Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Defenders API

45 actions 45 updates phrasing extends openapi/palo-alto-networks-defenders-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 45 · first 16 shown; the file carries all of them

$.info
$.paths['/api/v34.03/defenders'].get
$.paths['/api/v34.03/defenders/aci.yaml'].post
$.paths['/api/v34.03/defenders/app-embedded'].post
$.paths['/api/v34.03/defenders/cloud-run.yaml'].post
$.paths['/api/v34.03/defenders/daemonset.yaml'].post
$.paths['/api/v34.03/defenders/download'].get
$.paths['/api/v34.03/defenders/eks-fargate.yaml'].post
$.paths['/api/v34.03/defenders/fargate.json'].post
$.paths['/api/v34.03/defenders/fargate.yaml'].post
$.paths['/api/v34.03/defenders/helm/twistlock-defender-helm.tar.gz'].post
$.paths['/api/v34.03/defenders/image-name'].get
$.paths['/api/v34.03/defenders/install-bundle'].get
$.paths['/api/v34.03/defenders/names'].get
$.paths['/api/v34.03/defenders/serverless/bundle'].post
$.paths['/api/v34.03/defenders/summary'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Defenders API
  version: 1.0.0
extends: openapi/palo-alto-networks-defenders-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-09-26'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 44
- target: $.paths['/api/v34.03/defenders'].get
  update:
    x-apievangelist-phrasing:
      intent: List deployed Defenders (API v34.03)
      effect: read
      questions:
      - Which Defenders are deployed in my Compute console, per the v34.03 API?
      - Can the v34.03 Defenders list show only disconnected agents or ones on an expired CA?
      instructions:
      - text: Using API v34.03, list deployed Defenders on host {hostname}.
        slots:
          hostname: query.hostname
      - text: With the v34.03 endpoint, list Defenders in cluster {cluster} filtered by connected={connected}.
        slots:
          cluster: query.cluster
          connected: query.connected
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/aci.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Add Defenders to an ACI container group YAML (v34.03)
      effect: write
      questions:
      - Can the v34.03 API inject a Defender into my Azure Container Instances group YAML?
      - What does the v34.03 ACI YAML endpoint return after it augments my container group definition?
      instructions:
      - text: Using API v34.03, augment my ACI container group YAML with a Defender pointing at console {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Via v34.03, protect my ACI container group YAML using Defender image {defenderImage}.
        slots:
          defenderImage: query.defenderImage
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/app-embedded'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate an App-Embedded Defender Dockerfile (v34.03)
      effect: write
      questions:
      - Can the v34.03 API rewrite my Dockerfile to embed a Defender in the app?
      - What inputs does the v34.03 app-embedded Defender Dockerfile generator need?
      instructions:
      - text: Using API v34.03, generate an App-Embedded Defender Dockerfile for app {appID}.
        slots:
          appID: requestBody.appID
      - text: With the v34.03 endpoint, embed a Defender into Dockerfile {dockerfile} using data folder {dataFolder}.
        slots:
          dockerfile: requestBody.dockerfile
          dataFolder: requestBody.dataFolder
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/cloud-run.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Add Defenders to a Cloud Run service YAML (v34.03)
      effect: write
      questions:
      - Can the v34.03 API add a Defender to my Google Cloud Run service YAML?
      - Does the v34.03 Cloud Run YAML generator support filesystem monitoring?
      instructions:
      - text: Using API v34.03, augment my Cloud Run service YAML with a Defender reporting to {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Via v34.03, protect my Cloud Run service YAML with filesystem monitoring set to {filesystemMonitoring}.
        slots:
          filesystemMonitoring: query.filesystemMonitoring
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/daemonset.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a Defender DaemonSet YAML (v34.03)
      effect: write
      questions:
      - How do I get a Kubernetes DaemonSet YAML to roll out Defenders using API v34.03?
      - Can the v34.03 DaemonSet generator set CPU and memory limits for the Defender pods?
      instructions:
      - text: Using API v34.03, generate a Defender DaemonSet YAML for cluster {cluster} in namespace {namespace}.
        slots:
          cluster: requestBody.cluster
          namespace: requestBody.namespace
      - text: Via v34.03, build a Defender DaemonSet YAML for the {orchestration} orchestrator with container runtime {containerRuntime}.
        slots:
          orchestration: requestBody.orchestration
          containerRuntime: requestBody.containerRuntime
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download the deployed Defenders list as CSV (v34.03)
      effect: read
      questions:
      - Can I export my deployed Defenders to a file with the v34.03 API?
