IBM Cloud Kubernetes Service GraphQL API reference
The IBM Cloud Kubernetes Service GraphQL API is available at https://containers.cloud.ibm.com/graphql. Use this API to manage Satellite Connectors, Kubernetes clusters, and bare metal worker nodes programmatically.
This page is auto-generated from the live schema.
Queries
Queries retrieve data without modifying any resources. Send a POST request to https://containers.cloud.ibm.com/graphql with your query in the request body.
node
Find a Node for the given ID. Use fragments to select additional fields.
| Type | Name | Description |
|---|---|---|
| Returns | Node |
|
| Argument | id (ID!) (required) |
The globally unique node identifier. |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "query node($id: ID!) {\n node(id: $id) {\n # ... select your fields here\n }\n}",
"variables": {
"id": "abc123"
}
}'
Example response
{
"data": {
"node": "<Node>"
}
}
satelliteConnectors
List the Satellite Connectors you have access to.
| Type | Name | Description |
|---|---|---|
| Returns | SatelliteConnectorConnection |
|
| Argument | after (String) |
Return Satellite Connectors after this cursor. |
| Argument | first (Int) |
Return the first N Satellite Connectors. |
| Argument | last (Int) |
Return the last N Satellite Connectors. |
| Argument | before (String) |
Return Satellite Connectors before this cursor. |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "query satelliteConnectors($after: String, $first: Int, $last: Int, $before: String) {\n satelliteConnectors(after: $after, first: $first, last: $last, before: $before) {\n # ... select your fields here\n }\n}",
"variables": {
"after": "example-value",
"first": 0,
"last": 0,
"before": "example-value"
}
}'
Example response
{
"data": {
"satelliteConnectors": {
"edges": [
{
"cursor": "example-value",
"node": {
"createdDate": "2025-01-01T00:00:00Z",
"crn": "<CloudResourceName>",
"id": "abc123",
"name": "example-value",
"region": {
"displayName": "...",
"id": "...",
"name": "..."
},
"resourceGroup": {
"externalID": "...",
"id": "...",
"name": "..."
},
"state": "CREATED"
}
}
],
"pageInfo": {
"endCursor": "example-value",
"hasNextPage": true,
"hasPreviousPage": true,
"startCursor": "example-value"
}
}
}
}
Mutations
Mutations create, update, or delete resources. Each mutation requires an IAM bearer token in the Authorization header.
addVirtualNetworkInterfaceToBareMetalNode
Adds a virtual network interface (VNI) to a bare metal Kubernetes worker node.
| Type | Name | Description |
|---|---|---|
| Returns | AddVirtualNetworkInterfaceToBareMetalNodePayload |
|
| Argument | input (AddVirtualNetworkInterfaceToBareMetalNodeInput!) (required) |
Input parameters for adding the VNI to a bare metal node. |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "mutation addVirtualNetworkInterfaceToBareMetalNode($input: AddVirtualNetworkInterfaceToBareMetalNodeInput!) {\n addVirtualNetworkInterfaceToBareMetalNode(input: $input) {\n # ... select your fields here\n }\n}",
"variables": {
"input": "<AddVirtualNetworkInterfaceToBareMetalNodeInput>"
}
}'
Example response
{
"data": {
"addVirtualNetworkInterfaceToBareMetalNode": {
"networkAttachment": "<NetworkAttachment>"
}
}
}
createSatelliteConnector
Create a Satellite Connector.
| Type | Name | Description |
|---|---|---|
| Returns | CreateSatelliteConnectorPayload |
|
| Argument | input (CreateSatelliteConnectorInput) |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "mutation createSatelliteConnector($input: CreateSatelliteConnectorInput) {\n createSatelliteConnector(input: $input) {\n # ... select your fields here\n }\n}",
"variables": {
"input": "<CreateSatelliteConnectorInput>"
}
}'
Example response
{
"data": {
"createSatelliteConnector": {
"satelliteConnector": {
"createdDate": "2025-01-01T00:00:00Z",
"crn": "<CloudResourceName>",
"id": "abc123",
"name": "example-value",
"region": {
"displayName": "example-value",
"id": "abc123",
"name": "example-value"
},
"resourceGroup": {
"externalID": "example-value",
"id": "abc123",
"name": "example-value"
},
"state": "CREATED"
}
}
}
}
reinitializeKubernetesNode
Reinitialize a Kubernetes node. Not supported on VPC virtual server instances today.
