openapi: 3.0.1
info:
title: FlashArray REST Active Directory Policies - SMB Share API
version: '2.52'
description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos
or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by
mapping identities across the NFS and SMB protocols by using LDAP queries.
'
servers:
- url: /
tags:
- name: Policies - SMB Share
description: An SMB Share policy manages access to SMB file systems on a per-user/group basis. These policies can be applied to one or more file systems.
paths:
/api/2.26/smb-share-policies:
get:
tags:
- Policies - SMB Share
summary: Pure Storage GET Smb-share-policies
description: Display SMB Share policies and their attributes.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Sort'
- $ref: '#/components/parameters/Workload_ids'
- $ref: '#/components/parameters/Workload_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyGetResponse'
post:
tags:
- Policies - SMB Share
summary: Pure Storage POST Smb-share-policies
description: Create a new SMB Share policy.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Names_required'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyPost'
required: false
x-codegen-request-body-name: policy
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyResponse'
x-codegen-request-body-name: policy
delete:
tags:
- Policies - SMB Share
summary: Pure Storage DELETE Smb-share-policies
description: Delete one or more SMB Share policies.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- Policies - SMB Share
summary: Pure Storage PATCH Smb-share-policies
description: Modify an existing SMB Share policy's attributes.
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyPatch'
required: true
x-codegen-request-body-name: policy
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyResponse'
x-codegen-request-body-name: policy
/api/2.26/smb-share-policies/rules:
get:
tags:
- Policies - SMB Share
summary: Pure Storage GET Smb-share-policies/rules
description: 'Displays a list of SMB Share policy rules.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Allow_errors'
- $ref: '#/components/parameters/Context_names_get'
- $ref: '#/components/parameters/Continuation_token'
- $ref: '#/components/parameters/Filter'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Limit'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Offset'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
- $ref: '#/components/parameters/Sort'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyRuleGetResponse'
'207':
description: 'Partial success. Some resources were returned, but there
were also errors possibly preventing some resources from
being returned.
'
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyRuleGetResponse'
post:
tags:
- Policies - SMB Share
summary: Pure Storage POST Smb-share-policies/rules
description: 'Add an SMB Share policy rule.
The `policy_ids` or `policy_names` parameter is required, but they cannot be
set together.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyRulePost'
required: true
x-codegen-request-body-name: rule
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyRuleResponse'
x-codegen-request-body-name: rule
delete:
tags:
- Policies - SMB Share
summary: Pure Storage DELETE Smb-share-policies/rules
description: 'Delete one or more SMB Share policy rules.
One of the following is required: `ids` or `names`.
If `names` is provided, the `policy_ids` or `policy_names` parameter is also required.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content: {}
patch:
tags:
- Policies - SMB Share
summary: Pure Storage PATCH Smb-share-policies/rules
description: 'Modify an existing SMB Share policy rule.
One of the following is required: `ids` or `names`.
If `names` is provided, the `policy_ids` or `policy_names` parameter is also required.
'
parameters:
- $ref: '#/components/parameters/XRequestId'
- $ref: '#/components/parameters/Context_names'
- $ref: '#/components/parameters/Ids'
- $ref: '#/components/parameters/Names'
- $ref: '#/components/parameters/Policy_ids'
- $ref: '#/components/parameters/Policy_names'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyRule'
required: true
x-codegen-request-body-name: rule
responses:
'200':
description: OK
headers:
X-Request-ID:
description: Supplied by client during request or generated by server.
schema:
type: string
content:
application/json:
schema:
$ref: '#/components/schemas/SmbSharePolicyRuleResponse'
x-codegen-request-body-name: rule
components:
schemas:
_errorContextResponseErrors:
type: object
properties:
context:
description: 'Contains information relating to the cause of this error,
or the name of the object that was being processed when the error was encountered.
This may be `null` for more general errors.
'
type: string
location_context:
description: 'Contains information relating to the context in which the request was executing
when the error occurred.
For example, this may be the name of an array in the same fleet.
This may be `null` for more general errors, or if no explicit `context` parameter
was provided with the request.
'
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
message:
description: A description of the error which occurred.
type: string
example: Resource does not exist.
SmbSharePolicyGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/SmbSharePolicyResponse'
- $ref: '#/components/schemas/_errorContextResponse'
_errorContextResponse:
type: object
properties:
errors:
description: The list of errors encountered when attempting to perform an operation.
type: array
readOnly: true
items:
$ref: '#/components/schemas/_errorContextResponseErrors'
SmbSharePolicyRule:
allOf:
- $ref: '#/components/schemas/_builtIn'
- type: object
properties:
change:
description: 'The state of the principal''s Change access permission.
Valid values are `allow` and `deny`. When not set, value is `null`.
When allowed, includes all access granted by the Read permission. Users
can also change data within files and add or delete files and folders.
When denied, these operations are explicitly blocked.
If not set for any applicable rule on any applicable policy, acts as an
implicit deny.
If set to `allow`, implicitly sets the Read permission to `allow`. This
is incompatible with explicitly setting any permission to `deny`.
If set to `deny`, implicitly sets the Read permission to `deny`, and
clears the Full Control permission if it is currently `allow`. This is
incompatible with explicitly setting any permission to `allow`.
If set to an empty string (`""`), the value (and implicitly the Full
Control permission) will be cleared. This is incompatible with
explicitly setting the Full Control permission to `allow` or `deny`.
'
type: string
full_control:
description: 'The state of the principal''s Full Control access permission.
Valid values are `allow` and `deny`. When not set, value is `null`.
When allowed, includes all access granted by the Change permission. Users
can also change the permissions for files and folders.
When denied, these operations are explicitly blocked.
If not set for any applicable rule on any applicable policy, acts as an
implicit deny.
If set to `allow`, implicitly sets the Change and Read permissions to
`allow`. This is incompatible with explicitly setting any permission to
`deny`.
If set to `deny`, implicitly sets the Change and Read permissions to
`deny`. This is incompatible with explicitly setting any permission to
`allow`.
If set to an empty string (`""`), the value will be cleared.
'
type: string
policy:
description: The policy to which this rule belongs.
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
principal:
description: 'The user or group who is the subject of this rule, and their domain.
If modifying this value, providing the domain is optional. If no domain
is provided, it will be derived if possible.
For example, `PURESTORAGE\Administrator`, `samplegroup@PureStorage`, or
`sampleuser`.
'
type: string
read:
description: 'The state of the principal''s Read access permission.
Valid values are `allow` and `deny`.
When allowed, users can view file names, read the data in those files, and
run some programs.
When denied, these operations are explicitly blocked.
If set to `allow`, implicitly clears the Full Control and Change
permissions if they are currently `deny`. This is incompatible with
explicitly setting any permission to `deny`.
If set to `deny`, implicitly clears the Full Control and Change
permissions if they are currently `allow`. This is incompatible with
explicitly setting any permission to `allow`.
'
type: string
SmbSharePolicyRulePost:
allOf:
- $ref: '#/components/schemas/_builtIn'
- type: object
properties:
change:
description: 'The state of the principal''s Change access permission.
Valid values are `allow` and `deny`. When not set, value is `null`.
When allowed, includes all access granted by the Read permission. Users
can also change data within files and add or delete files and folders.
When denied, these operations are explicitly blocked.
If not set for any applicable rule on any applicable policy, acts as an
implicit deny.
If set to `allow`, implicitly sets the Read permission to `allow`. This
is incompatible with explicitly setting any permission to `deny`.
If set to `deny`, implicitly sets the Read permission to `deny`. This is
incompatible with explicitly setting any permission to `allow`.
Defaults to `null`.
'
type: string
full_control:
description: 'The state of the principal''s Full Control access permission.
Valid values are `allow` and `deny`. When not set, value is `null`.
When allowed, includes all access granted by the Change permission. Users
can also change the permissions for files and folders.
When denied, these operations are explicitly blocked.
If not set for any applicable rule on any applicable policy, acts as an
implicit deny.
If set to `allow`, implicitly sets the Change and Read permissions to
`allow`. This is incompatible with explicitly setting any permission to
`deny`.
If set to `deny`, implicitly sets the Change and Read permissions to
`deny`. This is incompatible with explicitly setting any permission to
`allow`.
Defaults to `null`.
'
type: string
principal:
description: 'The user or group who is the subject of this rule, and optionally their
domain. If no domain is provided, it will be derived if possible.
For example, `PURESTORAGE\Administrator`, `samplegroup@PureStorage`, or
`sampleuser`.
'
type: string
read:
description: 'The state of the principal''s Read access permission.
Valid values are `allow` and `deny`.
When allowed, users can view file names, read the data in those files, and
run some programs.
When denied, these operations are explicitly blocked.
When setting to `allow`, cannot explicitly set any permission to `deny`.
When setting to `deny`, cannot explicitly set any permission to `allow`.
'
type: string
PolicyBase:
allOf:
- $ref: '#/components/schemas/PolicyBaseRenameable'
_resource:
description: 'An ordinary (as opposed to built-in) resource that can be created, named,
renamed or deleted by the user. This might be a virtual resource (e.g., a
file system), or correspond to something in the environment, like a host or a
server.
'
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified and cannot refer to another resource.
'
type: string
readOnly: true
name:
description: 'A user-specified name.
The name must be locally unique and can be changed.
