Kuma MeshTLS API
The MeshTLS API from Kuma — 2 operation(s) for meshtls.
Documentation
Documentation
https://kuma.io/docs/latest/reference/http-api/
GettingStarted
https://kuma.io/docs/latest/installation/
The MeshTLS API from Kuma — 2 operation(s) for meshtls.
openapi: 3.1.0
info:
title: Kuma Dataplane MeshTLS API
description: Kuma API
version: v1alpha1
x-ref-schema-name: DataplaneOverview
security:
- BasicAuth: []
- BearerAuth: []
- {}
tags:
- name: MeshTLS
paths:
/meshes/{mesh}/meshtlses/{name}:
get:
operationId: getMeshTLS
summary: Returns MeshTLS entity
tags:
- MeshTLS
parameters:
- in: path
name: mesh
schema:
type: string
required: true
description: name of the mesh
- in: path
name: name
schema:
type: string
required: true
description: name of the MeshTLS
responses:
'200':
$ref: '#/components/responses/MeshTLSItem'
'404':
$ref: '#/components/responses/NotFound'
put:
operationId: putMeshTLS
summary: Creates or Updates MeshTLS entity
tags:
- MeshTLS
parameters:
- in: path
name: mesh
schema:
type: string
required: true
description: name of the mesh
- in: path
name: name
schema:
type: string
required: true
description: name of the MeshTLS
requestBody:
description: Put request
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/MeshTLSItem'
responses:
'200':
$ref: '#/components/responses/MeshTLSCreateOrUpdateSuccessResponse'
'201':
$ref: '#/components/responses/MeshTLSCreateOrUpdateSuccessResponse'
delete:
operationId: deleteMeshTLS
summary: Deletes MeshTLS entity
tags:
- MeshTLS
parameters:
- in: path
name: mesh
schema:
type: string
required: true
description: name of the mesh
- in: path
name: name
schema:
type: string
required: true
description: name of the MeshTLS
responses:
'200':
$ref: '#/components/responses/MeshTLSDeleteSuccessResponse'
'404':
$ref: '#/components/responses/NotFound'
/meshes/{mesh}/meshtlses:
get:
operationId: getMeshTLSList
summary: Returns a list of MeshTLS in the mesh.
tags:
- MeshTLS
parameters:
- in: query
name: offset
description: offset in the list of entities
required: false
schema:
type: integer
example: 0
- in: query
name: size
description: the number of items per page
required: false
schema:
type: integer
default: 100
maximum: 1000
minimum: 1
- in: query
name: filter
description: filter by labels when multiple filters are present, they are ANDed
required: false
schema:
type: object
properties:
key:
type: string
value:
type: string
example:
label.k8s.kuma.io/namespace: my-ns
- in: path
name: mesh
schema:
type: string
required: true
description: name of the mesh
responses:
'200':
$ref: '#/components/responses/MeshTLSList'
components:
responses:
MeshTLSList:
description: List
content:
application/json:
schema:
type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/MeshTLSItem'
total:
type: number
description: The total number of entities
next:
type: string
description: URL to the next page
NotFound:
description: Not Found
content:
application/problem+json:
schema:
$ref: '#/components/schemas/NotFoundError'
MeshTLSCreateOrUpdateSuccessResponse:
description: Successful response
content:
application/json:
schema:
type: object
properties:
warnings:
type: array
readOnly: true
description: 'warnings is a list of warning messages to return to the requesting Kuma API clients.
Warning messages describe a problem the client making the API request should correct or be aware of.
'
items:
type: string
MeshTLSDeleteSuccessResponse:
description: Successful response
content:
application/json:
schema:
type: object
MeshTLSItem:
description: Successful response
content:
application/json:
schema:
$ref: '#/components/schemas/MeshTLSItem'
schemas:
NotFoundError:
allOf:
- $ref: '#/components/schemas/Error'
- type: object
properties:
status:
type: integer
enum:
- 404
example: 404
description: 'The HTTP status code for NotFoundError MUST be 404.
'
title:
type: string
example: Not Found
type:
type: string
example: https://httpstatuses.com/404
detail:
type: string
example: The requested resource was not found
InvalidParameters:
type: object
title: Invalid Parameters
required:
- field
- reason
- source
properties:
field:
type: string
description: The name of the field that caused the error.
reason:
type: string
description: 'A short, human-readable description of the problem.
_Should_ be provided as "Sentence case" for direct use in a UI.
'
rule:
type: string
description: 'May be provided as a hint to the user to help understand the type of failure.
Additional guidance may be provided in additional fields, i.e. `choices`.
