Policy Exceptions

Policies API v1 endpoints for reading Kyverno policy exceptions.

Read the Kyverno policy exceptions that Nirmata Control Hub tracks across your clusters, and the resources each exception covers.

All paths are relative to /policies/api/v1. See Policies API v1 for authentication and conventions.

Endpoints

OperationMethodPath
List policy exceptionsGET/policy-exceptions
Count policy exceptionsGET/policy-exceptions/count
Find policy exceptions for a policy on a clusterGET/policy-exceptions/search
Get policy exception summaryGET/policy-exceptions/summary
Get a policy exceptionGET/policy-exceptions/{id}
List policy exceptions for a clusterGET/policy-exceptions/by-cluster/{clusterId}
List policy exceptions by kindGET/policy-exceptions/by-kind/{kind}
List policy exceptions in a namespaceGET/policy-exceptions/by-namespace/{namespace}
List resources excepted by a policy exceptionGET/policy-exceptions/{id}/excepted-resources

Reference

List policy exceptions

GET /policies/api/v1/policy-exceptions

Returns all Kyverno policy exceptions in the tenant, paginated in memory with limit/offset.

Roles: admin

Query parameters

NameTypeRequiredDefaultDescription
limitintegerNo50Maximum items to return
offsetintegerNo0Number of items to skip

Response 200 (application/json)

Paginated: {items: PolicyException[], total, limit, offset}

FieldTypeDescription
idstringPolicy exception ID
apiVersionstringKyverno API version of the PolicyException resource
kindstringResource kind (e.g. PolicyException)
namestringPolicy exception name
namespacestringKubernetes namespace of the exception
uidstringKubernetes UID
resourceVersionstringKubernetes resource version
clusterRefobjectReference to the cluster: {service, modelIndex, id}
exceptionsarray<object>Excepted policies/rules: {policyName, ruleNames, namespace, policyUID, kind, policyRef}
exceptedResourcesarray<object>Resources currently excepted: {apiVersion, kind, name, namespace, fieldPath, resourceVersion, uid, resourceRef}
yamlstringFull YAML of the PolicyException resource
requestDetailsstringJSON-encoded string with details of the originating exception request, if any

Errors

  • 500 — Failed to retrieve policy exceptions
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

Count policy exceptions

GET /policies/api/v1/policy-exceptions/count

Returns the total number of policy exceptions in the tenant.

Roles: admin

Response 200 (application/json)

{count: integer}

FieldTypeDescription
countintegerNumber of policy exceptions

Errors

  • 500 — Failed to count policy exceptions
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

Find policy exceptions for a policy on a cluster

GET /policies/api/v1/policy-exceptions/search

Returns lightweight records of policy exceptions on a cluster that except the named policy, optionally restricted to a namespace.

Roles: Any role with permission for this resource. See Roles.

Query parameters

NameTypeRequiredDefaultDescription
clusterIdstringYes—Cluster ID
policystringYes—Exact policy name to match in the exception’s policy list
namespacestringNo—Restrict to exceptions in this namespace

Response 200 (application/json)

Array of {id, name, namespace}

FieldTypeDescription
idstringPolicy exception ID
namestringName (empty string if unset)
namespacestringNamespace (empty string if unset)

Errors

  • 400 — clusterId or policy query parameter missing
  • 500 — Failed to search policy exceptions
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

Example

curl -H 'Authorization: NIRMATA-API <token>' 'https://<host>/policies/api/v1/policy-exceptions/search?clusterId=<id>&policy=disallow-privileged-containers'

Get policy exception summary

GET /policies/api/v1/policy-exceptions/summary

Returns counts of policy exceptions in the tenant: total, those with excepted resources, those listing policies, and empty ones.

Roles: Any role with permission for this resource. See Roles.

Response 200 (application/json)

{total, withExceptedResources, withPolicyExceptions, empty}

FieldTypeDescription
totalintegerTotal policy exceptions
withExceptedResourcesintegerExceptions that currently match at least one resource
withPolicyExceptionsintegerExceptions that list at least one policy
emptyintegerApproximate count of exceptions without policies/resources

Errors

  • 500 — Failed to get policy exceptions summary
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

Get a policy exception

GET /policies/api/v1/policy-exceptions/{id}

Returns a single policy exception by ID. Users with own-scope access can only read exceptions they requested.

Roles: Any role with permission for this resource. See Roles.