      - Which filters apply when downloading the Defender inventory through v34.03?
      instructions:
      - text: Using API v34.03, download the deployed Defenders report for cluster {cluster}.
        slots:
          cluster: query.cluster
      - text: Via v34.03, export a file of every Defender running an old CA.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/eks-fargate.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Add Defenders to an EKS Fargate manifest (v34.03)
      effect: write
      questions:
      - Can the v34.03 API inject Defenders into a Kubernetes controller manifest for EKS on Fargate?
      - What comes back from the v34.03 EKS Fargate manifest generator?
      instructions:
      - text: Using API v34.03, augment my EKS Fargate controller manifest with Defenders reporting to {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Via v34.03, protect my EKS Fargate Kubernetes manifest with Defender image {defenderImage}.
        slots:
          defenderImage: query.defenderImage
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/fargate.json'].post
  update:
    x-apievangelist-phrasing:
      intent: Protect an ECS Fargate task definition in JSON (v34.03)
      effect: write
      questions:
      - Can the v34.03 API return a protected Fargate task definition in JSON?
      - Does the v34.03 JSON Fargate generator support CloudFormation output?
      instructions:
      - text: Using API v34.03, generate a protected JSON Fargate task definition pulling from registry type {registryType}.
        slots:
          registryType: query.registryType
      - text: Via v34.03, protect my Fargate task definition in JSON with Defender type {defenderType}.
        slots:
          defenderType: query.defenderType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/fargate.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Protect an ECS Fargate task definition in YAML (v34.03)
      effect: write
      questions:
      - Can the v34.03 API return a protected Fargate task definition as YAML instead of JSON?
      - Can v34.03 extract the entrypoint when building a YAML Fargate task definition?
      instructions:
      - text: Using API v34.03, generate a protected YAML Fargate task definition with registry credential {registryCredentialID}.
        slots:
          registryCredentialID: query.registryCredentialID
      - text: Via v34.03, produce a YAML Fargate task definition protected by Defender image {defenderImage}.
        slots:
          defenderImage: query.defenderImage
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/helm/twistlock-defender-helm.tar.gz'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a Defender Helm chart (v34.03)
      effect: write
      questions:
      - Can I get a Helm chart for deploying Defenders from the v34.03 API?
      - Does the v34.03 Helm chart support GKE Autopilot or Bottlerocket nodes?
      instructions:
      - text: Using API v34.03, generate a Defender Helm chart for cluster {cluster} in namespace {namespace}.
        slots:
          cluster: requestBody.cluster
          namespace: requestBody.namespace
      - text: Via v34.03, build the Defender Helm tarball using image {image} and proxy {proxy}.
        slots:
          image: requestBody.image
          proxy: requestBody.proxy
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/image-name'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the Defender Docker image name (v34.03)
      effect: read
      questions:
      - What Docker image name should I pull for the Defender, per API v34.03?
      - Where does the v34.03 API tell me the Defender container image to use?
      instructions:
      - text: Using API v34.03, fetch the Defender Docker image name.
      - text: Via v34.03, tell me which container image the Defender runs as.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/install-bundle'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the Defender certificate install bundle (v34.03)
      effect: read
      questions:
      - Where do I get the certificate bundle a Defender needs to install, via API v34.03?
      - Can the v34.03 install bundle be scoped to a specific Defender type?
      instructions:
      - text: Using API v34.03, get the Defender certificate install bundle for console {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Via v34.03, fetch the install bundle for Defender type {defenderType}.
        slots:
          defenderType: query.defenderType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/names'].get
  update:
    x-apievangelist-phrasing:
      intent: List Defender hostnames only (v34.03)
      effect: read
      questions:
      - Can I get just the names of my Defenders, without full details, from API v34.03?
