Pure Storage Policies - NFS API

Manages NFS export policies. These policies are composed of rules which govern a client's ability to access the exported filesystem.

Documentation

Specifications

Code Examples

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-volume-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-host-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-array-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-volume-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-file-system-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-bucket-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-array-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-file-system-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-bucket-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-metric-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-alert-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/pure1-cloud-api-array-structure.json

Other Resources

🔗
SDKs
https://pypi.org/project/py-pure-client/
🔗
SDKs
https://github.com/PureStorage-OpenConnect/PureStorage.Pure1
🔗
SDKs
https://github.com/PureStorage-OpenConnect/powershell-toolkit-3
🔗
SDKs
https://github.com/PureStorage-OpenConnect/rest-client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/terraform-provider-flash
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fa-openmetrics-exporter
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flasharray-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-volume-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-array-example.json
🔗
SDKs
https://github.com/PureStorage-OpenConnect/flashblade-powershell
🔗
SDKs
https://github.com/purestorage/purity_fb_python_client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fb-openmetrics-exporter
🔗
Tools
https://github.com/PureStorage-OpenConnect/flashblade-mcp-server
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flashblade-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-file-system-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-bucket-example.json
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-pure1-cloud-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/pure1-cloud-api-array-example.json

OpenAPI Specification

pure-storage-policies-nfs-api-openapi.yml Raw ↑
openapi: 3.0.1
info:
  title: FlashArray REST Active Directory Policies - NFS API
  version: '2.52'
  description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos

    or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by

    mapping identities across the NFS and SMB protocols by using LDAP queries.

    '
servers:
- url: /
tags:
- name: Policies - NFS
  description: Manages NFS export policies. These policies are composed of rules which govern a client's ability to access the exported filesystem.
paths:
  /api/2.26/nfs-export-policies:
    get:
      tags:
      - Policies - NFS
      summary: Pure Storage GET Nfs-export-policies
      description: Displays a list of NFS export policies.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      - $ref: '#/components/parameters/Workload_ids'
      - $ref: '#/components/parameters/Workload_names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyGetResponse'
    post:
      tags:
      - Policies - NFS
      summary: Pure Storage POST Nfs-export-policies
      description: Create a new NFS export policy.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Names_required'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NfsExportPolicyPost'
        required: false
        x-codegen-request-body-name: policy
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyResponse'
      x-codegen-request-body-name: policy
    delete:
      tags:
      - Policies - NFS
      summary: Pure Storage DELETE Nfs-export-policies
      description: Delete one or more NFS export policies.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
    patch:
      tags:
      - Policies - NFS
      summary: Pure Storage PATCH Nfs-export-policies
      description: Modify an existing NFS export policy's attributes.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NfsExportPolicyPatch'
        required: true
        x-codegen-request-body-name: policy
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyResponse'
      x-codegen-request-body-name: policy
  /api/2.26/nfs-export-policies/rules:
    get:
      tags:
      - Policies - NFS
      summary: Pure Storage GET Nfs-export-policies/rules
      description: 'Displays a list of NFS export policy rules.

        The default sort is by policy name, then index.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyRuleGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyRuleGetResponse'
    post:
      tags:
      - Policies - NFS
      summary: Pure Storage POST Nfs-export-policies/rules
      description: 'Add a NFS export policy rule. Rules are ordered in three groups; ip addresses, other and `*`.

        The new rule will be added at the end of the appropriate group if neither

        `before_rule_id` and `before_rule_name` are specified. Rules can only be inserted into the

        appropriate group.

        Either `policy_ids` or `policy_names` parameter is required.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Before_rule_id'
      - $ref: '#/components/parameters/Before_rule_name'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Versions'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NfsExportPolicyRule'
        required: true
        x-codegen-request-body-name: rule
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyRuleResponse'
      x-codegen-request-body-name: rule
    delete:
      tags:
      - Policies - NFS
      summary: Pure Storage DELETE Nfs-export-policies/rules
      description: 'Delete one or more NFS export policy rules.

