# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand. overlay: 1.0.0 info: title: API Evangelist conversational phrasing for Cloudera Environments Service Environments2 API version: 1.0.0 extends: openapi/cloudera-environments2-api-openapi.yml actions: - target: $.info update: x-apievangelist-phrasing: method: generated generated: '2026-10-01' generator: build-phrasing.py label: Generated by API Evangelist operations: 104 - target: $.paths['/api/v1/environments2/getCredentialPrerequisites'].post update: x-apievangelist-phrasing: intent: Get credential prerequisites for a cloud provider effect: read questions: - What do I need to set up in my cloud account before creating a CDP credential? - Which policies does a commercial-cloud credential require for my provider? instructions: - text: Get the credential prerequisites for {cloudPlatform}. slots: cloudPlatform: requestBody.cloudPlatform - text: Show the role and policy prerequisites for a {cloudPlatform} credential. slots: cloudPlatform: requestBody.cloudPlatform method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getGovCloudCredentialPrerequisites'].post update: x-apievangelist-phrasing: intent: Get GovCloud credential prerequisites effect: read questions: - What prerequisites apply to a GovCloud credential in CDP? - Which policies must exist before I create a credential for GovCloud? instructions: - text: Get GovCloud credential prerequisites for {cloudPlatform}. slots: cloudPlatform: requestBody.cloudPlatform - text: Show what a GovCloud credential on {cloudPlatform} needs set up first. slots: cloudPlatform: requestBody.cloudPlatform method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createAWSEnvironment'].post update: x-apievangelist-phrasing: intent: Create an AWS environment effect: write questions: - How do I create a new CDP environment in AWS commercial regions? - Can CDP create private subnets for me when I set up an AWS environment? instructions: - text: Create AWS environment {environmentName} in {region} using credential {credentialName}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName - text: Set up AWS environment {environmentName} with credential {credentialName} in {region}, inside VPC {vpcId}. slots: environmentName: requestBody.environmentName credentialName: requestBody.credentialName region: requestBody.region vpcId: requestBody.vpcId method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createAWSGovCloudEnvironment'].post update: x-apievangelist-phrasing: intent: Create an AWS GovCloud environment effect: write questions: - How do I create a CDP environment in AWS GovCloud? - Can I give a network CIDR when creating a GovCloud environment? instructions: - text: Create AWS GovCloud environment {environmentName} in {region} with credential {credentialName}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName - text: Set up GovCloud environment {environmentName} in {region} using {credentialName} and network CIDR {networkCidr}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName networkCidr: requestBody.networkCidr method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createAzureEnvironment'].post update: x-apievangelist-phrasing: intent: Create an Azure environment effect: write questions: - What's needed to create a CDP environment on Azure? - Can my Azure environment use an existing resource group and availability zones? instructions: - text: Create Azure environment {environmentName} in {region} with credential {credentialName}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName - text: Set up Azure environment {environmentName} in {region} using {credentialName} in resource group {resourceGroupName}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName resourceGroupName: requestBody.resourceGroupName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createGCPEnvironment'].post update: x-apievangelist-phrasing: intent: Create a GCP environment effect: write questions: - How do I create a CDP environment on Google Cloud? - Can a GCP environment use a customer encryption key? instructions: - text: Create GCP environment {environmentName} in {region} with credential {credentialName}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName - text: Set up Google Cloud environment {environmentName} in {region} using {credentialName} and encryption key {encryptionKey}. slots: environmentName: requestBody.environmentName region: requestBody.region credentialName: requestBody.credentialName encryptionKey: requestBody.encryptionKey method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createPrivateEnvironment'].post update: x-apievangelist-phrasing: intent: Create a Private Cloud environment effect: write questions: - How do I register an on-prem Private Cloud environment from Cloudera Manager? - Which Cloudera Manager clusters can I attach when creating a Private Cloud environment? instructions: - text: Create Private Cloud environment {environmentName} from Cloudera Manager at {address} as {user} with clusters {clusterNames}. slots: environmentName: requestBody.environmentName address: requestBody.address user: requestBody.user clusterNames: requestBody.clusterNames - text: Register private environment {environmentName} using Cloudera Manager {address}, user {user}, token {authenticationToken}, clusters {clusterNames}. slots: environmentName: requestBody.environmentName address: requestBody.address user: requestBody.user authenticationToken: requestBody.authenticationToken clusterNames: requestBody.clusterNames method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createAWSCredential'].post update: x-apievangelist-phrasing: intent: Create an AWS credential effect: write questions: - How do I give CDP access to my AWS account with a cross-account role? - What IAM role ARN does a new AWS credential need? instructions: - text: Create AWS credential {credentialName} with role ARN {roleArn}. slots: credentialName: requestBody.credentialName roleArn: requestBody.roleArn - text: Add a new commercial AWS credential named {credentialName} for role {roleArn}. slots: credentialName: requestBody.credentialName roleArn: requestBody.roleArn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createAWSGovCloudCredential'].post update: x-apievangelist-phrasing: intent: Create an AWS GovCloud credential effect: write questions: - How do I create a credential for AWS GovCloud in CDP? - Does a GovCloud credential also use a cross-account role ARN? instructions: - text: Create GovCloud credential {credentialName} with role ARN {roleArn}. slots: credentialName: requestBody.credentialName roleArn: requestBody.roleArn - text: Add an AWS GovCloud credential named {credentialName} using role {roleArn}. slots: credentialName: requestBody.credentialName roleArn: requestBody.roleArn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createAzureCredential'].post update: x-apievangelist-phrasing: intent: Create an Azure credential effect: write questions: - What do I need to create an Azure credential for CDP? - Can I make an app-based Azure credential tied to a specific subscription and tenant? instructions: - text: Create Azure credential {credentialName} for subscription {subscriptionId} and tenant {tenantId}. slots: credentialName: requestBody.credentialName subscriptionId: requestBody.subscriptionId tenantId: requestBody.tenantId - text: Add a new app-based Azure credential named {credentialName} with app details {appBased}. slots: credentialName: requestBody.credentialName appBased: requestBody.appBased method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAzureCredential'].post update: x-apievangelist-phrasing: intent: Update a certificate-based Azure credential effect: write questions: - Can I change the subscription or tenant on an existing certificate-based Azure credential? - How do I refresh the app details on an Azure credential I already have? instructions: - text: Update existing Azure credential {credentialName} to subscription {subscriptionId}, tenant {tenantId}, app {appBased}. slots: credentialName: requestBody.credentialName subscriptionId: requestBody.subscriptionId tenantId: requestBody.tenantId appBased: requestBody.appBased - text: Modify the certificate-based Azure credential {credentialName} for tenant {tenantId}, subscription {subscriptionId}, app {appBased}. slots: credentialName: requestBody.credentialName tenantId: requestBody.tenantId subscriptionId: requestBody.subscriptionId appBased: requestBody.appBased method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAwsCredential'].post update: x-apievangelist-phrasing: intent: Update an existing AWS credential effect: write questions: - How do I point an existing AWS credential at a new role ARN? - Can permissions be verified when I update an AWS credential? instructions: - text: Update existing AWS credential {credentialName} to use role {roleArn}. slots: credentialName: requestBody.credentialName roleArn: requestBody.roleArn - text: Swap the role on AWS credential {credentialName} to {roleArn} and verify its permissions. slots: credentialName: requestBody.credentialName roleArn: requestBody.roleArn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createGCPCredential'].post update: x-apievangelist-phrasing: intent: Create a GCP credential effect: write questions: - How do I give CDP access to my Google Cloud project? - What service account key does a GCP credential need? instructions: - text: Create GCP credential {credentialName} with service account key {credentialKey}. slots: credentialName: requestBody.credentialName credentialKey: requestBody.credentialKey - text: Add a Google Cloud credential named {credentialName} using key {credentialKey}. slots: credentialName: requestBody.credentialName credentialKey: requestBody.credentialKey method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/changeEnvironmentCredential'].post update: x-apievangelist-phrasing: intent: Switch the credential an environment uses effect: write questions: - Can I swap which credential an existing environment uses? - How do I move an environment onto a different cloud credential? instructions: - text: Change environment {environmentName} to use credential {credentialName}. slots: environmentName: requestBody.environmentName credentialName: requestBody.credentialName - text: Switch {environmentName} over to credential {credentialName}. slots: environmentName: requestBody.environmentName credentialName: requestBody.credentialName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAzureEncryptionResources'].post update: x-apievangelist-phrasing: intent: Enable customer-managed keys on an Azure environment effect: write questions: - How do I turn on server-side encryption with my own key for an existing Azure environment? - Can I add a user-managed identity for Azure disk encryption later? instructions: - text: Set Azure encryption key {encryptionKeyUrl} on environment {environment}. slots: encryptionKeyUrl: requestBody.encryptionKeyUrl environment: requestBody.environment - text: Enable CMK encryption for Azure environment {environment} with key {encryptionKeyUrl} in resource group {encryptionKeyResourceGroupName}. slots: environment: requestBody.environment encryptionKeyUrl: requestBody.encryptionKeyUrl encryptionKeyResourceGroupName: requestBody.encryptionKeyResourceGroupName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAzureDatabaseResources'].post update: x-apievangelist-phrasing: intent: Enable private Flexible Server on an Azure environment effect: write questions: - How do I deploy a private Azure Flexible Server database for an existing environment? - Can I set the private DNS zone used for the environment's database? instructions: - text: Update Azure environment {environment} to use Flexible Server subnets {flexibleServerSubnetIds}. slots: environment: requestBody.environment flexibleServerSubnetIds: requestBody.flexibleServerSubnetIds - text: Set database private DNS zone {databasePrivateDnsZoneId} on Azure environment {environment}. slots: databasePrivateDnsZoneId: requestBody.databasePrivateDnsZoneId environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAzureAvailabilityZones'].post update: x-apievangelist-phrasing: intent: Change availability zones for an Azure environment effect: write questions: - Can I change which availability zones my Azure environment spreads across? - How do I add zones to an existing Azure environment? instructions: - text: Set availability zones {availabilityZones} on Azure environment {environment}. slots: availabilityZones: requestBody.availabilityZones environment: requestBody.environment - text: Update the Azure zones for {environment} to {availabilityZones}. slots: environment: requestBody.environment availabilityZones: requestBody.availabilityZones method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAwsDiskEncryptionParameters'].post update: x-apievangelist-phrasing: intent: Set the AWS encryption key for an environment effect: write questions: - How do I enable KMS customer-managed key encryption on an existing AWS environment? - Will a new encryption key ARN apply to resources already created? instructions: - text: Set encryption key ARN {encryptionKeyArn} on AWS environment {environment}. slots: encryptionKeyArn: requestBody.encryptionKeyArn environment: requestBody.environment - text: Turn on CMK disk encryption for {environment} with key {encryptionKeyArn}. slots: environment: requestBody.environment encryptionKeyArn: requestBody.encryptionKeyArn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/deleteEnvironment'].post update: x-apievangelist-phrasing: intent: Delete an environment effect: destructive questions: - How do I delete a CDP environment I no longer need? - Can deleting an environment also cascade to its attached clusters? instructions: - text: Delete environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Delete environment {environmentName} and everything attached to it. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/deleteCredential'].post update: x-apievangelist-phrasing: intent: Delete a credential effect: destructive questions: - How do I remove an environment credential I no longer use? - Is deleting a credential permanent? instructions: - text: Delete credential {credentialName}. slots: credentialName: requestBody.credentialName - text: Remove the environment credential called {credentialName}. slots: credentialName: requestBody.credentialName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listEnvironments'].post update: x-apievangelist-phrasing: intent: List environments effect: read questions: - Which CDP environments exist in my account? - What environments do I have across all clouds? instructions: - text: List all my environments. - text: Show every environment in the account. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listCredentials'].post update: x-apievangelist-phrasing: intent: List environment credentials effect: read questions: - Which cloud credentials are registered for my environments? - Can I look up one credential by name? instructions: - text: List my environment credentials. - text: Find the credential named {credentialName}. slots: credentialName: requestBody.credentialName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/describeEnvironment'].post update: x-apievangelist-phrasing: intent: Describe an environment effect: read questions: - What's the status and configuration of a specific environment? - Can I see the network and region details of one environment? instructions: - text: Describe environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Show me the full details of {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/syncAllUsers'].post update: x-apievangelist-phrasing: intent: Sync all users and groups to environments effect: write questions: - How do I push all user and group changes out to my environments? - Can I limit a full user sync to certain environments? instructions: - text: Sync all users and groups to every environment. - text: Run a full user and group sync on environments {environmentNames}. slots: environmentNames: requestBody.environmentNames method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/syncUser'].post update: x-apievangelist-phrasing: intent: Sync the current user to FreeIPA effect: write questions: - Can I sync just my own user to the FreeIPA servers without a full sync? - Is there a single-user sync for environments? instructions: - text: Sync my user to the FreeIPA servers in all environments. - text: Push only my user account out to FreeIPA. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/syncStatus'].post update: x-apievangelist-phrasing: intent: Check status of a user sync operation effect: read questions: - Did the user sync I started finish successfully? - How do I check a sync operation by its operation ID? instructions: - text: Get the status of user sync operation {operationId}. slots: operationId: requestBody.operationId - text: Check whether sync {operationId} has completed. slots: operationId: requestBody.operationId method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/lastSyncStatus'].post update: x-apievangelist-phrasing: intent: Get the last user sync status for an environment effect: read questions: - When did user sync last run for this environment, and did it work? - Can I see the most recent sync result by environment CRN? instructions: - text: Show the last user sync status for environment {envNameOrCrn}. slots: envNameOrCrn: requestBody.envNameOrCrn - text: Get the most recent sync outcome for {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listConnectedDataServices'].post update: x-apievangelist-phrasing: intent: List data services attached to an environment effect: read questions: - Which data services and clusters are running in my environment? - What would be affected if I deleted this environment? instructions: - text: List the data services attached to {environment}. slots: environment: requestBody.environment - text: Show connected data service clusters in environment {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getEnvironmentUserSyncState'].post update: x-apievangelist-phrasing: intent: Get an environment's user sync state effect: read questions: - Is user synchronization in a healthy state for my environment? - Does this environment need a user sync? instructions: - text: Get the user sync state of {environmentName}. slots: environmentName: requestBody.environmentName - text: Check if {environmentName} is in sync with users and groups. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setPassword'].post update: x-apievangelist-phrasing: intent: Set a workload password (deprecated) effect: write questions: - Is there an older environments call for setting my workload password? - Can I set my workload password for only certain environments? instructions: - text: Set my workload password to {password} using the deprecated environments call. slots: password: requestBody.password - text: Update my workload password to {password} in environments {environmentCRNs}. slots: password: requestBody.password environmentCRNs: requestBody.environmentCRNs method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getRootCertificate'].post update: x-apievangelist-phrasing: intent: Get an environment's root certificate effect: read questions: - Where can I download the root CA certificate for my environment? - Which certificate do clients need to trust to connect over TLS? instructions: - text: Get the root certificate for {environmentName}. slots: environmentName: requestBody.environmentName - text: Download the public root CA cert of environment {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getKeytab'].post update: x-apievangelist-phrasing: intent: Retrieve a Kerberos keytab effect: read questions: - How do I get a keytab for my user in an environment? - Can I retrieve a keytab for a machine user? instructions: - text: Get my keytab for environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Retrieve the keytab for {actorCrn} in {environmentName}. slots: actorCrn: requestBody.actorCrn environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getAutomatedSyncEnvironmentStatus'].post update: x-apievangelist-phrasing: intent: Get automated user sync status effect: read questions: - Is automated user sync turned on and working for my environment? - What does the automatic sync report for this environment? instructions: - text: Get the automated sync status for {environmentName}. slots: environmentName: requestBody.environmentName - text: Check automatic user sync on environment {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getIdBrokerMappings'].post update: x-apievangelist-phrasing: intent: Get ID Broker mappings for an environment effect: read questions: - Which cloud roles are users and groups mapped to through ID Broker? - What data access role does my environment's ID Broker use? instructions: - text: Show the ID Broker mappings for {environmentName}. slots: environmentName: requestBody.environmentName - text: Get all user and group role mappings in ID Broker for {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setIdBrokerMappings'].post update: x-apievangelist-phrasing: intent: Set ID Broker mappings for an environment effect: write questions: - How do I map users and groups to cloud roles in ID Broker? - Will setting ID Broker mappings overwrite the ones already there? instructions: - text: Set ID Broker mappings on {environmentName} with data access role {dataAccessRole}. slots: environmentName: requestBody.environmentName dataAccessRole: requestBody.dataAccessRole - text: Replace the ID Broker mappings for {environmentName} with {mappings}, using data access role {dataAccessRole}. slots: environmentName: requestBody.environmentName mappings: requestBody.mappings dataAccessRole: requestBody.dataAccessRole method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/syncIdBrokerMappings'].post update: x-apievangelist-phrasing: intent: Push ID Broker mappings to data lakes effect: write questions: - How do I apply my ID Broker mapping changes to the data lake clusters? - Do ID Broker mappings need syncing after I change them? instructions: - text: Sync ID Broker mappings to the data lakes in {environmentName}. slots: environmentName: requestBody.environmentName - text: Push the current ID Broker mappings out for environment {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getIdBrokerMappingsSyncStatus'].post update: x-apievangelist-phrasing: intent: Check ID Broker mappings sync status effect: read questions: - Did my last ID Broker mappings sync succeed? - Are the ID Broker mappings still syncing to the data lake? instructions: - text: Get the ID Broker mappings sync status for {environmentName}. slots: environmentName: requestBody.environmentName - text: Check the most recent ID Broker sync result in {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/startEnvironment'].post update: x-apievangelist-phrasing: intent: Start an environment effect: write questions: - How do I start a stopped environment? - Can I start the Data Hub clusters along with the environment? instructions: - text: Start environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Start {environmentName} and its Data Hub clusters too. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/stopEnvironment'].post update: x-apievangelist-phrasing: intent: Stop an environment effect: write questions: - Can I stop an environment to save cloud costs? - What's the way to pause a whole CDP environment? instructions: - text: Stop environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Pause {environmentName} until I need it again. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getOperation'].post update: x-apievangelist-phrasing: intent: Get the latest operation on an environment effect: read questions: - What operation is currently running on my environment? - Did the last environment operation finish or fail? instructions: - text: Get the latest operation for environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Show progress of operation {operationId} on {environmentName}. slots: operationId: requestBody.operationId environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/checkEnvironmentConnectivity'].post update: x-apievangelist-phrasing: intent: Test connectivity to Cloudera Manager effect: read questions: - Can CDP reach my Cloudera Manager before I create a Private Cloud environment? - How do I test Cloudera Manager credentials ahead of registering an environment? instructions: - text: Check connectivity to Cloudera Manager at {address} as {user} with token {authenticationToken}. slots: address: requestBody.address user: requestBody.user authenticationToken: requestBody.authenticationToken - text: Test whether Cloudera Manager {address} accepts login {user} using token {authenticationToken}. slots: address: requestBody.address user: requestBody.user authenticationToken: requestBody.authenticationToken method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/checkDatabaseConnectivity'].post update: x-apievangelist-phrasing: intent: Test database connectivity effect: read questions: - Can I verify a database is reachable with given host, port and credentials? - Is there a way to test a database login before using it? instructions: - text: Check connectivity to database {name} at {host}:{port} as {username} with password {password}. slots: name: requestBody.name host: requestBody.host port: requestBody.port username: requestBody.username password: requestBody.password - text: Test login to {name} on host {host} port {port} using {username} / {password}. slots: name: requestBody.name host: requestBody.host port: requestBody.port username: requestBody.username password: requestBody.password method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/checkKubernetesConnectivity'].post update: x-apievangelist-phrasing: intent: Test Kubernetes connectivity with a kubeconfig effect: read questions: - Will my kubeconfig let CDP reach the Kubernetes cluster? - How can I validate a Kubernetes connection before setting up Private Cloud? instructions: - text: Check Kubernetes connectivity using kubeconfig {kubeConfig}. slots: kubeConfig: requestBody.kubeConfig - text: Test that kubeconfig {kubeConfig} in {format} format reaches the cluster. slots: kubeConfig: requestBody.kubeConfig format: requestBody.format method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getFreeipaStatus'].post update: x-apievangelist-phrasing: intent: Get FreeIPA service health effect: read questions: - Are the FreeIPA nodes in my environment healthy? - Which FreeIPA services are down right now? instructions: - text: Get the FreeIPA status for {environmentName}. slots: environmentName: requestBody.environmentName - text: Check FreeIPA node services and connectivity in {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/attachFreeIpaRecipes'].post update: x-apievangelist-phrasing: intent: Attach recipes to FreeIPA effect: write questions: - How do I run custom scripts on my FreeIPA nodes? - Can I add recipes to FreeIPA after the environment exists? instructions: - text: Attach recipes {recipes} to FreeIPA in {environment}. slots: recipes: requestBody.recipes environment: requestBody.environment - text: Add FreeIPA recipes {recipes} to environment {environment}. slots: recipes: requestBody.recipes environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/detachFreeIpaRecipes'].post update: x-apievangelist-phrasing: intent: Detach recipes from FreeIPA effect: write questions: - How do I stop a recipe from running on FreeIPA? - Can I detach several FreeIPA recipes at once? instructions: - text: Detach recipes {recipes} from FreeIPA in {environment}. slots: recipes: requestBody.recipes environment: requestBody.environment - text: Remove FreeIPA recipes {recipes} from environment {environment}. slots: recipes: requestBody.recipes environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/repairFreeipa'].post update: x-apievangelist-phrasing: intent: Repair broken FreeIPA nodes effect: write questions: - My FreeIPA nodes are not working; how do I repair them? - Can I repair only specific FreeIPA instances? instructions: - text: Repair FreeIPA in {environmentName}. slots: environmentName: requestBody.environmentName - text: Repair FreeIPA instances {instances} in {environmentName}. slots: instances: requestBody.instances environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getRepairFreeipaStatus'].post update: x-apievangelist-phrasing: intent: Check a FreeIPA repair's status effect: read questions: - Is my FreeIPA repair still running? - Did the FreeIPA repair operation succeed? instructions: - text: Get the status of FreeIPA repair {operationId}. slots: operationId: requestBody.operationId - text: Check FreeIPA repair operation {operationId}. slots: operationId: requestBody.operationId method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/createProxyConfig'].post update: x-apievangelist-phrasing: intent: Create a proxy configuration effect: write questions: - How do I route environment traffic through an outbound proxy? - Can a proxy config include hosts that bypass the proxy? instructions: - text: Create proxy config {proxyConfigName} for {protocol}://{host}:{port}. slots: proxyConfigName: requestBody.proxyConfigName protocol: requestBody.protocol host: requestBody.host port: requestBody.port - text: Add proxy {proxyConfigName} at {host} port {port} over {protocol}, skipping {noProxyHosts}. slots: proxyConfigName: requestBody.proxyConfigName host: requestBody.host port: requestBody.port protocol: requestBody.protocol noProxyHosts: requestBody.noProxyHosts method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listProxyConfigs'].post update: x-apievangelist-phrasing: intent: List proxy configurations effect: read questions: - Which proxy configs are defined in my account? - Can I look up a proxy config by name? instructions: - text: List my proxy configs. - text: Find the proxy config named {proxyConfigName}. slots: proxyConfigName: requestBody.proxyConfigName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/deleteProxyConfig'].post update: x-apievangelist-phrasing: intent: Delete a proxy configuration effect: destructive questions: - How do I delete a proxy config I no longer need? - Is removing a proxy config reversible? instructions: - text: Delete proxy config {proxyConfigName}. slots: proxyConfigName: requestBody.proxyConfigName - text: Remove the proxy configuration called {proxyConfigName}. slots: proxyConfigName: requestBody.proxyConfigName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setTelemetryFeatures'].post update: x-apievangelist-phrasing: intent: Configure telemetry for an environment effect: write questions: - Can I turn workload analytics on or off for one environment? - Where is environment-level telemetry