Googleapis Binaryauthorization
Google Binary Authorization is a deployment security service that enforces trusted container image policies.
- Base URL:
https://binaryauthorization.googleapis.com - Auth: OAuth 2.0 (user-delegated) — attach an InTouch
oauthcredential. Mint one withitcli.py /oauth <provider>(device-code) or/google-auth(Google); the server auto-refreshes the access token before each run, so the connector never handles or stores tokens.
Operations
binaryauthorization_systempolicy_getpolicy— GET /v1beta1/{name} — Gets the current system policy in the specified location.binaryauthorization_projects_attestors_list— GET /v1beta1/{parent}/attestors — Lists attestors. Returns INVALID_ARGUMENT if the project does not exist.binaryauthorization_projects_policy_getiampolicy— GET /v1beta1/{resource}:getIamPolicy — Gets the access control policy for a resource. Returns an empty policy if the rebinaryauthorization_projects_attestors_validatea— POST /v1beta1/{attestor}:validateAttestationOccurrence — Returns whether the given Attestation for the given image URI was signed by thebinaryauthorization_projects_attestors_update— PUT /v1beta1/{name} — Updates an attestor. Returns NOT_FOUND if the attestor does not exist.binaryauthorization_projects_attestors_delete— DELETE /v1beta1/{name} — Deletes an attestor. Returns NOT_FOUND if the attestor does not exist.
Inputs
- a linked
oauthcredential (no key inputs) — the server injects a freshAuthorization: Bearerfrom it operation— one of the operations above- path parameters when an operation's path contains
{...} query— optional JSON object of query paramsbody— JSON object for create/update ops
Example
operation: binaryauthorization_systempolicy_getpolicy
# (attach an 'oauth' credential to the task — no inline secrets)
Publishes
The keys a later task may reference as {{taskName.key}}. Referencing anything not listed here resolves to nothing at run time.
erroroperationresultstatus
Input Properties
Every property this tool accepts, from its own tool.iml.
| Property | Type | Required | Default | Description |
|---|---|---|---|---|
operation |
string | yes | — | One of: binaryauthorization_systempolicy_getpolicy, binaryauthorization_projects_attestors_list, binaryauthorization_projects_policy_getiampolicy, binaryauthorization_projects_attestors_validatea, binaryauthorization_projects_attestors_update, binaryauthorization_projects_attestors_delete |
attestor |
string | no | — | Path parameter attestor (required by some operations). |
name |
string | no | — | Path parameter name (required by some operations). |
parent |
string | no | — | Path parameter parent (required by some operations). |
resource |
string | no | — | Path parameter resource (required by some operations). |
query |
string | no | — | Optional query params as a JSON object string, e.g. {"limit": 10}. |
body |
string | no | — | Request body as a JSON object string (for create/update operations). |