Appearance
List all rules for a component
GET
/components/{componentId}/rules
Returns all rules in the component with full content fields (title, fixtext, check_content, vuln_discussion, etc.). Used by the component editor to populate the rule list. Requires project membership.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
All component rules
application/json
JSON { "id": 100, "rule_id": "CNTR-00-000050", "title": "Container images must be signed", "status": "Applicable - Configurable", "locked": false, "satisfies": [ ], "satisfied_by": [ ] }, { "id": 101, "rule_id": "CNTR-00-000051", "title": "Container images must come from approved registries", "status": "Applicable - Configurable", "locked": false, "satisfies": [ ], "satisfied_by": [ ] }
[
]
Create a new requirement in a component
POST
/components/{componentId}/rules
Creates a requirement in one call, shaped by the component's document_type — a STIG rule (seeded from the source SRG's CCI-000366 baseline row; severity and weight are inherited from it) or an authored SRG requirement. Content fields apply at creation: provided values win over seeded defaults, and provided nested attributes replace the built defaults. Duplicate mode copies an existing requirement of THIS component. Requirement numbers are server-owned and assigned from the component's sequence. Blank/content creation requires project admin; duplication requires author. Returns 422 when a STIG component's source SRG has no CCI-000366 baseline row, or when provided content fails the kind's validations.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "rule": { "duplicate": false }
{
}
Responses
Rule created
application/json
JSON "toast": { "title": "Control created.", "message": [ "Successfully created control." ], "variant": "success" }, "data": { "id": 5000, "rule_id": "000204", "title": "New container security requirement", "status": "Not Yet Determined", "locked": false, "satisfies": [ ], "satisfied_by": [ ] }
{
}
Lightweight rule list for picker UI
GET
/components/{componentId}/rules_picker
Returns a compact list of requirements for dropdown/picker selection (e.g., the move-to-rule admin action or duplicate-of picker). Lighter than the full rules list — omits content fields. Rows are shaped by the component's document_type: STIG rule objects carry the satisfaction relationships, authored SRG requirement objects omit them entirely. Requires project membership.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
Requirements for picker selection
application/json
JSON "rules": [ { "id": 100, "rule_id": "000050", "displayed_name": "CNTR-00-000050", "title": "Container images must be signed", "locked": false, "satisfies": [ ], "satisfied_by": [ ] }, { "id": 101, "rule_id": "000051", "displayed_name": "CNTR-00-000051", "title": "Container images must come from approved registries", "locked": true, "satisfies": [ ], "satisfied_by": [ ] } ]
{
}
Rule detail
GET
/rules/{ruleId}
Returns the full requirement editor payload for either document kind — checks, descriptions, and review history for both; satisfactions (satisfies/satisfied_by) appear on stig rules only, and authored SRG requirements omit those keys entirely.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
Rule data
application/json
JSON "id": 1786, "rule_id": "000001", "title": "The operating system must provide automated mechanisms for supporting account management functions.", "version": "SRG-OS-000001-GPOS-00001", "status": "Not Yet Determined", "rule_severity": "medium", "locked": true, "review_requestor_id": 0, "changes_requested": false, "comment_summary": { "open": 0, "total": 0 }, "rule_weight": "10.0", "fixtext": "Configure the operating system to provide automated mechanisms...", "fixtext_fixref": "F-3716r557030_fix", "ident": "CCI-000015", "ident_system": "http://cyber.mil/cci", "vendor_comments": "string", "vuln_id": "string", "legacy_ids": "V-56571, SV-70831", "component_id": 1, "status_justification": "string", "artifact_description": "string", "locked_fields": { "additionalProperties": true }, "nist_control_family": "AC-2 (1)", "srg_id": "SRG-OS-000001-GPOS-00001", "inspec_control_body": "string", "inspec_control_file": "string", "inspec_control_body_lang": "ruby", "inspec_control_file_lang": "ruby", "fix_id": "F-3716r557030_fix", "disa_rule_descriptions_attributes": [ { "id": 300, "vuln_discussion": "Without verification, containers may execute untrusted code...", "false_positives": "string", "false_negatives": "string", "documentable": false, "mitigations": "string", "severity_override_guidance": "string", "potential_impacts": "string", "third_party_tools": "string", "mitigation_control": "string", "responsibility": "string", "ia_controls": "string", "mitigations_available": "string", "poam_available": "string", "poam": "string", "_destroy": false } ], "checks_attributes": [ { "id": 200, "system": "C-56947r840354_chk", "content_ref_name": "M", "content_ref_href": "DPMS_XCCDF-Container_Platform_SRG.xml", "content": "Verify the container platform restricts access to container images...", "_destroy": false } ], "satisfies": [ { "id": 50, "rule_id": 100, "srg_id": "CNTR-00-000050" } ], "satisfied_by": [ { "id": 50, "rule_id": 100, "srg_id": "CNTR-00-000050", "fixtext": "Configure the container platform to restrict access..." } ], "histories": [ { "id": 224, "action": "update", "auditable_type": "Component", "auditable_id": 1, "name": "Demo Admin", "audited_name": "string", "comment": "string", "created_at": "2026-05-19 14:07:49 UTC", "audited_changes": [ { "field": "released", "prev_value": false, "new_value": true } ] } ], "rule_descriptions_attributes": [ { "id": 400, "description": "<VulnDiscussion>Without verification, containers may execute untrusted code.</VulnDiscussion>", "_destroy": false } ], "reviews": [ { "id": 1, "action": "comment", "comment": "The check says "verify that TLS 1.2 or greater is being used" but does not specify HOW to verify.", "created_at": "2026-05-19 14:08:17 UTC", "triage_status": "pending", "triage_set_at": "string", "adjudicated_at": "string", "rule_id": 2976, "section": "check_content", "responding_to_review_id": 0, "duplicate_of_review_id": 0, "addressed_by_rule_id": 0, "triage_set_by_id": 0, "name": "Demo Viewer", "author_name": "Demo Viewer", "triager_display_name": "string", "triager_imported": false, "adjudicator_display_name": "string", "adjudicator_imported": false, "commenter_display_name": "Demo Viewer", "commenter_imported": false, "commentable_type": "BaseRule", "responses_count": 0, "rule_displayed_name": "PHOS-03-000001", "author_email": "string", "commenter_email": "string", "reactions": { "up": 1, "down": 0, "mine": "string" } } ], "additional_answers_attributes": [ { "id": 10, "additional_question_id": 3, "answer": "Yes, this applies to all container runtime environments." } ], "srg_rule_attributes": { "id": 500, "rule_id": "SV-222396r857506_rule", "title": "The container platform must enforce approved authorizations for access.", "version": "CNTR-00-000050", "rule_severity": "medium", "rule_weight": "10.0", "ident": "CCI-000213", "ident_system": "http://cyber.mil/cci", "fixtext": "Configure the container platform to enforce approved authorizations...", "fixtext_fixref": "F-25073r857505_fix", "fix_id": "F-25073r857505_fix", "inspec_control_body": "string", "inspec_control_file": "string", "inspec_control_body_lang": "string", "inspec_control_file_lang": "string", "vuln_id": "V-222396", "legacy_ids": "SV-42474, V-32157", "rule_descriptions_attributes": [ { "id": 400, "description": "<VulnDiscussion>Without verification, containers may execute untrusted code.</VulnDiscussion>", "_destroy": false } ], "disa_rule_descriptions_attributes": [ { "id": 300, "vuln_discussion": "Without verification, containers may execute untrusted code...", "false_positives": "string", "false_negatives": "string", "documentable": false, "mitigations": "string", "severity_override_guidance": "string", "potential_impacts": "string", "third_party_tools": "string", "mitigation_control": "string", "responsibility": "string", "ia_controls": "string", "mitigations_available": "string", "poam_available": "string", "poam": "string", "_destroy": false } ], "checks_attributes": [ { "id": 200, "system": "C-56947r840354_chk", "content_ref_name": "M", "content_ref_href": "DPMS_XCCDF-Container_Platform_SRG.xml", "content": "Verify the container platform restricts access to container images...", "_destroy": false } ] }, "srg_info": { "version": "V2R4" }
