Pulumi PolicyResults API

The PolicyResults API from Pulumi — 8 operation(s) for policyresults.

OpenAPI Specification

pulumi-policyresults-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  description: APIs and Definitions for the Pulumi Cloud product.
  title: Pulumi APIs AccessTokens PolicyResults API
  version: 1.0.0
tags:
- name: PolicyResults
paths:
  /api/orgs/{orgName}/policyresults/compliance:
    post:
      description: Returns compliance results for policy issues grouped by entity. The grouping can be by stack, cloud account, or severity, providing different views of the organization's policy compliance posture. This powers the compliance dashboard in the Pulumi Cloud console.
      operationId: GetPolicyComplianceResults
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/GetPolicyComplianceResultsRequest'
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetPolicyComplianceResultsResponse'
          description: OK
        '400':
          description: Invalid entity parameter. Must be 'stack', 'account', or 'severity'
        '404':
          description: Organization not found
      summary: GetPolicyComplianceResults
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/issues:
    post:
      description: Returns all policy issues for an organization with support for pagination and advanced filtering via the grid request format. Policy issues represent violations detected by Policy Packs during stack updates or continuous compliance scans. Each issue includes the violating resource, policy details, enforcement level (advisory or mandatory), severity, and triage status.
      operationId: ListPolicyIssues
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AngularGridGetRowsRequest'
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListPolicyIssuesResponse'
          description: OK
        '400':
          description: Invalid filter parameters
        '404':
          description: Organization not found
      summary: ListPolicyIssues
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/issues/export:
    post:
      description: Exports policy issues for an organization to CSV format for offline analysis or reporting. Policy issues represent violations detected by Policy Packs during stack updates or continuous compliance scans. The export includes issue details such as the violating resource, policy name, enforcement level, and severity.
      operationId: ExportPolicyIssues
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AngularGridGetRowsRequest'
        x-originalParamName: body
      responses:
        '200':
          content:
            text/plain:
              schema:
                type: string
          description: OK
        '400':
          description: Invalid request parameters
        '404':
          description: Organization not found
      summary: ExportPolicyIssues
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/issues/filters:
    post:
      description: Returns the available filter options for listing policy issues, such as policy pack names, enforcement levels, severity values, and resource types. This is used to populate filter dropdowns in the policy issues UI.
      operationId: GetPolicyIssuesFilters
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PolicyIssueFiltersRequest'
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyIssueFiltersResponse'
          description: OK
        '400':
          description: Field parameter is required
        '404':
          description: Organization not found
      summary: GetPolicyIssuesFilters
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/issues/{issueId}:
    get:
      description: Returns the details of a specific policy issue, including the violating resource, the policy pack and policy name that flagged the violation, the enforcement level (advisory or mandatory), severity, and the current triage status of the issue.
      operationId: GetPolicyIssue
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      - description: The issue identifier
        in: path
        name: issueId
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetPolicyIssueResponse'
          description: OK
        '404':
          description: Organization or Policy issue not found
      summary: GetPolicyIssue
      tags:
      - PolicyResults
    patch:
      description: 'Updates a policy issue''s triage status and other mutable fields. All body fields are optional — only provide the fields you want to update.


        - `status`: `open`, `in_progress`, `by_design`, `fixed`, or `ignored`

        - `priority`: `p0`, `p1`, `p2`, `p3`, or `p4`

        - `assignedTo`: username to assign the issue to, or `null` to unassign'
      operationId: UpdatePolicyIssue
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      - description: The issue identifier
        in: path
        name: issueId
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/UpdatePolicyIssueRequest'
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetPolicyIssueResponse'
          description: OK
        '400':
          description: Invalid input
        '404':
          description: Organization or Policy issue not found
      summary: UpdatePolicyIssue
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/metadata:
    get:
      description: Returns high-level policy compliance statistics for an organization, including total violation counts, breakdown by severity and enforcement level, and trends over time. This provides an overview of the organization's policy compliance posture.
      operationId: GetPolicyResultsMetadata
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyResultsMetadata'
          description: OK
        '404':
          description: Organization not found
      summary: GetPolicyResultsMetadata
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/policies:
    post:
      description: Returns policy compliance data grouped by policy pack and policy name, showing how many stacks are in compliance or violation for each individual policy rule. Supports pagination and filtering via the grid request format.
      operationId: ListPoliciesCompliance
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AngularGridGetRowsRequest'
        x-originalParamName: body
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListPoliciesComplianceResponse'
          description: OK
        '400':
          description: Invalid grid request parameters
        '404':
          description: Organization not found
      summary: ListPoliciesCompliance
      tags:
      - PolicyResults
  /api/orgs/{orgName}/policyresults/violationsv2:
    get:
      deprecated: true
      description: 'ListPolicyViolationsV2Handler gets all the policy violations for an org.

