api-service.ospp

Api service

The api service configuration define a external api accessible from OnSphere.

This allow the front-end to execute action (POST, GET, PUT, PATCH, DELETE) on this api without having a direct access.

The request to the api is done from the OnSphere server. This can be useful if the client cannot access the api because it is only internal.

type

object

properties

  • credential

The credential to access the api if needed. The following types are supported:

  • USERNAME: For a basic auth with username and password.

  • TOKEN: For a bearer token.

  • OIDC: For application OpenIDConnect.

oneOf

USERNAME

TOKEN

OIDC

HEADER

  • host

The host of the api. It must not end with / and contain the protocol (http or https).

The endpoint (/user, /building) are defined on api-endpoint.ospp.

type

string

pattern

^http(s?)://.*(?<!/)$

  • isTemplateGeneratedByOspComposer

Name of the playbook that generated this file. If present, the file is managed by the Composer and may be overwritten on regeneration. Used for selective clean. Do not edit or set manually.

type

string

  • moduleId

The id of the module who need this configuration. Supported module [web, script, keycloak]

type

array

items

type

string

  • responseTimeout

The maximum time allowed to get a response from this api.

This value will be used as the default for each endpoint. The endpoint can override it.

It is also possible to override it when doing the request.

Default value is [{“unit”:”MINUTES”,”value”:1}]

default

unit

MINUTES

value

1

DurationConfigurationEntity

  • templateId

The id of the template to use for this file

type

string

  • templateVariables

The variables and their values to be replaced from the template

type

object

additionalProperties

  • variablesFiles

The variables files to use to replace the variables. The first file of the list will take precedence over the following one. Template variables take precedence over the contents of the files.

type

array

items

type

string

additionalProperties

False

USERNAME

type

object

properties

  • type

type

string

enum

USERNAME

default

USERNAME

  • password

The password of the user.

oneOf

PLAINTEXT

SECRET

ENCRYPTED

  • usePreemptiveAuthentication

When preemptive authentication is enabled, the Basic Auth header is sent with the first request. This ensures proper handling of servers that may respond incorrectly (e.g., returning a 403 instead of 401) and avoids unnecessary additional requests.

Default value is [false]

type

boolean

default

False

  • username

type

string

additionalProperties

False

PLAINTEXT

type

object

properties

  • type

type

string

enum

PLAINTEXT

default

PLAINTEXT

  • password

The password to use in plaintext. It can be for example thisIs@TestPassword123.

type

string

additionalProperties

False

SECRET

type

object

properties

  • type

type

string

enum

SECRET

default

SECRET

  • secretPath

The path of the secret containing the password. This is a path to the secret containing the password.

type

string

additionalProperties

False

ENCRYPTED

type

object

properties

  • type

type

string

enum

ENCRYPTED

default

ENCRYPTED

  • encryptedPassword

The password encrypted Base64(IV+AES256(password, input)) the password must be a shared secret available for the osp-configuration-dispatcher

see documentation ↗️ see toolbox ↗️

type

string

  • secretPath

The full path to the secret exposed by the orchestrator; this password is used to encrypt the encryptedPassword.

type

string

additionalProperties

False

TOKEN

type

object

properties

  • type

type

string

enum

TOKEN

default

TOKEN

  • token

The token to use in the authorization bearer header.

oneOf

PLAINTEXT

SECRET

ENCRYPTED

additionalProperties

False

OIDC

The OIDC credential allow an application to request an access token from an identity provider using it’s id and secret.

It will generate a new token when needed during the request execution.

The response format expected to be:

{
    "access_token": "..."
    "token_type": "Bearer"
    "expires_in": 600
}

type

object

properties

  • type

type

string

enum

OIDC

default

OIDC

  • clientId

The id of the client to use to get the token

type

string

  • clientSecret

The shared secret between the client and server.

oneOf

PLAINTEXT

SECRET

ENCRYPTED

  • expirationMargin

The margin to use to validate the token validity.

The token live will be reduce by this margin to avoid using it when it is close to expire.

DurationConfigurationEntity

  • grantType

The method to use to generate the access token

type

string

enum

CLIENT_CREDENTIALS

  • host

The host where to request an access token using the client id and secret.

For example, https://idp.example.org

type

string

  • path

The path where to request an access token using the client id and secret.

For example, /oauth2/v2.0/token

type

string

  • scope

The wanted scope for the token.

This should be the resource identifier (application ID URI) of the resource you want.

type

string

additionalProperties

False

DurationConfigurationEntity

type

object

properties

  • unit

The unit of time expressed

type

string

enum

NANOSECONDS, MICROSECONDS, MILLISECONDS, SECONDS, MINUTES, HOURS, DAYS

  • value

The amount of time expressed with the unit

type

integer

additionalProperties

False