NeuVector Admission API

Admission Control

Operations 12

GET /v1/admission/options Get a list of admission options #
GET /v1/admission/rule/{id} Show an admission rule #
DELETE /v1/admission/rule/{id} Delete an admission rule #
POST /v1/admission/rule Add admission control rule #
PATCH /v1/admission/rule Update admission rule #
POST /v1/admission/rule/promote Promote admission control rule #
GET /v1/admission/rules Get a list of admission rules #
DELETE /v1/admission/rules Delete all admission rules #
GET /v1/admission/state Get admission state #
PATCH /v1/admission/state Update admission state #
GET /v1/admission/stats Get admission control statistics #
POST /v1/assess/admission/rule Test admission control rules #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/neuvector-admission-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

neuvector-admission-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  description: Secure Docker and Kubernetes based container deployments with the NeuVector run-time security solution.
  version: 5.6.0
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: NeuVector Admission API
  contact:
    email: support@neuvector.com
tags:
- name: Admission
  description: Admission Control
paths:
  /v1/admission/options:
    get:
      tags:
      - Admission
      summary: Get a list of admission options
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmissionConfigData'
      operationId: getV1AdmissionOptions
      x-operation-id-source: derived
  /v1/admission/rule/{id}:
    get:
      tags:
      - Admission
      summary: Show an admission rule
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      parameters:
      - in: path
        name: id
        description: Rule ID
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmissionRuleData'
      operationId: getV1AdmissionRuleById
      x-operation-id-source: derived
    delete:
      tags:
      - Admission
      summary: Delete an admission rule
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      parameters:
      - in: path
        name: id
        description: Rule ID
        required: true
        schema:
          type: string
      responses:
        '200':
          description: Success
      operationId: deleteV1AdmissionRuleById
      x-operation-id-source: derived
  /v1/admission/rule:
    post:
      tags:
      - Admission
      summary: Add admission control rule
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmissionRuleData'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RESTAdmissionRuleConfigData'
        description: Admission rule data
        required: true
      operationId: postV1AdmissionRule
      x-operation-id-source: derived
    patch:
      tags:
      - Admission
      summary: Update admission rule
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RESTAdmissionRuleConfigData'
        description: Admission rule data
        required: true
      operationId: patchV1AdmissionRule
      x-operation-id-source: derived
  /v1/admission/rule/promote:
    post:
      tags:
      - Admission
      summary: Promote admission control rule
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RESTAdmCtrlPromoteRequestData'
        description: Admission control rule data
        required: true
      operationId: postV1AdmissionRulePromote
      x-operation-id-source: derived
  /v1/admission/rules:
    get:
      tags:
      - Admission
      summary: Get a list of admission rules
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      parameters:
      - in: query
        name: scope
        required: false
        description: When set to fed, returned fed admission rules. When set to local, returned local admission rules. If there is no query string 'scope', all admission rules will be returned.
        schema:
          type: string
          enum:
          - fed
          - local
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmissionRulesData'
      operationId: getV1AdmissionRules
      x-operation-id-source: derived
    delete:
      tags:
      - Admission
      summary: Delete all admission rules
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      parameters:
      - in: query
        name: scope
        required: false
        description: When set to fed, fed admission rules get removed. When set to local or no query string, local admission rules will be removed.
        schema:
          type: string
          enum:
          - fed
          - local
      responses:
        '200':
          description: Success
      operationId: deleteV1AdmissionRules
      x-operation-id-source: derived
  /v1/admission/state:
    get:
      tags:
      - Admission
      summary: Get admission state
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmissionConfigData'
        '404':
          description: Operation not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTError'
      operationId: getV1AdmissionState
      x-operation-id-source: derived
    patch:
      tags:
      - Admission
      summary: Update admission state
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
        '404':
          description: Operation not allowed
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTError'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RESTAdmissionConfigData'
        description: Admission config state data
        required: true
      operationId: patchV1AdmissionState
      x-operation-id-source: derived
  /v1/admission/stats:
    get:
      tags:
      - Admission
      summary: Get admission control statistics
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmissionStatsData'
      operationId: getV1AdmissionStats
      x-operation-id-source: derived
  /v1/assess/admission/rule:
    post:
      tags:
      - Admission
      description: Testing admission control rules. The payload body is the content of a resource yaml file.
