{"resources":{"stackit":{"id":"stackit","name":"stackit","fields":{"affinityGroup":{"name":"affinityGroup","type":"\u001bstackit.affinityGroup","title":"STACKIT affinity group","desc":"Server placement group that keeps its member servers on the same underlying host (affinity) or spreads them across different hosts (anti-affinity). The group is keyed by its UUID id and exposes the placement policy and the member servers.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"affinityGroups":{"name":"affinityGroups","type":"\u0019\u001bstackit.affinityGroup","title":"Server affinity and anti-affinity placement groups","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"alb":{"name":"alb","type":"\u001bstackit.alb","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"albLoadBalancers":{"name":"albLoadBalancers","type":"\u0019\u001bstackit.alb.loadBalancer","title":"Application Load Balancers separate from the legacy loadBalancers product","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"albWafs":{"name":"albWafs","type":"\u0019\u001bstackit.alb.waf","title":"Web Application Firewall configurations for Application Load Balancers","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"backup":{"name":"backup","type":"\u001bstackit.backup","title":"STACKIT volume backup","desc":"Backup of a volume in the project, keyed by its UUID id. Exposes the status, size, availability zone, encryption flag, the source volume and snapshot, and timestamps. This is the compute-service backup resource; backups managed by the Server Backup service are reached through a server's backups instead.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"backups":{"name":"backups","type":"\u0019\u001bstackit.backup","title":"Volume backups","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"certificate":{"name":"certificate","type":"\u001bstackit.certificate","title":"STACKIT-managed TLS server certificate","desc":"TLS server certificate uploaded to STACKIT for use by Application Load Balancer listeners. Selected by its UUID `id`, for example stackit.certificate(id: \"d290f1ee-6c54-4b01-90e6-d701748f0851\"). The parsed X.509 attributes let audits verify the certificate's identity, key strength, signing algorithm, and validity window without decoding the PEM chain, and the `usage` field reveals which load balancer listeners depend on the certificate.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"certificates":{"name":"certificates","type":"\u0019\u001bstackit.certificate","title":"TLS server certificates managed by STACKIT Certificates","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"dns":{"name":"dns","type":"\u001bstackit.dns","title":"Managed DNS namespace","provider":"go.mondoo.com/mql/providers/stackit"},"iam":{"name":"iam","type":"\u001bstackit.iam","title":"Project-level IAM bindings (members) and roles","provider":"go.mondoo.com/mql/providers/stackit"},"image":{"name":"image","type":"\u001bstackit.image","title":"STACKIT compute image","desc":"Bootable VM image available in a project, either a public image provided by STACKIT or a private image owned by the project. The image is keyed by its UUID, for example stackit.image(id: \"a1b2c3d4-...\"). Query the disk format, minimum disk and RAM requirements, protection flag, scope, and the operating-system configuration to audit which base images the project's servers and volumes are built from.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"images":{"name":"images","type":"\u0019\u001bstackit.image","title":"VM images","provider":"go.mondoo.com/mql/providers/stackit"},"keyPair":{"name":"keyPair","type":"\u001bstackit.keyPair","title":"STACKIT SSH key pair","desc":"SSH key pair registered in the project and used to grant login access when provisioning servers. The pair is keyed by `name`, for example `stackit.keyPair(name: \"admin-key\")`, and exposes the public key material, its SHA256 fingerprint, and user-defined labels. Auditing key pairs helps confirm which public keys can be injected into new instances.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"keyPairs":{"name":"keyPairs","type":"\u0019\u001bstackit.keyPair","title":"SSH key pairs available in the project","provider":"go.mondoo.com/mql/providers/stackit"},"kms":{"name":"kms","type":"\u001bstackit.kms","title":"Key Management Service namespace (key rings + keys)","provider":"go.mondoo.com/mql/providers/stackit"},"loadBalancer":{"name":"loadBalancer","type":"\u001bstackit.loadBalancer","title":"STACKIT load balancer","desc":"Layer 4 (TCP/UDP) load balancer that distributes traffic across a backend target pool. The balancer is keyed by its `name` (unique within the project and region), for example `stackit.loadBalancer(name: \"my-lb\")`. Query it to audit the public reachability of a service: the external address, the listener port and protocol bindings, the access-control allow-list carried in `options`, and whether the balancer is confined to the private network. The `exposure` field gives the combined public-address and allow-list verdict.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"loadBalancers":{"name":"loadBalancers","type":"\u0019\u001bstackit.loadBalancer","title":"Load balancers","provider":"go.mondoo.com/mql/providers/stackit"},"logMe":{"name":"logMe","type":"\u001bstackit.logMe","title":"LogMe (managed Grafana Loki/OpenSearch logging) namespace","provider":"go.mondoo.com/mql/providers/stackit"},"mariaDb":{"name":"mariaDb","type":"\u001bstackit.mariaDb","title":"MariaDB managed namespace","provider":"go.mondoo.com/mql/providers/stackit"},"modelServing":{"name":"modelServing","type":"\u001bstackit.modelServing","title":"Managed AI Model Serving namespace","provider":"go.mondoo.com/mql/providers/stackit"},"mongoDbFlex":{"name":"mongoDbFlex","type":"\u001bstackit.mongoDbFlex","title":"MongoDB Flex managed database namespace","provider":"go.mondoo.com/mql/providers/stackit"},"network":{"name":"network","type":"\u001bstackit.network","title":"STACKIT project network","desc":"Network within a STACKIT project, keyed by its UUID `id`, for example `stackit.network(id: \"...\")`. The `routed` flag distinguishes a routed network reachable beyond the project from an isolated one, which is the first thing to check when reasoning about whether workloads on the network can be reached from outside the project. IPv4 and IPv6 prefixes, gateways, and name servers describe its addressing.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"networks":{"name":"networks","type":"\u0019\u001bstackit.network","title":"Project networks","provider":"go.mondoo.com/mql/providers/stackit"},"nic":{"name":"nic","type":"\u001bstackit.nic","title":"STACKIT network interface","desc":"Network interface belonging to a network and, when attached, to a server. The interface is keyed by its UUID id and exposes the private ipv4 and ipv6 addresses, MAC address, the network it lives in, the security groups filtering its traffic, allowed address pairs, and whether NIC-level security filtering is active.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"objectStorage":{"name":"objectStorage","type":"\u001bstackit.objectStorage","title":"S3-compatible object storage namespace","provider":"go.mondoo.com/mql/providers/stackit"},"observability":{"name":"observability","type":"\u001bstackit.observability","title":"Observability (managed Prometheus/Alertmanager) namespace","provider":"go.mondoo.com/mql/providers/stackit"},"openSearch":{"name":"openSearch","type":"\u001bstackit.openSearch","title":"OpenSearch managed namespace","provider":"go.mondoo.com/mql/providers/stackit"},"postgresFlex":{"name":"postgresFlex","type":"\u001bstackit.postgresFlex","title":"Postgres Flex managed database namespace","provider":"go.mondoo.com/mql/providers/stackit"},"project":{"name":"project","type":"\u001bstackit.project","title":"STACKIT project the connection is scoped to","provider":"go.mondoo.com/mql/providers/stackit"},"publicIp":{"name":"publicIp","type":"\u001bstackit.publicIp","title":"STACKIT public IP address","desc":"Floating public IP that can be attached to a network interface to expose a resource to the internet, useful for auditing which addresses are externally routable and whether they are currently bound to anything. The IP is keyed by its UUID, for example `stackit.publicIp(id: \"...\")`. The `networkInterfaceId` field is empty when the address is allocated but unassigned.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"publicIps":{"name":"publicIps","type":"\u0019\u001bstackit.publicIp","title":"Public (floating) IP addresses","provider":"go.mondoo.com/mql/providers/stackit"},"rabbitMq":{"name":"rabbitMq","type":"\u001bstackit.rabbitMq","title":"RabbitMQ managed namespace","provider":"go.mondoo.com/mql/providers/stackit"},"redis":{"name":"redis","type":"\u001bstackit.redis","title":"Redis managed namespace","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","title":"Region the connection targets (e.g., eu01)","provider":"go.mondoo.com/mql/providers/stackit"},"secretsManager":{"name":"secretsManager","type":"\u001bstackit.secretsManager","title":"Secrets Manager namespace","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroup":{"name":"securityGroup","type":"\u001bstackit.securityGroup","title":"STACKIT security group","desc":"Firewall rule set that governs which inbound and outbound traffic reaches the servers and network interfaces it is attached to. Auditing a security group reveals its exposure surface: overly permissive rules, whether it is stateful (return traffic for an allowed connection is admitted automatically), and its ingress and egress rules through `rules`. Selected by its UUID `id`, for example `stackit.securityGroup(id: \"9f8e7d6c-...\")`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"securityGroups":{"name":"securityGroups","type":"\u0019\u001bstackit.securityGroup","title":"Security groups","provider":"go.mondoo.com/mql/providers/stackit"},"server":{"name":"server","type":"\u001bstackit.server","title":"STACKIT compute server","desc":"Single virtual machine in a STACKIT project, keyed by its UUID `id` (for example `stackit.server(id: \"fa1d2...\")`). Central to auditing a project's compute posture: the attached volumes and their encryption state, the security groups and network interfaces that govern who can reach the instance, whether a virtual TPM backs measured boot, the image and SSH key pair it booted from, and the service accounts, backups, and operating-system update runs bound to it. The exposure breakdown pairs a public IP with security group ingress to flag servers reachable from the internet.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"servers":{"name":"servers","type":"\u0019\u001bstackit.server","title":"Compute servers (virtual machines)","provider":"go.mondoo.com/mql/providers/stackit"},"serviceAccount":{"name":"serviceAccount","type":"\u001bstackit.serviceAccount","title":"STACKIT project service account","desc":"Service account within a STACKIT project, the project-scoped principal used by automation and SDK callers to authenticate against STACKIT APIs. Service accounts are keyed by their email address, for example `stackit.serviceAccount(email: \"...\")`, and expose the project they belong to along with the access tokens and long-lived keys issued for authentication (useful for auditing credential age and active status).","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"serviceAccounts":{"name":"serviceAccounts","type":"\u0019\u001bstackit.serviceAccount","title":"Project service accounts","provider":"go.mondoo.com/mql/providers/stackit"},"sfs":{"name":"sfs","type":"\u001bstackit.sfs","title":"Managed NFS file storage (SFS) namespace","provider":"go.mondoo.com/mql/providers/stackit"},"ske":{"name":"ske","type":"\u001bstackit.ske","title":"Managed Kubernetes (SKE) namespace","provider":"go.mondoo.com/mql/providers/stackit"},"snapshot":{"name":"snapshot","type":"\u001bstackit.snapshot","title":"STACKIT volume snapshot","desc":"Point-in-time copy of a block-storage volume in the project, keyed by its UUID `id` (for example `stackit.snapshot(id: \"...\")`). Snapshots capture volume contents for backup, restore, and cloning, so the `status` and the source `volume` are the fields to check when auditing data-protection coverage.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"snapshots":{"name":"snapshots","type":"\u0019\u001bstackit.snapshot","title":"Volume snapshots","provider":"go.mondoo.com/mql/providers/stackit"},"sqlServerFlex":{"name":"sqlServerFlex","type":"\u001bstackit.sqlServerFlex","title":"SQLServer Flex managed database namespace","provider":"go.mondoo.com/mql/providers/stackit"},"telemetry":{"name":"telemetry","type":"\u001bstackit.telemetry","title":"Telemetry routing and federation namespace","provider":"go.mondoo.com/mql/providers/stackit"},"volume":{"name":"volume","type":"\u001bstackit.volume","title":"STACKIT block storage volume","desc":"Block storage volume that backs compute instances, keyed by its UUID `id` (for example `stackit.volume(id: \"...\")`). Reports the volume's size in GiB, lifecycle status, and availability zone, whether it is encrypted at rest and which key-encryption key wraps its data key, the image, snapshot, or backup it was created from, and the server it is attached to. Use it to audit unattached, unencrypted, or oversized volumes.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"volumes":{"name":"volumes","type":"\u0019\u001bstackit.volume","title":"Block storage volumes","provider":"go.mondoo.com/mql/providers/stackit"},"vpn":{"name":"vpn","type":"\u001bstackit.vpn","title":"Site-to-site VPN namespace (gateways, connections, tunnels)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT project","desc":"Project-scoped entry point for the stackit provider, covering the full estate of a single STACKIT project. The `project` field carries the project's metadata (parent organization, lifecycle state, labels) and `region` reports the region the connection targets. From here you can reach the IaaS layer (compute servers, block storage volumes, snapshots, backups, images, networks, public IPs, security groups, SSH key pairs), managed Kubernetes through `ske`, S3-compatible object storage, managed NFS file storage, managed DNS, load balancers, the managed database namespaces (Postgres Flex, MongoDB Flex, SQLServer Flex, OpenSearch, MariaDB, Redis, RabbitMQ, LogMe), the secrets vault, the managed Prometheus/Alertmanager stack, key management, project IAM bindings, and service accounts. Use it to audit what a project exposes and how its resources are configured.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.affinityGroup":{"id":"stackit.affinityGroup","name":"stackit.affinityGroup","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Affinity group UUID","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Group name","provider":"go.mondoo.com/mql/providers/stackit"},"policy":{"name":"policy","type":"\u0007","is_mandatory":true,"title":"Placement policy (for example hard-affinity, soft-affinity, hard-anti-affinity, soft-anti-affinity)","provider":"go.mondoo.com/mql/providers/stackit"},"servers":{"name":"servers","type":"\u0019\u001bstackit.server","title":"Member servers","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT affinity group","desc":"Server placement group that keeps its member servers on the same underlying host (affinity) or spreads them across different hosts (anti-affinity). The group is keyed by its UUID id and exposes the placement policy and the member servers.","private":true,"min_provider_version":"13.4.2","defaults":"id name policy","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb":{"id":"stackit.alb","fields":{"customRule":{"name":"customRule","type":"\u001bstackit.alb.customRule","title":"STACKIT Application Load Balancer custom rule","desc":"User-defined Web Application Firewall rule within a custom rule group, identified by its numeric id. Exposes the match conditions and the behavior applied when they match: the action taken (ACTION_ALLOW, ACTION_DENY, ACTION_PASS), whether the match is logged, the log message, and the severity recorded.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"customRuleCondition":{"name":"customRuleCondition","type":"\u001bstackit.alb.customRuleCondition","title":"STACKIT Application Load Balancer custom rule condition","desc":"Single match condition of a custom Web Application Firewall rule. The condition tests a request variable against a value using an operator, after applying any transformations. For example variableType REQUEST_HEADERS with variableValue \"User-Agent\", operatorType CONTAINS with operatorValue \"curl\", and a LOWERCASE transformation.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"customRuleGroup":{"name":"customRuleGroup","type":"\u001bstackit.alb.customRuleGroup","title":"STACKIT Application Load Balancer custom rule group","desc":"User-defined group of Web Application Firewall rules that match on request attributes and apply a behavior. The group is keyed by its name and exposes the custom rules it contains.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"loadBalancer":{"name":"loadBalancer","type":"\u001bstackit.alb.loadBalancer","title":"STACKIT Application Load Balancer","desc":"STACKIT Application Load Balancer (ALB)  Layer 7 (HTTP) load balancer, the newer product distinct from the legacy stackit.loadBalancer. Keyed by name (for example stackit.alb.loadBalancers.where(name == \"my-alb\")), it carries the public and private addresses, plan, status, and the listeners and target pools that route traffic. The exposure field combines the public address with the access-control allow-list to judge internet reachability, and wafs surfaces the Web Application Firewall configurations the listeners reference.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"managedRule":{"name":"managedRule","type":"\u001bstackit.alb.managedRule","title":"STACKIT Application Load Balancer managed rule","desc":"Single rule within a managed rule set, identified by its rule name. The mode determines how a matching request is handled: MODE_ENABLED blocks it, MODE_LOG_ONLY only records it, and MODE_DISABLED turns the rule off. Also exposes the rule group the rule belongs to, its severity, and its description.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"managedRuleSet":{"name":"managedRuleSet","type":"\u001bstackit.alb.managedRuleSet","title":"STACKIT Application Load Balancer managed rule set","desc":"Provider-maintained set of Web Application Firewall rules, grouped and individually toggled between blocking and detection behavior. The set is keyed by its name and exposes the rule set type and version and the rule groups, each holding the per-rule mode.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"waf":{"name":"waf","type":"\u001bstackit.alb.waf","title":"STACKIT Application Load Balancer WAF configuration","desc":"Web Application Firewall configuration that a load balancer listener can reference by name to inspect and filter inbound HTTP traffic. The configuration is keyed by its name and binds a managed rule set and a custom rule group, both resolvable as managedRuleSet and customRuleGroup.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true}},"is_extension":true},"stackit.alb.customRule":{"id":"stackit.alb.customRule","name":"stackit.alb.customRule","fields":{"action":{"name":"action","type":"\u0007","is_mandatory":true,"title":"Action applied when the conditions match (ACTION_ALLOW, ACTION_DENY, ACTION_PASS, ACTION_UNSPECIFIED)","provider":"go.mondoo.com/mql/providers/stackit"},"conditions":{"name":"conditions","type":"\u0019\u001bstackit.alb.customRuleCondition","title":"Match conditions that must hold for the rule to apply","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Rule ID (unique within the custom rule group)","provider":"go.mondoo.com/mql/providers/stackit"},"log":{"name":"log","type":"\u0004","is_mandatory":true,"title":"Whether a match is logged","provider":"go.mondoo.com/mql/providers/stackit"},"logMsg":{"name":"logMsg","type":"\u0007","is_mandatory":true,"title":"Log message emitted on a match","provider":"go.mondoo.com/mql/providers/stackit"},"severity":{"name":"severity","type":"\u0007","is_mandatory":true,"title":"Severity recorded for a match","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Application Load Balancer custom rule","desc":"User-defined Web Application Firewall rule within a custom rule group, identified by its numeric id. Exposes the match conditions and the behavior applied when they match: the action taken (ACTION_ALLOW, ACTION_DENY, ACTION_PASS), whether the match is logged, the log message, and the severity recorded.","private":true,"min_provider_version":"13.4.2","defaults":"id action severity","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb.customRuleCondition":{"id":"stackit.alb.customRuleCondition","name":"stackit.alb.customRuleCondition","fields":{"operatorType":{"name":"operatorType","type":"\u0007","is_mandatory":true,"title":"Operator applied to the variable (for example CONTAINS, EQUALS, REGEX)","provider":"go.mondoo.com/mql/providers/stackit"},"operatorValue":{"name":"operatorValue","type":"\u0007","is_mandatory":true,"title":"Value the operator compares the variable against","provider":"go.mondoo.com/mql/providers/stackit"},"transformations":{"name":"transformations","type":"\u0019\u0007","is_mandatory":true,"title":"Transformations applied to the variable before evaluation (for example LOWERCASE, URL_DECODE)","provider":"go.mondoo.com/mql/providers/stackit"},"variableType":{"name":"variableType","type":"\u0007","is_mandatory":true,"title":"Request attribute the condition inspects (for example REQUEST_HEADERS, REQUEST_URI)","provider":"go.mondoo.com/mql/providers/stackit"},"variableValue":{"name":"variableValue","type":"\u0007","is_mandatory":true,"title":"Specifier for the variable, such as a header name (empty when not applicable)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Application Load Balancer custom rule condition","desc":"Single match condition of a custom Web Application Firewall rule. The condition tests a request variable against a value using an operator, after applying any transformations. For example variableType REQUEST_HEADERS with variableValue \"User-Agent\", operatorType CONTAINS with operatorValue \"curl\", and a LOWERCASE transformation.","private":true,"min_provider_version":"13.4.2","defaults":"variableType operatorType operatorValue","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb.customRuleGroup":{"id":"stackit.alb.customRuleGroup","name":"stackit.alb.customRuleGroup","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Custom rule group name (unique within the project+region)","provider":"go.mondoo.com/mql/providers/stackit"},"rules":{"name":"rules","type":"\u0019\u001bstackit.alb.customRule","title":"Custom rules the group contains","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT Application Load Balancer custom rule group","desc":"User-defined group of Web Application Firewall rules that match on request attributes and apply a behavior. The group is keyed by its name and exposes the custom rules it contains.","private":true,"min_provider_version":"13.4.2","defaults":"name","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb.loadBalancer":{"id":"stackit.alb.loadBalancer","name":"stackit.alb.loadBalancer","fields":{"disableTargetSecurityGroupAssignment":{"name":"disableTargetSecurityGroupAssignment","type":"\u0004","is_mandatory":true,"title":"Whether the operator opted out of auto-assigning the target SG to backends","provider":"go.mondoo.com/mql/providers/stackit"},"errors":{"name":"errors","type":"\u0019\n","is_mandatory":true,"title":"Errors reported by the ALB ([{type, description}])","provider":"go.mondoo.com/mql/providers/stackit"},"exposure":{"name":"exposure","type":"\u001bstackit.network.exposure","title":"Internet-exposure breakdown (public address combined with the access-control allow-list)","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"externalAddress":{"name":"externalAddress","type":"\u0007","is_mandatory":true,"title":"External (public) IPv4/IPv6 address (empty if private-only)","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"listeners":{"name":"listeners","type":"\u0019\n","is_mandatory":true,"title":"Frontend listeners","desc":"Port and protocol bindings that accept inbound traffic. Each entry is a dict with keys name, port, protocol, http, https, and wafConfigName (the name of the WAF configuration applied to the listener).","provider":"go.mondoo.com/mql/providers/stackit"},"loadBalancerSecurityGroup":{"name":"loadBalancerSecurityGroup","type":"\n","is_mandatory":true,"title":"STACKIT-managed security group","desc":"Security group STACKIT provisions and attaches to the balancer itself, a dict with keys id and name. Null when none is assigned.","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"ALB name (unique within the project+region)","provider":"go.mondoo.com/mql/providers/stackit"},"networks":{"name":"networks","type":"\u0019\n","is_mandatory":true,"title":"Networks attached to the LB ([{networkId, role}])","provider":"go.mondoo.com/mql/providers/stackit"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Load balancer options","desc":"Behavioral settings for the balancer, a dict with keys accessControl (holding allowedSourceRanges, the CIDR allow-list restricting who may reach the balancer), ephemeralAddress, observability, and privateNetworkOnly.