openapi: 3.1.0 info: title: Application Research CNAB Bundle API Resources SecretStores API version: 1.0.0 description: 'API for managing Cloud Native Application Bundles (CNAB). This API provides endpoints for managing CNAB bundles, claims, claim results, dependencies, parameter sources, relocation mappings, and installation status. ' contact: name: CNAB Specification url: https://cnab.io license: name: Apache-2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://api.example.com/v1 description: Production server - url: https://staging-api.example.com/v1 description: Staging server security: - bearerAuth: [] - apiKey: [] tags: - name: SecretStores description: Secret store operations paths: /planes/radius/{planeName}/resourceGroups/{resourceGroupName}/providers/Applications.Core/secretStores/{secretStoreName}: get: tags: - SecretStores summary: Application Research Get secret store operationId: SecretStores_Get parameters: - $ref: '#/components/parameters/PlaneNameParameter' - $ref: '#/components/parameters/ResourceGroupNameParameter' - $ref: '#/components/parameters/SecretStoreNameParameter' - $ref: '#/components/parameters/ApiVersionParameter' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/SecretStoreResource' examples: genericSecretStore: $ref: '#/components/examples/GenericSecretStoreExample' default: $ref: '#/components/responses/ErrorResponse' put: tags: - SecretStores summary: Application Research Create or update secret store operationId: SecretStores_CreateOrUpdate parameters: - $ref: '#/components/parameters/PlaneNameParameter' - $ref: '#/components/parameters/ResourceGroupNameParameter' - $ref: '#/components/parameters/SecretStoreNameParameter' - $ref: '#/components/parameters/ApiVersionParameter' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SecretStoreResource' examples: genericSecretStore: $ref: '#/components/examples/GenericSecretStoreExample' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/SecretStoreResource' '201': description: Created content: application/json: schema: $ref: '#/components/schemas/SecretStoreResource' default: $ref: '#/components/responses/ErrorResponse' components: schemas: EnvironmentCompute: type: object description: Represents backing compute resource properties: kind: type: string resourceId: type: string identity: $ref: '#/components/schemas/IdentitySettings' required: - kind discriminator: propertyName: kind mapping: kubernetes: '#/components/schemas/KubernetesCompute' aci: '#/components/schemas/AzureContainerInstanceCompute' ProvisioningState: type: string description: Provisioning state of the resource at the time the operation was called enum: - Creating - Updating - Deleting - Accepted - Provisioning - Succeeded - Failed - Canceled readOnly: true SecretValueProperties: type: object properties: encoding: type: string default: raw enum: - raw - base64 value: type: string format: password valueFrom: $ref: '#/components/schemas/ValueFromProperties' IdentitySettingKind: type: string description: IdentitySettingKind is the kind of supported external identity setting enum: - undefined - azure.com.workload - aws.com.irsa - userAssigned - systemAssigned - systemAssignedUserAssigned OutputResource: type: object description: Properties of an output resource properties: localId: type: string id: type: string radiusManaged: type: boolean SecretStoreProperties: type: object properties: environment: type: string application: type: string provisioningState: $ref: '#/components/schemas/ProvisioningState' readOnly: true status: $ref: '#/components/schemas/ResourceStatus' readOnly: true type: type: string default: generic enum: - generic - certificate - basicAuthentication - azureWorkloadIdentity - awsIRSA data: type: object additionalProperties: $ref: '#/components/schemas/SecretValueProperties' resource: type: string required: - data SecretStoreResource: type: object properties: properties: $ref: '#/components/schemas/SecretStoreProperties' id: type: string readOnly: true name: type: string readOnly: true type: type: string readOnly: true systemData: type: object readOnly: true tags: type: object additionalProperties: type: string location: type: string required: - properties - location IdentitySettings: type: object description: IdentitySettings is the external identity setting properties: kind: $ref: '#/components/schemas/IdentitySettingKind' oidcIssuer: type: string description: The URI for your compute platform's OIDC issuer resource: type: string description: The resource ID of the provisioned identity managedIdentity: type: array items: type: string required: - kind RecipeStatus: type: object description: Recipe status at deployment time properties: templateKind: type: string templatePath: type: string templateVersion: type: string required: - templateKind - templatePath ValueFromProperties: type: object properties: name: type: string version: type: string required: - name ResourceStatus: type: object description: Status of a resource properties: compute: $ref: '#/components/schemas/EnvironmentCompute' recipe: $ref: '#/components/schemas/RecipeStatus' readOnly: true outputResources: type: array items: $ref: '#/components/schemas/OutputResource' parameters: ApiVersionParameter: name: api-version in: query required: true description: The API version to use for this operation schema: type: string default: 2023-10-01-preview ResourceGroupNameParameter: name: resourceGroupName in: path required: true description: The name of the resource group schema: type: string pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ maxLength: 63 SecretStoreNameParameter: name: secretStoreName in: path required: true description: The name of the secret store schema: type: string PlaneNameParameter: name: planeName in: path required: true description: The name of the plane schema: type: string pattern: ^[A-Za-z]([-A-Za-z0-9]*[A-Za-z0-9])?$ maxLength: 63 examples: GenericSecretStoreExample: summary: Generic secret store with database credentials value: properties: application: /planes/radius/local/resourceGroups/ecommerce-rg/providers/Applications.Core/applications/ecommerce-platform type: generic data: username: encoding: raw value: ecommerce_admin password: encoding: base64 value: c3VwZXJzZWNyZXRwYXNzd29yZA== location: eastus tags: secret-type: database responses: ErrorResponse: description: Error response content: application/json: schema: type: object properties: error: type: object properties: code: type: string description: Error code message: type: string description: Error message target: type: string description: Error target required: - code - message required: - error securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: JWT-based authentication apiKey: type: apiKey in: header name: X-API-Key description: API key authentication