      summary: Test admission control rules
      security:
      - ApiKeyAuth: []
      - TokenAuth: []
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/RESTAdmCtrlRulesTestResults'
      requestBody:
        content:
          text/plain; charset=utf-8:
            schema:
              type: string
              example: "apiVersion: apps/v1\nkind: Deployment\nmetadata:\n  name: nginx-deployment\n  labels:\n    app: nginx\nspec:\n  replicas: 3\n  selector:\n    matchLabels:\n      app: nginx\n  template:\n    metadata:\n      labels:\n        app: nginx\n    spec:\n      containers:\n        - name: nginx\n          image: nginx:latest\n          ports:\n            - containerPort: 80\n"
        description: Resource yaml file
        required: true
      operationId: postV1AssessAdmissionRule
      x-operation-id-source: derived
components:
  schemas:
    RESTAdminCustomCriteriaOptions:
      type: object
      required:
      - ops
      - valuetype
      properties:
        ops:
          type: array
          items:
            type: string
          example:
          - exist
          - notExist
        values:
          type: array
          items:
            type: string
          example:
          - 'true'
          - 'false'
        valuetype:
          type: string
          example: key
    RESTAdmissionStats:
      type: object
      required:
      - k8s_allowed_requests
      - k8s_denied_requests
      - k8s_erroneous_requests
      - k8s_ignored_requests
      - jenkins_allowed_requests
      - jenkins_denied_requests
      - jenkins_erroneous_requests
      properties:
        k8s_allowed_requests:
          type: integer
          format: int64
          example: 2
        k8s_denied_requests:
          type: integer
          format: int64
          example: 1
        k8s_erroneous_requests:
          type: integer
          format: int64
          example: 1
        k8s_ignored_requests:
          type: integer
          format: int64
          example: 1
        jenkins_allowed_requests:
          type: integer
          format: int64
          example: 3
        jenkins_denied_requests:
          type: integer
          format: int64
          example: 1
        jenkins_erroneous_requests:
          type: integer
          format: int64
          example: 1
    RESTImportTaskData:
      type: object
      required:
      - data
      properties:
        data:
          $ref: '#/components/schemas/RESTImportTask'
    RESTAdmRuleCriterion:
      type: object
      required:
      - name
      - op
      - value
      properties:
        name:
          type: string
          example: namespace
        op:
          type: string
          example: '='
        value:
          type: string
          example: kube-system
        sub_criteria:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmRuleCriterion'
        type:
          type: string
          example: customPath
        template_kind:
          type: string
          example: podTemplate
        path:
          type: string
          example: item.spec.serviceAccountName
        value_type:
          type: string
          example: string
    RESTAdmissionRuleData:
      type: object
      required:
      - rule
      properties:
        rule:
          $ref: '#/components/schemas/RESTAdmissionRule'
    RESTImportTask:
      type: object
      required:
      - tid
      - ctrler_id
      - percentage
      properties:
        tid:
          type: string
          example: c5af897b62a258212ece91c0551d3a4a
        ctrler_id:
          type: string
          example: 6e60452b244b90456f3450c9fed0a50f57f4b849dcb74a5fad289e8116f32f36
        last_update_time:
          type: string
          format: date-time
          example: '2022-03-17T17:31:55.832768041Z'
        percentage:
          type: integer
          example: 100
        triggered_by:
          type: string
          example: admin
        status:
          type: string
          example: done
        temp_token:
          type: string
          example: ''
        fail_to_decrypt_key_fields:
          type: object
          description: Object key is kv key and value is array of cloaked fields that cannot be decrypted
          additionalProperties:
            type: array
            items:
              type: string
            example:
            - x509_cert
            - signing_cert
    RESTError:
      type: object
      required:
      - code
      - error
      - message
      properties:
        code:
          type: integer
          example: 3
        error:
          type: string
          example: Request failed
        message:
          type: string
          example: Invalid format
