Skip to content
qibdo qibdo
v1
API version
  • v1
Theme
Book a demo

Update Access Policy

PATCH
/vault/v1/workspaces/{workspace}/engines/qibdo/accessPolicies/{id}
curl --request PATCH \
--url https://example.com/vault/v1/workspaces/example/engines/qibdo/accessPolicies/example \
--header 'Content-Type: application/json' \
--data '{ "name": "example", "document": { "rules": [ { "resource_name_pattern": "example", "permissions": [ "example" ], "ttl_cap": "example", "conditions": [ { "source_ip": { "operator": "SOURCE_IP_OPERATOR_UNSPECIFIED", "cidrs": [ "example" ] }, "time_window": { "operator": "TIME_WINDOW_OPERATOR_UNSPECIFIED", "from": "example", "to": "example", "timezone": "example" } } ] } ] } }'

Replaces the active policy document with a new one. The previous document is pushed onto the policy’s version_history. Per AIP-134, supply the resource fields to update alongside a FieldMask; * requests full replacement semantics.

workspace
required
string

The workspace the access policy belongs to.

id
required
string

The unique identifier of the access policy to update.

update_mask
string format: field-mask

AIP-134 FieldMask. Omit for implicit mask of populated fields; * for full replacement.

Media type application/json

QibdoAccessPolicy resource: workspace-scoped access policy document layered on top of Qibdo IAM. The policy document composes one or more rules that grant a set of permissions on a resource-name pattern, optionally constrained by source IP ranges or time windows. The version_history list is a Qibdo-invented enhancement: every update appends the previous document so the full revision trail is auditable. Policies are consulted as a second-pass check after the IAM @PreAuthorize gate.

object
id

The unique identifier of the access policy (UUID).

stringOutput only
workspace_id

The workspace this policy belongs to (UUID, weak reference to taxonomy).

stringOutput only
name
required

Human-readable name of the policy, unique within the workspace (3–256 chars, lowercase alphanumerics plus / - _).

string
schema_version

The JSONB schema version governing the shape of document and version_history entries. Server-managed.

stringOutput only
document
required

The active policy document (rules + conditions).

object
rules

The rules that make up this policy. Every rule’s resource_name_pattern MUST be unique within a document.

Array<object>

AccessPolicyRule: grants a set of permissions on a resource-name pattern, optionally bounded by TTL and conditions.

object
resource_name_pattern
required

Resource-name pattern, e.g. “workspaces//secrets/”. The wildcard semantics follow Google AIP-159.

string
permissions
required

Permissions granted when the rule matches, e.g. “vault.secret.get”. At least one permission is required per rule.

Array<string>
ttl_cap

Optional upper bound on the lifetime of credentials issued via this rule. Unset means no TTL cap imposed by this rule.

string
/^-?(?:0|[1-9][0-9]{0,11})(?:\.[0-9]{1,9})?s$/
conditions

Conjunctive constraints; all listed conditions must evaluate to true for the rule to apply.

Array<object>

AccessPolicyCondition: a constraint evaluated at authorization time. Mirrors IAM’s Condition hierarchy structurally (DOM-003: no shared domain types across bounded contexts).

object
source_ip

SourceIpCondition: restricts access to callers whose source IP falls inside (or outside) a set of CIDR ranges.

object
operator
required

Whether the rule grants when the source IP is in any listed CIDR, or in none.

string format: enum
Allowed values: SOURCE_IP_OPERATOR_UNSPECIFIED SOURCE_IP_OPERATOR_IN_RANGE SOURCE_IP_OPERATOR_NOT_IN_RANGE
cidrs
required

List of CIDR ranges to match against the caller’s source IP.

Array<string>
time_window

TimeWindowCondition: restricts access to callers whose request timestamp falls inside (or outside) a daily time window in the given timezone.

object
operator
required

Whether the rule grants when the current time is inside [from, to], or outside it.

string format: enum
Allowed values: TIME_WINDOW_OPERATOR_UNSPECIFIED TIME_WINDOW_OPERATOR_WITHIN TIME_WINDOW_OPERATOR_OUTSIDE
from
required

Start of the window in HH:mm 24-hour notation.

string
to
required

End of the window in HH:mm 24-hour notation.

string
timezone
required

IANA timezone identifier, e.g. “Europe/Amsterdam”.

string
version_history

Append-only list of previous document revisions. Each update pushes the pre-mutation document onto this list. Server-managed.