        Deprecated: Use /policyresults/issues'
      operationId: ListPolicyViolationsV2
      parameters:
      - description: The organization name
        in: path
        name: orgName
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListPolicyViolationsV2Response'
          description: OK
        '404':
          description: Organization not found
      summary: ListPolicyViolationsV2
      tags:
      - PolicyResults
      x-pulumi-route-property:
        Deprecated: true
        SupersededBy: ListPolicyIssues
        Visibility: Public
components:
  schemas:
    PolicyComplianceResult:
      description: Policy compliance result row for an entity
      properties:
        entityName:
          description: Entity name (stack name or account name)
          type: string
          x-order: 1
        scores:
          description: Array of compliance scores correlating to columns array. -1 indicates N/A
          items:
            format: int64
            type: integer
          type: array
          x-order: 2
      required:
      - entityName
      - scores
      type: object
    AngularGridFilterModel:
      description: Represents angular grid filter model.
      properties:
        colId:
          description: The col identifier
          type: string
          x-order: 2
        conditions:
          description: List of conditions
          items:
            $ref: '#/components/schemas/AngularGridFilterModel'
          type: array
          x-order: 5
        filter:
          description: The filter expression
          type: string
          x-order: 1
        filterType:
          description: The filter type
          type: string
          x-order: 3
        type:
          description: The type
          type: string
          x-order: 4
      required:
      - colId
      - filter
      - filterType
      - type
      type: object
    AppPolicyComplianceFramework:
      description: PolicyComplianceFramework represents a compliance framework that a policy belongs to.
      properties:
        name:
          description: The compliance framework name.
          type: string
          x-order: 1
        reference:
          description: The compliance framework reference.
          type: string
          x-order: 3
        specification:
          description: The compliance framework specification.
          type: string
          x-order: 4
        version:
          description: The compliance framework version.
          type: string
          x-order: 2
      type: object
    AppPolicy:
      description: Policy defines the metadata for an individual Policy within a Policy Pack.
      properties:
        configSchema:
          $ref: '#/components/schemas/AppPolicyConfigSchema'
          description: The JSON schema for the Policy's configuration.
          x-order: 6
        description:
          description: Description is used to provide more context about the purpose of the policy.
          type: string
          x-order: 3
        displayName:
          description: The display name
          type: string
          x-order: 2
        enforcementLevel:
          description: The enforcement level
          enum:
          - advisory
          - mandatory
          - remediate
          - disabled
          type: string
          x-order: 4
          x-pulumi-model-property:
            enumTypeName: AppEnforcementLevel
            enumComments: EnforcementLevel indicates how a policy should be enforced
            enumFieldComments:
            - 'Advisory is an enforcement level where the resource is still created, but a

              message is displayed to the user for informational / warning purposes.'
            - Mandatory is an enforcement level that prevents a resource from being created.
            - Remediate is an enforcement level that fixes policy issues instead of issuing diagnostics.
            - Disabled is an enforcement level that disables the policy from being enforced.
        framework:
          $ref: '#/components/schemas/AppPolicyComplianceFramework'
          description: The compliance framework that this policy belongs to.
          x-order: 8
        message:
          description: Message is the message that will be displayed to end users when they violate this policy.
          type: string
          x-order: 5
        name:
          description: Unique URL-safe name for the policy.  This is unique to a specific version of a Policy Pack.
          type: string
          x-order: 1
        remediationSteps:
          description: A description of the steps to take to remediate a policy violation.
          type: string
          x-order: 10
        severity:
          description: The severity of the policy.
          enum:
          - ''
          - low
          - medium
          - high
          - critical
          type: string
          x-order: 7
          x-pulumi-model-property:
            enumTypeName: AppPolicySeverity
            enumComments: Indicates the severity of a policy.
            enumFieldNames:
            - Unspecified
            - Low
            - Medium
            - High
            - Critical
        tags:
          description: Tags associated with the policy.
          items:
            type: string
          type: array
          x-order: 9
        url:
          description: A URL to more information about the policy.
          type: string
          x-order: 11
      required:
      - description
      - displayName
      - enforcementLevel
      - message
      - name
      type: object
    ListPolicyViolationsV2Response:
      description: Response containing a paginated list of policy violations (v2).
      properties:
        continuationToken:
          description: Continuation token for pagination
          type: string
          x-order: 2
        policyViolations:
          description: The list of policy violations
          items:
            $ref: '#/components/schemas/PolicyViolationV2'
          type: array
          x-order: 1
      required:
      - policyViolations
      type: object
    PolicyIssueFilterValue:
      description: PolicyIssueFilterValue represents a filter option with its count of matching policy issues.
      properties:
        count:
          description: The count of policy issues matching this filter value.
          format: int64
          type: integer
          x-order: 2
        name:
          description: The name of the filter value.
          type: string
          x-order: 1
      required:
      - count
      - name
      type: object
    PolicyIssueFiltersResponse:
      description: PolicyIssueFiltersResponse contains the available filter values for a given field in policy issues.
      properties:
        field:
          description: The field name for which filter values are provided.
          type: string
          x-order: 1
        values:
          description: The available filter values for the field.
          items:
            $ref: '#/components/schemas/PolicyIssueFilterValue'
          type: array
          x-order: 2
      required:
      - field
      - values
      type: object
    UserInfo:
      description: 'UserInfo contains just the display information for a user.  This information may be returned from public APIs,

        and as such this structure must not contain sensitive information.  Please refer to User for this sort of thing.'
      properties:
        avatarUrl:
          description: The URL of the user's avatar image.
          type: string
          x-order: 3
        email:
          description: 'IMPORTANT: The email address of the user is only included on a few admin-only APIs.

            For nearly all APIs that return a UserInfo object, this will not be provided.

            considered sensitive information.'
          type: string
          x-order: 4
        githubLogin:
          description: The user's login name.
          type: string
          x-order: 2
        name:
          description: The user's display name.
          type: string
          x-order: 1
      required:
      - avatarUrl
      - githubLogin
      - name
      type: object
    AppPolicyConfigSchema:
      description: PolicyConfigSchema defines the JSON schema of a particular Policy's configuration.
      properties:
        properties:
          additionalProperties:
            type: object
          description: Config property name to JSON Schema map.
          type: object
          x-order: 1
        required:
          description: Required config properties.
          items:
            type: string
          type: array
          x-order: 2
        type:
          description: Type defines the data type allowed for the schema.
          enum:
          - object
          type: string
          x-order: 3
          x-pulumi-model-property:
            enumTypeName: AppJSONSchemaType
            enumComments: JSONSchemaType in an enum of allowed data types for a schema.
            enumFieldComments:
            - Object is a dictionary.
      required:
      - type
      type: object
    ListPoliciesComplianceResponse:
      description: Response containing a list of policy compliance results.
      properties:
        continuationToken:
          description: Continuation token for pagination
          type: string
          x-order: 3
        policies:
          description: The list of policy compliance rows
          items:
            $ref: '#/components/schemas/PolicyComplianceRow'
          type: array
          x-order: 1
        totalCount:
          description: The total number of policies
          format: int64
          type: integer
          x-order: 2
      required:
      - policies
      type: object
    GetPolicyComplianceResultsResponse:
      description: Response for policy compliance results
      properties:
        columns:
          description: Column names (policy pack names) in order
          items:
            type: string
          type: array
          x-order: 1
        continuationToken:
          description: Continuation token for next page
          type: string
          x-order: 3
        rows:
          description: List of policy compliance result rows
          items:
            $ref: '#/components/schemas/PolicyComplianceResult'
          type: array
          x-order: 2
      required:
      - columns
      - rows
      type: object
    AngularGridSortModelItem:
      description: Represents angular grid sort model item.
      properties:
        colId:
          description: Column Id to apply the sort to.
          type: string
          x-order: 1
        sort:
          description: Sort direction
          type: string
          x-order: 2
      required:
      - colId
      - sort
      type: object
    AngularGridColumn:
      description: Represents angular grid column.
      properties:
        aggFunc:
          description: The agg func
          type: string
          x-order: 4
        displayName:
          description: The display name
          type: string
          x-order: 2
        field:
          description: The field
          type: string
          x-order: 3
        id:
          description: The unique identifier
          type: string
          x-order: 1
      required:
      - displayName
      - id
      type: object
    GetPolicyComplianceResultsRequest:
      description: Request for policy compliance results
      properties:
        continuationToken:
          description: Continuation token for pagination
          type: string
          x-order: 2
        entity:
          description: Entity type to filter by
          enum:
          - stack
          - account
          - severity
          type: string
          x-order: 1
          x-pulumi-model-property:
            enumTypeName: PolicyComplianceEntityType
            enumComments: PolicyComplianceEntityType defines the types of entities for policy compliance results.
            enumFieldComments:
            - Stack entity type for policy compliance results
            - Account entity type for policy compliance results
            - Severity heat map for policy compliance results
        size:
          description: Number of results to return
          format: int64
          type: integer
          x-order: 3
      required:
      - entity
      type: object
    AngularGridAdvancedFilterModel:
      description: Represents angular grid advanced filter model.
      properties:
        conditions:
          description: List of conditions
          items:
            $ref: '#/components/schemas/AngularGridFilterModel'
          type: array
          x-order: 2
        type:
          description: The type
          type: string
          x-order: 1
      required:
      - conditions
      - type
      type: object
    PolicyIssue:
      description: PolicyIssue represents a policy violation or issue detected during policy evaluation.
      properties:
        assignedTo:
          $ref: '#/components/schemas/UserInfo'
          description: The user the policy issue is assigned to.
          x-order: 22
        entityId:
          description: The identifier of the entity this issue applies to.
          type: string
          x-order: 4
        entityProject:
          description: The project name (for stack entities) or parent Insights account name (for resource entities).
          type: string
          x-order: 3
        entityType:
          description: The type of entity this issue applies to.
          enum:
          - stack
          - insights-account
          type: string
          x-order: 2
          x-pulumi-model-property:
            enumTypeName: IssueEntityType
            enumComments: 'The type of entity associated with a policy issue. Valid values: ''stack'', ''insights-account''.'
            enumFieldNames:
            - Stack
            - InsightsAccount
        id:
          description: The unique identifier of the policy issue.
          type: string
          x-order: 1
        kind:
          description: The kind of policy issue (audit or preventative).
          enum:
          - audit
          - preventative
