# Home

CatalyX by IntellectEU is a product suite designed to streamline how enterprises deploy, manage, and operate blockchain infrastructure and applications.

## CatalyX Product Docs

Explore the dedicated documentation for each CatalyX product. Additional products are in development and will be documented here as they become available.

<table data-card-size="large" data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="image">Cover image</th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>CatalyX Blockchain Manager</strong></td><td>Infrastructure management for enterprise-ready blockchain applications.</td><td><a href="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-13891d217c933ac2b6e024e350d30505fd664446%2FFrame%202095584625.png?alt=media">Frame 2095584625.png</a></td><td><a href="/catalyx-blockchain-manager">CatalyX Blockchain Manager</a></td></tr><tr><td><strong>CatalyX Package Manager</strong></td><td>Streamlined package management for the Canton Network.</td><td><a href="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-67e2591494003b0ee7e1f99ba024c74110c58623%2FFrame%202095584625%20(1).png?alt=media">Frame 2095584625 (1).png</a></td><td><a href="/catalyx-package-manager">CatalyX Package Manager</a></td></tr><tr><td><strong>CatalyX Daml Coding Assistant</strong></td><td>AI-powered inline code completion for Daml in VS Code.</td><td><a href="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-fff9ac0ee14e328a7a1749fd909ab9578a23613b%2Fimage%202.png?alt=media">image 2.png</a></td><td><a href="/catalyx-daml-coding-assistant">CatalyX Daml Coding Assistant</a></td></tr><tr><td><strong>CatalyX Fee &#x26; Reward Toolkit</strong></td><td><em>Coming Soon</em></td><td><a href="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-99a3c6f6978d6a59b2f9c26afb84ffd81a752cea%2Fimage%203.png?alt=media">image 3.png</a></td><td></td></tr></tbody></table>

***

## CatalyX Support Center

Need help with a CatalyX product? Raise a ticket through the Service Desk, browse the documentation, or reach the team directly via Slack or email.

<p align="center"><button type="button" class="button primary" data-action="search" data-icon="magnifying-glass">Ask GitBook AI</button> <a href="/support-center" class="button primary">Access Support Center</a></p>

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-message-question">:message-question:</i></td><td><strong>Access the Service Desk</strong></td><td>Report incidents, submit service and feature requests, and track the progress of open tickets.</td><td><a href="/support-center/service-desk">Service Desk</a></td></tr><tr><td><i class="fa-envelope-dot">:envelope-dot:</i></td><td><strong>Contact Support</strong></td><td>Three ways to reach us: Service Desk, email, or Slack. Find the right channel for your request.</td><td><a href="/support-center/contact-support">Contact Support</a></td></tr><tr><td><i class="fa-bug">:bug:</i></td><td><strong>Report a Bug</strong></td><td>Found something that isn't working as expected? Submit a bug report and our team will investigate.</td><td><a href="/support-center/service-desk#submit-a-support-ticket">Service Desk</a></td></tr><tr><td><i class="fa-desktop">:desktop:</i></td><td><strong>Suggest New Feature</strong></td><td>Have an idea that would improve CatalyX? Submit a feature request and help shape the roadmap.</td><td><a href="/support-center/service-desk#submit-a-support-ticket">Service Desk</a></td></tr><tr><td><i class="fa-money-bill-wave">:money-bill-wave:</i></td><td><strong>Plans and billing</strong></td><td>Questions about your licence, subscription, or billing? Get in touch through the Service Desk.</td><td><a href="/support-center/service-desk#submit-a-support-ticket">Service Desk</a></td></tr><tr><td><i class="fa-bullhorn">:bullhorn:</i></td><td><strong>Stay Up to Date</strong></td><td>Follow product releases, announcements, and updates across our newsletter and social channels.</td><td><a href="/support-center/stay-up-to-date">Stay Up To Date</a></td></tr></tbody></table>

***


# CatalyX Blockchain Manager

CatalyX Blockchain Manager (CAT-BM) is an infrastructure management and application deployment platform for enterprise DLT and digital assets.

CAT-BM enables enterprises to **build, deploy, manage, and scale** blockchain infrastructure and applications with high automation and guaranteed uptime:

* **Build**: choose your protocol, launch applications, and onboard participants.
* **Deploy**: automate setups rapidly through a UI and API that abstracts away technical complexity.
* **Manage**: highly responsive support, auto-recovery, and observability to resolve issues quickly.
* **Scale**: cloud-agnostic deployment with enterprise-grade HA, monitoring, and security.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-35c4c88fa05ba871a27cc9afd51a629be038fb19%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

***

### CatalyX Blockchain Manager Overview

<details>

<summary>Key Features</summary>

1. **Self-Service Management Console**

   Manage networks, validator nodes, and other components of your infrastructure through an intuitive self-service console.
2. **Enterprise-Grade Security**

   Integrated secrets management (HashiCorp Vault, Kubernetes Secrets), custody provider connectivity, and KMS-enabled key infrastructure — with SOC 2 certification in progress.
3. **High-Availability & Monitoring**\
   Benefit from built-in failover, disaster recovery, and multi-site high availability, supported by comprehensive monitoring.
4. **Cloud-Agnostic Deployment**

   Deploy across any cloud provider, hybrid environment, or on-premises infrastructure — without vendor lock-in.
5. **Intuitive UI & API**\
   CAT-BM streamlines access to all functionality, including CI/CD hooks.
6. **Expert Operational Support**\
   Access highly qualified, responsive support from a DevOps team with 11+ years of enterprise-grade blockchain expertise.

</details>

<details>

<summary>Commercial Models</summary>

| Tier           | Positioning                                              | Operational responsibility                                  |
| -------------- | -------------------------------------------------------- | ----------------------------------------------------------- |
| **Basic**      | Validator setup & platform access                        | Self-managed                                                |
| **Managed**    | Fully managed operations                                 | Self-managed *or* managed by IntellectEU                    |
| **Enterprise** | Enterprise-grade managed infrastructure with custom SLAs | Self-managed *or* managed by IntellectEU, custom deployment |

</details>

<details>

<summary>Visit Website</summary>

{% embed url="<https://www.catalyx.solutions/catalyx-blockchain-manager>" %}

</details>

***

### Supported Protocols

Catalyst Blockchain Manager supports a range of different protocols. More details and dedicated documentation can be found for each. Dive into each protocol-specific docs to get started.

<table data-view="cards"><thead><tr><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td>Canton Network</td><td><a href="/catalyx-blockchain-manager/canton-network">Canton Network</a></td></tr><tr><td>Hyperledger Fabric</td><td><a href="/catalyx-blockchain-manager/hyperledger-fabric">Hyperledger Fabric</a></td></tr><tr><td>Hyperledger Besu</td><td><a href="/catalyx-blockchain-manager/hyperledger-besu">Hyperledger Besu</a></td></tr><tr><td>Stellar</td><td><a href="/catalyx-blockchain-manager/stellar">Stellar</a></td></tr></tbody></table>

***


# Canton Network


# Version 2.0


# Getting Started

This section covers how to get started with CatalyX Blockchain Manager (CAT-BM) 2.0 for the Canton Network.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-dc46fa989b106363d8213245bcb84eb22290f5ab%2Fimage%20(152).png?alt=media" alt=""><figcaption></figcaption></figure></div>

CatalyX Blockchain Manager (CAT-BM) 2.0 is a Kubernetes-native platform for deploying and operating Canton Network validator nodes, with GitOps-driven operations and full lifecycle automation for Canton Network components.

{% hint style="info" %}
CAT-BM 2.0 is a complete rewrite succeeding the 1.x line: a new operator, a new REST API, and a rebuilt web platform. You declare a validator as a single Kubernetes custom resource, and the platform provisions the entire stack (i.e. the Canton participant node, the validator app, the Wallet and CNS UIs, and the authentication behind them). It then gives you a management plane and an API to operate it without direct cluster access.
{% endhint %}

## Documentation Overview

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-hexagon-nodes">:hexagon-nodes:</i></td><td><strong>Introduction to Canton Network</strong></td><td>Learn more about Canton Network.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/introduction-to-canton-network">Introduction to Canton Network</a></td></tr><tr><td><i class="fa-gear-complex-code">:gear-complex-code:</i></td><td><strong>Technical Architecture</strong></td><td>System design, topology, and infrastructure.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/architecture">Technical Architecture</a></td></tr><tr><td><i class="fa-circle-arrow-down">:circle-arrow-down:</i></td><td><strong>Installation Instructions</strong></td><td>Prerequisites and platform install.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton">Installation Instructions</a></td></tr><tr><td><i class="fa-book-atlas">:book-atlas:</i></td><td><strong>Validator CRD Reference</strong></td><td>Validator CRD fields walkthrough.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-crd">Validator CRD Reference</a></td></tr><tr><td><i class="fa-desktop-arrow-down">:desktop-arrow-down:</i></td><td><strong>User Guide</strong></td><td>Walkthrough of the CatalyX platform.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton">User Guide</a></td></tr><tr><td><i class="fa-tachograph-digital">:tachograph-digital:</i></td><td><strong>Validator Management</strong></td><td>Core functionality and validator operations.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management">Validator Management</a></td></tr><tr><td><i class="fa-memo">:memo:</i></td><td><strong>Release Notes</strong></td><td>Latest product updates and release notes.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/release-notes">Release Notes</a></td></tr><tr><td><i class="fa-square-info">:square-info:</i></td><td><strong>Support &#x26; Resources</strong></td><td>Additional support and resources.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources">Support &amp; Resources</a></td></tr></tbody></table>

***

## Where to start

{% stepper %}
{% step %}
**Understand the shape of the system**

Read [Architecture](/catalyx-blockchain-manager/canton-network/version-2.0/architecture) to see how the operator, API, UI, and Canton nodes fit together.
{% endstep %}

{% step %}
**Install the platform**

Follow [Installation Instructions](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton) to check prerequisites and install the Helm chart into your cluster.

{% hint style="warning" %}
2.0 is **not an in-place upgrade** from 1.10 or 1.11. It installs fresh alongside or in place of an existing deployment. Contact IntellectEU support before planning a migration.
{% endhint %}
{% endstep %}

{% step %}
**Create your first validator**

Apply a `Validator` resource as described in [Create a Validator](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/create-a-validator).
{% endstep %}

{% step %}
**Operate it from the platform**

Open the [User Guide](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton) to learn what each screen shows and which operations it supports.
{% endstep %}
{% endstepper %}


# Introduction to Canton Network

This section covers the introduction to the Canton Network, including its core components, architecture, and key concepts relevant to operating nodes with CatalyX Blockchain Manager.

## What is Canton Network?

Canton Network is a public layer 1 blockchain designed for privacy-preserving transactions. Unlike traditional blockchains where all transactions are visible to all participants, Canton enables selective disclosure - parties see only the data they’re entitled to see.

{% embed url="<https://docs.canton.network/overview/understand/what-is-canton>" %}

## Core Concepts

Please refer to the Canton Network documentation to learn more about the core concepts of the Canton Network.

{% embed url="<https://docs.canton.network/overview/understand/core-concepts>" %}

***

## Glossary

This section defines the key business and technical terms used throughout CatalyX Blockchain Manager and the Canton integration. Use it as the first reference when encountering unfamiliar terminology.

<details>

<summary>Business Concepts</summary>

| **Term**                    | **Definition**                                                                                                                                                                                    |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Party**                   | A **party** is an on-ledger identity in Canton—analogous to an address or account on other blockchains, but with explicit authorization semantics.                                                |
| **Validator**               | A **validator** hosts parties, stores their contract data, and participates in the Canton protocol. A validator contains a participant node (the Daml execution engine) plus a validator process. |
| **Super Validator**         | A special Canton participant node that participates in network governance, permissioning, and topology management on the global sync domain.                                                      |
| **Splice**                  | The open-source governance and reward infrastructure for the Canton Network.                                                                                                                      |
| **CatalyX**                 | IntellectEU's suite of blockchain infrastructure products built on Canton and other protocols.                                                                                                    |
| **CAT-BM**                  | CatalyX Blockchain Manager, IntellectEU's platform for deploying and operating Canton and other DLT infrastructure.                                                                               |
| **CPM**                     | CatalyX Package Manager, the application registry for discovering, publishing, and downloading Canton applications.                                                                               |
| **GSF / Canton Foundation** | Global Synchronizer Foundation, which governs the Global Sync Domain on Canton.                                                                                                                   |

</details>

<details>

<summary>Technical Concepts</summary>

| **Term**                             | **Definition**                                                                                                  |
| ------------------------------------ | --------------------------------------------------------------------------------------------------------------- |
| **Ledger API**                       | The gRPC API exposed by Canton participant nodes for submitting and reading transactions.                       |
| **Admin API**                        | The API for managing participant configuration, parties, and packages.                                          |
| **Topology**                         | The configuration of domains, participants, parties, and their relationships on the network.                    |
| **PartyToParticipant mapping**       | The topology record that says which participants host a party, with what permission and confirmation threshold. |
| **Confirmation threshold**           | How many confirming hosts must confirm each of a party's transactions.                                          |
| **PQS (Participant Query Store)**    | A queryable off-ledger store for Canton contract data.                                                          |
| **KMS driver**                       | Canton integration module that delegates key operations to an external KMS or HSM.                              |
| **WaaS**                             | Wallet-as-a-Service — an external key custody and signing service supported by CAT-BM.                          |
| **ArgoCD**                           | GitOps continuous-delivery tool used to synchronise desired state from Git into the Kubernetes cluster.         |
| **Helm chart**                       | Kubernetes packaging format used to deploy Canton components.                                                   |
| **CRD (Custom Resource Definition)** | Kubernetes extension used by the CAT-BM Canton Operator to manage node lifecycle.                               |
| **CAT-BM Canton Operator**           | Custom Kubernetes operator that watches CRDs and reconciles Canton component state.                             |
| **Round**                            | 10-minute cycle on Canton Network governing minting and distribution of Canton Coin.                            |

</details>

***

## Learn More <a href="#learn-more-about-canton" id="learn-more-about-canton"></a>

| **Resource**                                                                                                    | **Purpose**                                                |
| --------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- |
| [Canton Network Website](https://canton.network/)                                                               | Official Canton Network site                               |
| [Canton Network Docs](https://docs.canton.network/)                                                             | Official Canton Network documentation                      |
| [Canton Network Github](https://github.com/canton-network)                                                      | Canton Network repositories, including Splice              |
| [Canton Network Whitepaper](https://www.digitalasset.com/hubfs/Canton/Canton%20Network%20-%20White%20Paper.pdf) | Official Canton Network whitepaper                         |
| [Digital Asset / Daml Documentation](https://docs.digitalasset.com/)                                            | Canton and Daml technical documentation from Digital Asset |
| [Canton Foundation Website](https://canton.foundation/)                                                         | GSF governance, committees, and network information        |
| [CIPs](https://github.com/canton-foundation/cips)                                                               | Canton Improvement Proposals                               |

***


# Technical Architecture

System context, high-level architecture, and design principles of CatalyX Blockchain Manager version 2.0 for the Canton Network.

CAT-BM is a Kubernetes-native solution designed to manage Canton's distributed ledger infrastructure with enterprise-grade security and operational automation. It uses a custom Kubernetes operator and custom resource definitions (CRDs) to manage Canton components across environments. While the reference setup runs on Amazon EKS, it is fully portable to Microsoft Azure (AKS), Google Cloud (GKE), or on-premises Kubernetes / OpenShift.

Beyond infrastructure management, CAT-BM provides operational capabilities at the Canton and Daml application level, including managing parties and users, deploying DARs, configuring identity providers, performing backup and restore operations, monitoring, integration with wallet providers, and handling upgrades.

## System Context

CAT-BM sits between the operators who run Canton infrastructure and the Canton nodes and applications themselves. It is the control plane: it deploys, operates, and monitors Canton DLT, while the nodes and applications remain standard Canton components.

<table><thead><tr><th width="220">Software system</th><th>Functional responsibilities</th><th width="220">Interfaces</th></tr></thead><tbody><tr><td>CatalyX Blockchain Manager</td><td>Canton and Daml infrastructure provisioning, application deployment, and operations.</td><td>CatalyX UI, HTTP API, Kubernetes custom resources</td></tr><tr><td>Identity provider</td><td>User management, RBAC.</td><td>Web UI, API (OAuth / OIDC)</td></tr><tr><td>Canton nodes</td><td>Distributed ledger.</td><td>REST API, gRPC API, TCP</td></tr><tr><td>Canton applications</td><td>End-user Daml applications.</td><td>Web UI, HTTP API</td></tr></tbody></table>

CAT-BM runs on any conformant Kubernetes distribution, including managed Kubernetes services and OpenShift, on AWS, GCP, Azure, or on-premises.

## High-Level Architecture

CAT-BM separates a management plane (i.e. the components CatalyX ships) from the Canton stack those components create and operate.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-0abee83c4741504b219f4623e7afb8cd1c431abb%2FCatalyx2-Architecture.png?alt=media" alt=""><figcaption><p>High Level Architecture</p></figcaption></figure></div>

### CatalyX Components

<table><thead><tr><th width="230">Component</th><th>Functional responsibilities</th><th width="180">Interfaces</th></tr></thead><tbody><tr><td>CAT-BM Canton UI</td><td>User interface for the Canton infrastructure and application operator.</td><td>Web UI</td></tr><tr><td>CAT-BM Canton API</td><td>Backend API for the user interface and third-party integrations.</td><td>REST API</td></tr><tr><td>CAT-BM Canton Operator</td><td>Kubernetes operator for Canton deployment operations.</td><td>Kubernetes custom resource definitions for Canton infrastructure</td></tr><tr><td>Canton Nodes</td><td>Canton DLT infrastructure.</td><td>gRPC API, REST API</td></tr><tr><td>Identity Provider</td><td>Authenticates and authorises every CatalyX component and validator UI. Either managed automatically (Keycloak, provisioned by the operator) or supplied externally as any OIDC-compliant provider (Okta, Microsoft Entra ID, Auth0, Ping Identity, and others).</td><td>Web UI, API (OAuth / OIDC)</td></tr></tbody></table>

***

### CatalyX management plane

Three components make up the CatalyX management plane. They are installed together by a single Helm chart.

<details>

<summary>Catalyx-operator</summary>

The operator watches `Validator` resources and reconciles each one into the workloads that make up a working validator. For a single `Validator` it will:

1. Provision the OIDC clients, scopes, and wallet user in the identity provider (when managed authentication is enabled).
2. Create the participant and validator-app databases and schemas.
3. Create one child `Application` resource per component.

Each `Application` is then reconciled into a Kubernetes `Deployment`, a `Service`, and — for components that are externally reachable — a Traefik `IngressRoute`.

```
Validator                      user-managed entry point
  └─ Application × 4–6         operator-managed, one per component
       └─ Deployment + Service + IngressRoute
```

{% hint style="warning" %}
`Application` resources are an operator implementation detail. Never create, edit, or delete them by hand — the operator owns them and will revert manual changes on the next reconcile. All configuration flows through the `Validator` resource.
{% endhint %}

The components created for a validator are:

| Component        | Always created    | Purpose                                  |
| ---------------- | ----------------- | ---------------------------------------- |
| `participant`    | Yes               | The Canton participant node              |
| `validator`      | Yes               | The validator app (Splice backend)       |
| `wallet-ui`      | Yes               | Canton Wallet web UI                     |
| `cns-ui`         | Yes               | Canton Name Service web UI               |
| `pqs`            | Only when enabled | Participant Query Store                  |
| `wallet-gateway` | Only when enabled | Wallet Gateway, for external key custody |

</details>

<details>

<summary>Catalyx-api</summary>

The API is a stateless service that does two jobs:

* **Reads** validator and application state from the Kubernetes custom resources. It never writes them.
* **Proxies** privileged Canton operations — the Ledger API, the participant Admin API, the Scan API, and the validator app's admin API — so operators and integrations do not need direct network access to the nodes.

It also hosts the WebSocket endpoint that backs the interactive Canton console, and publishes an OpenAPI description of itself.

</details>

<details>

<summary>Catalyx-ui</summary>

The CatalyX UI is a single-page application that talks only to the API. It never talks to Kubernetes or to Canton directly, which means the permissions a UI user needs are API permissions, not cluster permissions.

</details>

***

### The Canton stack

Everything the operator creates for a validator sits in the Canton stack:

* **`participant`** — the Canton participant node. Owns its own PostgreSQL database. Exposes the Ledger API, the Admin API, a JSON API, and a metrics endpoint.
* **`validator`** — the validator app. Owns its own PostgreSQL database and connects to the network's sequencer, sponsoring Super Validator, and Scan services.
* **`wallet-ui`** and **`cns-ui`** — static web applications served behind the ingress, authenticating against the identity provider.
* **`pqs`** — optional. Streams the ledger into a queryable PostgreSQL store.
* **`wallet-gateway`** — optional. Delegates party signing to an external Wallet-as-a-Service provider.

All external traffic enters through Traefik over HTTPS. The UI, the API, and each externally reachable validator component are exposed on their own hostnames or path prefixes derived from the base hostname configured at install time.

***

## Design principles

The platform is built around the following capabilities.

<details>

<summary>Enterprise-grade security</summary>

* Encrypted persistent storage and encrypted communication channels (TLS / mTLS).
* Secure secret management via cloud secret managers or Kubernetes Secrets.
* Integration with enterprise Key Management Services (AWS KMS, Azure Key Vault) for encryption key lifecycle management.
* Support for integration with external Wallet-as-a-Service providers for secure signing and transaction management.
* Support for OIDC-compliant identity providers (Keycloak, Okta, Microsoft Entra ID, Auth0, Ping Identity, and others) for authentication and authorisation.
* Fine-grained access control using scope and claim mapping from the identity provider.
* Role-based access control (RBAC).
* Network-level security: IP allowlisting, VPN, and firewall / WAF integration options.
* Security audit logging with integration into SIEM platforms.
* Regular security patching and vulnerability scanning of container images and dependencies.

</details>

<details>

<summary>GitOps-driven operations</summary>

* All infrastructure and deployment configuration is defined declaratively using Helm charts and managed through GitOps practices.
* ArgoCD can be used to synchronise desired state from Git repositories to the Kubernetes cluster, enabling traceable, auditable, and consistent deployment pipelines across development, test, staging, and production environments.

</details>

<details>

<summary>Infrastructure-as-Code</summary>

* Cloud infrastructure is defined declaratively (for example with Terraform) and provisioned through the same GitOps pipelines described above, so changes stay traceable and reproducible across environments.

</details>

<details>

<summary>Automated lifecycle management</summary>

* CAT-BM automates node provisioning, dependency management, certificate distribution, and topology orchestration.
* Built-in support for scaling, patching, and configuration updates through CRDs.

</details>

<details>

<summary>Monitoring and observability</summary>

* Integrated with Prometheus and Grafana for metrics collection, visualisation, and alerting.
* Logs are aggregated and forwarded to a centralised log store such as Loki.
* Health checks, liveness and readiness probes, and custom metrics are exposed for proactive monitoring and incident response.

</details>

<details>

<summary>Scalability and extensibility</summary>

* Horizontal and vertical pod autoscaling based on resource usage.
* Support for multi-tenant deployments and workload isolation via Kubernetes namespaces and network policies.

</details>

***

## CatalyX validator hosting reference document

{% hint style="info" %}
For a worked example of a full production deployment on AWS — networking, compute sizing, and the managed services used — see the [CatalyX Canton Validator Hosting reference document](https://docs.google.com/document/d/1B2NQxLI4dqTpHY16DS1_wf6ddpKiaiq9/edit).
{% endhint %}

***

## Supported versions

| Component       | Version         |
| --------------- | --------------- |
| Canton Protocol | v2.10 or higher |
| Daml            | v2.10 or higher |


# Installation Instructions

How to install CatalyX Blockchain Manager 2.0 for the Canton Network.

One Helm chart installs the operator, the API, and the ui into your cluster. You do this once.

Each validator is a `Validator` custom resource that you apply to the cluster. The operator does the rest. This is a separate, ongoing task once the platform is installed — see [Create a Validator](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/create-a-validator) in [Validator Management](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management).

{% hint style="warning" %}
CAT-BM 2.0 is not an in-place upgrade from 1.10 or 1.11. Install it fresh. Contact IntellectEU support before planning a migration from a 1.x deployment.
{% endhint %}

## In this section

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Prerequisites</strong></td><td>Cluster, tooling, and access you need before you start.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/prerequisites">Prerequisites</a></td></tr><tr><td><strong>Keycloak Realm Setup</strong></td><td>Create the realm, clients, and login user the platform needs before you install.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/keycloak-realm-setup">Keycloak Realm Setup</a></td></tr><tr><td><strong>Platform Installation</strong></td><td>Install the operator, API, and UI with Helm.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation">Platform Installation</a></td></tr><tr><td><strong>Identity Provider Configuration</strong></td><td>Managed Keycloak, or bring your own OIDC provider.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration">Identity Provider Configuration</a></td></tr></tbody></table>


# Prerequisites

Cluster, tooling, and access required before installing CAT-BM 2.0.

## Cluster and tooling

<table><thead><tr><th width="170">Requirement</th><th width="140">Version</th><th>Notes</th></tr></thead><tbody><tr><td>Kubernetes</td><td><code>1.26+</code></td><td>Any conformant distribution, including managed services and OpenShift.</td></tr><tr><td>Helm</td><td><code>3.x</code></td><td></td></tr><tr><td>Traefik</td><td><code>3.x</code></td><td>Must already be installed in the cluster. CAT-BM creates <code>IngressRoute</code> resources in the <code>traefik.io/v1alpha1</code> API group.</td></tr><tr><td>Keycloak</td><td><code>26.x</code></td><td>Or another OIDC-compliant identity provider — see <a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration">Identity Provider Configuration</a>.</td></tr><tr><td>PostgreSQL</td><td><code>14+</code></td><td>Reachable from the cluster. In-cluster or managed (for example Amazon RDS).</td></tr></tbody></table>

{% hint style="warning" %}
Traefik must be configured with entry points named exactly **`web`** (HTTP) and **`websecure`** (HTTPS). CAT-BM references these names when creating ingress routes; a Traefik installation using different entry point names will not route traffic to the platform.
{% endhint %}

## Optional cluster components

Each of these unlocks an optional feature. The corresponding CRDs must already be installed in the cluster.

<table><thead><tr><th width="230">Component</th><th>Enables</th></tr></thead><tbody><tr><td><a href="https://cert-manager.io/">cert-manager</a></td><td>Automatic TLS certificate issuance for the platform hostname, instead of supplying a TLS secret yourself.</td></tr><tr><td>Prometheus Operator</td><td>A <code>ServiceMonitor</code> so Prometheus scrapes validator component metrics automatically.</td></tr><tr><td><a href="https://external-secrets.io/">External Secrets Operator</a></td><td>Sourcing the platform's Keycloak secrets from an external secret store instead of creating Kubernetes Secrets by hand.</td></tr></tbody></table>

## Database access

CAT-BM provisions validator databases for you. The credentials you give it must therefore be able to create databases and schemas.

* The credentials referenced by `spec.database.credentialsSecretRef` need `CREATEDB` privileges.
* The operator connects to the `postgres` maintenance database on the host you specify, so that database must be reachable.

Each validator uses at least two databases — one for the participant node and one for the validator app — plus one more when the Participant Query Store is enabled, and two more when the Wallet Gateway is enabled.

## Identity provider

An OIDC-compliant identity provider must be reachable from the cluster before you install.

{% hint style="danger" %}
**The realm must already exist.** CAT-BM never creates a realm. When managed authentication is enabled, the operator creates clients, client scopes, protocol mappers, and users *inside* an existing realm.
{% endhint %}

You need:

* An existing realm for the validators.
* An **admin client** in that realm, with a service account holding realm-management permissions. The operator authenticates as this client to provision per-validator objects.

{% hint style="warning" %}
The admin client must live **in the target realm**, not in the `master` realm. The operator authenticates against the realm you configure as `operator.keycloak.realm` using the client credentials grant.
{% endhint %}

* Two clients for the management plane itself:
  * a **confidential client** used by the API to mint per-validator Ledger API tokens — `catalyx-api` by default;
  * a **public client** used by the ui for browser login (authorization code with PKCE) — `catalyx-canton-ui` by default.

## Network access

<table><thead><tr><th width="260">From</th><th>To</th></tr></thead><tbody><tr><td>Cluster workloads</td><td>Your identity provider</td></tr><tr><td>Cluster workloads</td><td>PostgreSQL</td></tr><tr><td>Validator components</td><td>The Canton Network sequencer, sponsoring Super Validator, and Scan endpoints for your target network</td></tr><tr><td>Operators / users</td><td>The platform hostname, over HTTPS</td></tr><tr><td>Participant node</td><td>Your KMS endpoint, if KMS is enabled</td></tr></tbody></table>

For the global Canton Network, your egress IP addresses must be allowlisted by the network governance body and Super Validators. Start this process early — it requires a two-thirds approval threshold and is usually the longest lead-time item in an onboarding.

## Container images

Platform images are published to the IntellectEU Artifactory registry at `intellecteu-catbp-docker.jfrog.io`, built for `linux/amd64` and `linux/arm64`:

| Component | Repository                        |
| --------- | --------------------------------- |
| Operator  | `catalyx/canton/catalyx-operator` |
| API       | `catalyx/canton/catalyx-console`  |
| UI        | `catalyx/canton/catalyx-ui`       |

You need an image pull secret with credentials for that registry. Contact IntellectEU support to obtain access.

{% hint style="info" %}
Pin `image.tag` to the release you intend to run — for example `v2.0.0`. The chart default is `latest`, which is convenient for evaluation but not appropriate for production.
{% endhint %}

## Onboarding secret

To join a validator to a network you need a one-time onboarding secret from a sponsoring Super Validator.

* Request it against the **Super Validator** URL (`sv.…`), not the Scan URL.
* Onboarding secrets are single-use and short-lived — typically valid for **48 hours**, and only **1 hour** for DevNet self-service tokens.
* Request the secret shortly before you apply the `Validator` resource, not days in advance.


# Keycloak Realm Setup

Create the realm, clients, and login user the platform needs before you install — with the commands to do it by hand.

Before you run [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation), a Keycloak realm has to exist with three clients and a login user already in it. The operator only *provisions into* an existing realm (see [Managed Keycloak](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/managed-keycloak)) — it never creates the realm itself, so this is a one-time manual step.

## One realm, shared by the platform and every validator

Everything below goes into one realm. That's the same realm you point the operator at with `operator.keycloak.realm` in [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation), and the same realm [Managed Keycloak](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/managed-keycloak) later provisions per-validator clients into. There's no separate "platform realm" and "validator realm" — one realm serves both.

## Placeholders used below

<table><thead><tr><th width="200">Placeholder</th><th width="260">Example</th><th>Is</th></tr></thead><tbody><tr><td><code>$REALM</code></td><td><code>validator-intellecteu-devnet</code></td><td>The realm you create — becomes <code>operator.keycloak.realm</code>.</td></tr><tr><td><code>$BASE_HOSTNAME</code></td><td><code>validators.example.com</code></td><td>Should match <code>operatorRuntime.baseHostname</code> — used in the UI client's redirect URI.</td></tr><tr><td><code>$UI_USERNAME</code> / <code>$UI_EMAIL</code></td><td><code>catalyx-ui-admin</code> / <code>catalyx-ui-admin@example.com</code></td><td>The browser login user you create for <code>catalyx-canton-ui</code>.</td></tr></tbody></table>

{% hint style="danger" %}
Pick your own values — don't reuse the examples above, and don't leave any password as a placeholder like `admin` in anything beyond a local minikube run.
{% endhint %}

## What to create

<table><thead><tr><th width="220">Object</th><th width="110">Realm</th><th>Configuration</th></tr></thead><tbody><tr><td>Realm</td><td>—</td><td><code>$REALM</code>, enabled, display name "CatalyX Canton Validator" (or your own).</td></tr><tr><td>Client — <code>catalyx-operator-admin</code></td><td><code>$REALM</code></td><td>Confidential, service accounts enabled, standard flow <strong>disabled</strong> (service account only — never used for browser login). Its secret is what you store as <code>admin-client-secret</code> in the <code>catalyx-operator-keycloak</code> secret in <a href="/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation">Platform Installation</a>, and is referenced by <code>operator.keycloak.adminClientId</code>.</td></tr><tr><td>Client — <code>catalyx-api</code></td><td><code>$REALM</code></td><td>Confidential, service accounts enabled, standard flow enabled, direct access grants <strong>disabled</strong>, <code>redirectUris: ["/*"]</code>, <code>webOrigins: ["/*"]</code>. Its secret is what you store as <code>client-secret</code> in the <code>catalyx-api-credentials</code> secret.</td></tr><tr><td>Client — <code>catalyx-canton-ui</code></td><td><code>$REALM</code></td><td>Public, standard flow enabled (browser OIDC with PKCE), direct access grants disabled, redirect URI <code>https://$BASE_HOSTNAME/*</code>, web origin <code>https://$BASE_HOSTNAME</code>. Matches <code>ui.oidc.clientId</code> (default <code>catalyx-canton-ui</code>).</td></tr><tr><td>User — <code>$UI_USERNAME</code></td><td><code>$REALM</code></td><td>Enabled, email verified, password set. Used to sign in to the CatalyX UI in a browser via <code>catalyx-canton-ui</code>. Carries no realm roles — it's a plain login, not an admin account.</td></tr></tbody></table>

## Permission to grant

There is one role assignment to make: the `catalyx-operator-admin` service account (`service-account-catalyx-operator-admin`) gets the **`realm-admin`** client role of **`$REALM`**'s own **`realm-management`** client — not `master`'s. That scopes the operator to administering just `$REALM`, and is what lets its client-credentials login create and update the per-validator clients, scopes, and users described in [Managed Keycloak](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/managed-keycloak).

## Commands

Everything below can equally be done by hand in the Keycloak Admin Console (**Realm settings → Create realm**, **Clients → Create client**, **Users → Add user**, and the role assignment under a user's **Role mapping** tab).

Run these with `kcadm.sh` against your Keycloak — from a shell with `kcadm.sh` on the path (for example `kubectl exec` into the Keycloak pod), or adapt them to the [Admin REST API](https://www.keycloak.org/docs-api/latest/rest-api/index.html) if you're not using the CLI.

{% stepper %}
{% step %}
**Authenticate**

```bash
kcadm.sh config credentials \
  --server "$KEYCLOAK_URL" \
  --realm master \
  --user admin \
  --password <admin-password>
```

{% endstep %}

{% step %}
**Create the realm**

```bash
kcadm.sh create realms \
  -s realm="$REALM" \
  -s enabled=true \
  -s displayName="CatalyX Canton Validator"
```

{% endstep %}

{% step %}
**Create `catalyx-operator-admin` in `$REALM` and grant it `realm-admin`**

```bash
kcadm.sh create clients -r "$REALM" \
  -s clientId=catalyx-operator-admin \
  -s enabled=true \
  -s publicClient=false \
  -s serviceAccountsEnabled=true \
  -s standardFlowEnabled=false

kcadm.sh add-roles -r "$REALM" \
  --uusername service-account-catalyx-operator-admin \
  --cclientid realm-management \
  --rolename realm-admin
```

{% endstep %}

{% step %}
**Create `catalyx-api` in `$REALM`**

```bash
kcadm.sh create clients -r "$REALM" \
  -s clientId=catalyx-api \
  -s enabled=true \
  -s publicClient=false \
  -s serviceAccountsEnabled=true \
  -s standardFlowEnabled=true \
  -s directAccessGrantsEnabled=false \
  -s 'redirectUris=["/*"]' \
  -s 'webOrigins=["/*"]'
```

{% endstep %}

{% step %}
**Create `catalyx-canton-ui` in `$REALM`**

```bash
kcadm.sh create clients -r "$REALM" \
  -s clientId=catalyx-canton-ui \
  -s enabled=true \
  -s publicClient=true \
  -s serviceAccountsEnabled=false \
  -s standardFlowEnabled=true \
  -s directAccessGrantsEnabled=false \
  -s "redirectUris=[\"https://$BASE_HOSTNAME/*\"]" \
  -s "webOrigins=[\"https://$BASE_HOSTNAME\"]"
```

{% endstep %}

{% step %}
**Create the UI login user**

```bash
kcadm.sh create users -r "$REALM" \
  -s username="$UI_USERNAME" \
  -s email="$UI_EMAIL" \
  -s enabled=true \
  -s emailVerified=true

kcadm.sh set-password -r "$REALM" \
  --username "$UI_USERNAME" \
  --new-password <choose-a-password>
```

{% endstep %}

{% step %}
**Retrieve the `catalyx-operator-admin` secret**

```bash
CLIENT_ID=$(kcadm.sh get clients -r "$REALM" \
  -q clientId=catalyx-operator-admin --fields id --format csv --noquotes)
kcadm.sh get "clients/$CLIENT_ID/client-secret" -r "$REALM"
```

Store the printed `value` as `admin-client-secret` in the `catalyx-operator-keycloak` secret — see step 2 of [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation).
{% endstep %}

{% step %}
**Retrieve the `catalyx-api` secret**

```bash
CLIENT_ID=$(kcadm.sh get clients -r "$REALM" \
  -q clientId=catalyx-api --fields id --format csv --noquotes)
kcadm.sh get "clients/$CLIENT_ID/client-secret" -r "$REALM"
```

Store the printed `value` as `client-secret` in the `catalyx-api-credentials` secret — also step 2 of [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation).
{% endstep %}
{% endstepper %}

***

## Next step

With the realm, its three clients, and the UI login user in place, continue to [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation) to create the Kubernetes secrets from the two client secrets above and install the Helm chart.


