Palo Alto Networks · OpenAPI Overlay 1.0.0

API Evangelist conversational phrasing for Palo Alto Networks Policies API

167 actions 167 updates phrasing extends openapi/palo-alto-networks-policies-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Palo Alto Networks's API. It is a proposal applied on top of the contract, not a document Palo Alto Networks publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-phrasing

Targets 167 · first 16 shown; the file carries all of them

$.info
$.paths['/code/api/v1/policies/definition/{queryId}'].post
$.paths['/code/api/v1/policies'].post
$.paths['/code/api/v1/policies/table/data'].get
$.paths['/code/api/v1/policies/{policyId}'].put
$.paths['/code/api/v1/policies/{policyId}'].delete
$.paths['/code/api/v1/policies/preview'].post
$.paths['/code/api/v1/policies/clone/{policyId}'].post
$.paths['/api/v34.03/policies/compliance/ci/images'].get
$.paths['/api/v34.03/policies/compliance/ci/images'].put
$.paths['/api/v34.03/policies/compliance/ci/serverless'].get
$.paths['/api/v34.03/policies/compliance/ci/serverless'].put
$.paths['/api/v34.03/policies/compliance/container'].get
$.paths['/api/v34.03/policies/compliance/container'].put
$.paths['/api/v34.03/policies/compliance/container/impacted'].get
$.paths['/api/v34.03/policies/compliance/host'].get

OpenAPI Overlay

Raw ↑
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
  title: API Evangelist conversational phrasing for Palo Alto Networks Policies API
  version: 1.0.0
extends: openapi/palo-alto-networks-policies-api-openapi.yml
actions:
- target: $.info
  update:
    x-apievangelist-phrasing:
      method: generated
      generated: '2026-10-01'
      generator: build-phrasing.py
      label: Generated by API Evangelist
      operations: 166
- target: $.paths['/code/api/v1/policies/definition/{queryId}'].post
  update:
    x-apievangelist-phrasing:
      intent: Validate a YAML code policy definition
      effect: read
      questions:
      - Can I check that my YAML build policy definition is valid before saving it?
      - What happens if my policy-as-code query has a syntax error?
      instructions:
      - text: Validate the YAML policy definition for query {queryId}.
        slots:
          queryId: path.queryId
      - text: Check whether code policy query {queryId} is well formed.
        slots:
          queryId: path.queryId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/code/api/v1/policies'].post
  update:
    x-apievangelist-phrasing:
      intent: Save a new custom code policy
      effect: write
      questions:
      - How do I save a new YAML-based build policy in Prisma Cloud Application Security?
      - Can I add my own attribute or connection check as a custom code policy?
      instructions:
      - text: Save this YAML definition as a new custom build policy.
      - text: Create a new policy-as-code rule from my composite check.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/code/api/v1/policies/table/data'].get
  update:
    x-apievangelist-phrasing:
      intent: List custom code policies as a table
      effect: read
      questions:
      - Where can I see all the custom build policies I've written?
      - Which policy-as-code rules exist in my Application Security tenant?
      instructions:
      - text: Show the custom code policies table.
      - text: List every custom build policy with its table data.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/code/api/v1/policies/{policyId}'].put
  update:
    x-apievangelist-phrasing:
      intent: Update a custom YAML code policy
      effect: write
      questions:
      - Can I edit the YAML of a custom build policy I already saved?
      - How do I change the definition of an existing policy-as-code rule?
      instructions:
      - text: Update custom code policy {policyId} with my revised YAML.
        slots:
          policyId: path.policyId
      - text: Replace the build policy definition of {policyId}.
        slots:
          policyId: path.policyId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/code/api/v1/policies/{policyId}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a custom code policy
      effect: destructive
      questions:
      - How do I remove a custom build policy I no longer need?
      - Is deleting a policy-as-code rule permanent?
      instructions:
      - text: Delete custom code policy {policyId}.
        slots:
          policyId: path.policyId
      - text: Remove build policy {policyId} from Application Security.
        slots:
          policyId: path.policyId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/code/api/v1/policies/preview'].post
  update:
    x-apievangelist-phrasing:
      intent: Preview results of a code policy
      effect: read
      questions:
      - Can I see which resources a YAML build policy would flag before I save it?
