openapi: 3.2.0 info: title: Harbor Configure API description: These APIs provide services for manipulating Harbor project. version: '2.0' servers: - url: http://localhost/api/v2.0 - url: https://localhost/api/v2.0 security: - basic: [] - {} tags: - name: Configure paths: /internalconfig: get: summary: Get internal configurations operationId: getInternalconfig description: This endpoint is for retrieving system configurations that only provides for internal api call. tags: - Configure parameters: - $ref: '#/components/parameters/requestId' responses: '200': description: Get system configurations successfully. The response body is a map. content: application/json: schema: $ref: '#/components/schemas/InternalConfigurationsResponse' '401': description: User need to log in first. '403': description: User does not have permission of admin role. '500': $ref: '#/components/responses/500' /configurations: get: summary: Get system configurations operationId: getConfigurations description: This endpoint is for retrieving system configurations that only provides for admin user. tags: - Configure parameters: - $ref: '#/components/parameters/requestId' responses: '200': description: Get system configurations successfully. The response body is a map. content: application/json: schema: $ref: '#/components/schemas/ConfigurationsResponse' '401': description: User need to log in first. '403': description: User does not have permission of admin role. '500': description: Unexpected internal errors. put: summary: Modify system configurations operationId: updateConfigurations description: This endpoint is for modifying system configurations that only provides for admin user. tags: - Configure parameters: - $ref: '#/components/parameters/requestId' responses: '200': description: Modify system configurations successfully. '400': $ref: '#/components/responses/400' '401': $ref: '#/components/responses/401' '403': $ref: '#/components/responses/403' '422': $ref: '#/components/responses/422' '500': $ref: '#/components/responses/500' requestBody: content: application/json: schema: $ref: '#/components/schemas/Configurations' description: The configuration map can contain a subset of the attributes of the schema, which are to be updated. required: true components: responses: '403': description: Forbidden. The caller does not have sufficient permission to perform the requested operation. headers: X-Request-Id: description: The ID of the corresponding request for the response schema: type: string content: application/json: schema: $ref: '#/components/schemas/Errors' '422': description: Unprocessable entity. The request was well-formed but could not be processed (for example, due to validation errors). Inspect the `errors` array in the response body for details. headers: X-Request-Id: description: The ID of the corresponding request for the response schema: type: string content: application/json: schema: $ref: '#/components/schemas/Errors' '500': description: Internal server error. Inspect the `errors` array in the response body for details. headers: X-Request-Id: description: The ID of the corresponding request for the response schema: type: string content: application/json: schema: $ref: '#/components/schemas/Errors' '401': description: Unauthorized. Authentication is required to access this resource. headers: X-Request-Id: description: The ID of the corresponding request for the response schema: type: string content: application/json: schema: $ref: '#/components/schemas/Errors' '400': description: Bad request. The request body or query parameters are invalid. Inspect the `errors` array in the response body for details. headers: X-Request-Id: description: The ID of the corresponding request for the response schema: type: string content: application/json: schema: $ref: '#/components/schemas/Errors' schemas: InternalConfigurationValue: type: object properties: value: type: object description: The value of current config item editable: type: boolean x-omitempty: false description: The configure item can be updated or not BoolConfigItem: type: object properties: value: type: boolean x-omitempty: false description: The boolean value of current config item editable: type: boolean x-omitempty: false description: The configure item can be updated or not ConfigurationsResponse: type: object properties: auth_mode: $ref: '#/components/schemas/StringConfigItem' description: The auth mode of current system, such as "db_auth", "ldap_auth", "oidc_auth" primary_auth_mode: $ref: '#/components/schemas/BoolConfigItem' description: The flag to indicate whether the current auth mode should consider as a primary one. ldap_base_dn: $ref: '#/components/schemas/StringConfigItem' description: The Base DN for LDAP binding. ldap_filter: $ref: '#/components/schemas/StringConfigItem' description: The filter for LDAP search ldap_group_base_dn: $ref: '#/components/schemas/StringConfigItem' description: The base DN to search LDAP group. ldap_group_admin_dn: $ref: '#/components/schemas/StringConfigItem' description: Specify the ldap group which have the same privilege with Harbor admin ldap_group_attribute_name: $ref: '#/components/schemas/StringConfigItem' description: The attribute which is used as identity of the LDAP group, default is cn.' ldap_group_search_filter: $ref: '#/components/schemas/StringConfigItem' description: The filter to search the ldap group ldap_group_search_scope: $ref: '#/components/schemas/IntegerConfigItem' description: The scope to search ldap group. ''0-LDAP_SCOPE_BASE, 1-LDAP_SCOPE_ONELEVEL, 2-LDAP_SCOPE_SUBTREE'' ldap_group_attach_parallel: $ref: '#/components/schemas/BoolConfigItem' description: Attach LDAP user group information in parallel. ldap_scope: $ref: '#/components/schemas/IntegerConfigItem' description: The scope to search ldap users,'0-LDAP_SCOPE_BASE, 1-LDAP_SCOPE_ONELEVEL, 2-LDAP_SCOPE_SUBTREE' ldap_search_dn: $ref: '#/components/schemas/StringConfigItem' description: The DN of the user to do the search. ldap_timeout: $ref: '#/components/schemas/IntegerConfigItem' description: Timeout in seconds for connection to LDAP server ldap_uid: $ref: '#/components/schemas/StringConfigItem' description: The attribute which is used as identity for the LDAP binding, such as "CN" or "SAMAccountname" ldap_url: $ref: '#/components/schemas/StringConfigItem' description: The URL of LDAP server ldap_verify_cert: $ref: '#/components/schemas/BoolConfigItem' description: Whether verify your OIDC server certificate, disable it if your OIDC server is hosted via self-hosted certificate. ldap_group_membership_attribute: $ref: '#/components/schemas/StringConfigItem' description: The user attribute to identify the group membership project_creation_restriction: $ref: '#/components/schemas/StringConfigItem' description: Indicate who can create projects, it could be ''adminonly'' or ''everyone''. read_only: $ref: '#/components/schemas/BoolConfigItem' description: The flag to indicate whether Harbor is in readonly mode. self_registration: $ref: '#/components/schemas/BoolConfigItem' description: Whether the Harbor instance supports self-registration. If it''s set to false, admin need to add user to the instance. token_expiration: $ref: '#/components/schemas/IntegerConfigItem' description: The expiration time of the token for internal Registry, in minutes. uaa_client_id: $ref: '#/components/schemas/StringConfigItem' description: The client id of UAA uaa_client_secret: $ref: '#/components/schemas/StringConfigItem' description: The client secret of the UAA uaa_endpoint: $ref: '#/components/schemas/StringConfigItem' description: The endpoint of the UAA uaa_verify_cert: $ref: '#/components/schemas/BoolConfigItem' description: Verify the certificate in UAA server http_authproxy_endpoint: $ref: '#/components/schemas/StringConfigItem' description: The endpoint of the HTTP auth http_authproxy_tokenreview_endpoint: $ref: '#/components/schemas/StringConfigItem' description: The token review endpoint http_authproxy_admin_groups: $ref: '#/components/schemas/StringConfigItem' description: The group which has the harbor admin privileges http_authproxy_admin_usernames: $ref: '#/components/schemas/StringConfigItem' description: The usernames which has the harbor admin privileges http_authproxy_verify_cert: $ref: '#/components/schemas/BoolConfigItem' description: Verify the HTTP auth provider's certificate http_authproxy_skip_search: $ref: '#/components/schemas/BoolConfigItem' description: Search user before onboard http_authproxy_server_certificate: $ref: '#/components/schemas/StringConfigItem' description: The certificate of the HTTP auth provider oidc_name: $ref: '#/components/schemas/StringConfigItem' description: The OIDC provider name oidc_endpoint: $ref: '#/components/schemas/StringConfigItem' description: The endpoint of the OIDC provider oidc_client_id: $ref: '#/components/schemas/StringConfigItem' description: The client ID of the OIDC provider oidc_groups_claim: $ref: '#/components/schemas/StringConfigItem' description: The attribute claims the group name oidc_admin_group: $ref: '#/components/schemas/StringConfigItem' description: The OIDC group which has the harbor admin privileges oidc_group_filter: $ref: '#/components/schemas/StringConfigItem' description: The OIDC group filter which filters out the group doesn't match the regular expression oidc_scope: $ref: '#/components/schemas/StringConfigItem' description: The scope of the OIDC provider oidc_user_claim: $ref: '#/components/schemas/StringConfigItem' description: The attribute claims the username oidc_verify_cert: $ref: '#/components/schemas/BoolConfigItem' description: Verify the OIDC provider's certificate' oidc_auto_onboard: $ref: '#/components/schemas/BoolConfigItem' description: Auto onboard the OIDC user oidc_extra_redirect_parms: $ref: '#/components/schemas/StringConfigItem' description: Extra parameters to add when redirect request to OIDC provider oidc_logout: $ref: '#/components/schemas/BoolConfigItem' description: Extra parameters to logout user session from the OIDC provider robot_token_duration: $ref: '#/components/schemas/IntegerConfigItem' description: The robot account token duration in days robot_name_prefix: $ref: '#/components/schemas/StringConfigItem' description: The rebot account name prefix notification_enable: $ref: '#/components/schemas/BoolConfigItem' description: Enable notification quota_per_project_enable: $ref: '#/components/schemas/BoolConfigItem' description: Enable quota per project storage_per_project: $ref: '#/components/schemas/IntegerConfigItem' description: The storage quota per project audit_log_forward_endpoint: $ref: '#/components/schemas/StringConfigItem' description: The endpoint of the audit log forwarder skip_audit_log_database: $ref: '#/components/schemas/BoolConfigItem' description: Whether skip the audit log in database scanner_skip_update_pulltime: $ref: '#/components/schemas/BoolConfigItem' description: Whether or not to skip update the pull time for scanner scan_all_policy: type: object properties: type: type: string description: The type of scan all policy, currently the valid values are "none" and "daily" parameter: type: object properties: daily_time: type: integer description: The offset in seconds of UTC 0 o'clock, only valid when the policy type is "daily" description: The parameters of the policy, the values are dependent on the type of the policy. session_timeout: $ref: '#/components/schemas/IntegerConfigItem' description: The session timeout in minutes banner_message: $ref: '#/components/schemas/StringConfigItem' description: The banner message for the UI.It is the stringified result of the banner message object disabled_audit_log_event_types: $ref: '#/components/schemas/StringConfigItem' description: The audit log event types to skip to log in database Configurations: type: object properties: auth_mode: type: string description: The auth mode of current system, such as "db_auth", "ldap_auth", "oidc_auth" x-omitempty: true x-isnullable: true primary_auth_mode: type: - boolean - 'null' x-omitempty: true description: The flag to indicate whether the current auth mode should consider as a primary one. ldap_base_dn: type: string description: The Base DN for LDAP binding. x-omitempty: true x-isnullable: true ldap_filter: type: string description: The filter for LDAP search x-omitempty: true x-isnullable: true ldap_group_base_dn: type: string description: The base DN to search LDAP group. x-omitempty: true x-isnullable: true ldap_group_admin_dn: type: string description: Specify the ldap group which have the same privilege with Harbor admin x-omitempty: true x-isnullable: true ldap_group_attribute_name: type: string description: The attribute which is used as identity of the LDAP group, default is cn.' x-omitempty: true x-isnullable: true ldap_group_search_filter: type: string description: The filter to search the ldap group x-omitempty: true x-isnullable: true ldap_group_search_scope: type: integer description: The scope to search ldap group. ''0-LDAP_SCOPE_BASE, 1-LDAP_SCOPE_ONELEVEL, 2-LDAP_SCOPE_SUBTREE'' x-omitempty: true x-isnullable: true ldap_group_attach_parallel: type: boolean description: Attach LDAP user group information in parallel, the parallel worker count is 5 x-omitempty: true x-isnullable: true ldap_scope: type: integer description: The scope to search ldap users,'0-LDAP_SCOPE_BASE, 1-LDAP_SCOPE_ONELEVEL, 2-LDAP_SCOPE_SUBTREE' x-omitempty: true x-isnullable: true ldap_search_dn: type: string description: The DN of the user to do the search. x-omitempty: true x-isnullable: true ldap_search_password: type: string description: The password of the ldap search dn x-omitempty: true x-isnullable: true ldap_timeout: type: integer description: Timeout in seconds for connection to LDAP server x-omitempty: true x-isnullable: true ldap_uid: type: string description: The attribute which is used as identity for the LDAP binding, such as "CN" or "SAMAccountname" x-omitempty: true x-isnullable: true ldap_url: type: string description: The URL of LDAP server x-omitempty: true x-isnullable: true ldap_verify_cert: type: boolean description: Whether verify your OIDC server certificate, disable it if your OIDC server is hosted via self-hosted certificate. x-omitempty: true x-isnullable: true ldap_group_membership_attribute: type: string description: The user attribute to identify the group membership x-omitempty: true x-isnullable: true project_creation_restriction: type: string description: Indicate who can create projects, it could be ''adminonly'' or ''everyone''. x-omitempty: true x-isnullable: true read_only: type: boolean description: The flag to indicate whether Harbor is in readonly mode. x-omitempty: true x-isnullable: true self_registration: type: boolean description: Whether the Harbor instance supports self-registration. If it''s set to false, admin need to add user to the instance. x-omitempty: true x-isnullable: true token_expiration: type: integer description: The expiration time of the token for internal Registry, in minutes. x-omitempty: true x-isnullable: true uaa_client_id: type: string description: The client id of UAA x-omitempty: true x-isnullable: true uaa_client_secret: type: string description: The client secret of the UAA x-omitempty: true x-isnullable: true uaa_endpoint: type: string description: The endpoint of the UAA x-omitempty: true x-isnullable: true uaa_verify_cert: type: boolean description: Verify the certificate in UAA server x-omitempty: true x-isnullable: true http_authproxy_endpoint: type: string description: The endpoint of the HTTP auth x-omitempty: true x-isnullable: true http_authproxy_tokenreview_endpoint: type: string description: The token review endpoint x-omitempty: true x-isnullable: true http_authproxy_admin_groups: type: string description: The group which has the harbor admin privileges x-omitempty: true x-isnullable: true http_authproxy_admin_usernames: type: string description: The username which has the harbor admin privileges x-omitempty: true x-isnullable: true http_authproxy_verify_cert: type: boolean description: Verify the HTTP auth provider's certificate x-omitempty: true x-isnullable: true http_authproxy_skip_search: type: boolean description: Search user before onboard x-omitempty: true x-isnullable: true http_authproxy_server_certificate: type: string description: The certificate of the HTTP auth provider x-omitempty: true x-isnullable: true oidc_name: type: string description: The OIDC provider name x-omitempty: true x-isnullable: true oidc_endpoint: type: string description: The endpoint of the OIDC provider x-omitempty: true x-isnullable: true oidc_client_id: type: string description: The client ID of the OIDC provider x-omitempty: true x-isnullable: true oidc_client_secret: type: string description: The OIDC provider secret x-omitempty: true x-isnullable: true oidc_groups_claim: type: string description: The attribute claims the group name x-omitempty: true x-isnullable: true oidc_admin_group: type: string description: The OIDC group which has the harbor admin privileges x-omitempty: true x-isnullable: true oidc_group_filter: type: string description: The OIDC group filter which filters out the group name doesn't match the regular expression x-omitempty: true x-isnullable: true oidc_scope: type: string description: The scope of the OIDC provider x-omitempty: true x-isnullable: true oidc_user_claim: type: string description: The attribute claims the username x-omitempty: true x-isnullable: true oidc_verify_cert: type: boolean description: Verify the OIDC provider's certificate' x-omitempty: true x-isnullable: true oidc_auto_onboard: type: boolean description: Auto onboard the OIDC user x-omitempty: true x-isnullable: true oidc_extra_redirect_parms: type: string description: Extra parameters to add when redirect request to OIDC provider x-omitempty: true x-isnullable: true oidc_logout: type: boolean description: Logout OIDC user session x-omitempty: true x-isnullable: true robot_token_duration: type: integer description: The robot account token duration in days x-omitempty: true x-isnullable: true robot_name_prefix: type: string description: The rebot account name prefix x-omitempty: true x-isnullable: true notification_enable: type: boolean description: Enable notification x-omitempty: true x-isnullable: true quota_per_project_enable: type: boolean description: Enable quota per project x-omitempty: true x-isnullable: true storage_per_project: type: integer description: The storage quota per project x-omitempty: true x-isnullable: true audit_log_forward_endpoint: type: string description: The audit log forward endpoint x-omitempty: true x-isnullable: true skip_audit_log_database: type: boolean description: Skip audit log database x-omitempty: true x-isnullable: true session_timeout: type: integer description: The session timeout for harbor, in minutes. x-omitempty: true x-isnullable: true scanner_skip_update_pulltime: type: boolean description: Whether or not to skip update pull time for scanner x-omitempty: true x-isnullable: true banner_message: type: string description: The banner message for the UI.It is the stringified result of the banner message object x-omitempty: true x-isnullable: true disabled_audit_log_event_types: type: string description: the list to disable log audit event types. x-omitempty: true x-isnullable: true IntegerConfigItem: type: object properties: value: type: integer x-omitempty: false description: The integer value of current config item editable: type: boolean x-omitempty: false description: The configure item can be updated or not InternalConfigurationsResponse: type: object additionalProperties: $ref: '#/components/schemas/InternalConfigurationValue' StringConfigItem: type: object properties: value: type: string x-omitempty: false description: The string value of current config item editable: type: boolean x-omitempty: false description: The configure item can be updated or not Errors: description: The error array that describe the errors got during the handling of request type: object properties: errors: type: array items: $ref: '#/components/schemas/Error' Error: description: a model for all the error response coming from harbor type: object properties: code: type: string description: The error code message: type: string description: The error message example: code: NOT_FOUND message: artifact library/hello-world:latest not found parameters: requestId: name: X-Request-Id description: An unique ID for the request in: header required: false schema: type: string minLength: 1 securitySchemes: basic: type: http scheme: basic