Compliance Standards

Policies API v1 endpoints for compliance standards, enablement, and custom standards.

List the compliance standards available to your tenant, enable or disable them for clusters, trigger rescans, and manage custom standards that map Kyverno policies to your own controls.

All paths are relative to /policies/api/v1. See Policies API v1 for authentication and conventions.

Endpoints

OperationMethodPath
List custom compliance standardsGET/compliance/kyverno/custom-mappings
Create a custom compliance standardPOST/compliance/kyverno/custom-mappings
List compliance standardsGET/compliance/kyverno/standards
Download an example custom standardGET/compliance/kyverno/custom-mappings/example
Download the custom standard JSON SchemaGET/compliance/kyverno/custom-mappings/schema
Get a custom compliance standardGET/compliance/kyverno/custom-mappings/{standardKey}
Update a custom compliance standardPUT/compliance/kyverno/custom-mappings/{standardKey}
Delete a custom compliance standardDELETE/compliance/kyverno/custom-mappings/{standardKey}
List enabled compliance standardsGET/compliance/kyverno/standards/enabled
Rescan all enabled standardsPOST/compliance/kyverno/standards/rescan
Get a standard’s control catalogGET/compliance/kyverno/standards/{standard}/controls
Enable a standard for targetsPUT/compliance/kyverno/standards/{standard}/enablement
Update standard enablement flagsPATCH/compliance/kyverno/standards/{standard}/enablement
Disable a compliance standardDELETE/compliance/kyverno/standards/{standard}/enablement
Get a standard’s policy-to-control mappingGET/compliance/kyverno/standards/{standard}/mappings
Rescan one compliance standardPOST/compliance/kyverno/standards/{standard}/rescan

Reference

List custom compliance standards

GET /policies/api/v1/compliance/kyverno/custom-mappings

Lists the custom compliance standards uploaded by this tenant.

Roles: admin, platform, security, devops

Response 200 (application/json)

Array of custom standard summaries (not paginated)

FieldTypeDescription
standardKeystringUnique key of the custom standard
displayNamestring—
policyCountintegerNumber of mapped policies
controlCountintegerDistinct controls mapped
adminStatestring—
createdBystring—
createdAtstring (date-time)—
updatedAtstring (date-time)—

Errors

  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Create a custom compliance standard

POST /policies/api/v1/compliance/kyverno/custom-mappings

Uploads a YAML definition of a new custom standard. It is validated against the schema and then scanned, scored and reported exactly like a built-in standard. Non-blocking issues (e.g. policy names not yet managed in Nirmata) are returned in a warnings array.

Roles: admin, security

Request body (text/yaml (also application/x-yaml, text/plain))

FieldTypeRequiredDescription
standardKeystringYesLowercase letters, digits, hyphens; must not match a built-in standard
displayNamestringYes—
preferVpolbooleanNoInformational
sourcesobject[]No{id, title, ref, effective}
policiesobjectYesMap of Kyverno policy name to {clusterScoped, controls[]}; unknown policy names produce warnings, not errors
non-automatableobject[]No{id, family, reason} controls reported as not automatable

Response 201 (application/json)

Custom standard detail plus optional warnings: string[]

FieldTypeDescription
standardKeystringUnique key of the custom standard
displayNamestring—
policyCountintegerNumber of mapped policies
controlCountintegerDistinct controls mapped
adminStatestring—
createdBystring—
createdAtstring (date-time)—
updatedAtstring (date-time)—
preferVpolboolean—
sourcesobject[]{id, title, ref, effective}
policiesobjectMap of policy name to {clusterScoped, controls}
nonAutomatableobject[]{id, family, reason}
rawYamlstringThe uploaded YAML
contentSha256string—
warningsstring[]Present only when there are warnings

Errors

  • 400 — YAML fails validation (code VALIDATION_FAILED)
  • 409 — standardKey already exists for this tenant or collides with a built-in standard (code CONFLICT)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Example

curl -X POST -H 'Content-Type: text/yaml' --data-binary @custom-acme-baseline.yaml .../compliance/kyverno/custom-mappings

List compliance standards

GET /policies/api/v1/compliance/kyverno/standards

Lists every compliance standard available to the tenant: built-in standards plus the tenant’s custom standards. Does not require any reports to exist.

Roles: admin, platform, security, devops

Response 200 (application/json)

Array of ComplianceStandardDto

FieldTypeDescription
standardstringStandard key
standardDisplayNamestring—
custombooleanTrue for tenant-uploaded standards
typestringbuilt-in | industry | custom
domainstring[]Topical tags, e.g. kubernetes, identity-rbac, supply-chain

Errors

  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Download an example custom standard

GET /policies/api/v1/compliance/kyverno/custom-mappings/example

Returns a fully commented, schema-valid example custom standard YAML (custom-mapping.example.yaml) that can be edited and uploaded.

Roles: admin, platform, security, devops

Response 200 (text/yaml)

YAML document (attachment)

Errors

  • 500 — Example resource unavailable
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Download the custom standard JSON Schema

GET /policies/api/v1/compliance/kyverno/custom-mappings/schema

Returns the JSON Schema describing the YAML body accepted when creating or updating a custom compliance standard, as an attachment (custom-mapping.schema.json).

Roles: admin, platform, security, devops

Response 200 (application/json)

JSON Schema document (attachment)

Errors

  • 500 — Schema resource unavailable
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Get a custom compliance standard

GET /policies/api/v1/compliance/kyverno/custom-mappings/{standardKey}

Returns one custom standard including its policy-to-control mapping and the raw uploaded YAML.

Roles: admin, platform, security, devops

Path parameters

NameTypeDescription
standardKeystringCustom standard key

Response 200 (application/json)

Custom standard detail

FieldTypeDescription
standardKeystringUnique key of the custom standard
displayNamestring—
policyCountintegerNumber of mapped policies
controlCountintegerDistinct controls mapped
adminStatestring—
createdBystring—
createdAtstring (date-time)—
updatedAtstring (date-time)—
preferVpolboolean—
sourcesobject[]{id, title, ref, effective}
policiesobjectMap of policy name to {clusterScoped, controls}
nonAutomatableobject[]{id, family, reason}
rawYamlstringThe uploaded YAML
contentSha256string—

Errors

  • 404 — No such custom standard (code NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Update a custom compliance standard

PUT /policies/api/v1/compliance/kyverno/custom-mappings/{standardKey}

Replaces an existing custom standard with a new YAML definition. The YAML’s standardKey must match the path.

Roles: admin, security

Path parameters

NameTypeDescription
standardKeystringCustom standard key

Request body (text/yaml (also application/x-yaml, text/plain))

FieldTypeRequiredDescription
standardKeystringYesLowercase letters, digits, hyphens; must not match a built-in standard
displayNamestringYes—
preferVpolbooleanNoInformational
sourcesobject[]No{id, title, ref, effective}
policiesobjectYesMap of Kyverno policy name to {clusterScoped, controls[]}; unknown policy names produce warnings, not errors
non-automatableobject[]No{id, family, reason} controls reported as not automatable

Response 200 (application/json)

Custom standard detail plus optional warnings

FieldTypeDescription
standardKeystringUnique key of the custom standard
displayNamestring—
policyCountintegerNumber of mapped policies
controlCountintegerDistinct controls mapped
adminStatestring—
createdBystring—
createdAtstring (date-time)—
updatedAtstring (date-time)—
preferVpolboolean—
sourcesobject[]{id, title, ref, effective}
policiesobjectMap of policy name to {clusterScoped, controls}
nonAutomatableobject[]{id, family, reason}
rawYamlstringThe uploaded YAML
contentSha256string—
warningsstring[]Present only when there are warnings

Errors

  • 400 — YAML fails validation or standardKey mismatch (code VALIDATION_FAILED)
  • 409 — No custom standard with that key exists to update (code CONFLICT)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Delete a custom compliance standard

DELETE /policies/api/v1/compliance/kyverno/custom-mappings/{standardKey}

Deletes a custom standard and its standard-level enablement and target settings. Built-in standards cannot be deleted.

