API reference
Every HTTP endpoint of the managed-identity module: authentication, IAM action, parameters, bodies and status codes.
Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.
Docs
GET /docs/managed-identity/manifest.json
- Authentication: required
- Operation name:
DocsManifest_managed-identity
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /docs/managed-identity/{path}
- Authentication: required
- Operation name:
DocsFile_managed-identity
Parameters
| Name | In | Type | Required |
|---|---|---|---|
path |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
Managed Identity
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/providers/identity/managedidentities
Lists managed identities in a resource group, or gets a specific one by resourceName.
- Authentication: required
- IAM action:
managedidentities/read— evaluated at the resource in the path - Operation name:
ListManagedIdentities
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceName |
query | string |
No |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold managedidentities/read at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/providers/identity/managedidentities
Provisions a managed identity for a resource.
- Authentication: required
- IAM action:
managedidentities/write— evaluated at the resource in the path - Operation name:
ProvisionManagedIdentity
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
Request body: ProvisionRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold managedidentities/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/providers/identity/managedidentities/{resourceUid}
Deprovisions (deletes) the managed identity for a resource.
- Authentication: required
- IAM action:
managedidentities/delete— evaluated at the resource in the path - Operation name:
DeprovisionManagedIdentity
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceUid |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold managedidentities/delete at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/providers/identity/managedidentities/{resourceUid}
Gets the managed identity for a specific resource by its Kubernetes UID.
- Authentication: required
- IAM action:
managedidentities/read— evaluated at the resource in the path - Operation name:
GetManagedIdentity
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceUid |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold managedidentities/read at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroup}/providers/identity/managedidentities/{resourceUid}/token
Retrieves credentials for a managed identity to perform a client_credentials grant.
- Authentication: required
- IAM action:
managedidentities/readSecrets— evaluated at the resource in the path; a data action - Operation name:
GetManagedIdentityToken
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroup |
path | string |
Yes |
resourceUid |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold managedidentities/readSecrets at the evaluated scope |
Other endpoints
GET /readyz
- Authentication: none — anonymous callers are accepted
- Operation name:
StackshipReadiness
Responses
| Status | Meaning | Body |
|---|
Schemas
ProvisionRequest
| Property | Type | Nullable |
|---|---|---|
resourceName |
string |
No |
resourceType |
string |
No |
resourceUid |
string |
No |