configured? instructions: - text: Set telemetry features on environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Set workload analytics to {workloadAnalytics} for environment {environmentName}. slots: workloadAnalytics: requestBody.workloadAnalytics environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getEnvironmentSetting'].post update: x-apievangelist-phrasing: intent: Read an environment configuration setting effect: read questions: - What value is a configuration setting set to in the environment service? - Can I read specific settings attributes for one environment? instructions: - text: Read environment settings {attrs}. slots: attrs: requestBody.attrs - text: Get the setting values {attrs} for environment {environmentName}. slots: attrs: requestBody.attrs environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setEnvironmentSetting'].post update: x-apievangelist-phrasing: intent: Change an environment configuration setting effect: write questions: - Can I change configuration settings in the environment service? - Is it possible to apply a setting to just one environment? instructions: - text: Apply environment settings {settings}. slots: settings: requestBody.settings - text: Write settings {settings} to environment {environmentName}. slots: settings: requestBody.settings environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setAccountTelemetry'].post update: x-apievangelist-phrasing: intent: Set account-wide telemetry and anonymization effect: write questions: - How do I configure telemetry for the whole account rather than one environment? - Can I add anonymization rules to account telemetry? instructions: - text: Set account telemetry anonymization rules to {rules}. slots: rules: requestBody.rules - text: Set account-level workload analytics to {workloadAnalytics}. slots: workloadAnalytics: requestBody.workloadAnalytics method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getAccountTelemetry'].post update: x-apievangelist-phrasing: intent: Get account telemetry settings effect: read questions: - What telemetry features and anonymization rules are set on my account? - Is workload analytics enabled account-wide right now? instructions: - text: Show my account's current telemetry settings. - text: Get the account anonymization rules in effect. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getAccountTelemetryDefault'].post update: x-apievangelist-phrasing: intent: Get default account telemetry settings effect: read questions: - What are the default account telemetry values if I want to reset them? - Which anonymization rules ship by default? instructions: - text: Get the default account telemetry settings. - text: Show the factory default telemetry configuration so I can restore it. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/testAccountTelemetryRules'].post update: x-apievangelist-phrasing: intent: Test anonymization rules against sample text effect: read questions: - Will my telemetry anonymization rules actually mask this text? - Can I dry-run anonymization rules before saving them? instructions: - text: Test anonymization rules {rules} against {testInput}. slots: rules: requestBody.rules testInput: requestBody.testInput - text: Show what {testInput} looks like after applying rules {rules}. slots: testInput: requestBody.testInput rules: requestBody.rules method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getFreeipaLogDescriptors'].post update: x-apievangelist-phrasing: intent: List FreeIPA log descriptors for diagnostics effect: read questions: - Which logs can be included in a FreeIPA diagnostics collection? - What log descriptors does FreeIPA diagnostics use? instructions: - text: List the FreeIPA log descriptors. - text: Show which logs FreeIPA diagnostics can gather. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/collectFreeipaDiagnostics'].post update: x-apievangelist-phrasing: intent: Start a FreeIPA diagnostics collection effect: write questions: - How do I gather FreeIPA logs for a support case? - Can FreeIPA diagnostics be limited to a date range or specific hosts? instructions: - text: Collect FreeIPA diagnostics in {environmentName} to {destination} described as {description}. slots: environmentName: requestBody.environmentName destination: requestBody.destination description: requestBody.description - text: Start FreeIPA log collection for {environmentName} to {destination}, note {description}, case {caseNumber}. slots: environmentName: requestBody.environmentName destination: requestBody.destination description: requestBody.description caseNumber: requestBody.caseNumber method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listFreeipaDiagnostics'].post update: x-apievangelist-phrasing: intent: List recent FreeIPA diagnostics collections effect: read questions: - Which FreeIPA diagnostics collections have run recently? - Is a FreeIPA log collection still in progress? instructions: - text: List recent FreeIPA diagnostics in {environmentName}. slots: environmentName: requestBody.environmentName - text: Show past FreeIPA log collections for {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/cancelFreeipaDiagnostics'].post update: x-apievangelist-phrasing: intent: Cancel a running FreeIPA diagnostics collection effect: destructive questions: - How do I stop a FreeIPA diagnostics collection that's taking too long? - Can a running FreeIPA log collection be cancelled? instructions: - text: Cancel FreeIPA diagnostics running in {environmentName}. slots: environmentName: requestBody.environmentName - text: Abort the in-progress FreeIPA log collection on {environmentName}. slots: environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getAuditCredentialPrerequisites'].post update: x-apievangelist-phrasing: intent: Get audit credential prerequisites effect: read questions: - What does my cloud account need before I set an audit credential? - Which policies are required for a commercial-cloud audit credential? instructions: - text: Get audit credential prerequisites for {cloudPlatform}. slots: cloudPlatform: requestBody.cloudPlatform - text: Show what an audit credential on {cloudPlatform} requires. slots: cloudPlatform: requestBody.cloudPlatform method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getGovCloudAuditCredentialPrerequisites'].post update: x-apievangelist-phrasing: intent: Get GovCloud audit credential prerequisites effect: read questions: - What prerequisites apply to an audit credential in GovCloud? - Which GovCloud policies does the audit credential need? instructions: - text: Get GovCloud audit credential prerequisites for {cloudPlatform}. slots: cloudPlatform: requestBody.cloudPlatform - text: Show the GovCloud audit credential setup needed on {cloudPlatform}. slots: cloudPlatform: requestBody.cloudPlatform method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listAuditCredentials'].post update: x-apievangelist-phrasing: intent: List audit credentials effect: read questions: - Which audit credentials are configured for my account? - Do I already have an audit credential set up? instructions: - text: List my audit credentials. - text: Show the account's audit credentials. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setAWSAuditCredential'].post update: x-apievangelist-phrasing: intent: Create or update the AWS audit credential effect: write questions: - How do I set up the AWS audit credential for my account? - Can I change the role ARN of the existing AWS audit credential? instructions: - text: Set the AWS audit credential to role {roleArn}. slots: roleArn: requestBody.roleArn - text: Create or update my commercial AWS audit credential with role ARN {roleArn}. slots: roleArn: requestBody.roleArn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setAWSGovCloudAuditCredential'].post update: x-apievangelist-phrasing: intent: Create or update the GovCloud audit credential effect: write questions: - Can I configure an audit credential for AWS GovCloud? - What role does the GovCloud audit credential use? instructions: - text: Point the GovCloud audit credential for this account at IAM role {roleArn}. slots: roleArn: requestBody.roleArn - text: Create or update my GovCloud audit credential with role ARN {roleArn}. slots: roleArn: requestBody.roleArn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setAzureAuditCredential'].post update: x-apievangelist-phrasing: intent: Create or update the Azure audit credential effect: write questions: - How do I set the Azure audit credential for my account? - Which subscription and tenant does the Azure audit credential use? instructions: - text: Set the Azure audit credential for subscription {subscriptionId}, tenant {tenantId}, app {appBased}. slots: subscriptionId: requestBody.subscriptionId tenantId: requestBody.tenantId appBased: requestBody.appBased - text: Create or update the account's Azure audit credential with tenant {tenantId}, subscription {subscriptionId} and app {appBased}. slots: tenantId: requestBody.tenantId subscriptionId: requestBody.subscriptionId appBased: requestBody.appBased method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setGCPAuditCredential'].post update: x-apievangelist-phrasing: intent: Create or update the GCP audit credential effect: write questions: - Can I set an audit credential for Google Cloud? - What key does the GCP audit credential need? instructions: - text: Set the GCP audit credential with key {credentialKey}. slots: credentialKey: requestBody.credentialKey - text: Create or update my Google Cloud audit credential using {credentialKey}. slots: credentialKey: requestBody.credentialKey method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/deleteAuditCredential'].post update: x-apievangelist-phrasing: intent: Delete an audit credential effect: destructive questions: - How do I remove an audit credential from my account? - Is deleting an audit credential permanent? instructions: - text: Delete audit credential {credentialName}. slots: credentialName: requestBody.credentialName - text: Remove the audit credential named {credentialName}. slots: credentialName: requestBody.credentialName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setEndpointAccessGateway'].post update: x-apievangelist-phrasing: intent: Configure the endpoint access gateway effect: write questions: - Can I make my environment's endpoint access gateway public or private? - Which subnets does the endpoint access gateway use? instructions: - text: Set the endpoint access gateway on {environment} to scheme {endpointAccessGatewayScheme}. slots: environment: requestBody.environment endpointAccessGatewayScheme: requestBody.endpointAccessGatewayScheme - text: Configure {environment}'s endpoint gateway as {endpointAccessGatewayScheme} on subnets {endpointAccessGatewaySubnetIds}. slots: environment: requestBody.environment endpointAccessGatewayScheme: requestBody.endpointAccessGatewayScheme endpointAccessGatewaySubnetIds: requestBody.endpointAccessGatewaySubnetIds method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateSshKey'].post update: x-apievangelist-phrasing: intent: Change an environment's SSH key effect: write questions: - How do I rotate the SSH key used for new Data Hub clusters? - Will an updated SSH key apply to clusters that already exist? instructions: - text: Update the SSH key on {environment} to {newPublicKey}. slots: environment: requestBody.environment newPublicKey: requestBody.newPublicKey - text: Switch {environment} to existing public key {existingPublicKeyId}. slots: environment: requestBody.environment existingPublicKeyId: requestBody.existingPublicKeyId method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateSubnet'].post update: x-apievangelist-phrasing: intent: Change an environment's subnets effect: write questions: - Can I add subnets to an existing environment for new Data Hub clusters? - Do updated subnets affect the clusters already running? instructions: - text: Update the subnets of {environment} to {subnetIds}. slots: environment: requestBody.environment subnetIds: requestBody.subnetIds - text: Set endpoint gateway subnets {endpointAccessGatewaySubnetIds} on environment {environment}. slots: endpointAccessGatewaySubnetIds: requestBody.endpointAccessGatewaySubnetIds environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateSecurityAccess'].post update: x-apievangelist-phrasing: intent: Change an environment's security groups effect: write questions: - How do I swap the security groups used by an environment? - Which security groups apply to gateway nodes versus the default? instructions: - text: 'Update {environment} security groups: gateway {gatewayNodeSecurityGroupId}, default {defaultSecurityGroupId}.' slots: environment: requestBody.environment gatewayNodeSecurityGroupId: requestBody.gatewayNodeSecurityGroupId defaultSecurityGroupId: requestBody.defaultSecurityGroupId - text: Set gateway node group {gatewayNodeSecurityGroupId} and default group {defaultSecurityGroupId} on environment {environment}. slots: gatewayNodeSecurityGroupId: requestBody.gatewayNodeSecurityGroupId defaultSecurityGroupId: requestBody.defaultSecurityGroupId environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateTags'].post update: x-apievangelist-phrasing: intent: Update an environment's user-defined tags effect: write questions: - Can I change the cloud resource tags on an existing environment? - Do new environment tags apply to clusters created before the change? instructions: - text: Update the tags on {environment} to {tags}. slots: environment: requestBody.environment tags: requestBody.tags - text: Apply user-defined tags {tags} to environment {environment}. slots: tags: requestBody.tags environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/validateAwsCloudStorage'].post update: x-apievangelist-phrasing: intent: Validate AWS cloud storage settings effect: read questions: - Will my S3 storage location and instance profile work for this environment? - How can I check AWS storage permissions before deploying? instructions: - text: Validate AWS storage {storageLocation} with instance profile {instanceProfile} and credential {credentialCrn}. slots: storageLocation: requestBody.storageLocation instanceProfile: requestBody.instanceProfile credentialCrn: requestBody.credentialCrn - text: Check S3 location {storageLocation} using credential {credentialCrn} and profile {instanceProfile}. slots: storageLocation: requestBody.storageLocation credentialCrn: requestBody.credentialCrn instanceProfile: requestBody.instanceProfile method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/validateAzureCloudStorage'].post update: x-apievangelist-phrasing: intent: Validate Azure cloud storage settings effect: read questions: - Is my Azure storage location configured correctly for the environment? - Can I validate Azure storage with a managed identity? instructions: - text: Validate Azure storage {storageLocation} with credential {credentialCrn}. slots: storageLocation: requestBody.storageLocation credentialCrn: requestBody.credentialCrn - text: Check Azure location {storageLocation} using managed identity {managedIdentity} and credential {credentialCrn}. slots: storageLocation: requestBody.storageLocation managedIdentity: requestBody.managedIdentity credentialCrn: requestBody.credentialCrn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setCatalog'].post update: x-apievangelist-phrasing: intent: Set the image catalog for