openapi: 3.2.0 info: title: Chronosphere Service Account API version: v1 description: 'Operations tagged ServiceAccount across 2 of this provider''s published API definitions: chronosphere-config-v1-openapi3.json, chronosphere-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://{tenant}.chronosphere.io variables: tenant: default: tenant description: tenant ID assigned by the service provider - url: / tags: - name: Service Account paths: /api/v1/config/service-accounts: get: operationId: ListServiceAccounts parameters: - description: 'Sets the preferred number of items to return per page. If set to `0`, the server will use its default value. Regardless of the value specified, clients must never assume how many items will be returned.' in: query name: page.max_size schema: format: int64 type: integer - description: 'An opaque page token that identifies which page the client should request. An empty value indicates the first page.' in: query name: page.token schema: type: string - description: Filters results by slug, where any ServiceAccount with a matching slug in the given list (and matches all other filters) will be returned. in: query name: slugs schema: items: type: string type: array - description: Filters results by name, where any ServiceAccount with a matching name in the given list (and matches all other filters) will be returned. in: query name: names schema: items: type: string type: array responses: '200': content: application/json: schema: $ref: '#/components/schemas/configv1ListServiceAccountsResponse' description: A successful response. '500': content: application/json: schema: $ref: '#/components/schemas/apiError' description: An unexpected error response. default: content: application/json: schema: $ref: '#/components/schemas/genericError' description: An undefined error response. tags: - Service Account security: - ApiKeyAuth: [] summary: List service accounts x-summary-source: derived post: operationId: CreateServiceAccount requestBody: content: application/json: schema: $ref: '#/components/schemas/configv1CreateServiceAccountRequest' required: true x-originalParamName: body responses: '200': content: application/json: schema: $ref: '#/components/schemas/configv1CreateServiceAccountResponse' description: A successful response containing the created ServiceAccount. '400': content: application/json: schema: $ref: '#/components/schemas/apiError' description: Cannot create the ServiceAccount because the request is invalid. '409': content: application/json: schema: $ref: '#/components/schemas/apiError' description: Cannot create the ServiceAccount because there is a conflict with an existing ServiceAccount. '500': content: application/json: schema: $ref: '#/components/schemas/apiError' description: An unexpected error response. default: content: application/json: schema: $ref: '#/components/schemas/genericError' description: An undefined error response. tags: - Service Account security: - ApiKeyAuth: [] summary: Create service account x-summary-source: derived servers: - url: https://{tenant}.chronosphere.io variables: tenant: default: tenant description: tenant ID assigned by the service provider /api/v1/config/service-accounts/{slug}: delete: operationId: DeleteServiceAccount parameters: - in: path name: slug required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/configv1DeleteServiceAccountResponse' description: A successful response. '400': content: application/json: schema: $ref: '#/components/schemas/apiError' description: Cannot delete the ServiceAccount because it is in use. '404': content: application/json: schema: $ref: '#/components/schemas/apiError' description: Cannot delete the ServiceAccount because the slug does not exist. '500': content: application/json: schema: $ref: '#/components/schemas/apiError' description: An unexpected error response. default: content: application/json: schema: $ref: '#/components/schemas/genericError' description: An undefined error response. tags: - Service Account security: - ApiKeyAuth: [] summary: Delete service account x-summary-source: derived get: operationId: ReadServiceAccount parameters: - in: path name: slug required: true schema: type: string responses: '200': content: application/json: schema: $ref: '#/components/schemas/configv1ReadServiceAccountResponse' description: A successful response. '404': content: application/json: schema: $ref: '#/components/schemas/apiError' description: Cannot read the ServiceAccount because the slug does not exist. '500': content: application/json: schema: $ref: '#/components/schemas/apiError' description: An unexpected error response. default: content: application/json: schema: $ref: '#/components/schemas/genericError' description: An undefined error response. tags: - Service Account security: - ApiKeyAuth: [] summary: Read service account x-summary-source: derived servers: - url: https://{tenant}.chronosphere.io variables: tenant: default: tenant description: tenant ID assigned by the service provider components: schemas: configv1PageResult: properties: next_token: description: 'An opaque page token that identifies the next page of items that the client should request. An empty value indicates that there are no more items to return.' type: string type: object MetricsRestrictionPermission: enum: - READ - WRITE - READ_WRITE type: string configv1ServiceAccount: properties: created_at: description: Timestamp of when the ServiceAccount was created. Cannot be set by clients. format: date-time readOnly: true type: string email: description: The unique email user for this service account. Cannot be set by clients. readOnly: true type: string metrics_restriction: allOf: - $ref: '#/components/schemas/ServiceAccountMetricsRestriction' description: 'If set, restricts access of the service account to only metric data. Only one of `unrestricted` or `metrics_restriction` must be set.' name: description: The name of the ServiceAccount. You can