Skip to content
Ona Docs

GetSecurityPolicy

client.securityPolicies.retrieve(SecurityPolicyRetrieveParams { securityPolicyId } body, RequestOptionsoptions?): SecurityPolicyRetrieveResponse { securityPolicy }
POST/gitpod.v1.SecurityService/GetSecurityPolicy

Gets details about a specific security policy.

Use this method to:

  • View security policy configuration
  • Inspect enforcement rules

Examples

  • Get security policy:

    Retrieves a security policy by ID.

    securityPolicyId: "d2c94c27-3b76-4a42-b88c-95a85e392c68"
ParametersExpand Collapse
body: SecurityPolicyRetrieveParams { securityPolicyId }
securityPolicyId?: string
formatuuid
ReturnsExpand Collapse
SecurityPolicyRetrieveResponse { securityPolicy }
securityPolicy: SecurityPolicy { metadata, spec, id, 3 more }
metadata: Metadata { name }
name?: string
maxLength80
minLength1
spec: Spec { executables }

Mandate/deploy security agents, e.g. CrowdStrike. Mandate credential security/proxy use. These can be modeled later as explicit fields if needed.

executables?: Executables { defaultEffect, rules }

executables is the public Veto Exec GA policy surface.

defaultEffect?: "EFFECT_UNSPECIFIED" | "EFFECT_ALLOW" | "EFFECT_BLOCK" | "EFFECT_AUDIT"

default_effect controls executables that do not match a rule. For Veto Exec, omit this field or set it to EFFECT_ALLOW. EFFECT_UNSPECIFIED is normalized to EFFECT_ALLOW.

One of the following:
"EFFECT_UNSPECIFIED"
"EFFECT_ALLOW"
"EFFECT_BLOCK"
"EFFECT_AUDIT"
rules?: Array<Rule>

rules contains executable-specific audit or block decisions.

effect?: "EFFECT_UNSPECIFIED" | "EFFECT_ALLOW" | "EFFECT_BLOCK" | "EFFECT_AUDIT"

effect must be EFFECT_AUDIT or EFFECT_BLOCK. EFFECT_ALLOW is not supported on an executable rule.

One of the following:
"EFFECT_UNSPECIFIED"
"EFFECT_ALLOW"
"EFFECT_BLOCK"
"EFFECT_AUDIT"
path?: string

path is either an absolute executable path, such as /usr/bin/curl, or a bare executable name, such as npx. Bare names are expanded by runtime discovery. Surrounding whitespace is ignored. Empty or whitespace-only selectors and relative paths with directory separators are invalid. Enforcement uses executable content hashes, so different paths with identical content share one runtime decision and block wins conflicts.

id?: string
formatuuid
createdAt?: string

A Timestamp represents a point in time independent of any time zone or local calendar, encoded as a count of seconds and fractions of seconds at nanosecond resolution. The count is relative to an epoch at UTC midnight on January 1, 1970, in the proleptic Gregorian calendar which extends the Gregorian calendar backwards to year one.

All minutes are 60 seconds long. Leap seconds are “smeared” so that no leap second table is needed for interpretation, using a 24-hour linear smear.

The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By restricting to that range, we ensure that we can convert to and from RFC 3339 date strings.

Examples

Example 1: Compute Timestamp from POSIX time().

 Timestamp timestamp;
 timestamp.set_seconds(time(NULL));
 timestamp.set_nanos(0);

Example 2: Compute Timestamp from POSIX gettimeofday().

 struct timeval tv;
 gettimeofday(&tv, NULL);

 Timestamp timestamp;
 timestamp.set_seconds(tv.tv_sec);
 timestamp.set_nanos(tv.tv_usec * 1000);

Example 3: Compute Timestamp from Win32 GetSystemTimeAsFileTime().

 FILETIME ft;
 GetSystemTimeAsFileTime(&ft);
 UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

 // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
 // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
 Timestamp timestamp;
 timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
 timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

Example 4: Compute Timestamp from Java System.currentTimeMillis().

 long millis = System.currentTimeMillis();

 Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
     .setNanos((int) ((millis % 1000) * 1000000)).build();

Example 5: Compute Timestamp from Java Instant.now().

 Instant now = Instant.now();

 Timestamp timestamp =
     Timestamp.newBuilder().setSeconds(now.getEpochSecond())
         .setNanos(now.getNano()).build();

Example 6: Compute Timestamp from current time in Python.

 timestamp = Timestamp()
 timestamp.GetCurrentTime()

JSON Mapping

In JSON format, the Timestamp type is encoded as a string in the RFC 3339 format. That is, the format is “{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z” where {year} is always expressed using four digits while {month}, {day}, {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), are optional. The “Z” suffix indicates the timezone (“UTC”); the timezone is required. A proto3 JSON serializer should always use UTC (as indicated by “Z”) when printing the Timestamp type and a proto3 JSON parser should be able to accept both UTC and other timezones (as indicated by an offset).

For example, “2017-01-15T01:30:15.01Z” encodes 15.01 seconds past 01:30 UTC on January 15, 2017.

In JavaScript, one can convert a Date object to this format using the standard toISOString() method. In Python, a standard datetime.datetime object can be converted to this format using strftime with the time format spec ‘%Y-%m-%dT%H:%M:%S.%fZ’. Likewise, in Java, one can use the Joda Time’s ISODateTimeFormat.dateTime() to obtain a formatter capable of generating timestamps in this format.

formatdate-time
organizationId?: string
formatuuid
updatedAt?: string

A Timestamp represents a point in time independent of any time zone or local calendar, encoded as a count of seconds and fractions of seconds at nanosecond resolution. The count is relative to an epoch at UTC midnight on January 1, 1970, in the proleptic Gregorian calendar which extends the Gregorian calendar backwards to year one.

All minutes are 60 seconds long. Leap seconds are “smeared” so that no leap second table is needed for interpretation, using a 24-hour linear smear.

The range is from 0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z. By restricting to that range, we ensure that we can convert to and from RFC 3339 date strings.

Examples

Example 1: Compute Timestamp from POSIX time().

 Timestamp timestamp;
 timestamp.set_seconds(time(NULL));
 timestamp.set_nanos(0);

Example 2: Compute Timestamp from POSIX gettimeofday().

 struct timeval tv;
 gettimeofday(&tv, NULL);

 Timestamp timestamp;
 timestamp.set_seconds(tv.tv_sec);
 timestamp.set_nanos(tv.tv_usec * 1000);

Example 3: Compute Timestamp from Win32 GetSystemTimeAsFileTime().

 FILETIME ft;
 GetSystemTimeAsFileTime(&ft);
 UINT64 ticks = (((UINT64)ft.dwHighDateTime) << 32) | ft.dwLowDateTime;

 // A Windows tick is 100 nanoseconds. Windows epoch 1601-01-01T00:00:00Z
 // is 11644473600 seconds before Unix epoch 1970-01-01T00:00:00Z.
 Timestamp timestamp;
 timestamp.set_seconds((INT64) ((ticks / 10000000) - 11644473600LL));
 timestamp.set_nanos((INT32) ((ticks % 10000000) * 100));

Example 4: Compute Timestamp from Java System.currentTimeMillis().

 long millis = System.currentTimeMillis();

 Timestamp timestamp = Timestamp.newBuilder().setSeconds(millis / 1000)
     .setNanos((int) ((millis % 1000) * 1000000)).build();

Example 5: Compute Timestamp from Java Instant.now().

 Instant now = Instant.now();

 Timestamp timestamp =
     Timestamp.newBuilder().setSeconds(now.getEpochSecond())
         .setNanos(now.getNano()).build();

Example 6: Compute Timestamp from current time in Python.

 timestamp = Timestamp()
 timestamp.GetCurrentTime()

JSON Mapping

In JSON format, the Timestamp type is encoded as a string in the RFC 3339 format. That is, the format is “{year}-{month}-{day}T{hour}:{min}:{sec}[.{frac_sec}]Z” where {year} is always expressed using four digits while {month}, {day}, {hour}, {min}, and {sec} are zero-padded to two digits each. The fractional seconds, which can go up to 9 digits (i.e. up to 1 nanosecond resolution), are optional. The “Z” suffix indicates the timezone (“UTC”); the timezone is required. A proto3 JSON serializer should always use UTC (as indicated by “Z”) when printing the Timestamp type and a proto3 JSON parser should be able to accept both UTC and other timezones (as indicated by an offset).

For example, “2017-01-15T01:30:15.01Z” encodes 15.01 seconds past 01:30 UTC on January 15, 2017.

In JavaScript, one can convert a Date object to this format using the standard toISOString() method. In Python, a standard datetime.datetime object can be converted to this format using strftime with the time format spec ‘%Y-%m-%dT%H:%M:%S.%fZ’. Likewise, in Java, one can use the Joda Time’s ISODateTimeFormat.dateTime() to obtain a formatter capable of generating timestamps in this format.

formatdate-time

GetSecurityPolicy

import Gitpod from '@gitpod/sdk';

const client = new Gitpod({
  bearerToken: process.env['GITPOD_API_KEY'], // This is the default and can be omitted
});

const securityPolicy = await client.securityPolicies.retrieve({
  securityPolicyId: 'd2c94c27-3b76-4a42-b88c-95a85e392c68',
});

console.log(securityPolicy.securityPolicy);
{
  "securityPolicy": {
    "metadata": {
      "name": "x"
    },
    "spec": {
      "blockDevices": {
        "defaultEffect": "EFFECT_UNSPECIFIED"
      },
      "data": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "destination": {
              "host": "host"
            },
            "effect": "EFFECT_UNSPECIFIED",
            "source": {
              "file": "file",
              "integration": "integration",
              "selector": "selector"
            }
          }
        ]
      },
      "executables": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "files": {
        "defaultActions": [
          "ACTION_UNSPECIFIED"
        ],
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "actions": [
              "ACTION_UNSPECIFIED"
            ],
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "ports": {
        "maxAdmissionLevel": "ADMISSION_LEVEL_UNSPECIFIED"
      }
    },
    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "createdAt": "2019-12-27T18:11:19.117Z",
    "organizationId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "updatedAt": "2019-12-27T18:11:19.117Z"
  }
}
Returns Examples
{
  "securityPolicy": {
    "metadata": {
      "name": "x"
    },
    "spec": {
      "blockDevices": {
        "defaultEffect": "EFFECT_UNSPECIFIED"
      },
      "data": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "destination": {
              "host": "host"
            },
            "effect": "EFFECT_UNSPECIFIED",
            "source": {
              "file": "file",
              "integration": "integration",
              "selector": "selector"
            }
          }
        ]
      },
      "executables": {
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "files": {
        "defaultActions": [
          "ACTION_UNSPECIFIED"
        ],
        "defaultEffect": "EFFECT_UNSPECIFIED",
        "rules": [
          {
            "actions": [
              "ACTION_UNSPECIFIED"
            ],
            "effect": "EFFECT_UNSPECIFIED",
            "path": "path"
          }
        ]
      },
      "ports": {
        "maxAdmissionLevel": "ADMISSION_LEVEL_UNSPECIFIED"
      }
    },
    "id": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "createdAt": "2019-12-27T18:11:19.117Z",
    "organizationId": "182bd5e5-6e1a-4fe4-a799-aa6d9a6ab26e",
    "updatedAt": "2019-12-27T18:11:19.117Z"
  }
}