IBM Cloud Kubernetes Service GraphQL API reference

The IBM Cloud Kubernetes Service GraphQL API is available at https://containers.cloud.ibm.com/graphql. Use this API to manage Satellite Connectors, Kubernetes clusters, and bare metal worker nodes programmatically.

This page is auto-generated from the live schema.

Queries

Queries retrieve data without modifying any resources. Send a POST request to https://containers.cloud.ibm.com/graphql with your query in the request body.

node

Find a Node for the given ID. Use fragments to select additional fields.

Returns and arguments for node
Type Name Description
Returns Node
Argument id (ID!) (required) The globally unique node identifier.

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "query node($id: ID!) {\n  node(id: $id) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "id": "abc123"
  }
}'

Example response

{
  "data": {
    "node": "<Node>"
  }
}

satelliteConnectors

List the Satellite Connectors you have access to.

Returns and arguments for satelliteConnectors
Type Name Description
Returns SatelliteConnectorConnection
Argument after (String) Return Satellite Connectors after this cursor.
Argument first (Int) Return the first N Satellite Connectors.
Argument last (Int) Return the last N Satellite Connectors.
Argument before (String) Return Satellite Connectors before this cursor.

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "query satelliteConnectors($after: String, $first: Int, $last: Int, $before: String) {\n  satelliteConnectors(after: $after, first: $first, last: $last, before: $before) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "after": "example-value",
    "first": 0,
    "last": 0,
    "before": "example-value"
  }
}'

Example response

{
  "data": {
    "satelliteConnectors": {
      "edges": [
        {
          "cursor": "example-value",
          "node": {
            "createdDate": "2025-01-01T00:00:00Z",
            "crn": "<CloudResourceName>",
            "id": "abc123",
            "name": "example-value",
            "region": {
              "displayName": "...",
              "id": "...",
              "name": "..."
            },
            "resourceGroup": {
              "externalID": "...",
              "id": "...",
              "name": "..."
            },
            "state": "CREATED"
          }
        }
      ],
      "pageInfo": {
        "endCursor": "example-value",
        "hasNextPage": true,
        "hasPreviousPage": true,
        "startCursor": "example-value"
      }
    }
  }
}

Mutations

Mutations create, update, or delete resources. Each mutation requires an IAM bearer token in the Authorization header.

addVirtualNetworkInterfaceToBareMetalNode

Adds a virtual network interface (VNI) to a bare metal Kubernetes worker node.

Returns and arguments for addVirtualNetworkInterfaceToBareMetalNode
Type Name Description
Returns AddVirtualNetworkInterfaceToBareMetalNodePayload
Argument input (AddVirtualNetworkInterfaceToBareMetalNodeInput!) (required) Input parameters for adding the VNI to a bare metal node.

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "mutation addVirtualNetworkInterfaceToBareMetalNode($input: AddVirtualNetworkInterfaceToBareMetalNodeInput!) {\n  addVirtualNetworkInterfaceToBareMetalNode(input: $input) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "input": "<AddVirtualNetworkInterfaceToBareMetalNodeInput>"
  }
}'

Example response

{
  "data": {
    "addVirtualNetworkInterfaceToBareMetalNode": {
      "networkAttachment": "<NetworkAttachment>"
    }
  }
}

createSatelliteConnector

Create a Satellite Connector.

Returns and arguments for createSatelliteConnector
Type Name Description
Returns CreateSatelliteConnectorPayload
Argument input (CreateSatelliteConnectorInput)

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "mutation createSatelliteConnector($input: CreateSatelliteConnectorInput) {\n  createSatelliteConnector(input: $input) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "input": "<CreateSatelliteConnectorInput>"
  }
}'

Example response

{
  "data": {
    "createSatelliteConnector": {
      "satelliteConnector": {
        "createdDate": "2025-01-01T00:00:00Z",
        "crn": "<CloudResourceName>",
        "id": "abc123",
        "name": "example-value",
        "region": {
          "displayName": "example-value",
          "id": "abc123",
          "name": "example-value"
        },
        "resourceGroup": {
          "externalID": "example-value",
          "id": "abc123",
          "name": "example-value"
        },
        "state": "CREATED"
      }
    }
  }
}

reinitializeKubernetesNode

Reinitialize a Kubernetes node. Not supported on VPC virtual server instances today.

Returns and arguments for reinitializeKubernetesNode
Type Name Description
Returns ReinitializeKubernetesNodePayload
Argument input (ReinitializeKubernetesNodeInput)

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "mutation reinitializeKubernetesNode($input: ReinitializeKubernetesNodeInput) {\n  reinitializeKubernetesNode(input: $input) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "input": "<ReinitializeKubernetesNodeInput>"
  }
}'

Example response

{
  "data": {
    "reinitializeKubernetesNode": {
      "node": "<KubernetesNode>"
    }
  }
}

removeSatelliteConnector

Remove a Satellite Connector.

Returns and arguments for removeSatelliteConnector
Type Name Description
Returns RemoveSatelliteConnectorPayload
Argument input (RemoveSatelliteConnectorInput)

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "mutation removeSatelliteConnector($input: RemoveSatelliteConnectorInput) {\n  removeSatelliteConnector(input: $input) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "input": "<RemoveSatelliteConnectorInput>"
  }
}'

Example response

{
  "data": {
    "removeSatelliteConnector": {
      "satelliteConnector": {
        "createdDate": "2025-01-01T00:00:00Z",
        "crn": "<CloudResourceName>",
        "id": "abc123",
        "name": "example-value",
        "region": {
          "displayName": "example-value",
          "id": "abc123",
          "name": "example-value"
        },
        "resourceGroup": {
          "externalID": "example-value",
          "id": "abc123",
          "name": "example-value"
        },
        "state": "CREATED"
      }
    }
  }
}

removeVirtualNetworkInterfaceFromNode

Removes a virtual network interface from a Kubernetes worker node.

Returns and arguments for removeVirtualNetworkInterfaceFromNode
Type Name Description
Returns RemoveVirtualNetworkInterfaceFromNodePayload
Argument input (RemoveVirtualNetworkInterfaceFromNodeInput!) (required) Input parameters for removing the VNI from a node.

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "mutation removeVirtualNetworkInterfaceFromNode($input: RemoveVirtualNetworkInterfaceFromNodeInput!) {\n  removeVirtualNetworkInterfaceFromNode(input: $input) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "input": "<RemoveVirtualNetworkInterfaceFromNodeInput>"
  }
}'

Example response

{
  "data": {
    "removeVirtualNetworkInterfaceFromNode": {
      "cluster": {
        "id": "abc123",
        "name": "example-value",
        "networkAttachments": {
          "edges": [
            {
              "cursor": "...",
              "node": "..."
            }
          ],
          "pageInfo": {
            "endCursor": "...",
            "hasNextPage": "...",
            "hasPreviousPage": "...",
            "startCursor": "..."
          }
        },
        "region": {
          "displayName": "example-value",
          "id": "abc123",
          "name": "example-value"
        }
      },
      "node": "<NetworkAttachable>",
      "virtualNetworkInterface": "<VirtualNetworkInterface>"
    }
  }
}

updateSatelliteLocation

Update a Satellite Location.

Returns and arguments for updateSatelliteLocation
Type Name Description
Returns UpdateSatelliteLocationPayload
Argument input (UpdateSatelliteLocationInput)

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "mutation updateSatelliteLocation($input: UpdateSatelliteLocationInput) {\n  updateSatelliteLocation(input: $input) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "input": "<UpdateSatelliteLocationInput>"
  }
}'

Example response

{
  "data": {
    "updateSatelliteLocation": {
      "satelliteLocation": {
        "description": "example-value",
        "id": "abc123",
        "name": "example-value"
      }
    }
  }
}

Object types

Object types represent the concrete resources and response payloads returned by the API.

Account

An IBM Cloud account.

Fields for Account
Type Name Description
Field externalID (String!) The account's IBM Cloud ID.

AddVirtualNetworkInterfaceToBareMetalNodePayload

Response payload for adding a VNI to a bare metal node.

Fields for AddVirtualNetworkInterfaceToBareMetalNodePayload
Type Name Description
Field networkAttachment (NetworkAttachment!) The created network attachment with its properties.

BareMetalNetworkAttachmentByVLAN

Network attachment for bare metal nodes using VLAN tagging.

Fields for BareMetalNetworkAttachmentByVLAN
Type Name Description
Implements NetworkAttachment
Field attachedTo (NetworkAttachable!) The bare metal node this interface is attached to.
Field canFloat (Boolean!) Whether this attachment can float between nodes in the cluster.
Field virtualNetworkInterface (VirtualNetworkInterface!) The virtual network interface that is attached.
Field vlanID (Int) VLAN ID used for this attachment (2-500). Null if not yet assigned.

BareMetalVirtualNetworkInterface

Virtual network interface attached to a bare metal server.

Fields for BareMetalVirtualNetworkInterface
Type Name Description
Implements VirtualNetworkInterface
Field autoDelete (Boolean) Whether the VNI should be automatically deleted when detached.
Field externalID (String!) The VPC resource ID of this VNI.
Field macAddress (MACAddress) MAC address assigned to this network interface.
Field name (String) Human-readable name of the VNI.
Field primaryIPAddress (IPv4Address) Primary IPv4 address assigned to this network interface.
Field securityGroups (SecurityGroupConnection)

Security groups applied to this network interface.
Arguments for securityGroups

  • after (String) — Cursor to start fetching from.
  • first (Int) — Maximum number of items to return.
Field subnet (Subnet!) The VPC subnet this network interface is connected to.

CreateSatelliteConnectorPayload

Output type for createSatelliteConnector.

Fields for CreateSatelliteConnectorPayload
Type Name Description
Field satelliteConnector (SatelliteConnector) The new SatelliteConnector.

KubernetesCluster

An IBM Cloud Kubernetes Service or IBM Cloud OpenShift Service cluster.

Fields for KubernetesCluster
Type Name Description
Implements Node
Field id (ID!) The cluster's unique identifier.
Field name (String) The cluster's name.
Field networkAttachments (NetworkAttachmentConnection)

Network attachments for this cluster (if applicable).
Arguments for networkAttachments

  • after (String) — Cursor to start fetching from.
  • first (Int) — Maximum number of items to return.
Field region (Region) The cluster's IBM Cloud catalog region.

Region

An IBM Cloud catalog region.

Fields for Region
Type Name Description
Implements Location
Implements Node
Field displayName (String) The translated name of this region.
Field id (ID!) The ID of this region.
Field name (String) The name of this region.

ReinitializeKubernetesNodePayload

Output type for reinitializeKubernetesNode.

Fields for ReinitializeKubernetesNodePayload
Type Name Description
Field node (KubernetesNode) The reinitializing Kubernetes node.

RemoveSatelliteConnectorPayload

Output type for removeSatelliteConnector.

Fields for RemoveSatelliteConnectorPayload
Type Name Description
Field satelliteConnector (SatelliteConnector) The removed SatelliteConnector.

RemoveVirtualNetworkInterfaceFromNodePayload

Response payload for removing a VNI from a node.

Fields for RemoveVirtualNetworkInterfaceFromNodePayload
Type Name Description
Field cluster (KubernetesCluster!) The cluster the VNI was removed from.
Field node (NetworkAttachable!) The node the VNI was removed from.
Field virtualNetworkInterface (VirtualNetworkInterface!) The virtual network interface that was removed.

ResourceGroup

A ResourceGroup is a way for you to organize your account resources in customizable groupings so that you can quickly assign users access to multiple resources at a time.

Fields for ResourceGroup
Type Name Description
Implements Node
Field externalID (String!) The resource group's IBM Cloud ID.
Field id (ID!) The resource group's Node ID.
Field name (String) The resource group's name.

SatelliteConnector

A Satellite Connector provides a secure connection between a specific remote location and IBM Cloud.

Fields for SatelliteConnector
Type Name Description
Implements Node
Field createdDate (DateTime) The date when this resource was created.
Field crn (CloudResourceName) The resource's IBM Cloud CRN.
Field id (ID!) The resource's unique identifier.
Field name (String!) The resource's name.
Field region (Region) The region the resource is managed from.
Field resourceGroup (ResourceGroup) The resource group containing this resource.
Field state (SatelliteConnectorState) The current state of this resource.

SatelliteLocation

A Satellite Location.

Fields for SatelliteLocation
Type Name Description
Implements Node
Field description (String) The Location description.
Field id (ID!) The resource's unique identifier.
Field name (String) The Location name.

SecurityGroup

Represents a VPC security group.

Fields for SecurityGroup
Type Name Description
Field externalID (String!) The VPC resource ID of this security group.

Subnet

Represents a VPC subnet.

