API reference
Every HTTP endpoint of the s3 module: authentication, IAM action, parameters, bodies and status codes.
Generated from the module's code when its image was built — do not edit. Paths are relative to https://api.example.com.
Docs
GET /docs/s3/manifest.json
- Authentication: required
- Operation name:
DocsManifest_s3
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
GET /docs/s3/{path}
- Authentication: required
- Operation name:
DocsFile_s3
Parameters
| Name | In | Type | Required |
|---|---|---|---|
path |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid |
S3 Access Keys
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/managedidentities/{managedIdentityId}/s3accesskeys
- Authentication: required
- IAM action:
s3accesskeys/read— evaluated at the resource in the path - Operation name:
ListS3AccessKeys
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
managedIdentityId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3accesskeys/read at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/managedidentities/{managedIdentityId}/s3accesskeys
- Authentication: required
- IAM action:
s3accesskeys/write— evaluated at the resource in the path - Operation name:
IssueS3AccessKey
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
managedIdentityId |
path | uuid |
Yes |
Request body: IssueAccessKeyRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3accesskeys/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/managedidentities/{managedIdentityId}/s3accesskeys/{keyId}
- Authentication: required
- IAM action:
s3accesskeys/delete— evaluated at the resource in the path - Operation name:
DeleteS3AccessKey
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
managedIdentityId |
path | uuid |
Yes |
keyId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3accesskeys/delete at the evaluated scope |
PATCH /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/managedidentities/{managedIdentityId}/s3accesskeys/{keyId}
- Authentication: required
- IAM action:
s3accesskeys/write— evaluated at the resource in the path - Operation name:
UpdateS3AccessKeyStatus
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
managedIdentityId |
path | uuid |
Yes |
keyId |
path | uuid |
Yes |
Request body: UpdateAccessKeyStatusRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3accesskeys/write at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{accountName}/accesskeys
- Authentication: required
- IAM action:
s3accesskeys/read— evaluated at the resource in the path - Operation name:
ListS3AccessKeysForAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
accountName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3accesskeys/read at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{accountName}/accesskeys
- Authentication: required
- IAM action:
s3accesskeys/write— evaluated at the resource in the path - Operation name:
IssueS3AccessKeyForAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
accountName |
path | string |
Yes |
Request body: IssueAccessKeyRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3accesskeys/write at the evaluated scope |
S3 Buckets
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{accountName}/buckets
- Authentication: required
- IAM action:
s3buckets/read— evaluated at the resource in the path - Operation name:
ListS3Buckets
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
accountName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3buckets/read at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{accountName}/buckets
- Authentication: required
- IAM action:
s3buckets/write— evaluated at the resource in the path - Operation name:
CreateS3Bucket
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
accountName |
path | string |
Yes |
Request body: BucketCreateDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3buckets/write at the evaluated scope |
DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{accountName}/buckets/{bucketName}
- Authentication: required
- IAM action:
s3buckets/delete— evaluated at the resource in the path - Operation name:
DeleteS3Bucket
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
accountName |
path | string |
Yes |
bucketName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3buckets/delete at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{accountName}/buckets/{bucketName}
- Authentication: required
- IAM action:
s3buckets/read— evaluated at the resource in the path - Operation name:
GetS3Bucket
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
accountName |
path | string |
Yes |
bucketName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3buckets/read at the evaluated scope |
S3 STS
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}/sts/sessions
- Authentication: required
- IAM action:
s3sts/issue— evaluated at the resource in the path - Operation name:
IssueS3StsSession
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Request body: IssueStsRequest
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3sts/issue at the evaluated scope |
S3 Storage Accounts
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts
- Authentication: required
- IAM action:
s3storageaccounts/read— evaluated at the resource in the path - Operation name:
