Skip to content
Ona Docs

GetSecurityPolicy

client.SecurityPolicies.Get(ctx, body) (*SecurityPolicyGetResponse, error)
POST/gitpod.v1.SecurityService/GetSecurityPolicy

Gets details about a specific security policy.

Use this method to:

  • View security policy configuration
  • Inspect enforcement rules

Examples

  • Get security policy:

    Retrieves a security policy by ID.

    securityPolicyId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
ParametersExpand Collapse
body SecurityPolicyGetParams
SecurityPolicyID param.Field[string]Optional
formatuuid
ReturnsExpand Collapse
type SecurityPolicyGetResponse struct{…}
SecurityPolicy SecurityPolicy
Metadata SecurityPolicyMetadata
Name stringOptional
maxLength80
minLength1
Spec SecurityPolicySpec

Mandate/deploy security agents, e.g. CrowdStrike. Mandate credential security/proxy use. These can be modeled later as explicit fields if needed.

Executables SecurityPolicySpecExecutablesOptional

executables is the public Veto Exec GA policy surface.

DefaultEffect SecurityPolicySpecExecutablesDefaultEffectOptional

default_effect controls executables that do not match a rule. For Veto Exec, omit this field or set it to EFFECT_ALLOW. EFFECT_UNSPECIFIED is normalized to EFFECT_ALLOW.

One of the following:
const SecurityPolicySpecExecutablesDefaultEffectEffectUnspecified SecurityPolicySpecExecutablesDefaultEffect = "EFFECT_UNSPECIFIED"
const SecurityPolicySpecExecutablesDefaultEffectEffectAllow SecurityPolicySpecExecutablesDefaultEffect = "EFFECT_ALLOW"
const SecurityPolicySpecExecutablesDefaultEffectEffectBlock SecurityPolicySpecExecutablesDefaultEffect = "EFFECT_BLOCK"
const SecurityPolicySpecExecutablesDefaultEffectEffectAudit SecurityPolicySpecExecutablesDefaultEffect = "EFFECT_AUDIT"
Rules []SecurityPolicySpecExecutablesRuleOptional

rules contains executable-specific audit or block decisions.

Effect SecurityPolicySpecExecutablesRulesEffectOptional

effect must be EFFECT_AUDIT or EFFECT_BLOCK. EFFECT_ALLOW is not supported on an executable rule.

One of the following:
const SecurityPolicySpecExecutablesRulesEffectEffectUnspecified SecurityPolicySpecExecutablesRulesEffect = "EFFECT_UNSPECIFIED"
const SecurityPolicySpecExecutablesRulesEffectEffectAllow SecurityPolicySpecExecutablesRulesEffect = "EFFECT_ALLOW"
const SecurityPolicySpecExecutablesRulesEffectEffectBlock SecurityPolicySpecExecutablesRulesEffect = "EFFECT_BLOCK"
const SecurityPolicySpecExecutablesRulesEffectEffectAudit SecurityPolicySpecExecutablesRulesEffect = "EFFECT_AUDIT"
Path stringOptional

path is either an absolute executable path, such as /usr/bin/curl, or a bare executable name, such as npx. Bare names are expanded by runtime discovery. Surrounding whitespace is ignored. Empty or whitespace-only selectors and relative paths with directory separators are invalid. Enforcement uses executable content hashes, so different paths with identical content share one runtime decision and block wins conflicts.

ID stringOptional
formatuuid
CreatedAt TimeOptional

A Timestamp represents a point in time independent of any time zone or local calendar, encoded as a count of seconds and fractions of seconds at nanosecond resolution. The count is relative to an epoch at UTC midnight on January 1, 1970, in the proleptic Gregorian calendar which extends the Gregorian calendar backwards to year one.

All minutes are 60 seconds long. Leap seconds are “smeared” so that no leap second table is needed for interpretation, using a 24-hour linear smear.

The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By restricting to that range, we ensure that we can convert to and from RFC 3339 date strings.

Examples

Example 1: Compute Timestamp from POSIX time().

 Timestamp timestamp;
 timestamp.set_seconds(time(NULL));
 timestamp.set_nanos(0);

Example 2: Compute Timestamp from POSIX gettimeofday().

 struct timeval tv;
 gettimeofday(&tv, NULL);

 Timestamp timestamp;
 timestamp.set_seconds(tv.tv_sec);
 timestamp.set_nanos(tv.tv_usec * 1000);

Example 3: Compute Timestamp from Win32 GetSystemTimeAsFileTime().

 FILETIME ft;
 GetSystemTimeAsFileTime(&ft);
 UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

 // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
 // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
 Timestamp timestamp;
 timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
 timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

Example 4: Compute Timestamp from Java System.currentTimeMillis().

 long millis = System.currentTimeMillis();

 Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
     .setNanos((int) ((millis % 1000) * 1000000)).build();

Example 5: Compute Timestamp from Java Instant.now().

 Instant now = Instant.now();

 Timestamp timestamp =
     Timestamp.newBuilder().setSeconds(now.getEpochSecond())
         .setNanos(now.getNano()).build();

Example 6: Compute Timestamp from current time in Python.

 timestamp = Timestamp()
 timestamp.GetCurrentTime()

JSON Mapping

In JSON format, the Timestamp type is encoded as a string in the RFC 3339 format. That is, the format is “{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z” where {year} is always expressed using four digits while {month}, {day}, {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), are optional. The “Z” suffix indicates the timezone (“UTC”); the timezone is required. A proto3 JSON serializer should always use UTC (as indicated by “Z”) when printing the Timestamp type and a proto3 JSON parser should be able to accept both UTC and other timezones (as indicated by an offset).

