openapi: 3.0.1
info:
title: FlashArray REST Active Directory Policies - Object Store Access API
version: '2.52'
description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos
or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by
mapping identities across the NFS and SMB protocols by using LDAP queries.
'
servers:
- url: /
tags:
- name: Policies - Object Store Access
description: Manages access policies for object store users. Administrators can assign policies to users for managing buckets and objects.
paths:
/api/2.26/object-store-access-policies:
get:
tags:
- Policies - Object Store Access
summary: Pure Storage GET Object-store-access-policies
description: List access policies and their attributes.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Exclude_rules'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyGetResponse'
post:
tags:
- Policies - Object Store Access
summary: Pure Storage POST Object-store-access-policies
description: Create a new access policy.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Enforce_action_restrictions'
- $ref: '#/components/parameters/Names_required'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyPost'
required: false
x-codegen-request-body-name: policy
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyResponse'
x-codegen-request-body-name: policy
delete:
tags:
- Policies - Object Store Access
summary: Pure Storage DELETE Object-store-access-policies
description: Delete one or more access policies.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- Policies - Object Store Access
summary: Pure Storage PATCH Object-store-access-policies
description: Modify the rules of an object store access policy.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Enforce_action_restrictions'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyPatch'
required: false
x-codegen-request-body-name: policy
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyResponse'
x-codegen-request-body-name: policy
/api/2.26/object-store-access-policies/object-store-roles:
get:
tags:
- Policies - Object Store Access
summary: Pure Storage GET Object-store-access-policies/object-store-roles
description: List object store roles and their access policies.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Member_ids'
- $ref: '#/components/parameters/Member_names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
- $ref: '#/components/parameters/Sort'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyMemberContextGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyMemberContextGetResponse'
post:
tags:
- Policies - Object Store Access
summary: Pure Storage POST Object-store-access-policies/object-store-roles
description: Grant access policies to an object store role.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Member_ids'
- $ref: '#/components/parameters/Member_names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyMemberContextResponse'
delete:
tags:
- Policies - Object Store Access
summary: Pure Storage DELETE Object-store-access-policies/object-store-roles
description: Revoke an object store role's access policy.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Member_ids'
- $ref: '#/components/parameters/Member_names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
/api/2.26/object-store-access-policies/object-store-users:
get:
tags:
- Policies - Object Store Access
summary: Pure Storage GET Object-store-access-policies/object-store-users
description: List object store users and their access policies.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Member_ids'
- $ref: '#/components/parameters/Member_names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
- $ref: '#/components/parameters/Sort'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyMemberContextGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyMemberContextGetResponse'
post:
tags:
- Policies - Object Store Access
summary: Pure Storage POST Object-store-access-policies/object-store-users
description: Grant access policies to an object store user.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Member_ids'
- $ref: '#/components/parameters/Member_names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyMemberContextResponse'
delete:
tags:
- Policies - Object Store Access
summary: Pure Storage DELETE Object-store-access-policies/object-store-users
description: Revokes an object store user's access policy.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Member_ids'
- $ref: '#/components/parameters/Member_names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
/api/2.26/object-store-access-policies/rules:
get:
tags:
- Policies - Object Store Access
summary: Pure Storage GET Object-store-access-policies-rules
description: List access policy rules and their attributes.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
- $ref: '#/components/parameters/Sort'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyRuleGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyRuleGetResponse'
post:
tags:
- Policies - Object Store Access
summary: Pure Storage POST Object-store-access-policies-rules
description: Create a new access policy rule.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Enforce_action_restrictions'
- $ref: '#/components/parameters/Names_required'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyRuleObjectAccessPost'
required: true
x-codegen-request-body-name: rule
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyRuleResponse'
x-codegen-request-body-name: rule
delete:
tags:
- Policies - Object Store Access
summary: Pure Storage DELETE Object-store-access-policies-rules
description: Delete one or more access policy rules.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- Policies - Object Store Access
summary: Pure Storage PATCH Object-store-access-policies-rules
description: Modify an access policy rule's attributes.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Enforce_action_restrictions'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/PolicyRuleObjectAccessPost'
required: true
x-codegen-request-body-name: rule
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyRuleResponse'
x-codegen-request-body-name: rule
/api/2.26/object-store-access-policy-actions:
get:
tags:
- Policies - Object Store Access
summary: Pure Storage GET Object-store-access-policy-actions
description: 'List valid actions for access policy rules. Each action is either a valid
AWS S3 action (prefixed by `s3:`) or our special wildcard action (`s3:*`).
