openapi: 3.2.0 info: title: Harness Repositories API version: '1.0' description: The Harness Software Delivery Platform uses OpenAPI Specification v3.0. contact: name: API Support email: contact@harness.io url: https://harness.io/ x-logo: url: https://mma.prnewswire.com/media/779232/Harnes_logo_horizontal.jpg?p=facebook altText: Harness termsOfService: https://harness.io/terms-of-use/ servers: - url: https://app.harness.io description: Harness host URL - url: https://{vanity} description: Vanity URL variables: vanity: default: app.harness.io security: - x-api-key: [] tags: - name: Repositories description: Read APIs backing the STO Target Code Repositories page. paths: /gitops/api/v1/agents/{agentIdentifier}/repositories: get: summary: ListRepositories gets a list of all configured repositories description: ListRepositories gets a list of all configured repositories. operationId: AgentRepositoryService_ListRepositories responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRepositoryList' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string tags: - Repositories post: summary: CreateRepository creates a new repository configuration description: CreateRepository creates a new repository configuration. operationId: AgentRepositoryService_CreateRepository responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/servicev1Repository' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string - name: repoCredsId in: query required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoCreateRequest' required: true tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/eso/check: get: summary: Checks whether External Secrets Operator is installed description: CheckExternalSecretsOperator Checks whether External Secrets Operator is installed or not operationId: AgentRepositoryService_CheckExternalSecretsOperator responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesCheckESOResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/eso/generators: get: summary: Returns a list of ESO generators installed in agent namespace description: Returns a list of ESO generators installed in agent namespace. operationId: AgentRepositoryService_ListESOGenerators responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesESOGeneratorResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: type in: query required: false schema: type: string enum: - UNSET - AWS_ECR - GOOGLE_GCR default: UNSET - name: name in: query required: false schema: type: string - name: url in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/oci/type: post: summary: Returns the Repository type of OCI repo description: CheckOCIRepoType Returns the Repository type of OCI repo operationId: AgentRepositoryService_CheckOCIRepoType responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/v1OCIRepoTypeResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/v1OCIRepoType' required: true tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/validate: post: summary: ValidateAccess gets connection state for a repository description: ValidateAccess gets connection state for a repository. operationId: AgentRepositoryService_ValidateAccess responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/commonsConnectionState' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoAccessQuery' required: true tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/{identifier}: get: summary: Get returns a repository or its credentials description: Get returns a repository or its credentials. operationId: AgentRepositoryService_Get responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/servicev1Repository' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string tags: - Repositories delete: summary: DeleteRepository deletes a repository from the configuration description: DeleteRepository deletes a repository from the configuration. operationId: AgentRepositoryService_DeleteRepository responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string - name: forceDelete in: query required: false schema: type: boolean tags: - Repositories put: summary: UpdateRepository updates a repository configuration description: UpdateRepository updates a repository configuration. operationId: AgentRepositoryService_UpdateRepository responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/servicev1Repository' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string requestBody: content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoUpdateRequest' required: true tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/{identifier}/appdetails: get: summary: GetAppDetails returns application details by given path description: GetAppDetails returns application details by given path. operationId: AgentRepositoryService_GetAppDetails responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoAppDetailsResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: query.source.repoURL description: RepoURL is the URL to the repository (Git or Helm) that contains the application manifests. in: query required: false schema: type: string - name: query.source.path description: Path is a directory path within the Git repository, and is only valid for applications sourced from Git. in: query required: false schema: type: string - name: query.source.targetRevision description: 'TargetRevision defines the revision of the source to sync the application to. In case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD. In case of Helm, this is a semver tag for the Chart''s version.' in: query required: false schema: type: string - name: query.source.helm.valueFiles description: ValuesFiles is a list of Helm value files to use when generating a template. in: query required: false explode: true schema: type: array items: type: string - name: query.source.helm.releaseName description: ReleaseName is the Helm release name to use. If omitted it will use the application name. in: query required: false schema: type: string - name: query.source.helm.values description: Values specifies Helm values to be passed to helm template, typically defined as a block. in: query required: false schema: type: string - name: query.source.helm.version description: Version is the Helm version to use for templating (either "2" or "3"). in: query required: false schema: type: string - name: query.source.helm.passCredentials description: PassCredentials pass credentials to all domains (Helm's --pass-credentials). in: query required: false schema: type: boolean - name: query.source.helm.ignoreMissingValueFiles description: IgnoreMissingValueFiles prevents helm template from failing when valueFiles do not exist locally by not appending them to helm template --values. in: query required: false schema: type: boolean - name: query.source.helm.skipCrds description: SkipCrds skips custom resource definition installation step (Helm's --skip-crds). in: query required: false schema: type: boolean - name: query.source.helm.namespace description: Namespace is an optional namespace to template with. If left empty, defaults to the app's destination namespace. in: query required: false schema: type: string - name: query.source.helm.kubeVersion description: 'KubeVersion specifies the Kubernetes API version to pass to Helm when templating manifests. By default, Argo CD uses the Kubernetes version of the target cluster.' in: query required: false schema: type: string - name: query.source.helm.apiVersions description: 'APIVersions specifies the Kubernetes resource API versions to pass to Helm when templating manifests. By default, Argo CD uses the API versions of the target cluster. The format is [group/]version/kind.' in: query required: false explode: true schema: type: array items: type: string - name: query.source.helm.skipTests description: SkipTests skips test manifest installation step (Helm's --skip-tests). in: query required: false schema: type: boolean - name: query.source.helm.skipSchemaValidation description: SkipSchemaValidation skips JSON schema validation (Helm's --skip-schema-validation). in: query required: false schema: type: boolean - name: query.source.kustomize.namePrefix description: NamePrefix overrides the namePrefix in the kustomization.yaml for Kustomize apps. in: query required: false schema: type: string - name: query.source.kustomize.nameSuffix description: NameSuffix overrides the nameSuffix in the kustomization.yaml for Kustomize apps. in: query required: false schema: type: string - name: query.source.kustomize.images description: Images is a list of Kustomize image override specifications. in: query required: false explode: true schema: type: array items: type: string - name: query.source.kustomize.version description: Version controls which version of Kustomize to use for rendering manifests. in: query required: false schema: type: string - name: query.source.kustomize.forceCommonLabels description: ForceCommonLabels specifies whether to force applying common labels to resources for Kustomize apps. in: query required: false schema: type: boolean - name: query.source.kustomize.forceCommonAnnotations description: ForceCommonAnnotations specifies whether to force applying common annotations to resources for Kustomize apps. in: query required: false schema: type: boolean - name: query.source.kustomize.namespace description: Namespace sets the namespace that Kustomize adds to all resources. in: query required: false schema: type: string - name: query.source.kustomize.commonAnnotationsEnvsubst description: CommonAnnotationsEnvsubst specifies whether to apply env variables substitution for annotation values. in: query required: false schema: type: boolean - name: query.source.kustomize.components description: Components specifies a list of kustomize components to add to the kustomization before building. in: query required: false explode: true schema: type: array items: type: string - name: query.source.kustomize.labelWithoutSelector description: LabelWithoutSelector specifies whether to apply common labels to resource selectors or not. in: query required: false schema: type: boolean - name: query.source.kustomize.kubeVersion description: 'KubeVersion specifies the Kubernetes API version to pass to Helm when templating manifests. By default, Argo CD uses the Kubernetes version of the target cluster.' in: query required: false schema: type: string - name: query.source.kustomize.apiVersions description: 'APIVersions specifies the Kubernetes resource API versions to pass to Helm when templating manifests. By default, Argo CD uses the API versions of the target cluster. The format is [group/]version/kind.' in: query required: false explode: true schema: type: array items: type: string - name: query.source.kustomize.ignoreMissingComponents description: IgnoreMissingComponents prevents kustomize from failing when components do not exist locally by not appending them to kustomization file. in: query required: false schema: type: boolean - name: query.source.kustomize.labelIncludeTemplates description: LabelIncludeTemplates specifies whether to apply common labels to resource templates or not. in: query required: false schema: type: boolean - name: query.source.ksonnet.environment description: Environment is a ksonnet application environment name. in: query required: false schema: type: string - name: query.source.directory.recurse description: Recurse specifies whether to scan a directory recursively for manifests. in: query required: false schema: type: boolean - name: query.source.directory.jsonnet.libs description: Additional library search dirs. in: query required: false explode: true schema: type: array items: type: string - name: query.source.directory.exclude description: Exclude contains a glob pattern to match paths against that should be explicitly excluded from being used during manifest generation. in: query required: false schema: type: string - name: query.source.directory.include description: Include contains a glob pattern to match paths against that should be explicitly included during manifest generation. in: query required: false schema: type: string - name: query.source.plugin.name in: query required: false schema: type: string - name: query.source.chart description: Chart is a Helm chart name, and must be specified for applications sourced from a Helm repo. in: query required: false schema: type: string - name: query.source.ref description: Ref is reference to another source within sources field. This field will not be used if used with a `source` tag. in: query required: false schema: type: string - name: query.source.name description: Name is used to refer to a source and is displayed in the UI. It is used in multi-source Applications. in: query required: false schema: type: string - name: query.appName in: query required: false schema: type: string - name: query.appProject in: query required: false schema: type: string - name: query.sourceIndex description: source index (for multi source apps). in: query required: false schema: type: integer format: int32 - name: query.versionId description: versionId from historical data (for multi source apps). in: query required: false schema: type: integer format: int32 tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/{identifier}/apps: get: summary: ListApps returns list of apps in the repo description: ListApps returns list of apps in the repo. operationId: AgentRepositoryService_ListApps responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoAppsResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: query.repo in: query required: false schema: type: string - name: query.revision in: query required: false schema: type: string - name: query.appName in: query required: false schema: type: string - name: query.appProject in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/{identifier}/helmcharts: get: summary: GetHelmCharts returns list of helm charts in the specified repository description: GetHelmCharts returns list of helm charts in the specified repository. operationId: AgentRepositoryService_GetHelmCharts responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesHelmChartsResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories/{identifier}/refs: get: summary: Returns a list of refs (e.g. branches and tags) in the repo description: Returns a list of refs (e.g. branches and tags) in the repo. operationId: AgentRepositoryService_ListRefs responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRefs' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: identifier in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories_byurl/appdetails: get: summary: GetAppDetailsByUrl returns application details by given path for repositories… description: GetAppDetails returns application details by given path. operationId: AgentRepositoryService_GetAppDetailsByUrl responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoAppDetailsResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string - name: query.source.repoURL description: RepoURL is the URL to the repository (Git or Helm) that contains the application manifests. in: query required: false schema: type: string - name: query.source.path description: Path is a directory path within the Git repository, and is only valid for applications sourced from Git. in: query required: false schema: type: string - name: query.source.targetRevision description: 'TargetRevision defines the revision of the source to sync the application to. In case of Git, this can be commit, tag, or branch. If omitted, will equal to HEAD. In case of Helm, this is a semver tag for the Chart''s version.' in: query required: false schema: type: string - name: query.source.helm.valueFiles description: ValuesFiles is a list of Helm value files to use when generating a template. in: query required: false explode: true schema: type: array items: type: string - name: query.source.helm.releaseName description: ReleaseName is the Helm release name to use. If omitted it will use the application name. in: query required: false schema: type: string - name: query.source.helm.values description: Values specifies Helm values to be passed to helm template, typically defined as a block. in: query required: false schema: type: string - name: query.source.helm.version description: Version is the Helm version to use for templating (either "2" or "3"). in: query required: false schema: type: string - name: query.source.helm.passCredentials description: PassCredentials pass credentials to all domains (Helm's --pass-credentials). in: query required: false schema: type: boolean - name: query.source.helm.ignoreMissingValueFiles description: IgnoreMissingValueFiles prevents helm template from failing when valueFiles do not exist locally by not appending them to helm template --values. in: query required: false schema: type: boolean - name: query.source.helm.skipCrds description: SkipCrds skips custom resource definition installation step (Helm's --skip-crds). in: query required: false schema: type: boolean - name: query.source.helm.namespace description: Namespace is an optional namespace to template with. If left empty, defaults to the app's destination namespace. in: query required: false schema: type: string - name: query.source.helm.kubeVersion description: 'KubeVersion specifies the Kubernetes API version to pass to Helm when templating manifests. By default, Argo CD uses the Kubernetes version of the target cluster.' in: query required: false schema: type: string - name: query.source.helm.apiVersions description: 'APIVersions specifies the Kubernetes resource API versions to pass to Helm when templating manifests. By default, Argo CD uses the API versions of the target cluster. The format is [group/]version/kind.' in: query required: false explode: true schema: type: array items: type: string - name: query.source.helm.skipTests description: SkipTests skips test manifest installation step (Helm's --skip-tests). in: query required: false schema: type: boolean - name: query.source.helm.skipSchemaValidation description: SkipSchemaValidation skips JSON schema validation (Helm's --skip-schema-validation). in: query required: false schema: type: boolean - name: query.source.kustomize.namePrefix description: NamePrefix overrides the namePrefix in the kustomization.yaml for Kustomize apps. in: query required: false schema: type: string - name: query.source.kustomize.nameSuffix description: NameSuffix overrides the nameSuffix in the kustomization.yaml for Kustomize apps. in: query required: false schema: type: string - name: query.source.kustomize.images description: Images is a list of Kustomize image override specifications. in: query required: false explode: true schema: type: array items: type: string - name: query.source.kustomize.version description: Version controls which version of Kustomize to use for rendering manifests. in: query required: false schema: type: string - name: query.source.kustomize.forceCommonLabels description: ForceCommonLabels specifies whether to force applying common labels to resources for Kustomize apps. in: query required: false schema: type: boolean - name: query.source.kustomize.forceCommonAnnotations description: ForceCommonAnnotations specifies whether to force applying common annotations to resources for Kustomize apps. in: query required: false schema: type: boolean - name: query.source.kustomize.namespace description: Namespace sets the namespace that Kustomize adds to all resources. in: query required: false schema: type: string - name: query.source.kustomize.commonAnnotationsEnvsubst description: CommonAnnotationsEnvsubst specifies whether to apply env variables substitution for annotation values. in: query required: false schema: type: boolean - name: query.source.kustomize.components description: Components specifies a list of kustomize components to add to the kustomization before building. in: query required: false explode: true schema: type: array items: type: string - name: query.source.kustomize.labelWithoutSelector description: LabelWithoutSelector specifies whether to apply common labels to resource selectors or not. in: query required: false schema: type: boolean - name: query.source.kustomize.kubeVersion description: 'KubeVersion specifies the Kubernetes API version to pass to Helm when templating manifests. By default, Argo CD uses the Kubernetes version of the target cluster.' in: query required: false schema: type: string - name: query.source.kustomize.apiVersions description: 'APIVersions specifies the Kubernetes resource API versions to pass to Helm when templating manifests. By default, Argo CD uses the API versions of the target cluster. The format is [group/]version/kind.' in: query required: false explode: true schema: type: array items: type: string - name: query.source.kustomize.ignoreMissingComponents description: IgnoreMissingComponents prevents kustomize from failing when components do not exist locally by not appending them to kustomization file. in: query required: false schema: type: boolean - name: query.source.kustomize.labelIncludeTemplates description: LabelIncludeTemplates specifies whether to apply common labels to resource templates or not. in: query required: false schema: type: boolean - name: query.source.ksonnet.environment description: Environment is a ksonnet application environment name. in: query required: false schema: type: string - name: query.source.directory.recurse description: Recurse specifies whether to scan a directory recursively for manifests. in: query required: false schema: type: boolean - name: query.source.directory.jsonnet.libs description: Additional library search dirs. in: query required: false explode: true schema: type: array items: type: string - name: query.source.directory.exclude description: Exclude contains a glob pattern to match paths against that should be explicitly excluded from being used during manifest generation. in: query required: false schema: type: string - name: query.source.directory.include description: Include contains a glob pattern to match paths against that should be explicitly included during manifest generation. in: query required: false schema: type: string - name: query.source.plugin.name in: query required: false schema: type: string - name: query.source.chart description: Chart is a Helm chart name, and must be specified for applications sourced from a Helm repo. in: query required: false schema: type: string - name: query.source.ref description: Ref is reference to another source within sources field. This field will not be used if used with a `source` tag. in: query required: false schema: type: string - name: query.source.name description: Name is used to refer to a source and is displayed in the UI. It is used in multi-source Applications. in: query required: false schema: type: string - name: query.appName in: query required: false schema: type: string - name: query.appProject in: query required: false schema: type: string - name: query.sourceIndex description: source index (for multi source apps). in: query required: false schema: type: integer format: int32 - name: query.versionId description: versionId from historical data (for multi source apps). in: query required: false schema: type: integer format: int32 tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories_byurl/apps: get: summary: ListAppsByUrl returns list of apps in the repo description: ListApps returns list of apps in the repo. operationId: AgentRepositoryService_ListAppsByUrl responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRepoAppsResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string - name: query.repo in: query required: false schema: type: string - name: query.revision in: query required: false schema: type: string - name: query.appName in: query required: false schema: type: string - name: query.appProject in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories_byurl/helmcharts: get: summary: GetHelmChartsByUrl returns list of helm charts in the repository by URL description: GetHelmCharts returns list of helm charts in the specified repository. operationId: AgentRepositoryService_GetHelmChartsByUrl responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesHelmChartsResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repositories_byurl/refs: get: summary: Returns a list of refs (e.g. branches and tags) in the repo by URL description: Returns a list of refs (e.g. branches and tags) in the repo. operationId: AgentRepositoryService_ListRefsByUrl responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/repositoriesRefs' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: identifier in: query required: false schema: type: string - name: query.repo description: Repo URL for query. in: query required: false schema: type: string - name: query.forceRefresh description: Whether to force a cache refresh on repo's connection state. in: query required: false schema: type: boolean - name: query.project description: The associated project project. in: query required: false schema: type: string tags: - Repositories /gitops/api/v1/agents/{agentIdentifier}/repository_byurl: get: summary: Get a repository configured in gitops by URL from Harness description: Returns a repository by URL operationId: AgentRepositoryService_GetByUrl responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/v1RepoByUrlRespList' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: agentIdentifier description: Agent identifier for entity. in: path required: true schema: type: string - name: accountIdentifier description: Account Identifier for the Agent. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Agent. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Agent. in: query required: false schema: type: string - name: url description: URL by which to find the repository entity managed by agent. in: query required: false explode: true schema: type: array items: type: string - name: fetchScopePrefixedIdentifier description: Indicates whether the identifier of repo fetched must contain the harness scope prefix such (account./org.) in: query required: false schema: type: boolean tags: - Repositories /gitops/api/v1/repositories: get: summary: List Repositories by repository credential template description: ListRepositoriesByRepositoryCredentialTemplate lists Repositories by repositories credential template operationId: RepositoryService_ListRepositoriesByRepositoryCredentialTemplate responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/v1Repositorylist' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: repositoryCredentialURL in: query required: false schema: type: string - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: agentIdentifier description: Agent identifier for entity. in: query required: false schema: type: string - name: pageSize in: query required: false schema: type: integer format: int32 - name: pageIndex in: query required: false schema: type: integer format: int32 tags: - Repositories post: summary: List repositories description: ListRepositories retrieves a list of all configured repositories. operationId: RepositoryService_ListRepositories responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/v1Repositorylist' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' requestBody: content: application/json: schema: $ref: '#/components/schemas/v1RepoListReq' required: true tags: - Repositories /gitops/api/v1/repositories/exists: get: summary: Check if a repository exists description: Exists checks whether a repository with the given URL exists. operationId: RepositoryService_Exists responses: '200': description: A successful response. content: application/json: schema: type: boolean default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/gatewayruntimeError' parameters: - name: accountIdentifier description: Account Identifier for the Entity. in: query required: false schema: type: string - name: orgIdentifier description: Organization Identifier for the Entity. in: query required: false schema: type: string - name: projectIdentifier description: Project Identifier for the Entity. in: query required: false schema: type: string - name: agentIdentifier description: Agent identifier for entity. in: query required: false schema: type: string - name: url in: query required: false schema: type: string tags: - Repositories /sto/api/v2/repositories: x-internal: true get: description: List code repositories scoped to a project, served from target_summary joined with hierarchy_lookup. operationId: Repositories#ListRepositories parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Page number to fetch (starting from 0) example: 4 in: query name: page schema: default: 0 description: Page number to fetch (starting from 0) example: 4 format: int64 minimum: 0 type: integer - allowEmptyValue: true description: Number of results per page example: 50 in: query name: pageSize schema: default: 30 description: Number of results per page example: 50 format: int64 maximum: 100 minimum: 1 type: integer - allowEmptyValue: true description: Field to sort by. 'severity' sorts on the sum of open occurrence counts for critical, high, medium, and low only (CHML — same vulnerability total shown on the main page; info and unassigned are excluded). 'lastScanAt' sorts on the most recent scan timestamp. example: severity in: query name: sort schema: default: lastScanAt description: Field to sort by. 'severity' sorts on the sum of open occurrence counts for critical, high, medium, and low only (CHML — same vulnerability total shown on the main page; info and unassigned are excluded). 'lastScanAt' sorts on the most recent scan timestamp. enum: - severity - lastScanAt example: severity type: string - allowEmptyValue: true description: Sort direction. Defaults to DESC so that, under the default lastScanAt sort, the most recently scanned repositories appear first. example: DESC in: query name: order schema: default: DESC description: Sort direction. Defaults to DESC so that, under the default lastScanAt sort, the most recently scanned repositories appear first. enum: - ASC - DESC example: DESC type: string - allowEmptyValue: true description: Case-insensitive substring match on the repository (target) name. Empty/absent means no name filter. example: nodegoat in: query name: search schema: description: Case-insensitive substring match on the repository (target) name. Empty/absent means no name filter. example: nodegoat maxLength: 256 type: string - allowEmptyValue: true description: Keep repositories whose source is in this comma-separated set (IN). Values are matched as stored in target_summary (e.g. Github, Gitlab, Harness — same casing the UI sends). Empty/absent means no source filter. example: Github,Gitlab in: query name: source schema: description: Keep repositories whose source is in this comma-separated set (IN). Values are matched as stored in target_summary (e.g. Github, Gitlab, Harness — same casing the UI sends). Empty/absent means no source filter. example: Github,Gitlab maxLength: 1024 pattern: ^([^,]+(,[^,]+)*)?$ type: string - allowEmptyValue: true description: Keep repositories that have any of these comma-separated scan types (array overlap) against target_summary.scan_types. Empty/absent means no scan-type filter. Values are free text in the DB (e.g. SAST, SCA, DAST, SECRET, IAC, CONTAINER), so this is pattern-bounded rather than enum-constrained to avoid drift as new scan types are added. example: SAST,SCA in: query name: scanTypes schema: description: Keep repositories that have any of these comma-separated scan types (array overlap) against target_summary.scan_types. Empty/absent means no scan-type filter. Values are free text in the DB (e.g. SAST, SCA, DAST, SECRET, IAC, CONTAINER), so this is pattern-bounded rather than enum-constrained to avoid drift as new scan types are added. example: SAST,SCA maxLength: 256 pattern: ^([^,]+(,[^,]+)*)?$ type: string - allowEmptyValue: true description: Keep repositories with a non-zero occurrence count (>0) for any of these comma-separated severities — the same vulnerability count shown on the main page. Empty/absent means no severity filter. example: critical,high in: query name: severity schema: description: Keep repositories with a non-zero occurrence count (>0) for any of these comma-separated severities — the same vulnerability count shown on the main page. Empty/absent means no severity filter. example: critical,high pattern: ^((critical|high|medium|low|info|unassigned)(,(critical|high|medium|low|info|unassigned))*)?$ type: string responses: '200': content: application/json: example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo schema: $ref: '#/components/schemas/RepositoriesListRepositoriesResponseBody' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_testtarget_view summary: List code repositories tags: - Repositories /sto/api/v2/repositories/{targetId}/variants: x-internal: true get: description: List Target Variants scanned for a repository (only variants with at least one scan are returned), ordered by most-recent scan. Optional search filter matches variant name (case-insensitive substring) or exact variant id — backs the baseline-picker default list and typeahead. operationId: Repositories#ListRepositoryVariants parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - description: Associated Target ID example: abcdef1234567890ghijkl in: path name: targetId required: true schema: description: Associated Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: 'Optional filter: case-insensitive substring match on the variant name (parameters->>''variant''), OR an exact match on the variant id. Empty/absent returns all scanned variants for the target.' example: mai in: query name: search schema: description: 'Optional filter: case-insensitive substring match on the variant name (parameters->>''variant''), OR an exact match on the variant id. Empty/absent returns all scanned variants for the target.' example: mai maxLength: 256 type: string - allowEmptyValue: true description: Page number to fetch (starting from 0) example: 4 in: query name: page schema: default: 0 description: Page number to fetch (starting from 0) example: 4 format: int64 minimum: 0 type: integer - allowEmptyValue: true description: Number of results per page. Defaults to 10 for this endpoint (baseline-picker/variant typeahead). example: 50 in: query name: pageSize schema: default: 10 description: Number of results per page. Defaults to 10 for this endpoint (baseline-picker/variant typeahead). example: 50 format: int64 maximum: 100 minimum: 1 type: integer responses: '200': content: application/json: example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl schema: $ref: '#/components/schemas/RepositoriesListRepositoryVariantsResponseBody' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_testtarget_view summary: List a repository's scanned variants tags: - Repositories /sto/api/v2/repositories/overview: x-internal: true get: description: 'Aggregate widgets for the Target Code Repositories page (UI 3.0): total repositories, source breakdown, baseline set count and vulnerability totals. Single-table aggregates over target_summary.' operationId: Repositories#RepositoriesOverview parameters: - allowEmptyValue: true description: Harness Account ID example: abcdef1234567890ghijkl in: query name: accountId required: true schema: description: Harness Account ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ type: string - allowEmptyValue: true description: Harness Organization ID example: example_org in: query name: orgId required: true schema: description: Harness Organization ID example: example_org maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string - allowEmptyValue: true description: Harness Project ID example: example_project in: query name: projectId required: true schema: description: Harness Project ID example: example_project maxLength: 128 pattern: ^[A-Za-z_][A-Za-z0-9_]*$ type: string responses: '200': content: application/json: example: baselineSet: 90 issueSeverityDeltas: critical: -2 high: 1 info: 0 low: -5 medium: 0 unassigned: 0 issueSeverityTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityDeltas: critical: -2 high: 1 info: 0 low: -5 medium: 0 unassigned: 0 occurrenceSeverityTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 sourceBreakdown: - count: 42 source: Github - count: 42 source: Github - count: 42 source: Github - count: 42 source: Github totalRepositories: 128 schema: $ref: '#/components/schemas/RepositoriesOverviewResult' description: OK response. '400': content: application/json: example: message: 'Bad Request: accountId parameter is required' status: 400 schema: $ref: '#/components/schemas/NotFound' description: 'BadRequest: Bad Request response.' '401': content: application/json: example: message: Unauthorized status: 401 schema: $ref: '#/components/schemas/NotFound' description: 'Unauthorized: Unauthorized response.' '403': content: application/json: example: message: Forbidden status: 403 schema: $ref: '#/components/schemas/NotFound' description: 'Forbidden: Forbidden response.' '404': content: application/json: example: message: Not Found status: 404 schema: $ref: '#/components/schemas/NotFound' description: 'NotFound: Not Found response.' '429': content: application/json: example: message: Too Many Requests status: 429 schema: $ref: '#/components/schemas/NotFound' description: 'TooManyRequests: Too Many Requests response.' '500': content: application/json: example: message: Internal Server Error status: 500 schema: $ref: '#/components/schemas/NotFound' description: 'InternalServerError: Internal Server Error response.' security: - jwt_header_Authorization: - sto_testtarget_view summary: Get repositories overview tags: - Repositories components: schemas: repositoriesRepoUpdateRequest: type: object properties: repo: $ref: '#/components/schemas/repositoriesRepository' updateMask: $ref: '#/components/schemas/protobufFieldMask' genType: $ref: '#/components/schemas/repositoriesESOGeneratorType' ecrGen: $ref: '#/components/schemas/repositoriesECRAuthorizationTokenGenerator' gcrGen: $ref: '#/components/schemas/repositoriesGCRAccessTokenGenerator' refreshInterval: type: string description: refreshInterval in format 1s, 1m, 1h... repositoriesRepoResponse: type: object applicationsHelmParameter: type: object properties: name: type: string title: Name is the name of the Helm parameter value: type: string title: Value is the value for the Helm parameter forceString: type: boolean title: ForceString determines whether to tell Helm to interpret booleans and numbers as strings title: HelmParameter is a parameter that's passed to helm template during manifest generation RepositorySourceBreakdownItem: type: object properties: count: type: integer description: Number of repositories with this source example: 42 format: int64 minimum: 0 source: type: string description: Source value as stored in target_summary (e.g. Github, Gitlab, Harness) example: Github description: Repository count for a single source (one GROUP BY source bucket). example: count: 42 source: Github required: - source - count repositoriesESOGeneratorType: type: string enum: - UNSET - AWS_ECR - GOOGLE_GCR default: UNSET repositoriesHelmChart: type: object properties: name: type: string versions: type: array items: type: string repositoriesAWSSecretRef: type: object properties: awsAccessKeyID: type: string awsSecretAccessKey: type: string awsSessionToken: type: string v1Repositorylist: type: object properties: content: type: array items: $ref: '#/components/schemas/servicev1Repository' totalPages: type: integer format: int32 totalItems: type: integer format: int32 pageItemCount: type: integer format: int32 pageSize: type: integer format: int32 pageIndex: type: integer format: int32 empty: type: boolean v1RepoListReq: type: object properties: accountIdentifier: type: string description: Account Identifier for the Entity. projectIdentifier: type: string description: Project Identifier for the Entity. orgIdentifier: type: string description: Organization Identifier for the Entity. agentIdentifier: type: string description: Agent identifier for entity. searchTerm: type: string pageSize: type: integer format: int32 pageIndex: type: integer format: int32 filter: type: object description: 'Filters for Repositories. Eg. "identifier": { "$in": ["id1", "id2"]' sortBy: $ref: '#/components/schemas/RepoListReqRepoSortByOptions' sortOrder: $ref: '#/components/schemas/v1SortOrderOptions' inheritedCreds: type: boolean includeChildScopes: type: boolean v1RepoByUrlRespList: type: object properties: repository: type: array items: $ref: '#/components/schemas/servicev1Repository' v1SortOrderOptions: type: string enum: - SORT_ORDER_NOT_SET - ASC - DESC default: SORT_ORDER_NOT_SET v1ListMeta: type: object properties: selfLink: type: string title: 'Deprecated: selfLink is a legacy read-only field that is no longer populated by the system. +optional' resourceVersion: type: string title: 'String that identifies the server''s internal version of this object that can be used by clients to determine when objects have changed. Value must be treated as opaque by clients and passed unmodified back to the server. Populated by the system. Read-only. More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#concurrency-control-and-consistency +optional' continue: type: string description: 'continue may be set if the user set a limit on the number of items returned, and indicates that the server has more data available. The value is opaque and may be used to issue another request to the endpoint that served this list to retrieve the next set of available objects. Continuing a consistent list may not be possible if the server configuration has changed or more than a few minutes have passed. The resourceVersion field returned when using this continue value will be identical to the value in the first response, unless you have received this token from an error message.' remainingItemCount: type: string format: int64 title: 'remainingItemCount is the number of subsequent items in the list which are not included in this list response. If the list request contained label or field selectors, then the number of remaining items is unknown and the field will be left unset and omitted during serialization. If the list is complete (either because it is not chunking or because this is the last chunk), then there are no more remaining items and this field will be left unset and omitted during serialization. Servers older than v1.15 do not set this field. The intended use of the remainingItemCount is *estimating* the size of a collection. Clients should not rely on the remainingItemCount to be set or to be exact. +optional' description: 'ListMeta describes metadata that synthetic resources must have, including lists and various status objects. A resource may have only one of {ObjectMeta, ListMeta}.' applicationsKsonnetParameter: type: object properties: component: type: string name: type: string value: type: string title: KsonnetParameter is a ksonnet component parameter repositoriesDirectoryAppSpec: type: object title: DirectoryAppSpec contains directory repositoriesHelmChartsResponse: type: object properties: items: type: array items: $ref: '#/components/schemas/repositoriesHelmChart' RepositorySeverityCounts: type: object properties: critical: type: integer description: Critical severity count example: 3 format: int64 minimum: 0 high: type: integer description: High severity count example: 4 format: int64 minimum: 0 info: type: integer description: Info severity count example: 1 format: int64 minimum: 0 low: type: integer description: Low severity count example: 2 format: int64 minimum: 0 medium: type: integer description: Medium severity count example: 5 format: int64 minimum: 0 unassigned: type: integer description: Unassigned severity count example: 0 format: int64 minimum: 0 description: Counts by severity, sourced from target_summary. example: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 required: - critical - high - medium - low - info - unassigned servicev1Repository: type: object properties: accountIdentifier: type: string description: Account Identifier for the Entity. orgIdentifier: type: string description: Organization Identifier for the Entity. projectIdentifier: type: string description: Project Identifier for the Entity. agentIdentifier: type: string description: Agent identifier for entity. identifier: type: string repository: $ref: '#/components/schemas/repositoriesRepository' createdAt: type: string format: date-time lastModifiedAt: type: string format: date-time stale: type: boolean repositoryCredentialsId: type: string repositoriesServiceAccountSelector: type: object properties: name: type: string namespace: type: string audiences: type: array items: type: string repositoriesCheckESOResponse: type: object properties: esoPresent: type: boolean RepositoriesOverviewResult: type: object properties: baselineSet: type: integer description: COUNT(*) FILTER (WHERE is_baseline) — repositories that have a baseline variant set example: 90 format: int64 minimum: 0 issueSeverityDeltas: $ref: '#/components/schemas/RepositorySeverityDeltas' issueSeverityTotals: $ref: '#/components/schemas/RepositorySeverityCounts' occurrenceSeverityDeltas: $ref: '#/components/schemas/RepositorySeverityDeltas' occurrenceSeverityTotals: $ref: '#/components/schemas/RepositorySeverityCounts' sourceBreakdown: type: array items: $ref: '#/components/schemas/RepositorySourceBreakdownItem' description: Repository counts grouped by source example: - count: 42 source: Github - count: 42 source: Github totalRepositories: type: integer description: COUNT(*) of repositories in scope example: 128 format: int64 minimum: 0 description: Aggregate widgets for the Target Code Repositories page (UI 3.0). example: baselineSet: 90 issueSeverityDeltas: critical: -2 high: 1 info: 0 low: -5 medium: 0 unassigned: 0 issueSeverityTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 occurrenceSeverityDeltas: critical: -2 high: 1 info: 0 low: -5 medium: 0 unassigned: 0 occurrenceSeverityTotals: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 sourceBreakdown: - count: 42 source: Github - count: 42 source: Github totalRepositories: 128 required: - totalRepositories - sourceBreakdown - baselineSet - occurrenceSeverityTotals - issueSeverityTotals StoRepository: type: object properties: id: type: string description: Target id example: abcdef1234567890ghijkl isBaseline: type: boolean description: Whether this variant is the repository's baseline (target_summary.is_baseline). example: true issueSeverityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' lastScanAt: type: integer description: Timestamp of the most recent scan, in milliseconds since Unix epoch (no server-side formatting; the UI formats it). Sortable. Null when the repository has never been scanned. example: 1751793300000 format: int64 name: type: string description: Repository (target) name example: NodeGoat occurrenceSeverityCounts: $ref: '#/components/schemas/RepositorySeverityCounts' scanType: type: object description: 'Scan types present for this repository mapped to the scanners that produced them, from target_summary.scan_type_scanners (e.g. {"SAST": ["bandit"], "SCA": ["snyk"]}). Keys are the distinct scan types; the UI derives the scan-type count and any display label from them.' example: SAST: - bandit SCA: - snyk - twistlock additionalProperties: type: array items: type: string example: Eveniet sequi rerum. example: - Eos quia sit recusandae porro. - Sit sequi debitis similique. - Quis qui rerum voluptate. - Molestiae vero. source: type: string description: Origin/source of the repository (e.g. the SCM integration). Filterable via the source filter. Stored and returned with UI casing (e.g. Github, Gitlab, Harness). Null when target_summary.source is not set. example: Github maxLength: 256 targetName: type: string description: Variant name — target_summary.variant_name for this row (e.g. branch name). Null when not set. example: main targetVariantId: type: string description: Target variant id — target_summary.variant_id for this row. Null when not set. example: abcdef1234567890ghijkl url: type: string description: Repository URL (the git clone/browse URL). Sourced from the chosen variant's last scan's git_metadata.RepositoryHTTP when available (the URL the scanner actually cloned), falling back to target.url. Null when neither is set. target_summary does not store it, so it is joined in from target/scan. example: https://github.com/example/repo maxLength: 1024 description: A code repository target as shown on the Target Code Repositories page (UI 3.0). example: id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo required: - id - name - scanType - occurrenceSeverityCounts - issueSeverityCounts repositoriesRepositoryList: type: object properties: metadata: $ref: '#/components/schemas/v1ListMeta' items: type: array items: $ref: '#/components/schemas/repositoriesRepository' description: RepositoryList is a collection of Repositories. repositoriesAppInfo: type: object properties: type: type: string path: type: string title: AppInfo contains application type and app file path repositoriesRepository: type: object properties: repo: type: string title: Repo contains the URL to the remote repository username: type: string title: Username contains the user name used for authenticating at the remote repository password: type: string title: Password contains the password or PAT used for authenticating at the remote repository sshPrivateKey: type: string description: SSHPrivateKey contains the PEM data for authenticating at the repo server. Only used with Git repos. connectionState: $ref: '#/components/schemas/commonsConnectionState' insecureIgnoreHostKey: type: boolean title: 'InsecureIgnoreHostKey should not be used anymore, Insecure is favoured Used only for Git repos' insecure: type: boolean title: Insecure specifies whether the connection to the repository ignores any errors when verifying TLS certificates or SSH host keys enableLfs: type: boolean description: EnableLFS specifies whether git-lfs support should be enabled for this repo. Only valid for Git repositories. tlsClientCertData: type: string title: TLSClientCertData contains a certificate in PEM format for authenticating at the repo server tlsClientCertKey: type: string title: TLSClientCertKey contains a private key in PEM format for authenticating at the repo server type: type: string description: Type specifies the type of the repo. Can be either "git" or "helm. "git" is assumed if empty or absent. name: type: string title: Name specifies a name to be used for this repo. Only used with Helm repos inheritedCreds: type: boolean title: Whether credentials were inherited from a credential set enableOCI: type: boolean title: EnableOCI specifies whether helm-oci support should be enabled for this repo githubAppPrivateKey: type: string title: Github App Private Key PEM data githubAppID: type: string format: int64 title: GithubAppId specifies the ID of the GitHub app used to access the repo githubAppInstallationID: type: string format: int64 title: GithubAppInstallationId specifies the installation ID of the GitHub App used to access the repo githubAppEnterpriseBaseUrl: type: string title: GithubAppEnterpriseBaseURL specifies the base URL of GitHub Enterprise installation. If empty will default to https://api.github.com proxy: type: string title: Proxy specifies the HTTP/HTTPS proxy used to access the repo project: type: string title: Reference between project and repository that allow you automatically to be added as item inside SourceRepos project entity connectionType: type: string title: Identifies the authentication method used to connect to the repository forceHttpBasicAuth: type: boolean title: ForceHttpBasicAuth specifies whether Argo CD should attempt to force basic auth for HTTP connections noProxy: type: string title: NoProxy specifies a list of targets where the proxy isn't used, applies only in cases where the proxy is applied useAzureWorkloadIdentity: type: boolean title: UseAzureWorkloadIdentity specifies whether to use Azure Workload Identity for authentication bearerToken: type: string title: BearerToken contains the bearer token used for Git BitBucket Data Center auth at the repo server insecureOCIForceHttp: type: boolean description: InsecureOCIForceHttp specifies whether the connection to the repository uses TLS at _all_. If true, no TLS. This flag is applicable for OCI repos only. depth: type: string format: int64 description: Depth specifies the depth for shallow clones. A value of 0 or omitting the field indicates a full clone. title: Repository is a repository holding application configurations repositoriesKsonnetAppSpec: type: object properties: name: type: string environments: type: object additionalProperties: $ref: '#/components/schemas/repositoriesKsonnetEnvironment' parameters: type: array items: $ref: '#/components/schemas/applicationsKsonnetParameter' title: 'KsonnetAppSpec contains Ksonnet app response This roughly reflects: ksonnet/ksonnet/metadata/app/schema.go' repositoriesGCRWorkloadIdentity: type: object properties: serviceAccountRef: $ref: '#/components/schemas/repositoriesServiceAccountSelector' clusterLocation: type: string clusterName: type: string clusterProjectID: type: string commonsConnectionState: type: object properties: status: type: string title: Status contains the current status indicator for the connection message: type: string title: Message contains human readable information about the connection status attemptedAt: $ref: '#/components/schemas/v1Time' attemptedAtTs: type: string format: date-time title: attemptedAtTs is the google timestamp variation of attemptedAt title: ConnectionState contains information about remote resource connection state, currently used for clusters and repositories RepositoriesListRepositoryVariantsResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/TargetVariant' example: - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl - created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl required: - results - pagination StoPagination: type: object properties: link: type: string description: Link-based paging example: '' page: type: integer description: Page number (starting from 0) example: 4 format: int64 pageSize: type: integer description: Requested page size example: 20 format: int64 totalItems: type: integer description: Total results available example: 230 format: int64 totalPages: type: integer description: Total pages available example: 12 format: int64 example: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 required: - page - pageSize - totalPages - totalItems RepositoriesListRepositoriesResponseBody: type: object properties: pagination: $ref: '#/components/schemas/StoPagination' results: type: array items: $ref: '#/components/schemas/StoRepository' example: - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo example: pagination: link: '' page: 4 pageSize: 20 totalItems: 230 totalPages: 12 results: - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo - id: abcdef1234567890ghijkl isBaseline: true issueSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 lastScanAt: 1751793300000 name: NodeGoat occurrenceSeverityCounts: critical: 3 high: 4 info: 1 low: 2 medium: 5 unassigned: 0 scanType: SAST: - bandit SCA: - snyk - twistlock source: Github targetName: main targetVariantId: abcdef1234567890ghijkl url: https://github.com/example/repo required: - results - pagination repositoriesRefs: type: object properties: branches: type: array items: type: string tags: type: array items: type: string title: A subset of the repository's named refs RepositorySeverityDeltas: type: object properties: critical: type: integer description: Change in critical count example: -2 format: int64 high: type: integer description: Change in high count example: 1 format: int64 info: type: integer description: Change in info count example: 0 format: int64 low: type: integer description: Change in low count example: -5 format: int64 medium: type: integer description: Change in medium count example: 0 format: int64 unassigned: type: integer description: Change in unassigned count example: 0 format: int64 description: Change in counts by severity since the last UTC 12:00 AM snapshot. Positive means increased, negative means decreased. example: critical: -2 high: 1 info: 0 low: -5 medium: 0 unassigned: 0 required: - critical - high - medium - low - info - unassigned NotFound: type: object properties: message: type: string example: Not Found status: type: integer default: 404 example: 404 format: int64 example: message: Not Found status: 404 required: - message protobufAny: type: object properties: type_url: type: string description: "A URL/resource name that uniquely identifies the type of the serialized\nprotocol buffer message. This string must contain at least\none \"/\" character. The last segment of the URL's path must represent\nthe fully qualified name of the type (as in\n`path/google.protobuf.Duration`). The name should be in a canonical form\n(e.g., leading \".\" is not accepted).\n\nIn practice, teams usually precompile into the binary all types that they\nexpect it to use in the context of Any. However, for URLs which use the\nscheme `http`, `https`, or no scheme, one can optionally set up a type\nserver that maps type URLs to message definitions as follows:\n\n* If no scheme is provided, `https` is assumed.\n* An HTTP GET on the URL must yield a [google.protobuf.Type][]\n value in binary format, or produce an error.\n* Applications are allowed to cache lookup results based on the\n URL, or have them precompiled into a binary to avoid any\n lookup. Therefore, binary compatibility needs to be preserved\n on changes to types. (Use versioned type names to manage\n breaking changes.)\n\nNote: this functionality is not currently available in the official\nprotobuf release, and it is not used for type URLs beginning with\ntype.googleapis.com. As of May 2023, there are no widely used type server\nimplementations and no plans to implement one.\n\nSchemes other than `http`, `https` (or the empty scheme) might be\nused with implementation specific semantics." value: type: string format: byte description: Must be a valid serialized protocol buffer of the above specified type. description: "`Any` contains an arbitrary serialized protocol buffer message along with a\nURL that describes the type of the serialized message.\n\nProtobuf library provides support to pack/unpack Any values in the form\nof utility functions or additional generated methods of the Any type.\n\nExample 1: Pack and unpack a message in C++.\n\n Foo foo = ...;\n Any any;\n any.PackFrom(foo);\n ...\n if (any.UnpackTo(&foo)) {\n ...\n }\n\nExample 2: Pack and unpack a message in Java.\n\n Foo foo = ...;\n Any any = Any.pack(foo);\n ...\n if (any.is(Foo.class)) {\n foo = any.unpack(Foo.class);\n }\n // or ...\n if (any.isSameTypeAs(Foo.getDefaultInstance())) {\n foo = any.unpack(Foo.getDefaultInstance());\n }\n\n Example 3: Pack and unpack a message in Python.\n\n foo = Foo(...)\n any = Any()\n any.Pack(foo)\n ...\n if any.Is(Foo.DESCRIPTOR):\n any.Unpack(foo)\n ...\n\n Example 4: Pack and unpack a message in Go\n\n foo := &pb.Foo{...}\n any, err := anypb.New(foo)\n if err != nil {\n ...\n }\n ...\n foo := &pb.Foo{}\n if err := any.UnmarshalTo(foo); err != nil {\n ...\n }\n\nThe pack methods provided by protobuf library will by default use\n'type.googleapis.com/full.type.name' as the type URL and the unpack\nmethods only use the fully qualified type name after the last '/'\nin the type URL, for example \"foo.bar.com/x/y.z\" will yield type\nname \"y.z\".\n\nJSON\n====\nThe JSON representation of an `Any` value uses the regular\nrepresentation of the deserialized, embedded message, with an\nadditional field `@type` which contains the type URL. Example:\n\n package google.profile;\n message Person {\n string first_name = 1;\n string last_name = 2;\n }\n\n {\n \"@type\": \"type.googleapis.com/google.profile.Person\",\n \"firstName\": ,\n \"lastName\": \n }\n\nIf the embedded message type is well-known and has a custom JSON\nrepresentation, that representation will be embedded adding a field\n`value` which holds the custom JSON in addition to the `@type`\nfield. Example (for message [google.protobuf.Duration][]):\n\n {\n \"@type\": \"type.googleapis.com/google.protobuf.Duration\",\n \"value\": \"1.212s\"\n }" repositoriesRepoCreateRequest: type: object properties: repo: $ref: '#/components/schemas/repositoriesRepository' upsert: type: boolean title: Whether to create in upsert mode credsOnly: type: boolean title: Whether to operate on credential set instead of repository genType: $ref: '#/components/schemas/repositoriesESOGeneratorType' ecrGen: $ref: '#/components/schemas/repositoriesECRAuthorizationTokenGenerator' gcrGen: $ref: '#/components/schemas/repositoriesGCRAccessTokenGenerator' refreshInterval: type: string description: refreshInterval in format 1s, 1m, 1h... title: RepoCreateRequest is a request for creating repository config v1OCIRepoTypeResponse: type: object properties: ociRepoType: $ref: '#/components/schemas/OCIRepoTypeResponseOCIRepoTypeEnum' repositoriesGCRAccessTokenGenerator: type: object properties: projectID: type: string accessKey: type: string workloadIdentity: $ref: '#/components/schemas/repositoriesGCRWorkloadIdentity' repositoriesKsonnetEnvironmentDestination: type: object properties: server: type: string description: Server is the Kubernetes server that the cluster is running on. namespace: type: string title: Namespace is the namespace of the Kubernetes server that targets should be deployed to repositoriesRepoAppsResponse: type: object properties: items: type: array items: $ref: '#/components/schemas/repositoriesAppInfo' title: RepoAppsResponse contains applications of specified repository repositoriesHelmAppSpec: type: object properties: name: type: string valueFiles: type: array items: type: string parameters: type: array items: $ref: '#/components/schemas/applicationsHelmParameter' title: the output of `helm inspect values` values: type: string title: the contents of values.yaml fileParameters: type: array items: $ref: '#/components/schemas/applicationsHelmFileParameter' title: helm file parameters title: HelmAppSpec contains helm app name in source repo repositoriesECRAuthorizationTokenGenerator: type: object properties: region: type: string secretRef: $ref: '#/components/schemas/repositoriesAWSSecretRef' jwtAuth: $ref: '#/components/schemas/repositoriesServiceAccountSelector' role: type: string description: ECRAuthorizationTokenSpec represents externalSecret for ECR External Secret Operator generator. OCIRepoTypeResponseOCIRepoTypeEnum: type: string enum: - UNSET - AWS - GOOGLE - GITHUB - DOCKERHUB default: UNSET repositoriesRepoAppDetailsResponse: type: object properties: type: type: string ksonnet: $ref: '#/components/schemas/repositoriesKsonnetAppSpec' helm: $ref: '#/components/schemas/repositoriesHelmAppSpec' kustomize: $ref: '#/components/schemas/repositoriesKustomizeAppSpec' directory: $ref: '#/components/schemas/repositoriesDirectoryAppSpec' title: RepoAppDetailsResponse application details v1OCIRepoType: type: object properties: repoURL: type: string description: OCI Repository URL. gatewayruntimeError: type: object properties: error: type: string code: type: integer format: int32 message: type: string details: type: array items: $ref: '#/components/schemas/protobufAny' TargetVariant: type: object properties: created: type: integer description: Unix timestamp at which the resource was created example: 1651578240 format: int64 hash: type: string description: Git Commit or Container Image hash example: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef maxLength: 64 id: type: string description: Resource identifier example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ lastModified: type: integer description: Unix timestamp at which the resource was most recently modified example: 1651578240 format: int64 parameters: type: object description: Parameters for this Variant, as a JSON-encoded string example: branch: main additionalProperties: type: string example: Rerum qui aliquid laboriosam atque eligendi. targetId: type: string description: Associated Target ID example: abcdef1234567890ghijkl pattern: ^[a-zA-Z0-9_-]{22}$ description: Information about a Scan Target Variant example: created: 1651578240 hash: deadbeefdeadbeefdeadbeefdeadbeefdeadbeef id: abcdef1234567890ghijkl lastModified: 1651578240 parameters: branch: main targetId: abcdef1234567890ghijkl required: - targetId - parameters - id - created - lastModified repositoriesKustomizeAppSpec: type: object properties: images: type: array items: type: string description: images is a list of available images. title: KustomizeAppSpec contains kustomize images repositoriesRepoAccessQuery: type: object properties: repo: type: string title: The URL to the repo username: type: string title: Username for accessing repo password: type: string title: Password for accessing repo sshPrivateKey: type: string title: Private key data for accessing SSH repository insecure: type: boolean title: Whether to skip certificate or host key validation tlsClientCertData: type: string title: TLS client cert data for accessing HTTPS repository tlsClientCertKey: type: string title: TLS client cert key for accessing HTTPS repository type: type: string title: The type of the repo name: type: string title: The name of the repo enableOci: type: boolean title: Whether helm-oci support should be enabled for this repo githubAppPrivateKey: type: string title: Github App Private Key PEM data githubAppID: type: string format: int64 title: Github App ID of the app used to access the repo githubAppInstallationID: type: string format: int64 title: Github App Installation ID of the installed GitHub App githubAppEnterpriseBaseUrl: type: string title: Github App Enterprise base url if empty will default to https://api.github.com proxy: type: string title: HTTP/HTTPS proxy to access the repository project: type: string title: Reference between project and repository that allow you automatically to be added as item inside SourceRepos project entity connectionType: type: string title: Connection type of the repository updateMask: $ref: '#/components/schemas/protobufFieldMask' title: RepoAccessQuery is a query for checking access to a repo protobufFieldMask: type: object properties: paths: type: array items: type: string description: The set of field mask paths. description: "paths: \"f.a\"\n paths: \"f.b.d\"\n\nHere `f` represents a field in some root message, `a` and `b`\nfields in the message found in `f`, and `d` a field found in the\nmessage in `f.b`.\n\nField masks are used to specify a subset of fields that should be\nreturned by a get operation or modified by an update operation.\nField masks also have a custom JSON encoding (see below).\n\n# Field Masks in Projections\n\nWhen used in the context of a projection, a response message or\nsub-message is filtered by the API to only contain those fields as\nspecified in the mask. For example, if the mask in the previous\nexample is applied to a response message as follows:\n\n f {\n a : 22\n b {\n d : 1\n x : 2\n }\n y : 13\n }\n z: 8\n\nThe result will not contain specific values for fields x,y and z\n(their value will be set to the default, and omitted in proto text\noutput):\n\n\n f {\n a : 22\n b {\n d : 1\n }\n }\n\nA repeated field is not allowed except at the last position of a\npaths string.\n\nIf a FieldMask object is not present in a get operation, the\noperation applies to all fields (as if a FieldMask of all fields\nhad been specified).\n\nNote that a field mask does not necessarily apply to the\ntop-level response message. In case of a REST get operation, the\nfield mask applies directly to the response, but in case of a REST\nlist operation, the mask instead applies to each individual message\nin the returned resource list. In case of a REST custom method,\nother definitions may be used. Where the mask applies will be\nclearly documented together with its declaration in the API. In\nany case, the effect on the returned resource/resources is required\nbehavior for APIs.\n\n# Field Masks in Update Operations\n\nA field mask in update operations specifies which fields of the\ntargeted resource are going to be updated. The API is required\nto only change the values of the fields as specified in the mask\nand leave the others untouched. If a resource is passed in to\ndescribe the updated values, the API ignores the values of all\nfields not covered by the mask.\n\nIf a repeated field is specified for an update operation, new values will\nbe appended to the existing repeated field in the target resource. Note that\na repeated field is only allowed in the last position of a `paths` string.\n\nIf a sub-message is specified in the last position of the field mask for an\nupdate operation, then new value will be merged into the existing sub-message\nin the target resource.\n\nFor example, given the target message:\n\n f {\n b {\n d: 1\n x: 2\n }\n c: [1]\n }\n\nAnd an update message:\n\n f {\n b {\n d: 10\n }\n c: [2]\n }\n\nthen if the field mask is:\n\n paths: [\"f.b\", \"f.c\"]\n\nthen the result will be:\n\n f {\n b {\n d: 10\n x: 2\n }\n c: [1, 2]\n }\n\nAn implementation may provide options to override this default behavior for\nrepeated and message fields.\n\nNote that libraries which implement FieldMask resolution have various\ndifferent behaviors in the face of empty masks or the special \"*\" mask.\nWhen implementing a service you should confirm these cases have the\nappropriate behavior in the underlying FieldMask library that you desire,\nand you may need to special case those cases in your application code if\nthe underlying field mask library behavior differs from your intended\nservice semantics.\n\nUpdate methods implementing https://google.aip.dev/134\n- MUST support the special value * meaning \"full replace\"\n- MUST treat an omitted field mask as \"replace fields which are present\".\n\nOther methods implementing https://google.aip.dev/157\n- SHOULD support the special value \"*\" to mean \"get all\".\n- MUST treat an omitted field mask to mean \"get all\", unless otherwise\ndocumented.\n\n## Considerations for HTTP REST\n\nThe HTTP kind of an update operation which uses a field mask must\nbe set to PATCH instead of PUT in order to satisfy HTTP semantics\n(PUT must only be used for full updates).\n\n# JSON Encoding of Field Masks\n\nIn JSON, a field mask is encoded as a single string where paths are\nseparated by a comma. Fields name in each path are converted\nto/from lower-camel naming conventions.\n\nAs an example, consider the following message declarations:\n\n message Profile {\n User user = 1;\n Photo photo = 2;\n }\n message User {\n string display_name = 1;\n string address = 2;\n }\n\nIn proto a field mask for `Profile` may look as such:\n\n mask {\n paths: \"user.display_name\"\n paths: \"photo\"\n }\n\nIn JSON, the same mask is represented as below:\n\n {\n mask: \"user.displayName,photo\"\n }\n\n# Field Masks and Oneof Fields\n\nField masks treat fields in oneofs just as regular fields. Consider the\nfollowing message:\n\n message SampleMessage {\n oneof test_oneof {\n string name = 4;\n SubMessage sub_message = 9;\n }\n }\n\nThe field mask can be:\n\n mask {\n paths: \"name\"\n }\n\nOr:\n\n mask {\n paths: \"sub_message\"\n }\n\nNote that oneof type names (\"test_oneof\" in this case) cannot be used in\npaths.\n\n## Field Mask Verification\n\nThe implementation of any API method which has a FieldMask type field in the\nrequest should verify the included field paths, and return an\n`INVALID_ARGUMENT` error if any path is unmappable." title: '`FieldMask` represents a set of symbolic field paths, for example:' applicationsHelmFileParameter: type: object properties: name: type: string title: Name is the name of the Helm parameter path: type: string title: Path is the path to the file containing the values for the Helm parameter title: HelmFileParameter is a file parameter that's passed to helm template during manifest generation RepoListReqRepoSortByOptions: type: string enum: - SORT_BY_NOT_SET - NAME - CONNECTIVITY_STATUS - TYPE - REPOSITORY default: SORT_BY_NOT_SET v1Time: type: object properties: seconds: type: string format: int64 description: 'Represents seconds of UTC time since Unix epoch 1970-01-01T00:00:00Z. Must be from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59Z inclusive.' nanos: type: integer format: int32 description: 'Non-negative fractions of a second at nanosecond resolution. Negative second values with fractions must still have non-negative nanos values that count forward in time. Must be from 0 to 999,999,999 inclusive. This field may be limited in precision depending on context.' description: 'Time is a wrapper around time.Time which supports correct marshaling to YAML and JSON. Wrappers are provided for many of the factory methods that the time package offers. +protobuf.options.marshal=false +protobuf.as=Timestamp +protobuf.options.(gogoproto.goproto_stringer)=false' repositoriesKsonnetEnvironment: type: object properties: name: type: string title: Name is the user defined name of an environment k8sVersion: type: string description: KubernetesVersion is the kubernetes version the targeted cluster is running on. destination: $ref: '#/components/schemas/repositoriesKsonnetEnvironmentDestination' repositoriesESOGeneratorResponse: type: object properties: type: $ref: '#/components/schemas/repositoriesESOGeneratorType' ecrGen: $ref: '#/components/schemas/repositoriesECRAuthorizationTokenGenerator' gcrGen: $ref: '#/components/schemas/repositoriesGCRAccessTokenGenerator' securitySchemes: x-api-key: name: x-api-key type: apiKey in: header description: API key is a token provided while making the API calls. This is used to authenticate the client at the exposed endpoint. externalDocs: description: Find out more about Swagger url: http://swagger.io x-stoplight: id: oc91t4vrfnjyi x-tagGroups: - name: Organizations tags: - Organization - name: Projects tags: - Org Project - Project - name: Secrets tags: - Account Secret - Org Secret - Project Secret - Secrets - name: Connectors tags: - Account Connector - Org Connector - Project Connector - Connectors - GoogleSecretManagerConnector - name: Roles tags: - Account Roles - Organization Roles - Project Roles - Roles - name: Resource Groups tags: - Account Resource Groups - Organization Resource Groups - Project Resource Groups - Filter Resource Groups - Harness Resource Group - Zendesk - name: Role Assignments tags: - Account Role Assignments - Org Role Assignments - Project Role Assignments - Role Assignments - name: Platform tags: - Access Control List - Account Banner - Account Banner - Account Licensed Modules - Account License Type - Account Webhooks - AccountSetting - Accounts - Analyze Account Access Policy - Analyze Organization Access Policy - Analyze Project Access Policy - ApiKey - Audit - AuditFilters - Authentication Settings - Canny - Devops Essentials License Data By Account - EULA - Filter - Harness Resource Type - Invite - IP Allowlist - Nextgen Ldap - Notification Channels - Notification Rules - OIDC - Oidc-Access-Token - Oidc-ID-Token - Org Webhooks - Permissions - Project Webhooks - Secret Managers - Service Account - Setting - SMTP - Source Code Manager - Token - User - User Group - Variables - name: Delegate tags: - Agent mTLS Endpoint Management - Delegate Download Resource - Delegate Group Tags Resource - Delegate Setup Resource - Delegate Token Resource - name: Pipelines tags: - Pipelines - Input Sets - Approvals - Pipeline Execution - Pipeline Dashboard - Pipeline Input Set - Pipeline - Pipeline Execution Details - Pipeline Execute - Pipeline Refresh - Pipeline data retention - Triggers - TriggersEvents - Webhook Triggers - Webhook Event Handler - DryRunPipeline - name: Artifact Registry tags: - Registries - Artifacts - Docker Artifacts - Helm Artifacts - quarantine - Webhooks - Spaces - Replication - Registry V3 - Registries - Registry V3 - Packages - Registry V3 - Versions - Registry V3 - Files - Registry V3 - Metadata - Registry V3 - Firewall - Registry V3 - Transfer - name: Database DevOps tags: - Database Schema - Database Instance - Deployed State - Execution Config - Migration State - name: CD tags: - K8s Release Service Mapping - CustomDeployment - Environments - EnvironmentGroup - Infrastructures - Usage - File Store - Service Dashboard - ServiceOverrides - Rollback - tas - name: Deployment Freeze tags: - Freeze CRUD - Freeze Evaluation - Freeze Schema - name: Services tags: - Account Services - Org Services - Project Services - Services - name: Rancher Infrastructures tags: - Account Rancher Infrastructure - Org Rancher Infrastructure - Project Rancher Infrastructure - name: Templates tags: - Account Template - Org Template - Project Template - Templates - Global Templates - name: GitOps tags: - Agents - Application - Applications - Certificates - Clusters - Dashboard Aggregates - Dashboards - GnuPGP Keys - GPG Keys - Hosts - Project mappings - Projects - Reconciler - Repositories - Repository Certificates - Repository credentials - ValidateHost - name: GitX tags: - GitX Webhooks - Org Gitx Webhooks - Project Gitx Webhooks - name: CACM tags: - Anomalies Ignorelist Rule - Anomalies - BI Dashboards - Budgets - Budget Groups - Cost Categories - Cloud Accounts - K8S Connectors Metadata - Notification Settings v2 - Overview - Data Job Status - Recommendation cost settings - Unit Metric - Anomaly Comments - Cloud and AI cost anomaly details - Cloud and AI cost anomalies v2 - Cost Details - Currency Preferences - External Data Provider - AiEngine - CACM governance cost settings - Governance Enforcement Recommendation APIs - Governance Alert - Governance Overview - Governance Recommendation APIs - RuleEnforcement - Rule Executions - Rule - Rule Sets - Perspectives Folders - Perspective Reports - Perspectives - Cost Category Jira Project Mapping - Recommendations Details - Recommendations - Recommendation Jira - Recommendation Preferences - Recommendation Presets - Recommendation Servicenow - Recommendation Tags - Recommendation Ignore List - AutoStopping Rules - AutoStopping Rules V2 - AutoStopping Load Balancers - AutoStopping Fixed Schedules - AutoStopping Alerts - Commitment Orchestrator Events APIs - name: Feature Flags tags: - API Keys - Feature Flags - Targets - Target Groups - Environment Perspectives - Anomalies - Proxy - Tags - name: SRM tags: - Monitored Services - SLOs dashboard - NG SLOs - SLOs - Downtime - Srm Notification - name: Internal Developer Portal - IDP tags: - Entities - Teams - CatalogCustomProperties - Scores - DataSource - KubernetesDataPoints - AggregationRules - AppConfig - PluginInfo - LayoutProxy - Kinds - LayoutsV3 - LayoutsV4 - name: Environment Management - IDP tags: - Environment - Infrastructure - Instance - name: Custom Dashboards tags: - aida - dashboards - downloads - embed - folders - name: Policy Management tags: - dashboard - examples - policies - evaluate - evaluations - policysets - system - name: Code tags: - repository - status_checks - pullreq - upload - webhook - resource - rules - labels - name: IaCM tags: - usage - approvals - costs - executions - module-registry - workspaces - settings - tf-standard-backend - variables - name: STO tags: - Exemptions - Issues - Scans - Products - Test Targets - Target Variants - name: SEI tags: - Collection categories - Collections - Contributors - DORA - name: Git Sync (deprecated) tags: - Git Branches - Git Full Sync - Git Sync Settings - Git Sync - Git Sync Errors - name: Error Models tags: - Error Response - Governance Metadata - name: Supply Chain Security tags: - integration - PipelineInfraConfig - SBOM - Integration Step Config - Delete Step Config - Delete Repositories - Pipeline Store Config - Evidence Vault [Beta] - name: Release Management tags: - Release Groups - Releases - Orchestration Processes - Orchestration Activities - Orchestration Executions - Conflicts - Freeze - Reports - Uploads - name: Resilience Testing tags: - Actions - Action Templates - Chaos Components - Chaos Hubs - ChaosGuard Conditions - ChaosGuard Rules - DR Tests - Experiments - Experiment Templates - Faults - Fault Templates - Chaos Infrastructure - Health - Network Maps - Onboarding - Probes - Probe Templates - Chaos Recommendations - Risks