From a54443ddc6be3220a39c46a1a4161eb94f41e79f Mon Sep 17 00:00:00 2001 From: Chandler Ortman Date: Thu, 19 Mar 2026 16:12:47 -0700 Subject: [PATCH 1/2] Update cloud-api protos to v0.12.0 --- crates/client/src/grpc.rs | 10 + .../common/protos/api_cloud_upstream/Makefile | 2 +- .../common/protos/api_cloud_upstream/VERSION | 2 +- .../protos/api_cloud_upstream/buf.gen.yaml | 1 + .../common/protos/api_cloud_upstream/buf.lock | 9 +- .../common/protos/api_cloud_upstream/buf.yaml | 1 + .../api/cloud/account/v1/message.proto | 36 + .../api/cloud/auditlog/v1/message.proto | 59 ++ .../api/cloud/billing/v1/message.proto | 67 ++ .../cloudservice/v1/request_response.proto | 139 ++++ .../api/cloud/cloudservice/v1/service.proto | 710 +++++++++++++++- .../api/cloud/namespace/v1/message.proto | 152 +++- .../options/annotations.proto | 51 ++ .../options/openapiv2.proto | 759 ++++++++++++++++++ crates/common/src/protos/mod.rs | 10 + 15 files changed, 1991 insertions(+), 17 deletions(-) create mode 100644 crates/common/protos/api_cloud_upstream/temporal/api/cloud/auditlog/v1/message.proto create mode 100644 crates/common/protos/api_cloud_upstream/temporal/api/cloud/billing/v1/message.proto create mode 100644 crates/common/protos/protoc-gen-openapiv2/options/annotations.proto create mode 100644 crates/common/protos/protoc-gen-openapiv2/options/openapiv2.proto diff --git a/crates/client/src/grpc.rs b/crates/client/src/grpc.rs index 5f49cbe39..f67524563 100644 --- a/crates/client/src/grpc.rs +++ b/crates/client/src/grpc.rs @@ -1680,6 +1680,16 @@ proxier! { (delete_connectivity_rule, cloudreq::DeleteConnectivityRuleRequest, cloudreq::DeleteConnectivityRuleResponse); (set_service_account_namespace_access, cloudreq::SetServiceAccountNamespaceAccessRequest, cloudreq::SetServiceAccountNamespaceAccessResponse); (validate_account_audit_log_sink, cloudreq::ValidateAccountAuditLogSinkRequest, cloudreq::ValidateAccountAuditLogSinkResponse); + (get_current_identity, cloudreq::GetCurrentIdentityRequest, cloudreq::GetCurrentIdentityResponse); + (get_audit_logs, cloudreq::GetAuditLogsRequest, cloudreq::GetAuditLogsResponse); + (create_account_audit_log_sink, cloudreq::CreateAccountAuditLogSinkRequest, cloudreq::CreateAccountAuditLogSinkResponse); + (get_account_audit_log_sink, cloudreq::GetAccountAuditLogSinkRequest, cloudreq::GetAccountAuditLogSinkResponse); + (get_account_audit_log_sinks, cloudreq::GetAccountAuditLogSinksRequest, cloudreq::GetAccountAuditLogSinksResponse); + (update_account_audit_log_sink, cloudreq::UpdateAccountAuditLogSinkRequest, cloudreq::UpdateAccountAuditLogSinkResponse); + (delete_account_audit_log_sink, cloudreq::DeleteAccountAuditLogSinkRequest, cloudreq::DeleteAccountAuditLogSinkResponse); + (get_namespace_capacity_info, cloudreq::GetNamespaceCapacityInfoRequest, cloudreq::GetNamespaceCapacityInfoResponse); + (create_billing_report, cloudreq::CreateBillingReportRequest, cloudreq::CreateBillingReportResponse); + (get_billing_report, cloudreq::GetBillingReportRequest, cloudreq::GetBillingReportResponse); } proxier! { diff --git a/crates/common/protos/api_cloud_upstream/Makefile b/crates/common/protos/api_cloud_upstream/Makefile index cf901cd14..cdc065215 100644 --- a/crates/common/protos/api_cloud_upstream/Makefile +++ b/crates/common/protos/api_cloud_upstream/Makefile @@ -42,7 +42,7 @@ grpc-install: openapiv2-install: printf $(COLOR) "Install/update openapiv2 protoc gen..." - go install github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2@v2.16.2 + go install github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2@v2.26.3 ##### Linters ##### buf-lint: diff --git a/crates/common/protos/api_cloud_upstream/VERSION b/crates/common/protos/api_cloud_upstream/VERSION index b19b52118..87a1cf595 100644 --- a/crates/common/protos/api_cloud_upstream/VERSION +++ b/crates/common/protos/api_cloud_upstream/VERSION @@ -1 +1 @@ -v0.8.0 +v0.12.0 diff --git a/crates/common/protos/api_cloud_upstream/buf.gen.yaml b/crates/common/protos/api_cloud_upstream/buf.gen.yaml index ea5bdf587..68c86b8dc 100644 --- a/crates/common/protos/api_cloud_upstream/buf.gen.yaml +++ b/crates/common/protos/api_cloud_upstream/buf.gen.yaml @@ -12,3 +12,4 @@ plugins: opt: - output_format=yaml - allow_delete_body + - disable_service_tags=true diff --git a/crates/common/protos/api_cloud_upstream/buf.lock b/crates/common/protos/api_cloud_upstream/buf.lock index 2fdf3c98c..b2a2b6e60 100644 --- a/crates/common/protos/api_cloud_upstream/buf.lock +++ b/crates/common/protos/api_cloud_upstream/buf.lock @@ -4,8 +4,13 @@ deps: - remote: buf.build owner: googleapis repository: googleapis - commit: e93e34f48be043dab55be31b4b47f458 - digest: shake256:93dbe51c27606999eef918360df509485a4d272e79aaed6d0016940379a9b06d316fc5228b7b50cca94bb310f34c5fc5955ce7474f655f0d0a224c4121dda3c1 + commit: 72c8614f3bd0466ea67931ef2c43d608 + digest: shake256:b3ac4d383db09f92ab0ca85d12bff8c49eddf7031bd3a854c260b6ac4ed6a2bb85b52b3393c316d28f8038bf3b8e70cb3d16470e8cc4423007678fb6d89d36d4 + - remote: buf.build + owner: grpc-ecosystem + repository: grpc-gateway + commit: 4c5ba75caaf84e928b7137ae5c18c26a + digest: shake256:e174ad9408f3e608f6157907153ffec8d310783ee354f821f57178ffbeeb8faa6bb70b41b61099c1783c82fe16210ebd1279bc9c9ee6da5cffba9f0e675b8b99 - remote: buf.build owner: temporalio repository: api diff --git a/crates/common/protos/api_cloud_upstream/buf.yaml b/crates/common/protos/api_cloud_upstream/buf.yaml index 90bbf2240..e80774c05 100644 --- a/crates/common/protos/api_cloud_upstream/buf.yaml +++ b/crates/common/protos/api_cloud_upstream/buf.yaml @@ -3,6 +3,7 @@ name: buf.build/temporalio/cloud-api deps: - buf.build/googleapis/googleapis - buf.build/temporalio/api:v1.43.0 + - buf.build/grpc-ecosystem/grpc-gateway:v2.26.3 breaking: use: diff --git a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/account/v1/message.proto b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/account/v1/message.proto index 5905f132e..56a1aef23 100644 --- a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/account/v1/message.proto +++ b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/account/v1/message.proto @@ -11,6 +11,7 @@ option csharp_namespace = "Temporalio.Api.Cloud.Account.V1"; import "temporal/api/cloud/resource/v1/message.proto"; import "temporal/api/cloud/sink/v1/message.proto"; +import "google/protobuf/timestamp.proto"; message MetricsSpec { // The ca cert(s) in PEM format that clients connecting to the metrics endpoint can use for authentication. @@ -62,3 +63,38 @@ message AuditLogSinkSpec { // Enabled indicates whether the sink is enabled or not. bool enabled = 4; } + +// AuditLogSink is only used by Audit Log +message AuditLogSink { + // Name of the sink e.g. "audit_log_01" + string name = 1; + + // The version of the audit log sink resource. + string resource_version = 2; + + // The current state of the audit log sink. + temporal.api.cloud.resource.v1.ResourceState state = 3; + + // The specification details of the audit log sink. + AuditLogSinkSpec spec = 4; + + // The health status of the audit log sink. + Health health = 5; + + // An error message describing any issues with the audit log sink, if applicable. + string error_message = 6; + + // The last succeeded timestamp for the internal workflow responsible for adding data to the sink. + google.protobuf.Timestamp last_succeeded_time = 7; + + // The health status of the audit log sink. + enum Health { + HEALTH_UNSPECIFIED = 0; + // The audit log sink is healthy and functioning correctly. + HEALTH_OK = 1; + // The audit log sink has an internal error. + HEALTH_ERROR_INTERNAL = 2; + // The audit log sink has a configuration error. + HEALTH_ERROR_USER_CONFIGURATION = 3; + } +} diff --git a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/auditlog/v1/message.proto b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/auditlog/v1/message.proto new file mode 100644 index 000000000..991dda2eb --- /dev/null +++ b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/auditlog/v1/message.proto @@ -0,0 +1,59 @@ +syntax = "proto3"; + +package temporal.api.cloud.auditlog.v1; + +option go_package = "go.temporal.io/api/cloud/auditlog/v1;auditlog"; +option java_package = "io.temporal.api.cloud.auditlog.v1"; +option java_multiple_files = true; +option java_outer_classname = "MessageProto"; +option ruby_package = "Temporalio::Api::Cloud::AuditLog::V1"; +option csharp_namespace = "Temporalio.Api.Cloud.AuditLog.V1"; + +import "google/protobuf/timestamp.proto"; +import "google/protobuf/struct.proto"; + +// LogRecord represents an audit log entry from Temporal, structured for easy parsing and analysis. +message LogRecord { + // Time when the log was emitted. + google.protobuf.Timestamp emit_time = 1; + + // The operation performed. + string operation = 5; + + // The status of the operation. + string status = 7; + + // The internal version of the log message. Can be used in deduplication if needed. + int32 version = 9; + + // Unique ID for the log record. + string log_id = 10; + + // The principal that performed the operation. + Principal principal = 12; + + // The raw details of the operation. + google.protobuf.Struct raw_details = 13; + + // The originating IP address of the request. + string x_forwarded_for = 14; + + // The ID of the async operation. + string async_operation_id = 15; +} + +message Principal { + // The type of the principal. + // Possible type values: user, serviceaccount. + string type = 1; + + // The id of the principal. + string id = 2; + + // The name of the principal. + string name = 3; + + // The api key id of the principal if provided. + string api_key_id = 4; +} + diff --git a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/billing/v1/message.proto b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/billing/v1/message.proto new file mode 100644 index 000000000..3d1888847 --- /dev/null +++ b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/billing/v1/message.proto @@ -0,0 +1,67 @@ +syntax = "proto3"; + +package temporal.api.cloud.billing.v1; + +option go_package = "go.temporal.io/api/cloud/billing/v1;billing"; +option java_package = "io.temporal.api.cloud.billing.v1"; +option java_multiple_files = true; +option java_outer_classname = "MessageProto"; +option ruby_package = "Temporalio::Api::Cloud::Billing::V1"; +option csharp_namespace = "Temporalio.Api.Cloud.Billing.V1"; + +import "google/protobuf/duration.proto"; +import "google/protobuf/timestamp.proto"; + +message BillingReportSpec { + // The start time of the billing report (in UTC). + google.protobuf.Timestamp start_time_inclusive = 1; + // The end time of the billing report (in UTC). + google.protobuf.Timestamp end_time_exclusive = 2; + // The duration after which the download url will expire. + // Optional, default is 5 minutes and maximum is 1 hour. + google.protobuf.Duration download_url_expiration_duration = 3; + // The description for the billing report. + // Optional, default is empty. + string description = 4; +} + +message BillingReport { + // The id of the billing report. + string id = 1; + // The current state of the billing report. + BillingReportState state = 2; + // The spec used to generate this billing report. + BillingReportSpec spec = 3; + // The download information for the billing report. + // For future-proofness this is repeated as we may return multiple files (e.g. csv+meta/json, split by size/date, etc.) + repeated Download download_info = 4; + // The date and time when the billing report was requested. + google.protobuf.Timestamp requested_time = 5; + // The date and time when the billing report generation completed. + google.protobuf.Timestamp generated_time = 6; + // The async operation id associated with the billing report generation. + string async_operation_id = 7; + + message Download { + // The download url. + string url = 1; + // The time when the download url will expire. + google.protobuf.Timestamp url_expiration_time = 2; + // The file format of the billing report + FileFormat file_format = 3; + // The size of the file in bytes. Useful for pre-allocating space, progress indicators, etc. + int64 file_size_bytes = 4; + + enum FileFormat { + FILE_FORMAT_UNSPECIFIED = 0; + FILE_FORMAT_CSV = 1; + } + } + + enum BillingReportState { + BILLING_REPORT_STATE_UNSPECIFIED = 0; + BILLING_REPORT_STATE_IN_PROGRESS = 1; + BILLING_REPORT_STATE_GENERATED = 2; + BILLING_REPORT_STATE_FAILED = 3; + } +} \ No newline at end of file diff --git a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/request_response.proto b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/request_response.proto index e769473a2..e9815dab9 100644 --- a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/request_response.proto +++ b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/request_response.proto @@ -19,6 +19,23 @@ import "temporal/api/cloud/region/v1/message.proto"; import "temporal/api/cloud/account/v1/message.proto"; import "temporal/api/cloud/usage/v1/message.proto"; import "temporal/api/cloud/connectivityrule/v1/message.proto"; +import "temporal/api/cloud/auditlog/v1/message.proto"; +import "temporal/api/cloud/billing/v1/message.proto"; + +message GetCurrentIdentityRequest { +} + +message GetCurrentIdentityResponse { + // The authenticated principal making the request + oneof principal { + // The user is a regular user + temporal.api.cloud.identity.v1.User user = 1; + // The user is a service account + temporal.api.cloud.identity.v1.ServiceAccount service_account = 2; + } + // The API key info used to authenticate the request, if any + temporal.api.cloud.identity.v1.ApiKey principal_api_key = 3; +} message GetUsersRequest { // The requested size of the page to retrieve - optional. @@ -307,6 +324,7 @@ message GetApiKeysRequest { string owner_id = 3; // Filter api keys by owner type - optional. // Possible values: user, service-account + // temporal:versioning:max_version=v0.3.0 string owner_type_deprecated = 4 [deprecated = true]; // Filter api keys by owner type - optional. // temporal:enums:replaces=owner_type_deprecated @@ -948,6 +966,25 @@ message DeleteConnectivityRuleResponse { temporal.api.cloud.operation.v1.AsyncOperation async_operation = 1; } +message GetAuditLogsRequest { + // The requested size of the page to retrieve - optional. + // Cannot exceed 1000. Defaults to 100. + int32 page_size = 1; + // The page token if this is continuing from another response - optional. + string page_token = 2; + // Filter for UTC time >= (defaults to 30 days ago) - optional. + google.protobuf.Timestamp start_time_inclusive = 3; + // Filter for UTC time < (defaults to current time) - optional. + google.protobuf.Timestamp end_time_exclusive = 4; +} + +message GetAuditLogsResponse { + // The list of audit logs ordered by emit time, log_id + repeated temporal.api.cloud.auditlog.v1.LogRecord logs = 1; + // The next page's token. + string next_page_token = 2; +} + message ValidateAccountAuditLogSinkRequest { // The audit log sink spec that will be validated temporal.api.cloud.account.v1.AuditLogSinkSpec spec = 1; @@ -955,3 +992,105 @@ message ValidateAccountAuditLogSinkRequest { message ValidateAccountAuditLogSinkResponse { } + +message CreateAccountAuditLogSinkRequest { + // The specification for the audit log sink. + temporal.api.cloud.account.v1.AuditLogSinkSpec spec = 1; + // Optional. The ID to use for this async operation. + string async_operation_id = 2; +} + +message CreateAccountAuditLogSinkResponse { + // The async operation. + temporal.api.cloud.operation.v1.AsyncOperation async_operation = 1; +} + +message GetAccountAuditLogSinkRequest { + // The name of the sink to retrieve. + string name = 1; +} + +message GetAccountAuditLogSinkResponse { + // The audit log sink retrieved. + temporal.api.cloud.account.v1.AuditLogSink sink = 1; +} + +message GetAccountAuditLogSinksRequest { + // The requested size of the page to retrieve. Cannot exceed 1000. + // Defaults to 100 if not specified. + int32 page_size = 1; + // The page token if this is continuing from another response - optional. + string page_token = 2; +} + +message GetAccountAuditLogSinksResponse { + // The list of audit log sinks retrieved. + repeated temporal.api.cloud.account.v1.AuditLogSink sinks = 1; + // The next page token, set if there is another page. + string next_page_token = 2; +} + +message UpdateAccountAuditLogSinkRequest { + // The updated audit log sink specification. + temporal.api.cloud.account.v1.AuditLogSinkSpec spec = 1; + // The version of the audit log sink to update. The latest version can be + // retrieved using the GetAuditLogSink call. + string resource_version = 2; + // The ID to use for this async operation - optional. + string async_operation_id = 3; +} + +message UpdateAccountAuditLogSinkResponse { + // The async operation. + temporal.api.cloud.operation.v1.AsyncOperation async_operation = 1; +} + +message DeleteAccountAuditLogSinkRequest { + // The name of the sink to delete. + string name = 1; + // The version of the sink to delete. The latest version can be + // retrieved using the GetAccountAuditLogSink call. + string resource_version = 2; + // The ID to use for this async operation - optional. + string async_operation_id = 3; +} + +message DeleteAccountAuditLogSinkResponse { + // The async operation. + temporal.api.cloud.operation.v1.AsyncOperation async_operation = 1; +} + +message GetNamespaceCapacityInfoRequest { + // The namespace identifier. + // Required. + string namespace = 1; +} + +message GetNamespaceCapacityInfoResponse { + // Capacity information for the namespace. + temporal.api.cloud.namespace.v1.NamespaceCapacityInfo capacity_info = 1; +} + +message CreateBillingReportRequest { + // The specification for the billing report. + temporal.api.cloud.billing.v1.BillingReportSpec spec = 1; + // Optional, if not provided a random id will be generated. + string async_operation_id = 2; +} + +message CreateBillingReportResponse { + // The id of the billing report created. + string billing_report_id = 1; + // The async operation. + temporal.api.cloud.operation.v1.AsyncOperation async_operation = 2; +} + +message GetBillingReportRequest { + // The id of the billing report to retrieve. + string billing_report_id = 1; +} + +message GetBillingReportResponse { + // The billing report retrieved. + temporal.api.cloud.billing.v1.BillingReport billing_report = 1; +} \ No newline at end of file diff --git a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/service.proto b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/service.proto index 2d1eabaf1..d65c95853 100644 --- a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/service.proto +++ b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/cloudservice/v1/service.proto @@ -11,15 +11,78 @@ option csharp_namespace = "Temporalio.Api.Cloud.CloudService.V1"; import "temporal/api/cloud/cloudservice/v1/request_response.proto"; import "google/api/annotations.proto"; +import "protoc-gen-openapiv2/options/annotations.proto"; + +option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_swagger) = { + info: { + title: "Temporal Cloud Ops API"; + description: "Programmatic access to manage Temporal Cloud control plane resources including namespaces, users, service accounts, and more.\n\n## Authentication\n\nAll API requests require authentication using an API Key. Include your API key in the `Authorization` header using the Bearer scheme:\n\n```\nAuthorization: Bearer YOUR_API_KEY\n```\n\nAPI keys can be created and managed through the [API Keys endpoints](#tag/API-Keys) or via the Temporal Cloud UI. For more information, see [API Keys Documentation](https://docs.temporal.io/cloud/api-keys).\n\n## Authorization\n\nThe API uses Role-Based Access Control (RBAC) to manage permissions. Each operation requires specific role-based permissions in addition to a valid API key.\n\n### Account-Level Roles\n\n- **Account Owner** - Full account administration access\n- **Account Admin** - Manage namespaces, users, and service accounts \n- **Account Developer** - Create namespaces and manage Nexus endpoints\n- **Finance Admin** - View usage and billing information\n- **Account Read** - Read-only access to account resources\n\n### Namespace-Level Roles\n\n- **Namespace Admin** - Full access to namespace configuration and data\n- **Namespace Write** - Execute workflows and modify workflow data\n- **Namespace Read** - Read-only access to namespace data\n\nNamespace-level permissions are scoped to specific namespaces. A user or service account may have different permission levels across different namespaces.\n\nFor detailed information about roles and permissions, see [Access Control Documentation](https://docs.temporal.io/cloud/users)."; + version: "1.0"; + extensions: { + key: "x-logo"; + value: { + struct_value: { + fields: { + key: "url"; + value: { + string_value: "https://images.ctfassets.net/0uuz8ydxyd9p/4YGUnEoCaH9SyoUDhlJkau/e1600205d17eeee3033d926ef06664a9/Temporal_LogoLockup_Horizontal_dark_1.svg"; + } + } + } + } + } + }; + external_docs: { + url: "https://docs.temporal.io/cloud"; + description: "Temporal Cloud Documentation"; + }; + tags: [ + {name: "Namespaces"; description: "Manage Temporal Cloud namespaces"}, + {name: "Users"; description: "Manage users and their namespace access"}, + {name: "Service Accounts"; description: "Manage service accounts and their namespace access"}, + {name: "API Keys"; description: "Manage API keys for authentication"}, + {name: "Groups"; description: "Manage user groups and group membership"}, + {name: "Nexus"; description: "Manage Nexus endpoints"}, + {name: "High Availability"; description: "Manage high availability (multi-region, multi-cloud, and same-region replication) namespace configurations"}, + {name: "Export"; description: "Manage workflow history export configurations"}, + {name: "Connectivity Rules"; description: "Manage network connectivity rules"}, + {name: "Regions"; description: "Query available regions"}, + {name: "Account"; description: "Manage account settings and usage"}, + {name: "Operations"; description: "Query async operation status"} + ]; +}; // WARNING: This service is currently experimental and may change in // incompatible ways. service CloudService { + + // Get information about the current authenticated user or service account principal + rpc GetCurrentIdentity(GetCurrentIdentityRequest) returns (GetCurrentIdentityResponse) { + option (google.api.http) = { + get: "/cloud/current-identity", + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Get current identity"; + description: "Returns information about the currently authenticated user or service account principal"; + }; + } + // Gets all known users rpc