{
}
Full replacement of rule attributes
PUT
/rules/{ruleId}
Full replacement — all fields required. Updates rule fields. Requires author or admin role on the component.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "rule": { "status": "Applicable - Configurable", "title": "The container platform must enforce approved authorizations.", "fixtext": "Configure the container platform to enforce approved authorizations.", "vendor_comments": "Met by the recommended runtime configuration." }
{
}
Responses
Rule updated
application/json
JSON "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Soft-delete a rule
DELETE
/rules/{ruleId}
Marks the rule as deleted. Requires admin role on the component.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
Rule deleted
application/json
JSON "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Partial update of rule attributes
PATCH
/rules/{ruleId}
Partial update — send only changed fields. Updates one or more rule fields. Requires author or admin role on the component.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "rule": { "status": "Applicable - Configurable", "vendor_comments": "Met by the recommended runtime configuration." }
{
}
Responses
Rule updated
application/json
JSON "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Revert requirement fields to a previous audit version
POST
/rules/{ruleId}/revert
Restores the named audited fields to their prior values from the specified history entry. Applies to both document kinds — stig rules and authored SRG requirements. Requires author or admin role.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "audit_id": 4211, "fields": [ [ "title" ] ], "audit_comment": "Restore the original wording"
{
}
Responses
Rule reverted
application/json
JSON "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Lock or unlock a single section on a rule
PATCH
/rules/{ruleId}/section_locks
Locks or unlocks a single section (e.g., Fix, Check) on a rule. Requires reviewer role or higher on the parent component. Creates an audit entry.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "section": "Fix", "locked": true, "comment": "Locking the Fix section for final review"
{
}
Responses
Section locks updated
application/json
JSON "rule": { "id": 1786, "rule_id": "000001", "title": "The operating system must provide automated mechanisms for supporting account management functions.", "version": "SRG-OS-000001-GPOS-00001", "status": "Not Yet Determined", "rule_severity": "medium", "locked": true, "review_requestor_id": 0, "changes_requested": false, "comment_summary": { "open": 0, "total": 0 }, "rule_weight": "10.0", "fixtext": "Configure the operating system to provide automated mechanisms...", "fixtext_fixref": "F-3716r557030_fix", "ident": "CCI-000015", "ident_system": "http://cyber.mil/cci", "vendor_comments": "string", "vuln_id": "string", "legacy_ids": "V-56571, SV-70831", "component_id": 1, "status_justification": "string", "artifact_description": "string", "locked_fields": { "additionalProperties": true }, "nist_control_family": "AC-2 (1)", "srg_id": "SRG-OS-000001-GPOS-00001", "inspec_control_body": "string", "inspec_control_file": "string", "inspec_control_body_lang": "ruby", "inspec_control_file_lang": "ruby", "fix_id": "F-3716r557030_fix", "disa_rule_descriptions_attributes": [ { "id": 300, "vuln_discussion": "Without verification, containers may execute untrusted code...", "false_positives": "string", "false_negatives": "string", "documentable": false, "mitigations": "string", "severity_override_guidance": "string", "potential_impacts": "string", "third_party_tools": "string", "mitigation_control": "string", "responsibility": "string", "ia_controls": "string", "mitigations_available": "string", "poam_available": "string", "poam": "string", "_destroy": false } ], "checks_attributes": [ { "id": 200, "system": "C-56947r840354_chk", "content_ref_name": "M", "content_ref_href": "DPMS_XCCDF-Container_Platform_SRG.xml", "content": "Verify the container platform restricts access to container images...", "_destroy": false } ], "satisfies": [ { "id": 50, "rule_id": 100, "srg_id": "CNTR-00-000050" } ], "satisfied_by": [ { "id": 50, "rule_id": 100, "srg_id": "CNTR-00-000050", "fixtext": "Configure the container platform to restrict access..." } ], "histories": [ { "id": 224, "action": "update", "auditable_type": "Component", "auditable_id": 1, "name": "Demo Admin", "audited_name": "string", "comment": "string", "created_at": "2026-05-19 14:07:49 UTC", "audited_changes": [ { "field": "released", "prev_value": false, "new_value": true } ] } ], "rule_descriptions_attributes": [ { "id": 400, "description": "<VulnDiscussion>Without verification, containers may execute untrusted code.</VulnDiscussion>", "_destroy": false } ], "reviews": [ { "id": 1, "action": "comment", "comment": "The check says "verify that TLS 1.2 or greater is being used" but does not specify HOW to verify.", "created_at": "2026-05-19 14:08:17 UTC", "triage_status": "pending", "triage_set_at": "string", "adjudicated_at": "string", "rule_id": 2976, "section": "check_content", "responding_to_review_id": 0, "duplicate_of_review_id": 0, "addressed_by_rule_id": 0, "triage_set_by_id": 0, "name": "Demo Viewer", "author_name": "Demo Viewer", "triager_display_name": "string", "triager_imported": false, "adjudicator_display_name": "string", "adjudicator_imported": false, "commenter_display_name": "Demo Viewer", "commenter_imported": false, "commentable_type": "BaseRule", "responses_count": 0, "rule_displayed_name": "PHOS-03-000001", "author_email": "string", "commenter_email": "string", "reactions": { "up": 1, "down": 0, "mine": "string" } } ], "additional_answers_attributes": [ { "id": 10, "additional_question_id": 3, "answer": "Yes, this applies to all container runtime environments." } ], "srg_rule_attributes": { "id": 500, "rule_id": "SV-222396r857506_rule", "title": "The container platform must enforce approved authorizations for access.", "version": "CNTR-00-000050", "rule_severity": "medium", "rule_weight": "10.0", "ident": "CCI-000213", "ident_system": "http://cyber.mil/cci", "fixtext": "Configure the container platform to enforce approved authorizations...", "fixtext_fixref": "F-25073r857505_fix", "fix_id": "F-25073r857505_fix", "inspec_control_body": "string", "inspec_control_file": "string", "inspec_control_body_lang": "string", "inspec_control_file_lang": "string", "vuln_id": "V-222396", "legacy_ids": "SV-42474, V-32157", "rule_descriptions_attributes": [ { "id": 400, "description": "<VulnDiscussion>Without verification, containers may execute untrusted code.</VulnDiscussion>", "_destroy": false } ], "disa_rule_descriptions_attributes": [ { "id": 300, "vuln_discussion": "Without verification, containers may execute untrusted code...", "false_positives": "string", "false_negatives": "string", "documentable": false, "mitigations": "string", "severity_override_guidance": "string", "potential_impacts": "string", "third_party_tools": "string", "mitigation_control": "string", "responsibility": "string", "ia_controls": "string", "mitigations_available": "string", "poam_available": "string", "poam": "string", "_destroy": false } ], "checks_attributes": [ { "id": 200, "system": "C-56947r840354_chk", "content_ref_name": "M", "content_ref_href": "DPMS_XCCDF-Container_Platform_SRG.xml", "content": "Verify the container platform restricts access to container images...", "_destroy": false } ] }, "srg_info": { "version": "V2R4" } }, "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Bulk update locked sections
PATCH
/rules/{ruleId}/bulk_section_locks
Locks or unlocks multiple sections at once on a rule. Requires reviewer role or higher on the parent component. Creates an audit trail entry.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "sections": [ [ "Fix", "Check" ] ], "locked": true, "comment": "Locking the Fix and Check sections for review"
{
}
Responses
Section locks updated, returns updated rule + toast
application/json
