StackRox DetectionService API
The DetectionService API from StackRox — 3 operation(s) for detectionservice.
The DetectionService API from StackRox — 3 operation(s) for detectionservice.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/stackrox-detectionservice-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Reference AlertService Detection Service API
version: '1'
description: API reference for the StackRox Kubernetes Security Platform (upstream of Red Hat Advanced Cluster Security). Provides risk analysis, visibility, runtime alerts, policy management, compliance checking, and vulnerability management for containerized workloads. Authentication uses API tokens generated via /v1/apitokens/generate and passed as Bearer tokens.
contact:
email: support@stackrox.com
url: https://www.stackrox.io/
license:
name: All Rights Reserved
url: https://www.stackrox.com/
servers:
- url: https://{central-host}
description: StackRox Central API server
variables:
central-host:
default: stackrox.localhost
description: StackRox Central hostname or IP
security:
- ApiToken: []
tags:
- name: DetectionService
paths:
/v1/detect/build:
post:
summary: DetectBuildTime checks if any images violate build time policies.
operationId: DetectBuildTime
responses:
'200':
description: A successful response.
content:
application/json:
schema:
$ref: '#/components/schemas/v1BuildDetectionResponse'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/v1BuildDetectionRequest'
required: true
tags:
- DetectionService
/v1/detect/deploy:
post:
summary: DetectDeployTime checks if any deployments violate deploy time policies.
operationId: DetectDeployTime
responses:
'200':
description: A successful response.
content:
application/json:
schema:
$ref: '#/components/schemas/v1DeployDetectionResponse'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/v1DeployDetectionRequest'
required: true
tags:
- DetectionService
/v1/detect/deploy/yaml:
post:
summary: DetectDeployTimeFromYAML checks if the given deployment yaml violates any deploy time policies.
operationId: DetectDeployTimeFromYAML
responses:
'200':
description: A successful response.
content:
application/json:
schema:
$ref: '#/components/schemas/v1DeployDetectionResponse'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/v1DeployYAMLDetectionRequest'
required: true
tags:
- DetectionService
components:
schemas:
storageVolume:
type: object
properties:
name:
type: string
source:
type: string
destination:
type: string
readOnly:
type: boolean
format: boolean
type:
type: string
storagePortConfig:
type: object
properties:
name:
type: string
containerPort:
type: integer
format: int32
protocol:
type: string
exposure:
$ref: '#/components/schemas/PortConfigExposureLevel'
exposedPort:
type: integer
format: int32
exposureInfos:
type: array
items:
$ref: '#/components/schemas/PortConfigExposureInfo'
title: 'Next Available Tag: 6'
storageContainerInstanceID:
type: object
properties:
containerRuntime:
$ref: '#/components/schemas/storageContainerRuntime'
id:
type: string
description: The ID of the container, specific to the given runtime.
node:
type: string
description: The node on which this container runs.
storageSecurityContext:
type: object
properties:
privileged:
type: boolean
format: boolean
selinux:
$ref: '#/components/schemas/SecurityContextSELinux'
dropCapabilities:
type: array
items:
type: string
addCapabilities:
type: array
items:
type: string
readOnlyRootFilesystem:
type: boolean
format: boolean
storageComparator:
type: string
enum:
- LESS_THAN
- LESS_THAN_OR_EQUALS
- EQUALS
- GREATER_THAN_OR_EQUALS
- GREATER_THAN
default: LESS_THAN
storageProcessPolicy:
type: object
properties:
name:
type: string
args:
type: string
ancestor:
type: string
uid:
type: string
storageLabelSelectorOperator:
type: string
enum:
- UNKNOWN
- IN
- NOT_IN
- EXISTS
- NOT_EXISTS
default: UNKNOWN
storageComponent:
type: object
properties:
name:
type: string
version:
type: string
storageLabelSelector:
type: object
properties:
matchLabels:
type: object
additionalProperties:
type: string
description: This is actually a oneof, but we can't make it one due to backwards compatibility constraints.
requirements:
type: array
items:
$ref: '#/components/schemas/LabelSelectorRequirement'
title: 'Next available tag: 3'
storagePortPolicy:
type: object
properties:
port:
type: integer
format: int32
protocol:
type: string
storageToleration:
type: object
properties:
key:
type: string
operator:
$ref: '#/components/schemas/storageTolerationOperator'
value:
type: string
taintEffect:
$ref: '#/components/schemas/storageTaintEffect'
storageContainerConfig:
type: object
properties:
env:
type: array
items:
$ref: '#/components/schemas/ContainerConfigEnvironmentConfig'
command:
type: array
items:
type: string
args:
type: array
items:
type: string
directory:
type: string
user:
type: string
uid:
type: string
format: int64
storageImageNamePolicy:
type: object
properties:
registry:
type: string
remote:
type: string
tag:
type: string
EnvironmentConfigEnvVarSource:
type: string
enum:
- UNSET
- RAW
- SECRET_KEY
- CONFIG_MAP_KEY
- FIELD
- RESOURCE_FIELD
- UNKNOWN
default: UNSET
title: For any update to EnvVarSource, please also update 'ui/src/messages/common.js'
storageTolerationOperator:
type: string
enum:
- TOLERATION_OPERATION_UNKNOWN
- TOLERATION_OPERATOR_EXISTS
- TOLERATION_OPERATOR_EQUAL
default: TOLERATION_OPERATION_UNKNOWN
PortConfigExposureInfo:
type: object
properties:
level:
$ref: '#/components/schemas/PortConfigExposureLevel'
serviceName:
type: string
title: only set if level is not HOST
serviceId:
type: string
serviceClusterIp:
type: string
servicePort:
type: integer
format: int32
nodePort:
type: integer
format: int32
title: only set if level is HOST, NODE, or EXTERNAL
externalIps:
type: array
items:
type: string
title: only set if level is EXTERNAL
externalHostnames:
type: array
items:
type: string
storageProcessSignal:
type: object
properties:
id:
type: string
description: 'A unique UUID for identifying the message
We have this here instead of at the top level
because we want to have each message to be
self contained.'
containerId:
type: string
title: ID of container associated with this process
time:
type: string
format: date-time
title: Process creation time
name:
type: string
title: Process name
args:
type: string
title: Process arguments
execFilePath:
type: string
title: Process executable file path
pid:
type: integer
format: int64
title: Host process ID
uid:
type: integer
format: int64
title: Real user ID
gid:
type: integer
format: int64
title: Real group ID
lineage:
type: array
items:
type: string
title: Process Lineage
storageKeyValuePolicy:
type: object
properties:
key:
type: string
value:
type: string
envVarSource:
$ref: '#/components/schemas/EnvironmentConfigEnvVarSource'
storageWhitelistDeployment:
type: object
properties:
name:
type: string
scope:
$ref: '#/components/schemas/storageScope'
storageVolumePolicy:
type: object
properties:
name:
type: string
source:
type: string
destination:
type: string
readOnly:
type: boolean
format: boolean
type:
type: string
v1BuildDetectionRequest:
type: object
properties:
image:
$ref: '#/components/schemas/storageContainerImage'
imageName:
type: string
noExternalMetadata:
type: boolean
format: boolean
DeployDetectionResponseRun:
type: object
properties:
name:
type: string
type:
type: string
alerts:
type: array
items:
$ref: '#/components/schemas/storageAlert'
AlertDeploymentContainer:
type: object
properties:
image:
$ref: '#/components/schemas/storageContainerImage'
name:
type: string
storageResources:
type: object
properties:
cpuCoresRequest:
type: number
format: float
cpuCoresLimit:
type: number
format: float
memoryMbRequest:
type: number
format: float
memoryMbLimit:
type: number
format: float
storageTaintEffect:
type: string
enum:
- UNKNOWN_TAINT_EFFECT
- NO_SCHEDULE_TAINT_EFFECT
- PREFER_NO_SCHEDULE_TAINT_EFFECT
- NO_EXECUTE_TAINT_EFFECT
default: UNKNOWN_TAINT_EFFECT
storagePermissionPolicy:
type: object
properties:
permissionLevel:
$ref: '#/components/schemas/storagePermissionLevel'
description: K8S RBAC Permission level configuration.
