2017-05-03 18:43:24 +00:00
|
|
|
|
---
|
2020-01-18 00:18:09 +00:00
|
|
|
|
layout: api
|
|
|
|
|
page_title: /sys/plugins/catalog - HTTP API
|
|
|
|
|
description: The `/sys/plugins/catalog` endpoint is used to manage plugins.
|
2017-05-03 18:43:24 +00:00
|
|
|
|
---
|
|
|
|
|
|
|
|
|
|
# `/sys/plugins/catalog`
|
|
|
|
|
|
2018-11-14 17:17:12 +00:00
|
|
|
|
The `/sys/plugins/catalog` endpoint is used to read, register, update, and
|
2017-05-03 18:43:24 +00:00
|
|
|
|
remove plugins in Vault's catalog. Plugins must be registered before use, and
|
|
|
|
|
once registered backends can use the plugin by querying the catalog.
|
|
|
|
|
|
2018-11-14 17:17:12 +00:00
|
|
|
|
## LIST Plugins
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
2018-11-14 17:17:12 +00:00
|
|
|
|
This endpoint lists the plugins in the catalog by type.
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
2020-01-18 00:18:09 +00:00
|
|
|
|
| Method | Path |
|
|
|
|
|
| :----- | :--------------------- |
|
|
|
|
|
| `GET` | `/sys/plugins/catalog` |
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Sample Request
|
|
|
|
|
|
2020-05-21 17:18:17 +00:00
|
|
|
|
```shell-session
|
2017-05-03 18:43:24 +00:00
|
|
|
|
$ curl \
|
|
|
|
|
--header "X-Vault-Token: ..." \
|
2018-03-23 15:41:51 +00:00
|
|
|
|
http://127.0.0.1:8200/v1/sys/plugins/catalog
|
2017-05-03 18:43:24 +00:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Sample Response
|
|
|
|
|
|
|
|
|
|
```javascript
|
|
|
|
|
{
|
|
|
|
|
"data": {
|
2018-11-14 17:17:12 +00:00
|
|
|
|
"auth": [
|
|
|
|
|
"aws",
|
|
|
|
|
"azure",
|
|
|
|
|
"custom-auth-plugin",
|
|
|
|
|
"gcp",
|
|
|
|
|
"ldap"
|
|
|
|
|
],
|
|
|
|
|
"database": [
|
2017-05-03 18:43:24 +00:00
|
|
|
|
"cassandra-database-plugin",
|
|
|
|
|
"mssql-database-plugin",
|
|
|
|
|
"mysql-database-plugin",
|
|
|
|
|
"postgresql-database-plugin"
|
2018-11-14 17:17:12 +00:00
|
|
|
|
],
|
|
|
|
|
"secret": [
|
|
|
|
|
"ad",
|
|
|
|
|
"aws",
|
|
|
|
|
"azure",
|
|
|
|
|
"gcp",
|
|
|
|
|
"transit"
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
```
|
2020-01-18 00:18:09 +00:00
|
|
|
|
|
2018-11-14 17:17:12 +00:00
|
|
|
|
## LIST Plugins
|
|
|
|
|
|
|
|
|
|
This endpoint lists the plugins in the catalog by type.
|
|
|
|
|
|
2020-01-18 00:18:09 +00:00
|
|
|
|
| Method | Path |
|
|
|
|
|
| :----- | :------------------------------ |
|
|
|
|
|
| `LIST` | `/sys/plugins/catalog/auth` |
|
|
|
|
|
| `LIST` | `/sys/plugins/catalog/database` |
|
|
|
|
|
| `LIST` | `/sys/plugins/catalog/secret` |
|
2018-11-14 17:17:12 +00:00
|
|
|
|
|
|
|
|
|
### Sample Request
|
|
|
|
|
|
2020-05-21 17:18:17 +00:00
|
|
|
|
```shell-session
|
2018-11-14 17:17:12 +00:00
|
|
|
|
$ curl \
|
|
|
|
|
--header "X-Vault-Token: ..." \
|
|
|
|
|
--request LIST
|
|
|
|
|
http://127.0.0.1:8200/v1/sys/plugins/catalog/auth
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Sample Response
|
|
|
|
|
|
|
|
|
|
```javascript
|
|
|
|
|
{
|
|
|
|
|
"data": {
|
|
|
|
|
"keys": [
|
|
|
|
|
"aws",
|
|
|
|
|
"azure",
|
|
|
|
|
"custom-auth-plugin",
|
|
|
|
|
"gcp",
|
|
|
|
|
"ldap"
|
2017-05-03 18:43:24 +00:00
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
## Register Plugin
|
|
|
|
|
|
|
|
|
|
This endpoint registers a new plugin, or updates an existing one with the
|
|
|
|
|
supplied name.
|
|
|
|
|
|
|
|
|
|
- **`sudo` required** – This endpoint requires `sudo` capability in addition to
|
|
|
|
|
any path-specific capabilities.
|
|
|
|
|
|
2020-01-18 00:18:09 +00:00
|
|
|
|
| Method | Path |
|
|
|
|
|
| :----- | :--------------------------------- |
|
2022-02-25 14:52:24 +00:00
|
|
|
|
| `POST` | `/sys/plugins/catalog/:type/:name` |
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Parameters
|
|
|
|
|
|
|
|
|
|
- `name` `(string: <required>)` – Specifies the name for this plugin. The name
|
|
|
|
|
is what is used to look up plugins in the catalog. This is part of the request
|
|
|
|
|
URL.
|
2020-01-18 00:18:09 +00:00
|
|
|
|
|
|
|
|
|
- `type` `(string: <required>)` – Specifies the type of this plugin. May be
|
2018-11-14 17:17:12 +00:00
|
|
|
|
"auth", "database", or "secret".
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
2017-08-16 15:17:50 +00:00
|
|
|
|
- `sha256` `(string: <required>)` – This is the SHA256 sum of the plugin's
|
2017-05-03 18:43:24 +00:00
|
|
|
|
binary. Before a plugin is run it's SHA will be checked against this value, if
|
|
|
|
|
they do not match the plugin can not be run.
|
|
|
|
|
|
|
|
|
|
- `command` `(string: <required>)` – Specifies the command used to execute the
|
2018-09-20 17:50:29 +00:00
|
|
|
|
plugin. This is relative to the plugin directory. e.g. `"myplugin"`.
|
|
|
|
|
|
|
|
|
|
- `args` `(array: [])` – Specifies the arguments used to execute the plugin. If
|
|
|
|
|
the arguments are provided here, the `command` parameter should only contain
|
|
|
|
|
the named program. e.g. `"--my_flag=1"`.
|
|
|
|
|
|
|
|
|
|
- `env` `(array: [])` – Specifies the environment variables used during the
|
|
|
|
|
execution of the plugin. Each entry is of the form "key=value". e.g
|
|
|
|
|
`"FOO=BAR"`.
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Sample Payload
|
|
|
|
|
|
|
|
|
|
```json
|
|
|
|
|
{
|
2018-10-04 16:51:54 +00:00
|
|
|
|
"sha256": "d130b9a0fbfddef9709d8ff92e5e6053ccd246b78632fc03b8548457026961e9",
|
2017-05-03 18:43:24 +00:00
|
|
|
|
"command": "mysql-database-plugin"
|
|
|
|
|
}
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Sample Request
|
|
|
|
|
|
2020-05-21 17:18:17 +00:00
|
|
|
|
```shell-session
|
2017-05-03 18:43:24 +00:00
|
|
|
|
$ curl \
|
|
|
|
|
--header "X-Vault-Token: ..." \
|
2022-02-25 14:52:24 +00:00
|
|
|
|
--request POST \
|
2017-05-03 18:43:24 +00:00
|
|
|
|
--data @payload.json \
|
2018-11-14 17:17:12 +00:00
|
|
|
|
http://127.0.0.1:8200/v1/sys/plugins/catalog/secret/example-plugin
|
2017-05-03 18:43:24 +00:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
## Read Plugin
|
|
|
|
|
|
|
|
|
|
This endpoint returns the configuration data for the plugin with the given name.
|
|
|
|
|
|
|
|
|
|
- **`sudo` required** – This endpoint requires `sudo` capability in addition to
|
|
|
|
|
any path-specific capabilities.
|
|
|
|
|
|
2020-01-18 00:18:09 +00:00
|
|
|
|
| Method | Path |
|
|
|
|
|
| :----- | :--------------------------------- |
|
|
|
|
|
| `GET` | `/sys/plugins/catalog/:type/:name` |
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Parameters
|
|
|
|
|
|
|
|
|
|
- `name` `(string: <required>)` – Specifies the name of the plugin to retrieve.
|
|
|
|
|
This is part of the request URL.
|
2020-01-18 00:18:09 +00:00
|
|
|
|
|
|
|
|
|
- `type` `(string: <required>)` – Specifies the type of this plugin. May be
|
2018-11-14 17:17:12 +00:00
|
|
|
|
"auth", "database", or "secret".
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Sample Request
|
|
|
|
|
|
2020-05-21 17:18:17 +00:00
|
|
|
|
```shell-session
|
2017-05-03 18:43:24 +00:00
|
|
|
|
$ curl \
|
|
|
|
|
--header "X-Vault-Token: ..." \
|
|
|
|
|
--request GET \
|
2018-11-14 17:17:12 +00:00
|
|
|
|
http://127.0.0.1:8200/v1/sys/plugins/catalog/secret/example-plugin
|
2017-05-03 18:43:24 +00:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Sample Response
|
|
|
|
|
|
|
|
|
|
```javascript
|
|
|
|
|
{
|
|
|
|
|
"data": {
|
2017-09-01 12:34:54 +00:00
|
|
|
|
"args": [],
|
|
|
|
|
"builtin": false,
|
|
|
|
|
"command": "/tmp/vault-plugins/mysql-database-plugin",
|
|
|
|
|
"name": "example-plugin",
|
|
|
|
|
"sha256": "0TC5oPv93vlwnY/5Ll5gU8zSRreGMvwDuFSEVwJpYek="
|
2017-05-03 18:43:24 +00:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
```
|
2020-01-18 00:18:09 +00:00
|
|
|
|
|
2017-05-03 18:43:24 +00:00
|
|
|
|
## Remove Plugin from Catalog
|
|
|
|
|
|
|
|
|
|
This endpoint removes the plugin with the given name.
|
|
|
|
|
|
|
|
|
|
- **`sudo` required** – This endpoint requires `sudo` capability in addition to
|
|
|
|
|
any path-specific capabilities.
|
|
|
|
|
|
2020-01-18 00:18:09 +00:00
|
|
|
|
| Method | Path |
|
|
|
|
|
| :------- | :--------------------------------- |
|
2019-03-22 16:15:37 +00:00
|
|
|
|
| `DELETE` | `/sys/plugins/catalog/:type/:name` |
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Parameters
|
|
|
|
|
|
|
|
|
|
- `name` `(string: <required>)` – Specifies the name of the plugin to delete.
|
|
|
|
|
This is part of the request URL.
|
2020-01-18 00:18:09 +00:00
|
|
|
|
|
|
|
|
|
- `type` `(string: <required>)` – Specifies the type of this plugin. May be
|
2018-11-14 17:17:12 +00:00
|
|
|
|
"auth", "database", or "secret".
|
2017-05-03 18:43:24 +00:00
|
|
|
|
|
|
|
|
|
### Sample Request
|
|
|
|
|
|
2020-05-21 17:18:17 +00:00
|
|
|
|
```shell-session
|
2017-05-03 18:43:24 +00:00
|
|
|
|
$ curl \
|
|
|
|
|
--header "X-Vault-Token: ..." \
|
|
|
|
|
--request DELETE \
|
2018-11-14 17:17:12 +00:00
|
|
|
|
http://127.0.0.1:8200/v1/sys/plugins/catalog/secret/example-plugin
|
2017-05-03 18:43:24 +00:00
|
|
|
|
```
|