JSON "rule": { "id": 1786, "rule_id": "000001", "title": "The operating system must provide automated mechanisms for supporting account management functions.", "version": "SRG-OS-000001-GPOS-00001", "status": "Not Yet Determined", "rule_severity": "medium", "locked": true, "review_requestor_id": 0, "changes_requested": false, "comment_summary": { "open": 0, "total": 0 }, "rule_weight": "10.0", "fixtext": "Configure the operating system to provide automated mechanisms...", "fixtext_fixref": "F-3716r557030_fix", "ident": "CCI-000015", "ident_system": "http://cyber.mil/cci", "vendor_comments": "string", "vuln_id": "string", "legacy_ids": "V-56571, SV-70831", "component_id": 1, "status_justification": "string", "artifact_description": "string", "locked_fields": { "additionalProperties": true }, "nist_control_family": "AC-2 (1)", "srg_id": "SRG-OS-000001-GPOS-00001", "inspec_control_body": "string", "inspec_control_file": "string", "inspec_control_body_lang": "ruby", "inspec_control_file_lang": "ruby", "fix_id": "F-3716r557030_fix", "disa_rule_descriptions_attributes": [ { "id": 300, "vuln_discussion": "Without verification, containers may execute untrusted code...", "false_positives": "string", "false_negatives": "string", "documentable": false, "mitigations": "string", "severity_override_guidance": "string", "potential_impacts": "string", "third_party_tools": "string", "mitigation_control": "string", "responsibility": "string", "ia_controls": "string", "mitigations_available": "string", "poam_available": "string", "poam": "string", "_destroy": false } ], "checks_attributes": [ { "id": 200, "system": "C-56947r840354_chk", "content_ref_name": "M", "content_ref_href": "DPMS_XCCDF-Container_Platform_SRG.xml", "content": "Verify the container platform restricts access to container images...", "_destroy": false } ], "satisfies": [ { "id": 50, "rule_id": 100, "srg_id": "CNTR-00-000050" } ], "satisfied_by": [ { "id": 50, "rule_id": 100, "srg_id": "CNTR-00-000050", "fixtext": "Configure the container platform to restrict access..." } ], "histories": [ { "id": 224, "action": "update", "auditable_type": "Component", "auditable_id": 1, "name": "Demo Admin", "audited_name": "string", "comment": "string", "created_at": "2026-05-19 14:07:49 UTC", "audited_changes": [ { "field": "released", "prev_value": false, "new_value": true } ] } ], "rule_descriptions_attributes": [ { "id": 400, "description": "<VulnDiscussion>Without verification, containers may execute untrusted code.</VulnDiscussion>", "_destroy": false } ], "reviews": [ { "id": 1, "action": "comment", "comment": "The check says "verify that TLS 1.2 or greater is being used" but does not specify HOW to verify.", "created_at": "2026-05-19 14:08:17 UTC", "triage_status": "pending", "triage_set_at": "string", "adjudicated_at": "string", "rule_id": 2976, "section": "check_content", "responding_to_review_id": 0, "duplicate_of_review_id": 0, "addressed_by_rule_id": 0, "triage_set_by_id": 0, "name": "Demo Viewer", "author_name": "Demo Viewer", "triager_display_name": "string", "triager_imported": false, "adjudicator_display_name": "string", "adjudicator_imported": false, "commenter_display_name": "Demo Viewer", "commenter_imported": false, "commentable_type": "BaseRule", "responses_count": 0, "rule_displayed_name": "PHOS-03-000001", "author_email": "string", "commenter_email": "string", "reactions": { "up": 1, "down": 0, "mine": "string" } } ], "additional_answers_attributes": [ { "id": 10, "additional_question_id": 3, "answer": "Yes, this applies to all container runtime environments." } ], "srg_rule_attributes": { "id": 500, "rule_id": "SV-222396r857506_rule", "title": "The container platform must enforce approved authorizations for access.", "version": "CNTR-00-000050", "rule_severity": "medium", "rule_weight": "10.0", "ident": "CCI-000213", "ident_system": "http://cyber.mil/cci", "fixtext": "Configure the container platform to enforce approved authorizations...", "fixtext_fixref": "F-25073r857505_fix", "fix_id": "F-25073r857505_fix", "inspec_control_body": "string", "inspec_control_file": "string", "inspec_control_body_lang": "string", "inspec_control_file_lang": "string", "vuln_id": "V-222396", "legacy_ids": "SV-42474, V-32157", "rule_descriptions_attributes": [ { "id": 400, "description": "<VulnDiscussion>Without verification, containers may execute untrusted code.