'
choices:
type: array
description: 'Optional field to provide a list of valid choices for the field that caused the error.
'
items:
type: string
source:
type: string
description: 'The location of the field that caused the error.
'
enum:
- body
- query
- header
- path
MeshTLSItem:
type: object
description: MeshTLS configures TLS and mutual TLS (mTLS) settings for secure communication between services in the mesh. It allows you to enforce encryption, configure TLS versions and cipher suites, and control whether mTLS is required (strict mode) or optional (permissive mode) for inbound traffic.
required:
- type
- name
- spec
properties:
type:
description: the type of the resource
type: string
enum:
- MeshTLS
mesh:
description: Mesh is the name of the Kuma mesh this resource belongs to. It may be omitted for cluster-scoped resources.
type: string
default: default
kri:
description: A unique identifier for this resource instance used by internal tooling and integrations. Typically derived from resource attributes and may be used for cross-references or indexing
type: string
readOnly: true
example: kri_mtls_default_zone-east_kuma-demo_mypolicy1_
name:
description: Name of the Kuma resource
type: string
labels:
additionalProperties:
type: string
description: The labels to help identity resources
type: object
spec:
description: Spec is the specification of the Kuma MeshTLS resource.
properties:
from:
description: From list makes a match between clients and corresponding configurations
items:
properties:
default:
description: 'Default is a configuration specific to the group of clients referenced in
''targetRef'''
properties:
mode:
description: Mode defines the behavior of inbound listeners with regard to traffic encryption.
enum:
- Permissive
- Strict
type: string
tlsCiphers:
description: TlsCiphers section for providing ciphers specification.
items:
enum:
- ECDHE-ECDSA-AES128-GCM-SHA256
- ECDHE-ECDSA-AES256-GCM-SHA384
- ECDHE-ECDSA-CHACHA20-POLY1305
- ECDHE-RSA-AES128-GCM-SHA256
- ECDHE-RSA-AES256-GCM-SHA384
- ECDHE-RSA-CHACHA20-POLY1305
type: string
type: array
tlsVersion:
description: Version section for providing version specification.
properties:
max:
default: TLSAuto
description: Max defines maximum supported version. One of `TLSAuto`, `TLS10`, `TLS11`, `TLS12`, `TLS13`.
enum:
- TLSAuto
- TLS10
- TLS11
- TLS12
- TLS13
type: string
min:
default: TLSAuto
description: Min defines minimum supported version. One of `TLSAuto`, `TLS10`, `TLS11`, `TLS12`, `TLS13`.
enum:
- TLSAuto
- TLS10
- TLS11
- TLS12
- TLS13
type: string
type: object
type: object
targetRef:
description: 'TargetRef is a reference to the resource that represents a group of
clients.'
properties:
kind:
description: Kind of the referenced resource
enum:
- Mesh
- MeshSubset
- MeshGateway
- MeshService
- MeshExternalService
- MeshMultiZoneService
- MeshServiceSubset
- MeshHTTPRoute
- Dataplane
type: string
labels:
additionalProperties:
type: string
description: 'Labels are used to select group of MeshServices that match labels. Either Labels or
Name and Namespace can be used.'
type: object
mesh:
description: Mesh is reserved for future use to identify cross mesh resources.
type: string
name:
description: 'Name of the referenced resource. Can only be used with kinds: `MeshService`,
`MeshServiceSubset` and `MeshGatewayRoute`'
type: string
namespace:
description: 'Namespace specifies the namespace of target resource. If empty only resources in policy namespace
will be targeted.'
type: string
proxyTypes:
description: 'ProxyTypes specifies the data plane types that are subject to the policy. When not specified,
all data plane types are targeted by the policy.'
items:
enum:
- Sidecar
- Gateway
type: string
type: array
sectionName:
description: 'SectionName is used to target specific section of resource.
For example, you can target port from MeshService.ports[] by its name. Only traffic to this port will be affected.'
type: string
tags:
additionalProperties:
type: string
description: 'Tags used to select a subset of proxies by tags. Can only be used with kinds
`MeshSubset` and `MeshServiceSubset`'
type: object
required:
- kind
type: object
required:
- targetRef
type: object
type: array
rules:
description: 'Rules defines inbound tls configurations. Currently limited to
selecting all inbound traffic, as L7 matching is not yet implemented.'
items:
properties:
default:
description: Default contains configuration of the inbound tls
properties:
mode:
description: Mode defines the behavior of inbound listeners with regard to traffic encryption.
