import requests
url = "https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/elevate"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/elevate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request POST \
--url https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/elevate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'{
"grant": {
"ankra_user_id": "<string>",
"cluster_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"id": "<string>",
"namespace": "<string>",
"organisation_id": "<string>",
"reconcile_error": "<string>",
"reconcile_status": "pending",
"reconciled_at": "2023-11-07T05:31:56Z",
"role": "view",
"scope": "cluster",
"expires_at": "2023-11-07T05:31:56Z",
"reason": "<string>",
"created_by": "<string>",
"created_by_email": "<string>",
"user_email": "<string>"
}
}{
"detail": "Cluster not found"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Elevate your own cluster access
Break-glass addressed to the caller: the body names no member (a user_email is refused with 422), and the route grants the authenticated principal itself (a member or a service account, which has no email the grants route could name) a Kubernetes role on the whole cluster or one namespace. The grant must expire (expires_in or expires_at) within the organisation policy’s elevated_max_ttl_seconds, or 4 hours when unset, must carry a reason, and stays under max_grant_role; re-posting with a new expiry re-times only the caller’s own elevation. Requires kube_access.elevate (or kube_access.manage, held to the same bounds). Refusals answer 403 with detail cluster_access_policy_violation, cluster_access_grant_expiry_required, cluster_access_grant_lifetime_exceeded or cluster_access_grant_reason_required, naming the bound, and 409 when a matching grant exists that is not the caller’s own elevation. End it early with DELETE /api/v1/clusters//access/grants/.
import requests
url = "https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/elevate"
payload = {}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({})
};
fetch('https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/elevate', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request POST \
--url https://platform.ankra.app/api/v1/clusters/{cluster_id}/access/elevate \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{}'{
"grant": {
"ankra_user_id": "<string>",
"cluster_id": "<string>",
"created_at": "2023-11-07T05:31:56Z",
"id": "<string>",
"namespace": "<string>",
"organisation_id": "<string>",
"reconcile_error": "<string>",
"reconcile_status": "pending",
"reconciled_at": "2023-11-07T05:31:56Z",
"role": "view",
"scope": "cluster",
"expires_at": "2023-11-07T05:31:56Z",
"reason": "<string>",
"created_by": "<string>",
"created_by_email": "<string>",
"user_email": "<string>"
}
}{
"detail": "Cluster not found"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Body
view, edit, admin, cluster-admin Relative window: a duration such as 30m or 4h. Mutually exclusive with expires_at; one of the two is required.
Absolute expiry (RFC 3339). Mutually exclusive with expires_in; one of the two is required.
Why the access is needed; required, recorded on the grant, in the audit log and on the notification.
3 - 500The whole cluster (default) or one namespace.
cluster, namespace Response
Successful Response
Show child attributes
Show child attributes