CreateAuthorizationPolicy
Creates an authorization policy for a given tenant.
curl --request POST \
--url https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies \
--header 'Content-Type: application/json' \
--data '
{
"meta": {
"name": "<string>",
"annotations": {},
"description": "<string>",
"index_data": {},
"parent_kind": "<string>",
"parent_uuid": "<string>",
"tags": [
"<string>"
]
},
"spec": {
"clause": [
"<string>"
],
"permissions": {
"except_resources": [
"<string>"
],
"roles": [
"SYSTEM_ROLE_UNSPECIFIED"
],
"rules": {}
},
"propagate": true,
"target_namespaces": [
"<string>"
],
"expiration_time": "2023-11-07T05:31:56Z"
},
"tenant_meta": {},
"propagate": true
}
'import requests
url = "https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies"
payload = {
"meta": {
"name": "<string>",
"annotations": {},
"description": "<string>",
"index_data": {},
"parent_kind": "<string>",
"parent_uuid": "<string>",
"tags": ["<string>"]
},
"spec": {
"clause": ["<string>"],
"permissions": {
"except_resources": ["<string>"],
"roles": ["SYSTEM_ROLE_UNSPECIFIED"],
"rules": {}
},
"propagate": True,
"target_namespaces": ["<string>"],
"expiration_time": "2023-11-07T05:31:56Z"
},
"tenant_meta": {},
"propagate": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
meta: {
name: '<string>',
annotations: {},
description: '<string>',
index_data: {},
parent_kind: '<string>',
parent_uuid: '<string>',
tags: ['<string>']
},
spec: {
clause: ['<string>'],
permissions: {except_resources: ['<string>'], roles: ['SYSTEM_ROLE_UNSPECIFIED'], rules: {}},
propagate: true,
target_namespaces: ['<string>'],
expiration_time: '2023-11-07T05:31:56Z'
},
tenant_meta: {},
propagate: true
})
};
fetch('https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'meta' => [
'name' => '<string>',
'annotations' => [
],
'description' => '<string>',
'index_data' => [
],
'parent_kind' => '<string>',
'parent_uuid' => '<string>',
'tags' => [
'<string>'
]
],
'spec' => [
'clause' => [
'<string>'
],
'permissions' => [
'except_resources' => [
'<string>'
],
'roles' => [
'SYSTEM_ROLE_UNSPECIFIED'
],
'rules' => [
]
],
'propagate' => true,
'target_namespaces' => [
'<string>'
],
'expiration_time' => '2023-11-07T05:31:56Z'
],
'tenant_meta' => [
],
'propagate' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies"
payload := strings.NewReader("{\n \"meta\": {\n \"name\": \"<string>\",\n \"annotations\": {},\n \"description\": \"<string>\",\n \"index_data\": {},\n \"parent_kind\": \"<string>\",\n \"parent_uuid\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"spec\": {\n \"clause\": [\n \"<string>\"\n ],\n \"permissions\": {\n \"except_resources\": [\n \"<string>\"\n ],\n \"roles\": [\n \"SYSTEM_ROLE_UNSPECIFIED\"\n ],\n \"rules\": {}\n },\n \"propagate\": true,\n \"target_namespaces\": [\n \"<string>\"\n ],\n \"expiration_time\": \"2023-11-07T05:31:56Z\"\n },\n \"tenant_meta\": {},\n \"propagate\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies")
.header("Content-Type", "application/json")
.body("{\n \"meta\": {\n \"name\": \"<string>\",\n \"annotations\": {},\n \"description\": \"<string>\",\n \"index_data\": {},\n \"parent_kind\": \"<string>\",\n \"parent_uuid\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"spec\": {\n \"clause\": [\n \"<string>\"\n ],\n \"permissions\": {\n \"except_resources\": [\n \"<string>\"\n ],\n \"roles\": [\n \"SYSTEM_ROLE_UNSPECIFIED\"\n ],\n \"rules\": {}\n },\n \"propagate\": true,\n \"target_namespaces\": [\n \"<string>\"\n ],\n \"expiration_time\": \"2023-11-07T05:31:56Z\"\n },\n \"tenant_meta\": {},\n \"propagate\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"meta\": {\n \"name\": \"<string>\",\n \"annotations\": {},\n \"description\": \"<string>\",\n \"index_data\": {},\n \"parent_kind\": \"<string>\",\n \"parent_uuid\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"spec\": {\n \"clause\": [\n \"<string>\"\n ],\n \"permissions\": {\n \"except_resources\": [\n \"<string>\"\n ],\n \"roles\": [\n \"SYSTEM_ROLE_UNSPECIFIED\"\n ],\n \"rules\": {}\n },\n \"propagate\": true,\n \"target_namespaces\": [\n \"<string>\"\n ],\n \"expiration_time\": \"2023-11-07T05:31:56Z\"\n },\n \"tenant_meta\": {},\n \"propagate\": true\n}"
