openapi: 3.1.0 info: title: Kuma Dataplane MeshTrust API description: Kuma API version: v1alpha1 x-ref-schema-name: DataplaneOverview security: - BasicAuth: [] - BearerAuth: [] - {} tags: - name: MeshTrust paths: /meshes/{mesh}/meshtrusts/{name}: get: operationId: getMeshTrust summary: Returns MeshTrust entity tags: - MeshTrust parameters: - in: path name: mesh schema: type: string required: true description: name of the mesh - in: path name: name schema: type: string required: true description: name of the MeshTrust responses: '200': $ref: '#/components/responses/MeshTrustItem' '404': $ref: '#/components/responses/NotFound' put: operationId: putMeshTrust summary: Creates or Updates MeshTrust entity tags: - MeshTrust parameters: - in: path name: mesh schema: type: string required: true description: name of the mesh - in: path name: name schema: type: string required: true description: name of the MeshTrust requestBody: description: Put request required: true content: application/json: schema: $ref: '#/components/schemas/MeshTrustItem' responses: '200': $ref: '#/components/responses/MeshTrustCreateOrUpdateSuccessResponse' '201': $ref: '#/components/responses/MeshTrustCreateOrUpdateSuccessResponse' delete: operationId: deleteMeshTrust summary: Deletes MeshTrust entity tags: - MeshTrust parameters: - in: path name: mesh schema: type: string required: true description: name of the mesh - in: path name: name schema: type: string required: true description: name of the MeshTrust responses: '200': $ref: '#/components/responses/MeshTrustDeleteSuccessResponse' '404': $ref: '#/components/responses/NotFound' /meshes/{mesh}/meshtrusts: get: operationId: getMeshTrustList summary: Returns a list of MeshTrust in the mesh. tags: - MeshTrust parameters: - in: query name: offset description: offset in the list of entities required: false schema: type: integer example: 0 - in: query name: size description: the number of items per page required: false schema: type: integer default: 100 maximum: 1000 minimum: 1 - in: query name: filter description: filter by labels when multiple filters are present, they are ANDed required: false schema: type: object properties: key: type: string value: type: string example: label.k8s.kuma.io/namespace: my-ns - in: path name: mesh schema: type: string required: true description: name of the mesh responses: '200': $ref: '#/components/responses/MeshTrustList' components: responses: NotFound: description: Not Found content: application/problem+json: schema: $ref: '#/components/schemas/NotFoundError' MeshTrustCreateOrUpdateSuccessResponse: description: Successful response content: application/json: schema: type: object properties: warnings: type: array readOnly: true description: 'warnings is a list of warning messages to return to the requesting Kuma API clients. Warning messages describe a problem the client making the API request should correct or be aware of. ' items: type: string MeshTrustDeleteSuccessResponse: description: Successful response content: application/json: schema: type: object MeshTrustItem: description: Successful response content: application/json: schema: $ref: '#/components/schemas/MeshTrustItem' MeshTrustList: description: List content: application/json: schema: type: object properties: items: type: array items: $ref: '#/components/schemas/MeshTrustItem' total: type: number description: The total number of entities next: type: string description: URL to the next page schemas: MeshTrustItem: type: object description: MeshTrust defines trusted Certificate Authority (CA) bundles for a trust domain in the mesh. It establishes trust relationships for service-to-service mTLS authentication by specifying which CA certificates are trusted to verify service identities, supporting PEM-encoded CA bundles and enabling secure cross-service communication within the trust domain. required: - type - name - spec properties: type: description: the type of the resource type: string enum: - MeshTrust mesh: description: Mesh is the name of the Kuma mesh this resource belongs to. It may be omitted for cluster-scoped resources. type: string default: default kri: description: A unique identifier for this resource instance used by internal tooling and integrations. Typically derived from resource attributes and may be used for cross-references or indexing type: string readOnly: true example: kri_mtrust_default_zone-east_kuma-system_myresource1_ name: description: Name of the Kuma resource type: string labels: additionalProperties: type: string description: The labels to help identity resources type: object spec: description: Spec is the specification of the Kuma MeshTrust resource. properties: caBundles: description: 'CABundles contains a list of CA bundles supported by this TrustDomain. At least one CA bundle must be specified.' items: properties: pem: description: Pem contains the PEM-encoded CA bundle if the Type is set to a PEM-based format. properties: value: description: Value holds the PEM-encoded CA bundle as a string. type: string required: - value type: object type: description: Type specifies the format or source type of the CA bundle. enum: - Pem type: string required: - type type: object minItems: 1 type: array origin: description: 'Origin specifies whether the resource was created from a MeshIdentity. Deprecated: use Status.Origin instead' properties: kri: description: Resource identifier type: string type: object trustDomain: description: TrustDomain is the trust domain associated with this resource. maxLength: 253 type: string required: - caBundles - trustDomain type: object creationTime: readOnly: true type: string description: Time at which the resource was created format: date-time example: '0001-01-01T00:00:00Z' modificationTime: readOnly: true type: string description: Time at which the resource was updated format: date-time example: '0001-01-01T00:00:00Z' status: description: Status is the current status of the Kuma MeshTrust resource. properties: origin: description: Origin specifies whether the resource was created from a MeshIdentity. properties: kri: description: Resource identifier type: string type: object type: object readOnly: true NotFoundError: allOf: - $ref: '#/components/schemas/Error' - type: object properties: status: type: integer enum: - 404 example: 404 description: 'The HTTP status code for NotFoundError MUST be 404. ' title: type: string example: Not Found type: type: string example: https://httpstatuses.com/404 detail: type: string example: The requested resource was not found InvalidParameters: type: object title: Invalid Parameters required: - field - reason - source properties: field: type: string description: The name of the field that caused the error. reason: type: string description: 'A short, human-readable description of the problem. _Should_ be provided as "Sentence case" for direct use in a UI. ' rule: type: string description: 'May be provided as a hint to the user to help understand the type of failure. Additional guidance may be provided in additional fields, i.e. `choices`. ' choices: type: array description: 'Optional field to provide a list of valid choices for the field that caused the error. ' items: type: string source: type: string description: 'The location of the field that caused the error. ' enum: - body - query - header - path Error: type: object title: Error description: 'Standard error. Follows the [AIP #193 - Errors](https://kong-aip.netlify.app/aip/193/) specification. ' x-examples: Example 1: status: 404 title: Not Found type: https://kongapi.info/konnect/not-found instance: portal:trace:2287285207635123011 detail: The requested document was not found required: - status - title - instance - type - detail properties: status: type: integer description: The HTTP status code. example: 404 title: type: string description: 'A short, human-readable summary of the problem. It **should not** change between occurrences of a problem, except for localization. Should be provided as "Sentence case" for potential direct use in a UI ' example: Not Found type: type: string description: 'A unique identifier for this error. When dereferenced it must provide human-readable documentation for the problem. ' example: Not Found instance: type: string example: portal:trace:2287285207635123011 description: 'Used to return the correlation ID back to the user, in the format `:trace:`. ' detail: type: string example: The requested team was not found description: 'A human readable explanation specific to this occurrence of the problem. This field may contain request/entity data to help the user understand what went wrong. Enclose variable values in square brackets. _Should_ be provided as "Sentence case" for direct use in a UI ' invalid_parameters: type: array description: 'All 400 errors **MUST** return an `invalid_parameters` key in the response. Used to indicate which fields have invalid values when validated. ' items: $ref: '#/components/schemas/InvalidParameters' securitySchemes: BasicAuth: type: http scheme: basic BearerAuth: type: http scheme: bearer