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan ID (sizing tier)","provider":"go.mondoo.com/mql/providers/stackit"},"privateAddress":{"name":"privateAddress","type":"\u0007","is_mandatory":true,"title":"Internal/private address","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the ALB lives in","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (STATUS_READY, STATUS_PENDING, STATUS_ERROR, STATUS_TERMINATING, STATUS_UNSPECIFIED)","provider":"go.mondoo.com/mql/providers/stackit"},"targetPools":{"name":"targetPools","type":"\u0019\n","is_mandatory":true,"title":"Backend target pools","desc":"Backend server groups that receive forwarded traffic. Each entry is a dict with keys name, targetPort, targets, activeHealthCheck, and tlsConfig.","provider":"go.mondoo.com/mql/providers/stackit"},"targetSecurityGroup":{"name":"targetSecurityGroup","type":"\n","is_mandatory":true,"title":"STACKIT-managed target security group","desc":"Security group STACKIT provisions for the backend targets, a dict with keys id and name. Null when none is assigned.","provider":"go.mondoo.com/mql/providers/stackit"},"wafs":{"name":"wafs","type":"\u0019\u001bstackit.alb.waf","title":"Web Application Firewall configurations referenced by the LB's listeners","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Application Load Balancer","desc":"STACKIT Application Load Balancer (ALB)  Layer 7 (HTTP) load balancer, the newer product distinct from the legacy stackit.loadBalancer. Keyed by name (for example stackit.alb.loadBalancers.where(name == \"my-alb\")), it carries the public and private addresses, plan, status, and the listeners and target pools that route traffic. The exposure field combines the public address with the access-control allow-list to judge internet reachability, and wafs surfaces the Web Application Firewall configurations the listeners reference.","private":true,"min_provider_version":"13.0.1","defaults":"name status externalAddress","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb.managedRule":{"id":"stackit.alb.managedRule","name":"stackit.alb.managedRule","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Rule description","provider":"go.mondoo.com/mql/providers/stackit"},"groupName":{"name":"groupName","type":"\u0007","is_mandatory":true,"title":"Name of the rule group the rule belongs to","provider":"go.mondoo.com/mql/providers/stackit"},"mode":{"name":"mode","type":"\u0007","is_mandatory":true,"title":"Mode applied to the rule (MODE_ENABLED, MODE_DISABLED, MODE_LOG_ONLY, MODE_UNSPECIFIED)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Rule name (identifier within the managed rule set)","provider":"go.mondoo.com/mql/providers/stackit"},"severity":{"name":"severity","type":"\u0007","is_mandatory":true,"title":"Rule severity (CRITICAL, ERROR, WARNING, INFO)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Application Load Balancer managed rule","desc":"Single rule within a managed rule set, identified by its rule name. The mode determines how a matching request is handled: MODE_ENABLED blocks it, MODE_LOG_ONLY only records it, and MODE_DISABLED turns the rule off. Also exposes the rule group the rule belongs to, its severity, and its description.","private":true,"min_provider_version":"13.4.2","defaults":"name groupName mode severity","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb.managedRuleSet":{"id":"stackit.alb.managedRuleSet","name":"stackit.alb.managedRuleSet","fields":{"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Managed rule set name (unique within the project+region)","provider":"go.mondoo.com/mql/providers/stackit"},"rules":{"name":"rules","type":"\u0019\u001bstackit.alb.managedRule","title":"Rules in the set, each toggled between blocking and detection behavior","provider":"go.mondoo.com/mql/providers/stackit"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Rule set type","provider":"go.mondoo.com/mql/providers/stackit"},"version":{"name":"version","type":"\u0007","is_mandatory":true,"title":"Rule set version","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT Application Load Balancer managed rule set","desc":"Provider-maintained set of Web Application Firewall rules, grouped and individually toggled between blocking and detection behavior. The set is keyed by its name and exposes the rule set type and version and the rule groups, each holding the per-rule mode.","private":true,"min_provider_version":"13.4.2","defaults":"name type version","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.alb.waf":{"id":"stackit.alb.waf","name":"stackit.alb.waf","fields":{"customRuleGroup":{"name":"customRuleGroup","type":"\u001bstackit.alb.customRuleGroup","title":"Custom rule group bound to the configuration","provider":"go.mondoo.com/mql/providers/stackit"},"customRuleGroupName":{"name":"customRuleGroupName","type":"\u0007","is_mandatory":true,"title":"Name of the custom rule group bound to the configuration (empty if none)","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"managedRuleSet":{"name":"managedRuleSet","type":"\u001bstackit.alb.managedRuleSet","title":"Managed rule set bound to the configuration","provider":"go.mondoo.com/mql/providers/stackit"},"managedRuleSetName":{"name":"managedRuleSetName","type":"\u0007","is_mandatory":true,"title":"Name of the managed rule set bound to the configuration (empty if none)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"WAF configuration name (unique within the project+region)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT Application Load Balancer WAF configuration","desc":"Web Application Firewall configuration that a load balancer listener can reference by name to inspect and filter inbound HTTP traffic. The configuration is keyed by its name and binds a managed rule set and a custom rule group, both resolvable as managedRuleSet and customRuleGroup.","private":true,"min_provider_version":"13.4.2","defaults":"name managedRuleSetName customRuleGroupName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.backup":{"id":"stackit.backup","name":"stackit.backup","fields":{"availabilityZone":{"name":"availabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the backup is encrypted at rest","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Backup UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Backup name","provider":"go.mondoo.com/mql/providers/stackit"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Size in GiB","provider":"go.mondoo.com/mql/providers/stackit"},"snapshot":{"name":"snapshot","type":"\u001bstackit.snapshot","title":"Source snapshot the backup was taken from (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backup status","desc":"One of AVAILABLE, CREATING, DELETED, DELETING, ERROR, or RESTORING.","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"volume":{"name":"volume","type":"\u001bstackit.volume","title":"Source volume the backup was taken from (nullable)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT volume backup","desc":"Backup of a volume in the project, keyed by its UUID id. Exposes the status, size, availability zone, encryption flag, the source volume and snapshot, and timestamps. This is the compute-service backup resource; backups managed by the Server Backup service are reached through a server's backups instead.","private":true,"min_provider_version":"13.4.2","defaults":"id name status size","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.certificate":{"id":"stackit.certificate","name":"stackit.certificate","fields":{"dnsNames":{"name":"dnsNames","type":"\u0007","is_mandatory":true,"title":"Subject Alternative Names the certificate is valid for","desc":"Comma-separated list of all domains and IP addresses covered by the certificate.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"extendedKeyUsage":{"name":"extendedKeyUsage","type":"\u0007","is_mandatory":true,"title":"Extended key usages the certificate is valid for","desc":"Comma-separated list of purposes, for example \"Server Auth\", which is required for load balancer use.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"fingerprintSha1":{"name":"fingerprintSha1","type":"\u0007","is_mandatory":true,"title":"SHA1 thumbprint of the certificate","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"fingerprintSha256":{"name":"fingerprintSha256","type":"\u0007","is_mandatory":true,"title":"SHA256 hash of the raw certificate bytes","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Certificate UUID","provider":"go.mondoo.com/mql/providers/stackit"},"issuer":{"name":"issuer","type":"\u0007","is_mandatory":true,"title":"Common name (CN) of the certificate authority that issued the certificate","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"keyAlgorithm":{"name":"keyAlgorithm","type":"\u0007","is_mandatory":true,"title":"Public-key algorithm of the key pair, for example RSA or ECDSA","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"keyBitSize":{"name":"keyBitSize","type":"\u0005","is_mandatory":true,"title":"Key size in bits","desc":"Bit length of the public key, for example 2048 for RSA. Null for elliptic-curve keys, which are described by a curve name rather than a bit size (see keyStrength).","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"keyStrength":{"name":"keyStrength","type":"\u0007","is_mandatory":true,"title":"Public-key strength summary","desc":"Human-readable description of the key's algorithm and bit length or curve name, for example \"RSA 2048\", \"ECDSA P-256\", or \"Ed25519\".","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels attached to the certificate","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"User-supplied certificate name","provider":"go.mondoo.com/mql/providers/stackit"},"notAfter":{"name":"notAfter","type":"\t","is_mandatory":true,"title":"Expiration of the certificate validity period","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"notBefore":{"name":"notBefore","type":"\t","is_mandatory":true,"title":"Start of the certificate validity period","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"publicKey":{"name":"publicKey","type":"\u0007","is_mandatory":true,"title":"PEM-encoded certificate chain (leaf + intermediates)","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the certificate is uploaded to","provider":"go.mondoo.com/mql/providers/stackit"},"serialNumber":{"name":"serialNumber","type":"\u0007","is_mandatory":true,"title":"Serial number assigned by the CA, in uppercase hexadecimal","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"signingAlgorithm":{"name":"signingAlgorithm","type":"\u0007","is_mandatory":true,"title":"Algorithm the issuing CA used to sign the certificate","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"subject":{"name":"subject","type":"\u0007","is_mandatory":true,"title":"Subject common name (CN) of the certificate","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"usage":{"name":"usage","type":"\u0019\n","is_mandatory":true,"title":"Load balancer listeners consuming the certificate","desc":"One entry per load balancer that references the certificate, each with `loadBalancerName` and the `listenerNames` on that load balancer using it ([{loadBalancerName, listenerNames}]).","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT-managed TLS server certificate","desc":"TLS server certificate uploaded to STACKIT for use by Application Load Balancer listeners. Selected by its UUID `id`, for example stackit.certificate(id: \"d290f1ee-6c54-4b01-90e6-d701748f0851\"). The parsed X.509 attributes let audits verify the certificate's identity, key strength, signing algorithm, and validity window without decoding the PEM chain, and the `usage` field reveals which load balancer listeners depend on the certificate.","private":true,"min_provider_version":"13.0.1","defaults":"id name region","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.dns":{"id":"stackit.dns","name":"stackit.dns","fields":{"recordSet":{"name":"recordSet","type":"\u001bstackit.dns.recordSet","title":"STACKIT DNS record set","desc":"Resource record set (RRSet) within a DNS zone, keyed by its UUID `id`. Groups every record of one `type` (A, AAAA, CNAME, MX, TXT, NS, SRV, and so on) under a single `name`, along with the record values, TTL, and lifecycle state. Query record sets to inspect the actual DNS answers a zone serves, for example CNAME targets, MX hosts, or TXT verification and SPF values.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"zone":{"name":"zone","type":"\u001bstackit.dns.zone","title":"STACKIT DNS zone","desc":"Managed DNS zone within the project, keyed by its UUID `id`. Covers the domain name, primary or secondary type, public or private visibility, SOA timing (refresh, retry, expire, negative cache), the query ACL, and lifecycle state. Query zones to audit which domains the project is authoritative for and whether their records are reachable publicly.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"zones":{"name":"zones","type":"\u0019\u001bstackit.dns.zone","title":"DNS zones managed by the project","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT DNS namespace","desc":"Managed DNS zones in the project and the record sets within them. Query zones to audit which domains the project is authoritative for, their public or private visibility, and TTL hygiene; each zone in turn exposes its record sets for inspecting individual DNS answers.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.dns.recordSet":{"id":"stackit.dns.recordSet","name":"stackit.dns.recordSet","fields":{"active":{"name":"active","type":"\u0004","is_mandatory":true,"title":"Whether the record set is for active healthcheck failover","provider":"go.mondoo.com/mql/providers/stackit"},"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Comment","provider":"go.mondoo.com/mql/providers/stackit"},"creationFinishedAt":{"name":"creationFinishedAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"creationStartedAt":{"name":"creationStartedAt","type":"\t","is_mandatory":true,"title":"When record set creation started","min_provider_version":"13.2.2","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Record set UUID","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Record name (FQDN, e.g., `www.example.com.`)","provider":"go.mondoo.com/mql/providers/stackit"},"records":{"name":"records","type":"\u0019\u0007","is_mandatory":true,"title":"Record values (textual representation of each record in the set)","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (CREATING, CREATE_SUCCEEDED, CREATE_FAILED, DELETING, DELETE_SUCCEEDED, DELETE_FAILED, UPDATING, UPDATE_SUCCEEDED, UPDATE_FAILED)","provider":"go.mondoo.com/mql/providers/stackit"},"ttl":{"name":"ttl","type":"\u0005","is_mandatory":true,"title":"Record TTL (seconds)","provider":"go.mondoo.com/mql/providers/stackit"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Record type (A, AAAA, CNAME, MX, TXT, NS, SRV, …)","provider":"go.mondoo.com/mql/providers/stackit"},"updateFinishedAt":{"name":"updateFinishedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"zone":{"name":"zone","type":"\u001bstackit.dns.zone","title":"Zone the record set belongs to","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"zoneId":{"name":"zoneId","type":"\u0007","is_mandatory":true,"title":"Owning zone UUID","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT DNS record set","desc":"Resource record set (RRSet) within a DNS zone, keyed by its UUID `id`. Groups every record of one `type` (A, AAAA, CNAME, MX, TXT, NS, SRV, and so on) under a single `name`, along with the record values, TTL, and lifecycle state. Query record sets to inspect the actual DNS answers a zone serves, for example CNAME targets, MX hosts, or TXT verification and SPF values.","private":true,"min_provider_version":"13.0.0","defaults":"name type state","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.dns.zone":{"id":"stackit.dns.zone","name":"stackit.dns.zone","fields":{"acl":{"name":"acl","type":"\u0007","is_mandatory":true,"title":"ACL CIDRs allowed to query (for zones with restricted ACL)","provider":"go.mondoo.com/mql/providers/stackit"},"contactEmail":{"name":"contactEmail","type":"\u0007","is_mandatory":true,"title":"Authoritative contact email","provider":"go.mondoo.com/mql/providers/stackit"},"creationFinishedAt":{"name":"creationFinishedAt","type":"\t","is_mandatory":true,"title":"When zone creation finished","provider":"go.mondoo.com/mql/providers/stackit"},"creationStartedAt":{"name":"creationStartedAt","type":"\t","is_mandatory":true,"title":"When zone creation started","min_provider_version":"13.2.2","provider":"go.mondoo.com/mql/providers/stackit"},"defaultTtl":{"name":"defaultTtl","type":"\u0005","is_mandatory":true,"title":"Default record TTL (seconds)","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"dnsName":{"name":"dnsName","type":"\u0007","is_mandatory":true,"title":"Zone name (e.g., `example.com.`)","provider":"go.mondoo.com/mql/providers/stackit"},"expireTime":{"name":"expireTime","type":"\u0005","is_mandatory":true,"title":"SOA expire (seconds)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Zone UUID","provider":"go.mondoo.com/mql/providers/stackit"},"isReverseZone":{"name":"isReverseZone","type":"\u0004","is_mandatory":true,"title":"Whether this is a reverse DNS zone","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"negativeCache":{"name":"negativeCache","type":"\u0005","is_mandatory":true,"title":"Negative-cache TTL (seconds)","provider":"go.mondoo.com/mql/providers/stackit"},"primaries":{"name":"primaries","type":"\u0019\u0007","is_mandatory":true,"title":"Primary nameservers (for secondary zones)","provider":"go.mondoo.com/mql/providers/stackit"},"primaryNameServer":{"name":"primaryNameServer","type":"\u0007","is_mandatory":true,"title":"SOA primary nameserver","provider":"go.mondoo.com/mql/providers/stackit"},"recordCount":{"name":"recordCount","type":"\u0005","is_mandatory":true,"title":"Number of record sets in the zone","provider":"go.mondoo.com/mql/providers/stackit"},"recordSets":{"name":"recordSets","type":"\u0019\u001bstackit.dns.recordSet","title":"Record sets in the zone","provider":"go.mondoo.com/mql/providers/stackit"},"refreshTime":{"name":"refreshTime","type":"\u0005","is_mandatory":true,"title":"SOA refresh (seconds)","provider":"go.mondoo.com/mql/providers/stackit"},"retryTime":{"name":"retryTime","type":"\u0005","is_mandatory":true,"title":"SOA retry (seconds)","provider":"go.mondoo.com/mql/providers/stackit"},"serialNumber":{"name":"serialNumber","type":"\u0005","is_mandatory":true,"title":"SOA serial","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (CREATING, CREATE_SUCCEEDED, CREATE_FAILED, DELETING, DELETE_SUCCEEDED, DELETE_FAILED, UPDATING, UPDATE_SUCCEEDED, UPDATE_FAILED)","provider":"go.mondoo.com/mql/providers/stackit"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Zone type (primary, secondary)","provider":"go.mondoo.com/mql/providers/stackit"},"visibility":{"name":"visibility","type":"\u0007","is_mandatory":true,"title":"Visibility (public, private)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT DNS zone","desc":"Managed DNS zone within the project, keyed by its UUID `id`. Covers the domain name, primary or secondary type, public or private visibility, SOA timing (refresh, retry, expire, negative cache), the query ACL, and lifecycle state. Query zones to audit which domains the project is authoritative for and whether their records are reachable publicly.","private":true,"min_provider_version":"13.0.0","defaults":"id dnsName type state","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.iam":{"id":"stackit.iam","name":"stackit.iam","fields":{"member":{"name":"member","type":"\u001bstackit.iam.member","title":"STACKIT IAM project member","desc":"Single project member binding that ties one principal (a user email, service-account email, or group identifier) to one role on the project. Each binding is keyed by `subject/role`, so the same principal appears once per role it holds. Audit these bindings to find over-privileged or stale access.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"members":{"name":"members","type":"\u0019\u001bstackit.iam.member","title":"Members bound to the project (one entry per (subject, role) pair)","provider":"go.mondoo.com/mql/providers/stackit"},"role":{"name":"role","type":"\u001bstackit.iam.role","title":"STACKIT IAM role","desc":"Single role defined on the project, grouping the set of `permissions` that members assigned to it are granted. Inspect a role to see the exact actions it confers when reviewing what a member binding allows.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"roles":{"name":"roles","type":"\u0019\u001bstackit.iam.role","title":"Roles defined on the project","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT IAM namespace","desc":"Project-level identity and access management for a STACKIT project: the member bindings that grant principals access and the roles defined on the project. This namespace is the source for least-privilege and stale-access audits. Enumerate the bindings with members and the roles with roles.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.iam.member":{"id":"stackit.iam.member","name":"stackit.iam.member","fields":{"role":{"name":"role","type":"\u0007","is_mandatory":true,"title":"Role assigned to the subject","provider":"go.mondoo.com/mql/providers/stackit"},"subject":{"name":"subject","type":"\u0007","is_mandatory":true,"title":"Principal identifier (user/service-account email, group id)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT IAM project member","desc":"Single project member binding that ties one principal (a user email, service-account email, or group identifier) to one role on the project. Each binding is keyed by `subject/role`, so the same principal appears once per role it holds. Audit these bindings to find over-privileged or stale access.","private":true,"min_provider_version":"13.0.1","defaults":"subject role","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.iam.role":{"id":"stackit.iam.role","name":"stackit.iam.role","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description (free text)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Role name (unique within the project)","provider":"go.mondoo.com/mql/providers/stackit"},"permissions":{"name":"permissions","type":"\u0019\u0007","is_mandatory":true,"title":"Permissions granted by the role (`\u003cresource\u003e.\u003caction\u003e` strings)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT IAM role","desc":"Single role defined on the project, grouping the set of `permissions` that members assigned to it are granted. Inspect a role to see the exact actions it confers when reviewing what a member binding allows.","private":true,"min_provider_version":"13.0.1","defaults":"name","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.image":{"id":"stackit.image","name":"stackit.image","fields":{"checksum":{"name":"checksum","type":"\n","is_mandatory":true,"title":"Image checksum","desc":"Content checksum with keys `algorithm` (the hash algorithm, for example md5 or sha512) and `digest` (the hex checksum value).","provider":"go.mondoo.com/mql/providers/stackit"},"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Image configuration","desc":"Boot and hardware settings with keys `bootMenu`, `cdromBus`, `diskBus`, `nicModel`, `operatingSystem`, `operatingSystemDistro`, `operatingSystemVersion`, `rescueBus`, `rescueDevice`, `secureBoot`, `uefi`, `videoModel`, and `virtioScsi`.","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"diskFormat":{"name":"diskFormat","type":"\u0007","is_mandatory":true,"title":"Disk format (qcow2, raw, iso, …)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Image UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"minDiskSize":{"name":"minDiskSize","type":"\u0005","is_mandatory":true,"title":"Minimum disk size required (GiB)","provider":"go.mondoo.com/mql/providers/stackit"},"minRam":{"name":"minRam","type":"\u0005","is_mandatory":true,"title":"Minimum RAM required (MiB)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Image name","provider":"go.mondoo.com/mql/providers/stackit"},"owner":{"name":"owner","type":"\u0007","is_mandatory":true,"title":"Owning project (empty for public images)","provider":"go.mondoo.com/mql/providers/stackit"},"protected":{"name":"protected","type":"\u0004","is_mandatory":true,"title":"Image protected flag (true = cannot be deleted)","provider":"go.mondoo.com/mql/providers/stackit"},"scope":{"name":"scope","type":"\u0007","is_mandatory":true,"title":"Image scope (public, private)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (CREATING, AVAILABLE, DELETING, ERROR)","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT compute image","desc":"Bootable VM image available in a project, either a public image provided by STACKIT or a private image owned by the project. The image is keyed by its UUID, for example stackit.image(id: \"a1b2c3d4-...\"). Query the disk format, minimum disk and RAM requirements, protection flag, scope, and the operating-system configuration to audit which base images the project's servers and volumes are built from.","private":true,"min_provider_version":"13.0.0","defaults":"id name status diskFormat","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.keyPair":{"id":"stackit.keyPair","name":"stackit.keyPair","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"fingerprint":{"name":"fingerprint","type":"\u0007","is_mandatory":true,"title":"SHA256 fingerprint","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Key pair name (primary identifier)","provider":"go.mondoo.com/mql/providers/stackit"},"publicKey":{"name":"publicKey","type":"\u0007","is_mandatory":true,"title":"Public key content (OpenSSH format)","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT SSH key pair","desc":"SSH key pair registered in the project and used to grant login access when provisioning servers. The pair is keyed by `name`, for example `stackit.keyPair(name: \"admin-key\")`, and exposes the public key material, its SHA256 fingerprint, and user-defined labels. Auditing key pairs helps confirm which public keys can be injected into new instances.","private":true,"min_provider_version":"13.0.0","defaults":"name fingerprint","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.kms":{"id":"stackit.kms","name":"stackit.kms","fields":{"key":{"name":"key","type":"\u001bstackit.kms.key","title":"STACKIT KMS key","desc":"Cryptographic key managed by STACKIT KMS. Each key is keyed by its UUID `id` and is scoped to a `keyRingId`. The `purpose` describes what the key is allowed to do (SYMMETRIC_ENCRYPT_DECRYPT and siblings), `algorithm` is the underlying primitive, `protection` is the storage backend (SOFTWARE, HSM), and `state` is the lifecycle state. `deletionDate` is non-null only when the key has been scheduled for deletion.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"keyRing":{"name":"keyRing","type":"\u001bstackit.kms.keyRing","title":"STACKIT KMS key ring","desc":"Logical container that groups KMS keys for IAM and lifecycle purposes. Keyed by its UUID `id`, for example `stackit.kms.keyRing(id: \"...\")`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"keyRings":{"name":"keyRings","type":"\u0019\u001bstackit.kms.keyRing","title":"Key rings in the project's KMS scope","provider":"go.mondoo.com/mql/providers/stackit"},"keys":{"name":"keys","type":"\u0019\u001bstackit.kms.key","title":"All keys across all key rings (flattened convenience)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT KMS namespace","desc":"Key Management Service (KMS) scope for a project, exposing the cryptographic key rings and the keys within them. STACKIT KMS is the source of the KEKs that wrap volume- and bucket-level data-encryption keys, so this is the entry point for customer-managed-key audits.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.kms.key":{"id":"stackit.kms.key","name":"stackit.kms.key","fields":{"accessScope":{"name":"accessScope","type":"\u0007","is_mandatory":true,"title":"Access scope (PUBLIC, SNA)","provider":"go.mondoo.com/mql/providers/stackit"},"algorithm":{"name":"algorithm","type":"\u0007","is_mandatory":true,"title":"Algorithm (e.g., aes_256_gcm, rsa_4096_oaep_sha256, ecdsa_p256_sha256)","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"deletionDate":{"name":"deletionDate","type":"\t","is_mandatory":true,"title":"Scheduled deletion timestamp (nil unless the key is in PENDING_DELETION)","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Key UUID","provider":"go.mondoo.com/mql/providers/stackit"},"importOnly":{"name":"importOnly","type":"\u0004","is_mandatory":true,"title":"Whether the key material was imported (cannot be rotated server-side)","provider":"go.mondoo.com/mql/providers/stackit"},"keyRing":{"name":"keyRing","type":"\u001bstackit.kms.keyRing","title":"Key ring the key belongs to","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"keyRingId":{"name":"keyRingId","type":"\u0007","is_mandatory":true,"title":"Parent key ring UUID","provider":"go.mondoo.com/mql/providers/stackit"},"protection":{"name":"protection","type":"\u0007","is_mandatory":true,"title":"Protection level (software)","provider":"go.mondoo.com/mql/providers/stackit"},"purpose":{"name":"purpose","type":"\u0007","is_mandatory":true,"title":"Purpose (symmetric_encrypt_decrypt, asymmetric_encrypt_decrypt, message_authentication_code, asymmetric_sign_verify)","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (active, deleted, not_available, errors_exist, creating, no_version)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT KMS key","desc":"Cryptographic key managed by STACKIT KMS. Each key is keyed by its UUID `id` and is scoped to a `keyRingId`. The `purpose` describes what the key is allowed to do (SYMMETRIC_ENCRYPT_DECRYPT and siblings), `algorithm` is the underlying primitive, `protection` is the storage backend (SOFTWARE, HSM), and `state` is the lifecycle state. `deletionDate` is non-null only when the key has been scheduled for deletion.","private":true,"min_provider_version":"13.0.1","defaults":"id displayName state purpose","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.kms.keyRing":{"id":"stackit.kms.keyRing","name":"stackit.kms.keyRing","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description (free text)","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"User-supplied display name","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Key ring UUID","provider":"go.mondoo.com/mql/providers/stackit"},"keys":{"name":"keys","type":"\u0019\u001bstackit.kms.key","title":"Keys inside this key ring","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (creating, active, deleted)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT KMS key ring","desc":"Logical container that groups KMS keys for IAM and lifecycle purposes. Keyed by its UUID `id`, for example `stackit.kms.keyRing(id: \"...\")`.","private":true,"min_provider_version":"13.0.1","defaults":"id displayName state","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.loadBalancer":{"id":"stackit.loadBalancer","name":"stackit.loadBalancer","fields":{"errors":{"name":"errors","type":"\u0019\n","is_mandatory":true,"title":"Errors reported during creation/operation [{type, description}]","provider":"go.mondoo.com/mql/providers/stackit"},"exposure":{"name":"exposure","type":"\u001bstackit.network.exposure","title":"Internet-exposure breakdown (public address combined with the access-control allow-list)","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"externalAddress":{"name":"externalAddress","type":"\u0007","is_mandatory":true,"title":"External (public) IPv4/IPv6 address (empty if private only)","provider":"go.mondoo.com/mql/providers/stackit"},"listener":{"name":"listener","type":"\u001bstackit.loadBalancer.listener","title":"STACKIT load balancer listener","desc":"Frontend port and protocol binding that accepts client connections and forwards them into a single target pool. Each listener records the bound `port`, the wire `protocol`, and the SNI hostnames it matches for TLS, making it the place to audit which ports a load balancer exposes. Listeners are keyed by the parent load-balancer name together with the listener `name`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"listeners":{"name":"listeners","type":"\u0019\u001bstackit.loadBalancer.listener","title":"Listeners — frontend port/protocol bindings","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Load balancer name","provider":"go.mondoo.com/mql/providers/stackit"},"networks":{"name":"networks","type":"\u0019\n","is_mandatory":true,"title":"Networks attached to the load balancer [{networkId, role}]","provider":"go.mondoo.com/mql/providers/stackit"},"options":{"name":"options","type":"\n","is_mandatory":true,"title":"Load balancer options","desc":"Keys: `accessControl` ({allowedSourceRanges []string}, the CIDR allow-list for inbound traffic), `ephemeralAddress` (bool, whether a managed public IP is attached), `observability` ({logs, metrics}, each {credentialsRef, pushUrl} for external log and metric push), and `privateNetworkOnly` (bool, mirrored by the privateNetworkOnly field).","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan ID (sizing tier)","provider":"go.mondoo.com/mql/providers/stackit"},"privateNetworkOnly":{"name":"privateNetworkOnly","type":"\u0004","is_mandatory":true,"title":"Whether the load balancer is reachable *only* from inside the project's private network (no public IP)","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region (network and listeners live here)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (STATUS_READY, STATUS_PENDING, STATUS_ERROR, STATUS_TERMINATING, STATUS_UNSPECIFIED)","provider":"go.mondoo.com/mql/providers/stackit"},"targetPool":{"name":"targetPool","type":"\u001bstackit.loadBalancer.targetPool","title":"STACKIT load balancer target pool","desc":"Backend group that a listener forwards traffic to. Each target pool holds one or more targets (member IP addresses reachable on `targetPort`) plus the active health check and session-persistence policy used to distribute requests across them. Target pools are keyed by the parent load-balancer name together with the pool `name`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"targetPools":{"name":"targetPools","type":"\u0019\u001bstackit.loadBalancer.targetPool","title":"Target pools — backend groups with their health checks and members","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT load balancer","desc":"Layer 4 (TCP/UDP) load balancer that distributes traffic across a backend target pool. The balancer is keyed by its `name` (unique within the project and region), for example `stackit.loadBalancer(name: \"my-lb\")`. Query it to audit the public reachability of a service: the external address, the listener port and protocol bindings, the access-control allow-list carried in `options`, and whether the balancer is confined to the private network. The `exposure` field gives the combined public-address and allow-list verdict.","private":true,"min_provider_version":"13.0.0","defaults":"name status externalAddress","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.loadBalancer.listener":{"id":"stackit.loadBalancer.listener","name":"stackit.loadBalancer.listener","fields":{"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Listener display name (user-facing label)","provider":"go.mondoo.com/mql/providers/stackit"},"loadBalancerName":{"name":"loadBalancerName","type":"\u0007","is_mandatory":true,"title":"Parent load-balancer name","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Listener machine name (parent-unique key)","provider":"go.mondoo.com/mql/providers/stackit"},"port":{"name":"port","type":"\u0005","is_mandatory":true,"title":"Frontend port the listener binds","provider":"go.mondoo.com/mql/providers/stackit"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Wire protocol","desc":"One of PROTOCOL_TCP, PROTOCOL_UDP, PROTOCOL_TCP_PROXY, PROTOCOL_TLS_PASSTHROUGH, or PROTOCOL_UNSPECIFIED.","provider":"go.mondoo.com/mql/providers/stackit"},"serverNameIndicators":{"name":"serverNameIndicators","type":"\u0019\u0007","is_mandatory":true,"title":"SNI hostnames matched by this listener (TLS only)","provider":"go.mondoo.com/mql/providers/stackit"},"targetPool":{"name":"targetPool","type":"\u0007","is_mandatory":true,"title":"Name of the targetPool this listener forwards to","provider":"go.mondoo.com/mql/providers/stackit"},"tcp":{"name":"tcp","type":"\n","is_mandatory":true,"title":"TCP listener options","desc":"Single key `idleTimeout` (duration) after which an idle TCP connection is closed. Empty for non-TCP listeners.","provider":"go.mondoo.com/mql/providers/stackit"},"udp":{"name":"udp","type":"\n","is_mandatory":true,"title":"UDP listener options","desc":"Single key `idleTimeout` (duration) after which an idle UDP flow is dropped. Empty for non-UDP listeners.","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT load balancer listener","desc":"Frontend port and protocol binding that accepts client connections and forwards them into a single target pool. Each listener records the bound `port`, the wire `protocol`, and the SNI hostnames it matches for TLS, making it the place to audit which ports a load balancer exposes. Listeners are keyed by the parent load-balancer name together with the listener `name`.","private":true,"min_provider_version":"13.0.1","defaults":"name port protocol targetPool","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.loadBalancer.targetPool":{"id":"stackit.loadBalancer.targetPool","name":"stackit.loadBalancer.targetPool","fields":{"activeHealthCheck":{"name":"activeHealthCheck","type":"\n","is_mandatory":true,"title":"Active health check","desc":"Keys: `interval` and `intervalJitter` (probe timing), `timeout` (per-probe deadline), `healthyThreshold` and `unhealthyThreshold` (consecutive results before a target flips state), `altPort` (an alternate probe port), and `httpHealthChecks` (HTTP-level probe settings).","provider":"go.mondoo.com/mql/providers/stackit"},"loadBalancerName":{"name":"loadBalancerName","type":"\u0007","is_mandatory":true,"title":"Parent load-balancer name","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Target pool name (parent-unique key)","provider":"go.mondoo.com/mql/providers/stackit"},"sessionPersistence":{"name":"sessionPersistence","type":"\n","is_mandatory":true,"title":"Session persistence","desc":"Single key `useSourceIpAddress` (bool): when true, requests from the same client source IP are pinned to the same target.","provider":"go.mondoo.com/mql/providers/stackit"},"targetPort":{"name":"targetPort","type":"\u0005","is_mandatory":true,"title":"Backend port the pool forwards to","provider":"go.mondoo.com/mql/providers/stackit"},"targets":{"name":"targets","type":"\u0019\n","is_mandatory":true,"title":"Member backends","desc":"Each entry is {displayName, ip}: the backend's label and the IP address the pool forwards requests to.","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT load balancer target pool","desc":"Backend group that a listener forwards traffic to. Each target pool holds one or more targets (member IP addresses reachable on `targetPort`) plus the active health check and session-persistence policy used to distribute requests across them. Target pools are keyed by the parent load-balancer name together with the pool `name`.","private":true,"min_provider_version":"13.0.1","defaults":"name targetPort","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.logMe":{"id":"stackit.logMe","name":"stackit.logMe","fields":{"instance":{"name":"instance","type":"\u001bstackit.logMe.instance","title":"STACKIT LogMe managed instance","desc":"A single managed LogMe log-aggregation instance, keyed by its UUID `id` (for example `stackit.logMe.instance(id: \"...\")`). Reports the plan and service offering it runs on, the connection `parameters` the service returns, and `internetReachable` to flag instances open to the public internet.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.logMe.instance","title":"LogMe instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT LogMe namespace","desc":"Managed LogMe log-aggregation instances in the project. LogMe is a hosted OpenSearch-based logging service; the `instances` field lists every provisioned instance so you can audit their plans, connection parameters, and internet exposure.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.logMe.instance":{"id":"stackit.logMe.instance","name":"stackit.logMe.instance","fields":{"cfOrganizationGuid":{"name":"cfOrganizationGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style organization GUID","provider":"go.mondoo.com/mql/providers/stackit"},"cfSpaceGuid":{"name":"cfSpaceGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style space GUID","provider":"go.mondoo.com/mql/providers/stackit"},"dashboardUrl":{"name":"dashboardUrl","type":"\u0007","is_mandatory":true,"title":"Dashboard URL for the DBaaS UI (empty if not provisioned)","provider":"go.mondoo.com/mql/providers/stackit"},"fluentdTlsCiphers":{"name":"fluentdTlsCiphers","type":"\u0007","title":"Fluentd endpoint TLS cipher list","desc":"Cipher suites the Fluentd ingestion listener offers, from the `fluentd-tls-ciphers` parameter. Empty when the instance uses the service default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"fluentdTlsMaxVersion":{"name":"fluentdTlsMaxVersion","type":"\u0007","title":"Maximum TLS version for the Fluentd log-ingestion endpoint","desc":"Highest TLS protocol version accepted by the Fluentd ingestion listener, from the `fluentd-tls-max-version` parameter. Empty when the instance uses the service default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"fluentdTlsMinVersion":{"name":"fluentdTlsMinVersion","type":"\u0007","title":"Minimum TLS version for the Fluentd log-ingestion endpoint","desc":"Lowest TLS protocol version accepted by the Fluentd ingestion listener, from the `fluentd-tls-min-version` parameter (for example TLSv1.2). Empty when the instance uses the service default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"imageUrl":{"name":"imageUrl","type":"\u0007","is_mandatory":true,"title":"Image / engine version","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True when the instance's parameters enable public access and the source-IP allow-list (`sgw_acl`) is empty or admits any address (0.0.0.0/0 or ::/0), making the instance reachable from the internet.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"offeringName":{"name":"offeringName","type":"\u0007","is_mandatory":true,"title":"Service offering name","provider":"go.mondoo.com/mql/providers/stackit"},"opensearchTlsCiphers":{"name":"opensearchTlsCiphers","type":"\u0019\u0007","title":"OpenSearch endpoint TLS cipher list","desc":"Cipher suites the instance's OpenSearch API offers, from the `opensearch-tls-ciphers` parameter. Empty when the instance uses the service default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"opensearchTlsProtocols":{"name":"opensearchTlsProtocols","type":"\u0019\u0007","title":"Enabled TLS protocol versions for the embedded OpenSearch endpoint","desc":"TLS protocol versions accepted by the instance's OpenSearch API, from the `opensearch-tls-protocols` parameter (for example TLSv1.2 or TLSv1.3). Empty when the instance uses the service default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"parameters":{"name":"parameters","type":"\n","is_mandatory":true,"title":"Connection and networking parameters","desc":"Free-form settings the service reports for the instance. Keys include `enable_public_access` (bool) toggling a public endpoint and `sgw_acl` (list of CIDR strings) as the source-IP allow-list; both feed the `internetReachable` exposure check.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan UUID","provider":"go.mondoo.com/mql/providers/stackit"},"planName":{"name":"planName","type":"\u0007","is_mandatory":true,"title":"Plan name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (\"in progress\", \"succeeded\", \"failed\")","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT LogMe managed instance","desc":"A single managed LogMe log-aggregation instance, keyed by its UUID `id` (for example `stackit.logMe.instance(id: \"...\")`). Reports the plan and service offering it runs on, the connection `parameters` the service returns, and `internetReachable` to flag instances open to the public internet.","private":true,"min_provider_version":"13.0.1","defaults":"id name status planName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.mariaDb":{"id":"stackit.mariaDb","name":"stackit.mariaDb","fields":{"instance":{"name":"instance","type":"\u001bstackit.mariaDb.instance","title":"STACKIT MariaDB managed database instance","desc":"Single managed MariaDB instance, keyed by its UUID `id` (for example `stackit.mariaDb.instance(id: \"...\")`). Carries the plan and service offering that size the database, the connection `parameters` the API returns, and `internetReachable`, which reports whether the instance is reachable from the public internet.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.mariaDb.instance","title":"MariaDB instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT MariaDB namespace","desc":"Entry point for the managed MariaDB database service in the project. The `instances` field lists every MariaDB instance, each a managed database whose plan, service offering, connection parameters, and internet reachability you can audit.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.mariaDb.instance":{"id":"stackit.mariaDb.instance","name":"stackit.mariaDb.instance","fields":{"cfOrganizationGuid":{"name":"cfOrganizationGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style organization GUID","provider":"go.mondoo.com/mql/providers/stackit"},"cfSpaceGuid":{"name":"cfSpaceGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style space GUID","provider":"go.mondoo.com/mql/providers/stackit"},"dashboardUrl":{"name":"dashboardUrl","type":"\u0007","is_mandatory":true,"title":"Dashboard URL for the DBaaS UI (empty if not provisioned)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"imageUrl":{"name":"imageUrl","type":"\u0007","is_mandatory":true,"title":"Image / engine version","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True when the instance's parameters enable public access and the source-IP allow-list (`sgw_acl`) is empty or admits any address (0.0.0.0/0 or ::/0), making the instance reachable from the internet.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"offeringName":{"name":"offeringName","type":"\u0007","is_mandatory":true,"title":"Service offering name","provider":"go.mondoo.com/mql/providers/stackit"},"parameters":{"name":"parameters","type":"\n","is_mandatory":true,"title":"Connection and networking parameters returned by the API","desc":"Free-form map of instance settings. Security-relevant keys include `enable_public_access` (whether a public endpoint is exposed) and `sgw_acl` (the source-IP allow-list applied to that endpoint). The derived `internetReachable` field folds these into a single public-reachability verdict.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan UUID","provider":"go.mondoo.com/mql/providers/stackit"},"planName":{"name":"planName","type":"\u0007","is_mandatory":true,"title":"Plan name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (\"in progress\", \"succeeded\", \"failed\")","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT MariaDB managed database instance","desc":"Single managed MariaDB instance, keyed by its UUID `id` (for example `stackit.mariaDb.instance(id: \"...