response = http.request(request)
puts response.read_body{
"meta": {
"name": "<string>",
"annotations": {},
"create_time": "2023-11-07T05:31:56Z",
"created_by": "<string>",
"description": "<string>",
"index_data": {
"data": [
"<string>"
],
"search_score": 123,
"tenant": "<string>",
"will_be_deleted_at": "2023-11-07T05:31:56Z"
},
"kind": "<string>",
"parent_kind": "<string>",
"parent_uuid": "<string>",
"references": {},
"tags": [
"<string>"
],
"update_time": "2023-11-07T05:31:56Z",
"updated_by": "<string>",
"upsert_time": "2023-11-07T05:31:56Z",
"version": "<string>"
},
"spec": {
"clause": [
"<string>"
],
"permissions": {
"except_resources": [
"<string>"
],
"roles": [
"SYSTEM_ROLE_UNSPECIFIED"
],
"rules": {}
},
"propagate": true,
"target_namespaces": [
"<string>"
],
"expiration_time": "2023-11-07T05:31:56Z",
"is_support_policy": true
},
"tenant_meta": {
"namespace": "<string>"
},
"propagate": true,
"uuid": "<string>"
}{
"code": 123,
"details": [
{
"@type": "<string>"
}
],
"message": "<string>"
}Path Parameters
Namespaces are a way to organize organizational units into virtual groupings of resources. Namespaces must be a fully qualified name, for example, the child namespace of namespace "endor.prod" called "app" is called "endor.prod.app".
Body
Represents an authorization policy in the system.
Common fields for all Endor Labs resources.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Authorization policies are associated with a tenant.
Indicates that the object should be visible in the child namespaces.
Response
A successful response.
Represents an authorization policy in the system.
Common fields for all Endor Labs resources.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Tenant related data for the tenant containing the resource.
Show child attributes
Show child attributes
Indicates that the object should be visible in the child namespaces.
The UUID of the AuthorizationPolicy resource.
Was this page helpful?
curl --request POST \
--url https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies \
--header 'Content-Type: application/json' \
--data '
{
"meta": {
"name": "<string>",
"annotations": {},
"description": "<string>",
"index_data": {},
"parent_kind": "<string>",
"parent_uuid": "<string>",
"tags": [
"<string>"
]
},
"spec": {
"clause": [
"<string>"
],
"permissions": {
"except_resources": [
"<string>"
],
"roles": [
"SYSTEM_ROLE_UNSPECIFIED"
],
"rules": {}
},
"propagate": true,
"target_namespaces": [
"<string>"
],
"expiration_time": "2023-11-07T05:31:56Z"
},
"tenant_meta": {},
"propagate": true
}
'import requests
url = "https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies"
payload = {
"meta": {
"name": "<string>",
"annotations": {},
"description": "<string>",
"index_data": {},
"parent_kind": "<string>",
"parent_uuid": "<string>",
"tags": ["<string>"]
},
"spec": {
"clause": ["<string>"],
"permissions": {
"except_resources": ["<string>"],
"roles": ["SYSTEM_ROLE_UNSPECIFIED"],
"rules": {}
},
"propagate": True,
"target_namespaces": ["<string>"],
"expiration_time": "2023-11-07T05:31:56Z"
},
"tenant_meta": {},
"propagate": True
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({
meta: {
name: '<string>',
annotations: {},
description: '<string>',
index_data: {},
parent_kind: '<string>',
parent_uuid: '<string>',
tags: ['<string>']
},
spec: {
clause: ['<string>'],
permissions: {except_resources: ['<string>'], roles: ['SYSTEM_ROLE_UNSPECIFIED'], rules: {}},
propagate: true,
target_namespaces: ['<string>'],
expiration_time: '2023-11-07T05:31:56Z'
},
tenant_meta: {},
propagate: true
})
};
fetch('https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'meta' => [
'name' => '<string>',
'annotations' => [
],
'description' => '<string>',
'index_data' => [
],
'parent_kind' => '<string>',
'parent_uuid' => '<string>',
'tags' => [
'<string>'
]
],
'spec' => [
'clause' => [
'<string>'
],
'permissions' => [
'except_resources' => [
'<string>'
],
'roles' => [
'SYSTEM_ROLE_UNSPECIFIED'
],
'rules' => [
]
],
'propagate' => true,
'target_namespaces' => [
'<string>'
],
'expiration_time' => '2023-11-07T05:31:56Z'
],
'tenant_meta' => [
],
'propagate' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies"
payload := strings.NewReader("{\n \"meta\": {\n \"name\": \"<string>\",\n \"annotations\": {},\n \"description\": \"<string>\",\n \"index_data\": {},\n \"parent_kind\": \"<string>\",\n \"parent_uuid\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"spec\": {\n \"clause\": [\n \"<string>\"\n ],\n \"permissions\": {\n \"except_resources\": [\n \"<string>\"\n ],\n \"roles\": [\n \"SYSTEM_ROLE_UNSPECIFIED\"\n ],\n \"rules\": {}\n },\n \"propagate\": true,\n \"target_namespaces\": [\n \"<string>\"\n ],\n \"expiration_time\": \"2023-11-07T05:31:56Z\"\n },\n \"tenant_meta\": {},\n \"propagate\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies")
.header("Content-Type", "application/json")
.body("{\n \"meta\": {\n \"name\": \"<string>\",\n \"annotations\": {},\n \"description\": \"<string>\",\n \"index_data\": {},\n \"parent_kind\": \"<string>\",\n \"parent_uuid\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"spec\": {\n \"clause\": [\n \"<string>\"\n ],\n \"permissions\": {\n \"except_resources\": [\n \"<string>\"\n ],\n \"roles\": [\n \"SYSTEM_ROLE_UNSPECIFIED\"\n ],\n \"rules\": {}\n },\n \"propagate\": true,\n \"target_namespaces\": [\n \"<string>\"\n ],\n \"expiration_time\": \"2023-11-07T05:31:56Z\"\n },\n \"tenant_meta\": {},\n \"propagate\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.endorlabs.com/v1/namespaces/{tenant_meta.namespace}/authorization-policies")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"meta\": {\n \"name\": \"<string>\",\n \"annotations\": {},\n \"description\": \"<string>\",\n \"index_data\": {},\n \"parent_kind\": \"<string>\",\n \"parent_uuid\": \"<string>\",\n \"tags\": [\n \"<string>\"\n ]\n },\n \"spec\": {\n \"clause\": [\n \"<string>\"\n ],\n \"permissions\": {\n \"except_resources\": [\n \"<string>\"\n ],\n \"roles\": [\n \"SYSTEM_ROLE_UNSPECIFIED\"\n ],\n \"rules\": {}\n },\n \"propagate\": true,\n \"target_namespaces\": [\n \"<string>\"\n ],\n \"expiration_time\": \"2023-11-07T05:31:56Z\"\n },\n \"tenant_meta\": {},\n \"propagate\": true\n}"
response = http.request(request)
puts response.read_body{
"meta": {
"name": "<string>",
"annotations": {},
"create_time": "2023-11-07T05:31:56Z",
"created_by": "<string>",
"description": "<string>",
"index_data": {
"data": [
"<string>"
],
"search_score": 123,
"tenant": "<string>",
"will_be_deleted_at": "2023-11-07T05:31:56Z"
},
"kind": "<string>",
"parent_kind": "<string>",
"parent_uuid": "<string>",
"references": {},
"tags": [
"<string>"
],
"update_time": "2023-11-07T05:31:56Z",
"updated_by": "<string>",
"upsert_time": "2023-11-07T05:31:56Z",
"version": "<string>"
},
"spec": {
"clause": [
"<string>"
],
"permissions": {
"except_resources": [
"<string>"
],
"roles": [
"SYSTEM_ROLE_UNSPECIFIED"
],
"rules": {}
},
"propagate": true,
"target_namespaces": [
"<string>"
],
"expiration_time": "2023-11-07T05:31:56Z",
"is_support_policy": true
},
"tenant_meta": {
"namespace": "<string>"
},
"propagate": true,
"uuid": "<string>"
}{
"code": 123,
"details": [
{
"@type": "<string>"
}
],
"message": "<string>"
}