AlertViolation:
type: object
properties:
message:
type: string
DEPRECATEDProcesses:
type: array
items:
$ref: '#/components/schemas/storageProcessIndicator'
v1DeployYAMLDetectionRequest:
type: object
properties:
yaml:
type: string
noExternalMetadata:
type: boolean
format: boolean
enforcementOnly:
type: boolean
format: boolean
storageSeverity:
type: string
enum:
- UNSET_SEVERITY
- LOW_SEVERITY
- MEDIUM_SEVERITY
- HIGH_SEVERITY
- CRITICAL_SEVERITY
default: UNSET_SEVERITY
storagePermissionLevel:
type: string
enum:
- UNSET
- NONE
- DEFAULT
- ELEVATED_IN_NAMESPACE
- ELEVATED_CLUSTER_WIDE
- CLUSTER_ADMIN
default: UNSET
title: 'For any update to PermissionLevel, also update:
- central/searchbasedpolicies/builders/k8s_rbac.go
- ui/src/messages/common.js'
storageAlertDeployment:
type: object
properties:
id:
type: string
name:
type: string
type:
type: string
namespace:
type: string
labels:
type: object
additionalProperties:
type: string
clusterId:
type: string
clusterName:
type: string
containers:
type: array
items:
$ref: '#/components/schemas/AlertDeploymentContainer'
annotations:
type: object
additionalProperties:
type: string
inactive:
type: boolean
format: boolean
ContainerConfigEnvironmentConfig:
type: object
properties:
key:
type: string
value:
type: string
envVarSource:
$ref: '#/components/schemas/EnvironmentConfigEnvVarSource'
storageWhitelist:
type: object
properties:
name:
type: string
deployment:
$ref: '#/components/schemas/storageWhitelistDeployment'
image:
$ref: '#/components/schemas/storageWhitelistImage'
expiration:
type: string
format: date-time
storageImageName:
type: object
properties:
registry:
type: string
remote:
type: string
tag:
type: string
fullName:
type: string
v1BuildDetectionResponse:
type: object
properties:
alerts:
type: array
items:
$ref: '#/components/schemas/storageAlert'
storageScope:
type: object
properties:
cluster:
type: string
namespace:
type: string
label:
$ref: '#/components/schemas/storageScopeLabel'
storageResourcePolicy:
type: object
properties:
cpuResourceRequest:
$ref: '#/components/schemas/storageNumericalPolicy'
cpuResourceLimit:
$ref: '#/components/schemas/storageNumericalPolicy'
memoryResourceRequest:
$ref: '#/components/schemas/storageNumericalPolicy'
memoryResourceLimit:
$ref: '#/components/schemas/storageNumericalPolicy'
AlertProcessViolation:
type: object
properties:
message:
type: string
processes:
type: array
items:
$ref: '#/components/schemas/storageProcessIndicator'
v1DeployDetectionResponse:
type: object
properties:
runs:
type: array
items:
$ref: '#/components/schemas/DeployDetectionResponseRun'
storageEnforcementAction:
type: string
enum:
- UNSET_ENFORCEMENT
- SCALE_TO_ZERO_ENFORCEMENT
- UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT
- KILL_POD_ENFORCEMENT
- FAIL_BUILD_ENFORCEMENT
default: UNSET_ENFORCEMENT
PortConfigExposureLevel:
type: string
enum:
- UNSET
- EXTERNAL
- NODE
- INTERNAL
- HOST
default: UNSET
storageDockerfileLineRuleField:
type: object
properties:
instruction:
type: string
value:
type: string
storageDeployment:
type: object
properties:
id:
type: string
name:
type: string
hash:
type: string
format: uint64
type:
type: string
namespace:
type: string
namespaceId:
type: string
replicas:
type: string
format: int64
labels:
type: object
additionalProperties:
type: string
podLabels:
type: object
additionalProperties:
type: string
labelSelector:
$ref: '#/components/schemas/storageLabelSelector'
created:
type: string
format: date-time
clusterId:
type: string
clusterName:
type: string
containers:
type: array
items:
