All Products
Search
Document Center

Security Center:ListKspmInstances

Last Updated:Jun 15, 2026

Queries Kubernetes asset information.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:ListKspmInstances

get

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

No

The ID of the region where the instance resides.

cn-hangzhou

Criteria

string

No

The search conditions for assets. This parameter is in JSON format. Pay attention to letter case when you specify this parameter. The following fields are included:

  • name: the search item.

  • value: the value of the search item.

  • logicalExp: the logical relationship between multiple conditions. Valid values:
    • OR: The conditions are in an OR relationship.

    • AND: The conditions are in an AND relationship.

Note

You can search by region, instance name, instance ID, alert status, risk status, or tag.

[{"name":"vulStatus","value":"YES","logicalExp":"AND"}]

LogicalExp

string

No

The logical relationship between multiple search conditions. Valid values:

  • OR: The search conditions are in an OR relationship.

  • AND: The search conditions are in an AND relationship.

OR

PageSize

integer

No

The maximum number of entries per page in a paged query. Default value: 20.

20

CurrentPage

integer

No

The page number of the page to return in the query results. Default value: 1, which indicates that the results are returned starting from page 1.

1

CloudAssetTypes

array<object>

No

The list of asset type information for Kubernetes assets.

object

No

The asset type information for a Kubernetes asset.

AssetType

integer

No

The type of the asset. Valid values:

  • 0: Workload

  • 1: Service

  • 2: Namespace

  • 3: Authorization

  • 4: Storage

  • 5: Container

  • 6: Network

  • 7: Configuration

  • 8: Policies.

0

AssetSubType

integer

No

The subtype of the asset. The value is in the format of asset type - subtype. Valid values:

  • 0: Workload
    • 0: Pod

    • 1: DaemonSet

    • 2: StatefulSet

  • 1: Service
    • 0: Service

  • 2: Namespace
    • 0: Namespace

  • 3: Authorization
    • 0: Role

    • 1: ClusterRole

    • 2: ClusterRoleBinding

    • 3: RoleBinding

    • 4: ServiceAccount

  • 4: Storage
    • 0: PersistentVolume

    • 1: PersistentVolumeClaim

    • 2: StorageClass

  • 5: Container
    • 0: Image

  • 6: Network
    • 0: Route

    • 0: Ingress

  • 7: Configuration
    • 0: ConfigMap

  • 8: Policies
    • 0: LimitRanges

    • 1: ResourceQuota.

0

Vendor

integer

No

The asset vendor. This parameter is fixed to 200.

200

Response elements

Element

Type

Description

Example

object

The response parameters.

Success

boolean

Indicates whether the API call is successful. Valid values:

  • true: successful.

  • false: failed.

true

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

7532B7EE-7CE7-5F4D-BF04-B12447DDCAE1

PageInfo

object

The paging information for a paged query.

CurrentPage

integer

The page number of the current page in a paged query.

1

PageSize

integer

The maximum number of entries per page in a paged query.

20

TotalCount

integer

The total number of entries returned.

55

Count

integer

The number of entries on the current page.

4

Instances

array<object>

The list of Kubernetes asset information.

object

The Kubernetes asset information.

RegionId

string

The ID of the region where the asset resides.

cn-hanghzou

Vendor

integer

The asset vendor. This parameter is fixed to 200.

200

AssetType

integer

The type of the asset.

1

AssetSubType

string

The subtype of the asset.

1

InstanceId

string

The instance ID.

rm-uf6t6u05n6g48****

InstanceName

string

The instance name.

yztest-l***

CreatedTime

integer

The timestamp when the instance was created. Unit: milliseconds.

1607365213000

InternetIp

string

The public IP address of the instance.

1.2.XX.XX

AlarmStatus

string

Indicates whether security alerts exist for the asset. Valid values:

  • YES: Security alerts exist.

  • NO: No security alerts exist.

NO

RiskStatus

string

Indicates whether security risks exist for the asset. Valid values:

  • YES: Security risks exist.

  • NO: No security risks exist.

NO

AssetTypeName

string

The name of the asset type.

Workload

AssetSubTypeName

string

The name of the asset subtype.

Pod

SecurityInfo

string

The security information of the asset.

