This is a cache of https://docs.openshift.com/acs/4.5/api/NetworkBaselineService.html. It is a snapshot of the page at 2024-11-20T18:12:01.235+0000.
NetworkBaselineService | API reference | Red Hat Advanced Cluster Security for Kubernetes 4.5
×

GetNetworkBaseline

GET /v1/networkbaseline/{id}

Description

Parameters

Path Parameters

Name Description Required Default Pattern

id

X

null

Content Type

  • application/json

Responses

Table 1. HTTP Response Codes
Code Message Datatype

200

A successful response.

StorageNetworkBaseline

0

An unexpected error response.

RuntimeError

Samples

GetNetworkBaselineStatusForFlows

POST /v1/networkbaseline/{deploymentId}/status

Description

Parameters

Path Parameters

Name Description Required Default Pattern

deploymentId

X

null

Body Parameter

Name Description Required Default Pattern

body

V1NetworkBaselineStatusRequest

X

Content Type

  • application/json

Responses

Table 2. HTTP Response Codes
Code Message Datatype

200

A successful response.

V1NetworkBaselineStatusResponse

0

An unexpected error response.

RuntimeError

Samples

LockNetworkBaseline

PATCH /v1/networkbaseline/{id}/lock

Description

Parameters

Path Parameters

Name Description Required Default Pattern

id

X

null

Body Parameter

Name Description Required Default Pattern

body

V1ResourceByID

X

Return Type

Object

Content Type

  • application/json

Responses

Table 3. HTTP Response Codes
Code Message Datatype

200

A successful response.

Object

0

An unexpected error response.

RuntimeError

Samples

ModifyBaselineStatusForPeers

PATCH /v1/networkbaseline/{deploymentId}/peers

Description

Parameters

Path Parameters

Name Description Required Default Pattern

deploymentId

X

null

Body Parameter

Name Description Required Default Pattern

body

V1ModifyBaselineStatusForPeersRequest

X

Return Type

Object

Content Type

  • application/json

Responses

Table 4. HTTP Response Codes
Code Message Datatype

200

A successful response.

Object

0

An unexpected error response.

RuntimeError

Samples

UnlockNetworkBaseline

PATCH /v1/networkbaseline/{id}/unlock

Description

Parameters

Path Parameters

Name Description Required Default Pattern

id

X

null

Body Parameter

Name Description Required Default Pattern

body

V1ResourceByID

X

Return Type

Object

Content Type

  • application/json

Responses

Table 5. HTTP Response Codes
Code Message Datatype

200

A successful response.

Object

0

An unexpected error response.

RuntimeError

Samples

Common object reference

DeploymentListenPort

Field Name Required Nullable Type Description Format

port

Long

int64

l4protocol

StorageL4Protocol

L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY,

NetworkEntityInfoExternalSource

Update normalizeDupNameExtSrcs(…​) in central/networkgraph/aggregator/aggregator.go whenever this message is updated.

Field Name Required Nullable Type Description Format

name

String

cidr

String

default

Boolean

default indicates whether the external source is user-generated or system-generated.

ProtobufAny

Any contains an arbitrary serialized protocol buffer message along with a URL that describes the type of the serialized message.

Protobuf library provides support to pack/unpack Any values in the form of utility functions or additional generated methods of the Any type.

Example 1: Pack and unpack a message in C++.

Foo foo = ...;
Any any;
any.PackFrom(foo);
...
if (any.UnpackTo(&foo)) {
  ...
}

Example 2: Pack and unpack a message in Java.

Foo foo = ...;
Any any = Any.pack(foo);
...
if (any.is(Foo.class)) {
  foo = any.unpack(Foo.class);
}
// or ...
if (any.isSameTypeAs(Foo.getDefaultInstance())) {
  foo = any.unpack(Foo.getDefaultInstance());
}
Example 3: Pack and unpack a message in Python.
foo = Foo(...)
any = Any()
any.Pack(foo)
...
if any.Is(Foo.DESCRIPTOR):
  any.Unpack(foo)
  ...
Example 4: Pack and unpack a message in Go
foo := &pb.Foo{...}
any, err := anypb.New(foo)
if err != nil {
  ...
}
...
foo := &pb.Foo{}
if err := any.UnmarshalTo(foo); err != nil {
  ...
}

The pack methods provided by protobuf library will by default use 'type.googleapis.com/full.type.name' as the type URL and the unpack methods only use the fully qualified type name after the last '/' in the type URL, for example "foo.bar.com/x/y.z" will yield type name "y.z".

JSON representation

The JSON representation of an Any value uses the regular representation of the deserialized, embedded message, with an additional field @type which contains the type URL. Example:

package google.profile;
message Person {
  string first_name = 1;
  string last_name = 2;
}
{
  "@type": "type.googleapis.com/google.profile.Person",
  "firstName": <string>,
  "lastName": <string>
}

If the embedded message type is well-known and has a custom JSON representation, that representation will be embedded adding a field value which holds the custom JSON in addition to the @type field. Example (for message [google.protobuf.Duration][]):