# Platform Installation

Install the CAT-BM operator, API, and UI with Helm.

The `catalyx-canton` Helm chart installs three components — the operator, the API, and the CatalyX UI component — plus the two custom resource definitions they depend on.

## Before you install

{% stepper %}
{% step %}
**Create the namespace**

Create a namespace for the platform — any name works. This guide uses `<namespace>` as a placeholder throughout; substitute your own choice everywhere you see it.

```bash
kubectl create namespace <namespace>
```

{% endstep %}

{% step %}
**Create the identity provider secrets**

Two secrets are required, both live in the release namespace, and both hold client secrets from an existing Keycloak realm — see [Keycloak Realm Setup](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/keycloak-realm-setup) if that realm and its clients don't exist yet.

```bash
# The operator's Keycloak admin client secret
kubectl create secret generic catalyx-operator-keycloak \
  --from-literal=admin-client-secret=<keycloak-admin-client-secret> \
  -n <namespace>

# The API's Keycloak confidential client secret
kubectl create secret generic catalyx-api-credentials \
  --from-literal=client-secret=<catalyx-api-client-secret> \
  -n <namespace>
```

{% hint style="danger" %}
`catalyx-api-credentials` is **not optional**. The API pod will not start without it — it fails with `CreateContainerConfigError`.
{% endhint %}
{% endstep %}

{% step %}
**Create the TLS secret**

The chart does not create a TLS certificate unless you enable cert-manager. The default name is `catalyx-app-tls`.

```bash
kubectl create secret tls catalyx-app-tls \
  --cert=<path-to-cert.pem> --key=<path-to-key.pem> \
  -n <namespace>
```

{% hint style="warning" %}
This secret name is used by **every ingress route the operator creates for validators**, not just by the UI and API. If it does not exist, validator UIs will fail to serve over HTTPS even if you never set `ingress.tls.secretName` yourself.
{% endhint %}
{% endstep %}

{% step %}
**Create the image pull secret**

```bash
kubectl create secret docker-registry intellecteu-jfrog-access \
  --docker-server=intellecteu-catbp-docker.jfrog.io \
  --docker-username=<username> --docker-password=<token> \
  -n <namespace>
```

{% endstep %}
{% endstepper %}

***

## Install

```bash
helm install catalyx-canton catalyx/catalyx-canton \
  -n <namespace> \
  --set image.tag=v2.0.0 \
  --set 'image.pullSecrets[0].name=intellecteu-jfrog-access' \
  --set operator.keycloak.serverUrl=https://keycloak.example.com \
  --set operator.keycloak.realm=my-realm \
  --set operator.keycloak.adminClientId=catalyx-operator-admin \
  --set operator.keycloak.adminClientSecretRef.name=catalyx-operator-keycloak \
  --set api.auth.jwksUri=https://keycloak.example.com/realms/my-realm/protocol/openid-connect/certs \
  --set ui.oidc.authority=https://keycloak.example.com/realms/my-realm \
  --set ui.oidc.redirectUri=https://validators.example.com \
  --set operatorRuntime.baseHostname=validators.example.com \
  --set ingress.host=validators.example.com \
  --set ingress.tls.secretName=catalyx-app-tls
```

Contact IntellectEU support for the Helm repository URL and credentials.

Verify the rollout:

```bash
kubectl -n <namespace> get deploy
kubectl -n <namespace> wait --for=condition=Available deployment \
  -l app.kubernetes.io/instance=catalyx-canton --timeout=180s
```

The UI is then available at `https://<ingress.host>/`, and the API at `https://<ingress.host>/api`.

***

## Values you must set

These have defaults that are only suitable for local development. Every production install should override all of them.

<table><thead><tr><th width="330">Value</th><th>Purpose</th></tr></thead><tbody><tr><td><code>ingress.host</code></td><td>Hostname the UI and API are served on. When empty, ingress routes match on path only, with no host clause.</td></tr><tr><td><code>ingress.tls.secretName</code></td><td>TLS secret for the UI and API routes.</td></tr><tr><td><code>operatorRuntime.baseHostname</code></td><td>Base hostname for every per-validator hostname the operator generates, and for the identity provider redirect URIs it registers. Changing it later rewrites those redirect URIs on the next reconcile.</td></tr><tr><td><code>operatorRuntime.tlsSecretName</code></td><td>TLS secret used by every ingress route the operator creates. Default <code>catalyx-app-tls</code>.</td></tr><tr><td><code>api.auth.jwksUri</code></td><td>JWKS endpoint the API validates UI tokens against.</td></tr><tr><td><code>ui.oidc.authority</code></td><td>OIDC issuer the UI redirects browser logins to.</td></tr><tr><td><code>ui.oidc.clientId</code></td><td>Public OIDC client for the UI. Default <code>catalyx-canton-ui</code>.</td></tr><tr><td><code>ui.oidc.redirectUri</code></td><td>Where the identity provider returns the browser after login. Must match a redirect URI registered on the client.</td></tr><tr><td><code>image.tag</code></td><td>Pin to a release tag. Default is <code>latest</code>.</td></tr><tr><td><code>image.pullSecrets</code></td><td>Pull secret for the IntellectEU registry.</td></tr></tbody></table>

## Managed authentication values

Required only if you intend to use `managedKeycloak: true` on any validator.

<table><thead><tr><th width="380">Value</th><th>Purpose</th></tr></thead><tbody><tr><td><code>operator.keycloak.serverUrl</code></td><td>Identity provider base URL.</td></tr><tr><td><code>operator.keycloak.realm</code></td><td>Realm the operator provisions into. Must already exist.</td></tr><tr><td><code>operator.keycloak.adminClientId</code></td><td>Admin client the operator authenticates as. Must exist <strong>in that realm</strong>.</td></tr><tr><td><code>operator.keycloak.adminClientSecretRef.name</code> / <code>.key</code></td><td>Secret holding the admin client secret. Key defaults to <code>admin-client-secret</code>.</td></tr><tr><td><code>operator.keycloak.apiClientId</code></td><td>The client that per-validator Ledger API scopes are attached to. Default <code>catalyx-api</code>.</td></tr></tbody></table>

## Component values

<table><thead><tr><th width="300">Value</th><th width="150">Default</th><th>Notes</th></tr></thead><tbody><tr><td><code>operator.replicaCount</code></td><td><code>1</code></td><td><strong>Must remain 1.</strong> The operator has no leader election; a second replica double-reconciles every resource.</td></tr><tr><td><code>api.replicaCount</code></td><td><code>1</code></td><td><strong>Must remain 1.</strong> Canton console sessions are held in process, so they do not survive being load-balanced across replicas.</td></tr><tr><td><code>ui.replicaCount</code></td><td><code>2</code></td><td>The UI is stateless and runs highly available by default, with a pod disruption budget and topology spread.</td></tr><tr><td><code>api.namespace</code></td><td>release namespace</td><td>Namespace the API reads validators from. The API's RBAC is namespaced to the release namespace, so pointing this elsewhere produces authorisation errors.</td></tr><tr><td><code>operator.rbac.clusterAdmin</code></td><td><code>false</code></td><td>Leave <code>false</code>. When <code>true</code>, the operator service account is bound to <code>cluster-admin</code> instead of the chart's least-privilege role.</td></tr><tr><td><code>ui.grafana.baseUrl</code></td><td>—</td><td>Base URL for the Grafana deep links in the UI. See <a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/grafana-dashboards">Grafana Links</a>.</td></tr><tr><td><code>monitoring.serviceMonitor.enabled</code></td><td><code>false</code></td><td>Set <code>true</code> to have Prometheus scrape validator component metrics. Requires the Prometheus Operator CRDs.</td></tr><tr><td><code>certManager.enabled</code></td><td><code>false</code></td><td>Set <code>true</code>, with <code>certManager.certificate.create</code> and <code>certManager.certificate.dnsNames</code>, to have cert-manager issue the platform certificate.</td></tr></tbody></table>

{% hint style="warning" %}
**Harden the OpenAPI endpoints before exposing the platform publicly.** The chart publishes `/swagger-ui` and `/v3/api-docs` on the same hostname as the API, and both are served without authentication. If that is not acceptable in your environment, restrict them with a Traefik middleware via `api.ingress.middlewares`, or block them at your edge.
{% endhint %}

***

## Upgrading

```bash
helm upgrade catalyx-canton catalyx/catalyx-canton -n <namespace> -f my-values.yaml
```

{% hint style="danger" %}
**Helm does not upgrade CRDs.** `helm upgrade` never touches the chart's `crds/` directory. When a release changes the `Validator` or `Application` schema, apply the CRDs explicitly before upgrading:

```bash
kubectl apply -f <chart>/crds
```

{% endhint %}

Existing validators are re-reconciled after an upgrade. The operator applies rolling updates to component deployments, so a component with more than one replica is updated without downtime.


# Validator CRD Reference

Every field on the Validator custom resource, with types and defaults.

## How to read this reference

Two different kinds of default appear in the tables, and the distinction is load-bearing.

<table><thead><tr><th width="230">Kind</th><th>Behaviour</th></tr></thead><tbody><tr><td><strong>Schema default</strong></td><td>Applied by the Kubernetes API server when you omit the field. It is written into the stored resource, so <code>kubectl get -o yaml</code> shows it.</td></tr><tr><td><strong>Operator default</strong></td><td>Applied by the operator at reconcile time. The field stays absent from the stored resource — the value appears only in the resulting workload.</td></tr></tbody></table>

Similarly, two kinds of "required":

<table><thead><tr><th width="230">Kind</th><th>Behaviour</th></tr></thead><tbody><tr><td><strong>Schema required</strong></td><td>The API server rejects the resource at <code>kubectl apply</code>. Fast, obvious failure.</td></tr><tr><td><strong>Reconcile required</strong></td><td>Accepted at apply, then fails during reconciliation. Surfaces as the <code>Ready</code> condition with reason <code>InvalidSpec</code> and a message naming the field.</td></tr></tbody></table>

{% hint style="danger" %}
**Unknown fields are silently pruned.** The API server drops any field not in the schema, without an error. A misspelled field name has no effect and produces no warning. After applying, confirm your fields survived:

```bash
kubectl -n <namespace> get validator my-validator -o yaml
```

{% endhint %}

***

## Top level

Three blocks are schema-required: `auth`, `database`, and `network`.

<table><thead><tr><th width="230">Field</th><th width="130">Required</th><th>Purpose</th></tr></thead><tbody><tr><td><code>spec.auth</code></td><td><strong>Schema</strong></td><td>Authentication for every component.</td></tr><tr><td><code>spec.database</code></td><td><strong>Schema</strong></td><td>PostgreSQL connection and database names.</td></tr><tr><td><code>spec.network</code></td><td><strong>Schema</strong></td><td>Canton network connectivity.</td></tr><tr><td><code>spec.participant</code></td><td>No</td><td>Canton participant node configuration.</td></tr><tr><td><code>spec.validator</code></td><td>No</td><td>Validator app configuration.</td></tr><tr><td><code>spec.ui</code></td><td>No</td><td>Wallet UI and CNS UI configuration and branding.</td></tr><tr><td><code>spec.pqs</code></td><td>No</td><td>Participant Query Store.</td></tr><tr><td><code>spec.walletGateway</code></td><td>No</td><td>Wallet Gateway.</td></tr><tr><td><code>spec.kms</code></td><td>No</td><td>External key management.</td></tr><tr><td><code>spec.overrides</code></td><td>No</td><td>Extra environment variables per component.</td></tr></tbody></table>

***

## `spec.auth`

<table><thead><tr><th width="330">Field</th><th width="110">Type</th><th width="130">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>enabled</code></td><td>boolean</td><td><code>true</code></td><td>Master authentication switch. <code>false</code> disables authentication on the participant.</td></tr><tr><td><code>managedKeycloak</code></td><td>boolean</td><td><code>false</code></td><td><code>true</code> → the operator provisions the OIDC objects and reads configuration from <code>status.managedAuth</code>.</td></tr><tr><td><code>authUrl</code></td><td>string</td><td>—</td><td>OIDC issuer or token endpoint.</td></tr><tr><td><code>jwksUrl</code></td><td>string</td><td>—</td><td>JWKS endpoint for token verification.</td></tr><tr><td><code>targetAudience</code></td><td>string</td><td>—</td><td>Audience every token must carry.</td></tr><tr><td><code>ledgerApiUserManagementScope</code></td><td>string</td><td>—</td><td>OAuth scope granting Ledger API user management.</td></tr><tr><td><code>ledgerApiUser</code></td><td>string</td><td>—</td><td>Participant admin user name.</td></tr><tr><td><code>walletUserName</code></td><td>string</td><td>—</td><td>Wallet owner user name.</td></tr><tr><td><code>ledgerApiClientId</code></td><td>string</td><td>—</td><td>Confidential backend client ID.</td></tr><tr><td><code>walletUiClientId</code></td><td>string</td><td>—</td><td>Public client ID for the Wallet UI.</td></tr><tr><td><code>cnsUiClientId</code></td><td>string</td><td>—</td><td>Public client ID for the CNS UI.</td></tr><tr><td><code>walletGatewayClientId</code></td><td>string</td><td>—</td><td>Public client ID for the Wallet Gateway.</td></tr><tr><td><code>ledgerApiClientSecretRef.name</code></td><td>string</td><td>—</td><td>Secret holding the backend client secret.</td></tr><tr><td><code>ledgerApiClientSecretRef.key</code></td><td>string</td><td><code>client-secret</code></td><td>Key within that secret.</td></tr></tbody></table>

{% hint style="info" %}
With `managedKeycloak: false`, the fields the components need are **reconcile-required**, not schema-required. A `Validator` missing them applies successfully and then reports `InvalidSpec`. See [External Identity Provider](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/external-identity-provider).
{% endhint %}

***

## `spec.database`

Schema-required inside: `host`, `participantDb`, `validatorDb`, `credentialsSecretRef.name`.

<table><thead><tr><th width="330">Field</th><th width="110">Type</th><th width="130">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>host</code></td><td>string</td><td>—</td><td>PostgreSQL host. <strong>Schema required.</strong></td></tr><tr><td><code>port</code></td><td>integer</td><td><code>5432</code></td><td>PostgreSQL port. Must be 1–65535.</td></tr><tr><td><code>participantDb</code></td><td>string</td><td>—</td><td>Participant database name. <strong>Schema required.</strong></td></tr><tr><td><code>participantSchema</code></td><td>string</td><td><code>participant</code></td><td>Participant schema.</td></tr><tr><td><code>validatorDb</code></td><td>string</td><td>—</td><td>Validator app database name. <strong>Schema required.</strong></td></tr><tr><td><code>validatorSchema</code></td><td>string</td><td><code>validator</code></td><td>Validator app schema.</td></tr><tr><td><code>pqsDatabase</code></td><td>string</td><td>—</td><td>PQS database name. <strong>Reconcile required when <code>pqs.enabled</code>.</strong></td></tr><tr><td><code>pqsSchema</code></td><td>string</td><td><code>pqs</code></td><td>PQS schema.</td></tr><tr><td><code>walletGatewayStoreDatabase</code></td><td>string</td><td>—</td><td>Wallet Gateway store database. <strong>Reconcile required when <code>walletGateway.enabled</code>.</strong></td></tr><tr><td><code>walletGatewaySigningDatabase</code></td><td>string</td><td>—</td><td>Wallet Gateway signing database. <strong>Reconcile required when <code>walletGateway.enabled</code>.</strong></td></tr><tr><td><code>credentialsSecretRef.name</code></td><td>string</td><td>—</td><td>Secret with the database credentials. <strong>Schema required.</strong></td></tr><tr><td><code>credentialsSecretRef.usernameKey</code></td><td>string</td><td><code>username</code></td><td>Key holding the username.</td></tr><tr><td><code>credentialsSecretRef.passwordKey</code></td><td>string</td><td><code>password</code></td><td>Key holding the password.</td></tr></tbody></table>

{% hint style="info" %}
The operator creates the databases and schemas for you, so these credentials need `CREATEDB` privileges and access to the `postgres` maintenance database.
{% endhint %}

***

## `spec.network`

Schema-required inside: `partyHint`.

<table><thead><tr><th width="330">Field</th><th width="130">Type</th><th width="110">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>partyHint</code></td><td>string</td><td>—</td><td>Party ID hint, and the wallet username under managed authentication. <strong>Schema required</strong>, and pattern-validated — see below.</td></tr><tr><td><code>spliceVersion</code></td><td>string</td><td>—</td><td>Single image tag for the participant, validator app, and both UIs, used when a component has no <code>version</code> of its own.</td></tr><tr><td><code>migrationId</code></td><td>string</td><td><code>"1"</code></td><td>Canton domain migration ID. A string, not an integer.</td></tr><tr><td><code>onboardingSecretName</code></td><td>string</td><td>—</td><td>Secret holding the Super Validator onboarding token, under the key <code>secret</code>.</td></tr><tr><td><code>sponsorSvUrl</code></td><td>string</td><td>—</td><td>Sponsoring Super Validator URL.</td></tr><tr><td><code>contactPoint</code></td><td>string</td><td>—</td><td>Operator contact point published to the network.</td></tr><tr><td><code>scan.address</code></td><td>string</td><td>—</td><td>Scan service address.</td></tr><tr><td><code>scan.type</code></td><td>string</td><td>—</td><td>Scan mode. Use <code>bft</code> with <code>seedUrls</code>, or <code>trust-single</code> with a single <code>address</code>.</td></tr><tr><td><code>scan.seedUrls</code></td><td>string[]</td><td>—</td><td>BFT scan seed URLs.</td></tr><tr><td><code>synchronizer.connectionType</code></td><td>string</td><td>—</td><td>Sequencer connection mode: <code>bft</code> or <code>trust-single</code>.</td></tr><tr><td><code>synchronizer.url</code></td><td>string</td><td>—</td><td>Sequencer URL. Used with <code>trust-single</code>.</td></tr></tbody></table>

{% hint style="danger" %}
**`partyHint` is pattern-validated** as `^[a-zA-Z0-9]+-[a-zA-Z0-9]+-[0-9]+$` — two alphanumeric segments and a numeric segment, hyphen-separated. `catalyx-devnet-001` is valid; `myvalidator` and `my_validator_1` are rejected at apply time.
{% endhint %}

{% hint style="warning" %}
**`scan` and `synchronizer` are effectively required**, even though the schema does not mark them so. A validator without them fails to reconcile.

**`scan.type` and `synchronizer.connectionType` are not enum-validated.** Only `trust-single` is treated specially; every other value — including a typo — takes the BFT path. Check the spelling.
{% endhint %}

***

## `spec.participant` and `spec.validator`

Both blocks are optional and take operator defaults. `spec.participant` additionally has `nodeIdentifier`; `spec.validator` additionally has `dumpPath`.

<table><thead><tr><th width="330">Field</th><th width="180">Operator default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>version</code></td><td><code>spec.network.spliceVersion</code></td><td>Image tag. <strong>Reconcile required</strong> if <code>spliceVersion</code> is also unset.</td></tr><tr><td><code>participant.nodeIdentifier</code></td><td><code>spec.network.partyHint</code></td><td>Canton participant node identifier.</td></tr><tr><td><code>validator.dumpPath</code></td><td>—</td><td>Path to a domain migration dump.</td></tr><tr><td><code>resources.requests.cpu</code> / <code>.memory</code></td><td><code>2</code> / <code>3Gi</code></td><td>CPU and memory requests.</td></tr><tr><td><code>resources.limits.cpu</code> / <code>.memory</code></td><td><code>3</code> / <code>6Gi</code></td><td>CPU and memory limits.</td></tr><tr><td><code>jvm.minHeap</code> / <code>.maxHeap</code></td><td><code>2048m</code> / <code>4096m</code></td><td>JVM heap bounds.</td></tr><tr><td><code>jvm.logbackConfigFile</code></td><td><code>/app/logback.xml</code></td><td>Logback configuration path.</td></tr><tr><td><code>participant.service.jsonApiPort</code></td><td><code>7575</code></td><td>JSON API port.</td></tr><tr><td><code>participant.service.ledgerApiPort</code></td><td><code>5001</code></td><td>Ledger API port.</td></tr><tr><td><code>participant.service.adminApiPort</code></td><td><code>5002</code></td><td>Admin API port.</td></tr><tr><td><code>validator.service.apiPort</code></td><td><code>5003</code></td><td>Validator app HTTP API port.</td></tr><tr><td><code>service.metricsPort</code></td><td><code>10013</code></td><td>Metrics port.</td></tr></tbody></table>

{% hint style="danger" %}
**Heap and memory limit are validated together.** The operator rejects the validator if `jvm.maxHeap` would not fit inside `resources.limits.memory` — the container would otherwise be OOM-killed. The limit must also leave headroom for JVM non-heap memory.

Heap values use **JVM units** with an optional `k`, `m`, or `g` suffix — `2048m`, `2g`. Kubernetes-style units such as `Mi` and `Gi` are rejected.
{% endhint %}

{% hint style="warning" %}
If you supply a `requests` or `limits` block, **both `cpu` and `memory` are required inside it**. A partial block is rejected at apply time.
{% endhint %}

***

## `spec.ui`

`wallet` and `cns` take the same fields.

<table><thead><tr><th width="330">Field</th><th width="180">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>wallet.enabled</code> / <code>cns.enabled</code></td><td><code>true</code> (schema)</td><td>Whether the UI runs.</td></tr><tr><td><code>wallet.version</code> / <code>cns.version</code></td><td><code>spliceVersion</code> (operator)</td><td>Image tag. <strong>Reconcile required</strong> if <code>spliceVersion</code> is also unset — <em>even when the UI is disabled.</em></td></tr><tr><td><code>resources.requests.cpu</code> / <code>.memory</code></td><td><code>100m</code> / <code>128Mi</code> (operator)</td><td>Requests.</td></tr><tr><td><code>resources.limits.cpu</code> / <code>.memory</code></td><td><code>3</code> / <code>128Mi</code> (operator)</td><td>Limits.</td></tr><tr><td><code>branding.networkName</code></td><td><code>Canton Network</code></td><td>Network display name.</td></tr><tr><td><code>branding.networkFaviconUrl</code></td><td>Canton Network favicon</td><td>Favicon URL.</td></tr><tr><td><code>branding.amuletName</code></td><td><code>Canton Coin</code></td><td>Coin display name.</td></tr><tr><td><code>branding.amuletNameAcronym</code></td><td><code>CC</code></td><td>Coin acronym.</td></tr><tr><td><code>branding.nameServiceName</code></td><td><code>Amulet Name Service</code></td><td>Name service display name.</td></tr><tr><td><code>branding.nameServiceNameAcronym</code></td><td><code>ANS</code></td><td>Name service acronym.</td></tr></tbody></table>

{% hint style="info" %}
Setting `enabled: false` scales the UI to zero replicas rather than removing it. It still appears as a component in the UI and still requires a resolvable version.
{% endhint %}

***

## `spec.pqs`

<table><thead><tr><th width="330">Field</th><th width="180">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>enabled</code></td><td><code>false</code> (schema)</td><td>Deploy the Participant Query Store.</td></tr><tr><td><code>version</code></td><td>—</td><td>Image tag. <strong>Required when enabled</strong>, and does <em>not</em> fall back to <code>spliceVersion</code>.</td></tr><tr><td><code>ledgerStart</code></td><td><code>Latest</code> (schema)</td><td>Where the pipeline starts reading.</td></tr><tr><td><code>resources.requests.cpu</code> / <code>.memory</code></td><td><code>500m</code> / <code>1Gi</code></td><td>Requests.</td></tr><tr><td><code>resources.limits.cpu</code> / <code>.memory</code></td><td><code>3</code> / <code>2Gi</code></td><td>Limits.</td></tr><tr><td><code>jvm.minHeap</code> / <code>.maxHeap</code></td><td><code>512m</code> / <code>1536m</code></td><td>JVM heap bounds.</td></tr></tbody></table>

Also requires `spec.database.pqsDatabase`. See [Participant Query Store](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/participant-query-store).

***

## `spec.walletGateway`

<table><thead><tr><th width="380">Field</th><th width="170">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>enabled</code></td><td><code>false</code> (schema)</td><td>Deploy the Wallet Gateway.</td></tr><tr><td><code>version</code></td><td>—</td><td>Image tag. <strong>Required when enabled</strong>, enforced by the schema.</td></tr><tr><td><code>resources.requests.cpu</code> / <code>.memory</code></td><td><code>250m</code> / <code>512Mi</code></td><td>Requests.</td></tr><tr><td><code>resources.limits.cpu</code> / <code>.memory</code></td><td><code>1</code> / <code>1Gi</code></td><td>Limits.</td></tr><tr><td><code>dfns.orgId</code></td><td>—</td><td>Provider organisation ID.</td></tr><tr><td><code>dfns.apiUrl</code></td><td>—</td><td>Provider API base URL.</td></tr><tr><td><code>dfns.credentialId</code></td><td>—</td><td>Provider credential ID.</td></tr><tr><td><code>dfns.credentialsSecretRef.name</code></td><td>—</td><td>Secret with the provider credentials. <strong>Schema required</strong> when the block is present.</td></tr><tr><td><code>dfns.credentialsSecretRef.privateKeyKey</code></td><td><code>private-key</code></td><td>Key holding the private key.</td></tr><tr><td><code>dfns.credentialsSecretRef.authTokenKey</code></td><td><code>auth-token</code></td><td>Key holding the auth token.</td></tr></tbody></table>

Also requires `spec.auth.enabled: true`, an auth URL, a backend client ID, a Wallet Gateway client ID, a target audience, a user-management scope, and both Wallet Gateway databases. See [Wallet Gateway](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway).

***

## `spec.kms`

<table><thead><tr><th width="330">Field</th><th width="130">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>enabled</code></td><td><code>false</code></td><td>Hold Canton keys in an external KMS.</td></tr><tr><td><code>provider</code></td><td>—</td><td><code>azure</code> or <code>aws</code>. <strong>Case-sensitive</strong>, and required when enabled.</td></tr></tbody></table>

### `spec.kms.azure`

Schema-required inside: `vaultUrl`, `preBuiltImage`.

<table><thead><tr><th width="330">Field</th><th width="150">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>vaultUrl</code></td><td>—</td><td>Key vault URL. <strong>Schema required.</strong></td></tr><tr><td><code>preBuiltImage</code></td><td>—</td><td>KMS-enabled participant image. <strong>Schema required</strong>, and it <em>replaces</em> the normal participant image.</td></tr><tr><td><code>imagePullSecret</code></td><td>—</td><td>Pull secret for that image.</td></tr><tr><td><code>keyNamePrefix</code></td><td>—</td><td>Prefix for generated key names.</td></tr><tr><td><code>credentialType</code></td><td>—</td><td><code>default</code>, <code>environment</code>, or <code>managedIdentity</code>. Omit for a service principal.</td></tr><tr><td><code>tenantId</code>, <code>clientId</code></td><td>—</td><td>Service principal identifiers.</td></tr><tr><td><code>clientSecretRef.name</code> / <code>.key</code></td><td>— / <code>client-secret</code></td><td>Service principal secret. The key default is applied by the operator, not the schema.</td></tr><tr><td><code>hardwareBackedKeys</code></td><td>driver default</td><td>Create HSM-protected keys.</td></tr><tr><td><code>healthProbeKey</code></td><td>driver default</td><td>Key name used as a connectivity probe.</td></tr><tr><td><code>auditLogging</code>, <code>auditNodeId</code></td><td>driver default</td><td>KMS request auditing.</td></tr><tr><td><code>eagerCredentialCheck</code></td><td>driver default</td><td>Acquire a token at startup to fail fast.</td></tr><tr><td><code>aesKeySizeBits</code></td><td>driver default</td><td>128, 192, or 256.</td></tr><tr><td><code>kekRsaKeySizeBits</code></td><td>driver default</td><td>2048, 3072, or 4096.</td></tr><tr><td><code>requirePinnedKeyVersion</code>, <code>validateKeySpec</code>, <code>requireKeyOps</code>, <code>rejectExportableKeys</code>, <code>hardenGeneratedKeys</code>, <code>requireStrongKek</code></td><td>driver default</td><td>Strict-mode security checks.</td></tr><tr><td><code>cryptoClientCacheSize</code>, <code>cryptoClientCacheIdleMinutes</code>, <code>ioThreads</code>, <code>httpIdleTimeoutSeconds</code>, <code>httpMaxConnections</code>, <code>httpResponseTimeoutSeconds</code></td><td>driver default</td><td>Performance and connection tuning.</td></tr></tbody></table>

{% hint style="info" %}
Fields marked *driver default* have **no default in the CRD**. Omitting one emits no configuration at all, and the KMS driver's own default applies. Set a value explicitly if you need to depend on it.
{% endhint %}

### `spec.kms.aws`

Schema-required inside: `region`.

<table><thead><tr><th width="380">Field</th><th width="180">Default</th><th>Purpose</th></tr></thead><tbody><tr><td><code>region</code></td><td>—</td><td>AWS region. <strong>Schema required.</strong></td></tr><tr><td><code>serviceAccountName</code></td><td>—</td><td>Pre-created service account for IRSA. CAT-BM does not create it.</td></tr><tr><td><code>credentialsSecretRef.name</code></td><td>—</td><td>Static credentials secret. <strong>Schema required</strong> when the block is present.</td></tr><tr><td><code>credentialsSecretRef.accessKeyIdKey</code></td><td><code>access-key-id</code></td><td>Applied by the operator, not the schema.</td></tr><tr><td><code>credentialsSecretRef.secretAccessKeyKey</code></td><td><code>secret-access-key</code></td><td>Applied by the operator, not the schema.</td></tr><tr><td><code>credentialsSecretRef.sessionTokenKey</code></td><td>—</td><td>For temporary or assumed-role credentials.</td></tr><tr><td><code>multiRegionKey</code></td><td>—</td><td>Use a multi-region key.</td></tr><tr><td><code>auditLogging</code></td><td>—</td><td>Log KMS operations.</td></tr></tbody></table>

There is no `preBuiltImage` for AWS — the standard participant image is used.

***

## `spec.overrides`

Appends environment variables to a component's container. Each block takes an `extraEnv` array using the standard Kubernetes `EnvVar` schema, so `value`, `secretKeyRef`, `configMapKeyRef`, and the other reference forms are all available.

```yaml
spec:
  overrides:
    participant:
      extraEnv:
        - name: MY_SETTING
          value: "value"
```

Available for `participant`, `validator`, `walletUi`, and `cnsUi`.

{% hint style="info" %}
There is no `overrides` block for PQS or the Wallet Gateway. Those components are configured only through their own fields.
{% endhint %}

***

## Status

The status subresource is written by the operator. It is read-only.

<table><thead><tr><th width="380">Field</th><th>Meaning</th></tr></thead><tbody><tr><td><code>status.observedGeneration</code></td><td>The resource generation the operator last reconciled. Compare against <code>metadata.generation</code> to see whether your change has been picked up.</td></tr><tr><td><code>status.conditions[]</code></td><td>A single <code>Ready</code> condition, with <code>status</code>, <code>reason</code>, <code>message</code>, and <code>lastTransitionTime</code>.</td></tr><tr><td><code>status.databaseProvisioned</code></td><td>Participant and validator databases created.</td></tr><tr><td><code>status.pqsDatabaseProvisioned</code></td><td>PQS database created. Present only when PQS is enabled.</td></tr><tr><td><code>status.walletGatewayDatabaseProvisioned</code></td><td>Wallet Gateway databases created. Present only when enabled.</td></tr><tr><td><code>status.applications.&#x3C;component></code></td><td>Per-component summary — <code>name</code>, <code>ready</code>, <code>reason</code>, <code>message</code>, <code>lastTransitionTime</code>. Components: <code>participant</code>, <code>validatorBackend</code>, <code>walletUi</code>, <code>cnsUi</code>, and <code>pqs</code> / <code>walletGateway</code> when enabled.</td></tr><tr><td><code>status.managedAuth</code></td><td>The result of managed authentication provisioning. See <a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/managed-keycloak">Managed Keycloak</a>.</td></tr></tbody></table>

### `Ready` condition reasons

| Reason                 | Meaning                                                                                 |
| ---------------------- | --------------------------------------------------------------------------------------- |
| `AllApplicationsReady` | Healthy                                                                                 |
| `ApplicationNotReady`  | A component has not come up. Check `status.applications`                                |
| `InvalidSpec`          | Configuration error. The message names the field                                        |
| `ReconcileError`       | A non-configuration failure — often the database or identity provider being unreachable |

### Printer columns

```bash
kubectl -n <namespace> get validators        # NAME, READY, AGE
kubectl -n <namespace> get validators -o wide  # adds REASON
```

***

## The `Application` resource

The operator creates one `Application` per component, as a child of the `Validator`.

{% hint style="danger" %}
**Never create, edit, or delete `Application` resources.** They are an operator implementation detail. A hand-created one is unowned and unmanaged; an edited one is reverted on the next reconcile. All configuration flows through the `Validator`.
{% endhint %}

`Application` resources are useful to *read*, though — they show exactly what the operator generated:

```bash
kubectl -n <namespace> get applications
kubectl -n <namespace> get application my-validator-participant -o yaml
```

Their status carries the generated `deployment`, `service`, and `ingress` names, the internal and external `endpoints`, and a `Ready` condition whose reason is one of `DeploymentNotFound`, `DeploymentAvailable`, or `DeploymentUnavailable`. The UI surfaces all of it on the [Applications](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications) pages.

***

## Schema stability

{% hint style="info" %}
The served version is `catalyx.manager.canton/v1alpha1`. **Field-level changes may still occur in a future minor release.** Keep your `Validator` resources under version control, and read the [Release Notes](/catalyx-blockchain-manager/canton-network/version-2.0/release-notes) before upgrading the platform.
{% endhint %}


# User Guide

The CatalyX UI is a web application for operating Canton validators without direct cluster access. It talks only to the CatalyX API, never to Kubernetes or to the Canton nodes directly.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-843402cb0fb6628bc946a92e4f489929ad61b149%2Fimage%20(150).png?alt=media" alt=""><figcaption></figcaption></figure></div>

***

## Overview

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Dashboard</strong></td><td>Fleet-wide health at a glance.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/dashboard">Dashboard</a></td></tr><tr><td><strong>Validator Overview</strong></td><td>Every validator in the cluster, with live status.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators-list">Validator Overview</a></td></tr><tr><td><strong>Validator Details</strong></td><td>The 13-tab detail view for a single validator.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators">Validator Details</a></td></tr><tr><td><strong>Applications</strong></td><td>Component-level health and resource usage.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications">Applications</a></td></tr><tr><td><strong>Canton Console</strong></td><td>An interactive Canton console in the browser.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console">Canton Console</a></td></tr><tr><td><strong>Grafana</strong></td><td>Metrics and log deep links.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/grafana-dashboards">Grafana Dashboards</a></td></tr></tbody></table>

***

## Navigation

The sidebar has three primary destinations:

|                  |                                                       |
| ---------------- | ----------------------------------------------------- |
| **Dashboard**    | Fleet-wide summary and the Canton console             |
| **Validators**   | The validator list, and every validator's detail view |
| **Applications** | Every component deployed for every validator          |

Below them, **Help** opens this documentation. The sidebar can be collapsed with **Cmd/Ctrl + `\`**.

### Environment badge

The sidebar shows which environment you are looking at, derived from the hostname you are on:

| Badge        | Shown when                                             |
| ------------ | ------------------------------------------------------ |
| `Local`      | The hostname is `localhost`, `127.0.0.1`, or `0.0.0.0` |
| `Dev`        | The hostname contains a `dev` or `staging` segment     |
| `Production` | Anything else                                          |

{% hint style="warning" %}
`Production` is the fallback, not a positive detection. Any hostname that does not look local or dev is labelled `Production`.
{% endhint %}

***

## How to read the UI

### Everything refreshes itself

There is no refresh button on most screens, and no "last updated" indicator — the UI polls continuously:

| Data                                                    | Interval  |
| ------------------------------------------------------- | --------- |
| Validator status, applications list, application status | 3 seconds |
| Resource metrics                                        | 5 seconds |

The Parties tab is the exception: its lists have an explicit **Refresh** button, because reading the synchronizer topology store is comparatively expensive.

### Status vocabulary

The UI uses a small, consistent set of status words. Two of them are worth learning precisely, because they mean different things in different places.

**Validator readiness**

| Value      | Meaning                                                |
| ---------- | ------------------------------------------------------ |
| `Ready`    | Every component the validator owns is ready            |
| `Degraded` | At least one is not (shown on the lists and Dashboard) |

On the validator detail header, a validator that is not ready shows the underlying **reason** instead of the word `Degraded` — which is more specific and worth reading.

