Create Repository Access Policy
const url = 'https://example.com/registry/v1/workspaces/example/engines/example/repositories/example/access-policies';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"principal_id":"example","principal_type":"PRINCIPAL_TYPE_UNSPECIFIED","actions":["REGISTRY_ACTION_UNSPECIFIED"],"repo_name_pattern":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://example.com/registry/v1/workspaces/example/engines/example/repositories/example/access-policies \ --header 'Content-Type: application/json' \ --data '{ "principal_id": "example", "principal_type": "PRINCIPAL_TYPE_UNSPECIFIED", "actions": [ "REGISTRY_ACTION_UNSPECIFIED" ], "repo_name_pattern": "example" }'Creates an access policy scoped to a single repository. The policy grants the principal registry actions on that repository.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The unique identifier of the repository the policy is bound to.
Request Body required
Section titled “Request Body required ”An access policy grants a principal one or more registry actions on a scope — the whole
workspace registry, a single repository, or a name pattern. Policies narrow a principal below
their workspace role; they never grant beyond it. The scope is derived from the URL path (and
the pattern from the body) and echoed back on the resolved scope.
object
The resolved scope of this policy. On input the workspace and repository ids are derived from the URL path; a pattern is supplied in the body.
object
The scope discriminator.
The workspace the policy is scoped to. Set for WORKSPACE and PATTERN scopes.
The repository the policy is scoped to. Set for REPOSITORY scope.
The doublestar glob matched against repository names. Set for PATTERN scope.
The actions granted. Limited to PULL and PUSH — an access policy can only restrict a principal’s role baseline, never extend it.
The provider this policy applies to.
The repository-name glob for PATTERN-scoped policies. Ignored for WORKSPACE and REPOSITORY scopes.
Responses
Section titled “ Responses ”OK
Registry Operation
An acknowledgment of a mutation request, carrying tracking metadata, errors, and warnings. Follows GCP’s Operations pattern (AIP-151).
object
Operation ID
Unique identifier for this operation.
Resource ID
The ID of the resource affected by this operation. May be empty for async operations where the resource does not yet exist.
Resource Type
The type of resource (e.g., “com.qibdo.cloud.registry:repository”).
Operation Type
The kind of mutation that was requested.
Status
Current lifecycle state of the operation.
Insert Time
When the operation was first created.
Start Time
When the operation started executing.
End Time
When the operation completed (either successfully or with errors).
Errors
Business rule errors encountered during the operation.
Operation Error
A structured error returned inside an operation when a business rule fails.
object
Error Code
Numeric identifier following the S_SSS_EEE convention.
Description
Human-readable explanation of the error.
Reason
Machine-readable error identifier in UPPER_SNAKE form — the same dispatch
key google.rpc.ErrorInfo.reason carries on the synchronous error plane.
Warnings
Non-fatal notices about the operation.
Operation Warning
A non-fatal notice attached to an operation.
object
Warning Code
Numeric identifier following the S_SSS_EEE convention.
Description
Human-readable explanation of the warning.
Progress
Percentage of completion (0-100).
Scope Type
The category of scope the operation ran in or was triggered from. REGISTRY_SCOPE_TYPE_UNSPECIFIED when the operation is not scoped.
Scope ID
The resource this operation was scoped to — for example, when scope_type is REGISTRY_SCOPE_TYPE_WORKSPACE this is the workspace id. Empty for REGISTRY_SCOPE_TYPE_PLATFORM, which has no scoped resource, and when unscoped.
Principal ID
Who performed or triggered the operation, whether a person or a machine account. Always populated: platform-driven work records the reserved system principal, so every audit record names an actor.
Trace ID
W3C trace id, for correlating this operation with the traces and log lines of the request that caused it. Empty when the operation ran with no trace context — a scheduled or event-driven action rather than a request.
Example
{ "operation_type": "REGISTRY_OPERATION_TYPE_UNSPECIFIED", "status": "REGISTRY_OPERATION_STATUS_UNSPECIFIED", "scope_type": "REGISTRY_SCOPE_TYPE_UNSPECIFIED"}default
Section titled “default ”Default error response
The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.
object
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
A list of messages that carry the error details. There is a common set of message types for APIs to use.
Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
object
The type of the serialized message.
Example generated
{ "code": 1, "message": "example", "details": [ { "@type": "example" } ]}