HTTP API
The UI talks to the server over a JSON API under /api/v1/ and WebSockets under /ws/. You can call the same API from scripts and tools. The MCP server is a client of it.
The API follows the UI and may change between minor versions; see API stability.
Authentication
Section titled “Authentication”Requests are authenticated the same way as the browser:
| Auth mode | Send |
|---|---|
local |
Nothing. Every request is the local user |
oidc |
Authorization: Bearer <token> from your identity provider |
impersonation |
Go through your auth proxy, which adds X-Forwarded-User and X-Forwarded-Groups |
Requests that change something (POST, PUT, PATCH, DELETE) must also carry Authorization, X-Requested-With, X-CSRF-Token or Content-Type: application/json; otherwise they are rejected as a possible cross-site request.
Every Kubernetes call runs as the authenticated user, so the API returns the same 403 you would get from kubectl.
Other request headers KubeGlass reads:
| Header | Does |
|---|---|
X-Session-ID |
The browser session, and with it the chosen cluster. Without it, the kubeglass-session-id cookie is used, and a new session starts when there is neither, or when the session belongs to another user |
X-Impersonate-User, X-Impersonate-Group |
Act as another user and groups, like kubectl --as and --as-group, after KubeGlass checks that you may impersonate them. Groups may repeat or be comma-separated. WebSockets take as and asGroup query parameters instead |
X-KubeGlass-Read-Only: 1 |
Refuse the request with 403 read_only if it would change the cluster. The UI sends it for a cluster you marked read-only |
Choosing the cluster
Section titled “Choosing the cluster”Requests act on the session’s current context. Switch it with PUT /api/v1/contexts/{name}/switch.
Responses and errors
Section titled “Responses and errors”Successful responses put the result in data, with meta for paged lists. Errors have a status code and a body like:
{ "error": "not_found", "message": "pods \"web-1\" not found", "requestId": "4f1c…"}error is a stable code; see Error codes. Include requestId when you report a problem: it appears in the server log next to the failure.
Status summaries
Section titled “Status summaries”Lists from /api/v1/objects, single-object GETs and /ws/watch events come with a summary of each object’s status, so a client doesn’t need rules for every kind:
| Field | Holds |
|---|---|
tone |
ok, warn, error, progress or neutral (kinds with no health of their own, such as ConfigMaps) |
state |
For pods, the STATUS column of kubectl get pods. For other kinds a code such as Available, Progressing, Degraded, ScaledDown, Complete, Failed, Running, Suspended, Active, Bound, Pending, Ready, NotReady, Cordoned or Terminating |
ready |
ready/total: a pod’s containers, a workload’s replicas, a job’s completions |
restarts |
A pod’s container restarts |
problem |
Empty when the object is fine. Pod codes such as CrashLoop, ImagePull, ConfigError, OOMKilled, Unschedulable; for other kinds RolloutStuck, Unavailable, ReplicaFailure, JobFailed, CronJobFailing, NodeNotReady, NodePressure, PVCPending, PVCLost, PVFailed, HPAUnable, PDBBlocking, NamespaceStuck, CertNotReady, CertExpiring, ArgoDegraded, ArgoOutOfSync, ConditionFalse for custom resources whose Ready, Available, Healthy or Synced condition is False, and in problems only AlertFiring for a firing Alertmanager alert about the object (state is the alert’s name, message its summary) |
container |
The container a pod’s problem is about |
message |
The cluster’s own words: a condition, termination or scheduler message |
since |
When the state or problem began, if known (RFC 3339) |
GET /api/v1/objects/{group}/{version}/{resource} lists any kind, custom resources included (_core stands for the core group). It takes namespace, labelSelector and fieldSelector, returns every object (it follows the API server’s continue tokens) and answers { "data": [...], "summaries": { "<uid>": {...} } }. With table=1 it also returns columns and cells (by UID) from the API server’s Table form, which are the columns kubectl get prints, a custom resource’s printer columns included. Objects come without managedFields, and Secrets keep their keys with empty values.
Search
Section titled “Search”POST /api/v1/search with { "query": "web prod", "namespace": "", "maxResults": 50 } searches, as you, every kind KubeGlass keeps in its cache (all the built-in kinds the UI lists, except events). It looks at names, namespaces, kinds, labels, container images and each object’s state and problem, so crash or pending finds objects in that state, and every word must match. Results come best first, 50 by default and at most 100, each { "type": "resource", "score", "resource": { group, version, resource, kind, namespace, name, uid, labels, summary, url } }. With a namespace, cluster-scoped kinds are still searched. If you can’t list a kind in every namespace, search finds it only when you give a namespace.
Events
Section titled “Events”GET /api/v1/events (or /api/v1/namespaces/{namespace}/events) lists events, newest first, with repeats merged. involvedKind and involvedName pick one object’s events. With includeOwned=true and a namespace, the events of what that object owns come too, at any depth: a Deployment’s ReplicaSets and their Pods, a CronJob’s Jobs and Pods, a StatefulSet’s Pods. A workload’s own events rarely say why its pods fail; its pods’ events do (image pulls, scheduling, back-offs). type (Normal or Warning), reason and severity filter further.
Alertmanager and Prometheus
Section titled “Alertmanager and Prometheus”KubeGlass uses one Alertmanager and one Prometheus: the URLs in Settings, or the ones it finds in its current context. They answer only for that cluster. For a session on another cluster, GET /api/v1/metrics/alerts returns no alerts, GET /api/v1/alertmanager/status returns available: false with otherCluster naming the cluster KubeGlass uses, silences answer 404 dependency_unavailable, and POST /api/v1/metrics/query answers 503 prometheus_other_cluster.
Problems
Section titled “Problems”GET /api/v1/problems?namespace= lists what needs attention in the cluster, one row per object: every object whose summary has tone error or warn, errors first, then the longest-standing. Pods are rolled up to the controller at the top of their owners (a ReplicaSet’s Deployment, a Job’s CronJob), so three crash-looping pods of one Deployment are one row with count 3, owner set and from naming the pod the summary is from. On a chain of owners the finding that says most wins: a workload’s own Unavailable is left out when its pods say why, and a failed Job’s pods are left out because the Job’s failure says more. It reads pods, workloads, jobs, CronJobs, nodes, PVCs, autoscalers, disruption budgets, namespaces and Services, plus cert-manager Certificates and Argo CD Applications when those are installed.
Each row can carry:
| Field | Holds |
|---|---|
also |
The object’s other problems, each { summary, count }, and Services its pods leave without ready endpoints, as { summary: { problem: "NoReadyEndpoints" }, object: { kind: "Service", name } } |
alerts |
Firing Alertmanager alerts of severity critical or warning whose labels (pod, deployment, statefulset, daemonset, job_name, cronjob, persistentvolumeclaim, horizontalpodautoscaler, service or node) name the object or one it owns, as { name, tone, severity, summary, since } |
change |
The last change the change recorder saw (see Timeline) to the object or to a ConfigMap or Secret its pods read, in the day before the problem began, if you may list that kind there |
An object with only an alert gets a row whose problem is AlertFiring. Alerts are included for the cluster KubeGlass polls Alertmanager in, if you may list pods there (in the namespace asked for, or everywhere); those that name no object are listed in alerts as { name, tone, severity, namespace, summary, since, labels }. unavailable names the sources you may not read, alerts included.
GET /api/v1/contexts/problems does the same for every kubeconfig context, as you: reachable, counts of errors and warnings over the rows and the alerts that name no object, as the Overview counts them (with nodes, ready and total, when you may list nodes), the first 20 rows, and the first 5 of those alerts. GET /api/v1/problems without a namespace has the same nodes. Clusters are checked a few at a time; one that doesn’t answer /healthz within 3 seconds is unreachable and doesn’t hold up the rest. Results are reused for 15 seconds.
Audit events
Section titled “Audit events”GET /api/v1/audit/events returns the latest changes made through KubeGlass, newest last, as { "events", "total" }, 100 by default and at most 500 (limit). q is for a search box: every word must appear in the event’s user, action, resource, name, namespace or cluster. user and resource match part of that one field, and action and result take comma-separated values. Every filter given must match. after returns only events after that seq, for polling.
Each event records who made the change, the action (scale, restart, cordon, delete and so on), the object’s APIGroup, Resource, Namespace and Name when the route names them, the cluster (Context) and the result. Details holds the request path, the HTTP status and a SHA-256 hash of the body. The body itself is not stored.
