Pure Storage Policies - Network Access API

Manages network access policies. These policies are composed of rules which govern a client's ability to access different product interfaces.

Documentation

Specifications

Code Examples

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-volume-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-host-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-array-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-volume-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-file-system-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-bucket-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-array-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-file-system-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-bucket-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-metric-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-alert-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/pure1-cloud-api-array-structure.json

Other Resources

🔗
SDKs
https://pypi.org/project/py-pure-client/
🔗
SDKs
https://github.com/PureStorage-OpenConnect/PureStorage.Pure1
🔗
SDKs
https://github.com/PureStorage-OpenConnect/powershell-toolkit-3
🔗
SDKs
https://github.com/PureStorage-OpenConnect/rest-client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/terraform-provider-flash
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fa-openmetrics-exporter
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flasharray-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-volume-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-array-example.json
🔗
SDKs
https://github.com/PureStorage-OpenConnect/flashblade-powershell
🔗
SDKs
https://github.com/purestorage/purity_fb_python_client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fb-openmetrics-exporter
🔗
Tools
https://github.com/PureStorage-OpenConnect/flashblade-mcp-server
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flashblade-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-file-system-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-bucket-example.json
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-pure1-cloud-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/pure1-cloud-api-array-example.json

OpenAPI Specification

pure-storage-policies-network-access-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: FlashArray REST Active Directory Policies - Network Access API
  version: '2.52'
  description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos

    or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by

    mapping identities across the NFS and SMB protocols by using LDAP queries.

    '
servers:
- url: /
tags:
- name: Policies - Network Access
  description: Manages network access policies. These policies are composed of rules which govern a client's ability to access different product interfaces.
paths:
  /api/2.26/network-access-policies:
    get:
      tags:
      - Policies - Network Access
      summary: Pure Storage GET Network-access-policies
      description: Displays a list of network access policies.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NetworkAccessPolicyGetResponse'
    patch:
      tags:
      - Policies - Network Access
      summary: Pure Storage PATCH Network-access-policies
      description: Modify an existing network access policy's attributes.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkAccessPolicy'
        required: true
        x-codegen-request-body-name: policy
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NetworkAccessPolicyResponse'
      x-codegen-request-body-name: policy
  /api/2.26/network-access-policies/members:
    get:
      tags:
      - Policies - Network Access
      summary: Pure Storage GET Network-access-policies/members
      description: 'List network access policies mapped to different configurations on the array.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberGetResponse'
  /api/2.26/network-access-policies/rules:
    get:
      tags:
      - Policies - Network Access
      summary: Pure Storage GET Network-access-policies/rules
      description: Displays a list of network access policy rules.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NetworkAccessPolicyRuleGetResponse'
    post:
      tags:
      - Policies - Network Access
      summary: Pure Storage POST Network-access-policies/rules
      description: 'Create a new network access policy rule.

        Either `policy_ids` or `policy_names` parameter is required.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Before_rule_id'
      - $ref: '#/components/parameters/Before_rule_name'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Versions'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkAccessPolicyRulePost'
        required: true
        x-codegen-request-body-name: rule
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NetworkAccessPolicyRuleResponse'
      x-codegen-request-body-name: rule
    delete:
      tags:
      - Policies - Network Access
      summary: Pure Storage DELETE Network-access-policies/rules
      description: Delete one or more network access policy rules.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      responses:
        '200':
          description: OK
          content: {}
    patch:
      tags:
      - Policies - Network Access
      summary: Pure Storage PATCH Network-access-policies/rules
      description: Modify an existing network access policy rule.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Before_rule_id'
      - $ref: '#/components/parameters/Before_rule_name'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NetworkAccessPolicyRule'
        required: true
        x-codegen-request-body-name: rule
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NetworkAccessPolicyRuleResponse'
      x-codegen-request-body-name: rule
components:
  parameters:
    Versions:
      name: versions
      in: query
      description: 'A comma-separated list of versions. This is an optional query param used for concurrency control.

        The ordering should match the names or ids query param.

        This will fail with a 412 Precondition failed if the resource was changed and the current

        version of the resource doesn''t match the value in the query param.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Offset:
      name: offset
      in: query
      description: 'The offset of the first resource to return from a collection.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    Filter:
      name: filter
      in: query
      description: 'Narrows down the results to only the response objects

        that satisfy the filter criteria.

        '
      schema:
        type: string
    Before_rule_name:
      name: before_rule_name
      in: query
      description: 'The name of the rule to insert or move a rule before.

        This cannot be provided together with the `before_rule_id` query parameter.

        '
      schema:
        type: string
    Before_rule_id:
      name: before_rule_id
      in: query
      description: 'The id of the rule to insert or move a rule before.

        This cannot be provided together with the `before_rule_name` query parameter.

        '
      schema:
        type: string
    Policy_ids:
      name: policy_ids
      in: query
      description: 'A comma-separated list of policy IDs.

        If after filtering, there is not at least one resource that matches

        each of the elements of `policy_ids`, then an error is returned.

        This cannot be provided together with the `policy_names` query parameter.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Continuation_token:
      name: continuation_token
      in: query
      description: 'A token used to retrieve the next page of data

        with some consistency guaranteed.

        The token is a Base64 encoded value.

        Set `continuation_token` to the system-generated token taken from the `x-next-token`

        header field of the response.

        A query has reached its last page when the response does not include a token.

        Pagination requires the `limit` and `continuation_token`

        query parameters.

        '
      schema:
        type: string
    Policy_names:
      name: policy_names
      in: query
      description: 'A comma-separated list of policy names.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    XRequestId:
      name: X-Request-ID
      in: header
      description: 'Supplied by client during request or generated by server.

        '
      schema:
        type: string
    Limit:
      name: limit
      in: query
      description: 'Limits the size of the response to the specified number of objects on each page.

        To return the total number of resources, set `limit=0`.

        The total number of resources is returned as a `total_item_count` value.

        If the page size requested is larger than the system maximum limit,

        the server returns the maximum limit, disregarding the requested page size.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    Names:
      name: names
      in: query
      description: 'Performs the operation on the unique names specified.

        Enter multiple names in comma-separated format.

        For example, `name01,name02`.


        If there is not at least one resource that matches

        each of the elements of `names`, then an error is returned,

        except when creating new resources.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Member_ids:
      name: member_ids
      in: query
      description: 'A comma-separated list of member IDs.

        If after filtering, there is not at least one resource that matches

        each of the elements of `member_ids`, then an error is returned.

        This cannot be provided together with the `member_names` query parameter.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Member_names:
      name: member_names
      in: query
      description: 'A comma-separated list of member names.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Ids:
      name: ids
      in: query
      description: 'A comma-separated list of resource IDs.

        If after filtering, there is not at least one resource that matches

        each of the elements of `ids`, then an error is returned.

        This cannot be provided together with the `name` or `names` query parameters.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Sort:
      name: sort
      in: query
      description: 'Sort the response by the specified fields (in descending order if ''-''

        is appended to the field name).

        NOTE: If you provide a sort you will not get a `continuation_token` in

        the response.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          pattern: ^[a-z]+(_[a-z]+)*-?
          type: string
  schemas:
    NetworkAccessPolicyRuleGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/NetworkAccessPolicyRuleResponse'
    NetworkAccessPolicyRuleInPolicy:
      allOf:
      - $ref: '#/components/schemas/NetworkAccessPolicyRuleBase'
      - $ref: '#/components/schemas/_policyRuleIndexInPolicy'
    NetworkAccessPolicyResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/NetworkAccessPolicy'
    _resource:
      description: 'An ordinary (as opposed to built-in) resource that can be created, named,

        renamed or deleted by the user. This might be a virtual resource (e.g., a

        file system), or correspond to something in the environment, like a host or a

        server.

        '
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified and cannot refer to another resource.

            '
          type: string
          readOnly: true
        name:
          description: 'A user-specified name.

            The name must be locally unique and can be changed.

            '
          type: string
    NetworkAccessPolicyRule:
      allOf:
      - $ref: '#/components/schemas/NetworkAccessPolicyRuleBase'
      - $ref: '#/components/schemas/_policyRuleIndex'
    _fixedReferenceWithoutType:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'The resource name, such as volume name, file system name,

            snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
    NetworkAccessPolicyGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/NetworkAccessPolicyResponse'
    NetworkAccessPolicyRulePost:
      allOf:
      - $ref: '#/components/schemas/NetworkAccessPolicyRulePostBase'
      - $ref: '#/components/schemas/_policyRuleIndex'
    NetworkAccessPolicyRuleResponse:
      type: object
      properties:
        items:
          description: 'Displays a list of all items after filtering.

            '
          type: array
          items:
            $ref: '#/components/schemas/NetworkAccessPolicyRule'
    NetworkAccessPolicy:
      allOf:
      - $ref: '#/components/schemas/PolicyBaseRenameable'
      - $ref: '#/components/schemas/_version'
      - type: object
        properties:
          rules:
            description: 'All of the rules that are part of this policy. The order is the

              evaluation order.

              If a client does not match any rule in the policy for the interface that

              they are attempting to access, the default is to deny access.

              '
            type: array
            maxItems: 200
            items:
              $ref: '#/components/schemas/NetworkAccessPolicyRuleInPolicy'
    NetworkAccessPolicyRuleBase:
      allOf:
      - $ref: '#/components/schemas/_builtIn'
      - type: object
        properties:
          client:
            description: 'Specifies the clients that will be permitted or denied access to the interface.

              Accepted notations include a single IP address, subnet in CIDR notation,

              or all clients (specified as `*`).

              The default value is `*` if not specified.

              '
            type: string
            example: 1.2.3.4
          effect:
            description: 'If set to `allow`, the specified client will be permitted to access the specified

              interfaces. If set to `deny`, the specified client will be denied access to them.

              Valid values include `allow` and `deny`.

              '
            type: string
          interfaces:
            description: 'Specifies which product interfaces this rule applies to, whether it is

              permitting or denying access. Valid values include `management-ssh`,

              `management-rest-api`, `management-web-ui`, `snmp`, and

              `local-network-superuser-password-access`.

              '
            type: array
            maxItems: 5
            items:
              type: string
          policy:
            description: The policy to which this rule belongs.
            title: FixedReference
            allOf:
            - $ref: '#/components/schemas/_fixedReference'
          policy_version:
            description: 'The policy''s version. This can be used when updating the

              resource to ensure there aren''t any updates to the policy since the resource was read.

              '
            type: string
            readOnly: true
    _builtIn:
      type: object
      properties:
        id:
          description: 'A non-modifiable, globally unique ID chosen by the system.

            '
          type: string
          readOnly: true
        name:
          description: Name of the object (e.g., a file system or snapshot).
          type: string
          readOnly: true
    PolicyMemberGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/PolicyMemberResponse'
    PolicyMemberResponse:
      type: object
      properties:
        items:
          description: A list of members for policies.
          type: array
          items:
            $ref: '#/components/schemas/PolicyMember'
    PolicyBaseRenameable:
      allOf:
      - $ref: '#/components/schemas/_resource'
      - $ref: '#/components/schemas/_realmsReference'
      - type: object
        properties:
          enabled:
            description: 'If `true`, the policy is enabled. If not specified, defaults to `true`.

              '
            type: boolean
          is_local:
            description: Whether the policy is defined on the local array.
            type: boolean
            readOnly: true
          location:
            description: Reference to the array where the policy is defined.
            title: FixedReference
            allOf:
            - $ref: '#/components/schemas/_fixedReference'
          policy_type:
            description: 'Type of the policy. Valid values include `alert`, `audit`, `bucket-access`,

              `cross-origin-resource-sharing`, `network-access`, `nfs`, `object-access`,

              `s3-export`, smb-client`, `smb-share`, `ssh-certificate-authority`, and

              `telemetry-metrics`.

              '
            type: string
            readOnly: true
    _policyRuleIndex:
      type: object
      properties:
        index:
          description: 'The index within the policy. The `index` indicates the order the rules are evaluated.

            NOTE: It is recommended to use the query param `before_rule_id` to do reordering to

            avoid concurrency issues, but changing `index` is also supported. `index` can not be

            changed if `before_rule_id` or `before_rule_name` are specified.

            '
          type: integer
          format: int32
    _realmsReference:
      type: object
      properties:
        realms:
          description: 'Reference to the realms this resource belongs to.

            The value is set to empty array when the resource

            lives outside of a realm.

            '
          type: array
          readOnly: true
          items:
            $ref: '#/components/schemas/_fixedReference'
    _fixedReference:
      allOf:
      - $ref: '#/components/schemas/_fixedReferenceWithoutType'
      - type: object
        properties:
          resource_type:
            description: 'Type of the object (full name of the endpoint).

              Valid values are the unique part of the resource''s REST endpoint.

              For example, a reference to a file system would have a

              `resource_type` of `file-systems`.

              '
            type: string
            readOnly: true
    NetworkAccessPolicyRulePostBase:
      allOf:
      - $ref: '#/components/schemas/_builtIn'
      - type: object
        properties:
          client:
            description: 'Specifies the clients that will be permitted or denied access to the interface.

              Accepted notations include a single IP address, subnet in CIDR notation,

              or all clients (specified as `*`).

              The default value is `*` if not specified.

              '
            type: string
            example: 1.2.3.4
          effect:
            description: 'If set to `allow`, the specified client will be permitted to access the specified

              interfaces. If set to `deny`, the specified client will be denied access to them.

              Valid values include `allow` and `deny`.

              The default value is `allow` if not specified.

              '
            type: string
          interfaces:
            description: 'Specifies which product interfaces this rule applies to, whether it is

              permitting or denying access. Valid values include `management-ssh`,

              `management-rest-api`, `management-web-ui`, `snmp`, and

              `local-network-superuser-password-access`.

              '
            type: array
            maxItems: 5
            items:
              type: string
    _policyRuleIndexInPolicy:
      type: object
      properties:
        index:
          description: 'The index within the policy. The `index` indicates the order the rules are evaluated.

            '
          type: integer
          format: int32
          readOnly: true
    _version:
      type: object
      properties:
        version:
          description: 'A hash of the other properties of this resource. This can be used when

            updating the resource to ensure there aren''t any updates since the

            resource was read.

            '
          type: string
          readOnly: true
    PolicyMember:
      type: object
      properties:
        member:
          description: Reference to the resource the policy is applied to.
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
        policy:
          description: Reference to the policy.
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
    PageInfo:
      type: object
      properties:
        continuation_token:
          description: 'Continuation token that can be provided in the `continuation_token` query

            param to get the next page of data.

            If you use the `continuation_token` to page through data you

            are guaranteed to get all items exactly once regardless of

            how items are modified. If an item is added or deleted during

            the pagination then it may or may not be returned.

            The `continuation_token` is generated if the `limit` is less

            than the remaining number of items, and the default sort is used

            (no sort is specified).

            '
          type: string
        total_item_count:
          description: Total number of items after applying `filter` params.
          type: integer
          format: int32