Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

Create Cross-Workspace Pull Grant

POST
/registry/v1/workspaces/{workspace}/engines/{engine}/pull-grants
curl --request POST \
--url https://example.com/registry/v1/workspaces/example/engines/example/pull-grants \
--header 'Content-Type: application/json' \
--data '{ "target_workspace_id": "example", "repository_id": "example", "repo_name_pattern": "example" }'

Grants a target workspace read-only pull access to a source repository (or a glob of source repositories). The {workspace} path segment is the source workspace being shared out.

workspace
required
string

The source workspace whose repositories are shared out.

engine
required
string
Media type application/json

A cross-workspace pull grant lets principals of a TARGET workspace pull (read-only) from a SOURCE workspace’s registry — either one specific source repository or a glob of source repository names. Sharing out a source workspace’s repositories is the source owner’s act, so a grant is created under the source workspace path. Grants are pull-only by construction: there is no action field and no push is ever conferred.

object
id
stringOutput only
engine

The provider the grant applies to.

string format: enum Output only
Allowed values: ENGINE_UNSPECIFIED ENGINE_QIBDO
source_workspace_id

The workspace whose repositories are shared. Stamped from the request path — a caller cannot address one workspace in the path and grant out another’s repositories.

stringOutput only
target_workspace_id
required

The workspace whose principals gain pull access to the source’s repositories.

string
repository_id

A specific source repository to share. Exactly one of repository_id or repo_name_pattern must be set (enforced by the domain model). Present when the grant targets a single repository.

string
repo_name_pattern

A glob over source repository names (doublestar syntax, e.g. web/**). Exactly one of repository_id or repo_name_pattern must be set. Present when the grant targets a pattern.

string
create_time

Created Timestamp

When this grant was created.

string format: date-time Output only
update_time

Updated Timestamp

When this grant was last updated.

string format: date-time Output only

OK

Media type application/json

Registry Operation

An acknowledgment of a mutation request, carrying tracking metadata, errors, and warnings. Follows GCP’s Operations pattern (AIP-151).

object
id

Operation ID

Unique identifier for this operation.

stringOutput only
resource_id

Resource ID

The ID of the resource affected by this operation. May be empty for async operations where the resource does not yet exist.

stringOutput only
resource_type

Resource Type

The type of resource (e.g., “com.qibdo.cloud.registry:repository”).

stringOutput only
operation_type

Operation Type

The kind of mutation that was requested.

string format: enum Output only
Allowed values: REGISTRY_OPERATION_TYPE_UNSPECIFIED REGISTRY_OPERATION_TYPE_CREATE REGISTRY_OPERATION_TYPE_UPDATE REGISTRY_OPERATION_TYPE_DELETE REGISTRY_OPERATION_TYPE_TRIGGER
status

Status

Current lifecycle state of the operation.

string format: enum Output only
Allowed values: REGISTRY_OPERATION_STATUS_UNSPECIFIED REGISTRY_OPERATION_STATUS_PENDING REGISTRY_OPERATION_STATUS_RUNNING REGISTRY_OPERATION_STATUS_DONE REGISTRY_OPERATION_STATUS_ERROR
insert_time

Insert Time

When the operation was first created.

string format: date-time Output only
start_time

Start Time

When the operation started executing.

string format: date-time Output only
end_time

End Time

When the operation completed (either successfully or with errors).

string format: date-time Output only
errors

Errors

Business rule errors encountered during the operation.

Array<object>Output only

Operation Error

A structured error returned inside an operation when a business rule fails.

object
code

Error Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the error.

stringOutput only
reason

Reason

Machine-readable error identifier in UPPER_SNAKE form — the same dispatch key google.rpc.ErrorInfo.reason carries on the synchronous error plane.

stringOutput only
warnings

Warnings

Non-fatal notices about the operation.

Array<object>Output only

Operation Warning

A non-fatal notice attached to an operation.

object
code

Warning Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the warning.

stringOutput only
progress

Progress

Percentage of completion (0-100).

integer format: int32 Output only
scope_type

Scope Type

The category of scope the operation ran in or was triggered from. REGISTRY_SCOPE_TYPE_UNSPECIFIED when the operation is not scoped.

string format: enum Output only
Allowed values: REGISTRY_SCOPE_TYPE_UNSPECIFIED REGISTRY_SCOPE_TYPE_PLATFORM REGISTRY_SCOPE_TYPE_ORGANISATION REGISTRY_SCOPE_TYPE_WORKSPACE REGISTRY_SCOPE_TYPE_GROUP
scope_id

Scope ID

The resource this operation was scoped to — for example, when scope_type is REGISTRY_SCOPE_TYPE_WORKSPACE this is the workspace id. Empty for REGISTRY_SCOPE_TYPE_PLATFORM, which has no scoped resource, and when unscoped.

stringOutput only
principal_id

Principal ID

Who performed or triggered the operation, whether a person or a machine account. Always populated: platform-driven work records the reserved system principal, so every audit record names an actor.

stringOutput only
trace_id

Trace ID

W3C trace id, for correlating this operation with the traces and log lines of the request that caused it. Empty when the operation ran with no trace context — a scheduled or event-driven action rather than a request.

stringOutput only
Example
{
"operation_type": "REGISTRY_OPERATION_TYPE_UNSPECIFIED",
"status": "REGISTRY_OPERATION_STATUS_UNSPECIFIED",
"scope_type": "REGISTRY_SCOPE_TYPE_UNSPECIFIED"
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}