| Type | Name | Description |
|---|---|---|
| Returns | ReinitializeKubernetesNodePayload |
|
| Argument | input (ReinitializeKubernetesNodeInput) |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "mutation reinitializeKubernetesNode($input: ReinitializeKubernetesNodeInput) {\n reinitializeKubernetesNode(input: $input) {\n # ... select your fields here\n }\n}",
"variables": {
"input": "<ReinitializeKubernetesNodeInput>"
}
}'
Example response
{
"data": {
"reinitializeKubernetesNode": {
"node": "<KubernetesNode>"
}
}
}
removeSatelliteConnector
Remove a Satellite Connector.
| Type | Name | Description |
|---|---|---|
| Returns | RemoveSatelliteConnectorPayload |
|
| Argument | input (RemoveSatelliteConnectorInput) |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "mutation removeSatelliteConnector($input: RemoveSatelliteConnectorInput) {\n removeSatelliteConnector(input: $input) {\n # ... select your fields here\n }\n}",
"variables": {
"input": "<RemoveSatelliteConnectorInput>"
}
}'
Example response
{
"data": {
"removeSatelliteConnector": {
"satelliteConnector": {
"createdDate": "2025-01-01T00:00:00Z",
"crn": "<CloudResourceName>",
"id": "abc123",
"name": "example-value",
"region": {
"displayName": "example-value",
"id": "abc123",
"name": "example-value"
},
"resourceGroup": {
"externalID": "example-value",
"id": "abc123",
"name": "example-value"
},
"state": "CREATED"
}
}
}
}
removeVirtualNetworkInterfaceFromNode
Removes a virtual network interface from a Kubernetes worker node.
| Type | Name | Description |
|---|---|---|
| Returns | RemoveVirtualNetworkInterfaceFromNodePayload |
|
| Argument | input (RemoveVirtualNetworkInterfaceFromNodeInput!) (required) |
Input parameters for removing the VNI from a node. |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "mutation removeVirtualNetworkInterfaceFromNode($input: RemoveVirtualNetworkInterfaceFromNodeInput!) {\n removeVirtualNetworkInterfaceFromNode(input: $input) {\n # ... select your fields here\n }\n}",
"variables": {
"input": "<RemoveVirtualNetworkInterfaceFromNodeInput>"
}
}'
Example response
{
"data": {
"removeVirtualNetworkInterfaceFromNode": {
"cluster": {
"id": "abc123",
"name": "example-value",
"networkAttachments": {
"edges": [
{
"cursor": "...",
"node": "..."
}
],
"pageInfo": {
"endCursor": "...",
"hasNextPage": "...",
"hasPreviousPage": "...",
"startCursor": "..."
}
},
"region": {
"displayName": "example-value",
"id": "abc123",
"name": "example-value"
}
},
"node": "<NetworkAttachable>",
"virtualNetworkInterface": "<VirtualNetworkInterface>"
}
}
}
updateSatelliteLocation
Update a Satellite Location.
| Type | Name | Description |
|---|---|---|
| Returns | UpdateSatelliteLocationPayload |
|
| Argument | input (UpdateSatelliteLocationInput) |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "mutation updateSatelliteLocation($input: UpdateSatelliteLocationInput) {\n updateSatelliteLocation(input: $input) {\n # ... select your fields here\n }\n}",
"variables": {
"input": "<UpdateSatelliteLocationInput>"
}
}'
Example response
{
"data": {
"updateSatelliteLocation": {
"satelliteLocation": {
"description": "example-value",
"id": "abc123",
"name": "example-value"
}
}
}
}
Object types
Object types represent the concrete resources and response payloads returned by the API.
Account
An IBM Cloud account.
| Type | Name | Description |
|---|---|---|
| Field | externalID (String!) |
The account's IBM Cloud ID. |
AddVirtualNetworkInterfaceToBareMetalNodePayload
Response payload for adding a VNI to a bare metal node.
| Type | Name | Description |
|---|---|---|
| Field | networkAttachment (NetworkAttachment!) |
The created network attachment with its properties. |
BareMetalNetworkAttachmentByVLAN
Network attachment for bare metal nodes using VLAN tagging.
| Type | Name | Description |
|---|---|---|
| Implements | NetworkAttachment |
|
| Field | attachedTo (NetworkAttachable!) |
The bare metal node this interface is attached to. |
| Field | canFloat (Boolean!) |
Whether this attachment can float between nodes in the cluster. |
| Field | virtualNetworkInterface (VirtualNetworkInterface!) |
The virtual network interface that is attached. |
| Field | vlanID (Int) |
VLAN ID used for this attachment (2-500). Null if not yet assigned. |
BareMetalVirtualNetworkInterface
Virtual network interface attached to a bare metal server.
| Type | Name | Description |
|---|---|---|
| Implements | VirtualNetworkInterface |
|
| Field | autoDelete (Boolean) |
Whether the VNI should be automatically deleted when detached. |
| Field | externalID (String!) |
The VPC resource ID of this VNI. |
| Field | macAddress (MACAddress) |
MAC address assigned to this network interface. |
| Field | name (String) |
Human-readable name of the VNI. |
| Field | primaryIPAddress (IPv4Address) |
Primary IPv4 address assigned to this network interface. |
| Field | securityGroups (SecurityGroupConnection) |
Security groups applied to this network interface.
|
| Field | subnet (Subnet!) |
The VPC subnet this network interface is connected to. |
CreateSatelliteConnectorPayload
Output type for createSatelliteConnector.
| Type | Name | Description |
|---|---|---|
| Field | satelliteConnector (SatelliteConnector) |
The new SatelliteConnector. |
KubernetesCluster
An IBM Cloud Kubernetes Service or IBM Cloud OpenShift Service cluster.
| Type | Name | Description |
|---|---|---|
| Implements | Node |
|
| Field | id (ID!) |
The cluster's unique identifier. |
| Field | name (String) |
The cluster's name. |
| Field | networkAttachments (NetworkAttachmentConnection) |
Network attachments for this cluster (if applicable).
|
| Field | region (Region) |
The cluster's IBM Cloud catalog region. |
Region
An IBM Cloud catalog region.
| Type | Name | Description |
|---|---|---|
| Implements | Location |
|
| Implements | Node |
|
| Field | displayName (String) |
The translated name of this region. |
| Field | id (ID!) |
The ID of this region. |
| Field | name (String) |
The name of this region. |
ReinitializeKubernetesNodePayload
Output type for reinitializeKubernetesNode.
| Type | Name | Description |
|---|---|---|
| Field | node (KubernetesNode) |
The reinitializing Kubernetes node. |
RemoveSatelliteConnectorPayload
Output type for removeSatelliteConnector.
| Type | Name | Description |
|---|---|---|
| Field | satelliteConnector (SatelliteConnector) |
The removed SatelliteConnector. |
RemoveVirtualNetworkInterfaceFromNodePayload
Response payload for removing a VNI from a node.
| Type | Name | Description |
|---|---|---|
| Field | cluster (KubernetesCluster!) |
The cluster the VNI was removed from. |
| Field | node (NetworkAttachable!) |
The node the VNI was removed from. |
| Field | virtualNetworkInterface (VirtualNetworkInterface!) |
The virtual network interface that was removed. |
ResourceGroup
A ResourceGroup is a way for you to organize your account resources in customizable groupings so that you can quickly assign users access to multiple resources at a time.
| Type | Name | Description |
|---|---|---|
| Implements | Node |
|
| Field | externalID (String!) |
The resource group's IBM Cloud ID. |
| Field | id (ID!) |
The resource group's Node ID. |
| Field | name (String) |
The resource group's name. |
SatelliteConnector
A Satellite Connector provides a secure connection between a specific remote location and IBM Cloud.
| Type | Name | Description |
|---|---|---|
| Implements | Node |
|
| Field | createdDate (DateTime) |
The date when this resource was created. |
| Field | crn (CloudResourceName) |
The resource's IBM Cloud CRN. |
| Field | id (ID!) |
The resource's unique identifier. |
| Field | name (String!) |
The resource's name. |
| Field | region (Region) |
The region the resource is managed from. |
| Field | resourceGroup (ResourceGroup) |
The resource group containing this resource. |
| Field | state (SatelliteConnectorState) |
The current state of this resource. |
SatelliteLocation
A Satellite Location.
| Type | Name | Description |
|---|---|---|
| Implements | Node |
|
| Field | description (String) |
The Location description. |
| Field | id (ID!) |
The resource's unique identifier. |
| Field | name (String) |
The Location name. |
SecurityGroup
Represents a VPC security group.
| Type | Name | Description |
|---|---|---|
| Field | externalID (String!) |
The VPC resource ID of this security group. |
Subnet
Represents a VPC subnet.
