openapi: 3.1.0 info: title: Google Cloud Binary Authorization Attestations Policy API description: The Binary Authorization API provides deploy-time security controls for container images on Google Cloud. It enables management of policies, attestors, and attestations to ensure only trusted container images are deployed to GKE, Cloud Run, and Anthos environments. version: v1 contact: name: Google Cloud Support url: https://cloud.google.com/binary-authorization/docs/support termsOfService: https://cloud.google.com/terms servers: - url: https://binaryauthorization.googleapis.com/v1 description: Production Server security: - oauth2: [] tags: - name: Policy description: Operations for managing the Binary Authorization policy paths: /projects/{projectId}/policy: get: operationId: getPolicy summary: Google Cloud Binary Authorization Get project policy description: Gets the policy for a project. Returns a default policy if the project does not have one configured. tags: - Policy parameters: - $ref: '#/components/parameters/projectId' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/Policy' put: operationId: updatePolicy summary: Google Cloud Binary Authorization Update project policy description: Creates or updates a project's policy. tags: - Policy parameters: - $ref: '#/components/parameters/projectId' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Policy' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/Policy' components: parameters: projectId: name: projectId in: path required: true schema: type: string schemas: AdmissionRule: type: object properties: evaluationMode: type: string enum: - ALWAYS_ALLOW - ALWAYS_DENY - REQUIRE_ATTESTATION requireAttestationsBy: type: array items: type: string description: Resource names of attestors required enforcementMode: type: string enum: - ENFORCED_BLOCK_AND_AUDIT_LOG - DRYRUN_AUDIT_LOG_ONLY Policy: type: object properties: name: type: string description: The resource name of the policy globalPolicyEvaluationMode: type: string enum: - ENABLE - DISABLE description: Whether to enable the global policy evaluation mode admissionWhitelistPatterns: type: array items: type: object properties: namePattern: type: string description: An image name pattern to allowlist description: Admission allowlist patterns defaultAdmissionRule: $ref: '#/components/schemas/AdmissionRule' clusterAdmissionRules: type: object additionalProperties: $ref: '#/components/schemas/AdmissionRule' description: Per-cluster admission rules updateTime: type: string format: date-time securitySchemes: oauth2: type: oauth2 flows: authorizationCode: authorizationUrl: https://accounts.google.com/o/oauth2/auth tokenUrl: https://oauth2.googleapis.com/token scopes: https://www.googleapis.com/auth/cloud-platform: Full access to Google Cloud externalDocs: description: Binary Authorization API Documentation url: https://cloud.google.com/binary-authorization/docs/reference/rest