Obtém os detalhes da regra usada para bloquear imagens em risco.
Experimente agora
Testar
Autorização RAM
|
Ação |
Nível de acesso |
Tipo de recurso |
Chave de condição |
Ação dependente |
|
yundun-sas:GetOpaStrategyDetailNew |
get |
*All Resource
|
Nenhuma | Nenhuma |
Parâmetros da solicitação
|
Parâmetro |
Tipo |
Obrigatório |
Descrição |
Exemplo |
| StrategyId |
integer |
Não |
O ID da regra. Nota
Você pode chamar a operação ListOpaClusterStrategyNew para consultar o ID da regra. |
1349 |
Elementos de resposta
|
Elemento |
Tipo |
Descrição |
Exemplo |
|
object |
PlainResult. |
||
| Data |
object |
Os dados retornados. |
|
| StrategyId |
integer |
O ID da regra. |
1005 |
| StrategyTemplateId |
integer |
O ID do modelo de regra. |
1204 |
| ClusterId |
string |
O ID do cluster. |
c8ca91e0907d94efaba7fb0827eb9**** |
| StrategyName |
string |
O nome da regra. |
test001 |
| Description |
string |
A descrição. |
Custom defense configuration |
| ClusterName |
string |
O nome do cluster. |
test |
| UnScanedImage |
boolean |
Indica se a regra suporta imagens não verificadas. Valores válidos:
|
true |
| MaliciousImage |
boolean |
Indica se a regra suporta imagens maliciosas da Internet. Valores válidos:
|
true |
| ImageName |
array |
Os nomes das imagens. |
|
|
string |
O nome da imagem. |
opa-test |
|
| Label |
array |
As tags das imagens. |
|
|
string |
A tag da imagem. |
app.kubernetes.io/instance:devops |
|
| RuleAction |
integer |
A ação executada quando a regra é acionada. Valores válidos:
|
1 |
| WhiteList |
array |
As tags de imagem adicionadas à whitelist. |
|
|
string |
A tag de imagem adicionada à whitelist. |
test-tag |
|
| AlarmDetail |
object |
A configuração da regra. |
|
| Baseline |
object |
The baseline check configuration. |
|
| RiskLevel |
array |
The risk levels. |
|
|
string |
The risk level. Valid values:
|
low |
|
| Item |
array<object> |
The information about the baseline check item. |
|
|
object |
|||
| Id |
string |
The ID of the baseline check item. |
ak_leak |
| Name |
string |
The name of the baseline check item. |
Access Key plaintext storage |
| Vul |
object |
The vulnerability configuration. |
|
| RiskLevel |
array |
The risk levels. |
|
|
string |
The risk level. Valid values:
|
medium |
|
| Item |
array<object> |
The information about the vulnerability. |
|
|
object |
|||
| Id |
string |
The ID of the vulnerability. |
AVD-2023-1680169 |
| Name |
string |
The name of the vulnerability. |
ezOffice evoInterfaceServlet Info Leak |
| RiskClass |
array<object> |
Risk type of vulnerability. |
|
|
object |
|||
| Id |
string |
The ID of the vulnerability types. Valid values:
|
cve |
| Name |
string |
The name of the vulnerability. Valid values:
|
系统漏洞 |
| MaliciousFile |
object |
The configuration of malicious samples. |
|
| RiskLevel |
array |
The risk levels. |
|
|
string |
The risk level. Valid values:
|
high |
|
| Item |
array<object> |
The information about the malicious sample. |
|
|
object |
|||
| Id |
string |
The ID of the malicious sample. |
1811 |
| Name |
string |
The name of the malicious sample. |
abnormal binary file |
| SensitiveFile |
object |
The configuration of sensitive file. |
|
| RiskLevel |
array |
The risk levels. |
|
|
string |
The risk level. Valid values:
|
low |
|
| Item |
array<object> |
The configuration of sensitive file. |
|
|
object |
|||
| Id |
string |
The ID of the sensitive files. Nota
You can call the GetSensitiveDefineRuleConfig operation to query the ID of the malicious sample. |
key |
| Name |
string |