      - Which Defender names does v34.03 return for a given cluster?
      instructions:
      - text: Using API v34.03, list the names of Defenders in cluster {cluster}.
        slots:
          cluster: query.cluster
      - text: Via v34.03, return only the Defender names for role {role}.
        slots:
          role: query.role
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/serverless/bundle'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a serverless Defender bundle (v34.03)
      effect: write
      questions:
      - Can I get a serverless Defender bundle for my Lambda runtime with API v34.03?
      - Which cloud providers and runtimes does the v34.03 serverless bundle cover?
      instructions:
      - text: Using API v34.03, generate a serverless Defender bundle for provider {provider} and runtime {runtime}.
        slots:
          provider: requestBody.provider
          runtime: requestBody.runtime
      - text: Via v34.03, build a serverless Defender bundle that trusts proxy CA {proxyCA}.
        slots:
          proxyCA: requestBody.proxyCA
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/summary'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the Defenders summary (v34.03)
      effect: read
      questions:
      - How many Defenders do I have by category, according to the v34.03 summary?
      - What overview of my Defender fleet does API v34.03 give?
      instructions:
      - text: Using API v34.03, show the Defenders summary.
      - text: Via v34.03, give me a roll-up count of my deployed Defenders.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/tas-cloud-controller-address'].get
  update:
    x-apievangelist-phrasing:
      intent: Get TAS cloud controller addresses for Defenders (v34.03)
      effect: read
      questions:
      - Which Tanzu Application Service cloud controller addresses do my Defenders report, per v34.03?
      - Can I look up TAS cloud controller addresses by foundation using API v34.03?
      instructions:
      - text: Using API v34.03, list the TAS cloud controller addresses for foundations {tasFoundations}.
        slots:
          tasFoundations: query.tasFoundations
      - text: Via v34.03, get TAS cloud controller addresses for TAS clusters {tasClusterIDs}.
        slots:
          tasClusterIDs: query.tasClusterIDs
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/upgrade'].post
  update:
    x-apievangelist-phrasing:
      intent: Upgrade all connected single Linux Defenders (v34.03)
      effect: write
      questions:
      - Can I upgrade every connected single Linux Defender at once with API v34.03?
      - Does the v34.03 bulk Defender upgrade accept a cluster or hostname filter?
      instructions:
      - text: Using API v34.03, upgrade all connected single Linux Defenders in cluster {cluster}.
        slots:
          cluster: query.cluster
      - text: Via v34.03, bulk-upgrade the connected Linux Defenders that are not on the latest version.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Defender (v34.03)
      effect: destructive
      questions:
      - How do I remove a Defender from my console with the v34.03 API?
      - What happens to a decommissioned host's Defender record when I delete it via v34.03?
      instructions:
      - text: Using API v34.03, delete Defender {id}.
        slots:
          id: path.id
      - text: Via v34.03, remove the Defender record for host {id} from the console.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/{id}/features'].post
  update:
    x-apievangelist-phrasing:
      intent: Update a Defender's features (v34.03)
      effect: write
      questions:
      - Can I turn on cluster monitoring for one Defender using the v34.03 API?
      - Which Defender settings can v34.03 change, like the proxy listener type?
      instructions:
      - text: Using API v34.03, set cluster monitoring to {clusterMonitoring} on Defender {id}.
        slots:
          clusterMonitoring: requestBody.clusterMonitoring
          id: path.id
      - text: Via v34.03, change Defender {id} proxy listener type to {proxyListenerType}.
        slots:
          id: path.id
          proxyListenerType: requestBody.proxyListenerType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/{id}/restart'].post
  update:
    x-apievangelist-phrasing:
      intent: Restart a Defender (v34.03)
      effect: write
      questions:
      - Can I restart a single stuck Defender remotely with API v34.03?
      - Is there a v34.03 call to restart one Defender by its hostname?
      instructions:
      - text: Using API v34.03, restart Defender {id}.
        slots:
          id: path.id
      - text: Via v34.03, bounce the Defender running on {id}.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/defenders/{id}/upgrade'].post
  update:
    x-apievangelist-phrasing:
      intent: Upgrade one Defender (v34.03)
      effect: write
      questions:
      - How do I upgrade just one Defender to the console's version via API v34.03?