          type: string
          x-order: 20
          x-pulumi-model-property:
            enumTypeName: PolicyIssueKind
            enumComments: Whether a policy issue is audit-only or preventative. Audit issues are informational; preventative issues block operations.
        lastModified:
          description: The timestamp when the issue was last modified.
          format: date-time
          type: string
          x-order: 16
        level:
          description: The enforcement level of the policy (e.g. advisory, mandatory, disabled).
          type: string
          x-order: 17
        message:
          description: A human-readable message describing the policy violation.
          type: string
          x-order: 14
        observedAt:
          description: The timestamp when the issue was first observed.
          format: date-time
          type: string
          x-order: 15
        policyGroupName:
          description: The name of the policy group this issue belongs to.
          type: string
          x-order: 23
        policyGroupType:
          description: The type of the policy group this issue belongs to.
          enum:
          - audit
          - preventative
          type: string
          x-order: 24
          x-pulumi-model-property:
            enumTypeName: PolicyGroupMode
            enumComments: PolicyGroupMode represents the enforcement mode for a policy group
        policyName:
          description: The name of the policy that was violated.
          type: string
          x-order: 9
        policyPack:
          description: The name of the policy pack that produced this issue.
          type: string
          x-order: 7
        policyPackTag:
          description: The tag of the policy pack version that produced this issue.
          type: string
          x-order: 8
        priority:
          description: The priority level of the policy issue.
          enum:
          - p0
          - p1
          - p2
          - p3
          - p4
          type: string
          x-order: 21
          x-pulumi-model-property:
            enumTypeName: PolicyIssuePriority
            enumComments: Priority level of a policy issue, from P0 (most critical) to P4 (least critical).
        resourceName:
          description: The name of the resource that violated the policy.
          type: string
          x-order: 13
        resourceProvider:
          description: The provider of the resource that violated the policy.
          type: string
          x-order: 11
        resourceType:
          description: The type of the resource that violated the policy.
          type: string
          x-order: 12
        resourceURN:
          description: The URN of the resource that violated the policy.
          type: string
          x-order: 10
        resourceVersion:
          description: The resource version where the issue was detected.
          format: int64
          type: integer
          x-order: 6
        severity:
          description: The severity of the policy violation.
          enum:
          - ''
          - low
          - medium
          - high
          - critical
          type: string
          x-order: 18
          x-pulumi-model-property:
            enumTypeName: AppPolicySeverity
            enumComments: Indicates the severity of a policy.
            enumFieldNames:
            - Unspecified
            - Low
            - Medium
            - High
            - Critical
        stackVersion:
          description: The stack version where the issue was detected.
          format: int64
          type: integer
          x-order: 5
        status:
          description: The current status of the policy issue.
          enum:
          - open
          - in_progress
          - by_design
          - fixed
          - ignored
          type: string
          x-order: 19
          x-pulumi-model-property:
            enumTypeName: PolicyIssueStatus
            enumComments: 'Lifecycle status of a policy issue. Valid values: open, in_progress, by_design, fixed, ignored. Note: fixed is a read-only status set automatically when an issue is resolved; it cannot be manually set via the API.'
            enumFieldNames:
            - Open
            - InProgress
            - ByDesign
            - Fixed
            - Ignored
      required:
      - entityId
      - entityProject
      - entityType
      - id
      - kind
      - level
      - observedAt
      - policyName
      - policyPack
      - policyPackTag
      - priority
      - resourceName
      - resourceProvider
      - resourceType
      - resourceURN
      - severity
      - status
      type: object
    PolicyComplianceRow:
      description: PolicyComplianceRow represents a single row in a policy compliance report.
      properties:
        failingResources:
          description: Number of resources failing this policy
          format: int64
          type: integer
          x-order: 3
        governedResources:
          description: Total number of resources governed by this policy
          format: int64
          type: integer
          x-order: 4
        percentCompliant:
          description: Percentage of resources that are compliant (0-100)
          format: int64
          type: integer
          x-order: 5
        policyGroupName:
          description: The policy group this policy belongs to
          type: string
          x-order: 7
        policyGroupType:
          description: The type of the policy group this policy belongs to
          enum:
          - audit
          - preventative
          type: string
          x-order: 8
          x-pulumi-model-property:
            enumTypeName: PolicyGroupMode
            enumComments: PolicyGroupMode represents the enforcement mode for a policy group
        policyName:
          description: The name of the policy
          type: string
          x-order: 1
        policyPack:
          description: The policy pack this policy belongs to
          type: string
          x-order: 6
        severity:
          description: The severity level of the policy
          enum:
          - ''
          - low
          - medium
          - high
          - critical
          type: string
          x-order: 2
          x-pulumi-model-property:
            enumTypeName: AppPolicySeverity
            enumComments: Indicates the severity of a policy.
            enumFieldNames:
            - Unspecified
            - Low
            - Medium
            - High
            - Critical
      required:
      - failingResources
      - governedResources
      - percentCompliant
      - policyGroupName
      - policyGroupType
      - policyName
      - policyPack
      - severity
      type: object
    RegistryPolicyPack:
      description: 'RegistryPolicyPack represents the core metadata for a policy pack in the registry.

