API reference
Every HTTP endpoint of the boundaries module: authentication, IAM action, parameters, bodies and status codes.
Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.
Boundaries
GET /boundaries
- Authentication: required
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
POST /boundaries
- Authentication: required
- IAM action:
boundaries/create— evaluated at the platform root
Request body: CreateBoundaryRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/create at the evaluated scope |
GET /boundaries/config
- Authentication: required
- IAM action:
boundaries/read— evaluated at the resource in the path - Operation name:
GetBoundariesConfig
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/read at the evaluated scope |
DELETE /boundaries/{boundaryId}
- Authentication: required
- IAM action:
boundaries/delete— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/delete at the evaluated scope |
GET /boundaries/{boundaryId}
- Authentication: required
- IAM action:
boundaries/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/read at the evaluated scope |
PATCH /boundaries/{boundaryId}
- Authentication: required
- IAM action:
boundaries/manage— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: UpdateBoundaryRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/manage at the evaluated scope |
POST /boundaries/{boundaryId}/tenant
- Authentication: required
- IAM action:
boundaries/tenant/admin— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: MoveBoundaryTenantRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/tenant/admin at the evaluated scope |
Boundary Members
GET /boundaries/{boundaryId}/members
- Authentication: required
- IAM action:
boundaries/members/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/members/read at the evaluated scope |
POST /boundaries/{boundaryId}/members
- Authentication: required
- IAM action:
boundaries/members/manage— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: AddBoundaryMemberRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/members/manage at the evaluated scope |
GET /boundaries/{boundaryId}/members/config
- Authentication: required
- IAM action:
boundaries/members/read— evaluated at the resource in the path - Operation name:
GetBoundaryMemberConfig
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/members/read at the evaluated scope |
DELETE /boundaries/{boundaryId}/members/{assignmentId}
- Authentication: required
- IAM action:
boundaries/members/manage— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
assignmentId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/members/manage at the evaluated scope |
Boundary Network
POST /boundaries/{boundaryId}/network/check
- Authentication: required
- IAM action:
boundaries/network/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: NetworkCheckRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/network/read at the evaluated scope |
GET /boundaries/{boundaryId}/network/denies
- Authentication: required
- IAM action:
boundaries/network/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
direction |
query | string |
No |
pageSize |
query | integer |
No |
resource |
query | string |
No |
resourceGroup |
query | string |
No |
window |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/network/read at the evaluated scope |
GET /boundaries/{boundaryId}/network/denies/{denyId}
- Authentication: required
- IAM action:
boundaries/network/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
denyId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/network/read at the evaluated scope |
GET /boundaries/{boundaryId}/network/graph
- Authentication: required
- IAM action:
boundaries/network/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
query | string |
No |
window |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/network/read at the evaluated scope |
GET /boundaries/{boundaryId}/network/series
- Authentication: required
- IAM action:
boundaries/network/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resource |
query | string |
No |
resourceGroup |
query | string |
No |
window |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/network/read at the evaluated scope |
GET /boundaries/{boundaryId}/network/status
- Authentication: required
- IAM action:
boundaries/network/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/network/read at the evaluated scope |
Boundary Projections
GET /boundaries/{boundaryId}/projections
- Authentication: required
- IAM action:
boundaries/projections/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/projections/read at the evaluated scope |
POST /boundaries/{boundaryId}/projections
- Authentication: required
- IAM action:
boundaries/projections/manage— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CreateBoundaryProjectionRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/projections/manage at the evaluated scope |
DELETE /boundaries/{boundaryId}/projections/{projectionId}
- Authentication: required
- IAM action:
boundaries/projections/manage— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
projectionId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/projections/manage at the evaluated scope |
GET /boundaries/{boundaryId}/projections/{projectionId}
- Authentication: required
- IAM action:
boundaries/projections/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
projectionId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/projections/read at the evaluated scope |
PATCH /boundaries/{boundaryId}/projections/{projectionId}
- Authentication: required
- IAM action:
boundaries/projections/manage— evaluated at the platform root
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
projectionId |
path | uuid |
Yes |
Request body: UpdateBoundaryProjectionRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/projections/manage at the evaluated scope |
Crosslink
GET /boundaries/{boundaryId}/crosslink
- Authentication: required
- IAM action:
boundaries/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/read at the evaluated scope |
PUT /boundaries/{boundaryId}/crosslink
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: UpdateCrosslinkRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
GET /boundaries/{boundaryId}/crosslink/access-grant
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
POST /boundaries/{boundaryId}/crosslink/access-grant
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CrosslinkAccessGrantDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
GET /boundaries/{boundaryId}/crosslink/exposures
- Authentication: required
- IAM action:
boundaries/read— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold boundaries/read at the evaluated scope |
GET /boundaries/{boundaryId}/crosslink/hub-candidates
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
GET /boundaries/{boundaryId}/crosslink/inventory
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
clusterId |
query | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
POST /boundaries/{boundaryId}/crosslink/pki/rotate
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
POST /boundaries/{boundaryId}/crosslink/status
- Authentication: required
- IAM action:
crosslink/admin— evaluated at the resource in the path
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Request body: CrosslinkStatusReport
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold crosslink/admin at the evaluated scope |
Docs
GET /docs/boundaries/manifest.json
- Authentication: required
- Operation name:
DocsManifest_boundaries
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /docs/boundaries/{path}
- Authentication: required
- Operation name:
DocsFile_boundaries
Parameters
| Name | In | Type | Required |
|---|---|---|---|
path |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Other endpoints
GET /readyz
- Authentication: none — anonymous callers are accepted
- Operation name:
StackshipReadiness
Responses
| Status | Meaning | Body |
|---|
Schemas
AddBoundaryMemberRequest
| Property | Type | Nullable |
|---|---|---|
principalId |
uuid |
No |
principalType |
string |
Yes |
roleDefinitionName |
string |
No |
CreateBoundaryProjectionRequest
| Property | Type | Nullable |
|---|---|---|
clusterId |
uuid |
No |
namespaces |
string [] |
Yes |
CreateBoundaryRequest
| Property | Type | Nullable |
|---|---|---|
displayName |
string |
No |
CrosslinkAccessGrantDto
| Property | Type | Nullable |
|---|---|---|
caPem |
string |
No |
code |
string |
No |
expiresUtc |
date-time |
No |
hubEndpoint |
string |
No |
url |
string |
No |
CrosslinkCaReport
| Property | Type | Nullable |
|---|---|---|
certificatePem |
string |
No |
expiresUtc |
date-time |
No |
fingerprint |
string |
No |
issuedUtc |
date-time |
No |
version |
integer |
No |
CrosslinkExposureReport
| Property | Type | Nullable |
|---|---|---|
clusterId |
uuid |
No |
isConflict |
boolean |
No |
kind |
string |
No |
namespace |
string |
No |
podSelector |
string |
Yes |
publishedPort |
integer |
No |
routingKey |
string |
No |
serviceName |
string |
No |
statusReason |
string |
Yes |
CrosslinkLinkStatus
One of: 0 = NotApplicable, 1 = Connecting, 2 = Connected, 3 = Disconnected.
CrosslinkSiteReport
| Property | Type | Nullable |
|---|---|---|
clusterId |
uuid |
No |
linkStatus |
CrosslinkLinkStatus |
No |
observedPkiVersion |
integer |
Yes |
role |
CrosslinkSiteRole |
No |
status |
CrosslinkSiteStatus |
No |
statusReason |
string |
Yes |
CrosslinkSiteRole
One of: 0 = Hub, 1 = Spoke.
CrosslinkSiteStatus
One of: 0 = Provisioning, 1 = Active, 2 = Degraded, 3 = Failed.
CrosslinkStatusReport
| Property | Type | Nullable |
|---|---|---|
ca |
CrosslinkCaReport |
Yes |
exposures |
CrosslinkExposureReport [] |
No |
observedAtUtc |
date-time |
No |
sites |
CrosslinkSiteReport [] |
No |
MoveBoundaryTenantRequest
| Property | Type | Nullable |
|---|---|---|
tenantId |
uuid |
Yes |
NetworkCheckEndpointRequest
| Property | Type | Nullable |
|---|---|---|
kind |
string |
No |
labels |
map (string) |
Yes |
name |
string |
Yes |
resourceGroup |
string |
Yes |
value |
string |
Yes |
NetworkCheckRequest
| Property | Type | Nullable |
|---|---|---|
clusterId |
uuid |
Yes |
from |
NetworkCheckEndpointRequest |
No |
port |
integer |
No |
protocol |
string |
No |
to |
NetworkCheckEndpointRequest |
No |
UpdateBoundaryProjectionRequest
| Property | Type | Nullable |
|---|---|---|
namespaces |
string [] |
Yes |
UpdateBoundaryRequest
| Property | Type | Nullable |
|---|---|---|
displayName |
string |
No |
UpdateCrosslinkRequest
| Property | Type | Nullable |
|---|---|---|
enabled |
boolean |
No |
hubClusterId |
uuid |
Yes |