{"resources":{"digitalocean":{"id":"digitalocean","name":"digitalocean","fields":{"account":{"name":"account","type":"\u001bdigitalocean.account","title":"DigitalOcean account","desc":"Identity and standing of the DigitalOcean account the provider is authenticated against. The `status` field (active, warning, locked) and `statusMessage` reveal whether the account is in good standing or restricted, `emailVerified` flags an unverified primary email, and the per-resource limits (`dropletLimit`, `floatingIpLimit`, `volumeLimit`) cap what the account may provision. When the API token is scoped to a team, `teamUuid` and `teamName` identify the owning team.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"alertPolicies":{"name":"alertPolicies","type":"\u0019\u001bdigitalocean.alertPolicy","title":"Monitoring alert policies","provider":"go.mondoo.com/mql/providers/digitalocean"},"alertPolicy":{"name":"alertPolicy","type":"\u001bdigitalocean.alertPolicy","title":"DigitalOcean alert policy","desc":"Monitoring alert policy that fires when a metric crosses a threshold or an event occurs on the resources it watches. Use it to audit which conditions raise alerts, whether alerting is active (`enabled`), and where notifications are delivered. The `type` field (for example `v1/insights/droplet/cpu`) selects the metric or event being watched. The monitored resources resolve to `droplets`, `databases`, `loadBalancers`, and `kubernetesClusters` from the raw `entities` IDs.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"app":{"name":"app","type":"\u001bdigitalocean.app","title":"DigitalOcean App Platform application","desc":"Managed platform-as-a-service application on DigitalOcean, running containers, static sites, jobs, workers, and functions. The `liveUrl` and `liveDomain` report where the app is served, `activeDeploymentStatus` its current rollout state, and `spec` the component layout. Query the deployment history, active deployment, configured alerts, and running instances to audit what an app runs and how it is exposed.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"apps":{"name":"apps","type":"\u0019\u001bdigitalocean.app","title":"App Platform applications","provider":"go.mondoo.com/mql/providers/digitalocean"},"billing":{"name":"billing","type":"\u001bdigitalocean.billing","title":"Account billing balance and month-to-date usage","provider":"go.mondoo.com/mql/providers/digitalocean"},"byoipPrefix":{"name":"byoipPrefix","type":"\u001bdigitalocean.byoipPrefix","title":"DigitalOcean bring-your-own-IP prefix","desc":"Customer-owned IP prefix advertised into the account (BYOIP). The prefix CIDR, advertisement status, advertised and locked flags, region slug, and any failureReason from validation describe whether and where the address space routes. project resolves the owning project and resources lists the addresses the prefix is currently assigned to. Customer-controlled address space is a real ownership and attack-surface concern, so knowing which prefixes route into the account matters for security. Select a prefix by its uuid with `digitalocean.byoipPrefix(uuid: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"byoipPrefixes":{"name":"byoipPrefixes","type":"\u0019\u001bdigitalocean.byoipPrefix","title":"Bring-your-own-IP prefixes advertised into the account","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"cdn":{"name":"cdn","type":"\u001bdigitalocean.cdn","title":"DigitalOcean CDN endpoint","desc":"Content delivery network endpoint that fronts a Spaces bucket, caching its objects at edge locations for faster public delivery. Useful for auditing how bucket content is exposed: the origin Spaces endpoint it serves, the public CDN URL, cache time-to-live, any custom domain, and the TLS certificate securing that domain (the `certificate` accessor resolves the bound certificate, or is null when none is configured).","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"cdnEndpoints":{"name":"cdnEndpoints","type":"\u0019\u001bdigitalocean.cdn","title":"CDN endpoints","provider":"go.mondoo.com/mql/providers/digitalocean"},"certificate":{"name":"certificate","type":"\u001bdigitalocean.certificate","title":"DigitalOcean TLS certificate","desc":"TLS certificate held by DigitalOcean for use with load balancers, CDN endpoints, or App Platform. Audit these to confirm certificates are `verified` rather than stuck in `pending` or `error`, to catch approaching expirations via `notAfter`, and to see which DNS names each certificate covers. The `type` field distinguishes operator-supplied certificates from DigitalOcean-managed Let's Encrypt certificates.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"certificates":{"name":"certificates","type":"\u0019\u001bdigitalocean.certificate","title":"TLS certificates","provider":"go.mondoo.com/mql/providers/digitalocean"},"database":{"name":"database","type":"\u001bdigitalocean.database","title":"DigitalOcean managed database cluster","desc":"Managed relational, key-value, document, or streaming database cluster; the `engine` field distinguishes PostgreSQL, MySQL, Redis, MongoDB, Kafka, and OpenSearch. Reports the cluster's size, node count, region, and lifecycle status alongside its network exposure (public and private connection endpoints, the attached VPC, and the trusted-source firewall rules), its TLS material, and its backup, user, replica, and connection-pool children. Audit a cluster to confirm it is not reachable from the public internet, that its connections enforce TLS, and that automated backups are current. Select a cluster by id with `digitalocean.database(id: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"databases":{"name":"databases","type":"\u0019\u001bdigitalocean.database","title":"Managed databases","provider":"go.mondoo.com/mql/providers/digitalocean"},"domain":{"name":"domain","type":"\u001bdigitalocean.domain","title":"DigitalOcean DNS domain","desc":"DNS zone that DigitalOcean serves for a registered domain name. The zone TTL, the raw `zoneFile` contents as DigitalOcean serves them, and the individual `records` defined under the domain (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA) are queryable, which supports auditing zone contents for dangling references or unexpected entries.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"domains":{"name":"domains","type":"\u0019\u001bdigitalocean.domain","title":"Domains","provider":"go.mondoo.com/mql/providers/digitalocean"},"droplet":{"name":"droplet","type":"\u001bdigitalocean.droplet","title":"DigitalOcean Droplet","desc":"Cloud virtual machine in a DigitalOcean account, covering its compute shape (memory, vCPUs, disk, region and size slug), its network addresses (public and private IPv4, public IPv6), and the base image and kernel it boots. Security posture is queryable through the firewalls covering the droplet (resolved by direct ID or matching tag), the missingFirewall predicate that flags droplets with no firewall attached, and the exposure breakdown that combines a public IP with firewall ingress to gauge internet reachability.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"dropletAutoscalePool":{"name":"dropletAutoscalePool","type":"\u001bdigitalocean.dropletAutoscalePool","title":"DigitalOcean droplet autoscale pool","desc":"Group of droplets whose count automatically scales to meet CPU and memory targets, useful for confirming that elastic capacity stays within governed bounds. The scaling policy is flattened onto the pool: `minInstances` and `maxInstances` bound dynamic scaling, `targetCpuUtilization` and `targetMemoryUtilization` set the fractions that trigger it, `cooldownMinutes` throttles successive actions, and `targetNumberInstances` pins a fixed count for static scaling. `currentCpuUtilization` and `currentMemoryUtilization` report live load, while `dropletTemplate` captures the spec new members are created from. Select a pool by id with `digitalocean.dropletAutoscalePool(id: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"dropletAutoscalePools":{"name":"dropletAutoscalePools","type":"\u0019\u001bdigitalocean.dropletAutoscalePool","title":"Droplet autoscale pools","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"droplets":{"name":"droplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets (virtual machines)","provider":"go.mondoo.com/mql/providers/digitalocean"},"firewall":{"name":"firewall","type":"\u001bdigitalocean.firewall","title":"DigitalOcean firewall","desc":"Cloud-firewall rule set governing traffic to and from a group of droplets. The `status` field reports provisioning progress (waiting, succeeded, failed). The `ingressRules` and `egressRules` control incoming and outgoing traffic, each rule exposing protocol, ports, and the `openToInternet` predicate that flags rules reachable from any address (0.0.0.0/0 or ::/0), plus references to the droplets, load balancers, and Kubernetes clusters it targets. The `tags` select protected droplets by tag, and `droplets` resolves the full set covered by the firewall (by direct ID or matching tag).","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"firewalls":{"name":"firewalls","type":"\u0019\u001bdigitalocean.firewall","title":"Firewalls","provider":"go.mondoo.com/mql/providers/digitalocean"},"function":{"name":"function","type":"\u001bdigitalocean.function","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"functionNamespaces":{"name":"functionNamespaces","type":"\u0019\u001bdigitalocean.function.namespace","title":"Functions namespaces","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"gradientai":{"name":"gradientai","type":"\u001bdigitalocean.gradientai","title":"GenAI (GradientAI) platform","provider":"go.mondoo.com/mql/providers/digitalocean"},"image":{"name":"image","type":"\u001bdigitalocean.image","title":"DigitalOcean image","desc":"Bootable disk template a droplet is created from. The `type` field distinguishes distribution, application, snapshot, backup, custom, and admin images, and the `public` flag reports whether the image is shared with every DigitalOcean account or kept private to this one, which matters when auditing where droplets boot from. Also queryable are the `distribution` and `slug`, the `regions` the image is available in, minimum and on-disk sizes, the processing `status` and any `errorMessage`, applied tags, and the creation timestamp. Select an image by its numeric `id`, for example `digitalocean.image(id: 123456789)`. The `images` collection lists the account's own images (custom uploads, snapshots, and backups), while a droplet's `baseImage` may reference a public DigitalOcean catalog image.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"images":{"name":"images","type":"\u0019\u001bdigitalocean.image","title":"Custom images, snapshots, and backups owned by the account","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"kubernetes":{"name":"kubernetes","type":"\u001bdigitalocean.kubernetes","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"kubernetesClusters":{"name":"kubernetesClusters","type":"\u0019\u001bdigitalocean.kubernetes.cluster","title":"Kubernetes clusters","provider":"go.mondoo.com/mql/providers/digitalocean"},"latestSecurityScan":{"name":"latestSecurityScan","type":"\u001bdigitalocean.securityScan","title":"Most recent security scan; null when no scan has run","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"loadBalancer":{"name":"loadBalancer","type":"\u001bdigitalocean.loadBalancer","title":"DigitalOcean load balancer","desc":"Load balancer distributing incoming traffic across attached Droplets or, for a global load balancer, across regional load balancers. Reports the public IPv4 and IPv6 addresses, region, lifecycle status, and routing algorithm, alongside the forwardingRules, healthCheck, and stickySessions settings that govern how connections are accepted and dispatched. The firewallAllow and firewallDeny lists together with exposure describe what the load balancer accepts from the internet, making it a key checkpoint when auditing the public attack surface of a DigitalOcean deployment.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001bdigitalocean.loadBalancer","title":"Load balancers","provider":"go.mondoo.com/mql/providers/digitalocean"},"network":{"name":"network","type":"\u001bdigitalocean.network","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"nfs":{"name":"nfs","type":"\u001bdigitalocean.nfs","title":"DigitalOcean managed NFS share","desc":"Managed Network File System share that clients mount over the network. The lifecycle `status` (CREATING, ACTIVE, FAILED, DELETED) reports whether the share is usable, while `host` and `mountPath` give the mount target. `vpcs` resolves the VPCs the share is reachable from, and `accessPoints` lists the exports that govern client access. Select a share by id with `digitalocean.nfs(id: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"nfsShares":{"name":"nfsShares","type":"\u0019\u001bdigitalocean.nfs","title":"Managed NFS shares","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"partnerAttachment":{"name":"partnerAttachment","type":"\u001bdigitalocean.partnerAttachment","title":"DigitalOcean Partner Attachment (Partner Network Connect)","desc":"Partner Network Connect attachment: a private circuit, provisioned through a Network-as-a-Service provider such as Megaport, that bridges an external network into the account's VPCs. Reports the connection `state`, `connectionBandwidthInMbps`, `region`, `naasProvider`, `redundancyZone`, the `bgp` peering configuration, the parent/child relationships, and the `vpcs` the attachment connects. A private link bridging an external network into your VPCs is a network-trust boundary worth inventorying. Select an attachment by id with `digitalocean.partnerAttachment(id: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"partnerAttachments":{"name":"partnerAttachments","type":"\u0019\u001bdigitalocean.partnerAttachment","title":"Partner Network Connect attachments","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"DigitalOcean project","desc":"Resource grouping used to organize droplets, databases, load balancers, and other resources under a shared purpose and environment. The declared `environment` (Development, Staging, Production) and the `isDefault` flag help audit which resources fall under production controls versus development sandboxes, and `ownerUuid` identifies the account that owns the grouping.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"projects":{"name":"projects","type":"\u0019\u001bdigitalocean.project","title":"Projects","provider":"go.mondoo.com/mql/providers/digitalocean"},"registry":{"name":"registry","type":"\u001bdigitalocean.registry","title":"Container registry attached to the account","provider":"go.mondoo.com/mql/providers/digitalocean"},"registryRepositories":{"name":"registryRepositories","type":"\u0019\u001bdigitalocean.registry.repository","title":"Container registry repositories","provider":"go.mondoo.com/mql/providers/digitalocean"},"reservedIPs":{"name":"reservedIPs","type":"\u0019\u001bdigitalocean.reservedIp","title":"Reserved IPs","provider":"go.mondoo.com/mql/providers/digitalocean"},"reservedIPv6s":{"name":"reservedIPv6s","type":"\u0019\u001bdigitalocean.reservedIpV6","title":"Reserved IPv6 addresses","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"reservedIp":{"name":"reservedIp","type":"\u001bdigitalocean.reservedIp","title":"DigitalOcean reserved IP","desc":"Static public IPv4 address that can be reassigned between droplets without releasing it back to the shared pool. The `locked` flag reports whether an assignment is in flight, and `dropletId` names the droplet the IP currently routes to (zero when unassigned), so you can audit which public addresses are attached where and which are sitting idle.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"reservedIpV6":{"name":"reservedIpV6","type":"\u001bdigitalocean.reservedIpV6","title":"DigitalOcean reserved IPv6 address","desc":"Static, account-owned IPv6 address that can be assigned to a droplet. Useful for auditing which reserved addresses exist, the `region` they are held in, and whether each is attached to a droplet or sitting idle (`dropletId` is 0 when unassigned). Select by address with `digitalocean.reservedIpV6(ip: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"secret":{"name":"secret","type":"\u001bdigitalocean.secret","title":"DigitalOcean secret","desc":"A secret held in DigitalOcean's managed secrets store, scoped to a `region`. Surfaces the secret `name`, current `version`, and the `createdAt` and `updatedAt` timestamps. `deleteRequestedAt` is set when the secret is pending deletion and null otherwise. Iterate `versions` for the version history. Stored secret values are never exposed.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"secrets":{"name":"secrets","type":"\u0019\u001bdigitalocean.secret","title":"Secrets held in the managed secrets store","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"securityScan":{"name":"securityScan","type":"\u001bdigitalocean.securityScan","title":"DigitalOcean security scan","desc":"Managed security scan of the account's resources. The scan `status` and creation time summarize the run, and `findings` enumerate the issues the scan detected. Select a scan by id with `digitalocean.securityScan(id: \"...\")`, or use `digitalocean.latestSecurityScan` for the most recent run.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"securityScans":{"name":"securityScans","type":"\u0019\u001bdigitalocean.securityScan","title":"Security scans","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u001bdigitalocean.size","title":"DigitalOcean Droplet size","desc":"Hardware tier a Droplet or Kubernetes worker node runs on, selected by its `slug` (for example `s-1vcpu-1gb` or `g-2vcpu-8gb`). Surfaces the allocated `memory`, `vcpus` and `disk`, the `priceMonthly` and `priceHourly` in US dollars, the included outbound `transfer` allowance, `gpuInfo` for GPU tiers, the `regions` where the size can currently be provisioned, and the `available` flag reporting whether it can be provisioned at all. Select a single size by slug, for example `digitalocean.size(slug: \"s-1vcpu-1gb\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"sizes":{"name":"sizes","type":"\u0019\u001bdigitalocean.size","title":"Droplet size catalog (hardware tiers)","min_provider_version":"13.13.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"snapshot":{"name":"snapshot","type":"\u001bdigitalocean.snapshot","title":"DigitalOcean snapshot","desc":"Point-in-time copy of a droplet or a block-storage volume. The `resourceType` field records the source kind (droplet or volume) and determines which source reference is populated: `droplet` for a droplet snapshot, `volume` for a volume snapshot. Auditing snapshots helps track backup coverage, snapshot sprawl, and which regions copies are replicated to. Select a snapshot by its `id`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"snapshots":{"name":"snapshots","type":"\u0019\u001bdigitalocean.snapshot","title":"Droplet and volume snapshots","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"spacesBucket":{"name":"spacesBucket","type":"\u001bdigitalocean.spacesBucket","title":"DigitalOcean Spaces bucket","desc":"Object storage bucket in DigitalOcean Spaces, the S3-compatible storage service. The resolved access posture (public-access block, anonymous and authenticated-read ACLs), at-rest encryption settings, versioning state, bucket policy, CORS rules, and lifecycle rules make this the place to catch publicly readable or writable buckets, unencrypted data, missing versioning, and overly permissive CORS or lifecycle configuration. Auditing requires Spaces credentials supplied via the `DIGITALOCEAN_SPACES_KEY` and `DIGITALOCEAN_SPACES_SECRET` environment variables; an optional `DIGITALOCEAN_SPACES_REGION` scopes the listing to one region, otherwise the provider iterates the known Spaces regions.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"spacesBuckets":{"name":"spacesBuckets","type":"\u0019\u001bdigitalocean.spacesBucket","title":"Spaces (S3-compatible object storage) buckets","desc":"Requires Spaces credentials (DIGITALOCEAN_SPACES_KEY / DIGITALOCEAN_SPACES_SECRET) to be configured.","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"spacesKey":{"name":"spacesKey","type":"\u001bdigitalocean.spacesKey","title":"DigitalOcean Spaces access key","desc":"Access key for DigitalOcean Spaces, the S3-compatible object storage service. The `grants` list holds the per-bucket permission bindings that scope what the key can do, making this the place to audit whether a key is over-privileged (full access rather than read-only, or unscoped to a single bucket). The matching secret is only returned at creation time and is not exposed here.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"spacesKeys":{"name":"spacesKeys","type":"\u0019\u001bdigitalocean.spacesKey","title":"Spaces access keys","provider":"go.mondoo.com/mql/providers/digitalocean"},"sshKey":{"name":"sshKey","type":"\u001bdigitalocean.sshKey","title":"DigitalOcean SSH key","desc":"SSH public key registered to the DigitalOcean account and eligible to be injected into new Droplets at creation time. Auditing these keys shows which credentials can gain initial root access to fleet instances. The `publicKey` field holds the full stored key material, while `algorithm` and `bits` are parsed from it to flag weak or legacy key types (for example ssh-dss or short RSA moduli).","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"sshKeys":{"name":"sshKeys","type":"\u0019\u001bdigitalocean.sshKey","title":"SSH keys","provider":"go.mondoo.com/mql/providers/digitalocean"},"tag":{"name":"tag","type":"\u001bdigitalocean.tag","title":"DigitalOcean tag","desc":"Cross-resource label used to group droplets, volumes, load balancers, databases, and reserved IPs. Auditing tags helps confirm that assets are consistently labelled for cost allocation, access control, and automation. The `resourceCount` field reports how many resources are currently labelled with the tag.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"tags":{"name":"tags","type":"\u0019\u001bdigitalocean.tag","title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"uptimeCheck":{"name":"uptimeCheck","type":"\u001bdigitalocean.uptimeCheck","title":"DigitalOcean uptime check","desc":"Endpoint availability monitor that probes a target URL or IP from one or more DigitalOcean regions. Use it to confirm that public endpoints are being watched, that monitoring runs from the intended regions, and that a check has not been left disabled. The `type` field records the probe protocol (ping, http, or https).","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"uptimeChecks":{"name":"uptimeChecks","type":"\u0019\u001bdigitalocean.uptimeCheck","title":"Uptime checks","provider":"go.mondoo.com/mql/providers/digitalocean"},"vectorDatabase":{"name":"vectorDatabase","type":"\u001bdigitalocean.vectorDatabase","title":"DigitalOcean managed vector database","desc":"Managed vector database cluster (Weaviate) used for embedding storage and similarity search. Reports the region, size slug, lifecycle status, owning account, and the engine configuration (Weaviate version, automatic schema creation, and default quantization mode), along with the HTTP and gRPC connection endpoints and the retained backups. Select a cluster by id with `digitalocean.vectorDatabase(id: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"vectorDatabases":{"name":"vectorDatabases","type":"\u0019\u001bdigitalocean.vectorDatabase","title":"Managed vector databases","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"volume":{"name":"volume","type":"\u001bdigitalocean.volume","title":"DigitalOcean block storage volume","desc":"Block-storage volume that can be attached to Droplets for durable, resizable disk capacity independent of the Droplet lifecycle. The size in GB, region, filesystem type and label, and applied tags describe the volume, while `droplets` resolves the Droplets it is currently attached to, useful for auditing where persistent data lives and whether volumes are orphaned or shared.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"volumes":{"name":"volumes","type":"\u0019\u001bdigitalocean.volume","title":"Block storage volumes","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"DigitalOcean VPC","desc":"DigitalOcean Virtual Private Cloud, a private network that isolates Droplets, databases, load balancers, and Kubernetes clusters within a single region so they communicate over private addresses instead of the public internet. The `ipRange` field gives the network's CIDR and the `default` flag marks the region's default VPC, letting you audit network segmentation and confirm resources sit on the intended private network.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"vpcNatGateway":{"name":"vpcNatGateway","type":"\u001bdigitalocean.vpcNatGateway","title":"DigitalOcean VPC NAT gateway","desc":"Managed appliance that provides outbound internet connectivity for resources in one or more VPCs, letting them reach the internet without each holding a public address. The `type` field gives the gateway class (e.g., PUBLIC), alongside lifecycle `state`, `region`, and `size`. The `ingressVpcs` field lists each VPC attachment's gateway IP and whether it is the default route, and `egressPublicGatewayIps` are the public addresses outbound traffic egresses from, which downstream systems can allowlist. The `udpTimeoutSeconds`, `icmpTimeoutSeconds`, and `tcpTimeoutSeconds` fields expose the connection-tracking timeouts. Select a gateway by id with `digitalocean.vpcNatGateway(id: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"vpcNatGateways":{"name":"vpcNatGateways","type":"\u0019\u001bdigitalocean.vpcNatGateway","title":"VPC NAT gateways","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcPeering":{"name":"vpcPeering","type":"\u001bdigitalocean.vpcPeering","title":"DigitalOcean VPC peering","desc":"Private network connection between two DigitalOcean VPCs. A peering lets resources in the connected VPCs reach each other over the private network without traversing the public internet, so it defines a trust boundary between otherwise isolated networks that is worth auditing. The `vpcIds` field identifies the two VPCs participating and `status` reports where the peering sits in its lifecycle.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"vpcPeerings":{"name":"vpcPeerings","type":"\u0019\u001bdigitalocean.vpcPeering","title":"VPC peerings","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcs":{"name":"vpcs","type":"\u0019\u001bdigitalocean.vpc","title":"VPCs","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean account","desc":"Account-wide entry point for the DigitalOcean provider, grouping every queryable resource in the authenticated account: compute (droplets, autoscale pools, Kubernetes clusters, App Platform apps, serverless Functions), storage (block volumes, images, snapshots, Spaces buckets, container registry), networking (VPCs, VPC peerings and NAT gateways, load balancers, firewalls, reserved IPs, domains, CDN endpoints), managed databases, monitoring alert policies and uptime checks, projects and tags for grouping, and account billing. Start here to enumerate an account's full inventory or to scope an audit to one class of resource.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.account":{"id":"digitalocean.account","name":"digitalocean.account","fields":{"dropletLimit":{"name":"dropletLimit","type":"\u0005","is_mandatory":true,"title":"Droplet limit","provider":"go.mondoo.com/mql/providers/digitalocean"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Account email","provider":"go.mondoo.com/mql/providers/digitalocean"},"emailVerified":{"name":"emailVerified","type":"\u0004","is_mandatory":true,"title":"Email verified","provider":"go.mondoo.com/mql/providers/digitalocean"},"floatingIpLimit":{"name":"floatingIpLimit","type":"\u0005","is_mandatory":true,"title":"Floating IP limit","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Account status (active, warning, locked)","provider":"go.mondoo.com/mql/providers/digitalocean"},"statusMessage":{"name":"statusMessage","type":"\u0007","is_mandatory":true,"title":"Status message","provider":"go.mondoo.com/mql/providers/digitalocean"},"teamName":{"name":"teamName","type":"\u0007","is_mandatory":true,"title":"Display name of the team that owns this account; empty when the API token is not scoped to a team","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"teamUuid":{"name":"teamUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the team that owns this account; empty when the API token is not scoped to a team","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Account UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"volumeLimit":{"name":"volumeLimit","type":"\u0005","is_mandatory":true,"title":"Volume limit","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean account","desc":"Identity and standing of the DigitalOcean account the provider is authenticated against. The `status` field (active, warning, locked) and `statusMessage` reveal whether the account is in good standing or restricted, `emailVerified` flags an unverified primary email, and the per-resource limits (`dropletLimit`, `floatingIpLimit`, `volumeLimit`) cap what the account may provision. When the API token is scoped to a team, `teamUuid` and `teamName` identify the owning team.","min_provider_version":"13.0.1","defaults":"email status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.alertPolicy":{"id":"digitalocean.alertPolicy","name":"digitalocean.alertPolicy","fields":{"alertEmails":{"name":"alertEmails","type":"\u0019\u0007","is_mandatory":true,"title":"Email notification targets","provider":"go.mondoo.com/mql/providers/digitalocean"},"alertSlack":{"name":"alertSlack","type":"\u0019\n","is_mandatory":true,"title":"Slack notification targets","desc":"One entry per configured Slack destination. Each dict has a `channel` (the Slack channel name) and a `url` (the incoming webhook URL that receives the alert).","provider":"go.mondoo.com/mql/providers/digitalocean"},"compare":{"name":"compare","type":"\u0007","is_mandatory":true,"title":"Comparison operator (GreaterThan, LessThan)","provider":"go.mondoo.com/mql/providers/digitalocean"},"databases":{"name":"databases","type":"\u0019\u001bdigitalocean.database","title":"Managed databases monitored by this policy, resolved from entity IDs; empty for policies that target other entity types","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"droplets":{"name":"droplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets monitored by this policy, resolved from entity IDs; empty for policies that target non-droplet entities","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the alert is enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"entities":{"name":"entities","type":"\u0019\u0007","is_mandatory":true,"title":"Entity IDs being monitored","provider":"go.mondoo.com/mql/providers/digitalocean"},"kubernetesClusters":{"name":"kubernetesClusters","type":"\u0019\u001bdigitalocean.kubernetes.cluster","title":"Kubernetes clusters monitored by this policy, resolved from entity IDs; empty for policies that target other entity types","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001bdigitalocean.loadBalancer","title":"Load balancers monitored by this policy, resolved from entity IDs; empty for policies that target other entity types","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Alert type (e.g., v1/insights/droplet/cpu)","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Alert policy UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"value":{"name":"value","type":"\u0006","is_mandatory":true,"title":"Threshold value","provider":"go.mondoo.com/mql/providers/digitalocean"},"window":{"name":"window","type":"\u0007","is_mandatory":true,"title":"Window (5m, 10m, 30m, 1h)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean alert policy","desc":"Monitoring alert policy that fires when a metric crosses a threshold or an event occurs on the resources it watches. Use it to audit which conditions raise alerts, whether alerting is active (`enabled`), and where notifications are delivered. The `type` field (for example `v1/insights/droplet/cpu`) selects the metric or event being watched. The monitored resources resolve to `droplets`, `databases`, `loadBalancers`, and `kubernetesClusters` from the raw `entities` IDs.","min_provider_version":"13.0.1","defaults":"uuid type enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.app":{"id":"digitalocean.app","name":"digitalocean.app","fields":{"activeDeployment":{"name":"activeDeployment","type":"\u001bdigitalocean.app.deployment","title":"Currently active deployment, resolved from activeDeploymentId; null when the app has never deployed","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"activeDeploymentId":{"name":"activeDeploymentId","type":"\u0007","is_mandatory":true,"title":"ID of the currently active deployment; empty when the app has never deployed","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"activeDeploymentStatus":{"name":"activeDeploymentStatus","type":"\u0007","is_mandatory":true,"title":"Active deployment status","provider":"go.mondoo.com/mql/providers/digitalocean"},"alert":{"name":"alert","type":"\u001bdigitalocean.app.alert","title":"DigitalOcean App Platform alert","desc":"Single alert configured on an App Platform application or one of its components. `rule` identifies the metric or event the alert fires on (for example CPU_UTILIZATION or DEPLOYMENT_FAILED), with `operator`, `value`, and `window` describing the threshold for metric alerts. `componentName` is empty for app-level alerts, `disabled` reports whether the alert is currently off, `phase` its configuration state, and `emails` and `slackWebhookCount` the notification destinations. Use this to confirm that failure and resource-pressure alerting is actually enabled on production apps.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"alerts":{"name":"alerts","type":"\u0019\u001bdigitalocean.app.alert","title":"Alerts configured for the app and its components","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"defaultIngress":{"name":"defaultIngress","type":"\u0007","is_mandatory":true,"title":"Default DigitalOcean-assigned ingress hostname (under ondigitalocean.app)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"deployment":{"name":"deployment","type":"\u001bdigitalocean.app.deployment","title":"DigitalOcean App Platform deployment","desc":"Single deployment of an App Platform application. The `cause` records what triggered it (a manual action, a git push, or a container-image push), `phase` its lifecycle state, `tierSlug` the tier it ran on, `previousDeploymentId` the deployment it replaced, and `loadBalancerId` the load balancer serving it. The component-name lists (services, workers, jobs, staticSites, functions) record what the deployment ran, and the progress-step counts report how the build and deploy stages resolved. Audit change cadence, spot failed or superseded rollouts, and correlate a running app with the exact revision it serves.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"deployments":{"name":"deployments","type":"\u0019\u001bdigitalocean.app.deployment","title":"Deployment history for the app, most recent first","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"domains":{"name":"domains","type":"\u0019\n","is_mandatory":true,"title":"Custom domains attached to the app (each dict: id, name, phase, certificateExpiresAt)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"App ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"instances":{"name":"instances","type":"\u0019\n","title":"Ephemeral compute instances of the current deployment","desc":"Each entry: componentName, componentType (SERVICE, WORKER, JOB), instanceName, instanceAlias.","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"liveDomain":{"name":"liveDomain","type":"\u0007","is_mandatory":true,"title":"Primary custom domain serving the app; empty when none is configured","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"liveUrl":{"name":"liveUrl","type":"\u0007","is_mandatory":true,"title":"Live URL","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"App name","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the app belongs to","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the app belongs to","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug the app runs in","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"spec":{"name":"spec","type":"\n","is_mandatory":true,"title":"App component layout","desc":"Keys: name (the app name), and services, workers, jobs, staticSites, functions, each a list of that component type's names in the app spec.","provider":"go.mondoo.com/mql/providers/digitalocean"},"tierSlug":{"name":"tierSlug","type":"\u0007","is_mandatory":true,"title":"App tier slug (e.g., basic, professional)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the resource was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean App Platform application","desc":"Managed platform-as-a-service application on DigitalOcean, running containers, static sites, jobs, workers, and functions. The `liveUrl` and `liveDomain` report where the app is served, `activeDeploymentStatus` its current rollout state, and `spec` the component layout. Query the deployment history, active deployment, configured alerts, and running instances to audit what an app runs and how it is exposed.","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.app.alert":{"id":"digitalocean.app.alert","name":"digitalocean.app.alert","fields":{"appId":{"name":"appId","type":"\u0007","is_mandatory":true,"title":"ID of the parent app","provider":"go.mondoo.com/mql/providers/digitalocean"},"componentName":{"name":"componentName","type":"\u0007","is_mandatory":true,"title":"Component the alert applies to; empty for app-level alerts","provider":"go.mondoo.com/mql/providers/digitalocean"},"disabled":{"name":"disabled","type":"\u0004","is_mandatory":true,"title":"Whether the alert is disabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"emails":{"name":"emails","type":"\u0019\u0007","is_mandatory":true,"title":"Email destinations notified when the alert triggers","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Alert ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"operator":{"name":"operator","type":"\u0007","is_mandatory":true,"title":"Comparison operator (GREATER_THAN, LESS_THAN); empty for event alerts","provider":"go.mondoo.com/mql/providers/digitalocean"},"phase":{"name":"phase","type":"\u0007","is_mandatory":true,"title":"Configuration phase (PENDING, CONFIGURING, ACTIVE, ERROR)","provider":"go.mondoo.com/mql/providers/digitalocean"},"rule":{"name":"rule","type":"\u0007","is_mandatory":true,"title":"Metric or event the alert fires on (e.g., CPU_UTILIZATION, RESTART_COUNT, DEPLOYMENT_FAILED)","provider":"go.mondoo.com/mql/providers/digitalocean"},"slackWebhookCount":{"name":"slackWebhookCount","type":"\u0005","is_mandatory":true,"title":"Number of Slack webhook destinations configured for the alert","provider":"go.mondoo.com/mql/providers/digitalocean"},"value":{"name":"value","type":"\u0006","is_mandatory":true,"title":"Threshold value; meaningful only for metric alerts","provider":"go.mondoo.com/mql/providers/digitalocean"},"window":{"name":"window","type":"\u0007","is_mandatory":true,"title":"Evaluation window (e.g., FIVE_MINUTES, TEN_MINUTES, ONE_HOUR); empty for event alerts","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean App Platform alert","desc":"Single alert configured on an App Platform application or one of its components. `rule` identifies the metric or event the alert fires on (for example CPU_UTILIZATION or DEPLOYMENT_FAILED), with `operator`, `value`, and `window` describing the threshold for metric alerts. `componentName` is empty for app-level alerts, `disabled` reports whether the alert is currently off, `phase` its configuration state, and `emails` and `slackWebhookCount` the notification destinations. Use this to confirm that failure and resource-pressure alerting is actually enabled on production apps.","private":true,"min_provider_version":"13.10.2","defaults":"id rule phase","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.app.deployment":{"id":"digitalocean.app.deployment","name":"digitalocean.app.deployment","fields":{"appId":{"name":"appId","type":"\u0007","is_mandatory":true,"title":"ID of the parent app","provider":"go.mondoo.com/mql/providers/digitalocean"},"cause":{"name":"cause","type":"\u0007","is_mandatory":true,"title":"What triggered the deployment (e.g., a manual action, a git push, an image push)","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the deployment was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"functions":{"name":"functions","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the functions components in this deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Deployment ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"jobs":{"name":"jobs","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the job components in this deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"loadBalancer":{"name":"loadBalancer","type":"\u001bdigitalocean.loadBalancer","title":"Load balancer serving this deployment; null when the deployment has no dedicated load balancer","provider":"go.mondoo.com/mql/providers/digitalocean"},"loadBalancerId":{"name":"loadBalancerId","type":"\u0007","is_mandatory":true,"title":"ID of the load balancer serving this deployment; empty when none","provider":"go.mondoo.com/mql/providers/digitalocean"},"phase":{"name":"phase","type":"\u0007","is_mandatory":true,"title":"Lifecycle phase (UNKNOWN, PENDING_BUILD, BUILDING, PENDING_DEPLOY, DEPLOYING, ACTIVE, SUPERSEDED, ERROR, CANCELED)","provider":"go.mondoo.com/mql/providers/digitalocean"},"phaseLastUpdatedAt":{"name":"phaseLastUpdatedAt","type":"\t","is_mandatory":true,"title":"Time the deployment's phase last changed","provider":"go.mondoo.com/mql/providers/digitalocean"},"previousDeployment":{"name":"previousDeployment","type":"\u001bdigitalocean.app.deployment","title":"Deployment this one replaced; null for the first deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"previousDeploymentId":{"name":"previousDeploymentId","type":"\u0007","is_mandatory":true,"title":"ID of the deployment this one replaced; empty for the first deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"progressErrorSteps":{"name":"progressErrorSteps","type":"\u0005","is_mandatory":true,"title":"Number of build/deploy steps that errored","provider":"go.mondoo.com/mql/providers/digitalocean"},"progressSuccessSteps":{"name":"progressSuccessSteps","type":"\u0005","is_mandatory":true,"title":"Number of build/deploy steps that completed successfully","provider":"go.mondoo.com/mql/providers/digitalocean"},"progressTotalSteps":{"name":"progressTotalSteps","type":"\u0005","is_mandatory":true,"title":"Total number of build/deploy steps","provider":"go.mondoo.com/mql/providers/digitalocean"},"services":{"name":"services","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the service components in this deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"staticSites":{"name":"staticSites","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the static-site components in this deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"tierSlug":{"name":"tierSlug","type":"\u0007","is_mandatory":true,"title":"App tier slug active for this deployment","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the deployment was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"workers":{"name":"workers","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the worker components in this deployment","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean App Platform deployment","desc":"Single deployment of an App Platform application. The `cause` records what triggered it (a manual action, a git push, or a container-image push), `phase` its lifecycle state, `tierSlug` the tier it ran on, `previousDeploymentId` the deployment it replaced, and `loadBalancerId` the load balancer serving it. The component-name lists (services, workers, jobs, staticSites, functions) record what the deployment ran, and the progress-step counts report how the build and deploy stages resolved. Audit change cadence, spot failed or superseded rollouts, and correlate a running app with the exact revision it serves.","private":true,"min_provider_version":"13.10.2","defaults":"id phase cause","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.billing":{"id":"digitalocean.billing","name":"digitalocean.billing","fields":{"accountBalance":{"name":"accountBalance","type":"\u0007","is_mandatory":true,"title":"Total balance carried over at the start of the period (USD)","provider":"go.mondoo.com/mql/providers/digitalocean"},"generatedAt":{"name":"generatedAt","type":"\t","is_mandatory":true,"title":"Time these figures were generated","provider":"go.mondoo.com/mql/providers/digitalocean"},"monthToDateBalance":{"name":"monthToDateBalance","type":"\u0007","is_mandatory":true,"title":"Current month-to-date balance (USD)","provider":"go.mondoo.com/mql/providers/digitalocean"},"monthToDateUsage":{"name":"monthToDateUsage","type":"\u0007","is_mandatory":true,"title":"Usage accrued so far this billing period (USD)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean account billing balance","desc":"Account billing balance covering the balance carried over (accountBalance), the usage accrued so far this billing period (monthToDateUsage), the resulting monthToDateBalance, and the time the figures were generatedAt. A sudden jump in month-to-date usage is a common early signal of compromised resources (for example, crypto-mining droplets), so this is useful for spend-anomaly auditing. Amounts are USD strings as returned by the API to preserve exact formatting.","min_provider_version":"13.8.2","defaults":"monthToDateBalance monthToDateUsage","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.byoipPrefix":{"id":"digitalocean.byoipPrefix","name":"digitalocean.byoipPrefix","fields":{"advertised":{"name":"advertised","type":"\u0004","is_mandatory":true,"title":"Whether the prefix is currently advertised","provider":"go.mondoo.com/mql/providers/digitalocean"},"failureReason":{"name":"failureReason","type":"\u0007","is_mandatory":true,"title":"Reason the prefix failed validation/advertisement; empty on success","provider":"go.mondoo.com/mql/providers/digitalocean"},"locked":{"name":"locked","type":"\u0004","is_mandatory":true,"title":"Whether the prefix is locked (an operation is in flight)","provider":"go.mondoo.com/mql/providers/digitalocean"},"prefix":{"name":"prefix","type":"\u0007","is_mandatory":true,"title":"IP prefix in CIDR notation","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the prefix belongs to (resolved from projectId)","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the prefix belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"resource":{"name":"resource","type":"\u001bdigitalocean.byoipPrefix.resource","title":"DigitalOcean BYOIP prefix resource assignment","desc":"Single assignment of a bring-your-own-IP address to a resource in the account. The assigned byoip address, the resource URN it routes to (for example `do:droplet:123`), the region, and the assignedAt time record exactly what each advertised address reaches. Customer- owned address space routing to a specific droplet is an ownership and attack-surface concern worth inventorying. When the assignment targets a droplet, droplet resolves it.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"resources":{"name":"resources","type":"\u0019\u001bdigitalocean.byoipPrefix.resource","title":"Resources the prefix's addresses are currently assigned to","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Advertisement status","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Prefix UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"init":{"args":[{"name":"uuid","type":"\u0007","optional":true}]},"title":"DigitalOcean bring-your-own-IP prefix","desc":"Customer-owned IP prefix advertised into the account (BYOIP). The prefix CIDR, advertisement status, advertised and locked flags, region slug, and any failureReason from validation describe whether and where the address space routes. project resolves the owning project and resources lists the addresses the prefix is currently assigned to. Customer-controlled address space is a real ownership and attack-surface concern, so knowing which prefixes route into the account matters for security. Select a prefix by its uuid with `digitalocean.byoipPrefix(uuid: \"...\")`.","min_provider_version":"13.8.2","defaults":"prefix status region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.byoipPrefix.resource":{"id":"digitalocean.byoipPrefix.resource","name":"digitalocean.byoipPrefix.resource","fields":{"assignedAt":{"name":"assignedAt","type":"\t","is_mandatory":true,"title":"Time the address was assigned","provider":"go.mondoo.com/mql/providers/digitalocean"},"byoip":{"name":"byoip","type":"\u0007","is_mandatory":true,"title":"The specific BYOIP address assigned","provider":"go.mondoo.com/mql/providers/digitalocean"},"droplet":{"name":"droplet","type":"\u001bdigitalocean.droplet","title":"Droplet the address is assigned to; null unless the resource URN is a droplet","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Assignment ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"prefixUuid":{"name":"prefixUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the parent prefix","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"resource":{"name":"resource","type":"\u0007","is_mandatory":true,"title":"URN of the resource the address is assigned to (e.g., do:droplet:123)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean BYOIP prefix resource assignment","desc":"Single assignment of a bring-your-own-IP address to a resource in the account. The assigned byoip address, the resource URN it routes to (for example `do:droplet:123`), the region, and the assignedAt time record exactly what each advertised address reaches. Customer- owned address space routing to a specific droplet is an ownership and attack-surface concern worth inventorying. When the assignment targets a droplet, droplet resolves it.","private":true,"min_provider_version":"13.8.2","defaults":"resource region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.cdn":{"id":"digitalocean.cdn","name":"digitalocean.cdn","fields":{"certificate":{"name":"certificate","type":"\u001bdigitalocean.certificate","title":"TLS certificate bound to the endpoint; null when none is configured","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"certificateId":{"name":"certificateId","type":"\u0007","is_mandatory":true,"title":"TLS certificate ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"customDomain":{"name":"customDomain","type":"\u0007","is_mandatory":true,"title":"Custom domain","provider":"go.mondoo.com/mql/providers/digitalocean"},"endpoint":{"name":"endpoint","type":"\u0007","is_mandatory":true,"title":"CDN endpoint URL","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"CDN ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"origin":{"name":"origin","type":"\u0007","is_mandatory":true,"title":"Origin (Spaces bucket endpoint)","provider":"go.mondoo.com/mql/providers/digitalocean"},"ttl":{"name":"ttl","type":"\u0005","is_mandatory":true,"title":"TTL in seconds","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean CDN endpoint","desc":"Content delivery network endpoint that fronts a Spaces bucket, caching its objects at edge locations for faster public delivery. Useful for auditing how bucket content is exposed: the origin Spaces endpoint it serves, the public CDN URL, cache time-to-live, any custom domain, and the TLS certificate securing that domain (the `certificate` accessor resolves the bound certificate, or is null when none is configured).","min_provider_version":"13.0.1","defaults":"id origin","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.certificate":{"id":"digitalocean.certificate","name":"digitalocean.certificate","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"dnsNames":{"name":"dnsNames","type":"\u0019\u0007","is_mandatory":true,"title":"DNS names","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Certificate ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Certificate name","provider":"go.mondoo.com/mql/providers/digitalocean"},"notAfter":{"name":"notAfter","type":"\t","is_mandatory":true,"title":"Expiration","provider":"go.mondoo.com/mql/providers/digitalocean"},"sha1Fingerprint":{"name":"sha1Fingerprint","type":"\u0007","is_mandatory":true,"title":"SHA-1 fingerprint","provider":"go.mondoo.com/mql/providers/digitalocean"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"State (pending, verified, error)","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Type (custom, lets_encrypt)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean TLS certificate","desc":"TLS certificate held by DigitalOcean for use with load balancers, CDN endpoints, or App Platform. Audit these to confirm certificates are `verified` rather than stuck in `pending` or `error`, to catch approaching expirations via `notAfter`, and to see which DNS names each certificate covers. The `type` field distinguishes operator-supplied certificates from DigitalOcean-managed Let's Encrypt certificates.","min_provider_version":"13.0.1","defaults":"id name state","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.database":{"id":"digitalocean.database","name":"digitalocean.database","fields":{"backup":{"name":"backup","type":"\u001bdigitalocean.database.backup","title":"DigitalOcean database automated backup","desc":"Single automated backup retained for a managed database cluster. Surfaces the `createdAt` time and the on-disk `sizeGigabytes`. Use these to verify that backups are being taken on the expected cadence (no large gap in `createdAt`) and that backup size growth is tracking actual data growth.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"backupCount":{"name":"backupCount","type":"\u0005","title":"Number of automated backups currently retained","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"backups":{"name":"backups","type":"\u0019\u001bdigitalocean.database.backup","title":"Automated backups currently retained for the cluster","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"caCertificate":{"name":"caCertificate","type":"\u0007","title":"PEM-encoded X.509 CA certificate that signs the cluster's TLS endpoint (clients use this to verify connections)","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"connectionHost":{"name":"connectionHost","type":"\u0007","is_mandatory":true,"title":"Public connection host","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"connectionPort":{"name":"connectionPort","type":"\u0005","is_mandatory":true,"title":"Public connection port","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"connectionSslEnabled":{"name":"connectionSslEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the cluster's primary connection enforces TLS/SSL","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"dbNames":{"name":"dbNames","type":"\u0019\u0007","is_mandatory":true,"title":"Names of the logical databases hosted on the cluster","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"engine":{"name":"engine","type":"\u0007","is_mandatory":true,"title":"Database engine (pg, mysql, redis, mongodb, kafka, opensearch)","provider":"go.mondoo.com/mql/providers/digitalocean"},"evictionPolicy":{"name":"evictionPolicy","type":"\u0007","title":"Key eviction policy for Redis/Valkey clusters","desc":"One of noeviction, allkeys_lru, allkeys_random, volatile_lru, volatile_random, volatile_ttl. Empty for other engines.","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"firewallRules":{"name":"firewallRules","type":"\u0019\n","title":"Trusted-source firewall rules controlling which clients may reach the cluster","desc":"Each entry is a dict with keys: uuid (the rule's identifier), type (the trusted-source kind, one of ip_addr, droplet, k8s, tag, or app), value (the source identifier, a CIDR when type is ip_addr or the resource UUID/tag name otherwise), and createdAt (RFC 3339 timestamp). See `internetReachable` for whether these rules leave the public endpoint open to every address.","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Database cluster ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the cluster is reachable from the internet","desc":"True when the cluster has a public connection endpoint and its trusted-source firewall rules admit any address (an ip_addr rule of 0.0.0.0/0 or ::/0), or when no trusted-source rules are configured at all, which leaves the public endpoint open to every address.","min_provider_version":"13.7.