**Participant connection**

| List page      | Detail page    | Meaning                                                                                       |
| -------------- | -------------- | --------------------------------------------------------------------------------------------- |
| `Live`         | `Connected`    | The participant is initialised and its synchronizer connection is healthy                     |
| `Disconnected` | `Disconnected` | Initialised, but the synchronizer connection is unhealthy                                     |
| `Initializing` | `Initializing` | The participant is still starting up                                                          |
| `Not live`     | *(no badge)*   | No participant status was returned — usually still loading, or the participant is unreachable |

**Health values** on participant components and synchronizers are the raw values Canton reports, colour-coded: `ok` and `healthy` are good, `degraded` is a warning, `failed`, `fatal`, and `unhealthy` are errors, and anything else is treated as unknown.

**Kubernetes conditions** appear as `True`, `False`, or `Unknown`.

### Copying identifiers

Party IDs, package IDs, endpoints, and other long values are truncated for display, with the full value in a tooltip. A copy button beside each one copies the **complete** value, never the truncated form, and confirms with a brief toast.

### Tables

All tables in the UI behave the same way:

* Columns can be resized, and your widths are remembered per table.
* Rows that lead somewhere are clickable, and respond to Enter or Space.
* Some rows expand to reveal detail, via a chevron on the left.
* Narrow screens fall back to a card layout instead of a horizontal scroll.
* Tables with many rows paginate at 10 rows, with a page size selector offering 10, 25, 50, or 100.

***

## What the UI does not do

Being clear about this up front saves time hunting for a button that is not there.

<table><thead><tr><th width="290">Not in the UI</th><th>Where it lives instead</th></tr></thead><tbody><tr><td>Creating, editing, or deleting a validator</td><td>Apply or delete a <code>Validator</code> custom resource — see <a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/create-a-validator">Create a Validator</a></td></tr><tr><td>Creating, editing, deleting, scaling, or restarting an application</td><td>The operator owns these. Change the <code>Validator</code> resource</td></tr><tr><td>Ledger pruning</td><td>Not exposed in 2.0. Use the <a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console">Canton console</a></td></tr><tr><td>Traffic purchases or balance top-ups</td><td>Not exposed in 2.0. The Balances and Traffic tabs are read-only</td></tr><tr><td>Generating, rotating, or importing participant keys</td><td>Not exposed in 2.0. The Keys tab is read-only</td></tr><tr><td>Full-text search across validators</td><td>Search exists within the DAR packages list and the Parties tab only</td></tr></tbody></table>

## Permissions

The UI requires a valid OIDC token from the identity provider configured at install time. Any user who can authenticate can reach every screen, including the operations that change ledger state.

{% hint style="danger" %}
There is no per-validator or per-screen authorisation inside the UI in 2.0. Restrict who can obtain a token for the UI client in your identity provider, and treat UI access as privileged — the [Canton console](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console) in particular grants full administrative access to the participant.
{% endhint %}


# Dashboard

Fleet-wide validator and application health.

The Dashboard is the CatalyX UI's landing page. It answers one question — *is anything wrong?* — and gives you the Canton console.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-843402cb0fb6628bc946a92e4f489929ad61b149%2Fimage%20(150).png?alt=media" alt=""><figcaption></figcaption></figure></div>

## Summary cards

Four cards across the top aggregate every validator the UI can see.

<table><thead><tr><th width="180">Card</th><th width="230">Value</th><th>Badge</th></tr></thead><tbody><tr><td><strong>Validators</strong></td><td>Total number of validators.</td><td><strong>View all →</strong> links to the Validators list.</td></tr><tr><td><strong>Ready</strong></td><td><code>ready / total</code>.</td><td><strong>All healthy</strong> when every validator is ready.</td></tr><tr><td><strong>Issues</strong></td><td>Number of validators that are not ready.</td><td><strong>Degraded</strong> when the count is above zero.</td></tr><tr><td><strong>Applications</strong></td><td><code>ready / total</code> across every component of every validator.</td><td><strong>View all →</strong> links to the Applications list.</td></tr></tbody></table>

A validator counts as ready when its `Ready` condition is `True`. **Issues** is simply the remainder.

{% hint style="info" %}
The Applications count comes from each validator's reported component status, so it includes components that have not yet produced a workload. The [Applications](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications) list is the authoritative view of what is actually deployed.
{% endhint %}

## Canton Console panel

Below the cards sits the [Canton Console](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console) — an interactive Canton console session in the browser. It is collapsed by default and this is the only place in the UI where it appears.

## Where to go next

The Dashboard deliberately does not try to tell you *what* is wrong. When the **Issues** card is non-zero:

{% stepper %}
{% step %}
**Open the Validators list**

The [Validators list](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators-list) shows per-validator status, plus the participant connection state, which is usually the fastest signal.
{% endstep %}

{% step %}
**Open the affected validator**

Its [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) tab breaks readiness down per component.
{% endstep %}

{% step %}
**Read the conditions**

The [Status](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification) tab shows the reason and message the operator posted, which names the specific problem.
{% endstep %}
{% endstepper %}


# Validator Overview

The Validators list is the main working view for an operator running more than one validator. Every row is live — status, participant connection, and balance all refresh on their own.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-bc36ca9f6be3d0cd2434417ea4a17eb0e3789bdc%2Fimage%20(153).png?alt=media" alt=""><figcaption></figcaption></figure></div>

## Validator Overview

Above the table: **`n` total**, **`n` ready**, **`n` issues**. The issues figure turns amber when it is above zero.

<table><thead><tr><th width="170">Column</th><th>Contents</th></tr></thead><tbody><tr><td><strong>Name</strong></td><td>The validator's name.</td></tr><tr><td><strong>Network</strong></td><td><code>DevNet</code>, <code>TestNet</code>, or <code>MainNet</code>, inferred from the Canton endpoints configured on the validator.</td></tr><tr><td><strong>Party ID</strong></td><td>The validator's primary party, truncated, with a copy button.</td></tr><tr><td><strong>Version</strong></td><td>The validator app version — the component's own <code>version</code>, or the validator's <code>spliceVersion</code>.</td></tr><tr><td><strong>Balance</strong></td><td>The validator's Canton Coin balance, to two decimal places. Shows <code>Loading…</code> until the Scan endpoint responds.</td></tr><tr><td><strong>Participant</strong></td><td>Connection state: <code>Live</code>, <code>Disconnected</code>, <code>Initializing</code>, or <code>Not live</code>.</td></tr><tr><td><strong>Status</strong></td><td><code>Ready</code> or <code>Degraded</code>.</td></tr><tr><td><strong>Metrics</strong></td><td>Opens the participant dashboard in Grafana, in a new tab.</td></tr><tr><td><strong>Logs</strong></td><td>Opens the participant's logs in Grafana, in a new tab.</td></tr></tbody></table>

{% hint style="info" %}
**`Status` and `Participant` answer different questions.** `Status` is about Kubernetes: are all the workloads running? `Participant` is about Canton: is the node initialised and talking to the synchronizer? A validator can show `Ready` and `Disconnected` at the same time — every pod is healthy, but the node has lost its synchronizer connection. That combination is the one worth looking into first.
{% endhint %}

## Actions

* **Click a row** to open that validator's detail view.
* **Metrics** and **Logs** open Grafana without navigating away from the UI. See [Grafana Links](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/grafana-dashboards).

## Empty and error states

| Situation                    | What you see                                                                   |
| ---------------------------- | ------------------------------------------------------------------------------ |
| No validators exist          | **No validators found** — *No Canton validators are deployed in this cluster.* |
| The list could not be loaded | **Failed to load validators**, with the error message                          |

{% hint style="warning" %}
The UI only sees validators in the namespace the API is configured to watch. A validator applied to a different namespace will not appear here, and is not being reconciled by the platform either.
{% endhint %}


# Validator Details

Opening a validator opens the validator details, and a left-hand navigation of thirteen tabs grouped into four sections.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-4852713c00479f482f78ee94e7410bbb8fc5fdef%2Fimage%20(154).png?alt=media" alt=""><figcaption></figcaption></figure></div>

## Header Details

<table><thead><tr><th width="200">Element</th><th>Contents</th></tr></thead><tbody><tr><td>Breadcrumb</td><td><strong>Back to validators</strong>.</td></tr><tr><td>Title</td><td>The validator's name.</td></tr><tr><td>Network badge</td><td><code>DevNet</code>, <code>TestNet</code>, or <code>MainNet</code>.</td></tr><tr><td>Readiness badge</td><td><code>Ready</code>, or the <strong>reason</strong> the validator is not ready — for example <code>ApplicationNotReady</code> or <code>InvalidSpec</code>.</td></tr><tr><td>Connection badge</td><td><code>Connected</code>, <code>Disconnected</code>, or <code>Initializing</code>. No badge is shown when no participant status has been returned.</td></tr><tr><td><strong>Party ID</strong> row</td><td>The validator's primary party, with a copy button.</td></tr></tbody></table>

## Tab Details

### Overview

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Summary</strong></td><td>Component-by-component health, resources, and restarts.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary">Summary</a></td></tr><tr><td><strong>Status</strong></td><td>The raw conditions the operator posted, and provisioning flags.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification#status">Status &amp; Specification</a></td></tr><tr><td><strong>Specification</strong></td><td>The validator's configuration as applied.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification#specification">Status &amp; Specification</a></td></tr></tbody></table>

### Network

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Balances</strong></td><td>Canton Coin holdings and holding fees.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/balances-and-traffic#balances">Balances &amp; Traffic</a></td></tr><tr><td><strong>Traffic</strong></td><td>Synchronizer traffic counters.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/balances-and-traffic#traffic">Balances &amp; Traffic</a></td></tr></tbody></table>

### Ledger

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Parties</strong></td><td>Hosted parties, hosting proposals, and party lookup.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/parties">Parties</a></td></tr><tr><td><strong>DARs</strong></td><td>Daml packages known to the participant, and DAR upload.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/dars">DARs</a></td></tr><tr><td><strong>Participant</strong></td><td>Participant node health, synchronizers, and identity.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys#participant">Participant &amp; Keys</a></td></tr><tr><td><strong>Keys</strong></td><td>Public keys in the participant's key vault.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys#keys">Participant &amp; Keys</a></td></tr></tbody></table>

### Access

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Users</strong></td><td>Ledger users and their rights.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/users-and-wallet-users#users">Users &amp; Wallet Users</a></td></tr><tr><td><strong>Wallet Users</strong></td><td>Users onboarded to the Wallet UI.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/users-and-wallet-users#wallet-users">Users &amp; Wallet Users</a></td></tr><tr><td><strong>Identity</strong></td><td>OIDC configuration, and the identity dump download.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/identity-and-endpoints#identity">Identity &amp; Endpoints</a></td></tr><tr><td><strong>Endpoints</strong></td><td>Internal and external URLs for every component.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/identity-and-endpoints#endpoints">Identity &amp; Endpoints</a></td></tr></tbody></table>

## Which tabs can change something

Most of the detail view is read-only. Nine of the thirteen tabs only display information. Four support operations:

<table><thead><tr><th width="180">Tab</th><th>Operations</th></tr></thead><tbody><tr><td><strong>Parties</strong></td><td>Allocate a party, onboard an external party, approve a hosting proposal, amend a party's hosting.</td></tr><tr><td><strong>DARs</strong></td><td>Upload a <code>.dar</code> package.</td></tr><tr><td><strong>Users</strong></td><td>Create a ledger user, edit a user and its rights.</td></tr><tr><td><strong>Wallet Users</strong></td><td>Onboard and offboard wallet users.</td></tr></tbody></table>

Plus **Identity**, which lets you download an identity dump — a read operation, but one that produces a highly sensitive file.

{% hint style="danger" %}
These operations act on the live ledger and take effect immediately. Only wallet user removal asks for confirmation; DAR upload, party allocation, user changes, and hosting approval do not.
{% endhint %}


# Summary

The Summary tab is where you start when a validator is not behaving. It shows the participant node's health and then every component the validator owns, in one table.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-cb6cd0066a699aa88a0f1f7082154625eb0c7796%2Fimage%20(155).png?alt=media" alt=""><figcaption></figcaption></figure></div>

## Metric cards

| Card        | Value                                                                                   |
| ----------- | --------------------------------------------------------------------------------------- |
| **Status**  | `Ready` or `Degraded`, with a badge showing the percentage of components that are ready |
| **Network** | `DevNet`, `TestNet`, or `MainNet`                                                       |
| **Balance** | Canton Coin balance, to two decimal places                                              |

## Participant

Shown once the participant has reported status. The badge is `Connected`, `Disconnected`, or `Initializing`.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-08cc4945f70e40aaa9041f5d6fabfee330e83a8e%2Fimage%20(156).png?alt=media" alt=""><figcaption></figcaption></figure></div>

<table><thead><tr><th width="200">Row</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>Initialized</strong></td><td>Whether the node has completed initialisation.</td></tr><tr><td><strong>Active</strong></td><td>Whether the node is the active instance.</td></tr><tr><td><strong>Components</strong></td><td><code>healthy / total</code> of the participant's internal health components. Turns amber when any is unhealthy.</td></tr><tr><td><strong>Version</strong></td><td>The Canton participant version.</td></tr><tr><td><strong>UID</strong></td><td>The participant's unique identifier.</td></tr><tr><td><strong>Waiting for</strong></td><td>What the node is blocked on, when it is still initialising.</td></tr></tbody></table>

Below that, **Health components** lists each internal component with its status and description. The same table appears in more depth on the [Participant](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys) tab.

## Applications

One row per component, always in this order:

`Participant` · `Validator Backend` · `Wallet UI` · `CNS UI` · `PQS` · `Wallet Gateway`

PQS and Wallet Gateway rows only appear when those components are enabled.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-3434a20a4fb4cd35504b5c011bd8040da1609836%2Fimage%20(157).png?alt=media" alt=""><figcaption></figcaption></figure></div>

<table><thead><tr><th width="160">Column</th><th>Contents</th></tr></thead><tbody><tr><td><strong>Application</strong></td><td>The component name.</td></tr><tr><td><strong>CPU</strong></td><td>Current usage against the limit, as a bar and a percentage, with the raw <code>used / limit</code> beneath.</td></tr><tr><td><strong>Memory</strong></td><td>Same, in bytes.</td></tr><tr><td><strong>Restarts</strong></td><td>Container restart count. Amber when above zero.</td></tr><tr><td><strong>Since</strong></td><td>When the component last changed readiness.</td></tr><tr><td><strong>Status</strong></td><td><code>Ready</code> or <code>Pending</code>.</td></tr><tr><td>—</td><td>Grafana metrics link (participant only) and Grafana logs link.</td></tr></tbody></table>

{% hint style="info" %}
This tab uses `Pending` rather than `Degraded` for a component that is not ready — the same underlying state, a different word. The [Applications](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications) list shows the operator's specific reason instead.
{% endhint %}

### Expanding a row

Each row expands to show what the operator created and what Kubernetes reports back:

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-06f628da6497226097427412a4831db17f0eced5%2Fimage%20(158).png?alt=media" alt=""><figcaption></figcaption></figure></div>

<table><thead><tr><th width="230">Field</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>Deployment</strong></td><td>Name of the generated Deployment.</td></tr><tr><td><strong>Replicas</strong></td><td><code>ready / desired</code>.</td></tr><tr><td><strong>Service</strong></td><td>Name of the generated Service.</td></tr><tr><td><strong>Ingress</strong></td><td>Name of the generated IngressRoute, for externally reachable components.</td></tr><tr><td><strong>Observed Generation</strong></td><td>The generation of the resource the operator last reconciled.</td></tr><tr><td><strong>Internal URL</strong> / <strong>External URL</strong></td><td>In-cluster and public addresses.</td></tr></tbody></table>

Then **Resources by replica**, a per-pod table of phase, restarts, and CPU and memory usage against requests and limits; and finally the component's Kubernetes conditions, with type, status, reason, message, and last transition time.

{% hint style="warning" %}
If live usage figures are missing and a note says the cluster metrics API is not reachable, the `metrics-server` component is not installed or not healthy in your cluster. Requests and limits still display; only actual usage is unavailable.
{% endhint %}

## Restart notifications

While you have a validator open, the UI watches container restart counts. If a component restarts, a toast appears naming it and the number of new restarts. This is the fastest way to notice a crash-looping component without watching the table.

{% hint style="info" %}
Toasts are only shown in the desktop layout. On a narrow screen you will not see restart notifications — check the **Restarts** column instead.
{% endhint %}

## Empty state

**No application status** — *The validator has not reported any application status yet.* Normal for the first few seconds after applying a `Validator`; persistent otherwise, check the operator logs.


# Status & Specification

The conditions the operator posted, and the validator's configuration as applied. Status is what the operator reports, Specification is what you asked for.

## Status

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-d28e8e41d56ba0ef40d8df0b41dc18e49cc5c62a%2Fimage%20(159).png?alt=media" alt=""><figcaption></figcaption></figure></div>

### Metric cards

Each card appears only when the underlying value has been reported.

<table><thead><tr><th width="220">Card</th><th>Values</th></tr></thead><tbody><tr><td><strong>Database</strong></td><td><code>Provisioned</code> or <code>Pending</code> — whether the participant and validator databases have been created.</td></tr><tr><td><strong>Auth Provisioned</strong></td><td><code>Yes</code> or <code>No</code> — whether managed authentication has completed. Only meaningful when <code>managedKeycloak</code> is enabled.</td></tr><tr><td><strong>Observed Generation</strong></td><td>The generation of the <code>Validator</code> resource the operator last reconciled.</td></tr></tbody></table>

{% hint style="info" %}
**Observed Generation is the field to check after editing a validator.** If it lags behind the resource's current generation, your change has not been reconciled yet — or the reconcile is failing, in which case the conditions table below will say why.
{% endhint %}

### Conditions

| Column              | Contents                                         |
| ------------------- | ------------------------------------------------ |
| **Type**            | The condition type. In practice, always `Ready`. |
| **Status**          | `True`, `False`, or `Unknown`.                   |
| **Reason**          | A short machine-readable cause.                  |
| **Message**         | A human-readable explanation.                    |
| **Last transition** | When the status last changed.                    |

The reasons you will see:

<table><thead><tr><th width="230">Reason</th><th>What to do</th></tr></thead><tbody><tr><td><code>AllApplicationsReady</code></td><td>Nothing — the validator is healthy.</td></tr><tr><td><code>ApplicationNotReady</code></td><td>Go to <a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary">Summary</a> and find which component is <code>Pending</code>.</td></tr><tr><td><code>InvalidSpec</code></td><td>A configuration error. The message names the exact field. Fix the <code>Validator</code> resource and re-apply.</td></tr><tr><td><code>ReconcileError</code></td><td>Something outside the configuration failed — often the database or identity provider being unreachable. Check the operator logs.</td></tr></tbody></table>

Empty state: **No conditions reported** — *The controller has not posted any conditions for this validator.*

***

## Specification

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-d294b012786df9b63d401016ed505ba8c1c745c5%2Fimage%20(160).png?alt=media" alt=""><figcaption></figcaption></figure></div>

The validator's configuration, as it exists in the cluster, grouped by section: **Network**, **Participant**, **Validator**, **UI**, **Overrides**, then anything else alphabetically. Each group header shows how many fields it contains, and all groups are expanded by default.

* Booleans display as `Yes` / `No`.
* Long identifiers are truncated with a **Copy** button that copies the full value.
* Empty values show as `-`.

### What is deliberately hidden

{% hint style="warning" %}
This tab is **not** a faithful dump of the resource. Several things are filtered out by design:

* Any field whose path contains `secret`, `password`, `token`, `credential`, `privateKey`, `clientSecret`, or `apiKey`, plus the onboarding secret name — these are never displayed.
* Fields that are set to their default of `enabled: true`. Only `enabled: false` is shown, so an absent `enabled` row means the component is enabled.

For the complete resource, use `kubectl get validator <name> -o yaml`.
{% endhint %}

This is also the fastest way to confirm that a field you set actually took effect. Unknown fields are silently pruned by the Kubernetes API server, so a misspelled field name disappears without an error — if a setting seems to be ignored, look for it here first.

Empty state: **No spec fields** — *No specification fields available.*


# Balances & Traffic

Two read-only tabs covering the validator's economic position on the network: Canton Coin holdings and synchronizer traffic counters.

{% hint style="info" %}
Both tabs are **read-only in 2.0**. There is no top-up, purchase, mint, or transfer action in the UI in this release. Traffic purchases and Canton Coin transfers are performed through the Wallet UI or the Canton console.
{% endhint %}

## Balances

Canton Coin holdings, read from the network's Scan service.

### Metric cards

| Card               | Meaning                                                |
| ------------------ | ------------------------------------------------------ |
| **Total holdings** | The validator's total Canton Coin balance              |
| **Unlocked**       | The portion available to spend                         |
| **Locked**         | The portion locked in contracts. Amber when above zero |

### Snapshot

<table><thead><tr><th width="240">Row</th><th>Meaning</th></tr></thead><tbody><tr><td><strong>Owner party</strong></td><td>The party the balance belongs to.</td></tr><tr><td><strong>Available coin</strong></td><td>Spendable amount at the time of the snapshot.</td></tr><tr><td><strong>Record time</strong></td><td>Ledger time the snapshot was taken.</td></tr><tr><td><strong>Migration ID</strong></td><td>The Canton migration this balance is recorded against.</td></tr><tr><td><strong>Computed as of round</strong></td><td>The mining round the figures were computed for.</td></tr></tbody></table>

### Holding Fees

**Total**, **Unlocked**, and **Locked** holding fees — the ongoing cost of holding Canton Coin.

All amounts are formatted to exactly two decimal places, with thousands separators. A missing value shows as `—`.

### States

| Situation                                  | What you see                                                                                                                 |
| ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- |
| Scan has no balance for this validator yet | **No balance returned** — *Scan endpoint reported no balance for this validator yet.* Normal for a newly onboarded validator |
| The request failed                         | **Failed to load balances**, with the error                                                                                  |

***

## Traffic

Synchronizer traffic counters, read from the participant.

Canton meters the data a participant sends through the synchronizer. Each participant gets a base allowance that refills over time, and can purchase extra traffic beyond it. This tab shows where the validator stands against both.

### Metric cards

All three are byte-formatted (`B`, `KB`, `MB`, `GB`).

| Card               | Meaning                           |
| ------------------ | --------------------------------- |
| **Extra consumed** | Purchased traffic consumed so far |
| **Extra limit**    | Total purchased traffic allowance |
| **Base remaining** | Remaining base allowance          |

{% hint style="warning" %}
When **Base remaining** is near zero and **Extra consumed** is approaching **Extra limit**, the participant is close to being throttled by the synchronizer, and command submission will start failing. Purchase additional traffic through the Wallet UI before that happens.
{% endhint %}

### Routing

**Domain ID**, **Participant ID**, and **Endpoint**, each with a copy button. Shown when the synchronizer reports them.

### Counters

**Last consumed cost**, plus any additional counters the synchronizer returns, with humanised labels. The set of counters depends on the Canton protocol version, so this section is deliberately open-ended.

### States

| Situation          | What you see                                                            |
| ------------------ | ----------------------------------------------------------------------- |
| Loading            | *Loading traffic status…*                                               |
| No counters yet    | **No traffic data** — *The synchronizer has not reported counters yet.* |
| The request failed | **Failed to load traffic**, with the error                              |


# Parties

The Parties tab shows the parties this participant hosts, the hosting proposals waiting on it, and a lookup for any party on the synchronizer — and it is where all party operations start.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-c4eb04ccdfdf55fd1e97d53ee9ba2ccc7eab16ac%2Fimage%20(161).png?alt=media" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
This page describes the screens. For the concepts — what an external party is, what multi-hosting means, and the complete onboarding and approval workflow — see [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties).
{% endhint %}

## Header actions

| Button                     | Opens                                                                                                                                                                                                                                                          |
| -------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Onboard External Party** | The four-step external party onboarding wizard. For what each step does and why, see [Onboarding an external party](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties#onboarding-an-external-party). |
| **Allocate Party**         | The Allocate Party modal                                                                                                                                                                                                                                       |

## Sub-tabs

<table><thead><tr><th width="220">Sub-tab</th><th>Shows</th></tr></thead><tbody><tr><td><strong>Hosted Parties</strong></td><td>Parties currently hosted by this participant.</td></tr><tr><td><strong>Hosting Proposals</strong></td><td>Hosting proposals naming this participant that are not yet fully authorized. Badged with a count when there are any.</td></tr><tr><td><strong>Browse Parties</strong></td><td>Lookup for any party known to this participant, including parties hosted elsewhere.</td></tr></tbody></table>

***

## Hosted Parties

*Parties currently hosted by this participant.*

<table><thead><tr><th width="200">Column</th><th>Contents</th></tr></thead><tbody><tr><td><strong>Party ID</strong></td><td>The party's full identifier, truncated, with a copy button.</td></tr><tr><td><strong>Permission</strong></td><td>One badge per distinct permission across the party's hosts: <code>submission</code>, <code>confirmation</code>, or <code>observation</code>.</td></tr><tr><td><strong>Threshold / Hosts</strong></td><td>A row of dots — one per host that can confirm, filled up to the confirmation threshold. Hover for <em>"N of M confirming participant(s) must confirm"</em>. Falls back to a plain ratio when there are more than eight.</td></tr></tbody></table>

Rows are sorted by permission strength — submission, then confirmation, then observation — and then by party ID.

**Permission filter.** A button group above the table filters to **All**, **Submission**, **Confirmation**, or **Observation**. A party matches if any of its hosts holds that permission.

**Refresh.** Reading the topology mapping is comparatively slow, so this list has an explicit refresh button rather than polling. While it loads you will see *Loading topology mapping, this may take a while…*

### Expanding a row

An expanded row shows **Hosted on (`n`)** — every participant hosting the party, with its permission, sorted by permission strength. A participant still being onboarded carries an `onboarding` badge.

For a party whose keys are held externally, the expanded row also offers **Edit hosting**, which opens the hosting amendment flow. See [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties#changing-a-partys-hosting).

{% hint style="info" %}
**Edit hosting only appears for externally-signed parties.** A party managed by the participant itself has no external key holder to sign a hosting change, so its hosting cannot be amended this way.
{% endhint %}

### States

| Situation              | What you see                                                                                       |
| ---------------------- | -------------------------------------------------------------------------------------------------- |
| No hosted parties      | **No hosted parties** — *This participant has not authorized any PartyToParticipant mappings yet.* |
| Filter matches nothing | **No matching parties** — *No hosted party has a participant with `<permission>` permission.*      |
| Load failed            | **Failed to load hosted parties**, with the error                                                  |

***

## Hosting Proposals

*Hosting proposals naming this participant that are not yet authorized by everyone involved. These parties cannot be used until each named host approves. Approving makes this participant co-host the party — it replicates that party's data and takes part in confirming its transactions.*

Only proposals that name **this** participant are listed. The synchronizer's topology store is shared across the whole network and can hold hundreds of proposals; the rest are filtered out.

<table><thead><tr><th width="220">Column</th><th>Contents</th></tr></thead><tbody><tr><td><strong>Party ID</strong></td><td>The party being proposed.</td></tr><tr><td><strong>Hosting Participants</strong></td><td>Every named host. Your own participant is tagged <code>this participant</code>.</td></tr><tr><td><strong>Threshold</strong></td><td>The proposed confirmation threshold.</td></tr><tr><td>—</td><td>The action, or the current waiting state.</td></tr></tbody></table>

The action cell shows one of:

|                                | Meaning                                                    |
| ------------------------------ | ---------------------------------------------------------- |
| **Approve**                    | This participant is required to authorize, and has not yet |
| *Approved — updating topology* | You approved just now; the change is still propagating     |
| *Waiting on other hosts*       | This participant has already authorized; others have not   |

### Approving

Clicking **Approve** authorizes immediately — **there is no confirmation dialog.** The result appears as a toast:

| Toast                                             | Meaning                                                       |
| ------------------------------------------------- | ------------------------------------------------------------- |
| *Hosting approved — the party is now active*      | Every named host has now authorized                           |
| *Hosting approved — still waiting on other hosts* | Your authorization is recorded; the party is still not usable |
| *Approval failed*                                 | With the reason                                               |

After approving, the row's button disappears and the list polls for up to 30 seconds until the synchronizer agrees, so you do not need to refresh manually.

{% hint style="warning" %}
Approving is a real commitment. This participant will store that party's data and take part in confirming its transactions. Only approve proposals you recognise.
{% endhint %}

Empty state: **Nothing pending** — *Every party hosting involving this participant is fully authorized.*

***

## Browse Parties

*Search any party known to this participant by ID prefix, including parties hosted elsewhere on the synchronizer.*

Type at least **two characters** of a party ID prefix and press Enter or **Search**.

| Column                | Contents                                                  |
| --------------------- | --------------------------------------------------------- |
| **Party ID**          | The party's identifier                                    |
| **Identity Provider** | The identity provider ID, or `default`                    |
| **Scope**             | `Local` if hosted on this participant, `Remote` otherwise |

{% hint style="info" %}
This is a **prefix search, not a full listing.** On a production network a participant may know of hundreds of thousands of parties, so there is deliberately no "list all" — you must know roughly what you are looking for. Use **Hosted Parties** for the complete list of parties this participant hosts.
{% endhint %}

If nothing matches, the UI offers **Allocate "`<your search term>`"**, which opens the Allocate Party modal pre-filled with the term.

***

## Allocate Party

*Provision a new party on this validator. The hint is incorporated into the generated party ID.*

| Field             |                                                                                        |
| ----------------- | -------------------------------------------------------------------------------------- |
| **Party ID hint** | *Choose a short, human-readable hint. Backend appends a hash for uniqueness.* Required |

Buttons: **Cancel** and **Allocate**. On success a toast reports *Party allocated* with the resulting party ID, and both lists refresh.

{% hint style="info" %}
This allocates a **participant-managed** party — the participant holds its keys and can submit on its behalf. To create a party whose keys are held outside the participant, use **Onboard External Party** instead.
{% endhint %}


# DARs

The DARs tab lists every Daml package the participant knows about, and lets you upload new ones.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-336262c134b00d001582f4902c89739fca6efa09%2Fimage%20(162).png?alt=media" alt=""><figcaption></figcaption></figure></div>

## Columns

<table><thead><tr><th width="180">Column</th><th>Contents</th></tr></thead><tbody><tr><td><strong>Name</strong></td><td>The package name.</td></tr><tr><td><strong>Version</strong></td><td>The package version.</td></tr><tr><td><strong>Package ID</strong></td><td>The full package hash, truncated, with a copy button.</td></tr><tr><td><strong>Size</strong></td><td>Package size.</td></tr><tr><td><strong>Known since</strong></td><td>When the participant first saw the package.</td></tr></tbody></table>

## Searching

The search box matches on **name, version, or package ID**, and is forgiving: it matches substrings and in-order character sequences, so partial or approximate terms work. Search results replace the table; clear the box to return to the full list.

## Uploading a DAR

{% stepper %}
{% step %}
**Click `Upload .dar`**

A file picker opens, filtered to `.dar` files.
{% endstep %}

{% step %}
**Choose the file**

An upload strip appears below the toolbar showing the file name, its size, a progress bar, and the status **Ready to upload**.
{% endstep %}

{% step %}
**Click the upload button**

The status changes to **Uploading…** and the progress bar advances.
{% endstep %}

{% step %}
**Check the result**

On success the status becomes **Uploaded `<filename>`** and the package list refreshes. On failure the error message from the participant is shown in place of the status.
{% endstep %}
{% endstepper %}

Use the dismiss button to clear the strip and pick a different file.

{% hint style="danger" %}
**There is no confirmation step.** Clicking upload sends the DAR to the participant immediately. Uploading a Daml package cannot be undone — packages are permanent on the ledger — so check you have the right file and the right validator first.
{% endhint %}

{% hint style="warning" %}
The file picker will accept a file that is not really a DAR. Validation happens on the participant, so an invalid file produces an upload error rather than being rejected in the browser.
{% endhint %}

{% hint style="info" %}
Very large DARs may be rejected before reaching the participant, by the request size limit on the API. If a large upload fails with a size-related error rather than a Daml error, raise it with IntellectEU support — the limit is a platform setting, not something you can change from the UI.
{% endhint %}

## States

| Situation              | What you see                                                                          |
| ---------------------- | ------------------------------------------------------------------------------------- |
| No packages            | **No DAR packages yet** — *Upload a .dar file to deploy contracts to this validator.* |
| Search with no matches | **No packages match** — *Try a different search term.*                                |
| Load failed            | **Failed to load DAR packages**, with the error                                       |


# Participant & Keys

Two read-only tabs that expose what the Canton participant node itself reports: Participant node health, synchronizer connections, identity, and keys.

## Participant

The deepest health view in the UI. When something is wrong at the Canton level rather than the Kubernetes level, this is the tab that tells you. The heading carries the participant **Version** beside it.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-290b1bb7b942e55956f974ee58b1c9e0d78e793f%2Fimage%20(163).png?alt=media" alt=""><figcaption></figcaption></figure></div>

### While initialising

If the node has not finished initialising, the tab shows only:

* **Initialized** — `false`
* **Active** — `Yes` / `No`
* **Waiting for** — what the node is blocked on

{% hint style="info" %}
**Waiting for** is the single most useful field during onboarding. A participant that sits here for a long time is usually waiting on the synchronizer or on network onboarding to complete, not failing.
{% endhint %}

### Once initialised

| Card                        | Meaning                                                                                                                                                                      |
| --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Active**                  | Whether this is the active instance                                                                                                                                          |
| **Uptime**                  | Live-ticking, formatted `1d 2h 3m 4s`                                                                                                                                        |
| **Connected Synchronizers** | One row per synchronizer, with its ID (copyable) and health. This is where a lost synchronizer connection shows up first.                                                    |
| **Topology Queues**         | The depth of the **Manager**, **Dispatcher**, and **Clients** queues. Sustained non-zero values mean topology changes are backing up.                                        |
| **Identity**                | The participant's **UID**, its **Endpoint**, and the **Protocol Versions** it supports.                                                                                      |
| **Ports**                   | The ports the node exposes.                                                                                                                                                  |
| **Components**              | The participant's internal health components, each with a status and description. Component names are truncated after the `::` separator, with the full name in the tooltip. |

### Health values

The status values are Canton's own, colour-coded by the UI:

| Value                          | Reading  |
| ------------------------------ | -------- |
| `ok`, `healthy`                | Healthy  |
| `degraded`                     | Degraded |
| `failed`, `fatal`, `unhealthy` | Failed   |
| anything else                  | Unknown  |

### States

| Situation      | What you see                                                             |
| -------------- | ------------------------------------------------------------------------ |
| Loading        | *Loading participant status…*                                            |
| No status      | **No participant data** — *The participant has not reported status yet.* |
| Request failed | **Failed to load participant status**, with the error                    |

{% hint style="info" %}
This tab is entirely read-only. There is no restart, reconnect-synchronizer, or pruning action. For participant-level administration, use the [Canton console](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console).
{% endhint %}

***

## Keys

The public keys held in the participant's key vault.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-7c7d91b230b13ae4fe737057d426e56c7a02fe4d%2Fimage%20(164).png?alt=media" alt=""><figcaption></figcaption></figure></div>

| Column       | Contents                              |
| ------------ | ------------------------------------- |
| **Name**     | The key's name, or `—`                |
| **Purpose**  | `signing` or `encryption`             |
| **Key Spec** | The cryptographic algorithm and curve |
| **Usage**    | One badge per declared usage          |
| **Format**   | The key's encoding                    |

### What this tab tells you

It is the quickest way to confirm that KMS integration is working. With a KMS configured, the participant's operational keys are created and held in the key vault rather than in the participant database — and they appear here either way, so use the **Key Spec** and your KMS provider's own console to confirm where the private material actually lives.

### States

| Situation      | What you see                                                   |
| -------------- | -------------------------------------------------------------- |
| No keys        | **No keys** — *The participant vault returned no public keys.* |
| Request failed | **Failed to load keys**, with the error                        |

{% hint style="info" %}
Read-only. Key generation, rotation, import, and export are not exposed in the UI — they are participant and KMS operations. See [Key Management Service (KMS)](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/kms-integration).
{% endhint %}


# Users & Wallet Users

Two tabs covering two different kinds of user: Ledger users with their rights, and users onboarded to the Wallet UI.

## Overview

<table><thead><tr><th width="200">Tab</th><th>Manages</th></tr></thead><tbody><tr><td><strong>Users</strong></td><td><strong>Ledger users</strong> on the Canton participant. A ledger user has rights over specific parties, and is what an application authenticates as when it talks to the Ledger API.</td></tr><tr><td><strong>Wallet Users</strong></td><td><strong>Wallet UI users</strong> registered with the validator app, so a person can sign in to the Canton Wallet.</td></tr></tbody></table>

Neither creates an account in your identity provider. Both assume the identity already exists there.

