These certificate-based cluster endpoints are deprecated.

Use this API to manage and discover the certificate-based Kubernetes clusters of an instance, a group, or a project. Connecting a cluster to a group or an instance lets you use the same cluster across multiple projects.

Instance endpoints require administrator access. Group and project endpoints require the Maintainer or Owner role.

List all instance clusters

GET /api/v4/admin/clusters

Lists all instance clusters for the instance.

Responses

CodeDescriptionSchema
200OKAPIEntitiesCluster
403Forbidden—

Create an instance cluster

POST /api/v4/admin/clusters/add

Creates an instance cluster by adding an existing Kubernetes cluster.

Request body (application/json)

PropertyTypeDescription
domainStringCluster base domain
enabledBooleanDetermines if cluster is active or not, defaults to true
Default: true
environment_scopeStringThe associated environment to the cluster
Default: *
managedBooleanDetermines if GitLab will manage namespaces and service accounts for this cluster, defaults to true
Default: true
management_project_idIntegerThe ID of the management project
name
Required
StringCluster name
namespace_per_environmentBooleanDeploy each environment to a separate Kubernetes namespace
Default: true
platform_kubernetes_attributes
Required
ObjectPlatform Kubernetes data
platform_kubernetes_attributes.api_url
Required
StringURL to access the Kubernetes API
platform_kubernetes_attributes.authorization_typeStringCluster authorization type, defaults to RBAC
Allowed values: unknown_authorization, rbac, abac
Default: rbac
platform_kubernetes_attributes.ca_certStringTLS certificate (needed if API is using a self-signed TLS certificate)
platform_kubernetes_attributes.namespaceStringUnique namespace related to Project
platform_kubernetes_attributes.token
Required
StringToken to authenticate against Kubernetes

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesCluster
400Validation error—
403Forbidden—
404Not found—

Retrieve a single instance cluster

GET /api/v4/admin/clusters/{cluster_id}

Retrieves a specified instance cluster.

Parameters

NameTypeDescription
cluster_id
Path, required
IntegerThe cluster ID

Responses

CodeDescriptionSchema
200OKAPIEntitiesCluster
400Bad Request—
403Forbidden—
404Not found—

Update an instance cluster

PUT /api/v4/admin/clusters/{cluster_id}

Updates an existing instance cluster.

Parameters

NameTypeDescription
cluster_id
Path, required
IntegerThe cluster ID

Request body (application/json)

PropertyTypeDescription
domainStringCluster base domain
enabledBooleanEnable or disable Gitlab’s connection to your Kubernetes cluster
environment_scopeStringThe associated environment to the cluster
managedBooleanDetermines if GitLab will manage namespaces and service accounts for this cluster
management_project_idIntegerThe ID of the management project
nameStringCluster name
namespace_per_environmentBooleanDeploy each environment to a separate Kubernetes namespace
Default: true
platform_kubernetes_attributesObjectPlatform Kubernetes data
platform_kubernetes_attributes.api_urlStringURL to access the Kubernetes API
platform_kubernetes_attributes.ca_certStringTLS certificate (needed if API is using a self-signed TLS certificate)
platform_kubernetes_attributes.namespaceStringUnique namespace related to Project
platform_kubernetes_attributes.tokenStringToken to authenticate against Kubernetes

Responses

CodeDescriptionSchema
200OKAPIEntitiesCluster
400Validation error—
403Forbidden—
404Not found—

Delete instance cluster

DELETE /api/v4/admin/clusters/{cluster_id}

Deletes an existing instance cluster. Does not remove existing resources in the connected Kubernetes cluster.

Parameters

NameTypeDescription
cluster_id
Path, required
IntegerThe cluster ID

Responses

CodeDescriptionSchema
200OKAPIEntitiesCluster
400Bad Request—
403Forbidden—
404Not found—

List all certificate-based clusters

GET /api/v4/discover-cert-based-clusters

Lists all certificate-based clusters associated with a project. This feature was introduced in GitLab 17.9.