      - What results would a Checkov check return if I previewed it?
      instructions:
      - text: Preview the results of this code policy, showing {resultsNumber} results.
        slots:
          resultsNumber: requestBody.resultsNumber
      - text: Run a preview of Checkov check {checkovCheckId}.
        slots:
          checkovCheckId: requestBody.checkovCheckId
      method: generated
      generated: '2026-09-26'
- target: $.paths['/code/api/v1/policies/clone/{policyId}'].post
  update:
    x-apievangelist-phrasing:
      intent: Clone an existing code policy
      effect: write
      questions:
      - Can I copy an existing build policy and tweak it as my own?
      - How do I duplicate a code policy with a different severity?
      instructions:
      - text: Clone code policy {policyId} as a new custom policy.
        slots:
          policyId: path.policyId
      - text: Clone build policy {policyId} with title {title} and severity {severity}.
        slots:
          policyId: path.policyId
          title: requestBody.title
          severity: requestBody.severity
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/ci/images'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the CI image compliance policy (v34.03)
      effect: read
      questions:
      - What compliance rules apply to images scanned in CI under API v34.03?
      - Can I read the continuous integration image compliance policy with the v34.03 API?
      instructions:
      - text: Get the CI image compliance policy using v34.03.
      - text: Show the v34.03 compliance rules for CI-scanned images.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/ci/images'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the CI image compliance policy (v34.03)
      effect: write
      questions:
      - How do I change the compliance rules for CI image scans through v34.03?
      - Does the v34.03 update replace every CI image compliance rule at once?
      instructions:
      - text: Update the CI image compliance policy via v34.03 with these rules.
      - text: Replace the v34.03 CI image compliance rules with {rules}.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/ci/serverless'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the CI serverless compliance policy (v34.03)
      effect: read
      questions:
      - Which compliance checks run on serverless functions in CI under v34.03?
      - Can I read the CI serverless compliance policy from the v34.03 endpoint?
      instructions:
      - text: Get the v34.03 CI serverless compliance policy.
      - text: Show compliance rules for functions scanned in CI (v34.03).
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/ci/serverless'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the CI serverless compliance policy (v34.03)
      effect: write
      questions:
      - How do I edit the CI serverless compliance rules with the v34.03 API?
      - Can I push a new rule set for serverless CI compliance using v34.03?
      instructions:
      - text: Update the CI serverless compliance policy through v34.03.
      - text: Set the v34.03 CI serverless compliance rules to {rules}.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/container'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the container compliance policy (v34.03)
      effect: read
      questions:
      - What compliance rules are enforced on running containers in v34.03?
      - Can I fetch the container compliance policy via the v34.03 API?
      instructions:
      - text: Get the container compliance policy with v34.03.
      - text: Show my v34.03 container compliance rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/container'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the container compliance policy (v34.03)
      effect: write
      questions:
      - How do I change container compliance rules using v34.03?
      - Will a v34.03 container compliance update overwrite existing rules?
      instructions:
      - text: Update the container compliance policy via v34.03.
      - text: Replace v34.03 container compliance rules with {rules}.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/container/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List containers impacted by a compliance rule (v34.03)
      effect: read
      questions:
      - Which containers are affected by a given compliance rule in v34.03?
      - Can I page through containers impacted by a compliance rule on v34.03?
      instructions:
      - text: List containers impacted by compliance rule {rule} using v34.03.
        slots:
          rule: query.ruleName
      - text: Show the first {limit} containers hit by compliance rule {rule} (v34.03).
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/host'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the host compliance policy (v34.03)
      effect: read
      questions:
      - What compliance rules apply to my hosts under v34.03?
      - Can I read the host compliance policy through the v34.03 API?
      instructions:
      - text: Get the v34.03 host compliance policy.
      - text: Show host compliance rules from v34.03.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/host'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the host compliance policy (v34.03)
      effect: write
      questions:
      - How do I update host compliance rules with v34.03?
      - Can I replace the whole host compliance rule set on v34.03?
      instructions:
      - text: Update the host compliance policy via v34.03.
      - text: Set v34.03 host compliance rules to {rules}.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/serverless'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the serverless compliance policy (v34.03)
      effect: read
      questions:
      - Which compliance rules apply to deployed serverless functions in v34.03?
      - Can I fetch the serverless compliance policy on v34.03?
      instructions:
      - text: Get the serverless compliance policy using v34.03.
      - text: Show v34.03 compliance rules for deployed functions.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/serverless'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the serverless compliance policy (v34.03)
      effect: write
      questions:
      - How do I change serverless function compliance rules via v34.03?
      - Can I overwrite the deployed-function compliance rules on v34.03?
      instructions:
      - text: Update the v34.03 serverless compliance policy.
      - text: Replace serverless compliance rules with {rules} on v34.03.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/compliance/vms/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List VMs impacted by a compliance rule (v34.03)
      effect: read
      questions:
      - Which virtual machine images are affected by a compliance rule in v34.03?
      - Can I sort the VMs impacted by a compliance rule on v34.03?
      instructions:
      - text: List VMs impacted by compliance rule {rule} via v34.03.
        slots:
          rule: query.ruleName
      - text: Show {limit} VMs hit by compliance rule {rule} using v34.03.
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/agentless'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the agentless app firewall policy (v34.03)
      effect: read
      questions:
      - What does my agentless WAAS app firewall policy look like under v34.03?
      - Can I read the agentless app firewall rules through v34.03?
      instructions:
      - text: Get the agentless app firewall policy with v34.03.
      - text: Show the v34.03 agentless WAAS rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/agentless'].put
  update:
    x-apievangelist-phrasing:
      intent: Set the agentless app firewall policy (v34.03)
      effect: write
      questions:
      - How do I set the agentless WAAS policy rules via v34.03?
      - Can I limit the agentless app firewall to a port range on v34.03?
      instructions:
      - text: Set the agentless app firewall policy through v34.03.
      - text: Set the v34.03 agentless firewall port range from {minPort} to {maxPort}.
        slots:
          minPort: requestBody.minPort
          maxPort: requestBody.maxPort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/agentless/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List resources impacted by an agentless WAAS rule (v34.03)
      effect: read
      questions:
      - Which resources does an agentless app firewall rule cover in v34.03?
      - Can I page through agentless WAAS impacted resources on v34.03?
      instructions:
      - text: List resources impacted by agentless firewall rule {rule} via v34.03.
        slots:
          rule: query.ruleName
      - text: Show {limit} resources hit by agentless WAAS rule {rule} (v34.03).
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/agentless/resources'].get
  update:
    x-apievangelist-phrasing:
      intent: List agentless app firewall resources (v34.03)
      effect: read
      questions:
      - What resources are protected by the agentless app firewall under a given config in v34.03?
      - Can I filter agentless WAAS resources by config ID on v34.03?
      instructions:
      - text: List agentless app firewall resources for config {configID} using v34.03.
        slots:
          configID: query.configID
      - text: Show the v34.03 agentless WAAS resource list.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/agentless/state'].get
  update:
    x-apievangelist-phrasing:
      intent: Get agentless app firewall policy state (v34.03)
      effect: read
      questions:
      - Is my agentless app firewall policy deployed and in sync under v34.03?
      - What state is the agentless WAAS policy in on v34.03?
      instructions:
      - text: Get the agentless app firewall policy state via v34.03.
      - text: Check the v34.03 agentless WAAS deployment state.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/apispec'].post
  update:
    x-apievangelist-phrasing:
      intent: Generate a WAAS API specification object (v34.03)
      effect: read
      questions:
      - Can WAAS generate an API specification object for me in v34.03?
      - How do I produce a WAAS API spec object via the v34.03 API?
      instructions:
      - text: Generate a WAAS API specification object using v34.03.
