openapi: 3.2.0 info: contact: email: lxd@lists.canonical.com name: LXD upstream url: https://github.com/canonical/lxd description: 'This is the REST API used by all LXD clients. Internal endpoints aren''t included in this documentation. The LXD API is available over both a local unix+http and remote https API. Authentication for local users relies on group membership and access to the unix socket. For remote users, the default authentication method is TLS client.' license: name: AGPL-3.0-only url: https://www.gnu.org/licenses/agpl-3.0.en.html title: LXD external REST Network Acls API version: '1.0' tags: - name: Network ACLs paths: /1.0/network-acls: get: description: Returns a list of network ACLs (URLs). operationId: network_acls_get parameters: - description: Project name example: default in: query name: project schema: type: string - description: Retrieve network ACLs from all projects example: true in: query name: all-projects schema: type: boolean responses: '200': description: API endpoints content: application/json: schema: description: Sync response properties: metadata: description: List of endpoints example: "[\n \"/1.0/network-acls/foo\",\n \"/1.0/network-acls/bar\"\n]" items: type: string type: array status: description: Status description example: Success type: string status_code: description: Status code example: 200 type: integer type: description: Response type example: sync type: string type: object '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get the network ACLs tags: - Network ACLs post: description: Creates a new network ACL. operationId: network_acls_post parameters: - description: Project name example: default in: query name: project schema: type: string responses: '202': $ref: '#/components/responses/Operation' '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Add a network ACL tags: - Network ACLs requestBody: content: application/json: schema: $ref: '#/components/schemas/NetworkACLsPost' description: ACL required: true /1.0/network-acls/{name}: delete: description: Removes the network ACL. operationId: network_acl_delete parameters: - description: Project name example: default in: query name: project schema: type: string responses: '202': $ref: '#/components/responses/Operation' '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '500': $ref: '#/components/responses/InternalServerError' summary: Delete the network ACL tags: - Network ACLs get: description: Gets a specific network ACL. operationId: network_acl_get parameters: - description: Project name example: default in: query name: project schema: type: string responses: '200': description: ACL content: application/json: schema: description: Sync response properties: metadata: $ref: '#/components/schemas/NetworkACL' status: description: Status description example: Success type: string status_code: description: Status code example: 200 type: integer type: description: Response type example: sync type: string type: object '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get the network ACL tags: - Network ACLs patch: description: Updates a subset of the network ACL configuration. operationId: network_acl_patch parameters: - description: Project name example: default in: query name: project schema: type: string responses: '202': $ref: '#/components/responses/Operation' '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '412': $ref: '#/components/responses/PreconditionFailed' '500': $ref: '#/components/responses/InternalServerError' summary: Partially update the network ACL tags: - Network ACLs requestBody: content: application/json: schema: $ref: '#/components/schemas/NetworkACLPut' description: ACL configuration required: true post: description: Renames an existing network ACL. operationId: network_acl_post parameters: - description: Project name example: default in: query name: project schema: type: string responses: '202': $ref: '#/components/responses/Operation' '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Rename the network ACL tags: - Network ACLs requestBody: content: application/json: schema: $ref: '#/components/schemas/NetworkACLPost' description: ACL rename request required: true put: description: Updates the entire network ACL configuration. operationId: network_acl_put parameters: - description: Project name example: default in: query name: project schema: type: string responses: '202': $ref: '#/components/responses/Operation' '400': $ref: '#/components/responses/BadRequest' '403': $ref: '#/components/responses/Forbidden' '404': $ref: '#/components/responses/NotFound' '412': $ref: '#/components/responses/PreconditionFailed' '500': $ref: '#/components/responses/InternalServerError' summary: Update the network ACL tags: - Network ACLs requestBody: content: application/json: schema: $ref: '#/components/schemas/NetworkACLPut' description: ACL configuration required: true /1.0/network-acls/{name}/log: get: description: Gets a specific network ACL log entries. operationId: network_acl_log_get parameters: - description: Project name example: default in: query name: project schema: type: string responses: '200': description: Raw log file '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get the network ACL log tags: - Network ACLs /1.0/network-acls?recursion=1: get: description: Returns a list of network ACLs (structs). operationId: network_acls_get_recursion1 parameters: - description: Project name example: default in: query name: project schema: type: string - description: Retrieve network ACLs from all projects example: true in: query name: all-projects schema: type: boolean responses: '200': description: API endpoints content: application/json: schema: description: Sync response properties: metadata: description: List of network ACLs items: $ref: '#/components/schemas/NetworkACL' type: array status: description: Status description example: Success type: string status_code: description: Status code example: 200 type: integer type: description: Response type example: sync type: string type: object '403': $ref: '#/components/responses/Forbidden' '500': $ref: '#/components/responses/InternalServerError' summary: Get the network ACLs tags: - Network ACLs components: schemas: NetworkACLPut: properties: config: additionalProperties: type: string description: ACL configuration map (refer to doc/network-acls.md) example: user.mykey: foo type: object x-go-name: Config description: description: Description of the ACL example: Web servers type: string x-go-name: Description egress: description: List of egress rules (order independent) items: $ref: '#/components/schemas/NetworkACLRule' type: array x-go-name: Egress ingress: description: List of ingress rules (order independent) items: $ref: '#/components/schemas/NetworkACLRule' type: array x-go-name: Ingress title: NetworkACLPut used for updating an ACL. type: object x-go-package: github.com/canonical/lxd/shared/api NetworkACLsPost: properties: config: additionalProperties: type: string description: ACL configuration map (refer to doc/network-acls.md) example: user.mykey: foo type: object x-go-name: Config description: description: Description of the ACL example: Web servers type: string x-go-name: Description egress: description: List of egress rules (order independent) items: $ref: '#/components/schemas/NetworkACLRule' type: array x-go-name: Egress ingress: description: List of ingress rules (order independent) items: $ref: '#/components/schemas/NetworkACLRule' type: array x-go-name: Ingress name: description: The new name for the ACL example: bar type: string x-go-name: Name title: NetworkACLsPost used for creating an ACL. type: object x-go-package: github.com/canonical/lxd/shared/api NetworkACL: properties: access_entitlements: description: AccessEntitlements represents the entitlements that are granted to the requesting user on the attached entity. example: - can_view - can_edit items: type: string type: array x-go-name: AccessEntitlements config: additionalProperties: type: string description: ACL configuration map (refer to doc/network-acls.md) example: user.mykey: foo type: object x-go-name: Config description: description: Description of the ACL example: Web servers type: string x-go-name: Description egress: description: List of egress rules (order independent) items: $ref: '#/components/schemas/NetworkACLRule' type: array x-go-name: Egress ingress: description: List of ingress rules (order independent) items: $ref: '#/components/schemas/NetworkACLRule' type: array x-go-name: Ingress name: description: The new name for the ACL example: bar type: string x-go-name: Name project: description: 'Project name API extension: network_acls_all_projects' example: project1 type: string x-go-name: Project used_by: description: List of URLs of objects using this profile example: - /1.0/instances/c1 - /1.0/instances/v1 - /1.0/networks/lxdbr0 items: type: string readOnly: true type: array x-go-name: UsedBy title: NetworkACL used for displaying an ACL. type: object x-go-package: github.com/canonical/lxd/shared/api NetworkACLRule: description: Refer to doc/network-acls.md for details. properties: action: description: Action to perform on rule match example: allow type: string x-go-name: Action description: description: Description of the rule example: Allow DNS queries to Google DNS type: string x-go-name: Description destination: description: Destination address example: 8.8.8.8/32,8.8.4.4/32 type: string x-go-name: Destination destination_port: description: Destination port example: '53' type: string x-go-name: DestinationPort icmp_code: description: ICMP message code (for ICMP protocol) example: '0' type: string x-go-name: ICMPCode icmp_type: description: Type of ICMP message (for ICMP protocol) example: '8' type: string x-go-name: ICMPType protocol: description: Protocol example: udp type: string x-go-name: Protocol source: description: Source address example: '@internal' type: string x-go-name: Source source_port: description: Source port example: '1234' type: string x-go-name: SourcePort state: description: State of the rule example: enabled type: string x-go-name: State title: NetworkACLRule represents a single rule in an