Fields for Subnet
Type Name Description
Field externalID (String!) The VPC resource ID of this subnet.

UpdateSatelliteLocationPayload

Output type for updateSatelliteLocation.

Fields for UpdateSatelliteLocationPayload
Type Name Description
Field satelliteLocation (SatelliteLocation) The updated SatelliteLocation.

VPCBareMetalKubernetesNode

Represents a bare metal Kubernetes worker node in IBM Cloud VPC.

Fields for VPCBareMetalKubernetesNode
Type Name Description
Implements KubernetesNode
Implements NetworkAttachable
Implements Node
Field id (ID!) Globally unique identifier for this worker node.
Field networkAttachments (NetworkAttachmentConnection)

Network attachments for this bare metal node.
Arguments for networkAttachments

  • after (String) — Cursor to start fetching from.
  • first (Int) — Maximum number of items to return.
Field region (Region)

Interface types

Interface types define common fields that are shared across multiple concrete object types.

KubernetesNode

A Kubernetes Node runs your workload.

Fields for KubernetesNode
Type Name Description
Implementation KubernetesNode
Implementation VPCBareMetalKubernetesNode
Field id (ID!) The resource's unique identifier.
Field region (Region)

Location

An IBM Cloud catalog location.

Fields for Location
Type Name Description
Implementation Location
Implementation Region
Field displayName (String) Translated name of this location.
Field id (ID!) The ID of this location.
Field name (String) Name of this location.

NetworkAttachable

Represents an entity that can have network interfaces attached to it.

Fields for NetworkAttachable
Type Name Description
Implementation NetworkAttachable
Field id (ID!) Globally unique identifier for this node.
Field networkAttachments (NetworkAttachmentConnection)

Network attachments associated to this node.
Arguments for networkAttachments

  • after (String) — Cursor to start fetching from.
  • first (Int) — Maximum number of items to return.

NetworkAttachment

Represents a network interface attachment to a node.

Fields for NetworkAttachment
Type Name Description
Implementation BareMetalNetworkAttachmentByVLAN
Implementation NetworkAttachment
Field attachedTo (NetworkAttachable!) The node this network interface is attached to.
Field virtualNetworkInterface (VirtualNetworkInterface!) The virtual network interface that is attached.

Node

Fetches an object given its ID.

Fields for Node
Type Name Description
Implementation KubernetesCluster
Implementation KubernetesNode
Implementation NetworkAttachable
Implementation Node
Implementation Region
Implementation ResourceGroup
Implementation SatelliteConnector
Implementation SatelliteLocation
Implementation VPCBareMetalKubernetesNode
Field id (ID!) The globally unique object ID.

VirtualNetworkInterface

Represents a virtual network interface in IBM Cloud VPC. Can be attached to bare metal or virtual server instances.

Fields for VirtualNetworkInterface
Type Name Description
Implementation BareMetalVirtualNetworkInterface
Implementation VirtualNetworkInterface
Field autoDelete (Boolean) Whether the VNI should be automatically deleted when detached.
Field externalID (String!) The VPC resource ID of this virtual network interface.
Field macAddress (MACAddress) MAC address assigned to this network interface.
Field name (String) Human-readable name of the VNI.
Field primaryIPAddress (IPv4Address) Primary IPv4 address assigned to this network interface.
Field securityGroups (SecurityGroupConnection)

Security groups applied to this network interface.
Arguments for securityGroups

  • after (String) — Cursor to start fetching from.
  • first (Int) — Maximum number of items to return.
Field subnet (Subnet!) The VPC subnet this network interface is connected to.

Input types

Input types are used as arguments to mutations. Fields marked (required) must be provided.

AddVirtualNetworkInterfaceToBareMetalNodeInput

Input for adding a VNI to a bare metal node.

Input fields for AddVirtualNetworkInterfaceToBareMetalNodeInput
Type Name Description
Field autoDelete (Boolean) Whether to automatically delete the VNI from VPC when it is detached. Defaults to false if not specified.
Field cluster (ID) Cluster ID. Either cluster or node must be specified, but not both. If only cluster is provided, a node will be auto-selected and the attachment will float.
Field node (ID) Node ID. Either cluster or node must be specified, but not both. If specified, creates a non-floating attachment to this specific node.
Field virtualNetworkInterfaceID (String!) (required) The VPC resource ID of the virtual network interface to attach.
Field vlanID (Int!) (required) VLAN ID for the attachment (2-500). VLAN 1 is reserved for the primary network interface.