      - text: Build a v34.03 WAAS API spec object.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/app-embedded'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the WAAS app-embedded policy (v34.03)
      effect: read
      questions:
      - What WAAS rules protect my app-embedded defenders under v34.03?
      - Can I read the app-embedded web application firewall policy on v34.03?
      instructions:
      - text: Get the WAAS app-embedded policy via v34.03.
      - text: Show v34.03 app-embedded WAAS rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/app-embedded'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the WAAS app-embedded policy (v34.03)
      effect: write
      questions:
      - How do I update WAAS rules for app-embedded defenders with v34.03?
      - Can I set the port range of the app-embedded WAAS policy on v34.03?
      instructions:
      - text: Update the app-embedded WAAS policy through v34.03.
      - text: Set app-embedded WAAS ports {minPort} to {maxPort} using v34.03.
        slots:
          minPort: requestBody.minPort
          maxPort: requestBody.maxPort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/container'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the WAAS container policy (v34.03)
      effect: read
      questions:
      - Which WAAS rules protect my containerized web apps under v34.03?
      - Can I fetch the container WAAS policy with v34.03?
      instructions:
      - text: Get the WAAS container policy via v34.03.
      - text: Show v34.03 container web app firewall rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/container'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the WAAS container policy (v34.03)
      effect: write
      questions:
      - How do I change WAAS protection for containers through v34.03?
      - Can I replace the container WAAS rules on v34.03?
      instructions:
      - text: Update the container WAAS policy using v34.03.
      - text: Replace v34.03 container WAAS rules with {rules}.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/container/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List containers impacted by a WAAS rule (v34.03)
      effect: read
      questions:
      - Which containers are covered by a container app firewall rule in v34.03?
      - Can I sort containers impacted by a WAAS rule on v34.03?
      instructions:
      - text: List containers impacted by WAAS rule {rule} via v34.03.
        slots:
          rule: query.ruleName
      - text: Show {limit} containers under container firewall rule {rule} (v34.03).
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/host'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the WAAS host policy (v34.03)
      effect: read
      questions:
      - What WAAS rules protect web apps running directly on hosts in v34.03?
      - Can I read the host WAAS policy on v34.03?
      instructions:
      - text: Get the WAAS host policy with v34.03.
      - text: Show v34.03 host web app firewall rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/host'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the WAAS host policy (v34.03)
      effect: write
      questions:
      - How do I update host WAAS rules through v34.03?
      - Can I change the host app firewall port range on v34.03?
      instructions:
      - text: Update the host WAAS policy via v34.03.
      - text: Set host WAAS ports {minPort} to {maxPort} using v34.03.
        slots:
          minPort: requestBody.minPort
          maxPort: requestBody.maxPort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/host/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List hosts impacted by a WAAS rule (v34.03)
      effect: read
      questions:
      - Which hosts does a host app firewall rule apply to in v34.03?
      - Can I page through hosts impacted by a WAAS rule on v34.03?
      instructions:
      - text: List hosts impacted by WAAS rule {rule} using v34.03.
        slots:
          rule: query.ruleName
      - text: Show {limit} hosts under host firewall rule {rule} (v34.03).
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/network-list'].get
  update:
    x-apievangelist-phrasing:
      intent: List WAAS network lists (v34.03)
      effect: read
      questions:
      - What IP network lists are defined for WAAS in v34.03?
      - Can I see the subnets in my WAAS network lists via v34.03?
      instructions:
      - text: List WAAS network lists using v34.03.
      - text: Show all v34.03 WAAS network lists and their subnets.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/network-list'].put
  update:
    x-apievangelist-phrasing:
      intent: Update a WAAS network list (v34.03)
      effect: write
      questions:
      - How do I change the subnets in an existing WAAS network list on v34.03?
      - Can I rename a WAAS network list through v34.03?
      instructions:
      - text: Update WAAS network list {name} with subnets {subnets} via v34.03.
        slots:
          name: requestBody.name
          subnets: requestBody.subnets
      - text: Rename WAAS network list {previousName} to {name} using v34.03.
        slots:
          previousName: requestBody.previousName
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/network-list'].post
  update:
    x-apievangelist-phrasing:
      intent: Add a WAAS network list (v34.03)
      effect: write
      questions:
      - How do I create a new IP network list for WAAS with v34.03?
      - Can I add a WAAS network list of subnets on v34.03?
      instructions:
      - text: Add WAAS network list {name} with subnets {subnets} via v34.03.
        slots:
          name: requestBody.name
          subnets: requestBody.subnets
      - text: Create a new v34.03 WAAS network list named {name}.
        slots:
          name: requestBody.name
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/network-list/{id}'].delete
  update:
    x-apievangelist-phrasing:
      intent: Delete a WAAS network list (v34.03)
      effect: destructive
      questions:
      - How do I remove a WAAS network list using v34.03?
      - Can I delete a network list that WAAS rules reference on v34.03?
      instructions:
      - text: Delete WAAS network list {id} via v34.03.
        slots:
          id: path.id
      - text: Remove network list {id} from WAAS using v34.03.
        slots:
          id: path.id
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/out-of-band'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the out-of-band WAAS policy (v34.03)
      effect: read
      questions:
      - What out-of-band WAAS rules inspect mirrored traffic in v34.03?
      - Can I read the out-of-band web app firewall policy on v34.03?
      instructions:
      - text: Get the out-of-band WAAS policy with v34.03.
      - text: Show v34.03 out-of-band WAAS rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/out-of-band'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the out-of-band WAAS policy (v34.03)
      effect: write
      questions:
      - How do I update out-of-band WAAS rules through v34.03?
      - Can I set the port range for out-of-band WAAS on v34.03?
      instructions:
      - text: Update the out-of-band WAAS policy via v34.03.
      - text: Set out-of-band WAAS ports {minPort} to {maxPort} on v34.03.
        slots:
          minPort: requestBody.minPort
          maxPort: requestBody.maxPort
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/out-of-band/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List resources impacted by an out-of-band WAAS rule (v34.03)
      effect: read
      questions:
      - Which resources does an out-of-band WAAS rule cover in v34.03?
      - Can I page through out-of-band WAAS impacted resources on v34.03?
      instructions:
      - text: List resources impacted by out-of-band rule {rule} using v34.03.
        slots:
          rule: query.ruleName
      - text: Show {limit} resources under out-of-band WAAS rule {rule} (v34.03).
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/serverless'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the WAAS serverless policy (v34.03)
      effect: read
      questions:
      - What WAAS rules protect my serverless functions in v34.03?
      - Can I fetch the serverless web app firewall policy via v34.03?
      instructions:
      - text: Get the WAAS serverless policy with v34.03.
      - text: Show v34.03 serverless WAAS rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/app/serverless'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the WAAS serverless policy (v34.03)
      effect: write
      questions:
      - How do I change WAAS protection for functions through v34.03?
      - Can I replace the serverless WAAS rules on v34.03?
      instructions:
      - text: Update the serverless WAAS policy via v34.03.
      - text: Replace v34.03 serverless WAAS rules with {rules}.
        slots:
          rules: requestBody.rules
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/network'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the CNNS container and host policy (v34.03)
      effect: read
      questions:
      - What cloud native network segmentation rules apply to containers and hosts in v34.03?
      - Can I read the CNNS firewall policy on v34.03?
      instructions:
      - text: Get the CNNS container and host policy via v34.03.
      - text: Show v34.03 CNNS network firewall rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/firewall/network'].put
  update:
    x-apievangelist-phrasing:
      intent: Update the CNNS container and host policy (v34.03)
      effect: write
      questions:
      - How do I turn CNNS on for containers but off for hosts with v34.03?
      - Can I update the CNNS network entities and rules through v34.03?
      instructions:
      - text: Update the CNNS policy via v34.03 with container rules {containerRules}.
        slots:
          containerRules: requestBody.containerRules
      - text: Set CNNS host enforcement to {hostEnabled} using v34.03.
        slots:
          hostEnabled: requestBody.hostEnabled
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/app-embedded'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the runtime app-embedded policy (v34.03)
      effect: read
      questions:
      - What runtime defense rules apply to app-embedded defenders in v34.03?