***

## Users

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-b3d1f9d449878b5e979599fe92b9c8a2c2c68eb2%2Fimage%20(165).png?alt=media" alt=""><figcaption></figcaption></figure></div>

The heading shows the count: *`n` users provisioned on this validator.*

### Columns

| Column                | Contents                               |
| --------------------- | -------------------------------------- |
| **Username**          | The ledger user ID                     |
| **Primary party**     | The party the user acts as by default  |
| **Identity provider** | The identity provider ID, or `default` |
| **Active**            | `Active` or `Deactivated`              |
| —                     | Edit action                            |

### Viewing rights

Clicking a row opens a read-only drawer showing the user's rights, grouped by kind:

<table><thead><tr><th width="290">Right</th><th>Grants</th></tr></thead><tbody><tr><td><strong>Participant admin</strong></td><td>Full administrative control of the participant.</td></tr><tr><td><strong>Identity provider admin</strong></td><td>Administration of identity provider configuration.</td></tr><tr><td><strong>Can read as any party</strong></td><td>Read access to every party's data on this participant.</td></tr><tr><td><strong>Can execute as any party</strong></td><td>Execution on behalf of any party.</td></tr><tr><td><strong>Can act as</strong></td><td>Submitting commands on behalf of the listed parties.</td></tr><tr><td><strong>Can read as</strong></td><td>Reading the listed parties' data.</td></tr><tr><td><strong>Can execute as</strong></td><td>Executing on behalf of the listed parties.</td></tr></tbody></table>

The drawer's **Edit Rights** button moves you into the editor.

{% hint style="danger" %}
The first four are **participant-wide** rights, not party-scoped. `Participant admin` and `Can read as any party` in particular give access to every party's data on the node. Grant them sparingly, and prefer the party-scoped rights below them.
{% endhint %}

### Creating a user

{% stepper %}
{% step %}
**Click `Create User`**

*Provision a new participant user with a primary party and rights.*
{% endstep %}

{% step %}
**Fill in Basic info**

**User ID** is required — for example `analyst-01`. **Primary party** is optional.
{% endstep %}

{% step %}
**Grant rights**

Under **Rights**, add parties to **Can act as**, **Can read as**, and **Can execute as**. Type a party and press Enter — each becomes a removable chip. Under **Global flags**, tick any participant-wide rights.
{% endstep %}

{% step %}
**Click `Create`**

The modal closes on success.
{% endstep %}
{% endstepper %}

### Editing a user

The pencil icon on a row, or **Edit Rights** in the drawer, opens the same modal in edit mode: *User ID is read-only. Primary party, status, annotations and rights can be changed.*

Edit mode adds:

* a **Deactivated** checkbox — *user cannot authenticate to the ledger*;
* an **Annotations** section for arbitrary key/value metadata on the user.

{% hint style="warning" %}
**Saving rights replaces them wholesale.** The editor is not additive — the rights shown when you save become the user's complete set, and anything you removed is revoked. Always open the editor from the row or drawer so it is pre-populated with the current rights, rather than reconstructing them from memory.
{% endhint %}

{% hint style="info" %}
There is no success toast for user create or edit. The modal simply closes. Confirm the change landed by reopening the user's rights drawer.
{% endhint %}

### States

| Situation   | What you see                                                       |
| ----------- | ------------------------------------------------------------------ |
| No users    | **No users yet** — *Create the first user to grant ledger access.* |
| Load failed | **Failed to load users**, with the error                           |

***

## Wallet Users

The heading shows the count: *`n` users registered with the wallet UI.*

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-75f0f38bf8728e1a7631d3db7c12a179b7749e81%2Fimage%20(166).png?alt=media" alt=""><figcaption></figcaption></figure></div>

| Column       | Contents                                |
| ------------ | --------------------------------------- |
| **Username** | The wallet username, with a copy button |
| **Status**   | Always `Active`                         |
| —            | Remove action                           |

{% hint style="info" %}
**Status is always `Active`.** The validator app only returns usernames, so there is no other state to show. Treat the column as informational.
{% endhint %}

### Adding a wallet user

**Add Wallet User** — *Enter a username to onboard someone to the wallet UI.* Enter the **Username** and click **Add user**. A toast confirms *Wallet user added*.

The UI checks for duplicates before submitting and warns *Username already exists* rather than sending the request.

{% hint style="warning" %}
The username must match the user's identity in your identity provider. Onboarding a username that does not exist there creates a wallet user nobody can sign in as.
{% endhint %}

### Removing a wallet user

The trash icon opens a confirmation: *Offboard "`<username>`" from the wallet UI. This cannot be undone.* Confirm with **Remove**.

{% hint style="danger" %}
This is the **only destructive action in the UI that asks for confirmation**, and it cannot be undone. The validator refuses to offboard its own wallet user, so that request will fail with a conflict rather than breaking the validator.
{% endhint %}

### States

| Situation       | What you see                                                                        |
| --------------- | ----------------------------------------------------------------------------------- |
| No wallet users | **No wallet users yet** — *Add a username to give someone access to the wallet UI.* |
| Load failed     | **Failed to load wallet users**, with the error                                     |


# Identity & Endpoints

OIDC configuration and the identity dump download, plus the URLs each component exposes.

## Identity

*Managed Keycloak realm and OIDC client configuration for this validator.*

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-72e254f62282a1d8af49d7ed2d96a875d7a88e1a%2Fimage%20(167).png?alt=media" alt=""><figcaption></figcaption></figure></div>

The fastest way to confirm that a validator's authentication is wired up as you intended.

### Metric cards

| Card                 | Values                  |
| -------------------- | ----------------------- |
| **Auth enabled**     | `Yes` / `No`            |
| **Managed Keycloak** | `Managed` or `External` |
| **Provisioned**      | `Yes` / `No`            |

### Realm

Each row appears only when the value is set, and each is copyable:

**Auth URL** · **Target Audience** · **Ledger API client ID** · **Ledger API user** · **CNS UI client ID** · **Wallet UI client ID** · **Wallet user** · **Management Scope**

With managed authentication these are the values the operator provisioned. With an external identity provider they are the values you supplied on the `Validator` resource — so if a component is failing to authenticate, check them here first against what actually exists in your identity provider.

### Authenticated user

| Row                   | Meaning                                      |
| --------------------- | -------------------------------------------- |
| **User ID**           | The ledger user the API is authenticating as |
| **Primary party**     | That user's default party                    |
| **Identity provider** | The identity provider ID, or `default`       |
| **Status**            | `Active` or `Deactivated`                    |

{% hint style="info" %}
If this section fails to load, the API could not authenticate against the participant. That usually means the OIDC client secret, the audience, or the scope is wrong — the values above are where to look.
{% endhint %}

### Identity dump

The **Identity Dump** button downloads the participant's identity export as `<validator-name>-identities.json`.

{% hint style="danger" %}
**An identity dump is the validator's cryptographic identity.** Anyone holding it can reconstruct the node's identity on the network. Treat it exactly as you would a private key:

* store it in a secrets manager, not in a shared drive, ticket, or chat;
* never commit it to a repository;
* transfer it only over encrypted channels.

There is no confirmation step — clicking the button downloads the file immediately.
{% endhint %}

You need this file if the participant's database is ever lost or corrupted beyond recovery. See [Identity Dumps & Database Backups](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps).

### States

| Situation                         | What you see                                                                                                                      |
| --------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- |
| No managed authentication section | **No identity payload** — *No managedAuth section returned for this validator.* Expected when using an external identity provider |
| User lookup failed                | **Failed to load user**, with the error                                                                                           |

***

## Endpoints

*Network endpoints exposed by this validator and its applications.*

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-f2608addbecd7480a68d2d643e84b4fee3a666f2%2Fimage%20(168).png?alt=media" alt=""><figcaption></figcaption></figure></div>

Endpoints are grouped by the component that owns them, and each group lists:

| Label        | Meaning                                                |
| ------------ | ------------------------------------------------------ |
| **Internal** | The in-cluster address, reachable from other workloads |
| **External** | The public address through the ingress                 |

Every URL has a copy button. `https://` URLs render as links you can open directly.

### What you use these for

* **External** URLs are what you give to people — the Wallet UI and CNS UI addresses for end users, and the Wallet Gateway address where enabled.
* **Internal** URLs are what you give to applications running in the same cluster — a Daml application connecting to the Ledger API, for instance, should use the internal participant address rather than going out through the ingress.

{% hint style="info" %}
Only components with an ingress route have an **External** URL. The participant and the validator app are deliberately not exposed publicly; to reach the Ledger API from outside the cluster, front it yourself with appropriate authentication and network controls.
{% endhint %}

### States

| Situation     | What you see                                                                                                 |
| ------------- | ------------------------------------------------------------------------------------------------------------ |
| Loading       | *Loading endpoints…*                                                                                         |
| None reported | **No endpoints exposed** — *The validator and its applications have not reported any addressable endpoints.* |
| Load failed   | **Failed to load endpoints**, with the error                                                                 |


# Applications

Application component-level health and resource usage across every validator.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-58fbd347000a111d7790db70421157b6cb2fc1f6%2Fimage%20(169).png?alt=media" alt=""><figcaption></figcaption></figure></div>

Where the Validators list is organised by validator, the Applications list is organised by **component**. It is the view to use when you are chasing a resource problem, a crash loop, or a configuration question about one specific workload.

{% hint style="info" %}
Applications are created and owned by the operator. Nothing on these screens changes them — to change a component, change the `Validator` resource that owns it.
{% endhint %}

## Overview

### Columns

<table><thead><tr><th width="150">Column</th><th>Contents</th></tr></thead><tbody><tr><td><strong>Name</strong></td><td>The application resource name, <code>&#x3C;validator>-&#x3C;component></code>.</td></tr><tr><td><strong>Type</strong></td><td><code>Participant</code>, <code>Validator</code>, <code>Wallet UI</code>, <code>CNS UI</code>, <code>PQS</code>, or <code>Wallet Gateway</code>.</td></tr><tr><td><strong>Validator</strong></td><td>Link to the owning validator.</td></tr><tr><td><strong>Replicas</strong></td><td><code>ready / desired</code>.</td></tr><tr><td><strong>Restarts</strong></td><td>Container restart count.</td></tr><tr><td><strong>CPU</strong></td><td>Utilisation bar and percentage, with <code>used / limit</code> beneath.</td></tr><tr><td><strong>Memory</strong></td><td>Same, in bytes.</td></tr><tr><td><strong>Status</strong></td><td><code>Ready</code>, or the operator's reason for not being ready, or <code>Unknown</code>.</td></tr><tr><td><strong>Metrics</strong></td><td>Grafana dashboard link. Participant components only.</td></tr><tr><td><strong>Logs</strong></td><td>Grafana logs link.</td></tr></tbody></table>

### States

| Situation            | What you see                                                                                             |
| -------------------- | -------------------------------------------------------------------------------------------------------- |
| No applications      | **No applications found** — *No Canton applications are deployed in this cluster.*                       |
| Filtered, none match | **No applications for this validator** — *No Canton applications are deployed for validator "`<name>`".* |
| Load failed          | **Failed to load applications**, with the error                                                          |

***

## Application details

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-502fc24f7f3fb6ac0df8a4fb74bf4ad2e677fbb0%2Fimage%20(170).png?alt=media" alt=""><figcaption></figcaption></figure></div>

Clicking a row opens a single scrolling page.

### Overview Cards

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-396c78af8e1cd3c557556487c5edddef77184f09%2Fimage%20(171).png?alt=media" alt=""><figcaption></figcaption></figure></div>

| Column   | Contents                                                                       |
| -------- | ------------------------------------------------------------------------------ |
| Status   | `Ready`, or the operator's reason for not being ready, or `Unknown`.           |
| Replicas | `ready / desired`.                                                             |
| Restarts | Container restart count.                                                       |
| Type     | `Participant`, `Validator`, `Wallet UI`, `CNS UI`, `PQS`, or `Wallet Gateway`. |
| Port     | The port the component's service listens on.                                   |
| CPU      | Utilisation bar and percentage, with `used / limit` beneath.                   |
| Memory   | Same, in bytes.                                                                |

### Resources by replica

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-65444d225722fa606ad9abc525802ea519a2773b%2Fimage%20(172).png?alt=media" alt=""><figcaption></figcaption></figure></div>

| Column                                  | Contents                                       |
| --------------------------------------- | ---------------------------------------------- |
| **Replica**                             | The pod name                                   |
| **Phase**                               | The Kubernetes pod phase. `Running` is healthy |
| **Restarts**                            | Restart count for that pod                     |
| **CPU (used / limit)** · **CPU req**    | CPU usage against limit, and the request       |
| **Memory (used / limit)** · **Mem req** | Memory usage against limit, and the request    |

{% hint style="warning" %}
If a note says the cluster metrics API is not reachable, `metrics-server` is missing or unhealthy. Requests and limits still show; live usage does not.
{% endhint %}

### Endpoints

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-d2264b8add26c83ec2b5e2259ea5c9a0e2c59750%2Fimage%20(173).png?alt=media" alt=""><figcaption></figcaption></figure></div>

**Internal** and **External** URLs, plus **Metrics** and **Logs**, which render as **Open in Grafana** links.

### Conditions

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-f8df213bd33cf1aa37fee33a671947119a1183c3%2Fimage%20(174).png?alt=media" alt=""><figcaption></figcaption></figure></div>

The component's Kubernetes conditions — **Type**, **Status**, **Reason**, **Message**, **Last transition**. `DeploymentNotFound` means the workload has not been created yet; `DeploymentUnavailable` means it exists but has too few available replicas.

### Environment variables

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-43cc0d5e9c13e9eac29f742bf7f03ed6dcde3614%2Fimage%20(175).png?alt=media" alt=""><figcaption></figcaption></figure></div>

Every variable the operator set on the container, sorted by name, with a **Copy all** button that copies them as `NAME=value` lines.

{% hint style="info" %}
Values sourced from a Kubernetes Secret or another reference show a **`from secret`** or **`from ref`** badge instead of the value. Secret values are never displayed in the UI.
{% endhint %}

This is the most direct way to confirm how the operator configured a component — which auth URL the participant is using, which database it connects to, which network endpoints it was given.

### Specification

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-370646431b72e1580463386f4126a3d1b4a7e249%2Fimage%20(176).png?alt=media" alt=""><figcaption></figcaption></figure></div>

The application resource's fields as **Field** / **Value** pairs, excluding the environment variables, which have their own section.


# Canton Console

The Canton Console panel gives you a live, interactive Canton console attached to a participant node, from the UI, without cluster or shell access.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-2a2c526db71c8054672abeafbf6be401fefda0d2%2Fimage%20(177).png?alt=media" alt=""><figcaption></figcaption></figure></div>

{% hint style="danger" %}
**This is full administrative access to the participant node.** A Canton console session can read any party's data, change topology, and alter ledger state. It is the most privileged surface in the platform, and there is no read-only mode and no confirmation on anything you type.

Restrict who can obtain a console token in your identity provider, and treat access to the CatalyX UI as equivalent to participant administrator access.
{% endhint %}

## Where to find it

The panel sits on the [Dashboard](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/dashboard), directly below the summary cards. It is the only place in the UI where it appears — there is no separate page and no per-validator console.

It starts collapsed. Click the bar labelled **Canton Console** to expand it; the terminal and its connection are created the first time you do.

## Using the Canton Console

Once expanded, a status indicator appears beside the title:

| Status      | Meaning               |
| ----------- | --------------------- |
| `idle`      | Not connected         |
| `connected` | Session established   |
| `error`     | The connection failed |

Type commands directly into the terminal, exactly as you would in a Canton console attached to the node. Output is streamed back live. The terminal keeps 5,000 lines of scrollback.

**Reconnect** clears the terminal and opens a fresh session — useful if the connection has dropped or the session has become unresponsive.

Two messages come from the console itself rather than from Canton:

| Message                  | Meaning                                              |
| ------------------------ | ---------------------------------------------------- |
| `[Connection error]`     | The connection could not be established or was lost  |
| `[Disconnected: <code>]` | The session closed unexpectedly, with the close code |

## What to use it for

The console exists to cover what the graphical UI deliberately does not:

<table><thead><tr><th width="270">Task</th><th>Why here</th></tr></thead><tbody><tr><td><strong>Topology inspection and changes</strong></td><td>Beyond the read-only views and the external-party flows on the Parties tab.</td></tr><tr><td><strong>Diagnostics</strong></td><td><code>health.status</code> and similar commands, when the Participant tab does not give enough detail.</td></tr><tr><td><strong>One-off administrative operations</strong></td><td>Anything Canton supports that has no CatalyX equivalent.</td></tr></tbody></table>

### Canton console command reference

The commands themselves — what you type into the terminal — are Canton's, not CatalyX's, so they are documented upstream rather than duplicated here.

{% hint style="info" %}
See the official Canton Network documentation for the full [**Canton console command reference**](https://docs.canton.network/global-synchronizer/reference/canton-console-commands#canton-console-commands) — the admin console commands for participant, mediator, sequencer, and topology nodes.
{% endhint %}

## Session behaviour

**Collapsing does not disconnect.** The panel hides the terminal but keeps the session alive, so you can collapse it, navigate around the UI, and come back to the same session with its history intact.

**Sessions are per user and reused.** Reconnecting typically reattaches you to your existing session rather than starting a new one, and recent output is replayed.

**Idle sessions are reclaimed** after roughly ten minutes with nothing attached.

{% hint style="info" %}
The session attaches to a running participant pod. If no participant pod is running, the console reports that instead of connecting — check the validator's [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) tab first.
{% endhint %}

## Security notes for operators

{% hint style="warning" %}
Two properties of the current implementation are worth knowing when you assess this feature:

* **The session's access token is passed in the connection URL.** It may therefore be recorded in proxy and load-balancer access logs. Review your log retention accordingly.
* **The token is validated once, when the session is established.** An attached session is not re-checked afterwards, so it can outlive the token's expiry. Sessions are reclaimed on idle timeout rather than on token expiry.

If either is unacceptable in your environment, block the console's WebSocket path at your ingress and use a Canton console attached out-of-band instead.
{% endhint %}


# Grafana Dashboards

The CatalyX UI does not embed dashboards. Instead it links out to your Grafana instance, pre-filtered to the component you were looking at — so you land on the right data rather than a blank dashboard

## Where the links are

<table><thead><tr><th width="290">Location</th><th>Links</th></tr></thead><tbody><tr><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators-list">Validators list</a></td><td><strong>Metrics</strong> and <strong>Logs</strong> columns, per validator, targeting its participant.</td></tr><tr><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary">Validator → Summary</a></td><td>Per component row: metrics for the participant, logs for every component.</td></tr><tr><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications">Applications list</a></td><td><strong>Metrics</strong> and <strong>Logs</strong> columns per application.</td></tr><tr><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators">Application details</a></td><td><strong>Open in Grafana</strong> links in the <strong>Endpoints</strong> section.</td></tr></tbody></table>

All of them open in a new tab, so you keep your place in the UI.

## What each link opens

**Logs** opens Grafana's Loki log explorer, filtered to the component's service name, over the **last 24 hours**, newest first.

**Metrics** opens the Canton participant dashboard, filtered to that participant, over the **last hour**, refreshing every five minutes.

{% hint style="info" %}
**Metrics links only appear for participant components.** The participant is the component with a Canton-specific dashboard; other components expose standard Kubernetes workload metrics, which you can reach through your own dashboards. Logs are available for every component.
{% endhint %}

## Configuration

Set at install time, in the Helm values:

<table><thead><tr><th width="260">Value</th><th>Purpose</th></tr></thead><tbody><tr><td><code>ui.grafana.baseUrl</code></td><td>Base URL of your Grafana instance.</td></tr><tr><td><code>ui.grafana.dataSource</code></td><td>Optional. The UID of the Loki data source to query, when Grafana has more than one.</td></tr></tbody></table>

{% hint style="warning" %}
**The Grafana buttons are always rendered**, whether or not `ui.grafana.baseUrl` points at a reachable Grafana. If you have not configured it, the links will open a broken page rather than being hidden. Set `ui.grafana.baseUrl` as part of every install.
{% endhint %}

## Prerequisites

For these links to resolve to real data you need:

* **Grafana**, reachable by the people using the UI.
* **Loki**, receiving logs from the cluster, for the log links.
* **Prometheus**, scraping validator component metrics, for the metrics links. Enable `monitoring.serviceMonitor.enabled` in the Helm values if you use the Prometheus Operator.
* **The Canton participant dashboard** installed in your Grafana. Contact IntellectEU support for the dashboard definition.

{% hint style="info" %}
The resource figures shown *inside* the UI — the CPU and memory bars on the lists and detail pages — do not come from Prometheus. They come from the Kubernetes metrics API, which requires `metrics-server` in the cluster. Prometheus and Grafana are only needed for the deep links.
{% endhint %}


# Validator Management

This section covers creating a validator, and the operational tasks that go beyond viewing its health: managing parties, protecting keys, adding optional components, & keeping a validator upgradable &

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Create a Validator</strong></td><td>Apply your first <code>Validator</code> resource.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/create-a-validator">Create a Validator</a></td></tr><tr><td><strong>External &#x26; Multi-Host Parties</strong></td><td>Parties whose keys live outside the participant, and parties hosted across several participants.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties">External &amp; Multi-Host Parties</a></td></tr><tr><td><strong>Users &#x26; Rights</strong></td><td>Ledger users and wallet users, and how ledger rights work.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/users-and-rights">Users &amp; Rights</a></td></tr><tr><td><strong>Identity Dumps &#x26; Database Backups</strong></td><td>Identity dumps, database backups, and recovery.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps">Identity Dumps &amp; Database Backups</a></td></tr><tr><td><strong>Key Management Service (KMS)</strong></td><td>Hold Canton node keys in an external KMS.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/kms-integration">Key Management Service (KMS)</a></td></tr><tr><td><strong>Participant Query Store</strong></td><td>A queryable projection of the ledger.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/participant-query-store">Participant Query Store</a></td></tr><tr><td><strong>Wallet Gateway</strong></td><td>Custodial key holding and wallet management for a validator's parties.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway">Wallet Gateway</a></td></tr><tr><td><strong>Upgrades</strong></td><td>Upgrading the platform and validator components.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/upgrades">Upgrades</a></td></tr></tbody></table>

***

## How change reaches a validator

Worth internalising before you operate one, because it determines where you go to change things.

<table><thead><tr><th width="270">To change...</th><th>Do this</th></tr></thead><tbody><tr><td>Component versions, resources, database, authentication, optional components, KMS</td><td>Edit the <code>Validator</code> resource and re-apply. The operator reconciles the change.</td></tr><tr><td>Parties, ledger users, wallet users, DAR packages</td><td>Use the UI, or the REST API. These are ledger operations, not configuration.</td></tr><tr><td>Platform-wide settings — hostnames, TLS, the identity provider the UI uses, Grafana links</td><td>Change the Helm values and upgrade the release.</td></tr><tr><td>Anything Canton supports that CatalyX does not surface</td><td>Use the <a href="/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console">Canton console</a>.</td></tr></tbody></table>

{% hint style="info" %}
Editing a `Validator` is a normal Kubernetes update — `kubectl apply`, `kubectl edit`, or a GitOps commit. Watch the **Observed Generation** on the validator's [Status](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification) tab to confirm your change was picked up.
{% endhint %}


# Create a Validator

A validator is declared as a single Validator custom resource. You apply it, and the operator provisions everything else to create the validator.

Validators are created, changed, and deleted through custom resources — not through the UI. This keeps validator configuration reviewable and GitOps-friendly. The UI is where you *operate* a validator once it exists.

## What the operator does

{% stepper %}
{% step %}
**Provisions authentication**

When `spec.auth.managedKeycloak` is `true`, the operator creates the OIDC clients, client scopes, protocol mappers, and wallet user for this validator, then writes the generated backend client secret to a Kubernetes Secret and records the result in `status.managedAuth`.
{% endstep %}

{% step %}
**Provisions databases**

The participant and validator-app databases and schemas are created, plus the PQS and Wallet Gateway databases when those components are enabled.
{% endstep %}

{% step %}
**Creates the component applications**

One child `Application` resource per component: `participant`, `validator`, `wallet-ui`, `cns-ui`, and optionally `pqs` and `wallet-gateway`.
{% endstep %}

{% step %}
**Creates the workloads**

Each `Application` becomes a `Deployment`, a `Service`, and — for externally reachable components — a Traefik `IngressRoute`.
{% endstep %}
{% endstepper %}

The validator reports `Ready` once every component it owns is ready.

***

## Prepare the secrets

Two secrets are needed in the validator's namespace before you apply.

```bash
# Database credentials — must be able to CREATE DATABASE
kubectl create secret generic my-validator-db-credentials \
  --from-literal=username=<db-user> \
  --from-literal=password=<db-password> \
  -n <namespace>

# One-time onboarding secret from the sponsoring Super Validator
kubectl create secret generic my-validator-onboarding \
  --from-literal=secret=<onboarding-secret> \
  -n <namespace>
```

{% hint style="danger" %}
The onboarding secret's key **must be `secret`**. The operator reads that exact key name.
{% endhint %}

If you are using an external identity provider rather than managed authentication, you also need a secret holding the backend OIDC client secret — see [External Identity Provider](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/external-identity-provider).

***

## A minimal Validator

This example relies on managed authentication and on operator defaults for every component. It is the shortest useful `Validator`.

{% code title="my-validator.yaml" %}

```yaml
apiVersion: catalyx.manager.canton/v1alpha1
kind: Validator
metadata:
  name: my-validator
  namespace: <namespace>
spec:
  auth:
    managedKeycloak: true
    targetAudience: https://canton.network.global
    ledgerApiUserManagementScope: daml_ledger_api

  network:
    spliceVersion: "0.6.4"
    partyHint: catalyx-devnet-001
    onboardingSecretName: my-validator-onboarding
    sponsorSvUrl: https://sv.sv-1.dev.global.canton.network.sync.global
    scan:
      address: https://scan.sv-1.dev.global.canton.network.sync.global
      type: bft
      seedUrls:
        - https://scan.sv-1.dev.global.canton.network.sync.global
    synchronizer:
      connectionType: bft
      url: https://sequencer.sv-1.dev.global.canton.network.sync.global

  database:
    host: postgres.default.svc.cluster.local
    participantDb: participant_my_validator
    validatorDb: validator_my_validator
    credentialsSecretRef:
      name: my-validator-db-credentials
```

{% endcode %}

```bash
kubectl apply -f my-validator.yaml
```

{% hint style="warning" %}
**`spec.network.partyHint` is pattern-validated.** It must match `^[a-zA-Z0-9]+-[a-zA-Z0-9]+-[0-9]+$` — that is, two alphanumeric segments and a numeric segment, separated by hyphens. `catalyx-devnet-001` is valid; `myvalidator` and `my_validator_1` are rejected at apply time.
{% endhint %}

{% hint style="info" %}
`spec.network.spliceVersion` sets one version for the participant, validator app, and both UIs. You can still pin any component individually with its own `version` field. Either the component `version` or `spliceVersion` must be set, or the validator is rejected.
{% endhint %}

## Required fields

Only three top-level blocks are mandatory, and the API server rejects the resource at apply time if any is missing:

<table><thead><tr><th width="200">Block</th><th>Mandatory fields inside</th></tr></thead><tbody><tr><td><code>spec.auth</code></td><td>None individually, but the block itself is required.</td></tr><tr><td><code>spec.network</code></td><td><code>partyHint</code></td></tr><tr><td><code>spec.database</code></td><td><code>host</code>, <code>participantDb</code>, <code>validatorDb</code>, <code>credentialsSecretRef.name</code></td></tr></tbody></table>

{% hint style="warning" %}
`spec.network.scan` and `spec.network.synchronizer` are not marked mandatory in the schema, but the validator cannot reconcile without them. Always supply both.
{% endhint %}

For the complete field list, see the [Validator CRD Reference](/catalyx-blockchain-manager/canton-network/version-2.0/validator-crd).

***

## Watch it come up

```bash
kubectl -n <namespace> get validators
kubectl -n <namespace> get validators my-validator -o wide
```

The `Validator` resource prints a `READY` column, and `-o wide` adds the `REASON` for a validator that is not ready.

```bash
# Per-component detail
kubectl -n <namespace> get validators my-validator -o jsonpath='{.status.applications}' | jq

# The child applications and their workloads
kubectl -n <namespace> get applications
kubectl -n <namespace> get pods -l app.kubernetes.io/instance=my-validator
```

Or open the UI and watch the validator's [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) and [Status](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification) tabs, which refresh automatically.

## If it does not become ready

The `Ready` condition carries a reason that tells you which kind of problem you have:

<table><thead><tr><th width="200">Reason</th><th>Meaning</th></tr></thead><tbody><tr><td><code>InvalidSpec</code></td><td>A configuration problem the operator detected. The condition message names the exact field. Fix the <code>Validator</code> and re-apply.</td></tr><tr><td><code>ReconcileError</code></td><td>Something went wrong that is not a configuration error — for example the database or identity provider was unreachable. Check the operator logs.</td></tr><tr><td><code>ApplicationNotReady</code></td><td>The configuration is accepted but a component has not come up. Look at <code>status.applications</code> to see which one, then at that component's pods.</td></tr></tbody></table>

```bash
kubectl -n <namespace> logs deploy/catalyx-canton-operator
```

{% hint style="info" %}
Unknown fields are **silently pruned** by the Kubernetes API server. A misspelled field name is dropped without an error, and the setting simply has no effect. If a value seems to be ignored, check the spelling against the [CRD reference](/catalyx-blockchain-manager/canton-network/version-2.0/validator-crd) and confirm it survived with `kubectl get validator <name> -o yaml`.
{% endhint %}

***

## Deleting a validator

```bash
kubectl -n <namespace> delete validator my-validator
```

Kubernetes garbage-collects the child `Application` resources and their workloads.

{% hint style="danger" %}
Deleting a `Validator` does **not** remove:

* the **databases** — participant, validator, PQS, and Wallet Gateway data all remain;
* the **identity provider objects** created by managed authentication — clients, scopes, and users stay in the realm;
* the **managed authentication secret** `<validator-name>-managed-ledger-api-auth`.

Clean these up yourself if you are decommissioning a validator permanently. Retaining them is what makes it possible to recreate a validator against its existing state.
{% endhint %}


# External & Multi-Host Parties

Onboard parties whose signing keys live outside the participant, and host a single party across several participants.

Canton parties normally have their keys held by the participant that hosts them. Two capabilities change that, and they compose:<br>

1. **External parties:** The party's signing key lives *outside* the participant — with the party's owner. The participant cannot act on the party's behalf; the owner signs its own transactions.
2. **Multi-hosting:** A single party is hosted on *several* participants, which may belong to different organisations. The party survives the loss of any one of them.

### External parties and how they work

For the concept of external parties and the difference with local parties, please refer to the Canton documentation:

{% embed url="<https://docs.canton.network/overview/reference/external-party#external-party>" %}

### Why multi-host and how it works

For the concept and Canton's own guidance on resilience and disaster-recovery use cases, see Multi-Hosting and Resilience in the Canton documentation:

{% embed url="<https://docs.canton.network/appdev/deep-dives/multi-hosting#why-multi-host>" %}

***

## Onboarding an external party

Start from **Parties → Onboard External Party** on the validator.

{% stepper %}
{% step %}
**Identity — the party's key**

*Provide the party's public key. The participant will generate topology transactions for you to sign.*

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-c7ed1085ab9b5565795a91198fafbef86314f322%2Fimage%20(178).png?alt=media" alt=""><figcaption></figcaption></figure></div>

| Field                       | Notes                                                                                                     |
| --------------------------- | --------------------------------------------------------------------------------------------------------- |
| **Party hint**              | 2–64 characters, letters, digits, hyphens, and underscores only. Incorporated into the generated party ID |
| **Key algorithm**           | **Ed25519 (recommended)** or **ECDSA P-256**                                                              |
| **Public key (DER Base64)** | X.509 SubjectPublicKeyInfo, DER encoded, then Base64                                                      |

The wizard shows the commands to produce a key pair:

```bash
openssl genpkey -algorithm ed25519 -out key.pem
openssl pkey -in key.pem -pubout -outform DER | base64 -w 0
```

Nothing is sent to the participant at this step. Click **Next: Hosting →**.

{% hint style="warning" %}
`key.pem` is the party's private key. Whoever holds it controls the party. Generate it on the party owner's own machine wherever possible, and store it in a secrets manager or hardware token — not alongside your platform configuration.
{% endhint %}
{% endstep %}

{% step %}
**Hosting — choose the host set**

*Choose which participants host this party. This cannot be changed later — the host set is covered by the signature.*

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-abae42f0f766cad6314a76ae3dc5437fff2c80cc%2Fimage%20(179).png?alt=media" alt=""><figcaption></figcaption></figure></div>

Leave this step untouched to host the party on your validator alone. Otherwise:

* **Add participant** adds a row. Enter the participant UID in `alias::fingerprint` form, and choose **Confirming** or **Observing**.
* Tick **This validator observes only (does not confirm)** if confirmation should rest entirely on the other hosts.
* Set the **Confirmation threshold**. The hint below it tells you how many confirming participants you currently have.

Participant UIDs are entered as free text rather than chosen from a list — a production synchronizer carries hundreds of participants, and the useful ones are usually on other clusters. A participant UID is a public identifier; naming one needs no credentials for that node.

**The advisory lookup.** When you leave a UID field, CatalyX checks it against the synchronizer and reports:

| Chip                                                                                               | Meaning                        |
| -------------------------------------------------------------------------------------------------- | ------------------------------ |
| *Checking synchronizer…*                                                                           | Lookup in flight               |
| *Known on this synchronizer*                                                                       | The participant exists         |
| *This is this validator — remove it, it is already a host*                                         | You named your own participant |
| *Not found on this synchronizer… You can continue, but allocation will fail unless it joins first* | No match                       |

{% hint style="warning" %}
**The lookup warns; it never blocks.** Naming a participant that has not yet joined the synchronizer is legitimate — but the party's signature is spent at the next step, so a genuine typo costs you the whole onboarding. Resolve every warning before continuing.

All hosts must be on the **same synchronizer**. A participant that is absent from your local topology store — including one whose validator has been offline long enough to fall behind — will not resolve, and allocation will fail.
{% endhint %}

Click **Generate Transactions →**.
{% endstep %}

{% step %}
**Sign the multi-hash**

*Sign the hash below with your private key and paste the Base64 signature.*

The participant has generated the party ID and a **multi-hash** covering the topology transactions. When you named co-hosts, a **Co-hosts** line reports how many additional participants must authorize.

Give the multi-hash to the party's key holder to sign. The wizard shows the command for the chosen algorithm:

```bash
echo "<multi-hash>" | base64 --decode > hash.bin
openssl pkeyutl -sign -inkey key.pem -rawin -in hash.bin | base64
```

Paste the Base64 signature into **Signature (Base64)** and click **Complete Onboarding**.

{% hint style="danger" %}
This is the point of no return for the host set. If allocation fails because a named participant does not exist, the signature is consumed — you cannot retry with a corrected host list. Start again with a **fresh party hint**.
{% endhint %}
{% endstep %}

{% step %}
**Distribute — wait for the co-hosts**

Single-hosted, the wizard reports **External Party Onboarded** — *Hosted on this validator alone. The party is ready to use.*

Multi-hosted, it reports **Awaiting Other Hosts** and lists each participant still owing approval:

> The party is **not usable yet**. Each participant above must approve hosting it. The request is already visible to them — it appears under Hosting Proposals on their own Parties tab, whether they are in this cluster or another one. Nothing needs to be sent to them.

Click **Done**.
{% endstep %}
{% endstepper %}

***

## Approving a hosting proposal

This is the other half of the workflow, performed by each co-host's operator.

{% stepper %}
{% step %}
**Open Parties → Hosting Proposals**

The proposal is already there. Nothing was sent to you and there is nothing to import — the synchronizer's topology store is shared, and the proposal already carries the party's signature.
{% endstep %}

{% step %}
**Check what you are agreeing to**

The row shows the party ID, every named host with your own participant tagged **this participant**, and the confirmation threshold.

{% hint style="warning" %}
Approving means this participant will store that party's data and take part in confirming its transactions. Only approve proposals you recognise.
{% endhint %}
{% endstep %}

{% step %}
**Click Approve**

There is no confirmation dialog. A toast reports either *Hosting approved — the party is now active* or *Hosting approved — still waiting on other hosts*.

Rows where this participant has already authorized show *Waiting on other hosts* instead of a button.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
**Approval is safe to repeat.** Re-submitting an identical approval succeeds rather than erroring, so retrying after a network failure is harmless.

**A participant is only asked to approve when it takes on more responsibility** — when it is being added as a host, or when its permission is being strengthened. If you are named in a proposal but see no **Approve** button, nothing is required of you.
{% endhint %}

***

## Changing a party's hosting

{% hint style="info" %}
**Version note.** Hosting amendments were added after 2.0.0 and are newer than the onboarding flow above. Exercise them in a non-production environment first.
{% endhint %}

Hosting on an existing party can be changed: add a host, remove one, change a permission, or change the threshold. All four are the same operation — the party's hosting mapping is replaced at the next serial.

Open **Parties → Hosted Parties**, expand the party, and click **Edit hosting**.

<div data-with-frame="true"><figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-207c76dbe21344117f63eb9de925289c9d50fc15%2Fimage%20(180).png?alt=media" alt=""><figcaption></figcaption></figure></div>

{% stepper %}
{% step %}
**Edit Hosting**

*Replace the full set of participants hosting this party. Anything removed here stops hosting it.*

The current host set and threshold are pre-filled. Edit them, then click **Prepare Change →**.