Roles: admin, security

Path parameters

NameTypeDescription
standardKeystringCustom standard key

Response 204

No content

Errors

  • 404 — No such custom standard, or key is a built-in standard (code NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

List enabled compliance standards

GET /policies/api/v1/compliance/kyverno/standards/enabled

Lists every standard enabled for the tenant with its effective targets. Targets that no longer exist in inventory are omitted.

Roles: admin, security

Response 200 (application/json)

Array of ComplianceStandardEnablementDto

FieldTypeDescription
standardstring—
standardDisplayNamestring—
customboolean—
typestringbuilt-in | industry | custom
domainstring[]—
enabledbooleanCan be false in PATCH responses
applyToAllTargetsbooleanApplies to every target of targetTypes
targetTypesstring[]cluster | repository
historyEnabledbooleanTrend history tracking enabled
targetsobject[]Effective live targets {targetId, targetName, targetType}

Errors

  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Rescan all enabled standards

POST /policies/api/v1/compliance/kyverno/standards/rescan

Starts on-demand scans for every enabled standard and target pair, optionally limited to some standards. Pairs that cannot start (scan already running or capacity reached) are listed in skipped; the request still returns 200.

Roles: admin, security

Request body (application/json)

FieldTypeRequiredDescription
standardsstring[]NoLimit to these standards; omitted/empty = all enabled

Response 200 (application/json)

ComplianceRescanResponseDto

FieldTypeDescription
reportIdsobjectMap standard -> targetId -> new report ID
skippedobject[]{standard, targetId, code: SCAN_IN_PROGRESS | SCAN_CAPACITY_EXCEEDED}
triggeredAtstring (date-time)—

Errors

  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Get a standard’s control catalog

GET /policies/api/v1/compliance/kyverno/standards/{standard}/controls

Returns every control referenced by a standard with its name, description, whether it can be checked automatically, and the Kyverno policies mapped to it. Responses carry an ETag and Cache-Control (private, max-age=300); send If-None-Match to receive 304 when unchanged.

Roles: admin, platform, security, devops

Path parameters

NameTypeDescription
standardstringStandard key

Headers

NameRequiredDescription
If-None-MatchNoETag from a previous response; 304 if unchanged

Response 200 (application/json)

{standard, displayName, version, controls[]}

FieldTypeDescription
standardstring—
displayNamestring—
versionstringContent hash; also the ETag
controlsobject[]{id, name, description, automatable, family, reason, policies[]} in natural control-ID order

Errors

  • 304 — Not modified (If-None-Match matched)
  • 404 — Unknown standard (code STANDARD_NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Enable a standard for targets

PUT /policies/api/v1/compliance/kyverno/standards/{standard}/enablement

Enables a standard and replaces its target set, either an explicit list of clusters/repositories or all targets of the given types. Previously stored targets that no longer exist are dropped silently; a newly added unknown target is rejected.

Roles: admin, security

Path parameters

NameTypeDescription
standardstringStandard key

Request body (application/json)

FieldTypeRequiredDescription
applyToAllTargetsbooleanNoApply to every target of targetTypes
targetTypesstring[]NoRequired non-empty when applyToAllTargets; values cluster | repository
targetsobject[]No{targetId (uuid), targetType: cluster|repository, targetName (ignored; server resolves)}; required unless applyToAllTargets

Response 200 (application/json)

ComplianceStandardEnablementDto

FieldTypeDescription
standardstring—
standardDisplayNamestring—
customboolean—
typestringbuilt-in | industry | custom
domainstring[]—
enabledbooleanCan be false in PATCH responses
applyToAllTargetsbooleanApplies to every target of targetTypes
targetTypesstring[]cluster | repository
historyEnabledbooleanTrend history tracking enabled
targetsobject[]Effective live targets {targetId, targetName, targetType}

Errors

  • 400 — REQUEST_BODY_REQUIRED, UNKNOWN_STANDARD, TARGETS_REQUIRED, TARGET_TYPES_REQUIRED, UNSUPPORTED_TARGET_TYPE, INVALID_TARGET_ID, or UNKNOWN_TARGET
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Example

{"applyToAllTargets":false,"targets":[{"targetId":"3f1c...","targetType":"cluster"}]}

Update standard enablement flags

PATCH /policies/api/v1/compliance/kyverno/standards/{standard}/enablement

Toggles enabled and/or historyEnabled for a standard without changing its target set. Omitted (null) fields are left unchanged. Re-enabling restores the previous targets.

Roles: admin, security

Path parameters

NameTypeDescription
standardstringStandard key

Request body (application/json)

FieldTypeRequiredDescription
enabledbooleanNoEnable/disable
historyEnabledbooleanNoEnable/disable history tracking

Response 200 (application/json)

ComplianceStandardEnablementDto

FieldTypeDescription
standardstring—
standardDisplayNamestring—
customboolean—
typestringbuilt-in | industry | custom
domainstring[]—
enabledbooleanCan be false in PATCH responses
applyToAllTargetsbooleanApplies to every target of targetTypes
targetTypesstring[]cluster | repository
historyEnabledbooleanTrend history tracking enabled
targetsobject[]Effective live targets {targetId, targetName, targetType}

Errors

  • 400 — Body missing (REQUEST_BODY_REQUIRED)
  • 404 — Standard has never been configured (code NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Disable a compliance standard

DELETE /policies/api/v1/compliance/kyverno/standards/{standard}/enablement

Disables a standard for the tenant. Its target set is preserved, so re-enabling restores the same targets.

Roles: admin, security

Path parameters

NameTypeDescription
standardstringStandard key

Response 204

No content

Errors

  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Get a standard’s policy-to-control mapping

GET /policies/api/v1/compliance/kyverno/standards/{standard}/mappings

Returns the full policy-to-control mapping of a built-in or custom standard as JSON. With format=yaml, downloads it as a custom-standard YAML file ready to edit and upload; a built-in standard’s key is rewritten to custom-.

Roles: admin, platform, security, devops

Path parameters

NameTypeDescription
standardstringStandard key

Query parameters

NameTypeRequiredDefaultDescription
formatstringNojsonjson or yaml

Response 200 (application/json (or text/yaml attachment when format=yaml))

ComplianceStandardMappingDto

FieldTypeDescription
standardstring—
displayNamestring—
typestringbuilt-in | industry | custom
customboolean—
preferVpolboolean—
sourcesobject[]{id, title, ref, effective}
policiesobject[]{name, clusterScoped, path, controls[]} sorted by name
nonAutomatableobject[]{id, family, reason}

Errors

  • 400 — format is not json or yaml (code INVALID_FORMAT)
  • 404 — Unknown standard (code STANDARD_NOT_FOUND)
  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles

Rescan one compliance standard

POST /policies/api/v1/compliance/kyverno/standards/{standard}/rescan

Starts on-demand scans for every target the standard is currently enabled for. Skipped pairs are listed; returns 200 with empty results if the standard is not enabled.

Roles: admin, security

Path parameters

NameTypeDescription
standardstringStandard key

Response 200 (application/json)

ComplianceRescanResponseDto

FieldTypeDescription
reportIdsobjectMap standard -> targetId -> new report ID
skippedobject[]{standard, targetId, code: SCAN_IN_PROGRESS | SCAN_CAPACITY_EXCEEDED}
triggeredAtstring (date-time)—

Errors

  • 401 — Not authenticated
  • 403 — Caller’s role is not in the allowed roles