openapi: 3.2.0 info: title: Harness Action Templates API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Action Templates paths: /gateway/chaos/manager/api/rest/templates/actions: get: description: List all the action templates in a hub based on tag summary: List all the action templates in a hub operationId: listActionTemplate parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: chaos hub identity name: hubIdentity in: query required: true schema: type: string - description: page number name: page in: query required: true schema: type: integer default: 0 - description: limit per page name: limit in: query required: true schema: type: integer default: 15 - description: name of the action name: search in: query required: true schema: type: string - description: infra type of the action name: infraType in: query schema: type: string - description: filter based on Action name: entityType in: query schema: type: string - description: include all scope name: includeAllScope in: query schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/chaosfaulttemplate.ListActionTemplateResponse' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates post: description: Create action templates in a hub based on tag summary: Create the action templates in a hub operationId: createActionTemplate parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string requestBody: $ref: '#/components/requestBodies/chaosfaulttemplate.ActionTemplate' responses: '200': description: Successfully created Action content: '*/*': schema: $ref: '#/components/schemas/chaosfaulttemplate.ActionTemplate' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates /gateway/chaos/manager/api/rest/templates/actions/{identity}: get: description: Get the action template in a hub based on action ref summary: Get the action template in a hub operationId: getActionTemplate parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: chaos hub identity name: hubIdentity in: query required: true schema: type: string - description: revision of the 1st fault template name: revision in: query schema: type: string - description: name of the fault name: identity in: path required: true schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/chaosfaulttemplate.GetActionTemplateResponse' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates put: description: Update an existing action template in a hub with new configuration summary: Update the action templates in a hub operationId: updateActionTemplate parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: mark template as default name: isDefault in: query schema: type: boolean - description: ID of the Action to edit name: identity in: path required: true schema: type: string requestBody: $ref: '#/components/requestBodies/chaosfaulttemplate.ActionTemplate' responses: '200': description: Successfully updated Action content: '*/*': schema: $ref: '#/components/schemas/chaosfaulttemplate.ActionTemplate' '400': description: Bad Request content: '*/*': schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates delete: summary: Delete action template operationId: deleteActionTemplate parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: reference of the hub i.e. hub ID name: hubIdentity in: query required: true schema: type: string - description: name of the fault name: identity in: path required: true schema: type: string - description: revision of the action template to be deleted name: revision in: query schema: type: string responses: '200': description: OK content: application/json: schema: type: boolean '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates /gateway/chaos/manager/api/rest/templates/actions/{identity}/compare: get: description: Get the difference between 2 revisions of action template in a hub summary: Get the difference between 2 revisions of action template operationId: getActionTemplateRevisionDifference parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: reference of the hub i.e. hub ID name: hubIdentity in: query required: true schema: type: string - description: name of the fault name: identity in: path required: true schema: type: string - description: revision of the 1st fault template name: revision in: query required: true schema: type: string - description: revision to compare name: revisionToCompare in: query required: true schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/chaosfaulttemplate.ListActionTemplateResponse' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates /gateway/chaos/manager/api/rest/templates/actions/{identity}/revisions: get: description: List all the revision of a fault template in a hub summary: List all the revision of an action template in a hub operationId: listActionTemplateRevisions parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: chaos hub identity name: hubIdentity in: query required: true schema: type: string - description: name of the fault name: identity in: path required: true schema: type: string - description: page number name: page in: query required: true schema: type: integer default: 0 - description: limit per page name: limit in: query required: true schema: type: integer default: 15 responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/chaosfaulttemplate.ListActionTemplateResponse' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates /gateway/chaos/manager/api/rest/templates/actions/{identity}/variables: get: description: Get the list of inputs in a fault template based on revision summary: Get the list of inputs in an action template operationId: listVariablesInActionTemplate parameters: - description: account id that want to access the resource name: accountIdentifier in: query required: true schema: type: string - description: organization id that want to access the resource name: organizationIdentifier in: query required: true schema: type: string - description: project id that want to access the resource name: projectIdentifier in: query required: true schema: type: string - description: reference of the hub i.e. hub ID name: hubIdentity in: query required: true schema: type: string - description: name of the fault name: identity in: path required: true schema: type: string - description: revision of the 1st fault template name: revision in: query required: true schema: type: string responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/chaosfaulttemplate.ActionTemplateVariables' '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/api.RestError' tags: - Action Templates components: schemas: actions.ActionType: type: string enum: - delay - customScript - container x-enum-varnames: - DelayActionType - CustomScriptActionType - ContainerActionType actions.InfrastructureType: type: string enum: - Kubernetes - KubernetesV2 - Windows - Linux - CloudFoundry - Container x-enum-varnames: - InfrastructureTypeKubernetes - InfrastructureTypeKubernetesV2 - InfrastructureTypeWindows - InfrastructureTypeLinux - InfrastructureTypeCloudFoundry - InfrastructureTypeContainer github_com_harness_hce-saas_graphql_server_graph_model.UserDetails: type: object properties: email: type: string userID: type: string username: type: string common.PreferredNodeSelector: type: object properties: key: type: string operator: description: 'default: In' type: string values: type: string weight: type: string v1.PodFSGroupChangePolicy: type: string enum: - OnRootMismatch - Always x-enum-varnames: - FSGroupChangeOnRootMismatch - FSGroupChangeAlways template.Variable: type: object required: - name - value properties: allowedValues: type: array items: {} category: $ref: '#/components/schemas/template.InputCategory' default: {} description: type: string name: type: string path: type: string required: type: boolean stringify: type: boolean tags: type: array items: type: string tooltipId: type: string type: $ref: '#/components/schemas/template.InputType' validator: type: string value: {} common.VolumeType: type: string enum: - HostPath - EmptyDir - Secret - PersistentVolumeClaim - ConfigMap x-enum-varnames: - VolumeTypeHostPath - VolumeTypeEmptyDir - VolumeTypeSecret - VolumeTypePersistentVolumeClaim - VolumeTypeConfigMap chaosfaulttemplate.ListActionTemplateResponse: type: object properties: correlationID: type: string countDetails: type: array items: $ref: '#/components/schemas/chaosactiontemplate.ActionsTemplateCount' data: type: array items: $ref: '#/components/schemas/chaosactiontemplate.ChaosActionTemplate' pagination: $ref: '#/components/schemas/github_com_harness_hce-saas_graphql_server_api.Pagination' resource.Quantity: type: object properties: Format: type: string enum: - DecimalExponent - BinarySI - DecimalSI x-enum-comments: BinarySI: e.g., 12Mi (12 * 2^20) DecimalExponent: e.g., 12e6 DecimalSI: e.g., 12M (12 * 10^6) x-enum-varnames: - DecimalExponent - BinarySI - DecimalSI v1.Capabilities: type: object properties: add: description: 'Added capabilities +optional' type: array items: type: string drop: description: 'Removed capabilities +optional' type: array items: type: string chaosfaulttemplate.GetActionTemplateResponse: type: object properties: correlationID: type: string data: $ref: '#/components/schemas/chaosactiontemplate.ChaosActionTemplate' v1.TaintEffect: type: string enum: - NoSchedule - PreferNoSchedule - NoExecute x-enum-varnames: - TaintEffectNoSchedule - TaintEffectPreferNoSchedule - TaintEffectNoExecute chaosfaulttemplate.ActionTemplateVariables: type: object properties: actionProperties: type: array items: $ref: '#/components/schemas/template.Variable' actionRunProperty: type: array items: $ref: '#/components/schemas/template.Variable' inputs: type: array items: $ref: '#/components/schemas/template.Variable' variables: description: CHAOS-11100 type: array items: $ref: '#/components/schemas/template.Variable' api.ResponseErrorCode: type: string enum: - PIPELINE_NOT_FOUND x-enum-varnames: - PipelineNotFound action.ActionTemplateProperties: type: object properties: containerAction: $ref: '#/components/schemas/common.ContainerTemplate' customScriptAction: $ref: '#/components/schemas/action.CustomScriptActionTemplate' delayAction: $ref: '#/components/schemas/action.DelayActionTemplate' v1.StorageMedium: type: string enum: - '' - Memory - HugePages - HugePages- x-enum-comments: StorageMediumDefault: use whatever the default is for the node, assume anything we don't explicitly handle is this StorageMediumHugePages: use hugepages StorageMediumHugePagesPrefix: prefix for full medium notation HugePages- StorageMediumMemory: use memory (e.g. tmpfs on linux) x-enum-varnames: - StorageMediumDefault - StorageMediumMemory - StorageMediumHugePages - StorageMediumHugePagesPrefix v1.SeccompProfileType: type: string enum: - Unconfined - RuntimeDefault - Localhost x-enum-varnames: - SeccompProfileTypeUnconfined - SeccompProfileTypeRuntimeDefault - SeccompProfileTypeLocalhost chaosactiontemplate.ChaosActionTemplate: type: object required: - accountID - isRemoved - name properties: accountID: type: string actionProperties: description: Needed for API response *not to be stored in DB* allOf: - $ref: '#/components/schemas/action.ActionTemplateProperties' createdAt: type: integer createdBy: type: string createdByUserDetails: $ref: '#/components/schemas/github_com_harness_hce-saas_graphql_server_graph_model.UserDetails' description: type: string hubRef: type: string id: type: string identity: description: 'Unique identifier (human-readable) immutable Initially it will be same as name' type: string infrastructureType: $ref: '#/components/schemas/actions.InfrastructureType' inputs: type: array items: $ref: '#/components/schemas/template.Variable' isDefault: description: 'isDefault indicates if it is the default version for predefined faults, latest should be set as default' type: boolean isEnterprise: type: boolean isRemoved: type: boolean name: description: 'Fault name to sync the changes from the hub HubRef + Name should be unique' type: string orgID: type: string projectID: type: string revision: description: it increments every time a new version of fault is published type: integer runProperties: $ref: '#/components/schemas/action.ActionTemplateRunProperties' tags: type: array items: type: string template: type: string type: $ref: '#/components/schemas/actions.ActionType' updatedAt: type: integer updatedBy: type: string updatedByUserDetails: $ref: '#/components/schemas/github_com_harness_hce-saas_graphql_server_graph_model.UserDetails' variables: description: CHAOS-11100 type: array items: $ref: '#/components/schemas/template.Variable' api.RestError: type: object properties: code: $ref: '#/components/schemas/api.ResponseErrorCode' description: type: string message: type: string common.RequiredNodeSelector: type: object properties: key: type: string operator: description: 'default: In' type: string values: type: string v1.HostPathVolumeSource: type: object properties: path: description: 'Path of the directory on the host. If the path is a symlink, it will follow the link to the real path. More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath' type: string type: description: 'Type for HostPath Volume Defaults to "" More info: https://kubernetes.io/docs/concepts/storage/volumes#hostpath +optional' allOf: - $ref: '#/components/schemas/v1.HostPathType' action.ENV: type: object properties: name: type: string value: type: string k8s_io_api_core_v1.EnvVar: type: object properties: name: description: Name of the environment variable. Must be a C_IDENTIFIER. type: string value: description: 'Variable references $(VAR_NAME) are expanded using the previous defined environment variables in the container and any service environment variables. If a variable cannot be resolved, the reference in the input string will be unchanged. The $(VAR_NAME) syntax can be escaped with a double $$, ie: $$(VAR_NAME). Escaped references will never be expanded, regardless of whether the variable exists or not. Defaults to "". +optional' type: string valueFrom: description: 'Source for the environment variable''s value. Cannot be used if value is not empty. +optional' allOf: - $ref: '#/components/schemas/v1.EnvVarSource' v1.EnvVarSource: type: object properties: configMapKeyRef: description: 'Selects a key of a ConfigMap. +optional' allOf: - $ref: '#/components/schemas/v1.ConfigMapKeySelector' fieldRef: description: 'Selects a field of the pod: supports metadata.name, metadata.namespace, `metadata.labels['''']`, `metadata.annotations['''']`, spec.nodeName, spec.serviceAccountName, status.hostIP, status.podIP, status.podIPs. +optional' allOf: - $ref: '#/components/schemas/v1.ObjectFieldSelector' resourceFieldRef: description: 'Selects a resource of the container: only resources limits and requests (limits.cpu, limits.memory, limits.ephemeral-storage, requests.cpu, requests.memory and requests.ephemeral-storage) are currently supported. +optional' allOf: - $ref: '#/components/schemas/v1.ResourceFieldSelector' secretKeyRef: description: 'Selects a key of a secret in the pod''s namespace +optional' allOf: - $ref: '#/components/schemas/v1.SecretKeySelector' v1.PullPolicy: type: string enum: - Always - Never - IfNotPresent x-enum-varnames: - PullAlways - PullNever - PullIfNotPresent v1.SeccompProfile: type: object properties: localhostProfile: description: 'localhostProfile indicates a profile defined in a file on the node should be used. The profile must be preconfigured on the node to work. Must be a descending path, relative to the kubelet''s configured seccomp profile location. Must only be set if type is "Localhost". +optional' type: string type: description: 'type indicates which kind of seccomp profile will be applied. Valid options are: Localhost - a profile defined in a file on the node should be used. RuntimeDefault - the container runtime default profile should be used. Unconfined - no profile should be applied. +unionDiscriminator' allOf: - $ref: '#/components/schemas/v1.SeccompProfileType' v1.Sysctl: type: object properties: name: description: Name of a property to set type: string value: description: Value of a property to set type: string template.InputCategory: type: string enum: - FaultTarget - FaultTunable - TargetInfra - ExperimentTunable - ActionProperties - ProbeProperties - RunProperties - FaultAuthentication x-enum-varnames: - CategoryFaultTarget - CategoryFaultTunable - CategoryTargetInfra - CategoryExperimentTunable - CategoryActionProperties - CategoryProbeProperties - CategoryRunProperties - CategoryFaultAuthentication v1.ProcMountType: type: string enum: - Default - Unmasked x-enum-varnames: - DefaultProcMount - UnmaskedProcMount v1.EmptyDirVolumeSource: type: object properties: medium: description: 'What type of storage medium should back this directory. The default is "" which means to use the node''s default medium. Must be an empty string (default) or Memory. More info: https://kubernetes.io/docs/concepts/storage/volumes#emptydir +optional' allOf: - $ref: '#/components/schemas/v1.StorageMedium' sizeLimit: description: 'Total amount of local storage required for this EmptyDir volume. The size limit is also applicable for memory medium. The maximum usage on memory medium EmptyDir would be the minimum value between the SizeLimit specified here and the sum of memory limits of all containers in a pod. The default is nil which means that the limit is undefined. More info: http://kubernetes.io/docs/user-guide/volumes#emptydir +optional' allOf: - $ref: '#/components/schemas/resource.Quantity' v1.Toleration: type: object properties: effect: description: 'Effect indicates the taint effect to match. Empty means match all taint effects. When specified, allowed values are NoSchedule, PreferNoSchedule and NoExecute. +optional' allOf: - $ref: '#/components/schemas/v1.TaintEffect' key: description: 'Key is the taint key that the toleration applies to. Empty means match all taint keys. If the key is empty, operator must be Exists; this combination means to match all values and all keys. +optional' type: string operator: description: 'Operator represents a key''s relationship to the value. Valid operators are Exists and Equal. Defaults to Equal. Exists is equivalent to wildcard for value, so that a pod can tolerate all taints of a particular category. +optional' allOf: - $ref: '#/components/schemas/v1.TolerationOperator' tolerationSeconds: description: 'TolerationSeconds represents the period of time the toleration (which must be of effect NoExecute, otherwise this field is ignored) tolerates the taint. By default, it is not set, which means tolerate the taint forever (do not evict). Zero and negative values will be treated as 0 (evict immediately) by the system. +optional' type: integer value: description: 'Value is the taint value the toleration matches to. If the operator is Exists, the value should be empty, otherwise just a regular string. +optional' type: string v1.PodSecurityContext: type: object properties: fsGroup: description: 'A special supplemental group that applies to all containers in a pod. Some volume types allow the Kubelet to change the ownership of that volume to be owned by the pod: 1. The owning GID will be the FSGroup 2. The setgid bit is set (new files created in the volume will be owned by FSGroup) 3. The permission bits are OR''d with rw-rw---- If unset, the Kubelet will not modify the ownership and permissions of any volume. +optional' type: integer fsGroupChangePolicy: description: 'fsGroupChangePolicy defines behavior of changing ownership and permission of the volume before being exposed inside Pod. This field will only apply to volume types which support fsGroup based ownership(and permissions). It will have no effect on ephemeral volume types such as: secret, configmaps and emptydir. Valid values are "OnRootMismatch" and "Always". If not specified, "Always" is used. +optional' allOf: - $ref: '#/components/schemas/v1.PodFSGroupChangePolicy' runAsGroup: description: 'The GID to run the entrypoint of the container process. Uses runtime default if unset. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. +optional' type: integer runAsNonRoot: description: 'Indicates that the container must run as a non-root user. If true, the Kubelet will validate the image at runtime to ensure that it does not run as UID 0 (root) and fail to start the container if it does. If unset or false, no such validation will be performed. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' type: boolean runAsUser: description: 'The UID to run the entrypoint of the container process. Defaults to user specified in image metadata if unspecified. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. +optional' type: integer seLinuxOptions: description: 'The SELinux context to be applied to all containers. If unspecified, the container runtime will allocate a random SELinux context for each container. May also be set in SecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence for that container. +optional' allOf: - $ref: '#/components/schemas/v1.SELinuxOptions' seccompProfile: description: 'The seccomp options to use by the containers in this pod. +optional' allOf: - $ref: '#/components/schemas/v1.SeccompProfile' supplementalGroups: description: 'A list of groups applied to the first process run in each container, in addition to the container''s primary GID. If unspecified, no groups will be added to any container. +optional' type: array items: type: integer sysctls: description: 'Sysctls hold a list of namespaced sysctls used for the pod. Pods with unsupported sysctls (by the container runtime) might fail to launch. +optional' type: array items: $ref: '#/components/schemas/v1.Sysctl' windowsOptions: description: 'The Windows specific settings applied to all containers. If unspecified, the options within a container''s SecurityContext will be used. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' allOf: - $ref: '#/components/schemas/v1.WindowsSecurityContextOptions' common.NodeAffinity: type: object properties: preferred: type: array items: $ref: '#/components/schemas/common.PreferredNodeSelector' required: type: array items: $ref: '#/components/schemas/common.RequiredNodeSelector' v1.ConfigMapKeySelector: type: object properties: key: description: The key to select. type: string name: description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid? +optional' type: string optional: description: 'Specify whether the ConfigMap or its key must be defined +optional' type: boolean action.DelayActionTemplate: type: object properties: duration: type: string v1.ObjectFieldSelector: type: object properties: apiVersion: description: 'Version of the schema the FieldPath is written in terms of, defaults to "v1". +optional' type: string fieldPath: description: Path of the field to select in the specified API version. type: string v1.ResourceFieldSelector: type: object properties: containerName: description: 'Container name: required for volumes, optional for env vars +optional' type: string divisor: description: 'Specifies the output format of the exposed resources, defaults to "1" +optional' allOf: - $ref: '#/components/schemas/resource.Quantity' resource: description: 'Required: resource to select' type: string chaosactiontemplate.ActionsTemplateCount: type: object properties: count: type: integer type: $ref: '#/components/schemas/actions.ActionType' v1.VolumeMount: type: object properties: mountPath: description: 'Path within the container at which the volume should be mounted. Must not contain '':''.' type: string mountPropagation: description: 'mountPropagation determines how mounts are propagated from the host to container and the other way around. When not set, MountPropagationNone is used. This field is beta in 1.10. +optional' allOf: - $ref: '#/components/schemas/v1.MountPropagationMode' name: description: This must match the Name of a Volume. type: string readOnly: description: 'Mounted read-only if true, read-write otherwise (false or unspecified). Defaults to false. +optional' type: boolean subPath: description: 'Path within the volume from which the container''s volume should be mounted. Defaults to "" (volume''s