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"latestBackupAt":{"name":"latestBackupAt","type":"\t","title":"Timestamp of the most recent automated backup; zero when no backups are retained","min_provider_version":"13.2.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"maintenanceWindow":{"name":"maintenanceWindow","type":"\n","is_mandatory":true,"title":"Maintenance window during which the cluster applies updates","desc":"Dict with keys: day (weekday name the window opens, for example \"monday\"), hour (window start time formatted as \"HH:MM:SS\"), and pending (bool, true when maintenance updates are waiting to be applied in the next window).","provider":"go.mondoo.com/mql/providers/digitalocean"},"metricsEndpoints":{"name":"metricsEndpoints","type":"\u0019\n","is_mandatory":true,"title":"Prometheus-compatible metrics endpoints exposed by the cluster (each dict: host, port)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Database cluster name","provider":"go.mondoo.com/mql/providers/digitalocean"},"numNodes":{"name":"numNodes","type":"\u0005","is_mandatory":true,"title":"Number of nodes","provider":"go.mondoo.com/mql/providers/digitalocean"},"pool":{"name":"pool","type":"\u001bdigitalocean.database.pool","title":"DigitalOcean database connection pool","desc":"A connection pool fronting a managed database cluster. Surfaces the pool `name`, the logical `database` it connects to, the `user` it authenticates as, the pool `size`, and the connection `mode` (transaction, session, or statement).","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"pools":{"name":"pools","type":"\u0019\u001bdigitalocean.database.pool","title":"Connection pools","provider":"go.mondoo.com/mql/providers/digitalocean"},"privateConnectionHost":{"name":"privateConnectionHost","type":"\u0007","is_mandatory":true,"title":"Private connection host (reachable within the VPC)","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"privateConnectionPort":{"name":"privateConnectionPort","type":"\u0005","is_mandatory":true,"title":"Private connection port (reachable within the VPC)","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"privateNetworkUuid":{"name":"privateNetworkUuid","type":"\u0007","is_mandatory":true,"title":"Private network UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the cluster belongs to","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the cluster belongs to","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"replica":{"name":"replica","type":"\u001bdigitalocean.database.replica","title":"DigitalOcean database replica","desc":"A read-only replica of a managed database cluster. Surfaces the replica `name`, its `region` and `size` slug, lifecycle `status`, the applied `tags`, and the creation time. Use this to confirm replicas exist for read scaling or cross-region redundancy and that they are online.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"replicas":{"name":"replicas","type":"\u0019\u001bdigitalocean.database.replica","title":"Database replicas","provider":"go.mondoo.com/mql/providers/digitalocean"},"serviceCnames":{"name":"serviceCnames","type":"\u0019\u0007","is_mandatory":true,"title":"DNS CNAMEs that resolve to the cluster's connection endpoints","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0007","is_mandatory":true,"title":"Size slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"sqlMode":{"name":"sqlMode","type":"\u0007","title":"SQL mode flags configured on the cluster (MySQL only)","desc":"The comma-separated SQL mode string returned by the MySQL engine (for example STRICT_TRANS_TABLES, NO_ZERO_DATE). Empty for non-MySQL engines. Fetched on demand from the cluster's SQL-mode endpoint.","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"standbyConnectionHost":{"name":"standbyConnectionHost","type":"\u0007","is_mandatory":true,"title":"Standby (failover) public connection host; empty when the cluster has no standby node","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"standbyConnectionPort":{"name":"standbyConnectionPort","type":"\u0005","is_mandatory":true,"title":"Standby (failover) public connection port; zero when the cluster has no standby node","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"standbyPrivateConnectionHost":{"name":"standbyPrivateConnectionHost","type":"\u0007","is_mandatory":true,"title":"Standby (failover) private connection host reachable within the VPC; empty when the cluster has no standby node","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"standbyPrivateConnectionPort":{"name":"standbyPrivateConnectionPort","type":"\u0005","is_mandatory":true,"title":"Standby (failover) private connection port reachable within the VPC; zero when the cluster has no standby node","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (creating, online, resizing, migrating, forking)","provider":"go.mondoo.com/mql/providers/digitalocean"},"storageAutoscaleEnabled":{"name":"storageAutoscaleEnabled","type":"\u0004","is_mandatory":true,"title":"Whether storage autoscaling is enabled for the cluster","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"storageAutoscaleIncrementGib":{"name":"storageAutoscaleIncrementGib","type":"\u0005","is_mandatory":true,"title":"Storage increment added on each autoscale event, in gibibytes; null when autoscaling is disabled","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"storageAutoscaleThresholdPercent":{"name":"storageAutoscaleThresholdPercent","type":"\u0005","is_mandatory":true,"title":"Disk-usage percentage that triggers an autoscale storage increase; null when autoscaling is disabled","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"storageSizeMib":{"name":"storageSizeMib","type":"\u0005","is_mandatory":true,"title":"Allocated storage size, in mebibytes","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"user":{"name":"user","type":"\u001bdigitalocean.database.user","title":"DigitalOcean database user","desc":"A user account on a managed database cluster. Surfaces the `name` and the `role` (primary or normal) granted on the cluster. Use this to audit which accounts exist on a cluster and which hold the primary role.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"users":{"name":"users","type":"\u0019\u001bdigitalocean.database.user","title":"Database users","provider":"go.mondoo.com/mql/providers/digitalocean"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Database engine version","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the cluster is attached to (resolved from privateNetworkUuid)","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean managed database cluster","desc":"Managed relational, key-value, document, or streaming database cluster; the `engine` field distinguishes PostgreSQL, MySQL, Redis, MongoDB, Kafka, and OpenSearch. Reports the cluster's size, node count, region, and lifecycle status alongside its network exposure (public and private connection endpoints, the attached VPC, and the trusted-source firewall rules), its TLS material, and its backup, user, replica, and connection-pool children. Audit a cluster to confirm it is not reachable from the public internet, that its connections enforce TLS, and that automated backups are current. Select a cluster by id with `digitalocean.database(id: \"...\")`.","min_provider_version":"13.0.1","defaults":"id name engine","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.database.backup":{"id":"digitalocean.database.backup","name":"digitalocean.database.backup","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the backup was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"database":{"name":"database","type":"\u001bdigitalocean.database","title":"Parent database cluster","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"databaseId":{"name":"databaseId","type":"\u0007","is_mandatory":true,"title":"ID of the parent database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeGigabytes":{"name":"sizeGigabytes","type":"\u0006","is_mandatory":true,"title":"Backup size in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean database automated backup","desc":"Single automated backup retained for a managed database cluster. Surfaces the `createdAt` time and the on-disk `sizeGigabytes`. Use these to verify that backups are being taken on the expected cadence (no large gap in `createdAt`) and that backup size growth is tracking actual data growth.","private":true,"min_provider_version":"13.2.1","defaults":"databaseId createdAt sizeGigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.database.pool":{"id":"digitalocean.database.pool","name":"digitalocean.database.pool","fields":{"database":{"name":"database","type":"\u0007","is_mandatory":true,"title":"Database name the pool connects to","provider":"go.mondoo.com/mql/providers/digitalocean"},"databaseCluster":{"name":"databaseCluster","type":"\u001bdigitalocean.database","title":"Parent database cluster","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"databaseId":{"name":"databaseId","type":"\u0007","is_mandatory":true,"title":"ID of the parent database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Connection mode (transaction, session, statement)","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Pool name","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Pool size","provider":"go.mondoo.com/mql/providers/digitalocean"},"user":{"name":"user","type":"\u0007","is_mandatory":true,"title":"Database user the pool authenticates as","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean database connection pool","desc":"A connection pool fronting a managed database cluster. Surfaces the pool `name`, the logical `database` it connects to, the `user` it authenticates as, the pool `size`, and the connection `mode` (transaction, session, or statement).","private":true,"min_provider_version":"13.0.1","defaults":"name mode","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.database.replica":{"id":"digitalocean.database.replica","name":"digitalocean.database.replica","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"database":{"name":"database","type":"\u001bdigitalocean.database","title":"Parent database cluster","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"databaseId":{"name":"databaseId","type":"\u0007","is_mandatory":true,"title":"ID of the parent database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Replica name","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0007","is_mandatory":true,"title":"Size slug (DigitalOcean droplet size identifier)","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Replica status (e.g., creating, online, forking, migrating, offline)","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to the replica","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean database replica","desc":"A read-only replica of a managed database cluster. Surfaces the replica `name`, its `region` and `size` slug, lifecycle `status`, the applied `tags`, and the creation time. Use this to confirm replicas exist for read scaling or cross-region redundancy and that they are online.","private":true,"min_provider_version":"13.0.1","defaults":"name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.database.user":{"id":"digitalocean.database.user","name":"digitalocean.database.user","fields":{"database":{"name":"database","type":"\u001bdigitalocean.database","title":"Parent database cluster","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"databaseId":{"name":"databaseId","type":"\u0007","is_mandatory":true,"title":"ID of the parent database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Username","provider":"go.mondoo.com/mql/providers/digitalocean"},"role":{"name":"role","type":"\u0007","is_mandatory":true,"title":"Role (primary, normal)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean database user","desc":"A user account on a managed database cluster. Surfaces the `name` and the `role` (primary or normal) granted on the cluster. Use this to audit which accounts exist on a cluster and which hold the primary role.","private":true,"min_provider_version":"13.0.1","defaults":"name role","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.domain":{"id":"digitalocean.domain","name":"digitalocean.domain","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Domain name","provider":"go.mondoo.com/mql/providers/digitalocean"},"record":{"name":"record","type":"\u001bdigitalocean.domain.record","title":"DigitalOcean DNS record","desc":"A single DNS record within a DigitalOcean-managed domain. Surfaces the record `type` (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA), the record `name` (subdomain), the `data` it resolves to, the `ttl`, and the `priority`, `port`, and `weight` used by MX and SRV records. Use this to audit zone contents (for example, dangling CNAMEs or unexpected records).","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"records":{"name":"records","type":"\u0019\u001bdigitalocean.domain.record","title":"DNS records","provider":"go.mondoo.com/mql/providers/digitalocean"},"ttl":{"name":"ttl","type":"\u0005","is_mandatory":true,"title":"TTL in seconds","provider":"go.mondoo.com/mql/providers/digitalocean"},"zoneFile":{"name":"zoneFile","type":"\u0007","is_mandatory":true,"title":"Zone file contents","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean DNS domain","desc":"DNS zone that DigitalOcean serves for a registered domain name. The zone TTL, the raw `zoneFile` contents as DigitalOcean serves them, and the individual `records` defined under the domain (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA) are queryable, which supports auditing zone contents for dangling references or unexpected entries.","min_provider_version":"13.0.1","defaults":"name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.domain.record":{"id":"digitalocean.domain.record","name":"digitalocean.domain.record","fields":{"data":{"name":"data","type":"\u0007","is_mandatory":true,"title":"Record data (IP, hostname, etc.)","provider":"go.mondoo.com/mql/providers/digitalocean"},"domainName":{"name":"domainName","type":"\u0007","is_mandatory":true,"title":"Name of the parent domain","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Record ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Record name (subdomain)","provider":"go.mondoo.com/mql/providers/digitalocean"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Port (SRV)","provider":"go.mondoo.com/mql/providers/digitalocean"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Priority (MX, SRV)","provider":"go.mondoo.com/mql/providers/digitalocean"},"ttl":{"name":"ttl","type":"\u0005","is_mandatory":true,"title":"TTL in seconds","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Record type (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA)","provider":"go.mondoo.com/mql/providers/digitalocean"},"weight":{"name":"weight","type":"\u0005","is_mandatory":true,"title":"Weight (SRV)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean DNS record","desc":"A single DNS record within a DigitalOcean-managed domain. Surfaces the record `type` (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA), the record `name` (subdomain), the `data` it resolves to, the `ttl`, and the `priority`, `port`, and `weight` used by MX and SRV records. Use this to audit zone contents (for example, dangling CNAMEs or unexpected records).","private":true,"min_provider_version":"13.0.1","defaults":"type name data","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.droplet":{"id":"digitalocean.droplet","name":"digitalocean.droplet","fields":{"backups":{"name":"backups","type":"\u0019\u001bdigitalocean.image","title":"Automated backup images retained for this droplet","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"backupsEnabled":{"name":"backupsEnabled","type":"\u0004","is_mandatory":true,"title":"Backup enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"baseImage":{"name":"baseImage","type":"\u001bdigitalocean.image","title":"Base image the droplet runs","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"disk":{"name":"disk","type":"\u0005","is_mandatory":true,"title":"Disk capacity allocated to the droplet, in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletSize":{"name":"dropletSize","type":"\u001bdigitalocean.size","title":"Hardware tier the droplet runs on, resolved from the size slug","min_provider_version":"13.13.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"exposure":{"name":"exposure","type":"\u001bdigitalocean.network.exposure","title":"Internet-exposure breakdown (public IP combined with firewall ingress)","min_provider_version":"13.7.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"features":{"name":"features","type":"\u0019\u0007","is_mandatory":true,"title":"Features (e.g., monitoring, backups)","provider":"go.mondoo.com/mql/providers/digitalocean"},"firewalls":{"name":"firewalls","type":"\u0019\u001bdigitalocean.firewall","title":"Firewalls covering this droplet (by id or matching tag)","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Droplet ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"image":{"name":"image","type":"\n","is_mandatory":true,"title":"Raw image details dict (id, name, distribution, slug)","desc":"Deprecated in favor of `baseImage`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"kernel":{"name":"kernel","type":"\n","is_mandatory":true,"title":"Linux kernel the droplet boots (id, name, version); null on droplets using the current external boot loader","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"locked":{"name":"locked","type":"\u0004","is_mandatory":true,"title":"Whether the droplet is locked while an action is in progress","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"memory":{"name":"memory","type":"\u0005","is_mandatory":true,"title":"Memory allocated to the droplet, in megabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"missingFirewall":{"name":"missingFirewall","type":"\u0004","title":"True when no firewall is attached to the droplet (by id or tag); does not check inbound rule restrictiveness. For that, query `firewalls`","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"monitoringEnabled":{"name":"monitoringEnabled","type":"\u0004","is_mandatory":true,"title":"Monitoring enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Droplet name","provider":"go.mondoo.com/mql/providers/digitalocean"},"nextBackupWindowEnd":{"name":"nextBackupWindowEnd","type":"\t","is_mandatory":true,"title":"End of the next scheduled automated-backup window; null when backups are disabled","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"nextBackupWindowStart":{"name":"nextBackupWindowStart","type":"\t","is_mandatory":true,"title":"Start of the next scheduled automated-backup window; null when backups are disabled","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"privateIpv4":{"name":"privateIpv4","type":"\u0007","is_mandatory":true,"title":"Private IPv4 address","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicIpv4":{"name":"publicIpv4","type":"\u0007","is_mandatory":true,"title":"Public IPv4 address","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicIpv6":{"name":"publicIpv6","type":"\u0007","is_mandatory":true,"title":"Public IPv6 address","min_provider_version":"13.1.7","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug (DigitalOcean datacenter identifier, e.g., nyc3, ams3)","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0007","is_mandatory":true,"title":"Size slug (DigitalOcean droplet size identifier, e.g., s-1vcpu-1gb)","provider":"go.mondoo.com/mql/providers/digitalocean"},"snapshots":{"name":"snapshots","type":"\u0019\u001bdigitalocean.snapshot","title":"Snapshots taken of this droplet","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (new, active, off, archive)","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to the droplet","provider":"go.mondoo.com/mql/providers/digitalocean"},"vcpus":{"name":"vcpus","type":"\u0005","is_mandatory":true,"title":"Number of virtual CPUs allocated to the droplet","provider":"go.mondoo.com/mql/providers/digitalocean"},"volumes":{"name":"volumes","type":"\u0019\u001bdigitalocean.volume","title":"Block storage volumes attached to the droplet","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the droplet is attached to","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcUuid":{"name":"vpcUuid","type":"\u0007","is_mandatory":true,"title":"VPC UUID","desc":"Deprecated in favor of `vpc()`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"}},"title":"DigitalOcean Droplet","desc":"Cloud virtual machine in a DigitalOcean account, covering its compute shape (memory, vCPUs, disk, region and size slug), its network addresses (public and private IPv4, public IPv6), and the base image and kernel it boots. Security posture is queryable through the firewalls covering the droplet (resolved by direct ID or matching tag), the missingFirewall predicate that flags droplets with no firewall attached, and the exposure breakdown that combines a public IP with firewall ingress to gauge internet reachability.","min_provider_version":"13.0.1","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.dropletAutoscalePool":{"id":"digitalocean.dropletAutoscalePool","name":"digitalocean.dropletAutoscalePool","fields":{"cooldownMinutes":{"name":"cooldownMinutes","type":"\u0005","is_mandatory":true,"title":"Cooldown between scaling actions, in minutes","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the pool was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"currentCpuUtilization":{"name":"currentCpuUtilization","type":"\u0006","is_mandatory":true,"title":"Current average CPU utilization across the pool, as a fraction","provider":"go.mondoo.com/mql/providers/digitalocean"},"currentMemoryUtilization":{"name":"currentMemoryUtilization","type":"\u0006","is_mandatory":true,"title":"Current average memory utilization across the pool, as a fraction","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletTemplate":{"name":"dropletTemplate","type":"\n","is_mandatory":true,"title":"Droplet template new members are created from","desc":"Keys: `size`, `region`, `image`, `tags`, `sshKeys`, `vpcUuid`, `projectId`, `ipv6`, `withDropletAgent`, `publicNetworking`, and `userData`.","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Autoscale pool ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"maxInstances":{"name":"maxInstances","type":"\u0005","is_mandatory":true,"title":"Maximum number of droplets","provider":"go.mondoo.com/mql/providers/digitalocean"},"members":{"name":"members","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets that are currently members of the pool","provider":"go.mondoo.com/mql/providers/digitalocean"},"minInstances":{"name":"minInstances","type":"\u0005","is_mandatory":true,"title":"Minimum number of droplets","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project new members are created in","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","provider":"go.mondoo.com/mql/providers/digitalocean"},"targetCpuUtilization":{"name":"targetCpuUtilization","type":"\u0006","is_mandatory":true,"title":"Target average CPU utilization that triggers scaling, as a fraction","provider":"go.mondoo.com/mql/providers/digitalocean"},"targetMemoryUtilization":{"name":"targetMemoryUtilization","type":"\u0006","is_mandatory":true,"title":"Target average memory utilization that triggers scaling, as a fraction","provider":"go.mondoo.com/mql/providers/digitalocean"},"targetNumberInstances":{"name":"targetNumberInstances","type":"\u0005","is_mandatory":true,"title":"Fixed target droplet count (when using static rather than dynamic scaling)","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the pool was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC new members are attached to","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean droplet autoscale pool","desc":"Group of droplets whose count automatically scales to meet CPU and memory targets, useful for confirming that elastic capacity stays within governed bounds. The scaling policy is flattened onto the pool: `minInstances` and `maxInstances` bound dynamic scaling, `targetCpuUtilization` and `targetMemoryUtilization` set the fractions that trigger it, `cooldownMinutes` throttles successive actions, and `targetNumberInstances` pins a fixed count for static scaling. `currentCpuUtilization` and `currentMemoryUtilization` report live load, while `dropletTemplate` captures the spec new members are created from. Select a pool by id with `digitalocean.dropletAutoscalePool(id: \"...\")`.","min_provider_version":"13.4.2","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.firewall":{"id":"digitalocean.firewall","name":"digitalocean.firewall","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletIds":{"name":"dropletIds","type":"\u0019\u0005","is_mandatory":true,"title":"Droplet IDs protected by this firewall","desc":"Deprecated in favor of `droplets()`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"droplets":{"name":"droplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets covered by this firewall (by direct ID or matching tag)","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"egressRule":{"name":"egressRule","type":"\u001bdigitalocean.firewall.egressRule","title":"Egress rule of a DigitalOcean cloud firewall","desc":"Single egress (outbound) rule controlling traffic that leaves the droplets a firewall protects. `protocol` is tcp, udp, or icmp and `ports` is the affected port or range (a single port like \"3306\", a range like \"8000-9000\", or \"0\"/\"all\" for every port). `openToInternet` is true when the rule permits traffic to any address, that is, when `destinationAddresses` contains 0.0.0.0/0 or ::/0. The destination is otherwise described by `destinationAddresses` (CIDRs), `destinationTags`, and the `destinationDroplets`, `destinationLoadBalancers`, and `destinationKubernetesClusters` the rule allows.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"egressRules":{"name":"egressRules","type":"\u0019\u001bdigitalocean.firewall.egressRule","title":"Egress rules controlling outgoing traffic from protected droplets","min_provider_version":"13.5.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Firewall ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"inboundRules":{"name":"inboundRules","type":"\u0019\n","is_mandatory":true,"title":"Rules controlling incoming traffic to protected droplets","desc":"Deprecated in favor of `ingressRules`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"ingressRule":{"name":"ingressRule","type":"\u001bdigitalocean.firewall.ingressRule","title":"Ingress rule of a DigitalOcean cloud firewall","desc":"Single ingress (inbound) rule controlling traffic that reaches the droplets a firewall protects. `protocol` is tcp, udp, or icmp and `ports` is the affected port or range (a single port like \"3306\", a range like \"8000-9000\", or \"0\"/\"all\" for every port). `openToInternet` is true when the rule admits traffic from any address, that is, when `sourceAddresses` contains 0.0.0.0/0 or ::/0, which makes auditing publicly reachable ports a single predicate. The source is otherwise described by `sourceAddresses` (CIDRs), `sourceTags`, and the `sourceDroplets`, `sourceLoadBalancers`, and `sourceKubernetesClusters` the rule trusts.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"ingressRules":{"name":"ingressRules","type":"\u0019\u001bdigitalocean.firewall.ingressRule","title":"Ingress rules controlling incoming traffic to protected droplets","min_provider_version":"13.5.