{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/main/json-schema/palo-alto-networks-defender-defender-schema.json", "title": "defender.Defender", "description": "Defender is an update about an agent starting", "x-generated": "2026-10-03", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/palo-alto-networks-defenders-api-openapi.yml#/components/schemas/defender.Defender", "properties": { "category": { "$ref": "#/$defs/defender.Category" }, "certificateExpiration": { "description": "Client certificate expiration time.\n", "format": "date-time", "type": "string" }, "cloudMetadata": { "$ref": "#/$defs/common.CloudMetadata" }, "cluster": { "description": "Cluster name (fallback is internal IP).\n", "type": "string" }, "clusterID": { "description": "Unique ID generated for each DaemonSet. Used to group Defenders by clusters. Note: Kubernetes does not provide a cluster name as part of its API.\n", "type": "string" }, "clusterOIDCProviderURL": { "description": "ClusterOIDCProviderURL is the URL of the OpenID Connect (OIDC) identity provider of the associated Kubernetes cluster.\n", "type": "string" }, "clusterType": { "$ref": "#/$defs/common.ClusterType" }, "collections": { "description": "Collections to which this Defender belongs.\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "compatibleVersion": { "description": "Indicates if Defender has a compatible version for communication (e.g., request logs) (true) or not (false).\n", "type": "boolean" }, "connected": { "description": "Indicates whether Defender is connected (true) or not (false).\n", "type": "boolean" }, "container": { "description": "Container is the container name for app embedded defenders.\n", "type": "string" }, "features": { "$ref": "#/$defs/defender.Features" }, "firewallProtection": { "$ref": "#/$defs/waas.ProtectionStatus" }, "fqdn": { "description": "Full domain name of the host. Used in audit alerts to identify specific hosts.\n", "type": "string" }, "hostname": { "description": "Name of host where Defender is deployed.\n", "type": "string" }, "isARM64": { "description": "IsARM64 indicates whether the defender runs on aarch64 architecture.\n", "type": "boolean" }, "lastModified": { "description": "Datetime when the Defender's connectivity status last changed.\n", "format": "date-time", "type": "string" }, "podUid": { "description": "PodUID is the UID of the pod where the defender is running, the UID is unique within a Kubernetes cluster.\n", "type": "string" }, "port": { "description": "Port that Defender uses to connect to Console.\n", "type": "integer" }, "proxy": { "$ref": "#/$defs/common.ProxySettings" }, "remoteLoggingSupported": { "description": "Indicates if Defender logs can be retrieved remotely (true) or not (false).\n", "type": "boolean" }, "remoteMgmtSupported": { "description": "Indicates if Defender can be remotely managed (upgraded, restarted) (true) or not (false).\n", "type": "boolean" }, "status": { "$ref": "#/$defs/defender.Status" }, "systemInfo": { "$ref": "#/$defs/defender.SystemInfo" }, "tasBlobstoreScanner": { "description": "Indicates TAS blobstore scanning only Defender.\n", "type": "boolean" }, "tasClusterID": { "description": "TAS cluster ID where Defender runs. This is typically set to the Cloud controller's API address.\n", "type": "string" }, "tasFoundation": { "description": "TASFoundation is the foundation the Defender is running on.\n", "type": "string" }, "type": { "$ref": "#/$defs/defender.Type" }, "usingOldCA": { "description": "UsingOldCA indicates whether the defender client is using an old certificate signed by an old CA for TLS handshake.\n", "type": "boolean" }, "version": { "description": "Defender version.\n", "type": "string" }, "vpcObserver": { "description": "VPCObserver indicates whether the defender runs in a VPC observer.\n", "type": "boolean" } }, "type": "object", "$defs": { "common.ACIMetadata": { "properties": { "containerGroup": { "description": ".\n", "type": "string" } }, "type": "object" }, "common.AzureMetadata": { "properties": { "aci": { "$ref": "#/$defs/common.ACIMetadata" }, "resourceGroup": { "description": ".\n", "type": "string" } }, "type": "object" }, "common.CloudMetadata": { "description": "CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)", "properties": { "accountID": { "description": "Cloud account ID.\n", "type": "string" }, "awsExecutionEnv": { "description": "AWS execution environment (e.g. EC2/Fargate).\n", "type": "string" }, "azure": { "$ref": "#/$defs/common.AzureMetadata" }, "gcp": { "$ref": "#/$defs/common.GCPCloudMetadata" }, "image": { "description": "The name of the image the cloud managed host or container is based on.\n", "type": "string" }, "labels": { "description": "Cloud provider metadata labels.