openapi: 3.1.0 info: title: Juniper Networks Juniper Apstra Intent-Based Networking Alarms Security Groups API description: RESTful API for Juniper Apstra, an intent-based networking platform for automating data center network design, deployment, and operations. Apstra abstracts network infrastructure into design blueprints with logical models, rack types, templates, and connectivity. The platform continuously validates that the network state matches the intended configuration and raises anomalies when deviations occur. The API provides full access to design resources, blueprints, device management, telemetry, and IBA (Intent-Based Analytics) probes. Authentication uses token-based sessions obtained via the login endpoint. version: '4.2' contact: name: Juniper Networks Support url: https://www.juniper.net/documentation/product/us/en/juniper-apstra/ license: name: Proprietary url: https://www.juniper.net/us/en/legal-notices.html servers: - url: https://{apstra_server}/api description: Apstra server API endpoint. variables: apstra_server: description: Hostname or IP address of the Apstra server. default: apstra.example.com security: - authToken: [] tags: - name: Security Groups description: Security group rules for workload micro-segmentation. paths: /security-groups: get: operationId: listSecurityGroups summary: Juniper Networks List security groups description: Returns all security groups. Security groups provide stateful packet filtering at the virtual machine interface level, similar to OpenStack security groups. tags: - Security Groups responses: '200': description: Security groups returned. content: application/json: schema: type: object properties: security-groups: type: array items: $ref: '#/components/schemas/ObjectRef' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createSecurityGroup summary: Juniper Networks Create security group description: Creates a new security group with ingress/egress rules. tags: - Security Groups requestBody: required: true content: application/json: schema: type: object properties: security-group: $ref: '#/components/schemas/SecurityGroup' responses: '200': description: Security group created. '400': $ref: '#/components/responses/BadRequest' components: responses: BadRequest: description: Invalid request parameters. content: application/json: schema: $ref: '#/components/schemas/Error' Unauthorized: description: Authentication required or token expired. content: application/json: schema: $ref: '#/components/schemas/Error' schemas: Error: type: object properties: message: type: string SecurityGroup: type: object properties: uuid: type: string format: uuid fq_name: type: array items: type: string security_group_entries: type: object properties: policy_rule: type: array items: type: object properties: direction: type: string enum: - '>' - <> protocol: type: string ethertype: type: string enum: - IPv4 - IPv6 src_addresses: type: array items: type: object properties: subnet: type: object properties: ip_prefix: type: string ip_prefix_len: type: integer security_group: type: string dst_addresses: type: array items: type: object properties: subnet: type: object properties: ip_prefix: type: string ip_prefix_len: type: integer dst_ports: type: array items: type: object properties: start_port: type: integer end_port: type: integer ObjectRef: type: object properties: href: type: string format: uri description: Resource URL. fq_name: type: array items: type: string description: Fully qualified name path (domain, project, name). uuid: type: string format: uuid description: Object UUID. securitySchemes: authToken: type: apiKey in: header name: AuthToken description: Authentication token obtained from POST /api/aaa/login. Include in the AuthToken header for all authenticated API requests.