      - Can I read the app-embedded runtime policy on v34.03?
      instructions:
      - text: Get the runtime app-embedded policy with v34.03.
      - text: Show v34.03 app-embedded runtime rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/app-embedded'].put
  update:
    x-apievangelist-phrasing:
      intent: Replace the runtime app-embedded policy (v34.03)
      effect: write
      questions:
      - How do I replace all app-embedded runtime rules at once with v34.03?
      - Can I overwrite the full app-embedded runtime rule set on v34.03?
      instructions:
      - text: Replace the app-embedded runtime policy via v34.03 with {rules}.
        slots:
          rules: requestBody.rules
      - text: Overwrite all v34.03 app-embedded runtime rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/app-embedded'].post
  update:
    x-apievangelist-phrasing:
      intent: Add an app-embedded runtime rule (v34.03)
      effect: write
      questions:
      - How do I add a single app-embedded runtime rule with v34.03?
      - Can a new app-embedded runtime rule turn on WildFire analysis in v34.03?
      instructions:
      - text: Add app-embedded runtime rule {name} via v34.03.
        slots:
          name: requestBody.name
      - text: Add v34.03 app-embedded runtime rule {name} scoped to collections {collections}.
        slots:
          name: requestBody.name
          collections: requestBody.collections
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/container'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the runtime container policy (v34.03)
      effect: read
      questions:
      - What runtime defense rules protect my containers in v34.03?
      - Can I fetch the container runtime policy through v34.03?
      instructions:
      - text: Get the runtime container policy using v34.03.
      - text: Show v34.03 container runtime defense rules.
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/container'].put
  update:
    x-apievangelist-phrasing:
      intent: Set the container runtime policy (v34.03)
      effect: write
      questions:
      - How do I replace the whole container runtime rule set with v34.03?
      - Can I disable runtime learning for containers on v34.03?
      instructions:
      - text: Set the container runtime policy via v34.03 with {rules}.
        slots:
          rules: requestBody.rules
      - text: Set container runtime learning disabled to {learningDisabled} using v34.03.
        slots:
          learningDisabled: requestBody.learningDisabled
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/container'].post
  update:
    x-apievangelist-phrasing:
      intent: Add or update a container runtime rule (v34.03)
      effect: write
      questions:
      - How do I add one container runtime rule without replacing the rest in v34.03?
      - Can a single container runtime rule skip exec sessions on v34.03?
      instructions:
      - text: Add container runtime rule {name} via v34.03.
        slots:
          name: requestBody.name
      - text: Update v34.03 container runtime rule {name} with processes {processes}.
        slots:
          name: requestBody.name
          processes: requestBody.processes
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/container/impacted'].get
  update:
    x-apievangelist-phrasing:
      intent: List containers impacted by a runtime rule (v34.03)
      effect: read
      questions:
      - Which containers are affected by a runtime rule in v34.03?
      - Can I page through containers impacted by runtime rule changes on v34.03?
      instructions:
      - text: List containers impacted by runtime rule {rule} using v34.03.
        slots:
          rule: query.ruleName
      - text: Show {limit} containers under runtime rule {rule} (v34.03).
        slots:
          limit: query.limit
          rule: query.ruleName
      method: generated
      generated: '2026-09-26'
- target: $.paths['/api/v34.03/policies/runtime/host'].get
  update:
    x-apievangelist-phrasing:
      intent: Get the runtime host policy (v34.03)
      effect: read
      questions:
      - What runtime defense rules protect my hosts in v34.03?
      - Can I read the host runtime policy through v34.03?
      instructions:
      - text: Get the runtime host policy with v34.03.
      - text: Show v34.03 host runtime defense rules.
      method: generated
      generated: '2026-09-26'


# --- truncated at 32 KB (100 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/refs/heads/main/overlays/palo-alto-networks-policies-api-phrasing-overlay.yaml