root). +optional' type: string subPathExpr: description: 'Expanded path within the volume from which the container''s volume should be mounted. Behaves similarly to SubPath but environment variable references $(VAR_NAME) are expanded using the container''s environment. Defaults to "" (volume''s root). SubPathExpr and SubPath are mutually exclusive. +optional' type: string common.Volume: type: object properties: configMap: $ref: '#/components/schemas/common.VolumeInputTemplate' emptyDir: $ref: '#/components/schemas/v1.EmptyDirVolumeSource' hostPath: $ref: '#/components/schemas/v1.HostPathVolumeSource' name: type: string persistentVolumeClaim: $ref: '#/components/schemas/v1.PersistentVolumeClaimVolumeSource' secret: $ref: '#/components/schemas/common.VolumeInputTemplate' type: $ref: '#/components/schemas/common.VolumeType' v1.WindowsSecurityContextOptions: type: object properties: gmsaCredentialSpec: description: 'GMSACredentialSpec is where the GMSA admission webhook (https://github.com/kubernetes-sigs/windows-gmsa) inlines the contents of the GMSA credential spec named by the GMSACredentialSpecName field. +optional' type: string gmsaCredentialSpecName: description: 'GMSACredentialSpecName is the name of the GMSA credential spec to use. +optional' type: string runAsUserName: description: 'The UserName in Windows to run the entrypoint of the container process. Defaults to the user specified in image metadata if unspecified. May also be set in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' type: string v1.PersistentVolumeClaimVolumeSource: type: object properties: claimName: description: 'ClaimName is the name of a PersistentVolumeClaim in the same namespace as the pod using this volume. More info: https://kubernetes.io/docs/concepts/storage/persistent-volumes#persistentvolumeclaims' type: string readOnly: description: 'Will force the ReadOnly setting in VolumeMounts. Default false. +optional' type: boolean action.ActionTemplateRunProperties: type: object properties: initialDelay: type: string interval: type: string maxRetries: {} stopOnFailure: type: boolean timeout: type: string verbosity: type: string common.VolumeInputTemplate: type: object properties: defaultMode: type: string items: type: object additionalProperties: type: string name: type: string optional: type: boolean v1.SecretKeySelector: type: object properties: key: description: The key of the secret to select from. Must be a valid secret key. type: string name: description: 'Name of the referent. More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names TODO: Add other useful fields. apiVersion, kind, uid? +optional' type: string optional: description: 'Specify whether the Secret or its key must be defined +optional' type: boolean v1.SELinuxOptions: type: object properties: level: description: 'Level is SELinux level label that applies to the container. +optional' type: string role: description: 'Role is a SELinux role label that applies to the container. +optional' type: string type: description: 'Type is a SELinux type label that applies to the container. +optional' type: string user: description: 'User is a SELinux user label that applies to the container. +optional' type: string common.ResourceRequirements: type: object properties: limits: type: object additionalProperties: type: string requests: type: object additionalProperties: type: string common.ContainerTemplate: type: object properties: affinity: $ref: '#/components/schemas/common.NodeAffinity' annotations: type: object additionalProperties: type: string args: type: string command: type: array items: type: string containerSecurityContext: $ref: '#/components/schemas/v1.SecurityContext' env: type: array items: $ref: '#/components/schemas/k8s_io_api_core_v1.EnvVar' hostIPC: type: boolean hostNetwork: type: boolean hostPID: type: boolean image: type: string imagePullPolicy: $ref: '#/components/schemas/v1.PullPolicy' imagePullSecrets: type: array items: type: string labels: type: object additionalProperties: type: string namespace: type: string nodeSelector: type: object additionalProperties: type: string podSecurityContext: $ref: '#/components/schemas/v1.PodSecurityContext' resources: $ref: '#/components/schemas/common.ResourceRequirements' serviceAccountName: type: string tolerations: type: array items: $ref: '#/components/schemas/v1.Toleration' volumeMounts: type: array items: $ref: '#/components/schemas/v1.VolumeMount' volumes: type: array items: $ref: '#/components/schemas/common.Volume' v1.SecurityContext: type: object properties: allowPrivilegeEscalation: description: 'AllowPrivilegeEscalation controls whether a process can gain more privileges than its parent process. This bool directly controls if the no_new_privs flag will be set on the container process. AllowPrivilegeEscalation is true always when