import requests
url = "https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/grants"
payload = { "user_email": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({user_email: '<string>'})
};
fetch('https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/grants', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request POST \
--url https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/grants \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_email": "<string>"
}
'{
"grant": {
"ankra_user_id": "<string>",
"cluster_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"id": "<string>",
"namespace": "<string>",
"organisation_id": "<string>",
"reconcile_error": "<string>",
"reconcile_status": "pending",
"reconciled_at": "2023-11-07T05:31:56Z",
"role": "view",
"scope": "cluster",
"expires_at": "2023-11-07T05:31:56Z",
"reason": "<string>",
"created_by": "<string>",
"created_by_email": "<string>",
"user_email": "<string>"
}
}{
"detail": "Cluster not found"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Create a cluster access grant
Grants an active organisation member (by user_email) a Kubernetes role (view, edit, admin or cluster-admin) on the whole cluster or on one namespace, optionally expiring via expires_in or expires_at and with an audit reason. Requires kube_access.manage and organisation admin; returns 409 when a matching grant already exists and 400 when the user is not an active member.
import requests
url = "https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/grants"
payload = { "user_email": "<string>" }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({user_email: '<string>'})
};
fetch('https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/grants', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request POST \
--url https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/grants \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_email": "<string>"
}
'{
"grant": {
"ankra_user_id": "<string>",
"cluster_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"id": "<string>",
"namespace": "<string>",
"organisation_id": "<string>",
"reconcile_error": "<string>",
"reconcile_status": "pending",
"reconciled_at": "2023-11-07T05:31:56Z",
"role": "view",
"scope": "cluster",
"expires_at": "2023-11-07T05:31:56Z",
"reason": "<string>",
"created_by": "<string>",
"created_by_email": "<string>",
"user_email": "<string>"
}
}{
"detail": "Cluster not found"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Body
view, edit, admin, cluster-admin cluster, namespace Relative window for a time-boxed grant: a duration such as 30m or 4h, or whole days such as 7d. Mutually exclusive with expires_at. Omit both for a standing grant.
Absolute expiry for a time-boxed grant (RFC 3339). Mutually exclusive with expires_in. Re-posting a matching live grant with an expiry re-times it in place.
Why the access is granted; recorded on the grant and in the audit log.
3 - 500Response
Successful Response
Show child attributes
Show child attributes