openapi: 3.1.0 info: contact: email: support@cloudquery.io name: CloudQuery Support Team url: https://cloudquery.io description: 'Welcome to the CloudQuery Platform API documentation! This API can be used to interact with the CloudQuery platform. As a user, the API allows you to search the CloudQuery asset inventory, run SQL queries against the data warehouse, save and load searches, and much more. As an administrator, it allows you to manage your teams, syncs, and other objects. ### Authentication The API is secured using bearer tokens. To get started, you can generate an API key for your Platform deployment from your platform dashboard. For a step-by-step guide, see: https://www.cloudquery.io/docs/cli/managing-cloudquery/deployments/generate-api-key. The base URL for the API depends on where your CloudQuery Platform is hosted. If running locally, this is usually http://localhost:3000/api. In a production deployment it should be an HTTPS URL. For purposes of illustration, we will assume the platform instance is available at https://cloudquery.mycompany.com. In this case, the base API endpoint will be https://cloudquery.mycompany.com/api. ### Example Request To test your connection to the API, we can use the `/plugins` endpoint. For example: `curl -v -H "Authorization: Bearer $CLOUDQUERY_API_KEY" \ https://cloudquery.mycompany.com/api/plugins` ' license: name: MIT url: https://spdx.org/licenses/MIT termsOfService: https://www.cloudquery.io/terms title: CloudQuery Platform OpenAPI Spec admin rbac API version: 1.0.0 security: - bearerAuth: [] - cookieAuth: [] tags: - name: rbac paths: /rbac/permissions: get: description: List all permissions operationId: PlatformListAllRBACPermissions parameters: - $ref: '#/components/parameters/platform_per_page' - $ref: '#/components/parameters/platform_page' - $ref: '#/components/parameters/platform_rbac_permissions_sort_bys' - $ref: '#/components/parameters/platform_rbac_permissions_sort_dirs' - name: search_term in: query schema: type: string description: Filter permissions by name or description. responses: '200': description: Response content: application/json: schema: required: - items - metadata properties: items: items: $ref: '#/components/schemas/PlatformRBACPermission' type: array metadata: $ref: '#/components/schemas/PlatformListMetadata' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac post: description: Create a permission operationId: PlatformCreateRBACPermission requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PlatformRBACPermissionCreate' responses: '201': description: Success content: application/json: schema: $ref: '#/components/schemas/PlatformRBACPermission' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac /rbac/permissions/{permission_id}: get: description: Get a permission operationId: PlatformGetRBACPermission parameters: - $ref: '#/components/parameters/platform_rbac_permission_id' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/PlatformRBACPermission' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac patch: description: Update a permission operationId: PlatformUpdateRBACPermission parameters: - $ref: '#/components/parameters/platform_rbac_permission_id' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PlatformRBACPermissionUpdate' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/PlatformRBACPermission' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac delete: description: Delete a permission operationId: PlatformDeleteRBACPermission parameters: - $ref: '#/components/parameters/platform_rbac_permission_id' responses: '204': description: Success '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac /rbac/roles: get: description: List all roles operationId: PlatformListAllRBACRoles parameters: - $ref: '#/components/parameters/platform_per_page' - $ref: '#/components/parameters/platform_page' - $ref: '#/components/parameters/platform_rbac_roles_sort_bys' - $ref: '#/components/parameters/platform_rbac_roles_sort_dirs' - name: search_term in: query schema: type: string description: Filter roles by name or description. - name: type in: query schema: type: string description: Filter roles by type. responses: '200': description: Response content: application/json: schema: required: - items - metadata properties: items: items: $ref: '#/components/schemas/PlatformRole' type: array metadata: $ref: '#/components/schemas/PlatformListMetadata' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac post: description: Create a role operationId: PlatformCreateRBACRole requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PlatformRBACRoleCreate' responses: '201': description: Success content: application/json: schema: $ref: '#/components/schemas/PlatformRole' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac /rbac/roles/{role_id}: get: description: Get a role operationId: PlatformGetRBACRole parameters: - $ref: '#/components/parameters/platform_rbac_role_id' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/PlatformRole' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac patch: description: Update a role (custom roles only) operationId: PlatformUpdateRBACRole parameters: - $ref: '#/components/parameters/platform_rbac_role_id' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PlatformRBACRoleUpdate' responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/PlatformRole' '400': $ref: '#/components/responses/PlatformBadRequest' '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac delete: description: Delete a role operationId: PlatformDeleteRBACRole parameters: - $ref: '#/components/parameters/platform_rbac_role_id' responses: '204': description: Success '401': $ref: '#/components/responses/PlatformRequiresAuthentication' '403': $ref: '#/components/responses/PlatformForbidden' '404': $ref: '#/components/responses/PlatformNotFound' '422': $ref: '#/components/responses/PlatformUnprocessableEntity' '500': $ref: '#/components/responses/PlatformInternalError' tags: - rbac components: schemas: PlatformListMetadata: required: - page_size properties: total_count: type: integer last_page: type: integer page_size: type: integer time_ms: type: integer PlatformFieldError: allOf: - $ref: '#/components/schemas/PlatformBasicError' - properties: errors: items: type: string type: array field_errors: additionalProperties: type: string type: object type: object PlatformRoleID: description: The unique ID for the role. type: string format: uuid x-go-name: RoleID PlatformRole: type: object description: Role required: - id - name - description - permissions - created_by - created_at - updated_at - type properties: id: description: The unique ID for the role. type: string format: uuid x-go-name: ID name: type: string description: type: string permissions: type: array items: $ref: '#/components/schemas/PlatformRBACPermission' created_by: $ref: '#/components/schemas/PlatformCreatedBy' created_at: example: '2017-07-14T16:53:42Z' format: date-time type: string updated_at: example: '2017-07-14T16:53:42Z' format: date-time type: string type: $ref: '#/components/schemas/PlatformRoleType' PlatformRBACPermissionID: description: The unique ID for the data permission. type: string format: uuid x-go-name: RBACPermissionID PlatformRBACRoleSortDirection: title: RBACRoleSortDirection type: string enum: - asc - desc default: asc PlatformRBACPermissionSortDirection: title: RBACPermissionSortDirection type: string enum: - asc - desc default: asc PlatformUserName: description: The unique name for the user. minLength: 1 maxLength: 255 pattern: ^[a-zA-Z\p{L}][a-zA-Z\p{L} \-']*$ x-pattern-message: can contain only letters, spaces, hyphens, and apostrophes, starting with a letter type: string example: Sarah O'Connor PlatformRBACPermission: type: object required: - id - name - description - query - created_by - created_at - updated_at - number_of_affected_roles - number_of_affected_users properties: id: $ref: '#/components/schemas/PlatformRBACPermissionID' name: type: string description: type: string query: type: string created_by: $ref: '#/components/schemas/PlatformCreatedBy' created_at: example: '2017-07-14T16:53:42Z' format: date-time type: string updated_at: example: '2017-07-14T16:53:42Z' format: date-time type: string number_of_affected_roles: type: integer number_of_affected_users: type: integer PlatformRBACPermissionUpdate: type: object properties: name: type: string description: type: string query: type: string PlatformRoleType: type: string enum: - admin:write - admin:read - general:read - general:write - ci - schema-only - custom x-enum-varnames: - AdminWrite - AdminRead - GeneralRead - GeneralWrite - CI - SchemaOnly - Custom PlatformUserID: description: ID of the User type: string format: uuid example: 12345678-1234-1234-1234-1234567890ab x-go-name: UserID PlatformRBACPermissionCreate: type: object required: - name - description - query properties: name: type: string description: type: string query: type: string dry_run: type: boolean default: false PlatformRBACRoleCreate: type: object required: - name - permissions properties: name: type: string description: type: string permissions: type: array items: $ref: '#/components/schemas/PlatformRBACPermissionID' PlatformRBACPermissionSortBy: title: RBACPermissionSortBy type: string enum: - id - name - description - created_by - created_at - updated_at PlatformRBACRoleUpdate: type: object properties: name: type: string description: type: string permissions: type: array items: $ref: '#/components/schemas/PlatformRBACPermissionID' PlatformBasicError: additionalProperties: false description: Basic Error required: - message - status properties: message: type: string status: type: integer title: Basic Error type: object PlatformRBACRoleSortBy: title: RBACRoleSortBy type: string enum: - id - name - description - created_by - created_at - updated_at PlatformCreatedBy: type: object required: - id - name - email properties: id: $ref: '#/components/schemas/PlatformUserID' name: $ref: '#/components/schemas/PlatformUserName' email: type: string responses: PlatformBadRequest: content: application/json: schema: $ref: '#/components/schemas/PlatformFieldError' description: Bad request PlatformInternalError: content: application/json: schema: $ref: '#/components/schemas/PlatformBasicError' description: Internal Error PlatformNotFound: content: application/json: schema: $ref: '#/components/schemas/PlatformBasicError' description: Resource not found PlatformForbidden: content: application/json: schema: $ref: '#/components/schemas/PlatformFieldError' description: Forbidden PlatformUnprocessableEntity: content: application/json: schema: $ref: '#/components/schemas/PlatformFieldError' description: UnprocessableEntity PlatformRequiresAuthentication: content: application/json: schema: $ref: '#/components/schemas/PlatformBasicError' description: Requires authentication parameters: platform_rbac_role_id: in: path name: role_id required: true schema: $ref: '#/components/schemas/PlatformRoleID' x-go-name: RoleID platform_rbac_roles_sort_dirs: name: sort_dir in: query description: Sort direction options allowEmptyValue: true explode: true schema: type: array items: $ref: '#/components/schemas/PlatformRBACRoleSortDirection' x-go-type-skip-optional-pointer: true x-go-name: RBACRoleSortDirections platform_page: description: Page number of the results to fetch in: query name: page required: false schema: default: 1 minimum: 1 type: integer format: int64 platform_rbac_permissions_sort_dirs: name: sort_dir in: query description: Sort direction options allowEmptyValue: true explode: true schema: type: array items: $ref: '#/components/schemas/PlatformRBACPermissionSortDirection' x-go-type-skip-optional-pointer: true x-go-name: RBACPermissionSortDirections platform_per_page: description: The number of results per page (max 1000). in: query name: per_page required: false schema: default: 100 maximum: 1000 minimum: 1 type: integer format: int64 platform_rbac_permission_id: in: path name: permission_id required: true schema: $ref: '#/components/schemas/PlatformRBACPermissionID' x-go-name: RBACPermissionID platform_rbac_roles_sort_bys: name: sort_by in: query description: Sort by options allowEmptyValue: true explode: true schema: type: array items: $ref: '#/components/schemas/PlatformRBACRoleSortBy' x-go-type-skip-optional-pointer: true x-go-name: RBACRoleSortBys platform_rbac_permissions_sort_bys: name: sort_by in: query description: Sort by options allowEmptyValue: true explode: true schema: type: array items: $ref: '#/components/schemas/PlatformRBACPermissionSortBy' x-go-type-skip-optional-pointer: true x-go-name: RBACPermissionSortBys securitySchemes: bearerAuth: scheme: bearer type: http basicAuth: scheme: basic type: http cookieAuth: scheme: cookie type: http