Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

List Repository Access Policies

GET
/registry/v1/workspaces/{workspace}/engines/{engine}/repositories/{repository}/access-policies
curl --request GET \
--url https://example.com/registry/v1/workspaces/example/engines/example/repositories/example/access-policies

Returns a page of access policies scoped to a repository, filtered by AIP-160 expression and ordered per AIP-132.

workspace
required
string
engine
required
string
repository
required
string
page_size
integer format: int32

The maximum number of access policies to return. The service may return fewer than this value. If unspecified, at most 20 access policies will be returned. The maximum value is 100; values above 100 will be coerced to 100.

page_token
string

A page token, received from a previous ListRepositoryAccessPolicies call.

filter
string

AIP-160 filter expression. Filterable fields: create_time, engine, id, principal_id, principal_type, repo_name_pattern, scope.scope_repository_id, scope.scope_type, scope.scope_workspace_id, update_time.

order_by
string

AIP-132 order_by expression. Sortable fields: create_time, engine, principal_type, update_time.

skip
string

AIP-158 offset mode: number of resources to skip from the start of the filtered, sorted set. Use EITHER skip (offset paging) OR page_token (cursor paging) — never both in the same request. Supplying both is an invalid request. Default 0 (no skip).

OK

Media type application/json

ListRepositoryAccessPoliciesResponse

Response message for ListRepositoryAccessPolicies.

object
access_policies
Array<object>

An access policy grants a principal one or more registry actions on a scope — the whole workspace registry, a single repository, or a name pattern. Policies narrow a principal below their workspace role; they never grant beyond it. The scope is derived from the URL path (and the pattern from the body) and echoed back on the resolved scope.

object
id
stringOutput only
scope

The resolved scope of this policy. On input the workspace and repository ids are derived from the URL path; a pattern is supplied in the body.

object
scope_type
required

The scope discriminator.

string format: enum
Allowed values: POLICY_SCOPE_TYPE_UNSPECIFIED POLICY_SCOPE_TYPE_WORKSPACE POLICY_SCOPE_TYPE_REPOSITORY POLICY_SCOPE_TYPE_PATTERN
scope_workspace_id

The workspace the policy is scoped to. Set for WORKSPACE and PATTERN scopes.

string
scope_repository_id

The repository the policy is scoped to. Set for REPOSITORY scope.

string
repo_name_pattern

The doublestar glob matched against repository names. Set for PATTERN scope.

string
principal_id
required
string
principal_type
required
string format: enum
Allowed values: PRINCIPAL_TYPE_UNSPECIFIED PRINCIPAL_TYPE_USER PRINCIPAL_TYPE_GROUP PRINCIPAL_TYPE_SERVICE_ACCOUNT
actions
required

The actions granted. Limited to PULL and PUSH — an access policy can only restrict a principal’s role baseline, never extend it.

Array<string>
Allowed values: REGISTRY_ACTION_UNSPECIFIED REGISTRY_ACTION_PULL REGISTRY_ACTION_PUSH
engine

The provider this policy applies to.

string format: enum Output only
Allowed values: ENGINE_UNSPECIFIED ENGINE_QIBDO
repo_name_pattern

The repository-name glob for PATTERN-scoped policies. Ignored for WORKSPACE and REPOSITORY scopes.

string
create_time
string format: date-time Output only
update_time
string format: date-time Output only
next_page_token
string
total_size

Exact count of resources matching the request’s filter and scope (both pagination modes).

string
Example
{
"access_policies": [
{
"scope": {
"scope_type": "POLICY_SCOPE_TYPE_UNSPECIFIED"
},
"principal_type": "PRINCIPAL_TYPE_UNSPECIFIED",
"actions": [
"REGISTRY_ACTION_UNSPECIFIED"
],
"engine": "ENGINE_UNSPECIFIED"
}
]
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}