{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/palo-alto-networks/main/json-schema/palo-alto-networks-shared-registry-specification-schema.json", "title": "shared.RegistrySpecification", "description": "RegistrySpecification contains information for connecting to local/remote registry", "x-generated": "2026-10-04", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/palo-alto-networks-settings-api-openapi.yml#/components/schemas/shared.RegistrySpecification", "properties": { "azureCloudMetadata": { "$ref": "#/$defs/common.CloudMetadata" }, "caCert": { "description": "CACert is the Certificate Authority that signed the registry certificate.\n", "type": "string" }, "cap": { "description": "Specifies the maximum number of images from each repo to fetch and scan, sorted by most recently modified.\n", "type": "integer" }, "collections": { "description": "Specifies the set of Defenders in-scope for working on a scan job.\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "credential": { "$ref": "#/$defs/cred.Credential" }, "credentialID": { "description": "ID of the credentials in the credentials store to use for authenticating with the registry.\n", "type": "string" }, "excludedRepositories": { "description": "Repositories to exclude from scanning.\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "excludedTags": { "description": "Tags to exclude from scanning.\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "gitlabRegistrySpec": { "$ref": "#/$defs/shared.GitlabRegistrySpec" }, "harborDeploymentSecurity": { "description": "Indicates whether the Prisma Cloud plugin uses temporary tokens provided by Harbor to scan images in projects where Harbor's deployment security setting is enabled.\n", "type": "boolean" }, "id": { "description": "ID is a unique identifier of the registry spec.\n", "type": "string" }, "jfrogRepoTypes": { "description": "JFrog Artifactory repository types to scan.\n", "items": { "$ref": "#/$defs/shared.JFrogRepoType" }, "type": "array" }, "lastScanStatus": { "description": "LastScanStatus is the last scan status. we keep both LastScanStatus and ScanStatus in order to not lose the latest scan status when a scan starts.\n", "type": "string" }, "lastScanTime": { "description": "LastScanTime specifies the last time a scan was completed.\n", "format": "date-time", "type": "string" }, "namespace": { "description": "IBM Bluemix namespace https://console.bluemix.net/docs/services/Registry/registry_overview.html#registry_planning.\n", "type": "string" }, "os": { "$ref": "#/$defs/shared.RegistryOSType" }, "registry": { "description": "Registry address (e.g., https://gcr.io).\n", "type": "string" }, "repository": { "description": "Repositories to scan.\n", "type": "string" }, "scanError": { "description": "ScanError is the error received while scanning the specification.\n", "type": "string" }, "scanStatus": { "description": "ScanStatus is the scan status that's updated dynamically during the scan, when the scan finishes - its value is passed to the LastScanStatus field in the DB.\n", "type": "string" }, "scanTime": { "description": "ScanTime specifies the time a scan was started.\n", "format": "date-time", "type": "string" }, "scannedImagesSuccessTotal": { "description": "ScannedImagesSuccessTotal is the total number of registry images that were scanned successfully on the last registry specification scan.\n", "type": "integer" }, "scanners": { "description": "Number of Defenders that can be utilized for each scan job.\n", "type": "integer" }, "tag": { "description": "Tags to scan.\n", "type": "string" }, "version": { "description": "Registry type. Determines the protocol Prisma Cloud uses to communicate with the registry.\n", "type": "string" }, "versionPattern": { "description": "Pattern heuristic for quickly filtering images by tags without having to query all images for modification dates.\n", "type": "string" } }, "type": "object", "$defs": { "common.ACIMetadata": { "properties": { "containerGroup": { "description": ".\n", "type": "string" } }, "type": "object" }, "common.AzureMetadata": { "properties": { "aci": { "$ref": "#/$defs/common.ACIMetadata" }, "resourceGroup": { "description": ".\n", "type": "string" } }, "type": "object" }, "common.CloudMetadata": { "description": "CloudMetadata is the metadata for a cloud provider managed asset (e.g., as part of AWS/GCP/Azure/OCI)", "properties": { "accountID": { "description": "Cloud account ID.