Access
Section titled “Access”GET /api/v1/rbac/matrix/{subject} says what a subject may do, read from the cluster’s roles and bindings. {subject} is a user or group name, or a ServiceAccount as system:serviceaccount:<namespace>:<name>; kind=Group reads it as a group (User is the default). Each group= adds a group whose bindings count too, besides system:authenticated (and for a ServiceAccount system:serviceaccounts and system:serviceaccounts:<namespace>), which always count. With namespace, the answer is for that namespace alone, merging what is granted there and everywhere. It answers { subject: { kind, name, namespace }, groups, namespace, rules } with one rule per resource and place: { apiGroup, resource, resourceNames, namespace, verbs, grants }, where a rule’s namespace is empty for every namespace and each grant is { roleKind, role, bindingKind, binding, namespace }.
GET /api/v1/rbac/who-can-access?verb=&resource=&namespace= lists the subjects a binding gives that access, each { subject, subjectKind, namespace, roleName, roleKind, binding, bindingKind, bindingNamespace }. resource may name its API group as kubectl does (deployments.apps). Without namespace, RoleBindings in every namespace count.
Both read every Role, ClusterRole and binding as you, and answer 403 unless you may list them. GET /api/v1/authz/identity returns { user, groups }, who the session’s cluster takes you for (a SelfSubjectReview). POST /api/v1/rbac/roles and POST /api/v1/rbac/bindings create a ClusterRole or ClusterRoleBinding when the body has clusterScoped: true.
Applying manifests
Section titled “Applying manifests”POST /api/v1/apply applies a manifest as you, like kubectl apply --server-side -f. The body is { yaml, namespace }: one or more objects as YAML or JSON, documents separated by --- lines, each an object or a List, and the namespace for objects of namespaced kinds that name none (default when left out). Each object goes through Server-Side Apply with field manager kubeglass; an object with only generateName is created. Namespaces go first, then CustomResourceDefinitions (KubeGlass waits until each is established), then the rest in the manifest’s order. dryRun=true has the API server check every object without saving, and force=true takes over fields another field manager owns, like --force-conflicts.
The answer is { dryRun, results, failed } with one result per object in the manifest’s order: document (and item within a List), the line it’s about, apiVersion, kind, name, namespace (namespaceDefaulted when it came from the body) and action: created, configured, unchanged, applied (it worked, but you may not read the object), skipped (a dry run can’t check an object in a namespace or of a kind the same manifest creates) or error, with the API server’s message and reason. conflict marks an object that force=true would apply. A dry run adds before and after for objects it would change, without managedFields and with Secret values REDACTED. When every object fails the status is 422 apply_failed, with the results in data.
POST /api/v1/manifests/fetch with { url } downloads a manifest and returns { yaml } without applying it. The URL must be HTTPS, redirects included, and reach a public address; the file must be at most 2 MiB of YAML or JSON with at least one object.
Undoing a change
Section titled “Undoing a change”GET /api/v1/changes?namespace=&resource=&name=&after=&automatic=&limit= lists the changes the recorder saw, newest first, as { changes, total, since }, 200 by default and at most 1,000. Each change has an id, action (created, updated or deleted), the object, the fields an update changed, the field manager and, for changes made through KubeGlass, the user. revertible is set when KubeGlass can undo it; otherwise noRevert says why (secret, large or expired). reverted is set once it was undone.
POST /api/v1/namespaces/{namespace}/{resource}/{name}/revert?change=<id> undoes one, as you: for an update it applies a merge patch back to the earlier values, and for a deleted object it creates the object again. Add group= for a kind outside the core group (apps for Deployments) and dryRun=true to have the API server check it without saving. The answer is { before, after, dryRun }: the object now (null for a deleted one) and after the revert. It fails with 409 already_reverted, with 409 changed_since and the paths that changed again since, or with 422 not_revertible; see Error codes. A revert that isn’t a dry run is in the audit log as revert.
Extensions
Section titled “Extensions”GET /api/v1/extensions returns the extensions file as KubeGlass has it now: { path, found, problems, actions, columns, aliases }. Entries with mistakes are left out and described in problems.
Setup mode
Section titled “Setup mode”While KubeGlass waits for a kubeconfig, it answers GET /healthz, GET /readyz (503), GET /api/v1/demo-config and POST /api/v1/setup/kubeconfig, which takes a kubeconfig and adds it, and answers every other /api/ and /ws/ request with 503 no_cluster. It answers only to localhost, names under .localhost, IP addresses and allowed_hosts.
