openapi: 3.0.1 info: title: FlashArray REST Active Directory Policies - Management Access API version: '2.52' description: 'Active Directory configuration authenticates users for NFS using Kerberos or SMB using Kerberos or New Technology LAN Manager (NTLM). Active Directory is also used to authorize users by mapping identities across the NFS and SMB protocols by using LDAP queries. ' servers: - url: / tags: - name: Policies - Management Access description: Manages management access policies. These policies are composed of rules which govern an administrative user's permissions when managing resources. paths: /api/2.26/admins/management-access-policies: get: tags: - Policies - Management Access summary: Pure Storage GET Admins/management-access-policies description: 'List management access policies mapped to admins. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Admins/management-access-policies description: Map an admin to a management access policy. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextResponse' delete: tags: - Policies - Management Access summary: Pure Storage DELETE Admins/management-access-policies description: Remove the mapping of an admin to a management access policies. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} /api/2.26/directory-services/roles/management-access-policies: get: tags: - Policies - Management Access summary: Pure Storage GET Directory-services/roles/management-access-policies description: 'List management access policies mapped to directory service group mappings. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Directory-services/roles/management-access-policies description: Map a directory service group to a management access policy. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberResponse' delete: tags: - Policies - Management Access summary: Pure Storage DELETE Directory-services/roles/management-access-policies description: Remove the mapping of a directory service group to a management access policies. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} /api/2.26/management-access-policies: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies description: 'Displays a list of management access policies, which can be assigned to admins, API clients, or directory-service roles. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPoliciesGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPoliciesGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Management-access-policies description: 'Create a new management access policy, which can be assigned to admins, API clients, or directory-service roles. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Names_required' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyPost' required: false x-codegen-request-body-name: policy responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPoliciesResponse' x-codegen-request-body-name: policy delete: tags: - Policies - Management Access summary: Pure Storage DELETE Management-access-policies description: Delete one or more management access policies. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} patch: tags: - Policies - Management Access summary: Pure Storage PATCH Management-access-policies description: 'Modify an existing management access policy, which can be assigned to admins, API clients, or directory-service roles. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicy' required: true x-codegen-request-body-name: policy responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPoliciesResponse' x-codegen-request-body-name: policy /api/2.26/management-access-policies/admins: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/admins description: 'List management access policies mapped to admins. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Management-access-policies/admins description: Map an admin to a management access policy. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextResponse' delete: tags: - Policies - Management Access summary: Pure Storage DELETE Management-access-policies/admins description: Remove the mapping of an admin to a management access policies. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} /api/2.26/management-access-policies/directory-services/roles: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/directory-services/roles description: 'List management access policies mapped to directory service group mappings. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Management-access-policies/directory-services/roles description: Map a directory service group to a management access policy. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberResponse' delete: tags: - Policies - Management Access summary: Pure Storage DELETE Management-access-policies/directory-services/roles description: Remove the mapping of a directory service group to a management access policies. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} /api/2.26/management-access-policies/members: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/members description: 'List the members mapped to management access policies. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Member_ids' - $ref: '#/components/parameters/Member_names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/PolicyMemberContextGetResponse' /api/2.26/management-access-policies/roles: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/roles description: 'List management access policy roles. Returns all built-in and self created roles. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolesGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolesGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Management-access-policies/roles description: 'Create a new custom management access policy role. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Names_required' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePost' required: false x-codegen-request-body-name: role responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolesResponse' x-codegen-request-body-name: role delete: tags: - Policies - Management Access summary: Pure Storage DELETE Management-access-policies/roles description: 'Delete one or more management access policy roles. Self created roles that are referenced by any access policy cannot be deleted. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} /api/2.26/management-access-policies/roles/permissions: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/roles/permissions description: 'List permissions for self created management access policy roles. Requires exactly one of names, ids, role_names, or role_ids to be in the query parameters. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Management_access_role_ids' - $ref: '#/components/parameters/Management_access_role_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionsGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionsGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Management-access-policies/roles/permissions description: 'Add a new permission for a management access policy role. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Management_access_role_ids' - $ref: '#/components/parameters/Management_access_role_names' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionPost' required: true x-codegen-request-body-name: permission responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionsResponse' x-codegen-request-body-name: permission delete: tags: - Policies - Management Access summary: Pure Storage DELETE Management-access-policies/roles/permissions description: 'Remove one or more permissions from a management access policy role. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: {} patch: tags: - Policies - Management Access summary: Pure Storage PATCH Management-access-policies/roles/permissions description: 'Modify permissions for a management access policy roles. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionPatch' required: true x-codegen-request-body-name: permission responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionsResponse' x-codegen-request-body-name: permission /api/2.26/management-access-policies/roles/permissions/supported-resources: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/roles/permissions/supported-resources description: 'List the available resource terms to use when configuring custom role permissions. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Sort' responses: '200': description: OK headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionSupportedResourcesGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' headers: X-Request-ID: description: Supplied by client during request or generated by server. schema: type: string content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionSupportedResourcesGetResponse' /api/2.26/management-access-policies/rules: get: tags: - Policies - Management Access summary: Pure Storage GET Management-access-policies/rules description: Displays a list of management access policy rules. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Allow_errors' - $ref: '#/components/parameters/Context_names_get' - $ref: '#/components/parameters/Continuation_token' - $ref: '#/components/parameters/Filter' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Limit' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Offset' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Sort' responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRuleGetResponse' '207': description: 'Partial success. Some resources were returned, but there were also errors possibly preventing some resources from being returned. ' content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRuleGetResponse' post: tags: - Policies - Management Access summary: Pure Storage POST Management-access-policies/rules description: 'Create a new management access policy rule. Either `policy_ids` or `policy_names` parameter is required. ' parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Before_rule_id' - $ref: '#/components/parameters/Before_rule_name' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Policy_ids' - $ref: '#/components/parameters/Policy_names' - $ref: '#/components/parameters/Concurrency_versions' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRule' required: true x-codegen-request-body-name: rule responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRuleResponse' x-codegen-request-body-name: rule delete: tags: - Policies - Management Access summary: Pure Storage DELETE Management-access-policies/rules description: Delete one or more management access policy rules. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Concurrency_versions' responses: '200': description: OK content: {} patch: tags: - Policies - Management Access summary: Pure Storage PATCH Management-access-policies/rules description: Modify an existing management access policy rule. parameters: - $ref: '#/components/parameters/XRequestId' - $ref: '#/components/parameters/Before_rule_id' - $ref: '#/components/parameters/Before_rule_name' - $ref: '#/components/parameters/Context_names' - $ref: '#/components/parameters/Ids' - $ref: '#/components/parameters/Names' - $ref: '#/components/parameters/Concurrency_versions' requestBody: content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRule' required: true x-codegen-request-body-name: rule responses: '200': description: OK content: application/json: schema: $ref: '#/components/schemas/ManagementAccessPolicyRuleResponse' x-codegen-request-body-name: rule components: schemas: _referenceWithoutType: type: object properties: id: description: 'A globally unique, system-generated ID. The ID cannot be modified. ' type: string name: description: 'The resource name, such as volume name, pod name, snapshot name, and so on. ' type: string