\n", "items": { "$ref": "#/$defs/common.ExternalLabel" }, "type": "array" }, "name": { "description": "Resource name.\n", "type": "string" }, "ociTenantID": { "description": "OCI Tenant ID.\n", "type": "string" }, "provider": { "$ref": "#/$defs/common.CloudProvider" }, "region": { "description": "Resource's region.\n", "type": "string" }, "resourceID": { "description": "Unique ID of the resource.\n", "type": "string" }, "resourceURL": { "description": "Server-defined URL for the resource.\n", "type": "string" }, "type": { "description": "Instance type.\n", "type": "string" }, "vmID": { "description": "Azure unique vm ID.\n", "type": "string" }, "vmImageID": { "description": "VMImageID holds the VM instance's image ID.\n", "type": "string" } }, "type": "object" }, "common.CloudProvider": { "description": "CloudProvider specifies the cloud provider name", "enum": [ [ "aws", "azure", "gcp", "alibaba", "oci", "others" ] ], "type": "string" }, "common.CloudRunMetadata": { "properties": { "revision": { "description": ".\n", "type": "string" }, "service": { "description": ".\n", "type": "string" } }, "type": "object" }, "common.ClusterType": { "description": "ClusterType is the cluster type", "enum": [ [ "AKS", "ECS", "EKS", "GKE", "Kubernetes" ] ], "type": "string" }, "common.ExternalLabel": { "description": "ExternalLabel holds an external label with a source and timestamp", "properties": { "key": { "description": "Label key.\n", "type": "string" }, "sourceName": { "description": "Source name (e.g., for a namespace, the source name can be 'twistlock').\n", "type": "string" }, "sourceType": { "$ref": "#/$defs/common.ExternalLabelSourceType" }, "timestamp": { "description": "Time when the label was fetched.\n", "format": "date-time", "type": "string" }, "value": { "description": "Value of the label.\n", "type": "string" } }, "type": "object" }, "common.ExternalLabelSourceType": { "description": "ExternalLabelSourceType indicates the source of the labels", "enum": [ [ "namespace", "deployment", "pod", "aws", "azure", "gcp", "oci" ] ], "type": "string" }, "common.GCPCloudMetadata": { "properties": { "cloudRun": { "$ref": "#/$defs/common.CloudRunMetadata" } }, "type": "object" }, "common.ProxySettings": { "description": "ProxySettings are the http proxy settings", "properties": { "ca": { "description": "Proxy's CA for Defender to trust. Required when using TLS intercept proxies.\n", "type": "string" }, "httpProxy": { "description": "Proxy address.\n", "type": "string" }, "noProxy": { "description": "List of addresses for which the proxy should not be used.\n", "type": "string" }, "password": { "$ref": "#/$defs/common.Secret" }, "user": { "description": "Username to authenticate with the proxy.\n", "type": "string" } }, "type": "object" }, "common.Secret": { "description": "Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database", "properties": { "encrypted": { "description": "Specifies an encrypted value of the secret.\n", "type": "string" }, "plain": { "description": "Specifies the plain text value of the secret.\n", "type": "string" } }, "type": "object" }, "defender.Category": { "description": "Category represents the defender target category", "enum": [ [ "container", "host", "serverless", "appEmbedded", "hostAgentless", "containerAgentless", "cloudSecurityAgent" ] ], "type": "string" }, "defender.FeatureStatus": { "description": "FeatureStatus holds data about defender features", "properties": { "enabled": { "description": "Indicates if the feature is enabled (true) or not (false).\n", "type": "boolean" }, "err": { "description": "Error string, if an error occurred.\n", "type": "string" }, "hostname": { "description": "Name of host where Defender runs.\n", "type": "string" } }, "type": "object" }, "defender.Features": { "description": "Features is the defender features that can be updated", "properties": { "clusterMonitoring": { "description": "Indicates whether any of the cluster monitoring features are enabled (monitor service accounts, monitor Istio, collect Kubernetes pod labels).\n", "type": "boolean" }, "proxyListenerType": { "$ref": "#/$defs/defender.ProxyListenerType" } }, "type": "object" }, "defender.ProxyListenerType": { "description": "ProxyListenerType is the proxy listener type of defenders", "type": "string" }, "defender.ScanStatus": { "description": "ScanStatus represents the status of current scan", "properties": { "completed": { "description": "Indicates if scanning has successfully completed (true) or not (false).\n", "type": "boolean" }, "errors": { "description": "List of errors that occurred during the last scan.\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "hostname": { "description": "Name of the host where Defender runs.\n", "type": "string" }, "scanTime": { "description": "Datetime of the last completed scan.\n", "format": "date-time", "type": "string" }, "scanning": { "description": "Indicates whether scanning is in progress (true) or not (false).\n", "type": "boolean" }, "selective": { "description": "Indicates if the scan is for a specific resource (true) or not (false).\n", "type": "boolean" } }, "type": "object" }, "defender.Status": { "description": "Status is the generic status state per defender or global", "properties": { "appFirewall": { "$ref": "#/$defs/defender.FeatureStatus" }, "container": { "$ref": "#/$defs/defender.ScanStatus" }, "containerNetworkFirewall": { "$ref": "#/$defs/defender.FeatureStatus" }, "features": { "$ref": "#/$defs/defender.FeatureStatus" }, "filesystem": { "$ref": "#/$defs/defender.FeatureStatus" }, "hostCustomCompliance": { "$ref": "#/$defs/defender.FeatureStatus" }, "hostNetworkFirewall": { "$ref": "#/$defs/defender.FeatureStatus" }, "image": { "$ref": "#/$defs/defender.ScanStatus" }, "lastModified": { "description": "Datetime the status was last modified.\n", "format": "date-time", "type": "string" }, "network": { "$ref": "#/$defs/defender.FeatureStatus" }, "outOfBandAppFirewall": { "$ref": "#/$defs/defender.FeatureStatus" }, "process": { "$ref": "#/$defs/defender.FeatureStatus" }, "runc": { "$ref": "#/$defs/defender.FeatureStatus" }, "runtime": { "$ref": "#/$defs/defender.FeatureStatus" }, "tasDroplets": { "$ref": "#/$defs/defender.ScanStatus" }, "upgrade": { "$ref": "#/$defs/defender.UpgradeStatus" } }, "type": "object" }, "defender.SystemInfo": { "description": "SystemInfo is the OS information of the host", "properties": { "cpuCount": { "description": "CPU count on the host where Defender runs.\n", "type": "integer" }, "freeDiskSpaceGB": { "description": "Free disk space (in GB) on the host where Defender runs.\n", "type": "integer" }, "kernelVersion": { "description": "Kernel version on the host where Defender runs.\n", "type": "string" }, "memoryGB": { "description": "Total memory (in GB) on the host where Defender runs.\n", "format": "double", "type": "number" }, "totalDiskSpaceGB": { "description": "Total disk space (in GB) on the host where Defender runs.\n", "type": "integer" } }, "type": "object" }, "defender.Type": { "description": "Type is the type to be given at startup", "enum": [ [ "none", "docker", "dockerWindows", "containerdWindows", "swarm", "daemonset", "serverLinux", "serverWindows", "cri", "fargate", "appEmbedded", "tas", "tasWindows", "serverless", "ecs", "podman", "eksFargate" ] ], "type": "string" }, "defender.UpgradeStatus": { "description": "UpgradeStatus represents the status of current twistlock defender upgrade", "properties": { "err": { "description": "Error string, if an error occurred.\n", "type": "string" }, "hostname": { "description": "Name of the host where Defender runs.\n", "type": "string" }, "lastModified": { "description": "Datetime of the last upgrade.\n", "format": "date-time", "type": "string" }, "progress": { "description": "Upgrade progress.\n", "type": "integer" } }, "type": "object" }, "int": { "type": "integer" }, "string": { "type": "string" }, "waas.OutOfBandMode": { "description": "OutOfBandMode holds the app firewall out-of-band mode", "enum": [ [ "", "Observation", "Protection" ] ], "type": "string" }, "waas.ProtectionStatus": { "description": "ProtectionStatus describes the status of the WAAS protection", "properties": { "enabled": { "description": "Enabled indicates if WAAS proxy protection is enabled (true) or not (false).\n", "type": "boolean" }, "outOfBandMode": { "$ref": "#/$defs/waas.OutOfBandMode" }, "ports": { "description": "Ports indicates http open ports associated with the container.\n", "items": { "$ref": "#/$defs/int" }, "type": "array" }, "supported": { "description": "Supported indicates if WAAS protection is supported (true) or not (false).\n", "type": "boolean" }, "tlsPorts": { "description": "TLSPorts indicates https open ports associated with the container.\n", "items": { "$ref": "#/$defs/int" }, "type": "array" }, "unprotectedProcesses": { "description": "UnprotectedProcesses holds the processes that support HTTP/HTTPS without WAAS protection.\n", "items": { "$ref": "#/$defs/waas.UnprotectedProcess" }, "type": "array" } }, "type": "object" }, "waas.UnprotectedProcess": { "description": "UnprotectedProcess holds unprotected processes alongside the port", "properties": { "port": { "description": "Port is the process port.\n", "type": "integer" }, "process": { "description": "Process is the process name.\n", "type": "string" }, "tls": { "description": "TLS is the port TLS indication.\n", "type": "boolean" } }, "type": "object" } } }