Upgrade readiness
Section titled “Upgrade readiness”GET /api/v1/upgrade/readiness checks an upgrade of the control plane to the next minor version (targetVersion). deprecatedApis lists the deprecated API versions the cluster serves, each with when Kubernetes deprecates and removes it, what replaces it, and removedByTarget. The dates come from the lifecycle data in the k8s.io/api module KubeGlass is built with, so they cover every release up to latestStable. If you may read the API server’s /metrics, usageKnown is true and each entry says whether anything has requested it since the API server started. Deprecated versions the server reports that have no removal date, such as core v1 Endpoints, are included too. If you may list CustomResourceDefinitions, versions their CRDs mark deprecated are listed with custom set. nodes gives each kubelet’s skew (minor versions behind the control plane) and whether it stays supported after the upgrade.
Health
Section titled “Health”| Path | Answers |
|---|---|
GET /healthz, GET /livez |
200 while the process is up |
GET /readyz |
200 while the Kubernetes API server answers within 5 seconds, 503 otherwise |
GET /metrics |
Prometheus metrics for KubeGlass itself |
WebSockets
Section titled “WebSockets”| Path | Carries |
|---|---|
/ws/watch |
Watch events for any resource type, each with a summary. A watch starts with a resource_watch_snapshot of every object and their summaries, and sends a new one if it has to list again because its resource version expired. Given the listVersion of a list from /api/v1/objects/…, it sends resource_watch_resumed instead when that list is still current, or watches on from the list’s resource version. fieldSelector=metadata.name=<name> watches one object |
/ws/multiplex |
Several watches over one connection |
/ws/logs |
Streaming container logs |
/ws/cross-cluster-logs |
Logs from several clusters at once |
/ws/exec |
A shell in a container |
/ws/terminal |
A terminal session (pod, node or local) |
/ws/local-shell |
A shell on the server, when enabled |
WebSockets take as query parameters what HTTP requests send as headers: sid for the session, ctx for the cluster the client shows, ro=1 for a cluster marked read-only, and as and asGroup for Act As. A socket whose ctx isn’t its session’s cluster is closed with code 4409 and the reason context_mismatch: followed by the session’s cluster. A shell refused because KubeGlass or the cluster is read-only is closed with 4423.
Endpoints
Section titled “Endpoints”Kubernetes resources
Section titled “Kubernetes resources”| Method | Path |
|---|---|
POST |
/api/v1/apply |
POST |
/api/v1/manifests/fetch |
GET |
/api/v1/changes |
GET |
/api/v1/extensions |
GET |
/api/v1/clusterrolebindings |
GET |
/api/v1/clusterrolebindings/{name} |
GET |
/api/v1/clusterroles |
GET |
/api/v1/clusterroles/{name} |
GET |
/api/v1/configmaps |
GET |
/api/v1/cronjobs |
GET |
/api/v1/csidrivers |
GET |
/api/v1/csidrivers/{name} |
GET |
/api/v1/daemonsets |
GET |
/api/v1/deployments |
GET |
/api/v1/dynamic/{group}/{version}/{resource} |
POST |
/api/v1/dynamic/{group}/{version}/{resource} |
GET |
/api/v1/dynamic/{group}/{version}/{resource}/{name} |
DELETE |
/api/v1/dynamic/{group}/{version}/{resource}/{name} |
GET |
/api/v1/endpoints |
GET |
/api/v1/endpointslices |
GET |
/api/v1/events |
GET |
/api/v1/events/stream |
