openapi: 3.0.1
info:
title: FlashArray REST Active Directory API
version: '2.52'
description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos
or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by
mapping identities across the NFS and SMB protocols by using LDAP queries.
'
servers:
- url: /
tags:
- name: Active Directory
description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos
or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by
mapping identities across the NFS and SMB protocols by using LDAP queries.
'
paths:
/api/2.52/active-directory:
get:
tags:
- Active Directory
summary: Pure Storage List Active Directory Accounts
description: 'Displays configured Active Directory accounts.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Fqnames'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryGetResponse'
post:
tags:
- Active Directory
summary: Pure Storage Create Active Directory Account
description: 'Creates one or more Active Directory accounts.
The `user` and `password` provided are used
to join the array to the specified `domain`.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Join_existing_acct_ad'
- $ref: '#/components/parameters/Fqnames_required'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryPost'
required: true
x-codegen-request-body-name: active-directory
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryResponse'
x-codegen-request-body-name: active-directory
delete:
tags:
- Active Directory
summary: Pure Storage Delete Active Directory Account
description: 'Deletes one or more specified Active Directory accounts.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Local_only_ad'
- $ref: '#/components/parameters/Fqnames_required'
responses:
'200':
description: OK
content: {}
patch:
tags:
- Active Directory
summary: Pure Storage Modify Active Directory Account
description: 'Modifies specified Active Directory account.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Fqnames_required'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryPatch'
required: true
x-codegen-request-body-name: active-directory
responses:
'200':
description: OK
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryResponse'
x-codegen-request-body-name: active-directory
/api/2.52/active-directory/test:
get:
tags:
- Active Directory
summary: Pure Storage GET Active-directory/test
description: 'The diagnostic process that executes a series of validation tests on one or more `Active Directory` `accounts`. Each individual test verifies a specific aspect of the `configuration`, such as connectivity, authentication permissions, and service principal integrity, to ensure the environment is functioning properly.
'
parameters:
- $ref: '#/components/parameters/Authorization'
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names_required'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Total_item_count'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: The identifier or attribute provided by the `client` during the initial `request` or automatically generated by the `server` if not specified.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultWithResourceAndErrorContextPartialResourceResponse'
'207':
description: 'The status indicating a partial success. While some `resources`
were successfully returned, specific `errors` occurred during
the operation that may have prevented the full set of
requested data from being retrieved or displayed.
'
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultWithResourceAndErrorContextPartialResourceResponse'
/api/2.26/active-directory:
get:
tags:
- Active Directory
summary: Pure Storage GET Active-directory
description: List Active Directory accounts and their configuration.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset_2'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryGetResponse'
post:
tags:
- Active Directory
summary: Pure Storage POST Active-directory
description: 'Join an Active Directory domain and generate keytabs for the
registered SPNs and supported encryption types.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Join_existing_acct_ad_2'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryPost_2'
required: true
x-codegen-request-body-name: active-directory
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryResponse_2'
x-codegen-request-body-name: active-directory
delete:
tags:
- Active Directory
summary: Pure Storage DELETE Active-directory
description: Delete an Active Directory account.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Local_only_ad'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- Active Directory
summary: Pure Storage PATCH Active-directory
description: Modify the configuration of an Active Directory account.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryPatch_2'
required: true
x-codegen-request-body-name: active-directory
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ActiveDirectoryResponse_2'
x-codegen-request-body-name: active-directory
/api/2.26/active-directory/test:
get:
tags:
- Active Directory
summary: Pure Storage GET Active-directory/test
description: 'Executes a series of tests to verify if the configuration of one or more Active Directory accounts are functioning properly. Each test verifies a different aspect of the configuration.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids_2'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Sort_2'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultRemoteExecutionGet'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/TestResultRemoteExecutionGet'
components:
parameters:
Join_existing_acct_ad:
name: join_existing_account
in: query
description: 'If specified as `true`, the domain is searched for a pre-existing computer account to join to,
and no new account will be created within the domain.
The `user` specified when joining a pre-existing account must have permissions to
''read all properties from'' and ''reset the password of'' the pre-existing account.
`join_ou` will be read from the pre-existing account and cannot be specified
when joining to an existing account. If not specified, defaults to `false`.
'
schema:
type: boolean
Fqnames:
name: names
in: query
description: 'Performs the operation on the unique name specified.