      - Can v34.03 upgrade a single Defender without touching the rest of the fleet?
      instructions:
      - text: Using API v34.03, upgrade Defender {id}.
        slots:
          id: path.id
      - text: Via v34.03, bring the Defender on host {id} up to the current version.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders'].get
  update:
    x-apievangelist-phrasing:
      intent: List deployed Defenders (API v34.04)
      effect: read
      questions:
      - On the newer v34.04 release, what agents are currently running across my hosts?
      - Does v34.04 let me filter the agent inventory to ARM64 machines or VPC observers?
      instructions:
      - text: Show me every v34.04 agent installed on machine {hostname}.
        slots:
          hostname: query.hostname
      - text: Pull the v34.04 Defender inventory of kind {type}, ordered by {sort}.
        slots:
          type: query.type
          sort: query.sort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/aci.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Add Defenders to an ACI container group YAML (v34.04)
      effect: write
      questions:
      - Does the current v34.04 release accept an Azure Container Instances group definition and hand back a secured one?
      - Which interpreter options apply when v34.04 secures my ACI group spec?
      instructions:
      - text: Take this Azure container group spec and return a v34.04 secured version that talks to {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Secure my ACI group spec on v34.04, running interpreter {interpreter}.
        slots:
          interpreter: query.interpreter
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/app-embedded'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate an App-Embedded Defender Dockerfile (v34.04)
      effect: write
      questions:
      - On v34.04, can my container build file get a runtime agent baked right into the application image?
      - Is filesystem monitoring available for app-embedded agents in the v34.04 release?
      instructions:
      - text: Produce a v34.04 build file with an embedded agent for application {appID}.
        slots:
          appID: requestBody.appID
      - text: Bake the v34.04 runtime agent into this image build, reporting to console {consoleAddr}.
        slots:
          consoleAddr: requestBody.consoleAddr
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/cloud-run.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Add Defenders to a Cloud Run service YAML (v34.04)
      effect: write
      questions:
      - Will the current v34.04 release secure a Google serverless container service spec for me?
      - Which Defender image does v34.04 put into the Cloud Run spec it returns?
      instructions:
      - text: Secure this Cloud Run spec on v34.04 so it reports to console {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Return a v34.04 hardened Cloud Run spec that uses agent image {defenderImage}.
        slots:
          defenderImage: query.defenderImage
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/daemonset.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a Defender DaemonSet YAML (v34.04)
      effect: write
      questions:
      - With the v34.04 release, what manifest puts an agent on every node of my Kubernetes cluster?
      - Does v34.04 node-wide manifest generation handle Talos, SELinux or nftables?
      instructions:
      - text: Create a v34.04 per-node agent manifest for {cluster}, deploying into {namespace}.
        slots:
          cluster: requestBody.cluster
          namespace: requestBody.namespace
      - text: Give me the v34.04 node agent manifest with a memory cap of {memoryLimit} and a CPU cap of {cpuLimit}.
        slots:
          memoryLimit: requestBody.memoryLimit
          cpuLimit: requestBody.cpuLimit
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/download'].get
  update:
    x-apievangelist-phrasing:
      intent: Download the deployed Defenders list as CSV (v34.04)
      effect: read
      questions:
      - Is there a v34.04 export that saves my whole agent fleet to a spreadsheet?
      - In the current v34.04 release, can I export only agents on outdated, unsupported versions?
      instructions:
      - text: Save a v34.04 spreadsheet of agents tagged with role {role}.
        slots:
          role: query.role
      - text: Export the v34.04 agent fleet file, limited to hosts whose CA has expired.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/eks-fargate.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Add Defenders to an EKS Fargate manifest (v34.04)
      effect: write
      questions:
      - Does the v34.04 release secure a Kubernetes workload manifest bound for serverless EKS pods?
      - What interpreter settings does v34.04 accept when securing an EKS Fargate workload?
      instructions:
      - text: Harden this EKS serverless pod manifest on v34.04 so the agents call home to {consoleaddr}.
        slots:
          consoleaddr: query.consoleaddr
      - text: Secure my Fargate-on-EKS workload spec through v34.04 with interpreter {interpreter}.
        slots:
          interpreter: query.interpreter
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/fargate.json'].post
  update:
    x-apievangelist-phrasing:
      intent: Protect an ECS Fargate task definition in JSON (v34.04)
      effect: write
      questions:
      - With the v34.04 release, can I hand over an ECS task and get back a secured JSON version?