GET |
/api/v1/horizontalpodautoscalers |
GET |
/api/v1/ingresses |
GET |
/api/v1/jobs |
GET |
/api/v1/objects/{group}/{version}/{resource} |
GET |
/api/v1/leases |
GET |
/api/v1/limitranges |
GET |
/api/v1/namespaces |
GET |
/api/v1/namespaces/{namespace}/configmaps |
GET |
/api/v1/namespaces/{namespace}/cronjobs |
POST |
/api/v1/namespaces/{namespace}/cronjobs/{name}/resume |
POST |
/api/v1/namespaces/{namespace}/cronjobs/{name}/suspend |
POST |
/api/v1/namespaces/{namespace}/cronjobs/{name}/trigger |
GET |
/api/v1/namespaces/{namespace}/daemonsets |
GET |
/api/v1/namespaces/{namespace}/deployments |
POST |
/api/v1/namespaces/{namespace}/deployments/{name}/rollback |
GET |
/api/v1/namespaces/{namespace}/endpoints |
GET |
/api/v1/namespaces/{namespace}/endpointslices |
GET |
/api/v1/namespaces/{namespace}/events |
GET |
/api/v1/namespaces/{namespace}/horizontalpodautoscalers |
PUT |
/api/v1/namespaces/{namespace}/horizontalpodautoscalers/{name} |
GET |
/api/v1/namespaces/{namespace}/ingresses |
GET |
/api/v1/namespaces/{namespace}/jobs |
GET |
/api/v1/namespaces/{namespace}/leases |
GET |
/api/v1/namespaces/{namespace}/limitranges |
GET |
/api/v1/namespaces/{namespace}/networkpolicies |
GET |
/api/v1/namespaces/{namespace}/persistentvolumeclaims |
GET |
/api/v1/namespaces/{namespace}/poddisruptionbudgets |
GET |
/api/v1/namespaces/{namespace}/pods |
GET |
/api/v1/namespaces/{namespace}/pods/{name}/env |
POST |
/api/v1/namespaces/{namespace}/pods/{pod}/debug |
POST |
/api/v1/namespaces/{namespace}/pods/{pod}/eviction |
GET |
/api/v1/namespaces/{namespace}/pods/{pod}/files |
GET |
/api/v1/namespaces/{namespace}/pods/{pod}/files/content |
GET |
/api/v1/namespaces/{namespace}/pods/{pod}/files/download |
POST |
/api/v1/namespaces/{namespace}/pods/{pod}/files/upload |
GET |
/api/v1/namespaces/{namespace}/pods/{pod}/log |
POST |
/api/v1/namespaces/{namespace}/portforward |
GET |
/api/v1/namespaces/{namespace}/replicasets |
GET |
/api/v1/namespaces/{namespace}/resourcequotas |
GET |
/api/v1/namespaces/{namespace}/rolebindings |
GET |
/api/v1/namespaces/{namespace}/roles |
GET |
/api/v1/namespaces/{namespace}/secrets |
GET |
/api/v1/namespaces/{namespace}/serviceaccounts |
GET |
/api/v1/namespaces/{namespace}/services |
GET |
/api/v1/namespaces/{namespace}/statefulsets |
GET |
/api/v1/namespaces/{namespace}/volumesnapshots |
GET |
/api/v1/namespaces/{namespace}/{resource}/{name} (with summary) |
DELETE |
/api/v1/namespaces/{namespace}/{resource}/{name} |
PATCH |
/api/v1/namespaces/{namespace}/{resource}/{name}/metadata |
POST |
/api/v1/namespaces/{namespace}/{resource}/{name}/restart |
PUT |
/api/v1/namespaces/{namespace}/{resource}/{name}/scale |
PUT |
/api/v1/namespaces/{namespace}/{resource}/{name}/yaml |
POST |
/api/v1/namespaces/{namespace}/{resource}/{name}/revert |
GET |
/api/v1/namespaces/{name} |
GET |
/api/v1/namespaces/{ns}/resources/{kind}/{name}/dependencies |
GET |
/api/v1/networkpolicies |
GET |
/api/v1/nodes |
GET |
/api/v1/nodes/{name}/allocation |
GET |
/api/v1/nodes/{node} |
POST |
/api/v1/nodes/{node}/cordon |
POST |
/api/v1/nodes/{node}/drain |
GET |
/api/v1/nodes/{node}/drain |
DELETE |
/api/v1/nodes/{node}/drain |
POST |
/api/v1/nodes/{node}/shell |
POST |
/api/v1/nodes/{node}/taint |
DELETE |
/api/v1/nodes/{node}/taint/{key} |
POST |
/api/v1/nodes/{node}/uncordon |
GET |
