Pure Storage Policies - Object Store Access API

Manages access policies for object store users. Administrators can assign policies to users for managing buckets and objects.

Operations 15

GET /api/2.26/object-store-access-policies Pure Storage GET Object-store-access-policies
POST /api/2.26/object-store-access-policies Pure Storage POST Object-store-access-policies
DELETE /api/2.26/object-store-access-policies Pure Storage DELETE Object-store-access-policies
PATCH /api/2.26/object-store-access-policies Pure Storage PATCH Object-store-access-policies
GET /api/2.26/object-store-access-policies/object-store-roles Pure Storage GET Object-store-access-policies/object-store-roles
POST /api/2.26/object-store-access-policies/object-store-roles Pure Storage POST Object-store-access-policies/object-store-roles
DELETE /api/2.26/object-store-access-policies/object-store-roles Pure Storage DELETE Object-store-access-policies/object-store-roles
GET /api/2.26/object-store-access-policies/object-store-users Pure Storage GET Object-store-access-policies/object-store-users
POST /api/2.26/object-store-access-policies/object-store-users Pure Storage POST Object-store-access-policies/object-store-users
DELETE /api/2.26/object-store-access-policies/object-store-users Pure Storage DELETE Object-store-access-policies/object-store-users
GET /api/2.26/object-store-access-policies/rules Pure Storage GET Object-store-access-policies-rules
POST /api/2.26/object-store-access-policies/rules Pure Storage POST Object-store-access-policies-rules
DELETE /api/2.26/object-store-access-policies/rules Pure Storage DELETE Object-store-access-policies-rules
PATCH /api/2.26/object-store-access-policies/rules Pure Storage PATCH Object-store-access-policies-rules
GET /api/2.26/object-store-access-policy-actions Pure Storage GET Object-store-access-policy-actions

Documentation

Specifications

Code Examples

Schemas & Data

📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-volume-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flasharray-rest-api-host-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flasharray-rest-api-volume-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-file-system-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-bucket-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/flashblade-rest-api-array-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-file-system-structure.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/flashblade-rest-api-bucket-structure.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-array-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-metric-schema.json
📊
JSONSchema
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-schema/pure1-cloud-api-alert-schema.json
📊
JSONStructure
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-structure/pure1-cloud-api-array-structure.json

Other Resources

🔗
SDKs
https://pypi.org/project/py-pure-client/
🔗
SDKs
https://github.com/PureStorage-OpenConnect/PureStorage.Pure1
🔗
SDKs
https://github.com/PureStorage-OpenConnect/powershell-toolkit-3
🔗
SDKs
https://github.com/PureStorage-OpenConnect/rest-client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/terraform-provider-flash
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fa-openmetrics-exporter
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flasharray-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flasharray-rest-api-volume-example.json
🔗
SDKs
https://github.com/PureStorage-OpenConnect/flashblade-powershell
🔗
SDKs
https://github.com/purestorage/purity_fb_python_client
🔗
Integrations
https://github.com/PureStorage-OpenConnect/pure-fb-openmetrics-exporter
🔗
Tools
https://github.com/PureStorage-OpenConnect/flashblade-mcp-server
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-flashblade-rest-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-file-system-example.json
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/flashblade-rest-api-bucket-example.json
🔗
JSONLD
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/json-ld/pure-storage-pure1-cloud-api-context.jsonld
🔗
Examples
https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/examples/pure1-cloud-api-array-example.json

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/pure-storage-policies-object-store-access-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

pure-storage-policies-object-store-access-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: FlashArray REST Active Directory Policies - Object Store Access API
  version: '2.52'
  description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos

    or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by

    mapping identities across the NFS and SMB protocols by using LDAP queries.

    '
servers:
- url: /
tags:
- name: Policies - Object Store Access
  description: Manages access policies for object store users. Administrators can assign policies to users for managing buckets and objects.
paths:
  /api/2.26/object-store-access-policies:
    get:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage GET Object-store-access-policies
      description: List access policies and their attributes.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Exclude_rules'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyGetResponse'
    post:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage POST Object-store-access-policies
      description: Create a new access policy.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Enforce_action_restrictions'
      - $ref: '#/components/parameters/Names_required'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ObjectStoreAccessPolicyPost'
        required: false
        x-codegen-request-body-name: policy
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyResponse'
      x-codegen-request-body-name: policy
    delete:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage DELETE Object-store-access-policies
      description: Delete one or more access policies.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
    patch:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage PATCH Object-store-access-policies
      description: Modify the rules of an object store access policy.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Enforce_action_restrictions'
      - $ref: '#/components/parameters/Ids'
      - $ref: '#/components/parameters/Names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ObjectStoreAccessPolicyPatch'
        required: false
        x-codegen-request-body-name: policy
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyResponse'
      x-codegen-request-body-name: policy
  /api/2.26/object-store-access-policies/object-store-roles:
    get:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage GET Object-store-access-policies/object-store-roles
      description: List object store roles and their access policies.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberContextGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberContextGetResponse'
    post:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage POST Object-store-access-policies/object-store-roles
      description: Grant access policies to an object store role.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberContextResponse'
    delete:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage DELETE Object-store-access-policies/object-store-roles
      description: Revoke an object store role's access policy.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
  /api/2.26/object-store-access-policies/object-store-users:
    get:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage GET Object-store-access-policies/object-store-users
      description: List object store users and their access policies.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberContextGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberContextGetResponse'
    post:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage POST Object-store-access-policies/object-store-users
      description: Grant access policies to an object store user.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PolicyMemberContextResponse'
    delete:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage DELETE Object-store-access-policies/object-store-users
      description: Revokes an object store user's access policy.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Member_ids'
      - $ref: '#/components/parameters/Member_names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
  /api/2.26/object-store-access-policies/rules:
    get:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage GET Object-store-access-policies-rules
      description: List access policy rules and their attributes.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyRuleGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyRuleGetResponse'
    post:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage POST Object-store-access-policies-rules
      description: Create a new access policy rule.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Enforce_action_restrictions'
      - $ref: '#/components/parameters/Names_required'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PolicyRuleObjectAccessPost'
        required: true
        x-codegen-request-body-name: rule
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyRuleResponse'
      x-codegen-request-body-name: rule
    delete:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage DELETE Object-store-access-policies-rules
      description: Delete one or more access policy rules.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content: {}
    patch:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage PATCH Object-store-access-policies-rules
      description: Modify an access policy rule's attributes.
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Context_names'
      - $ref: '#/components/parameters/Enforce_action_restrictions'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Policy_ids'
      - $ref: '#/components/parameters/Policy_names'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PolicyRuleObjectAccessPost'
        required: true
        x-codegen-request-body-name: rule
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyRuleResponse'
      x-codegen-request-body-name: rule
  /api/2.26/object-store-access-policy-actions:
    get:
      tags:
      - Policies - Object Store Access
      summary: Pure Storage GET Object-store-access-policy-actions
      description: 'List valid actions for access policy rules. Each action is either a valid

        AWS S3 action (prefixed by `s3:`) or our special wildcard action (`s3:*`).

        Each action, when included in a rule, may restrict which other properties

        may be set for that rule.


        '
      parameters:
      - $ref: '#/components/parameters/XRequestId'
      - $ref: '#/components/parameters/Allow_errors'
      - $ref: '#/components/parameters/Context_names_get'
      - $ref: '#/components/parameters/Continuation_token'
      - $ref: '#/components/parameters/Filter'
      - $ref: '#/components/parameters/Limit'
      - $ref: '#/components/parameters/Names'
      - $ref: '#/components/parameters/Offset'
      - $ref: '#/components/parameters/Sort'
      responses:
        '200':
          description: OK
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyActionGetResponse'
        '207':
          description: 'Partial success. Some resources were returned, but there

            were also errors possibly preventing some resources from

            being returned.

            '
          headers:
            X-Request-ID:
              description: Supplied by client during request or generated by server.
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ObjectStoreAccessPolicyActionGetResponse'
components:
  schemas:
    ObjectStoreAccessPolicyPost:
      allOf:
      - $ref: '#/components/schemas/ObjectStoreAccessPolicyPatch'
      - type: object
        properties:
          description:
            description: 'A description of the policy, optionally specified when the policy is

              created. Cannot be modified for an existing policy.

              '
            type: string
    _builtInNoId:
      type: object
      properties:
        name:
          description: Name of the object (e.g., a file system or snapshot).
          type: string
          readOnly: true
    ObjectStoreAccessPolicyResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/ObjectStoreAccessPolicy'
    _fixedReferenceWithoutType:
      type: object
      properties:
        id:
          description: 'A globally unique, system-generated ID.

            The ID cannot be modified.

            '
          type: string
          readOnly: true
        name:
          description: 'The resource name, such as volume name, file system name,

            snapshot name, and so on.