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Firewall name","provider":"go.mondoo.com/mql/providers/digitalocean"},"outboundRules":{"name":"outboundRules","type":"\u0019\n","is_mandatory":true,"title":"Rules controlling outgoing traffic from protected droplets","desc":"Deprecated in favor of `egressRules`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (waiting, succeeded, failed)","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags used to target droplets","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean firewall","desc":"Cloud-firewall rule set governing traffic to and from a group of droplets. The `status` field reports provisioning progress (waiting, succeeded, failed). The `ingressRules` and `egressRules` control incoming and outgoing traffic, each rule exposing protocol, ports, and the `openToInternet` predicate that flags rules reachable from any address (0.0.0.0/0 or ::/0), plus references to the droplets, load balancers, and Kubernetes clusters it targets. The `tags` select protected droplets by tag, and `droplets` resolves the full set covered by the firewall (by direct ID or matching tag).","min_provider_version":"13.0.1","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.firewall.egressRule":{"id":"digitalocean.firewall.egressRule","name":"digitalocean.firewall.egressRule","fields":{"destinationAddresses":{"name":"destinationAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Destination address CIDRs allowed by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"destinationDroplets":{"name":"destinationDroplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets allowed as a traffic destination by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"destinationKubernetesClusters":{"name":"destinationKubernetesClusters","type":"\u0019\u001bdigitalocean.kubernetes.cluster","title":"Kubernetes clusters allowed as a traffic destination by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"destinationLoadBalancers":{"name":"destinationLoadBalancers","type":"\u0019\u001bdigitalocean.loadBalancer","title":"Load balancers allowed as a traffic destination by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"destinationTags":{"name":"destinationTags","type":"\u0019\u0007","is_mandatory":true,"title":"Destination droplet tags allowed by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"openToInternet":{"name":"openToInternet","type":"\u0004","is_mandatory":true,"title":"Whether the rule permits traffic to any address (0.0.0.0/0 or ::/0)","provider":"go.mondoo.com/mql/providers/digitalocean"},"ports":{"name":"ports","type":"\u0007","is_mandatory":true,"title":"Affected port or range","desc":"A single port (\"3306\"), a range (\"8000-9000\"), or \"0\"/\"all\" for every port.","provider":"go.mondoo.com/mql/providers/digitalocean"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Network protocol (tcp, udp, or icmp)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"Egress rule of a DigitalOcean cloud firewall","desc":"Single egress (outbound) rule controlling traffic that leaves the droplets a firewall protects. `protocol` is tcp, udp, or icmp and `ports` is the affected port or range (a single port like \"3306\", a range like \"8000-9000\", or \"0\"/\"all\" for every port). `openToInternet` is true when the rule permits traffic to any address, that is, when `destinationAddresses` contains 0.0.0.0/0 or ::/0. The destination is otherwise described by `destinationAddresses` (CIDRs), `destinationTags`, and the `destinationDroplets`, `destinationLoadBalancers`, and `destinationKubernetesClusters` the rule allows.","private":true,"min_provider_version":"13.5.2","defaults":"protocol ports openToInternet","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.firewall.ingressRule":{"id":"digitalocean.firewall.ingressRule","name":"digitalocean.firewall.ingressRule","fields":{"openToInternet":{"name":"openToInternet","type":"\u0004","is_mandatory":true,"title":"Whether the rule admits traffic from any address (0.0.0.0/0 or ::/0)","provider":"go.mondoo.com/mql/providers/digitalocean"},"ports":{"name":"ports","type":"\u0007","is_mandatory":true,"title":"Affected port or range","desc":"A single port (\"3306\"), a range (\"8000-9000\"), or \"0\"/\"all\" for every port.","provider":"go.mondoo.com/mql/providers/digitalocean"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Network protocol (tcp, udp, or icmp)","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceAddresses":{"name":"sourceAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Source address CIDRs trusted by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceDroplets":{"name":"sourceDroplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets trusted as a traffic source by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceKubernetesClusters":{"name":"sourceKubernetesClusters","type":"\u0019\u001bdigitalocean.kubernetes.cluster","title":"Kubernetes clusters trusted as a traffic source by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceLoadBalancers":{"name":"sourceLoadBalancers","type":"\u0019\u001bdigitalocean.loadBalancer","title":"Load balancers trusted as a traffic source by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceTags":{"name":"sourceTags","type":"\u0019\u0007","is_mandatory":true,"title":"Source droplet tags trusted by this rule","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"Ingress rule of a DigitalOcean cloud firewall","desc":"Single ingress (inbound) rule controlling traffic that reaches the droplets a firewall protects. `protocol` is tcp, udp, or icmp and `ports` is the affected port or range (a single port like \"3306\", a range like \"8000-9000\", or \"0\"/\"all\" for every port). `openToInternet` is true when the rule admits traffic from any address, that is, when `sourceAddresses` contains 0.0.0.0/0 or ::/0, which makes auditing publicly reachable ports a single predicate. The source is otherwise described by `sourceAddresses` (CIDRs), `sourceTags`, and the `sourceDroplets`, `sourceLoadBalancers`, and `sourceKubernetesClusters` the rule trusts.","private":true,"min_provider_version":"13.5.2","defaults":"protocol ports openToInternet","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.function":{"id":"digitalocean.function","fields":{"accessKey":{"name":"accessKey","type":"\u001bdigitalocean.function.accessKey","title":"DigitalOcean Functions access key","desc":"An access key issued for a Functions namespace's API. The secret value is never exposed; only metadata is surfaced: the key id and name, the creation and last-used times, and the expiry. Use `lastUsedAt` and `expiresAt` to audit for stale or never-expiring namespace credentials.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"action":{"name":"action","type":"\u001bdigitalocean.function.action","title":"DigitalOcean Functions action","desc":"Single function (action) deployed in a Functions namespace, covering the action `name` and the `package` it belongs to, the `runtime` it executes on, the resource limits (`timeoutMs`, `memoryMb`, `logSizeMb`, `concurrency`), and its security posture: `webExported` flags an action published as a raw public HTTP endpoint, and `requiresApiKey` reports whether such a web action still demands authentication. Query it to audit for unauthenticated web functions and to inventory the serverless code running in an account.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"namespace":{"name":"namespace","type":"\u001bdigitalocean.function.namespace","title":"DigitalOcean Functions namespace","desc":"Deployment unit that groups serverless functions and their schedules in a region. Each namespace has a human-readable `label`, an API host that serves its functions, and an internal `namespace` identifier used in API paths. The functions deployed here, the scheduled triggers that invoke them, and the access keys issued for the namespace API are all queryable, making this the entry point for inventorying serverless workloads and auditing the credentials that reach them.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"trigger":{"name":"trigger","type":"\u001bdigitalocean.function.trigger","title":"DigitalOcean Functions trigger","desc":"Trigger that invokes a function in a namespace, exposing the trigger `name`, its `type` (for example SCHEDULED), the `function` it invokes, and whether it is `enabled`. For scheduled triggers, `cron` is the schedule expression and `lastRunAt` and `nextRunAt` report the firing history. Query it to confirm that expected schedules are enabled and firing.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true}},"is_extension":true},"digitalocean.function.accessKey":{"id":"digitalocean.function.accessKey","name":"digitalocean.function.accessKey","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the key was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Time the key expires; null when the key does not expire","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Access key ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"lastUsedAt":{"name":"lastUsedAt","type":"\t","is_mandatory":true,"title":"Time the key was last used; null when the key has never been used","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/digitalocean"},"namespaceUuid":{"name":"namespaceUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the parent namespace","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the key was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Functions access key","desc":"An access key issued for a Functions namespace's API. The secret value is never exposed; only metadata is surfaced: the key id and name, the creation and last-used times, and the expiry. Use `lastUsedAt` and `expiresAt` to audit for stale or never-expiring namespace credentials.","private":true,"min_provider_version":"13.10.2","defaults":"name lastUsedAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.function.action":{"id":"digitalocean.function.action","name":"digitalocean.function.action","fields":{"concurrency":{"name":"concurrency","type":"\u0005","is_mandatory":true,"title":"Number of concurrent activations allowed","provider":"go.mondoo.com/mql/providers/digitalocean"},"logSizeMb":{"name":"logSizeMb","type":"\u0005","is_mandatory":true,"title":"Log size limit, in megabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"memoryMb":{"name":"memoryMb","type":"\u0005","is_mandatory":true,"title":"Memory limit, in megabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Action name","provider":"go.mondoo.com/mql/providers/digitalocean"},"namespaceUuid":{"name":"namespaceUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the parent namespace","provider":"go.mondoo.com/mql/providers/digitalocean"},"package":{"name":"package","type":"\u0007","is_mandatory":true,"title":"Package the action belongs to; empty for actions at the namespace root","provider":"go.mondoo.com/mql/providers/digitalocean"},"requiresApiKey":{"name":"requiresApiKey","type":"\u0004","is_mandatory":true,"title":"Whether an invoker must present an API key; meaningful only when webExported is true","provider":"go.mondoo.com/mql/providers/digitalocean"},"runtime":{"name":"runtime","type":"\u0007","is_mandatory":true,"title":"Runtime the action executes on (e.g., nodejs:18, python:3.11, go:1.21)","provider":"go.mondoo.com/mql/providers/digitalocean"},"timeoutMs":{"name":"timeoutMs","type":"\u0005","is_mandatory":true,"title":"Execution timeout, in milliseconds","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the action was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Version assigned to the action by the platform","provider":"go.mondoo.com/mql/providers/digitalocean"},"webExported":{"name":"webExported","type":"\u0004","is_mandatory":true,"title":"Whether the action is published as a public web endpoint","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Functions action","desc":"Single function (action) deployed in a Functions namespace, covering the action `name` and the `package` it belongs to, the `runtime` it executes on, the resource limits (`timeoutMs`, `memoryMb`, `logSizeMb`, `concurrency`), and its security posture: `webExported` flags an action published as a raw public HTTP endpoint, and `requiresApiKey` reports whether such a web action still demands authentication. Query it to audit for unauthenticated web functions and to inventory the serverless code running in an account.","private":true,"min_provider_version":"13.10.2","defaults":"name runtime updatedAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.function.namespace":{"id":"digitalocean.function.namespace","name":"digitalocean.function.namespace","fields":{"accessKeys":{"name":"accessKeys","type":"\u0019\u001bdigitalocean.function.accessKey","title":"Access keys issued for the namespace's Functions API (secret values are never exposed)","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"apiHost":{"name":"apiHost","type":"\u0007","is_mandatory":true,"title":"API host serving the namespace's functions","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"functions":{"name":"functions","type":"\u0019\u001bdigitalocean.function.action","title":"Functions (actions) deployed in the namespace","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"label":{"name":"label","type":"\u0007","is_mandatory":true,"title":"Human-readable namespace label","provider":"go.mondoo.com/mql/providers/digitalocean"},"namespace":{"name":"namespace","type":"\u0007","is_mandatory":true,"title":"Internal namespace identifier used in API paths","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"triggers":{"name":"triggers","type":"\u0019\u001bdigitalocean.function.trigger","title":"Scheduled triggers in the namespace","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the resource was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Namespace UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Functions namespace","desc":"Deployment unit that groups serverless functions and their schedules in a region. Each namespace has a human-readable `label`, an API host that serves its functions, and an internal `namespace` identifier used in API paths. The functions deployed here, the scheduled triggers that invoke them, and the access keys issued for the namespace API are all queryable, making this the entry point for inventorying serverless workloads and auditing the credentials that reach them.","min_provider_version":"13.1.7","defaults":"uuid label region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.function.trigger":{"id":"digitalocean.function.trigger","name":"digitalocean.function.trigger","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"cron":{"name":"cron","type":"\u0007","is_mandatory":true,"title":"Cron schedule expression (for scheduled triggers)","provider":"go.mondoo.com/mql/providers/digitalocean"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the trigger is enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"function":{"name":"function","type":"\u0007","is_mandatory":true,"title":"Name of the function the trigger invokes","provider":"go.mondoo.com/mql/providers/digitalocean"},"lastRunAt":{"name":"lastRunAt","type":"\t","is_mandatory":true,"title":"Time the trigger last fired","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Trigger name","provider":"go.mondoo.com/mql/providers/digitalocean"},"namespace":{"name":"namespace","type":"\u0007","is_mandatory":true,"title":"Internal identifier of the parent namespace","provider":"go.mondoo.com/mql/providers/digitalocean"},"nextRunAt":{"name":"nextRunAt","type":"\t","is_mandatory":true,"title":"Time the trigger is next scheduled to fire","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Trigger type (e.g., SCHEDULED)","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the resource was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Functions trigger","desc":"Trigger that invokes a function in a namespace, exposing the trigger `name`, its `type` (for example SCHEDULED), the `function` it invokes, and whether it is `enabled`. For scheduled triggers, `cron` is the schedule expression and `lastRunAt` and `nextRunAt` report the firing history. Query it to confirm that expected schedules are enabled and firing.","private":true,"min_provider_version":"13.1.7","defaults":"name function enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai":{"id":"digitalocean.gradientai","name":"digitalocean.gradientai","fields":{"agent":{"name":"agent","type":"\u001bdigitalocean.gradientai.agent","title":"DigitalOcean GradientAI agent","desc":"Deployed GenAI agent. Surfaces the `instruction` (system prompt), generation parameters (`temperature`, `topP`, `maxTokens`, `k`, `retrievalMethod`), and the security-relevant posture: whether the agent is publicly exposed (`deploymentVisibility`), whether prompts and responses are logged (`conversationLogsEnabled`), whether citations are provided, and the attached `guardrails`. Reach the backing `model`, the RAG `knowledgeBases`, the `project` and `vpc` it runs in, the external `anthropicApiKey`/`openaiApiKey` it uses, and the agent routing graph through `childAgents` and `parentAgents`. Select an agent by uuid with `digitalocean.gradientai.agent(uuid: \"...\")`.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"agents":{"name":"agents","type":"\u0019\u001bdigitalocean.gradientai.agent","title":"GenAI agents","provider":"go.mondoo.com/mql/providers/digitalocean"},"anthropicApiKey":{"name":"anthropicApiKey","type":"\u001bdigitalocean.gradientai.anthropicApiKey","title":"DigitalOcean GradientAI Anthropic API key","desc":"Registered Anthropic API key. The secret value is never exposed; only metadata is surfaced. Reach the `agents` that use the key.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"anthropicApiKeys":{"name":"anthropicApiKeys","type":"\u0019\u001bdigitalocean.gradientai.anthropicApiKey","title":"Registered Anthropic API keys","provider":"go.mondoo.com/mql/providers/digitalocean"},"batchJob":{"name":"batchJob","type":"\u001bdigitalocean.gradientai.batchJob","title":"DigitalOcean GradientAI batch inference job","desc":"Batch inference job. Surfaces the `provider`, the input `fileId`, the `completionWindow`, lifecycle `status`, whether a result is available, and the `requestCounts` (total, completed, failed). Select by batch id with `digitalocean.gradientai.batchJob(batchId: \"...\")`.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"batchJobs":{"name":"batchJobs","type":"\u0019\u001bdigitalocean.gradientai.batchJob","title":"Batch inference jobs","provider":"go.mondoo.com/mql/providers/digitalocean"},"customModel":{"name":"customModel","type":"\u001bdigitalocean.gradientai.customModel","title":"DigitalOcean GradientAI custom model","desc":"Account-uploaded custom model. Surfaces the `status`, `architecture`, `sourceType`, total size and file count, declared modalities, context length, monthly cost estimate, and the `activeDeployments` currently serving it.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"customModels":{"name":"customModels","type":"\u0019\u001bdigitalocean.gradientai.customModel","title":"Account-uploaded custom models","provider":"go.mondoo.com/mql/providers/digitalocean"},"dedicatedInferenceEndpoint":{"name":"dedicatedInferenceEndpoint","type":"\u001bdigitalocean.gradientai.dedicatedInferenceEndpoint","title":"DigitalOcean GradientAI dedicated inference endpoint","desc":"Dedicated GPU inference endpoint. Surfaces the lifecycle `status`, the `region`, the public and private endpoint FQDNs, and the `providerModelIds` served. Reach the `vpc` it runs in, and iterate `accelerators` and `tokens` (token secret values are never exposed). Select by id with `digitalocean.gradientai.dedicatedInferenceEndpoint(id: \"...\")`.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"dedicatedInferenceEndpoints":{"name":"dedicatedInferenceEndpoints","type":"\u0019\u001bdigitalocean.gradientai.dedicatedInferenceEndpoint","title":"Dedicated GPU inference endpoints","provider":"go.mondoo.com/mql/providers/digitalocean"},"indexingJob":{"name":"indexingJob","type":"\u001bdigitalocean.gradientai.indexingJob","title":"DigitalOcean GradientAI indexing job","desc":"Knowledge-base indexing run. Surfaces the `phase` and `status`, the tokens processed, datasource progress (`completedDatasources`/`totalDatasources`), and item counts. Reach the `knowledgeBase` being indexed.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"indexingJobs":{"name":"indexingJobs","type":"\u0019\u001bdigitalocean.gradientai.indexingJob","title":"Knowledge-base indexing jobs","provider":"go.mondoo.com/mql/providers/digitalocean"},"knowledgeBase":{"name":"knowledgeBase","type":"\u001bdigitalocean.gradientai.knowledgeBase","title":"DigitalOcean GradientAI knowledge base","desc":"RAG knowledge base. `isPublic` flags publicly readable knowledge bases. Reach the `embeddingModel` used to vectorize content, the backing `database` (a managed pgvector cluster), and the `project` it belongs to. `dataSources` lists the configured sources, and `lastIndexingJob` reports the most recent indexing run. Select by uuid with `digitalocean.gradientai.knowledgeBase(uuid: \"...\")`.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"knowledgeBases":{"name":"knowledgeBases","type":"\u0019\u001bdigitalocean.gradientai.knowledgeBase","title":"RAG knowledge bases","provider":"go.mondoo.com/mql/providers/digitalocean"},"model":{"name":"model","type":"\u001bdigitalocean.gradientai.model","title":"DigitalOcean GradientAI model","desc":"Foundation model available on the GradientAI platform. Surfaces the `provider`, model `type`, whether it is foundational, `modelAvailability`, declared `capabilities` and `usecases`, the `contextWindow`, `parameterCount`, supported `modalities`, and `pricing`. Select a model by uuid with `digitalocean.gradientai.model(uuid: \"...\")`.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"models":{"name":"models","type":"\u0019\u001bdigitalocean.gradientai.model","title":"Available foundation models","provider":"go.mondoo.com/mql/providers/digitalocean"},"openaiApiKey":{"name":"openaiApiKey","type":"\u001bdigitalocean.gradientai.openaiApiKey","title":"DigitalOcean GradientAI OpenAI API key","desc":"Registered OpenAI API key. The secret value is never exposed; only metadata is surfaced. Reach the `models` enabled by the key and the `agents` that use it.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"openaiApiKeys":{"name":"openaiApiKeys","type":"\u0019\u001bdigitalocean.gradientai.openaiApiKey","title":"Registered OpenAI API keys","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GenAI (GradientAI) platform","desc":"Entry point for DigitalOcean's GenAI platform. `agents` lists deployed AI agents, `models` the available foundation-model catalog, `customModels` account-uploaded models, `knowledgeBases` the RAG knowledge bases, `indexingJobs` knowledge-base indexing runs, `anthropicApiKeys` and `openaiApiKeys` the registered external provider keys, `dedicatedInferenceEndpoints` dedicated GPU inference, and `batchJobs` batch inference jobs.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.agent":{"id":"digitalocean.gradientai.agent","name":"digitalocean.gradientai.agent","fields":{"anthropicApiKey":{"name":"anthropicApiKey","type":"\u001bdigitalocean.gradientai.anthropicApiKey","title":"Registered Anthropic API key the agent uses, if any","provider":"go.mondoo.com/mql/providers/digitalocean"},"apiKey":{"name":"apiKey","type":"\u001bdigitalocean.gradientai.agent.apiKey","title":"DigitalOcean GradientAI agent API key","desc":"API key issued for an agent. The secret value is never exposed; only metadata (`name`, `createdBy`, timestamps) is surfaced.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"apiKeys":{"name":"apiKeys","type":"\u0019\u001bdigitalocean.gradientai.agent.apiKey","title":"API keys issued for the agent (secret values are never exposed)","provider":"go.mondoo.com/mql/providers/digitalocean"},"chatbot":{"name":"chatbot","type":"\n","is_mandatory":true,"title":"Chatbot widget configuration","desc":"Keys: `name`, `primaryColor`, `secondaryColor`, `startingMessage`, and `logo`.","provider":"go.mondoo.com/mql/providers/digitalocean"},"childAgents":{"name":"childAgents","type":"\u0019\u001bdigitalocean.gradientai.agent","title":"Child agents this agent can route to","provider":"go.mondoo.com/mql/providers/digitalocean"},"conversationLogsEnabled":{"name":"conversationLogsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether prompts and responses are logged","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the agent was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"deploymentName":{"name":"deploymentName","type":"\u0007","is_mandatory":true,"title":"Deployment name","provider":"go.mondoo.com/mql/providers/digitalocean"},"deploymentStatus":{"name":"deploymentStatus","type":"\u0007","is_mandatory":true,"title":"Deployment lifecycle status","provider":"go.mondoo.com/mql/providers/digitalocean"},"deploymentUrl":{"name":"deploymentUrl","type":"\u0007","is_mandatory":true,"title":"Deployment URL","provider":"go.mondoo.com/mql/providers/digitalocean"},"deploymentUuid":{"name":"deploymentUuid","type":"\u0007","is_mandatory":true,"title":"Deployment UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"deploymentVisibility":{"name":"deploymentVisibility","type":"\u0007","is_mandatory":true,"title":"Deployment exposure","desc":"Indicates whether the deployed agent is reachable publicly or only privately (e.g., VISIBILITY_PUBLIC or VISIBILITY_PRIVATE).","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"function":{"name":"function","type":"\u001bdigitalocean.gradientai.agent.function","title":"DigitalOcean GradientAI agent function","desc":"Tool / function-calling definition attached to an agent. Surfaces the backing serverless function (`faasName`, `faasNamespace`) and its `url`. The function's API key is never exposed.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"functions":{"name":"functions","type":"\u0019\u001bdigitalocean.gradientai.agent.function","title":"Tool / function-calling definitions attached to the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"guardrail":{"name":"guardrail","type":"\u001bdigitalocean.gradientai.agent.guardrail","title":"DigitalOcean GradientAI agent guardrail","desc":"Content guardrail attached to an agent. `type` and `isAttached`/`isDefault` confirm which guardrails are actively enforced, and `defaultResponse` is the canned reply returned on a guardrail trip.