Array<object>Output only

AccessPolicyRevision: a snapshot of a previous policy document captured at update time. Qibdo-invented audit trail (upstream clouds do not expose policy revision history).

object
revision_number

Monotonically increasing revision number; starts at 1 for the first edit.

stringOutput only
previous_document

The document that was replaced.

object
rules

The rules that make up this policy. Every rule’s resource_name_pattern MUST be unique within a document.

Array<object>

AccessPolicyRule: grants a set of permissions on a resource-name pattern, optionally bounded by TTL and conditions.

object
resource_name_pattern
required

Resource-name pattern, e.g. “workspaces//secrets/”. The wildcard semantics follow Google AIP-159.

string
permissions
required

Permissions granted when the rule matches, e.g. “vault.secret.get”. At least one permission is required per rule.

Array<string>
ttl_cap

Optional upper bound on the lifetime of credentials issued via this rule. Unset means no TTL cap imposed by this rule.

string
/^-?(?:0|[1-9][0-9]{0,11})(?:\.[0-9]{1,9})?s$/
conditions

Conjunctive constraints; all listed conditions must evaluate to true for the rule to apply.

Array<object>

AccessPolicyCondition: a constraint evaluated at authorization time. Mirrors IAM’s Condition hierarchy structurally (DOM-003: no shared domain types across bounded contexts).

object
source_ip

SourceIpCondition: restricts access to callers whose source IP falls inside (or outside) a set of CIDR ranges.

object
operator
required

Whether the rule grants when the source IP is in any listed CIDR, or in none.

string format: enum
Allowed values: SOURCE_IP_OPERATOR_UNSPECIFIED SOURCE_IP_OPERATOR_IN_RANGE SOURCE_IP_OPERATOR_NOT_IN_RANGE
cidrs
required

List of CIDR ranges to match against the caller’s source IP.

Array<string>
time_window

TimeWindowCondition: restricts access to callers whose request timestamp falls inside (or outside) a daily time window in the given timezone.

object
operator
required

Whether the rule grants when the current time is inside [from, to], or outside it.

string format: enum
Allowed values: TIME_WINDOW_OPERATOR_UNSPECIFIED TIME_WINDOW_OPERATOR_WITHIN TIME_WINDOW_OPERATOR_OUTSIDE
from
required

Start of the window in HH:mm 24-hour notation.

string
to
required

End of the window in HH:mm 24-hour notation.

string
timezone
required

IANA timezone identifier, e.g. “Europe/Amsterdam”.

string
edited_by

The principal that performed the edit (UUID, weak reference to IAM user).

stringOutput only
edit_time

When the edit happened (server-managed).

string format: date-time Output only
create_time

Timestamp when the policy was created (server-managed).

string format: date-time Output only
update_time

Timestamp when the policy was last updated (server-managed).

string format: date-time Output only
location_id

Weak reference to a topology Location: where this resource resides. Defaults to the global location when omitted at creation and is immutable thereafter. Only the global location is available in this release.

stringOutput only

OK

Media type application/json

Vault Operation

An acknowledgment of a mutation request, carrying tracking metadata, errors, and warnings. Follows GCP’s Operations pattern (AIP-151).

object
id

Operation ID

Unique identifier for this operation.

stringOutput only
resource_id

Resource ID

The ID of the resource affected by this operation. May be empty for vault-level lifecycle operations such as snapshot.

stringOutput only
resource_type

Resource Type

The type of resource (e.g., “com.qibdo.cloud.vault:secret”).

stringOutput only
operation_type

Operation Type

The kind of mutation that was requested.