        One of the following is required: `ids` or `names`.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
    patch:
      tags:
      - Policies - NFS
      summary: Pure Storage PATCH Nfs-export-policies/rules
      description: 'Modify an existing NFS export policy rule.

        If `before_rule_id` or `before_rule_name` are specified, the rule will be moved before that

        rule. Rules are ordered in three groups; ip addresses, other and `*` and can only be moved

        within the appropriate group.

        One of the following is required: `ids` or `names`.

        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Before_rule_id'
      - $ref: '#/components/parameters/Before_rule_name'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Versions'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NfsExportPolicyRulePatch'
        required: true
        x-codegen-request-body-name: rule
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/NfsExportPolicyRuleResponse'
      x-codegen-request-body-name: rule
components:
  parameters:
    Versions:
      name: versions
      in: query
      description: 'A comma-separated list of versions. This is an optional query param used for concurrency control.

        The ordering should match the names or ids query param.

        This will fail with a 412 Precondition failed if the resource was changed and the current

        version of the resource doesn''t match the value in the query param.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Filter:
      name: filter
      in: query
      description: 'Narrows down the results to only the response objects

        that satisfy the filter criteria.

        '
      schema:
        type: string
    Offset:
      name: offset
      in: query
      description: 'The offset of the first resource to return from a collection.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    Allow_errors:
      name: allow_errors
      in: query
      description: 'If set to `true`, the API will allow the operation to continue even if there are errors.

        Any errors will be returned in the `errors` field of the response.

        If set to `false`, the operation will fail if there are any errors.

        '
      schema:
        type: boolean
        default: false
    Before_rule_id:
      name: before_rule_id
      in: query
      description: 'The id of the rule to insert or move a rule before.

        This cannot be provided together with the `before_rule_name` query parameter.

        '
      schema:
        type: string
    Before_rule_name:
      name: before_rule_name
      in: query
      description: 'The name of the rule to insert or move a rule before.

        This cannot be provided together with the `before_rule_id` query parameter.

        '
      schema:
        type: string
    Policy_ids:
      name: policy_ids
      in: query
      description: 'A comma-separated list of policy IDs.

        If after filtering, there is not at least one resource that matches

        each of the elements of `policy_ids`, then an error is returned.

        This cannot be provided together with the `policy_names` query parameter.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Continuation_token:
      name: continuation_token
      in: query
      description: 'A token used to retrieve the next page of data

        with some consistency guaranteed.

        The token is a Base64 encoded value.

        Set `continuation_token` to the system-generated token taken from the `x-next-token`

        header field of the response.

        A query has reached its last page when the response does not include a token.

        Pagination requires the `limit` and `continuation_token`

        query parameters.

        '
      schema:
        type: string
    Policy_names:
      name: policy_names
      in: query
      description: 'A comma-separated list of policy names.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Context_names:
      name: context_names
      in: query
      description: 'Performs the operation on the context specified.


        If specified, the context names must be an array of size 1, and the single element

        must be the name of an array in the same fleet or the name of the fleet itself. If

        not specified, the context will default to the array that received this request.


        Other parameters provided with the request, such as names of volumes or snapshots,

        are resolved relative to the provided `context`.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Workload_ids:
      name: workload_ids
      in: query
      description: 'A comma-separated list of workload IDs. If, after filtering, there is not at least one

        resource that matches each of the elements, then an error is returned. This cannot be provided

        together with the `workload_names` query parameter.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    XRequestId:
      name: X-Request-ID
      in: header
      description: 'Supplied by client during request or generated by server.

        '
      schema:
        type: string
    Limit:
      name: limit
      in: query
      description: 'Limits the size of the response to the specified number of objects on each page.

        To return the total number of resources, set `limit=0`.

        The total number of resources is returned as a `total_item_count` value.

        If the page size requested is larger than the system maximum limit,

        the server returns the maximum limit, disregarding the requested page size.