            '
          type: string
          readOnly: true
      x-readOnly: true
    ObjectStoreAccessPolicyActionResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/ObjectStoreAccessPolicyAction'
    ObjectStoreAccessPolicyAction:
      allOf:
      - $ref: '#/components/schemas/_builtInNoId'
      - $ref: '#/components/schemas/_context'
      - type: object
        properties:
          description:
            description: 'A description of the action.

              '
            type: string
            readOnly: true
            example: Grants permission to create a new bucket.
    _realmsReference:
      type: object
      properties:
        realms:
          description: 'Reference to the realms this resource belongs to.

            The value is set to empty array when the resource

            lives outside of a realm.

            '
          type: array
          readOnly: true
          items:
            $ref: '#/components/schemas/_fixedReference'
    ObjectStoreAccessPolicyRuleGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/_errorContextResponse'
      - $ref: '#/components/schemas/ObjectStoreAccessPolicyRuleResponse'
    PolicyRuleObjectAccess:
      allOf:
      - $ref: '#/components/schemas/_builtInNoId'
      - $ref: '#/components/schemas/_context'
      - type: object
        properties:
          actions:
            description: 'The list of actions granted by this rule. Each included action may

              restrict other properties of the rule.

              Supported actions are returned by the

              `/object-store-access-policy-actions` endpoint.

              '
            type: array
            items:
              type: string
            example:
            - s3:CreateBucket
            - s3:PutObject
          conditions:
            description: 'Conditions used to limit the scope which this rule applies to.

              '
            title: PolicyRuleObjectAccessCondition
            allOf:
            - $ref: '#/components/schemas/_policyRuleObjectAccessCondition'
          effect:
            description: 'Effect of this rule.

              When `allow`, the rule allows the given actions to be performed on the

              given resources, subject to the given conditions.

              When `deny`, the rule disallows performing the given actions on the given

              resources, subject to the given condition. This takes precedence over any

              matching `allow` rules.

              Valid values include `allow` and `deny`.

              '
            type: string
            readOnly: true
            example: allow
          policy:
            description: The policy to which this rule belongs.
            title: FixedReference
            allOf:
            - $ref: '#/components/schemas/_fixedReference'
          resources:
            description: 'The list of resources which this rule applies to. Each resource can

              include a bucket component, optionally followed by an object component.

              The choice of which components a resource can include is dictated by

              which actions are included in the rule. For further details, see the

              Object Store Access Policy Actions section of the User Guide.

              '
            type: array
            items:
              type: string
            example:
            - '*'
            - mybucket
            - mybucket*
            - mybucket*/myobject*
    _errorContextResponseErrors:
      type: object
      properties:
        context:
          description: 'Contains information relating to the cause of this error,

            or the name of the object that was being processed when the error was encountered.

            This may be `null` for more general errors.

            '
          type: string
        location_context:
          description: 'Contains information relating to the context in which the request was executing

            when the error occurred.

            For example, this may be the name of an array in the same fleet.

            This may be `null` for more general errors, or if no explicit `context` parameter

            was provided with the request.

            '
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
        message:
          description: A description of the error which occurred.
          type: string
          example: Resource does not exist.
    ObjectStoreAccessPolicyPatch:
      type: object
      properties:
        rules:
          type: array
          items:
            $ref: '#/components/schemas/PolicyRuleObjectAccessBulkManage'
    _context:
      type: object
      properties:
        context:
          description: 'The context in which the operation was performed.


            Valid values include a reference to any array which is a member of the same fleet

            or to the fleet itself.


            Other parameters provided with the request, such as names of volumes or snapshots,

            are resolved relative to the provided `context`.

            '
          readOnly: true
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
    PolicyMember:
      type: object
      properties:
        member:
          description: Reference to the resource the policy is applied to.
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
        policy:
          description: Reference to the policy.
          title: FixedReference
          allOf:
          - $ref: '#/components/schemas/_fixedReference'
    ObjectStoreAccessPolicyRuleResponse:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/PolicyRuleObjectAccess'
    _fixedReference:
      allOf:
      - $ref: '#/components/schemas/_fixedReferenceWithoutType'
      - type: object
        properties:
          resource_type:
            description: 'Type of the object (full name of the endpoint).

              Valid values are the unique part of the resource''s REST endpoint.

              For example, a reference to a file system would have a

              `resource_type` of `file-systems`.

              '
            type: string
            readOnly: true
    PolicyRuleObjectAccessBulkManage:
      allOf:
      - $ref: '#/components/schemas/PolicyRuleObjectAccessPost'
      - type: object
        properties:
          name:
            description: Name of the object (e.g., a file system or snapshot).
            type: string
    ObjectStoreAccessPolicyActionGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/_errorContextResponse'
      - $ref: '#/components/schemas/ObjectStoreAccessPolicyActionResponse'
    PolicyRuleObjectAccessPost:
      type: object
      properties:
        actions:
          description: 'The list of actions granted by this rule. Each included action may

            restrict other properties of the rule.

            Supported actions are returned by the

            `/object-store-access-policy-actions` endpoint.

            '
          type: array
          items:
            type: string
          example:
          - s3:CreateBucket
          - s3:PutObject
        conditions:
          description: 'Conditions used to limit the scope which this rule applies to.

            '
          title: PolicyRuleObjectAccessCondition
          allOf:
          - $ref: '#/components/schemas/_policyRuleObjectAccessCondition'
        effect:
          description: 'Effect of this rule.

            When `allow`, the rule allows the given actions to be performed on the

            given resources, subject to the given conditions.

            When `deny`, the rule disallows performing the given actions on the given

            resources, subject to the given condition. This takes precedence over any

            matching `allow` rules.

            Valid values include `allow` and `deny`.

            '
          type: string
          example: allow
        resources:
          description: 'The list of resources which this rule applies to. Each resource can

            include a bucket component, optionally followed by an object component.

            The choice of which components a resource can include is dictated by

            which actions are included in the rule. For further details, see the

            Object Store Access Policy Actions section of the User Guide.

            '
          type: array
          items:
            type: string
          example:
          - '*'
          - mybucket
          - mybucket*
          - mybucket*/myobject*
    PolicyMemberContext:
      allOf:
      - $ref: '#/components/schemas/PolicyMember'
      - $ref: '#/components/schemas/_context'
    PolicyBaseRenameable:
      allOf:
      - $ref: '#/components/schemas/_resource'
      - $ref: '#/components/schemas/_realmsReference'
      - type: object
        properties:
          enabled:
            description: 'If `true`, the policy is enabled. If not specified, defaults to `true`.

              '
            type: boolean
          is_local:
            description: Whether the policy is defined on the local array.
            type: boolean
            readOnly: true
          location:
            description: Reference to the array where the policy is defined.
            title: FixedReference
            allOf:
            - $ref: '#/components/schemas/_fixedReference'
          policy_type:
            description: 'Type of the policy. Valid values include `alert`, `audit`, `bucket-access`,

              `cross-origin-resource-sharing`, `network-access`, `nfs`, `object-access`,

              `s3-export`, smb-client`, `smb-share`, `ssh-certificate-authority`, and

              `telemetry-metrics`.

              '
            type: string
            readOnly: true
    PolicyBase:
      allOf:
      - $ref: '#/components/schemas/PolicyBaseRenameable'
    _policyRuleObjectAccessCondition:
      type: object
      properties:
        s3_delimiters:
          description: 'If specified, groups result objects by the specified delimiter. Only

            top-level groupings will be returned.

            Can be used with the `s3:ListBucket` and `s3:ListBucketVersions` actions.

            '
          type: array
          items:
            type: string
            example: /
        s3_prefixes:
          description: 'If specified, restricts access and results based on the prefix of the

            relevant objects.

            Can be used with the `s3:ListBucket` and `s3:ListBucketVersions` actions.

            '
          type: array
          items:
            type: string
            example: home/
        source_ips:
          description: 'If specified, the rule will apply only to requests matching at least one

            provided IP address or subnet.

            Each entry must be in standard CIDR format (including an IP address

            without an associated routing prefix).

            Can be used with any action.

            '
          type: array
          items:
            type: string
          example:
          - 1.2.3.4
          - 5.6.7.0/24
          - 2001:DB8:1234:5678::/64
    _errorContextResponse:
      type: object
      properties:
        errors:
          description: The list of errors encountered when attempting to perform an operation.
          type: array
          readOnly: true
          items:
            $ref: '#/components/schemas/_errorContextResponseErrors'
    PolicyMemberContextGetResponse:
      allOf:
      - $ref: '#/components/schemas/PageInfo'
      - $ref: '#/components/schemas/PolicyMemberContextResponse'
      - $ref: '#/components/schemas/_errorContextResponse'
    ObjectStoreAccessPolicy:
      allOf:
      - $ref: '#/components/schemas/PolicyBase'
      - $ref: '#/components/schemas/_context'
      - type: object
        properties:
          account:
            description: 'Reference of the associated account. If the policy is not associated

              with an account, all fields in the reference possess `null` values.

              '
            title: FixedReferenc

# --- truncated at 32 KB (42 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-policies-object-store-access-api-openapi.yml