Each action, when included in a rule, may restrict which other properties
may be set for that rule.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyActionGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/ObjectStoreAccessPolicyActionGetResponse'
components:
schemas:
ObjectStoreAccessPolicyPost:
allOf:
- $ref: '#/components/schemas/ObjectStoreAccessPolicyPatch'
- type: object
properties:
description:
description: 'A description of the policy, optionally specified when the policy is
created. Cannot be modified for an existing policy.
'
type: string
_builtInNoId:
type: object
properties:
name:
description: Name of the object (e.g., a file system or snapshot).
type: string
readOnly: true
PolicyMember:
type: object
properties:
member:
description: Reference to the resource the policy is applied to.
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
policy:
description: Reference to the policy.
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
ObjectStoreAccessPolicy:
allOf:
- $ref: '#/components/schemas/PolicyBase'
- $ref: '#/components/schemas/_context'
- type: object
properties:
account:
description: 'Reference of the associated account. If the policy is not associated
with an account, all fields in the reference possess `null` values.
'
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
arn:
description: 'Amazon Resource Name of the policy. Used when referencing the policy via
S3 APIs.
'
type: string
readOnly: true
example: arn:aws:iam::myaccount:policy/mypolicy
created:
description: Creation timestamp of the object.
type: integer
format: int64
readOnly: true
description:
description: 'A description of the policy, optionally specified when the policy is
created. Cannot be modified for an existing policy.
'
type: string
readOnly: true
example: This policy allows users to list objects in production buckets.
enabled:
description: 'If `true`, the policy is enabled. If not specified, defaults to `true`.
'
type: boolean
readOnly: true
rules:
type: array
items:
$ref: '#/components/schemas/PolicyRuleObjectAccess'
updated:
description: The last updated timestamp of the object.
type: integer
format: int64
readOnly: true
_errorContextResponseErrors:
type: object
properties:
context:
description: 'Contains information relating to the cause of this error,
or the name of the object that was being processed when the error was encountered.
This may be `null` for more general errors.
'
type: string
location_context:
description: 'Contains information relating to the context in which the request was executing
when the error occurred.
For example, this may be the name of an array in the same fleet.
This may be `null` for more general errors, or if no explicit `context` parameter
was provided with the request.
'
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
message:
description: A description of the error which occurred.
type: string
example: Resource does not exist.
_errorContextResponse:
type: object
properties:
errors:
description: The list of errors encountered when attempting to perform an operation.
type: array
readOnly: true
items:
$ref: '#/components/schemas/_errorContextResponseErrors'
ObjectStoreAccessPolicyGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/_errorContextResponse'
- $ref: '#/components/schemas/ObjectStoreAccessPolicyResponse'
ObjectStoreAccessPolicyActionGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/_errorContextResponse'
- $ref: '#/components/schemas/ObjectStoreAccessPolicyActionResponse'
ObjectStoreAccessPolicyAction:
allOf:
- $ref: '#/components/schemas/_builtInNoId'
- $ref: '#/components/schemas/_context'
- type: object
properties:
description:
description: 'A description of the action.
'
type: string
readOnly: true
example: Grants permission to create a new bucket.
PolicyRuleObjectAccessBulkManage:
allOf:
- $ref: '#/components/schemas/PolicyRuleObjectAccessPost'
- type: object
properties:
name:
description: Name of the object (e.g., a file system or snapshot).
type: string
ObjectStoreAccessPolicyRuleResponse:
type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/PolicyRuleObjectAccess'
PolicyBase:
allOf:
- $ref: '#/components/schemas/PolicyBaseRenameable'
PolicyMemberContextGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/PolicyMemberContextResponse'
- $ref: '#/components/schemas/_errorContextResponse'
_resource:
description: 'An ordinary (as opposed to built-in) resource that can be created, named,
renamed or deleted by the user. This might be a virtual resource (e.g., a
file system), or correspond to something in the environment, like a host or a
server.
'
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified and cannot refer to another resource.
'
type: string
readOnly: true
name:
description: 'A user-specified name.
The name must be locally unique and can be changed.
'
type: string
_fixedReferenceWithoutType:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'The resource name, such as volume name, file system name,
snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
PolicyRuleObjectAccessPost:
type: object
properties:
actions:
description: 'The list of actions granted by this rule. Each included action may
restrict other properties of the rule.
Supported actions are returned by the
`/object-store-access-policy-actions` endpoint.