GetUsers(GetUsersRequest) returns (GetUsersResponse) { option (google.api.http) = { get: "/cloud/users", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Users"]; + summary: "List all users"; + description: "Returns a list of all users in the account"; + operation_id: "listUsers"; + external_docs: { + url: "https://docs.temporal.io/cloud/users"; + description: "User management documentation"; + }; + }; } // Get a user @@ -27,6 +90,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/users/{user_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Users"]; + summary: "Get user by ID"; + description: "Takes a user ID, returns user details"; + external_docs: { + url: "https://docs.temporal.io/cloud/users"; + description: "User management documentation"; + }; + }; } // Create a user @@ -35,6 +107,11 @@ service CloudService { post: "/cloud/users", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Users"]; + summary: "Create a user"; + description: "Creates a new user in the account"; + }; } // Update a user @@ -43,6 +120,11 @@ service CloudService { post: "/cloud/users/{user_id}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Users"]; + summary: "Update a user"; + description: "Updates an existing user's details"; + }; } // Delete a user @@ -50,6 +132,11 @@ service CloudService { option (google.api.http) = { delete: "/cloud/users/{user_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Users"]; + summary: "Delete a user"; + description: "Removes a user from the account"; + }; } // Set a user's access to a namespace @@ -58,6 +145,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/users/{user_id}/access", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Users"]; + summary: "Set user namespace access"; + description: "Configures a user's permissions for a specific namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/users-namespace-level-permissions"; + description: "Namespace permissions documentation"; + }; + }; } // Get the latest information on an async operation @@ -65,6 +161,11 @@ service CloudService { option (google.api.http) = { get: "/cloud/operations/{async_operation_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Operations"]; + summary: "Get async operation status"; + description: "Returns the current status and details of an asynchronous operation"; + }; } // Create a new namespace @@ -73,6 +174,15 @@ service CloudService { post: "/cloud/namespaces", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Create a namespace"; + description: "Creates a new namespace in the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/namespaces"; + description: "Namespace management documentation"; + }; + }; } // Get all namespaces @@ -80,6 +190,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/namespaces", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "List all namespaces"; + description: "Returns a list of all namespaces in the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/namespaces"; + description: "Namespace management documentation"; + }; + }; } // Get a namespace @@ -87,6 +206,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/namespaces/{namespace}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Get namespace details"; + description: "Returns detailed information about a specific namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/namespaces"; + description: "Namespace management documentation"; + }; + }; } // Update a namespace @@ -95,6 +223,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Update a namespace"; + description: "Updates configuration for an existing namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/namespaces"; + description: "Namespace management documentation"; + }; + }; } // Rename an existing customer search attribute @@ -103,6 +240,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/rename-custom-search-attribute", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Rename custom search attribute"; + description: "Renames a custom search attribute in a namespace"; + external_docs: { + url: "https://docs.temporal.io/search-attribute#custom-search-attribute"; + description: "Custom Search Attributes documentation"; + }; + }; } // Delete a namespace @@ -110,6 +256,15 @@ service CloudService { option (google.api.http) = { delete: "/cloud/namespaces/{namespace}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Delete a namespace"; + description: "Permanently deletes a namespace and all its data"; + external_docs: { + url: "https://docs.temporal.io/cloud/namespaces"; + description: "Namespace management documentation"; + }; + }; } // Failover a multi-region namespace @@ -118,6 +273,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/failover-region", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["High Availability"]; + summary: "Failover namespace region"; + description: "Initiates a regional failover for a high availability namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/high-availability"; + description: "High availability namespace documentation"; + }; + }; } // Add a new region to a namespace @@ -126,6 +290,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/add-region", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["High Availability"]; + summary: "Add namespace replica"; + description: "Adds a new replica to an existing namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/high-availability"; + description: "High availability namespace documentation"; + }; + }; } // Delete a region from a namespace @@ -133,6 +306,15 @@ service CloudService { option (google.api.http) = { delete: "/cloud/namespaces/{namespace}/regions/{region}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["High Availability"]; + summary: "Remove namespace replica"; + description: "Removes a replica from a high availability namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/high-availability"; + description: "High availability namespace documentation"; + }; + }; } // Get all regions @@ -140,6 +322,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/regions", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Regions"]; + summary: "List all regions"; + description: "Returns a list of all available cloud regions"; + external_docs: { + url: "https://docs.temporal.io/cloud/regions"; + description: "Regions documentation"; + }; + }; } // Get a region @@ -147,6 +338,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/regions/{region}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Regions"]; + summary: "Get region details"; + description: "Returns detailed information about a specific region"; + external_docs: { + url: "https://docs.temporal.io/cloud/regions"; + description: "Regions documentation"; + }; + }; } // Get all known API keys @@ -154,6 +354,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/api-keys", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["API Keys"]; + summary: "List all API keys"; + description: "Returns a list of all API keys in the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/api-keys"; + description: "API Keys documentation"; + }; + }; } // Get an API key @@ -161,6 +370,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/api-keys/{key_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["API Keys"]; + summary: "Get API key details"; + description: "Returns detailed information about a specific API key"; + external_docs: { + url: "https://docs.temporal.io/cloud/api-keys"; + description: "API Keys documentation"; + }; + }; } // Create an API key @@ -169,6 +387,15 @@ service CloudService { post: "/cloud/api-keys", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["API Keys"]; + summary: "Create an API key"; + description: "Creates a new API key for programmatic access"; + external_docs: { + url: "https://docs.temporal.io/cloud/api-keys"; + description: "API Keys documentation"; + }; + }; } // Update an API key @@ -177,6 +404,15 @@ service CloudService { post: "/cloud/api-keys/{key_id}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["API Keys"]; + summary: "Update an API key"; + description: "Updates an existing API key's properties"; + external_docs: { + url: "https://docs.temporal.io/cloud/api-keys"; + description: "API Keys documentation"; + }; + }; } // Delete an API key @@ -184,6 +420,15 @@ service CloudService { option (google.api.http) = { delete: "/cloud/api-keys/{key_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["API Keys"]; + summary: "Delete an API key"; + description: "Revokes and deletes an API key"; + external_docs: { + url: "https://docs.temporal.io/cloud/api-keys"; + description: "API Keys documentation"; + }; + }; } // Gets nexus endpoints @@ -191,6 +436,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/nexus/endpoints", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Nexus"]; + summary: "List all Nexus endpoints"; + description: "Returns a list of all Nexus endpoints in the account"; + external_docs: { + url: "https://docs.temporal.io/nexus"; + description: "Nexus documentation"; + }; + }; } // Get a nexus endpoint @@ -198,6 +452,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/nexus/endpoints/{endpoint_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Nexus"]; + summary: "Get Nexus endpoint details"; + description: "Returns detailed information about a specific Nexus endpoint"; + external_docs: { + url: "https://docs.temporal.io/nexus"; + description: "Nexus documentation"; + }; + }; } // Create a nexus endpoint @@ -206,6 +469,15 @@ service CloudService { post: "/cloud/nexus/endpoints", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Nexus"]; + summary: "Create a Nexus endpoint"; + description: "Creates a new Nexus endpoint for cross-namespace communication"; + external_docs: { + url: "https://docs.temporal.io/nexus"; + description: "Nexus documentation"; + }; + }; } // Update a nexus endpoint @@ -214,6 +486,15 @@ service CloudService { post: "/cloud/nexus/endpoints/{endpoint_id}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Nexus"]; + summary: "Update a Nexus endpoint"; + description: "Updates an existing Nexus endpoint's configuration"; + external_docs: { + url: "https://docs.temporal.io/nexus"; + description: "Nexus documentation"; + }; + }; } // Delete a nexus endpoint @@ -221,6 +502,15 @@ service CloudService { option (google.api.http) = { delete: "/cloud/nexus/endpoints/{endpoint_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Nexus"]; + summary: "Delete a Nexus endpoint"; + description: "Removes a Nexus endpoint from the account"; + external_docs: { + url: "https://docs.temporal.io/nexus"; + description: "Nexus documentation"; + }; + }; } // Get all user groups @@ -228,6 +518,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/user-groups", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "List all user groups"; + description: "Returns a list of all user groups in the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/users-account-level-roles"; + description: "User groups documentation"; + }; + }; } // Get a user group @@ -235,6 +534,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/user-groups/{group_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Get user group details"; + description: "Returns detailed information about a specific user group"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Create new a