openapi: 3.2.0 info: title: Eu Sovereign Cloud Role API version: v1 description: 'Operations tagged Role across 2 of this provider''s published API definitions: foundation.authorization.v1.yaml, eu-sovereign-cloud-api-foundation-authorization-v1-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: https://demo.secapi.cloud/providers/seca.authorization description: Path Schema - url: https://authorization.seca.demo.secapi.cloud description: DNS Schema security: - bearerAuth: [] tags: - name: Role description: Role management paths: /v1/tenants/{tenant}/roles: get: tags: - Role security: - bearerAuth: [] summary: List roles description: Lists roles and provides paginated, filtered access. operationId: listRoles parameters: - $ref: '#/components/parameters/tenantPathParam' - $ref: '#/components/parameters/labelSelector' - $ref: '#/components/parameters/limitParam' - $ref: '#/components/parameters/skipTokenParam' - $ref: '#/components/parameters/acceptHeader' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/RoleIterator' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '500': $ref: '#/components/responses/Error500' servers: - url: https://demo.secapi.cloud/providers/seca.authorization description: Path Schema - url: https://authorization.seca.demo.secapi.cloud description: DNS Schema /v1/tenants/{tenant}/roles/{name}: get: tags: - Role security: - bearerAuth: [] summary: Get role description: 'Get a specific role, useful for polling status updates of resources. A `404` response without proper schema has to be ignored and must be understood as server being unavailable. Only a response with proper schema can be trusted.' operationId: getRole parameters: - $ref: '#/components/parameters/tenantPathParam' - $ref: '#/components/parameters/resourcePathParam' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/Role' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '404': $ref: '#/components/responses/Error404' '500': $ref: '#/components/responses/Error500' put: tags: - Role security: - bearerAuth: [] summary: Create or update role description: 'System roles (seca.admin, seca.region-admin, seca.workspace-admin, seca.workspace-editor, seca.workspace-viewer) cannot be modified. Predefined system roles that cannot be modified: * `seca.admin` - Full system access, can manage everything * `seca.region-admin` - Full system access, can manage everything but authorization * `seca.workspace-admin` - Full access within a workspace * `seca.workspace-editor` - Can edit all resources in a workspace * `seca.workspace-viewer` - Can view all resources in a workspace' operationId: createOrUpdateRole parameters: - $ref: '#/components/parameters/tenantPathParam' - $ref: '#/components/parameters/resourcePathParam' - $ref: '#/components/parameters/ifUnmodifiedSince' requestBody: description: 'Any provided `metadata` on the role will be ignored by the resource server. ' required: true content: application/json: schema: $ref: '#/components/schemas/Role' responses: '200': description: 'Role successfully updated, doesn''t indicate successful resource provisioning. ' content: application/json: schema: $ref: '#/components/schemas/Role' '201': description: 'Role successfully created, doesn''t indicate successful resource provisioning. ' content: application/json: schema: $ref: '#/components/schemas/Role' '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '404': $ref: '#/components/responses/Error404' '409': $ref: '#/components/responses/Error409' '412': $ref: '#/components/responses/Error412' '422': $ref: '#/components/responses/Error422' '500': $ref: '#/components/responses/Error500' delete: tags: - Role security: - bearerAuth: [] summary: Delete role description: 'Deletes the specified role. When a role is deleted: * The role is removed from all role assignments * Role assignments are NOT deleted, even if the role array becomes empty * System roles (seca.admin, seca.region-admin, seca.workspace-admin, seca.workspace-editor, seca.workspace-viewer) cannot be deleted' operationId: deleteRole parameters: - $ref: '#/components/parameters/tenantPathParam' - $ref: '#/components/parameters/resourcePathParam' - $ref: '#/components/parameters/ifUnmodifiedSince' responses: '202': description: Role deletion accepted '400': $ref: '#/components/responses/Error400' '401': $ref: '#/components/responses/Error401' '403': $ref: '#/components/responses/Error403' '404': $ref: '#/components/responses/Error404' '409': $ref: '#/components/responses/Error409' '412': $ref: '#/components/responses/Error412' '500': $ref: '#/components/responses/Error500' servers: - url: https://demo.secapi.cloud/providers/seca.authorization description: Path Schema - url: https://authorization.seca.demo.secapi.cloud description: DNS Schema components: responses: Error409: description: Conflict content: application/json: schema: $ref: '#/components/schemas/Error409' example: status: 409 type: http://secapi.cloud/errors/resource-conflict title: Conflict detail: The request could not be completed due to a conflict with the current state of the resource. instance: /errors/409 sources: [] Error400: description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error400' example: status: 400 type: http://secapi.cloud/errors/invalid-request title: Bad Request detail: The request was invalid or cannot be served. instance: /errors/400 sources: [] Error412: description: Precondition Failed content: application/json: schema: $ref: '#/components/schemas/Error412' example: status: 412 type: http://secapi.cloud/errors/precondition-failed title: Precondition Failed detail: The precondition given in the If-Match header failed. instance: /errors/412 sources: [] Error401: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error401' example: status: 401 type: http://secapi.cloud/errors/unauthorized title: Unauthorized detail: Authentication is required and has failed or has not been provided. instance: /errors/401 sources: [] Error500: description: Internal Server Error content: application/json: schema: $ref: '#/components/schemas/Error500' example: status: 500 type: http://secapi.cloud/errors/internal-server-error title: Internal Server Error detail: The server encountered an unexpected condition that prevented it from fulfilling the request. instance: /errors/500 sources: [] Error422: description: Unprocessable Entity content: application/json: schema: $ref: '#/components/schemas/Error422' example: status: 422 type: http://secapi.cloud/errors/validation-error title: Unprocessable Entity detail: The subnetRef is not correctly formatted. sources: - pointer: /spec/subnetRef parameter: subnet instance: /errors/422 Error404: description: Not Found content: application/json: schema: $ref: '#/components/schemas/Error404' example: status: 404 type: http://secapi.cloud/errors/resource-not-found title: Not Found detail: The requested resource could not be found. instance: /errors/404 sources: [] Error403: description: Forbidden content: application/json: schema: $ref: '#/components/schemas/Error403' example: status: 403 type: http://secapi.cloud/errors/forbidden title: Forbidden detail: The request was valid, but the server is refusing action. instance: /errors/403 sources: [] schemas: GlobalTenantResourceMetadata: description: 'Metadata for global resources with name, permission, modification, type, and tenant information. ' allOf: - $ref: '#/components/schemas/NameMetadata' - $ref: '#/components/schemas/PermissionMetadata' - $ref: '#/components/schemas/ModificationMetadata' - $ref: '#/components/schemas/TypeMetadata' - $ref: '#/components/schemas/TenantMetadata' Labels: x-go-type-skip-optional-pointer: true type: object description: 'User-defined key/value pairs that are mutable and can be used to organize and categorize resources. They can be used to filter resources. The number of labels is eventually limited by the CSP. ' additionalProperties: type: string maxLength: 63 example: env: production RoleIterator: description: Iterator for roles type: object required: - items - metadata properties: items: description: List of roles type: array items: $ref: '#/components/schemas/Role' metadata: $ref: '#/components/schemas/ResponseMetadata' UserResourceMetadata: type: object description: Metadata for user-defined resource properties properties: labels: $ref: '#/components/schemas/Labels' annotations: $ref: '#/components/schemas/Annotations' extensions: $ref: '#/components/schemas/Extensions' Error409: allOf: - $ref: '#/components/schemas/Error' description: A 409 Conflict error response example: status: 409 type: http://secapi.cloud/errors/resource-conflict title: Conflict detail: The request could not be completed due to a conflict with the current state of the resource. instance: /errors/409 sources: [] Error403: allOf: - $ref: '#/components/schemas/Error' description: A 403 Forbidden error response example: status: 403 type: http://secapi.cloud/errors/forbidden title: Forbidden detail: The request was valid, but the server is refusing action. instance: /errors/403 sources: [] Status: type: object readOnly: true description: Current status of the resource required: - conditions properties: state: x-go-type-skip-optional-pointer: true allOf: - $ref: '#/components/schemas/ResourceState' conditions: type: array description: 'History of state transitions, ordered newest-first, complementing the current snapshot in `state`. ' maxItems: 32 items: $ref: '#/components/schemas/StatusCondition' x-oapi-codegen-extra-tags: x-kubebuilder-validation-max-items: '32' Error422: allOf: - $ref: '#/components/schemas/Error' description: A 422 Unprocessable Entity error response example: status: 422 type: http://secapi.cloud/errors/validation-error title: Unprocessable Entity detail: The request was well-formed but was unable to be followed due to semantic errors. sources: - pointer: /data/attributes/username parameter: username instance: /errors/422 NameMetadata: type: object readOnly: true required: - name description: Metadata for resource names properties: name: type: string description: 'Resource identifier in dash-case (kebab-case) format. Must start and end with an alphanumeric character. Can contain lowercase letters, numbers, and hyphens. Multiple segments can be joined with dots. Each segment follows the same rules. ' minLength: 1 maxLength: 128 pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ example: resource-name Extensions: x-go-type-skip-optional-pointer: true type: object description: 'User-defined key/value pairs that are mutable and can be used to add extensions. Extensions are subject to validation by the CSP, and any value that is not accepted will be rejected during admission. ' additionalProperties: type: string PermissionMetadata: type: object readOnly: true description: Metadata for permission management required: - provider - resource - verb properties: provider: type: string minLength: 1 maxLength: 64 example: seca.compute/v1 resource: type: string minLength: 1 maxLength: 256 example: tenants/tn-1/workspaces/ws-1/instances/my-server verb: type: string minLength: 1 maxLength: 7 example: get example: provider: seca.compute/v1 resource: tenants/tn-1/workspaces/ws-1/instances/my-server verb: get Error: type: object description: 'A detailed error response see https://datatracker.ietf.org/doc/html/rfc7807. ' required: - type - title - status - detail - instance - sources properties: type: type: string description: The type of error, expressed as a URI. minLength: 1 maxLength: 4000 example: https://httpstatuses.io/400 title: type: string description: 'A short, human-readable summary of the problem type. It SHOULD NOT change from occurrence to occurrence of the problem, except for purposes of localization (e.g., using proactive content negotiation; see [RFC7231], Section 3.4). ' minLength: 1 maxLength: 1024 status: type: number description: 'The HTTP status type ([http://secapi.cloud/errors/-rfc7231], Section 6) generated by the origin server for this occurrence of the problem. ' minimum: 100 maximum: 599 example: 400 detail: type: string description: A human-readable explanation specific to this occurrence of the problem. minLength: 1 maxLength: 32768 instance: type: string description: 'A URI reference that identifies the specific occurrence of the problem. It may or may not yield further information if dereferenced. ' minLength: 1 maxLength: 256 sources: type: array maxItems: 32 items: $ref: '#/components/schemas/ErrorSource' meta: type: object description: A meta object containing non-standard meta-information about the error. ResponseMetadata: description: 'Metadata for response objects. ' allOf: - $ref: '#/components/schemas/PermissionMetadata' - type: object readOnly: true properties: skipToken: type: string description: Opaque cursor to get the next page. Field is omitted when there are no more pages available. maxLength: 5 example: skipToken: 'false' provider: seca.compute/v1 resource: tenants/tn-1/workspaces/ws-1/instances/my-server verb: get Error500: allOf: - $ref: '#/components/schemas/Error' description: A 500 Internal Server Error error response example: status: 500 type: http://secapi.cloud/errors/internal-server-error title: Internal Server Error detail: The server encountered an unexpected condition that prevented it from fulfilling the request. instance: /errors/500 sources: [] StatusCondition: type: object description: 'StatusCondition describes the state of a resource at a certain point. Conditions are provider-specific and can represent different states depending on the resource type and provider implementation. ' required: - state - lastTransitionAt properties: state: $ref: '#/components/schemas/ResourceState' lastTransitionAt: type: string format: date-time description: 'LastTransitionAt is the last time