/api/v1/persistentvolumeclaims |
GET |
/api/v1/persistentvolumes |
GET |
/api/v1/persistentvolumes/{name} |
GET |
/api/v1/poddisruptionbudgets |
GET |
/api/v1/pods |
DELETE |
/api/v1/portforward/{id} |
GET |
/api/v1/portforwards |
GET |
/api/v1/replicasets |
GET |
/api/v1/resourcequotas |
GET |
/api/v1/resources |
GET |
/api/v1/resources/groups |
GET |
/api/v1/rolebindings |
GET |
/api/v1/roles |
GET |
/api/v1/secrets |
GET |
/api/v1/serviceaccounts |
GET |
/api/v1/services |
GET |
/api/v1/statefulsets |
GET |
/api/v1/storageclasses |
GET |
/api/v1/storageclasses/{name} |
GET |
/api/v1/terminal/sessions |
DELETE |
/api/v1/terminal/sessions/{id} |
GET |
/api/v1/terminal/shell-history |
GET |
/api/v1/terminal/shell-history/download |
POST |
/api/v1/terminal/shell-history/upload |
GET |
/api/v1/terminal/snapshots |
DELETE |
/api/v1/terminal/snapshots/{id} |
POST |
/api/v1/terminal/snapshots/{id}/restore |
GET |
/api/v1/volumesnapshotclasses |
GET |
/api/v1/volumesnapshots |
GET |
/api/v1/xray/namespaces/{namespace}/{resource}/{name} |
GET |
/api/v1/xray/{resource}/{name} |
PATCH |
/api/v1/{resource}/{name}/metadata |
Cluster and contexts
Section titled “Cluster and contexts”| Method | Path |
|---|---|
GET |
/api/v1/cluster/health |
GET |
/api/v1/cluster/info |
GET |
/api/v1/cluster/{resource}/{name} (with summary) |
DELETE |
/api/v1/cluster/{resource}/{name} |
PUT |
/api/v1/cluster/{resource}/{name}/yaml |
GET |
/api/v1/clusters/status |
POST |
/api/v1/connect/bootstrap |
POST |
/api/v1/connect/bulk |
GET |
/api/v1/connect/clusters |
DELETE |
/api/v1/connect/clusters/{name} |
POST |
/api/v1/connect/directory |
POST |
/api/v1/connect/kubeconfig |
GET |
/api/v1/connect/methods |
POST |
/api/v1/connect/multi-kubeconfig |
POST |
/api/v1/connect/serviceaccount |
POST |
/api/v1/connect/sso |
GET |
/api/v1/connect/sso/callback |
POST |
/api/v1/connect/sso/callback |
GET |
/api/v1/connect/sso/status |
POST |
/api/v1/connect/token |
GET |
/api/v1/connect/validate/{name} |
GET |
/api/v1/contexts |
GET |
/api/v1/contexts/current |
GET |
/api/v1/contexts/health-summary |
GET |
/api/v1/contexts/problems |
GET |
/api/v1/contexts/{name}/diagnose |
PUT |
/api/v1/contexts/{name}/switch |
GET |
/api/v1/dashboard/summary |
GET |
/api/v1/demo-config |
GET |
/api/v1/fleet/health |
POST |
/api/v1/setup/kubeconfig (setup mode only) |
Problems, checks and search
Section titled “Problems, checks and search”| Method | Path |
|---|---|
POST |
/api/v1/diagnose |
GET |
/api/v1/health-scan |
POST |
/api/v1/health-scan |
GET |
/api/v1/health-scan/rules |
GET |
/api/v1/problems |
POST |
/api/v1/search |
GET |
/api/v1/timeline |
GET |
/api/v1/upgrade/readiness |
Metrics
Section titled “Metrics”| Method | Path |
|---|---|
GET |
/api/v1/metrics/alerts |
GET |
/api/v1/metrics/alerts/{namespace} |
GET |
/api/v1/metrics/cluster |
GET |
/api/v1/metrics/namespaces/{namespace}/pods |
GET |
/api/v1/metrics/namespaces/{namespace}/pods/{pod} |
POST |
/api/v1/metrics/query |
GET |
/api/v1/metrics/query/presets |
GET |
/api/v1/rightsizing |
GET |
/api/v1/top/nodes |
GET |
/api/v1/top/pods |
Alerts
Section titled “Alerts”| Method | Path |
|---|---|
GET |
/api/v1/alertmanager/silences |
POST |
/api/v1/alertmanager/silences |
DELETE |
/api/v1/alertmanager/silences/{id} |
GET |
/api/v1/alertmanager/status |
Access and security