</VulnDiscussion>", "_destroy": false } ], "disa_rule_descriptions_attributes": [ { "id": 300, "vuln_discussion": "Without verification, containers may execute untrusted code...", "false_positives": "string", "false_negatives": "string", "documentable": false, "mitigations": "string", "severity_override_guidance": "string", "potential_impacts": "string", "third_party_tools": "string", "mitigation_control": "string", "responsibility": "string", "ia_controls": "string", "mitigations_available": "string", "poam_available": "string", "poam": "string", "_destroy": false } ], "checks_attributes": [ { "id": 200, "system": "C-56947r840354_chk", "content_ref_name": "M", "content_ref_href": "DPMS_XCCDF-Container_Platform_SRG.xml", "content": "Verify the container platform restricts access to container images...", "_destroy": false } ] }, "srg_info": { "version": "V2R4" } }, "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Find rules sharing the same SRG requirement
GET
/rules/{ruleId}/search/related_rules
Returns rules from other components and published STIGs that implement the same SRG requirement (matched by version/srg_id). Results are scoped to components the current user can access unless the user is an admin. The rules array is a mix of RuleEditorResponse (component rules) and StigRuleSummary (published STIG rules). The parents array is a mix of ComponentBlueprint :related and StigBlueprint :index for grouping. Stig rules only — the search keys off the stig rule's SRG-version linkage, so requests for an authored SRG requirement return 404 (no related-rules surface exists for that kind).
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
Related rules with parent containers
application/json
JSON "rules": [ { "id": 200, "rule_id": "SV-222387r960735_rule", "title": "The application must limit logon sessions", "version": "APSC-DV-000010", "rule_severity": "medium" }, { "id": 1800, "rule_id": "000001", "title": "The operating system must provide automated mechanisms", "status": "Not Yet Determined", "component_id": 1 } ], "parents": [ { "id": 1, "stig_id": "Application_Security_Development_STIG", "name": "Application Security Development STIG - Ver 6, Rel 4", "title": "Application Security and Development STIG" }, { "id": 1, "name": "Photon OS 3", "prefix": "PHOS-03", "project": { "id": 1, "name": "Photon 3" } } ]
{
}
Create a satisfaction relationship between two rules
POST
/rule_satisfactions
Links a child rule to a parent rule that satisfies it. Triggers ADNM status automation on the child.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "rule_id": 101, "satisfied_by_rule_id": 102
{
}
Responses
Satisfaction created
application/json
JSON "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Remove a satisfaction relationship
DELETE
/rule_satisfactions/{ruleId}
Removes the parent-child satisfaction link and reverts ADNM status on the child rule.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "rule_id": 0, "satisfied_by_rule_id": 0
{
}
Responses
Satisfaction removed
application/json
JSON "toast": { "title": "User updated.", "message": [ [ "Successfully updated user." ] ], "variant": "success" }
{
}
Propose relocating an authored SRG requirement
POST
/rules/{ruleId}/relocations
Creates an OPEN relocation proposal for an authored requirement of an SRG component, naming the destination SRG's abbreviation. Requires author role on the component. One open proposal per requirement; a second returns 422. The proposal is a record, never a status change on the requirement — the destination SRG's authors concur or non-concur.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "requirement_relocation": { "target_technology_token": "CTR" }
{
}
Responses
Relocation proposed
application/json
JSON "toast": { "title": "Relocation proposed.", "message": [ "Proposed for the CTR SRG." ], "variant": "success" }
{
}
List the open relocation-proposal backlog
GET
/requirement_relocations
Returns relocation proposals, optionally filtered to one destination SRG's abbreviation — the standing per-SRG backlog and the creation/open-time prompt count both read this. Rows are scoped to projects the caller can see. Executed records are immutable history and never listed.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Parameters
Query Parameters
target_technology_token
The destination SRG's abbreviation to filter by.
