List Workspace Access Policies
const url = 'https://example.com/registry/v1/workspaces/example/engines/example/access-policies';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://example.com/registry/v1/workspaces/example/engines/example/access-policiesReturns a page of access policies scoped to the workspace registry, filtered by AIP-160 expression and ordered per AIP-132.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”Query Parameters
Section titled “Query Parameters ”The maximum number of access policies to return. The service may return fewer than this value. If unspecified, at most 20 access policies will be returned. The maximum value is 100; values above 100 will be coerced to 100.
A page token, received from a previous ListWorkspaceAccessPolicies call.
AIP-160 filter expression. Filterable fields: create_time, engine, id, principal_id, principal_type, repo_name_pattern, scope.scope_repository_id, scope.scope_type, scope.scope_workspace_id, update_time.
AIP-132 order_by expression. Sortable fields: create_time, engine, principal_type, update_time.
AIP-158 offset mode: number of resources to skip from the start of the filtered, sorted set. Use EITHER skip (offset paging) OR page_token (cursor paging) — never both in the same request. Supplying both is an invalid request. Default 0 (no skip).
Responses
Section titled “ Responses ”OK
ListWorkspaceAccessPoliciesResponse
Response message for ListWorkspaceAccessPolicies.
object
An access policy grants a principal one or more registry actions on a scope — the whole
workspace registry, a single repository, or a name pattern. Policies narrow a principal below
their workspace role; they never grant beyond it. The scope is derived from the URL path (and
the pattern from the body) and echoed back on the resolved scope.
object
The resolved scope of this policy. On input the workspace and repository ids are derived from the URL path; a pattern is supplied in the body.
object
The scope discriminator.
The workspace the policy is scoped to. Set for WORKSPACE and PATTERN scopes.
The repository the policy is scoped to. Set for REPOSITORY scope.
The doublestar glob matched against repository names. Set for PATTERN scope.
The actions granted. Limited to PULL and PUSH — an access policy can only restrict a principal’s role baseline, never extend it.
The provider this policy applies to.
The repository-name glob for PATTERN-scoped policies. Ignored for WORKSPACE and REPOSITORY scopes.
Exact count of resources matching the request’s filter and scope (both pagination modes).
Example
{ "access_policies": [ { "scope": { "scope_type": "POLICY_SCOPE_TYPE_UNSPECIFIED" }, "principal_type": "PRINCIPAL_TYPE_UNSPECIFIED", "actions": [ "REGISTRY_ACTION_UNSPECIFIED" ], "engine": "ENGINE_UNSPECIFIED" } ]}default
Section titled “default ”Default error response
The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.
object
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
A list of messages that carry the error details. There is a common set of message types for APIs to use.
Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.
object
The type of the serialized message.
Example generated
{ "code": 1, "message": "example", "details": [ { "@type": "example" } ]}