Skip to main content

REST API Reference

The Okustera Cloud Platform provides a comprehensive, RESTful OpenAPI 3.1 interface for programmatic management of all cloud infrastructure, developer platform, and security resources.

Base Production Endpoint:

https://portal.okustera.com/api/v1

Authentication​

All API requests require authentication via an HTTP Authorization header containing an Okustera API Bearer token:

curl -H "Authorization: Bearer <YOUR_API_TOKEN>" \
-H "Content-Type: application/json" \
https://portal.okustera.com/api/v1/auth/me

Tokens can be generated from the Okustera Cloud Portal under User Settings $\to$ API Tokens or provisioned via Keystone.


API Endpoints Overview​

1. Authentication & Security (2FA)​

HTTP Method & PathDescription
POST /api/v1/auth/loginAuthenticate user credentials and optional TOTP code; receive JWT access token.
GET /api/v1/auth/meRetrieve profile and project membership of current caller.
POST /api/v1/auth/2fa/setupGenerate a new TOTP secret key and QR code provisioning URI.
POST /api/v1/auth/2fa/activateSubmit initial 6-digit verification code to activate 2FA on user account.
POST /api/v1/auth/2fa/verifyValidate a 6-digit code during authentication challenge.
POST /api/v1/auth/2fa/disableDeactivate 2FA by providing a valid verification code.

2. Compute Instances (Nova)​

HTTP Method & PathDescription
GET /api/v1/compute/instancesList all instances in current tenant project.
POST /api/v1/compute/instancesLaunch a new VM instance with flavor, image, and network.
GET /api/v1/compute/instances/{id}Inspect instance state, IP addresses, and hardware flavor.
DELETE /api/v1/compute/instances/{id}Terminate and delete an instance.
POST /api/v1/compute/instances/{id}/actionExecute lifecycle action (reboot, start, stop, pause, unpause, rebuild).
GET /api/v1/compute/instances/{id}/consoleRetrieve interactive VNC/SPICE console URL for out-of-band access.
GET /api/v1/compute/instances/{id}/console-logRetrieve live serial kernel boot logs.
GET /api/v1/compute/flavorsList available compute resource flavors.

3. VPC Networking & Security Groups (Neutron & OVN)​

HTTP Method & PathDescription
GET /api/v1/network/networksList tenant private VPC networks and subnets.
POST /api/v1/network/networksCreate a new private network with custom CIDR and DHCP.
DELETE /api/v1/network/networks/{id}Delete a private network.
GET /api/v1/network/routersList active virtual routers and gateway interfaces.
GET /api/v1/network/security-groupsList stateful firewall security groups and rules.
POST /api/v1/network/security-groupsCreate a new security group.
POST /api/v1/network/security-groups/{id}/rulesAdd ingress/egress firewall rule (protocol, port range, CIDR).
DELETE /api/v1/network/security-groups/rules/{rule_id}Remove a firewall rule.
GET /api/v1/network/floating-ipsList allocated floating public IP addresses.
POST /api/v1/network/floating-ipsAllocate a new public floating IP from external pool.
POST /api/v1/network/floating-ips/{id}/associateBind floating IP to compute instance or load balancer port.
POST /api/v1/network/floating-ips/{id}/disassociateUnbind floating IP from port.
DELETE /api/v1/network/floating-ips/{id}Release floating IP back to external pool.
GET /api/v1/network/portsList virtual network interfaces, MAC addresses, and IP bindings.

4. Load Balancers (Octavia LBaaS)​

HTTP Method & PathDescription
GET /api/v1/octavia/loadbalancersList active load balancers and provisioning status.
POST /api/v1/octavia/loadbalancersProvision a new high-availability load balancer with dedicated VIP.
GET /api/v1/octavia/loadbalancers/{id}Inspect load balancer status and VIP details.
DELETE /api/v1/octavia/loadbalancers/{id}Decommission and delete a load balancer.
GET /api/v1/octavia/listenersList listeners associated with tenant load balancers.
GET /api/v1/octavia/poolsList backend pools and member health states.

5. Persistent Block Storage (Cinder & Ceph)​

HTTP Method & PathDescription
GET /api/v1/storage/volumesList block storage volumes in current tenant project.
POST /api/v1/storage/volumesProvision a new persistent volume (from scratch, image, or snapshot).
GET /api/v1/storage/volumes/{id}Retrieve volume status, size, and instance attachments.
DELETE /api/v1/storage/volumes/{id}Delete an unattached volume.
POST /api/v1/storage/volumes/{id}/attachAttach volume to a running compute instance.
POST /api/v1/storage/volumes/{id}/detachDetach volume from an instance.
GET /api/v1/storage/snapshotsList point-in-time volume snapshots.
POST /api/v1/storage/snapshotsCreate an instantaneous copy-on-write volume snapshot.

6. S3-Compatible Object Storage (Ceph RGW)​

HTTP Method & PathDescription
GET /api/v1/storage/credentialsList active S3 access keys for the tenant project.
POST /api/v1/storage/credentialsGenerate a new S3 Access Key / Secret Key pair.
GET /api/v1/storage/bucketsList S3-compatible object storage buckets.
POST /api/v1/storage/bucketsCreate new S3 bucket with quota and ACL (private, public-read).
DELETE /api/v1/storage/buckets/{name}Delete an empty S3 bucket.
GET /api/v1/storage/buckets/{name}/objectsList objects in bucket with optional prefix filtering.
POST /api/v1/storage/buckets/{name}/objects/presignGenerate temporary presigned download or upload URL.
DELETE /api/v1/storage/buckets/{name}/objects/{key}Delete an object from a bucket.

7. Operating System Images (Glance)​

HTTP Method & PathDescription
GET /api/v1/glance/imagesList certified public and custom tenant images.
POST /api/v1/glance/imagesRegister and upload a custom image (QCOW2, RAW, ISO).
GET /api/v1/glance/images/{id}Retrieve image metadata, checksum, and status.
DELETE /api/v1/glance/images/{id}Remove a custom image from the catalog.

8. Secrets Vault & KMS (Barbican)​

HTTP Method & PathDescription
GET /api/v1/barbican/secretsList secrets in current tenant project.
POST /api/v1/barbican/secretsStore a new secret (passphrase, symmetric key, certificate, opaque).
GET /api/v1/barbican/secrets/{id}/payloadRetrieve decrypted secret payload.
DELETE /api/v1/barbican/secrets/{id}Permanently delete a secret from the vault.

9. Managed Kubernetes Service (Magnum & CAPI)​

HTTP Method & PathDescription
GET /api/v1/kubernetes/clustersList all managed Kubernetes clusters for tenant.
POST /api/v1/kubernetes/clustersProvision a new upstream Kubernetes cluster.
GET /api/v1/kubernetes/clusters/{id}Inspect cluster health, API endpoint, and node count.
POST /api/v1/kubernetes/clusters/{id}/scaleScale worker node pool count dynamically.
GET /api/v1/kubernetes/clusters/{id}/kubeconfigDownload cluster admin kubeconfig.
DELETE /api/v1/kubernetes/clusters/{id}Terminate a cluster and delete associated VMs.
GET /api/v1/kubernetes/cluster-templatesList certified upstream Kubernetes templates.

10. Managed Databases (DBaaS)​

HTTP Method & PathDescription
GET /api/v1/dbaas/clustersList managed clusters across all engines (PostgreSQL, MySQL, MongoDB, Valkey, Qdrant).
POST /api/v1/dbaas/postgresProvision high-availability PostgreSQL cluster (CloudNativePG).
GET /api/v1/dbaas/postgres/{ns}/{name}Retrieve details for a PostgreSQL cluster.
GET /api/v1/dbaas/valkeyList active Valkey Sentinel clusters.
POST /api/v1/dbaas/valkeyProvision high-availability Valkey cluster (Spotahome Sentinel).
GET /api/v1/dbaas/qdrantList tenant-isolated Qdrant Vector DB clusters.
POST /api/v1/dbaas/qdrantProvision tenant-isolated Qdrant Vector DB cluster with Barbican API key auth.
POST /api/v1/dbaas/mysqlProvision multi-master MySQL cluster (Percona XtraDB).
POST /api/v1/dbaas/mongodbProvision MongoDB replica set (Percona PSMDB).
GET /api/v1/dbaas/catalog/versionsList certified database engine versions available for deployment and upgrades.
GET /api/v1/dbaas/clusters/{engine}/{ns}/{name}/upgrade-candidatesDiscover certified upgrade targets and tier classification for a running cluster.
GET /api/v1/dbaas/clusters/{engine}/{ns}/{name}/preflightEvaluate the automated 5-point safety gate checklist prior to upgrading.
POST /api/v1/dbaas/clusters/{engine}/{ns}/{name}/upgradeDispatch an automated zero-downtime rolling upgrade job with auto-rollback.
GET /api/v1/dbaas/jobs/{job_id}Query real-time lifecycle stage transitions and diagnostic logs for an upgrade job.
POST /api/v1/dbaas/jobs/{job_id}/rollbackRequest manual rollback to restore the previous certified database engine version.

11. AI Inference PaaS & Model Foundry​

HTTP Method & PathDescription
GET /api/v1/ai/statusRetrieve operational AI inference and Qdrant cluster health status.
GET /api/v1/ai/modelsList active foundation models available for inference.
POST /api/v1/ai/chat/completionsOpenAI-compatible chat completions with unbuffered SSE streaming.
GET /api/v1/ai/rag/collectionsList and inspect RAG vector knowledge base collections.
POST /api/v1/ai/rag/collectionsCreate and index a new RAG document collection in Qdrant.