{\"seriousNum\":0,\"appNum\":0,\"baselineMedium\":0,\"remindNum\":0,\"imageVulNntf\":0,\"cveNum\":0,\"vul\":0,\"uuid\":\"rm-uf6t6u05n6g485o70\",\"emgNum\":0,\"weakPWNum\":0,\"imageMaliciousFileRemind\":0,\"imageBaselineMedium\":0,\"laterVulCount\":0,\"cmsNum\":0,\"imageMaliciousFileSerious\":0,\"agentlessMalicious\":0,\"suspNum\":0,\"imageBaselineHigh\":0,\"asapVulCount\":0,\"imageVulLater\":0,\"agentlessAll\":0,\"sysNum\":0,\"containerLater\":0,\"containerSuspicious\":0,\"imageBaselineNum\":0,\"newSuspicious\":0,\"nntfVulCount\":0,\"scaNum\":0,\"containerNntf\":0,\"health\":0,\"trojan\":0,\"suspicious\":0,\"imageMaliciousFileSuspicious\":0,\"containerRemind\":0,\"baselineLow\":0,\"imageVulAsap\":0,\"imageBaselineLow\":0,\"containerAsap\":0,\"agentlessBaseline\":0,\"agentlessVulSca\":0,\"agentlessVulCve\":0,\"containerSerious\":0,\"baselineHigh\":0,\"account\":0,\"baselineNum\":6}

Tags

array

The list of resource tags.

string

The resource tag.

AI

Examples

Success response

JSON format

{
  "Success": true,
  "RequestId": "7532B7EE-7CE7-5F4D-BF04-B12447DDCAE1",
  "PageInfo": {
    "CurrentPage": 1,
    "PageSize": 20,
    "TotalCount": 55,
    "Count": 4
  },
  "Instances": [
    {
      "RegionId": "cn-hanghzou",
      "Vendor": 200,
      "AssetType": 1,
      "AssetSubType": "1",
      "InstanceId": "rm-uf6t6u05n6g48****",
      "InstanceName": "yztest-l***",
      "CreatedTime": 1607365213000,
      "InternetIp": "1.2.XX.XX",
      "AlarmStatus": "NO",
      "RiskStatus": "NO",
      "AssetTypeName": "Workload",
      "AssetSubTypeName": "Pod",
      "SecurityInfo": "{\\\"seriousNum\\\":0,\\\"appNum\\\":0,\\\"baselineMedium\\\":0,\\\"remindNum\\\":0,\\\"imageVulNntf\\\":0,\\\"cveNum\\\":0,\\\"vul\\\":0,\\\"uuid\\\":\\\"rm-uf6t6u05n6g485o70\\\",\\\"emgNum\\\":0,\\\"weakPWNum\\\":0,\\\"imageMaliciousFileRemind\\\":0,\\\"imageBaselineMedium\\\":0,\\\"laterVulCount\\\":0,\\\"cmsNum\\\":0,\\\"imageMaliciousFileSerious\\\":0,\\\"agentlessMalicious\\\":0,\\\"suspNum\\\":0,\\\"imageBaselineHigh\\\":0,\\\"asapVulCount\\\":0,\\\"imageVulLater\\\":0,\\\"agentlessAll\\\":0,\\\"sysNum\\\":0,\\\"containerLater\\\":0,\\\"containerSuspicious\\\":0,\\\"imageBaselineNum\\\":0,\\\"newSuspicious\\\":0,\\\"nntfVulCount\\\":0,\\\"scaNum\\\":0,\\\"containerNntf\\\":0,\\\"health\\\":0,\\\"trojan\\\":0,\\\"suspicious\\\":0,\\\"imageMaliciousFileSuspicious\\\":0,\\\"containerRemind\\\":0,\\\"baselineLow\\\":0,\\\"imageVulAsap\\\":0,\\\"imageBaselineLow\\\":0,\\\"containerAsap\\\":0,\\\"agentlessBaseline\\\":0,\\\"agentlessVulSca\\\":0,\\\"agentlessVulCve\\\":0,\\\"containerSerious\\\":0,\\\"baselineHigh\\\":0,\\\"account\\\":0,\\\"baselineNum\\\":6}",
      "Tags": [
        "AI"
      ]
    }
  ]
}

Error codes

HTTP status code

Error code

Error message

Description

400 AccountIdNotExist AccountId not exist
400 NoPermission no permission
500 ServerError ServerError
403 NoPermission caller has no permission

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.