      - Does the current v34.04 JSON task hardening accept an image pull secret for the agent?
      instructions:
      - text: Secure my ECS task as JSON on v34.04, pulling the agent with secret {defenderImagePullSecret}.
        slots:
          defenderImagePullSecret: query.defenderImagePullSecret
      - text: Return a v34.04 hardened ECS task in JSON, formatted for CloudFormation set to {cloudFormation}.
        slots:
          cloudFormation: query.cloudFormation
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/fargate.yaml'].post
  update:
    x-apievangelist-phrasing:
      intent: Protect an ECS Fargate task definition in YAML (v34.04)
      effect: write
      questions:
      - Does the v34.04 release output a hardened ECS serverless task in YAML format?
      - Which registry types can the current v34.04 YAML task hardening pull the agent from?
      instructions:
      - text: Harden my ECS task as YAML on v34.04, using registry {registryType}.
        slots:
          registryType: query.registryType
      - text: Return a v34.04 secured ECS task in YAML with entrypoint extraction set to {extractEntrypoint}.
        slots:
          extractEntrypoint: query.extractEntrypoint
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/helm/twistlock-defender-helm.tar.gz'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a Defender Helm chart (v34.04)
      effect: write
      questions:
      - Where can I download a packaged chart tarball to install agents with helm on the v34.04 release?
      - Does the v34.04 chart accept node selectors, tolerations and a priority class?
      instructions:
      - text: Package a v34.04 helm tarball for {cluster} that runs with service accounts {serviceaccounts}.
        slots:
          cluster: requestBody.cluster
          serviceaccounts: requestBody.serviceaccounts
      - text: Build the v34.04 chart with node selector {nodeSelector} and tolerations {tolerations}.
        slots:
          nodeSelector: requestBody.nodeSelector
          tolerations: requestBody.tolerations
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/image-name'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the Defender Docker image name (v34.04)
      effect: read
      questions:
      - On the current v34.04 release, which registry path and tag is the agent image published under?
      - Is the agent container reference exposed by the v34.04 API for my own pull scripts?
      instructions:
      - text: Look up the v34.04 agent container reference.
      - text: Tell me what image tag v34.04 expects my nodes to pull for the agent.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/install-bundle'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the Defender certificate install bundle (v34.04)
      effect: read
      questions:
      - With v34.04, where are the certs an agent uses to trust and authenticate to the console?
      - Does the v34.04 release let me grab install certificates for a particular interpreter?
      instructions:
      - text: Retrieve the v34.04 agent certificates for interpreter {interpreter}.
        slots:
          interpreter: query.interpreter
      - text: Grab the v34.04 installation certs bundle for agent kind {defenderType}.
        slots:
          defenderType: query.defenderType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/names'].get
  update:
    x-apievangelist-phrasing:
      intent: List Defender hostnames only (v34.04)
      effect: read
      questions:
      - In the v34.04 release, is there a lightweight lookup returning only agent identifiers?
      - What agent hostnames does v34.04 give back when I filter to connected ones?
      instructions:
      - text: Fetch the v34.04 agent identifier list, filtered to connected={connected}.
        slots:
          connected: query.connected
      - text: Give me v34.04 agent hostnames only, capped at {limit}.
        slots:
          limit: query.limit
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/serverless/bundle'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a serverless Defender bundle (v34.04)
      effect: write
      questions:
      - On the v34.04 release, what package do I add to my functions to protect them?
      - Does the current v34.04 function protection package need my proxy certificate authority?
      instructions:
      - text: Build the v34.04 function protection package for cloud {provider}.
        slots:
          provider: requestBody.provider
      - text: Package a v34.04 function-protection agent for language runtime {runtime}.
        slots:
          runtime: requestBody.runtime
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/summary'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the Defenders summary (v34.04)
      effect: read
      questions:
      - Is there a v34.04 dashboard-style tally of my agent fleet?
      - What high-level agent totals does the current v34.04 release report?
      instructions:
      - text: Report the v34.04 agent fleet tally.
      - text: Summarize my v34.04 agents in one overview.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/tas-cloud-controller-address'].get
  update:
    x-apievangelist-phrasing:
      intent: Get TAS cloud controller addresses for Defenders (v34.04)
      effect: read
      questions:
      - On v34.04, what controller endpoints are my Tanzu-hosted agents connected to?