Enter multiple names in comma-separated format.
The name is expected to be fully qualified, meaning if the object is contained in some context,
the corresponding name would provide complete information about the containment hierarchy.
For example, `name01,pod01::name01`.
'
style: form
explode: false
schema:
type: array
items:
type: string
Filter:
name: filter
in: query
description: 'Narrows down the results to only the response objects
that satisfy the filter criteria.
'
schema:
type: string
Offset:
name: offset
in: query
description: 'The starting position based on the results of the query
in relation to the full set of response objects returned.
'
schema:
type: integer
format: int32
minimum: 0
example: 10
Allow_errors:
name: allow_errors
in: query
description: 'If set to `true`, the API will allow the operation to continue even if there are errors.
Any errors will be returned in the `errors` field of the response.
If set to `false`, the operation will fail if there are any errors.
'
schema:
type: boolean
default: false
Fqnames_required:
name: names
in: query
description: 'Performs the operation on the unique name specified.
Enter multiple names in comma-separated format.
The name is expected to be fully qualified, meaning if the object is contained in some context,
the corresponding name would provide complete information about the containment hierarchy.
For example, `name01,pod01::name01`.
'
required: true
style: form
explode: false
schema:
type: array
items:
type: string
Local_only_ad:
name: local_only
in: query
description: 'If specified as `true`, only delete the Active Directory
configuration on the local array, without deleting the
computer account created in the Active Directory domain.
If not specified, defaults to `false`.
'
schema:
type: boolean
Continuation_token:
name: continuation_token
in: query
description: 'A token used to retrieve the next page of data
with some consistency guaranteed.
The token is a Base64 encoded value.
Set `continuation_token` to the system-generated token taken from the `x-next-token`
header field of the response.
A query has reached its last page when the response does not include a token.
Pagination requires the `limit` and `continuation_token`
query parameters.
'
schema:
type: string
Offset_2:
name: offset
in: query
description: 'The offset of the first resource to return from a collection.
'
schema:
type: integer
format: int32
minimum: 0
example: 10
Names_required:
name: names
in: query
description: 'Performs the operation on the unique name specified.
For example, `name01`.
Enter multiple names in comma-separated format.
'
required: true
style: form
explode: false
schema:
type: array
items:
type: string
XRequestId:
name: X-Request-ID
in: header
description: 'Supplied by client during request or generated by server.
'
schema:
type: string
Limit:
name: limit
in: query
description: 'Limits the size of the response to the specified number of objects on each page.
To return the total number of resources, set `limit=0`.
The total number of resources is returned as a `total_item_count` value.
If the page size requested is larger than the system maximum limit,
the server returns the maximum limit, disregarding the requested page size.
'
schema:
type: integer
format: int32
minimum: 0
example: 10
Join_existing_acct_ad_2:
name: join_existing_account
in: query
description: 'If specified as `true`, the domain is searched for a pre-existing computer account to join to,
and no new account will be created within the domain.
The `user` specified when joining to a pre-existing account must have permissions to
''read attributes from'' and ''reset the password of'' the pre-existing account.
`service_principal_names`, `encryption_types`, and `join_ou` will be read from the
pre-existing account and cannot be specified when joining to an existing account.
If not specified, defaults to `false`.
'
schema:
type: boolean
Authorization:
name: Authorization
in: header
description: 'Access token (in JWT format) required to use any API
endpoint (except `/oauth2`, `/login`, and `/logout`)
'
schema:
type: string
Names:
name: names
in: query
description: 'Performs the operation on the unique names specified.
Enter multiple names in comma-separated format.
For example, `name01,name02`.
If there is not at least one resource that matches
each of the elements of `names`, then an error is returned,
except when creating new resources.
'
style: form
explode: false
schema:
type: array
items:
type: string
Context_names_get:
name: context_names
in: query
description: 'Performs the operation on the unique contexts specified.
If specified, each context name must be the name of an array in the same fleet or
the name of the fleet itself.
If not specified, the context will default to the array that received this request.
Other parameters provided with the request, such as names of volumes or snapshots,
are resolved relative to the provided `context`.
Enter multiple names in comma-separated format.
For example, `name01,name02`.
'
style: form
explode: false
schema:
type: array
items:
type: string
Sort_2:
name: sort
in: query
description: 'Sort the response by the specified fields (in descending order if ''-''
is appended to the field name).