ListS3StorageAccounts
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/read at the evaluated scope |
DELETE /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}
- Authentication: required
- IAM action:
s3storageaccounts/delete— evaluated at the resource in the path - Operation name:
DeleteS3StorageAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/delete at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}
- Authentication: required
- IAM action:
s3storageaccounts/read— evaluated at the resource in the path - Operation name:
GetS3StorageAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/read at the evaluated scope |
PATCH /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}
- Authentication: required
- IAM action:
s3storageaccounts/write— evaluated at the resource in the path - Operation name:
PatchS3StorageAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Request body: any
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/write at the evaluated scope |
POST /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}
- Authentication: required
- IAM action:
s3storageaccounts/write— evaluated at the resource in the path - Operation name:
CreateS3StorageAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Request body: S3StorageAccountCreateDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/write at the evaluated scope |
PUT /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}
- Authentication: required
- IAM action:
s3storageaccounts/write— evaluated at the resource in the path - Operation name:
UpdateS3StorageAccount
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Request body: S3StorageAccountCreateDto
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/write at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}/audit
- Authentication: required
- IAM action:
s3/audit/read— evaluated at the resource in the path - Operation name:
GetS3StorageAccountAudit
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3/audit/read at the evaluated scope |
GET /boundaries/{boundaryId}/resourcegroups/{resourceGroupName}/resources/s3storageaccounts/{name}/usage
- Authentication: required
- IAM action:
s3storageaccounts/read— evaluated at the resource in the path - Operation name:
GetS3StorageAccountUsage
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
resourceGroupName |
path | string |
Yes |
name |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/read at the evaluated scope |
GET /boundaries/{boundaryId}/resources/s3storageaccounts
- Authentication: required
- IAM action:
s3storageaccounts/read— evaluated at the resource in the path - Operation name:
ListAllS3StorageAccountsForBoundary
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | uuid |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/read at the evaluated scope |
GET /boundaries/{boundaryId}/resources/s3storageaccounts/config
- Authentication: required
- IAM action:
s3storageaccounts/read— evaluated at the resource in the path - Operation name:
GetAllS3StorageAccountsConfig
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/read at the evaluated scope |
GET /boundaries/{boundaryId}/resources/s3storageaccounts/runtime-info
- Authentication: required
- IAM action:
s3storageaccounts/read— evaluated at the resource in the path - Operation name:
GetS3RuntimeInfo
Parameters
| Name | In | Type | Required |
|---|---|---|---|
boundaryId |
path | string |
Yes |
Responses
| Status | Meaning | Body |
|---|---|---|
200 |
OK | |
401 |
Not signed in, or the token is invalid | |
403 |
The caller does not hold s3storageaccounts/read at the evaluated scope |
Other endpoints
GET /readyz
- Authentication: none — anonymous callers are accepted
- Operation name:
StackshipReadiness
Responses
| Status | Meaning | Body |
|---|
Schemas
BucketCreateDto
| Property | Type | Nullable |
|---|---|---|
name |
string |
No |
IssueAccessKeyRequest
| Property | Type | Nullable |
|---|---|---|
description |
string |
Yes |
IssueStsRequest
| Property | Type | Nullable |
|---|---|---|
ttlSeconds |
integer |
Yes |
S3AccessKeyStatus
One of: 0 = Active, 1 = Disabled.
S3ComputeSpecDto
| Property | Type | Nullable |
|---|---|---|
cpu |
string |
No |
memory |
string |
No |
S3CorsSpecDto
| Property | Type | Nullable |
|---|---|---|
additionalOrigins |
string [] |
No |
S3EndpointSpecDto
| Property | Type | Nullable |
|---|---|---|
hostname |
string |
No |
httpOnly |
boolean |
No |
issuer |
string |
No |
provider |
SslProvider |
No |
sslCertificateSecretName |
string |
Yes |
S3StorageAccountCreateDto
| Property | Type | Nullable |
|---|---|---|
clusterId |
uuid |
No |
spec |
S3StorageAccountSpecDto |
No |
S3StorageAccountSpecDto
| Property | Type | Nullable |
|---|---|---|
allowS3ApiBucketLifecycle |
boolean |
No |
compute |
S3ComputeSpecDto |
No |
cors |
S3CorsSpecDto |
Yes |
endpoint |
S3EndpointSpecDto |
No |
storage |
S3StorageSpecDto |
No |
S3StorageSpecDto
| Property | Type | Nullable |
|---|---|---|
backend |
StorageBackend |
No |
quota |
string |
No |
retainOnDelete |
boolean |
No |
storageClass |
string |
Yes |
SslProvider
One of: LetsEncrypt, Secret.
StorageBackend
One of: Pvc.
UpdateAccessKeyStatusRequest
| Property | Type | Nullable |
|---|---|---|
status |
S3AccessKeyStatus |
No |