      - Can the current v34.04 release show which Tanzu controller the blobstore scanners use?
      instructions:
      - text: Show the v34.04 Tanzu controller endpoint for blobstore scanner {tasBlobstoreScanner}.
        slots:
          tasBlobstoreScanner: query.tasBlobstoreScanner
      - text: Find v34.04 Tanzu controller endpoints for agents on host {hostname}.
        slots:
          hostname: query.hostname
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/upgrade'].post
  update:
    x-apievangelist-phrasing:
      intent: Upgrade all connected single Linux Defenders (v34.04)
      effect: write
      questions:
      - With v34.04, can I push the latest agent version to every connected standalone Linux host in one call?
      - Does the v34.04 fleet-wide upgrade skip agents that are already current?
      instructions:
      - text: Roll the v34.04 fleet upgrade out to standalone Linux agents on host {hostname}.
        slots:
          hostname: query.hostname
      - text: Push the v34.04 mass upgrade to every connected standalone Linux agent.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a Defender (v34.04)
      effect: destructive
      questions:
      - Can I purge a retired agent from the console on the v34.04 release?
      - Is removing an agent permanent when done through v34.04?
      instructions:
      - text: Purge agent {id} via v34.04.
        slots:
          id: path.id
      - text: Drop the retired v34.04 agent entry {id} from my console.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/{id}/features'].post
  update:
    x-apievangelist-phrasing:
      intent: Update a Defender's features (v34.04)
      effect: write
      questions:
      - On the current v34.04 release, can one agent be switched to monitor its cluster?
      - Which per-agent features does v34.04 let me toggle?
      instructions:
      - text: Toggle v34.04 cluster monitoring {clusterMonitoring} for agent {id}.
        slots:
          clusterMonitoring: requestBody.clusterMonitoring
          id: path.id
      - text: Reconfigure v34.04 agent {id} to listen as {proxyListenerType}.
        slots:
          id: path.id
          proxyListenerType: requestBody.proxyListenerType
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/{id}/restart'].post
  update:
    x-apievangelist-phrasing:
      intent: Restart a Defender (v34.04)
      effect: write
      questions:
      - With v34.04, can I reboot one unresponsive agent without logging into its host?
      - Does the v34.04 release support a remote relaunch of a single agent?
      instructions:
      - text: Relaunch agent {id} using v34.04.
        slots:
          id: path.id
      - text: Reboot the unresponsive v34.04 agent {id} remotely.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.04/defenders/{id}/upgrade'].post
  update:
    x-apievangelist-phrasing:
      intent: Upgrade one Defender (v34.04)
      effect: write
      questions:
      - On v34.04, can I move a single lagging agent onto the console's release?
      - Will a v34.04 per-agent update leave my other hosts untouched?
      instructions:
      - text: Update only agent {id} on v34.04.
        slots:
          id: path.id
      - text: Move the lagging v34.04 agent {id} to the console release.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/defenders'].get
  update:
    x-apievangelist-phrasing:
      intent: List Defenders on the unversioned endpoint
      effect: read
      questions:
      - Is there an unversioned Defenders endpoint that searches agents by name and shows their connection status?
      - Which Defenders are running on which hosts, using the legacy /defenders path without a version?
      instructions:
      - text: On the unversioned /defenders endpoint, search Defenders matching {search}.
        slots:
          search: query.search
      - text: Using the non-versioned Defenders list, show {type} Defenders in cluster {cluster}.
        slots:
          type: query.type
          cluster: query.cluster
      method: generated
      generated: '2026-09-26'
- target: $.paths['/defenders/summary'].get
  update:
    x-apievangelist-phrasing:
      intent: Get Defender statistics on the unversioned endpoint
      effect: read
      questions:
      - What is my Defender version distribution and deployment type breakdown from the unversioned summary endpoint?
      - How many Defenders are connected out of the total, per the legacy /defenders/summary path?
      instructions:
      - text: From the unversioned summary endpoint, show Defender counts by version and deployment type.
      - text: Using the non-versioned /defenders/summary path, report total versus connected Defenders.
      method: generated
      generated: '2026-09-26'