string format: enum Output only
Allowed values: VAULT_OPERATION_TYPE_UNSPECIFIED VAULT_OPERATION_TYPE_CREATE VAULT_OPERATION_TYPE_UPDATE VAULT_OPERATION_TYPE_DELETE VAULT_OPERATION_TYPE_ADD_VERSION VAULT_OPERATION_TYPE_DISABLE_VERSION VAULT_OPERATION_TYPE_DESTROY_VERSION VAULT_OPERATION_TYPE_SCHEDULE_DESTROY_VERSION VAULT_OPERATION_TYPE_ROTATE VAULT_OPERATION_TYPE_ENCRYPT VAULT_OPERATION_TYPE_DECRYPT VAULT_OPERATION_TYPE_SIGN VAULT_OPERATION_TYPE_VERIFY VAULT_OPERATION_TYPE_HMAC VAULT_OPERATION_TYPE_RE_ENCRYPT VAULT_OPERATION_TYPE_GENERATE_DATA_ENCRYPTION_KEY VAULT_OPERATION_TYPE_GENERATE_RANDOM_BYTES VAULT_OPERATION_TYPE_ISSUE VAULT_OPERATION_TYPE_REVOKE VAULT_OPERATION_TYPE_RENEW VAULT_OPERATION_TYPE_BULK_REVOKE VAULT_OPERATION_TYPE_SNAPSHOT VAULT_OPERATION_TYPE_RESTORE VAULT_OPERATION_TYPE_ROOT_KEY_ROTATION VAULT_OPERATION_TYPE_WRAP VAULT_OPERATION_TYPE_UNWRAP VAULT_OPERATION_TYPE_ROTATE_SECRET_ID VAULT_OPERATION_TYPE_AUTHENTICATE VAULT_OPERATION_TYPE_REGISTER_DATABASE_ROLE VAULT_OPERATION_TYPE_UPDATE_DATABASE_ROLE VAULT_OPERATION_TYPE_DELETE_DATABASE_ROLE VAULT_OPERATION_TYPE_REGISTER_PKI_ROLE VAULT_OPERATION_TYPE_UPDATE_PKI_ROLE VAULT_OPERATION_TYPE_DELETE_PKI_ROLE VAULT_OPERATION_TYPE_AUTHORIZE
status

Status

Current lifecycle state of the operation.

string format: enum Output only
Allowed values: VAULT_OPERATION_STATUS_UNSPECIFIED VAULT_OPERATION_STATUS_PENDING VAULT_OPERATION_STATUS_RUNNING VAULT_OPERATION_STATUS_DONE VAULT_OPERATION_STATUS_ERROR
insert_time

Insert Time

When the operation was first created.

string format: date-time Output only
start_time

Start Time

When the operation started executing.

string format: date-time Output only
end_time

End Time

When the operation completed (either successfully or with errors).

string format: date-time Output only
errors

Errors

Business rule errors encountered during the operation.

Array<object>Output only

Operation Error

A structured error returned inside an operation when a business rule fails.

object
code

Error Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the error.

stringOutput only
reason

Reason

Machine-readable error identifier in UPPER_SNAKE form — the same dispatch key google.rpc.ErrorInfo.reason carries on the synchronous error plane.

stringOutput only
warnings

Warnings

Non-fatal notices about the operation.

Array<object>Output only

Operation Warning

A non-fatal notice attached to an operation. The operation still completed; the warning surfaces unsupported features or capability gaps in the underlying engine.

object
code

Warning Code

Numeric identifier following the S_SSS_EEE convention.

integer format: uint32 Output only
description

Description

Human-readable explanation of the warning.

stringOutput only
progress

Progress

Percentage of completion (0-100).

integer format: int32 Output only
scope_type

Scope Type

The category of scope the operation ran in or was triggered from. VAULT_SCOPE_TYPE_UNSPECIFIED when the operation is not scoped.

string format: enum Output only
Allowed values: VAULT_SCOPE_TYPE_UNSPECIFIED VAULT_SCOPE_TYPE_PLATFORM VAULT_SCOPE_TYPE_ORGANISATION VAULT_SCOPE_TYPE_WORKSPACE VAULT_SCOPE_TYPE_GROUP
scope_id

Scope ID

The resource this operation was scoped to — for example, when scope_type is VAULT_SCOPE_TYPE_WORKSPACE this is the workspace id. Empty for VAULT_SCOPE_TYPE_PLATFORM, which has no scoped resource, and when unscoped.

stringOutput only
principal_id

Principal ID

Who performed or triggered the operation, whether a person or a machine account. Always populated: platform-driven work records the reserved system principal, so every audit record names an actor.

stringOutput only
trace_id

Trace ID

W3C trace id, for correlating this operation with the traces and log lines of the request that caused it. Empty when the operation ran with no trace context — a scheduled or event-driven action rather than a request.

stringOutput only
Example
{
"operation_type": "VAULT_OPERATION_TYPE_UNSPECIFIED",
"status": "VAULT_OPERATION_STATUS_UNSPECIFIED",
"scope_type": "VAULT_SCOPE_TYPE_UNSPECIFIED"
}

Default error response

Media type application/json

The Status type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by gRPC. Each Status message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the API Design Guide.

object
code

The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].

integer format: int32
message

A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.

string
details

A list of messages that carry the error details. There is a common set of message types for APIs to use.

Array<object>

Contains an arbitrary serialized message along with a @type that describes the type of the serialized message.

object
@type

The type of the serialized message.

string
key
additional properties
any
Example generated
{
"code": 1,
"message": "example",
"details": [
{
"@type": "example"
}
]
}