'
type: array
items:
type: string
example:
- s3:CreateBucket
- s3:PutObject
conditions:
description: 'Conditions used to limit the scope which this rule applies to.
'
title: PolicyRuleObjectAccessCondition
allOf:
- $ref: '#/components/schemas/_policyRuleObjectAccessCondition'
effect:
description: 'Effect of this rule.
When `allow`, the rule allows the given actions to be performed on the
given resources, subject to the given conditions.
When `deny`, the rule disallows performing the given actions on the given
resources, subject to the given condition. This takes precedence over any
matching `allow` rules.
Valid values include `allow` and `deny`.
'
type: string
example: allow
resources:
description: 'The list of resources which this rule applies to. Each resource can
include a bucket component, optionally followed by an object component.
The choice of which components a resource can include is dictated by
which actions are included in the rule. For further details, see the
Object Store Access Policy Actions section of the User Guide.
'
type: array
items:
type: string
example:
- '*'
- mybucket
- mybucket*
- mybucket*/myobject*
ObjectStoreAccessPolicyRuleGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/_errorContextResponse'
- $ref: '#/components/schemas/ObjectStoreAccessPolicyRuleResponse'
ObjectStoreAccessPolicyPatch:
type: object
properties:
rules:
type: array
items:
$ref: '#/components/schemas/PolicyRuleObjectAccessBulkManage'
PolicyMemberContextResponse:
type: object
properties:
items:
description: A list of members for policies.
type: array
items:
$ref: '#/components/schemas/PolicyMemberContext'
_policyRuleObjectAccessCondition:
type: object
properties:
s3_delimiters:
description: 'If specified, groups result objects by the specified delimiter. Only
top-level groupings will be returned.
Can be used with the `s3:ListBucket` and `s3:ListBucketVersions` actions.
'
type: array
items:
type: string
example: /
s3_prefixes:
description: 'If specified, restricts access and results based on the prefix of the
relevant objects.
Can be used with the `s3:ListBucket` and `s3:ListBucketVersions` actions.
'
type: array
items:
type: string
example: home/
source_ips:
description: 'If specified, the rule will apply only to requests matching at least one
provided IP address or subnet.
Each entry must be in standard CIDR format (including an IP address
without an associated routing prefix).
Can be used with any action.
'
type: array
items:
type: string
example:
- 1.2.3.4
- 5.6.7.0/24
- 2001:DB8:1234:5678::/64
_context:
type: object
properties:
context:
description: 'The context in which the operation was performed.
Valid values include a reference to any array which is a member of the same fleet
or to the fleet itself.
Other parameters provided with the request, such as names of volumes or snapshots,
are resolved relative to the provided `context`.
'
readOnly: true
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
PolicyBaseRenameable:
allOf:
- $ref: '#/components/schemas/_resource'
- $ref: '#/components/schemas/_realmsReference'
- type: object
properties:
enabled:
description: 'If `true`, the policy is enabled. If not specified, defaults to `true`.
'
type: boolean
is_local:
description: Whether the policy is defined on the local array.
type: boolean
readOnly: true
location:
description: Reference to the array where the policy is defined.
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
policy_type:
description: 'Type of the policy. Valid values include `alert`, `audit`, `bucket-access`,
`cross-origin-resource-sharing`, `network-access`, `nfs`, `object-access`,
`s3-export`, smb-client`, `smb-share`, `ssh-certificate-authority`, and
`telemetry-metrics`.
'
type: string
readOnly: true
ObjectStoreAccessPolicyActionResponse:
type: object
properties:
items:
type: array
items:
$ref: '#/components/schemas/ObjectStoreAccessPolicyAction'
PolicyRuleObjectAccess:
allOf:
- $ref: '#/components/schemas/_builtInNoId'
- $ref: '#/components/schemas/_context'
- type: object
properties:
actions:
description: 'The list of actions granted by this rule. Each included action may
restrict other properties of the rule.
Supported actions are returned by the
`/object-store-access-policy-actions` endpoint.
'
type: array
items:
type: string
example:
- s3:CreateBucket
- s3:PutObject
conditions:
description: 'Conditions used to limit the scope which this rule applies to.
'
title: PolicyRuleObjectAccessCondition
allOf:
- $ref: '#/components/schemas/_policyRuleObjectAccessCondition'
effect:
description: 'Effect of this rule.
When `allow`, the rule allows the given actions to be performed
# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-policies-object-store-access-api-openapi.yml