        '
      schema:
        type: integer
        format: int32
        minimum: 0
      example: 10
    Names:
      name: names
      in: query
      description: 'Performs the operation on the unique names specified.

        Enter multiple names in comma-separated format.

        For example, `name01,name02`.


        If there is not at least one resource that matches

        each of the elements of `names`, then an error is returned,

        except when creating new resources.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Context_names_get:
      name: context_names
      in: query
      description: 'Performs the operation on the unique contexts specified.


        If specified, each context name must be the name of an array in the same fleet or

        the name of the fleet itself.


        If not specified, the context will default to the array that received this request.


        Other parameters provided with the request, such as names of volumes or snapshots,

        are resolved relative to the provided `context`.


        Enter multiple names in comma-separated format.

        For example, `name01,name02`.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Ids:
      name: ids
      in: query
      description: 'A comma-separated list of resource IDs.

        If after filtering, there is not at least one resource that matches

        each of the elements of `ids`, then an error is returned.

        This cannot be provided together with the `name` or `names` query parameters.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Workload_names:
      name: workload_names
      in: query
      description: 'A comma-separated list of workload names. If, after filtering, there is not at least one

        resource that matches each of the elements, then an error is returned. This cannot be provided

        together with the `workload_ids` query parameter.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
    Sort:
      name: sort
      in: query
      description: 'Sort the response by the specified fields (in descending order if ''-''

        is appended to the field name).

        NOTE: If you provide a sort you will not get a `continuation_token` in

        the response.

        '
      style: form
      explode: false
      schema:
        type: array
        items:
          pattern: ^[a-z]+(_[a-z]+)*-?
          type: string
    Names_required:
      name: names
      in: query
      description: 'A comma-separated list of resource names.

        '
      required: true
      style: form
      explode: false
      schema:
        type: array
        items:
          type: string
  schemas:
    _errorContextResponseErrors:
      type: object
      properties:
        context:
          description: 'Contains information relating to the cause of this error,

            or the name of the object that was being processed when the error was encountered.

            This may be `null` for more general errors.

            '
          type: string
        location_context:
          description: 'Contains information relating to the context in which the request was executing

            when the error occurred.

            For example, this may be the name of an array in the same fleet.

            This may be `null` for more general errors, or if no explicit `context` parameter

            was provided with the request.

            '
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
        message:
          description: A description of the error which occurred.
          type: string
          example: Resource does not exist.
    _errorContextResponse:
      type: object
      properties:
        errors:
          description: The list of errors encountered when attempting to perform an operation.
          type: array
          readOnly: true
          items:
            $ref: '#/components/schemas/_errorContextResponseErrors'
    NfsExportPolicyRule:
      allOf:
      - $ref: '#/components/schemas/NfsExportPolicyRuleBase'
      - $ref: '#/components/schemas/_policyRuleIndex'
      - $ref: '#/components/schemas/_context'
    NfsExportPolicyResponse:
      type: object
      properties:
        items:
          description: A list of NFS export policy objects.
          type: array
          items:
            $ref: '#/components/schemas/NfsExportPolicy'
    NfsExportPolicy:
      allOf:
      - $ref: '#/components/schemas/PolicyBaseRenameable'
      - $ref: '#/components/schemas/_version'
      - $ref: '#/components/schemas/_context'
      - type: object
        properties:
          rules:
            description: 'All of the rules that are part of this policy. The order is the evaluation order.

              '
            type: array
            items:
              $ref: '#/components/schemas/NfsExportPolicyRuleInPolicy'
          workload:
            $ref: '#/components/schemas/_workloadConfigurationFixedReference'
    PolicyBase:
      allOf:
      - $ref: '#/components/schemas/PolicyBaseRenameable'
    _resource:
      description: 'An ordinary (as opposed to built-in) resource that can be created, named,

        renamed or deleted by the user. This might be a virtual resource (e.g., a

        file system), or correspond to something in the environment, like a host or a

        server.

        '
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified and cannot refer to another resource.

            '
          type: string
          readOnly: true
        name:
          description: 'A user-specified name.

            The name must be locally unique and can be changed.

            '
          type: string
    _fixedReferenceWithoutType:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'The resource name, such as volume name, file system name,

            snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
    NfsExportPolicyRuleBasePatchRequest:
      allOf:
      - $ref: '#/components/schemas/_builtIn'
      - type: object
        properties:
          access:
            description: 'Specifies access control for the export. Valid values are `root-squash`, `all-squash`, and

              `no-squash`.

              `root-squash` prevents client users and groups with root privilege from mapping their

              root privilege to a file system. All users with UID 0 will have their UID mapped to anonuid.

              All users with GID 0 will have their GID mapped to anongid.

              `all-squash` maps all UIDs (including root) to anonuid and all GIDs (including root) to

              anongid.

              `no-squash` allows users and groups to access the file system with their UIDs and GIDs.

              The default is `root-squash` if not specified.

              '
            type: string
          anongid:
            description: 'Any user whose GID is affected by an `access` of `root_squash` or `all_squash` will have

              their GID mapped to `anongid`. The default `anongid` is null, which means 65534.

              Use "" to clear.

              '
            type: string
            example: '65530'
          anonuid:
            description: 'Any user whose UID is affected by an `access` of `root_squash` or `all_squash` will have

              their UID mapped to `anonuid`. The default `anonuid` is null, which means 65534.

              Use "" to clear.

              '
            type: string
            example: '65530'
          atime:
            description: 'If `true`, after a read operation has occurred, the inode access time is updated only if any

              of the following conditions is true: the previous access time is less than the inode modify

              time, the previous access time is less than the inode change time, or the previous access

              time is more than 24 hours ago.

              If `false`, disables the update of inode access times after read operations.

              Defaults to `true`.

              '
            type: boolean
          client:
            description: 'Specifies the clients that will be permitted to access the export.

              Accepted notation is a single IP address, subnet in CIDR notation, netgroup,

              hostname (see RFC-1123 part 2.1), fully qualified domain name

              (see RFC-1123 part 2.1, RFC 2181 part 11), wildcards with fully qualified domain name

              or hostname, or anonymous (`*`).

              The default is `*` if not specified.

              '
            type: string
          fileid_32bit:
            description: 'Whether the file id is 32 bits or not. Defaults to `false`.

              '
            type: boolean
          permission:
            description: 'Specifies which read-write client access permissions are allowed for the export.

              Valid values are `rw` and `ro`. The default is `ro` if not specified.

              '
            type: string
          required_transport_security:
            description: 'Specifies the minimum transport security required for clients to access the export.

              If `tls` is set, then all clients must use TLS or their attempts to mount will be rejected,

              and further use of client certificate authentication is optional.

              If `mutual-tls` is set, then all clients must use TLS with client certificate authentication

              or their attempts to mount will be rejected.

              If `none`, then no specific transport security mechanism is required and any transport

              security mechanisms are permitted for use.

              If not specified when a rule is created, defaults to `none`.

              '
            type: string
            example: tls
          secure:
            description: 'If `true`, prevents NFS access to client connections coming from non-reserved ports. Applies

              to NFSv3, NFSv4.1, and auxiliary protocols MOUNT and NLM.

              If `false`, allows NFS access to client connections coming from non-reserved ports. Applies

              to NFSv3, NFSv4.1, and auxiliary protocols MOUNT and NLM.

              The default is `false` if not specified.

              '
            type: boolean
          security:
            description: 'The security flavors to use for accessing files on this mount point.  If the server does not

              support the requested flavor, the mount operation fails.

              If `sys`, trusts the client to specify user''s identity.

              If `krb5`, provides cryptographic proof of a user''s identity in each RPC request. This

              provides  strong verification of the identity of users accessing data on the server.

              Note that additional configuration besides adding this mount option is required in order to

              enable Kerberos security.

              If `krb5i`, adds integrity checking to krb5, to ensure the data has not been tampered with.