\n", "type": "string" }, "awsExecutionEnv": { "description": "AWS execution environment (e.g. EC2/Fargate).\n", "type": "string" }, "azure": { "$ref": "#/$defs/common.AzureMetadata" }, "gcp": { "$ref": "#/$defs/common.GCPCloudMetadata" }, "image": { "description": "The name of the image the cloud managed host or container is based on.\n", "type": "string" }, "labels": { "description": "Cloud provider metadata labels.\n", "items": { "$ref": "#/$defs/common.ExternalLabel" }, "type": "array" }, "name": { "description": "Resource name.\n", "type": "string" }, "ociTenantID": { "description": "OCI Tenant ID.\n", "type": "string" }, "provider": { "$ref": "#/$defs/common.CloudProvider" }, "region": { "description": "Resource's region.\n", "type": "string" }, "resourceID": { "description": "Unique ID of the resource.\n", "type": "string" }, "resourceURL": { "description": "Server-defined URL for the resource.\n", "type": "string" }, "type": { "description": "Instance type.\n", "type": "string" }, "vmID": { "description": "Azure unique vm ID.\n", "type": "string" }, "vmImageID": { "description": "VMImageID holds the VM instance's image ID.\n", "type": "string" } }, "type": "object" }, "common.CloudProvider": { "description": "CloudProvider specifies the cloud provider name", "enum": [ [ "aws", "azure", "gcp", "alibaba", "oci", "others" ] ], "type": "string" }, "common.CloudRunMetadata": { "properties": { "revision": { "description": ".\n", "type": "string" }, "service": { "description": ".\n", "type": "string" } }, "type": "object" }, "common.ExternalLabel": { "description": "ExternalLabel holds an external label with a source and timestamp", "properties": { "key": { "description": "Label key.\n", "type": "string" }, "sourceName": { "description": "Source name (e.g., for a namespace, the source name can be 'twistlock').\n", "type": "string" }, "sourceType": { "$ref": "#/$defs/common.ExternalLabelSourceType" }, "timestamp": { "description": "Time when the label was fetched.\n", "format": "date-time", "type": "string" }, "value": { "description": "Value of the label.\n", "type": "string" } }, "type": "object" }, "common.ExternalLabelSourceType": { "description": "ExternalLabelSourceType indicates the source of the labels", "enum": [ [ "namespace", "deployment", "pod", "aws", "azure", "gcp", "oci" ] ], "type": "string" }, "common.GCPCloudMetadata": { "properties": { "cloudRun": { "$ref": "#/$defs/common.CloudRunMetadata" } }, "type": "object" }, "common.Secret": { "description": "Secret Stores the plain and encrypted version of a value. The plain version is not stored in a database", "properties": { "encrypted": { "description": "Specifies an encrypted value of the secret.\n", "type": "string" }, "plain": { "description": "Specifies the plain text value of the secret.\n", "type": "string" } }, "type": "object" }, "cred.AzureMIType": { "enum": [ [ "user-assigned", "system-assigned" ] ], "type": "string" }, "cred.AzureSPInfo": { "description": "AzureSPInfo contains the Azure credentials needed for certificate based authentications", "properties": { "clientId": { "description": "ClientID is the client identifier.\n", "type": "string" }, "miType": { "$ref": "#/$defs/cred.AzureMIType" }, "subscriptionId": { "description": "SubscriptionID is a GUID that uniquely identifies the subscription to use Azure services.\n", "type": "string" }, "tenantId": { "description": "TenantID is the ID of the AAD directory in which the application was created.\n", "type": "string" } }, "type": "object" }, "cred.Credential": { "description": "Credential specifies the authentication data of an external provider", "properties": { "_id": { "description": "Specifies the unique ID for credential.\n", "type": "string" }, "accountGUID": { "description": "Specifies the unique ID for an IBM Cloud account.\n", "type": "string" }, "accountID": { "description": "Specifies the account identifier. Example: a username, access key, account GUID, and so on.\n", "type": "string" }, "accountName": { "description": "Specifies the name of the cloud account.\n", "type": "string" }, "apiToken": { "$ref": "#/$defs/common.Secret" }, "azureSPInfo": { "$ref": "#/$defs/cred.AzureSPInfo" }, "caCert": { "description": "Specifies the CA certificate for a certificate-based authentication.\n", "type": "string" }, "cloudProviderAccountID": { "description": "Specifies the cloud provider account ID.\n", "type": "string" }, "created": { "description": "Specifies the time when the credential was created (or, when the account ID was changed for AWS).