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"guardrails":{"name":"guardrails","type":"\u0019\u001bdigitalocean.gradientai.agent.guardrail","title":"Content guardrails attached to the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"ifCase":{"name":"ifCase","type":"\u0007","is_mandatory":true,"title":"Routing condition expression for child-agent routing","provider":"go.mondoo.com/mql/providers/digitalocean"},"instruction":{"name":"instruction","type":"\u0007","is_mandatory":true,"title":"System prompt / instruction given to the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"k":{"name":"k","type":"\u0005","is_mandatory":true,"title":"Number of knowledge-base results retrieved per query","provider":"go.mondoo.com/mql/providers/digitalocean"},"knowledgeBases":{"name":"knowledgeBases","type":"\u0019\u001bdigitalocean.gradientai.knowledgeBase","title":"RAG knowledge bases attached to the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"maxTokens":{"name":"maxTokens","type":"\u0005","is_mandatory":true,"title":"Maximum tokens generated per response","provider":"go.mondoo.com/mql/providers/digitalocean"},"model":{"name":"model","type":"\u001bdigitalocean.gradientai.model","title":"Backing foundation model","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"openaiApiKey":{"name":"openaiApiKey","type":"\u001bdigitalocean.gradientai.openaiApiKey","title":"Registered OpenAI API key the agent uses, if any","provider":"go.mondoo.com/mql/providers/digitalocean"},"parentAgents":{"name":"parentAgents","type":"\u0019\u001bdigitalocean.gradientai.agent","title":"Parent agents that can route to this agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the agent belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the agent belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"provideCitations":{"name":"provideCitations","type":"\u0004","is_mandatory":true,"title":"Whether the agent returns citations for retrieved content","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"retrievalMethod":{"name":"retrievalMethod","type":"\u0007","is_mandatory":true,"title":"Retrieval method used against attached knowledge bases","provider":"go.mondoo.com/mql/providers/digitalocean"},"routeName":{"name":"routeName","type":"\u0007","is_mandatory":true,"title":"Routing name","provider":"go.mondoo.com/mql/providers/digitalocean"},"routeUuid":{"name":"routeUuid","type":"\u0007","is_mandatory":true,"title":"Routing UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"temperature":{"name":"temperature","type":"\u0006","is_mandatory":true,"title":"Sampling temperature","provider":"go.mondoo.com/mql/providers/digitalocean"},"topP":{"name":"topP","type":"\u0006","is_mandatory":true,"title":"Nucleus sampling top-p","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the agent was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"Public agent URL","provider":"go.mondoo.com/mql/providers/digitalocean"},"userId":{"name":"userId","type":"\u0007","is_mandatory":true,"title":"ID of the user that owns the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Agent UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"version":{"name":"version","type":"\u001bdigitalocean.gradientai.agent.version","title":"DigitalOcean GradientAI agent version","desc":"Single version in an agent's history. `currentlyApplied` marks the live version and `canRollback` indicates whether the agent can be reverted to it. The instruction, model, and generation parameters captured at version time are also surfaced.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"versionHash":{"name":"versionHash","type":"\u0007","is_mandatory":true,"title":"Hash of the currently applied agent version","provider":"go.mondoo.com/mql/providers/digitalocean"},"versions":{"name":"versions","type":"\u0019\u001bdigitalocean.gradientai.agent.version","title":"Version history of the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the agent runs in","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcEgressIps":{"name":"vpcEgressIps","type":"\u0019\u0007","is_mandatory":true,"title":"Public IPs the agent egresses from","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcUuid":{"name":"vpcUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the VPC the agent runs in","desc":"Deprecated in favor of `vpc`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"}},"init":{"args":[{"name":"uuid","type":"\u0007","optional":true}]},"title":"DigitalOcean GradientAI agent","desc":"Deployed GenAI agent. Surfaces the `instruction` (system prompt), generation parameters (`temperature`, `topP`, `maxTokens`, `k`, `retrievalMethod`), and the security-relevant posture: whether the agent is publicly exposed (`deploymentVisibility`), whether prompts and responses are logged (`conversationLogsEnabled`), whether citations are provided, and the attached `guardrails`. Reach the backing `model`, the RAG `knowledgeBases`, the `project` and `vpc` it runs in, the external `anthropicApiKey`/`openaiApiKey` it uses, and the agent routing graph through `childAgents` and `parentAgents`. Select an agent by uuid with `digitalocean.gradientai.agent(uuid: \"...\")`.","min_provider_version":"13.4.2","defaults":"uuid name region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.agent.apiKey":{"id":"digitalocean.gradientai.agent.apiKey","name":"digitalocean.gradientai.agent.apiKey","fields":{"agentUuid":{"name":"agentUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the agent the key belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the key was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"User that created the key","provider":"go.mondoo.com/mql/providers/digitalocean"},"deletedAt":{"name":"deletedAt","type":"\t","is_mandatory":true,"title":"Time the key was deleted, if applicable","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"API key UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI agent API key","desc":"API key issued for an agent. The secret value is never exposed; only metadata (`name`, `createdBy`, timestamps) is surfaced.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.agent.function":{"id":"digitalocean.gradientai.agent.function","name":"digitalocean.gradientai.agent.function","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the function was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"faasName":{"name":"faasName","type":"\u0007","is_mandatory":true,"title":"Backing serverless function name","provider":"go.mondoo.com/mql/providers/digitalocean"},"faasNamespace":{"name":"faasNamespace","type":"\u0007","is_mandatory":true,"title":"Backing serverless function namespace","provider":"go.mondoo.com/mql/providers/digitalocean"},"guardrailUuid":{"name":"guardrailUuid","type":"\u0007","is_mandatory":true,"title":"UUID of an associated guardrail, if any","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the function was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"Invocation URL","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Function UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI agent function","desc":"Tool / function-calling definition attached to an agent. Surfaces the backing serverless function (`faasName`, `faasNamespace`) and its `url`. The function's API key is never exposed.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.agent.guardrail":{"id":"digitalocean.gradientai.agent.guardrail","name":"digitalocean.gradientai.agent.guardrail","fields":{"agentUuid":{"name":"agentUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the agent the guardrail is attached to","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the guardrail was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"defaultResponse":{"name":"defaultResponse","type":"\u0007","is_mandatory":true,"title":"Canned response returned when the guardrail trips","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"isAttached":{"name":"isAttached","type":"\u0004","is_mandatory":true,"title":"Whether the guardrail is currently attached","provider":"go.mondoo.com/mql/providers/digitalocean"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether the guardrail is a default","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"priority":{"name":"priority","type":"\u0005","is_mandatory":true,"title":"Evaluation priority","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Guardrail type","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the guardrail was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Guardrail UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI agent guardrail","desc":"Content guardrail attached to an agent. `type` and `isAttached`/`isDefault` confirm which guardrails are actively enforced, and `defaultResponse` is the canned reply returned on a guardrail trip.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name type","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.agent.version":{"id":"digitalocean.gradientai.agent.version","name":"digitalocean.gradientai.agent.version","fields":{"agentUuid":{"name":"agentUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the agent this version belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"canRollback":{"name":"canRollback","type":"\u0004","is_mandatory":true,"title":"Whether the agent can be rolled back to this version","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the version was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdByEmail":{"name":"createdByEmail","type":"\u0007","is_mandatory":true,"title":"Email of the user that created the version","provider":"go.mondoo.com/mql/providers/digitalocean"},"currentlyApplied":{"name":"currentlyApplied","type":"\u0004","is_mandatory":true,"title":"Whether this version is currently applied to the agent","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Version ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"instruction":{"name":"instruction","type":"\u0007","is_mandatory":true,"title":"System prompt / instruction captured in this version","provider":"go.mondoo.com/mql/providers/digitalocean"},"k":{"name":"k","type":"\u0005","is_mandatory":true,"title":"Number of knowledge-base results retrieved per query","provider":"go.mondoo.com/mql/providers/digitalocean"},"maxTokens":{"name":"maxTokens","type":"\u0005","is_mandatory":true,"title":"Maximum tokens generated per response","provider":"go.mondoo.com/mql/providers/digitalocean"},"modelName":{"name":"modelName","type":"\u0007","is_mandatory":true,"title":"Model name captured in this version","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"provideCitations":{"name":"provideCitations","type":"\u0004","is_mandatory":true,"title":"Whether the agent returns citations","provider":"go.mondoo.com/mql/providers/digitalocean"},"retrievalMethod":{"name":"retrievalMethod","type":"\u0007","is_mandatory":true,"title":"Retrieval method","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"temperature":{"name":"temperature","type":"\u0006","is_mandatory":true,"title":"Sampling temperature","provider":"go.mondoo.com/mql/providers/digitalocean"},"topP":{"name":"topP","type":"\u0006","is_mandatory":true,"title":"Nucleus sampling top-p","provider":"go.mondoo.com/mql/providers/digitalocean"},"triggerAction":{"name":"triggerAction","type":"\u0007","is_mandatory":true,"title":"Trigger action that created the version","provider":"go.mondoo.com/mql/providers/digitalocean"},"versionHash":{"name":"versionHash","type":"\u0007","is_mandatory":true,"title":"Version hash","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI agent version","desc":"Single version in an agent's history. `currentlyApplied` marks the live version and `canRollback` indicates whether the agent can be reverted to it. The instruction, model, and generation parameters captured at version time are also surfaced.","private":true,"min_provider_version":"13.4.2","defaults":"id name versionHash","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.anthropicApiKey":{"id":"digitalocean.gradientai.anthropicApiKey","name":"digitalocean.gradientai.anthropicApiKey","fields":{"agents":{"name":"agents","type":"\u0019\u001bdigitalocean.gradientai.agent","title":"Agents that use this key","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the key was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"User that created the key","provider":"go.mondoo.com/mql/providers/digitalocean"},"deletedAt":{"name":"deletedAt","type":"\t","is_mandatory":true,"title":"Time the key was deleted, if applicable","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the key was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"API key UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI Anthropic API key","desc":"Registered Anthropic API key. The secret value is never exposed; only metadata is surfaced. Reach the `agents` that use the key.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.batchJob":{"id":"digitalocean.gradientai.batchJob","name":"digitalocean.gradientai.batchJob","fields":{"batchId":{"name":"batchId","type":"\u0007","is_mandatory":true,"title":"Batch job ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"cancelRequestedAt":{"name":"cancelRequestedAt","type":"\t","is_mandatory":true,"title":"Time cancellation was requested, if applicable","provider":"go.mondoo.com/mql/providers/digitalocean"},"completionWindow":{"name":"completionWindow","type":"\u0007","is_mandatory":true,"title":"Completion window","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the job was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Time the job expires, if applicable","provider":"go.mondoo.com/mql/providers/digitalocean"},"fileId":{"name":"fileId","type":"\u0007","is_mandatory":true,"title":"ID of the input file","provider":"go.mondoo.com/mql/providers/digitalocean"},"provider":{"name":"provider","type":"\u0007","is_mandatory":true,"title":"Inference provider","provider":"go.mondoo.com/mql/providers/digitalocean"},"requestCounts":{"name":"requestCounts","type":"\n","is_mandatory":true,"title":"Request counts (total, completed, failed)","provider":"go.mondoo.com/mql/providers/digitalocean"},"requestId":{"name":"requestId","type":"\u0007","is_mandatory":true,"title":"Request ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"resultAvailable":{"name":"resultAvailable","type":"\u0004","is_mandatory":true,"title":"Whether a result is available for download","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the job was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI batch inference job","desc":"Batch inference job. Surfaces the `provider`, the input `fileId`, the `completionWindow`, lifecycle `status`, whether a result is available, and the `requestCounts` (total, completed, failed). Select by batch id with `digitalocean.gradientai.batchJob(batchId: \"...\")`.","private":true,"min_provider_version":"13.4.2","defaults":"batchId provider status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.customModel":{"id":"digitalocean.gradientai.customModel","name":"digitalocean.gradientai.customModel","fields":{"activeDeployments":{"name":"activeDeployments","type":"\u0019\n","is_mandatory":true,"title":"Deployments currently serving the model","provider":"go.mondoo.com/mql/providers/digitalocean"},"architecture":{"name":"architecture","type":"\u0007","is_mandatory":true,"title":"Model architecture","provider":"go.mondoo.com/mql/providers/digitalocean"},"configJson":{"name":"configJson","type":"\n","is_mandatory":true,"title":"Provider-specific configuration metadata for the model","min_provider_version":"13.5.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"contextLength":{"name":"contextLength","type":"\u0005","is_mandatory":true,"title":"Context length","provider":"go.mondoo.com/mql/providers/digitalocean"},"costEstimatePerMonth":{"name":"costEstimatePerMonth","type":"\u0005","is_mandatory":true,"title":"Estimated monthly serving cost","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the model was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"errorMessage":{"name":"errorMessage","type":"\u0007","is_mandatory":true,"title":"Failure detail reported when the model is in an error state","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"fileCount":{"name":"fileCount","type":"\u0005","is_mandatory":true,"title":"Number of files comprising the model","provider":"go.mondoo.com/mql/providers/digitalocean"},"inputModalities":{"name":"inputModalities","type":"\u0019\u0007","is_mandatory":true,"title":"Supported input modalities","provider":"go.mondoo.com/mql/providers/digitalocean"},"license":{"name":"license","type":"\u0007","is_mandatory":true,"title":"License","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"outputModalities":{"name":"outputModalities","type":"\u0019\u0007","is_mandatory":true,"title":"Supported output modalities","provider":"go.mondoo.com/mql/providers/digitalocean"},"parameters":{"name":"parameters","type":"\u0007","is_mandatory":true,"title":"Parameter count description","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceRef":{"name":"sourceRef","type":"\n","is_mandatory":true,"title":"Source location the model was imported from","desc":"Identifies where the model artifacts originate. For a Spaces object source: `bucket`, `region`, and `prefix`. For a Git/Hugging Face source: `repoId`, `commitSha`, and `accessType`. The Hugging Face token is omitted.","min_provider_version":"13.5.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"sourceType":{"name":"sourceType","type":"\u0007","is_mandatory":true,"title":"Source type the model was imported from","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","provider":"go.mondoo.com/mql/providers/digitalocean"},"storageRegion":{"name":"storageRegion","type":"\u0007","is_mandatory":true,"title":"Region the model is stored in","provider":"go.mondoo.com/mql/providers/digitalocean"},"teamId":{"name":"teamId","type":"\u0007","is_mandatory":true,"title":"ID of the owning team","provider":"go.mondoo.com/mql/providers/digitalocean"},"totalSizeBytes":{"name":"totalSizeBytes","type":"\u0007","is_mandatory":true,"title":"Total size of the model, in bytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the model was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Custom model UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI custom model","desc":"Account-uploaded custom model. Surfaces the `status`, `architecture`, `sourceType`, total size and file count, declared modalities, context length, monthly cost estimate, and the `activeDeployments` currently serving it.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.dedicatedInferenceEndpoint":{"id":"digitalocean.gradientai.dedicatedInferenceEndpoint","name":"digitalocean.gradientai.dedicatedInferenceEndpoint","fields":{"accelerator":{"name":"accelerator","type":"\u001bdigitalocean.gradientai.dedicatedInferenceEndpoint.accelerator","title":"DigitalOcean GradientAI dedicated inference accelerator","desc":"GPU accelerator backing a dedicated inference endpoint.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"accelerators":{"name":"accelerators","type":"\u0019\u001bdigitalocean.gradientai.dedicatedInferenceEndpoint.accelerator","title":"GPU accelerators backing the endpoint","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the endpoint was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Endpoint ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"privateEndpointFqdn":{"name":"privateEndpointFqdn","type":"\u0007","is_mandatory":true,"title":"Private endpoint FQDN","provider":"go.mondoo.com/mql/providers/digitalocean"},"providerModelIds":{"name":"providerModelIds","type":"\u0019\u0007","is_mandatory":true,"title":"Model IDs served by the endpoint","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicEndpointFqdn":{"name":"publicEndpointFqdn","type":"\u0007","is_mandatory":true,"title":"Public endpoint FQDN","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","provider":"go.mondoo.com/mql/providers/digitalocean"},"token":{"name":"token","type":"\u001bdigitalocean.gradientai.dedicatedInferenceEndpoint.token","title":"DigitalOcean GradientAI dedicated inference token","desc":"Access token issued for a dedicated inference endpoint. The token's secret value is never exposed; `isManaged` indicates whether the token is platform-managed.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"tokens":{"name":"tokens","type":"\u0019\u001bdigitalocean.gradientai.dedicatedInferenceEndpoint.token","title":"Access tokens issued for the endpoint (secret values are never exposed)","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the endpoint was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the endpoint runs in","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcUuid":{"name":"vpcUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the VPC the endpoint runs in","desc":"Deprecated in favor of `vpc`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"}},"title":"DigitalOcean GradientAI dedicated inference endpoint","desc":"Dedicated GPU inference endpoint. Surfaces the lifecycle `status`, the `region`, the public and private endpoint FQDNs, and the `providerModelIds` served. Reach the `vpc` it runs in, and iterate `accelerators` and `tokens` (token secret values are never exposed). Select by id with `digitalocean.gradientai.dedicatedInferenceEndpoint(id: \"...\")`.","private":true,"min_provider_version":"13.4.2","defaults":"id name region status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.dedicatedInferenceEndpoint.accelerator":{"id":"digitalocean.gradientai.dedicatedInferenceEndpoint.accelerator","name":"digitalocean.gradientai.dedicatedInferenceEndpoint.accelerator","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the accelerator was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Accelerator ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"slug":{"name":"slug","type":"\u0007","is_mandatory":true,"title":"Size slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI dedicated inference accelerator","desc":"GPU accelerator backing a dedicated inference endpoint.","private":true,"min_provider_version":"13.4.2","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.dedicatedInferenceEndpoint.token":{"id":"digitalocean.gradientai.dedicatedInferenceEndpoint.token","name":"digitalocean.gradientai.dedicatedInferenceEndpoint.token","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the token was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Token ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"isManaged":{"name":"isManaged","type":"\u0004","is_mandatory":true,"title":"Whether the token is platform-managed","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI dedicated inference token","desc":"Access token issued for a dedicated inference endpoint. The token's secret value is never exposed; `isManaged` indicates whether the token is platform-managed.","private":true,"min_provider_version":"13.4.2","defaults":"id name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.indexingJob":{"id":"digitalocean.gradientai.indexingJob","name":"digitalocean.gradientai.indexingJob","fields":{"completedDatasources":{"name":"completedDatasources","type":"\u0005","is_mandatory":true,"title":"Number of data sources completed","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the job was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"dataSourceUuids":{"name":"dataSourceUuids","type":"\u0019\u0007","is_mandatory":true,"title":"UUIDs of the data sources covered by the job","provider":"go.mondoo.com/mql/providers/digitalocean"},"finishedAt":{"name":"finishedAt","type":"\t","is_mandatory":true,"title":"Time the job finished","provider":"go.mondoo.com/mql/providers/digitalocean"},"knowledgeBase":{"name":"knowledgeBase","type":"\u001bdigitalocean.gradientai.knowledgeBase","title":"Knowledge base being indexed","provider":"go.mondoo.com/mql/providers/digitalocean"},"knowledgeBaseUuid":{"name":"knowledgeBaseUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the knowledge base being indexed","provider":"go.mondoo.com/mql/providers/digitalocean"},"phase":{"name":"phase","type":"\u0007","is_mandatory":true,"title":"Current phase","provider":"go.mondoo.com/mql/providers/digitalocean"},"startedAt":{"name":"startedAt","type":"\t","is_mandatory":true,"title":"Time the job started","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status","provider":"go.mondoo.com/mql/providers/digitalocean"},"tokens":{"name":"tokens","type":"\u0005","is_mandatory":true,"title":"Tokens processed","provider":"go.mondoo.com/mql/providers/digitalocean"},"totalDatasources":{"name":"totalDatasources","type":"\u0005","is_mandatory":true,"title":"Total number of data sources","provider":"go.mondoo.com/mql/providers/digitalocean"},"totalItemsFailed":{"name":"totalItemsFailed","type":"\u0007","is_mandatory":true,"title":"Total items that failed","provider":"go.mondoo.com/mql/providers/digitalocean"},"totalItemsIndexed":{"name":"totalItemsIndexed","type":"\u0007","is_mandatory":true,"title":"Total items indexed","provider":"go.mondoo.com/mql/providers/digitalocean"},"totalItemsSkipped":{"name":"totalItemsSkipped","type":"\u0007","is_mandatory":true,"title":"Total items skipped","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the job was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Indexing job UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI indexing job","desc":"Knowledge-base indexing run. Surfaces the `phase` and `status`, the tokens processed, datasource progress (`completedDatasources`/`totalDatasources`), and item counts. Reach the `knowledgeBase` being indexed.","private":true,"min_provider_version":"13.4.2","defaults":"uuid status phase","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.knowledgeBase":{"id":"digitalocean.gradientai.knowledgeBase","name":"digitalocean.gradientai.knowledgeBase","fields":{"addedToAgentAt":{"name":"addedToAgentAt","type":"\t","is_mandatory":true,"title":"Time the knowledge base was added to an agent, if applicable","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the knowledge base was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"dataSource":{"name":"dataSource","type":"\u001bdigitalocean.gradientai.knowledgeBase.dataSource","title":"DigitalOcean GradientAI knowledge base data source","desc":"Single data source feeding a knowledge base. `type` identifies the source kind; the matching `webCrawler`, `spaces`, or `fileUpload` dict carries its detail, and `lastIndexingJob` reports the most recent indexing run for the source.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"dataSources":{"name":"dataSources","type":"\u0019\u001bdigitalocean.gradientai.knowledgeBase.dataSource","title":"Configured data sources","provider":"go.mondoo.com/mql/providers/digitalocean"},"database":{"name":"database","type":"\u001bdigitalocean.database","title":"Backing managed database cluster (pgvector)","provider":"go.mondoo.com/mql/providers/digitalocean"},"databaseId":{"name":"databaseId","type":"\u0007","is_mandatory":true,"title":"ID of the backing managed database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"embeddingModel":{"name":"embeddingModel","type":"\u001bdigitalocean.gradientai.model","title":"Embedding model used to vectorize content","provider":"go.mondoo.com/mql/providers/digitalocean"},"embeddingModelUuid":{"name":"embeddingModelUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the embedding model used to vectorize content","provider":"go.mondoo.com/mql/providers/digitalocean"},"isDeleted":{"name":"isDeleted","type":"\u0004","is_mandatory":true,"title":"Whether the knowledge base has been deleted","provider":"go.mondoo.com/mql/providers/digitalocean"},"isPublic":{"name":"isPublic","type":"\u0004","is_mandatory":true,"title":"Whether the knowledge base is publicly readable","provider":"go.mondoo.com/mql/providers/digitalocean"},"lastIndexingJob":{"name":"lastIndexingJob","type":"\n","is_mandatory":true,"title":"Summary of the most recent indexing job","desc":"Keys: `uuid`, `knowledgeBaseUuid`, `phase`, `status`, `tokens`, `completedDatasources`, `totalDatasources`, `totalItemsIndexed`, `totalItemsFailed`, `totalItemsSkipped`, `startedAt`, and `finishedAt`.","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the knowledge base belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the knowledge base belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the knowledge base was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Knowledge base UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI knowledge base","desc":"RAG knowledge base. `isPublic` flags publicly readable knowledge bases. Reach the `embeddingModel` used to vectorize content, the backing `database` (a managed pgvector cluster), and the `project` it belongs to. `dataSources` lists the configured sources, and `lastIndexingJob` reports the most recent indexing run. Select by uuid with `digitalocean.gradientai.knowledgeBase(uuid: \"...\")`.