\")`). Carries the plan and service offering that size the database, the connection `parameters` the API returns, and `internetReachable`, which reports whether the instance is reachable from the public internet.","private":true,"min_provider_version":"13.0.0","defaults":"id name status planName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.modelServing":{"id":"stackit.modelServing","name":"stackit.modelServing","fields":{"model":{"name":"model","type":"\u001bstackit.modelServing.model","title":"STACKIT Model Serving model","desc":"Single model offered by the Model Serving catalog, keyed by its UUID `id`. The `type` field distinguishes chat, embedding, audio, and image models, `category` reflects the service tier, and `skus` carries the per-model pricing. Use it to inventory which models a project can invoke and at what cost.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"models":{"name":"models","type":"\u0019\u001bstackit.modelServing.model","title":"Models (chat and embedding) available in the region","provider":"go.mondoo.com/mql/providers/stackit"},"token":{"name":"token","type":"\u001bstackit.modelServing.token","title":"STACKIT Model Serving authentication token","desc":"Metadata of a single authentication token used to call the Model Serving inference API. The token is keyed by its UUID `id`, for example `stackit.modelServing.token(id: \"fa1d2...\")`, and lets audits check the lifecycle `state` and the `validUntil` expiry time. The secret token value is only returned once at creation and is not exposed here.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"tokens":{"name":"tokens","type":"\u0019\u001bstackit.modelServing.token","title":"Authentication tokens for the Model Serving API in the project","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Model Serving namespace","desc":"Entry point for STACKIT's managed AI inference API in a project. The `tokens` list enumerates the authentication tokens issued for calling the inference endpoints, and `models` lists the catalog of chat, embedding, audio, and image models available in the region together with their pricing.","min_provider_version":"13.0.4","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.modelServing.model":{"id":"stackit.modelServing.model","name":"stackit.modelServing.model","fields":{"category":{"name":"category","type":"\u0007","is_mandatory":true,"title":"Model category","desc":"Service tier of the model: one of standard, plus, or premium.","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"displayedName":{"name":"displayedName","type":"\u0007","is_mandatory":true,"title":"Human-readable display name","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Model UUID","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"API model name","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the model is served in","provider":"go.mondoo.com/mql/providers/stackit"},"skus":{"name":"skus","type":"\u0019\n","is_mandatory":true,"title":"Available pricing SKUs","desc":"Each entry is a dict with `id` (SKU UUID), `type` (the billing dimension), and `description`.","provider":"go.mondoo.com/mql/providers/stackit"},"tags":{"name":"tags","type":"\u0019\u0007","is_mandatory":true,"title":"Free-form tags attached to the model","provider":"go.mondoo.com/mql/providers/stackit"},"type":{"name":"type","type":"\u0007","is_mandatory":true,"title":"Model type","desc":"One of chat, embedding, audio, or image.","provider":"go.mondoo.com/mql/providers/stackit"},"url":{"name":"url","type":"\u0007","is_mandatory":true,"title":"Inference endpoint URL","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Model Serving model","desc":"Single model offered by the Model Serving catalog, keyed by its UUID `id`. The `type` field distinguishes chat, embedding, audio, and image models, `category` reflects the service tier, and `skus` carries the per-model pricing. Use it to inventory which models a project can invoke and at what cost.","private":true,"min_provider_version":"13.0.4","defaults":"name type category","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.modelServing.token":{"id":"stackit.modelServing.token","name":"stackit.modelServing.token","fields":{"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Token UUID","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Token name","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the token is valid in","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state","desc":"One of creating, active, deleting, or inactive.","provider":"go.mondoo.com/mql/providers/stackit"},"validUntil":{"name":"validUntil","type":"\t","is_mandatory":true,"title":"Expiry timestamp","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT Model Serving authentication token","desc":"Metadata of a single authentication token used to call the Model Serving inference API. The token is keyed by its UUID `id`, for example `stackit.modelServing.token(id: \"fa1d2...\")`, and lets audits check the lifecycle `state` and the `validUntil` expiry time. The secret token value is only returned once at creation and is not exposed here.","private":true,"min_provider_version":"13.0.4","defaults":"id name state validUntil","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.mongoDbFlex":{"id":"stackit.mongoDbFlex","name":"stackit.mongoDbFlex","fields":{"instance":{"name":"instance","type":"\u001bstackit.mongoDbFlex.instance","title":"STACKIT MongoDB Flex managed database instance","desc":"Managed MongoDB instance in a STACKIT project, selected by its UUID id. Covers the engine version, compute flavor, replica count, storage, backup schedule, region, and the connection ACL. The internetReachable predicate flags instances whose ACL admits a default route (0.0.0.0/0 or ::/0).","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.mongoDbFlex.instance","title":"MongoDB Flex instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT MongoDB Flex namespace","desc":"Entry point for the managed MongoDB Flex service in a STACKIT project. The instances field lists every managed MongoDB instance provisioned in the project.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.mongoDbFlex.instance":{"id":"stackit.mongoDbFlex.instance","name":"stackit.mongoDbFlex.instance","fields":{"acl":{"name":"acl","type":"\u0019\u0007","title":"CIDR blocks allowed to connect to the instance","provider":"go.mondoo.com/mql/providers/stackit"},"backupSchedule":{"name":"backupSchedule","type":"\u0007","title":"Backup schedule as a cron expression","provider":"go.mondoo.com/mql/providers/stackit"},"flavor":{"name":"flavor","type":"\n","title":"Compute flavor","desc":"Dict describing the compute flavor backing the instance, with keys id, cpu, memory, description, and categories.","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True only when the connection ACL explicitly admits a default route (0.0.0.0/0 or ::/0). An empty ACL is not flagged: the Flex API exposes no public-endpoint indicator, so an unpopulated ACL cannot be assumed to be internet-reachable.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"options":{"name":"options","type":"\u001a\u0007\u0007","title":"Free-form operator-tunable engine options keyed by option name","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the instance runs in","provider":"go.mondoo.com/mql/providers/stackit"},"replicas":{"name":"replicas","type":"\u0005","title":"Number of replicas backing the instance","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (READY, PENDING, PROCESSING, FAILED, UNKNOWN)","provider":"go.mondoo.com/mql/providers/stackit"},"storage":{"name":"storage","type":"\n","title":"Storage configuration","desc":"Dict describing the instance storage, with keys size and class.","provider":"go.mondoo.com/mql/providers/stackit"},"version":{"name":"version","type":"\u0007","title":"MongoDB major version","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT MongoDB Flex managed database instance","desc":"Managed MongoDB instance in a STACKIT project, selected by its UUID id. Covers the engine version, compute flavor, replica count, storage, backup schedule, region, and the connection ACL. The internetReachable predicate flags instances whose ACL admits a default route (0.0.0.0/0 or ::/0).","private":true,"min_provider_version":"13.0.0","defaults":"id name version status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.network":{"id":"stackit.network","name":"stackit.network","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","min_provider_version":"13.2.2","provider":"go.mondoo.com/mql/providers/stackit"},"exposure":{"name":"exposure","type":"\u001bstackit.network.exposure","title":"Server internet-exposure breakdown","desc":"Internet-reachability assessment for a server: whether one of its network interfaces carries a public IP and whether an attached security group admits inbound traffic from any address. A server counts as internet-reachable only when both hold, so this surfaces the servers most exposed to external attack.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Network UUID","provider":"go.mondoo.com/mql/providers/stackit"},"ipv4Gateway":{"name":"ipv4Gateway","type":"\u0007","is_mandatory":true,"title":"IPv4 gateway address (empty if no gateway)","provider":"go.mondoo.com/mql/providers/stackit"},"ipv4Nameservers":{"name":"ipv4Nameservers","type":"\u0019\u0007","is_mandatory":true,"title":"IPv4 name servers","provider":"go.mondoo.com/mql/providers/stackit"},"ipv4Prefix":{"name":"ipv4Prefix","type":"\u0007","is_mandatory":true,"title":"IPv4 prefix CIDR","provider":"go.mondoo.com/mql/providers/stackit"},"ipv4Prefixes":{"name":"ipv4Prefixes","type":"\u0019\u0007","is_mandatory":true,"title":"IPv4 prefix list","provider":"go.mondoo.com/mql/providers/stackit"},"ipv6Gateway":{"name":"ipv6Gateway","type":"\u0007","is_mandatory":true,"title":"IPv6 gateway address (empty if no gateway)","provider":"go.mondoo.com/mql/providers/stackit"},"ipv6Nameservers":{"name":"ipv6Nameservers","type":"\u0019\u0007","is_mandatory":true,"title":"IPv6 name servers","provider":"go.mondoo.com/mql/providers/stackit"},"ipv6Prefix":{"name":"ipv6Prefix","type":"\u0007","is_mandatory":true,"title":"IPv6 prefix CIDR","provider":"go.mondoo.com/mql/providers/stackit"},"ipv6Prefixes":{"name":"ipv6Prefixes","type":"\u0019\u0007","is_mandatory":true,"title":"IPv6 prefix list","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Network name","provider":"go.mondoo.com/mql/providers/stackit"},"nics":{"name":"nics","type":"\u0019\u001bstackit.nic","title":"Network interfaces attached to this network","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"routed":{"name":"routed","type":"\u0004","is_mandatory":true,"title":"Whether the network is routed (true) or isolated (false)","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Network state (CREATING, CREATED, UPDATING, DELETING, FAILED)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT project network","desc":"Network within a STACKIT project, keyed by its UUID `id`, for example `stackit.network(id: \"...\")`. The `routed` flag distinguishes a routed network reachable beyond the project from an isolated one, which is the first thing to check when reasoning about whether workloads on the network can be reached from outside the project. IPv4 and IPv6 prefixes, gateways, and name servers describe its addressing.","private":true,"min_provider_version":"13.0.0","defaults":"id name routed","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.network.exposure":{"id":"stackit.network.exposure","name":"stackit.network.exposure","fields":{"hasPublicIp":{"name":"hasPublicIp","type":"\u0004","is_mandatory":true,"title":"Whether any network interface has a public IP","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","is_mandatory":true,"title":"Whether the server is reachable from the internet (a public IP and a security group ingress rule that admits any address)","provider":"go.mondoo.com/mql/providers/stackit"},"openIngressRules":{"name":"openIngressRules","type":"\u0019\u001bstackit.securityGroup.rule","is_mandatory":true,"title":"Security group ingress rules that admit traffic from any address","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroupAllowsIngress":{"name":"securityGroupAllowsIngress","type":"\u0004","is_mandatory":true,"title":"Whether an attached security group permits inbound traffic from any address (0.0.0.0/0 or ::/0)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"Server internet-exposure breakdown","desc":"Internet-reachability assessment for a server: whether one of its network interfaces carries a public IP and whether an attached security group admits inbound traffic from any address. A server counts as internet-reachable only when both hold, so this surfaces the servers most exposed to external attack.","private":true,"min_provider_version":"13.0.6","defaults":"internetReachable hasPublicIp","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.nic":{"id":"stackit.nic","name":"stackit.nic","fields":{"allowedAddresses":{"name":"allowedAddresses","type":"\u0019\u0007","is_mandatory":true,"title":"Additional address pairs the interface may send from and receive on","provider":"go.mondoo.com/mql/providers/stackit"},"device":{"name":"device","type":"\u0007","is_mandatory":true,"title":"Device identifier presented to the guest operating system","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Network interface UUID","provider":"go.mondoo.com/mql/providers/stackit"},"ipv4":{"name":"ipv4","type":"\u0007","is_mandatory":true,"title":"Private IPv4 address","provider":"go.mondoo.com/mql/providers/stackit"},"ipv6":{"name":"ipv6","type":"\u0007","is_mandatory":true,"title":"Private IPv6 address","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"mac":{"name":"mac","type":"\u0007","is_mandatory":true,"title":"MAC address","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Interface name","provider":"go.mondoo.com/mql/providers/stackit"},"network":{"name":"network","type":"\u001bstackit.network","title":"Network the interface belongs to","provider":"go.mondoo.com/mql/providers/stackit"},"networkId":{"name":"networkId","type":"\u0007","is_mandatory":true,"title":"Network UUID the interface belongs to","provider":"go.mondoo.com/mql/providers/stackit"},"nicSecurity":{"name":"nicSecurity","type":"\u0004","is_mandatory":true,"title":"Whether NIC-level security filtering with security groups is active","provider":"go.mondoo.com/mql/providers/stackit"},"nicType":{"name":"nicType","type":"\u0007","is_mandatory":true,"title":"Interface type","desc":"One of `server`, `metadata`, `gateway`, or `none`.","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","is_mandatory":true,"title":"Security group UUIDs applied to the interface","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001bstackit.securityGroup","title":"Security groups applied to the interface","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Interface status","desc":"One of `ACTIVE` or `DOWN`.","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT network interface","desc":"Network interface belonging to a network and, when attached, to a server. The interface is keyed by its UUID id and exposes the private ipv4 and ipv6 addresses, MAC address, the network it lives in, the security groups filtering its traffic, allowed address pairs, and whether NIC-level security filtering is active.","private":true,"min_provider_version":"13.4.2","defaults":"id ipv4 mac status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.objectStorage":{"id":"stackit.objectStorage","name":"stackit.objectStorage","fields":{"accessKey":{"name":"accessKey","type":"\u001bstackit.objectStorage.accessKey","title":"STACKIT Object Storage access key","desc":"S3-compatible access key belonging to a credentials group. The key is keyed by its keyId and exposes the display name, the expiry timestamp (unset for keys that never expire), and the credentials group the key belongs to.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"bucket":{"name":"bucket","type":"\u001bstackit.objectStorage.bucket","title":"STACKIT Object Storage bucket","desc":"Single S3-compatible bucket in a STACKIT project. The bucket is keyed by its `name`, which is unique within the project and region (for example `stackit.objectStorage.bucket(name: \"my-bucket\")`), and exposes the S3 region, the virtual-hosted and path-style access URLs, and the Object Lock (WORM) retention settings that govern how long objects cannot be deleted or overwritten.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"buckets":{"name":"buckets","type":"\u0019\u001bstackit.objectStorage.bucket","title":"Object Storage buckets","provider":"go.mondoo.com/mql/providers/stackit"},"credentialsGroup":{"name":"credentialsGroup","type":"\u001bstackit.objectStorage.credentialsGroup","title":"STACKIT Object Storage credentials group","desc":"Group of S3-compatible access keys for a project's Object Storage. The group is keyed by its UUID id and exposes the display name, the URN that identifies the group, and the access keys it contains.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"credentialsGroups":{"name":"credentialsGroups","type":"\u0019\u001bstackit.objectStorage.credentialsGroup","title":"S3 credentials groups holding access keys","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Object Storage namespace","desc":"S3-compatible object storage in a STACKIT project. The namespace enumerates the project's buckets and the credentials groups that hold S3 access keys, so you can audit bucket exposure, retention settings, and which credentials can reach them. Individual buckets are exposed as stackit.objectStorage.bucket records.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.objectStorage.accessKey":{"id":"stackit.objectStorage.accessKey","name":"stackit.objectStorage.accessKey","fields":{"credentialsGroup":{"name":"credentialsGroup","type":"\u001bstackit.objectStorage.credentialsGroup","title":"Credentials group the key belongs to","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/stackit"},"expires":{"name":"expires","type":"\t","is_mandatory":true,"title":"Expiry timestamp (unset for keys that never expire)","provider":"go.mondoo.com/mql/providers/stackit"},"keyId":{"name":"keyId","type":"\u0007","is_mandatory":true,"title":"Access key ID","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Object Storage access key","desc":"S3-compatible access key belonging to a credentials group. The key is keyed by its keyId and exposes the display name, the expiry timestamp (unset for keys that never expire), and the credentials group the key belongs to.","private":true,"min_provider_version":"13.4.2","defaults":"keyId displayName expires","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.objectStorage.bucket":{"id":"stackit.objectStorage.bucket","name":"stackit.objectStorage.bucket","fields":{"defaultRetentionDays":{"name":"defaultRetentionDays","type":"\u0005","title":"Default-retention days; 0 when no default retention is configured","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"defaultRetentionMode":{"name":"defaultRetentionMode","type":"\u0007","title":"Default-retention mode; COMPLIANCE or GOVERNANCE, empty when unconfigured","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Bucket name (primary identifier)","provider":"go.mondoo.com/mql/providers/stackit"},"objectLockEnabled":{"name":"objectLockEnabled","type":"\u0004","is_mandatory":true,"title":"Whether S3 Object Lock is enabled (WORM retention)","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Bucket region","provider":"go.mondoo.com/mql/providers/stackit"},"urlPathStyle":{"name":"urlPathStyle","type":"\u0007","is_mandatory":true,"title":"S3-compatible URL in path style (https://\u003cendpoint\u003e/\u003cbucket\u003e)","provider":"go.mondoo.com/mql/providers/stackit"},"urlVirtualHostedStyle":{"name":"urlVirtualHostedStyle","type":"\u0007","is_mandatory":true,"title":"S3-compatible URL in virtual-hosted style (https://\u003cbucket\u003e.\u003cendpoint\u003e)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT Object Storage bucket","desc":"Single S3-compatible bucket in a STACKIT project. The bucket is keyed by its `name`, which is unique within the project and region (for example `stackit.objectStorage.bucket(name: \"my-bucket\")`), and exposes the S3 region, the virtual-hosted and path-style access URLs, and the Object Lock (WORM) retention settings that govern how long objects cannot be deleted or overwritten.","private":true,"min_provider_version":"13.0.0","defaults":"name region urlPathStyle","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.objectStorage.credentialsGroup":{"id":"stackit.objectStorage.credentialsGroup","name":"stackit.objectStorage.credentialsGroup","fields":{"accessKeys":{"name":"accessKeys","type":"\u0019\u001bstackit.objectStorage.accessKey","title":"Access keys belonging to the group","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Credentials group UUID","provider":"go.mondoo.com/mql/providers/stackit"},"urn":{"name":"urn","type":"\u0007","is_mandatory":true,"title":"URN identifying the credentials group","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT Object Storage credentials group","desc":"Group of S3-compatible access keys for a project's Object Storage. The group is keyed by its UUID id and exposes the display name, the URN that identifies the group, and the access keys it contains.","private":true,"min_provider_version":"13.4.2","defaults":"id displayName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.observability":{"id":"stackit.observability","name":"stackit.observability","fields":{"instance":{"name":"instance","type":"\u001bstackit.observability.instance","title":"STACKIT Observability managed instance","desc":"Single hosted Prometheus and Alertmanager instance, keyed by its UUID `id` (for example `stackit.observability.instance(id: \"fa1d2...\")`). Covers the instance name, lifecycle status, plan tier, dashboard URL, and the connection parameters clients use to push and query metrics and alerts.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.observability.instance","title":"Observability instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Observability namespace","desc":"Managed observability instances in the project, each a hosted Prometheus and Alertmanager stack. Query `instances` to enumerate them and audit their plan, lifecycle status, and connection endpoints.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.observability.instance":{"id":"stackit.observability.instance","name":"stackit.observability.instance","fields":{"dashboardUrl":{"name":"dashboardUrl","type":"\u0007","title":"Dashboard URL for the observability UI (empty if not provisioned)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"isUpdatable":{"name":"isUpdatable","type":"\u0004","title":"Whether the instance can be updated","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"offeringName":{"name":"offeringName","type":"\u0007","is_mandatory":true,"title":"Service offering name (e.g., \"observability\")","provider":"go.mondoo.com/mql/providers/stackit"},"parameters":{"name":"parameters","type":"\n","title":"Connection parameters","desc":"Map of parameter name to string value returned by the instance API, holding the endpoint URLs clients use to reach the instance (Alertmanager, Prometheus push and query, Grafana, and log or trace ingestion) along with credential hints. The available keys depend on the plan and provisioning state.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","title":"Plan UUID","provider":"go.mondoo.com/mql/providers/stackit"},"planName":{"name":"planName","type":"\u0007","is_mandatory":true,"title":"Plan name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (CREATING, CREATE_SUCCEEDED, CREATE_FAILED, DELETING, DELETE_SUCCEEDED, DELETE_FAILED, UPDATING, UPDATE_SUCCEEDED, UPDATE_FAILED)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT Observability managed instance","desc":"Single hosted Prometheus and Alertmanager instance, keyed by its UUID `id` (for example `stackit.observability.instance(id: \"fa1d2...