import requests
url = "https://platform.ankra.app/org/security/clusters/{cluster_id}/access-posture"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://platform.ankra.app/org/security/clusters/{cluster_id}/access-posture', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request GET \
--url https://platform.ankra.app/org/security/clusters/{cluster_id}/access-posture \
--header 'Authorization: Bearer <token>'{
"cluster_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"evaluated_at": "2023-11-07T05:31:56Z",
"summary": {
"grants_total": 123,
"standing_elevated": 123,
"over_policy": 123,
"impersonate_reachable": 123,
"impersonate_verified_grants": 123
},
"findings": [
{
"check": "impersonate_reachable",
"severity": "CRITICAL",
"title": "<string>",
"grant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"ankra_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"user_email": "<string>",
"role": "<string>",
"scope": "<string>",
"namespace": "<string>",
"detail": "<string>",
"remediation": "<string>"
}
],
"unknowns": [
{
"check": "<string>",
"grant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"reason": "<string>"
}
]
}{
"detail": "permission_denied",
"permission": "<string>",
"scope_type": "<string>"
}{
"detail": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "<string>"
}Get cluster access posture (browser session)
Evaluates one cluster’s Kubernetes access posture from its kube gateway grants: a standing cluster-wide cluster-admin or admin grant, a grant over the organisation’s access policy, the creator’s grant left unchanged for 90 days on a GitOps cluster, and a grant identity the cluster verified can impersonate. Each finding names the grant and the commands that fix it; checks that could not be evaluated are listed under unknowns. Requires security.read; grantee emails appear only when the caller also holds kube_access.manage, otherwise a grantee is its grant_id and ankra_user_id.
import requests
url = "https://platform.ankra.app/org/security/clusters/{cluster_id}/access-posture"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://platform.ankra.app/org/security/clusters/{cluster_id}/access-posture', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));curl --request GET \
--url https://platform.ankra.app/org/security/clusters/{cluster_id}/access-posture \
--header 'Authorization: Bearer <token>'{
"cluster_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"evaluated_at": "2023-11-07T05:31:56Z",
"summary": {
"grants_total": 123,
"standing_elevated": 123,
"over_policy": 123,
"impersonate_reachable": 123,
"impersonate_verified_grants": 123
},
"findings": [
{
"check": "impersonate_reachable",
"severity": "CRITICAL",
"title": "<string>",
"grant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"ankra_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"user_email": "<string>",
"role": "<string>",
"scope": "<string>",
"namespace": "<string>",
"detail": "<string>",
"remediation": "<string>"
}
],
"unknowns": [
{
"check": "<string>",
"grant_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"reason": "<string>"
}
]
}{
"detail": "permission_denied",
"permission": "<string>",
"scope_type": "<string>"
}{
"detail": "<string>"
}{
"detail": [
{
"loc": [
"<string>"
],
"msg": "<string>",
"type": "<string>"
}
]
}{
"detail": "<string>"
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Response
Successful response
A cluster's Kubernetes access posture: the summary line, every failed check with its remediation, and every check that could not be evaluated. A check on a grant absent from both findings and unknowns passed.
A cluster's Kubernetes access summary line (ankra-o1fa6.7). over_policy is null when the organisation's access policy could not be read; impersonate_reachable is null unless the impersonation probe has a fresh, verified answer for every live grant on the cluster. Null is unknown, never 0.
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes