Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

List trust policies

Lists an org's trust policies.

This method is not served on the public API. api.sylphx.com does not route this call: its backend is not deployed behind the public API, or does not implement the call. This page documents the contract. It is kept out of the sidebar and of search engines.

Lists an org's trust policies.

Not available yet. Sylphx Broker is declared in the registry but no backend serves it: every call answers 501 with the problem code UNIMPLEMENTED.

  • Path GET https://api.sylphx.com/v1/orgs/acme/trust_policies
  • Scope broker:read
  • Effect read — nothing is written.
  • Collection trust_policies
  • Query page_size, page_token, filter, order_by
  • Pagination the answer carries trust_policies and, when there is more, next_page_token

#Request

FieldTypeWhat it is
parentstringThe org to list in. Required.
page_sizeint32At most this many; default 50, clamped to 1000.
page_tokenstringnext_page_token of the previous page.
filterstringAIP-160 filter over labels and filterable fields.
order_bystringAIP-132 ordering over filterable fields.

#Response

FieldTypeWhat it is
trust_policiesTrustPolicy[]The page.
next_page_tokenstringThe token of the next page; empty on the last page.

#TrustPolicy

FieldTypeWhat it is
namestringorgs/{org}/trust_policies/{trust_policy}.
uidstringtrp_<cell><ulid>. Output only.
metaResourceMetaResource metadata.
specTrustPolicySpecDesired state. Required.
statusTrustPolicyStatusObserved state. Output only.

#ResourceMeta

FieldTypeWhat it is
generationint64Increases by one on every change to spec. Output only.
etagstringStrong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only.
create_timetimestampWhen the Resource was created. Output only.
update_timetimestampWhen the Resource last changed. Output only.
delete_timetimestampSet while the Resource is being deleted. Output only.
labelsmap<string, string>Caller-writable, indexed labels (AIP-122 label rules).
annotationsmap<string, string>Caller-writable, unindexed annotations.
display_namestringCaller-writable human-readable name.
creatorstringThe principal that created the Resource. Output only.

#TrustPolicySpec

FieldTypeWhat it is
connectionstringThe Connection credentials are issued on. Required.
subjectsstring[]The identities allowed to exchange: SPIFFE ids (spiffe://<trust-domain>/cell/<cell>/role/<role>, * matching one segment) or Sylphx Access principal names. The cell segment is never stripped. Required.
permissionsmap<string, string>The most a credential may carry, in the provider's permission names, for example {"contents": "read", "checks": "write"}. Required.
repositoriesstring[]The most repositories a credential may cover; empty means every repository the Connection covers.
credential_kindCredentialKindWhat the credential service issues. Required. One of access_token, runner_registration.
max_ttldurationThe longest a credential lives; default and maximum 1 hour.

#TrustPolicyStatus

FieldTypeWhat it is
observed_generationint64The generation this status was computed from. Output only.
conditionsCondition[]Ready, Reconciling, Stalled. Ready is FALSE with reason CapabilityMissing when the Connection lacks a permission the policy names. Output only.

#Condition

FieldTypeWhat it is
typestringThe condition type, for example Ready.
statusConditionStatusWhether the condition holds. One of true, false, unknown.
observed_generationint64The generation this observation was made against.
reasonstringA machine-readable UpperCamelCase reason.
messagestringA customer-safe human-readable message.
severitySeverityHow severe a FALSE condition is. One of info, warning, error.
transition_timetimestampWhen status last changed.

#Errors

Every error arrives in the body Errors describes.

#Examples

curl "https://api.sylphx.com/v1/orgs/acme/trust_policies" \
  -H "Authorization: Bearer $SYLPHX_API_KEY"