The name of the sensitive files. Nota
You can call the GetSensitiveDefineRuleConfig operation to query the ID of the malicious sample. |
name |
| BuildRisk |
object |
The configuration of image build risk. |
|
| RiskLevel |
array |
The risk levels. |
|
|
string |
The risk level. Valid values:
|
high |
|
| Item |
array<object> |
The configuration of image build risk. |
|
|
object |
|||
| Id |
string |
The ID of the image build risk. Nota
You can call the ListImageBuildRiskItem operation to query the ID of the malicious sample. |
key |
| Name |
string |
The name of the image build risk. Nota
You can call the ListImageBuildRiskItem operation to query the ID of the malicious sample. |
name |
| Scopes |
array<object> |
O escopo de aplicação. |
|
|
object |
|||
| ClusterId |
string |
The cluster ID. |
c1fdb5fd8d**7163 |
| AllNamespace |
integer |
Indicates whether all namespaces are included. Valid values:
|
1 |
| NamespaceList |
array |
The namespaces. |
|
|
string |
The namespace. |
namespace1 |
|
| AckPolicyInstanceId |
string |
The rule instance ID of the cluster. |
ack-0 |
| Lang |
string |
O idioma do conteúdo na solicitação e resposta. Valor padrão: zh. Valores válidos:
|
zh |
| CurrentPage |
integer |
O número da página. Valor padrão: 1. As páginas começam a partir da página 1. |
4 |
| PageSize |
integer |
O número de entradas por página. |
20 |
| Success |
boolean |
Indica se a solicitação foi bem-sucedida. Valores válidos:
|
true |
| Code |
string |
O código de status retornado. O código de status 200 indica que a solicitação foi bem-sucedida. Outros códigos de status indicam que a solicitação falhou. Você pode identificar a causa da falha com base no código de status. |
200 |
| Message |
string |
A mensagem retornada. |
success |
| RequestId |
string |
O ID da solicitação. |
E819FD71-D240-5E54-AA7F-20FED2ECBEB6 |
| HttpStatusCode |
integer |
O código de status HTTP retornado. |
200 |
Exemplos
Resposta de sucesso
JSON formato
{
"Data": {
"StrategyId": 1005,
"StrategyTemplateId": 1204,
"ClusterId": "c8ca91e0907d94efaba7fb0827eb9****",
"StrategyName": "test001",
"Description": "Custom defense configuration",
"ClusterName": "test",
"UnScanedImage": true,
"MaliciousImage": true,
"ImageName": [
"opa-test"
],
"Label": [
"app.kubernetes.io/instance:devops"
],
"RuleAction": 1,
"WhiteList": [
"test-tag"
],
"AlarmDetail": {
"Baseline": {
"RiskLevel": [
"low"
],
"Item": [
{
"Id": "ak_leak",
"Name": "Access Key plaintext storage"
}
]
},
"Vul": {
"RiskLevel": [
"medium"
],
"Item": [
{
"Id": "AVD-2023-1680169",
"Name": "ezOffice evoInterfaceServlet Info Leak"
}
],
"RiskClass": [
{
"Id": "cve",
"Name": "系统漏洞"
}
]
},
"MaliciousFile": {
"RiskLevel": [
"high"
],
"Item": [
{
"Id": "1811",
"Name": "abnormal binary file\n"
}
]
},
"SensitiveFile": {
"RiskLevel": [
"low"
],
"Item": [
{
"Id": "key",
"Name": "name"
}
]
},
"BuildRisk": {
"RiskLevel": [
"high"
],
"Item": [
{
"Id": "key",
"Name": "name"
}
]
}
},
"Scopes": [
{
"ClusterId": "c1fdb5fd8d**7163",
"AllNamespace": 1,
"NamespaceList": [
"namespace1"
],
"AckPolicyInstanceId": "ack-0"
}
],
"Lang": "zh",
"CurrentPage": 4,
"PageSize": 20
},
"Success": true,
"Code": "200",
"Message": "success",
"RequestId": "E819FD71-D240-5E54-AA7F-20FED2ECBEB6",
"HttpStatusCode": 200
}
Códigos de erro
|
Código de status HTTP |
Código de erro |
Mensagem de erro |
Descrição |
|---|---|---|---|
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission |
Consulte Códigos de Erro para uma lista completa.
Notas de versão
Consulte Notas de Versão para uma lista completa.