CloudTruth · Schema

AwsPush

Push actions can be configured to send configuration and secrets to integrations when tags are updated.

CompanyConfigManagementDevOpsCloudSecurity

Properties

Name Type Description
url string
id string Unique identifier for the action.
name string The action name.
description string The optional description for the action.
latest_task object The most recent task run for this action.
created_at string
modified_at stringnull
coerce_parameters boolean This setting allows parameters (non-secrets) to be pushed to a destination that only supports storing secrets. This may increase your overall cost from the cloud provider as some cloud providers charg
include_parameters boolean Include parameters (non-secrets) in the values being pushed. This setting requires the destination to support parameters or for the `coerce_parameters` flag to be enabled, otherwise the push will fail
include_secrets boolean Include secrets in the values being pushed. This setting requires the destination to support secrets, otherwise the push will fail.
include_templates boolean Include templates in the values being pushed.
dry_run boolean When set to dry-run mode an action will report the changes that it would have made in task steps, however those changes are not actually performed.
force boolean Normally, push will check to see if it originated the values in the destination before making changes to them. Forcing a push disables the ownership check.
local boolean Normally, push will process all parameters including those that flow in from project dependencies. Declaring a push as `local` will cause it to only process the parameters defined in the selected proj
projects array Projects that are included in the push.
tags array Tags are used to select parameters by environment from the projects included in the push. You cannot have two tags from the same environment in the same push.
region object The AWS region this push targets. This region must be enabled in the integration. * `af-south-1` - af-south-1 * `ap-east-1` - ap-east-1 * `ap-northeast-1` - ap-northeast-1 * `ap-northeast-2` - ap-nort
service object The AWS service this push targets. This service must be enabled in the integration. * `s3` - s3 * `secretsmanager` - secretsmanager * `ssm` - ssm
resource stringnull Defines a path through the integration to the location where values will be pushed. The following mustache-style substitutions can be used in the string: - ``{{ environment }}`` to insert the environm
View JSON Schema on GitHub