enum:
- Permissive
- Strict
type: string
tlsCiphers:
description: TlsCiphers section for providing ciphers specification.
items:
enum:
- ECDHE-ECDSA-AES128-GCM-SHA256
- ECDHE-ECDSA-AES256-GCM-SHA384
- ECDHE-ECDSA-CHACHA20-POLY1305
- ECDHE-RSA-AES128-GCM-SHA256
- ECDHE-RSA-AES256-GCM-SHA384
- ECDHE-RSA-CHACHA20-POLY1305
type: string
type: array
tlsVersion:
description: Version section for providing version specification.
properties:
max:
default: TLSAuto
description: Max defines maximum supported version. One of `TLSAuto`, `TLS10`, `TLS11`, `TLS12`, `TLS13`.
enum:
- TLSAuto
- TLS10
- TLS11
- TLS12
- TLS13
type: string
min:
default: TLSAuto
description: Min defines minimum supported version. One of `TLSAuto`, `TLS10`, `TLS11`, `TLS12`, `TLS13`.
enum:
- TLSAuto
- TLS10
- TLS11
- TLS12
- TLS13
type: string
type: object
type: object
type: object
type: array
targetRef:
description: 'TargetRef is a reference to the resource the policy takes an effect on.
The resource could be either a real store object or virtual resource
defined in-place.'
properties:
kind:
description: Kind of the referenced resource
enum:
- Mesh
- MeshSubset
- MeshGateway
- MeshService
- MeshExternalService
- MeshMultiZoneService
- MeshServiceSubset
- MeshHTTPRoute
- Dataplane
type: string
labels:
additionalProperties:
type: string
description: 'Labels are used to select group of MeshServices that match labels. Either Labels or
Name and Namespace can be used.'
type: object
mesh:
description: Mesh is reserved for future use to identify cross mesh resources.
type: string
name:
description: 'Name of the referenced resource. Can only be used with kinds: `MeshService`,
`MeshServiceSubset` and `MeshGatewayRoute`'
type: string
namespace:
description: 'Namespace specifies the namespace of target resource. If empty only resources in policy namespace
will be targeted.'
type: string
proxyTypes:
description: 'ProxyTypes specifies the data plane types that are subject to the policy. When not specified,
all data plane types are targeted by the policy.'
items:
enum:
- Sidecar
- Gateway
type: string
type: array
sectionName:
description: 'SectionName is used to target specific section of resource.
For example, you can target port from MeshService.ports[] by its name. Only traffic to this port will be affected.'
type: string
tags:
additionalProperties:
type: string
description: 'Tags used to select a subset of proxies by tags. Can only be used with kinds
`MeshSubset` and `MeshServiceSubset`'
type: object
required:
- kind
type: object
type: object
creationTime:
readOnly: true
type: string
description: Time at which the resource was created
format: date-time
example: '0001-01-01T00:00:00Z'
modificationTime:
readOnly: true
type: string
description: Time at which the resource was updated
format: date-time
example: '0001-01-01T00:00:00Z'
Error:
type: object
title: Error
description: 'Standard error. Follows the [AIP #193 - Errors](https://kong-aip.netlify.app/aip/193/) specification.
'
x-examples:
Example 1:
status: 404
title: Not Found
type: https://kongapi.info/konnect/not-found
instance: portal:trace:2287285207635123011
detail: The requested document was not found
required:
- status
- title
- instance
- type
- detail
properties:
status:
type: integer
description: The HTTP status code.
example: 404
title:
type: string
description: 'A short, human-readable summary of the problem.
It **should not** change between occurrences of a problem, except for localization.
Should be provided as "Sentence case" for potential direct use in a UI
'
example: Not Found
type:
type: string
description: 'A unique identifier for this error. When dereferenced it must provide human-readable documentation for the problem.
'
example: Not Found
instance:
type: string
example: portal:trace:2287285207635123011
description: 'Used to return the correlation ID back to the user, in the format `<app>:trace:<correlation_id>`.
'
detail:
type: string
example: The requested team was not found
description: 'A human readable explanation specific to this occurrence of the problem.
This field may contain request/entity data to help the user understand what went wrong.
Enclose variable values in square brackets.
_Should_ be provided as "Sentence case" for direct use in a UI
'
invalid_parameters:
type: array
description: 'All 400 errors **MUST** return an `invalid_parameters` key in the response.
Used to indicate which fields have invalid values when validated.
'
items:
$ref: '#/components/schemas/InvalidParameters'
securitySchemes:
BasicAuth:
type: http
scheme: basic
BearerAuth:
type: http
scheme: bearer