Section titled “Access and security”| Method | Path |
|---|---|
GET |
/api/v1/audit/events |
POST |
/api/v1/authz/can-i |
GET |
/api/v1/authz/identity |
GET |
/api/v1/authz/whoami |
GET |
/api/v1/certificates |
GET |
/api/v1/images |
GET |
/api/v1/policy/violations |
GET |
/api/v1/rbac/bindings |
POST |
/api/v1/rbac/bindings |
GET |
/api/v1/rbac/matrix/{subject} |
GET |
/api/v1/rbac/roles |
POST |
/api/v1/rbac/roles |
GET |
/api/v1/rbac/who-can-access |
GET |
/api/v1/rbac/who-can/{verb}/{resource} |
GET |
/api/v1/security/netpol-coverage |
GET |
/api/v1/vulnerabilities |
GET |
/api/v1/webhooks |
| Method | Path |
|---|---|
GET |
/api/v1/helm/releases |
POST |
/api/v1/helm/releases |
GET |
/api/v1/helm/releases/{namespace}/{name} |
PUT |
/api/v1/helm/releases/{namespace}/{name} |
DELETE |
/api/v1/helm/releases/{namespace}/{name} |
GET |
/api/v1/helm/releases/{namespace}/{name}/history |
POST |
/api/v1/helm/releases/{namespace}/{name}/rollback |
GET |
/api/v1/helm/releases/{namespace}/{name}/values |
GET |
/api/v1/helm/repos |
POST |
/api/v1/helm/repos |
GET |
/api/v1/helm/repos/{name}/charts |
GitOps and rollouts
Section titled “GitOps and rollouts”| Method | Path |
|---|---|
GET |
/api/v1/gitops/providers |
GET |
/api/v1/gitops/providers/apps |
GET |
/api/v1/gitops/providers/apps/{namespace}/{name} |
DELETE |
/api/v1/gitops/providers/apps/{namespace}/{name} |
GET |
/api/v1/gitops/providers/apps/{namespace}/{name}/details |
GET |
/api/v1/gitops/providers/apps/{namespace}/{name}/events |
GET |
/api/v1/gitops/providers/apps/{namespace}/{name}/history |
GET |
/api/v1/gitops/providers/apps/{namespace}/{name}/manifests |
POST |
/api/v1/gitops/providers/apps/{namespace}/{name}/refresh |
POST |
/api/v1/gitops/providers/apps/{namespace}/{name}/rollback |
POST |
/api/v1/gitops/providers/apps/{namespace}/{name}/sync |
POST |
/api/v1/gitops/providers/apps/{namespace}/{name}/terminate |
GET |
/api/v1/gitops/providers/apps/{namespace}/{name}/tree |
GET |
/api/v1/gitops/providers/clusters |
GET |
/api/v1/gitops/providers/ownership |
POST |
/api/v1/gitops/providers/refresh |
GET |
/api/v1/gitops/providers/sources |
GET |
/api/v1/gitops/providers/summary |
GET |
/api/v1/gitops/providers/topology |
GET |
/api/v1/rollouts |
POST |
/api/v1/rollouts/{namespace}/{name}/abort |
POST |
/api/v1/rollouts/{namespace}/{name}/promote |
POST |
/api/v1/rollouts/{namespace}/{name}/restart |
POST |
/api/v1/rollouts/{namespace}/{name}/retry |
Multiple clusters and drift
Section titled “Multiple clusters and drift”| Method | Path |
|---|---|
POST |
/api/v1/cross-cluster/compare |
POST |
/api/v1/cross-cluster/diff |
POST |
/api/v1/cross-cluster/drift |
POST |
/api/v1/cross-cluster/rbac-diff |
POST |
/api/v1/cross-cluster/search |
GET |
/api/v1/drift/policies |
POST |
/api/v1/drift/policies |
GET |
/api/v1/drift/policies/{id} |
PUT |
/api/v1/drift/policies/{id} |
DELETE |
/api/v1/drift/policies/{id} |
POST |
/api/v1/drift/policies/{id}/run |
GET |
/api/v1/drift/results |
GET |
/api/v1/drift/results/{id} |
DELETE |
/api/v1/drift/results/{id} |
POST |
/api/v1/drift/scan |
GET |
/api/v1/drift/scan/progress |
GET |
/api/v1/inventory/clusters/{name} |
GET |
/api/v1/inventory/fleet |
POST |
/api/v1/inventory/scan |
Settings
Section titled “Settings”| Method | Path |
|---|---|
GET |
/api/v1/settings |
PUT |
/api/v1/settings |
POST |
/api/v1/settings/test-webhook |