> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List the running pods of a stack with their containers' security posture



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /api/v1/org/clusters/imported/{cluster_id}/stacks/{stack_name}/security/pods
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
paths:
  /api/v1/org/clusters/imported/{cluster_id}/stacks/{stack_name}/security/pods:
    get:
      tags:
        - Security
      summary: List the running pods of a stack with their containers' security posture
      operationId: list_imported_cluster_stack_security_pods_api_v1
      parameters:
        - in: path
          name: cluster_id
          required: true
          schema:
            format: uuid
            type: string
        - in: path
          name: stack_name
          required: true
          schema:
            type: string
        - in: query
          name: page
          required: false
          schema:
            default: 1
            maximum: 10000
            minimum: 1
            type: integer
        - description: Values above 100 are clamped to 100.
          in: query
          name: page_size
          required: false
          schema:
            default: 50
            minimum: 1
            type: integer
        - in: query
          name: search
          required: false
          schema:
            type: string
          description: >-
            Case-insensitive match on pod name, namespace, member name, workload
            name, container name or image.
        - in: query
          name: member_resource_id
          required: false
          schema:
            anyOf:
              - format: uuid
                type: string
              - type: 'null'
          description: Only pods deployed by this add-on or manifest member of the stack.
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityStackSecurityPodListResponse'
          description: Successful response
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Business validation error
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityPermissionDenied'
          description: Permission denied
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Cluster or stack is not in the active organization
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Internal server error
components:
  schemas:
    SecurityStackSecurityPodListResponse:
      properties:
        result:
          items:
            $ref: '#/components/schemas/SecurityStackSecurityPod'
          type: array
        pagination:
          $ref: '#/components/schemas/SecurityPagination'
        members:
          items:
            $ref: '#/components/schemas/SecurityStackSecurityPodMember'
          type: array
        capped:
          type: boolean
          description: >-
            True when the read stopped at its cap of 2000 container rows - a pod
            with N containers spends N of it - so the listing is partial; every
            pod listed is complete.
        scanner:
          $ref: '#/components/schemas/SecurityScannerSummary'
        intelligence:
          $ref: '#/components/schemas/SecurityIntelligenceStatus'
      required:
        - result
        - pagination
        - members
        - capped
        - scanner
        - intelligence
      title: SecurityStackSecurityPodListResponse
      type: object
      description: >-
        The running pods of one stack, riskiest first, grouped by the add-on or
        manifest that deploys them.
    SecurityDetailError:
      properties:
        detail:
          type: string
      required:
        - detail
      type: object
    SecurityPermissionDenied:
      properties:
        detail:
          enum:
            - permission_denied
          type: string
        permission:
          type: string
        scope_type:
          type: string
      required:
        - detail
        - permission
        - scope_type
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    SecurityStackSecurityPod:
      properties:
        cluster_id:
          format: uuid
          type: string
        namespace:
          type: string
        pod_name:
          type: string
        pod_uid:
          anyOf:
            - type: string
            - type: 'null'
        owner_kind:
          anyOf:
            - type: string
            - type: 'null'
        owner_name:
          anyOf:
            - type: string
            - type: 'null'
        workload_kind:
          anyOf:
            - type: string
            - type: 'null'
        workload_name:
          anyOf:
            - type: string
            - type: 'null'
        member_resource_id:
          format: uuid
          type: string
        member_kind:
          enum:
            - addon
            - manifest
          type: string
        member_name:
          type: string
        last_seen_at:
          format: date-time
          type: string
        containers:
          items:
            $ref: '#/components/schemas/SecurityStackSecurityPodContainer'
          type: array
        scanned:
          type: boolean
          description: True when at least one container has a vulnerability report.