FreeIPA effect: write questions: - Can I point FreeIPA at a custom image catalog? - Which image catalog does my FreeIPA installation use? instructions: - text: Set FreeIPA image catalog {catalog} on {environment}. slots: catalog: requestBody.catalog environment: requestBody.environment - text: Use catalog {catalog} for the FreeIPA in environment {environment}. slots: catalog: requestBody.catalog environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/upgradeFreeipa'].post update: x-apievangelist-phrasing: intent: Upgrade FreeIPA to a newer image effect: write questions: - How do I upgrade FreeIPA to the latest image? - Can a FreeIPA upgrade include a major OS upgrade? instructions: - text: Upgrade FreeIPA in {environmentName} to the latest image. slots: environmentName: requestBody.environmentName - text: Upgrade FreeIPA on {environmentName} to image {imageId}. slots: environmentName: requestBody.environmentName imageId: requestBody.imageId method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getFreeipaUpgradeOptions'].post update: x-apievangelist-phrasing: intent: List available FreeIPA upgrade images effect: read questions: - Which images can my FreeIPA be upgraded to? - Are there FreeIPA upgrade options in a specific catalog? instructions: - text: Show FreeIPA upgrade options for {environment}. slots: environment: requestBody.environment - text: List FreeIPA upgrade images for {environment} from catalog {catalog}. slots: environment: requestBody.environment catalog: requestBody.catalog method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/upscaleFreeipa'].post update: x-apievangelist-phrasing: intent: Scale FreeIPA up to higher availability effect: write questions: - How do I add FreeIPA instances for high availability? - What availability types can FreeIPA be upscaled to? instructions: - text: Upscale FreeIPA in {environmentName} to {targetAvailabilityType}. slots: environmentName: requestBody.environmentName targetAvailabilityType: requestBody.targetAvailabilityType - text: Increase FreeIPA availability on {environmentName} to {targetAvailabilityType}. slots: environmentName: requestBody.environmentName targetAvailabilityType: requestBody.targetAvailabilityType method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/downscaleFreeipa'].post update: x-apievangelist-phrasing: intent: Scale FreeIPA down effect: write questions: - Can I reduce the number of FreeIPA instances to save cost? - Is it possible to remove specific FreeIPA instances when downscaling? instructions: - text: Downscale FreeIPA in {environmentName} to {targetAvailabilityType}. slots: environmentName: requestBody.environmentName targetAvailabilityType: requestBody.targetAvailabilityType - text: Remove FreeIPA instances {instances} from {environmentName}. slots: instances: requestBody.instances environmentName: requestBody.environmentName method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/retryFreeipa'].post update: x-apievangelist-phrasing: intent: Retry the last failed FreeIPA operation effect: write questions: - My last FreeIPA operation failed; can I retry it? - Is there a way to rerun a failed FreeIPA step without starting over? instructions: - text: Retry the last failed FreeIPA operation in {environment}. slots: environment: requestBody.environment - text: Rerun the failed FreeIPA step on {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/startFreeIpaVerticalScaling'].post update: x-apievangelist-phrasing: intent: Vertically scale FreeIPA instances effect: write questions: - Can I move FreeIPA to bigger instance types? - How is FreeIPA vertical scaling started? instructions: - text: Vertically scale FreeIPA in {environment} to instance template {instanceTemplate}. slots: environment: requestBody.environment instanceTemplate: requestBody.instanceTemplate - text: Resize the FreeIPA instances of {environment} using {instanceTemplate}. slots: environment: requestBody.environment instanceTemplate: requestBody.instanceTemplate method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/upgradeCcm'].post update: x-apievangelist-phrasing: intent: Upgrade Cluster Connectivity Manager effect: write questions: - How do I bring Cluster Connectivity Manager up to the latest version? - Is my environment's CCM upgradeable in place? instructions: - text: Upgrade Cluster Connectivity Manager on {environment}. slots: environment: requestBody.environment - text: Move {environment} to the latest CCM version. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/rotateSaltPassword'].post update: x-apievangelist-phrasing: intent: Rotate the FreeIPA SaltStack password (deprecated) effect: write questions: - Is there a legacy call that rotates only the SaltStack password on FreeIPA? - Can I still rotate the FreeIPA Salt user password the old way? instructions: - text: Rotate the SaltStack password on FreeIPA in {environment} using the deprecated call. slots: environment: requestBody.environment - text: Reset only the Salt user password on {environment}'s FreeIPA instances. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/rotateFreeipaSecrets'].post update: x-apievangelist-phrasing: intent: Rotate FreeIPA secrets effect: write questions: - How do I rotate secrets on my FreeIPA instances? - Can I choose which FreeIPA secret types get rotated? instructions: - text: Rotate FreeIPA secrets {secretTypes} in {environment}. slots: secretTypes: requestBody.secretTypes environment: requestBody.environment - text: Rotate secret types {secretTypes} for FreeIPA on environment {environment}. slots: secretTypes: requestBody.secretTypes environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/listFreeipaSecretTypes'].post update: x-apievangelist-phrasing: intent: List FreeIPA secret types effect: read questions: - Which FreeIPA secret types can be rotated? - What secrets does FreeIPA manage in my environment? instructions: - text: List FreeIPA secret types for {environment}. slots: environment: requestBody.environment - text: Show rotatable FreeIPA secrets in {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateOrchestratorState'].post update: x-apievangelist-phrasing: intent: Run an orchestrator state update on FreeIPA effect: write questions: - Can I re-apply the orchestrator engine state on my FreeIPA cluster? - How is a FreeIPA Salt state update triggered? instructions: - text: Run an orchestrator state update on FreeIPA in {environment}. slots: environment: requestBody.environment - text: Reapply orchestrator state to {environment}'s FreeIPA cluster. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateProxyConfig'].post update: x-apievangelist-phrasing: intent: Change or remove an environment's proxy effect: write questions: - Can I attach a different proxy config to an existing environment? - How do I remove the proxy from an environment? instructions: - text: Attach proxy config {proxyConfigName} to environment {environment}. slots: proxyConfigName: requestBody.proxyConfigName environment: requestBody.environment - text: Remove the proxy from environment {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateAzureImageTermsPolicy'].post update: x-apievangelist-phrasing: intent: Set the Azure Marketplace image terms policy effect: write questions: - Can CDP automatically accept Azure Marketplace image terms for me? - How do I opt out of automatic Azure image terms acceptance? instructions: - text: Set automatic Azure Marketplace image terms acceptance to {accepted}. slots: accepted: requestBody.accepted - text: Update the account Azure image terms policy to accepted={accepted}. slots: accepted: requestBody.accepted method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getAzureImageTermsPolicy'].post update: x-apievangelist-phrasing: intent: Get the Azure Marketplace image terms policy effect: read questions: - Is automatic acceptance of Azure Marketplace image terms turned on for my account? - What's my current Azure image terms setting? instructions: - text: Get my Azure Marketplace image terms policy. - text: Show whether Azure image terms are auto-accepted. method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateDataServiceResources'].post update: x-apievangelist-phrasing: intent: Update data service resources of an environment effect: write questions: - Can I change the data service resources configured on an environment? - Where do I update an environment's data services settings? instructions: - text: Update data service resources on {environment} to {dataServices}. slots: environment: requestBody.environment dataServices: requestBody.dataServices - text: Set data services {dataServices} for environment {environment}. slots: dataServices: requestBody.dataServices environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateCustomDockerRegistry'].post update: x-apievangelist-phrasing: intent: Set an environment's custom Docker registry effect: write questions: - Can my environment pull images from a custom Docker registry? - How do I change the Docker registry CRN on an environment? instructions: - text: Set custom Docker registry {customDockerRegistry} on {environment}. slots: customDockerRegistry: requestBody.customDockerRegistry environment: requestBody.environment - text: Point environment {environment} at registry {customDockerRegistry}. slots: environment: requestBody.environment customDockerRegistry: requestBody.customDockerRegistry method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateFreeipaToAwsImdsV2'].post update: x-apievangelist-phrasing: intent: Switch FreeIPA on AWS to IMDSv2 effect: write questions: - How do I enforce IMDSv2 on my FreeIPA AWS instances? - Can FreeIPA be moved to the more secure instance metadata service? instructions: - text: Update FreeIPA in {environmentCrn} to use IMDSv2. slots: environmentCrn: requestBody.environmentCrn - text: Enforce IMDSv2 on the FreeIPA cluster of {environmentCrn}. slots: environmentCrn: requestBody.environmentCrn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/updateFreeipaToAwsImdsV1'].post update: x-apievangelist-phrasing: intent: Revert FreeIPA on AWS to IMDSv1 effect: write questions: - Can I roll FreeIPA back to IMDSv1 on AWS? - Is downgrading FreeIPA's instance metadata to version 1 supported? instructions: - text: Update FreeIPA in {environmentCrn} to use IMDSv1. slots: environmentCrn: requestBody.environmentCrn - text: Revert the FreeIPA cluster of {environmentCrn} to IMDSv1. slots: environmentCrn: requestBody.environmentCrn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/initializeAWSComputeCluster'].post update: x-apievangelist-phrasing: intent: Initialize a compute cluster for an AWS environment effect: write questions: - How do I set up the compute cluster for an existing AWS environment? - Can I pass compute cluster settings when initializing on AWS? instructions: - text: Initialize the compute cluster for AWS environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Set up an AWS compute cluster in {environmentName} with configuration {computeClusterConfiguration}. slots: environmentName: requestBody.environmentName computeClusterConfiguration: requestBody.computeClusterConfiguration method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/initializeAzureComputeCluster'].post update: x-apievangelist-phrasing: intent: Initialize a compute cluster for an Azure environment effect: write questions: - What's the way to initialize a compute cluster on an Azure environment? - Can I configure the Azure compute cluster as it's initialized? instructions: - text: Initialize the compute cluster for Azure environment {environmentName}. slots: environmentName: requestBody.environmentName - text: Set up an Azure compute cluster in {environmentName} with configuration {computeClusterConfiguration}. slots: environmentName: requestBody.environmentName computeClusterConfiguration: requestBody.computeClusterConfiguration method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/setupActiveDirectoryTrust'].post update: x-apievangelist-phrasing: intent: Start FreeIPA to Active Directory trust setup effect: write questions: - How do I set up cross-realm trust between FreeIPA and Active Directory? - Which KDC servers and realm are needed to begin an AD trust? instructions: - text: Set up AD trust for {environment} with KDC servers {kdcServers}, realm {kdcRealm}, remote environment {remoteEnvironmentCrn}. slots: environment: requestBody.environment kdcServers: requestBody.kdcServers kdcRealm: requestBody.kdcRealm remoteEnvironmentCrn: requestBody.remoteEnvironmentCrn - text: Begin cross-realm trust from {environment} to realm {kdcRealm} via {kdcServers} using DNS {dnsServerIps}, remote env {remoteEnvironmentCrn}. slots: environment: requestBody.environment kdcRealm: requestBody.kdcRealm kdcServers: requestBody.kdcServers dnsServerIps: requestBody.dnsServerIps remoteEnvironmentCrn: requestBody.remoteEnvironmentCrn method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/finishSetupTrust'].post update: x-apievangelist-phrasing: intent: Complete cross-realm trust setup effect: write questions: - I've configured the Active Directory side; how do I finish the trust? - Does finishing the trust setup test both directions? instructions: - text: Finish the cross-realm trust setup for {environment}. slots: environment: requestBody.environment - text: Complete and validate the AD trust on {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/cancelTrust'].post update: x-apievangelist-phrasing: intent: Cancel cross-realm trust setup effect: destructive questions: - Can I abandon a FreeIPA to Active Directory trust setup? - What's the way to back out of a cross-realm trust? instructions: - text: Cancel the cross-realm trust for {environment}. slots: environment: requestBody.environment - text: Abort the Active Directory trust setup on {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/repairTrust'].post update: x-apievangelist-phrasing: intent: Repair cross-realm trust with Active Directory effect: write questions: - My FreeIPA trust with Active Directory is broken; can it be repaired? - Does repairing the trust reset the trust secret? instructions: - text: Repair the Active Directory trust for {environment}. slots: environment: requestBody.environment - text: Reset the FreeIPA trust secret for {environment}. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getTrustSetupCommands'].post update: x-apievangelist-phrasing: intent: Get commands to set up cross-realm trust effect: read questions: - Which commands do I run on the Active Directory side to set up trust? - What steps remain for the AD trust after I start it? instructions: - text: List the trust setup commands for {environment}. slots: environment: requestBody.environment - text: Show the AD-side setup commands for {environment}'s trust. slots: environment: requestBody.environment method: generated generated: '2026-10-01' - target: $.paths['/api/v1/environments2/getTrustCleanupCommands'].post update: x-apievangelist-phrasing: intent: Get commands to clean up cross-realm trust effect: read questions: - What commands remove the trust configuration from Active Directory? - Which cleanup steps follow cancelling a cross-realm trust? instructions: - text: Get the trust cleanup commands for {environment}. slots: environment: requestBody.environment - text: Show the AD cleanup commands for {environment}'s trust. slots: environment: requestBody.environment method: generated generated: '2026-10-01'