        password_profile_basic:
          $ref: '#/components/schemas/RESTPwdProfileBasic'
        import_task_data:
          $ref: '#/components/schemas/RESTImportTaskData'
    RESTAdmissionConfigData:
      type: object
      required:
      - k8s_env
      properties:
        state:
          $ref: '#/components/schemas/RESTAdmissionState'
        admission_options:
          $ref: '#/components/schemas/RESTAdmRuleTypeOptions'
        k8s_env:
          type: boolean
          example: false
        admission_custom_criteria_options:
          $ref: '#/components/schemas/RESTAdminCustomCriteriaOptions'
        admission_custom_criteria_templates:
          $ref: '#/components/schemas/RESTAdminCriteriaTemplate'
        predefined_risky_roles:
          type: array
          items:
            type: string
          example:
          - risky_role_view_secret
          - risky_role_create_pod
    RESTAdmCtrlRulesTestResult:
      type: object
      required:
      - index
      - name
      - kind
      - message
      - matched_rules
      - allowed
      properties:
        index:
          type: integer
          example: 1
        name:
          type: string
          example: iperfserver
        kind:
          type: string
          example: Deployment
        message:
          type: string
          example: '<Assessment> Creation of Kubernetes Deployment is allowed [Notice: the requested image(s) are not scanned: quay.io/nvlab/iperf].'
        matched_rules:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmCtrlTestRuleInfo'
        allowed:
          type: boolean
          example: false
    RESTAdminCriteriaTemplate:
      type: object
      required:
      - kind
      - rawjson
      properties:
        kind:
          type: string
          example: podTemplate
        rawjson:
          type: string
          example: '{"key": "value"}'
    RESTAdmissionState:
      type: object
      properties:
        enable:
          type: boolean
          example: true
        mode:
          type: string
          example: Protect
        default_action:
          type: string
          example: allow
        adm_client_mode:
          type: string
          example: service
        adm_svc_type:
          type: string
          example: ''
        adm_client_mode_options:
          type: object
          properties:
            service:
              type: string
              example: service
            url:
              type: string
              example: service:xyz-svc-admission-webhook.xyz.svc
        ctrl_states:
          type: object
          properties:
            validate:
              type: string
              example: validate
            states:
              type: boolean
              example: true
    RESTAdmissionRuleConfig:
      type: object
      required:
      - id
      - category
      - cfg_type
      - rule_type
      - containers
      properties:
        id:
          type: integer
          format: uint32
          example: 1
        category:
          type: string
          example: Kubernetes
        comment:
          type: string
          example: comment
        criteria:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmRuleCriterion'
        disable:
          type: boolean
          example: true
        actions:
          type: array
          items:
            type: string
            example: ''
        cfg_type:
          type: string
          enum:
          - user_created
          - ground
          - federal
        rule_type:
          type: string
          enum:
          - exception
          - deny
        rule_mode:
          type: string
          enum:
          - ''
          - monitor
          - protect
        containers:
          type: array
          items:
            type: string
            enum:
            - containers
            - init_containers
            - ephemeral_containers
    RESTAdmRuleTypeOptions:
      type: object
      required:
      - deny_options
      - exception_options
      properties:
        deny_options:
          $ref: '#/components/schemas/RESTAdmCatOptions'
        exception_options:
          $ref: '#/components/schemas/RESTAdmCatOptions'
        psp_collection:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmRuleCriterion'
        pss_collections:
          type: object
          description: map key is domain(string type)
          additionalProperties:
            type: array
            items:
              type: string
          example:
            restricted:
            - Uses illegal volume type.
            - Allows running as root user.
            baseline:
            - Sets HostNetwork, HostPID, or HostIPC to true.
            - Allows privileged container(s).
        sigstore_verifiers:
          type: array
          items:
            type: string
          example:
          - public/verifier1
          - private1/verifier1
          - private1/verifier2
    RESTAdmissionRule:
      type: object
      required:
      - id
      - category
      - comment
      - criteria
      - disable
      - critical
      - cfg_type
      - rule_type
      - rule_mode
      - containers
      properties:
        id:
          type: integer
          format: uint32
          example: 2
        category:
          type: string
          example: Kubernetes
        comment:
          type: string
          example: Do not delete this exception rule
        criteria:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmRuleCriterion'
        disable:
          type: boolean
          example: false
        critical:
          type: boolean
          example: false
        cfg_type:
          type: string
          enum:
          - user_created
          - ground
          - federal
        rule_type:
          type: string
          enum:
          - exception
          - deny
        rule_mode:
          type: string
          enum:
          - ''
          - monitor
          - protect
        containers:
          type: array
          items:
            type: string
            enum:
            - containers
            - init_containers
            - ephemeral_containers
    RESTAdmCtrlRulesTestResults:
      type: object
      properties:
        props_unavailable:
          type: array
          items:
            type: string
          example:
          - user
          - userGroups
        global_mode:
          type: string
          enum:
          - monitor
          - protect
          - ''
        results:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmCtrlRulesTestResult'
    RESTAdmissionStatsData:
      type: object
      required:
      - stats
      properties:
        stats:
          $ref: '#/components/schemas/RESTAdmissionStats'
    RESTAdmissionRulesData:
      type: object
      required:
      - rules
      properties:
        rules:
          type: array
          items:
            $ref: '#/components/schemas/RESTAdmissionRule'
    RESTPwdProfileBasic:
      type: object
      required:
      - min_len
      - min_uppercase_count
      - min_lowercase_count
      - min_digit_count
      - min_special_count
      properties:
        min_len:
          type: integer
          example: 6
        min_uppercase_count:
          type: integer
          example: 0
        min_lowercase_count:
          type: integer
          example: 0
        min_digit_count:
          type: integer
          example: 0
        min_special_count:
          type: integer
          example: 0
    RESTAdmRuleOptions:
      type: object
      required:
      - rule_options
      properties:
        rule_options:
          type: object
          properties:
            rule:
              type: string
              example: criterion_name
            options:
              $ref: '#/components/schemas/RESTAdmissionRuleOption'
    RESTAdmCtrlPromoteRequestData:
      type: object
      required:
      - request
      properties:
        request:
          $ref: '#/components/schemas/RESTAdmCtrlPromoteRequest'
    RESTAdmCtrlTestRuleInfo:
      type: object
      required:
      - container_image
      - id
      - disabled
      - type
      - mode
      - rule_details
      - rule_cfg_type
      properties:
        container_image:
          type: string
          description: the tested container image in the pod
        id:
          type: integer
          format: uint32
          example: 10001
        disabled:
          type: boolean
          example: false
        type:
          type: string
          enum:
          - allow
          - deny
        mode:
          type: string
          description: per-rule mode
          enum:
          - monitor
          - protect
          - ''
        rule_details:
          type: string
          example: 'It matches deny rule id 1000 with criteria: (allow privilege escalation = true)'
        rule_cfg_type:
          type: string
          enum:
          - federal
          - ground
          - user_created
    RESTAdmCatOptions:
      type: object
      properties:
        k8s_options:
          $ref: '#/components/schemas/RESTAdmRuleOptions'
    RESTAdmissionRuleOption:
      type: object
      required:
      - name
      - ops
      properties:
        name:
          type: string
          example: group
        ops:
          type: array
          items:
            type: string
          example:
          - containsAny
          - containsAll
          - '='
        values:
          type: array
          items:
            type: string
          example:
          - ''
          - 'true'
          - 'false'
        match_src:
          type: string
          example: yaml
        sub_options:
          type: object
          properties:
            rule:
              type: string
              example: criterion_name
            options:
              $ref: '#/components/schemas/RESTAdmissionRuleOption'
    RESTAdmissionRuleConfigData:
      type: object
      required:
      - config
      properties:
        config:
          $ref: '#/components/schemas/RESTAdmissionRuleConfig'
    RESTAdmCtrlPromoteRequest:
      type: object
      required:
      - ids
      properties:
        ids:
          type: array
          items:
            type: integer
            format: uint32
            example: 12
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-Auth-Apikey
    TokenAuth:
      type: apiKey
      in: header
      name: X-Auth-Token
externalDocs:
  description: Find out more about NeuVector
  url: https://www.suse.com/products/neuvector/