JSON Schema

cloudtruth-aws-push-schema.json Raw ↑
{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://raw.githubusercontent.com/api-evangelist/cloudtruth/main/json-schema/cloudtruth-aws-push-schema.json",
  "title": "AwsPush",
  "description": "Push actions can be configured to send configuration and secrets to\nintegrations when tags are updated.",
  "x-generated": "2026-10-09",
  "x-method": "derived",
  "x-generator": "derive-json-schema.py",
  "x-source": "openapi/cloudtruth-openapi.yml#/components/schemas/AwsPush",
  "type": "object",
  "properties": {
    "url": {
      "type": "string",
      "format": "uri",
      "readOnly": true
    },
    "id": {
      "type": "string",
      "format": "uuid",
      "readOnly": true,
      "description": "Unique identifier for the action."
    },
    "name": {
      "type": "string",
      "description": "The action name.",
      "maxLength": 256
    },
    "description": {
      "type": "string",
      "description": "The optional description for the action."
    },
    "latest_task": {
      "allOf": [
        {
          "$ref": "#/$defs/AwsPushTask"
        }
      ],
      "readOnly": true,
      "nullable": true,
      "description": "The most recent task run for this action."
    },
    "created_at": {
      "type": "string",
      "format": "date-time",
      "readOnly": true
    },
    "modified_at": {
      "type": [
        "string",
        "null"
      ],
      "format": "date-time",
      "readOnly": true
    },
    "coerce_parameters": {
      "type": "boolean",
      "description": "This setting allows parameters (non-secrets) to be pushed to a destination that only supports storing secrets.  This may increase your overall cost from the cloud provider as some cloud providers charge a premium for secrets-only storage."
    },
    "include_parameters": {
      "type": "boolean",
      "description": "Include parameters (non-secrets) in the values being pushed.  This setting requires the destination to support parameters or for the `coerce_parameters` flag to be enabled, otherwise the push will fail."
    },
    "include_secrets": {
      "type": "boolean",
      "description": "Include secrets in the values being pushed.  This setting requires the destination to support secrets, otherwise the push will fail."
    },
    "include_templates": {
      "type": "boolean",
      "description": "Include templates in the values being pushed."
    },
    "dry_run": {
      "type": "boolean",
      "description": "When set to dry-run mode an action will report the changes that it would have made in task steps, however those changes are not actually performed."
    },
    "force": {
      "type": "boolean",
      "description": "Normally, push will check to see if it originated the values in the destination before making changes to them.  Forcing a push disables the ownership check."
    },
    "local": {
      "type": "boolean",
      "description": "Normally, push will process all parameters including those that flow in from project dependencies.  Declaring a push as `local` will cause it to only process the parameters defined in the selected projects."
    },
    "projects": {
      "type": "array",
      "items": {
        "type": "string",
        "format": "uri"
      },
      "description": "Projects that are included in the push."
    },
    "tags": {
      "type": "array",
      "items": {
        "type": "string",
        "format": "uri"
      },
      "description": "Tags are used to select parameters by environment from the projects included in the push.  You cannot have two tags from the same environment in the same push."
    },
    "region": {
      "allOf": [
        {
          "$ref": "#/$defs/AwsRegionEnum"
        }
      ],
      "description": "The AWS region this push targets.  This region must be enabled in the integration.\n\n* `af-south-1` - af-south-1\n* `ap-east-1` - ap-east-1\n* `ap-northeast-1` - ap-northeast-1\n* `ap-northeast-2` - ap-northeast-2\n* `ap-northeast-3` - ap-northeast-3\n* `ap-south-1` - ap-south-1\n* `ap-southeast-1` - ap-southeast-1\n* `ap-southeast-2` - ap-southeast-2\n* `ca-central-1` - ca-central-1\n* `cn-north-1` - cn-north-1\n* `cn-northwest-1` - cn-northwest-1\n* `eu-central-1` - eu-central-1\n* `eu-north-1` - eu-north-1\n* `eu-south-1` - eu-south-1\n* `eu-west-1` - eu-west-1\n* `eu-west-2` - eu-west-2\n* `eu-west-3` - eu-west-3\n* `me-south-1` - me-south-1\n* `sa-east-1` - sa-east-1\n* `us-east-1` - us-east-1\n* `us-east-2` - us-east-2\n* `us-west-1` - us-west-1\n* `us-west-2` - us-west-2"
    },
    "service": {
      "allOf": [
        {
          "$ref": "#/$defs/AwsServiceEnum"
        }
      ],
      "description": "The AWS service this push targets.  This service must be enabled in the integration.\n\n* `s3` - s3\n* `secretsmanager` - secretsmanager\n* `ssm` - ssm"
    },
    "resource": {
      "type": [
        "string",
        "null"
      ],
      "description": "Defines a path through the integration to the location where values will be pushed.\n\nThe following mustache-style substitutions can be used in the string:\n\n  - ``{{ environment }}`` to insert the environment name\n  - ``{{ parameter }}`` to insert the parameter name\n  - ``{{ project }}`` to insert the project name\n  - ``{{ push }}`` to insert the push name\n  - ``{{ tag }}`` to insert the tag name\n\nWe recommend that you use project, environment, and parameter at a minimum to disambiguate your pushed resource identifiers.\n\nIf you include multiple projects in the push, the `project` substitution is required.  If you include multiple tags from different environments in the push, the `environment` substitution is required.  If you include multiple tags from the same environment in the push, the `tag` substitution is required.  In all cases, the `parameter` substitution is always required.",
      "maxLength": 1024
    }
  },
  "required": [
    "created_at",
    "id",
    "latest_task",
    "modified_at",
    "name",
    "projects",
    "region",
    "resource",
    "service",
    "tags",
    "url"
  ],
  "$defs": {
    "AwsPushTask": {
      "type": "object",
      "description": "Push task for an AWS integration.",
      "properties": {
        "url": {
          "type": "string",
          "format": "uri",
          "readOnly": true
        },
        "id": {
          "type": "string",
          "format": "uuid",
          "readOnly": true,
          "description": "The unique identifier for the task."
        },
        "reason": {
          "type": [
            "string",
            "null"
          ],
          "description": "The reason why this task was triggered.",
          "maxLength": 256
        },
        "dry_run": {
          "type": "boolean",
          "description": "Indicates task steps were only simulated, not actually performed."
        },
        "state": {
          "allOf": [
            {
              "$ref": "#/$defs/StateEnum"
            }
          ],
          "description": "The current state of this task.\n\n* `queued` - Queued\n* `running` - Running\n* `skipped` - Skipped\n* `success` - Success\n* `failure` - Failure"
        },
        "error_code": {
          "type": [
            "string",
            "null"
          ],
          "description": "If an error occurs early during processing, before attempting to process values, this code may be helpful in determining the problem.",
          "maxLength": 256
        },
        "error_detail": {
          "type": [
            "string",
            "null"
          ],
          "description": "If an error occurs early during processing, before attempting to process values, this detail may be helpful in determining the problem."
        },
        "created_at": {
          "type": "string",
          "format": "date-time",
          "readOnly": true
        },
        "modified_at": {
          "type": [
            "string",
            "null"
          ],
          "format": "date-time",
          "readOnly": true
        }
      },
      "required": [
        "created_at",
        "id",
        "modified_at",
        "url"
      ]
    },
    "AwsRegionEnum": {
      "enum": [
        "af-south-1",
        "ap-east-1",
        "ap-northeast-1",
        "ap-northeast-2",
        "ap-northeast-3",
        "ap-south-1",
        "ap-southeast-1",
        "ap-southeast-2",
        "ca-central-1",
        "cn-north-1",
        "cn-northwest-1",
        "eu-central-1",
        "eu-north-1",
        "eu-south-1",
        "eu-west-1",
        "eu-west-2",
        "eu-west-3",
        "me-south-1",
        "sa-east-1",
        "us-east-1",
        "us-east-2",
        "us-west-1",
        "us-west-2"
      ],
      "type": "string",
      "description": "* `af-south-1` - af-south-1\n* `ap-east-1` - ap-east-1\n* `ap-northeast-1` - ap-northeast-1\n* `ap-northeast-2` - ap-northeast-2\n* `ap-northeast-3` - ap-northeast-3\n* `ap-south-1` - ap-south-1\n* `ap-southeast-1` - ap-southeast-1\n* `ap-southeast-2` - ap-southeast-2\n* `ca-central-1` - ca-central-1\n* `cn-north-1` - cn-north-1\n* `cn-northwest-1` - cn-northwest-1\n* `eu-central-1` - eu-central-1\n* `eu-north-1` - eu-north-1\n* `eu-south-1` - eu-south-1\n* `eu-west-1` - eu-west-1\n* `eu-west-2` - eu-west-2\n* `eu-west-3` - eu-west-3\n* `me-south-1` - me-south-1\n* `sa-east-1` - sa-east-1\n* `us-east-1` - us-east-1\n* `us-east-2` - us-east-2\n* `us-west-1` - us-west-1\n* `us-west-2` - us-west-2"
    },
    "AwsServiceEnum": {
      "enum": [
        "s3",
        "secretsmanager",
        "ssm"
      ],
      "type": "string",
      "description": "* `s3` - s3\n* `secretsmanager` - secretsmanager\n* `ssm` - ssm"
    },
    "StateEnum": {
      "enum": [
        "queued",
        "running",
        "skipped",
        "success",
        "failure"
      ],
      "type": "string",
      "description": "* `queued` - Queued\n* `running` - Running\n* `skipped` - Skipped\n* `success` - Success\n* `failure` - Failure"
    }
  }
}

Work with this as data

Every JSON Schema here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for schemas

4 MCP tools reach this
  • find_json_schemasBrowse and filter every JSON Schema in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This JSON Schema
curl "https://apis.io/api/v1/json-schemas/cloudtruth-aws-push"
All schemas
curl "https://apis.io/api/v1/json-schemas?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.