Skip to content

Update internal API docs from consumer audit - #5452

Merged
svkrieger merged 1 commit into
mainfrom
refine-internal-endpoint-docs
Sep 18, 2026
Merged

svkrieger merged 1 commit into
mainfrom
refine-internal-endpoint-docs

Conversation

@svkrieger

@svkrieger svkrieger commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

Add readiness_changed and rescheduling endpoints; fix consumer/auth fields for staging, log_access, asg_latest_update, tasks/completed, metrics, and buildpacks download; add auth-mechanism legend; flag dead-consumer endpoints as removal candidates.

  • I have reviewed the contributing guide

  • I have viewed, signed, and submitted the Contributor License Agreement

  • I have made this pull request to the main branch

  • I have run all the unit tests using bundle exec rake

  • I have run CF Acceptance Tests

@svkrieger
svkrieger force-pushed the refine-internal-endpoint-docs branch 2 times, most recently from 50929cb to 35a69e3 Compare September 16, 2026 13:52

@stephanme stephanme left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Maybe we add per endpoint a "Routing" info (internal=port 9023, external=port 9022) so that routing is not implicit from Auth.

In the future, I would move most internal endpoints to internal routing. The access check endpoints should not require external routing but still need OAuth.
The only exceptions should be the download endpoints for local blobstore (needed for staging container). For production (no local blobstore), all internal endpoints should use internal routing.

My comments about changing the url of internal endpoints is for discussion only. This PR documents the current setup.

Comment thread docs/internal/README.md Outdated
Comment thread docs/internal/README.md

### GET /v2/buildpacks/:guid/download
**Description:** Download a buildpack file
**Description:** Download a buildpack file. Note: this is a `/v2` public-namespace path (served on the public listener), not an `/internal/*` endpoint — its `download` action is exempt from user OAuth and gated by staging basic auth instead.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This also means: when CF API v2 is disabled, local blobstore is broken.

Future: I suggest to move this endpoint to either /staging/v2/buildpacks/:guid/download or /internal/v2/buildpacks/:guid/download

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, even though the scenario is very unlikely as local blobstore is a dev tool and we don't usually have a working Diego instance running when working locally anyways. But it makes sense to move it in the future as someone could potentially use a local blobstore in a full deployment.

Comment thread docs/internal/README.md
**Auth Mechanism:** mTLS
**Auth Mechanism:** Staging basic auth

### GET /staging/packages/:guid

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Future: I would move this endpoint to /internal/staging/packages/:guid or /internal//v2/staging/packages/:guid.
This makes clear that this is an internal API that can be changed/dropped at any point in time.

Add readiness_changed and rescheduling endpoints; fix consumer/auth
fields for staging, log_access, asg_latest_update, tasks/completed,
metrics, and buildpacks download; add auth-mechanism legend; flag
dead-consumer endpoints as removal candidates.
@svkrieger
svkrieger force-pushed the refine-internal-endpoint-docs branch from 35a69e3 to 7076af2 Compare September 17, 2026 09:06
@svkrieger
svkrieger merged commit c9c90a8 into main Sep 18, 2026
6 checks passed
@svkrieger
svkrieger deleted the refine-internal-endpoint-docs branch September 18, 2026 06:14
ari-wg-gitbot added a commit to cloudfoundry/capi-release that referenced this pull request Sep 18, 2026
Changes in cloud_controller_ng:

- Update internal API docs from consumer audit
    PR: cloudfoundry/cloud_controller_ng#5452
    Author: Sven Krieger <37476281+svkrieger@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants