Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Create a trust policy
Creates a trust policy.
This method is not served on the public API.
api.sylphx.comdoes not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.
Creates a trust policy.
Not available yet. Sylphx Broker is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.
- Path
POST https://api.sylphx.com/v1/orgs/acme/trust_policies - Scope
broker:admin - Effect
write— a successful call changes state. - Collection trust_policies
- Query
trust_policy_id,validate_only
#Request
| Field | Type | What it is |
|---|---|---|
parent | string | The org to create in. Required. |
trust_policy | TrustPolicy | The trust policy to create; only spec and caller-writable metadata are read. Required. |
trust_policy_id | string | The id of the new trust policy, ^[a-z]([a-z0-9_-]{0,61}[a-z0-9])?$; the server assigns one when empty. |
validate_only | bool | Validate and return the result without writing anything. |
#TrustPolicy
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/trust_policies/{trust_policy}. |
meta | ResourceMeta | Resource metadata. |
spec | TrustPolicySpec | Desired state. Required. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
#TrustPolicySpec
| Field | Type | What it is |
|---|---|---|
connection | string | The Connection credentials are issued on. Required. |
subjects | string[] | The identities allowed to exchange: SPIFFE ids (spiffe://<trust-domain>/cell/<cell>/role/<role>, * matching one segment) or Sylphx Access principal names. The cell segment is never stripped. Required. |
permissions | map<string, string> | The most a credential may carry, in the provider's permission names, for example {"contents": "read", "checks": "write"}. Required. |
repositories | string[] | The most repositories a credential may cover; empty means every repository the Connection covers. |
credential_kind | CredentialKind | What the credential service issues. Required. One of access_token, runner_registration. |
max_ttl | duration | The longest a credential lives; default and maximum 1 hour. |
#Response
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/trust_policies/{trust_policy}. |
uid | string | trp_<cell><ulid>. Output only. |
meta | ResourceMeta | Resource metadata. |
spec | TrustPolicySpec | Desired state. Required. |
status | TrustPolicyStatus | Observed state. Output only. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
generation | int64 | Increases by one on every change to spec. Output only. |
etag | string | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only. |
create_time | timestamp | When the Resource was created. Output only. |
update_time | timestamp | When the Resource last changed. Output only. |
delete_time | timestamp | Set while the Resource is being deleted. Output only. |
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
creator | string | The principal that created the Resource. Output only. |
#TrustPolicySpec
| Field | Type | What it is |
|---|---|---|
connection | string | The Connection credentials are issued on. Required. |
subjects | string[] | The identities allowed to exchange: SPIFFE ids (spiffe://<trust-domain>/cell/<cell>/role/<role>, * matching one segment) or Sylphx Access principal names. The cell segment is never stripped. Required. |
permissions | map<string, string> | The most a credential may carry, in the provider's permission names, for example {"contents": "read", "checks": "write"}. Required. |
repositories | string[] | The most repositories a credential may cover; empty means every repository the Connection covers. |
credential_kind | CredentialKind | What the credential service issues. Required. One of access_token, runner_registration. |
max_ttl | duration | The longest a credential lives; default and maximum 1 hour. |
#TrustPolicyStatus
| Field | Type | What it is |
|---|---|---|
observed_generation | int64 | The generation this status was computed from. Output only. |
conditions | Condition[] | Ready, Reconciling, Stalled. Ready is FALSE with reason CapabilityMissing when the Connection lacks a permission the policy names. Output only. |
#Condition
| Field | Type | What it is |
|---|---|---|
type | string | The condition type, for example Ready. |
status | ConditionStatus | Whether the condition holds. One of true, false, unknown. |
observed_generation | int64 | The generation this observation was made against. |
reason | string | A machine-readable UpperCamelCase reason. |
message | string | A customer-safe human-readable message. |
severity | Severity | How severe a FALSE condition is. One of info, warning, error. |
transition_time | timestamp | When status last changed. |
#Errors
UNAUTHENTICATED— No valid key or token was presented.PERMISSION_DENIED— The key lacks the method's permission.UNKNOWN_FIELD— The request has a field the schema does not know.INVALID_FIELD— A field failed validation.RESOURCE_ALREADY_EXISTS— A Resource with this name exists.IDEMPOTENCY_KEY_REUSED— An Idempotency-Key was reused with another body.IDEMPOTENCY_IN_PROGRESS— The first call with this Idempotency-Key is still running.PLAN_LIMIT_REACHED— The plan's limit is reached.
Every error arrives in the body Errors describes.
#Examples
curl -X POST "https://api.sylphx.com/v1/orgs/acme/trust_policies" \
-H "Authorization: Bearer $SYLPHX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"spec":{"connection":"…","credential_kind":"access_token","permissions":{},"subjects":["…"]}}'