Path parameters

NameTypeDescription
idstringPolicy exception ID

Response 200 (application/json)

PolicyException

FieldTypeDescription
idstringPolicy exception ID
apiVersionstringKyverno API version of the PolicyException resource
kindstringResource kind (e.g. PolicyException)
namestringPolicy exception name
namespacestringKubernetes namespace of the exception
uidstringKubernetes UID
resourceVersionstringKubernetes resource version
clusterRefobjectReference to the cluster: {service, modelIndex, id}
exceptionsarray<object>Excepted policies/rules: {policyName, ruleNames, namespace, policyUID, kind, policyRef}
exceptedResourcesarray<object>Resources currently excepted: {apiVersion, kind, name, namespace, fieldPath, resourceVersion, uid, resourceRef}
yamlstringFull YAML of the PolicyException resource
requestDetailsstringJSON-encoded string with details of the originating exception request, if any

Errors

  • 404 — Policy exception not found
  • 500 — Failed to retrieve policy exception
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List policy exceptions for a cluster

GET /policies/api/v1/policy-exceptions/by-cluster/{clusterId}

Returns all policy exceptions belonging to the given cluster. Not paginated.

Roles: Any role with permission for this resource. See Roles.

Path parameters

NameTypeDescription
clusterIdstringCluster ID

Response 200 (application/json)

PolicyException[] (plain array)

FieldTypeDescription
idstringPolicy exception ID
apiVersionstringKyverno API version of the PolicyException resource
kindstringResource kind (e.g. PolicyException)
namestringPolicy exception name
namespacestringKubernetes namespace of the exception
uidstringKubernetes UID
resourceVersionstringKubernetes resource version
clusterRefobjectReference to the cluster: {service, modelIndex, id}
exceptionsarray<object>Excepted policies/rules: {policyName, ruleNames, namespace, policyUID, kind, policyRef}
exceptedResourcesarray<object>Resources currently excepted: {apiVersion, kind, name, namespace, fieldPath, resourceVersion, uid, resourceRef}
yamlstringFull YAML of the PolicyException resource
requestDetailsstringJSON-encoded string with details of the originating exception request, if any

Errors

  • 500 — Lookup failed
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List policy exceptions by kind

GET /policies/api/v1/policy-exceptions/by-kind/{kind}

Returns all policy exceptions whose resource kind exactly matches the given value (e.g. PolicyException). Not paginated.

Roles: Any role with permission for this resource. See Roles.

Path parameters

NameTypeDescription
kindstringResource kind

Response 200 (application/json)

PolicyException[] (plain array)

FieldTypeDescription
idstringPolicy exception ID
apiVersionstringKyverno API version of the PolicyException resource
kindstringResource kind (e.g. PolicyException)
namestringPolicy exception name
namespacestringKubernetes namespace of the exception
uidstringKubernetes UID
resourceVersionstringKubernetes resource version
clusterRefobjectReference to the cluster: {service, modelIndex, id}
exceptionsarray<object>Excepted policies/rules: {policyName, ruleNames, namespace, policyUID, kind, policyRef}
exceptedResourcesarray<object>Resources currently excepted: {apiVersion, kind, name, namespace, fieldPath, resourceVersion, uid, resourceRef}
yamlstringFull YAML of the PolicyException resource
requestDetailsstringJSON-encoded string with details of the originating exception request, if any

Errors

  • 500 — Lookup failed
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List policy exceptions in a namespace

GET /policies/api/v1/policy-exceptions/by-namespace/{namespace}

Returns all policy exceptions whose namespace exactly matches the given value. Not paginated.

Roles: Any role with permission for this resource. See Roles.

Path parameters

NameTypeDescription
namespacestringKubernetes namespace name

Response 200 (application/json)

PolicyException[] (plain array)

FieldTypeDescription
idstringPolicy exception ID
apiVersionstringKyverno API version of the PolicyException resource
kindstringResource kind (e.g. PolicyException)
namestringPolicy exception name
namespacestringKubernetes namespace of the exception
uidstringKubernetes UID
resourceVersionstringKubernetes resource version
clusterRefobjectReference to the cluster: {service, modelIndex, id}
exceptionsarray<object>Excepted policies/rules: {policyName, ruleNames, namespace, policyUID, kind, policyRef}
exceptedResourcesarray<object>Resources currently excepted: {apiVersion, kind, name, namespace, fieldPath, resourceVersion, uid, resourceRef}
yamlstringFull YAML of the PolicyException resource
requestDetailsstringJSON-encoded string with details of the originating exception request, if any

Errors

  • 500 — Lookup failed
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted

List resources excepted by a policy exception

GET /policies/api/v1/policy-exceptions/{id}/excepted-resources

Returns the Kubernetes resources currently matched (excepted) by the given policy exception.

Roles: Any role with permission for this resource. See Roles.

Path parameters

NameTypeDescription
idstringPolicy exception ID

Response 200 (application/json)

{exceptedResources: object[], count: integer}

FieldTypeDescription
exceptedResourcesarray<object>{apiVersion, kind, name, namespace, fieldPath, resourceVersion, uid, resourceRef}
countintegerNumber of excepted resources

Errors

  • 404 — Policy exception not found
  • 500 — Failed to get excepted resources
  • 401 — Missing or invalid credentials
  • 403 — Caller’s role is not permitted