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.knowledgeBase.dataSource":{"id":"digitalocean.gradientai.knowledgeBase.dataSource","name":"digitalocean.gradientai.knowledgeBase.dataSource","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the data source was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"fileUpload":{"name":"fileUpload","type":"\n","is_mandatory":true,"title":"File-upload source detail (originalFileName, size, storedObjectKey)","provider":"go.mondoo.com/mql/providers/digitalocean"},"lastIndexingJob":{"name":"lastIndexingJob","type":"\n","is_mandatory":true,"title":"Summary of the most recent indexing job for the source","desc":"Keys: `uuid`, `knowledgeBaseUuid`, `phase`, `status`, `tokens`, `completedDatasources`, `totalDatasources`, `totalItemsIndexed`, `totalItemsFailed`, `totalItemsSkipped`, `startedAt`, and `finishedAt`.","provider":"go.mondoo.com/mql/providers/digitalocean"},"spaces":{"name":"spaces","type":"\n","is_mandatory":true,"title":"Spaces source detail (bucketName, itemPath, region)","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Source kind: web_crawler, spaces, or file_upload","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the data source was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Data source UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"webCrawler":{"name":"webCrawler","type":"\n","is_mandatory":true,"title":"Web-crawler source detail (baseUrl, crawlingOption, embedMedia)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI knowledge base data source","desc":"Single data source feeding a knowledge base. `type` identifies the source kind; the matching `webCrawler`, `spaces`, or `fileUpload` dict carries its detail, and `lastIndexingJob` reports the most recent indexing run for the source.","private":true,"min_provider_version":"13.4.2","defaults":"uuid type","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.model":{"id":"digitalocean.gradientai.model","name":"digitalocean.gradientai.model","fields":{"agreementName":{"name":"agreementName","type":"\u0007","is_mandatory":true,"title":"Name of the usage agreement, if any","provider":"go.mondoo.com/mql/providers/digitalocean"},"agreementUrl":{"name":"agreementUrl","type":"\u0007","is_mandatory":true,"title":"URL of the usage agreement, if any","provider":"go.mondoo.com/mql/providers/digitalocean"},"capabilities":{"name":"capabilities","type":"\u0019\u0007","is_mandatory":true,"title":"Declared capabilities","provider":"go.mondoo.com/mql/providers/digitalocean"},"contextWindow":{"name":"contextWindow","type":"\u0007","is_mandatory":true,"title":"Context window size","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the model was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"inferenceName":{"name":"inferenceName","type":"\u0007","is_mandatory":true,"title":"Inference name","provider":"go.mondoo.com/mql/providers/digitalocean"},"inferenceVersion":{"name":"inferenceVersion","type":"\u0007","is_mandatory":true,"title":"Inference version","provider":"go.mondoo.com/mql/providers/digitalocean"},"isFoundational":{"name":"isFoundational","type":"\u0004","is_mandatory":true,"title":"Whether the model is a foundational model","provider":"go.mondoo.com/mql/providers/digitalocean"},"modalities":{"name":"modalities","type":"\n","is_mandatory":true,"title":"Supported input/output modalities","desc":"Keys: `input` and `output`, each a list of modality names.","provider":"go.mondoo.com/mql/providers/digitalocean"},"modelAvailability":{"name":"modelAvailability","type":"\u0007","is_mandatory":true,"title":"Availability status","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"parameterCount":{"name":"parameterCount","type":"\u0006","is_mandatory":true,"title":"Parameter count","provider":"go.mondoo.com/mql/providers/digitalocean"},"pricing":{"name":"pricing","type":"\n","is_mandatory":true,"title":"Pricing breakdown","desc":"Keys: `inputPricePerMillion`, `outputPricePerMillion`, `pricePerImage`, `pricePerSecond`, `textInputPricePerMillion`, and `textOutputPricePerMillion`.","provider":"go.mondoo.com/mql/providers/digitalocean"},"provider":{"name":"provider","type":"\u0007","is_mandatory":true,"title":"Provider (e.g., anthropic, openai, meta)","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Model type","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the model was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uploadComplete":{"name":"uploadComplete","type":"\u0004","is_mandatory":true,"title":"Whether upload of the model completed","provider":"go.mondoo.com/mql/providers/digitalocean"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"Model URL","provider":"go.mondoo.com/mql/providers/digitalocean"},"usecases":{"name":"usecases","type":"\u0019\u0007","is_mandatory":true,"title":"Declared use cases","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"Model UUID","provider":"go.mondoo.com/mql/providers/digitalocean"},"version":{"name":"version","type":"\n","is_mandatory":true,"title":"Semantic version (major, minor, patch)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI model","desc":"Foundation model available on the GradientAI platform. Surfaces the `provider`, model `type`, whether it is foundational, `modelAvailability`, declared `capabilities` and `usecases`, the `contextWindow`, `parameterCount`, supported `modalities`, and `pricing`. Select a model by uuid with `digitalocean.gradientai.model(uuid: \"...\")`.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name provider","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.gradientai.openaiApiKey":{"id":"digitalocean.gradientai.openaiApiKey","name":"digitalocean.gradientai.openaiApiKey","fields":{"agents":{"name":"agents","type":"\u0019\u001bdigitalocean.gradientai.agent","title":"Agents that use this key","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the key was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdBy":{"name":"createdBy","type":"\u0007","is_mandatory":true,"title":"User that created the key","provider":"go.mondoo.com/mql/providers/digitalocean"},"deletedAt":{"name":"deletedAt","type":"\t","is_mandatory":true,"title":"Time the key was deleted, if applicable","provider":"go.mondoo.com/mql/providers/digitalocean"},"models":{"name":"models","type":"\u0019\u001bdigitalocean.gradientai.model","title":"Models enabled by this key","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the key was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"API key UUID","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean GradientAI OpenAI API key","desc":"Registered OpenAI API key. The secret value is never exposed; only metadata is surfaced. Reach the `models` enabled by the key and the `agents` that use it.","private":true,"min_provider_version":"13.4.2","defaults":"uuid name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.image":{"id":"digitalocean.image","name":"digitalocean.image","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"distribution":{"name":"distribution","type":"\u0007","is_mandatory":true,"title":"Operating system distribution","provider":"go.mondoo.com/mql/providers/digitalocean"},"errorMessage":{"name":"errorMessage","type":"\u0007","is_mandatory":true,"title":"Error message set when image processing failed","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Image ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"minDiskSize":{"name":"minDiskSize","type":"\u0005","is_mandatory":true,"title":"Minimum disk size a droplet must have to use this image, in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Image name","provider":"go.mondoo.com/mql/providers/digitalocean"},"public":{"name":"public","type":"\u0004","is_mandatory":true,"title":"Whether the image is public (shared with every DigitalOcean account)","provider":"go.mondoo.com/mql/providers/digitalocean"},"regions":{"name":"regions","type":"\u0019\u0007","is_mandatory":true,"title":"Region slugs the image is available in","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeGigabytes":{"name":"sizeGigabytes","type":"\u0006","is_mandatory":true,"title":"Size of the image on disk, in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"slug":{"name":"slug","type":"\u0007","is_mandatory":true,"title":"Image slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Processing status (NEW, available, pending, deleted, retired)","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to the image","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Image type (distribution, application, snapshot, backup, custom, admin)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean image","desc":"Bootable disk template a droplet is created from. The `type` field distinguishes distribution, application, snapshot, backup, custom, and admin images, and the `public` flag reports whether the image is shared with every DigitalOcean account or kept private to this one, which matters when auditing where droplets boot from. Also queryable are the `distribution` and `slug`, the `regions` the image is available in, minimum and on-disk sizes, the processing `status` and any `errorMessage`, applied tags, and the creation timestamp. Select an image by its numeric `id`, for example `digitalocean.image(id: 123456789)`. The `images` collection lists the account's own images (custom uploads, snapshots, and backups), while a droplet's `baseImage` may reference a public DigitalOcean catalog image.","min_provider_version":"13.1.7","defaults":"id name distribution","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.kubernetes":{"id":"digitalocean.kubernetes","fields":{"cluster":{"name":"cluster","type":"\u001bdigitalocean.kubernetes.cluster","title":"DigitalOcean Kubernetes cluster","desc":"DOKS (DigitalOcean Kubernetes Service) managed cluster. Reports the Kubernetes version and upgrade posture, the region and lifecycle status, the pod and service network CIDRs, the attached vpc, the single sign-on configuration, the control-plane firewall and enabled add-ons, and the node pools that supply worker capacity. Audit it to confirm clusters run supported versions, keep API-server access restricted, and enforce the intended authentication and upgrade policies.","provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"node":{"name":"node","type":"\u001bdigitalocean.kubernetes.node","title":"DigitalOcean Kubernetes node","desc":"Single worker node in a DOKS node pool. Reports the node name, lifecycle status and status detail message, the backing droplet the node runs on, and its creation and update timestamps. Use the status to spot nodes stuck provisioning or draining, and inspect the droplet for the node's size, networking, and firewall posture.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"nodePool":{"name":"nodePool","type":"\u001bdigitalocean.kubernetes.nodePool","title":"DigitalOcean Kubernetes node pool","desc":"Pool of worker nodes within a DOKS cluster, sharing one droplet size, autoscaling configuration, and set of Kubernetes labels and taints. Audit pools to confirm node sizing, autoscaling bounds, and the scheduling constraints applied to workloads that land on them.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true}},"is_extension":true},"digitalocean.kubernetes.cluster":{"id":"digitalocean.kubernetes.cluster","name":"digitalocean.kubernetes.cluster","fields":{"amdGpuDeviceMetricsExporterPluginEnabled":{"name":"amdGpuDeviceMetricsExporterPluginEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the AMD GPU device metrics exporter add-on is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"amdGpuDevicePluginEnabled":{"name":"amdGpuDevicePluginEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the AMD GPU device plugin add-on is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"autoUpgrade":{"name":"autoUpgrade","type":"\u0004","is_mandatory":true,"title":"Auto-upgrade enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"availableUpgradeVersions":{"name":"availableUpgradeVersions","type":"\u0019\u0007","title":"Kubernetes versions this cluster can currently upgrade to; empty when the cluster is already on the newest available version","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"clusterAutoscaler":{"name":"clusterAutoscaler","type":"\n","is_mandatory":true,"title":"Cluster autoscaler tuning","desc":"Keys: scaleDownUtilizationThreshold (fraction), scaleDownUnneededTime (duration string), expanders (list). Empty when the cluster uses platform defaults.","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"clusterSubnet":{"name":"clusterSubnet","type":"\u0007","is_mandatory":true,"title":"Cluster subnet","provider":"go.mondoo.com/mql/providers/digitalocean"},"controlPlaneFirewallAllowedAddresses":{"name":"controlPlaneFirewallAllowedAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses (CIDRs) allowed to reach the API server when the control-plane firewall is enabled","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"controlPlaneFirewallEnabled":{"name":"controlPlaneFirewallEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the control-plane firewall restricting API-server access is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"corednsAutoscalerEnabled":{"name":"corednsAutoscalerEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the CoreDNS cluster-proportional autoscaler add-on is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"endpoint":{"name":"endpoint","type":"\u0007","is_mandatory":true,"title":"Public endpoint URL of the cluster's API server","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"ha":{"name":"ha","type":"\u0004","is_mandatory":true,"title":"HA control plane enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Cluster ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"ipv4":{"name":"ipv4","type":"\u0007","is_mandatory":true,"title":"Public IPv4 address of the cluster's API server","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"maintenancePolicy":{"name":"maintenancePolicy","type":"\n","is_mandatory":true,"title":"Weekly maintenance window","desc":"Keys: startTime (24-hour HH:MM start of the window), day (day of week the window runs), duration (length of the window). Empty when no maintenance policy is configured.","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster name","provider":"go.mondoo.com/mql/providers/digitalocean"},"nodePools":{"name":"nodePools","type":"\u0019\u001bdigitalocean.kubernetes.nodePool","title":"Node pools","provider":"go.mondoo.com/mql/providers/digitalocean"},"nvidiaGpuDevicePluginEnabled":{"name":"nvidiaGpuDevicePluginEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the NVIDIA GPU device plugin add-on is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"p2pOciRegistryEnabled":{"name":"p2pOciRegistryEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the peer-to-peer OCI registry add-on is enabled; null when unset","min_provider_version":"13.13.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"rdmaSharedDevicePluginEnabled":{"name":"rdmaSharedDevicePluginEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the RDMA shared device plugin add-on is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"registryEnabled":{"name":"registryEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the integrated DigitalOcean Container Registry is enabled for the cluster","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"routingAgentEnabled":{"name":"routingAgentEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the DigitalOcean routing agent add-on is enabled; null when unset","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"serviceSubnet":{"name":"serviceSubnet","type":"\u0007","is_mandatory":true,"title":"Service subnet","provider":"go.mondoo.com/mql/providers/digitalocean"},"ssoClientId":{"name":"ssoClientId","type":"\u0007","is_mandatory":true,"title":"OAuth client ID configured for cluster SSO","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"ssoEnabled":{"name":"ssoEnabled","type":"\u0004","is_mandatory":true,"title":"Whether single sign-on is enabled for the cluster","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"ssoIssuerUrl":{"name":"ssoIssuerUrl","type":"\u0007","is_mandatory":true,"title":"OIDC issuer URL configured for cluster SSO","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"ssoRequired":{"name":"ssoRequired","type":"\u0004","is_mandatory":true,"title":"Whether single sign-on is required for the cluster","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (running, provisioning, degraded, error, deleted, upgrading, invalid)","provider":"go.mondoo.com/mql/providers/digitalocean"},"statusMessage":{"name":"statusMessage","type":"\u0007","is_mandatory":true,"title":"Status detail message (e.g., the reason for a degraded or errored state)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"surgeUpgrade":{"name":"surgeUpgrade","type":"\u0004","is_mandatory":true,"title":"Surge upgrade enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/digitalocean"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Kubernetes version","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the cluster is attached to","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcUuid":{"name":"vpcUuid","type":"\u0007","is_mandatory":true,"title":"VPC UUID","desc":"Deprecated in favor of `vpc()`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"workerSubnetUuid":{"name":"workerSubnetUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the VPC subnet the cluster's worker nodes are placed in","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Kubernetes cluster","desc":"DOKS (DigitalOcean Kubernetes Service) managed cluster. Reports the Kubernetes version and upgrade posture, the region and lifecycle status, the pod and service network CIDRs, the attached vpc, the single sign-on configuration, the control-plane firewall and enabled add-ons, and the node pools that supply worker capacity. Audit it to confirm clusters run supported versions, keep API-server access restricted, and enforce the intended authentication and upgrade policies.","min_provider_version":"13.0.1","defaults":"id name version","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.kubernetes.node":{"id":"digitalocean.kubernetes.node","name":"digitalocean.kubernetes.node","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"droplet":{"name":"droplet","type":"\u001bdigitalocean.droplet","title":"Droplet backing this node; null before the node's droplet is provisioned","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Node ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Node name","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (provisioning, running, draining, deleting)","provider":"go.mondoo.com/mql/providers/digitalocean"},"statusMessage":{"name":"statusMessage","type":"\u0007","is_mandatory":true,"title":"Status detail message (e.g., the reason a node is stuck provisioning)","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Kubernetes node","desc":"Single worker node in a DOKS node pool. Reports the node name, lifecycle status and status detail message, the backing droplet the node runs on, and its creation and update timestamps. Use the status to spot nodes stuck provisioning or draining, and inspect the droplet for the node's size, networking, and firewall posture.","private":true,"min_provider_version":"13.6.2","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.kubernetes.nodePool":{"id":"digitalocean.kubernetes.nodePool","name":"digitalocean.kubernetes.nodePool","fields":{"autoScale":{"name":"autoScale","type":"\u0004","is_mandatory":true,"title":"Auto-scale enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"cluster":{"name":"cluster","type":"\u001bdigitalocean.kubernetes.cluster","title":"Cluster this node pool belongs to","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"clusterId":{"name":"clusterId","type":"\u0007","is_mandatory":true,"title":"Cluster ID (parent)","provider":"go.mondoo.com/mql/providers/digitalocean"},"count":{"name":"count","type":"\u0005","is_mandatory":true,"title":"Number of nodes","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletSize":{"name":"dropletSize","type":"\u001bdigitalocean.size","title":"Hardware tier the pool's worker nodes run on, resolved from the size slug","min_provider_version":"13.13.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Node pool ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"labels":{"name":"labels","type":"\n","is_mandatory":true,"title":"Kubernetes labels applied to nodes in this pool","provider":"go.mondoo.com/mql/providers/digitalocean"},"maxNodes":{"name":"maxNodes","type":"\u0005","is_mandatory":true,"title":"Maximum nodes (if auto-scale)","provider":"go.mondoo.com/mql/providers/digitalocean"},"minNodes":{"name":"minNodes","type":"\u0005","is_mandatory":true,"title":"Minimum nodes (if auto-scale)","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"nodes":{"name":"nodes","type":"\u0019\u001bdigitalocean.kubernetes.node","title":"Worker nodes currently in this pool","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0007","is_mandatory":true,"title":"Droplet size slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to nodes in this pool","provider":"go.mondoo.com/mql/providers/digitalocean"},"taints":{"name":"taints","type":"\u0019\n","is_mandatory":true,"title":"Kubernetes taints applied to nodes in this pool (each dict: key, value, effect)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Kubernetes node pool","desc":"Pool of worker nodes within a DOKS cluster, sharing one droplet size, autoscaling configuration, and set of Kubernetes labels and taints. Audit pools to confirm node sizing, autoscaling bounds, and the scheduling constraints applied to workloads that land on them.","private":true,"min_provider_version":"13.0.1","defaults":"id name size","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.loadBalancer":{"id":"digitalocean.loadBalancer","name":"digitalocean.loadBalancer","fields":{"algorithm":{"name":"algorithm","type":"\u0007","is_mandatory":true,"title":"Algorithm (round_robin, least_connections)","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"disableLetsEncryptDnsRecords":{"name":"disableLetsEncryptDnsRecords","type":"\u0004","is_mandatory":true,"title":"Disable automatic Let's Encrypt DNS records","provider":"go.mondoo.com/mql/providers/digitalocean"},"domains":{"name":"domains","type":"\u0019\n","is_mandatory":true,"title":"Managed domains served by a global load balancer (each dict: name, isManaged, certificateId, status)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletIds":{"name":"dropletIds","type":"\u0019\u0005","is_mandatory":true,"title":"Droplet IDs attached to the load balancer","desc":"Deprecated in favor of `droplets()`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"droplets":{"name":"droplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets attached to this load balancer","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"enableBackendKeepalive":{"name":"enableBackendKeepalive","type":"\u0004","is_mandatory":true,"title":"Enable backend keepalive","provider":"go.mondoo.com/mql/providers/digitalocean"},"enableProxyProtocol":{"name":"enableProxyProtocol","type":"\u0004","is_mandatory":true,"title":"Enable proxy protocol","provider":"go.mondoo.com/mql/providers/digitalocean"},"exposure":{"name":"exposure","type":"\u001bdigitalocean.network.exposure","title":"Internet-exposure breakdown (public IP combined with the load balancer firewall)","min_provider_version":"13.7.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"firewallAllow":{"name":"firewallAllow","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses (CIDRs or IPs) explicitly allowed by the load balancer firewall","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"firewallDeny":{"name":"firewallDeny","type":"\u0019\u0007","is_mandatory":true,"title":"Source addresses (CIDRs or IPs) explicitly denied by the load balancer firewall","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"forwardingRules":{"name":"forwardingRules","type":"\u0019\n","is_mandatory":true,"title":"Forwarding rules","desc":"Listener mappings from incoming connections to backend targets. Each dict has keys entryProtocol, entryPort, targetProtocol, targetPort, certificateId, and tlsPassthrough.","provider":"go.mondoo.com/mql/providers/digitalocean"},"glbSettings":{"name":"glbSettings","type":"\n","is_mandatory":true,"title":"Global load balancer routing settings (each dict: targetProtocol, targetPort, cdnEnabled)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"healthCheck":{"name":"healthCheck","type":"\n","is_mandatory":true,"title":"Health check configuration","desc":"Probe used to decide whether a backend is healthy. Dict with keys protocol, port, path, checkIntervalSeconds, responseTimeoutSeconds, unhealthyThreshold, and healthyThreshold.","provider":"go.mondoo.com/mql/providers/digitalocean"},"httpIdleTimeoutSeconds":{"name":"httpIdleTimeoutSeconds","type":"\u0005","is_mandatory":true,"title":"Idle timeout for HTTP connections, in seconds; null when using the platform default","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Load balancer ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"Public IP address","provider":"go.mondoo.com/mql/providers/digitalocean"},"ipv6":{"name":"ipv6","type":"\u0007","is_mandatory":true,"title":"Public IPv6 address","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"network":{"name":"network","type":"\u0007","is_mandatory":true,"title":"Network visibility (EXTERNAL for internet-facing, INTERNAL for VPC-only)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"networkStack":{"name":"networkStack","type":"\u0007","is_mandatory":true,"title":"IP stack served (IPV4 or DUALSTACK)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the load balancer belongs to","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the load balancer belongs to","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"redirectHttpToHttps":{"name":"redirectHttpToHttps","type":"\u0004","is_mandatory":true,"title":"Redirect HTTP to HTTPS","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeSlug":{"name":"sizeSlug","type":"\u0007","is_mandatory":true,"title":"Size slug (lb-small, lb-medium, lb-large); empty when sized by node count","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeUnit":{"name":"sizeUnit","type":"\u0005","is_mandatory":true,"title":"Number of nodes the load balancer is sized to; zero when sized by slug","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (new, active, errored)","provider":"go.mondoo.com/mql/providers/digitalocean"},"stickySessions":{"name":"stickySessions","type":"\n","is_mandatory":true,"title":"Sticky sessions configuration","desc":"Session-affinity settings. Dict with keys type (none or cookies), cookieName, and cookieTtlSeconds.","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"targetLoadBalancers":{"name":"targetLoadBalancers","type":"\u0019\u001bdigitalocean.loadBalancer","title":"Regional load balancers this global load balancer distributes traffic to","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"tlsCipherPolicy":{"name":"tlsCipherPolicy","type":"\u0007","is_mandatory":true,"title":"Minimum TLS cipher policy applied to HTTPS and TLS listeners (DEFAULT or STRONG)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Load balancer type (REGIONAL, REGIONAL_NETWORK, GLOBAL)","min_provider_version":"13.6.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the load balancer is attached to","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcUuid":{"name":"vpcUuid","type":"\u0007","is_mandatory":true,"title":"VPC UUID","desc":"Deprecated in favor of `vpc()`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"}},"title":"DigitalOcean load balancer","desc":"Load balancer distributing incoming traffic across attached Droplets or, for a global load balancer, across regional load balancers. Reports the public IPv4 and IPv6 addresses, region, lifecycle status, and routing algorithm, alongside the forwardingRules, healthCheck, and stickySessions settings that govern how connections are accepted and dispatched. The firewallAllow and firewallDeny lists together with exposure describe what the load balancer accepts from the internet, making it a key checkpoint when auditing the public attack surface of a DigitalOcean deployment.","min_provider_version":"13.0.1","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.network":{"id":"digitalocean.network","fields":{"exposure":{"name":"exposure","type":"\u001bdigitalocean.network.exposure","title":"Network internet-exposure breakdown","desc":"Explains whether a resource is reachable from the internet: whether it has a public IP and whether its firewall admits inbound traffic from any address, including the case where no firewall restricts ingress at all, which leaves it fully open. Shared by droplets and internet-facing load balancers.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true}},"is_extension":true},"digitalocean.network.exposure":{"id":"digitalocean.network.exposure","name":"digitalocean.network.exposure","fields":{"firewallAllowsIngress":{"name":"firewallAllowsIngress","type":"\u0004","is_mandatory":true,"title":"Whether inbound traffic from any address is admitted: a firewall ingress rule open to the internet, or no firewall restricting ingress at all","provider":"go.mondoo.com/mql/providers/digitalocean"},"hasPublicIp":{"name":"hasPublicIp","type":"\u0004","is_mandatory":true,"title":"Whether the resource has a public IPv4 or IPv6 address","provider":"go.mondoo.com/mql/providers/digitalocean"},"internetReachable":{"name":"internetReachable","type":"\u0004","is_mandatory":true,"title":"Whether the resource is reachable from the internet (a public IP and firewall ingress that admits any address)","provider":"go.mondoo.com/mql/providers/digitalocean"},"openIngressRules":{"name":"openIngressRules","type":"\u0019\u001bdigitalocean.firewall.ingressRule","is_mandatory":true,"title":"Droplet firewall ingress rules that admit traffic from any address; empty for resources that do not use cloud-firewall ingress rules","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"Network internet-exposure breakdown","desc":"Explains whether a resource is reachable from the internet: whether it has a public IP and whether its firewall admits inbound traffic from any address, including the case where no firewall restricts ingress at all, which leaves it fully open. Shared by droplets and internet-facing load balancers.","private":true,"min_provider_version":"13.7.1","defaults":"internetReachable hasPublicIp","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.nfs":{"id":"digitalocean.nfs","name":"digitalocean.nfs","fields":{"accessPoint":{"name":"accessPoint","type":"\u001bdigitalocean.nfs.accessPoint","title":"DigitalOcean NFS access point","desc":"An access point that exports a managed NFS share to clients under its own `path` and export policy. Surfaces the access point `name`, lifecycle `status` (ACCESS_POINT_CREATING, ACCESS_POINT_ACTIVE, ACCESS_POINT_FAILED, ACCESS_POINT_DELETED), and whether it is the share's default access point (`isDefault`). The export policy is flattened from the share configuration: `protocols` lists the permitted NFS protocols (NFS, NFS4), `squashConfig` sets the UID/GID squash mode (NO_SQUASH, ROOT_SQUASH, ALL_SQUASH), `identityEnforcementEnabled` gates identity checks, and `anonUid` / `anonGid` are the anonymous identity applied to squashed requests. `vpc` resolves the VPC the access point is reachable from.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"accessPoints":{"name":"accessPoints","type":"\u0019\u001bdigitalocean.nfs.accessPoint","title":"Access points that export the share to clients","min_provider_version":"13.8.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the share was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"host":{"name":"host","type":"\u0007","is_mandatory":true,"title":"Mount host","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"NFS share ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"mountPath":{"name":"mountPath","type":"\u0007","is_mandatory":true,"title":"Mount path","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"performanceTier":{"name":"performanceTier","type":"\u0007","is_mandatory":true,"title":"Performance tier","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeGib":{"name":"sizeGib","type":"\u0005","is_mandatory":true,"title":"Allocated size, in gibibytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status (CREATING, ACTIVE, FAILED, DELETED)","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcIds":{"name":"vpcIds","type":"\u0019\u0007","is_mandatory":true,"title":"UUIDs of the VPCs the share is reachable from","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcs":{"name":"vpcs","type":"\u0019\u001bdigitalocean.vpc","title":"VPCs the share is reachable from","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean managed NFS share","desc":"Managed Network File System share that clients mount over the network. The lifecycle `status` (CREATING, ACTIVE, FAILED, DELETED) reports whether the share is usable, while `host` and `mountPath` give the mount target. `vpcs` resolves the VPCs the share is reachable from, and `accessPoints` lists the exports that govern client access. Select a share by id with `digitalocean.nfs(id: \"...\")`.","min_provider_version":"13.4.2","defaults":"id name region status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.nfs.accessPoint":{"id":"digitalocean.nfs.accessPoint","name":"digitalocean.nfs.accessPoint","fields":{"anonGid":{"name":"anonGid","type":"\u0005","is_mandatory":true,"title":"Anonymous GID applied to squashed requests","provider":"go.mondoo.com/mql/providers/digitalocean"},"anonUid":{"name":"anonUid","type":"\u0005","is_mandatory":true,"title":"Anonymous UID applied to squashed requests","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the access point was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Access point ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"identityEnforcementEnabled":{"name":"identityEnforcementEnabled","type":"\u0004","is_mandatory":true,"title":"Whether identity enforcement is enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this is the share's default access point","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"path":{"name":"path","type":"\u0007","is_mandatory":true,"title":"Export path clients mount","provider":"go.mondoo.com/mql/providers/digitalocean"},"protocols":{"name":"protocols","type":"\u0019\u0007","is_mandatory":true,"title":"Permitted NFS protocols (NFS, NFS4)","provider":"go.mondoo.com/mql/providers/digitalocean"},"shareId":{"name":"shareId","type":"\u0007","is_mandatory":true,"title":"ID of the NFS share the access point belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"squashConfig":{"name":"squashConfig","type":"\u0007","is_mandatory":true,"title":"UID/GID squash mode (NO_SQUASH, ROOT_SQUASH, ALL_SQUASH)","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status (ACCESS_POINT_CREATING, ACCESS_POINT_ACTIVE, ACCESS_POINT_FAILED, ACCESS_POINT_DELETED)","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the access point was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpc":{"name":"vpc","type":"\u001bdigitalocean.vpc","title":"VPC the access point is reachable from","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean NFS access point","desc":"An access point that exports a managed NFS share to clients under its own `path` and export policy. Surfaces the access point `name`, lifecycle `status` (ACCESS_POINT_CREATING, ACCESS_POINT_ACTIVE, ACCESS_POINT_FAILED, ACCESS_POINT_DELETED), and whether it is the share's default access point (`isDefault`). The export policy is flattened from the share configuration: `protocols` lists the permitted NFS protocols (NFS, NFS4), `squashConfig` sets the UID/GID squash mode (NO_SQUASH, ROOT_SQUASH, ALL_SQUASH), `identityEnforcementEnabled` gates identity checks, and `anonUid` / `anonGid` are the anonymous identity applied to squashed requests. `vpc` resolves the VPC the access point is reachable from.","private":true,"min_provider_version":"13.8.2","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.partnerAttachment":{"id":"digitalocean.partnerAttachment","name":"digitalocean.partnerAttachment","fields":{"bgp":{"name":"bgp","type":"\n","is_mandatory":true,"title":"BGP peering configuration","desc":"A dict with localAsn, localRouterIp, peerAsn, and peerRouterIp. The BGP authentication key is intentionally omitted as it is a shared secret.","provider":"go.mondoo.com/mql/providers/digitalocean"},"childAttachments":{"name":"childAttachments","type":"\u0019\u001bdigitalocean.partnerAttachment","title":"Child attachments connected beneath this one","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"children":{"name":"children","type":"\u0019\u0007","is_mandatory":true,"title":"UUIDs of child attachments, if any","provider":"go.mondoo.com/mql/providers/digitalocean"},"connectionBandwidthInMbps":{"name":"connectionBandwidthInMbps","type":"\u0005","is_mandatory":true,"title":"Connection bandwidth in Mbps","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Attachment ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"naasProvider":{"name":"naasProvider","type":"\u0007","is_mandatory":true,"title":"Network-as-a-Service provider (e.g., megaport)","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Attachment name","provider":"go.mondoo.com/mql/providers/digitalocean"},"parentAttachment":{"name":"parentAttachment","type":"\u001bdigitalocean.partnerAttachment","title":"Parent attachment, when this attachment is a child; null otherwise","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"parentUuid":{"name":"parentUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the parent attachment, if this is a child","provider":"go.mondoo.com/mql/providers/digitalocean"},"redundancyZone":{"name":"redundancyZone","type":"\u0007","is_mandatory":true,"title":"Redundancy zone","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"State of the attachment","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcIds":{"name":"vpcIds","type":"\u0019\u0007","is_mandatory":true,"title":"IDs of the VPCs the attachment connects","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcs":{"name":"vpcs","type":"\u0019\u001bdigitalocean.vpc","title":"VPCs the attachment connects (resolved from vpcIds)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"DigitalOcean Partner Attachment (Partner Network Connect)","desc":"Partner Network Connect attachment: a private circuit, provisioned through a Network-as-a-Service provider such as Megaport, that bridges an external network into the account's VPCs. Reports the connection `state`, `connectionBandwidthInMbps`, `region`, `naasProvider`, `redundancyZone`, the `bgp` peering configuration, the parent/child relationships, and the `vpcs` the attachment connects. A private link bridging an external network into your VPCs is a network-trust boundary worth inventorying. Select an attachment by id with `digitalocean.partnerAttachment(id: \"...\")`.","min_provider_version":"13.8.2","defaults":"id name state","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.project":{"id":"digitalocean.project","name":"digitalocean.project","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"environment":{"name":"environment","type":"\u0007","is_mandatory":true,"title":"Environment (Development, Staging, Production)","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Project ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"isDefault":{"name":"isDefault","type":"\u0004","is_mandatory":true,"title":"Whether this is the default project","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"ownerUuid":{"name":"ownerUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the account that owns the project","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"purpose":{"name":"purpose","type":"\u0007","is_mandatory":true,"title":"Purpose","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Updated at","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean project","desc":"Resource grouping used to organize droplets, databases, load balancers, and other resources under a shared purpose and environment. The declared `environment` (Development, Staging, Production) and the `isDefault` flag help audit which resources fall under production controls versus development sandboxes, and `ownerUuid` identifies the account that owns the grouping.","min_provider_version":"13.0.1","defaults":"id name environment","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.registry":{"id":"digitalocean.registry","name":"digitalocean.registry","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"garbageCollection":{"name":"garbageCollection","type":"\u001bdigitalocean.registry.garbageCollection","title":"Garbage collection run for a DigitalOcean container registry","desc":"Single garbage collection run, recording when it ran, what type of cleanup it performed, and how many blobs and bytes it removed. Supports audits like \"registry GC has run within the last 30 days\" so stale untagged manifests (and any vulnerable layers they pin) don't accumulate indefinitely.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"garbageCollections":{"name":"garbageCollections","type":"\u0019\u001bdigitalocean.registry.garbageCollection","title":"Garbage collection history for this registry (most recent first)","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Registry name","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"repositories":{"name":"repositories","type":"\u0019\u001bdigitalocean.registry.repository","title":"Repositories hosted in this registry","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"repository":{"name":"repository","type":"\u001bdigitalocean.registry.repository","title":"DigitalOcean container registry repository","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"storageUsageBytes":{"name":"storageUsageBytes","type":"\u0005","is_mandatory":true,"title":"Storage usage in bytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"storageUsageBytesUpdatedAt":{"name":"storageUsageBytesUpdatedAt","type":"\t","is_mandatory":true,"title":"Time storageUsageBytes was last recomputed (DigitalOcean updates it asynchronously); null when never computed","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"subscription":{"name":"subscription","type":"\n","is_mandatory":true,"title":"Subscription details","desc":"Map with keys: tierName, tierSlug, includedRepositories, includedStorageBytes, includedBandwidthBytes, monthlyPriceInCents, allowStorageOverage, createdAt, updatedAt.","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"subscriptionTier":{"name":"subscriptionTier","type":"\u0007","is_mandatory":true,"title":"Subscription tier slug (e.g., \"starter\", \"basic\", \"professional\")","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean container registry","desc":"Private container image registry attached to the account, covering its region, subscription tier, and current storage usage. Query it to audit where images are stored, which tier caps storage and bandwidth, and whether garbage collection is keeping stale layers in check. The `repositories` field lists the hosted repositories and `garbageCollections` returns the GC run history, most recent first.","min_provider_version":"13.0.1","defaults":"name region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.registry.garbageCollection":{"id":"digitalocean.registry.garbageCollection","name":"digitalocean.registry.garbageCollection","fields":{"blobsDeleted":{"name":"blobsDeleted","type":"\u0005","is_mandatory":true,"title":"Number of blobs deleted by this run","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the run was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"freedBytes":{"name":"freedBytes","type":"\u0005","is_mandatory":true,"title":"Total bytes freed by this run","provider":"go.mondoo.com/mql/providers/digitalocean"},"registryName":{"name":"registryName","type":"\u0007","is_mandatory":true,"title":"Registry name (parent)","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status","desc":"One of: requested, waiting, running, cancelling, cancelled, succeeded, failed.","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Garbage collection type","desc":"One of: \"untagged manifests only\", \"unreferenced blobs only\", \"untagged manifests and unreferenced blobs\".","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the run last changed state","provider":"go.mondoo.com/mql/providers/digitalocean"},"uuid":{"name":"uuid","type":"\u0007","is_mandatory":true,"title":"UUID identifying this garbage collection run","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"Garbage collection run for a DigitalOcean container registry","desc":"Single garbage collection run, recording when it ran, what type of cleanup it performed, and how many blobs and bytes it removed. Supports audits like \"registry GC has run within the last 30 days\" so stale untagged manifests (and any vulnerable layers they pin) don't accumulate indefinitely.","private":true,"min_provider_version":"13.3.1","defaults":"uuid status createdAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.registry.repository":{"id":"digitalocean.registry.repository","name":"digitalocean.registry.repository","fields":{"latestManifest":{"name":"latestManifest","type":"\u001bdigitalocean.registry.repository.manifest","title":"Most recently pushed manifest; null when the repository has no manifests","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"manifest":{"name":"manifest","type":"\u001bdigitalocean.registry.repository.manifest","title":"Manifest in a DigitalOcean container registry repository","desc":"Single image manifest identified by its content digest, including the tags that currently point at it (empty when untagged) and the layer blobs it references. Supports audits like \"no untagged manifests older than N days\" or \"every running image is pinned to a digest that still exists in the registry\".","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"manifestCount":{"name":"manifestCount","type":"\u0005","is_mandatory":true,"title":"Number of manifests, including untagged ones","provider":"go.mondoo.com/mql/providers/digitalocean"},"manifests":{"name":"manifests","type":"\u0019\u001bdigitalocean.registry.repository.manifest","title":"Manifests stored in this repository, including untagged ones","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Repository name","provider":"go.mondoo.com/mql/providers/digitalocean"},"registryName":{"name":"registryName","type":"\u0007","is_mandatory":true,"title":"Registry name (parent)","provider":"go.mondoo.com/mql/providers/digitalocean"},"tag":{"name":"tag","type":"\u001bdigitalocean.registry.repository.tag","title":"Tag in a DigitalOcean container registry repository","desc":"Single published tag of a repository, recording the manifest digest it resolves to and when it was last pushed. Useful for auditing tag drift (a floating `:latest`), tag age, or correlating running images with the underlying digests they were built from.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"tagCount":{"name":"tagCount","type":"\u0005","is_mandatory":true,"title":"Number of tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u001bdigitalocean.registry.repository.tag","title":"Tags currently published in this repository","min_provider_version":"13.3.1","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean container registry repository","private":true,"min_provider_version":"13.0.1","defaults":"name tagCount","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.registry.repository.manifest":{"id":"digitalocean.registry.repository.manifest","name":"digitalocean.registry.repository.manifest","fields":{"blobs":{"name":"blobs","type":"\u0019\n","is_mandatory":true,"title":"Layer blobs referenced by this manifest","desc":"Each entry is a map with keys: digest, compressedSizeBytes.","provider":"go.mondoo.com/mql/providers/digitalocean"},"compressedSizeBytes":{"name":"compressedSizeBytes","type":"\u0005","is_mandatory":true,"title":"Compressed size in bytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"digest":{"name":"digest","type":"\u0007","is_mandatory":true,"title":"SHA-256 digest identifying this manifest (e.g., \"sha256:abc...\")","provider":"go.mondoo.com/mql/providers/digitalocean"},"registryName":{"name":"registryName","type":"\u0007","is_mandatory":true,"title":"Registry name (parent)","provider":"go.mondoo.com/mql/providers/digitalocean"},"repository":{"name":"repository","type":"\u0007","is_mandatory":true,"title":"Repository name (parent, without the registry prefix)","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeBytes":{"name":"sizeBytes","type":"\u0005","is_mandatory":true,"title":"Uncompressed size in bytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tag strings currently pointing at this manifest; empty when the manifest is untagged","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the manifest was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"Manifest in a DigitalOcean container registry repository","desc":"Single image manifest identified by its content digest, including the tags that currently point at it (empty when untagged) and the layer blobs it references. Supports audits like \"no untagged manifests older than N days\" or \"every running image is pinned to a digest that still exists in the registry\".","private":true,"min_provider_version":"13.3.1","defaults":"repository digest updatedAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.registry.repository.tag":{"id":"digitalocean.registry.repository.tag","name":"digitalocean.registry.repository.tag","fields":{"compressedSizeBytes":{"name":"compressedSizeBytes","type":"\u0005","is_mandatory":true,"title":"Compressed size in bytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"manifestDigest":{"name":"manifestDigest","type":"\u0007","is_mandatory":true,"title":"SHA-256 manifest digest the tag resolves to (e.g., \"sha256:abc...\")","provider":"go.mondoo.com/mql/providers/digitalocean"},"registryName":{"name":"registryName","type":"\u0007","is_mandatory":true,"title":"Registry name (parent)","provider":"go.mondoo.com/mql/providers/digitalocean"},"repository":{"name":"repository","type":"\u0007","is_mandatory":true,"title":"Repository name (parent, without the registry prefix)","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeBytes":{"name":"sizeBytes","type":"\u0005","is_mandatory":true,"title":"Uncompressed size in bytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"tag":{"name":"tag","type":"\u0007","is_mandatory":true,"title":"Tag string (e.g., \"v1.2.3\", \"latest\")","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the tag was last pushed","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"Tag in a DigitalOcean container registry repository","desc":"Single published tag of a repository, recording the manifest digest it resolves to and when it was last pushed. Useful for auditing tag drift (a floating `:latest`), tag age, or correlating running images with the underlying digests they were built from.","private":true,"min_provider_version":"13.3.1","defaults":"repository tag updatedAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.reservedIp":{"id":"digitalocean.reservedIp","name":"digitalocean.reservedIp","fields":{"droplet":{"name":"droplet","type":"\u001bdigitalocean.droplet","title":"Droplet the IP is routed to; null when unassigned","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletId":{"name":"dropletId","type":"\u0005","is_mandatory":true,"title":"Droplet ID (0 if unassigned)","provider":"go.mondoo.com/mql/providers/digitalocean"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"IP address","provider":"go.mondoo.com/mql/providers/digitalocean"},"locked":{"name":"locked","type":"\u0004","is_mandatory":true,"title":"Whether the IP is locked","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the IP belongs to","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"Project ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean reserved IP","desc":"Static public IPv4 address that can be reassigned between droplets without releasing it back to the shared pool. The `locked` flag reports whether an assignment is in flight, and `dropletId` names the droplet the IP currently routes to (zero when unassigned), so you can audit which public addresses are attached where and which are sitting idle.","min_provider_version":"13.0.1","defaults":"ip region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.reservedIpV6":{"id":"digitalocean.reservedIpV6","name":"digitalocean.reservedIpV6","fields":{"droplet":{"name":"droplet","type":"\u001bdigitalocean.droplet","title":"Droplet the address is assigned to; null when unassigned","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletId":{"name":"dropletId","type":"\u0005","is_mandatory":true,"title":"Droplet ID the address is assigned to (0 if unassigned)","provider":"go.mondoo.com/mql/providers/digitalocean"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"IPv6 address","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"reservedAt":{"name":"reservedAt","type":"\t","is_mandatory":true,"title":"Time the address was reserved","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean reserved IPv6 address","desc":"Static, account-owned IPv6 address that can be assigned to a droplet. Useful for auditing which reserved addresses exist, the `region` they are held in, and whether each is attached to a droplet or sitting idle (`dropletId` is 0 when unassigned). Select by address with `digitalocean.reservedIpV6(ip: \"...\")`.","min_provider_version":"13.4.2","defaults":"ip region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.secret":{"id":"digitalocean.secret","name":"digitalocean.secret","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the secret was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"deleteRequestedAt":{"name":"deleteRequestedAt","type":"\t","is_mandatory":true,"title":"Time deletion was requested; null when the secret is not pending deletion","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Secret name","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug the secret is stored in","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the secret was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"version":{"name":"version","type":"\u0005","is_mandatory":true,"title":"Current version number","provider":"go.mondoo.com/mql/providers/digitalocean"},"versions":{"name":"versions","type":"\u0019\n","title":"Version history","desc":"One entry per stored version of the secret, ordered by the API. Each entry has `version` (the version number), `createdAt`, and `updatedAt` timestamps. The secret value itself is never included.","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean secret","desc":"A secret held in DigitalOcean's managed secrets store, scoped to a `region`. Surfaces the secret `name`, current `version`, and the `createdAt` and `updatedAt` timestamps. `deleteRequestedAt` is set when the secret is pending deletion and null otherwise. Iterate `versions` for the version history. Stored secret values are never exposed.","min_provider_version":"13.8.2","defaults":"name region version","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.securityScan":{"id":"digitalocean.securityScan","name":"digitalocean.securityScan","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the scan was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"finding":{"name":"finding","type":"\u001bdigitalocean.securityScan.finding","title":"DigitalOcean security scan finding","desc":"Single finding from a security scan. `severity` and `businessImpact` classify the issue, `details` and `technicalDetails` describe it, `mitigationSteps` lists the remediation guidance, and `affectedResources` enumerate the resources the finding applies to (`affectedResourcesCount` is the total).","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"findings":{"name":"findings","type":"\u0019\u001bdigitalocean.securityScan.finding","title":"Findings detected by the scan","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Scan ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Scan status","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean security scan","desc":"Managed security scan of the account's resources. The scan `status` and creation time summarize the run, and `findings` enumerate the issues the scan detected. Select a scan by id with `digitalocean.securityScan(id: \"...\")`, or use `digitalocean.latestSecurityScan` for the most recent run.","private":true,"min_provider_version":"13.4.2","defaults":"id status createdAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.securityScan.finding":{"id":"digitalocean.securityScan.finding","name":"digitalocean.securityScan.finding","fields":{"affectedResources":{"name":"affectedResources","type":"\u0019\n","title":"Resources affected by the finding (each dict: urn, name, type)","provider":"go.mondoo.com/mql/providers/digitalocean"},"affectedResourcesCount":{"name":"affectedResourcesCount","type":"\u0005","is_mandatory":true,"title":"Number of resources affected by the finding","provider":"go.mondoo.com/mql/providers/digitalocean"},"businessImpact":{"name":"businessImpact","type":"\u0007","is_mandatory":true,"title":"Business impact summary","provider":"go.mondoo.com/mql/providers/digitalocean"},"details":{"name":"details","type":"\u0007","is_mandatory":true,"title":"Human-readable details","provider":"go.mondoo.com/mql/providers/digitalocean"},"foundAt":{"name":"foundAt","type":"\t","is_mandatory":true,"title":"Time the finding was first detected","provider":"go.mondoo.com/mql/providers/digitalocean"},"mitigationSteps":{"name":"mitigationSteps","type":"\u0019\n","is_mandatory":true,"title":"Ordered remediation steps (each dict: step, title, description)","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Finding name","provider":"go.mondoo.com/mql/providers/digitalocean"},"ruleUuid":{"name":"ruleUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the rule that produced the finding","provider":"go.mondoo.com/mql/providers/digitalocean"},"severity":{"name":"severity","type":"\u0007","is_mandatory":true,"title":"Severity (e.g., critical, high, medium, low)","provider":"go.mondoo.com/mql/providers/digitalocean"},"technicalDetails":{"name":"technicalDetails","type":"\u0007","is_mandatory":true,"title":"Technical details","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean security scan finding","desc":"Single finding from a security scan. `severity` and `businessImpact` classify the issue, `details` and `technicalDetails` describe it, `mitigationSteps` lists the remediation guidance, and `affectedResources` enumerate the resources the finding applies to (`affectedResourcesCount` is the total).","private":true,"min_provider_version":"13.4.2","defaults":"name severity","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.size":{"id":"digitalocean.size","name":"digitalocean.size","fields":{"available":{"name":"available","type":"\u0004","is_mandatory":true,"title":"Whether the size can currently be provisioned","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Human-readable description of the size","provider":"go.mondoo.com/mql/providers/digitalocean"},"disk":{"name":"disk","type":"\u0005","is_mandatory":true,"title":"Disk capacity allocated to the size, in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"gpuInfo":{"name":"gpuInfo","type":"\n","is_mandatory":true,"title":"GPU details for GPU sizes","desc":"Null on non-GPU sizes. On GPU sizes the dict carries `count` (number of GPUs), `model` (GPU model name), and a nested `vram` dict with `amount` and `unit` describing the video memory per GPU.","provider":"go.mondoo.com/mql/providers/digitalocean"},"memory":{"name":"memory","type":"\u0005","is_mandatory":true,"title":"Memory allocated to the size, in megabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"priceHourly":{"name":"priceHourly","type":"\u0006","is_mandatory":true,"title":"Hourly price in US dollars","provider":"go.mondoo.com/mql/providers/digitalocean"},"priceMonthly":{"name":"priceMonthly","type":"\u0006","is_mandatory":true,"title":"Monthly price in US dollars","provider":"go.mondoo.com/mql/providers/digitalocean"},"regions":{"name":"regions","type":"\u0019\u0007","is_mandatory":true,"title":"Region slugs where the size is offered","provider":"go.mondoo.com/mql/providers/digitalocean"},"slug":{"name":"slug","type":"\u0007","is_mandatory":true,"title":"Size slug, for example s-1vcpu-1gb","provider":"go.mondoo.com/mql/providers/digitalocean"},"transfer":{"name":"transfer","type":"\u0006","is_mandatory":true,"title":"Included outbound transfer allowance, in terabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"vcpus":{"name":"vcpus","type":"\u0005","is_mandatory":true,"title":"Number of virtual CPUs allocated to the size","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Droplet size","desc":"Hardware tier a Droplet or Kubernetes worker node runs on, selected by its `slug` (for example `s-1vcpu-1gb` or `g-2vcpu-8gb`). Surfaces the allocated `memory`, `vcpus` and `disk`, the `priceMonthly` and `priceHourly` in US dollars, the included outbound `transfer` allowance, `gpuInfo` for GPU tiers, the `regions` where the size can currently be provisioned, and the `available` flag reporting whether it can be provisioned at all. Select a single size by slug, for example `digitalocean.size(slug: \"s-1vcpu-1gb\")`.","min_provider_version":"13.13.2","defaults":"slug vcpus memory priceMonthly","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.snapshot":{"id":"digitalocean.snapshot","name":"digitalocean.snapshot","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"droplet":{"name":"droplet","type":"\u001bdigitalocean.droplet","title":"Source droplet the snapshot was taken from; null unless resourceType is \"droplet\"","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Snapshot ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"minDiskSize":{"name":"minDiskSize","type":"\u0005","is_mandatory":true,"title":"Minimum disk size a droplet must have to use this snapshot, in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Snapshot name","provider":"go.mondoo.com/mql/providers/digitalocean"},"regions":{"name":"regions","type":"\u0019\u0007","is_mandatory":true,"title":"Region slugs the snapshot is replicated to","provider":"go.mondoo.com/mql/providers/digitalocean"},"resourceId":{"name":"resourceId","type":"\u0007","is_mandatory":true,"title":"ID of the source resource the snapshot was taken from","provider":"go.mondoo.com/mql/providers/digitalocean"},"resourceType":{"name":"resourceType","type":"\u0007","is_mandatory":true,"title":"Type of the source resource (droplet, volume)","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeGigabytes":{"name":"sizeGigabytes","type":"\u0006","is_mandatory":true,"title":"Size of the snapshot on disk, in gigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags applied to the snapshot","provider":"go.mondoo.com/mql/providers/digitalocean"},"volume":{"name":"volume","type":"\u001bdigitalocean.volume","title":"Source block-storage volume the snapshot was taken from; null unless resourceType is \"volume\"","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean snapshot","desc":"Point-in-time copy of a droplet or a block-storage volume. The `resourceType` field records the source kind (droplet or volume) and determines which source reference is populated: `droplet` for a droplet snapshot, `volume` for a volume snapshot. Auditing snapshots helps track backup coverage, snapshot sprawl, and which regions copies are replicated to. Select a snapshot by its `id`.","min_provider_version":"13.1.7","defaults":"id name resourceType","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.spacesBucket":{"id":"digitalocean.spacesBucket","name":"digitalocean.spacesBucket","fields":{"aclGrants":{"name":"aclGrants","type":"\u0019\n","is_mandatory":true,"title":"Raw ACL grants (each entry: granteeType, granteeUri, granteeDisplayName, permission)","provider":"go.mondoo.com/mql/providers/digitalocean"},"authenticatedReadAcl":{"name":"authenticatedReadAcl","type":"\u0004","is_mandatory":true,"title":"Whether the bucket ACL grants READ to the AuthenticatedUsers group (any DO/AWS-compatible account can list)","provider":"go.mondoo.com/mql/providers/digitalocean"},"corsRules":{"name":"corsRules","type":"\u0019\n","is_mandatory":true,"title":"CORS rules configured on the bucket","desc":"Each entry: allowedHeaders, allowedMethods, allowedOrigins, exposeHeaders, maxAgeSeconds, id.","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the bucket was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"encryptionAlgorithm":{"name":"encryptionAlgorithm","type":"\u0007","is_mandatory":true,"title":"Default encryption algorithm (\"AES256\" or \"aws:kms\"); empty when encryption is not configured","provider":"go.mondoo.com/mql/providers/digitalocean"},"encryptionEnabled":{"name":"encryptionEnabled","type":"\u0004","is_mandatory":true,"title":"Whether server-side encryption is configured on the bucket","provider":"go.mondoo.com/mql/providers/digitalocean"},"encryptionKmsKeyId":{"name":"encryptionKmsKeyId","type":"\u0007","is_mandatory":true,"title":"KMS key id used for default encryption when `encryptionAlgorithm` is \"aws:kms\"","provider":"go.mondoo.com/mql/providers/digitalocean"},"lifecycleRules":{"name":"lifecycleRules","type":"\u0019\n","is_mandatory":true,"title":"Lifecycle rules configured on the bucket","desc":"Each entry: id, status, prefix, expirationDays, noncurrentVersionExpirationDays, abortIncompleteMultipartUploadDays.","provider":"go.mondoo.com/mql/providers/digitalocean"},"mfaDeleteEnabled":{"name":"mfaDeleteEnabled","type":"\u0004","is_mandatory":true,"title":"Whether MFA delete is required for permanent version deletion","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Bucket name (globally unique within DigitalOcean Spaces)","provider":"go.mondoo.com/mql/providers/digitalocean"},"policy":{"name":"policy","type":"\n","is_mandatory":true,"title":"Bucket policy JSON document; nil when no policy is set","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicAccessBlocked":{"name":"publicAccessBlocked","type":"\u0004","is_mandatory":true,"title":"Whether the bucket-level Public Access Block is fully in effect (all four block flags on)","desc":"True when `BlockPublicAcls`, `BlockPublicPolicy`, `IgnorePublicAcls`, and `RestrictPublicBuckets` are all set on the bucket's `PublicAccessBlock` configuration. DigitalOcean's S3-compatible API exposes this at the bucket level only, with no account-wide toggle. False can mean either an explicit weakening or no configuration at all.","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicReadAcl":{"name":"publicReadAcl","type":"\u0004","is_mandatory":true,"title":"Whether the bucket ACL grants READ to the AllUsers group (anonymous read)","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicWriteAcl":{"name":"publicWriteAcl","type":"\u0004","is_mandatory":true,"title":"Whether the bucket ACL grants WRITE to the AllUsers group (anonymous write, should always be false)","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Spaces region the bucket lives in (e.g., \"nyc3\", \"sfo3\", \"ams3\", \"sgp1\", \"fra1\", \"syd1\", \"tor1\", \"blr1\")","provider":"go.mondoo.com/mql/providers/digitalocean"},"versioningStatus":{"name":"versioningStatus","type":"\u0007","is_mandatory":true,"title":"Versioning state (\"Enabled\", \"Suspended\"); empty when versioning has never been configured","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Spaces bucket","desc":"Object storage bucket in DigitalOcean Spaces, the S3-compatible storage service. The resolved access posture (public-access block, anonymous and authenticated-read ACLs), at-rest encryption settings, versioning state, bucket policy, CORS rules, and lifecycle rules make this the place to catch publicly readable or writable buckets, unencrypted data, missing versioning, and overly permissive CORS or lifecycle configuration. Auditing requires Spaces credentials supplied via the `DIGITALOCEAN_SPACES_KEY` and `DIGITALOCEAN_SPACES_SECRET` environment variables; an optional `DIGITALOCEAN_SPACES_REGION` scopes the listing to one region, otherwise the provider iterates the known Spaces regions.","min_provider_version":"13.2.1","defaults":"name region publicAccessBlocked encryptionEnabled versioningStatus","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.spacesKey":{"id":"digitalocean.spacesKey","name":"digitalocean.spacesKey","fields":{"accessKey":{"name":"accessKey","type":"\u0007","is_mandatory":true,"title":"Access key ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"grants":{"name":"grants","type":"\u0019\n","is_mandatory":true,"title":"Per-bucket permission bindings","desc":"Each entry is a dict with `bucket` (the Spaces bucket the grant applies to; empty scopes the key to all buckets) and `permission` (one of \"read\", \"readwrite\", or \"fullaccess\").","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean Spaces access key","desc":"Access key for DigitalOcean Spaces, the S3-compatible object storage service. The `grants` list holds the per-bucket permission bindings that scope what the key can do, making this the place to audit whether a key is over-privileged (full access rather than read-only, or unscoped to a single bucket). The matching secret is only returned at creation time and is not exposed here.","min_provider_version":"13.0.1","defaults":"name accessKey","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.sshKey":{"id":"digitalocean.sshKey","name":"digitalocean.sshKey","fields":{"algorithm":{"name":"algorithm","type":"\u0007","is_mandatory":true,"title":"Key algorithm parsed from the public key","desc":"The key type as it appears in the public key, for example ssh-ed25519, ssh-rsa, ecdsa-sha2-nistp256, or ssh-dss. Empty when the public key cannot be parsed.","min_provider_version":"13.12.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"bits":{"name":"bits","type":"\u0005","is_mandatory":true,"title":"Key size in bits parsed from the public key","desc":"The modulus size for RSA/DSA keys or the curve size for ECDSA keys. Ed25519 keys report 256. 0 when the public key cannot be parsed or the size cannot be determined.","min_provider_version":"13.12.1","provider":"go.mondoo.com/mql/providers/digitalocean"},"fingerprint":{"name":"fingerprint","type":"\u0007","is_mandatory":true,"title":"Public key fingerprint","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"SSH key ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key name","provider":"go.mondoo.com/mql/providers/digitalocean"},"publicKey":{"name":"publicKey","type":"\u0007","is_mandatory":true,"title":"Public key content","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean SSH key","desc":"SSH public key registered to the DigitalOcean account and eligible to be injected into new Droplets at creation time. Auditing these keys shows which credentials can gain initial root access to fleet instances. The `publicKey` field holds the full stored key material, while `algorithm` and `bits` are parsed from it to flag weak or legacy key types (for example ssh-dss or short RSA moduli).","min_provider_version":"13.0.1","defaults":"id name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.tag":{"id":"digitalocean.tag","name":"digitalocean.tag","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Tag name","provider":"go.mondoo.com/mql/providers/digitalocean"},"resourceCount":{"name":"resourceCount","type":"\u0005","is_mandatory":true,"title":"Total number of resources with this tag","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean tag","desc":"Cross-resource label used to group droplets, volumes, load balancers, databases, and reserved IPs. Auditing tags helps confirm that assets are consistently labelled for cost allocation, access control, and automation. The `resourceCount` field reports how many resources are currently labelled with the tag.","min_provider_version":"13.0.1","defaults":"name","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.uptimeCheck":{"id":"digitalocean.uptimeCheck","name":"digitalocean.uptimeCheck","fields":{"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the check is enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Check ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Check name","provider":"go.mondoo.com/mql/providers/digitalocean"},"regions":{"name":"regions","type":"\u0019\u0007","is_mandatory":true,"title":"Monitoring regions","provider":"go.mondoo.com/mql/providers/digitalocean"},"target":{"name":"target","type":"\u0007","is_mandatory":true,"title":"Target URL or IP","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Check type (ping, http, https)","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean uptime check","desc":"Endpoint availability monitor that probes a target URL or IP from one or more DigitalOcean regions. Use it to confirm that public endpoints are being watched, that monitoring runs from the intended regions, and that a check has not been left disabled. The `type` field records the probe protocol (ping, http, or https).","min_provider_version":"13.0.1","defaults":"id name type","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.vectorDatabase":{"id":"digitalocean.vectorDatabase","name":"digitalocean.vectorDatabase","fields":{"backup":{"name":"backup","type":"\u001bdigitalocean.vectorDatabase.backup","title":"DigitalOcean vector database backup","desc":"Single retained snapshot of a managed vector database cluster. The `status` together with the `startedAt` and `completedAt` timestamps confirm that backups complete and are taken on the expected cadence, supporting recovery-readiness audits.","is_private":true,"provider":"go.mondoo.com/mql/providers/digitalocean","is_implicit_resource":true},"backups":{"name":"backups","type":"\u0019\u001bdigitalocean.vectorDatabase.backup","title":"Retained backups for the cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the cluster was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"defaultQuantization":{"name":"defaultQuantization","type":"\u0007","is_mandatory":true,"title":"Default vector quantization mode","provider":"go.mondoo.com/mql/providers/digitalocean"},"enableAutoSchema":{"name":"enableAutoSchema","type":"\u0004","is_mandatory":true,"title":"Whether automatic schema creation is enabled","provider":"go.mondoo.com/mql/providers/digitalocean"},"grpcEndpoint":{"name":"grpcEndpoint","type":"\u0007","is_mandatory":true,"title":"gRPC connection endpoint","provider":"go.mondoo.com/mql/providers/digitalocean"},"httpEndpoint":{"name":"httpEndpoint","type":"\u0007","is_mandatory":true,"title":"HTTP connection endpoint","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Vector database cluster ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster name","provider":"go.mondoo.com/mql/providers/digitalocean"},"ownerUuid":{"name":"ownerUuid","type":"\u0007","is_mandatory":true,"title":"UUID of the account that owns the cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0007","is_mandatory":true,"title":"Size slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (e.g., creating, online)","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the cluster was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"weaviateVersion":{"name":"weaviateVersion","type":"\u0007","is_mandatory":true,"title":"Weaviate engine version","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean managed vector database","desc":"Managed vector database cluster (Weaviate) used for embedding storage and similarity search. Reports the region, size slug, lifecycle status, owning account, and the engine configuration (Weaviate version, automatic schema creation, and default quantization mode), along with the HTTP and gRPC connection endpoints and the retained backups. Select a cluster by id with `digitalocean.vectorDatabase(id: \"...\")`.","min_provider_version":"13.4.2","defaults":"id name region status","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.vectorDatabase.backup":{"id":"digitalocean.vectorDatabase.backup","name":"digitalocean.vectorDatabase.backup","fields":{"backupId":{"name":"backupId","type":"\u0007","is_mandatory":true,"title":"Backup ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"completedAt":{"name":"completedAt","type":"\t","is_mandatory":true,"title":"Time the backup completed","provider":"go.mondoo.com/mql/providers/digitalocean"},"startedAt":{"name":"startedAt","type":"\t","is_mandatory":true,"title":"Time the backup started","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backup status","provider":"go.mondoo.com/mql/providers/digitalocean"},"vectorDatabase":{"name":"vectorDatabase","type":"\u001bdigitalocean.vectorDatabase","title":"Parent vector database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"},"vectorDatabaseId":{"name":"vectorDatabaseId","type":"\u0007","is_mandatory":true,"title":"ID of the parent vector database cluster","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean vector database backup","desc":"Single retained snapshot of a managed vector database cluster. The `status` together with the `startedAt` and `completedAt` timestamps confirm that backups complete and are taken on the expected cadence, supporting recovery-readiness audits.","private":true,"min_provider_version":"13.4.2","defaults":"backupId status startedAt","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.volume":{"id":"digitalocean.volume","name":"digitalocean.volume","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"dropletIds":{"name":"dropletIds","type":"\u0019\u0005","is_mandatory":true,"title":"Droplet IDs attached to this volume","desc":"Deprecated in favor of `droplets`.","provider":"go.mondoo.com/mql/providers/digitalocean","maturity":"deprecated"},"droplets":{"name":"droplets","type":"\u0019\u001bdigitalocean.droplet","title":"Droplets this volume is attached to","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/digitalocean"},"filesystemLabel":{"name":"filesystemLabel","type":"\u0007","is_mandatory":true,"title":"Filesystem label","provider":"go.mondoo.com/mql/providers/digitalocean"},"filesystemType":{"name":"filesystemType","type":"\u0007","is_mandatory":true,"title":"Filesystem type","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Volume ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Volume name","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"sizeGigabytes":{"name":"sizeGigabytes","type":"\u0005","is_mandatory":true,"title":"Size in GB","provider":"go.mondoo.com/mql/providers/digitalocean"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Tags","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean block storage volume","desc":"Block-storage volume that can be attached to Droplets for durable, resizable disk capacity independent of the Droplet lifecycle. The size in GB, region, filesystem type and label, and applied tags describe the volume, while `droplets` resolves the Droplets it is currently attached to, useful for auditing where persistent data lives and whether volumes are orphaned or shared.","min_provider_version":"13.0.1","defaults":"id name sizeGigabytes","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.vpc":{"id":"digitalocean.vpc","name":"digitalocean.vpc","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"default":{"name":"default","type":"\u0004","is_mandatory":true,"title":"Whether this is the default VPC","provider":"go.mondoo.com/mql/providers/digitalocean"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"VPC ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"ipRange":{"name":"ipRange","type":"\u0007","is_mandatory":true,"title":"IP range (CIDR)","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"urn":{"name":"urn","type":"\u0007","is_mandatory":true,"title":"Uniform resource name (URN) identifying the VPC across DigitalOcean APIs","min_provider_version":"13.10.2","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean VPC","desc":"DigitalOcean Virtual Private Cloud, a private network that isolates Droplets, databases, load balancers, and Kubernetes clusters within a single region so they communicate over private addresses instead of the public internet. The `ipRange` field gives the network's CIDR and the `default` flag marks the region's default VPC, letting you audit network segmentation and confirm resources sit on the intended private network.","min_provider_version":"13.0.1","defaults":"id name region","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.vpcNatGateway":{"id":"digitalocean.vpcNatGateway","name":"digitalocean.vpcNatGateway","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the gateway was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"egressPublicGatewayIps":{"name":"egressPublicGatewayIps","type":"\u0019\u0007","is_mandatory":true,"title":"Public IPv4 addresses that outbound traffic egresses from","provider":"go.mondoo.com/mql/providers/digitalocean"},"icmpTimeoutSeconds":{"name":"icmpTimeoutSeconds","type":"\u0005","is_mandatory":true,"title":"ICMP connection-tracking timeout, in seconds","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"NAT gateway ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"ingressVpcs":{"name":"ingressVpcs","type":"\u0019\n","is_mandatory":true,"title":"Per-VPC attachment detail","desc":"Each entry has `vpcUuid`, `gatewayIp`, and `defaultGateway`.","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Name","provider":"go.mondoo.com/mql/providers/digitalocean"},"project":{"name":"project","type":"\u001bdigitalocean.project","title":"Project the gateway belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"ID of the project the gateway belongs to","provider":"go.mondoo.com/mql/providers/digitalocean"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region slug","provider":"go.mondoo.com/mql/providers/digitalocean"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Gateway size","provider":"go.mondoo.com/mql/providers/digitalocean"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state","provider":"go.mondoo.com/mql/providers/digitalocean"},"tcpTimeoutSeconds":{"name":"tcpTimeoutSeconds","type":"\u0005","is_mandatory":true,"title":"TCP connection-tracking timeout, in seconds","provider":"go.mondoo.com/mql/providers/digitalocean"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Gateway type (e.g., PUBLIC)","provider":"go.mondoo.com/mql/providers/digitalocean"},"udpTimeoutSeconds":{"name":"udpTimeoutSeconds","type":"\u0005","is_mandatory":true,"title":"UDP connection-tracking timeout, in seconds","provider":"go.mondoo.com/mql/providers/digitalocean"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Time the gateway was last updated","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcs":{"name":"vpcs","type":"\u0019\u001bdigitalocean.vpc","title":"VPCs the gateway is attached to","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean VPC NAT gateway","desc":"Managed appliance that provides outbound internet connectivity for resources in one or more VPCs, letting them reach the internet without each holding a public address. The `type` field gives the gateway class (e.g., PUBLIC), alongside lifecycle `state`, `region`, and `size`. The `ingressVpcs` field lists each VPC attachment's gateway IP and whether it is the default route, and `egressPublicGatewayIps` are the public addresses outbound traffic egresses from, which downstream systems can allowlist. The `udpTimeoutSeconds`, `icmpTimeoutSeconds`, and `tcpTimeoutSeconds` fields expose the connection-tracking timeouts. Select a gateway by id with `digitalocean.vpcNatGateway(id: \"...\")`.","min_provider_version":"13.4.2","defaults":"id name region state","provider":"go.mondoo.com/mql/providers/digitalocean"},"digitalocean.vpcPeering":{"id":"digitalocean.vpcPeering","name":"digitalocean.vpcPeering","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Time the resource was created","provider":"go.mondoo.com/mql/providers/digitalocean"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Peering ID","provider":"go.mondoo.com/mql/providers/digitalocean"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Peering name","provider":"go.mondoo.com/mql/providers/digitalocean"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Peering lifecycle state","desc":"One of PENDING (the peering is being established), ACTIVE (traffic flows between the peered VPCs), or DELETING (the peering is being torn down).","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcIds":{"name":"vpcIds","type":"\u0019\u0007","is_mandatory":true,"title":"VPC IDs in this peering","provider":"go.mondoo.com/mql/providers/digitalocean"},"vpcs":{"name":"vpcs","type":"\u0019\u001bdigitalocean.vpc","title":"VPCs connected by this peering","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/digitalocean"}},"title":"DigitalOcean VPC peering","desc":"Private network connection between two DigitalOcean VPCs. A peering lets resources in the connected VPCs reach each other over the private network without traversing the public internet, so it defines a trust boundary between otherwise isolated networks that is worth auditing. The `vpcIds` field identifies the two VPCs participating and `status` reports where the peering sits in its lifecycle.","min_provider_version":"13.0.1","defaults":"id name status","provider":"go.mondoo.com/mql/providers/digitalocean"}}}