12. API Gateway & Ingress (APISIX)​

HTTP Method & PathDescription
GET /api/v1/gateway/routesList all APISIX ingress routing rules.
POST /api/v1/gateway/routesCreate or update traffic-split canary route.
GET /api/v1/gateway/routes/{id}/manifestGenerate Kubernetes ApisixRoute YAML manifest.
GET /api/v1/gateway/certificatesList SSL/TLS certificates registered on the gateway.
POST /api/v1/gateway/certificatesRegister new SSL/TLS certificate or request automated Let's Encrypt cert.

13. Serverless Functions & Layers (FaaS)​

HTTP Method & PathDescription
GET /api/v1/functions/templatesList certified language runtime templates and lifecycle statuses (active, deprecated).
GET /api/v1/functionsList active serverless functions.
POST /api/v1/functionsDeploy serverless function with gVisor sandbox.
POST /api/v1/functions/{id}/invokeInvoke serverless function synchronously or asynchronously.
GET /api/v1/functions/{id}/logsStream live function execution logs.
GET /api/v1/layersList available shared CephFS dependency layers.
POST /api/v1/layersCreate a new shared dependency layer definition.
POST /api/v1/layers/{id}/versionsPublish an immutable layer version with zip or package requirements.
POST /api/v1/layers/{id}/permissionsGrant cross-tenant layer sharing permissions.

14. Workflows & Orchestration (Airflow)​

HTTP Method & PathDescription
GET /api/v1/workflows/statusRetrieve operational health of Airflow Scheduler, PostgreSQL, and Ceph S3.
GET /api/v1/workflows/dagsList workflow DAGs accessible to current tenant.
PATCH /api/v1/workflows/dags/{dag_id}Pause or unpause a workflow DAG.
POST /api/v1/workflows/dags/{dag_id}/triggerTrigger immediate DAG execution with optional JSON parameters.
GET /api/v1/workflows/dags/{dag_id}/runsList historical and active DAG runs with state and duration.
GET /api/v1/workflows/dags/{dag_id}/runs/{run_id}/tasks/{task_id}/logsRetrieve streaming task execution logs.
POST /api/v1/workflows/dags/uploadUpload Python DAG file to S3 with automatic scheduler synchronization.
DELETE /api/v1/workflows/dags/{dag_id}Delete DAG file from storage and purge scheduler metadata.

15. Observability & Telemetry​

HTTP Method & PathDescription
GET /api/v1/observability/dashboardRetrieve tenant-scoped telemetry summary.
GET /api/v1/observability/logsQuery Grafana Loki log streams with LogQL expressions and time ranges.
GET /api/v1/observability/timeseries/{metric_type}Retrieve historical time-series data for CPU, RAM, Network, or Disk.
GET /api/v1/grafana/infoRetrieve tenant Grafana workspace URL and SSO endpoint.

16. FinOps, Billing & Payments​

HTTP Method & PathDescription
GET /api/v1/billing/overviewRetrieve real-time metering, budget limit, and forecasted spend.
GET /api/v1/billing/breakdownItemized cost breakdown across compute, storage, and databases.
GET /api/v1/billing/invoicesHistorical billing statements and line items.
GET /api/v1/billing/payment-methodsList configured customer payment cards.
POST /api/v1/billing/payment-methodsAdd and tokenize a new payment method via Stripe.
POST /api/v1/billing/payment-methods/{id}/defaultSet card as default payment method.
POST /api/v1/billing/checkout-sessionGenerate a secure Stripe payment checkout session.
GET /api/v1/billing/budgetRetrieve current budget limits and alert thresholds.
PUT /api/v1/billing/budgetUpdate monthly budget limit and notification thresholds.
GET /api/v1/billing/pricingRetrieve active rate card and unit prices.

17. Identity & Policy Simulation​

HTTP Method & PathDescription
GET /api/v1/identity/usersList users in current project.
POST /api/v1/identity/usersCreate user account with initial credentials.
GET /api/v1/identity/rolesList available IAM roles (admin, member, reader).
POST /api/v1/identity/role-assignmentsAssign a role to a user within a project.
DELETE /api/v1/identity/role-assignmentsRevoke a user's role assignment.
POST /api/v1/iam/simulateEvaluate whether an identity has permission to invoke an endpoint.
POST /api/v1/iam/sts/assume-roleExchange workload identity token for short-lived credentials.

18. Service Catalog & Inventory​

HTTP Method & PathDescription
GET /api/v1/services/servicesList available cloud catalog services and subscription statuses.
GET /api/v1/inventory/inventoryRetrieve unified inventory of all compute, K8s, DB, and network resources.

19. Tenant Quotas & Governance​

HTTP Method & PathDescription
GET /api/v1/tenant/quotaQuery live resource allocations, usage, and available balances across 9 quota dimensions.

Standard Error Response Format​

All failed API responses adhere to the standard JSON error schema:

{
"error": {
"code": "RESOURCE_NOT_FOUND",
"message": "Cluster with ID 'k8s-prod-01' was not found in tenant 'tenant-production'.",
"status": 404,
"timestamp": "2026-09-28T12:00:00Z"
}
}