        scanned_containers:
          type: integer
        observed:
          type: integer
        actionable:
          $ref: '#/components/schemas/SecuritySeverityCounts'
        known_exploited:
          type: integer
        fixable_severe:
          type: integer
        containers_with_sbom:
          type: integer
        containers_without_sbom:
          type: integer
        priority:
          enum:
            - critical
            - high
            - medium
            - low
            - unknown
            - clean
            - unscanned
          type: string
      required:
        - cluster_id
        - namespace
        - pod_name
        - pod_uid
        - owner_kind
        - owner_name
        - workload_kind
        - workload_name
        - member_resource_id
        - member_kind
        - member_name
        - last_seen_at
        - containers
        - scanned
        - scanned_containers
        - observed
        - actionable
        - known_exploited
        - fixable_severe
        - containers_with_sbom
        - containers_without_sbom
        - priority
      title: SecurityStackSecurityPod
      type: object
      description: >-
        One running pod of the stack: the member that deploys it, its owner
        chain, and each container's CVE posture and bill of materials.
    SecurityPagination:
      properties:
        page:
          type: integer
        page_size:
          type: integer
        total_count:
          type: integer
        total_pages:
          type: integer
      required:
        - page
        - page_size
        - total_pages
        - total_count
      type: object
    SecurityStackSecurityPodMember:
      properties:
        resource_id:
          format: uuid
          type: string
        kind:
          enum:
            - addon
            - manifest
          type: string
        name:
          type: string
        namespace:
          anyOf:
            - type: string
            - type: 'null'
        pods:
          type: integer
          description: >-
            Running pods attributed to the member across the whole stack - a
            facet, unaffected by search, member_resource_id or paging, so the
            member chips keep their totals while the listing is narrowed. Zero
            means none matched, which for an unsynced cluster is not the same as
            none running.
      required:
        - resource_id
        - kind
        - name
        - namespace
        - pods
      title: SecurityStackSecurityPodMember
      type: object
    SecurityScannerSummary:
      properties:
        fresh_clusters:
          type: integer
        last_scan:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        stale_after_seconds:
          type: integer
        stale_clusters:
          type: integer
        status:
          enum:
            - fresh
            - degraded
            - stale
            - unscanned
          type: string
        unscanned_clusters:
          type: integer
      required:
        - status
        - last_scan
        - fresh_clusters
        - stale_clusters
        - unscanned_clusters
        - stale_after_seconds
      type: object
    SecurityIntelligenceStatus:
      properties:
        epss_synced_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
        kev_listed:
          type: integer
        kev_synced_at:
          anyOf:
            - format: date-time
              type: string
            - type: 'null'
      required:
        - kev_synced_at
        - epss_synced_at
        - kev_listed
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
    SecurityStackSecurityPodContainer:
      properties:
        name:
          type: string
        kind:
          enum:
            - app
            - init
          type: string
        image:
          type: string
        image_digest:
          anyOf:
            - type: string
            - type: 'null'
        image_identity:
          anyOf:
            - type: string
            - type: 'null'
          description: >-
            The key the per-image vulnerability and component reads take: the
            stored bill of materials' identity, else the digest the kubelet
            reported, else the image reference.
        scanned:
          type: boolean
          description: >-
            False when no vulnerability report covers the container; not the
            same as clean.
        observed:
          type: integer
        actionable:
          $ref: '#/components/schemas/SecuritySeverityCounts'
        known_exploited:
          type: integer
        fixable_severe:
          type: integer
        sbom_status:
          enum:
            - present
            - absent
          type: string
        component_count:
          anyOf:
            - type: integer
            - type: 'null'
      required:
        - name
        - kind
        - image
        - image_digest
        - image_identity
        - scanned
        - observed
        - actionable
        - known_exploited
        - fixable_severe
        - sbom_status
        - component_count
      title: SecurityStackSecurityPodContainer
      type: object
    SecuritySeverityCounts:
      properties:
        critical:
          type: integer
        high:
          type: integer
        low:
          type: integer
        medium:
          type: integer
        unknown:
          type: integer
      required:
        - critical
        - high
        - medium
        - low
        - unknown
      type: object

````