'
type: string
_fixedReferenceWithoutType:
type: object
properties:
id:
description: 'A globally unique, system-generated ID.
The ID cannot be modified.
'
type: string
readOnly: true
name:
description: 'The resource name, such as volume name, file system name,
snapshot name, and so on.
'
type: string
readOnly: true
x-readOnly: true
SmbSharePolicyPost:
allOf:
- $ref: '#/components/schemas/PolicyBase'
- type: object
properties:
rules:
description: 'All of the rules that are part of this policy.
'
type: array
maxItems: 200
items:
$ref: '#/components/schemas/SmbSharePolicyRulePost'
SmbSharePolicyRuleResponse:
type: object
properties:
items:
description: A list of SMB Share policy rule objects.
type: array
items:
$ref: '#/components/schemas/SmbSharePolicyRuleWithContext'
_builtIn:
type: object
properties:
id:
description: 'A non-modifiable, globally unique ID chosen by the system.
'
type: string
readOnly: true
name:
description: Name of the object (e.g., a file system or snapshot).
type: string
readOnly: true
SmbSharePolicyRuleGetResponse:
allOf:
- $ref: '#/components/schemas/PageInfo'
- $ref: '#/components/schemas/SmbSharePolicyRuleResponse'
- $ref: '#/components/schemas/_errorContextResponse'
SmbSharePolicyRuleWithContext:
allOf:
- $ref: '#/components/schemas/SmbSharePolicyRule'
- $ref: '#/components/schemas/_context'
_context:
type: object
properties:
context:
description: 'The context in which the operation was performed.
Valid values include a reference to any array which is a member of the same fleet
or to the fleet itself.
Other parameters provided with the request, such as names of volumes or snapshots,
are resolved relative to the provided `context`.
'
readOnly: true
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
PolicyBaseRenameable:
allOf:
- $ref: '#/components/schemas/_resource'
- $ref: '#/components/schemas/_realmsReference'
- type: object
properties:
enabled:
description: 'If `true`, the policy is enabled. If not specified, defaults to `true`.
'
type: boolean
is_local:
description: Whether the policy is defined on the local array.
type: boolean
readOnly: true
location:
description: Reference to the array where the policy is defined.
title: FixedReference
allOf:
- $ref: '#/components/schemas/_fixedReference'
policy_type:
description: 'Type of the policy. Valid values include `alert`, `audit`, `bucket-access`,
`cross-origin-resource-sharing`, `network-access`, `nfs`, `object-access`,
`s3-export`, smb-client`, `smb-share`, `ssh-certificate-authority`, and
`telemetry-metrics`.
'
type: string
readOnly: true
SmbSharePolicy:
allOf:
- $ref: '#/components/schemas/_context'
- $ref: '#/components/schemas/PolicyBaseRenameable'
- type: object
properties:
rules:
description: 'All of the rules that are part of this policy.
'
type: array
maxItems: 200
items:
$ref: '#/components/schemas/SmbSharePolicyRule'
workload:
description: 'A reference to the workload that is managing this policy.
Set the `id` or `name` of the workload to an empty string to remove the
policy from the workload.
The `name` and `configuration` may show as the string "(unknown)" briefly after a failover.
'
title: WorkloadConfigurationFixedReference
allOf:
- $ref: '#/components/schemas/_workloadConfigurationFixedReference'
_realmsReference:
type: object
properties:
realms:
description: 'Reference to the realms this resource belongs to.
The value is set to empty array when the resource
lives outside of a realm.
'
type: array
readOnly: true
items:
$ref: '#/components/schemas/_fixedReference'
_fixedReference:
allOf:
- $ref: '#/components/schemas/_fixedReferenceWithoutType'
- type: object
properties:
resource_type:
description: 'Type of the object (full name of the endpoint).
Valid values are the unique part of the resource''s REST endpoint.
For example, a reference to a file system would have a
`resource_type` of `file-systems`.
'
type: string
readOnly: true
SmbSharePolicyResponse:
type: object
properties:
items:
description: A list of SMB Share policy objects.
type: array
items:
$ref: '#/components/schemas/SmbSharePolicy'
SmbSharePolicyPatch:
allOf:
- $ref: '#/components/schemas/PolicyBaseRenameable'
- type: object
properties:
rules:
description: 'All of the rules that are part of this policy.
'
type: array
maxItems: 200
items:
$ref: '#/components/schemas/SmbSharePolicyRule'
_workloadConfigurationFixedReference:
description: 'A reference to the workload that is managing this resource.
The `name` and `configuration` may show as the string "(unknown)" briefly after a failover.
'
allOf:
- $ref: '#/components/schemas/_fixedReference'
- type: object
properties:
configuration:
description: 'The name of the preset configuration object.
'
type: string
readOnly: true
PageInfo:
type: object
properties:
continuation_token:
description: 'Continuation token that can be provided in the `continuation_token` query
param to get the next page of data.
If you use the `continuation_token` to page through data you
are guaranteed to get all items exactly once regardless of
how items are modified. If an item is added or deleted during
the pagination then it may or may not be returned.
The `continuation_token` is generated if the `limit` is less
than the remaining number of items, and the default sort is used
(no sort is specified).
'
type: string
total_item_count:
description: Total number of items after applying `filter` params.
type: integer
format: int32
parameters:
Filter:
name: filter
in: query
description: 'Narrows down the results to only the response objects
that satisfy the filter criteria.
'
schema:
type: string
Offset:
name: offset
in: query
description: 'The offset of the first resource to return from a collection.
'
schema:
type: integer
format: int32
minimum: 0
example: 10
Allow_errors:
name: allow_errors
in: query
description: 'If set to `true`, the API will allow the operation to continue even if there are errors.
Any errors will be returned in the `errors` field of the response.
If set to `false`, the operation will fail if there are any errors.
'
schema:
type: boolean
default: false
Policy_ids:
name: policy_ids
in: query
description: 'A comma-separated list of policy IDs.
If after filtering, there is not at least one resource that matches
each of the elements of `policy_ids`, then an error is returned.
This cannot be provided together with the `policy_names` query parameter.
'
style: form
explode: false
schema:
type: array
items:
type: string
Continuation_token:
name: continuation_token
in: query
description: 'A token used to retrieve the next page of data
with some consistency guaranteed.
The token is a Base64 encoded value.
Set `continuation_token` to the system-generated token taken from the `x-next-token`
header field of the response.
A query has reached its last page when the response does not include a token.
Pagination requires the `limit` and `continuation_token`
query parameters.
'
schema:
type: string
Policy_names:
name: policy_names
in: query
description: 'A comma-separated list of policy names.
'
style: form
explode: false
schema:
type: array
items:
type: string
Context_names:
name: context_names
in: query
description: 'Performs the operation on the context specified.
If specified, the context names must be an array of size 1, and the single element
must be the name of an array in the same fleet or the name of the fleet itself. If
not specified, the context will default to the array that received this request.
Other parameters provided with the request, such as names of volumes or snapshots,
are resolved relative to the provided `context`.
'
style: form
explode: false
schema:
type: array
items:
type: string
Workload_ids:
name: workload_ids
in: query
description: 'A comma-separated list of workload IDs. If, after filtering, there is not at least one
resource that matches each of the elements, then an error is returned. This cannot be provided
together with the `workload_names` query parameter.
'
style: form
explode: false
schema:
type: array
items:
type: string
XRequestId:
name: X-Request-ID
in: header
description: 'Supplied by client during request or generated by server.
'
schema:
type: string
Limit:
name: limit
in: query
description: 'Limits the size of the response to the specified number of objects on each page.
To return the total number of resources, set `limit=0`.
The total number of resources is returned as a `total_item_count` value.
If the page size requested is larger than the system maximum limit,
the server returns the maximum limit, disregarding the requested page size.
'
schema:
type: integer
format: int32
minimum: 0
example: 10
Names:
name: names
in: query
description: 'Performs the operation on the unique names specified.
Enter multiple names in comma-separated format.
For example, `name01,name02`.
If there is not at least one resource that matches
each of the elements of `names`, then an error is returned,
except when creating new resources.
'
style: form
explode: false
schema:
type: array
items:
type: string
Context_names_get:
name: context_names
in: query
description: 'Performs the operation on the unique contexts specified.
If specified, each context name must be the name of an array in the same fleet or
the name of the fleet itself.
If not specified, the context will default to the array that received this request.
Other parameters provided with the request, such as names of volumes or snapshots,
are resolved relative to the provided `context`.
Enter multiple names in comma-separated format.
For example, `name01,name02`.
'
style: form
explode: false
schema:
type: array
items:
type: string
Ids:
name: ids
in: query
description: 'A comma-separated list of resource IDs.
If after filtering, there is not at least one resource that matches
each of the elements of `ids`, then an error is returned.
This cannot be provided together with the `name` or `names` query parameters.
'
style: form
explode: false
schema:
type: array
items:
type: string
Workload_names:
name: workload_names
in: query
description: 'A comma-separated list of workload names. If, after filtering, there is not at least one
resource that matches each of the elements, then an error is returned. This cannot be provided
together with the `workload_ids` query parameter.
'
style: form
explode: false
schem
# --- truncated at 32 KB (32 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/pure-storage/refs/heads/main/openapi/pure-storage-policies-smb-share-api-openapi.yml