type: string
          description: Resource version of the list for use in watch operations.
        continue:
          type: string
          description: Token used to retrieve the next page of results in a paginated list request.
        remainingItemCount:
          type: integer
          description: Number of items remaining in the list if pagination is in effect.
    SecretList:
      type: object
      description: A list of Secrets returned by list operations.
      required:
      - items
      properties:
        apiVersion:
          type: string
        kind:
          type: string
          const: SecretList
        metadata:
          $ref: '#/components/schemas/ListMeta'
        items:
          type: array
          items:
            $ref: '#/components/schemas/Secret'
  parameters:
    LabelSelector:
      name: labelSelector
      in: query
      description: 'Selector expression to filter resources by label. Supports equality (=, ==, !=), set-based (in, notin, exists) operations. Example: app=nginx,tier=frontend'
      schema:
        type: string
    Watch:
      name: watch
      in: query
      description: Watch for changes to the described resources and return them as a stream of add, update, and remove notifications. Specify resourceVersion to watch from a specific version.
      schema:
        type: boolean
    NamespaceParam:
      name: namespace
      in: path
      required: true
      description: The namespace name to scope the request to.
      schema:
        type: string
    Limit:
      name: limit
      in: query
      description: Maximum number of resources to return in a single response. Use with the continue parameter to paginate through large result sets.
      schema:
        type: integer
        minimum: 1
        maximum: 500
  responses:
    Unauthorized:
      description: Unauthorized — missing or invalid authentication credentials
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Status'
    BadRequest:
      description: Bad request — invalid resource specification
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Status'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Kubernetes service account token or user token issued by the cluster's authentication provider. Include in the Authorization header as 'Bearer <token>'.
    clientCertificate:
      type: mutualTLS
      description: Client certificate authentication using a TLS certificate issued by the cluster's certificate authority.
externalDocs:
  description: Kubernetes API Reference Documentation
  url: https://kubernetes.io/docs/reference/kubernetes-api/