modify this value after the ServiceAccount is created. type: string slug: description: The unique identifier of the ServiceAccount. If a `slug` isn't provided, one is generated based on the `name` field. You can't modify this field after the ServiceAccount is created. type: string token: description: 'Generated API token of the service account. Cannot be set by clients. The token is set only once by the server in the `CreateServiceAccount` response. The `ReadServiceAccount` response always returns an empty token. Therefore, when creating a service account, ensure you securely store the response token. If you lose the token, you must delete and recreate the service account to generate a new token.' readOnly: true type: string unrestricted: description: 'If set, grants the service account access to all Chronosphere APIs, including resource configuration and metric data within the access controls defined by the service account''s team membership. Only one of `unrestricted` or `metrics_restriction` must be set.' type: boolean updated_at: description: Timestamp of when the ServiceAccount was last updated. Cannot be set by clients. format: date-time readOnly: true type: string required: - name type: object apiError: properties: message: description: An error message describing what went wrong. type: string type: object configv1ListServiceAccountsResponse: properties: page: $ref: '#/components/schemas/configv1PageResult' service_accounts: items: $ref: '#/components/schemas/configv1ServiceAccount' type: array type: object configv1ReadServiceAccountResponse: properties: service_account: $ref: '#/components/schemas/configv1ServiceAccount' type: object configv1DeleteServiceAccountResponse: type: object ServiceAccountMetricsRestriction: properties: labels: additionalProperties: type: string description: 'Optional. Specifies labels that further restrict the service account to only read or write metrics with the given label names and values.' type: object permission: allOf: - $ref: '#/components/schemas/MetricsRestrictionPermission' description: 'Permission that defines the access level of the service account to only metric data: - `READ` grants read-only access. - `WRITE` grants write-only access. - `READ_WRITE` grants read and write access.' required: - permission type: object genericError: additionalProperties: true type: object configv1CreateServiceAccountRequest: properties: dry_run: description: If `true`, validates the specified configuration without creating the ServiceAccount. If the specified configuration is valid, the endpoint returns a partial response without the ServiceAccount. If the specified configuration is invalid, the endpoint returns an error. type: boolean service_account: allOf: - $ref: '#/components/schemas/configv1ServiceAccount' description: The ServiceAccount to create. type: object configv1CreateServiceAccountResponse: properties: service_account: $ref: '#/components/schemas/configv1ServiceAccount' type: object configv1PageResult_2: type: object properties: next_token: type: string description: 'Opaque page token which identifies the next page of items which the client should request. An empty next_token indicates that there are no more items to return.' configv1ServiceAccount_2: type: object properties: slug: type: string description: Unique identifier of the ServiceAccount. If a `slug` isn't provided, one will be generated based of the `name` field. You can't modify this field after the ServiceAccount is created. name: type: string description: Required. Name of the ServiceAccount. You can modify this value after the ServiceAccount is created. created_at: type: string description: Timestamp of when the ServiceAccount was created. Cannot be set by clients. format: date-time readOnly: true updated_at: type: string description: Timestamp of when the ServiceAccount was last updated. Cannot be set by clients. format: date-time readOnly: true token: type: string description: 'token is the generated API token of the service account. Cannot be set by clients. token is only set once by the server in the CreateServiceAccount response. ReadServiceAccount will always return an empty token. Therefore, when creating a service account, clients are responsible for securely storing the response token on their end, as they will not be able to read it again.' readOnly: true email: type: string description: 'email is the generated email address of the service account. Cannot be set by clients.' readOnly: true unrestricted: type: boolean description: 'If set, grants the service account access to all Chronosphere APIs (including resource configuration and metric data) within the access controls defined by the service account''s team membership. Exactly one of unrestricted or metrics_restriction must be set.' metrics_restriction: $ref: '#/components/schemas/ServiceAccountMetricsRestriction_2' apiError_2: type: object properties: code: type: integer description: An optional private error code whose values are undefined. format: int32 message: type: string description: An error message describing what went wrong. ServiceAccountMetricsRestriction_2: type: object properties: permission: $ref: '#/components/schemas/MetricsRestrictionPermission' labels: type: object additionalProperties: type: string description: 'Optional labels which further restricts the service account to only read or write metrics with the given label names and values.' configv1CreateServiceAccountRequest_2: type: object properties: service_account: $ref: '#/components/schemas/configv1ServiceAccount_2' dry_run: type: boolean description: If true, the ServiceAccount isn't created, and no response ServiceAccount will be returned. The response will return an error if the given ServiceAccount is invalid. securitySchemes: ApiKeyAuth: description: Chronosphere API token in: header name: API-Token type: apiKey x-refined-from: - chronosphere-config-v1-openapi3.json - chronosphere-openapi.yml