Pure Storage KMIP API

The Key Management Interoperability Protocol (KMIP) server is used in combination with the Pure Storage Rapid Data Locking (RDL) feature and EncryptReduce feature to further secure the encrypted data on a FlashArray.

Documentation

Specifications

Code Examples

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-volume-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-host-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-array-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-volume-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-file-system-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-bucket-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-array-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-file-system-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-bucket-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-metric-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-alert-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/pure1-cloud-api-array-structure.json

Other Resources

🔗
SDKs
https://pypi.org/project/py-pure-client/
🔗
SDKs
https://github.com/PureStorage-OpenConnect/PureStorage.Pure1
🔗
SDKs
https://github.com/PureStorage-OpenConnect/powershell-toolkit-3
🔗
SDKs
https://github.com/PureStorage-OpenConnect/rest-client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/terraform-provider-flash
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fa-openmetrics-exporter
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flasharray-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-volume-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-array-example.json
🔗
SDKs
https://github.com/PureStorage-OpenConnect/flashblade-powershell
🔗
SDKs
https://github.com/purestorage/purity_fb_python_client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fb-openmetrics-exporter
🔗
Tools
https://github.com/PureStorage-OpenConnect/flashblade-mcp-server
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flashblade-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-file-system-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-bucket-example.json
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-pure1-cloud-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/pure1-cloud-api-array-example.json

OpenAPI Specification

pure-storage-kmip-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: FlashArray REST Active Directory KMIP API
  version: '2.52'
  description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos

    or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by

    mapping identities across the NFS and SMB protocols by using LDAP queries.

    '
servers:
- url: /
tags:
- name: KMIP
  description: 'The Key Management Interoperability Protocol (KMIP) server is used in combination with the Pure

    Storage Rapid Data Locking (RDL) feature and EncryptReduce feature to further secure the

    encrypted data on a FlashArray.

    '
paths:
  /api/2.52/kmip:
    get:
      tags:
      - KMIP
      summary: Pure Storage List KMIP Server Objects
      description: 'Displays the list of KMIP server objects.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      - $ref: '#/components/parameters/Total_item_count'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipGetResponse'
    post:
      tags:
      - KMIP
      summary: Pure Storage Create KMIP Server Object
      description: 'Creates KMIP server objects.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KmipPost'
        required: true
        x-codegen-request-body-name: kmip
      responses:
        '200':
          description: Returns the newly created KMIP server object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipResponse'
      x-codegen-request-body-name: kmip
    delete:
      tags:
      - KMIP
      summary: Pure Storage Delete KMIP Server Object
      description: Deletes KMIP server objects.
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names'
      responses:
        '200':
          description: OK
          content: {}
    patch:
      tags:
      - KMIP
      summary: Pure Storage Modify KMIP Attributes
      description: 'Modifies one or more attributes of KMIP server objects.

        '
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KmipPatch'
        required: true
        x-codegen-request-body-name: kmip
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipResponse'
      x-codegen-request-body-name: kmip
  /api/2.52/kmip/test:
    get:
      tags:
      - KMIP
      summary: Pure Storage Lists KMIP Connection Tests
      description: Displays communication data between a FlashArray and KMIP server.
      parameters:
      - $ref: '#/components/parameters/Authorization'
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names_required'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipTestResultGetResponse'
  /api/2.26/kmip:
    get:
      tags:
      - KMIP
      summary: Pure Storage List KMIP Server Configurations
      description: 'Displays a list of KMIP server configurations.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset_2'
      - $ref: '#/components/parameters/Sort_2'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipServerResponse'
    post:
      tags:
      - KMIP
      summary: Pure Storage Create a KMIP Server Configuration
      description: Creates a KMIP server configuration.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KmipServer'
        required: true
        x-codegen-request-body-name: kmip-server
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipServerResponse'
      x-codegen-request-body-name: kmip-server
    delete:
      tags:
      - KMIP
      summary: Pure Storage Delete a KMIP Server Configuration
      description: 'Deletes a KMIP server configuration. A server can only be deleted when not in use by the array.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
    patch:
      tags:
      - KMIP
      summary: Pure Storage Modify a KMIP Server Configuration
      description: 'Modifies KMIP server properties - URI, certificate, certificate group.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/KmipServer'
        required: true
        x-codegen-request-body-name: kmip-server
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/KmipServerResponse'
      x-codegen-request-body-name: kmip-server
  /api/2.26/kmip/test:
    get:
      tags:
      - KMIP
      summary: Pure Storage Displays KMIP Server Test Results
      description: 'Displays a detailed result of of KMIP server test.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestResultResponse'
components:
  parameters:
    Offset:
      name: offset
      in: query
      description: 'The starting position based on the results of the query

        in relation to the full set of response objects returned.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    Filter:
      name: filter
      in: query
      description: 'Narrows down the results to only the response objects

        that satisfy the filter criteria.

        '
      schema:
        type: string
    Continuation_token:
      name: continuation_token
      in: query
      description: 'A token used to retrieve the next page of data

        with some consistency guaranteed.

        The token is a Base64 encoded value.

        Set `continuation_token` to the system-generated token taken from the `x-next-token`

        header field of the response.

        A query has reached its last page when the response does not include a token.

        Pagination requires the `limit` and `continuation_token`

        query parameters.

        '
      schema:
        type: string
    Offset_2:
      name: offset
      in: query
      description: 'The offset of the first resource to return from a collection.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    XRequestId:
      name: X-Request-ID
      in: header
      description: 'Supplied by client during request or generated by server.

        '
      schema:
        type: string
    Limit:
      name: limit
      in: query
      description: 'Limits the size of the response to the specified number of objects on each page.

        To return the total number of resources, set `limit=0`.

        The total number of resources is returned as a `total_item_count` value.

        If the page size requested is larger than the system maximum limit,

        the server returns the maximum limit, disregarding the requested page size.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    Authorization:
      name: Authorization
      in: header
      description: 'Access token (in JWT format) required to use any API

        endpoint (except `/oauth2`, `/login`, and `/logout`)

        '
      schema:
        type: string
    Names:
      name: names
      in: query
      description: 'Performs the operation on the unique names specified.

        Enter multiple names in comma-separated format.

        For example, `name01,name02`.


        If there is not at least one resource that matches

        each of the elements of `names`, then an error is returned,

        except when creating new resources.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Sort_2:
      name: sort
      in: query
      description: 'Sort the response by the specified fields (in descending order if ''-''

        is appended to the field name).

        NOTE: If you provide a sort you will not get a `continuation_token` in

        the response.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          pattern: ^[a-z]+(_[a-z]+)*-?
          type: string
    Ids:
      name: ids
      in: query
      description: 'A comma-separated list of resource IDs.

        If after filtering, there is not at least one resource that matches

        each of the elements of `ids`, then an error is returned.

        This cannot be provided together with the `name` or `names` query parameters.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Total_item_count:
      name: total_item_count
      in: query
      description: 'If set to `true`, the `total_item_count` matching the

        specified query parameters is calculated and returned in

        the response. If set to `false`, the `total_item_count`

        is `null` in the response. This may speed up queries

        where the `total_item_count` is large. If not specified,

        defaults to `false`.

        '
      schema:
        type: boolean
    Sort:
      name: sort
      in: query
      description: "Sorts the response objects by the specified fields. Sorting can be applied to any field name\n in the response, in ascending order by default, or in descending order by prefixing the\n field name with a minus sign (-). Multiple fields can be specified as a comma-separated\n list (e.g., sort volumes by size descending, then by name ascending). If sort is provided,\n the response will not include a continuation_token.\n"
      style: form
      explode: false
      schema:
        type: array
        items:
          pattern: ^[a-z]+(_[a-z]+)*-?
          type: string
    Names_required:
      name: names
      in: query
      description: 'Performs the operation on the unique name specified.

        For example, `name01`.

        Enter multiple names in comma-separated format.

        '
      required: true
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
  schemas:
    KmipResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/Kmip'
    _referenceNoId:
      type: object
      properties:
        name:
          description: 'The resource name, such as volume name, pod name, snapshot name, and so on.