ManagementAccessPolicyRolePermissionSupportedResourcesGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionSupportedResourcesResponse' - $ref: '#/components/schemas/_errorContextResponse' _errorContextResponseErrors: type: object properties: context: description: 'Contains information relating to the cause of this error, or the name of the object that was being processed when the error was encountered. This may be `null` for more general errors. ' type: string location_context: description: 'Contains information relating to the context in which the request was executing when the error occurred. For example, this may be the name of an array in the same fleet. This may be `null` for more general errors, or if no explicit `context` parameter was provided with the request. ' title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' message: description: A description of the error which occurred. type: string example: Resource does not exist. _errorContextResponse: type: object properties: errors: description: The list of errors encountered when attempting to perform an operation. type: array readOnly: true items: $ref: '#/components/schemas/_errorContextResponseErrors' ManagementAccessPolicyRule: allOf: - $ref: '#/components/schemas/_context' - $ref: '#/components/schemas/ManagementAccessPolicyRuleBase' - $ref: '#/components/schemas/_policyRuleIndex' - type: object properties: policy: description: The policy to which this rule belongs. readOnly: true title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' policy_version: description: 'The policy''s version. This can be used when updating the resource to ensure there aren''t any updates to the policy since the resource was read. ' type: string readOnly: true ManagementAccessPolicyRuleGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/ManagementAccessPolicyRuleResponse' - $ref: '#/components/schemas/_errorContextResponse' PolicyBaseContext: allOf: - $ref: '#/components/schemas/PolicyBase' - $ref: '#/components/schemas/_context' ManagementAccessPoliciesResponse: type: object properties: items: description: A list of management access policy configuration objects. type: array items: $ref: '#/components/schemas/ManagementAccessPolicy' PolicyBase: allOf: - $ref: '#/components/schemas/PolicyBaseRenameable' _resource: description: 'An ordinary (as opposed to built-in) resource that can be created, named, renamed or deleted by the user. This might be a virtual resource (e.g., a file system), or correspond to something in the environment, like a host or a server. ' type: object properties: id: description: 'A globally unique, system-generated ID. The ID cannot be modified and cannot refer to another resource. ' type: string readOnly: true name: description: 'A user-specified name. The name must be locally unique and can be changed. ' type: string ManagementAccessPolicyRuleInPolicy: allOf: - $ref: '#/components/schemas/ManagementAccessPolicyRuleBase' - $ref: '#/components/schemas/_policyRuleIndexInPolicy' PolicyMemberContextGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/PolicyMemberContextResponse' - $ref: '#/components/schemas/_errorContextResponse' _fixedReferenceWithoutType: type: object properties: id: description: 'A globally unique, system-generated ID. The ID cannot be modified. ' type: string readOnly: true name: description: 'The resource name, such as volume name, file system name, snapshot name, and so on. ' type: string readOnly: true x-readOnly: true ManagementAccessPolicyRolePermissionSupportedResource: allOf: - $ref: '#/components/schemas/_policyManagementAccessRolePermissionSupportedResource' _policyManagementAccessRolePermissionPatch: type: object properties: actions: description: 'List of allowed actions for this permission. Case insensitive. Valid values include `get`, `post`, `patch`, `delete`, or `all`. If `all` is specified, it may not be provided with other action strings. Duplicated actions will be ignored. ' type: array items: type: string example: - get - post ManagementAccessPolicy: allOf: - $ref: '#/components/schemas/PolicyBaseContext' - $ref: '#/components/schemas/_version' - $ref: '#/components/schemas/_context' - type: object properties: aggregation_strategy: description: 'When this is set to `least-common-permissions`, any users to whom this policy applies can receive no access rights exceeding those defined in this policy''s capability and resource. When this is set to `all-permissions`, any users to whom this policy applies are capable of receiving additional access rights from other policies that apply to them. If not specified, defaults to `all-permissions`. ' type: string rules: type: array maxItems: 200 items: $ref: '#/components/schemas/ManagementAccessPolicyRuleInPolicy' description: 'All of the rules that are part of this policy. The order is the evaluation order. ' _referenceWritable: allOf: - $ref: '#/components/schemas/_referenceWithoutType' - type: object properties: resource_type: description: 'Type of the object (full name of the endpoint). Valid values are `hosts`, `host-groups`, `network-interfaces`, `pods`, `ports`, `pod-replica-links`, `subnets`, `volumes`, `volume-snapshots`, `volume-groups`, `directories`, `policies/nfs`, `policies/smb`, `policies/snapshot`, etc. ' type: string x-aliases: - _reference ManagementAccessPolicyRolesResponse: type: object properties: items: description: 'Displays a list of all items after filtering. If applicable, the values are displayed for each name. ' type: array items: $ref: '#/components/schemas/ManagementAccessPolicyRole' ManagementAccessPolicyRolePermission: allOf: - $ref: '#/components/schemas/_policyManagementAccessRolePermission' - $ref: '#/components/schemas/_builtIn' ManagementAccessPoliciesGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/ManagementAccessPoliciesResponse' - $ref: '#/components/schemas/_errorContextResponse' ManagementAccessPolicyRolesGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/ManagementAccessPolicyRolesResponse' - $ref: '#/components/schemas/_errorContextResponse' PolicyMemberContextResponse: type: object properties: items: description: A list of members for policies. type: array items: $ref: '#/components/schemas/PolicyMemberContext' ManagementAccessPolicyRolePermissionSupportedResourcesResponse: type: object properties: items: description: 'Displays a list of all items after filtering. If applicable, the values are displayed for each name. ' type: array items: $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionSupportedResource' ManagementAccessPolicyRolePermissionPost: allOf: - $ref: '#/components/schemas/_policyManagementAccessRolePermissionPost' _policyManagementAccessRolePermissionSupportedResource: allOf: - $ref: '#/components/schemas/_context' - type: object properties: description: description: 'Description of what this resource controls. ' type: string readOnly: true example: Manage membership of management access policies with admins and directory roles. name: description: 'The canonical resource term to use when configuring management access policy role permissions. ' type: string readOnly: true example: policies/management-access/member supported_actions: description: 'List of supported actions for this resource. Case insensitive. Values include `get`, `post`, `patch`, `delete`. Note that `all` is supported by default and not listed here. ' type: array items: type: string example: - get - post _builtIn: type: object properties: id: description: 'A non-modifiable, globally unique ID chosen by the system. ' type: string readOnly: true name: description: Name of the object (e.g., a file system or snapshot). type: string readOnly: true ManagementAccessPolicyRuleResponse: type: object properties: items: description: 'Displays a list of all items after filtering. ' type: array items: $ref: '#/components/schemas/ManagementAccessPolicyRule' ManagementAccessPolicyRolePost: allOf: - $ref: '#/components/schemas/_policyManagementAccessRolePost' _policyManagementAccessRolePermissionPost: type: object properties: actions: description: 'List of allowed actions for this permission. Case insensitive. Valid values include `get`, `post`, `patch`, `delete`, or `all`. If `all` is specified, it may not be provided with other action strings. Duplicated actions will be ignored. ' type: array items: type: string example: - post - patch resource: description: 'The resource that this permission applies to. Both canonical (long) and short resource names are supported. Each provided permission resource governs access to one or more API endpoints, as multiple endpoints can perform the same logical functions or subsets of a logical function. For more details on specific API Endpoints governed by a given resource, consult the REST API user guide. ' type: string example: purestorage.com/api/v2/certificates, certificates ManagementAccessPolicyRolePermissionsGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/ManagementAccessPolicyRolePermissionsResponse' - $ref: '#/components/schemas/_errorContextResponse' PolicyMemberResponse: type: object properties: items: description: A list of members for policies. type: array items: $ref: '#/components/schemas/PolicyMember' PolicyMemberGetResponse: allOf: - $ref: '#/components/schemas/PageInfo' - $ref: '#/components/schemas/PolicyMemberResponse' ManagementAccessPolicyRuleBase: allOf: - $ref: '#/components/schemas/_builtIn' - properties: role: description: 'Role defines a set of permissions applicable in a scope. `viewer` grants users the ability to read within a scope. `support` grants the ability to perform general support-related actions as well as read within a scope. `storage` grants access to all storage operations within a scope. `admin` grants access to all operations. ' title: ReferenceWritable allOf: - $ref: '#/components/schemas/_referenceWritable' scope: description: 'Reference to the resource (e.g. arrays, realms) which specifies the scope that the role applies. One of `id` or `name` parameter is required, and `resource_type` must be set. ' title: ReferenceWritable allOf: - $ref: '#/components/schemas/_referenceWritable' _policyManagementAccessRolePermission: allOf: - $ref: '#/components/schemas/_context' - type: object properties: actions: description: 'List of allowed actions for this permission. Case insensitive. Valid values include `get`, `post`, `patch`, `delete`, or `all`. ' type: array items: type: string example: - post - patch resource: description: 'The resource endpoint that this permission applies to. Each provided permission resource governs access to one or more API endpoints, as multiple endpoints can perform the same logical functions or subsets of a logical function. For more details on specific API Endpoints governed by a given resource, consult the REST API user guide. ' type: string example: purestorage.com/api/v2/dns role: description: 'Reference to the admin role that this permission belongs to. ' readOnly: true title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' _context: type: object properties: context: description: 'The context in which the operation was performed. Valid values include a reference to any array which is a member of the same fleet or to the fleet itself. Other parameters provided with the request, such as names of volumes or snapshots, are resolved relative to the provided `context`. ' readOnly: true title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' ManagementAccessPolicyPost: allOf: - $ref: '#/components/schemas/PolicyBase' - properties: aggregation_strategy: description: 'When this is set to `least-common-permissions`, any users to whom this policy applies can receive no access rights exceeding those defined in this policy''s capability and resource. When this is set to `all-permissions`, any users to whom this policy applies are capable of receiving additional access