$ref: '#/components/schemas/storageContainer'
annotations:
type: object
additionalProperties:
type: string
priority:
type: string
format: int64
inactive:
type: boolean
format: boolean
imagePullSecrets:
type: array
items:
type: string
serviceAccount:
type: string
automountServiceAccountToken:
type: boolean
format: boolean
hostNetwork:
type: boolean
format: boolean
tolerations:
type: array
items:
$ref: '#/components/schemas/storageToleration'
ports:
type: array
items:
$ref: '#/components/schemas/storagePortConfig'
stateTimestamp:
type: string
format: int64
title: 'Next available tag: 28'
storagePolicy:
type: object
properties:
id:
type: string
name:
type: string
description:
type: string
rationale:
type: string
remediation:
type: string
disabled:
type: boolean
format: boolean
categories:
type: array
items:
type: string
fields:
$ref: '#/components/schemas/storagePolicyFields'
lifecycleStages:
type: array
items:
$ref: '#/components/schemas/storageLifecycleStage'
whitelists:
type: array
items:
$ref: '#/components/schemas/storageWhitelist'
scope:
type: array
items:
$ref: '#/components/schemas/storageScope'
severity:
$ref: '#/components/schemas/storageSeverity'
enforcementActions:
type: array
items:
$ref: '#/components/schemas/storageEnforcementAction'
notifiers:
type: array
items:
type: string
lastUpdated:
type: string
format: date-time
storagePortExposurePolicy:
type: object
properties:
exposureLevels:
type: array
items:
$ref: '#/components/schemas/PortConfigExposureLevel'
storageAlert:
type: object
properties:
id:
type: string
policy:
$ref: '#/components/schemas/storagePolicy'
lifecycleStage:
$ref: '#/components/schemas/storageLifecycleStage'
deployment:
$ref: '#/components/schemas/storageAlertDeployment'
violations:
type: array
items:
$ref: '#/components/schemas/AlertViolation'
processViolation:
$ref: '#/components/schemas/AlertProcessViolation'
enforcement:
$ref: '#/components/schemas/AlertEnforcement'
time:
type: string
format: date-time
firstOccurred:
type: string
format: date-time
state:
$ref: '#/components/schemas/storageViolationState'
snoozeTill:
type: string
format: date-time
storageViolationState:
type: string
enum:
- ACTIVE
- SNOOZED
- RESOLVED
default: ACTIVE
storageProcessIndicator:
type: object
properties:
id:
type: string
title: A unique uuid for the Indicator message
deploymentId:
type: string
deploymentStateTs:
type: string
format: int64
containerName:
type: string
podId:
type: string
signal:
$ref: '#/components/schemas/storageProcessSignal'
clusterId:
type: string
namespace:
type: string
containerStartTime:
type: string
format: date-time
title: 'Next available tag: 11'
storageContainer:
type: object
properties:
id:
type: string
config:
$ref: '#/components/schemas/storageContainerConfig'
image:
$ref: '#/components/schemas/storageContainerImage'
securityContext:
$ref: '#/components/schemas/storageSecurityContext'
volumes:
type: array
items:
$ref: '#/components/schemas/storageVolume'
ports:
type: array
items:
$ref: '#/components/schemas/storagePortConfig'
secrets:
type: array
items:
$ref: '#/components/schemas/storageEmbeddedSecret'
resources:
$ref: '#/components/schemas/storageResources'
instances:
type: array
items:
$ref: '#/components/schemas/storageContainerInstance'
name:
type: string
storageWhitelistImage:
type: object
properties:
name:
type: string
v1DeployDetectionRequest:
type: object
properties:
deployment:
$ref: '#/components/schemas/storageDeployment'
noExternalMetadata:
type: boolean
format: boolean
enforcementOnly:
type: boolean
format: boolean
clusterId:
type: string
storageNumericalPolicy:
type: object
properties:
op:
$ref: '#/components/schemas/storageComparator'
value:
type: number
format: float
storageHostMountPolicy:
type: object
properties:
readOnly:
type: boolean
format: boolean
storageContainerRuntime:
type: string
enum:
- UNKNOWN_CONTAINER_RUNTIME
- DOCKER_CONTAINER_RUNTIME
- CRIO_CONTAINER_RUNTIME
default: UNKNOWN_CONTAINER_RUNTIME
storageEmbeddedSecret:
type: object
properties:
name:
type: string
path:
type: string
LabelSelectorRequirement:
type: object
properties:
key:
type: string
op:
$ref: '#/components/schemas/storageLabelSelectorOperator'
values:
type: array
items:
type: string
title: 'Next available tag: 4'
storageContainerImage:
type: object
properties:
id:
type: string
title: These tags maintain backwards compatibiltiy with the previously embedded storage.Image
name:
$ref: '#/components/schemas/storageImageName'
notPullable:
type: boolean
format: boolean
storageLifecycleStage:
type: string
enum:
- DEPLOY
- BUILD
- RUNTIME
default: DEPLOY
storageScopeLabel:
type: object
properties:
key:
type: string
value:
type: string
storageContainerInstance:
type: object
properties:
instanceId:
$ref: '#/components/schemas/storageContainerInstanceID'
containingPodId:
type: string
description: The pod containing this container instance (kubernetes only).
containerIps:
type: array
items:
type: string
description: The IP addresses of this container.
started:
type: string
format: date-time
title: The start time of the container
description: ContainerInstanceID allows to uniquely identify a container within a cluster.
AlertEnforcement:
type: object
properties:
action:
$ref: '#/components/schemas/storageEnforcementAction'
message:
type: string
SecurityContextSELinux:
type: object
properties:
user:
type: string
role:
type: string
type:
type: string
level:
type: string
storagePolicyFields:
type: object
properties:
imageName:
$ref: '#/components/schemas/storageImageNamePolicy'
imageAgeDays:
type: string
format: int64
lineRule:
$ref: '#/components/schemas/storageDockerfileLineRuleField'
cvss:
$ref: '#/components/schemas/storageNumericalPolicy'
cve:
type: string
component:
$ref: '#/components/schemas/storageComponent'
scanAgeDays:
type: string
format: int64
noScanExists:
type: boolean
format: boolean
env:
$ref: '#/components/schemas/storageKeyValuePolicy'
command:
type: string
args:
type: string
directory:
type: string
user:
type: string
volumePolicy:
$ref: '#/components/schemas/storageVolumePolicy'
portPolicy:
$ref: '#/components/schemas/storagePortPolicy'
requiredLabel:
$ref: '#/components/schemas/storageKeyValuePolicy'
requiredAnnotation:
$ref: '#/components/schemas/storageKeyValuePolicy'
disallowedAnnotation:
$ref: '#/components/schemas/storageKeyValuePolicy'
privileged:
type: boolean
format: boolean
dropCapabilities:
type: array
items:
type: string
addCapabilities:
type: array
items:
type: string
containerResourcePolicy:
$ref: '#/components/schemas/storageResourcePolicy'
processPolicy:
$ref: '#/components/schemas/storageProcessPolicy'
readOnlyRootFs:
type: boolean
format: boolean
fixedBy:
type: string
portExposurePolicy:
$ref: '#/components/schemas/storagePortExposurePolicy'
permissionPolicy:
$ref: '#/components/schemas/storagePermissionPolicy'
hostMountPolicy:
$ref: '#/components/schemas/storageHostMountPolicy'
whitelistEnabled:
type: boolean
format: boolean
title: 'Next Available Tag: 29'
securitySchemes:
ApiToken:
type: apiKey
in: header
name: Authorization
description: 'StackRox API token. Format: Bearer {token}'