StackRox PolicyService API

The PolicyService API from StackRox — 8 operation(s) for policyservice.

OpenAPI Specification

stackrox-policyservice-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  title: API Reference AlertService PolicyService API
  version: '1'
  description: API reference for the StackRox Kubernetes Security Platform (upstream of Red Hat Advanced Cluster Security). Provides risk analysis, visibility, runtime alerts, policy management, compliance checking, and vulnerability management for containerized workloads. Authentication uses API tokens generated via /v1/apitokens/generate and passed as Bearer tokens.
  contact:
    email: support@stackrox.com
    url: https://www.stackrox.io/
  license:
    name: All Rights Reserved
    url: https://www.stackrox.com/
servers:
- url: https://{central-host}
  description: StackRox Central API server
  variables:
    central-host:
      default: stackrox.localhost
      description: StackRox Central hostname or IP
security:
- ApiToken: []
tags:
- name: PolicyService
paths:
  /v1/policies:
    get:
      summary: ListPolicies returns the list of policies.
      operationId: ListPolicies
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1ListPoliciesResponse'
      parameters:
      - name: query
        in: query
        required: false
        schema:
          type: string
      - name: pagination.limit
        in: query
        required: false
        schema:
          type: integer
          format: int32
      - name: pagination.offset
        in: query
        required: false
        schema:
          type: integer
          format: int32
      - name: pagination.sort_option.field
        in: query
        required: false
        schema:
          type: string
      - name: pagination.sort_option.reversed
        in: query
        required: false
        schema:
          type: boolean
          format: boolean
      tags:
      - PolicyService
    post:
      summary: PostPolicy creates a new policy.
      operationId: PostPolicy
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/storagePolicy'
      requestBody:
        $ref: '#/components/requestBodies/storagePolicy'
      tags:
      - PolicyService
  /v1/policies/dryrun:
    post:
      summary: DryRunPolicy evaluates the given policy and returns any alerts without creating the policy.
      operationId: DryRunPolicy
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1DryRunResponse'
      requestBody:
        $ref: '#/components/requestBodies/storagePolicy'
      tags:
      - PolicyService
  /v1/policies/reassess:
    post:
      summary: ReassessPolicies reevaluates all the policies.
      operationId: ReassessPolicies
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      tags:
      - PolicyService
  /v1/policies/{id}:
    get:
      summary: GetPolicy returns the requested policy by ID.
      operationId: GetPolicy
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/storagePolicy'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      tags:
      - PolicyService
    delete:
      summary: DeletePolicy removes a policy by ID.
      operationId: DeletePolicy
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      tags:
      - PolicyService
    put:
      summary: PutPolicy modifies an existing policy.
      operationId: PutPolicy
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      requestBody:
        $ref: '#/components/requestBodies/storagePolicy'
      tags:
      - PolicyService
    patch:
      summary: PatchPolicy edits an existing policy.
      operationId: PatchPolicy
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      parameters:
      - name: id
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1PatchPolicyRequest'
        required: true
      tags:
      - PolicyService
  /v1/policies/{policyId}/notifiers:
    patch:
      summary: EnableDisablePolicyNotification enables or disables notifications for a policy by ID.
      operationId: EnableDisablePolicyNotification
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      parameters:
      - name: policyId
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1EnableDisablePolicyNotificationRequest'
        required: true
      tags:
      - PolicyService
  /v1/policyCategories:
    get:
      summary: GetPolicyCategories returns the policy categories.
      operationId: GetPolicyCategories
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1PolicyCategoriesResponse'
      tags:
      - PolicyService
  /v1/policyCategories/{category}:
    delete:
      summary: DeletePolicyCategory removes the given policy category.
      operationId: DeletePolicyCategory
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      parameters:
      - name: category
        in: path
        required: true
        schema:
          type: string
      tags:
      - PolicyService
  /v1/policyCategories/{oldCategory}:
    put:
      summary: RenamePolicyCategory renames the given policy category.
      operationId: RenamePolicyCategory
      responses:
        '200':
          description: A successful response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/v1Empty'
      parameters:
      - name: oldCategory
        in: path
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/v1RenamePolicyCategoryRequest'
        required: true
      tags:
      - PolicyService
components:
  schemas:
    storagePortPolicy:
      type: object
      properties:
        port:
          type: integer
          format: int32
        protocol:
          type: string
    storageComponent:
      type: object
      properties:
        name:
          type: string
        version:
          type: string
    storageProcessPolicy:
      type: object
      properties:
        name:
          type: string
        args:
          type: string
        ancestor:
          type: string
        uid:
          type: string
    storageScopeLabel:
      type: object
      properties:
        key:
          type: string
        value:
          type: string
    v1PatchPolicyRequest:
      type: object
      properties:
        id:
          type: string
        disabled:
          type: boolean
          format: boolean
    storageNumericalPolicy:
      type: object
      properties:
        op:
          $ref: '#/components/schemas/storageComparator'
        value:
          type: number
          format: float
    EnvironmentConfigEnvVarSource:
      type: string
      enum:
      - UNSET
      - RAW
      - SECRET_KEY
      - CONFIG_MAP_KEY
      - FIELD
      - RESOURCE_FIELD
      - UNKNOWN
      default: UNSET
      title: For any update to EnvVarSource, please also update 'ui/src/messages/common.js'
    storageKeyValuePolicy:
      type: object
      properties:
        key:
          type: string
        value:
          type: string
        envVarSource:
          $ref: '#/components/schemas/EnvironmentConfigEnvVarSource'
    v1Empty:
      type: object
    storageHostMountPolicy:
      type: object
      properties:
        readOnly:
          type: boolean
          format: boolean
    v1DryRunResponseAlert:
      type: object
      properties:
        deployment:
          type: string
        violations:
          type: array
          items:
            type: string
    storageVolumePolicy:
      type: object
      properties:
        name:
          type: string
        source:
          type: string
        destination:
          type: string
        readOnly:
          type: boolean
          format: boolean
        type:
          type: string
    storagePermissionLevel:
      type: string
      enum:
      - UNSET
      - NONE
      - DEFAULT
      - ELEVATED_IN_NAMESPACE
      - ELEVATED_CLUSTER_WIDE
      - CLUSTER_ADMIN
      default: UNSET
      title: 'For any update to PermissionLevel, also update:

        - central/searchbasedpolicies/builders/k8s_rbac.go

        - ui/src/messages/common.js'
    storageLifecycleStage:
      type: string
      enum:
      - DEPLOY
      - BUILD
      - RUNTIME
      default: DEPLOY
    storageWhitelistImage:
      type: object
      properties:
        name:
          type: string
    storageDockerfileLineRuleField:
      type: object
      properties:
        instruction:
          type: string
        value:
          type: string
    storagePolicyFields:
      type: object
      properties:
        imageName:
          $ref: '#/components/schemas/storageImageNamePolicy'
        imageAgeDays:
          type: string
          format: int64
        lineRule:
          $ref: '#/components/schemas/storageDockerfileLineRuleField'
        cvss:
          $ref: '#/components/schemas/storageNumericalPolicy'
        cve:
          type: string
        component:
          $ref: '#/components/schemas/storageComponent'
        scanAgeDays:
          type: string
          format: int64
        noScanExists:
          type: boolean
          format: boolean
        env:
          $ref: '#/components/schemas/storageKeyValuePolicy'
        command:
          type: string
        args:
          type: string
        directory:
          type: string
        user:
          type: string
        volumePolicy:
          $ref: '#/components/schemas/storageVolumePolicy'
        portPolicy:
          $ref: '#/components/schemas/storagePortPolicy'
        requiredLabel:
          $ref: '#/components/schemas/storageKeyValuePolicy'
        requiredAnnotation:
          $ref: '#/components/schemas/storageKeyValuePolicy'
        disallowedAnnotation:
          $ref: '#/components/schemas/storageKeyValuePolicy'
        privileged:
          type: boolean
          format: boolean
        dropCapabilities:
          type: array
          items:
            type: string
        addCapabilities:
          type: array
          items:
            type: string
        containerResourcePolicy:
          $ref: '#/components/schemas/storageResourcePolicy'
        processPolicy:
          $ref: '#/components/schemas/storageProcessPolicy'
        readOnlyRootFs:
          type: boolean
          format: boolean
        fixedBy:
          type: string
        portExposurePolicy:
          $ref: '#/components/schemas/storagePortExposurePolicy'
        permissionPolicy:
          $ref: '#/components/schemas/storagePermissionPolicy'
        hostMountPolicy:
          $ref: '#/components/schemas/storageHostMountPolicy'
        whitelistEnabled:
          type: boolean
          format: boolean
      title: 'Next Available Tag: 29'
    storageWhitelist:
      type: object
      properties:
        name:
          type: string
        deployment:
          $ref: '#/components/schemas/storageWhitelistDeployment'
        image:
          $ref: '#/components/schemas/storageWhitelistImage'
        expiration:
          type: string
          format: date-time
    storageEnforcementAction:
      type: string
      enum:
      - UNSET_ENFORCEMENT
      - SCALE_TO_ZERO_ENFORCEMENT
      - UNSATISFIABLE_NODE_CONSTRAINT_ENFORCEMENT
      - KILL_POD_ENFORCEMENT
      - FAIL_BUILD_ENFORCEMENT
      default: UNSET_ENFORCEMENT
    v1RenamePolicyCategoryRequest:
      type: object
      properties:
        oldCategory:
          type: string
        newCategory:
          type: string
    storageListPolicy:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        description:
          type: string
        severity:
          $ref: '#/components/schemas/storageSeverity'
        disabled:
          type: boolean
          format: boolean
        lifecycleStages:
          type: array
          items:
            $ref: '#/components/schemas/storageLifecycleStage'
        notifiers:
          type: array
          items:
            type: string
        lastUpdated:
          type: string
          format: date-time
    DryRunResponseExcluded:
      type: object
      properties:
        deployment:
          type: string
        whitelist:
          $ref: '#/components/schemas/storageWhitelist'
    storageScope:
      type: object
      properties:
        cluster:
          type: string