Parameters

NameTypeDescription
group_id
Query, required
IntegerThe group ID to find all certificate-based clusters in the hierarchy

Responses

CodeDescriptionSchema
200OKAPIEntitiesDiscoveredClusters
400Bad Request—
403Forbidden—

List all group clusters

GET /api/v4/groups/{id}/clusters

Lists all group clusters for a specified group.

Parameters

NameTypeDescription
id
Path, required
StringThe ID of the group
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesCluster
400Bad Request—
403Forbidden—
404Not Found—

Create a group cluster

POST /api/v4/groups/{id}/clusters/user

Creates a group cluster for a specified group by adding an existing Kubernetes cluster.

Parameters

NameTypeDescription
id
Path, required
StringThe ID of the group

Request body (application/json)

PropertyTypeDescription
domainStringCluster base domain
enabledBooleanDetermines if cluster is active or not, defaults to true
Default: true
environment_scopeStringThe associated environment to the cluster
Default: *
managedBooleanDetermines if GitLab will manage namespaces and service accounts for this cluster, defaults to true
Default: true
management_project_idIntegerThe ID of the management project
name
Required
StringCluster name
namespace_per_environmentBooleanDeploy each environment to a separate Kubernetes namespace
Default: true
platform_kubernetes_attributes
Required
ObjectPlatform Kubernetes data
platform_kubernetes_attributes.api_url
Required
StringURL to access the Kubernetes API
platform_kubernetes_attributes.authorization_typeStringCluster authorization type, defaults to RBAC
Allowed values: unknown_authorization, rbac, abac
Default: rbac
platform_kubernetes_attributes.ca_certStringTLS certificate (needed if API is using a self-signed TLS certificate)
platform_kubernetes_attributes.namespaceStringUnique namespace related to Group
platform_kubernetes_attributes.token
Required
StringToken to authenticate against Kubernetes

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesClusterGroup
400Validation error—
403Forbidden—
404Not found—

Retrieve a group cluster

GET /api/v4/groups/{id}/clusters/{cluster_id}

Retrieves a specified group cluster.

Parameters

NameTypeDescription
id
Path, required
StringThe ID of the group
cluster_id
Path, required
IntegerThe cluster ID

Responses

CodeDescriptionSchema
200OKAPIEntitiesClusterGroup
400Bad Request—
403Forbidden—
404Not found—

Update a group cluster

PUT /api/v4/groups/{id}/clusters/{cluster_id}

Updates a specified group cluster.

Parameters

NameTypeDescription
id
Path, required
StringThe ID of the group
cluster_id
Path, required
IntegerThe cluster ID

Request body (application/json)

PropertyTypeDescription
domainStringCluster base domain
enabledBooleanDetermines if cluster is active or not
environment_scopeStringThe associated environment to the cluster
managedBooleanDetermines if GitLab will manage namespaces and service accounts for this cluster
management_project_idIntegerThe ID of the management project
nameStringCluster name
namespace_per_environmentBooleanDeploy each environment to a separate Kubernetes namespace
Default: true
platform_kubernetes_attributesObjectPlatform Kubernetes data
platform_kubernetes_attributes.api_urlStringURL to access the Kubernetes API
platform_kubernetes_attributes.ca_certStringTLS certificate (needed if API is using a self-signed TLS certificate)
platform_kubernetes_attributes.namespaceStringUnique namespace related to Group
platform_kubernetes_attributes.tokenStringToken to authenticate against Kubernetes

Responses

CodeDescriptionSchema
200OKAPIEntitiesClusterGroup
400Validation error—
403Forbidden—
404Not found—

Delete a group cluster

DELETE /api/v4/groups/{id}/clusters/{cluster_id}

Deletes a specified group cluster. Does not remove existing resources in the connected Kubernetes cluster.

Parameters

NameTypeDescription
id
Path, required
StringThe ID of the group
cluster_id
Path, required
IntegerThe Cluster ID

Responses

CodeDescriptionSchema
200OKAPIEntitiesClusterGroup
400Bad Request—
403Forbidden—
404Not found—

List all clusters in a project

GET /api/v4/projects/{id}/clusters

Lists all clusters in a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesCluster
400Bad Request—
403Forbidden—
404Not Found—

Add a cluster to a project

POST /api/v4/projects/{id}/clusters/user

Adds a cluster to a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Request body (application/json)

PropertyTypeDescription
domainStringCluster base domain
enabledBooleanDetermines if cluster is active or not, defaults to true
Default: true
environment_scopeStringThe associated environment to the cluster
Default: *
managedBooleanDetermines if GitLab will manage namespaces and service accounts for this cluster, defaults to true
Default: true
management_project_idIntegerThe ID of the management project
name
Required
StringCluster name
namespace_per_environmentBooleanDeploy each environment to a separate Kubernetes namespace
Default: true
platform_kubernetes_attributes
Required
ObjectPlatform Kubernetes data
platform_kubernetes_attributes.api_url
Required
StringURL to access the Kubernetes API
platform_kubernetes_attributes.authorization_typeStringCluster authorization type, defaults to RBAC
Allowed values: unknown_authorization, rbac, abac
Default: rbac
platform_kubernetes_attributes.ca_certStringTLS certificate (needed if API is using a self-signed TLS certificate)
platform_kubernetes_attributes.namespaceStringUnique namespace related to Project
platform_kubernetes_attributes.token
Required
StringToken to authenticate against Kubernetes

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesClusterProject
400Validation error—
403Forbidden—
404Not found—

Retrieve a cluster from a project

GET /api/v4/projects/{id}/clusters/{cluster_id}

Retrieves a specified cluster in a project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
cluster_id
Path, required
IntegerThe cluster ID

Responses

CodeDescriptionSchema
200OKAPIEntitiesClusterProject
400Bad Request—
403Forbidden—
404Not found—

Update a cluster in a project

PUT /api/v4/projects/{id}/clusters/{cluster_id}

Updates a cluster in a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
cluster_id
Path, required
IntegerThe cluster ID

Request body (application/json)

PropertyTypeDescription
domainStringCluster base domain
enabledBooleanDetermines if cluster is active or not
environment_scopeStringThe associated environment to the cluster
managedBooleanDetermines if GitLab will manage namespaces and service accounts for this cluster
management_project_idIntegerThe ID of the management project
nameStringCluster name
namespace_per_environmentBooleanDeploy each environment to a separate Kubernetes namespace
Default: true
platform_kubernetes_attributesObjectPlatform Kubernetes data
platform_kubernetes_attributes.api_urlStringURL to access the Kubernetes API
platform_kubernetes_attributes.ca_certStringTLS certificate (needed if API is using a self-signed TLS certificate)
platform_kubernetes_attributes.namespaceStringUnique namespace related to Project
platform_kubernetes_attributes.tokenStringToken to authenticate against Kubernetes

Responses

CodeDescriptionSchema
200OKAPIEntitiesClusterProject
400Validation error—
403Forbidden—
404Not found—

Delete cluster from a project

DELETE /api/v4/projects/{id}/clusters/{cluster_id}

Deletes a specified cluster from a project. Does not remove existing resources in the connected Kubernetes cluster.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
cluster_id
Path, required
IntegerThe Cluster ID

Responses

CodeDescriptionSchema
200OKAPIEntitiesClusterProject
400Bad Request—
403Forbidden—
404Not found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesBasicGroupDetails

PropertyTypeDescription
idInteger (int64)—
nameStringExample: Diaspora
web_urlStringExample: http://gitlab.example.com/groups/diaspora

APIEntitiesBasicProjectDetails

PropertyTypeDescription
avatar_urlStringExample: http://example.com/uploads/project/avatar/3/uploads/avatar.png
created_atString (date-time)Example: 2020-05-07T04:27:17.016Z
custom_attributesAPIEntitiesCustomAttribute—
default_branchStringExample: main
descriptionStringExample: desc
forks_countIntegerExample: 1
http_url_to_repoStringExample: https://gitlab.example.com/gitlab/gitlab.git
idInteger (int64)Example: 1
last_activity_atString (date-time)Example: 2013-09-30T13:46:02Z
licenseAPIEntitiesLicenseBasic—
license_urlStringExample: https://gitlab.example.com/gitlab/gitlab/blob/master/LICENCE
nameStringExample: project1
name_with_namespaceStringExample: John Doe / project1
namespaceAPIEntitiesNamespaceBasic—
pathStringExample: project1
path_with_namespaceStringExample: namespace1/project1
readme_urlStringExample: https://gitlab.example.com/gitlab/gitlab/blob/master/README.md
repository_storageStringExample: default
ssh_url_to_repoStringExample: git@gitlab.example.com:gitlab/gitlab.git
star_countIntegerExample: 1
tag_listArray of stringsExample: ["tag"]
topicsArray of stringsExample: ["topic"]
visibilityStringExample: public
web_urlStringExample: https://gitlab.example.com/gitlab/gitlab

APIEntitiesCluster

PropertyTypeDescription
cluster_typeString—
created_atString—
domainString—
enabledString—
environment_scopeString—
idString—
managedString—
management_projectAPIEntitiesProjectIdentity—
nameString—
namespace_per_environmentString—
platform_kubernetesAPIEntitiesPlatformKubernetes—
platform_typeString—
provider_gcpAPIEntitiesProviderGcp—
provider_typeString—
userAPIEntitiesUserBasic—

APIEntitiesClusterGroup

PropertyTypeDescription
cluster_typeString—
created_atString—
domainString—
enabledString—
environment_scopeString—
groupAPIEntitiesBasicGroupDetails—
idString—
managedString—
management_projectAPIEntitiesProjectIdentity—
nameString—
namespace_per_environmentString—
platform_kubernetesAPIEntitiesPlatformKubernetes—
platform_typeString—
provider_gcpAPIEntitiesProviderGcp—
provider_typeString—
userAPIEntitiesUserBasic—

APIEntitiesClusterProject

PropertyTypeDescription
cluster_typeString—
created_atString—
domainString—
enabledString—
environment_scopeString—
idString—
managedString—
management_projectAPIEntitiesProjectIdentity—
nameString—
namespace_per_environmentString—
platform_kubernetesAPIEntitiesPlatformKubernetes—
platform_typeString—
projectAPIEntitiesBasicProjectDetails—
provider_gcpAPIEntitiesProviderGcp—
provider_typeString—
userAPIEntitiesUserBasic—

APIEntitiesCustomAttribute

PropertyTypeDescription
keyStringExample: foo
valueStringExample: bar

APIEntitiesDiscoveredClusters

PropertyTypeDescription
groupsObject—
projectsObject—

APIEntitiesLicenseBasic

PropertyTypeDescription
html_urlStringExample: http://choosealicense.com/licenses/gpl-3.0
keyStringExample: gpl-3.0
nameStringExample: GNU General Public License v3.0
nicknameStringExample: GNU GPLv3
source_urlString—

APIEntitiesNamespaceBasic

PropertyTypeDescription
avatar_urlStringExample: https://example.com/avatar/12345
full_pathStringExample: group/my_project
idInteger (int64)Example: 2
kindStringExample: project
nameStringExample: project
parent_idInteger (int64)Example: 1
pathStringExample: my_project
web_urlStringExample: https://example.com/group/my_project

APIEntitiesPlatformKubernetes

PropertyTypeDescription
api_urlString—
authorization_typeString—
ca_certString—
namespaceString—

APIEntitiesProjectIdentity

PropertyTypeDescription
created_atString (date-time)Example: 2020-05-07T04:27:17.016Z
descriptionStringExample: desc
idInteger (int64)Example: 1
nameStringExample: project1
name_with_namespaceStringExample: John Doe / project1
pathStringExample: project1
path_with_namespaceStringExample: namespace1/project1

APIEntitiesProviderGcp

PropertyTypeDescription
cluster_idString—
endpointString—
gcp_project_idString—
machine_typeString—
num_nodesString—
status_nameString—
zoneString—

APIEntitiesUserBasic

PropertyTypeDescription
avatar_pathStringExample: /user/avatar/28/The-Big-Lebowski-400-400.png
avatar_urlStringExample: https://gravatar.com/avatar/1
custom_attributesArray of APIEntitiesCustomAttribute—
idInteger (int64)Example: 1
lockedBoolean—
nameStringExample: Administrator
public_emailStringExample: john@example.com
stateStringExample: active
usernameStringExample: admin
web_urlStringExample: https://gitlab.example.com/root