swagger: '2.0' info: description: Secure Docker and Kubernetes based container deployments with the NeuVector run-time security solution. version: 5.6.0 license: name: Apache 2.0 url: https://www.apache.org/licenses/LICENSE-2.0.html title: NeuVector Authentication API contact: email: support@neuvector.com schemes: - https tags: - name: Authentication description: Authenticates login or logout paths: /v1/auth: post: tags: - Authentication summary: Login Authentication consumes: - application/json produces: - application/json parameters: - in: body name: body description: User login data required: true schema: $ref: '#/definitions/RESTAuthData' responses: '200': description: Success schema: $ref: '#/definitions/RESTTokenData' '401': description: Authentication failed schema: $ref: '#/definitions/RESTError' patch: tags: - Authentication summary: Keep login session alive security: - ApiKeyAuth: [] - TokenAuth: [] responses: '200': description: Success delete: tags: - Authentication summary: Logout current logged in user security: - ApiKeyAuth: [] - TokenAuth: [] responses: '200': description: Success '408': description: Authentication failed schema: $ref: '#/definitions/RESTError' /v1/auth/{server}: post: tags: - Authentication summary: Authenticate to specified server security: - ApiKeyAuth: [] - TokenAuth: [] consumes: - application/json parameters: - in: path name: server description: Name of the specified server required: true type: string - in: body name: body description: User login data required: true schema: $ref: '#/definitions/RESTAuthData' responses: '200': description: Success definitions: RESTPwdProfileBasic: type: object required: - min_len - min_uppercase_count - min_lowercase_count - min_digit_count - min_special_count properties: min_len: type: integer example: 6 min_uppercase_count: type: integer example: 0 min_lowercase_count: type: integer example: 0 min_digit_count: type: integer example: 0 min_special_count: type: integer example: 0 RESTToken: type: object required: - token - fullname - server - username - password - email - role - timeout - locale - default_password - modify_password - last_login_timestamp - last_login_at - login_count properties: token: type: string example: 1d3123585728afee5c37d410a2fbad43 fullname: type: string example: admin server: type: string example: server1 username: type: string example: admin password: type: string example: '' email: type: string format: email example: user@email.com role: type: string example: admin global_permissions: description: permissions on global domain. only for Rancher SSO type: array items: $ref: '#/definitions/RESTRolePermission' timeout: type: integer format: uint32 example: 300 locale: type: string example: en default_password: type: boolean modify_password: type: boolean default: false role_domains: type: object description: Object key is role and value is array of domains additionalProperties: type: array items: type: string example: - domain1 - domain2 domain_permissions: type: array description: permissions on namespaces. only for Rancher SSO items: $ref: '#/definitions/RESTRolePermission' extra_permissions: description: extra permissions(other than 'role') on global domain. only for Rancher SSO type: array items: $ref: '#/definitions/RESTRolePermission' extra_permissions_domains: type: array description: list of extra permissions(other than specified in 'role_domains') on namespaces. only for Rancher SSO items: $ref: '#/definitions/RESTPermitsAssigned' remote_role_permissions: type: object description: role/permissions on managed clusters in fed. only for Rancher SSO properties: user: $ref: '#/definitions/RESTRemoteRolePermits' last_login_timestamp: type: integer format: int64 example: 1505755716 last_login_at: type: string example: '' login_count: type: integer format: uint32 example: 1 RESTRolePermission: type: object required: - id - read - write properties: id: type: string example: ci_scan read: type: boolean example: false write: type: boolean example: true RESTRemoteRolePermits: type: object required: - role properties: role: type: string description: global role on managed clusters in fed example: admin role_domains: type: object description: role -> domains on managed clusters in fed properties: key: description: role type: string value: type: object description: array of domains additionalProperties: type: array items: type: string example: - domain1 - domain2 extra_permissions: description: extra permissions(other than 'role') for global domain on managed clusters in fed. only for Rancher SSO type: array items: $ref: '#/definitions/RESTRolePermission' extra_permissions_domains: type: array description: list of extra permissions(other than 'role_domains') for namespaces on managed clusters in fed. only for Rancher SSO items: $ref: '#/definitions/RESTPermitsAssigned' RESTError: type: object required: - code - error - message properties: code: type: integer example: 3 error: type: string example: Request failed message: type: string example: Invalid format password_profile_basic: $ref: '#/definitions/RESTPwdProfileBasic' import_task_data: $ref: '#/definitions/RESTImportTaskData' RESTAuthToken: type: object required: - token - state - redirect_endpoint properties: token: type: string example: '' state: type: string example: '' redirect_endpoint: type: string example: '' RESTTokenData: type: object required: - token - password_days_until_expire - password_hours_until_expire properties: token: $ref: '#/definitions/RESTToken' password_days_until_expire: type: integer example: null password_hours_until_expire: type: integer example: null need_to_reset_password: type: boolean description: prompt the uer to login again & provide the new password to reset after login default: false RESTAuthPassword: type: object required: - username - password properties: username: type: string example: admin password: type: string format: password example: mypassword new_password: type: string description: need to specify when server responds the user needs to change password example: mynewpassword RESTImportTaskData: type: object required: - data properties: data: $ref: '#/definitions/RESTImportTask' RESTAuthData: type: object required: - client_ip properties: client_ip: type: string example: '' password: $ref: '#/definitions/RESTAuthPassword' Token: $ref: '#/definitions/RESTAuthToken' RESTPermitsAssigned: type: object properties: permissions: type: array description: array of permissions items: $ref: '#/definitions/RESTRolePermission' domains: type: array description: array of domains that have the same permissions items: type: string example: - domain1 - domain2 RESTImportTask: type: object required: - tid - ctrler_id - percentage properties: tid: type: string example: c5af897b62a258212ece91c0551d3a4a ctrler_id: type: string example: 6e60452b244b90456f3450c9fed0a50f57f4b849dcb74a5fad289e8116f32f36 last_update_time: type: string format: date-time example: '2022-03-17T17:31:55.832768041Z' percentage: type: integer example: 100 triggered_by: type: string example: admin status: type: string example: done temp_token: type: string example: '' fail_to_decrypt_key_fields: type: object description: Object key is kv key and value is array of cloaked fields that cannot be decrypted additionalProperties: type: array items: type: string example: - x509_cert - signing_cert securityDefinitions: ApiKeyAuth: type: apiKey in: header name: X-Auth-Apikey TokenAuth: type: apiKey in: header name: X-Auth-Token externalDocs: description: Find out more about NeuVector url: https://www.suse.com/products/neuvector/