the container is: 1) run as Privileged 2) has CAP_SYS_ADMIN +optional' type: boolean capabilities: description: 'The capabilities to add/drop when running containers. Defaults to the default set of capabilities granted by the container runtime. +optional' allOf: - $ref: '#/components/schemas/v1.Capabilities' privileged: description: 'Run container in privileged mode. Processes in privileged containers are essentially equivalent to root on the host. Defaults to false. +optional' type: boolean procMount: description: 'procMount denotes the type of proc mount to use for the containers. The default is DefaultProcMount which uses the container runtime defaults for readonly paths and masked paths. This requires the ProcMountType feature flag to be enabled. +optional' allOf: - $ref: '#/components/schemas/v1.ProcMountType' readOnlyRootFilesystem: description: 'Whether this container has a read-only root filesystem. Default is false. +optional' type: boolean runAsGroup: description: 'The GID to run the entrypoint of the container process. Uses runtime default if unset. May also be set in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' type: integer runAsNonRoot: description: 'Indicates that the container must run as a non-root user. If true, the Kubelet will validate the image at runtime to ensure that it does not run as UID 0 (root) and fail to start the container if it does. If unset or false, no such validation will be performed. May also be set in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' type: boolean runAsUser: description: 'The UID to run the entrypoint of the container process. Defaults to user specified in image metadata if unspecified. May also be set in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' type: integer seLinuxOptions: description: 'The SELinux context to be applied to the container. If unspecified, the container runtime will allocate a random SELinux context for each container. May also be set in PodSecurityContext. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' allOf: - $ref: '#/components/schemas/v1.SELinuxOptions' seccompProfile: description: 'The seccomp options to use by this container. If seccomp options are provided at both the pod & container level, the container options override the pod options. +optional' allOf: - $ref: '#/components/schemas/v1.SeccompProfile' windowsOptions: description: 'The Windows specific settings applied to all containers. If unspecified, the options from the PodSecurityContext will be used. If set in both SecurityContext and PodSecurityContext, the value specified in SecurityContext takes precedence. +optional' allOf: - $ref: '#/components/schemas/v1.WindowsSecurityContextOptions' v1.TolerationOperator: type: string enum: - Exists - Equal x-enum-varnames: - TolerationOpExists - TolerationOpEqual chaosfaulttemplate.ActionTemplate: type: object required: - name properties: actionProperties: $ref: '#/components/schemas/action.ActionTemplateProperties' description: type: string hubRef: type: string identity: type: string infrastructureType: $ref: '#/components/schemas/actions.InfrastructureType' inputs: type: array items: $ref: '#/components/schemas/template.Variable' isDefault: type: boolean name: type: string revision: type: integer runProperties: $ref: '#/components/schemas/action.ActionTemplateRunProperties' tags: type: array items: type: string type: type: string variables: description: CHAOS-11100 type: array items: $ref: '#/components/schemas/template.Variable' action.CustomScriptActionTemplate: type: object properties: args: type: array items: type: string command: type: string env: type: array items: $ref: '#/components/schemas/action.ENV' v1.HostPathType: type: string enum: - '' - DirectoryOrCreate - Directory - FileOrCreate - File - Socket - CharDevice - BlockDevice x-enum-varnames: - HostPathUnset - HostPathDirectoryOrCreate - HostPathDirectory - HostPathFileOrCreate - HostPathFile - HostPathSocket - HostPathCharDev - HostPathBlockDev github_com_harness_hce-saas_graphql_server_api.Pagination: type: object properties: index: type: integer limit: type: integer totalItems: type: integer totalPages: type: integer template.InputType: type: string enum: - String - Integer - Boolean - Number - SecretFile - SecretText x-enum-varnames: - StringInput - IntegerInput - BooleanInput - NumberInput - SecretFileInput - SecretTextInput v1.MountPropagationMode: type: string enum: - None - HostToContainer - Bidirectional x-enum-varnames: - MountPropagationNone - MountPropagationHostToContainer - MountPropagationBidirectional requestBodies: chaosfaulttemplate.ActionTemplate: content: application/json: schema: $ref: '#/components/schemas/chaosfaulttemplate.ActionTemplate' description: action configuration required: true securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks