Container Waivers API

Container Waivers API

API endpoints for automation with Firewall for Container.

GET    /api/v2/firewall/container-image/policyViolations/quarantined
POST   /api/v2/firewall/container-image/{containerImageId}/policyWaiver
GET    /api/v2/firewall/container-image/policyWaiver
DELETE /api/v2/firewall/container-image/{containerImageId}/policyWaiver

Get Quarantined Containers

This endpoint returns the policy violations for quarantined containers.

GET /api/v2/firewall/container-image/policyViolations/quarantined

This endpoint requires the following parameters to be included in the request as parameters at the end of the request URL.

Example request:

curl -X GET 'https://iq-server.example/platform/api/v2/firewall/container-image/policyViolations/quarantined?page=1&pageSize=100'

Example response:

{
  "total": 35,
  "page": 1,
  "pageSize": 100,
  "pageCount": 1,
  "results": [\
    {\
      "threatLevel": 10,\
      "openTime": 1752597551260,\
      "applicationPublicId": "repo.example-docker-proxy-library-nginx-1.19.6",\
      "applicationId": "9d03e8759202421b916d95c400000000",\
      "applicationName": "repo.example-docker-proxy-library-nginx-1.19.6",\
      "repositoryPublicId": "docker-proxy",\
      "repositoryId": "a1ee756e8eed484c82952d8000000000",\
      "policyViolationCount": 252,\
      "scanId": "52459e9548454a9abd889fb000000000"\
    }, ...\
  ]
}

Either the applicationPublicId or the applicationId may be used as the containerImageId when applying or deleting waivers.

Waive All Container Violations

An API endpoint to waive all policy violations from a container image evaluated. The path param near the end of the URL must contain the container image identifier.

POST /api/v2/firewall/container-image/{containerImageId}/policyWaiver

Use the quarantined containers endpoint above for the containerImageId of the container.

The body of the request JSON can include the following fields:

{
  "expiryTime": "2025-07-29T18:23:01.554Z",
  "waiverReasonId": "some reason as a string",
  "comment": "test-comment as a string"
}

The response code returns a 204 when the waiver has been created successfully.

Get Container Waivers

This endpoint returns a list of applied container waivers.

GET /api/v2/firewall/container-image/policyWaiver

This endpoint requires the following parameters to be included in the request as parameters at the end of the request URL.

Example request:

curl -X GET 'https://iq-server.example/platform/api/v2/firewall/container-image/policyWaiver?page=1&pageSize=100'

Example response:

NEED EXAMPLE

Remove Container Waiver

Endpoint to remove the waiver applied to all of the violations for the container.

DELETE /api/v2/firewall/container-image/{containerImageId}/policyWaiver

The response code returns a 204 when the waiver has been successfully removed.

Search results

No results found.