user group @@ -243,6 +551,15 @@ service CloudService { post: "/cloud/user-groups", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Create a user group"; + description: "Creates a new user group for managing permissions"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Update a user group @@ -251,6 +568,15 @@ service CloudService { post: "/cloud/user-groups/{group_id}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Update a user group"; + description: "Updates an existing user group's properties"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Delete a user group @@ -258,6 +584,15 @@ service CloudService { option (google.api.http) = { delete: "/cloud/user-groups/{group_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Delete a user group"; + description: "Removes a user group from the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Set a user group's access to a namespace @@ -266,6 +601,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/user-groups/{group_id}/access", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Set user group namespace access"; + description: "Configures a user group's permissions for a specific namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Add a member to the group, can only be used with Cloud group types. @@ -274,6 +618,15 @@ service CloudService { post: "/cloud/user-groups/{group_id}/members", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Add user to group"; + description: "Adds a user to a user group (Cloud groups only)"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Remove a member from the group, can only be used with Cloud group types. @@ -282,12 +635,30 @@ service CloudService { post: "/cloud/user-groups/{group_id}/remove-member", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "Remove user from group"; + description: "Removes a user from a user group (Cloud groups only)"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } rpc GetUserGroupMembers(GetUserGroupMembersRequest) returns (GetUserGroupMembersResponse) { option (google.api.http) = { get: "/cloud/user-groups/{group_id}/members", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Groups"]; + summary: "List users in a group"; + description: "Returns a list of all users in a user group"; + external_docs: { + url: "https://docs.temporal.io/cloud/user-groups"; + description: "User groups documentation"; + }; + }; } // Create a service account. @@ -296,6 +667,15 @@ service CloudService { post: "/cloud/service-accounts", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Service Accounts"]; + summary: "Create a service account"; + description: "Creates a new service account for automated access"; + external_docs: { + url: "https://docs.temporal.io/cloud/service-accounts"; + description: "Service Accounts documentation"; + }; + }; } // Get a service account. @@ -303,6 +683,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/service-accounts/{service_account_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Service Accounts"]; + summary: "Get service account details"; + description: "Returns detailed information about a specific service account"; + external_docs: { + url: "https://docs.temporal.io/cloud/service-accounts"; + description: "Service Accounts documentation"; + }; + }; } // Get service accounts. @@ -310,6 +699,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/service-accounts", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Service Accounts"]; + summary: "List all service accounts"; + description: "Returns a list of all service accounts in the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/service-accounts"; + description: "Service Accounts documentation"; + }; + }; } // Update a service account. @@ -318,6 +716,15 @@ service CloudService { post: "/cloud/service-accounts/{service_account_id}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Service Accounts"]; + summary: "Update a service account"; + description: "Updates an existing service account's properties"; + external_docs: { + url: "https://docs.temporal.io/cloud/service-accounts"; + description: "Service Accounts documentation"; + }; + }; } // Set a service account's access to a namespace. @@ -326,6 +733,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/service-accounts/{service_account_id}/access", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Service Accounts"]; + summary: "Set service account namespace access"; + description: "Configures a service account's permissions for a specific namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/service-accounts"; + description: "Service Accounts documentation"; + }; + }; } // Delete a service account. @@ -333,6 +749,15 @@ service CloudService { option (google.api.http) = { delete: "/cloud/service-accounts/{service_account_id}", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Service Accounts"]; + summary: "Delete a service account"; + description: "Removes a service account from the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/service-accounts"; + description: "Service Accounts documentation"; + }; + }; } // WARNING: Pre-Release Feature @@ -341,6 +766,12 @@ service CloudService { option (google.api.http) = { get: "/cloud/usage", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Get usage data"; + description: "Get usage data across namespaces"; + deprecated: true; + }; } // Get account information. @@ -348,6 +779,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/account", }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Get account details"; + description: "Returns detailed information about the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/billing-and-cost"; + description: "Billing documentation"; + }; + }; } // Update account information. @@ -355,7 +795,16 @@ service CloudService { option (google.api.http) = { post: "/cloud/account", body: "*" - }; + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Update account details"; + description: "Updates account configuration and settings"; + external_docs: { + url: "https://docs.temporal.io/cloud/billing-and-cost"; + description: "Billing documentation"; + }; + }; } // Create an export sink @@ -364,6 +813,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/export-sinks", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Export"]; + summary: "Create history export sink"; + description: "Creates a new workflow history export sink"; + external_docs: { + url: "https://docs.temporal.io/cloud/export"; + description: "Export documentation"; + }; + }; } // Get an export sink @@ -371,6 +829,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/namespaces/{namespace}/export-sinks/{name}" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Export"]; + summary: "Get history sink details"; + description: "Returns detailed information about a specific workflow history export sink"; + external_docs: { + url: "https://docs.temporal.io/cloud/export"; + description: "Export documentation"; + }; + }; } // Get export sinks @@ -378,6 +845,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/namespaces/{namespace}/export-sinks" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Export"]; + summary: "List history export sinks"; + description: "Returns a list of all workflow history export sinks for a namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/export"; + description: "Export documentation"; + }; + }; } // Update an export sink @@ -386,6 +862,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/export-sinks/{spec.name}", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Export"]; + summary: "Update history export sink"; + description: "Updates an existing workflow history export sink's configuration"; + external_docs: { + url: "https://docs.temporal.io/cloud/export"; + description: "Export documentation"; + }; + }; } // Delete an export sink @@ -393,15 +878,33 @@ service CloudService { option (google.api.http) = { delete: "/cloud/namespaces/{namespace}/export-sinks/{name}" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Export"]; + summary: "Delete history export sink"; + description: "Removes a workflow history export sink from a namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/export"; + description: "Export documentation"; + }; + }; } // Validates an export sink configuration by delivering an empty test file to the specified sink. // This operation verifies that the sink is correctly configured, accessible, and ready for data export. rpc ValidateNamespaceExportSink(ValidateNamespaceExportSinkRequest) returns (ValidateNamespaceExportSinkResponse) { option (google.api.http) = { - post: "/cloud/namespaces/{namespace}/export-sinks/validate", + post: "/cloud/namespaces/{namespace}/export-sink-validate", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Export"]; + summary: "Validate history export sink configuration"; + description: "Tests workflow history export sink configuration by delivering a test file to verify accessibility"; + external_docs: { + url: "https://docs.temporal.io/cloud/export"; + description: "Export documentation"; + }; + }; } // Update the tags for a namespace @@ -410,6 +913,15 @@ service CloudService { post: "/cloud/namespaces/{namespace}/update-tags" body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Update namespace tags"; + description: "Updates the tags associated with a namespace"; + external_docs: { + url: "https://docs.temporal.io/cloud/namespaces#tag-a-namespace"; + description: "Namespace tag documentation"; + }; + }; } // Creates a connectivity rule @@ -418,6 +930,15 @@ service CloudService { post: "/cloud/connectivity-rules" body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Connectivity Rules"]; + summary: "Create connectivity rule"; + description: "Creates a new connectivity rule for network access control"; + external_docs: { + url: "https://docs.temporal.io/cloud/connectivity"; + description: "Connectivity documentation"; + }; + }; } // Gets a connectivity rule by id @@ -425,6 +946,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/connectivity-rules/{connectivity_rule_id}" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Connectivity Rules"]; + summary: "Get connectivity rule details"; + description: "Returns detailed information about a specific connectivity rule"; + external_docs: { + url: "https://docs.temporal.io/cloud/connectivity"; + description: "Connectivity documentation"; + }; + }; } // Lists connectivity rules by account @@ -432,6 +962,15 @@ service CloudService { option (google.api.http) = { get: "/cloud/connectivity-rules" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Connectivity Rules"]; + summary: "List all connectivity rules"; + description: "Returns a list of all connectivity rules in the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/connectivity"; + description: "Connectivity documentation"; + }; + }; } // Deletes a connectivity rule by id @@ -439,14 +978,179 @@ service CloudService { option (google.api.http) = { delete: "/cloud/connectivity-rules/{connectivity_rule_id}" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Connectivity Rules"]; + summary: "Delete connectivity rule"; + description: "Removes a connectivity rule from the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/connectivity"; + description: "Connectivity documentation"; + }; + }; + } + + // Get audit logs + rpc GetAuditLogs(GetAuditLogsRequest) returns (GetAuditLogsResponse) { + option (google.api.http) = { + get: "/cloud/audit-logs", + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Get audit logs" + description: "Returns a paginated list of audit logs for the account, optionally filtered by time range" + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; } // Validate customer audit log sink is accessible from Temporal's workflow by delivering an empty file to the specified sink. // The operation verifies that the sink is correctly configured, accessible and ready to receive audit logs. rpc ValidateAccountAuditLogSink(ValidateAccountAuditLogSinkRequest) returns (ValidateAccountAuditLogSinkResponse) { option (google.api.http) = { - post: "/cloud/account/audit-logs/sink/validate", + post: "/cloud/audit-log-sink-validate", body: "*" }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Validate audit log sink" + description: "Validate customer audit log sink is accessible from Temporal's workflow by delivering an empty file to the specified sink. The operation verifies that the sink is correctly configured, accessible and ready to receive audit logs." + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; + } + + // Create an audit log sink + rpc CreateAccountAuditLogSink(CreateAccountAuditLogSinkRequest) returns (CreateAccountAuditLogSinkResponse) { + option (google.api.http) = { + post: "/cloud/audit-log-sinks", + body: "*" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Create audit log sink"; + description: "Creates a new audit log sink for exporting audit logs"; + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; + } + + // Get an audit log sink + rpc GetAccountAuditLogSink(GetAccountAuditLogSinkRequest) returns (GetAccountAuditLogSinkResponse) { + option (google.api.http) = { + get: "/cloud/audit-log-sinks/{name}" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Get audit log sink details"; + description: "Returns detailed information about a specific audit log sink"; + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; + } + + // Get audit log sinks + rpc GetAccountAuditLogSinks(GetAccountAuditLogSinksRequest) returns (GetAccountAuditLogSinksResponse) { + option (google.api.http) = { + get: "/cloud/audit-log-sinks" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "List audit log sinks"; + description: "Returns a list of all audit log sinks for the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; + } + + // Update an audit log sink + rpc UpdateAccountAuditLogSink(UpdateAccountAuditLogSinkRequest) returns (UpdateAccountAuditLogSinkResponse) { + option (google.api.http) = { + post: "/cloud/audit-log-sinks/{spec.name}", + body: "*" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Update audit log sink"; + description: "Updates an existing audit log sink's configuration"; + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; + } + + // Delete an audit log sink + rpc DeleteAccountAuditLogSink(DeleteAccountAuditLogSinkRequest) returns (DeleteAccountAuditLogSinkResponse) { + option (google.api.http) = { + delete: "/cloud/audit-log-sinks/{name}" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Delete audit log sink"; + description: "Removes an audit log sink from the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/audit-logging"; + description: "Audit logging documentation"; + }; + }; + } + + // Get namespace capacity information + rpc GetNamespaceCapacityInfo(GetNamespaceCapacityInfoRequest) returns (GetNamespaceCapacityInfoResponse) { + option (google.api.http) = { + get: "/cloud/namespaces/{namespace}/capacity-info" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Namespaces"]; + summary: "Get namespace capacity information"; + description: "Returns capacity information for a namespace. This includes provisioned capacity options, on-demand limits, and 7 day historical APS statistics useful for capacity planning."; + external_docs: { + url: "https://docs.temporal.io/cloud/capacity-modes"; + description: "Capacity modes information documentation"; + }; + }; + } + + // Create a billing report + rpc CreateBillingReport(CreateBillingReportRequest) returns (CreateBillingReportResponse) { + option (google.api.http) = { + post: "/cloud/billing-reports" + body: "*" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Create a billing report"; + description: "Creates a billing report for the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/billing-reports"; + description: "Billing report documentation"; + }; + }; + } + + // Get a billing report + rpc GetBillingReport(GetBillingReportRequest) returns (GetBillingReportResponse) { + option (google.api.http) = { + get: "/cloud/billing-reports/{billing_report_id}" + }; + option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { + tags: ["Account"]; + summary: "Get a billing report"; + description: "Gets an existing billing report for the account"; + external_docs: { + url: "https://docs.temporal.io/cloud/billing-reports"; + description: "Billing report documentation"; + }; + }; } } diff --git a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/namespace/v1/message.proto b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/namespace/v1/message.proto index e441bdb1f..0080a0e5a 100644 --- a/crates/common/protos/api_cloud_upstream/temporal/api/cloud/namespace/v1/message.proto +++ b/crates/common/protos/api_cloud_upstream/temporal/api/cloud/namespace/v1/message.proto @@ -36,7 +36,7 @@ message MtlsAuthSpec { // (-- api-linter: core::0140::base64=disabled --) // Deprecated: Not supported after v0.2.0 api version. Use accepted_client_ca instead. // temporal:versioning:max_version=v0.2.0 - string accepted_client_ca_deprecated = 1; + string accepted_client_ca_deprecated = 1 [deprecated = true]; // The ca cert(s) in PEM format that the clients can use for authentication and authorization. // This must only be one value, but the CA can have a chain. // temporal:versioning:min_version=v0.2.0 @@ -57,6 +57,11 @@ message ApiKeyAuthSpec { bool enabled = 1; } +message LifecycleSpec { + // Flag to enable delete protection for the namespace. + bool enable_delete_protection = 1; +} + message CodecServerSpec { // The codec server endpoint. string endpoint = 1; @@ -81,16 +86,72 @@ message CodecServerSpec { } } -message LifecycleSpec { - // Flag to enable delete protection for the namespace. - bool enable_delete_protection = 1; -} - message HighAvailabilitySpec { // Flag to disable managed failover for the namespace. bool disable_managed_failover = 1; } + +// temporal:versioning:min_version=v0.10.0 +message CapacitySpec { + oneof spec { + // The on-demand capacity mode configuration. + OnDemand on_demand = 1; + // The provisioned capacity mode configuration. + Provisioned provisioned = 2; + } + + message OnDemand { + } + + message Provisioned { + // The units of provisioned capacity in TRU (Temporal Resource Units). + // Each TRU unit assigned to the namespace will entitle it with additional APS limits as specified in the documentation. + double value = 1; + } +} + +message Capacity { + oneof current_mode { + // The status of on-demand capacity mode. + OnDemand on_demand = 1; + // The status of provisioned capacity mode. + Provisioned provisioned = 2; + } + + message OnDemand { + } + + message Provisioned { + // The current provisioned capacity for the namespace in Temporal Resource Units. + // Can be different from the requested capacity in latest_request if the request is still in progress. + double current_value = 1; + } + + message Request { + // The current state of the capacity request (e.g. in-progress, completed, failed). + State state = 1; + // The date and time when the capacity request was created. + google.protobuf.Timestamp start_time = 2; + // The date and time when the capacity request was completed or failed. + google.protobuf.Timestamp end_time = 3; + // The id of the async operation that is creating/updating/deleting the capacity, if any. + string async_operation_id = 4; + // The requested capacity specification. + CapacitySpec spec = 5; + + enum State { + STATE_CAPACITY_REQUEST_UNSPECIFIED = 0; + STATE_CAPACITY_REQUEST_COMPLETED = 1; + STATE_CAPACITY_REQUEST_IN_PROGRESS = 2; + STATE_CAPACITY_REQUEST_FAILED = 3; + } + } + + // The latest requested capacity for the namespace, if any. + Request latest_request = 3; +} + message NamespaceSpec { // The name to use for the namespace. // This will create a namespace that's available at '..tmprl.cloud:7233'. @@ -134,17 +195,27 @@ message NamespaceSpec { // Codec server spec used by UI to decode payloads for all users interacting with this namespace. // Optional, default is unset. CodecServerSpec codec_server = 6; + // The lifecycle configuration for the namespace. // temporal:versioning:min_version=v0.4.0 LifecycleSpec lifecycle = 9; + // The high availability configuration for the namespace. // temporal:versioning:min_version=v0.4.0 HighAvailabilitySpec high_availability = 10; + // The private connectivity configuration for the namespace. // This will apply the connectivity rules specified to the namespace. // temporal:versioning:min_version=v0.6.0 repeated string connectivity_rule_ids = 11; + // The capacity configuration for the namespace. + // There are two capacity modes: on-demand and provisioned. + // On-demand capacity mode allows the namespace to scale automatically based on usage. + // Provisioned capacity mode allows the user to specify a fixed amount of capacity (in TRUs) for the namespace. + // Can be changed only when the last capacity request is not in progress. + // temporal:versioning:min_version=v0.10.0 + CapacitySpec capacity_spec = 12; enum SearchAttributeType { SEARCH_ATTRIBUTE_TYPE_UNSPECIFIED = 0; @@ -228,6 +299,8 @@ message Namespace { repeated temporal.api.cloud.connectivityrule.v1.ConnectivityRule connectivity_rules = 14; // The tags for the namespace. map tags = 15; + // The status of namespace's capacity, if any. + Capacity capacity = 16; } message NamespaceRegionStatus { @@ -255,21 +328,22 @@ message NamespaceRegionStatus { } message ExportSinkSpec { - // The unique name of the export sink, it can't be changed once set. + // The unique name of the export sink, it can't be changed once set. string name = 1; // A flag indicating whether the export sink is enabled or not. bool enabled = 2; - + // The S3 configuration details when destination_type is S3. temporal.api.cloud.sink.v1.S3Spec s3 = 3; - // The GCS configuration details when destination_type is GCS. + // This is a feature under development. We will allow GCS sink support for GCP Namespaces. + // The GCS configuration details when destination_type is GCS. temporal.api.cloud.sink.v1.GCSSpec gcs = 4; } message ExportSink { - // The unique name of the export sink. + // The unique name of the export sink, once set it can't be changed string name = 1; // The version of the export sink resource. @@ -300,3 +374,61 @@ message ExportSink { HEALTH_ERROR_USER_CONFIGURATION = 3; } } + +// NamespaceCapacityInfo contains detailed capacity information for a namespace. +message NamespaceCapacityInfo { + // The namespace identifier. + string namespace = 1; + + // Whether the namespace's APS limit was set by Temporal Support. + // When true, adjusting the namespace's capacity will reset this limit. + bool has_legacy_limits = 2; + + // The current capacity of the namespace. + // Includes the current mode (on-demand or provisioned) and latest request status. + Capacity current_capacity = 3; + + // Available capacity mode options for this namespace. + // Contains configuration limits for both provisioned and on-demand modes. + CapacityModeOptions mode_options = 4; + + // Usage statistics for the namespace over the last 7 days. + // Used to calculate On-Demand capacity limits, also useful for capacity planning. + Stats stats = 5; + + message CapacityModeOptions { + // Provisioned capacity options and entitlements. + Provisioned provisioned = 1; + + // On-Demand capacity information. + OnDemand on_demand = 2; + + message Provisioned { + // The valid TRU (Temporal Resource Unit) values that can be set. + // These are the discrete capacity tiers available for selection. + repeated double valid_tru_values = 1; + + // The maximum TRU value that can currently be set for this namespace. + // This may be lower than the highest value in valid_tru_values due to + // inventory constraints. + double max_available_tru_value = 2; + } + + message OnDemand { + // The APS limit that would apply to this namespace in on-demand mode. + // See: https://docs.temporal.io/cloud/limits#actions-per-second + double aps_limit = 1; + } + } + + message Stats { + // Actions-per-second measurements summarized over the last 7 days. + Summary aps = 1; + + message Summary { + double mean = 1; + double p90 = 2; + double p99 = 3; + } + } +} diff --git a/crates/common/protos/protoc-gen-openapiv2/options/annotations.proto b/crates/common/protos/protoc-gen-openapiv2/options/annotations.proto new file mode 100644 index 000000000..aecc5e709 --- /dev/null +++ b/crates/common/protos/protoc-gen-openapiv2/options/annotations.proto @@ -0,0 +1,51 @@ +syntax = "proto3"; + +package grpc.gateway.protoc_gen_openapiv2.options; + +import "google/protobuf/descriptor.proto"; +import "protoc-gen-openapiv2/options/openapiv2.proto"; + +option go_package = "github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2/options"; + +extend google.protobuf.FileOptions { + // ID assigned by protobuf-global-extension-registry@google.com for gRPC-Gateway project. + // + // All IDs are the same, as assigned. It is okay that they are the same, as they extend + // different descriptor messages. + Swagger openapiv2_swagger = 1042; +} +extend google.protobuf.MethodOptions { + // ID assigned by protobuf-global-extension-registry@google.com for gRPC-Gateway project. + // + // All IDs are the same, as assigned. It is okay that they are the same, as they extend + // different descriptor messages. + Operation openapiv2_operation = 1042; +} +extend google.protobuf.MessageOptions { + // ID assigned by protobuf-global-extension-registry@google.com for gRPC-Gateway project. + // + // All IDs are the same, as assigned. It is okay that they are the same, as they extend + // different descriptor messages. + Schema openapiv2_schema = 1042; +} +extend google.protobuf.EnumOptions { + // ID assigned by protobuf-global-extension-registry@google.com for gRPC-Gateway project. + // + // All IDs are the same, as assigned. It is okay that they are the same, as they extend + // different descriptor messages. + EnumSchema openapiv2_enum = 1042; +} +extend google.protobuf.ServiceOptions { + // ID assigned by protobuf-global-extension-registry@google.com for gRPC-Gateway project. + // + // All IDs are the same, as assigned. It is okay that they are the same, as they extend + // different descriptor messages. + Tag openapiv2_tag = 1042; +} +extend google.protobuf.FieldOptions { + // ID assigned by protobuf-global-extension-registry@google.com for gRPC-Gateway project. + // + // All IDs are the same, as assigned. It is okay that they are the same, as they extend + // different descriptor messages. + JSONSchema openapiv2_field = 1042; +} diff --git a/crates/common/protos/protoc-gen-openapiv2/options/openapiv2.proto b/crates/common/protos/protoc-gen-openapiv2/options/openapiv2.proto new file mode 100644 index 000000000..5313f0818 --- /dev/null +++ b/crates/common/protos/protoc-gen-openapiv2/options/openapiv2.proto @@ -0,0 +1,759 @@ +syntax = "proto3"; + +package grpc.gateway.protoc_gen_openapiv2.options; + +import "google/protobuf/struct.proto"; + +option go_package = "github.com/grpc-ecosystem/grpc-gateway/v2/protoc-gen-openapiv2/options"; + +// Scheme describes the schemes supported by the OpenAPI Swagger +// and Operation objects. +enum Scheme { + UNKNOWN = 0; + HTTP = 1; + HTTPS = 2; + WS = 3; + WSS = 4; +} + +// `Swagger` is a representation of OpenAPI v2 specification's Swagger object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#swaggerObject +// +// Example: +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_swagger) = { +// info: { +// title: "Echo API"; +// version: "1.0"; +// description: ""; +// contact: { +// name: "gRPC-Gateway project"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway"; +// email: "none@example.com"; +// }; +// license: { +// name: "BSD 3-Clause License"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway/blob/main/LICENSE"; +// }; +// }; +// schemes: HTTPS; +// consumes: "application/json"; +// produces: "application/json"; +// }; +// +message Swagger { + // Specifies the OpenAPI Specification version being used. It can be + // used by the OpenAPI UI and other clients to interpret the API listing. The + // value MUST be "2.0". + string swagger = 1; + // Provides metadata about the API. The metadata can be used by the + // clients if needed. + Info info = 2; + // The host (name or ip) serving the API. This MUST be the host only and does + // not include the scheme nor sub-paths. It MAY include a port. If the host is + // not included, the host serving the documentation is to be used (including + // the port). The host does not support path templating. + string host = 3; + // The base path on which the API is served, which is relative to the host. If + // it is not included, the API is served directly under the host. The value + // MUST start with a leading slash (/). The basePath does not support path + // templating. + // Note that using `base_path` does not change the endpoint paths that are + // generated in the resulting OpenAPI file. If you wish to use `base_path` + // with relatively generated OpenAPI paths, the `base_path` prefix must be + // manually removed from your `google.api.http` paths and your code changed to + // serve the API from the `base_path`. + string base_path = 4; + // The transfer protocol of the API. Values MUST be from the list: "http", + // "https", "ws", "wss". If the schemes is not included, the default scheme to + // be used is the one used to access the OpenAPI definition itself. + repeated Scheme schemes = 5; + // A list of MIME types the APIs can consume. This is global to all APIs but + // can be overridden on specific API calls. Value MUST be as described under + // Mime Types. + repeated string consumes = 6; + // A list of MIME types the APIs can produce. This is global to all APIs but + // can be overridden on specific API calls. Value MUST be as described under + // Mime Types. + repeated string produces = 7; + // field 8 is reserved for 'paths'. + reserved 8; + // field 9 is reserved for 'definitions', which at this time are already + // exposed as and customizable as proto messages. + reserved 9; + // An object to hold responses that can be used across operations. This + // property does not define global responses for all operations. + map responses = 10; + // Security scheme definitions that can be used across the specification. + SecurityDefinitions security_definitions = 11; + // A declaration of which security schemes are applied for the API as a whole. + // The list of values describes alternative security schemes that can be used + // (that is, there is a logical OR between the security requirements). + // Individual operations can override this definition. + repeated SecurityRequirement security = 12; + // A list of tags for API documentation control. Tags can be used for logical + // grouping of operations by resources or any other qualifier. + repeated Tag tags = 13; + // Additional external documentation. + ExternalDocumentation external_docs = 14; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 15; +} + +// `Operation` is a representation of OpenAPI v2 specification's Operation object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#operationObject +// +// Example: +// +// service EchoService { +// rpc Echo(SimpleMessage) returns (SimpleMessage) { +// option (google.api.http) = { +// get: "/v1/example/echo/{id}" +// }; +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_operation) = { +// summary: "Get a message."; +// operation_id: "getMessage"; +// tags: "echo"; +// responses: { +// key: "200" +// value: { +// description: "OK"; +// } +// } +// }; +// } +// } +message Operation { + // A list of tags for API documentation control. Tags can be used for logical + // grouping of operations by resources or any other qualifier. + repeated string tags = 1; + // A short summary of what the operation does. For maximum readability in the + // swagger-ui, this field SHOULD be less than 120 characters. + string summary = 2; + // A verbose explanation of the operation behavior. GFM syntax can be used for + // rich text representation. + string description = 3; + // Additional external documentation for this operation. + ExternalDocumentation external_docs = 4; + // Unique string used to identify the operation. The id MUST be unique among + // all operations described in the API. Tools and libraries MAY use the + // operationId to uniquely identify an operation, therefore, it is recommended + // to follow common programming naming conventions. + string operation_id = 5; + // A list of MIME types the operation can consume. This overrides the consumes + // definition at the OpenAPI Object. An empty value MAY be used to clear the + // global definition. Value MUST be as described under Mime Types. + repeated string consumes = 6; + // A list of MIME types the operation can produce. This overrides the produces + // definition at the OpenAPI Object. An empty value MAY be used to clear the + // global definition. Value MUST be as described under Mime Types. + repeated string produces = 7; + // field 8 is reserved for 'parameters'. + reserved 8; + // The list of possible responses as they are returned from executing this + // operation. + map responses = 9; + // The transfer protocol for the operation. Values MUST be from the list: + // "http", "https", "ws", "wss". The value overrides the OpenAPI Object + // schemes definition. + repeated Scheme schemes = 10; + // Declares this operation to be deprecated. Usage of the declared operation + // should be refrained. Default value is false. + bool deprecated = 11; + // A declaration of which security schemes are applied for this operation. The + // list of values describes alternative security schemes that can be used + // (that is, there is a logical OR between the security requirements). This + // definition overrides any declared top-level security. To remove a top-level + // security declaration, an empty array can be used. + repeated SecurityRequirement security = 12; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 13; + // Custom