\n", "format": "date-time", "type": "string" }, "description": { "description": "Specifies the description for a credential.\n", "type": "string" }, "external": { "description": "Indicates whether the credential was onboarded from the Prisma platform.\n", "type": "boolean" }, "global": { "description": "Indicates whether the credential scope is global.\nAvailable values are:\ntrue: Global\nfalse: Not Global\nNote: For GCP, the credential scope is the organization.\n", "type": "boolean" }, "lastModified": { "description": "Specifies the time when the credential was last modified.\n", "format": "date-time", "type": "string" }, "ociCred": { "$ref": "#/$defs/cred.OCICred" }, "owner": { "description": "Specifies the user who created or modified the credential.\n", "type": "string" }, "prismaLastModified": { "description": "Specifies the time when the account was last modified by Prisma Cloud Compute.\n", "format": "int64", "type": "integer" }, "roleArn": { "description": "Specifies the Amazon Resource Name (ARN) of the role to be assumed.\n", "type": "string" }, "secret": { "$ref": "#/$defs/common.Secret" }, "skipVerify": { "description": "Indicates whether to skip the certificate verification in TLS communication.\n", "type": "boolean" }, "stsEndpoints": { "description": "Specifies a list of specific endpoints for use in STS sessions in various regions.\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "tokens": { "$ref": "#/$defs/cred.TemporaryToken" }, "type": { "$ref": "#/$defs/cred.Type" }, "url": { "description": "Specifies the base server URL.\n", "type": "string" }, "useAWSRole": { "description": "Indicates whether to authenticate using the IAM Role attached to the instance.\nAvailable values are:\ntrue: Authenticate with the attached credentials\nfalse: Don’t authenticate with the attached credentials.\n", "type": "boolean" }, "useSTSRegionalEndpoint": { "description": "Indicates whether to use the regional STS endpoint for an STS session.\nAvailable values are:\ntrue: Use the regional STS\nfalse: Don’t use the regional STS.\n", "type": "boolean" } }, "type": "object" }, "cred.OCICred": { "description": "OCICred are additional parameters required for OCI credentials", "properties": { "fingerprint": { "description": "Fingerprint is the public key signature.\n", "type": "string" }, "tenancyId": { "description": "TenancyID is the OCID of the tenancy.\n", "type": "string" } }, "type": "object" }, "cred.TemporaryToken": { "description": "TemporaryToken is a temporary session token for cloud provider APIs\nAWS - https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html\nGCP - https://cloud.google.com/iam/docs/creating-short-lived-service-account-credentials\nAzure - https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/what-is-single-sign-on", "properties": { "awsAccessKeyId": { "description": "Specifies a temporary access key.\n", "type": "string" }, "awsSecretAccessKey": { "$ref": "#/$defs/common.Secret" }, "duration": { "description": "Specifies a duration for the token.\n", "format": "int64", "type": "integer" }, "expirationTime": { "description": "Specifies an expiration time for the token.\n", "format": "date-time", "type": "string" }, "token": { "$ref": "#/$defs/common.Secret" } }, "type": "object" }, "cred.Type": { "description": "Type specifies the credential type", "enum": [ [ "aws", "azure", "gcp", "ibmCloud", "oci", "apiToken", "basic", "dtr", "kubeconfig", "certificate", "gitlabToken" ] ], "type": "string" }, "shared.GitlabRegistrySpec": { "description": "GitlabRegistrySpec represents a specification for registry scanning in GitLab", "properties": { "apiDomainName": { "description": ".\n", "type": "string" }, "excludedGroupIDs": { "description": ".\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "groupIDs": { "description": ".\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "projectIDs": { "description": ".\n", "items": { "$ref": "#/$defs/string" }, "type": "array" }, "userID": { "description": ".\n", "type": "string" } }, "type": "object" }, "shared.JFrogRepoType": { "description": "JFrogRepoType represents the type of JFrog Artifactory repository", "enum": [ [ "local", "remote", "virtual" ] ], "type": "string" }, "shared.RegistryOSType": { "description": "RegistryOSType specifies the registry images base OS type", "enum": [ [ "linux", "linuxARM64", "windows" ] ], "type": "string" }, "string": { "type": "string" } } }