\")`). Covers the instance name, lifecycle status, plan tier, dashboard URL, and the connection parameters clients use to push and query metrics and alerts.","private":true,"min_provider_version":"13.0.0","defaults":"id name status planName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.openSearch":{"id":"stackit.openSearch","name":"stackit.openSearch","fields":{"instance":{"name":"instance","type":"\u001bstackit.openSearch.instance","title":"STACKIT OpenSearch managed database instance","desc":"Single managed OpenSearch database provisioned through the STACKIT DBaaS platform. The instance is keyed by its UUID `id`, for example `stackit.openSearch.instance(id: \"...\")`. Query it to audit the service plan and offering, provisioning status, and network exposure: `parameters` carries the public-access flag and source-IP allow-list, and `internetReachable` reports whether the instance accepts connections from any address.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.openSearch.instance","title":"OpenSearch instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT OpenSearch namespace","desc":"Entry point for the managed OpenSearch service in a STACKIT project. The `instances` field lists every provisioned OpenSearch database instance, so you can audit their plans, provisioning status, and network exposure across the project.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.openSearch.instance":{"id":"stackit.openSearch.instance","name":"stackit.openSearch.instance","fields":{"cfOrganizationGuid":{"name":"cfOrganizationGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style organization GUID","provider":"go.mondoo.com/mql/providers/stackit"},"cfSpaceGuid":{"name":"cfSpaceGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style space GUID","provider":"go.mondoo.com/mql/providers/stackit"},"dashboardUrl":{"name":"dashboardUrl","type":"\u0007","is_mandatory":true,"title":"Dashboard URL for the DBaaS UI (empty if not provisioned)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"imageUrl":{"name":"imageUrl","type":"\u0007","is_mandatory":true,"title":"Image / engine version","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True when the instance's parameters enable public access and the source-IP allow-list (`sgw_acl`) is empty or admits any address (0.0.0.0/0 or ::/0), making the instance reachable from the internet.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"offeringName":{"name":"offeringName","type":"\u0007","is_mandatory":true,"title":"Service offering name (e.g., opensearch)","provider":"go.mondoo.com/mql/providers/stackit"},"parameters":{"name":"parameters","type":"\n","is_mandatory":true,"title":"Instance connection and networking parameters","desc":"Free-form map returned by the DBaaS API, holding the connection endpoint details along with the networking controls that drive `internetReachable`: `enable_public_access` (bool) toggles a public endpoint, and `sgw_acl` is the source-IP allow-list of CIDR ranges. The password is not included.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan UUID","provider":"go.mondoo.com/mql/providers/stackit"},"planName":{"name":"planName","type":"\u0007","is_mandatory":true,"title":"Plan name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (\"in progress\", \"succeeded\", \"failed\")","provider":"go.mondoo.com/mql/providers/stackit"},"tlsCiphers":{"name":"tlsCiphers","type":"\u0019\u0007","title":"Enabled TLS cipher list","desc":"Cipher suites the OpenSearch endpoint offers, from the `tls-ciphers` parameter. Empty when the instance uses the service default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"tlsProtocols":{"name":"tlsProtocols","type":"\u0019\u0007","title":"Enabled TLS protocol versions","desc":"TLS protocol versions the instance's OpenSearch endpoint accepts, from the `tls-protocols` parameter (for example TLSv1.2 or TLSv1.3). Empty when the instance uses the service default. Use it to audit instances still accepting legacy TLS versions.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT OpenSearch managed database instance","desc":"Single managed OpenSearch database provisioned through the STACKIT DBaaS platform. The instance is keyed by its UUID `id`, for example `stackit.openSearch.instance(id: \"...\")`. Query it to audit the service plan and offering, provisioning status, and network exposure: `parameters` carries the public-access flag and source-IP allow-list, and `internetReachable` reports whether the instance accepts connections from any address.","private":true,"min_provider_version":"13.0.0","defaults":"id name status planName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.postgresFlex":{"id":"stackit.postgresFlex","name":"stackit.postgresFlex","fields":{"instance":{"name":"instance","type":"\u001bstackit.postgresFlex.instance","title":"STACKIT Postgres Flex managed database instance","desc":"Single managed PostgreSQL instance, selected by its UUID `id` (for example `stackit.postgresFlex.instance(id: \"...\")`). Surfaces the engine version, connection ACL, backup schedule, storage sizing, replica count, and operator options, so audits can check whether a database is reachable from the internet, adequately backed up, or running a supported PostgreSQL release.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.postgresFlex.instance","title":"Postgres Flex instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Postgres Flex namespace","desc":"Managed PostgreSQL service for a STACKIT project. The `instances` field lists every Postgres Flex database provisioned in the project, each inspectable for engine version, connection ACL, backup schedule, storage sizing, and replica count.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.postgresFlex.instance":{"id":"stackit.postgresFlex.instance","name":"stackit.postgresFlex.instance","fields":{"acl":{"name":"acl","type":"\u0019\u0007","title":"CIDR ranges allowed to connect to the instance","provider":"go.mondoo.com/mql/providers/stackit"},"backupSchedule":{"name":"backupSchedule","type":"\u0007","title":"Backup schedule as a cron expression","provider":"go.mondoo.com/mql/providers/stackit"},"flavor":{"name":"flavor","type":"\n","title":"Compute flavor","desc":"Machine sizing for the instance. Keys: `id` (flavor identifier), `cpu` (vCPU count), `memory` (RAM in GB), and `description`.","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True only when the connection ACL explicitly admits a default route (0.0.0.0/0 or ::/0). An empty ACL is not flagged: the Flex API exposes no public-endpoint indicator, so an unpopulated ACL cannot be assumed to be internet-reachable.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"options":{"name":"options","type":"\u001a\u0007\u0007","title":"Operator-tunable engine options as name/value pairs","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the instance runs in","provider":"go.mondoo.com/mql/providers/stackit"},"replicas":{"name":"replicas","type":"\u0005","title":"Number of replicas","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (READY, CREATING, UPDATING, DELETING, FAILED, …)","provider":"go.mondoo.com/mql/providers/stackit"},"storage":{"name":"storage","type":"\n","title":"Storage configuration","desc":"Disk allocation for the instance. Keys: `size` (provisioned capacity in GB) and `class` (storage performance class).","provider":"go.mondoo.com/mql/providers/stackit"},"version":{"name":"version","type":"\u0007","title":"Postgres major version","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT Postgres Flex managed database instance","desc":"Single managed PostgreSQL instance, selected by its UUID `id` (for example `stackit.postgresFlex.instance(id: \"...\")`). Surfaces the engine version, connection ACL, backup schedule, storage sizing, replica count, and operator options, so audits can check whether a database is reachable from the internet, adequately backed up, or running a supported PostgreSQL release.","private":true,"min_provider_version":"13.0.0","defaults":"id name version status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.project":{"id":"stackit.project","name":"stackit.project","fields":{"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Project container ID (UUID)","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels attached to the project","provider":"go.mondoo.com/mql/providers/stackit"},"lifecycleState":{"name":"lifecycleState","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (CREATING, ACTIVE, DELETING, INACTIVE)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Project name","provider":"go.mondoo.com/mql/providers/stackit"},"parent":{"name":"parent","type":"\u0007","is_mandatory":true,"title":"Parent container ID (organization or folder)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT project metadata","desc":"Metadata for the project the connection is scoped to. Projects are the container that owns STACKIT resources, so this record identifies which project a scan ran against and its administrative state. The `id` is the project container ID, `parent` is the owning organization or folder container, and `lifecycleState` (one of CREATING, ACTIVE, DELETING, INACTIVE) tells you whether the project is usable or being torn down. The `labels` map holds user-defined key/value tags.","private":true,"min_provider_version":"13.0.0","defaults":"id name lifecycleState","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.publicIp":{"id":"stackit.publicIp","name":"stackit.publicIp","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Public IP UUID","provider":"go.mondoo.com/mql/providers/stackit"},"ip":{"name":"ip","type":"\u0007","is_mandatory":true,"title":"IP address","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"networkInterfaceId":{"name":"networkInterfaceId","type":"\u0007","is_mandatory":true,"title":"Network interface UUID the IP is bound to (empty if unassigned)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT public IP address","desc":"Floating public IP that can be attached to a network interface to expose a resource to the internet, useful for auditing which addresses are externally routable and whether they are currently bound to anything. The IP is keyed by its UUID, for example `stackit.publicIp(id: \"...\")`. The `networkInterfaceId` field is empty when the address is allocated but unassigned.","private":true,"min_provider_version":"13.0.0","defaults":"id ip","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.rabbitMq":{"id":"stackit.rabbitMq","name":"stackit.rabbitMq","fields":{"instance":{"name":"instance","type":"\u001bstackit.rabbitMq.instance","title":"STACKIT RabbitMQ managed instance","desc":"Single managed RabbitMQ message-broker instance, keyed by its UUID `id`, for example `stackit.rabbitMq.instance(id: \"...\")`. Carries the instance's plan, offering, and connection parameters, and an `internetReachable` predicate reporting whether the broker accepts connections from any address.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.rabbitMq.instance","title":"RabbitMQ instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT RabbitMQ namespace","desc":"Managed RabbitMQ message-broker instances in the project. The `instances` field enumerates every provisioned RabbitMQ instance, each carrying its plan, offering, connection parameters, and an internet-reachability assessment.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.rabbitMq.instance":{"id":"stackit.rabbitMq.instance","name":"stackit.rabbitMq.instance","fields":{"cfOrganizationGuid":{"name":"cfOrganizationGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style organization GUID","provider":"go.mondoo.com/mql/providers/stackit"},"cfSpaceGuid":{"name":"cfSpaceGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style space GUID","provider":"go.mondoo.com/mql/providers/stackit"},"dashboardUrl":{"name":"dashboardUrl","type":"\u0007","is_mandatory":true,"title":"Dashboard URL for the DBaaS UI (empty if not provisioned)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"imageUrl":{"name":"imageUrl","type":"\u0007","is_mandatory":true,"title":"Image / engine version","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True when the instance's parameters enable public access and the source-IP allow-list (`sgw_acl`) is empty or admits any address (0.0.0.0/0 or ::/0), making the instance reachable from the internet.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"offeringName":{"name":"offeringName","type":"\u0007","is_mandatory":true,"title":"Service offering name","provider":"go.mondoo.com/mql/providers/stackit"},"parameters":{"name":"parameters","type":"\n","is_mandatory":true,"title":"Connection and networking parameters returned by the API","desc":"Free-form key/value blob describing the instance's connection and networking settings. Security-relevant keys include `enable_public_access` (bool, whether a public endpoint is exposed) and `sgw_acl` (the source-IP allow-list of CIDR ranges permitted to connect). The `internetReachable` predicate is derived from these two keys.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan UUID","provider":"go.mondoo.com/mql/providers/stackit"},"planName":{"name":"planName","type":"\u0007","is_mandatory":true,"title":"Plan name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (\"in progress\", \"succeeded\", \"failed\")","provider":"go.mondoo.com/mql/providers/stackit"},"tlsCiphers":{"name":"tlsCiphers","type":"\u0019\u0007","title":"Enabled TLS cipher list","desc":"Cipher suites the broker offers, from the `tls-ciphers` parameter. Empty when the instance uses the broker default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"tlsProtocols":{"name":"tlsProtocols","type":"\u0019\u0007","title":"Enabled TLS protocol versions","desc":"TLS protocol versions the broker accepts, from the `tls-protocols` parameter (for example TLSv1.2 or TLSv1.3). Empty when the instance uses the broker default. Use it to audit brokers still accepting legacy TLS versions.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT RabbitMQ managed instance","desc":"Single managed RabbitMQ message-broker instance, keyed by its UUID `id`, for example `stackit.rabbitMq.instance(id: \"...\")`. Carries the instance's plan, offering, and connection parameters, and an `internetReachable` predicate reporting whether the broker accepts connections from any address.","private":true,"min_provider_version":"13.0.0","defaults":"id name status planName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.redis":{"id":"stackit.redis","name":"stackit.redis","fields":{"instance":{"name":"instance","type":"\u001bstackit.redis.instance","title":"STACKIT Redis managed instance","desc":"Single managed Redis instance in the project, keyed by its UUID `id` (for example `stackit.redis.instance(id: \"...\")`). Exposes the plan and service offering that determine sizing and quota, the Cloud Foundry organization and space it belongs to, the connection parameters, and whether the instance is reachable from the internet.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.redis.instance","title":"Redis instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Redis namespace","desc":"Managed Redis instances in the project. The `instances` field enumerates every provisioned Redis instance, each with its plan, service offering, connection parameters, and derived internet-reachability assessment.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.redis.instance":{"id":"stackit.redis.instance","name":"stackit.redis.instance","fields":{"cfOrganizationGuid":{"name":"cfOrganizationGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style organization GUID","provider":"go.mondoo.com/mql/providers/stackit"},"cfSpaceGuid":{"name":"cfSpaceGuid","type":"\u0007","is_mandatory":true,"title":"Cloud-Foundry-style space GUID","provider":"go.mondoo.com/mql/providers/stackit"},"dashboardUrl":{"name":"dashboardUrl","type":"\u0007","is_mandatory":true,"title":"Dashboard URL for the DBaaS UI (empty if not provisioned)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"imageUrl":{"name":"imageUrl","type":"\u0007","is_mandatory":true,"title":"Image / engine version","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True when the instance's parameters enable public access and the source-IP allow-list (`sgw_acl`) is empty or admits any address (0.0.0.0/0 or ::/0), making the instance reachable from the internet.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"offeringName":{"name":"offeringName","type":"\u0007","is_mandatory":true,"title":"Service offering name","provider":"go.mondoo.com/mql/providers/stackit"},"parameters":{"name":"parameters","type":"\n","is_mandatory":true,"title":"Connection and configuration parameters returned by the DBaaS API","desc":"Provider-specific settings for the instance. Includes `enable_public_access` (bool, whether the instance accepts public connections) and `sgw_acl` (list of CIDR strings allowed to reach the instance); the `internetReachable` field is derived from these two keys. Additional engine-specific keys may also be present.","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan UUID","provider":"go.mondoo.com/mql/providers/stackit"},"planName":{"name":"planName","type":"\u0007","is_mandatory":true,"title":"Plan name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (\"in progress\", \"succeeded\", \"failed\")","provider":"go.mondoo.com/mql/providers/stackit"},"tlsCiphers":{"name":"tlsCiphers","type":"\u0019\u0007","title":"Enabled TLS 1.2 cipher list","desc":"Cipher suites offered for TLS 1.2 connections, from the `tls-ciphers` parameter. Empty when the instance uses the engine default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"tlsCiphersuites":{"name":"tlsCiphersuites","type":"\u0007","title":"Enabled TLS 1.3 cipher suites","desc":"Colon-separated TLS 1.3 cipher suites the instance offers, from the `tls-ciphersuites` parameter. Empty when the instance uses the engine default.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"tlsProtocols":{"name":"tlsProtocols","type":"\u0019\u0007","title":"Enabled TLS protocol versions","desc":"TLS protocol versions the instance accepts, from the `tls-protocols` parameter (for example TLSv1.2 or TLSv1.3). Empty when the instance uses the engine default. Use it to audit instances still accepting legacy TLS versions.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT Redis managed instance","desc":"Single managed Redis instance in the project, keyed by its UUID `id` (for example `stackit.redis.instance(id: \"...\")`). Exposes the plan and service offering that determine sizing and quota, the Cloud Foundry organization and space it belongs to, the connection parameters, and whether the instance is reachable from the internet.","private":true,"min_provider_version":"13.0.0","defaults":"id name status planName","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.secretsManager":{"id":"stackit.secretsManager","name":"stackit.secretsManager","fields":{"instance":{"name":"instance","type":"\u001bstackit.secretsManager.instance","title":"STACKIT Secrets Manager instance","desc":"Single managed Secrets Manager instance, a vault that stores key/value secrets behind an access-controlled API. Keyed by its UUID `id`, for example `stackit.secretsManager.instance(id: \"...\")`. The `acls` field reports the CIDR ranges permitted to reach the vault, and `secretCount` tracks how many secrets it currently holds.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.secretsManager.instance","title":"Secrets Manager instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Secrets Manager namespace","desc":"Secrets Manager instances in the project, each a managed vault that stores key/value secrets behind an access-controlled API. Query `instances` to audit which vaults exist, their lifecycle state, the network ACLs that gate access, and how many secrets each one holds.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.secretsManager.instance":{"id":"stackit.secretsManager.instance","name":"stackit.secretsManager.instance","fields":{"acls":{"name":"acls","type":"\u0019\u0007","title":"ACL CIDRs allowed to connect","provider":"go.mondoo.com/mql/providers/stackit"},"apiUrl":{"name":"apiUrl","type":"\u0007","is_mandatory":true,"title":"API URL","provider":"go.mondoo.com/mql/providers/stackit"},"creationFinishedAt":{"name":"creationFinishedAt","type":"\t","is_mandatory":true,"title":"When instance creation finished","min_provider_version":"13.2.2","provider":"go.mondoo.com/mql/providers/stackit"},"creationStartedAt":{"name":"creationStartedAt","type":"\t","is_mandatory":true,"title":"When instance creation started","min_provider_version":"13.2.2","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"secretCount":{"name":"secretCount","type":"\u0005","is_mandatory":true,"title":"Number of secrets stored in the instance","provider":"go.mondoo.com/mql/providers/stackit"},"secretsEngine":{"name":"secretsEngine","type":"\u0007","is_mandatory":true,"title":"Engine type (e.g., kv)","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (CREATING, CREATED, UPDATING, FAILED, DELETING, …)","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT Secrets Manager instance","desc":"Single managed Secrets Manager instance, a vault that stores key/value secrets behind an access-controlled API. Keyed by its UUID `id`, for example `stackit.secretsManager.instance(id: \"...\")`. The `acls` field reports the CIDR ranges permitted to reach the vault, and `secretCount` tracks how many secrets it currently holds.","private":true,"min_provider_version":"13.0.0","defaults":"id name state","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.securityGroup":{"id":"stackit.securityGroup","name":"stackit.securityGroup","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Security group UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Security group name","provider":"go.mondoo.com/mql/providers/stackit"},"rule":{"name":"rule","type":"\u001bstackit.securityGroup.rule","title":"STACKIT security group rule","desc":"Single ingress or egress rule within a security group, defining which traffic the group permits. Auditing rules surfaces overly permissive access, for example an ingress rule whose `ipRange` is `0.0.0.0/0` or `::/0`. The remote endpoint is either an IP CIDR (`ipRange`) or another security group (`remoteSecurityGroupId`); one is set and the other empty. Keyed by its UUID `id`, unique within the owning security group.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"rules":{"name":"rules","type":"\u0019\u001bstackit.securityGroup.rule","title":"Security group rules","provider":"go.mondoo.com/mql/providers/stackit"},"stateful":{"name":"stateful","type":"\u0004","is_mandatory":true,"title":"Whether the security group is stateful","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT security group","desc":"Firewall rule set that governs which inbound and outbound traffic reaches the servers and network interfaces it is attached to. Auditing a security group reveals its exposure surface: overly permissive rules, whether it is stateful (return traffic for an allowed connection is admitted automatically), and its ingress and egress rules through `rules`. Selected by its UUID `id`, for example `stackit.securityGroup(id: \"9f8e7d6c-...\")`.","private":true,"min_provider_version":"13.0.0","defaults":"id name stateful","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.securityGroup.rule":{"id":"stackit.securityGroup.rule","name":"stackit.securityGroup.rule","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","min_provider_version":"13.2.2","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"direction":{"name":"direction","type":"\u0007","is_mandatory":true,"title":"Direction (ingress, egress)","provider":"go.mondoo.com/mql/providers/stackit"},"ethertype":{"name":"ethertype","type":"\u0007","is_mandatory":true,"title":"Ethertype (IPv4, IPv6)","provider":"go.mondoo.com/mql/providers/stackit"},"icmpCode":{"name":"icmpCode","type":"\u0005","is_mandatory":true,"title":"ICMP code (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"icmpType":{"name":"icmpType","type":"\u0005","is_mandatory":true,"title":"ICMP type (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Rule UUID","provider":"go.mondoo.com/mql/providers/stackit"},"ipRange":{"name":"ipRange","type":"\u0007","is_mandatory":true,"title":"Remote IP CIDR (empty if remote is a security group)","provider":"go.mondoo.com/mql/providers/stackit"},"portRangeMax":{"name":"portRangeMax","type":"\u0005","is_mandatory":true,"title":"Upper bound of the port range (0 if not applicable)","provider":"go.mondoo.com/mql/providers/stackit"},"portRangeMin":{"name":"portRangeMin","type":"\u0005","is_mandatory":true,"title":"Lower bound of the port range (0 if not applicable)","provider":"go.mondoo.com/mql/providers/stackit"},"protocol":{"name":"protocol","type":"\u0007","is_mandatory":true,"title":"Protocol name or number (tcp, udp, icmp, …)","provider":"go.mondoo.com/mql/providers/stackit"},"remoteSecurityGroupId":{"name":"remoteSecurityGroupId","type":"\u0007","is_mandatory":true,"title":"Remote security group UUID (empty if remote is a CIDR)","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroupId":{"name":"securityGroupId","type":"\u0007","is_mandatory":true,"title":"Owning security group UUID","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT security group rule","desc":"Single ingress or egress rule within a security group, defining which traffic the group permits. Auditing rules surfaces overly permissive access, for example an ingress rule whose `ipRange` is `0.0.0.0/0` or `::/0`. The remote endpoint is either an IP CIDR (`ipRange`) or another security group (`remoteSecurityGroupId`); one is set and the other empty. Keyed by its UUID `id`, unique within the owning security group.","private":true,"min_provider_version":"13.0.0","defaults":"id direction protocol","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.server":{"id":"stackit.server","name":"stackit.server","fields":{"availabilityZone":{"name":"availabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone","provider":"go.mondoo.com/mql/providers/stackit"},"backup":{"name":"backup","type":"\u001bstackit.server.backup","title":"STACKIT server backup","desc":"Point-in-time backup of a server's volumes taken by the Server Backup service. The backup is keyed by its UUID id and exposes the status and size, the per-volume backup entries, the volumes the backup protects, and the creation, expiry, and last-restore timestamps.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"backupSchedule":{"name":"backupSchedule","type":"\u001bstackit.server.backupSchedule","title":"STACKIT server backup schedule","desc":"Recurring backup schedule attached to a server by the Server Backup service. The schedule is keyed by its numeric id and exposes whether it is enabled, the iCalendar recurrence rule, the retention period, and the volumes it backs up.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"backupSchedules":{"name":"backupSchedules","type":"\u0019\u001bstackit.server.backupSchedule","title":"Recurring backup schedules attached to the server","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"backups":{"name":"backups","type":"\u0019\u001bstackit.server.backup","title":"Point-in-time backups taken from the server by the Server Backup service","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"configDrive":{"name":"configDrive","type":"\u0004","is_mandatory":true,"title":"Whether a config drive is attached","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"errorMessage":{"name":"errorMessage","type":"\u0007","is_mandatory":true,"title":"Last error message reported by the server (empty if none)","provider":"go.mondoo.com/mql/providers/stackit"},"exposure":{"name":"exposure","type":"\u001bstackit.network.exposure","title":"Internet-exposure breakdown (public IP combined with security group ingress)","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Server UUID","provider":"go.mondoo.com/mql/providers/stackit"},"image":{"name":"image","type":"\u001bstackit.image","title":"Image the server was created from (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"Image ID the server was created from (empty for boot-volume-only servers)","provider":"go.mondoo.com/mql/providers/stackit"},"keyPair":{"name":"keyPair","type":"\u001bstackit.keyPair","title":"SSH key pair used at boot (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"keypairName":{"name":"keypairName","type":"\u0007","is_mandatory":true,"title":"SSH key pair name used at boot (empty if none)","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"launchedAt":{"name":"launchedAt","type":"\t","is_mandatory":true,"title":"Launch timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"machineType":{"name":"machineType","type":"\u0007","is_mandatory":true,"title":"Machine type / flavor name","provider":"go.mondoo.com/mql/providers/stackit"},"metadata":{"name":"metadata","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Free-form metadata key/value pairs","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Server name","provider":"go.mondoo.com/mql/providers/stackit"},"networkInterfaces":{"name":"networkInterfaces","type":"\u0019\u001bstackit.nic","title":"Network interfaces attached to the server","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"nics":{"name":"nics","type":"\u0019\n","is_mandatory":true,"title":"Network interface summaries","desc":"Deprecated in favor of networkInterfaces, which exposes each interface as a resource with network and security-group references. Each entry has {nicId, networkId, networkName, ipv4, ipv6, mac, securityGroups, allowedAddresses, publicIp, nicSecurity}.","provider":"go.mondoo.com/mql/providers/stackit","maturity":"deprecated"},"powerStatus":{"name":"powerStatus","type":"\u0007","is_mandatory":true,"title":"Power status (RUNNING, STOPPED, CRASHED, ERROR)","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroupIds":{"name":"securityGroupIds","type":"\u0019\u0007","is_mandatory":true,"title":"Security group IDs attached to the server","provider":"go.mondoo.com/mql/providers/stackit"},"securityGroups":{"name":"securityGroups","type":"\u0019\u001bstackit.securityGroup","title":"Security groups attached to the server","provider":"go.mondoo.com/mql/providers/stackit"},"serviceAccountMails":{"name":"serviceAccountMails","type":"\u0019\u0007","is_mandatory":true,"title":"Service account mail addresses","desc":"Deprecated in favor of serviceAccounts, which resolves each mail to a resource exposing the service account's email and project.","provider":"go.mondoo.com/mql/providers/stackit","maturity":"deprecated"},"serviceAccounts":{"name":"serviceAccounts","type":"\u0019\u001bstackit.serviceAccount","title":"Service accounts attached to the server","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Server status (ACTIVE, CREATING, ERROR, …)","provider":"go.mondoo.com/mql/providers/stackit"},"update":{"name":"update","type":"\u001bstackit.server.update","title":"STACKIT server update run","desc":"Operating-system update run applied to a server by the Server Update service. The run is keyed by its numeric id and exposes the status, start and end timestamps, the counts of installed and failed updates, and the failure reason when the run did not succeed.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"updateSchedule":{"name":"updateSchedule","type":"\u001bstackit.server.updateSchedule","title":"STACKIT server update schedule","desc":"Recurring maintenance schedule attached to a server by the Server Update service. The schedule is keyed by its numeric id and exposes whether it is enabled, the iCalendar recurrence rule, and the maintenance window start hour.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"updateSchedules":{"name":"updateSchedules","type":"\u0019\u001bstackit.server.updateSchedule","title":"Recurring maintenance schedules attached to the server","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"updates":{"name":"updates","type":"\u0019\u001bstackit.server.update","title":"Operating-system update runs applied to the server by the Server Update service","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"userData":{"name":"userData","type":"\u0007","is_mandatory":true,"title":"User data (base64-encoded cloud-init)","provider":"go.mondoo.com/mql/providers/stackit"},"volumeIds":{"name":"volumeIds","type":"\u0019\u0007","is_mandatory":true,"title":"Volume UUIDs attached to the server","provider":"go.mondoo.com/mql/providers/stackit"},"volumes":{"name":"volumes","type":"\u0019\u001bstackit.volume","title":"Volumes attached to the server","provider":"go.mondoo.com/mql/providers/stackit"},"vtpmEnabled":{"name":"vtpmEnabled","type":"\u0004","is_mandatory":true,"title":"Whether a virtual TPM (vTPM) device is attached for measured boot","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT compute server","desc":"Single virtual machine in a STACKIT project, keyed by its UUID `id` (for example `stackit.server(id: \"fa1d2...\")`). Central to auditing a project's compute posture: the attached volumes and their encryption state, the security groups and network interfaces that govern who can reach the instance, whether a virtual TPM backs measured boot, the image and SSH key pair it booted from, and the service accounts, backups, and operating-system update runs bound to it. The exposure breakdown pairs a public IP with security group ingress to flag servers reachable from the internet.","private":true,"min_provider_version":"13.0.0","defaults":"id name status machineType","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.server.backup":{"id":"stackit.server.backup","name":"stackit.server.backup","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"expireAt":{"name":"expireAt","type":"\t","is_mandatory":true,"title":"Expiry timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Backup UUID","provider":"go.mondoo.com/mql/providers/stackit"},"lastRestoredAt":{"name":"lastRestoredAt","type":"\t","is_mandatory":true,"title":"Timestamp of the most recent restore from this backup (unset if never restored)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Backup name","provider":"go.mondoo.com/mql/providers/stackit"},"server":{"name":"server","type":"\u001bstackit.server","title":"Server the backup was taken from","provider":"go.mondoo.com/mql/providers/stackit"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"Owning server UUID","provider":"go.mondoo.com/mql/providers/stackit"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Total backup size in GiB","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Backup status","provider":"go.mondoo.com/mql/providers/stackit"},"volumeBackup":{"name":"volumeBackup","type":"\u001bstackit.server.backup.volumeBackup","title":"STACKIT server volume backup entry","desc":"Backup of a single volume that is part of a server backup, keyed by its UUID id. Exposes the size and status of the volume's backup, the volume it protects, and, once a restore has run, the timestamp and the volume the data was restored into.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"volumeBackups":{"name":"volumeBackups","type":"\u0019\u001bstackit.server.backup.volumeBackup","title":"Per-volume backup entries that make up the backup","provider":"go.mondoo.com/mql/providers/stackit"},"volumes":{"name":"volumes","type":"\u0019\u001bstackit.volume","title":"Volumes protected by this backup","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT server backup","desc":"Point-in-time backup of a server's volumes taken by the Server Backup service. The backup is keyed by its UUID id and exposes the status and size, the per-volume backup entries, the volumes the backup protects, and the creation, expiry, and last-restore timestamps.","private":true,"min_provider_version":"13.4.2","defaults":"id name status size","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.server.backup.volumeBackup":{"id":"stackit.server.backup.volumeBackup","name":"stackit.server.backup.volumeBackup","fields":{"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Volume backup UUID","provider":"go.mondoo.com/mql/providers/stackit"},"lastRestoredAt":{"name":"lastRestoredAt","type":"\t","is_mandatory":true,"title":"Timestamp of the most recent restore from this entry (unset if never restored)","provider":"go.mondoo.com/mql/providers/stackit"},"lastRestoredVolume":{"name":"lastRestoredVolume","type":"\u001bstackit.volume","title":"Volume the data was most recently restored into (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"lastRestoredVolumeId":{"name":"lastRestoredVolumeId","type":"\u0007","is_mandatory":true,"title":"UUID of the volume the data was most recently restored into (empty if never restored)","provider":"go.mondoo.com/mql/providers/stackit"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Size of the volume backup in GiB","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status of the volume backup","provider":"go.mondoo.com/mql/providers/stackit"},"volume":{"name":"volume","type":"\u001bstackit.volume","title":"Volume this entry backs up","provider":"go.mondoo.com/mql/providers/stackit"},"volumeId":{"name":"volumeId","type":"\u0007","is_mandatory":true,"title":"UUID of the volume this entry backs up","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT server volume backup entry","desc":"Backup of a single volume that is part of a server backup, keyed by its UUID id. Exposes the size and status of the volume's backup, the volume it protects, and, once a restore has run, the timestamp and the volume the data was restored into.","private":true,"min_provider_version":"13.4.2","defaults":"id status size","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.server.backupSchedule":{"id":"stackit.server.backupSchedule","name":"stackit.server.backupSchedule","fields":{"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the schedule is enabled","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Schedule ID","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Schedule name","provider":"go.mondoo.com/mql/providers/stackit"},"retentionPeriod":{"name":"retentionPeriod","type":"\u0005","is_mandatory":true,"title":"Number of days backups are retained","provider":"go.mondoo.com/mql/providers/stackit"},"rrule":{"name":"rrule","type":"\u0007","is_mandatory":true,"title":"iCalendar RRULE describing when backups run","provider":"go.mondoo.com/mql/providers/stackit"},"server":{"name":"server","type":"\u001bstackit.server","title":"Server the schedule is attached to","provider":"go.mondoo.com/mql/providers/stackit"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"Owning server UUID","provider":"go.mondoo.com/mql/providers/stackit"},"volumeIds":{"name":"volumeIds","type":"\u0019\u0007","is_mandatory":true,"title":"Volume UUIDs the schedule backs up","provider":"go.mondoo.com/mql/providers/stackit"},"volumes":{"name":"volumes","type":"\u0019\u001bstackit.volume","title":"Volumes the schedule backs up","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT server backup schedule","desc":"Recurring backup schedule attached to a server by the Server Backup service. The schedule is keyed by its numeric id and exposes whether it is enabled, the iCalendar recurrence rule, the retention period, and the volumes it backs up.","private":true,"min_provider_version":"13.4.2","defaults":"id name enabled","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.server.update":{"id":"stackit.server.update","name":"stackit.server.update","fields":{"endDate":{"name":"endDate","type":"\t","is_mandatory":true,"title":"End timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"failReason":{"name":"failReason","type":"\u0007","is_mandatory":true,"title":"Failure reason (empty when the run succeeded)","provider":"go.mondoo.com/mql/providers/stackit"},"failedUpdates":{"name":"failedUpdates","type":"\u0005","is_mandatory":true,"title":"Number of updates that failed during the run","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Update run ID","provider":"go.mondoo.com/mql/providers/stackit"},"installedUpdates":{"name":"installedUpdates","type":"\u0005","is_mandatory":true,"title":"Number of updates installed by the run","provider":"go.mondoo.com/mql/providers/stackit"},"server":{"name":"server","type":"\u001bstackit.server","title":"Server the update ran on","provider":"go.mondoo.com/mql/providers/stackit"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"Owning server UUID","provider":"go.mondoo.com/mql/providers/stackit"},"startDate":{"name":"startDate","type":"\t","is_mandatory":true,"title":"Start timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Update run status","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT server update run","desc":"Operating-system update run applied to a server by the Server Update service. The run is keyed by its numeric id and exposes the status, start and end timestamps, the counts of installed and failed updates, and the failure reason when the run did not succeed.","private":true,"min_provider_version":"13.4.2","defaults":"id status startDate","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.server.updateSchedule":{"id":"stackit.server.updateSchedule","name":"stackit.server.updateSchedule","fields":{"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the schedule is enabled","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0005","is_mandatory":true,"title":"Schedule ID","provider":"go.mondoo.com/mql/providers/stackit"},"maintenanceWindow":{"name":"maintenanceWindow","type":"\u0005","is_mandatory":true,"title":"Maintenance window start hour (0-23)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Schedule name","provider":"go.mondoo.com/mql/providers/stackit"},"rrule":{"name":"rrule","type":"\u0007","is_mandatory":true,"title":"iCalendar RRULE describing when maintenance runs","provider":"go.mondoo.com/mql/providers/stackit"},"server":{"name":"server","type":"\u001bstackit.server","title":"Server the schedule is attached to","provider":"go.mondoo.com/mql/providers/stackit"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"Owning server UUID","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT server update schedule","desc":"Recurring maintenance schedule attached to a server by the Server Update service. The schedule is keyed by its numeric id and exposes whether it is enabled, the iCalendar recurrence rule, and the maintenance window start hour.","private":true,"min_provider_version":"13.4.2","defaults":"id name enabled","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.serviceAccount":{"id":"stackit.serviceAccount","name":"stackit.serviceAccount","fields":{"accessTokens":{"name":"accessTokens","type":"\u0019\n","title":"Access tokens issued for this service account","desc":"Each entry has `id`, `active` (whether the token is currently valid), `createdAt`, and `validUntil`.","provider":"go.mondoo.com/mql/providers/stackit"},"email":{"name":"email","type":"\u0007","is_mandatory":true,"title":"Service account email (primary identifier)","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Internal service-account ID (UUID), if returned by the API","provider":"go.mondoo.com/mql/providers/stackit"},"keys":{"name":"keys","type":"\u0019\n","title":"Long-lived keys associated with this service account","desc":"Each entry has `id`, `keyType`, `keyAlgorithm`, `keyOrigin`, `active`, `createdAt`, and `validUntil`.","provider":"go.mondoo.com/mql/providers/stackit"},"projectId":{"name":"projectId","type":"\u0007","is_mandatory":true,"title":"Project ID the service account belongs to","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"email","type":"\u0007","optional":true}]},"title":"STACKIT project service account","desc":"Service account within a STACKIT project, the project-scoped principal used by automation and SDK callers to authenticate against STACKIT APIs. Service accounts are keyed by their email address, for example `stackit.serviceAccount(email: \"...\")`, and expose the project they belong to along with the access tokens and long-lived keys issued for authentication (useful for auditing credential age and active status).","private":true,"min_provider_version":"13.0.0","defaults":"email projectId","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sfs":{"id":"stackit.sfs","name":"stackit.sfs","fields":{"exportPolicies":{"name":"exportPolicies","type":"\u0019\u001bstackit.sfs.exportPolicy","title":"Share export policies (NFS export rule sets) defined in the project","provider":"go.mondoo.com/mql/providers/stackit"},"exportPolicy":{"name":"exportPolicy","type":"\u001bstackit.sfs.exportPolicy","title":"STACKIT File Storage share export policy","desc":"Single NFS export policy, the rule set that controls which clients may mount shares and with what access. The policy is keyed by its UUID `id`, for example `stackit.sfs.exportPolicy(id: \"fa1d2…\")`, and exposes the `name`, the count of shares referencing it (`sharesUsingExportPolicy`), labels, creation time, and the ordered list of `rules`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"lockId":{"name":"lockId","type":"\u0007","title":"SnapLock project lock ID; empty when the project is not locked","provider":"go.mondoo.com/mql/providers/stackit"},"resourcePool":{"name":"resourcePool","type":"\u001bstackit.sfs.resourcePool","title":"STACKIT File Storage resource pool","desc":"Single SFS capacity pool. The pool is keyed by its UUID `id`, for example `stackit.sfs.resourcePool(id: \"fa1d2…\")`, and exposes the `name`, lifecycle `state`, `performanceClass` (with peak IOPS and throughput), availability zone, NFS `mountPath`, the `ipAcl` of CIDRs allowed to mount, capacity accounting in gigabytes (`sizeGigabytes`, `usedGigabytes`, `availableGigabytes`, `usedBySnapshotsGigabytes`), the attached snapshot policy, labels, and creation time. The shares hosted in the pool are available through `shares` and point-in-time copies through `snapshots`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"resourcePools":{"name":"resourcePools","type":"\u0019\u001bstackit.sfs.resourcePool","title":"File-storage resource pools (capacity pools) in the project","provider":"go.mondoo.com/mql/providers/stackit"},"share":{"name":"share","type":"\u001bstackit.sfs.share","title":"STACKIT File Storage share","desc":"Single NFS file share within a resource pool. The share is keyed by its UUID `id` and exposes the `name`, lifecycle `state`, the NFS `mountPath` clients use, the per-share hard quota (`spaceHardLimitGigabytes`), labels, and creation time. The NFS export rules governing client access are available through the `exportPolicy` accessor.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"snapshot":{"name":"snapshot","type":"\u001bstackit.sfs.snapshot","title":"STACKIT File Storage resource pool snapshot","desc":"Point-in-time snapshot of a resource pool. The snapshot is selected by its `name` within the pool and exposes the logical and physical sizes in gigabytes (`logicalSizeGigabytes`, `sizeGigabytes`), an optional `comment`, the SnapLock expiry time (`snaplockExpiryTime`, when WORM-protected), and the creation time.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true}},"title":"STACKIT File Storage namespace","desc":"SFS (STACKIT File Storage) namespace for managed NFS storage in the project: the `resourcePools` that provide capacity, the `exportPolicies` that govern NFS client access, and the SnapLock project lock (`lockId`). Individual file shares and pool snapshots hang off each resource pool.","min_provider_version":"13.0.2","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sfs.exportPolicy":{"id":"stackit.sfs.exportPolicy","name":"stackit.sfs.exportPolicy","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Export policy UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels attached to the policy","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Export policy name","provider":"go.mondoo.com/mql/providers/stackit"},"rule":{"name":"rule","type":"\u001bstackit.sfs.exportPolicy.rule","title":"STACKIT File Storage export policy rule","desc":"Single NFS export rule within an export policy. Each rule grants the CIDRs in `ipAcl` access at the given evaluation `order`, keyed by its UUID `id`, with an optional `description` and creation time.