parameters such as HTTP request headers. + // See: https://swagger.io/docs/specification/2-0/describing-parameters/ + // and https://swagger.io/specification/v2/#parameter-object. + Parameters parameters = 14; +} + +// `Parameters` is a representation of OpenAPI v2 specification's parameters object. +// Note: This technically breaks compatibility with the OpenAPI 2 definition structure as we only +// allow header parameters to be set here since we do not want users specifying custom non-header +// parameters beyond those inferred from the Protobuf schema. +// See: https://swagger.io/specification/v2/#parameter-object +message Parameters { + // `Headers` is one or more HTTP header parameter. + // See: https://swagger.io/docs/specification/2-0/describing-parameters/#header-parameters + repeated HeaderParameter headers = 1; +} + +// `HeaderParameter` a HTTP header parameter. +// See: https://swagger.io/specification/v2/#parameter-object +message HeaderParameter { + // `Type` is a supported HTTP header type. + // See https://swagger.io/specification/v2/#parameterType. + enum Type { + UNKNOWN = 0; + STRING = 1; + NUMBER = 2; + INTEGER = 3; + BOOLEAN = 4; + } + + // `Name` is the header name. + string name = 1; + // `Description` is a short description of the header. + string description = 2; + // `Type` is the type of the object. The value MUST be one of "string", "number", "integer", or "boolean". The "array" type is not supported. + // See: https://swagger.io/specification/v2/#parameterType. + Type type = 3; + // `Format` The extending format for the previously mentioned type. + string format = 4; + // `Required` indicates if the header is optional + bool required = 5; + // field 6 is reserved for 'items', but in OpenAPI-specific way. + reserved 6; + // field 7 is reserved `Collection Format`. Determines the format of the array if type array is used. + reserved 7; +} + +// `Header` is a representation of OpenAPI v2 specification's Header object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#headerObject +// +message Header { + // `Description` is a short description of the header. + string description = 1; + // The type of the object. The value MUST be one of "string", "number", "integer", or "boolean". The "array" type is not supported. + string type = 2; + // `Format` The extending format for the previously mentioned type. + string format = 3; + // field 4 is reserved for 'items', but in OpenAPI-specific way. + reserved 4; + // field 5 is reserved `Collection Format` Determines the format of the array if type array is used. + reserved 5; + // `Default` Declares the value of the header that the server will use if none is provided. + // See: https://tools.ietf.org/html/draft-fge-json-schema-validation-00#section-6.2. + // Unlike JSON Schema this value MUST conform to the defined type for the header. + string default = 6; + // field 7 is reserved for 'maximum'. + reserved 7; + // field 8 is reserved for 'exclusiveMaximum'. + reserved 8; + // field 9 is reserved for 'minimum'. + reserved 9; + // field 10 is reserved for 'exclusiveMinimum'. + reserved 10; + // field 11 is reserved for 'maxLength'. + reserved 11; + // field 12 is reserved for 'minLength'. + reserved 12; + // 'Pattern' See https://tools.ietf.org/html/draft-fge-json-schema-validation-00#section-5.2.3. + string pattern = 13; + // field 14 is reserved for 'maxItems'. + reserved 14; + // field 15 is reserved for 'minItems'. + reserved 15; + // field 16 is reserved for 'uniqueItems'. + reserved 16; + // field 17 is reserved for 'enum'. + reserved 17; + // field 18 is reserved for 'multipleOf'. + reserved 18; +} + +// `Response` is a representation of OpenAPI v2 specification's Response object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#responseObject +// +message Response { + // `Description` is a short description of the response. + // GFM syntax can be used for rich text representation. + string description = 1; + // `Schema` optionally defines the structure of the response. + // If `Schema` is not provided, it means there is no content to the response. + Schema schema = 2; + // `Headers` A list of headers that are sent with the response. + // `Header` name is expected to be a string in the canonical format of the MIME header key + // See: https://golang.org/pkg/net/textproto/#CanonicalMIMEHeaderKey + map headers = 3; + // `Examples` gives per-mimetype response examples. + // See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#example-object + map examples = 4; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 5; +} + +// `Info` is a representation of OpenAPI v2 specification's Info object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#infoObject +// +// Example: +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_swagger) = { +// info: { +// title: "Echo API"; +// version: "1.0"; +// description: ""; +// contact: { +// name: "gRPC-Gateway project"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway"; +// email: "none@example.com"; +// }; +// license: { +// name: "BSD 3-Clause License"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway/blob/main/LICENSE"; +// }; +// }; +// ... +// }; +// +message Info { + // The title of the application. + string title = 1; + // A short description of the application. GFM syntax can be used for rich + // text representation. + string description = 2; + // The Terms of Service for the API. + string terms_of_service = 3; + // The contact information for the exposed API. + Contact contact = 4; + // The license information for the exposed API. + License license = 5; + // Provides the version of the application API (not to be confused + // with the specification version). + string version = 6; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 7; +} + +// `Contact` is a representation of OpenAPI v2 specification's Contact object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#contactObject +// +// Example: +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_swagger) = { +// info: { +// ... +// contact: { +// name: "gRPC-Gateway project"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway"; +// email: "none@example.com"; +// }; +// ... +// }; +// ... +// }; +// +message Contact { + // The identifying name of the contact person/organization. + string name = 1; + // The URL pointing to the contact information. MUST be in the format of a + // URL. + string url = 2; + // The email address of the contact person/organization. MUST be in the format + // of an email address. + string email = 3; +} + +// `License` is a representation of OpenAPI v2 specification's License object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#licenseObject +// +// Example: +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_swagger) = { +// info: { +// ... +// license: { +// name: "BSD 3-Clause License"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway/blob/main/LICENSE"; +// }; +// ... +// }; +// ... +// }; +// +message License { + // The license name used for the API. + string name = 1; + // A URL to the license used for the API. MUST be in the format of a URL. + string url = 2; +} + +// `ExternalDocumentation` is a representation of OpenAPI v2 specification's +// ExternalDocumentation object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#externalDocumentationObject +// +// Example: +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_swagger) = { +// ... +// external_docs: { +// description: "More about gRPC-Gateway"; +// url: "https://github.com/grpc-ecosystem/grpc-gateway"; +// } +// ... +// }; +// +message ExternalDocumentation { + // A short description of the target documentation. GFM syntax can be used for + // rich text representation. + string description = 1; + // The URL for the target documentation. Value MUST be in the format + // of a URL. + string url = 2; +} + +// `Schema` is a representation of OpenAPI v2 specification's Schema object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#schemaObject +// +message Schema { + JSONSchema json_schema = 1; + // Adds support for polymorphism. The discriminator is the schema property + // name that is used to differentiate between other schema that inherit this + // schema. The property name used MUST be defined at this schema and it MUST + // be in the required property list. When used, the value MUST be the name of + // this schema or any schema that inherits it. + string discriminator = 2; + // Relevant only for Schema "properties" definitions. Declares the property as + // "read only". This means that it MAY be sent as part of a response but MUST + // NOT be sent as part of the request. Properties marked as readOnly being + // true SHOULD NOT be in the required list of the defined schema. Default + // value is false. + bool read_only = 3; + // field 4 is reserved for 'xml'. + reserved 4; + // Additional external documentation for this schema. + ExternalDocumentation external_docs = 5; + // A free-form property to include an example of an instance for this schema in JSON. + // This is copied verbatim to the output. + string example = 6; +} + +// `EnumSchema` is subset of fields from the OpenAPI v2 specification's Schema object. +// Only fields that are applicable to Enums are included +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#schemaObject +// +// Example: +// +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_enum) = { +// ... +// title: "MyEnum"; +// description:"This is my nice enum"; +// example: "ZERO"; +// required: true; +// ... +// }; +// +message EnumSchema { + // A short description of the schema. + string description = 1; + string default = 2; + // The title of the schema. + string title = 3; + bool required = 4; + bool read_only = 5; + // Additional external documentation for this schema. + ExternalDocumentation external_docs = 6; + string example = 7; + // Ref is used to define an external reference to include in the message. + // This could be a fully qualified proto message reference, and that type must + // be imported into the protofile. If no message is identified, the Ref will + // be used verbatim in the output. + // For example: + // `ref: ".google.protobuf.Timestamp"`. + string ref = 8; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 9; +} + +// `JSONSchema` represents properties from JSON Schema taken, and as used, in +// the OpenAPI v2 spec. +// +// This includes changes made by OpenAPI v2. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#schemaObject +// +// See also: https://cswr.github.io/JsonSchema/spec/basic_types/, +// https://github.com/json-schema-org/json-schema-spec/blob/master/schema.json +// +// Example: +// +// message SimpleMessage { +// option (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_schema) = { +// json_schema: { +// title: "SimpleMessage" +// description: "A simple message." +// required: ["id"] +// } +// }; +// +// // Id represents the message identifier. +// string id = 1; [ +// (grpc.gateway.protoc_gen_openapiv2.options.openapiv2_field) = { +// description: "The unique identifier of the simple message." +// }]; +// } +// +message JSONSchema { + // field 1 is reserved for '$id', omitted from OpenAPI v2. + reserved 1; + // field 2 is reserved for '$schema', omitted from OpenAPI v2. + reserved 2; + // Ref is used to define an external reference to include in the message. + // This could be a fully qualified proto message reference, and that type must + // be imported into the protofile. If no message is identified, the Ref will + // be used verbatim in the output. + // For example: + // `ref: ".google.protobuf.Timestamp"`. + string ref = 3; + // field 4 is reserved for '$comment', omitted from OpenAPI v2. + reserved 4; + // The title of the schema. + string title = 5; + // A short description of the schema. + string description = 6; + string default = 7; + bool read_only = 8; + // A free-form property to include a JSON example of this field. This is copied + // verbatim to the output swagger.json. Quotes must be escaped. + // This property is the same for 2.0 and 3.0.0 https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/3.0.0.md#schemaObject https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#schemaObject + string example = 9; + double multiple_of = 10; + // Maximum represents an inclusive upper limit for a numeric instance. The + // value of MUST be a number, + double maximum = 11; + bool exclusive_maximum = 12; + // minimum represents an inclusive lower limit for a numeric instance. The + // value of MUST be a number, + double minimum = 13; + bool exclusive_minimum = 14; + uint64 max_length = 15; + uint64 min_length = 16; + string pattern = 17; + // field 18 is reserved for 'additionalItems', omitted from OpenAPI v2. + reserved 18; + // field 19 is reserved for 'items', but in OpenAPI-specific way. + // TODO(ivucica): add 'items'? + reserved 19; + uint64 max_items = 20; + uint64 min_items = 21; + bool unique_items = 22; + // field 23 is reserved for 'contains', omitted from OpenAPI v2. + reserved 23; + uint64 max_properties = 24; + uint64 min_properties = 25; + repeated string required = 26; + // field 27 is reserved for 'additionalProperties', but in OpenAPI-specific + // way. TODO(ivucica): add 'additionalProperties'? + reserved 27; + // field 28 is reserved for 'definitions', omitted from OpenAPI v2. + reserved 28; + // field 29 is reserved for 'properties', but in OpenAPI-specific way. + // TODO(ivucica): add 'additionalProperties'? + reserved 29; + // following fields are reserved, as the properties have been omitted from + // OpenAPI v2: + // patternProperties, dependencies, propertyNames, const + reserved 30 to 33; + // Items in 'array' must be unique. + repeated string array = 34; + + enum JSONSchemaSimpleTypes { + UNKNOWN = 0; + ARRAY = 1; + BOOLEAN = 2; + INTEGER = 3; + NULL = 4; + NUMBER = 5; + OBJECT = 6; + STRING = 7; + } + + repeated JSONSchemaSimpleTypes type = 35; + // `Format` + string format = 36; + // following fields are reserved, as the properties have been omitted from + // OpenAPI v2: contentMediaType, contentEncoding, if, then, else + reserved 37 to 41; + // field 42 is reserved for 'allOf', but in OpenAPI-specific way. + // TODO(ivucica): add 'allOf'? + reserved 42; + // following fields are reserved, as the properties have been omitted from + // OpenAPI v2: + // anyOf, oneOf, not + reserved 43 to 45; + // Items in `enum` must be unique https://tools.ietf.org/html/draft-fge-json-schema-validation-00#section-5.5.1 + repeated string enum = 46; + + // Additional field level properties used when generating the OpenAPI v2 file. + FieldConfiguration field_configuration = 1001; + + // 'FieldConfiguration' provides additional field level properties used when generating the OpenAPI v2 file. + // These properties are not defined by OpenAPIv2, but they are used to control the generation. + message FieldConfiguration { + // Alternative parameter name when used as path parameter. If set, this will + // be used as the complete parameter name when this field is used as a path + // parameter. Use this to avoid having auto generated path parameter names + // for overlapping paths. + string path_param_name = 47; + } + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 48; +} + +// `Tag` is a representation of OpenAPI v2 specification's Tag object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#tagObject +// +message Tag { + // The name of the tag. Use it to allow override of the name of a + // global Tag object, then use that name to reference the tag throughout the + // OpenAPI file. + string name = 1; + // A short description for the tag. GFM syntax can be used for rich text + // representation. + string description = 2; + // Additional external documentation for this tag. + ExternalDocumentation external_docs = 3; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 4; +} + +// `SecurityDefinitions` is a representation of OpenAPI v2 specification's +// Security Definitions object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#securityDefinitionsObject +// +// A declaration of the security schemes available to be used in the +// specification. This does not enforce the security schemes on the operations +// and only serves to provide the relevant details for each scheme. +message SecurityDefinitions { + // A single security scheme definition, mapping a "name" to the scheme it + // defines. + map security = 1; +} + +// `SecurityScheme` is a representation of OpenAPI v2 specification's +// Security Scheme object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#securitySchemeObject +// +// Allows the definition of a security scheme that can be used by the +// operations. Supported schemes are basic authentication, an API key (either as +// a header or as a query parameter) and OAuth2's common flows (implicit, +// password, application and access code). +message SecurityScheme { + // The type of the security scheme. Valid values are "basic", + // "apiKey" or "oauth2". + enum Type { + TYPE_INVALID = 0; + TYPE_BASIC = 1; + TYPE_API_KEY = 2; + TYPE_OAUTH2 = 3; + } + + // The location of the API key. Valid values are "query" or "header". + enum In { + IN_INVALID = 0; + IN_QUERY = 1; + IN_HEADER = 2; + } + + // The flow used by the OAuth2 security scheme. Valid values are + // "implicit", "password", "application" or "accessCode". + enum Flow { + FLOW_INVALID = 0; + FLOW_IMPLICIT = 1; + FLOW_PASSWORD = 2; + FLOW_APPLICATION = 3; + FLOW_ACCESS_CODE = 4; + } + + // The type of the security scheme. Valid values are "basic", + // "apiKey" or "oauth2". + Type type = 1; + // A short description for security scheme. + string description = 2; + // The name of the header or query parameter to be used. + // Valid for apiKey. + string name = 3; + // The location of the API key. Valid values are "query" or + // "header". + // Valid for apiKey. + In in = 4; + // The flow used by the OAuth2 security scheme. Valid values are + // "implicit", "password", "application" or "accessCode". + // Valid for oauth2. + Flow flow = 5; + // The authorization URL to be used for this flow. This SHOULD be in + // the form of a URL. + // Valid for oauth2/implicit and oauth2/accessCode. + string authorization_url = 6; + // The token URL to be used for this flow. This SHOULD be in the + // form of a URL. + // Valid for oauth2/password, oauth2/application and oauth2/accessCode. + string token_url = 7; + // The available scopes for the OAuth2 security scheme. + // Valid for oauth2. + Scopes scopes = 8; + // Custom properties that start with "x-" such as "x-foo" used to describe + // extra functionality that is not covered by the standard OpenAPI Specification. + // See: https://swagger.io/docs/specification/2-0/swagger-extensions/ + map extensions = 9; +} + +// `SecurityRequirement` is a representation of OpenAPI v2 specification's +// Security Requirement object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#securityRequirementObject +// +// Lists the required security schemes to execute this operation. The object can +// have multiple security schemes declared in it which are all required (that +// is, there is a logical AND between the schemes). +// +// The name used for each property MUST correspond to a security scheme +// declared in the Security Definitions. +message SecurityRequirement { + // If the security scheme is of type "oauth2", then the value is a list of + // scope names required for the execution. For other security scheme types, + // the array MUST be empty. + message SecurityRequirementValue { + repeated string scope = 1; + } + // Each name must correspond to a security scheme which is declared in + // the Security Definitions. If the security scheme is of type "oauth2", + // then the value is a list of scope names required for the execution. + // For other security scheme types, the array MUST be empty. + map security_requirement = 1; +} + +// `Scopes` is a representation of OpenAPI v2 specification's Scopes object. +// +// See: https://github.com/OAI/OpenAPI-Specification/blob/3.0.0/versions/2.0.md#scopesObject +// +// Lists the available scopes for an OAuth2 security scheme. +message Scopes { + // Maps between a name of a scope to a short description of it (as the value + // of the property). + map scope = 1; +} diff --git a/crates/common/src/protos/mod.rs b/crates/common/src/protos/mod.rs index fc64e5b08..c22a77298 100644 --- a/crates/common/src/protos/mod.rs +++ b/crates/common/src/protos/mod.rs @@ -1984,6 +1984,16 @@ pub mod temporal { tonic::include_proto!("temporal.api.cloud.account.v1"); } } + pub mod auditlog { + pub mod v1 { + tonic::include_proto!("temporal.api.cloud.auditlog.v1"); + } + } + pub mod billing { + pub mod v1 { + tonic::include_proto!("temporal.api.cloud.billing.v1"); + } + } pub mod cloudservice { pub mod v1 { tonic::include_proto!("temporal.api.cloud.cloudservice.v1"); From 33bfa3472b0543c6e3e9fea2a3b527a8bd7f3a3a Mon Sep 17 00:00:00 2001 From: Chandler Ortman Date: Thu, 19 Mar 2026 16:26:43 -0700 Subject: [PATCH 2/2] add missing cloud RPC methods to C bridge --- crates/sdk-core-c-bridge/src/client.rs | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/crates/sdk-core-c-bridge/src/client.rs b/crates/sdk-core-c-bridge/src/client.rs index 80a7549b5..b5b988c88 100644 --- a/crates/sdk-core-c-bridge/src/client.rs +++ b/crates/sdk-core-c-bridge/src/client.rs @@ -1132,6 +1132,32 @@ async fn call_cloud_service( "ValidateAccountAuditLogSink" => { rpc_call_on_trait!(client, call, CloudService, validate_account_audit_log_sink) } + "GetCurrentIdentity" => { + rpc_call_on_trait!(client, call, CloudService, get_current_identity) + } + "GetAuditLogs" => rpc_call_on_trait!(client, call, CloudService, get_audit_logs), + "CreateAccountAuditLogSink" => { + rpc_call_on_trait!(client, call, CloudService, create_account_audit_log_sink) + } + "GetAccountAuditLogSink" => { + rpc_call_on_trait!(client, call, CloudService, get_account_audit_log_sink) + } + "GetAccountAuditLogSinks" => { + rpc_call_on_trait!(client, call, CloudService, get_account_audit_log_sinks) + } + "UpdateAccountAuditLogSink" => { + rpc_call_on_trait!(client, call, CloudService, update_account_audit_log_sink) + } + "DeleteAccountAuditLogSink" => { + rpc_call_on_trait!(client, call, CloudService, delete_account_audit_log_sink) + } + "GetNamespaceCapacityInfo" => { + rpc_call_on_trait!(client, call, CloudService, get_namespace_capacity_info) + } + "CreateBillingReport" => { + rpc_call_on_trait!(client, call, CloudService, create_billing_report) + } + "GetBillingReport" => rpc_call_on_trait!(client, call, CloudService, get_billing_report), rpc => Err(anyhow::anyhow!("Unknown RPC call {rpc}")), } }