NOTE: If you provide a sort you will not get a `continuation_token` in
the response.
'
style: form
explode: false
schema:
type: array
items:
pattern: ^[a-z]+(_[a-z]+)*-?
type: string
Ids:
name: ids
in: query
description: "A comma-separated list of unique resource IDs. At least one resource must match\n each specified ID, otherwise an error is returned. This parameter is required\n if ids or names is not provided, but it cannot be used together with name or names.\n"
style: form
explode: false
schema:
type: array
items:
type: string
Ids_2:
name: ids
in: query
description: 'A comma-separated list of resource IDs.
If after filtering, there is not at least one resource that matches
each of the elements of `ids`, then an error is returned.
This cannot be provided together with the `name` or `names` query parameters.
'
style: form
explode: false
schema:
type: array
items:
type: string
Total_item_count:
name: total_item_count
in: query
description: 'If set to `true`, the `total_item_count` matching the
specified query parameters is calculated and returned in
the response. If set to `false`, the `total_item_count`
is `null` in the response. This may speed up queries
where the `total_item_count` is large. If not specified,
defaults to `false`.
'
schema:
type: boolean
Sort:
name: sort
in: query
description: "Sorts the response objects by the specified fields. Sorting can be applied to any field name\n in the response, in ascending order by default, or in descending order by prefixing the\n field name with a minus sign (-). Multiple fields can be specified as a comma-separated\n list (e.g., sort volumes by size descending, then by name ascending). If sort is provided,\n the response will not include a continuation_token.\n"
style: form
explode: false
schema:
type: array
items:
pattern: ^[a-z]+(_[a-z]+)*-?
type: string
schemas:
_errorContextResponseErrors:
type: object
properties:
context:
description: 'Contains information relating to the cause of this error,
or the name of the object that was being processed when the error was encountered.
This may be `null` for more general errors.
'
type: string
location_context:
description: 'Contains information relating to the context in which the request was executing
when the error occurred.
For example, this may be the name of an array in the same fleet.
This may be `null` for more general errors, or if no explicit `context` parameter
was provided with the request.
'
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference_2'
message:
description: A description of the error which occurred.
type: string
example: Resource does not exist.
_errorContextResponse:
type: object
properties:
errors:
description: The list of errors encountered when attempting to perform an operation.
type: array
readOnly: true
items:
$ref: '#/components/schemas/_errorcontextresponseErrors'
TestResultRemoteExecutionGet:
allOf:
- $ref: '#/components/schemas/TestResultRemoteExecution'
- $ref: '#/components/schemas/_errorContextResponse_2'
- $ref: '#/components/schemas/PageInfo_2'
- type: object
properties:
total_item_count:
description: Total number of items after applying `filter` params.
type: integer
format: int32
ActiveDirectoryResponse_2:
type: object
properties:
items:
description: A list of Active Directory computer account configuration objects.
type: array
items:
$ref: '#/components/schemas/ActiveDirectory_2'
ActiveDirectoryPatch:
type: object
properties:
sources:
description: 'List of network interfaces used for egress. For directory services
at the array level, the list can be empty.
If the list is empty, the system will use VIFs with the "ds" service
(or if none, the "management" service) for egress.
'
type: array
items:
$ref: '#/components/schemas/_reference'
tls:
description: 'TLS mode for communication with domain controllers.
Valid values are `required` and `optional`.
`required` forces TLS communication with domain controller.
`optional` allows the use of non-TLS communication,
TLS will still be preferred, if available.
If not specified, defaults to `required`.
'
type: string
example: required
TestResult:
type: object
properties:
component_address:
description: Address of the component running the test.
type: string
example: 10.230.94.21
component_name:
description: Name of the component running the test.
type: string
example: CT0
description:
description: What the test is doing.
type: string
example: Testing phonehome connectivity
destination:
description: The URI of the target server being tested.
type: string
example: ra.cloud-support.purestorage.com
enabled:
description: 'Whether the object being tested is enabled or not.
Returns a value of `true` if the the service is enabled.
Returns a value of `false` if the service is disabled.
'
type: boolean
example: true
result_details:
description: Additional information about the test result.
type: string
example: Timeout connecting to phonehome endpoint
success:
description: 'Whether the object being tested passed the test or not.
Returns a value of `true` if the specified test has succeeded.
Returns a value of `false` if the specified test has failed.
'
type: boolean
test_type:
description: 'Displays the type of test being performed. The returned values are determined
by the `resource` being tested and its configuration.
Values include `array-admin-group-searching`, `binding`, `connecting`, `phonehome`,
`phonehome-ping`, `remote-assist`, `rootdse-searching`, `read-only-group-searching`,
`storage-admin-group-searching`, and `validate-ntp-configuration`.
'
type: string
example: phonehome
_reference:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
name:
description: 'The resource name, such as volume name, pod name,
snapshot name, and so on.
'
type: string
x-aliases:
- _referenceWithoutType
ActiveDirectory_2:
allOf:
- $ref: '#/components/schemas/_builtIn'
- $ref: '#/components/schemas/_realmsReference'
- type: object
properties:
computer_name:
description: 'The common name of the computer account to be created in the Active Directory
domain.
If not specified, defaults to the name of the Active Directory
configuration.
'
type: string
example: FLASHBLADE01
directory_servers:
description: 'A list of directory servers that will be used for lookups related to user authorization.
Accepted server formats are IP address and DNS name with optional @domain suffix.
If the suffix is ommited, the joined domain is assumed.
All specified servers must be registered to the domain appropriately in the array''s
configured DNS and will only be communicated with over the secure LDAP (LDAPS) protocol.
'
type: array
items:
type: string
example: ldap.my-corporation.com
domain:
description: The Active Directory domain to join.
type: string
example: my-corporation.com
encryption_types:
description: 'The encryption types that are supported for use by clients for Kerberos
authentication.
'
type: array
items:
type: string
example: aes256-cts-hmac-sha1-96
global_catalog_servers:
description: 'A list of global catalog servers that will be used
for lookups related to user authorization.
Accepted server formats are IP address and DNS name with optional @domain suffix.
If the suffix is ommited, the joined domain is assumed.
All specified servers must be registered to the domain appropriately in the array''s
configured DNS and will only be communicated with over the secure LDAP (LDAPS) protocol.
'
type: array
items:
type: string
example: gc.my-corporation.com
join_ou:
description: 'The relative distinguished name of the organizational unit in which the
computer account was created when joining the domain.
'
type: string
example: CN=Computers
kerberos_servers:
description: 'A list of key distribution servers to use for Kerberos protocol.
Accepted server formats are IP address and DNS name.
All specified servers must be registered to the domain appropriately in the array''s
configured DNS.
'
type: array
items:
type: string
example: krb-host.my-corporation.com
server:
description: 'The server containing this active directory account.
'
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference_2'
service_principal_names:
description: 'A list of service principal names registered for the machine account,
which can be used for the creation of keys for Kerberos authentication.
'
type: array
items:
pattern: (service)/(fqdn)
type: string
example: nfs/vip1.my-array.my-corporation.com
_fixedReferenceWithoutType:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'The resource name, such as volume name, file system name,
snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
_errorcontextresponseErrors:
type: object
properties:
context:
description: 'Contains information relating to the cause of this error,
or the name of the object that was being processed when the error was encountered.
This may be `null` for more general errors.
'
type: string
location_context:
description: 'Contains information relating to the context in which the request was executing
when the error occurred.
For example, this may be the name of an array in the same fleet.
This may be `null` for more general errors, or if no explicit `context` parameter
was provided with the request.
'
title: FixedReferenceWithType
allOf:
- $ref: '#/components/schemas/_fixedReferenceWithType'
message:
description: A description of the error which occurred.
type: string
example: Resource does not exist.
x-aliases:
- _errorContextResponseErrors
TestResultWithResource:
allOf:
- $ref: '#/components/schemas/TestResult'
- $ref: '#/components/schemas/_context'
- type: object
properties:
resource:
description: A reference to the object being tested.
title: FixedReferenceNoId
allOf:
- $ref: '#/components/schemas/_fixedReferenceNoId'
_errorContextResponse_2:
type: object
properties:
errors:
description: The list of errors encountered when attempting to perform an operation.
type: array
readOnly: true
items:
$ref: '#/components/schemas/_errorContextResponseErrors'
_referenceWithType:
allOf:
- $ref: '#/components/schemas/_reference'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are `hosts`, `host-groups`, `network-interfaces`, `pods`,
`ports`, `pod-replica-links`, `subnets`, `volumes`, `volume-snapshots`,
`v
# --- truncated at 32 KB (58 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-active-directory-api-openapi.yml