openapi: 3.2.0 info: description: '# Authentication The Chef Automate API typically uses an API token passed in the header of your API request.' title: Chef Automate API Documentation Secrets Service API termsOfService: https://www.chef.io/terms-and-conditions-of-use/ contact: url: https://www.chef.io/support/ email: support@chef.io license: name: Apache 2.0 url: https://github.com/chef/automate/blob/main/LICENSE version: version not set x-logo: altText: Chef logo url: /images/chef-automate-logo.svg servers: - url: https://automate.chef.io tags: - name: SecretsService x-displayName: Secrets paths: /api/v0/secrets: post: description: 'Creates a secret. Requires values for name, type, and data. Supported types: ssh, winrm, sudo, aws, azure, gcp, service_now Supported keys by type: ssh: username, password, key winrm: username, password sudo: username, password service_now: username, password aws: AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN azure: AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_TENANT_ID azure: AZURE_SUBSCRIPTION_ID is optional gcp: GOOGLE_CREDENTIALS_JSON Example: ``` { "name": "my ssh secret", "type": "ssh", "data": [ { "key": "username", "value": "vagrant" }, { "key": "password", "value": "vagrant"} ] } ``` Authorization Action: ``` secrets:secrets:create ```' tags: - SecretsService summary: Create a secret operationId: SecretsService_Create responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.Id' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/grpc.gateway.runtime.Error' requestBody: content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.Secret' required: true /api/v0/secrets/id/{id}: get: description: 'Reads a secret given the ID of the secret. Note that the secret information (password and key values) will not be returned by the API, as a safety measure. Authorization Action: ``` secrets:secrets:get ```' tags: - SecretsService summary: Read a secret operationId: SecretsService_Read parameters: - description: Unique node ID (UUID). name: id in: path required: true schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.Secret' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/grpc.gateway.runtime.Error' delete: description: 'Deletes a secret given the ID of the secret. Note that any nodes that were using the secret will no longer be associated with the deleted secret. Authorization Action: ``` secrets:secrets:delete ```' tags: - SecretsService summary: Delete a secret operationId: SecretsService_Delete parameters: - description: Unique node ID (UUID). name: id in: path required: true schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.DeleteResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/grpc.gateway.runtime.Error' patch: description: 'Updates a secret. This is a PATCH operation, meaning the details sent in will override/replace those stored in the DB. Secret information that is not in the body of the request will persist. Example: ``` given a credential with a username and password, a user could update the password by passing in the following body, and the name of the secret as well as the username for the secret be unchanged: { "id": "525c013a-2ab3-4e6f-9005-51bc620e9157", "data": [ { "key": "password", "value": "new-value"} ] } ``` Authorization Action: ``` secrets:secrets:update ```' tags: - SecretsService summary: Update a secret operationId: SecretsService_Update parameters: - description: Unique node ID (UUID). name: id in: path required: true schema: type: string responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.UpdateResponse' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/grpc.gateway.runtime.Error' requestBody: content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.Secret' required: true /api/v0/secrets/search: post: description: 'Makes a list of secrets. Supports filtering, pagination, and sorting. Adding a filter narrows the list of secrets to only those that match the filter or filters. Supported filters: type, name Supported sort types: name, type, last modified Example: ``` { "sort": "type", "order": "ASC", "filters": [ { "key": "type", "values": ["ssh","winrm","sudo"] } ], "page":1, "per_page":100 } ``` Authorization Action: ``` secrets:secrets:list ```' tags: - SecretsService summary: List and filter secrets operationId: SecretsService_List responses: '200': description: A successful response. content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.Secrets' default: description: An unexpected error response. content: application/json: schema: $ref: '#/components/schemas/grpc.gateway.runtime.Error' requestBody: content: application/json: schema: $ref: '#/components/schemas/chef.automate.api.secrets.Query' required: true components: schemas: chef.automate.api.common.query.Filter: type: object properties: exclude: description: "Include matches for this filter.(boolean)\n`true` (default) *includes* all nodes that match this filter. \n`false` *excludes* all nodes that match this filter." type: boolean key: description: Field to filter on. type: string values: description: Field values to filter on. type: array items: type: string grpc.gateway.runtime.Error: type: object properties: code: type: integer format: int32 details: type: array items: $ref: '#/components/schemas/google.protobuf.Any' error: type: string message: type: string chef.automate.api.common.query.Kv: type: object properties: key: description: Tag key. type: string value: description: Tag value. type: string chef.automate.api.secrets.Query: type: object properties: filters: description: Use filters to limit the set of secrets. type: array items: $ref: '#/components/schemas/chef.automate.api.common.query.Filter' order: $ref: '#/components/schemas/chef.automate.api.secrets.Query.OrderType' page: description: Starting page for the results. type: integer format: int32 per_page: description: The number of results on each page. type: integer format: int32 sort: description: Sort the results on a specific field. type: string chef.automate.api.secrets.Secrets: type: object properties: secrets: description: List of secrets. type: array items: $ref: '#/components/schemas/chef.automate.api.secrets.Secret' total: type: integer format: int32 title: Total count of secrets chef.automate.api.secrets.Id: type: object properties: id: description: Unique node ID (UUID). type: string google.protobuf.Any: type: object properties: type_url: type: string value: type: string format: byte chef.automate.api.secrets.DeleteResponse: type: object chef.automate.api.secrets.UpdateResponse: type: object chef.automate.api.secrets.Secret: type: object properties: data: description: Secret data, where the kv structs for the credential data live. type: array items: $ref: '#/components/schemas/chef.automate.api.common.query.Kv' id: description: Unique node ID (UUID). type: string last_modified: description: Timestamp denoting when the secret was last modified. type: string format: date-time name: description: User-specified name for the secret. type: string tags: description: Tags to associate with the secret. type: array items: $ref: '#/components/schemas/chef.automate.api.common.query.Kv' type: type: string title: 'Type of credential: ssh, winrm, sudo, aws, azure, gcp, service_now' chef.automate.api.secrets.Query.OrderType: description: Return the results in ascending or descending order. type: string default: ASC enum: - ASC - DESC securitySchemes: APIToken: description: Authenticate with the Automate API using an API Token. type: apiKey name: api-token in: header x-tagGroups: - name: Compliance tags: - ReportingService - StatsService - JobsService - ProfilesService - Comp_Assets - name: Report Manager tags: - ReportManagerService - name: Infra tags: - ConfigMgmt - InfraProxy - name: Ingest tags: - ChefIngester - JobScheduler - name: Node Management tags: - NodeManagerService - NodesService - name: Event Feed tags: - EventFeedService - name: Secrets tags: - SecretsService - name: Applications tags: - service_groups - retention - ApplicationsService - name: Data Feed tags: - DatafeedService - name: Data Lifecycle tags: - DataLifecycle - name: Notifications tags: - Notifications - name: Content Delivery tags: - Cds - name: Audit and Settings tags: - UserSettingsService - name: System tags: - Gateway - Deployment - License - Telemetry - LegacyDataCollector - name: Identity tags: - users - teams - tokens - name: Access Management tags: - policies - roles - projects - rules - Authorization