        namespace:
          type: string
        label:
          $ref: '#/components/schemas/storageScopeLabel'
    PortConfigExposureLevel:
      type: string
      enum:
      - UNSET
      - EXTERNAL
      - NODE
      - INTERNAL
      - HOST
      default: UNSET
    storageSeverity:
      type: string
      enum:
      - UNSET_SEVERITY
      - LOW_SEVERITY
      - MEDIUM_SEVERITY
      - HIGH_SEVERITY
      - CRITICAL_SEVERITY
      default: UNSET_SEVERITY
    storageComparator:
      type: string
      enum:
      - LESS_THAN
      - LESS_THAN_OR_EQUALS
      - EQUALS
      - GREATER_THAN_OR_EQUALS
      - GREATER_THAN
      default: LESS_THAN
    storageWhitelistDeployment:
      type: object
      properties:
        name:
          type: string
        scope:
          $ref: '#/components/schemas/storageScope'
    v1ListPoliciesResponse:
      type: object
      properties:
        policies:
          type: array
          items:
            $ref: '#/components/schemas/storageListPolicy'
    storagePermissionPolicy:
      type: object
      properties:
        permissionLevel:
          $ref: '#/components/schemas/storagePermissionLevel'
      description: K8S RBAC Permission level configuration.
    v1DryRunResponse:
      type: object
      properties:
        alerts:
          type: array
          items:
            $ref: '#/components/schemas/v1DryRunResponseAlert'
        excluded:
          type: array
          items:
            $ref: '#/components/schemas/DryRunResponseExcluded'
    storagePolicy:
      type: object
      properties:
        id:
          type: string
        name:
          type: string
        description:
          type: string
        rationale:
          type: string
        remediation:
          type: string
        disabled:
          type: boolean
          format: boolean
        categories:
          type: array
          items:
            type: string
        fields:
          $ref: '#/components/schemas/storagePolicyFields'
        lifecycleStages:
          type: array
          items:
            $ref: '#/components/schemas/storageLifecycleStage'
        whitelists:
          type: array
          items:
            $ref: '#/components/schemas/storageWhitelist'
        scope:
          type: array
          items:
            $ref: '#/components/schemas/storageScope'
        severity:
          $ref: '#/components/schemas/storageSeverity'
        enforcementActions:
          type: array
          items:
            $ref: '#/components/schemas/storageEnforcementAction'
        notifiers:
          type: array
          items:
            type: string
        lastUpdated:
          type: string
          format: date-time
    storageImageNamePolicy:
      type: object
      properties:
        registry:
          type: string
        remote:
          type: string
        tag:
          type: string
    storageResourcePolicy:
      type: object
      properties:
        cpuResourceRequest:
          $ref: '#/components/schemas/storageNumericalPolicy'
        cpuResourceLimit:
          $ref: '#/components/schemas/storageNumericalPolicy'
        memoryResourceRequest:
          $ref: '#/components/schemas/storageNumericalPolicy'
        memoryResourceLimit:
          $ref: '#/components/schemas/storageNumericalPolicy'
    storagePortExposurePolicy:
      type: object
      properties:
        exposureLevels:
          type: array
          items:
            $ref: '#/components/schemas/PortConfigExposureLevel'
    v1EnableDisablePolicyNotificationRequest:
      type: object
      properties:
        policyId:
          type: string
        notifierIds:
          type: array
          items:
            type: string
        disable:
          type: boolean
          format: boolean
    v1PolicyCategoriesResponse:
      type: object
      properties:
        categories:
          type: array
          items:
            type: string
  requestBodies:
    storagePolicy:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/storagePolicy'
      required: true
  securitySchemes:
    ApiToken:
      type: apiKey
      in: header
      name: Authorization
      description: 'StackRox API token. Format: Bearer {token}'