rights from other policies that apply to them. If not specified, defaults to `all-permissions`. ' type: string rules: type: array maxItems: 200 items: $ref: '#/components/schemas/ManagementAccessPolicyRuleInPolicy' description: 'All of the rules that are part of this policy. The order is the evaluation order. ' PolicyBaseRenameable: allOf: - $ref: '#/components/schemas/_resource' - $ref: '#/components/schemas/_realmsReference' - type: object properties: enabled: description: 'If `true`, the policy is enabled. If not specified, defaults to `true`. ' type: boolean is_local: description: Whether the policy is defined on the local array. type: boolean readOnly: true location: description: Reference to the array where the policy is defined. title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' policy_type: description: 'Type of the policy. Valid values include `alert`, `audit`, `bucket-access`, `cross-origin-resource-sharing`, `network-access`, `nfs`, `object-access`, `s3-export`, smb-client`, `smb-share`, `ssh-certificate-authority`, and `telemetry-metrics`. ' type: string readOnly: true _policyRuleIndex: type: object properties: index: description: 'The index within the policy. The `index` indicates the order the rules are evaluated. NOTE: It is recommended to use the query param `before_rule_id` to do reordering to avoid concurrency issues, but changing `index` is also supported. `index` can not be changed if `before_rule_id` or `before_rule_name` are specified. ' type: integer format: int32 PolicyMemberContext: allOf: - $ref: '#/components/schemas/PolicyMember' - $ref: '#/components/schemas/_context' ManagementAccessPolicyRolePermissionPatch: allOf: - $ref: '#/components/schemas/_policyManagementAccessRolePermissionPatch' _policyManagementAccessRole: allOf: - $ref: '#/components/schemas/_context' - type: object properties: description: description: 'Optional description of the role. Maximum 256 characters. ' type: string maxLength: 256 example: Manages file system snapshots and restores pure_defined: description: 'If `true`, then the role is system-created (Pure-defined), such as `admin`, `storage`, `support`, or `viewer`. If `false`, then the role is customer-defined. ' type: boolean readOnly: true _realmsReference: type: object properties: realms: description: 'Reference to the realms this resource belongs to. The value is set to empty array when the resource lives outside of a realm. ' type: array readOnly: true items: $ref: '#/components/schemas/_fixedReference' _fixedReference: allOf: - $ref: '#/components/schemas/_fixedReferenceWithoutType' - type: object properties: resource_type: description: 'Type of the object (full name of the endpoint). Valid values are the unique part of the resource''s REST endpoint. For example, a reference to a file system would have a `resource_type` of `file-systems`. ' type: string readOnly: true _policyManagementAccessRolePost: type: object properties: description: description: 'Optional description of the role. Maximum 256 characters. ' type: string maxLength: 256 example: Manages file system snapshots and restores PageInfo: type: object properties: continuation_token: description: 'Continuation token that can be provided in the `continuation_token` query param to get the next page of data. If you use the `continuation_token` to page through data you are guaranteed to get all items exactly once regardless of how items are modified. If an item is added or deleted during the pagination then it may or may not be returned. The `continuation_token` is generated if the `limit` is less than the remaining number of items, and the default sort is used (no sort is specified). ' type: string total_item_count: description: Total number of items after applying `filter` params. type: integer format: int32 ManagementAccessPolicyRole: allOf: - $ref: '#/components/schemas/_policyManagementAccessRole' - $ref: '#/components/schemas/_builtIn' _policyRuleIndexInPolicy: type: object properties: index: description: 'The index within the policy. The `index` indicates the order the rules are evaluated. ' type: integer format: int32 readOnly: true ManagementAccessPolicyRolePermissionsResponse: type: object properties: items: description: 'Displays a list of all items after filtering. If applicable, the values are displayed for each name. ' type: array items: $ref: '#/components/schemas/ManagementAccessPolicyRolePermission' _version: type: object properties: version: description: 'A hash of the other properties of this resource. This can be used when updating the resource to ensure there aren''t any updates since the resource was read. ' type: string readOnly: true PolicyMember: type: object properties: member: description: Reference to the resource the policy is applied to. title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' policy: description: Reference to the policy. title: FixedReference allOf: - $ref: '#/components/schemas/_fixedReference' parameters: Filter: name: filter in: query description: 'Narrows down the results to only the response objects that satisfy the filter criteria. ' schema: type: string Offset: name: offset in: query description: 'The offset of the first resource to return from a collection. ' schema: type: integer format: int32 minimum: 0 example: 10 Concurrency_versions: name: versions in: query description: 'A comma-separated list of versions. This is an optional query param used for concurrency control. The ordering should match the names or ids query param. This will fail with a 412 Precondition failed if the resource was changed and the current version of the resource doesn''t match the value in the query param. ' style: form explode: false schema: type: array items: type: string Allow_errors: name: allow_errors in: query description: 'If set to `true`, the API will allow the operation to continue even if there are errors. Any errors will be returned in the `errors` field of the response. If set to `false`, the operation will fail if there are any errors. ' schema: type: boolean default: false Before_rule_id: name: before_rule_id in: query description: 'The id of the rule to insert or move a rule before. This cannot be provided together with the `before_rule_name` query parameter. ' schema: type: string Before_rule_name: name: before_rule_name in: query description: 'The name of the rule to insert or move a rule before. This cannot be provided together with the `before_rule_id` query parameter. ' schema: type: string Policy_ids: name: policy_ids in: query description: 'A comma-separated list of policy IDs. If after filtering, there is not at least one resource that matches each of the elements of `policy_ids`, then an error is returned. This cannot be provided together with the `policy_names` query parameter. ' style: form explode: false schema: type: array items: type: string Continuation_token: name: continuation_token in: query description: 'A token used to retrieve the next page of data with some consistency guaranteed. The token is a Base64 encoded value. Set `continuation_token` to the system-generated token taken from the `x-next-token` header field of the response. A query has reached its last page when the response does not include a token. Pagination requires the `limit` and `continuation_token` query parameters. ' schema: type: string Policy_names: name: policy_names in: query description: 'A comma-separated list of policy names. ' style: form explode: false schema: type: array items: type: string Context_names: name: context_names in: query description: 'Performs the operation on the context specified. If specified, the context names must be an array of size 1, and the single element must be the name of an array in the same fleet or the name of the fleet itself. If not specified, the context will default to the array that received this request. Other parameters provided with the request, such as names of volumes or snapshots, are resolved relative to the provided `context`. ' style: form explode: false schema: type: array items: type: string Management_access_role_ids: name: role_ids in: query description: 'A comma-separated list of management access policy roles ids. If after filtering, there is not at least one resource that matches each of the elements of `role_ids`, then an error is returned. This cannot be provided together with the `ids`, `names` or `role_names` query parameters. ' style: form explode: false schema: type: array items: type: string XRequestId: name: X-Request-ID in: header description: 'Supplied by client during request or generated by server. ' schema: type: string Limit: name: limit in: query description: 'Limits the size of the response to the specified number of objects on each page. To return the total number of resources, set `limit=0`. The total number of resources is returned as a `total_item_count` value. If the page size requested is larger than the system maximum limit, the server returns the maximum limit, disregarding the requested page size. ' schema: type: integer format: int32 minimum: 0 example: 10 Names: name: names in: query description: 'Performs the operation on the unique names specified. Enter multiple names in comma-separated format. For example, `name01,name02`. If there is not at least one resource that matches each of the elements of `names`, then an error is returned, except when creating new resources. ' style: form explode: false schema: type: array items: type: string Management_access_role_names: name: role_names in: query description: 'A comma-separated list of management access policy roles names. If there is not at least one resource that matches each of the elements of `role_names`, then an error is returned. This cannot be provided together with the `ids`, `names`, or `role_ids` query parameters. ' style: form explode: false schema: type: array items: type: string Context_names_get: name: context_names in: query description: 'Performs the operation on the unique contexts specified. If specified, each context name must be the name of an array in the same fleet or the name of the fleet itself. If not specified, the context will default to the array that received this request. Other parameters provided with the request, such as names of volumes or snapshots, are resolved relative to the provided `context`. Enter multiple names in comma-separated format. For example, `name01,name02`. ' style: form explode: false schema: type: array items: type: string Member_ids: name: member_ids in: query description: 'A comma-separated list of member IDs. If after filtering, there is not at least one resource that matches each of the elements of `member_ids`, then an error is returned. This cannot be provided together with the `member_names` query parameter. ' style: form explode: false schema: type: array items: type: string Member_names: name: member_names in: query description: 'A comma-separated list of member names. ' style: form explode: false schema: type: array items: type: string Ids: name: ids in: query description: 'A comma-separated list of resource IDs. If after filtering, there is not at least one resource that matches each of the elements of `ids`, then an error is returned. This cannot be provided together with the `name` or `names` query parameters. ' style: form explode: false schema: type: array items: type: string Sort: name: sort in: query description: 'Sort the response by the specified fields (in descending order if ''-'' is appended to the field name). NOTE: If you provide a sort you will not get a `continuation_token` in the response. ' style: form explode: false schema: type: array items: pattern: ^[a-z]+(_[a-z]+)*-? type: string Names_required: name: names in: query description: 'A comma-separated list of resource names. ' required: true style: form explode: false schema: type: array items: type: string