{
  "@type": "type.googleapis.com/google.protobuf.Duration",
  "value": "1.212s"
}
Field Name Required Nullable Type Description Format

typeUrl

String

A URL/resource name that uniquely identifies the type of the serialized protocol buffer message. This string must contain at least one \"/\" character. The last segment of the URL’s path must represent the fully qualified name of the type (as in path/google.protobuf.Duration). The name should be in a canonical form (e.g., leading \".\" is not accepted). In practice, teams usually precompile into the binary all types that they expect it to use in the context of Any. However, for URLs which use the scheme http, https, or no scheme, one can optionally set up a type server that maps type URLs to message definitions as follows: * If no scheme is provided, https is assumed. * An HTTP GET on the URL must yield a [google.protobuf.Type][] value in binary format, or produce an error. * Applications are allowed to cache lookup results based on the URL, or have them precompiled into a binary to avoid any lookup. Therefore, binary compatibility needs to be preserved on changes to types. (Use versioned type names to manage breaking changes.) Note: this functionality is not currently available in the official protobuf release, and it is not used for type URLs beginning with type.googleapis.com. As of May 2023, there are no widely used type server implementations and no plans to implement one. Schemes other than http, https (or the empty scheme) might be used with implementation specific semantics.

value

byte[]

Must be a valid serialized protocol buffer of the above specified type.

byte

RuntimeError

Field Name Required Nullable Type Description Format

error

String

code

Integer

int32

message

String

details

List of ProtobufAny

StorageL4Protocol

Enum Values

L4_PROTOCOL_UNKNOWN

L4_PROTOCOL_TCP

L4_PROTOCOL_UDP

L4_PROTOCOL_ICMP

L4_PROTOCOL_RAW

L4_PROTOCOL_SCTP

L4_PROTOCOL_ANY

StorageNetworkBaseline

NetworkBaseline represents a network baseline of a deployment. It contains all the baseline peers and their respective connections. next available tag: 8
Field Name Required Nullable Type Description Format

deploymentId

String

This is the ID of the baseline.

clusterId

String

namespace

String

peers

List of StorageNetworkBaselinePeer

forbiddenPeers

List of StorageNetworkBaselinePeer

A list of peers that will never be added to the baseline. For now, this contains peers that the user has manually removed. This is used to ensure we don’t add it back in the event we see the flow again.

observationPeriodEnd

Date

date-time

locked

Boolean

deploymentName

String

StorageNetworkBaselineConnectionProperties

NetworkBaselineConnectionProperties represents information about a baseline connection next available tag: 4
Field Name Required Nullable Type Description Format

ingress

Boolean

port

Long

int64

protocol

StorageL4Protocol

L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY,

StorageNetworkBaselinePeer

NetworkBaselinePeer represents a baseline peer. next available tag: 3
Field Name Required Nullable Type Description Format

entity

StorageNetworkEntity

properties

List of StorageNetworkBaselineConnectionProperties

StorageNetworkEntity

Field Name Required Nullable Type Description Format

info

StorageNetworkEntityInfo

scope

StorageNetworkEntityScope

StorageNetworkEntityInfo

Field Name Required Nullable Type Description Format

type

StorageNetworkEntityInfoType

UNKNOWN_TYPE, DEPLOYMENT, INTERNET, LISTEN_ENDPOINT, EXTERNAL_SOURCE, INTERNAL_ENTITIES,

id

String

deployment

StorageNetworkEntityInfoDeployment

externalSource

NetworkEntityInfoExternalSource

StorageNetworkEntityInfoDeployment

Field Name Required Nullable Type Description Format

name

String

namespace

String

cluster

String

listenPorts

List of DeploymentListenPort

StorageNetworkEntityInfoType

  • INTERNAL_ENTITIES: INTERNAL_ENTITIES is for grouping all internal entities under a single network graph node

Enum Values

UNKNOWN_TYPE

DEPLOYMENT

INTERNET

LISTEN_ENDPOINT

EXTERNAL_SOURCE

INTERNAL_ENTITIES

StorageNetworkEntityScope

Field Name Required Nullable Type Description Format

clusterId

String

V1ModifyBaselineStatusForPeersRequest

Field Name Required Nullable Type Description Format

deploymentId

String

peers

List of V1NetworkBaselinePeerStatus

V1NetworkBaselinePeerEntity

Field Name Required Nullable Type Description Format

id

String

type

StorageNetworkEntityInfoType

UNKNOWN_TYPE, DEPLOYMENT, INTERNET, LISTEN_ENDPOINT, EXTERNAL_SOURCE, INTERNAL_ENTITIES,

V1NetworkBaselinePeerStatus

Field Name Required Nullable Type Description Format

peer

V1NetworkBaselineStatusPeer

status

V1NetworkBaselinePeerStatusStatus

BASELINE, ANOMALOUS,

V1NetworkBaselinePeerStatusStatus

Status of this peer connection. As of now we only have two statuses:   - BASELINE: the connection is in the current deployment baseline   - ANOMALOUS: the connection is not recognized by the current deployment baseline
Enum Values

BASELINE

ANOMALOUS

V1NetworkBaselineStatusPeer

Field Name Required Nullable Type Description Format

entity

V1NetworkBaselinePeerEntity

port

Long

The port and protocol of the destination of the given connection.

int64

protocol

StorageL4Protocol

L4_PROTOCOL_UNKNOWN, L4_PROTOCOL_TCP, L4_PROTOCOL_UDP, L4_PROTOCOL_ICMP, L4_PROTOCOL_RAW, L4_PROTOCOL_SCTP, L4_PROTOCOL_ANY,

ingress

Boolean

A boolean representing whether the query is for an ingress or egress connection. This is defined with respect to the current deployment. Thus: - If the connection in question is in the outEdges of the current deployment, this should be false. - If it is in the outEdges of the peer deployment, this should be true.

V1NetworkBaselineStatusRequest

Field Name Required Nullable Type Description Format

deploymentId

String

peers

List of V1NetworkBaselineStatusPeer

V1NetworkBaselineStatusResponse

Field Name Required Nullable Type Description Format

statuses

List of V1NetworkBaselinePeerStatus

V1ResourceByID

Field Name Required Nullable Type Description Format

id

String