              If `krb5p`, adds integrity checking and encryption to krb5. This is the most secure setting,

              but it also involves the most performance overhead.

              The default is `sys` if not specified.

              '
            type: array
            items:
              type: string
              example: sys
    _builtIn:
      type: object
      properties:
        id:
          description: 'A non-modifiable, globally unique ID chosen by the system.

            '
          type: string
          readOnly: true
        name:
          description: Name of the object (e.g., a file system or snapshot).
          type: string
          readOnly: true
    NfsExportPolicyRuleBase:
      allOf:
      - $ref: '#/components/schemas/_builtIn'
      - type: object
        properties:
          access:
            description: 'Specifies access control for the export. Valid values are `root-squash`, `all-squash`, and

              `no-squash`.

              `root-squash` prevents client users and groups with root privilege from mapping their

              root privilege to a file system. All users with UID 0 will have their UID mapped to anonuid.

              All users with GID 0 will have their GID mapped to anongid.

              `all-squash` maps all UIDs (including root) to anonuid and all GIDs (including root) to

              anongid.

              `no-squash` allows users and groups to access the file system with their UIDs and GIDs.

              The default is `root-squash` if not specified.

              '
            type: string
          anongid:
            description: 'Any user whose GID is affected by an `access` of `root_squash` or `all_squash` will have

              their GID mapped to `anongid`. The default `anongid` is null, which means 65534.

              Use "" to clear.

              '
            type: integer
            format: int64
            minimum: 0
            example: 65530
          anonuid:
            description: 'Any user whose UID is affected by an `access` of `root_squash` or `all_squash` will have

              their UID mapped to `anonuid`. The default `anonuid` is null, which means 65534.

              Use "" to clear.

              '
            type: integer
            format: int64
            minimum: 0
            example: 65530
          atime:
            description: 'If `true`, after a read operation has occurred, the inode access time is updated only if any

              of the following conditions is true: the previous access time is less than the inode modify

              time, the previous access time is less than the inode change time, or the previous access

              time is more than 24 hours ago.

              If `false`, disables the update of inode access times after read operations.

              Defaults to `true`.

              '
            type: boolean
          client:
            description: 'Specifies the clients that will be permitted to access the export.

              Accepted notation is a single IP address, subnet in CIDR notation, netgroup,

              hostname (see RFC-1123 part 2.1), fully qualified domain name

              (see RFC-1123 part 2.1, RFC 2181 part 11), wildcards with fully qualified domain name

              or hostname, or anonymous (`*`).

              The default is `*` if not specified.

              '
            type: string
          fileid_32bit:
            description: 'Whether the file id is 32 bits or not. Defaults to `false`.

              '
            type: boolean
          permission:
            description: 'Specifies which read-write client access permissions are allowed for the export.

              Valid values are `rw` and `ro`. The default is `ro` if not specified.

              '
            type: string
          policy:
            description: The policy to which this rule belongs.
            title: FixedReference
            allOf:
            - $ref: '#/components/schemas/_fixedReference'
          policy_version:
            description: 'The policy''s version. This can be used when updating the

              resource to ensure there aren''t any updates to the policy since the resource was read.

              '
            type: string
            readOnly: true
          required_transport_security:
            description: 'Specifies the minimum transport security required for clients to access the export.

              If `tls` is set, then all clients must use TLS or their attempts to mount will be rejected,

              and further use of client certificate authentication is optional.

              If `mutual-tls` is set, then all clients must use TLS with client certificate authentication

              or their attempts to mount will be rejected.

              If `none`, then no specific transport security mechanism is required and any transport

              security mechanisms are permitted for use.

              If not specified when a rule is created, defaults to `none`.

              '
            type: string
            example: tls
          secure:
            description: 'If `true`, prevents NFS access to client connections coming from non-reserved ports. Applies

              to NFSv3, NFSv4.1, and auxiliary protocols MOUNT and NLM.

              If `false`, allows NFS access to cl

# --- truncated at 32 KB (40 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-policies-nfs-api-openapi.yml