Get Cerbos superadmin policy template
curl --request GET \
--url https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-templateimport requests
url = "https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template"
response = requests.get(url)
print(response.text)const options = {method: 'GET'};
fetch('https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template"
req, _ := http.NewRequest("GET", url, nil)
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template")
.asString();require 'uri'
require 'net/http'
url = URI("https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
response = http.request(request)
puts response.read_body{
"apiVersion": "api.cerbos.dev/v1",
"kind": "RolePolicy",
"metadata": {
"storeIdentifier": "role_superadmin"
},
"rolePolicy": {
"role": "superadmin",
"version": "default",
"rules": [
{
"resource": "*",
"actions": [
{
"action": "*",
"effect": "EFFECT_ALLOW"
}
]
}
]
}
}health
Get Cerbos superadmin policy template
Get the Cerbos policy template for granting superadmin permissions.
This endpoint provides the policy configuration that should be applied to Cerbos when the admin API is disabled and manual policy configuration is required.
Use Case: When Heimdall cannot automatically create the superadmin policy (e.g., Cerbos admin API is disabled), use this template to manually configure the policy in your Cerbos deployment.
Instructions:
- Get the policy template from this endpoint
- Save it as a YAML or JSON file in your Cerbos configuration
- Apply it via your Cerbos deployment method (ConfigMap, file system, etc.)
GET
/
api
/
v1
/
cerbos-policy-template
Get Cerbos superadmin policy template
curl --request GET \
--url https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-templateimport requests
url = "https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template"
response = requests.get(url)
print(response.text)const options = {method: 'GET'};
fetch('https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template"
req, _ := http.NewRequest("GET", url, nil)
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template")
.asString();require 'uri'
require 'net/http'
url = URI("https://services.pref.rio/heimdall-admin/api/v1/cerbos-policy-template")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
response = http.request(request)
puts response.read_body{
"apiVersion": "api.cerbos.dev/v1",
"kind": "RolePolicy",
"metadata": {
"storeIdentifier": "role_superadmin"
},
"rolePolicy": {
"role": "superadmin",
"version": "default",
"rules": [
{
"resource": "*",
"actions": [
{
"action": "*",
"effect": "EFFECT_ALLOW"
}
]
}
]
}
}Response
200 - application/json
Cerbos policy template retrieved successfully