For example, “2017-01-15T01:30:15.01Z” encodes 15.01 seconds past 01:30 UTC on January 15, 2017.

In JavaScript, one can convert a Date object to this format using the standard toISOString() method. In Python, a standard datetime.datetime object can be converted to this format using strftime with the time format spec ‘%Y-%m-%dT%H:%M:%S.%fZ’. Likewise, in Java, one can use the Joda Time’s ISODateTimeFormat.dateTime() to obtain a formatter capable of generating timestamps in this format.

formatdate-time
OrganizationID stringOptional
formatuuid
UpdatedAt TimeOptional

A Timestamp represents a point in time independent of any time zone or local calendar, encoded as a count of seconds and fractions of seconds at nanosecond resolution. The count is relative to an epoch at UTC midnight on January 1, 1970, in the proleptic Gregorian calendar which extends the Gregorian calendar backwards to year one.

All minutes are 60 seconds long. Leap seconds are “smeared” so that no leap second table is needed for interpretation, using a 24-hour linear smear.

The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By restricting to that range, we ensure that we can convert to and from RFC 3339 date strings.

Examples

Example 1: Compute Timestamp from POSIX time().

 Timestamp timestamp;
 timestamp.set_seconds(time(NULL));
 timestamp.set_nanos(0);

Example 2: Compute Timestamp from POSIX gettimeofday().

 struct timeval tv;
 gettimeofday(&tv, NULL);

 Timestamp timestamp;
 timestamp.set_seconds(tv.tv_sec);
 timestamp.set_nanos(tv.tv_usec * 1000);

Example 3: Compute Timestamp from Win32 GetSystemTimeAsFileTime().

 FILETIME ft;
 GetSystemTimeAsFileTime(&ft);
 UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

 // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
 // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
 Timestamp timestamp;
 timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
 timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

Example 4: Compute Timestamp from Java System.currentTimeMillis().

 long millis = System.currentTimeMillis();

 Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
     .setNanos((int) ((millis % 1000) * 1000000)).build();

Example 5: Compute Timestamp from Java Instant.now().

 Instant now = Instant.now();

 Timestamp timestamp =
     Timestamp.newBuilder().setSeconds(now.getEpochSecond())
         .setNanos(now.getNano()).build();

Example 6: Compute Timestamp from current time in Python.

 timestamp = Timestamp()
 timestamp.GetCurrentTime()

JSON Mapping

In JSON format, the Timestamp type is encoded as a string in the RFC 3339 format. That is, the format is “{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z” where {year} is always expressed using four digits while {month}, {day}, {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), are optional. The “Z” suffix indicates the timezone (“UTC”); the timezone is required. A proto3 JSON serializer should always use UTC (as indicated by “Z”) when printing the Timestamp type and a proto3 JSON parser should be able to accept both UTC and other timezones (as indicated by an offset).

For example, “2017-01-15T01:30:15.01Z” encodes 15.01 seconds past 01:30 UTC on January 15, 2017.

In JavaScript, one can convert a Date object to this format using the standard toISOString() method. In Python, a standard datetime.datetime object can be converted to this format using strftime with the time format spec ‘%Y-%m-%dT%H:%M:%S.%fZ’. Likewise, in Java, one can use the Joda Time’s ISODateTimeFormat.dateTime() to obtain a formatter capable of generating timestamps in this format.

formatdate-time

GetSecurityPolicy

package main

import (
  "context"
  "fmt"

  "github.com/gitpod-io/gitpod-sdk-go"
  "github.com/gitpod-io/gitpod-sdk-go/option"
)

func main() {
  client := gitpod.NewClient(
    option.WithBearerToken("My Bearer Token"),
  )
  securityPolicy, err := client.SecurityPolicies.Get(context.TODO(), gitpod.SecurityPolicyGetParams{
    SecurityPolicyID: gitpod.F("d2c94c27-3b76-4a42-b88c-95a85e392c68"),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", securityPolicy.SecurityPolicy)
}
{
  "securityPolicy": {
    "metadata": {
      "name": "x"
    },
    "spec": {
      "blockDevices": {
        "defaultEffect": "EFFECT_UNSPECIFIED"
      },
      "data": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "destination": {
              "host": "host"
            },
            "effect": "EFFECT_UNSPECIFIED",
            "source": {
              "file": "file",
              "integration": "integration",
              "selector": "selector"
            }
          }
        ]
      },
      "executables": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "files": {
        "defaultActions": [
          "ACTION_UNSPECIFIED"
        ],
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "actions": [
              "ACTION_UNSPECIFIED"
            ],
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "ports": {
        "maxAdmissionLevel": "ADMISSION_LEVEL_UNSPECIFIED"
      }
    },
    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "createdAt": "2019-12-27T18:11:19.117Z",
    "organizationId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "updatedAt": "2019-12-27T18:11:19.117Z"
  }
}
Returns Examples
{
  "securityPolicy": {
    "metadata": {
      "name": "x"
    },
    "spec": {
      "blockDevices": {
        "defaultEffect": "EFFECT_UNSPECIFIED"
      },
      "data": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "destination": {
              "host": "host"
            },
            "effect": "EFFECT_UNSPECIFIED",
            "source": {
              "file": "file",
              "integration": "integration",
              "selector": "selector"
            }
          }
        ]
      },
      "executables": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "files": {
        "defaultActions": [
          "ACTION_UNSPECIFIED"
        ],
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "actions": [
              "ACTION_UNSPECIFIED"
            ],
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "ports": {
        "maxAdmissionLevel": "ADMISSION_LEVEL_UNSPECIFIED"
      }
    },
    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "createdAt": "2019-12-27T18:11:19.117Z",
    "organizationId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "updatedAt": "2019-12-27T18:11:19.117Z"
  }
}