        This is the primary data structure returned by most registry API endpoints.'
      properties:
        accessLevel:
          description: AccessLevel is the client's level of access to this policy pack.
          enum:
          - full
          - view-only
          - deny
          type: string
          x-order: 7
          x-pulumi-model-property:
            enumTypeName: RegistryPolicyPackAccessLevel
            enumComments: The level of access a client has to a registry policy pack.
            enumFieldNames:
            - Full
            - ViewOnly
            - Deny
            enumFieldComments:
            - Full access to a policy pack (view + use)
            - Access to view a policy pack
            - No access to a policy pack
        displayName:
          description: 'DisplayName is a human-readable name for this policy pack.

            This is typically more descriptive than the technical name.'
          type: string
          x-order: 6
        enforcementLevels:
          description: EnforcementLevels are the client's allowed enforcement levels for this policy pack.
          items:
            enum:
            - advisory
            - mandatory
            - remediate
            - disabled
            type: string
            x-pulumi-model-property:
              enumTypeName: AppEnforcementLevel
              enumComments: EnforcementLevel indicates how a policy should be enforced
              enumFieldComments:
              - 'Advisory is an enforcement level where the resource is still created, but a

                message is displayed to the user for informational / warning purposes.'
              - Mandatory is an enforcement level that prevents a resource from being created.
              - Remediate is an enforcement level that fixes policy issues instead of issuing diagnostics.
              - Disabled is an enforcement level that disables the policy from being enforced.
          type: array
          x-order: 8
        id:
          description: 'ID is the unique identifier for this policy pack in the registry.

            This is a UUID that corresponds to the policy pack''s database ID.'
   

# --- truncated at 32 KB (41 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pulumi/refs/heads/main/openapi/pulumi-policyresults-api-openapi.yml