ACL ruleset. type: object x-go-package: github.com/canonical/lxd/shared/api NetworkACLPost: properties: name: description: The new name for the ACL example: bar type: string x-go-name: Name title: NetworkACLPost used for renaming an ACL. type: object x-go-package: github.com/canonical/lxd/shared/api StatusCode: format: int64 title: StatusCode represents a valid LXD operation and container status. type: integer x-go-package: github.com/canonical/lxd/shared/api Operation: description: Operation represents a LXD background operation properties: child_count: description: 'Number of child operations. API extension: operation_child_count' example: 2 format: int64 type: integer x-go-name: ChildCount class: description: Type of operation (task, token or websocket) example: websocket type: string x-go-name: Class created_at: description: Operation creation time example: '2021-03-23T17:38:37.753398689-04:00' format: date-time type: string x-go-name: CreatedAt description: description: Description of the operation example: Executing command type: string x-go-name: Description err: description: Operation error message example: Some error message type: string x-go-name: Err err_code: description: 'Operation error code API extension: bulk_operations' example: 404 format: int64 type: integer x-go-name: ErrCode id: description: UUID of the operation example: 6916c8a6-9b7d-4abd-90b3-aedfec7ec7da type: string x-go-name: ID location: description: 'Which cluster member this record was found on API extension: operation_location' example: lxd01 type: string x-go-name: Location may_cancel: description: Whether the operation can be canceled example: false type: boolean x-go-name: MayCancel metadata: additionalProperties: {} description: Operation specific metadata example: command: - bash environment: HOME: /root LANG: C.UTF-8 PATH: /usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin TERM: xterm USER: root fds: '0': da3046cf02c0116febf4ef3fe4eaecdf308e720c05e5a9c730ce1a6f15417f66 '1': 05896879d8692607bd6e4a09475667da3b5f6714418ab0ee0e5720b4c57f754b interactive: true type: object x-go-name: Metadata requestor: $ref: '#/components/schemas/OperationRequestor' resources: additionalProperties: items: type: string type: array description: Affected resources example: instances: - /1.0/instances/foo - /1.0/instances/bar type: object x-go-name: Resources status: description: Status name example: Running type: string x-go-name: Status status_code: $ref: '#/components/schemas/StatusCode' updated_at: description: Operation last change example: '2021-03-23T17:38:37.753398689-04:00' format: date-time type: string x-go-name: UpdatedAt type: object x-go-package: github.com/canonical/lxd/shared/api OperationRequestor: description: 'API extension: operation_requestor.' properties: address: description: Address is the origin address of the request. example: 10.0.2.15 type: string x-go-name: Address protocol: description: Protocol represents the method used to authenticate the requestor. example: oidc type: string x-go-name: Protocol username: description: Username is the username of the requestor. This is the identifier of the identity, or the username if using the unix socket. example: jane.doe@example.com type: string x-go-name: Username title: OperationRequestor represents the initial requestor of an operation type: object x-go-package: github.com/canonical/lxd/shared/api responses: InternalServerError: description: Internal Server Error content: application/json: schema: properties: error: example: internal server error type: string x-go-name: Error error_code: example: 500 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object PreconditionFailed: description: Precondition Failed content: application/json: schema: properties: error: example: precondition failed type: string x-go-name: Error error_code: example: 412 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object BadRequest: description: Bad Request content: application/json: schema: properties: error: example: bad request type: string x-go-name: Error error_code: example: 400 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object NotFound: description: Not found content: application/json: schema: properties: error: example: not found type: string x-go-name: Error error_code: example: 404 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object Forbidden: description: Forbidden content: application/json: schema: properties: error: example: not authorized type: string x-go-name: Error error_code: example: 403 format: int64 type: integer x-go-name: ErrorCode type: example: error type: string x-go-name: Type type: object Operation: description: Operation content: application/json: schema: properties: metadata: $ref: '#/components/schemas/Operation' operation: example: /1.0/operations/66e83638-9dd7-4a26-aef2-5462814869a1 type: string x-go-name: Operation status: example: Operation created type: string x-go-name: Status status_code: example: 100 format: int64 type: integer x-go-name: StatusCode type: example: async type: string x-go-name: Type type: object