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"rules":{"name":"rules","type":"\u0019\u001bstackit.sfs.exportPolicy.rule","title":"Ordered NFS export rules","provider":"go.mondoo.com/mql/providers/stackit"},"sharesUsingExportPolicy":{"name":"sharesUsingExportPolicy","type":"\u0005","is_mandatory":true,"title":"Number of shares currently referencing this policy","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT File Storage share export policy","desc":"Single NFS export policy, the rule set that controls which clients may mount shares and with what access. The policy is keyed by its UUID `id`, for example `stackit.sfs.exportPolicy(id: \"fa1d2…\")`, and exposes the `name`, the count of shares referencing it (`sharesUsingExportPolicy`), labels, creation time, and the ordered list of `rules`.","private":true,"min_provider_version":"13.0.2","defaults":"id name sharesUsingExportPolicy","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sfs.exportPolicy.rule":{"id":"stackit.sfs.exportPolicy.rule","name":"stackit.sfs.exportPolicy.rule","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Optional rule description","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Rule UUID","provider":"go.mondoo.com/mql/providers/stackit"},"ipAcl":{"name":"ipAcl","type":"\u0019\u0007","is_mandatory":true,"title":"CIDRs granted access by this rule","provider":"go.mondoo.com/mql/providers/stackit"},"order":{"name":"order","type":"\u0005","is_mandatory":true,"title":"Evaluation order (lower numbers are evaluated first)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT File Storage export policy rule","desc":"Single NFS export rule within an export policy. Each rule grants the CIDRs in `ipAcl` access at the given evaluation `order`, keyed by its UUID `id`, with an optional `description` and creation time.","private":true,"min_provider_version":"13.0.2","defaults":"order ipAcl","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sfs.resourcePool":{"id":"stackit.sfs.resourcePool","name":"stackit.sfs.resourcePool","fields":{"availabilityZone":{"name":"availabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone hosting the pool","provider":"go.mondoo.com/mql/providers/stackit"},"availableGigabytes":{"name":"availableGigabytes","type":"\u0006","is_mandatory":true,"title":"Available capacity in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"},"countShares":{"name":"countShares","type":"\u0005","is_mandatory":true,"title":"Number of shares hosted in the pool","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Resource pool UUID","provider":"go.mondoo.com/mql/providers/stackit"},"ipAcl":{"name":"ipAcl","type":"\u0019\u0007","is_mandatory":true,"title":"CIDRs allowed to mount shares in this pool","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels attached to the pool","provider":"go.mondoo.com/mql/providers/stackit"},"mountPath":{"name":"mountPath","type":"\u0007","is_mandatory":true,"title":"Base NFS mount path exported by the pool","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Resource pool name","provider":"go.mondoo.com/mql/providers/stackit"},"performanceClass":{"name":"performanceClass","type":"\u0007","is_mandatory":true,"title":"Performance class name (sizing/quota tier)","provider":"go.mondoo.com/mql/providers/stackit"},"performanceClassPeakIops":{"name":"performanceClassPeakIops","type":"\u0005","is_mandatory":true,"title":"Performance class peak IOPS","provider":"go.mondoo.com/mql/providers/stackit"},"performanceClassThroughput":{"name":"performanceClassThroughput","type":"\u0005","is_mandatory":true,"title":"Performance class throughput in MiB/s","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the pool runs in","provider":"go.mondoo.com/mql/providers/stackit"},"shares":{"name":"shares","type":"\u0019\u001bstackit.sfs.share","title":"File shares hosted in this pool","provider":"go.mondoo.com/mql/providers/stackit"},"sizeGigabytes":{"name":"sizeGigabytes","type":"\u0005","is_mandatory":true,"title":"Provisioned capacity in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"},"snapshotPolicyId":{"name":"snapshotPolicyId","type":"\u0007","is_mandatory":true,"title":"Attached snapshot policy UUID; empty when none is attached","provider":"go.mondoo.com/mql/providers/stackit"},"snapshotPolicyName":{"name":"snapshotPolicyName","type":"\u0007","is_mandatory":true,"title":"Attached snapshot policy name; empty when none is attached","provider":"go.mondoo.com/mql/providers/stackit"},"snapshots":{"name":"snapshots","type":"\u0019\u001bstackit.sfs.snapshot","title":"Point-in-time snapshots of this pool","provider":"go.mondoo.com/mql/providers/stackit"},"snapshotsAreVisible":{"name":"snapshotsAreVisible","type":"\u0004","is_mandatory":true,"title":"Whether snapshots are visible to clients under the share mount","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (CREATING, READY, UPDATING, DELETING, FAILED, …)","provider":"go.mondoo.com/mql/providers/stackit"},"usedBySnapshotsGigabytes":{"name":"usedBySnapshotsGigabytes","type":"\u0006","is_mandatory":true,"title":"Capacity consumed by snapshots in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"},"usedGigabytes":{"name":"usedGigabytes","type":"\u0006","is_mandatory":true,"title":"Used capacity in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT File Storage resource pool","desc":"Single SFS capacity pool. The pool is keyed by its UUID `id`, for example `stackit.sfs.resourcePool(id: \"fa1d2…\")`, and exposes the `name`, lifecycle `state`, `performanceClass` (with peak IOPS and throughput), availability zone, NFS `mountPath`, the `ipAcl` of CIDRs allowed to mount, capacity accounting in gigabytes (`sizeGigabytes`, `usedGigabytes`, `availableGigabytes`, `usedBySnapshotsGigabytes`), the attached snapshot policy, labels, and creation time. The shares hosted in the pool are available through `shares` and point-in-time copies through `snapshots`.","private":true,"min_provider_version":"13.0.2","defaults":"id name state performanceClass","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sfs.share":{"id":"stackit.sfs.share","name":"stackit.sfs.share","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"exportPolicy":{"name":"exportPolicy","type":"\u001bstackit.sfs.exportPolicy","title":"Export policy (NFS export rule set) applied to this share","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Share UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels attached to the share","provider":"go.mondoo.com/mql/providers/stackit"},"mountPath":{"name":"mountPath","type":"\u0007","is_mandatory":true,"title":"NFS mount path clients use to mount the share","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Share name","provider":"go.mondoo.com/mql/providers/stackit"},"spaceHardLimitGigabytes":{"name":"spaceHardLimitGigabytes","type":"\u0005","is_mandatory":true,"title":"Per-share hard quota in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"},"state":{"name":"state","type":"\u0007","is_mandatory":true,"title":"Lifecycle state (CREATING, READY, UPDATING, DELETING, FAILED, …)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT File Storage share","desc":"Single NFS file share within a resource pool. The share is keyed by its UUID `id` and exposes the `name`, lifecycle `state`, the NFS `mountPath` clients use, the per-share hard quota (`spaceHardLimitGigabytes`), labels, and creation time. The NFS export rules governing client access are available through the `exportPolicy` accessor.","private":true,"min_provider_version":"13.0.2","defaults":"id name state","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sfs.snapshot":{"id":"stackit.sfs.snapshot","name":"stackit.sfs.snapshot","fields":{"comment":{"name":"comment","type":"\u0007","is_mandatory":true,"title":"Optional snapshot comment","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"logicalSizeGigabytes":{"name":"logicalSizeGigabytes","type":"\u0005","is_mandatory":true,"title":"Logical size in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Snapshot name (unique within the pool)","provider":"go.mondoo.com/mql/providers/stackit"},"sizeGigabytes":{"name":"sizeGigabytes","type":"\u0005","is_mandatory":true,"title":"Physical size in gigabytes","provider":"go.mondoo.com/mql/providers/stackit"},"snaplockExpiryTime":{"name":"snaplockExpiryTime","type":"\t","is_mandatory":true,"title":"SnapLock expiry time; null when the snapshot is not WORM-protected","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT File Storage resource pool snapshot","desc":"Point-in-time snapshot of a resource pool. The snapshot is selected by its `name` within the pool and exposes the logical and physical sizes in gigabytes (`logicalSizeGigabytes`, `sizeGigabytes`), an optional `comment`, the SnapLock expiry time (`snaplockExpiryTime`, when WORM-protected), and the creation time.","private":true,"min_provider_version":"13.0.2","defaults":"name sizeGigabytes createdAt","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.ske":{"id":"stackit.ske","name":"stackit.ske","fields":{"cluster":{"name":"cluster","type":"\u001bstackit.ske.cluster","title":"STACKIT managed Kubernetes (SKE) cluster","desc":"Single managed Kubernetes cluster, keyed by its `name` (unique within the project and region). Exposes the `status` (aggregated lifecycle), the Kubernetes version, the node pools (with their flavor, OS, taints, autoscaling, labels), the hibernation and maintenance windows, network and DNS overrides, extensions (ACL, observability, application load balancer), whether API server audit logging is enabled, the cluster-level `labels`, and the creation and update timestamps.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"clusters":{"name":"clusters","type":"\u0019\u001bstackit.ske.cluster","title":"Managed Kubernetes clusters","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Kubernetes Engine namespace","desc":"Managed Kubernetes clusters running in the project. The `clusters` field enumerates every SKE cluster as a stackit.ske.cluster record, each carrying its Kubernetes version, node pools, network binding, and security configuration.","min_provider_version":"13.0.0","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.ske.cluster":{"id":"stackit.ske.cluster","name":"stackit.ske.cluster","fields":{"apiServerAclAllowedCidrs":{"name":"apiServerAclAllowedCidrs","type":"\u0019\u0007","is_mandatory":true,"title":"CIDR blocks permitted to reach the kube-apiserver when the access ACL is enforced","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"apiServerAclEnabled":{"name":"apiServerAclEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the kube-apiserver access ACL is enforced","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"applicationLoadBalancerEnabled":{"name":"applicationLoadBalancerEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the application load balancer extension is enabled","desc":"STACKIT gates this extension to accounts explicitly enabled for it and may still change its shape, so treat the field as provisional.","min_provider_version":"13.4.4","provider":"go.mondoo.com/mql/providers/stackit","maturity":"preview"},"auditEnabled":{"name":"auditEnabled","type":"\u0004","is_mandatory":true,"title":"Whether Kubernetes API server audit logging is enabled for the cluster","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"creationTime":{"name":"creationTime","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"credentialsRotationLastCompleted":{"name":"credentialsRotationLastCompleted","type":"\t","is_mandatory":true,"title":"Time the most recent credentials rotation completed","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"credentialsRotationLastInitiated":{"name":"credentialsRotationLastInitiated","type":"\t","is_mandatory":true,"title":"Time the most recent credentials rotation was initiated","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"credentialsRotationPhase":{"name":"credentialsRotationPhase","type":"\u0007","is_mandatory":true,"title":"Credentials-rotation phase","desc":"One of NEVER, PREPARING, PREPARED, COMPLETING, or COMPLETED.","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"dnsEnabled":{"name":"dnsEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the DNS extension is enabled","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"dnsGatewayApi":{"name":"dnsGatewayApi","type":"\u0004","is_mandatory":true,"title":"Whether the DNS extension exposes the Kubernetes Gateway API","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"dnsZones":{"name":"dnsZones","type":"\u0019\u0007","is_mandatory":true,"title":"DNS zones managed by the DNS extension","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"egressAddressRanges":{"name":"egressAddressRanges","type":"\u0019\u0007","is_mandatory":true,"title":"Egress IP ranges from which cluster traffic originates","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"extensions":{"name":"extensions","type":"\n","is_mandatory":true,"title":"Extension add-ons keyed by acl, observability, dns, and applicationLoadBalancer","desc":"Dict of the cluster's enabled add-ons. The `acl` key holds the kube-apiserver access ACL (enabled, allowedCidrs); `observability` holds the metrics and logs integration (enabled, instanceId); `dns` holds the managed-DNS extension (enabled, gatewayApi, zones); `applicationLoadBalancer` holds the application load balancer extension (enabled). See `apiServerAclEnabled`, `observabilityEnabled`, `dnsEnabled`, and `applicationLoadBalancerEnabled` for the hoisted flags.","provider":"go.mondoo.com/mql/providers/stackit"},"hibernations":{"name":"hibernations","type":"\u0019\n","is_mandatory":true,"title":"Hibernation schedules [{start, end, timezone}]","provider":"go.mondoo.com/mql/providers/stackit"},"idpEnabled":{"name":"idpEnabled","type":"\u0004","is_mandatory":true,"title":"Whether an identity provider is enabled for cluster access","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"idpType":{"name":"idpType","type":"\u0007","is_mandatory":true,"title":"Identity-provider type configured for cluster access","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"kubernetesVersion":{"name":"kubernetesVersion","type":"\u0007","is_mandatory":true,"title":"Kubernetes minor version (e.g., 1.30)","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Labels applied to the cluster","desc":"Key-value pairs set on the cluster itself, distinct from the labels on each node pool. Keys may carry a domain prefix separated by a slash and values may be empty.","min_provider_version":"13.4.4","provider":"go.mondoo.com/mql/providers/stackit"},"maintenance":{"name":"maintenance","type":"\n","is_mandatory":true,"title":"Maintenance window {timeWindow, autoUpdate: {kubernetesVersion, machineImageVersion}}","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Cluster name","provider":"go.mondoo.com/mql/providers/stackit"},"network":{"name":"network","type":"\n","is_mandatory":true,"title":"Network association: the STACKIT network id, control-plane access scope, and CNI configuration","desc":"Holds `id` (the STACKIT network the cluster is attached to, resolved by `networkRef`) and `cni`, the container network interface configuration. The `cni` object carries a `calico` key whose contents are the provider-defined Calico options and are not a fixed set.","provider":"go.mondoo.com/mql/providers/stackit"},"networkRef":{"name":"networkRef","type":"\u001bstackit.network","title":"STACKIT network the cluster is attached to","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"nodePool":{"name":"nodePool","type":"\u001bstackit.ske.cluster.nodePool","title":"SKE node pool","desc":"Single node pool within a managed-Kubernetes cluster, keyed by `clusterName/name`. Exposes the machine type and image, volume size and type, node-count bounds and rolling-update budget (maxSurge/maxUnavailable), the worker availability zones, container runtime, taints, labels, and whether the cluster's system components are allowed to schedule onto the pool.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"nodePools":{"name":"nodePools","type":"\u0019\u001bstackit.ske.cluster.nodePool","title":"Node pools, one stackit.ske.cluster.nodePool per pool","provider":"go.mondoo.com/mql/providers/stackit"},"observabilityEnabled":{"name":"observabilityEnabled","type":"\u0004","is_mandatory":true,"title":"Whether the observability (argus) extension is enabled","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"observabilityInstance":{"name":"observabilityInstance","type":"\u001bstackit.observability.instance","title":"Observability instance the cluster ships metrics and logs to","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"podAddressRanges":{"name":"podAddressRanges","type":"\u0019\u0007","is_mandatory":true,"title":"Pod IP ranges assigned to the cluster","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"serviceAccountIssuer":{"name":"serviceAccountIssuer","type":"\u0007","is_mandatory":true,"title":"OIDC service-account token issuer URL","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Aggregated status","desc":"One of STATE_HEALTHY, STATE_HIBERNATED, STATE_UNHEALTHY, STATE_RECONCILING, STATE_CREATING, STATE_DELETING, STATE_HIBERNATING, or STATE_WAKINGUP.","provider":"go.mondoo.com/mql/providers/stackit"},"statusDetails":{"name":"statusDetails","type":"\n","is_mandatory":true,"title":"Status object (raw): aggregated state, hibernated, errors, credentials rotation, …","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"name","type":"\u0007","optional":true}]},"title":"STACKIT managed Kubernetes (SKE) cluster","desc":"Single managed Kubernetes cluster, keyed by its `name` (unique within the project and region). Exposes the `status` (aggregated lifecycle), the Kubernetes version, the node pools (with their flavor, OS, taints, autoscaling, labels), the hibernation and maintenance windows, network and DNS overrides, extensions (ACL, observability, application load balancer), whether API server audit logging is enabled, the cluster-level `labels`, and the creation and update timestamps.","private":true,"min_provider_version":"13.0.0","defaults":"name kubernetesVersion status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.ske.cluster.nodePool":{"id":"stackit.ske.cluster.nodePool","name":"stackit.ske.cluster.nodePool","fields":{"allowSystemComponents":{"name":"allowSystemComponents","type":"\u0004","is_mandatory":true,"title":"Whether DaemonSets/system components may schedule on this pool","provider":"go.mondoo.com/mql/providers/stackit"},"availabilityZones":{"name":"availabilityZones","type":"\u0019\u0007","is_mandatory":true,"title":"Worker availability zones","provider":"go.mondoo.com/mql/providers/stackit"},"clusterName":{"name":"clusterName","type":"\u0007","is_mandatory":true,"title":"Parent cluster name","provider":"go.mondoo.com/mql/providers/stackit"},"cri":{"name":"cri","type":"\u0007","is_mandatory":true,"title":"Container runtime name (containerd, …)","provider":"go.mondoo.com/mql/providers/stackit"},"kubernetesVersion":{"name":"kubernetesVersion","type":"\u0007","is_mandatory":true,"title":"Kubernetes version running on this node pool, when it differs from the control plane","min_provider_version":"13.1.1","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"Kubelet/Node labels","provider":"go.mondoo.com/mql/providers/stackit"},"machineImage":{"name":"machineImage","type":"\u0007","is_mandatory":true,"title":"OS image name (e.g., flatcar)","provider":"go.mondoo.com/mql/providers/stackit"},"machineImageVersion":{"name":"machineImageVersion","type":"\u0007","is_mandatory":true,"title":"OS image version","provider":"go.mondoo.com/mql/providers/stackit"},"machineType":{"name":"machineType","type":"\u0007","is_mandatory":true,"title":"Machine flavor (e.g., g1.2)","provider":"go.mondoo.com/mql/providers/stackit"},"maxSurge":{"name":"maxSurge","type":"\u0005","is_mandatory":true,"title":"MaxSurge for rolling updates (extra nodes allowed beyond `maximum`)","provider":"go.mondoo.com/mql/providers/stackit"},"maxUnavailable":{"name":"maxUnavailable","type":"\u0005","is_mandatory":true,"title":"MaxUnavailable nodes during rolling updates","provider":"go.mondoo.com/mql/providers/stackit"},"maximum":{"name":"maximum","type":"\u0005","is_mandatory":true,"title":"Maximum node count (cluster-autoscaler upper bound)","provider":"go.mondoo.com/mql/providers/stackit"},"minimum":{"name":"minimum","type":"\u0005","is_mandatory":true,"title":"Minimum node count (cluster-autoscaler lower bound)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Node pool name (unique within the cluster)","provider":"go.mondoo.com/mql/providers/stackit"},"taints":{"name":"taints","type":"\u0019\n","is_mandatory":true,"title":"Taints [{key, value, effect}]","provider":"go.mondoo.com/mql/providers/stackit"},"volumeSize":{"name":"volumeSize","type":"\u0005","is_mandatory":true,"title":"Boot volume size in GiB","provider":"go.mondoo.com/mql/providers/stackit"},"volumeType":{"name":"volumeType","type":"\u0007","is_mandatory":true,"title":"Boot volume type (e.g., storage_premium)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"SKE node pool","desc":"Single node pool within a managed-Kubernetes cluster, keyed by `clusterName/name`. Exposes the machine type and image, volume size and type, node-count bounds and rolling-update budget (maxSurge/maxUnavailable), the worker availability zones, container runtime, taints, labels, and whether the cluster's system components are allowed to schedule onto the pool.","private":true,"min_provider_version":"13.0.1","defaults":"name machineType minimum maximum","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.snapshot":{"id":"stackit.snapshot","name":"stackit.snapshot","fields":{"availabilityZone":{"name":"availabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Snapshot UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Snapshot name","provider":"go.mondoo.com/mql/providers/stackit"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Size in GiB","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (CREATING, AVAILABLE, DELETING, ERROR)","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"volume":{"name":"volume","type":"\u001bstackit.volume","title":"Source volume (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"volumeId":{"name":"volumeId","type":"\u0007","is_mandatory":true,"title":"Source volume UUID","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT volume snapshot","desc":"Point-in-time copy of a block-storage volume in the project, keyed by its UUID `id` (for example `stackit.snapshot(id: \"...\")`). Snapshots capture volume contents for backup, restore, and cloning, so the `status` and the source `volume` are the fields to check when auditing data-protection coverage.","private":true,"min_provider_version":"13.0.0","defaults":"id name status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sqlServerFlex":{"id":"stackit.sqlServerFlex","name":"stackit.sqlServerFlex","fields":{"instance":{"name":"instance","type":"\u001bstackit.sqlServerFlex.instance","title":"STACKIT SQLServer Flex managed database instance","desc":"Single managed Microsoft SQL Server instance provisioned through SQLServer Flex, selected by its UUID `id` (for example `stackit.sqlServerFlex.instance(id: \"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\")`). Covers the deployment shape (flavor, replicas, storage, version), operational status, backup schedule, and the connection ACL that governs which networks may reach the database. The `internetReachable` predicate reports whether that ACL leaves the instance open to the public internet.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"instances":{"name":"instances","type":"\u0019\u001bstackit.sqlServerFlex.instance","title":"SQLServer Flex instances","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT SQLServer Flex namespace","desc":"Managed Microsoft SQL Server instances running on STACKIT's SQLServer Flex service. The `instances` field lists every SQL Server Flex instance provisioned in the project, the entry point for auditing their sizing, backup schedule, and network exposure.","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.sqlServerFlex.instance":{"id":"stackit.sqlServerFlex.instance","name":"stackit.sqlServerFlex.instance","fields":{"acl":{"name":"acl","type":"\u0019\u0007","title":"CIDR blocks allowed to connect to the instance","provider":"go.mondoo.com/mql/providers/stackit"},"backupSchedule":{"name":"backupSchedule","type":"\u0007","title":"Backup schedule as a cron expression","provider":"go.mondoo.com/mql/providers/stackit"},"flavor":{"name":"flavor","type":"\n","title":"Machine flavor","desc":"Compute shape of the instance, with keys `id`, `cpu` (vCPU count), `memory` (RAM), and `description`.","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Instance UUID","provider":"go.mondoo.com/mql/providers/stackit"},"internetReachable":{"name":"internetReachable","type":"\u0004","title":"Whether the instance accepts connections from any address","desc":"True only when the connection ACL explicitly admits a default route (0.0.0.0/0 or ::/0). An empty ACL is not flagged: the Flex API exposes no public-endpoint indicator, so an unpopulated ACL cannot be assumed to be internet-reachable.","min_provider_version":"13.0.6","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Instance name","provider":"go.mondoo.com/mql/providers/stackit"},"options":{"name":"options","type":"\u001a\u0007\u0007","title":"Operator-tunable engine options as key/value pairs","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the instance runs in","provider":"go.mondoo.com/mql/providers/stackit"},"replicas":{"name":"replicas","type":"\u0005","title":"Number of replicas","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (READY, CREATING, UPDATING, DELETING, FAILED, …)","provider":"go.mondoo.com/mql/providers/stackit"},"storage":{"name":"storage","type":"\n","title":"Storage configuration","desc":"Disk allocation of the instance, with keys `size` (in GB) and `class` (storage class).","provider":"go.mondoo.com/mql/providers/stackit"},"version":{"name":"version","type":"\u0007","title":"SQLServer version","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT SQLServer Flex managed database instance","desc":"Single managed Microsoft SQL Server instance provisioned through SQLServer Flex, selected by its UUID `id` (for example `stackit.sqlServerFlex.instance(id: \"xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx\")`). Covers the deployment shape (flavor, replicas, storage, version), operational status, backup schedule, and the connection ACL that governs which networks may reach the database. The `internetReachable` predicate reports whether that ACL leaves the instance open to the public internet.","private":true,"min_provider_version":"13.0.1","defaults":"id name version status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.telemetry":{"id":"stackit.telemetry","name":"stackit.telemetry","fields":{"link":{"name":"link","type":"\u001bstackit.telemetry.link","title":"Project telemetry link (federation to a telemetry router)","provider":"go.mondoo.com/mql/providers/stackit"},"router":{"name":"router","type":"\u001bstackit.telemetry.router","title":"STACKIT telemetry router","desc":"Single telemetry router, the pipeline that ingests observability data, applies a routing `filter`, and forwards it to configured destinations. The router is keyed by its UUID `id`, for example `stackit.telemetry.router(id: \"fa1d2…\")`. Audit where telemetry leaves the project by reviewing the forwarding targets under `destinations` and the ingest credentials issued under `accessTokens`.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"routers":{"name":"routers","type":"\u0019\u001bstackit.telemetry.router","title":"Telemetry routers defined in the project","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT Telemetry namespace","desc":"Entry point for the project's telemetry pipeline. Telemetry `routers` receive, filter, and forward observability data (logs, metrics, traces) to external destinations, and the project telemetry `link` federates the project's own data to one of those routers. Audit this namespace to see where a project's telemetry can flow and which external systems receive it.","min_provider_version":"13.0.3","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.telemetry.link":{"id":"stackit.telemetry.link","name":"stackit.telemetry.link","fields":{"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Human-readable display name","provider":"go.mondoo.com/mql/providers/stackit"},"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the telemetry link is enabled","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Link UUID","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the link applies to","provider":"go.mondoo.com/mql/providers/stackit"},"router":{"name":"router","type":"\u001bstackit.telemetry.router","title":"Telemetry router this link forwards data to","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of active, inactive, failed, reconciling, or deleting.","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT project telemetry link","desc":"Project's telemetry link, the federation binding that forwards the project's own observability data to a telemetry router. Check `enabled` and `status` to confirm whether the project is actively shipping telemetry, and follow `router` to the destination pipeline that receives it. The link's access token is a secret and is not exposed.","private":true,"min_provider_version":"13.0.3","defaults":"id displayName enabled status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.telemetry.router":{"id":"stackit.telemetry.router","name":"stackit.telemetry.router","fields":{"accessToken":{"name":"accessToken","type":"\u001bstackit.telemetry.router.accessToken","title":"STACKIT telemetry router access token","desc":"Metadata for a single access token issued for a telemetry router. These tokens authorize clients to push telemetry into the router's ingest endpoint, so `status` and `expiresAt` reveal which ingest credentials are still live. The token is keyed by its UUID `id`. The secret token value is returned only once at creation and is never exposed here.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"accessTokens":{"name":"accessTokens","type":"\u0019\u001bstackit.telemetry.router.accessToken","title":"Access tokens issued for the router (metadata only; secrets are not exposed)","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"destination":{"name":"destination","type":"\u001bstackit.telemetry.router.destination","title":"STACKIT telemetry router destination","desc":"Single forwarding target on a telemetry router, the external system a router ships observability data to. The destination is keyed by its UUID `id`. Audit `credentialType` and `config` to see which external endpoint (an OpenTelemetry collector or an S3 bucket) receives the project's telemetry and how the router authenticates to it.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"destinations":{"name":"destinations","type":"\u0019\u001bstackit.telemetry.router.destination","title":"Forwarding destinations configured on the router","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Human-readable display name","provider":"go.mondoo.com/mql/providers/stackit"},"filter":{"name":"filter","type":"\n","is_mandatory":true,"title":"Routing filter applied to ingested telemetry","desc":"Holds an `attributes` list, where each entry has `key` (the attribute name to match), `level` (one of resource, scope, or logRecord), `matcher` (`=` or `!=`), and `values` (the strings compared against). Telemetry is forwarded only when it matches these attribute conditions.","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Router UUID","provider":"go.mondoo.com/mql/providers/stackit"},"region":{"name":"region","type":"\u0007","is_mandatory":true,"title":"Region the router runs in","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status (reconciling, active, deleting, …)","provider":"go.mondoo.com/mql/providers/stackit"},"uri":{"name":"uri","type":"\u0007","is_mandatory":true,"title":"Ingest URI clients send telemetry to","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT telemetry router","desc":"Single telemetry router, the pipeline that ingests observability data, applies a routing `filter`, and forwards it to configured destinations. The router is keyed by its UUID `id`, for example `stackit.telemetry.router(id: \"fa1d2…\")`. Audit where telemetry leaves the project by reviewing the forwarding targets under `destinations` and the ingest credentials issued under `accessTokens`.","private":true,"min_provider_version":"13.0.3","defaults":"id displayName status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.telemetry.router.accessToken":{"id":"stackit.telemetry.router.accessToken","name":"stackit.telemetry.router.accessToken","fields":{"creatorId":{"name":"creatorId","type":"\u0007","is_mandatory":true,"title":"ID of the principal that created the token","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Human-readable display name","provider":"go.mondoo.com/mql/providers/stackit"},"expiresAt":{"name":"expiresAt","type":"\t","is_mandatory":true,"title":"Expiry timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Access token UUID","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of active, expired, or deleting.","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT telemetry router access token","desc":"Metadata for a single access token issued for a telemetry router. These tokens authorize clients to push telemetry into the router's ingest endpoint, so `status` and `expiresAt` reveal which ingest credentials are still live. The token is keyed by its UUID `id`. The secret token value is returned only once at creation and is never exposed here.","private":true,"min_provider_version":"13.0.3","defaults":"id displayName status expiresAt","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.telemetry.router.destination":{"id":"stackit.telemetry.router.destination","name":"stackit.telemetry.router.destination","fields":{"config":{"name":"config","type":"\n","is_mandatory":true,"title":"Destination configuration","desc":"Shape depends on `configType`: `OpenTelemetry` populates an `openTelemetry` object with `uri` and an optional `basicAuth` (`username`, `password`) or `bearerToken`; `S3` populates an `s3` object with `bucket`, `endpoint`, and an optional `accessKey` (`id`, `secret`). An optional `filter` (same `attributes` shape as the router filter) narrows what this destination forwards.","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"credentialType":{"name":"credentialType","type":"\u0007","is_mandatory":true,"title":"Credential type used to authenticate to the destination","desc":"One of bearerToken, basicAuth, or accessKey.","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"displayName":{"name":"displayName","type":"\u0007","is_mandatory":true,"title":"Human-readable display name","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Destination UUID","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Lifecycle status","desc":"One of reconciling, active, or deleting.","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT telemetry router destination","desc":"Single forwarding target on a telemetry router, the external system a router ships observability data to. The destination is keyed by its UUID `id`. Audit `credentialType` and `config` to see which external endpoint (an OpenTelemetry collector or an S3 bucket) receives the project's telemetry and how the router authenticates to it.","private":true,"min_provider_version":"13.0.3","defaults":"id displayName status credentialType","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.volume":{"id":"stackit.volume","name":"stackit.volume","fields":{"availabilityZone":{"name":"availabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone","provider":"go.mondoo.com/mql/providers/stackit"},"bootable":{"name":"bootable","type":"\u0004","is_mandatory":true,"title":"Whether the volume is bootable","provider":"go.mondoo.com/mql/providers/stackit"},"createdAt":{"name":"createdAt","type":"\t","is_mandatory":true,"title":"Creation timestamp","provider":"go.mondoo.com/mql/providers/stackit"},"description":{"name":"description","type":"\u0007","is_mandatory":true,"title":"Description","provider":"go.mondoo.com/mql/providers/stackit"},"encrypted":{"name":"encrypted","type":"\u0004","is_mandatory":true,"title":"Whether the volume is encrypted at rest","provider":"go.mondoo.com/mql/providers/stackit"},"encryptionKeyId":{"name":"encryptionKeyId","type":"\u0007","is_mandatory":true,"title":"KEK UUID used to wrap the volume data-encryption key; empty when using platform-managed encryption","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"encryptionKeyVersion":{"name":"encryptionKeyVersion","type":"\u0005","is_mandatory":true,"title":"KEK version number; 0 when unset","min_provider_version":"13.0.1","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Volume UUID","provider":"go.mondoo.com/mql/providers/stackit"},"image":{"name":"image","type":"\u001bstackit.image","title":"Image the volume was created from (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"imageId":{"name":"imageId","type":"\u0007","is_mandatory":true,"title":"Source image UUID (empty if not image-based)","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Volume name","provider":"go.mondoo.com/mql/providers/stackit"},"performanceClass":{"name":"performanceClass","type":"\u0007","is_mandatory":true,"title":"Performance class (storage_premium, storage_standard, …)","provider":"go.mondoo.com/mql/providers/stackit"},"server":{"name":"server","type":"\u001bstackit.server","title":"Server the volume is attached to (nullable)","provider":"go.mondoo.com/mql/providers/stackit"},"serverId":{"name":"serverId","type":"\u0007","is_mandatory":true,"title":"Attached server UUID (empty if detached)","provider":"go.mondoo.com/mql/providers/stackit"},"size":{"name":"size","type":"\u0005","is_mandatory":true,"title":"Size in GiB","provider":"go.mondoo.com/mql/providers/stackit"},"sourceBackup":{"name":"sourceBackup","type":"\u001bstackit.backup","title":"Backup the volume was created from (nullable)","min_provider_version":"13.4.3","provider":"go.mondoo.com/mql/providers/stackit"},"sourceBackupId":{"name":"sourceBackupId","type":"\u0007","is_mandatory":true,"title":"Source backup UUID (empty if not backup-based)","min_provider_version":"13.4.3","provider":"go.mondoo.com/mql/providers/stackit"},"sourceSnapshot":{"name":"sourceSnapshot","type":"\u001bstackit.snapshot","title":"Snapshot the volume was created from (nullable)","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"sourceSnapshotId":{"name":"sourceSnapshotId","type":"\u0007","is_mandatory":true,"title":"Source snapshot UUID (empty if not snapshot-based)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Status (CREATING, AVAILABLE, IN_USE, DELETING, ERROR)","provider":"go.mondoo.com/mql/providers/stackit"},"updatedAt":{"name":"updatedAt","type":"\t","is_mandatory":true,"title":"Last update timestamp","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT block storage volume","desc":"Block storage volume that backs compute instances, keyed by its UUID `id` (for example `stackit.volume(id: \"...\")`). Reports the volume's size in GiB, lifecycle status, and availability zone, whether it is encrypted at rest and which key-encryption key wraps its data key, the image, snapshot, or backup it was created from, and the server it is attached to. Use it to audit unattached, unencrypted, or oversized volumes.","private":true,"min_provider_version":"13.0.0","defaults":"id name size status","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.vpn":{"id":"stackit.vpn","name":"stackit.vpn","fields":{"gateway":{"name":"gateway","type":"\u001bstackit.vpn.gateway","title":"STACKIT VPN gateway","desc":"Site-to-site VPN gateway that terminates encrypted tunnels for a project. The gateway is keyed by its UUID id and exposes the display name, state, routing type, plan, the availability zones its two tunnel endpoints run in, the border gateway protocol settings, and its connections.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"gateways":{"name":"gateways","type":"\u0019\u001bstackit.vpn.gateway","title":"VPN gateways","provider":"go.mondoo.com/mql/providers/stackit"},"tunnel":{"name":"tunnel","type":"\u001bstackit.vpn.tunnel","title":"STACKIT VPN tunnel","desc":"Single encrypted tunnel of a VPN connection, terminating at a remote peer. Exposes the peer address, the border gateway protocol and peering addressing, and the negotiated cryptographic parameters for both the key exchange (IKE) and the data channel (IPsec/ESP): the Diffie-Hellman groups, encryption and integrity algorithms, and rekey intervals. Use these to flag tunnels that permit weak ciphers or groups.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true}},"title":"STACKIT VPN namespace","desc":"Site-to-site VPN gateways in the project and, through each gateway, the connections and the encrypted tunnels that carry traffic. Enumerate the gateways with gateways.","min_provider_version":"13.4.2","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.vpn.gateway":{"id":"stackit.vpn.gateway","name":"stackit.vpn.gateway","fields":{"bgpLocalAsn":{"name":"bgpLocalAsn","type":"\u0005","is_mandatory":true,"title":"Local autonomous system number advertised over the border gateway protocol","provider":"go.mondoo.com/mql/providers/stackit"},"bgpOverrideAdvertisedRoutes":{"name":"bgpOverrideAdvertisedRoutes","type":"\u0019\u0007","is_mandatory":true,"title":"Routes advertised over the border gateway protocol in place of the automatically derived set","provider":"go.mondoo.com/mql/providers/stackit"},"connection":{"name":"connection","type":"\u001bstackit.vpn.gateway.connection","title":"STACKIT VPN connection","desc":"Single site-to-site connection on a VPN gateway, keyed by its UUID id. The connection exposes whether it is enabled, the local and remote subnets it routes between, any static routes, and its two redundant encrypted tunnels.","is_private":true,"provider":"go.mondoo.com/mql/providers/stackit","is_implicit_resource":true},"connections":{"name":"connections","type":"\u0019\u001bstackit.vpn.gateway.connection","title":"Connections configured on the gateway","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Gateway UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/stackit"},"planId":{"name":"planId","type":"\u0007","is_mandatory":true,"title":"Plan ID (sizing tier)","provider":"go.mondoo.com/mql/providers/stackit"},"routingType":{"name":"routingType","type":"\u0007","is_mandatory":true,"title":"Routing type (ROUTE_BASED, POLICY_BASED, BGP_ROUTE_BASED)","provider":"go.mondoo.com/mql/providers/stackit"},"status":{"name":"status","type":"\u0007","is_mandatory":true,"title":"Gateway state (READY, PENDING, DELETING, ERROR)","provider":"go.mondoo.com/mql/providers/stackit"},"tunnel1AvailabilityZone":{"name":"tunnel1AvailabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone the first tunnel endpoint runs in","provider":"go.mondoo.com/mql/providers/stackit"},"tunnel2AvailabilityZone":{"name":"tunnel2AvailabilityZone","type":"\u0007","is_mandatory":true,"title":"Availability zone the second tunnel endpoint runs in","provider":"go.mondoo.com/mql/providers/stackit"}},"init":{"args":[{"name":"id","type":"\u0007","optional":true}]},"title":"STACKIT VPN gateway","desc":"Site-to-site VPN gateway that terminates encrypted tunnels for a project. The gateway is keyed by its UUID id and exposes the display name, state, routing type, plan, the availability zones its two tunnel endpoints run in, the border gateway protocol settings, and its connections.","private":true,"min_provider_version":"13.4.2","defaults":"id name status routingType","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.vpn.gateway.connection":{"id":"stackit.vpn.gateway.connection","name":"stackit.vpn.gateway.connection","fields":{"enabled":{"name":"enabled","type":"\u0004","is_mandatory":true,"title":"Whether the connection is enabled","provider":"go.mondoo.com/mql/providers/stackit"},"id":{"name":"id","type":"\u0007","is_mandatory":true,"title":"Connection UUID","provider":"go.mondoo.com/mql/providers/stackit"},"labels":{"name":"labels","type":"\u001a\u0007\u0007","is_mandatory":true,"title":"User-defined labels","provider":"go.mondoo.com/mql/providers/stackit"},"localSubnets":{"name":"localSubnets","type":"\u0019\u0007","is_mandatory":true,"title":"Local subnets routed into the tunnel (CIDR)","provider":"go.mondoo.com/mql/providers/stackit"},"name":{"name":"name","type":"\u0007","is_mandatory":true,"title":"Display name","provider":"go.mondoo.com/mql/providers/stackit"},"remoteSubnets":{"name":"remoteSubnets","type":"\u0019\u0007","is_mandatory":true,"title":"Remote subnets reachable across the tunnel (CIDR)","provider":"go.mondoo.com/mql/providers/stackit"},"staticRoutes":{"name":"staticRoutes","type":"\u0019\u0007","is_mandatory":true,"title":"Static routes configured on the connection (CIDR)","provider":"go.mondoo.com/mql/providers/stackit"},"tunnel1":{"name":"tunnel1","type":"\u001bstackit.vpn.tunnel","title":"First (primary) encrypted tunnel","provider":"go.mondoo.com/mql/providers/stackit"},"tunnel2":{"name":"tunnel2","type":"\u001bstackit.vpn.tunnel","title":"Second (redundant) encrypted tunnel","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT VPN connection","desc":"Single site-to-site connection on a VPN gateway, keyed by its UUID id. The connection exposes whether it is enabled, the local and remote subnets it routes between, any static routes, and its two redundant encrypted tunnels.","private":true,"min_provider_version":"13.4.2","defaults":"id name enabled","provider":"go.mondoo.com/mql/providers/stackit"},"stackit.vpn.tunnel":{"id":"stackit.vpn.tunnel","name":"stackit.vpn.tunnel","fields":{"bgpRemoteAsn":{"name":"bgpRemoteAsn","type":"\u0005","is_mandatory":true,"title":"Remote autonomous system number for the border gateway protocol (0 if unset)","provider":"go.mondoo.com/mql/providers/stackit"},"dpdAction":{"name":"dpdAction","type":"\u0007","is_mandatory":true,"title":"Action taken on dead-peer detection (clear, restart)","provider":"go.mondoo.com/mql/providers/stackit"},"peeringLocalAddress":{"name":"peeringLocalAddress","type":"\u0007","is_mandatory":true,"title":"Local peering address (empty if unset)","provider":"go.mondoo.com/mql/providers/stackit"},"peeringRemoteAddress":{"name":"peeringRemoteAddress","type":"\u0007","is_mandatory":true,"title":"Remote peering address (empty if unset)","provider":"go.mondoo.com/mql/providers/stackit"},"phase1DhGroups":{"name":"phase1DhGroups","type":"\u0019\u0007","is_mandatory":true,"title":"Key-exchange Diffie-Hellman groups offered","provider":"go.mondoo.com/mql/providers/stackit"},"phase1EncryptionAlgorithms":{"name":"phase1EncryptionAlgorithms","type":"\u0019\u0007","is_mandatory":true,"title":"Key-exchange encryption algorithms offered","provider":"go.mondoo.com/mql/providers/stackit"},"phase1IntegrityAlgorithms":{"name":"phase1IntegrityAlgorithms","type":"\u0019\u0007","is_mandatory":true,"title":"Key-exchange integrity algorithms offered","provider":"go.mondoo.com/mql/providers/stackit"},"phase1RekeyTime":{"name":"phase1RekeyTime","type":"\u0005","is_mandatory":true,"title":"Key-exchange rekey interval in seconds (0 if unset)","provider":"go.mondoo.com/mql/providers/stackit"},"phase2DhGroups":{"name":"phase2DhGroups","type":"\u0019\u0007","is_mandatory":true,"title":"Data-channel Diffie-Hellman groups offered","provider":"go.mondoo.com/mql/providers/stackit"},"phase2EncryptionAlgorithms":{"name":"phase2EncryptionAlgorithms","type":"\u0019\u0007","is_mandatory":true,"title":"Data-channel encryption algorithms offered","provider":"go.mondoo.com/mql/providers/stackit"},"phase2IntegrityAlgorithms":{"name":"phase2IntegrityAlgorithms","type":"\u0019\u0007","is_mandatory":true,"title":"Data-channel integrity algorithms offered","provider":"go.mondoo.com/mql/providers/stackit"},"phase2RekeyTime":{"name":"phase2RekeyTime","type":"\u0005","is_mandatory":true,"title":"Data-channel rekey interval in seconds (0 if unset)","provider":"go.mondoo.com/mql/providers/stackit"},"remoteAddress":{"name":"remoteAddress","type":"\u0007","is_mandatory":true,"title":"Remote peer IP address","provider":"go.mondoo.com/mql/providers/stackit"},"startAction":{"name":"startAction","type":"\u0007","is_mandatory":true,"title":"Action taken when establishing the data channel (none, start)","provider":"go.mondoo.com/mql/providers/stackit"}},"title":"STACKIT VPN tunnel","desc":"Single encrypted tunnel of a VPN connection, terminating at a remote peer. Exposes the peer address, the border gateway protocol and peering addressing, and the negotiated cryptographic parameters for both the key exchange (IKE) and the data channel (IPsec/ESP): the Diffie-Hellman groups, encryption and integrity algorithms, and rekey intervals. Use these to flag tunnels that permit weak ciphers or groups.","private":true,"min_provider_version":"13.4.2","defaults":"remoteAddress","provider":"go.mondoo.com/mql/providers/stackit"}}}