the condition transitioned from one status to another. This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable. ' type: type: string x-go-type-skip-optional-pointer: true description: 'Type of condition. The condition type is provider-specific and should reflect the specific states relevant to your resource. ' reason: type: string x-go-type-skip-optional-pointer: true description: 'The reason for the condition''s last transition in CamelCase. The specific set of reason values is provider-specific and should be documented by the provider. ' maxLength: 1024 pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ x-oapi-codegen-extra-tags: x-kubebuilder-validation-max-length: '1024' x-kubebuilder-validation-pattern: ^[A-Za-z]([A-Za-z0-9_,:]*[A-Za-z0-9_])?$ message: type: string x-go-type-skip-optional-pointer: true description: 'A human-readable message indicating details about the transition. ' maxLength: 32768 x-oapi-codegen-extra-tags: x-kubebuilder-validation-max-length: '32768' example: state: active lastTransitionAt: '2024-11-21T14:39:22Z' Error412: allOf: - $ref: '#/components/schemas/Error' description: A 412 Precondition Failed error response example: status: 412 type: http://secapi.cloud/errors/precondition-failed title: Precondition Failed detail: The precondition given in the If-Match header failed. instance: /errors/412 sources: [] Error400: allOf: - $ref: '#/components/schemas/Error' description: A 400 Bad Request error response example: status: 400 type: http://secapi.cloud/errors/invalid-request title: Bad Request detail: The request was invalid or cannot be served. instance: /errors/400 sources: [] Error404: allOf: - $ref: '#/components/schemas/Error' description: A 404 Not Found error response example: status: 404 type: http://secapi.cloud/errors/resource-not-found title: Not Found detail: The requested resource could not be found. instance: /errors/404 sources: [] ModificationMetadata: type: object readOnly: true description: Base metadata for all resources with optional region references required: - createdAt - lastModifiedAt - resourceVersion properties: createdAt: type: string format: date-time description: Indicates the time when the resource was created. The field is set by the provider and should not be modified by the user. deletedAt: type: string format: date-time description: If set, indicates the time when the resource was marked for deletion. Resources with this field set are considered pending deletion. lastModifiedAt: type: string format: date-time description: Indicates the time when the resource was created or last modified. Field is used for "If-Unmodified-Since" logic for concurrency control. The provider guarantees that a modification on a single resource can happen only once every millisecond. resourceVersion: type: integer description: Incremented on every modification of the resource. Used for optimistic concurrency control. minimum: 1 format: int64 Permission: type: object description: 'Permission specification, including providers, resources, and verbs. Permissions are used to define access control policies for user accounts. ' required: - provider - resources - verb properties: provider: type: string description: 'The provider for which the resource and verbs are defined. ' minLength: 1 maxLength: 64 example: seca.storage/v1 x-oapi-codegen-extra-tags: x-kubebuilder-validation-min-length: '1' x-kubebuilder-validation-max-length: '64' resources: type: array minItems: 1 items: type: string minLength: 1 maxLength: 256 x-oapi-codegen-extra-tags: x-kubebuilder-validation-max-length: '256' description: 'The resources are the specific resources that the permission applies to. The resource can be a wildcard `*` to represent all resources or a specific resource type. For example, `images/my-image` or `images/*`. ' example: - images/* - skus/* maxItems: 256 x-oapi-codegen-extra-tags: x-kubebuilder-validation-items-min-length: '1' x-kubebuilder-validation-items-max-length: '256' x-kubebuilder-validation-min-items: '1' x-kubebuilder-validation-max-items: '256' verb: type: array minItems: 1 items: type: string minLength: 1 maxLength: 7 x-oapi-codegen-extra-tags: x-kubebuilder-validation-max-length: '7' description: 'The verb is a string that represents the action to be performed on a resource. The standard operations are defined as `get`, `put`, `list`, `delete`. If the resource has additional actions they can to be permitted individually as verb and action in the form `:`. For example, `post.start`, `post.stop`, `post.restart` or with a wildcard for all actions `post`. ' example: - read - write maxItems: 16 x-oapi-codegen-extra-tags: x-kubebuilder-validation-items-min-length: '1' x-kubebuilder-validation-items-max-length: '7' x-kubebuilder-validation-min-items: '1' x-kubebuilder-validation-max-items: '16' ReferenceURN: type: string minLength: 1 description: "A unique resource name (URN) used to identify and reference this resource.\n\nThe URN is NOT a URL — it does not contain a protocol scheme (http/https), a host,\nor any endpoint-specific prefix. It is a portable, transport-agnostic identifier.\nA configured SDK client — which knows the provider's base URL and endpoint mapping —\ncan derive a URL from a URN, but the URN alone cannot be turned into a URL without\nthat SDK configuration context. This separation keeps the URN portable across\nenvironments and CSP deployments.\n\nThe full URN format is:\n `{provider}/{version}/tenants/{tenant}/workspaces/{workspace}/{type}/{name}`\n\nFor hierarchical (nested) resources, additional parent path segments are included:\n `seca.network/v1/tenants/tn-1/workspaces/ws-1/networks/my-net/route-tables/my-rt`\n\n### Automatic Prefix Inference\n\nIn most cases, the prefix of the URN can be automatically derived in the given context.\nTo simplify usage, only the resource type and name might be specified as a reference\nusing the `/` notation. The suffix can be made more specific by adding\nadditional segments separated by slashes.\n\nThe prefix is automatically inferred from the context. For example, if the resource is a\nblock storage in the same workspace the reference can be specified as\n`block-storages/my-block-storage`. If the resource is a block storage in a different workspace, the\nreference can be specified as `workspaces/ws-1/block-storages/my-block-storage`.\n\nFor automatic prefix inference, the following rules apply:\n- the version is inferred from the current resource version\n- the workspace is inferred from the current workspace\n- the region is inferred from the current region\n- the provider is inferred from the type and context of the usage\n\nThe prefix inference is resolved on admission into the full URN format, which makes it\nmostly suitable for human use.\n" maxLength: 255 example: seca.compute/v1/tenants/tn-1/workspaces/ws-1/instances/my-server Role: description: 'Role represents a set of permissions that can be assigned to users. ' allOf: - $ref: '#/components/schemas/UserResourceMetadata' - type: object required: - spec properties: metadata: $ref: '#/components/schemas/GlobalTenantResourceMetadata' spec: $ref: '#/components/schemas/RoleSpec' status: $ref: '#/components/schemas/Status' Annotations: x-go-type-skip-optional-pointer: true type: object description: 'User-defined key/value pairs that are mutable and can be used to add annotations. The number of annotations is eventually limited by the CSP. ' additionalProperties: type: string maxLength: 1024 example: description: Human readable description ErrorSource: type: object description: An object containing references to the source of the error. required: - pointer - parameter properties: pointer: type: string description: A JSON Pointer [RFC6901] to the associated entity in the request document. minLength: 1 maxLength: 256 parameter: type: string description: A string indicating which URI query parameter caused the error. minLength: 1 maxLength: 64 TypeMetadata: type: object readOnly: true required: - apiVersion - kind - ref description: 'Metadata for all resources with type information. ' properties: apiVersion: type: string description: API version of the resource minLength: 1 maxLength: 16 default: v1 kind: type: string description: Type of the resource enum: - activity-log - block-storage - image - instance - instance-sku - internet-gateway - network - network-load-balancer - network-sku - nic - object-storage-account - public-ip - region - role - role-assignment - routing-table - security-group - security-group-rule - storage-sku - subnet - workspace x-enumNames: - ResourceKindActivityLog - ResourceKindBlockStorage - ResourceKindImage - ResourceKindInstance - ResourceKindInstanceSku - ResourceKindInternetGateway - ResourceKindNetwork - ResourceKindNetworkLoadBalancer - ResourceKindNetworkSku - ResourceKindNic - ResourceKindObjectStorageAccount - ResourceKindPublicIP - ResourceKindRegion - ResourceKindRole - ResourceKindRoleAssignment - ResourceKindRoutingTable - ResourceKindSecurityGroup - ResourceKindSecurityGroupRule - ResourceKindStorageSku - ResourceKindSubnet - ResourceKindWorkspace ref: $ref: '#/components/schemas/ReferenceURN' Error401: allOf: - $ref: '#/components/schemas/Error' description: A 401 Unauthorized error response example: status: 401 type: http://secapi.cloud/errors/unauthorized title: Unauthorized detail: Authentication is required and has failed or has not been provided. instance: /errors/401 sources: [] RoleSpec: type: object description: 'Role specification defined as a list of permissions. Roles are used to define access control policies for a user account using a role assignment. ' required: - permissions properties: permissions: type: array minItems: 1 maxItems: 256 items: $ref: '#/components/schemas/Permission' description: List of permissions granted by this role x-oapi-codegen-extra-tags: x-kubebuilder-validation-min-items: '1' x-kubebuilder-validation-max-items: '256' example: - provider: seca.storage/v1 resources: - images/* - block-storages/* verb: - get - list - provider: seca.compute/v1 resources: - instances/* verb: - get - list - provider: seca.network/v1 resources: - networks/* - subnets/* - route-tables/* - nics/* - internet-gateways/* - security-groups/* - public-ips/* verb: - get - list TenantMetadata: type: object description: Metadata for resources with tenant constraints readOnly: true required: - tenant properties: tenant: type: string description: Tenant identifier minLength: 1 maxLength: 64 ResourceState: type: string description: 'Current phase of the resource: - pending: not available, waiting for other resources - creating: not available, creation started - active: available for data layer usage - updating: available for data layer usage - deleting: maybe still available for data layer user, can fail any moment - error: failed to fulfill the request; would be related to provider issue or customer related input. ' enum: - pending - creating - active - updating - deleting - error x-enumNames: - ResourceStatePending - ResourceStateCreating - ResourceStateActive - ResourceStateUpdating - ResourceStateDeleting - ResourceStateError example: active parameters: tenantPathParam: name: tenant in: path required: true schema: type: string minLength: 1 maxLength: 64 description: Tenant ID skipTokenParam: in: query name: skipToken description: Opaque cursor for pagination. Use the skipToken from the previous response to get the next page of results. Note that skipTokens do not guarantee consistency across pages if the underlying data changes between requests required: false schema: type: string ifUnmodifiedSince: in: header name: if-unmodified-since schema: type: integer required: false description: 'Returns resources only if they have not been modified since the specified version. Uses metadata.resourceVersion for comparison. ' limitParam: in: query name: limit description: Maximum number of resources to return in the response required: false schema: type: integer minimum: 1 maximum: 10000 default: 1000 resourcePathParam: name: name in: path required: true schema: type: string maxLength: 128 minLength: 1 pattern: ^[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*$ description: Resource name acceptHeader: in: header name: Accept schema: type: string default: application/json example: application/json; deleted=true enum: - application/json - application/json; deleted=true - application/json; deleted=only x-enumNames: - AcceptHeaderJson - AcceptHeaderJsonDeletedTrue - AcceptHeaderJsonDeletedOnly description: 'Controls whether deleted resources are included: - `"application/json"`: Returns only non-deleted resources - `"application/json; deleted=true"`: Returns both deleted and non-deleted resources - `"application/json; deleted=only"`: Returns only deleted resources ' labelSelector: in: query name: labels description: "Filter resources by their labels. Multiple filters are combined with comma.\nFilter syntax:\n - Equals: key=value\n - Not equals: key!=value\n - Wildcards: \\*key\\*=\\*value\\* - substring (contains) match on both key and value. Each `*` can appear at start, end or in the middle to mean \"any characters\". Example: \\*env\\*=\\*prod\\* matches a label key containing \"env\" whose value contains \"prod\".\n - Numeric: key>value, key=value, key<=value\n - Namespaced key examples: 'monitoring:alert-level=high' or 'billing:team=platform'\n" required: false schema: type: string example: cloud:region=us-east-1,billing:team=platform,tier!=dev securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'Use a JWT token for authentication. The token identifies the user, and policies (RBAC, ABAC, or hybrid) determine authorization. ' x-refined-from: - foundation.authorization.v1.yaml - eu-sovereign-cloud-api-foundation-authorization-v1-openapi.yml