Export All Modules to Seed Files
Exports every module's endpoint permissions and writes each one to $DATA_DIR/rbac/<module>.rbac.yaml on the server. Takes no body. A module that fails to export or write is reported in errors and does not fail the request, so a 200 does not mean every module was written - compare success_count with total_modules.
Authorization
BearerAuth In: header
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/rbac/endpoint-role/export/modules"{
"message": "Exported 12 modules",
"exported_files": {
"customers": "/data/rbac/customers.rbac.yaml"
},
"errors": {},
"total_modules": 12,
"success_count": 12,
"error_count": 0
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"status": 400,
"code": "rbac_m.endpoint_not_found",
"message": "Invalid input",
"details": [
{
"field": "roles",
"rule": "required",
"param": "string",
"message": "roles is required"
}
],
"class": "validation",
"retryable": false
}{
"overall_status": "unhealthy",
"message": "Service is shutting down",
"timestamp": "2019-08-24T14:15:22Z"
}Assigns one or more roles to a specific API endpoint. Existing assignments are preserved (additive). **Important:** This operation is atomic - if ANY role fails to assign (e.g., role not found), the ENTIRE operation is rejected and NO roles are assigned. This prevents partial/inconsistent permission states.
Generates one YAML seed snippet covering the listed endpoints. The response is the YAML itself, not JSON: the module name is repeated in the X-Module-Name header and in the Content-Disposition filename, which the Configurator uses when saving the download. Partial failure is not an error. An entry that names no active endpoint — or whose role lookup fails — is dropped and the export succeeds with 200 covering the rest; the only signal is a `# Note: N endpoints could not be exported` comment line in the YAML, and which ones failed appears in the server log only. The request fails with 404 only when NONE of the listed endpoints resolves.