Puppet Commands API
POST endpoints that trigger orchestrator actions.
POST endpoints that trigger orchestrator actions.
openapi: 3.1.0
info:
title: Puppet Enterprise Orchestrator Commands API
version: v1
description: 'The Puppet Enterprise Orchestrator API enables programmatic management of
orchestrator jobs, tasks, plans, and on-demand Puppet runs across the
PE-managed estate. Requests use HTTPS on port 8143 and authenticate with a
PE RBAC user token supplied via the `X-Authentication` header.
'
contact:
name: Puppet Enterprise
url: https://help.puppet.com/pe/2025.10/
servers:
- url: https://{pe_host}:8143/orchestrator/v1
description: Puppet Enterprise primary server
variables:
pe_host:
default: pe-master.example.com
description: DNS name of the PE primary server.
security:
- rbacToken: []
tags:
- name: Commands
description: POST endpoints that trigger orchestrator actions.
paths:
/command/deploy:
post:
tags:
- Commands
summary: Run Puppet on demand
description: Executes a Puppet run on the specified scope of nodes.
operationId: commandDeploy
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CommandRequest'
responses:
'202':
$ref: '#/components/responses/JobAccepted'
'401':
$ref: '#/components/responses/Unauthorized'
/command/task:
post:
tags:
- Commands
summary: Run a task
description: Executes a Puppet task across the specified nodes.
operationId: commandTask
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CommandRequest'
responses:
'202':
$ref: '#/components/responses/JobAccepted'
'401':
$ref: '#/components/responses/Unauthorized'
/command/task_target:
post:
tags:
- Commands
summary: Create a task target
description: Defines a task and node/group target combination for privilege-escalated execution.
operationId: commandTaskTarget
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CommandRequest'
responses:
'200':
description: Task target created.
'401':
$ref: '#/components/responses/Unauthorized'
/command/plan_run:
post:
tags:
- Commands
summary: Run a plan
description: Executes a Puppet plan.
operationId: commandPlanRun
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CommandRequest'
responses:
'202':
$ref: '#/components/responses/JobAccepted'
'401':
$ref: '#/components/responses/Unauthorized'
/command/environment_plan_run:
post:
tags:
- Commands
summary: Run a plan in an environment
description: Executes a Puppet plan within a specified environment.
operationId: commandEnvironmentPlanRun
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/CommandRequest'
responses:
'202':
$ref: '#/components/responses/JobAccepted'
'401':
$ref: '#/components/responses/Unauthorized'
/command/stop:
post:
tags:
- Commands
summary: Stop a job
description: Halts a currently executing orchestrator job.
operationId: commandStop
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- job
properties:
job:
type: string
description: Job identifier to stop.
responses:
'202':
description: Stop accepted.
'401':
$ref: '#/components/responses/Unauthorized'
/command/stop_plan:
post:
tags:
- Commands
summary: Stop a plan job
description: Halts a currently executing plan job.
operationId: commandStopPlan
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- plan_job
properties:
plan_job:
type: string
description: Plan job identifier to stop.
responses:
'202':
description: Stop accepted.
'401':
$ref: '#/components/responses/Unauthorized'
components:
responses:
Unauthorized:
description: Missing or invalid RBAC token.
JobAccepted:
description: Command accepted; a job has been queued.
content:
application/json:
schema:
type: object
properties:
job:
type: object
properties:
id:
type: string
description: URI of the created job.
name:
type: string
schemas:
CommandRequest:
type: object
description: Generic orchestrator command request body. The exact shape varies per command (environment, scope, task, plan_name, parameters, etc.).
additionalProperties: true
properties:
environment:
type: string
description: Puppet environment.
scope:
type: object
description: Selection of target nodes.
additionalProperties: true
description:
type: string
securitySchemes:
rbacToken:
type: apiKey
in: header
name: X-Authentication
description: 'Puppet Enterprise RBAC user authentication token. May be retrieved via
`puppet-access show`. Required on every request.
'
externalDocs:
description: Orchestrator API documentation
url: https://help.puppet.com/pe/2025.10/topics/orchestrator_api.htm