| Type | Name | Description |
|---|---|---|
| Field | externalID (String!) |
The VPC resource ID of this subnet. |
UpdateSatelliteLocationPayload
Output type for updateSatelliteLocation.
| Type | Name | Description |
|---|---|---|
| Field | satelliteLocation (SatelliteLocation) |
The updated SatelliteLocation. |
VPCBareMetalKubernetesNode
Represents a bare metal Kubernetes worker node in IBM Cloud VPC.
| Type | Name | Description |
|---|---|---|
| Implements | KubernetesNode |
|
| Implements | NetworkAttachable |
|
| Implements | Node |
|
| Field | id (ID!) |
Globally unique identifier for this worker node. |
| Field | networkAttachments (NetworkAttachmentConnection) |
Network attachments for this bare metal node.
|
| Field | region (Region) |
Interface types
Interface types define common fields that are shared across multiple concrete object types.
KubernetesNode
A Kubernetes Node runs your workload.
| Type | Name | Description |
|---|---|---|
| Implementation | KubernetesNode |
|
| Implementation | VPCBareMetalKubernetesNode |
|
| Field | id (ID!) |
The resource's unique identifier. |
| Field | region (Region) |
Location
An IBM Cloud catalog location.
| Type | Name | Description |
|---|---|---|
| Implementation | Location |
|
| Implementation | Region |
|
| Field | displayName (String) |
Translated name of this location. |
| Field | id (ID!) |
The ID of this location. |
| Field | name (String) |
Name of this location. |
NetworkAttachable
Represents an entity that can have network interfaces attached to it.
| Type | Name | Description |
|---|---|---|
| Implementation | NetworkAttachable |
|
| Field | id (ID!) |
Globally unique identifier for this node. |
| Field | networkAttachments (NetworkAttachmentConnection) |
Network attachments associated to this node.
|
NetworkAttachment
Represents a network interface attachment to a node.
| Type | Name | Description |
|---|---|---|
| Implementation | BareMetalNetworkAttachmentByVLAN |
|
| Implementation | NetworkAttachment |
|
| Field | attachedTo (NetworkAttachable!) |
The node this network interface is attached to. |
| Field | virtualNetworkInterface (VirtualNetworkInterface!) |
The virtual network interface that is attached. |
Node
Fetches an object given its ID.
| Type | Name | Description |
|---|---|---|
| Implementation | KubernetesCluster |
|
| Implementation | KubernetesNode |
|
| Implementation | NetworkAttachable |
|
| Implementation | Node |
|
| Implementation | Region |
|
| Implementation | ResourceGroup |
|
| Implementation | SatelliteConnector |
|
| Implementation | SatelliteLocation |
|
| Implementation | VPCBareMetalKubernetesNode |
|
| Field | id (ID!) |
The globally unique object ID. |
VirtualNetworkInterface
Represents a virtual network interface in IBM Cloud VPC. Can be attached to bare metal or virtual server instances.
| Type | Name | Description |
|---|---|---|
| Implementation | BareMetalVirtualNetworkInterface |
|
| Implementation | VirtualNetworkInterface |
|
| Field | autoDelete (Boolean) |
Whether the VNI should be automatically deleted when detached. |
| Field | externalID (String!) |
The VPC resource ID of this virtual network interface. |
| Field | macAddress (MACAddress) |
MAC address assigned to this network interface. |
| Field | name (String) |
Human-readable name of the VNI. |
| Field | primaryIPAddress (IPv4Address) |
Primary IPv4 address assigned to this network interface. |
| Field | securityGroups (SecurityGroupConnection) |
Security groups applied to this network interface.
|
| Field | subnet (Subnet!) |
The VPC subnet this network interface is connected to. |
Input types
Input types are used as arguments to mutations. Fields marked (required) must be provided.
AddVirtualNetworkInterfaceToBareMetalNodeInput
Input for adding a VNI to a bare metal node.
| Type | Name | Description |
|---|---|---|
| Field | autoDelete (Boolean) |
Whether to automatically delete the VNI from VPC when it is detached. Defaults to false if not specified. |
| Field | cluster (ID) |
Cluster ID. Either cluster or node must be specified, but not both. If only cluster is provided, a node will be auto-selected and the attachment will float. |
| Field | node (ID) |
Node ID. Either cluster or node must be specified, but not both. If specified, creates a non-floating attachment to this specific node. |
| Field | virtualNetworkInterfaceID (String!) (required) |
The VPC resource ID of the virtual network interface to attach. |
| Field | vlanID (Int!) (required) |
VLAN ID for the attachment (2-500). VLAN 1 is reserved for the primary network interface. |
CreateSatelliteConnectorInput
Details needed to provision a Satellite Connector.