CreateSatelliteConnectorInput

Details needed to provision a Satellite Connector.

Input fields for CreateSatelliteConnectorInput
Type Name Description
Field name (String!) (required) The resource's name.
Field regionName (String!) (required) The region name indicating where the new connector should be managed from.
Field resourceGroupID (String!) (required) The resource group ID to provision inside.

ReinitializeKubernetesNodeInput

Input type for reinitializeKubernetesNode.

Input fields for ReinitializeKubernetesNodeInput
Type Name Description
Field bypassUnhealthyControlPlane (Boolean) Set to true to proceed with reinitialization, even when the cluster's control plane is unhealthy.
Field id (ID!) (required) Kubernetes node to reinitialize.

RemoveSatelliteConnectorInput

Input type for removeSatelliteConnector.

Input fields for RemoveSatelliteConnectorInput
Type Name Description
Field id (ID!) (required) Satellite Connector ID to remove.

RemoveVirtualNetworkInterfaceFromNodeInput

Input for removing a VNI from a node.

Input fields for RemoveVirtualNetworkInterfaceFromNodeInput
Type Name Description
Field cluster (ID) Cluster ID. Either cluster or node must be specified, but not both.
Field node (ID) Node ID. Either cluster or node must be specified, but not both.
Field virtualNetworkInterfaceID (String!) (required) The VPC resource ID of the virtual network interface to remove.

UpdateSatelliteLocationInput

Input type for updateSatelliteLocation.

Input fields for UpdateSatelliteLocationInput
Type Name Description
Field description (String)
Field id (ID!) (required) Satellite Location ID to update.
Field name (String)

Enum types

Enum types define the set of allowed string values for a field.

SatelliteConnectorState

The administrative state of a Satellite Connector.

The values are expected to expand in the future. When processing, check for and log unknown values. Optionally halt processing and surface the error, or bypass the Satellite Connector on which the unexpected value was encountered.

Values for SatelliteConnectorState
Type Name Description
Value CREATED The connector has completed provisioning and is ready to use.
Value CREATING The connector is provisioning and may not be ready to use.
Value DELETING The connector is deprovisioning and may be unavailable.
Value FAILED The connector's most recent operation has failed and it must be deleted to continue.

Scalar types

Scalar types are primitive leaf values in the GraphQL schema.

CloudResourceName

A Cloud Resource Name (CRN) uniquely identifies IBM Cloud resources. A CRN is used to specify a resource in an unambiguous way that is guaranteed to be globally unique.

DateTime

A DateTime is an RFC3339 compliant combination of a date and time.

IPv4Address

IPv4 address in dotted-decimal notation (e.g., 192.168.1.1).

MACAddress

MAC address in colon-hexadecimal notation (e.g., 00:1A:2B:3C:4D:5E).

Internal queries

The following queries are for internal use only and are not supported for external callers. They are documented here for completeness.

globalSearchSatelliteConnectorAccounts

Globally searchable results for the IBM Global Search service. Internal use only.

Returns and arguments for globalSearchSatelliteConnectorAccounts
Type Name Description
Returns GlobalSearchSatelliteConnectorAccountsConnection
Argument after (String)
Argument first (Int)
Argument last (Int)
Argument before (String)
Argument regionName (String!) (required)

Example request

curl -X POST https://containers.cloud.ibm.com/graphql \
  -H "Authorization: Bearer $IAM_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "query": "query globalSearchSatelliteConnectorAccounts($after: String, $first: Int, $last: Int, $before: String, $regionName: String!) {\n  globalSearchSatelliteConnectorAccounts(after: $after, first: $first, last: $last, before: $before, regionName: $regionName) {\n    # ... select your fields here\n  }\n}",
  "variables": {
    "after": "example-value",
    "first": 0,
    "last": 0,
    "before": "example-value",
    "regionName": "example-value"
  }
}'

Example response

{
  "data": {
    "globalSearchSatelliteConnectorAccounts": {
      "edges": [
        {
          "cursor": "example-value",
          "node": {
            "externalID": "example-value"
          }
        }
      ],
      "pageInfo": {
        "endCursor": "example-value",
        "hasNextPage": true,
        "hasPreviousPage": true,
        "startCursor": "example-value"
      }
    }
  }
}