            '
          type: string
    TestResult:
      type: object
      properties:
        component_address:
          description: Address of the component running the test.
          type: string
          example: 10.230.94.21
        component_name:
          description: Name of the component running the test.
          type: string
          example: fm1
        description:
          description: What the test is doing.
          type: string
          example: Testing phonehome connectivity
        destination:
          description: The URI of the target server being tested.
          type: string
          example: ra.cloud-support.purestorage.com
        enabled:
          description: Is the service enabled or not?
          type: boolean
          example: true
        resource:
          description: A reference to the object being tested.
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
        result_details:
          description: Additional information about the test result.
          type: string
          example: Timeout connecting to phonehome endpoint
        success:
          description: 'Returns a value of `true` if the specified test succeeded.

            Returns a value of `false` if the specified test failed.

            '
          type: boolean
        test_type:
          description: 'Displays the type of test being performed. The returned values are determined

            by the `resource` being tested and its configuration.

            '
          type: string
          example: phonehome
    _reference:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
        name:
          description: 'The resource name,

            such as volume name, pod name, snapshot name, and so on.

            '
          type: string
        resource_type:
          description: 'Type of the object (full name of the endpoint).

            Valid values are `hosts`, `host-groups`, `network-interfaces`, `pods`,

            `ports`, `pod-replica-links`, `subnets`, `volumes`, `volume-snapshots`,

            `volume-groups`, `directories`, `policies/nfs`, `policies/smb`, and

            `policies/snapshot`, etc.

            '
          type: string
          readOnly: true
      x-aliases:
      - _referenceWithFixedType
    TestResultResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/TestResult'
    Kmip_certificate:
      type: object
      properties:
        name:
          description: 'The resource name, such as volume name, pod name, snapshot name, and so on.

            '
          type: string
    _fixedReferenceWithoutType:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'The resource name, such as volume name, file system name,

            snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
    KmipServerResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/KmipServer'
    KmipPost:
      type: object
      properties:
        ca_certificate:
          description: The text of the CA certificate for the KMIP server.
          type: string
          maxLength: 3000
          example: '-----BEGIN CERTIFICATE-----...-----END CERTIFICATE-----'
        certificate:
          description: 'The certificate used to verify FlashArray authenticity to the KMIP servers.

            '
          title: ReferenceNoId
          allOf:
          - $ref: '#/components/schemas/_referenceNoId'
        uris:
          description: List of URIs for the configured KMIP servers.
          type: array
          items:
            type: string
          example:
          - 1.1.1.1:8888
          - 2.2.2.2:9999
    _builtIn:
      type: object
      properties:
        id:
          description: 'A non-modifiable, globally unique ID chosen by the system.

            '
          type: string
          readOnly: true
        name:
          description: Name of the object (e.g., a file system or snapshot).
          type: string
          readOnly: true
    KmipServer:
      allOf:
      - $ref: '#/components/schemas/_builtIn'
      - type: object
        properties:
          ca_certificate:
            description: 'CA certificate used to validate the authenticity of the configured servers.

              '
            title: Reference
            allOf:
            - $ref: '#/components/schemas/_reference'
          ca_certificate_group:
            description: 'A certificate group containing CA certificates that can be used to

              validate the authenticity of the configured servers.

              '
            title: Reference
            allOf:
            - $ref: '#/components/schemas/_reference'
          uris:
            description: List of URIs for the configured KMIP servers in the format [protocol://]hostname:port.
            type: array
            minItems: 1
            maxItems: 30
            items:
              pattern: ^(tls://)?
              type: string
            example:
            - my1.kmipserver.com:5696
            - tls://my2.kmipserver.com:5696
    KmipPatch:
      type: object
      properties:
        ca_certificate:
          description: The text of the CA certificate for the KMIP server.
          type: string
          maxLength: 3000
          example: '-----BEGIN CERTIFICATE-----...-----END CERTIFICATE-----'
        certificate:
          description: 'The certificate used to verify FlashArray authenticity to the KMIP servers.

            '
          title: ReferenceNoId
          allOf:
          - $ref: '#/components/schemas/_referenceNoId'
        uris:
          description: List of URIs for the configured KMIP servers.
          type: array
          items:
            type: string
          example:
          - 1.1.1.1:8888
          - 2.2.2.2:9999
    KmipTestResult:
      type: object
      properties:
        component_address:
          description: Address of the component running the test.
          type: string
          example: 10.230.94.21
        component_name:
          description: Name of the component running the test.
          type: string
          example: kmip-test1
        description:
          description: Description of what is being tested.
          type: string
          example: Testing kmip connectivity.
        destination:
          description: The URI of the target server being tested.
          type: string
          example: kmip-test-server.dev.purestorage.com
        enabled:
          description: Expresses whether the service is enabled or not.
          type: boolean
          example: true
        result_details:
          description: Additional information about the test result.
          type: string
          example: KMIP test failed
        success:
          description: 'Expresses whether communication between the FlashArray and the KMIP server succeeded

            or not.

            '
          type: boolean
          example: true
        test_type:
          description: Description of what is being tested.
          type: string
          example: kmip
    Kmip_object:
      type: object
      properties:
        name:
          description: 'Name of the KMIP object.

            '
          type: string
        uid:
          description: 'User ID of the KMIP object.

            '
          type: string
    Kmip:
      description: 'A built-in resource. Many are singletons predefined by Purity (e.g., support

        settings). Some correspond to a piece of software, like an app, or hardware,

        like a controller. Others are created by the system in response to some event

        (e.g., alerts, audit records).


        Typically, a user can''t create, delete or rename a built-in resource. A few

        can be created or deleted, but not renamed because the names are meaningful

        to Purity (e.g., VIFs, file systems, file system snapshots, volume snapshot).

        '
      type: object
      properties:
        ca_certificate:
          description: 'CA certificate text for the KMIP server.

            '
          type: string
          maxLength: 3000
          example: '-----BEGIN CERTIFICATE-----...-----END CERTIFICATE-----'
        certificate:
          description: 'The certificate used to verify FlashArray authenticity to the KMIP servers.

            '
          title: Kmip_certificate
          allOf:
          - $ref: '#/components/schemas/Kmip_certificate'
        kmip_objects:
          description: 'List of the name and UID of the KMIP objects.

            '
          type: array
          items:
            $ref: '#/components/schemas/Kmip_object'
        name:
          description: 'A locally unique, system-generated name. The name cannot be modified.

            '
          type: string
          readOnly: true
        uris:
          description: 'List of URIs for the configured KMIP servers.

            '
          type: array
          items:
            type: string
          example:
          - 1.1.1.1:8888
          - 2.2.2.2:9999
    KmipTestResultGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - type: object
        properties:
          items:
            type: array
            items:
              $ref: '#/components/schemas/KmipTestResult'
    _fixedReference:
      allOf:
      - $ref: '#/components/schemas/_fixedReferenceWithoutType'
      - type: object
        properties:
          resource_type:
            description: 'Type of the object (full name of the endpoint).

              Valid values are the unique part of the resource''s REST endpoint.

              For example, a reference to a file system would have a

              `resource_type` of `file-systems`.

              '
            type: string
            readOnly: true
    PageInfo:
      type: object
      properties:
        continuation_token:
          description: 'Continuation token that can be provided in the `continuation_token`

            query param to get the next page of data.

            If you use the continuation token to page through data you

            are guaranteed to get all items exactly once regardless of

            how items are modified. If an item is added or deleted during

            the pagination then it may or may not be returned.

            The continuation token is generated if the limit is less

            than the remaining number of items, and the default sort is used

            (no sort is specified).

            '
          type: string
        more_items_remaining:
          description: 'Returns a value of `true` if subsequent items can be retrieved.

            '
          type: boolean
          example: false
        total_item_count:
          description: 'The total number of records after applying all filter query parameters.

            The `total_item_count` will be calculated if and only if the corresponding

            query parameter `total_item_count` is set to `true`. If this query parameter

            is not set or set to `false`, a value of `null` will be returned.

            '
          type: integer
          format: int32
    KmipGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/KmipResponse'