Type
string
Example
"CTR"Responses
Open proposals (and retained declines), oldest first
application/json
JSON { "id": 12, "source_rule_id": 5137, "target_technology_token": "CTR", "created_at": "2026-07-20 15:36:06 UTC", "source_displayed_name": "CNTR-00-000051", "component_id": 42, "component_name": "Container Platform SRG", "requested_by_name": "Jane Doe" }
[
]
List destination SRG options for the propose flow
GET
/requirement_relocations/destinations
Serves the Destination SRG picker: one row per SRG abbreviation across the SRG components in projects the caller can see (member or discoverable). An open component wins its abbreviation's row; released true marks the queued next-release case. Hidden projects' SRGs never appear — proposing to them remains possible through the free abbreviation entry, which discloses nothing.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
Destination options, ordered by abbreviation
application/json
JSON { "token": "CTR", "name": "Container Platform SRG", "released": false }, { "token": "GPOS", "name": "General Purpose Operating System SRG", "released": true }
[
]
Un-mark a requirement for relocation
DELETE
/requirement_relocations/{id}
Destroys a PENDING relocation record, removing the move marker. Audited. Requires author role on the source component. Executed records are immutable — they answer 404 exactly like a record that never existed.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Responses
Marker removed
application/json
JSON "toast": { "title": "Relocation marker removed.", "message": [ "The requirement is no longer marked for relocation." ], "variant": "success" }
{
}
Preview accepting a relocation with zero writes
POST
/requirement_relocations/{id}/dry_run
Returns exactly what accepting the proposal would do for this destination component — or every reason it cannot run — without writing anything. This preview is the adjudication review artifact. Requires author role on the DESTINATION component only. Adjudicated proposals (declined or executed) answer 404 like a record that never existed.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "target_component_id": 42
{
}
Responses
The preview, valid or not
application/json
JSON "valid": true, "errors": [ ], "source_displayed_name": "CNTR-00-000051", "target_component_id": 42, "target_component_name": "Container Platform SRG", "would_create": { "title": "The application must enforce approved authorizations", "status": "Applicable", "derived_from_srg_rule_id": 5137 }, "would_tombstone_source": true
{
}
Concur with a relocation proposal — land the requirement
POST
/requirement_relocations/{id}/accept
Receiver-side adjudication (displayed as Concur): acceptance and landing are ONE transaction — creates the requirement in the destination component with content and core lineage carried over, tombstones the source row, and stamps the record executed with the accepting actor — atomically, or not at all. Requires author role on the DESTINATION component only; the proposal itself carries source consent. Audited. Adjudicated proposals (declined or executed) answer 404 like a record that never existed.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "target_component_id": 42
{
}
Responses
Proposal concurred with and requirement landed
application/json
JSON "toast": { "title": "Concurred.", "message": [ "Moved to Container Platform SRG — the source requirement is now history." ], "variant": "success" }, "landed_rule_id": 5137
{
}
Non-concur with a relocation proposal, with a rationale
POST
/requirement_relocations/{id}/decline
Receiver-side adjudication (displayed as Non-concur): declines the proposal with a REQUIRED rationale. The record is retained as terminal history — never destroyed — and the rationale surfaces to the source author in the backlog, so the refusal communicates back across the ownership boundary. Requires author role on the destination component named in the request, and that component must be an ELIGIBLE receiver — an unreleased SRG component, other than the source, that declares the source requirement's core SRG (the same eligibility accept enforces). Audited. A declined source may be proposed again.
Authorizations
cookieAuth
Type
API Key (cookie: _vulcan_session)
or
tokenAuth
Personal access token authentication. Send via Authorization header: Authorization: Token vulcan_xxx. Tokens are SHA-256 hashed server-side (never stored in plaintext). Scopes: read (GET), write (mutations), admin (everything). Create tokens via Settings → API Tokens in the web UI.
Type
HTTP (token)
Request Body
application/json
JSON "target_component_id": 42, "requirement_relocation": { "adjudication_rationale": "Covered by CNTR-00-000001 already." }
{
}
Responses
Proposal non-concurred with and retained with the rationale
application/json
JSON "toast": { "title": "Non-concurred.", "message": [ "The source author can see your rationale in the backlog." ], "variant": "success" }
{
}