openapi: 3.1.0 info: title: Istio Extensions AuthorizationPolicy API description: The Istio Extensions API (extensions.istio.io) provides configuration resources for extending the Istio service mesh with custom functionality. The WasmPlugin resource enables deploying WebAssembly (Wasm) modules as plugins to the Envoy sidecar proxies, allowing custom processing of network traffic at various phases of the request lifecycle. These resources are defined as Kubernetes Custom Resource Definitions (CRDs) and are accessed via the Kubernetes API server. version: v1alpha1 contact: name: Istio url: https://istio.io/ license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0 servers: - url: https://{cluster}/apis/extensions.istio.io/v1alpha1 description: Kubernetes API server endpoint for Istio Extensions v1alpha1 variables: cluster: default: kubernetes.default.svc description: Kubernetes API server hostname tags: - name: AuthorizationPolicy description: Fine-grained access control policies for workloads externalDocs: url: https://istio.io/latest/docs/reference/config/security/authorization-policy/ paths: /namespaces/{namespace}/authorizationpolicies: get: operationId: listAuthorizationPolicies summary: Istio List AuthorizationPolicies description: List all AuthorizationPolicy resources in the specified namespace. An AuthorizationPolicy enables access control on workloads in the mesh, supporting ALLOW, DENY, AUDIT, and CUSTOM actions based on source, operation, and condition matching. tags: - AuthorizationPolicy parameters: - $ref: '#/components/parameters/namespace' - $ref: '#/components/parameters/labelSelector' - $ref: '#/components/parameters/limit' - $ref: '#/components/parameters/continue' responses: '200': description: Successful response containing list of AuthorizationPolicies content: application/json: schema: $ref: '#/components/schemas/AuthorizationPolicyList' '401': description: Unauthorized post: operationId: createAuthorizationPolicy summary: Istio Create an AuthorizationPolicy description: Create a new AuthorizationPolicy resource in the specified namespace. tags: - AuthorizationPolicy parameters: - $ref: '#/components/parameters/namespace' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AuthorizationPolicy' responses: '201': description: AuthorizationPolicy created content: application/json: schema: $ref: '#/components/schemas/AuthorizationPolicy' '401': description: Unauthorized '409': description: Conflict - resource already exists /namespaces/{namespace}/authorizationpolicies/{name}: get: operationId: getAuthorizationPolicy summary: Istio Get an AuthorizationPolicy description: Read the specified AuthorizationPolicy resource. tags: - AuthorizationPolicy parameters: - $ref: '#/components/parameters/namespace' - $ref: '#/components/parameters/name' responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/AuthorizationPolicy' '401': description: Unauthorized '404': description: Not found put: operationId: replaceAuthorizationPolicy summary: Istio Replace an AuthorizationPolicy description: Replace the specified AuthorizationPolicy resource. tags: - AuthorizationPolicy parameters: - $ref: '#/components/parameters/namespace' - $ref: '#/components/parameters/name' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AuthorizationPolicy' responses: '200': description: AuthorizationPolicy replaced content: application/json: schema: $ref: '#/components/schemas/AuthorizationPolicy' '401': description: Unauthorized '404': description: Not found delete: operationId: deleteAuthorizationPolicy summary: Istio Delete an AuthorizationPolicy description: Delete the specified AuthorizationPolicy resource. tags: - AuthorizationPolicy parameters: - $ref: '#/components/parameters/namespace' - $ref: '#/components/parameters/name' responses: '200': description: AuthorizationPolicy deleted '401': description: Unauthorized '404': description: Not found components: parameters: labelSelector: name: labelSelector in: query description: A selector to restrict the list of returned objects by their labels schema: type: string continue: name: continue in: query description: Continue token for paginated list requests schema: type: string name: name: name in: path required: true description: The resource name schema: type: string namespace: name: namespace in: path required: true description: The Kubernetes namespace schema: type: string limit: name: limit in: query description: Maximum number of resources to return schema: type: integer schemas: AuthorizationPolicyList: type: object properties: apiVersion: type: string kind: type: string enum: - AuthorizationPolicyList metadata: $ref: '#/components/schemas/ListMeta' items: type: array items: $ref: '#/components/schemas/AuthorizationPolicy' ObjectMeta: type: object properties: name: type: string description: Name of the resource namespace: type: string description: Namespace of the resource labels: type: object additionalProperties: type: string annotations: type: object additionalProperties: type: string creationTimestamp: type: string format: date-time resourceVersion: type: string AuthorizationRule: type: object properties: from: type: array items: type: object properties: source: type: object properties: principals: type: array items: type: string description: Peer identities derived from the peer certificate. notPrincipals: type: array items: type: string requestPrincipals: type: array items: type: string description: Request identities derived from the JWT token. notRequestPrincipals: type: array items: type: string namespaces: type: array items: type: string description: Namespaces derived from the peer certificate. notNamespaces: type: array items: type: string ipBlocks: type: array items: type: string description: IP blocks in CIDR notation. notIpBlocks: type: array items: type: string description: Source identities (peers and request principals) to match. to: type: array items: type: object properties: operation: type: object properties: hosts: type: array items: type: string description: The request host header values. notHosts: type: array items: type: string ports: type: array items: type: string description: The request port values. notPorts: type: array items: type: string methods: type: array items: type: string description: The request HTTP methods (GET, POST, etc.). notMethods: type: array items: type: string paths: type: array items: type: string description: The request URL paths. notPaths: type: array items: type: string description: Operations (hosts, ports, methods, paths) to match. when: type: array items: type: object properties: key: type: string description: The name of an Istio attribute (e.g. request.headers[X-Custom]). values: type: array items: type: string notValues: type: array items: type: string description: Additional conditions to match. AuthorizationPolicy: type: object properties: apiVersion: type: string enum: - security.istio.io/v1 kind: type: string enum: - AuthorizationPolicy metadata: $ref: '#/components/schemas/ObjectMeta' spec: type: object properties: selector: type: object properties: matchLabels: type: object additionalProperties: type: string description: Workload selector to apply the policy to specific workloads. action: type: string enum: - ALLOW - DENY - AUDIT - CUSTOM description: The action to take when a request matches the policy rules. provider: type: object properties: name: type: string description: Specifies the name of the extension provider. Required when action is CUSTOM. rules: type: array items: $ref: '#/components/schemas/AuthorizationRule' description: Rules to match for the policy. A match occurs when at least one rule is matched. An empty rule list means all requests are matched. targetRefs: type: array items: type: object properties: kind: type: string group: type: string name: type: string description: References to the target resources to which the policy applies. ListMeta: type: object properties: resourceVersion: type: string continue: type: string securitySchemes: BearerAuth: type: http scheme: bearer description: Kubernetes API server bearer token authentication externalDocs: description: Istio Extensions Configuration Reference url: https://istio.io/latest/docs/reference/config/