openapi: 3.1.0 info: title: NetBird REST Accounts Policies API description: API to manipulate groups, rules, policies and retrieve information about peers and users version: 0.0.1 servers: - url: https://api.netbird.io description: Default server security: - BearerAuth: [] - TokenAuth: [] tags: - name: Policies description: Interact with and view information about policies. paths: /api/policies: get: summary: List all Policies description: Returns a list of all policies tags: - Policies security: - BearerAuth: [] - TokenAuth: [] responses: '200': description: A JSON Array of Policies content: application/json: schema: type: array items: $ref: '#/components/schemas/Policy' '400': $ref: '#/components/responses/bad_request' '401': $ref: '#/components/responses/requires_authentication' '403': $ref: '#/components/responses/forbidden' '500': $ref: '#/components/responses/internal_error' post: summary: Create a Policy description: Creates a policy tags: - Policies security: - BearerAuth: [] - TokenAuth: [] requestBody: description: New Policy request content: application/json: schema: $ref: '#/components/schemas/PolicyUpdate' responses: '200': description: A Policy Object content: application/json: schema: $ref: '#/components/schemas/Policy' /api/policies/{policyId}: get: summary: Retrieve a Policy description: Get information about a Policies tags: - Policies security: - BearerAuth: [] - TokenAuth: [] parameters: - in: path name: policyId required: true schema: type: string description: The unique identifier of a policy responses: '200': description: A Policy object content: application/json: schema: $ref: '#/components/schemas/Policy' '400': $ref: '#/components/responses/bad_request' '401': $ref: '#/components/responses/requires_authentication' '403': $ref: '#/components/responses/forbidden' '500': $ref: '#/components/responses/internal_error' put: summary: Update a Policy description: Update/Replace a Policy tags: - Policies security: - BearerAuth: [] - TokenAuth: [] parameters: - in: path name: policyId required: true schema: type: string description: The unique identifier of a policy requestBody: description: Update Policy request content: application/json: schema: $ref: '#/components/schemas/PolicyCreate' responses: '200': description: A Policy object content: application/json: schema: $ref: '#/components/schemas/Policy' '400': $ref: '#/components/responses/bad_request' '401': $ref: '#/components/responses/requires_authentication' '403': $ref: '#/components/responses/forbidden' '500': $ref: '#/components/responses/internal_error' delete: summary: Delete a Policy description: Delete a policy tags: - Policies security: - BearerAuth: [] - TokenAuth: [] parameters: - in: path name: policyId required: true schema: type: string description: The unique identifier of a policy responses: '200': description: Delete status code content: {} '400': $ref: '#/components/responses/bad_request' '401': $ref: '#/components/responses/requires_authentication' '403': $ref: '#/components/responses/forbidden' '500': $ref: '#/components/responses/internal_error' components: schemas: PolicyRule: allOf: - $ref: '#/components/schemas/PolicyRuleMinimum' - type: object properties: id: description: Policy rule ID type: string example: ch8i4ug6lnn4g9hqv7mg sources: description: Policy rule source group IDs type: array items: $ref: '#/components/schemas/GroupMinimum' sourceResource: description: Policy rule source resource that the rule is applied to $ref: '#/components/schemas/Resource' destinations: description: Policy rule destination group IDs type: array items: $ref: '#/components/schemas/GroupMinimum' destinationResource: description: Policy rule destination resource that the rule is applied to $ref: '#/components/schemas/Resource' NetworkResourceType: description: Network resource type based of the address type: string enum: - host - subnet - domain example: host PolicyCreate: allOf: - $ref: '#/components/schemas/PolicyMinimum' - type: object properties: source_posture_checks: description: Posture checks ID's applied to policy source groups type: array items: type: string example: chacdk86lnnboviihd70 rules: description: Policy rule object for policy UI editor type: array items: $ref: '#/components/schemas/PolicyRuleUpdate' required: - rules RulePortRange: description: Policy rule affected ports range type: object properties: start: description: The starting port of the range type: integer example: 80 end: description: The ending port of the range type: integer example: 320 required: - start - end Resource: type: object properties: id: description: ID of the resource type: string example: chacdk86lnnboviihd7g type: description: Type of the resource $ref: '#/components/schemas/ResourceType' required: - id - type Policy: allOf: - $ref: '#/components/schemas/PolicyMinimum' - type: object properties: id: description: Policy ID type: string example: ch8i4ug6lnn4g9hqv7mg source_posture_checks: description: Posture checks ID's applied to policy source groups type: array items: type: string example: chacdk86lnnboviihd70 rules: description: Policy rule object for policy UI editor type: array items: $ref: '#/components/schemas/PolicyRule' required: - rules - source_posture_checks ResourceType: allOf: - $ref: '#/components/schemas/NetworkResourceType' - type: string enum: - peer example: peer GroupMinimum: type: object properties: id: description: Group ID type: string example: ch8i4ug6lnn4g9hqv7m0 name: description: Group Name identifier type: string example: devs peers_count: description: Count of peers associated to the group type: integer example: 2 resources_count: description: Count of resources associated to the group type: integer example: 5 issued: description: How the group was issued (api, integration, jwt) type: string enum: - api - integration - jwt example: api required: - id - name - peers_count - resources_count PolicyUpdate: allOf: - $ref: '#/components/schemas/PolicyMinimum' - type: object properties: source_posture_checks: description: Posture checks ID's applied to policy source groups type: array items: type: string example: chacdk86lnnboviihd70 rules: description: Policy rule object for policy UI editor type: array items: $ref: '#/components/schemas/PolicyRuleUpdate' required: - rules PolicyRuleMinimum: type: object properties: name: description: Policy rule name identifier type: string example: Default description: description: Policy rule friendly description type: string example: This is a default rule that allows connections between all the resources enabled: description: Policy rule status type: boolean example: true action: description: Policy rule accept or drops packets type: string enum: - accept - drop example: accept bidirectional: description: Define if the rule is applicable in both directions, sources, and destinations. type: boolean example: true protocol: description: Policy rule type of the traffic type: string enum: - all - tcp - udp - icmp - netbird-ssh example: tcp ports: description: Policy rule affected ports type: array items: type: string example: '80' port_ranges: description: Policy rule affected ports ranges list type: array items: $ref: '#/components/schemas/RulePortRange' authorized_groups: description: Map of user group ids to a list of local users type: object additionalProperties: type: array items: type: string example: group1 required: - name - enabled - bidirectional - protocol - action PolicyMinimum: type: object properties: name: description: Policy name identifier type: string example: ch8i4ug6lnn4g9hqv7mg description: description: Policy friendly description type: string example: This is a default policy that allows connections between all the resources enabled: description: Policy status type: boolean example: true required: - name - enabled PolicyRuleUpdate: allOf: - $ref: '#/components/schemas/PolicyRuleMinimum' - type: object properties: id: description: Policy rule ID type: string example: ch8i4ug6lnn4g9hqv7mg sources: description: Policy rule source group IDs type: array items: type: string example: ch8i4ug6lnn4g9hqv797 sourceResource: description: Policy rule source resource that the rule is applied to $ref: '#/components/schemas/Resource' destinations: description: Policy rule destination group IDs type: array items: type: string example: ch8i4ug6lnn4g9h7v7m0 destinationResource: description: Policy rule destination resource that the rule is applied to $ref: '#/components/schemas/Resource' responses: bad_request: description: Bad Request content: {} internal_error: description: Internal Server Error content: {} requires_authentication: description: Requires authentication content: {} forbidden: description: Forbidden content: {} securitySchemes: BearerAuth: type: http scheme: bearer bearerFormat: JWT TokenAuth: type: apiKey in: header name: Authorization description: Enter the token with the `Token` prefix, e.g. "Token nbp_F3f0d.....".