| Type | Name | Description |
|---|---|---|
| Field | name (String!) (required) |
The resource's name. |
| Field | regionName (String!) (required) |
The region name indicating where the new connector should be managed from. |
| Field | resourceGroupID (String!) (required) |
The resource group ID to provision inside. |
ReinitializeKubernetesNodeInput
Input type for reinitializeKubernetesNode.
| Type | Name | Description |
|---|---|---|
| Field | bypassUnhealthyControlPlane (Boolean) |
Set to true to proceed with reinitialization, even when the cluster's control plane is unhealthy. |
| Field | id (ID!) (required) |
Kubernetes node to reinitialize. |
RemoveSatelliteConnectorInput
Input type for removeSatelliteConnector.
| Type | Name | Description |
|---|---|---|
| Field | id (ID!) (required) |
Satellite Connector ID to remove. |
RemoveVirtualNetworkInterfaceFromNodeInput
Input for removing a VNI from a node.
| Type | Name | Description |
|---|---|---|
| Field | cluster (ID) |
Cluster ID. Either cluster or node must be specified, but not both. |
| Field | node (ID) |
Node ID. Either cluster or node must be specified, but not both. |
| Field | virtualNetworkInterfaceID (String!) (required) |
The VPC resource ID of the virtual network interface to remove. |
UpdateSatelliteLocationInput
Input type for updateSatelliteLocation.
| Type | Name | Description |
|---|---|---|
| Field | description (String) |
|
| Field | id (ID!) (required) |
Satellite Location ID to update. |
| Field | name (String) |
Enum types
Enum types define the set of allowed string values for a field.
SatelliteConnectorState
The administrative state of a Satellite Connector.
The values are expected to expand in the future. When processing, check for and log unknown values. Optionally halt processing and surface the error, or bypass the Satellite Connector on which the unexpected value was encountered.
| Type | Name | Description |
|---|---|---|
| Value | CREATED |
The connector has completed provisioning and is ready to use. |
| Value | CREATING |
The connector is provisioning and may not be ready to use. |
| Value | DELETING |
The connector is deprovisioning and may be unavailable. |
| Value | FAILED |
The connector's most recent operation has failed and it must be deleted to continue. |
Scalar types
Scalar types are primitive leaf values in the GraphQL schema.
CloudResourceName
A Cloud Resource Name (CRN) uniquely identifies IBM Cloud resources. A CRN is used to specify a resource in an unambiguous way that is guaranteed to be globally unique.
DateTime
A DateTime is an RFC3339 compliant combination of a date and time.
IPv4Address
IPv4 address in dotted-decimal notation (e.g., 192.168.1.1).
MACAddress
MAC address in colon-hexadecimal notation (e.g., 00:1A:2B:3C:4D:5E).
Internal queries
The following queries are for internal use only and are not supported for external callers. They are documented here for completeness.
globalSearchSatelliteConnectorAccounts
Globally searchable results for the IBM Global Search service. Internal use only.
| Type | Name | Description |
|---|---|---|
| Returns | GlobalSearchSatelliteConnectorAccountsConnection |
|
| Argument | after (String) |
|
| Argument | first (Int) |
|
| Argument | last (Int) |
|
| Argument | before (String) |
|
| Argument | regionName (String!) (required) |
Example request
curl -X POST https://containers.cloud.ibm.com/graphql \
-H "Authorization: Bearer $IAM_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"query": "query globalSearchSatelliteConnectorAccounts($after: String, $first: Int, $last: Int, $before: String, $regionName: String!) {\n globalSearchSatelliteConnectorAccounts(after: $after, first: $first, last: $last, before: $before, regionName: $regionName) {\n # ... select your fields here\n }\n}",
"variables": {
"after": "example-value",
"first": 0,
"last": 0,
"before": "example-value",
"regionName": "example-value"
}
}'
Example response
{
"data": {
"globalSearchSatelliteConnectorAccounts": {
"edges": [
{
"cursor": "example-value",
"node": {
"externalID": "example-value"
}
}
],
"pageInfo": {
"endCursor": "example-value",
"hasNextPage": true,
"hasPreviousPage": true,
"startCursor": "example-value"
}
}
}
}