{% hint style="danger" %}
**This is a replacement, not a delta.** What you leave in the list becomes the party's complete new host set — anything you remove stops hosting the party. At least one host must remain.
{% endhint %}
{% endstep %}

{% step %}
**Sign the Change**

*Sign the transaction hash with the party's private key and paste the Base64 signature.*

The modal shows the serial transition — `current → next` — and a transaction hash to sign, with the matching `openssl` command. Paste the signature and click **Submit Change**.

{% hint style="warning" %}
Check the **Key algorithm** selector matches the party's actual key. It defaults to Ed25519 and does not detect the party's algorithm, so an ECDSA P-256 party needs the selector changed or the signature will be rejected.
{% endhint %}
{% endstep %}

{% step %}
**Wait for approvals**

A toast confirms *Hosting change submitted at serial `n` — awaiting approval from affected participants*.

As with onboarding, every participant taking on more responsibility must approve from its own **Hosting Proposals** tab before the change takes effect.
{% endstep %}
{% endstepper %}

### Not supported

{% hint style="warning" %}
**Multi-hosting a participant-managed party.** A party allocated with **Allocate Party** is managed by the participant, which holds its keys. There is no external key holder to sign a hosting change, so its hosting cannot be amended through this flow — which is why **Edit hosting** only appears for externally-signed parties.

If you need a party hosted on more than one participant, onboard it as an external party from the start.
{% endhint %}

***

## Things to know

Behaviour established by testing against a live network:

<table><thead><tr><th width="330">Question</th><th>Answer</th></tr></thead><tbody><tr><td>Does generating the topology validate that a named participant exists?</td><td><strong>No.</strong> It succeeds for an unknown UID; allocation then fails — <em>after</em> the party has signed.</td></tr><tr><td>Is a multi-hosted mapping effective before all hosts authorize?</td><td><strong>No.</strong> It exists as a proposal and is absent from effective state. The party is unusable until the last host approves.</td></tr><tr><td>Is approval idempotent?</td><td><strong>Yes.</strong> Replaying an identical approval succeeds. Re-approving is safe.</td></tr><tr><td>Can the onboarding flow amend an existing party?</td><td><strong>No.</strong> It always creates a party at the first serial. Use <strong>Edit hosting</strong> instead.</td></tr><tr><td>Is a proposal visible to participants that did not submit it?</td><td><strong>Yes.</strong> The synchronizer's topology store is fully shared — a single query returns hundreds of proposals, nearly all naming participants the querying node has no relationship with.</td></tr><tr><td>Do stored proposals carry the party's signature?</td><td><strong>Yes.</strong> Which is why nothing has to be transferred between operators.</td></tr></tbody></table>

Additional notes:

* **Topology propagation is not instant.** Immediately after an approval, a party may still read as pending. The UI polls for up to 30 seconds; if in doubt, refresh the Hosted Parties list.
* **A blank permission in the advisory lookup is normal.** Per-participant synchronizer terms are optional in Canton; whether the participant is *on* the synchronizer is the signal that matters.
* **Naming your own validator as a co-host is not blocked.** The lookup warns you, but nothing prevents it — remove the row.

## Related

* [Parties tab](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/parties) — the UI screens in detail
* [Wallet Gateway](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway) — custodial key holding for a party, intended to eventually replace the manual signing step above


# Users & Rights

The two kinds of users in a CAT-BM deployment, and how ledger rights work.

CAT-BM distinguishes between two different kinds of users: ledger users and wallet users

* A ledger user has rights over specific parties, and is what an application authenticates as when it talks to the Ledger API.
* A wallet user is an off-ledger entity (e.g., a wallet login) that gets associated with one or more parties and is registered with the validator app, so a person can sign in to the Canton Wallet.

For more depth on the party/user model, refer the the Canton docs: [Manage Daml parties](https://docs.canton.network/appdev/deep-dives/manage-daml-parties) and [Validator Users and Wallets](https://docs.canton.network/global-synchronizer/deployment/validator-users).

***

## Onboarding a user end to end

{% stepper %}
{% step %}
**Create the user in your identity provider**

Create the user in the realm your validator authenticates against, and give them a credential. Note the username exactly — you will reuse it.
{% endstep %}

{% step %}
**Allocate a party, if they need one**

On the validator's **Parties** tab, use **Allocate Party** with a short hint. The participant generates the full party ID.

If the person should hold their own signing key rather than trusting the participant, onboard them as an [external party](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties) instead.
{% endstep %}

{% step %}
**Create the ledger user**

On the **Users** tab, **Create User**. Set the **User ID** to match the identity provider username, set the **Primary party** to the party from the previous step, and grant **Can act as** that party.
{% endstep %}

{% step %}
**Onboard the wallet user, if they need the Wallet UI**

On the **Wallet Users** tab, **Add Wallet User** with the same username.
{% endstep %}

{% step %}
**Hand over the URL**

Give them the Wallet UI address from the validator's **Endpoints** tab.
{% endstep %}
{% endstepper %}

***

## Ledger rights

A ledger user's rights fall into two groups, and the distinction matters a great deal.

### Party-scoped rights

These name specific parties, and are what you should be using in almost every case.

<table><thead><tr><th width="220">Right</th><th>Grants</th></tr></thead><tbody><tr><td><strong>Can act as</strong></td><td>Submitting commands on behalf of the named parties — creating and exercising contracts as them.</td></tr><tr><td><strong>Can read as</strong></td><td>Reading the named parties' contracts and transaction history.</td></tr><tr><td><strong>Can execute as</strong></td><td>Executing on behalf of the named parties.</td></tr></tbody></table>

### Participant-wide rights

These are not scoped to any party.

<table><thead><tr><th width="270">Right</th><th>Grants</th></tr></thead><tbody><tr><td><strong>Participant admin</strong></td><td>Full administrative control of the participant node.</td></tr><tr><td><strong>Identity provider admin</strong></td><td>Administration of the participant's identity provider configuration.</td></tr><tr><td><strong>Can read as any party</strong></td><td>Read access to <em>every</em> party's data on the node.</td></tr><tr><td><strong>Can execute as any party</strong></td><td>Execution on behalf of any party on the node.</td></tr></tbody></table>

{% hint style="danger" %}
`Can read as any party` defeats Canton's per-party data privacy on that participant, and `Participant admin` grants everything. Reserve both for platform service accounts, never for individual users or per-tenant applications.
{% endhint %}

### Editing rights is a replacement

{% hint style="warning" %}
Saving the rights editor sets the user's **complete** rights — anything you removed is revoked. Always open the editor from the user's row or rights drawer, so it starts pre-populated with the current rights.
{% endhint %}

## Deactivating a user

In edit mode, tick **Deactivated** — *user cannot authenticate to the ledger*. This is preferable to deleting rights: it blocks access immediately while preserving the user's configuration, so it is reversible and leaves an audit trail.

## Annotations

Edit mode also allows arbitrary key/value **annotations** on a ledger user. These are metadata for your own use — a tenant ID, an owning team, a ticket reference. They are not interpreted by CatalyX or Canton.

## Related

* [Users & Wallet Users](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/users-and-wallet-users) — the UI screens
* [Identity Provider Configuration](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration) — how a validator authenticates


# Identity Dumps & Database Backups

Identity dumps, database backups, and what each one recovers.

A validator has two kinds of state, and they need different protection.

<table><thead><tr><th width="230">State</th><th width="230">Where it lives</th><th>Protected by</th></tr></thead><tbody><tr><td><strong>Node identity</strong> — the cryptographic identity the network knows this participant by</td><td>The participant's key store, or your KMS</td><td>An <strong>identity dump</strong></td></tr><tr><td><strong>Ledger state</strong> — contracts, transaction history, topology</td><td>The participant and validator PostgreSQL databases</td><td><strong>Database backups</strong></td></tr></tbody></table>

You need both. A database backup without the identity cannot be restored onto a node the network recognises; an identity without a database gives you a recognised node with no history.

***

## Identity dumps

An identity dump exports the participant's identity so the node can be reconstructed if its database is lost beyond recovery.

### Downloading an identity dump

Open the validator's [Identity](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/identity-and-endpoints) tab and click **Identity Dump**. The file downloads as `<validator-name>-identities.json`.

{% hint style="danger" %}
**An identity dump is equivalent to the validator's private key material.** Anyone holding it can reconstruct your node's identity on the network.

* Store it in a secrets manager or an encrypted vault — never in a shared drive, a ticket, a wiki page, or a chat message.
* Never commit it to a repository.
* Transfer it only over encrypted channels.
* Keep access to it as tightly held as your production credentials.

There is no confirmation dialog. Clicking the button downloads the file immediately.
{% endhint %}

### When to take one

* **After onboarding**, once the validator is initialised and connected. This is the dump you cannot do without.
* **Before any migration or major upgrade.**
* **Periodically**, on whatever cadence your change-management process requires.

{% hint style="info" %}
An identity dump reflects the identity at the moment it was taken. It does not need to be refreshed as ledger state changes — but retake it if the node's identity or keys change.
{% endhint %}

***

## Database backups

Each validator has at least two databases, and more when optional components are enabled:

| Database                         | Contains                                                                                                                                                                   |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Participant                      | The ledger — contracts, transaction history, topology state, and the key store unless a KMS holds the keys                                                                 |
| Validator app                    | Validator app state, including wallet and onboarding data                                                                                                                  |
| PQS                              | A rebuildable projection of the ledger. See [Participant Query Store](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/participant-query-store) |
| Wallet Gateway store and signing | Wallet Gateway state. See [Wallet Gateway](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway)                                     |

Back these up with your standard PostgreSQL tooling — managed service snapshots, or your own `pg_basebackup` and WAL archiving. CAT-BM does not manage database backups, deliberately: this is the layer where your organisation's existing backup, retention, and testing policy should apply.

For more details on database backups, please refer the Canton guidelines:

{% embed url="<https://docs.canton.network/global-synchronizer/production-operations/node-backup-restore>" %}

{% hint style="warning" %}
**Deleting a `Validator` resource does not delete its databases.** That is what makes it possible to recreate a validator against its existing state — but it also means decommissioning is a two-step job: delete the resource, then drop the databases.
{% endhint %}

***

## Recovery paths

In order of preference.

{% stepper %}
{% step %}
**Restore from a database backup**

The normal path. Restore the participant and validator databases, and the node resumes with the state in the backup. Some transaction loss is possible, bounded by your backup frequency.
{% endstep %}

{% step %}
**Fail over to a standby region**

Where a multi-region deployment is configured, workloads move to the secondary region. See [Canton's own documentation](https://docs.canton.network/) for high-availability and disaster-recovery guidance for validators.
{% endstep %}

{% step %}
**Reinitialise from an identity dump**

The last resort, for when database backups are unavailable or corrupted. The node is recreated with its original network identity, but without its ledger history. Coordinate this with IntellectEU support and with your sponsoring Super Validator.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Recovery objectives are defined per engagement in the applicable service agreement. Contact IntellectEU for the objectives that apply to your deployment.
{% endhint %}

***

## What else to keep alongside the backups

A restore also needs the surrounding configuration. Keep these under version control or in your secrets manager:

* The **`Validator` resource** for each validator — ideally in Git, which is the main argument for managing them through GitOps.
* The **Helm values** used to install the platform.
* The **database credentials secret** for each validator.
* The **identity provider configuration** — realm, clients, and scopes. With managed authentication the operator can recreate the clients, but the realm and the admin client are yours.
* For an external identity provider, the **backend client secret**.
* For KMS-backed validators, access to the **key vault** itself. Without it the keys are unrecoverable, whatever else you have.

{% hint style="danger" %}
If you use a KMS, the KMS becomes part of your recovery path. Losing access to the key vault is unrecoverable — an identity dump will not substitute for keys the node no longer has permission to use. Make sure your KMS has its own backup, replication, and access-recovery plan.
{% endhint %}


# Key Management Service (KMS)

Hold the Canton participant's operational keys in an external key management service.

By default a Canton participant generates its operational keys and stores them in its own PostgreSQL database. For deployments that require stronger key-protection guarantees, CAT-BM can configure the participant to hold those keys in an external KMS instead.

<table><thead><tr><th width="230">Without KMS</th><th>With KMS</th></tr></thead><tbody><tr><td>Keys are generated by the node and stored in the participant database.</td><td>Keys are generated and held in the KMS. Private key material never enters the node.</td></tr><tr><td>Protecting the keys means protecting the database.</td><td>Keys are customer-managed, with the KMS's own access control and audit trail.</td></tr><tr><td>Sufficient for many deployments; it is Canton's out-of-the-box model.</td><td>Supports FIPS 140-2 validated modules and HSM backing where the provider offers them.</td></tr></tbody></table>

{% hint style="info" %}
KMS protects the **participant node's operational keys**. It is a different concern from external party keys, which are held by the party's owner — see [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties) — and from the Wallet Gateway, which delegates *party* signing to a custody provider.
{% endhint %}

***

## Azure Key Vault

### Prerequisites

{% stepper %}
{% step %}
**A key vault**

An Azure Key Vault the participant can reach, with the identity CAT-BM will use granted permission to create keys and to sign and decrypt with them.

For HSM-backed keys you need a Premium vault or Managed HSM.
{% endstep %}

{% step %}
**A KMS-enabled participant image**

Azure Key Vault support requires a purpose-built participant image containing the KMS driver. Contact IntellectEU support to obtain it, together with the pull secret for the registry it is published to.
{% endstep %}

{% step %}
**Credentials**

Either a workload identity, or a service principal whose client secret you store in a Kubernetes Secret.

```bash
kubectl create secret generic azure-kms-credentials \
  --from-literal=client-secret=<azure-client-secret> \
  -n <namespace>
```

{% endstep %}
{% endstepper %}

### Configuration

```yaml
spec:
  kms:
    enabled: true
    provider: azure
    azure:
      vaultUrl: https://my-vault.vault.azure.net/
      keyNamePrefix: my-validator
      preBuiltImage: <kms-enabled-participant-image>
      imagePullSecret: azure-kms-registry-credentials
      tenantId: <azure-tenant-id>
      clientId: <azure-client-id>
      clientSecretRef:
        name: azure-kms-credentials
        key: client-secret
```

<table><thead><tr><th width="230">Field</th><th>Purpose</th></tr></thead><tbody><tr><td><code>vaultUrl</code></td><td><strong>Required.</strong> The key vault URL.</td></tr><tr><td><code>preBuiltImage</code></td><td><strong>Required.</strong> The KMS-enabled participant image.</td></tr><tr><td><code>keyNamePrefix</code></td><td>Prefixes generated key names, so several nodes can share one vault without colliding.</td></tr><tr><td><code>credentialType</code></td><td>How the driver authenticates: <code>default</code>, <code>environment</code>, or <code>managedIdentity</code>. Omit it to use a service principal from the secret.</td></tr><tr><td><code>tenantId</code>, <code>clientId</code>, <code>clientSecretRef</code></td><td>Service principal credentials. Not needed with <code>default</code> or <code>managedIdentity</code>.</td></tr><tr><td><code>hardwareBackedKeys</code></td><td>Create HSM-protected keys. Needs a Premium vault or Managed HSM.</td></tr><tr><td><code>imagePullSecret</code></td><td>Pull secret for the participant image's registry.</td></tr></tbody></table>

{% hint style="danger" %}
**With Azure KMS enabled, `preBuiltImage` replaces the participant image entirely.** `spec.participant.version` and `spec.network.spliceVersion` are ignored for the participant. That means the KMS image's Canton version is what runs — coordinate its version with the rest of your deployment, and re-check it at every upgrade.
{% endhint %}

{% hint style="warning" %}
`spec.kms.provider` is matched **case-sensitively**. `Azure` or `AZURE` will not enable KMS — and because the validator otherwise reconciles normally, it will silently come up with keys in the database. Use lowercase `azure`.
{% endhint %}

### Hardening options

The driver exposes a set of strict-mode checks — pinned key versions, key spec validation, key operation validation, rejection of exportable keys, hardened generated keys, and a minimum key-encryption-key strength. Leave them at their defaults unless you have a specific reason to relax one; they are there to fail closed.

Sizing and connection tunables — cache size and idle window, AES and RSA key sizes, I/O threads, and HTTP timeouts and pool limits — are also available. Omit them to use the driver's defaults. See the [Validator CRD Reference](/catalyx-blockchain-manager/canton-network/version-2.0/validator-crd) for the full list.

{% hint style="info" %}
Two driver defaults changed after the initial 2.0.0 release: audit logging is now enabled by default, and the default AES key size changed. If you depend on either, set the value explicitly rather than relying on the default.
{% endhint %}

***

## AWS KMS

{% hint style="warning" %}
**Confirm availability before relying on this.** An AWS KMS provider is present in the current 2.0 line, but it postdates the 2.0.0 release and is less exercised than the Azure integration. Check with IntellectEU support before adopting it in production.
{% endhint %}

Unlike Azure, AWS KMS does not require a special participant image — it uses Canton's native AWS KMS support, so the standard participant image applies.

```yaml
spec:
  kms:
    enabled: true
    provider: aws
    aws:
      region: eu-central-1
      auditLogging: true
      # Either IRSA:
      serviceAccountName: catalyx-kms-sa
      # or static credentials:
      # credentialsSecretRef:
      #   name: aws-kms-credentials
```

<table><thead><tr><th width="250">Field</th><th>Purpose</th></tr></thead><tbody><tr><td><code>region</code></td><td><strong>Required.</strong> The AWS region holding the keys.</td></tr><tr><td><code>serviceAccountName</code></td><td>A pre-created Kubernetes service account annotated for IAM Roles for Service Accounts. <strong>CAT-BM does not create it</strong> — you do.</td></tr><tr><td><code>credentialsSecretRef</code></td><td>Static credentials, as an alternative to IRSA. Keys default to <code>access-key-id</code> and <code>secret-access-key</code>, with an optional <code>session-token</code> for assumed roles.</td></tr><tr><td><code>multiRegionKey</code></td><td>Use a multi-region key.</td></tr><tr><td><code>auditLogging</code></td><td>Log KMS operations.</td></tr></tbody></table>

IRSA is preferable to static credentials: it avoids long-lived secrets in the cluster entirely.

***

## Verifying it works

{% stepper %}
{% step %}
**Check the validator reconciled**

The [Status](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification) tab should show `Ready`. A misconfiguration reports `InvalidSpec` with the exact field named in the message.
{% endstep %}

{% step %}
**Check the participant image**

On the participant's [Application](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications) detail page, confirm the **Image** is the KMS-enabled one when using Azure.
{% endstep %}

{% step %}
**Check the keys**

The validator's [Keys](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys) tab lists the participant's public keys. Cross-check them against your key vault — the vault is the authority on where the private material lives.
{% endstep %}
{% endstepper %}

***

## Operational consequences

{% hint style="danger" %}
Enabling KMS makes the KMS part of your validator's critical path and its recovery path.

* **Availability** — if the participant cannot reach the KMS, it cannot sign, and it cannot operate.
* **Permissions** — revoking or rotating the identity's access stops the node.
* **Recovery** — losing access to the key vault is unrecoverable. An identity dump does not substitute for keys the node can no longer use.

Give the key vault the same backup, replication, and access-recovery treatment as the databases. See [Identity Dumps & Database Backups](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps).
{% endhint %}

Enable KMS **before** onboarding a validator where you can. Moving an existing validator's keys into a KMS is a Canton-level key migration, not a configuration change — plan it with IntellectEU support.


# Participant Query Store

The Participant Query Store (PQS) streams the ledger from the participant into a PostgreSQL database, so applications can query contract state with SQL instead of walking the Ledger API.

<table><thead><tr><th width="270">Use PQS when</th><th>Skip it when</th></tr></thead><tbody><tr><td>Applications need to query current contract state by attribute, not just by contract ID.</td><td>Applications only stream transactions and maintain their own state.</td></tr><tr><td>You want reporting or analytics over ledger data.</td><td>You have no read-heavy consumers.</td></tr><tr><td>Read load would otherwise fall on the participant.</td><td>The extra database and workload are not worth the benefit.</td></tr></tbody></table>

{% hint style="info" %}
PQS is a **projection**, not a source of truth. The participant's own database remains authoritative — PQS can be rebuilt from the ledger at any time.
{% endhint %}

## Enabling it

Two things are needed on the `Validator`: the component, and a database for it.

```yaml
spec:
  pqs:
    enabled: true
    version: "3.4.1"
    ledgerStart: Latest

  database:
    host: postgres.default.svc.cluster.local
    participantDb: participant_my_validator
    validatorDb: validator_my_validator
    pqsDatabase: pqs_my_validator
    pqsSchema: pqs
    credentialsSecretRef:
      name: my-validator-db-credentials
```

<table><thead><tr><th width="230">Field</th><th>Notes</th></tr></thead><tbody><tr><td><code>pqs.enabled</code></td><td>Defaults to <code>false</code>.</td></tr><tr><td><code>pqs.version</code></td><td><strong>Required when enabled.</strong> It does not fall back to <code>spliceVersion</code> — PQS is versioned independently of the Splice components.</td></tr><tr><td><code>pqs.ledgerStart</code></td><td>Where the pipeline begins reading. Defaults to <code>Latest</code>.</td></tr><tr><td><code>database.pqsDatabase</code></td><td><strong>Required when enabled.</strong> The operator creates the database for you.</td></tr><tr><td><code>database.pqsSchema</code></td><td>Defaults to <code>pqs</code>.</td></tr><tr><td><code>pqs.resources</code>, <code>pqs.jvm</code></td><td>Optional overrides. Defaults are requests <code>500m</code> / <code>1Gi</code>, limits <code>3</code> / <code>2Gi</code>, heap <code>512m</code>–<code>1536m</code>.</td></tr></tbody></table>

{% hint style="warning" %}
`ledgerStart: Latest` means PQS begins from the current ledger end and does **not** backfill history. If you need historical contracts in the store, set the start point when you first enable PQS — changing it later requires rebuilding the store.
{% endhint %}

## What gets created

Enabling PQS adds a sixth component to the validator: a `pqs` application with its own deployment and service, plus the PQS database and schema.

It appears as a `PQS` row on the validator's [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) tab and as an entry on the [Applications](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications) list, with the same health, resource, and log surface as every other component. The validator's overall readiness includes it.

{% hint style="info" %}
There is no PQS-specific screen in the UI — no query browser and no pipeline status view. PQS is monitored like any other component. Query the store directly with your own SQL tooling.
{% endhint %}

## Connecting to it

The store is an ordinary PostgreSQL database. Connect with the credentials from the validator's database credentials secret, at the host, database, and schema you configured.

For the schema itself and the query patterns it supports, see Canton's [Participant Query Store documentation](https://docs.canton.network/sdks-tools/development-tools/pqs#pqs-participant-query-store).

## Operating it

**Sizing.** PQS holds a projection of contract state, so its size tracks your active contract set and retention rather than the full transaction history. Start from the defaults and measure.

**Backups.** PQS can be rebuilt from the ledger, so it does not strictly need backing up — but rebuilding a large store takes time. Back it up if your recovery time matters more than the storage cost.

**Restarts.** PQS resumes from where it left off. A restart causes a lag in the projection, not data loss.

{% hint style="warning" %}
If PQS is not ready, the whole validator reports `Degraded` — its readiness is included in the validator's. A PQS pipeline problem will therefore show up as a validator-level alert. Check the `PQS` row on the Summary tab to distinguish it from a participant problem.
{% endhint %}

**Extra environment variables.** Unlike the participant, validator app, and UIs, PQS does not support `spec.overrides` environment variables. Configuration is limited to the fields above.


# Wallet Gateway

Deploy a custodial key-holding service for a validator's parties, and manage wallets from the CatalyX UI or the API — without holding private keys yourself.

{% hint style="info" %}
**Version note.** The Wallet Gateway was added after the 2.0.0 release. It is not part of the 2.0.0 artifact set. Contact IntellectEU support to confirm availability and supported versions for your deployment.
{% endhint %}

Wallet Gateway is a third-party product, built by Digital Asset (the company behind Canton), that sits next to a validator and holds a party's private key with an external custodian — currently **DFNS**. CatalyX deploys and configures a Wallet Gateway instance per validator, and provides a UI screen and API for creating and browsing the wallets it manages.

<table><thead><tr><th width="250">Approach</th><th>Keys held by</th><th>Suits</th></tr></thead><tbody><tr><td>Participant-managed party</td><td>The participant node</td><td>Parties the operator legitimately acts for.</td></tr><tr><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties">External party</a></td><td>The party's owner, directly</td><td>Counterparties who hold their own keys and sign for themselves.</td></tr><tr><td><strong>Wallet Gateway</strong></td><td>An external custody provider</td><td>Parties that need custodial key management with institutional controls, without either side running key infrastructure.</td></tr></tbody></table>

{% hint style="warning" %}
**Wallet Gateway holds keys; it does not yet sign anything for CatalyX.** Today it can create and hold a wallet, but nothing in CatalyX asks it to sign a transaction — the manual `openssl` signing step in [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties) still applies even for a party custodied here. See [What's not yet available](#whats-not-yet-available).
{% endhint %}

## Why use it

* **Private keys never touch application code or platform infrastructure.** DFNS holds and can sign with them; CatalyX only ever talks to Wallet Gateway's API, never to a key.
* **Institutional custody controls** — the provider's access policies, approval workflows, and audit trail apply to every signing operation the provider itself performs.
* **HSM backing and compliance** — where the provider offers it, key storage can satisfy FIPS 140-2 and comparable requirements.
* **One integrated workflow** — create and browse wallets from the CatalyX UI or API, without needing DFNS's own dashboard for day-to-day operator tasks.

***

## What gets created

Enabling the Wallet Gateway adds a component to the validator with:

* its own deployment and service;
* its own public hostname, `https://wallet-gateway-<validator-name>.<baseHostname>`, so it is reachable from a browser;
* two dedicated PostgreSQL databases — a store and a signing store;
* a public OIDC client, provisioned automatically under managed authentication;
* a generated configuration file, delivered as a Kubernetes Secret, mounted into the container.

It appears as a `Wallet Gateway` row on the validator's [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) tab and on the [Applications](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/applications) list, and its readiness is included in the validator's. It also gets its own **Wallet Gateway** tab on the validator detail page — see [Managing wallets](#managing-wallets) below.

***

## Enabling it

```yaml
spec:
  auth:
    enabled: true
    managedKeycloak: true
    targetAudience: https://canton.network.global
    ledgerApiUserManagementScope: daml_ledger_api

  walletGateway:
    enabled: true
    version: "v1.7.0"
    dfns:
      orgId: <organisation-id>
      apiUrl: <provider-api-url>
      credentialId: <credential-id>
      credentialsSecretRef:
        name: my-validator-waas-credentials

  database:
    host: postgres.default.svc.cluster.local
    participantDb: participant_my_validator
    validatorDb: validator_my_validator
    walletGatewayStoreDatabase: wg_store_my_validator
    walletGatewaySigningDatabase: wg_signing_my_validator
    credentialsSecretRef:
      name: my-validator-db-credentials
```

### Requirements

The Wallet Gateway has more prerequisites than any other optional component, and the validator will report `InvalidSpec` naming the exact missing field if any are absent.

<table><thead><tr><th width="330">Requirement</th><th>Why</th></tr></thead><tbody><tr><td><code>walletGateway.version</code></td><td>Required when enabled; it does not fall back to <code>spliceVersion</code>.</td></tr><tr><td><code>auth.enabled: true</code></td><td>The Wallet Gateway cannot run without authentication.</td></tr><tr><td><code>auth.targetAudience</code> and <code>auth.ledgerApiUserManagementScope</code></td><td>Needed for both browser and machine-to-machine flows.</td></tr><tr><td>An auth URL, a backend client ID, and a Wallet Gateway client ID</td><td>Provisioned for you under managed authentication; supplied by you with an external identity provider.</td></tr><tr><td><code>database.walletGatewayStoreDatabase</code> and <code>walletGatewaySigningDatabase</code></td><td>Both are required — supplying only one fails.</td></tr><tr><td><code>database.credentialsSecretRef</code></td><td>The databases are provisioned with these credentials.</td></tr></tbody></table>

### Provider credentials

```bash
kubectl create secret generic my-validator-waas-credentials \
  --from-literal=private-key=<provider-private-key> \
  --from-literal=auth-token=<provider-auth-token> \
  -n <namespace>
```

The key names default to `private-key` and `auth-token`, and can be overridden on the `credentialsSecretRef`.

{% hint style="info" %}
With **managed authentication**, the Wallet Gateway's OIDC client is created automatically when the validator is provisioned, so no extra identity provider work is needed.

With an **external identity provider** you must create the client yourself and set `spec.auth.walletGatewayClientId`. Note that this field cannot currently be set through the `catalyx-canton-validator` Helm chart — apply the `Validator` resource directly instead.
{% endhint %}

***

## Updating provider settings without a redeploy

Once a validator has Wallet Gateway enabled, its DFNS connection details — the enabled flag, connection details, and credentials — can be viewed and updated live through the API, without editing the `Validator` resource or restarting anything.

<table><thead><tr><th width="90">Method</th><th width="420">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>GET</td><td><code>/api/v1/validators/{name}/wallet-gateway/providers/dfns</code></td><td>Reads the current settings. Never returns credentials.</td></tr><tr><td>PUT</td><td><code>/api/v1/validators/{name}/wallet-gateway/providers/dfns</code></td><td>Updates the settings. Each field is optional per call, so rotating just a credential doesn't require resending the rest.</td></tr></tbody></table>

{% hint style="info" %}
**The `Validator` resource's `dfns` fields are fallback defaults only.** Once you call the settings API, the live enabled flag and connection details live in a ConfigMap instead and take precedence over the CR, field by field. Credentials are never put in that ConfigMap — they always go straight to the Secret named by `credentialsSecretRef`. This is what lets the UI's Create Wallet screen know whether a provider is actually usable before offering it.
{% endhint %}

***

## Managing wallets

On a validator's detail page, alongside Parties, DARs, Participant, and Keys, there is a **Wallet Gateway** tab. This is separate from the Summary tab, which only shows whether the Wallet Gateway *service* is deployed and healthy — the tab is where wallet management happens.

### Browsing wallets

The tab lists every wallet held by that validator's Wallet Gateway, refreshing automatically every 30 seconds (and immediately after creating one). Each row shows:

* the wallet's name and its Canton party ID;
* which provider holds its key (`dfns` today);
* its status — `initialized`, `allocated`, `removed`, or `disabled`;
* whether it's marked primary.

Expanding a row shows more detail: namespace, network, and public key. If more than one provider is ever configured, the list can be filtered by provider.

{% hint style="info" %}
Wallets the validator signs for itself — i.e. not custodied externally — are **not** shown here. Those already appear on the [Parties](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/parties) tab.
{% endhint %}

### Creating a wallet

Fill in a short, human-readable name for the party (for example `treasury` or `my-bank`) and pick a signing provider — DFNS is pre-selected when it's the only one configured. You can optionally mark the new wallet as the party's primary. CatalyX then asks Wallet Gateway to allocate a new Canton party and have DFNS generate and hold its key; the wallet appears in the list once allocation completes.

{% hint style="warning" %}
**"Make primary" is a shared setting, not a personal one.** CatalyX calls Wallet Gateway with one shared service identity rather than a per-user login, so marking a wallet primary affects everyone using the UI for this validator. The UI calls this out when the box is checked.
{% endhint %}

If Wallet Gateway isn't enabled for the validator, or no signing provider is configured yet, the screen explains what's missing rather than failing silently.

***

## Startup behaviour

{% hint style="info" %}
On a brand-new validator using managed authentication, the Wallet Gateway does **not** appear on the first reconcile. It waits until identity provider provisioning has completed, then starts. A validator that briefly shows no Wallet Gateway component, or shows it with zero replicas, is behaving correctly — give it a reconcile cycle.
{% endhint %}

***

## Security considerations

{% hint style="danger" %}
Review these before enabling the Wallet Gateway in a production namespace.

**Database credentials reach the pod as a Kubernetes Secret.** The generated configuration file — and the DFNS/OAuth secrets injected alongside it — is delivered via a Secret rather than a ConfigMap (tightened after the initial rollout). Anyone who can read Secrets in the validator's namespace can still read it, so restrict `get secret` there with RBAC, and consider a dedicated database user with access limited to the two Wallet Gateway databases.

**The service accepts requests from any origin**, and does not verify the TLS certificate of its database connection. Neither is configurable. Deploy it behind your own network controls and treat its hostname as a sensitive endpoint.
{% endhint %}

Access to the provider credentials secret should be as tightly held as any signing credential — it is what authorises the platform to request signatures.

***

## Related

* [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties) — the alternative, where the party holds its own keys
* [Key Management Service (KMS)](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/kms-integration) — protecting the *participant's* keys, a separate concern


# Upgrades

Upgrading the platform, and upgrading validator components.

There are two independent upgrade tracks, and it helps to keep them separate.

<table><thead><tr><th width="230">Track</th><th width="200">Changes</th><th>Mechanism</th></tr></thead><tbody><tr><td><strong>Platform</strong></td><td>The operator, API, and UI</td><td><code>helm upgrade</code></td></tr><tr><td><strong>Validator components</strong></td><td>The Canton participant, validator app, UIs, PQS, Wallet Gateway</td><td>Edit the <code>Validator</code> resource</td></tr></tbody></table>

You can upgrade either without the other, within a compatible range.

***

## Upgrading the platform

```bash
helm upgrade catalyx-canton catalyx/catalyx-canton \
  -n <namespace> -f my-values.yaml
```

{% hint style="danger" %}
**Apply the CRDs first.** Helm never upgrades the resources in a chart's `crds/` directory. If a release changes the `Validator` or `Application` schema and you skip this, new fields will be silently pruned from resources you apply.

```bash
kubectl apply -f <chart>/crds
```

{% endhint %}

### What happens

The operator, API, and UI deployments are rolled. The UI runs multiple replicas by default and has a pod disruption budget, so it stays available. The operator and API run a single replica each — expect a brief interruption while they restart.

Once the new operator starts, it re-reconciles every existing validator. Validators are not restarted unless something they depend on has changed.

### Rolling back

```bash
helm rollback catalyx-canton -n <namespace>
```

{% hint style="warning" %}
Rolling back the chart does **not** roll back the CRDs, because Helm never managed them. If the upgrade introduced schema changes and you roll back the release, the newer CRDs remain in place. The older operator will ignore fields it does not understand.
{% endhint %}

***

## Upgrading validator components

Canton networks upgrade on a schedule, and validators are expected to keep pace with the network's supported protocol versions.

### The simple case

If the validator uses `spec.network.spliceVersion`, one change upgrades the participant, validator app, and both UIs together:

```yaml
spec:
  network:
    spliceVersion: "0.6.13"
```

```bash
kubectl apply -f my-validator.yaml
```

The operator rolls each component in turn. Watch the validator's [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) tab as components return to `Ready`.

### Pinned components

A component with its own `version` ignores `spliceVersion`. Check for pinned versions before upgrading:

```bash
kubectl -n <namespace> get validator my-validator \
  -o jsonpath='{.spec.participant.version} {.spec.validator.version} {.spec.ui.wallet.version} {.spec.ui.cns.version}'
```

Independently versioned components — PQS and the Wallet Gateway — always need their own `version` set, and never follow `spliceVersion`.

{% hint style="warning" %}
**Azure KMS bypasses this entirely.** When Azure KMS is enabled, the participant runs the KMS-enabled image from `spec.kms.azure.preBuiltImage`, and both `spec.participant.version` and `spliceVersion` are ignored for the participant. Upgrading such a validator means obtaining an updated KMS image. Factor that into your upgrade lead time.
{% endhint %}

***

## Before you upgrade

{% stepper %}
{% step %}
**Confirm the target version is supported by the network**

Your validator's protocol version must remain compatible with the synchronizer. Check the network's published schedule; for the global Canton Network this is governed by the Global Synchronizer Foundation.
{% endstep %}

{% step %}
**Take an identity dump and confirm your database backups**

See [Identity Dumps & Database Backups](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps). Do this before every version change, not just major ones.
{% endstep %}

{% step %}
**Upgrade a non-production validator first**

Component versions are per validator, so a lower environment can run the new version while production stays put.
{% endstep %}

{% step %}
**Check the release notes**

See [Release Notes](/catalyx-blockchain-manager/canton-network/version-2.0/release-notes) for behaviour changes in the CatalyX release, and the Canton release notes for protocol changes.
{% endstep %}
{% endstepper %}

***

## Domain migrations

When a network performs a domain migration, the migration is coordinated by the network, not by CAT-BM. Two fields participate:

<table><thead><tr><th width="290">Field</th><th>Purpose</th></tr></thead><tbody><tr><td><code>spec.network.migrationId</code></td><td>The migration the validator is operating against.</td></tr><tr><td><code>spec.validator.dumpPath</code></td><td>Path to a migration dump, when the migration requires one.</td></tr></tbody></table>

{% hint style="warning" %}
Domain migrations are network-wide events with their own timing and procedure. Coordinate them with IntellectEU support and your sponsoring Super Validator — do not change `migrationId` speculatively.
{% endhint %}

***

## Version compatibility

{% hint style="info" %}
The `Validator` and `Application` custom resources are served at `catalyx.manager.canton/v1alpha1`.

**Field-level changes may still occur in a future minor release.** Treat the CRD schema as stable in shape but not frozen in detail, and read the release notes before upgrading the platform. Keep your `Validator` resources under version control so a schema change is a reviewable diff rather than a surprise.
{% endhint %}

## Getting help

Upgrade paths, supported version combinations, and migration procedures for a specific deployment are provided by IntellectEU support. See [Contact Support](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources).


# Identity Provider Configuration

Choose between letting CAT-BM provision authentication for a validator, or supplying your own OIDC configuration.

Every validator authenticates its users and components through an OIDC identity provider. CAT-BM supports two modes, chosen per validator with a single field.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Managed Keycloak</strong></td><td><code>managedKeycloak: true</code> — CAT-BM creates the clients, scopes, and users for you.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/managed-keycloak">Managed Keycloak</a></td></tr><tr><td><strong>External Identity Provider</strong></td><td><code>managedKeycloak: false</code> — you create everything and reference it by ID.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration/external-identity-provider">External Identity Provider</a></td></tr></tbody></table>

## Which should I use?

<table><thead><tr><th width="230">Use managed Keycloak when</th><th>Use an external provider when</th></tr></thead><tbody><tr><td>You run Keycloak and are happy for CAT-BM to hold an admin client in the validator realm.</td><td>Your identity provider is not Keycloak — for example Okta, Microsoft Entra ID, Auth0, or Ping Identity.</td></tr><tr><td>You want to add validators without a manual identity provider change for each one.</td><td>Client creation is centrally governed and cannot be automated by a platform component.</td></tr><tr><td>You want per-validator client isolation without designing the naming yourself.</td><td>You already have OIDC clients you must reuse.</td></tr></tbody></table>

{% hint style="info" %}
The mode is per validator, so you can mix both in one cluster.
{% endhint %}

## Two separate identity concerns

It is worth being precise about this, because the two are easy to conflate.

<table><thead><tr><th width="250">Concern</th><th>Configured where</th></tr></thead><tbody><tr><td><strong>The management plane</strong> — who can log in to the CatalyX UI and call the CatalyX API.</td><td>Helm values at install time: <code>ui.oidc.*</code> and <code>api.auth.jwksUri</code>. Not per validator.</td></tr><tr><td><strong>The validator</strong> — how the participant, validator app, Wallet UI, and CNS UI authenticate.</td><td><code>spec.auth</code> on each <code>Validator</code> resource.</td></tr></tbody></table>

This page and its children cover the second. For the first, see [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation).


# Managed Keycloak

Let CAT-BM provision the OIDC clients, scopes, and users a validator needs.

With `spec.auth.managedKeycloak: true`, the operator provisions everything the validator's components need inside an existing Keycloak realm, on the validator's first reconcile.

## Configuration

At the platform level, set the operator's Keycloak values at install time — see [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation).

On the validator, the whole `spec.auth` block reduces to four fields:

```yaml
spec:
  auth:
    managedKeycloak: true
    targetAudience: https://canton.network.global
    ledgerApiUserManagementScope: daml_ledger_api
```

`spec.network.partyHint` must also be set — it becomes the wallet user's username.

{% hint style="danger" %}
The realm must already exist, and the operator's admin client must exist **inside that realm** with realm-management permissions. The operator authenticates with the client credentials grant against the realm named in `operator.keycloak.realm`.
{% endhint %}

***

## What gets created

For a validator named `my-validator`, in the realm you configured:

<table><thead><tr><th width="240">Object</th><th width="200">Name</th><th>Notes</th></tr></thead><tbody><tr><td>Public client — CNS UI</td><td><code>my-validator-cns-ui</code></td><td>Redirect URI and web origin derived from <code>operatorRuntime.baseHostname</code>. Gets an audience mapper for <code>targetAudience</code>.</td></tr><tr><td>Public client — Wallet UI</td><td><code>my-validator-wallet-ui</code></td><td>As above.</td></tr><tr><td>Public client — Wallet Gateway</td><td><code>my-validator-wallet-gateway</code></td><td>Created whether or not the Wallet Gateway is enabled. Gets an audience mapper, a hardcoded <code>sub</code> claim mapper, and a 30-minute access token lifespan. The <code>profile</code> and <code>email</code> default scopes are removed.</td></tr><tr><td>Confidential client — backend</td><td><code>my-validator-validator-backend</code></td><td>Service accounts enabled. Its generated secret is written to a Kubernetes Secret.</td></tr><tr><td>Client scope — Ledger API</td><td>the value of <code>ledgerApiUserManagementScope</code></td><td>Created once per realm, with an audience mapper for <code>targetAudience</code>.</td></tr><tr><td>Client scope — per validator</td><td><code>my-validator-ledger-api</code></td><td>Attached as an optional scope to the platform's API client. Carries the audience, the user-management scope claim, and the backend service account's subject.</td></tr><tr><td>User — wallet</td><td>the value of <code>spec.network.partyHint</code></td><td>Enabled, email verified, no password and no roles.</td></tr></tbody></table>

## The generated secret

The operator writes an `Opaque` Kubernetes Secret in the validator's namespace:

|       |                                                              |
| ----- | ------------------------------------------------------------ |
| Name  | `<validator-name>-managed-ledger-api-auth`                   |
| Key   | `client-secret`                                              |
| Value | The generated secret of `<validator-name>-validator-backend` |

{% hint style="warning" %}
This secret has no owner reference, so it is **not** deleted when the validator is deleted. That is deliberate — it lets you recreate a validator without re-provisioning — but it means you must remove it yourself when decommissioning permanently.
{% endhint %}

## Checking the result

Provisioning results are recorded on the validator's status and shown on the UI's [Identity](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/identity-and-endpoints) tab.

```bash
kubectl -n <namespace> get validator my-validator -o jsonpath='{.status.managedAuth}' | jq
```

<table><thead><tr><th width="300">Status field</th><th>Meaning</th></tr></thead><tbody><tr><td><code>provisioned</code></td><td><code>true</code> once provisioning has completed successfully.</td></tr><tr><td><code>walletUiClientId</code>, <code>cnsUiClientId</code>, <code>walletGatewayClientId</code>, <code>ledgerApiClientId</code></td><td>The client IDs that were created.</td></tr><tr><td><code>ledgerApiClientSecretName</code>, <code>ledgerApiClientSecretKey</code></td><td>Where the backend client secret was written.</td></tr><tr><td><code>authUrl</code></td><td>The resolved OIDC issuer URL.</td></tr><tr><td><code>ledgerApiUser</code>, <code>walletUserName</code></td><td>Internal Keycloak user identifiers for the backend service account and the wallet user. These are IDs, not usernames.</td></tr></tbody></table>

{% hint style="info" %}
Once `provisioned` is `true`, the operator stops contacting Keycloak on subsequent reconciles and reads all authentication configuration from `status.managedAuth`.
{% endhint %}

***

## Things to know before you rely on it

**Provisioning is idempotent, but not fully self-correcting.** Clients that already exist have their redirect URIs and web origins overwritten to match the current `operatorRuntime.baseHostname`. **Client scopes are not updated** — a scope created with the wrong `targetAudience` must be corrected by hand in Keycloak.

**Changing the base hostname rewrites redirect URIs.** If you change `operatorRuntime.baseHostname` after validators exist, their public clients are updated on the next provisioning cycle.

**The platform API client is optional but recommended.** If the client named by `operator.keycloak.apiClientId` (default `catalyx-api`) does not exist in the realm, the operator logs a warning and continues — but the UI will not be able to perform Ledger API operations for that validator.

**Nothing is cleaned up on delete.** Clients, scopes, and users created for a validator remain in the realm after the validator is deleted.


# External Identity Provider

Configure a validator against OIDC clients you create yourself, in any OIDC-compliant identity provider.

With `spec.auth.managedKeycloak: false` — the default — you create the OIDC objects yourself and reference them from the `Validator` resource. This works with any OIDC-compliant identity provider, including Okta, Microsoft Entra ID, Auth0, and Ping Identity.

## What to create in your identity provider

<table><thead><tr><th width="230">Object</th><th width="140">Type</th><th>Used by</th></tr></thead><tbody><tr><td>Wallet UI client</td><td>Public</td><td>The Canton Wallet web UI. Needs a redirect URI of <code>https://wallet-&#x3C;validator-name>.&#x3C;baseHostname>/*</code> and the matching web origin.</td></tr><tr><td>CNS UI client</td><td>Public</td><td>The Canton Name Service web UI. Redirect URI <code>https://cns-&#x3C;validator-name>.&#x3C;baseHostname>/*</code>.</td></tr><tr><td>Backend client</td><td>Confidential</td><td>The validator app, PQS, and the Wallet Gateway, for machine-to-machine access to the Ledger API. Needs the client credentials grant enabled.</td></tr><tr><td>Wallet Gateway client</td><td>Public</td><td>Only when the Wallet Gateway is enabled. Redirect URI <code>https://wallet-gateway-&#x3C;validator-name>.&#x3C;baseHostname>/*</code>.</td></tr><tr><td>Participant admin user</td><td>User</td><td>The Canton participant's admin user identity.</td></tr><tr><td>Wallet user</td><td>User</td><td>The user the validator app treats as the wallet owner.</td></tr></tbody></table>

Every token issued to these clients must carry the audience you configure as `spec.auth.targetAudience`. Add an audience mapper or equivalent to each client.

## Store the backend client secret

```bash
kubectl create secret generic my-validator-ledger-api-auth \
  --from-literal=client-secret=<backend-client-secret> \
  -n <namespace>
```

***

## Configuration

```yaml
spec:
  auth:
    enabled: true
    managedKeycloak: false

    authUrl: https://idp.example.com/realms/canton
    jwksUrl: https://idp.example.com/realms/canton/protocol/openid-connect/certs
    targetAudience: https://canton.network.global
    ledgerApiUserManagementScope: daml_ledger_api

    ledgerApiUser: participant-admin
    walletUserName: wallet-user

    ledgerApiClientId: my-validator-backend
    walletUiClientId: my-validator-wallet-ui
    cnsUiClientId: my-validator-cns-ui
    ledgerApiClientSecretRef:
      name: my-validator-ledger-api-auth
      key: client-secret
```

### Field reference

<table><thead><tr><th width="330">Field</th><th>Purpose</th></tr></thead><tbody><tr><td><code>authUrl</code></td><td>OIDC issuer URL. Used by the UIs, and by the validator app, PQS, and Wallet Gateway to obtain tokens. Either an issuer URL or a token endpoint is accepted — an issuer URL is discovered via <code>.well-known/openid-configuration</code>.</td></tr><tr><td><code>jwksUrl</code></td><td>JWKS endpoint the participant and validator app verify tokens against.</td></tr><tr><td><code>targetAudience</code></td><td>The audience every token must carry.</td></tr><tr><td><code>ledgerApiUserManagementScope</code></td><td>The OAuth scope that grants Ledger API user-management rights.</td></tr><tr><td><code>ledgerApiUser</code></td><td>The participant's admin user name.</td></tr><tr><td><code>walletUserName</code></td><td>The wallet owner's user name.</td></tr><tr><td><code>ledgerApiClientId</code></td><td>The confidential backend client ID.</td></tr><tr><td><code>walletUiClientId</code> / <code>cnsUiClientId</code></td><td>The public client IDs for the two web UIs.</td></tr><tr><td><code>walletGatewayClientId</code></td><td>The public client ID for the Wallet Gateway. Required only when the Wallet Gateway is enabled.</td></tr><tr><td><code>ledgerApiClientSecretRef</code></td><td>Secret holding the backend client secret. <code>key</code> defaults to <code>client-secret</code>.</td></tr></tbody></table>

{% hint style="warning" %}
None of these fields is marked required in the CRD schema, so a `Validator` missing them will be **accepted** by the API server and then fail during reconciliation. The `Ready` condition will report `InvalidSpec` with the name of the missing field. Check the condition after applying.
{% endhint %}

{% hint style="info" %}
The `walletGatewayClientId` field cannot currently be set through the `catalyx-canton-validator` Helm chart. If you use that chart and need the Wallet Gateway with an external identity provider, apply the `Validator` resource directly instead.
{% endhint %}

***

## Verifying

Open the validator's [Identity](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/identity-and-endpoints) tab in the UI. It shows `Managed Keycloak: External`, the resolved auth URL, the target audience, and each client ID — a quick way to confirm the values reached the components.

If tokens are being rejected, the usual causes are:

* the audience mapper is missing on one of the clients, so `targetAudience` does not match;
* the redirect URI registered on a public client does not match the hostname the operator generated from `operatorRuntime.baseHostname`;
* the client credentials grant is not enabled on the backend client.

***

## Disabling authentication

`spec.auth.enabled: false` disables authentication on the participant entirely.

{% hint style="danger" %}
Never do this outside a local development cluster. It leaves the Ledger API open to anyone who can reach it.
{% endhint %}


# Release Notes

Product updates and release notes for CAT-BM 2.0 for Canton.

## Version 2.0.0

**Released 31 July 2026**

CAT-BM 2.0 is a **complete rewrite succeeding the 1.x line**: a new operator, a new REST API, and a rebuilt web UI.

{% hint style="danger" %}
**2.0 is not an in-place upgrade from 1.x.** Install it fresh. Contact IntellectEU support before planning a migration from an existing 1.10 or 1.11 deployment.
{% endhint %}

### Operator

Apply a single `Validator` custom resource and the operator provisions the full stack — the identity provider realm objects and OIDC clients, the Canton participant node, the validator app, the Wallet UI, and the CNS UI, plus an optional Participant Query Store. Components are managed as child `Application` resources with per-component readiness and reconciliation status. Traefik ingress, and PostgreSQL-backed participant and validator databases provisioned automatically.

### REST API

Read-only against the Kubernetes custom resources, read/write through the Canton Ledger API proxy: balances, traffic status, participant health, DAR packages, ledger users and wallet users, parties — local, external, and onboarding — and participant public keys. Stateless OAuth 2.0 resource server with per-validator scoped tokens. An interactive Canton console over WebSocket. OpenAPI description published at `/v3/api-docs`.

### Web UI

A React single-page application for operating validators without cluster access: a Dashboard, a Validators list, and a 13-tab validator detail view — Summary, Specification, Status, Balances, Traffic, Identity, DARs, Users, Wallet Users, Parties, Endpoints, Participant, and Keys. Application health and resource metrics, with optional Grafana deep links. External party onboarding, and the Canton console.

### Artifacts

| Artifact                                                           | Version  |
| ------------------------------------------------------------------ | -------- |
| `catalyx-console` image (multi-arch `linux/amd64`, `linux/arm64`)  | `v2.0.0` |
| `catalyx-operator` image (multi-arch `linux/amd64`, `linux/arm64`) | `v2.0.0` |
| `catalyx-ui` image (multi-arch `linux/amd64`, `linux/arm64`)       | `v2.0.0` |
| `catalyx-canton` Helm chart                                        | 2.0.0    |
| `catalyx-canton-validator` Helm chart                              | 2.0.0    |

### Upgrading from 1.x

2.0 is a fresh installation. Contact IntellectEU support for the migration procedure that applies to your deployment.

### Known limitations

* The CRD served version is `catalyx.manager.canton/v1alpha1`. **Field-level changes may still occur in a future minor release.**
* Ledger pruning is not exposed in the UI. Use the [Canton console](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console).
* Traffic purchases and balance top-ups are not exposed in the UI. The Balances and Traffic tabs are read-only.
* Participant key generation, rotation, and import are not exposed in the UI.
* The UI has no per-validator or per-screen authorisation. Restrict access at token issuance in your identity provider.

***

## Later 2.0 updates

The following landed after the 2.0.0 release and are available in the current 2.0 line. Confirm the exact version that carries each with IntellectEU support before planning around them.

{% hint style="info" %}
Each feature page carries a version note where the behaviour differs from 2.0.0, so you can tell what your build supports.
{% endhint %}

### Multi-host external parties

A party can now be hosted on **several participants**, including participants operated by other organisations, so it survives the loss of any single validator.

* The external party onboarding wizard gained a **Hosting** step: name additional hosting participants as confirming or observing, set the confirmation threshold, and optionally make the local validator observation-only.
* A new **Hosting Proposals** sub-tab on the Parties tab lists proposals naming this participant, with an **Approve** action. Local and remote co-hosts follow the identical path — nothing is transferred between operators.
* An advisory participant lookup warns when a named participant UID is not present on the synchronizer.
* The **Hosted Parties** sub-tab shows each party's hosts, their permissions, and its confirmation threshold, with a permission filter.

See [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties).

### Hosting amendments

An existing externally-signed party's hosting can be changed — add a host, remove one, change a permission, or change the threshold — via **Edit hosting** on the Hosted Parties sub-tab. The party's key holder signs the change, and every participant taking on more responsibility approves it from its own Hosting Proposals tab.

### Wallet Gateway

A new optional validator component providing a remote wallet whose signing keys are held by an external Wallet-as-a-Service provider. See [Wallet Gateway](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway).

### AWS KMS

An AWS KMS provider alongside Azure Key Vault, using Canton's native AWS KMS support with either IAM Roles for Service Accounts or static credentials. Unlike Azure, it does not require a purpose-built participant image. See [Key Management Service (KMS)](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/kms-integration).

### Azure KMS hardening

New Azure Key Vault options: a `credentialType` selector supporting workload and managed identity, a configurable key-encryption-key size, an audit node identifier, and six strict-mode security checks — pinned key versions, key spec validation, key operation validation, rejection of exportable keys, hardened generated keys, and a minimum key-encryption-key strength.

{% hint style="warning" %}
**Two Azure KMS defaults changed.** Audit logging is now enabled by default, and the default AES key size changed. If you depend on either value, set it explicitly rather than relying on the default.
{% endhint %}

### Availability hardening

Pod disruption budgets for the operator, API, and UI deployments, so voluntary node disruptions do not take the management plane offline.

***

## Earlier versions

Release notes for the 1.x line are published under their own versions in this space.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Version 1.11</strong></td><td>Release notes for the 1.11 line.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/release-notes">Release Notes</a></td></tr><tr><td><strong>Version 1.10</strong></td><td>Release notes for the 1.10 line.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.10/release-notes">Release Notes</a></td></tr></tbody></table>


# Support & Resources

Additional support and resources for CAT-BM 2.0 for Canton.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>FAQ</strong></td><td>Frequently asked questions.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/faq">FAQ</a></td></tr><tr><td><strong>API Reference</strong></td><td>The CatalyX REST API — endpoints, authentication, and error handling.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/api-reference">API Reference</a></td></tr><tr><td><strong>Troubleshooting</strong></td><td>Common problems and where to look.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/troubleshooting">Troubleshooting</a></td></tr><tr><td><strong>Open Source Licenses</strong></td><td>Licences used for the CAT-BM platform.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses">Open Source Licenses</a></td></tr></tbody></table>

## Getting help

For support requests, see the [Support Center](/support-center) — it covers the service desk, contact details, and how to stay up to date with releases.

## External documentation

CAT-BM operates Canton; it does not replace Canton's own documentation. For protocol-level detail, go to the source:

| Resource                                                                  | Covers                                                                                                            |
| ------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- |
| [Canton Network documentation](https://docs.canton.network/)              | Canton Network documentation and resources.                                                                       |
| [Digital Asset documentation](https://docs.digitalasset.com/)             | Daml documentation and resources, including topology, party hosting, KMS drivers, and the Participant Query Store |
| [Global Synchronizer Foundation](https://sync.global/)                    | Network governance, upgrade schedules, and validator operator guidance                                            |
| [Splice](https://github.com/hyperledger-labs/splice)                      | The open-source validator app, Wallet UI, and CNS UI                                                              |
| [Canton Improvement Proposals](https://github.com/canton-foundation/cips) | Proposed and accepted protocol and network changes                                                                |


# FAQ

Frequently asked questions about CAT-BM 2.0 for Canton.

## Getting started

<details>

<summary>Can I upgrade a 1.10 or 1.11 deployment in place?</summary>

No. 2.0 is a complete rewrite with a new operator, a new API, and new custom resources. It installs fresh. Contact IntellectEU support before planning a migration — the procedure depends on your deployment.

</details>

<details>

<summary>Why can't I create a validator from the UI?</summary>

By design. A validator is a `Validator` custom resource, so creating one is a Kubernetes apply — which makes it reviewable, diffable, and GitOps-friendly. The UI is for operating validators once they exist.

See [Create a Validator](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/create-a-validator).

</details>

<details>

<summary>Do I have to use Keycloak?</summary>

No. Any OIDC-compliant identity provider works — Okta, Microsoft Entra ID, Auth0, Ping Identity, and others. Set `managedKeycloak: false` and supply the client IDs yourself.

Managed provisioning, where CAT-BM creates the clients for you, is Keycloak-specific. See [Identity Provider Configuration](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-provider-configuration).

</details>

<details>

<summary>Do I need to create the validator databases first?</summary>

No. The operator creates them, provided the credentials you give it can `CREATEDB` and can reach the `postgres` maintenance database.

</details>

***

## Operating

<details>

<summary>My validator says Ready but the participant says Disconnected. Which is right?</summary>

Both. They measure different things.

* **Ready** is about Kubernetes — every workload the validator owns is running.
* **Disconnected** is about Canton — the participant node has lost its synchronizer connection.

A healthy set of pods with an unhealthy network connection is exactly this combination. Start on the validator's [Participant](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys) tab, under **Connected Synchronizers**.

</details>

<details>

<summary>I changed the Validator resource and nothing happened.</summary>

Check three things, in order:

1. **Observed Generation** on the [Status](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification) tab. If it lags behind, the change has not been reconciled.
2. **The `Ready` condition.** A reason of `InvalidSpec` means the operator rejected your change and the message names the field.
3. **Whether the field survived.** Unknown fields are silently pruned by the Kubernetes API server, so a typo disappears without an error. Run `kubectl get validator <name> -o yaml` and look for it.

</details>

<details>

<summary>Where is ledger pruning?</summary>

It is not exposed in the CatalyX UI in 2.0. Prune through the [Canton console](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console), which gives you the participant's full administrative command set.

</details>

<details>

<summary>Where do I buy traffic or top up a balance?</summary>

Not in the CatalyX UI — the Balances and Traffic tabs are read-only monitoring. Use the Wallet UI, or the Canton console.

Watch **Base remaining** and **Extra consumed** on the [Traffic](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/balances-and-traffic) tab: a participant that exhausts both is throttled by the synchronizer and command submission starts failing.

</details>

<details>

<summary>The CPU and Memory columns are empty.</summary>

Live usage comes from the Kubernetes metrics API, which needs `metrics-server` installed and healthy in the cluster. Requests and limits still display without it; only actual usage is missing.

</details>

<details>

<summary>Why do the Grafana links go nowhere?</summary>

The buttons are always rendered, whether or not Grafana is configured. Set `ui.grafana.baseUrl` in the Helm values. See [Grafana Links](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/grafana-dashboards).

</details>

***

## Parties and users

<details>

<summary>What is the difference between a party, a ledger user, and a wallet user?</summary>

* A **party** is an on-ledger identity that can hold contracts.
* A **ledger user** is an account on the participant that has rights over one or more parties, and is what an application authenticates as.
* A **wallet user** is a registration with the validator app so a person can sign in to the Wallet UI.

None of them is an account in your identity provider — that has to exist already. See [Users & Rights](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/users-and-rights).

</details>

<details>

<summary>Why can't I see all the parties on the network?</summary>

Because a production participant may know of hundreds of thousands of parties, so a full listing is impractical. **Browse Parties** is a prefix search requiring at least two characters. For the parties this participant hosts, use **Hosted Parties**, which is a complete list.

</details>

<details>

<summary>When should I use an external party instead of allocating one?</summary>

Allocate a party when your participant should legitimately act on its behalf. Onboard an **external party** when the party's owner should hold its own signing key — the participant then cannot submit for it.

External parties are also the prerequisite for multi-hosting. See [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties).

</details>

<details>

<summary>I onboarded a multi-hosted party and it doesn't work.</summary>

A multi-hosted party is not usable until **every** named host has authorized it. Until then it exists as a proposal, not as effective state.

Check the Distribute step's host list, or ask each co-host's operator to look at their own **Hosting Proposals** tab. Note that approval propagation takes a few seconds.

</details>

<details>

<summary>I mistyped a participant UID and onboarding failed. Can I retry?</summary>

Not with the same party. The party's signature covers the host set, so it is consumed by the failed attempt. Start again with a **fresh party hint**.

This is why the wizard runs an advisory lookup on every UID — resolve any warning before you reach the signing step.

</details>

<details>

<summary>Can I multi-host a party I allocated with Allocate Party?</summary>

No. A participant-managed party has no external key holder to sign a hosting change. If you need a party on more than one participant, onboard it as an external party from the start.

</details>

<details>

<summary>Does the confirmation threshold control how many participants must approve the hosting?</summary>

No — that is the most common misreading of the field. Hosting authorization is **all-of-N**: every named host must authorize, regardless of the threshold.

The threshold governs how many *confirming* hosts must confirm each of the party's **ledger transactions**, once it is live.

</details>

***

## Security

<details>

<summary>Who can do what in the UI?</summary>

In 2.0 there is no per-validator or per-screen authorisation. Any user who can obtain a token for the UI client can reach every screen, including the operations that change ledger state and the Canton console.

Enforce access control at token issuance in your identity provider, and treat UI access as platform administrator access.

</details>

<details>

<summary>Are secrets visible in the UI?</summary>

No. The Specification tab filters out any field whose path looks like a secret, and application environment variables sourced from a Kubernetes Secret show a `from secret` badge instead of the value.

</details>

<details>

<summary>How sensitive is an identity dump?</summary>

Extremely. It is the validator's cryptographic identity — treat it as private key material. Store it in a secrets manager, never in a repository, ticket, or chat, and transfer it only over encrypted channels. See [Identity Dumps & Database Backups](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps).

</details>

<details>

<summary>Are the OpenAPI endpoints public?</summary>

Yes — `/v3/api-docs` and `/swagger-ui.html` are served without authentication on the platform hostname. If that is unacceptable in your environment, restrict them with a Traefik middleware or block them at your edge. See [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation).

</details>

***

## Backups and recovery

<details>

<summary>Does CAT-BM back up my databases?</summary>

No. Database backups are yours to run, with your existing PostgreSQL tooling and retention policy. CAT-BM provides the identity dump, which is the other half of a recoverable validator.

See [Identity Dumps & Database Backups](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps).

</details>

<details>

<summary>What happens when I delete a Validator resource?</summary>

The child applications and their workloads are removed. **Not** removed: the databases, the identity provider clients and users created by managed authentication, and the managed authentication secret.

That is deliberate — it lets you recreate a validator against its existing state. It also means decommissioning permanently is a two-step job.

</details>

<details>

<summary>If I use a KMS, is an identity dump still enough to recover?</summary>

No. With a KMS, the keys live in the key vault, and an identity dump does not substitute for keys the node can no longer reach. Losing access to the vault is unrecoverable — give it the same backup and access-recovery treatment as your databases.

</details>


# API Reference

The CatalyX REST API — endpoints, authentication, and error handling.

The CatalyX API is the integration surface for the platform. The UI is built entirely on it, so anything you can do in the UI you can automate.

It does two things:

* **Reads** validator and application state from the Kubernetes custom resources. It never writes them.
* **Proxies** privileged Canton operations — the Ledger API, the participant Admin API, the network Scan API, and the validator app's admin API — so callers do not need direct network access to the nodes.

{% hint style="warning" %}
The API is **not** read-only overall. Reading CRDs is read-only, but the proxy operations create parties and users, upload DAR packages, onboard and offboard wallet users, and authorize topology changes. Treat it as a privileged administrative API.
{% endhint %}

## Base URL and discovery

Endpoints are served under `/api/v1` on the platform hostname, for example `https://validators.example.com/api/v1/validators`.

The API publishes its own OpenAPI description:

|                  |                        |
| ---------------- | ---------------------- |
| OpenAPI document | `GET /v3/api-docs`     |
| Swagger UI       | `GET /swagger-ui.html` |

{% hint style="danger" %}
Both are served **without authentication**, so anyone who can reach the hostname can enumerate the API surface. If that is unacceptable in your environment, restrict them with a Traefik middleware via `api.ingress.middlewares`, or block the paths at your edge. See [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation).

The published document also declares no security scheme, so Swagger UI has no *Authorize* control and generated clients get no authentication wiring. Add the bearer token yourself.
{% endhint %}

## Authentication

Send an OIDC bearer token on every `/api/v1` request:

```
Authorization: Bearer <access-token>
```

Tokens are validated against the JWKS endpoint configured at install time (`api.auth.jwksUri`). Signature and expiry are checked.

{% hint style="warning" %}
**In 2.0 there is no scope, audience, or per-validator authorisation.** Any token the configured issuer signs can call every endpoint, including the mutating ones. Access control must therefore be enforced at token issuance: restrict who can obtain a token for the UI client in your identity provider, and treat API access as equivalent to platform administrator access.
{% endhint %}

Unauthenticated requests return `401` with an empty body and a `WWW-Authenticate: Bearer` header.

## Namespace scoping

Every endpoint operates on the single namespace the API is configured to watch (`api.namespace` in the Helm values — see [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation)). There is no namespace parameter, and resources elsewhere return `404`.

***

## Validators

<table><thead><tr><th width="90">Method</th><th width="380">Path</th><th>Returns</th></tr></thead><tbody><tr><td>GET</td><td><code>/api/v1/validators</code></td><td>Every <code>Validator</code> resource, sorted by namespace and name.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}</code></td><td>One <code>Validator</code> resource.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/status</code></td><td>Just the resource's <code>status</code>.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/details</code></td><td>Aggregate view: the validator, its Ledger API endpoint, the authenticated user, all ledger users, and all DAR packages.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/balances</code></td><td>Canton Coin balance from the Scan service.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/traffic-status</code></td><td>Synchronizer traffic counters.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/participant-status</code></td><td>Participant node health.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/keys</code></td><td>Public keys in the participant's key vault.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/identity-dump</code></td><td>The participant identity export, as a file download.</td></tr></tbody></table>

{% hint style="info" %}
`/details` degrades rather than failing. If one of its sections cannot be fetched, the response still returns `200` with that section replaced by a corresponding `*Error` field. Check for those fields rather than relying on the status code alone.

`/balances` behaves similarly: a balance lookup failure returns `200` with an `error` field in the body.
{% endhint %}

{% hint style="danger" %}
`/identity-dump` returns the validator's cryptographic identity. Protect calls to it as you would a private key export, and never log the response body. See [Identity Dumps & Database Backups](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/identity-dumps).
{% endhint %}

## Applications

<table><thead><tr><th width="90">Method</th><th width="380">Path</th><th>Returns</th></tr></thead><tbody><tr><td>GET</td><td><code>/api/v1/applications</code></td><td>Every <code>Application</code> resource.</td></tr><tr><td>GET</td><td><code>/api/v1/applications/{name}</code></td><td>One <code>Application</code> resource.</td></tr><tr><td>GET</td><td><code>/api/v1/applications/{name}/status</code></td><td>Just the resource's <code>status</code>.</td></tr><tr><td>GET</td><td><code>/api/v1/applications/metrics</code></td><td>Resource metrics for every application.</td></tr><tr><td>GET</td><td><code>/api/v1/applications/{name}/metrics</code></td><td>Resource metrics for one application.</td></tr></tbody></table>

Metrics report **CPU in millicores and memory in bytes**. Any usage, request, or limit value may be `null`. A `metricsAvailable: false` response means the cluster metrics API was unreachable — usually a missing `metrics-server`.

## Parties

<table><thead><tr><th width="90">Method</th><th width="440">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>GET</td><td><code>/api/v1/validators/{name}/parties</code></td><td>Look up parties by ID prefix. Optional <code>partyId</code> query parameter.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/parties</code></td><td>Allocate a participant-managed party. Requires the <code>partyIdHint</code> query parameter.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/local-parties</code></td><td>Parties hosted by this participant, with their hosts, permissions, and threshold.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/external-parties</code></td><td>Externally-signed parties onboarded here.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/topology-proposals</code></td><td>Hosting proposals on the synchronizer, each flagged with whether this participant must act.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/participant-lookup</code></td><td>Advisory check of a participant UID. Requires <code>participantUid</code>.</td></tr></tbody></table>

## External parties

The onboarding and hosting flow. See [External & Multi-Host Parties](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/external-and-multi-host-parties) for the concepts.

<table><thead><tr><th width="90">Method</th><th width="470">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>POST</td><td><code>/api/v1/validators/{name}/external-parties/generate-topology</code></td><td>Generate topology transactions and the multi-hash to sign.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/external-parties/allocate</code></td><td>Allocate the party using the party's signature over the multi-hash.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/external-parties/approve-pending</code></td><td>Authorize a hosting proposal naming this participant. Requires <code>partyId</code>.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/external-parties/amend-hosting/prepare</code></td><td>Prepare a hosting change, returning a transaction hash to sign.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/external-parties/amend-hosting/submit</code></td><td>Submit the signed hosting change.</td></tr></tbody></table>

### `generate-topology`

<table><thead><tr><th width="290">Field</th><th width="130">Required</th><th>Notes</th></tr></thead><tbody><tr><td><code>partyHint</code></td><td>Yes</td><td>Incorporated into the generated party ID.</td></tr><tr><td><code>publicKeyBase64</code></td><td>Yes</td><td>X.509 SubjectPublicKeyInfo, DER encoded, then Base64.</td></tr><tr><td><code>keySpec</code></td><td>No</td><td>Defaults to Ed25519.</td></tr><tr><td><code>hosts</code></td><td>No</td><td>Array of <code>{ participantUid, permission }</code>. <code>permission</code> is <code>CONFIRMING</code> or <code>OBSERVING</code>; <code>participantUid</code> must be <code>alias::fingerprint</code>. Omit for a single-hosted party.</td></tr><tr><td><code>confirmationThreshold</code></td><td>No</td><td>Defaults to <code>1</code>. Must not exceed the number of confirming participants.</td></tr><tr><td><code>localParticipantObservationOnly</code></td><td>No</td><td>Defaults to <code>false</code>. When <code>true</code>, this validator observes but does not confirm.</td></tr></tbody></table>

Returns the generated `partyId`, the `multiHash` to sign, the `topologyTransactions`, the `synchronizerId`, and `otherHostingParticipantUids`.

{% hint style="danger" %}
**This call does not verify that the participant UIDs you name exist.** It succeeds for an unknown UID; `allocate` then fails — after the party has already signed the multi-hash, which consumes it. Use `participant-lookup` to check every UID first.
{% endhint %}

### `allocate`

Requires `synchronizerId`, `topologyTransactions`, `signature`, and `publicKeyFingerprint`. `signatureFormat` and `signingAlgorithmSpec` default to the Ed25519 pair and must match the key you used.

Returns `partyId`, the `hosts` still owing approval, and `complete` — which is `false` until every named host has authorized.

{% hint style="warning" %}
`allocate` affects **this participant only**. It does not fan out to co-hosts. Each co-host authorizes independently via `approve-pending`.
{% endhint %}

### `amend-hosting`

`prepare` takes `partyId`, the complete new `hosts` array, and `confirmationThreshold`, and returns the current and next serial plus a `transactionHash` to sign. `submit` takes the signed transaction back.

{% hint style="warning" %}
`hosts` is a **complete replacement**, not a delta. Any host you omit stops hosting the party. At least one must remain.
{% endhint %}

## Ledger users

<table><thead><tr><th width="90">Method</th><th width="420">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>POST</td><td><code>/api/v1/validators/{name}/users</code></td><td>Create a ledger user.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/users/{userId}</code></td><td>Update a user's primary party, deactivation state, and annotations.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/users/{userId}/rights</code></td><td>List a user's rights.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/users/{userId}/rights</code></td><td>Replace a user's rights.</td></tr></tbody></table>

User creation and rights take **query or form parameters**, not a JSON body: `userId`, `primaryParty`, the boolean flags `participantAdmin`, `identityProviderAdmin`, `canReadAsAnyParty`, `canExecuteAsAnyParty`, and the repeatable party lists `canActAs`, `canReadAs`, `canExecuteAs`.

{% hint style="danger" %}
Updating rights **revokes and re-grants** — the rights you send become the user's complete set. Read the current rights first and send them back with your change applied, or you will silently remove access.
{% endhint %}

There is no endpoint that lists users directly. The user list is the `allUsers` field of `/details`.

## Wallet users

<table><thead><tr><th width="90">Method</th><th width="440">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>GET</td><td><code>/api/v1/validators/{name}/wallet-users</code></td><td>List wallet usernames.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/wallet-users</code></td><td>Onboard a wallet user. Body <code>{ "name": "&#x3C;username>" }</code>.</td></tr><tr><td>DELETE</td><td><code>/api/v1/validators/{name}/wallet-users/{username}</code></td><td>Offboard a wallet user.</td></tr></tbody></table>

The validator refuses to offboard its own wallet user, returning `409`.

## Wallet Gateway

<table><thead><tr><th width="90">Method</th><th width="420">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>GET</td><td><code>/api/v1/validators/{name}/wallet-gateway/wallets</code></td><td>Lists the wallets Wallet Gateway manages for this validator.</td></tr><tr><td>POST</td><td><code>/api/v1/validators/{name}/wallet-gateway/wallets</code></td><td>Creates a wallet for a party. Requires a party hint and a signing provider (<code>dfns</code> today); optionally a primary flag and a DFNS vault.</td></tr><tr><td>GET</td><td><code>/api/v1/validators/{name}/wallet-gateway/providers/dfns</code></td><td>Reads the validator's current DFNS provider settings. Never returns credentials.</td></tr><tr><td>PUT</td><td><code>/api/v1/validators/{name}/wallet-gateway/providers/dfns</code></td><td>Updates the enabled flag, connection details, and/or credentials for the DFNS provider. Each field is optional per call. Takes effect immediately, without editing the <code>Validator</code> resource or restarting anything.</td></tr></tbody></table>

{% hint style="info" %}
These calls only manage wallet *custody* — creating a wallet and reading its state. Nothing here asks Wallet Gateway to sign a transaction; that flow does not exist yet. See [Wallet Gateway](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway#whats-not-yet-available).
{% endhint %}

***

## DAR packages

<table><thead><tr><th width="90">Method</th><th width="380">Path</th><th>Purpose</th></tr></thead><tbody><tr><td>POST</td><td><code>/api/v1/validators/{name}/dars/upload</code></td><td>Upload a DAR. <code>multipart/form-data</code>, part name <code>file</code>.</td></tr></tbody></table>

The package list is the `dars` field of `/details`.

## Health

<table><thead><tr><th width="90">Method</th><th width="280">Path</th><th>Auth</th></tr></thead><tbody><tr><td>GET</td><td><code>/actuator/health</code></td><td>Public</td></tr><tr><td>GET</td><td><code>/actuator/info</code></td><td>Public</td></tr></tbody></table>

These are the platform's own health endpoints, used by Kubernetes probes. Validator component metrics are exposed by the components themselves, not here.

## Canton console

`GET /api/ws/canton-console` upgrades to a WebSocket carrying a raw terminal stream. It is not a REST endpoint and is intended for the console UI. See [Canton Console](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/canton-console), including its security notes.

***

## Conventions

<table><thead><tr><th width="200">Aspect</th><th>Behaviour in 2.0</th></tr></thead><tbody><tr><td><strong>Status codes</strong></td><td>Success is always <code>200</code> — including creates, which do not return <code>201</code>, and deletes, which return <code>200</code> with a body.</td></tr><tr><td><strong>Pagination</strong></td><td>None. Collection endpoints return complete lists. A <code>nextPageToken</code> may appear in passthrough payloads but cannot be used — there is no corresponding request parameter.</td></tr><tr><td><strong>Filtering</strong></td><td>Only <code>partyId</code> on party lookup and <code>participantUid</code> on participant lookup. Both are <strong>prefix</strong> filters.</td></tr><tr><td><strong>Sorting</strong></td><td>Validators and applications are sorted by namespace and name. Not client-controllable.</td></tr><tr><td><strong>Rate limiting</strong></td><td>None.</td></tr><tr><td><strong>Timeouts</strong></td><td>Upstream calls have their own timeouts; an upstream that is slow or unavailable surfaces as <code>502</code>.</td></tr></tbody></table>

{% hint style="warning" %}
Because there is no pagination, a party lookup on a production participant can match a very large number of parties. Always send a specific enough `partyId` prefix.
{% endhint %}

## Errors

Two response shapes are in use, and the status code alone does not tell you which you will get. Handle both.

**Validation and not-found errors**

```json
{
  "timestamp": "2026-08-18T10:15:30.123456+00:00",
  "status": 404,
  "error": "Validator not found: <namespace>/my-validator"
}
```

**Upstream errors**

```json
{
  "endpoint": "my-validator-participant.<namespace>.svc.cluster.local:5001",
  "error": "UNAVAILABLE: io exception"
}
```

`401` and `403` return an **empty body**. A robust client should read `error` from the body when present and fall back to the status code otherwise.

### Status codes

| Code  | Meaning                                                                            |
| ----- | ---------------------------------------------------------------------------------- |
| `200` | Success — including creates and deletes                                            |
| `400` | Invalid request. The `error` field names the problem                               |
| `401` | Missing, invalid, or expired token. Empty body                                     |
| `404` | No such validator, application, or party                                           |
| `409` | Conflict — for example offboarding the validator's own wallet user                 |
| `422` | Canton rejected the request as invalid, typically a signature that does not verify |
| `502` | An upstream Canton, Scan, or validator app call failed                             |

{% hint style="info" %}
`422` and `502` are worth distinguishing in your integration. `422` means the request was wrong and retrying will not help. `502` means something upstream was unavailable and retrying may succeed.
{% endhint %}


# Troubleshooting

Common problems, and the order in which to look at things.

## A general method

Most problems resolve quickly if you work from the outside in.

{% stepper %}
{% step %}
**Is it a configuration problem or a runtime problem?**

Check the validator's `Ready` condition on the [Status](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/status-and-specification) tab.

* `InvalidSpec` — configuration. The message names the field. Nothing else needs investigating.
* `ReconcileError` — the operator could not complete an action, usually because something external was unreachable.
* `ApplicationNotReady` — configuration is fine, a component has not come up.
  {% endstep %}

{% step %}
**Which component?**

The [Summary](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/summary) tab breaks readiness down per component. Expand the offending row for its conditions and per-replica state.
{% endstep %}

{% step %}
**Kubernetes problem or Canton problem?**

A component that is `Ready` but not working is a Canton-level problem. Go to the [Participant](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys) tab.
{% endstep %}

{% step %}
**Read the logs**

The **Logs** link on the component's row opens Grafana, filtered to that component.
{% endstep %}
{% endstepper %}

***

## Installation

<details>

<summary>The API pod will not start — CreateContainerConfigError</summary>

Almost always the missing `catalyx-api-credentials` secret. It is mandatory and the pod cannot start without it.

```bash
kubectl create secret generic catalyx-api-credentials \
  --from-literal=client-secret=<catalyx-api-client-secret> \
  -n <namespace>
```

</details>

<details>

<summary>Validator UIs are unreachable, or serve a certificate error</summary>

Every ingress route the operator creates references the TLS secret named by `operatorRuntime.tlsSecretName`, which defaults to `catalyx-app-tls`. If that secret does not exist, those routes cannot serve HTTPS — even if you configured `ingress.tls.secretName` separately for the UI and API.

Check the secret exists in the validator's namespace, and that its certificate covers the hostnames derived from `operatorRuntime.baseHostname`.

</details>

<details>

<summary>Traffic does not reach the platform at all</summary>

Confirm Traefik is installed with entry points named exactly `web` and `websecure`, and that it is version 3.x — CAT-BM creates `IngressRoute` resources in the `traefik.io` API group.

</details>

<details>

<summary>A field I set after upgrading has no effect</summary>

Helm never upgrades the resources in a chart's `crds/` directory, so a new field may not exist in the installed schema — in which case the API server prunes it silently.

```bash
kubectl apply -f <chart>/crds
```

Then re-apply your `Validator`.

</details>

***

## Validators

<details>

<summary>Ready is False with reason InvalidSpec</summary>

The message names the field. The most common causes:

| Message mentions                                              | Cause                                                                                                            |
| ------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
| `version or spec.network.spliceVersion must be set`           | A component has no version and no `spliceVersion` to fall back on                                                |
| `jvm.maxHeap … exceeds … limits.memory`                       | The heap would not fit in the container. Lower the heap or raise the limit, leaving headroom for non-heap memory |
| `is not a valid JVM heap size`                                | You used Kubernetes units. Heap values need `k`, `m`, or `g` — `2048m`, not `2Gi`                                |
| `pqsDatabase must be set`                                     | PQS is enabled without its database                                                                              |
| `walletGatewayStoreDatabase and walletGatewaySigningDatabase` | The Wallet Gateway is enabled without both of its databases                                                      |
| `partyHint`                                                   | It does not match the required pattern — two alphanumeric segments and a numeric segment, hyphen-separated       |

</details>

<details>

<summary>Ready is False with reason ReconcileError</summary>

Something outside the resource failed. Check the operator logs:

```bash
kubectl -n <namespace> logs deploy/catalyx-canton-operator --tail=200
```

Usual causes: PostgreSQL unreachable or the credentials lacking `CREATEDB`; the identity provider unreachable; the realm or admin client missing; the database credentials secret missing or missing a key.

</details>

<details>

<summary>The database never provisions</summary>

The operator connects to the `postgres` maintenance database on your configured host and issues `CREATE DATABASE`. Confirm the host is reachable from the cluster, the `postgres` database exists, and the credentials have `CREATEDB`.

</details>

<details>

<summary>Managed authentication never completes</summary>

`Auth Provisioned` stays `No` on the Status tab. Check, in order:

1. The realm exists. CAT-BM never creates a realm.
2. The admin client exists **in that realm** — not in `master` — and its service account has realm-management permissions.
3. `operator.keycloak.serverUrl`, `realm`, and `adminClientId` are set on the release.
4. The `catalyx-operator-keycloak` secret exists with the expected key.
5. `spec.network.partyHint` is set on the validator.

</details>

<details>

<summary>The participant stays Initializing</summary>

Look at **Waiting for** on the [Participant](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/participant-and-keys) tab — it names what the node is blocked on.

During onboarding this is usually normal and resolves once the network accepts the validator. If it persists, check that the onboarding secret is present and has not expired — they are single-use and short-lived — and that the sequencer, Scan, and sponsoring Super Validator endpoints are reachable.

</details>

<details>

<summary>The participant was working and is now Disconnected</summary>

Check **Connected Synchronizers** on the Participant tab for the synchronizer's health, and confirm the sequencer endpoint is still reachable from the cluster.

Also check the [Traffic](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/balances-and-traffic) tab: a participant that has exhausted both its base allowance and its purchased traffic is throttled by the synchronizer.

</details>

<details>

<summary>The Wallet Gateway component is missing</summary>

On a new validator using managed authentication, the Wallet Gateway waits for identity provider provisioning to finish before it starts. A missing or zero-replica Wallet Gateway on the first reconcile is expected — give it a cycle.

If it persists, the validator's `Ready` condition will name the missing field. The Wallet Gateway has more prerequisites than any other component; see [Wallet Gateway](/catalyx-blockchain-manager/canton-network/version-2.0/validator-management/wallet-gateway).

</details>

<details>

<summary>KMS is configured but keys are still in the database</summary>

Check the spelling and case of `spec.kms.provider`. It is matched case-sensitively — `Azure` or `AWS` silently disables KMS, and the validator otherwise reconciles normally. Use lowercase `azure` or `aws`.

</details>

***

## Parties

<details>

<summary>Allocation failed after the party signed</summary>

A named participant UID does not exist on the synchronizer. The signature is consumed; restart onboarding with a fresh party hint, and use the advisory lookup on every UID before signing.

</details>

<details>

<summary>A multi-hosted party is not usable</summary>

It needs authorization from **every** named host. Check which are outstanding, and note that all hosts must be on the same synchronizer — a participant that is absent from your topology store, including one whose validator has been offline long enough to fall behind, will not resolve.

</details>

<details>

<summary>I am named in a proposal but there is no Approve button</summary>

Nothing is required of you. A participant is only asked to authorize when it takes on more responsibility — when it is being added, or when its permission is being strengthened.

</details>

<details>

<summary>A hosting amendment signature is rejected</summary>

Check the **Key algorithm** selector in the Edit Hosting modal. It defaults to Ed25519 and does not detect the party's actual algorithm, so an ECDSA P-256 party needs it changed before signing.

</details>

***

## UI

<details>

<summary>A validator does not appear in the list</summary>

The UI only shows validators in the namespace the API is configured to watch (`api.namespace` in the Helm values — see [Platform Installation](/catalyx-blockchain-manager/canton-network/version-2.0/installation-instructions-canton/platform-installation)). A validator in another namespace is also not being reconciled, so this is usually a real problem rather than a display one.

</details>

<details>

<summary>A tab shows "Failed to load…"</summary>

These tabs read live from Canton through the API, so the failure is upstream rather than in the UI. Check that the component is `Ready`, then that the API can authenticate — the [Identity](/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validators/identity-and-endpoints) tab failing to load its **Authenticated user** section points at the client secret, audience, or scope.

</details>

<details>

<summary>The Canton console will not connect</summary>

It attaches to a running participant pod. If none is running it reports so rather than connecting — check the validator's Summary tab first. **Reconnect** clears and re-establishes the session.

</details>

<details>

<summary>Nothing seems to update</summary>

The UI polls continuously — status every three seconds, metrics every five. There is no refresh button and no "last updated" indicator, so stale data means the API is not responding rather than that you need to refresh. The exception is the Parties tab, which has explicit **Refresh** buttons because reading the topology store is expensive.

</details>

***

## Escalating

If none of the above helps, gather the following before raising a ticket:

```bash
kubectl -n <namespace> get validators -o wide
kubectl -n <namespace> get validator <name> -o yaml
kubectl -n <namespace> get applications
kubectl -n <namespace> logs deploy/catalyx-canton-operator --tail=500
kubectl -n <namespace> get events --sort-by=.lastTimestamp | tail -50
```

{% hint style="danger" %}
Review the output before attaching it. `kubectl get validator -o yaml` includes secret **names** but not values — that is fine. Never attach an identity dump, a client secret, or database credentials.
{% endhint %}

See [Support & Resources](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources) for how to reach the service desk.


# Open Source Licenses

In this page we list all the software/components/libraries and their licenses used for CatalyX Blockchain Manager v1.11

## API

| Package                                                                                                                                                                               | Version                                   | License(s)                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| [ch.qos.logback:logback-classic](https://mvnrepository.com/artifact/ch.qos.logback/logback-classic)                                                                                   | 1.5.32                                    | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html)                                                                                                                                                                                                        |
| [ch.qos.logback:logback-core](https://mvnrepository.com/artifact/ch.qos.logback/logback-core)                                                                                         | 1.5.32                                    | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html)                                                                                                                                                                                                        |
| [com.auth0:auth0](https://mvnrepository.com/artifact/com.auth0/auth0)                                                                                                                 | 2.10.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [com.auth0:java-jwt](https://mvnrepository.com/artifact/com.auth0/java-jwt)                                                                                                           | 4.4.0                                     | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [com.cronutils:cron-utils](https://mvnrepository.com/artifact/com.cronutils/cron-utils)                                                                                               | 9.2.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.daml:bindings-java](https://mvnrepository.com/artifact/com.daml/bindings-java)                                                                                                   | 3.2.0-adhoc.20241030.13394.0.v3e6a4a6c    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml:classmate](https://mvnrepository.com/artifact/com.fasterxml/classmate)                                                                                                 | 1.7.3                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson:jackson-bom](https://mvnrepository.com/artifact/com.fasterxml.jackson/jackson-bom)                                                                             | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-annotations)                                                   | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-core](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-core)                                                                 | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-databind](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind)                                                         | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://mvnrepository.com/artifact/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml)                               | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jdk8](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jdk8)                                       | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jsr310](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jsr310)                                   | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-base](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base)                               | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-json-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider)             | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-yaml-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-yaml-provider)             | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations) | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-parameter-names](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-parameter-names)                         | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.github.ben-manes.caffeine:caffeine](https://mvnrepository.com/artifact/com.github.ben-manes.caffeine/caffeine)                                                                   | 3.2.3                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.github.java-json-tools:json-patch](https://mvnrepository.com/artifact/com.github.java-json-tools/json-patch)                                                                     | 1.13                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [LGPL-3.0](https://www.gnu.org/licenses/lgpl-3.0.html)                                                                                                                                                                                                                                |
| [com.github.stephenc.jcip:jcip-annotations](https://mvnrepository.com/artifact/com.github.stephenc.jcip/jcip-annotations)                                                             | 1.0-1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.android:annotations](https://mvnrepository.com/artifact/com.google.android/annotations)                                                                                   | 4.1.1.4                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.api.grpc:proto-google-common-protos](https://mvnrepository.com/artifact/com.google.api.grpc/proto-google-common-protos)                                                   | 2.41.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.findbugs:jsr305](https://mvnrepository.com/artifact/com.google.code.findbugs/jsr305)                                                                                 | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.gson:gson](https://mvnrepository.com/artifact/com.google.code.gson/gson)                                                                                             | 2.13.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.errorprone:error\_prone\_annotations](https://mvnrepository.com/artifact/com.google.errorprone/error_prone_annotations)                                                   | 2.43.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:failureaccess](https://mvnrepository.com/artifact/com.google.guava/failureaccess)                                                                                   | 1.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:guava](https://mvnrepository.com/artifact/com.google.guava/guava)                                                                                                   | 33.3.0-jre                                | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:listenablefuture](https://mvnrepository.com/artifact/com.google.guava/listenablefuture)                                                                             | 9999.0-empty-to-avoid-conflict-with-guava | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.protobuf:protobuf-java](https://mvnrepository.com/artifact/com.google.protobuf/protobuf-java)                                                                             | 3.25.5                                    | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [com.google.protobuf:protobuf-javalite](https://mvnrepository.com/artifact/com.google.protobuf/protobuf-javalite)                                                                     | 3.25.5                                    | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [com.ibm.async:asyncutil](https://mvnrepository.com/artifact/com.ibm.async/asyncutil)                                                                                                 | 0.1.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.javax0.license3j:license3j](https://mvnrepository.com/artifact/com.javax0.license3j/license3j)                                                                                   | 3.2.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:content-type](https://mvnrepository.com/artifact/com.nimbusds/content-type)                                                                                             | 2.2                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:lang-tag](https://mvnrepository.com/artifact/com.nimbusds/lang-tag)                                                                                                     | 1.7                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:nimbus-jose-jwt](https://mvnrepository.com/artifact/com.nimbusds/nimbus-jose-jwt)                                                                                       | 9.37.4                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:oauth2-oidc-sdk](https://mvnrepository.com/artifact/com.nimbusds/oauth2-oidc-sdk)                                                                                       | 9.43.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okhttp3:logging-interceptor](https://mvnrepository.com/artifact/com.squareup.okhttp3/logging-interceptor)                                                               | 4.12.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okhttp3:okhttp](https://mvnrepository.com/artifact/com.squareup.okhttp3/okhttp)                                                                                         | 4.12.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio](https://mvnrepository.com/artifact/com.squareup.okio/okio)                                                                                                   | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio-jvm](https://mvnrepository.com/artifact/com.squareup.okio/okio-jvm)                                                                                           | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.sun.istack:istack-commons-runtime](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-runtime)                                                                     | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.istack:istack-commons-tools](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-tools)                                                                         | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:relaxng-datatype](https://mvnrepository.com/artifact/com.sun.xml.bind.external/relaxng-datatype)                                                           | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:rngom](https://mvnrepository.com/artifact/com.sun.xml.bind.external/rngom)                                                                                 | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.typesafe:config](https://mvnrepository.com/artifact/com.typesafe/config)                                                                                                         | 1.4.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-codec:commons-codec](https://mvnrepository.com/artifact/commons-codec/commons-codec)                                                                                         | 1.15                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-io:commons-io](https://mvnrepository.com/artifact/commons-io/commons-io)                                                                                                     | 2.14.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-logging:commons-logging](https://mvnrepository.com/artifact/commons-logging/commons-logging)                                                                                 | 1.2                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client)                                                                                       | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client-api](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client-api)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-httpclient-okhttp](https://mvnrepository.com/artifact/io.fabric8/kubernetes-httpclient-okhttp)                                                                 | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-admissionregistration](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-admissionregistration)                                             | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apiextensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apiextensions)                                                             | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apps](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apps)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-autoscaling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-autoscaling)                                                                 | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-batch](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-batch)                                                                             | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-certificates](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-certificates)                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-common](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-common)                                                                           | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-coordination](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-coordination)                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-core](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-core)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-discovery](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-discovery)                                                                     | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-events](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-events)                                                                           | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-extensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-extensions)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-flowcontrol](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-flowcontrol)                                                                 | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-gatewayapi](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-gatewayapi)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-metrics](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-metrics)                                                                         | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-networking](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-networking)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-node](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-node)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-policy](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-policy)                                                                           | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-rbac](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-rbac)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-resource](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-resource)                                                                       | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-scheduling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-scheduling)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-storageclass](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-storageclass)                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:zjsonpatch](https://mvnrepository.com/artifact/io.fabric8/zjsonpatch)                                                                                                     | 0.3.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-api](https://mvnrepository.com/artifact/io.grpc/grpc-api)                                                                                                               | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-context](https://mvnrepository.com/artifact/io.grpc/grpc-context)                                                                                                       | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-core](https://mvnrepository.com/artifact/io.grpc/grpc-core)                                                                                                             | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-netty](https://mvnrepository.com/artifact/io.grpc/grpc-netty)                                                                                                           | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf)                                                                                                     | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf-lite](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf-lite)                                                                                           | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-stub](https://mvnrepository.com/artifact/io.grpc/grpc-stub)                                                                                                             | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-util](https://mvnrepository.com/artifact/io.grpc/grpc-util)                                                                                                             | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-commons](https://mvnrepository.com/artifact/io.micrometer/micrometer-commons)                                                                               | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-core](https://mvnrepository.com/artifact/io.micrometer/micrometer-core)                                                                                     | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-jakarta9](https://mvnrepository.com/artifact/io.micrometer/micrometer-jakarta9)                                                                             | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-observation](https://mvnrepository.com/artifact/io.micrometer/micrometer-observation)                                                                       | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-all](https://mvnrepository.com/artifact/io.netty/netty-all)                                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-buffer](https://mvnrepository.com/artifact/io.netty/netty-buffer)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec](https://mvnrepository.com/artifact/io.netty/netty-codec)                                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-dns](https://mvnrepository.com/artifact/io.netty/netty-codec-dns)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-haproxy](https://mvnrepository.com/artifact/io.netty/netty-codec-haproxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http](https://mvnrepository.com/artifact/io.netty/netty-codec-http)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http2](https://mvnrepository.com/artifact/io.netty/netty-codec-http2)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-memcache](https://mvnrepository.com/artifact/io.netty/netty-codec-memcache)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-mqtt](https://mvnrepository.com/artifact/io.netty/netty-codec-mqtt)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-redis](https://mvnrepository.com/artifact/io.netty/netty-codec-redis)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-smtp](https://mvnrepository.com/artifact/io.netty/netty-codec-smtp)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-socks](https://mvnrepository.com/artifact/io.netty/netty-codec-socks)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-stomp](https://mvnrepository.com/artifact/io.netty/netty-codec-stomp)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-xml](https://mvnrepository.com/artifact/io.netty/netty-codec-xml)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-common](https://mvnrepository.com/artifact/io.netty/netty-common)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler](https://mvnrepository.com/artifact/io.netty/netty-handler)                                                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-proxy](https://mvnrepository.com/artifact/io.netty/netty-handler-proxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-ssl-ocsp](https://mvnrepository.com/artifact/io.netty/netty-handler-ssl-ocsp)                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver](https://mvnrepository.com/artifact/io.netty/netty-resolver)                                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns)                                                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-classes-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-classes-macos)                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-native-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-native-macos)                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport](https://mvnrepository.com/artifact/io.netty/netty-transport)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-epoll)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-kqueue)                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-native-epoll)                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-native-kqueue)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-unix-common](https://mvnrepository.com/artifact/io.netty/netty-transport-native-unix-common)                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-rxtx](https://mvnrepository.com/artifact/io.netty/netty-transport-rxtx)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-sctp](https://mvnrepository.com/artifact/io.netty/netty-transport-sctp)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-udt](https://mvnrepository.com/artifact/io.netty/netty-transport-udt)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.perfmark:perfmark-api](https://mvnrepository.com/artifact/io.perfmark/perfmark-api)                                                                                               | 0.27.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor:reactor-core](https://mvnrepository.com/artifact/io.projectreactor/reactor-core)                                                                                   | 3.7.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-core](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-core)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-http](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-http)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.sentry:sentry](https://mvnrepository.com/artifact/io.sentry/sentry)                                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-reactor](https://mvnrepository.com/artifact/io.sentry/sentry-reactor)                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-jakarta)                                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-starter-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-starter-jakarta)                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-jakarta)                                                                                 | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.swagger.core.v3:swagger-annotations-jakarta](https://mvnrepository.com/artifact/io.swagger.core.v3/swagger-annotations-jakarta)                                                   | 2.2.47                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.swagger.core.v3:swagger-core-jakarta](https://mvnrepository.com/artifact/io.swagger.core.v3/swagger-core-jakarta)                                                                 | 2.2.47                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.swagger.core.v3:swagger-models-jakarta](https://mvnrepository.com/artifact/io.swagger.core.v3/swagger-models-jakarta)                                                             | 2.2.47                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [jakarta.activation:jakarta.activation-api](https://mvnrepository.com/artifact/jakarta.activation/jakarta.activation-api)                                                             | 2.1.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [jakarta.annotation:jakarta.annotation-api](https://mvnrepository.com/artifact/jakarta.annotation/jakarta.annotation-api)                                                             | 2.1.1                                     | [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html)                                                               |
| [jakarta.mail:jakarta.mail-api](https://mvnrepository.com/artifact/jakarta.mail/jakarta.mail-api)                                                                                     | 2.1.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [jakarta.validation:jakarta.validation-api](https://mvnrepository.com/artifact/jakarta.validation/jakarta.validation-api)                                                             | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                         |
| [jakarta.ws.rs:jakarta.ws.rs-api](https://mvnrepository.com/artifact/jakarta.ws.rs/jakarta.ws.rs-api)                                                                                 | 3.1.0                                     | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                                                                                    |
| [jakarta.xml.bind:jakarta.xml.bind-api](https://mvnrepository.com/artifact/jakarta.xml.bind/jakarta.xml.bind-api)                                                                     | 4.0.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [javax.annotation:javax.annotation-api](https://mvnrepository.com/artifact/javax.annotation/javax.annotation-api)                                                                     | 1.3.2                                     | [CDDL-1.0](https://opensource.org/licenses/CDDL-1.0)                                                                                                                                                                                                                                                                                             |
| [net.jodah:failsafe](https://mvnrepository.com/artifact/net.jodah/failsafe)                                                                                                           | 2.4.4                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:accessors-smart](https://mvnrepository.com/artifact/net.minidev/accessors-smart)                                                                                         | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:json-smart](https://mvnrepository.com/artifact/net.minidev/json-smart)                                                                                                   | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.commons:commons-compress](https://mvnrepository.com/artifact/org.apache.commons/commons-compress)                                                                         | 1.27.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.commons:commons-lang3](https://mvnrepository.com/artifact/org.apache.commons/commons-lang3)                                                                               | 3.18.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpclient](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpclient)                                                                       | 4.5.14                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpcore](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpcore)                                                                           | 4.4.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-core](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core)                                                                         | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-dom](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-dom)                                                                           | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-storage](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-storage)                                                                   | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-api](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-api)                                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-to-slf4j](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-to-slf4j)                                                                 | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-core](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-core)                                                             | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-el](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-el)                                                                 | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-websocket](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-websocket)                                                   | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.bouncycastle:bcprov-jdk18on](https://mvnrepository.com/artifact/org.bouncycastle/bcprov-jdk18on)                                                                                 | 1.83                                      | [Bouncy Castle](https://www.bouncycastle.org/licence.html)                                                                                                                                                                                                                                                                                       |
| [org.checkerframework:checker-qual](https://mvnrepository.com/artifact/org.checkerframework/checker-qual)                                                                             | 3.43.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.codehaus.mojo:animal-sniffer-annotations](https://mvnrepository.com/artifact/org.codehaus.mojo/animal-sniffer-annotations)                                                       | 1.24                                      | [MIT](https://opensource.org/licenses/MIT), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                            |
| [org.eclipse.angus:angus-activation](https://mvnrepository.com/artifact/org.eclipse.angus/angus-activation)                                                                           | 2.0.3                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.eclipse.angus:angus-mail](https://mvnrepository.com/artifact/org.eclipse.angus/angus-mail)                                                                                       | 2.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [org.eclipse.microprofile.openapi:microprofile-openapi-api](https://mvnrepository.com/artifact/org.eclipse.microprofile.openapi/microprofile-openapi-api)                             | 4.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.glassfish:jakarta.el](https://mvnrepository.com/artifact/org.glassfish/jakarta.el)                                                                                               | 3.0.4                                     | [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html)                                                               |
| [org.glassfish.jaxb:codemodel](https://mvnrepository.com/artifact/org.glassfish.jaxb/codemodel)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-core](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-core)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-jxc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-jxc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-runtime](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-runtime)                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-xjc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-xjc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:txw2](https://mvnrepository.com/artifact/org.glassfish.jaxb/txw2)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:xsom](https://mvnrepository.com/artifact/org.glassfish.jaxb/xsom)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.hdrhistogram:HdrHistogram](https://mvnrepository.com/artifact/org.hdrhistogram/HdrHistogram)                                                                                     | 2.2.2                                     | [BSD-2-Clause](https://opensource.org/licenses/BSD-2-Clause), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                            |
| [org.hibernate.validator:hibernate-validator](https://mvnrepository.com/artifact/org.hibernate.validator/hibernate-validator)                                                         | 8.0.3.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.honton.chas.hocon:jackson-dataformat-hocon](https://mvnrepository.com/artifact/org.honton.chas.hocon/jackson-dataformat-hocon)                                                   | 1.1.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss:jandex](https://mvnrepository.com/artifact/org.jboss/jandex)                                                                                                               | 2.4.5.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:commons-logging-jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/commons-logging-jboss-logging)                                                 | 1.0.0.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/jboss-logging)                                                                                 | 3.6.3.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client)                                                                           | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client-api](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client-api)                                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core)                                                                               | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core-spi](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core-spi)                                                                       | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jackson2-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jackson2-provider)                                                     | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jaxb-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jaxb-provider)                                                             | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-multipart-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-multipart-provider)                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains:annotations](https://mvnrepository.com/artifact/org.jetbrains/annotations)                                                                                             | 13.0                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib)                                                                           | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-common](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-common)                                                             | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk7](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk7)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk8](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk8)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jspecify:jspecify](https://mvnrepository.com/artifact/org.jspecify/jspecify)                                                                                                     | 1.0.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.keycloak:keycloak-admin-client](https://mvnrepository.com/artifact/org.keycloak/keycloak-admin-client)                                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.keycloak:keycloak-client-common-synced](https://mvnrepository.com/artifact/org.keycloak/keycloak-client-common-synced)                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.latencyutils:LatencyUtils](https://mvnrepository.com/artifact/org.latencyutils/LatencyUtils)                                                                                     | 2.0.3                                     | [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                                                                                          |
| [org.ow2.asm:asm](https://mvnrepository.com/artifact/org.ow2.asm/asm)                                                                                                                 | 9.7.1                                     | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                          |
| [org.reactivestreams:reactive-streams](https://mvnrepository.com/artifact/org.reactivestreams/reactive-streams)                                                                       | 1.0.4                                     | [MIT-0](https://spdx.org/licenses/MIT-0.html)                                                                                                                                                                                                                                                                                                    |
| [org.slf4j:jul-to-slf4j](https://mvnrepository.com/artifact/org.slf4j/jul-to-slf4j)                                                                                                   | 2.0.17                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.slf4j:slf4j-api](https://mvnrepository.com/artifact/org.slf4j/slf4j-api)                                                                                                         | 2.0.17                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.snakeyaml:snakeyaml-engine](https://mvnrepository.com/artifact/org.snakeyaml/snakeyaml-engine)                                                                                   | 2.7                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springdoc:springdoc-openapi-starter-common](https://mvnrepository.com/artifact/org.springdoc/springdoc-openapi-starter-common)                                                   | 2.8.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springdoc:springdoc-openapi-starter-webmvc-api](https://mvnrepository.com/artifact/org.springdoc/springdoc-openapi-starter-webmvc-api)                                           | 2.8.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://mvnrepository.com/artifact/org.springdoc/springdoc-openapi-starter-webmvc-ui)                                             | 2.8.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-aop](https://mvnrepository.com/artifact/org.springframework/spring-aop)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-beans](https://mvnrepository.com/artifact/org.springframework/spring-beans)                                                                               | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-context](https://mvnrepository.com/artifact/org.springframework/spring-context)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-context-support](https://mvnrepository.com/artifact/org.springframework/spring-context-support)                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-core](https://mvnrepository.com/artifact/org.springframework/spring-core)                                                                                 | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-expression](https://mvnrepository.com/artifact/org.springframework/spring-expression)                                                                     | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-jcl](https://mvnrepository.com/artifact/org.springframework/spring-jcl)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-web](https://mvnrepository.com/artifact/org.springframework/spring-web)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webflux](https://mvnrepository.com/artifact/org.springframework/spring-webflux)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webmvc](https://mvnrepository.com/artifact/org.springframework/spring-webmvc)                                                                             | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot)                                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-actuator](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-actuator)                                                     | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-actuator-autoconfigure](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-actuator-autoconfigure)                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-autoconfigure](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-autoconfigure)                                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter)                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-actuator](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-actuator)                                     | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-cache](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-cache)                                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-json](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-json)                                             | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-logging](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-logging)                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-oauth2-client](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-oauth2-client)                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-oauth2-resource-server](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-oauth2-resource-server)         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-reactor-netty](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-reactor-netty)                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-security](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-security)                                     | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-tomcat](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-tomcat)                                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-validation](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-validation)                                 | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-web](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web)                                               | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-webflux](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-webflux)                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.cloud:spring-cloud-gateway-mvc](https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-gateway-mvc)                                           | 4.0.4                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-config](https://mvnrepository.com/artifact/org.springframework.security/spring-security-config)                                         | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-core](https://mvnrepository.com/artifact/org.springframework.security/spring-security-core)                                             | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-crypto](https://mvnrepository.com/artifact/org.springframework.security/spring-security-crypto)                                         | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-client](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-client)                           | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-core](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-core)                               | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-jose](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-jose)                               | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-resource-server](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-resource-server)         | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-web](https://mvnrepository.com/artifact/org.springframework.security/spring-security-web)                                               | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.webjars:swagger-ui](https://mvnrepository.com/artifact/org.webjars/swagger-ui)                                                                                                   | 5.32.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.webjars:webjars-locator-lite](https://mvnrepository.com/artifact/org.webjars/webjars-locator-lite)                                                                               | 1.1.3                                     | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.yaml:snakeyaml](https://mvnrepository.com/artifact/org.yaml/snakeyaml)                                                                                                           | 2.4                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |

## Operator

| Package                                                                                                                                                                               | Version                                   | License(s)                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| [com.daml:bindings-java](https://mvnrepository.com/artifact/com.daml/bindings-java)                                                                                                   | 2.8.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson:jackson-bom](https://mvnrepository.com/artifact/com.fasterxml.jackson/jackson-bom)                                                                             | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-annotations)                                                   | 2.21                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-core](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-core)                                                                 | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-databind](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind)                                                         | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://mvnrepository.com/artifact/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml)                               | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jdk8](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jdk8)                                       | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jsr310](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jsr310)                                   | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-base](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base)                               | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-json-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider)             | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-yaml-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-yaml-provider)             | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations) | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-parameter-names](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-parameter-names)                         | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.github.java-json-tools:json-patch](https://mvnrepository.com/artifact/com.github.java-json-tools/json-patch)                                                                     | 1.13                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [LGPL-3.0](https://www.gnu.org/licenses/lgpl-3.0.html)                                                                                                                                                                                                                                |
| [com.github.stephenc.jcip:jcip-annotations](https://mvnrepository.com/artifact/com.github.stephenc.jcip/jcip-annotations)                                                             | 1.0-1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.android:annotations](https://mvnrepository.com/artifact/com.google.android/annotations)                                                                                   | 4.1.1.4                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.api.grpc:proto-google-common-protos](https://mvnrepository.com/artifact/com.google.api.grpc/proto-google-common-protos)                                                   | 2.22.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.findbugs:jsr305](https://mvnrepository.com/artifact/com.google.code.findbugs/jsr305)                                                                                 | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.gson:gson](https://mvnrepository.com/artifact/com.google.code.gson/gson)                                                                                             | 2.13.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.errorprone:error\_prone\_annotations](https://mvnrepository.com/artifact/com.google.errorprone/error_prone_annotations)                                                   | 2.41.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:failureaccess](https://mvnrepository.com/artifact/com.google.guava/failureaccess)                                                                                   | 1.0.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:guava](https://mvnrepository.com/artifact/com.google.guava/guava)                                                                                                   | 32.0.1-android                            | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:listenablefuture](https://mvnrepository.com/artifact/com.google.guava/listenablefuture)                                                                             | 9999.0-empty-to-avoid-conflict-with-guava | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.j2objc:j2objc-annotations](https://mvnrepository.com/artifact/com.google.j2objc/j2objc-annotations)                                                                       | 2.8                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.protobuf:protobuf-java](https://mvnrepository.com/artifact/com.google.protobuf/protobuf-java)                                                                             | 3.25.5                                    | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [com.ibm.async:asyncutil](https://mvnrepository.com/artifact/com.ibm.async/asyncutil)                                                                                                 | 0.1.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:content-type](https://mvnrepository.com/artifact/com.nimbusds/content-type)                                                                                             | 2.3                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:lang-tag](https://mvnrepository.com/artifact/com.nimbusds/lang-tag)                                                                                                     | 1.7                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:nimbus-jose-jwt](https://mvnrepository.com/artifact/com.nimbusds/nimbus-jose-jwt)                                                                                       | 10.0.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:oauth2-oidc-sdk](https://mvnrepository.com/artifact/com.nimbusds/oauth2-oidc-sdk)                                                                                       | 11.21.3                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup:javapoet](https://mvnrepository.com/artifact/com.squareup/javapoet)                                                                                                     | 1.13.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okhttp3:okhttp](https://mvnrepository.com/artifact/com.squareup.okhttp3/okhttp)                                                                                         | 4.12.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio](https://mvnrepository.com/artifact/com.squareup.okio/okio)                                                                                                   | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio-jvm](https://mvnrepository.com/artifact/com.squareup.okio/okio-jvm)                                                                                           | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.sun.istack:istack-commons-runtime](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-runtime)                                                                     | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.istack:istack-commons-tools](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-tools)                                                                         | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:relaxng-datatype](https://mvnrepository.com/artifact/com.sun.xml.bind.external/relaxng-datatype)                                                           | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:rngom](https://mvnrepository.com/artifact/com.sun.xml.bind.external/rngom)                                                                                 | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.typesafe:config](https://mvnrepository.com/artifact/com.typesafe/config)                                                                                                         | 1.4.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.zaxxer:HikariCP](https://mvnrepository.com/artifact/com.zaxxer/HikariCP)                                                                                                         | 5.0.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-codec:commons-codec](https://mvnrepository.com/artifact/commons-codec/commons-codec)                                                                                         | 1.18.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-io:commons-io](https://mvnrepository.com/artifact/commons-io/commons-io)                                                                                                     | 2.14.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-logging:commons-logging](https://mvnrepository.com/artifact/commons-logging/commons-logging)                                                                                 | 1.2                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client)                                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client-api](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client-api)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-httpclient-jdk](https://mvnrepository.com/artifact/io.fabric8/kubernetes-httpclient-jdk)                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-httpclient-vertx](https://mvnrepository.com/artifact/io.fabric8/kubernetes-httpclient-vertx)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-admissionregistration](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-admissionregistration)                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apiextensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apiextensions)                                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apps](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apps)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-autoscaling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-autoscaling)                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-batch](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-batch)                                                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-certificates](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-certificates)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-common](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-common)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-coordination](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-coordination)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-core](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-core)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-discovery](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-discovery)                                                                     | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-events](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-events)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-extensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-extensions)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-flowcontrol](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-flowcontrol)                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-gatewayapi](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-gatewayapi)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-metrics](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-metrics)                                                                         | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-networking](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-networking)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-node](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-node)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-policy](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-policy)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-rbac](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-rbac)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-resource](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-resource)                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-scheduling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-scheduling)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-storageclass](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-storageclass)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-client](https://mvnrepository.com/artifact/io.fabric8/openshift-client)                                                                                         | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-client-api](https://mvnrepository.com/artifact/io.fabric8/openshift-client-api)                                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model](https://mvnrepository.com/artifact/io.fabric8/openshift-model)                                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-autoscaling](https://mvnrepository.com/artifact/io.fabric8/openshift-model-autoscaling)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-config](https://mvnrepository.com/artifact/io.fabric8/openshift-model-config)                                                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-console](https://mvnrepository.com/artifact/io.fabric8/openshift-model-console)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-hive](https://mvnrepository.com/artifact/io.fabric8/openshift-model-hive)                                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-installer](https://mvnrepository.com/artifact/io.fabric8/openshift-model-installer)                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-machine](https://mvnrepository.com/artifact/io.fabric8/openshift-model-machine)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-machineconfiguration](https://mvnrepository.com/artifact/io.fabric8/openshift-model-machineconfiguration)                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-miscellaneous](https://mvnrepository.com/artifact/io.fabric8/openshift-model-miscellaneous)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-monitoring](https://mvnrepository.com/artifact/io.fabric8/openshift-model-monitoring)                                                                     | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-operator](https://mvnrepository.com/artifact/io.fabric8/openshift-model-operator)                                                                         | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-operatorhub](https://mvnrepository.com/artifact/io.fabric8/openshift-model-operatorhub)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-storageversionmigrator](https://mvnrepository.com/artifact/io.fabric8/openshift-model-storageversionmigrator)                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-tuned](https://mvnrepository.com/artifact/io.fabric8/openshift-model-tuned)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-whereabouts](https://mvnrepository.com/artifact/io.fabric8/openshift-model-whereabouts)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:zjsonpatch](https://mvnrepository.com/artifact/io.fabric8/zjsonpatch)                                                                                                     | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.github.java-diff-utils:java-diff-utils](https://mvnrepository.com/artifact/io.github.java-diff-utils/java-diff-utils)                                                             | 4.16                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-api](https://mvnrepository.com/artifact/io.grpc/grpc-api)                                                                                                               | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-context](https://mvnrepository.com/artifact/io.grpc/grpc-context)                                                                                                       | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-core](https://mvnrepository.com/artifact/io.grpc/grpc-core)                                                                                                             | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-netty](https://mvnrepository.com/artifact/io.grpc/grpc-netty)                                                                                                           | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf)                                                                                                     | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf-lite](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf-lite)                                                                                           | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-stub](https://mvnrepository.com/artifact/io.grpc/grpc-stub)                                                                                                             | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-util](https://mvnrepository.com/artifact/io.grpc/grpc-util)                                                                                                             | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.javaoperatorsdk:operator-framework](https://mvnrepository.com/artifact/io.javaoperatorsdk/operator-framework)                                                                     | 5.1.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.javaoperatorsdk:operator-framework-core](https://mvnrepository.com/artifact/io.javaoperatorsdk/operator-framework-core)                                                           | 5.1.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.javaoperatorsdk:operator-framework-spring-boot-starter](https://mvnrepository.com/artifact/io.javaoperatorsdk/operator-framework-spring-boot-starter)                             | 6.1.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-commons](https://mvnrepository.com/artifact/io.micrometer/micrometer-commons)                                                                               | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-observation](https://mvnrepository.com/artifact/io.micrometer/micrometer-observation)                                                                       | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-all](https://mvnrepository.com/artifact/io.netty/netty-all)                                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-buffer](https://mvnrepository.com/artifact/io.netty/netty-buffer)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec](https://mvnrepository.com/artifact/io.netty/netty-codec)                                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-dns](https://mvnrepository.com/artifact/io.netty/netty-codec-dns)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-haproxy](https://mvnrepository.com/artifact/io.netty/netty-codec-haproxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http](https://mvnrepository.com/artifact/io.netty/netty-codec-http)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http2](https://mvnrepository.com/artifact/io.netty/netty-codec-http2)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-memcache](https://mvnrepository.com/artifact/io.netty/netty-codec-memcache)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-mqtt](https://mvnrepository.com/artifact/io.netty/netty-codec-mqtt)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-redis](https://mvnrepository.com/artifact/io.netty/netty-codec-redis)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-smtp](https://mvnrepository.com/artifact/io.netty/netty-codec-smtp)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-socks](https://mvnrepository.com/artifact/io.netty/netty-codec-socks)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-stomp](https://mvnrepository.com/artifact/io.netty/netty-codec-stomp)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-xml](https://mvnrepository.com/artifact/io.netty/netty-codec-xml)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-common](https://mvnrepository.com/artifact/io.netty/netty-common)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler](https://mvnrepository.com/artifact/io.netty/netty-handler)                                                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-proxy](https://mvnrepository.com/artifact/io.netty/netty-handler-proxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-ssl-ocsp](https://mvnrepository.com/artifact/io.netty/netty-handler-ssl-ocsp)                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver](https://mvnrepository.com/artifact/io.netty/netty-resolver)                                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns)                                                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-classes-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-classes-macos)                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-native-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-native-macos)                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport](https://mvnrepository.com/artifact/io.netty/netty-transport)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-epoll)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-kqueue)                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-native-epoll)                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-native-kqueue)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-unix-common](https://mvnrepository.com/artifact/io.netty/netty-transport-native-unix-common)                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-rxtx](https://mvnrepository.com/artifact/io.netty/netty-transport-rxtx)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-sctp](https://mvnrepository.com/artifact/io.netty/netty-transport-sctp)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-udt](https://mvnrepository.com/artifact/io.netty/netty-transport-udt)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.pebbletemplates:pebble](https://mvnrepository.com/artifact/io.pebbletemplates/pebble)                                                                                             | 3.2.0                                     | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [io.perfmark:perfmark-api](https://mvnrepository.com/artifact/io.perfmark/perfmark-api)                                                                                               | 0.26.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor:reactor-core](https://mvnrepository.com/artifact/io.projectreactor/reactor-core)                                                                                   | 3.7.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-core](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-core)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-http](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-http)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.sentry:sentry](https://mvnrepository.com/artifact/io.sentry/sentry)                                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-reactor](https://mvnrepository.com/artifact/io.sentry/sentry-reactor)                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-jakarta)                                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-starter-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-starter-jakarta)                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-jakarta)                                                                                 | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.vertx:vertx-auth-common](https://mvnrepository.com/artifact/io.vertx/vertx-auth-common)                                                                                           | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                 |
| [io.vertx:vertx-core](https://mvnrepository.com/artifact/io.vertx/vertx-core)                                                                                                         | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                           |
| [io.vertx:vertx-web-client](https://mvnrepository.com/artifact/io.vertx/vertx-web-client)                                                                                             | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                 |
| [io.vertx:vertx-web-common](https://mvnrepository.com/artifact/io.vertx/vertx-web-common)                                                                                             | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                 |
| [jakarta.activation:jakarta.activation-api](https://mvnrepository.com/artifact/jakarta.activation/jakarta.activation-api)                                                             | 2.1.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [jakarta.annotation:jakarta.annotation-api](https://mvnrepository.com/artifact/jakarta.annotation/jakarta.annotation-api)                                                             | 2.1.1                                     | [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html)                                                               |
| [jakarta.mail:jakarta.mail-api](https://mvnrepository.com/artifact/jakarta.mail/jakarta.mail-api)                                                                                     | 2.1.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [jakarta.validation:jakarta.validation-api](https://mvnrepository.com/artifact/jakarta.validation/jakarta.validation-api)                                                             | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                         |
| [jakarta.ws.rs:jakarta.ws.rs-api](https://mvnrepository.com/artifact/jakarta.ws.rs/jakarta.ws.rs-api)                                                                                 | 3.1.0                                     | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                                                                                    |
| [jakarta.xml.bind:jakarta.xml.bind-api](https://mvnrepository.com/artifact/jakarta.xml.bind/jakarta.xml.bind-api)                                                                     | 4.0.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [javax.annotation:javax.annotation-api](https://mvnrepository.com/artifact/javax.annotation/javax.annotation-api)                                                                     | 1.3.2                                     | [CDDL-1.0](https://opensource.org/licenses/CDDL-1.0)                                                                                                                                                                                                                                                                                             |
| [net.bytebuddy:byte-buddy](https://mvnrepository.com/artifact/net.bytebuddy/byte-buddy)                                                                                               | 1.17.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.bytebuddy:byte-buddy-agent](https://mvnrepository.com/artifact/net.bytebuddy/byte-buddy-agent)                                                                                   | 1.17.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:accessors-smart](https://mvnrepository.com/artifact/net.minidev/accessors-smart)                                                                                         | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:json-smart](https://mvnrepository.com/artifact/net.minidev/json-smart)                                                                                                   | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.commons:commons-lang3](https://mvnrepository.com/artifact/org.apache.commons/commons-lang3)                                                                               | 3.18.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpclient](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpclient)                                                                       | 4.5.14                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpcore](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpcore)                                                                           | 4.4.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-core](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core)                                                                         | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-dom](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-dom)                                                                           | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-storage](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-storage)                                                                   | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-api](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-api)                                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-core](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core)                                                                         | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-jul](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-jul)                                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-slf4j2-impl](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-slf4j2-impl)                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-core](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-core)                                                             | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-el](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-el)                                                                 | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-websocket](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-websocket)                                                   | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.aspectj:aspectjrt](https://mvnrepository.com/artifact/org.aspectj/aspectjrt)                                                                                                     | 1.9.21                                    | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt)                                                                                                                                                                                                                                                                             |
| [org.bouncycastle:bcprov-jdk18on](https://mvnrepository.com/artifact/org.bouncycastle/bcprov-jdk18on)                                                                                 | 1.83                                      | [Bouncy Castle](https://www.bouncycastle.org/licence.html)                                                                                                                                                                                                                                                                                       |
| [org.checkerframework:checker-qual](https://mvnrepository.com/artifact/org.checkerframework/checker-qual)                                                                             | 3.33.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.codehaus.mojo:animal-sniffer-annotations](https://mvnrepository.com/artifact/org.codehaus.mojo/animal-sniffer-annotations)                                                       | 1.23                                      | [MIT](https://opensource.org/licenses/MIT), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                            |
| [org.eclipse.angus:angus-activation](https://mvnrepository.com/artifact/org.eclipse.angus/angus-activation)                                                                           | 2.0.3                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.eclipse.angus:angus-mail](https://mvnrepository.com/artifact/org.eclipse.angus/angus-mail)                                                                                       | 2.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [org.eclipse.microprofile.openapi:microprofile-openapi-api](https://mvnrepository.com/artifact/org.eclipse.microprofile.openapi/microprofile-openapi-api)                             | 4.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.glassfish.jaxb:codemodel](https://mvnrepository.com/artifact/org.glassfish.jaxb/codemodel)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-core](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-core)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-jxc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-jxc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-runtime](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-runtime)                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-xjc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-xjc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:txw2](https://mvnrepository.com/artifact/org.glassfish.jaxb/txw2)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:xsom](https://mvnrepository.com/artifact/org.glassfish.jaxb/xsom)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.honton.chas.hocon:jackson-dataformat-hocon](https://mvnrepository.com/artifact/org.honton.chas.hocon/jackson-dataformat-hocon)                                                   | 1.1.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss:jandex](https://mvnrepository.com/artifact/org.jboss/jandex)                                                                                                               | 2.4.5.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:commons-logging-jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/commons-logging-jboss-logging)                                                 | 1.0.0.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/jboss-logging)                                                                                 | 3.6.3.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client)                                                                           | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client-api](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client-api)                                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core)                                                                               | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core-spi](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core-spi)                                                                       | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jackson2-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jackson2-provider)                                                     | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jaxb-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jaxb-provider)                                                             | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-multipart-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-multipart-provider)                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains:annotations](https://mvnrepository.com/artifact/org.jetbrains/annotations)                                                                                             | 13.0                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib)                                                                           | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-common](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-common)                                                             | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk7](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk7)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk8](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk8)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.keycloak:keycloak-admin-client](https://mvnrepository.com/artifact/org.keycloak/keycloak-admin-client)                                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.keycloak:keycloak-client-common-synced](https://mvnrepository.com/artifact/org.keycloak/keycloak-client-common-synced)                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.mockito:mockito-core](https://mvnrepository.com/artifact/org.mockito/mockito-core)                                                                                               | 5.17.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.objenesis:objenesis](https://mvnrepository.com/artifact/org.objenesis/objenesis)                                                                                                 | 3.3                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.ow2.asm:asm](https://mvnrepository.com/artifact/org.ow2.asm/asm)                                                                                                                 | 9.7.1                                     | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                          |
| [org.postgresql:postgresql](https://mvnrepository.com/artifact/org.postgresql/postgresql)                                                                                             | 42.3.9                                    | [BSD-2-Clause](https://opensource.org/licenses/BSD-2-Clause)                                                                                                                                                                                                                                                                                     |
| [org.reactivestreams:reactive-streams](https://mvnrepository.com/artifact/org.reactivestreams/reactive-streams)                                                                       | 1.0.4                                     | [MIT-0](https://spdx.org/licenses/MIT-0.html)                                                                                                                                                                                                                                                                                                    |
| [org.slf4j:slf4j-api](https://mvnrepository.com/artifact/org.slf4j/slf4j-api)                                                                                                         | 2.0.17                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.snakeyaml:snakeyaml-engine](https://mvnrepository.com/artifact/org.snakeyaml/snakeyaml-engine)                                                                                   | 2.9                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-aop](https://mvnrepository.com/artifact/org.springframework/spring-aop)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-beans](https://mvnrepository.com/artifact/org.springframework/spring-beans)                                                                               | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-context](https://mvnrepository.com/artifact/org.springframework/spring-context)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-core](https://mvnrepository.com/artifact/org.springframework/spring-core)                                                                                 | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-expression](https://mvnrepository.com/artifact/org.springframework/spring-expression)                                                                     | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-jcl](https://mvnrepository.com/artifact/org.springframework/spring-jcl)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-web](https://mvnrepository.com/artifact/org.springframework/spring-web)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webflux](https://mvnrepository.com/artifact/org.springframework/spring-webflux)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webmvc](https://mvnrepository.com/artifact/org.springframework/spring-webmvc)                                                                             | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot)                                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-autoconfigure](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-autoconfigure)                                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter)                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-json](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-json)                                             | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-log4j2](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-log4j2)                                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-reactor-netty](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-reactor-netty)                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-tomcat](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-tomcat)                                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-web](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web)                                               | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-webflux](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-webflux)                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.unbescape:unbescape](https://mvnrepository.com/artifact/org.unbescape/unbescape)                                                                                                 | 1.1.6.RELEASE                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.yaml:snakeyaml](https://mvnrepository.com/artifact/org.yaml/snakeyaml)                                                                                                           | 2.4                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |

## UI

| Package                                                                                                                    | Version      | License(s)                                                                                                       |
| -------------------------------------------------------------------------------------------------------------------------- | ------------ | ---------------------------------------------------------------------------------------------------------------- |
| [@babel/code-frame](https://www.npmjs.com/package/@babel/code-frame)                                                       | 7.26.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/generator](https://www.npmjs.com/package/@babel/generator)                                                         | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/helper-module-imports](https://www.npmjs.com/package/@babel/helper-module-imports)                                 | 7.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/helper-string-parser](https://www.npmjs.com/package/@babel/helper-string-parser)                                   | 7.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/helper-validator-identifier](https://www.npmjs.com/package/@babel/helper-validator-identifier)                     | 7.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/parser](https://www.npmjs.com/package/@babel/parser)                                                               | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/runtime](https://www.npmjs.com/package/@babel/runtime)                                                             | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/runtime](https://www.npmjs.com/package/@babel/runtime)                                                             | 7.27.6       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/runtime](https://www.npmjs.com/package/@babel/runtime)                                                             | 7.28.4       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/template](https://www.npmjs.com/package/@babel/template)                                                           | 7.26.9       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/traverse](https://www.npmjs.com/package/@babel/traverse)                                                           | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@babel/types](https://www.npmjs.com/package/@babel/types)                                                                 | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@bufbuild/protobuf](https://www.npmjs.com/package/@bufbuild/protobuf)                                                     | 2.2.4        | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [@emotion/babel-plugin](https://www.npmjs.com/package/@emotion/babel-plugin)                                               | 11.13.5      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/cache](https://www.npmjs.com/package/@emotion/cache)                                                             | 11.14.0      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/hash](https://www.npmjs.com/package/@emotion/hash)                                                               | 0.9.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/memoize](https://www.npmjs.com/package/@emotion/memoize)                                                         | 0.9.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/react](https://www.npmjs.com/package/@emotion/react)                                                             | 11.14.0      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/serialize](https://www.npmjs.com/package/@emotion/serialize)                                                     | 1.3.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/sheet](https://www.npmjs.com/package/@emotion/sheet)                                                             | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/unitless](https://www.npmjs.com/package/@emotion/unitless)                                                       | 0.10.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/use-insertion-effect-with-fallbacks](https://www.npmjs.com/package/@emotion/use-insertion-effect-with-fallbacks) | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/utils](https://www.npmjs.com/package/@emotion/utils)                                                             | 1.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@emotion/weak-memoize](https://www.npmjs.com/package/@emotion/weak-memoize)                                               | 0.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@esbuild-plugins/node-modules-polyfill](https://www.npmjs.com/package/@esbuild-plugins/node-modules-polyfill)             | 0.2.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [@esbuild/darwin-arm64](https://www.npmjs.com/package/@esbuild/darwin-arm64)                                               | 0.18.20      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@floating-ui/core](https://www.npmjs.com/package/@floating-ui/core)                                                       | 1.6.9        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@floating-ui/dom](https://www.npmjs.com/package/@floating-ui/dom)                                                         | 1.6.13       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@floating-ui/utils](https://www.npmjs.com/package/@floating-ui/utils)                                                     | 0.2.9        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@intellecteu/common-ui](https://www.npmjs.com/package/@intellecteu/common-ui)                                             | 0.1.51       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@jridgewell/gen-mapping](https://www.npmjs.com/package/@jridgewell/gen-mapping)                                           | 0.3.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@jridgewell/resolve-uri](https://www.npmjs.com/package/@jridgewell/resolve-uri)                                           | 3.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@jridgewell/set-array](https://www.npmjs.com/package/@jridgewell/set-array)                                               | 1.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@jridgewell/source-map](https://www.npmjs.com/package/@jridgewell/source-map)                                             | 0.3.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@jridgewell/sourcemap-codec](https://www.npmjs.com/package/@jridgewell/sourcemap-codec)                                   | 1.5.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@jridgewell/trace-mapping](https://www.npmjs.com/package/@jridgewell/trace-mapping)                                       | 0.3.25       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@loadable/component](https://www.npmjs.com/package/@loadable/component)                                                   | 5.16.4       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@nodelib/fs.scandir](https://www.npmjs.com/package/@nodelib/fs.scandir)                                                   | 2.1.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@nodelib/fs.stat](https://www.npmjs.com/package/@nodelib/fs.stat)                                                         | 2.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@nodelib/fs.walk](https://www.npmjs.com/package/@nodelib/fs.walk)                                                         | 1.2.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@popperjs/core](https://www.npmjs.com/package/@popperjs/core)                                                             | 2.11.8       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@remix-run/router](https://www.npmjs.com/package/@remix-run/router)                                                       | 1.23.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@sindresorhus/is](https://www.npmjs.com/package/@sindresorhus/is)                                                         | 0.7.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@tanstack/query-core](https://www.npmjs.com/package/@tanstack/query-core)                                                 | 4.36.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@tanstack/react-query](https://www.npmjs.com/package/@tanstack/react-query)                                               | 4.36.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@tanstack/react-table](https://www.npmjs.com/package/@tanstack/react-table)                                               | 8.21.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@tanstack/table-core](https://www.npmjs.com/package/@tanstack/table-core)                                                 | 8.21.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@trysound/sax](https://www.npmjs.com/package/@trysound/sax)                                                               | 0.2.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [@types/eslint-scope](https://www.npmjs.com/package/@types/eslint-scope)                                                   | 3.7.7        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/eslint](https://www.npmjs.com/package/@types/eslint)                                                               | 9.6.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/estree](https://www.npmjs.com/package/@types/estree)                                                               | 1.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/glob](https://www.npmjs.com/package/@types/glob)                                                                   | 7.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/hoist-non-react-statics](https://www.npmjs.com/package/@types/hoist-non-react-statics)                             | 3.3.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/json-schema](https://www.npmjs.com/package/@types/json-schema)                                                     | 7.0.15       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/minimatch](https://www.npmjs.com/package/@types/minimatch)                                                         | 5.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/node](https://www.npmjs.com/package/@types/node)                                                                   | 22.13.10     | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/parse-json](https://www.npmjs.com/package/@types/parse-json)                                                       | 4.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/react-transition-group](https://www.npmjs.com/package/@types/react-transition-group)                               | 4.4.12       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@types/react](https://www.npmjs.com/package/@types/react)                                                                 | 19.0.11      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/ast](https://www.npmjs.com/package/@webassemblyjs/ast)                                                     | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/floating-point-hex-parser](https://www.npmjs.com/package/@webassemblyjs/floating-point-hex-parser)         | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/helper-api-error](https://www.npmjs.com/package/@webassemblyjs/helper-api-error)                           | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/helper-buffer](https://www.npmjs.com/package/@webassemblyjs/helper-buffer)                                 | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/helper-numbers](https://www.npmjs.com/package/@webassemblyjs/helper-numbers)                               | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/helper-wasm-bytecode](https://www.npmjs.com/package/@webassemblyjs/helper-wasm-bytecode)                   | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/helper-wasm-section](https://www.npmjs.com/package/@webassemblyjs/helper-wasm-section)                     | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/ieee754](https://www.npmjs.com/package/@webassemblyjs/ieee754)                                             | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/leb128](https://www.npmjs.com/package/@webassemblyjs/leb128)                                               | 1.13.2       | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [@webassemblyjs/utf8](https://www.npmjs.com/package/@webassemblyjs/utf8)                                                   | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/wasm-edit](https://www.npmjs.com/package/@webassemblyjs/wasm-edit)                                         | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/wasm-gen](https://www.npmjs.com/package/@webassemblyjs/wasm-gen)                                           | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/wasm-opt](https://www.npmjs.com/package/@webassemblyjs/wasm-opt)                                           | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/wasm-parser](https://www.npmjs.com/package/@webassemblyjs/wasm-parser)                                     | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@webassemblyjs/wast-printer](https://www.npmjs.com/package/@webassemblyjs/wast-printer)                                   | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [@xtuc/ieee754](https://www.npmjs.com/package/@xtuc/ieee754)                                                               | 1.2.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [@xtuc/long](https://www.npmjs.com/package/@xtuc/long)                                                                     | 4.2.2        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [ace-builds](https://www.npmjs.com/package/ace-builds)                                                                     | 1.39.0       | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [acorn](https://www.npmjs.com/package/acorn)                                                                               | 7.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [acorn](https://www.npmjs.com/package/acorn)                                                                               | 8.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ajv-formats](https://www.npmjs.com/package/ajv-formats)                                                                   | 2.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ajv-keywords](https://www.npmjs.com/package/ajv-keywords)                                                                 | 3.5.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ajv-keywords](https://www.npmjs.com/package/ajv-keywords)                                                                 | 5.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ajv](https://www.npmjs.com/package/ajv)                                                                                   | 6.12.6       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ajv](https://www.npmjs.com/package/ajv)                                                                                   | 8.17.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [arch](https://www.npmjs.com/package/arch)                                                                                 | 2.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [archive-type](https://www.npmjs.com/package/archive-type)                                                                 | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [array-union](https://www.npmjs.com/package/array-union)                                                                   | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [asap](https://www.npmjs.com/package/asap)                                                                                 | 2.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [babel-plugin-macros](https://www.npmjs.com/package/babel-plugin-macros)                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [balanced-match](https://www.npmjs.com/package/balanced-match)                                                             | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [base16](https://www.npmjs.com/package/base16)                                                                             | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [base64-js](https://www.npmjs.com/package/base64-js)                                                                       | 1.5.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [big.js](https://www.npmjs.com/package/big.js)                                                                             | 5.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [bin-build](https://www.npmjs.com/package/bin-build)                                                                       | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [bin-check](https://www.npmjs.com/package/bin-check)                                                                       | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [bin-version-check](https://www.npmjs.com/package/bin-version-check)                                                       | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [bin-version](https://www.npmjs.com/package/bin-version)                                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [bin-wrapper](https://www.npmjs.com/package/bin-wrapper)                                                                   | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [bl](https://www.npmjs.com/package/bl)                                                                                     | 1.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [body-scroll-lock](https://www.npmjs.com/package/body-scroll-lock)                                                         | 4.0.0-beta.0 | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [boolbase](https://www.npmjs.com/package/boolbase)                                                                         | 1.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [brace-expansion](https://www.npmjs.com/package/brace-expansion)                                                           | 1.1.11       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [braces](https://www.npmjs.com/package/braces)                                                                             | 3.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [browserslist](https://www.npmjs.com/package/browserslist)                                                                 | 4.24.4       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer-alloc-unsafe](https://www.npmjs.com/package/buffer-alloc-unsafe)                                                   | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer-alloc](https://www.npmjs.com/package/buffer-alloc)                                                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer-builder](https://www.npmjs.com/package/buffer-builder)                                                             | 0.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer-crc32](https://www.npmjs.com/package/buffer-crc32)                                                                 | 0.2.13       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer-fill](https://www.npmjs.com/package/buffer-fill)                                                                   | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer-from](https://www.npmjs.com/package/buffer-from)                                                                   | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer](https://www.npmjs.com/package/buffer)                                                                             | 5.7.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [buffer](https://www.npmjs.com/package/buffer)                                                                             | 6.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cacheable-request](https://www.npmjs.com/package/cacheable-request)                                                       | 2.1.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [callsites](https://www.npmjs.com/package/callsites)                                                                       | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [caniuse-lite](https://www.npmjs.com/package/caniuse-lite)                                                                 | 1.0.30001706 | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [caw](https://www.npmjs.com/package/caw)                                                                                   | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [chrome-trace-event](https://www.npmjs.com/package/chrome-trace-event)                                                     | 1.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [classnames](https://www.npmjs.com/package/classnames)                                                                     | 2.5.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [clone-response](https://www.npmjs.com/package/clone-response)                                                             | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [clsx](https://www.npmjs.com/package/clsx)                                                                                 | 2.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [colorjs.io](https://www.npmjs.com/package/colorjs.io)                                                                     | 0.5.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [commander](https://www.npmjs.com/package/commander)                                                                       | 2.20.3       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [commander](https://www.npmjs.com/package/commander)                                                                       | 7.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [concat-map](https://www.npmjs.com/package/concat-map)                                                                     | 0.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [config-chain](https://www.npmjs.com/package/config-chain)                                                                 | 1.1.13       | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [content-disposition](https://www.npmjs.com/package/content-disposition)                                                   | 0.5.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [convert-source-map](https://www.npmjs.com/package/convert-source-map)                                                     | 1.9.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [copy-webpack-plugin](https://www.npmjs.com/package/copy-webpack-plugin)                                                   | 11.0.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [core-js](https://www.npmjs.com/package/core-js)                                                                           | 3.41.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [core-util-is](https://www.npmjs.com/package/core-util-is)                                                                 | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cosmiconfig](https://www.npmjs.com/package/cosmiconfig)                                                                   | 7.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cron-validate](https://www.npmjs.com/package/cron-validate)                                                               | 1.5.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cross-fetch](https://www.npmjs.com/package/cross-fetch)                                                                   | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cross-spawn](https://www.npmjs.com/package/cross-spawn)                                                                   | 5.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cross-spawn](https://www.npmjs.com/package/cross-spawn)                                                                   | 6.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cross-spawn](https://www.npmjs.com/package/cross-spawn)                                                                   | 7.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [crypto-js](https://www.npmjs.com/package/crypto-js)                                                                       | 4.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [css-select](https://www.npmjs.com/package/css-select)                                                                     | 4.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [css-select](https://www.npmjs.com/package/css-select)                                                                     | 5.1.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [css-tree](https://www.npmjs.com/package/css-tree)                                                                         | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [css-tree](https://www.npmjs.com/package/css-tree)                                                                         | 2.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [css-tree](https://www.npmjs.com/package/css-tree)                                                                         | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [css-what](https://www.npmjs.com/package/css-what)                                                                         | 6.1.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [csso](https://www.npmjs.com/package/csso)                                                                                 | 4.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [csso](https://www.npmjs.com/package/csso)                                                                                 | 5.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [csstype](https://www.npmjs.com/package/csstype)                                                                           | 3.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [cwebp-bin](https://www.npmjs.com/package/cwebp-bin)                                                                       | 7.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [debug](https://www.npmjs.com/package/debug)                                                                               | 4.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decode-uri-component](https://www.npmjs.com/package/decode-uri-component)                                                 | 0.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decompress-response](https://www.npmjs.com/package/decompress-response)                                                   | 3.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decompress-tar](https://www.npmjs.com/package/decompress-tar)                                                             | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decompress-tarbz2](https://www.npmjs.com/package/decompress-tarbz2)                                                       | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decompress-targz](https://www.npmjs.com/package/decompress-targz)                                                         | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decompress-unzip](https://www.npmjs.com/package/decompress-unzip)                                                         | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [decompress](https://www.npmjs.com/package/decompress)                                                                     | 4.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [deepmerge](https://www.npmjs.com/package/deepmerge)                                                                       | 2.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [detect-node-es](https://www.npmjs.com/package/detect-node-es)                                                             | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [diff-match-patch](https://www.npmjs.com/package/diff-match-patch)                                                         | 1.0.5        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [dir-glob](https://www.npmjs.com/package/dir-glob)                                                                         | 3.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [dom-helpers](https://www.npmjs.com/package/dom-helpers)                                                                   | 5.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [dom-serializer](https://www.npmjs.com/package/dom-serializer)                                                             | 1.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [dom-serializer](https://www.npmjs.com/package/dom-serializer)                                                             | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [domelementtype](https://www.npmjs.com/package/domelementtype)                                                             | 2.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [domhandler](https://www.npmjs.com/package/domhandler)                                                                     | 4.3.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [domhandler](https://www.npmjs.com/package/domhandler)                                                                     | 5.0.3        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [domutils](https://www.npmjs.com/package/domutils)                                                                         | 2.8.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [domutils](https://www.npmjs.com/package/domutils)                                                                         | 3.2.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [download](https://www.npmjs.com/package/download)                                                                         | 6.2.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [download](https://www.npmjs.com/package/download)                                                                         | 7.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [duplexer3](https://www.npmjs.com/package/duplexer3)                                                                       | 0.1.5        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [electron-to-chromium](https://www.npmjs.com/package/electron-to-chromium)                                                 | 1.5.120      | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [emojis-list](https://www.npmjs.com/package/emojis-list)                                                                   | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [end-of-stream](https://www.npmjs.com/package/end-of-stream)                                                               | 1.4.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [enhanced-resolve](https://www.npmjs.com/package/enhanced-resolve)                                                         | 5.18.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [entities](https://www.npmjs.com/package/entities)                                                                         | 2.2.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [entities](https://www.npmjs.com/package/entities)                                                                         | 4.5.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [error-ex](https://www.npmjs.com/package/error-ex)                                                                         | 1.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [es-module-lexer](https://www.npmjs.com/package/es-module-lexer)                                                           | 1.6.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [esbuild](https://www.npmjs.com/package/esbuild)                                                                           | 0.18.20      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [escalade](https://www.npmjs.com/package/escalade)                                                                         | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [escape-string-regexp](https://www.npmjs.com/package/escape-string-regexp)                                                 | 1.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [escape-string-regexp](https://www.npmjs.com/package/escape-string-regexp)                                                 | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [eslint-scope](https://www.npmjs.com/package/eslint-scope)                                                                 | 5.1.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [esrecurse](https://www.npmjs.com/package/esrecurse)                                                                       | 4.3.0        | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [estraverse](https://www.npmjs.com/package/estraverse)                                                                     | 4.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [estraverse](https://www.npmjs.com/package/estraverse)                                                                     | 5.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [estree-walker](https://www.npmjs.com/package/estree-walker)                                                               | 0.6.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [events](https://www.npmjs.com/package/events)                                                                             | 3.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [eventsource](https://www.npmjs.com/package/eventsource)                                                                   | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [exec-buffer](https://www.npmjs.com/package/exec-buffer)                                                                   | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 0.7.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 5.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [executable](https://www.npmjs.com/package/executable)                                                                     | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ext-list](https://www.npmjs.com/package/ext-list)                                                                         | 2.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ext-name](https://www.npmjs.com/package/ext-name)                                                                         | 5.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fast-deep-equal](https://www.npmjs.com/package/fast-deep-equal)                                                           | 3.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fast-glob](https://www.npmjs.com/package/fast-glob)                                                                       | 3.3.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fast-json-stable-stringify](https://www.npmjs.com/package/fast-json-stable-stringify)                                     | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fast-uri](https://www.npmjs.com/package/fast-uri)                                                                         | 3.0.6        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [fast-xml-parser](https://www.npmjs.com/package/fast-xml-parser)                                                           | 4.5.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fastq](https://www.npmjs.com/package/fastq)                                                                               | 1.19.1       | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [fbemitter](https://www.npmjs.com/package/fbemitter)                                                                       | 3.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [fbjs-css-vars](https://www.npmjs.com/package/fbjs-css-vars)                                                               | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fbjs](https://www.npmjs.com/package/fbjs)                                                                                 | 3.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fd-slicer](https://www.npmjs.com/package/fd-slicer)                                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 10.11.0      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 12.4.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 3.9.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 4.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 5.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 6.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 8.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [filename-reserved-regex](https://www.npmjs.com/package/filename-reserved-regex)                                           | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [filenamify](https://www.npmjs.com/package/filenamify)                                                                     | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fill-range](https://www.npmjs.com/package/fill-range)                                                                     | 7.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [find-root](https://www.npmjs.com/package/find-root)                                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [find-versions](https://www.npmjs.com/package/find-versions)                                                               | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [flux](https://www.npmjs.com/package/flux)                                                                                 | 4.0.4        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [focus-lock](https://www.npmjs.com/package/focus-lock)                                                                     | 1.3.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [formik](https://www.npmjs.com/package/formik)                                                                             | 2.4.6        | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [from2](https://www.npmjs.com/package/from2)                                                                               | 2.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fs-constants](https://www.npmjs.com/package/fs-constants)                                                                 | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [fs.realpath](https://www.npmjs.com/package/fs.realpath)                                                                   | 1.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [function-bind](https://www.npmjs.com/package/function-bind)                                                               | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [get-proxy](https://www.npmjs.com/package/get-proxy)                                                                       | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 5.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 6.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [gifsicle](https://www.npmjs.com/package/gifsicle)                                                                         | 5.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [glob-parent](https://www.npmjs.com/package/glob-parent)                                                                   | 5.1.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [glob-parent](https://www.npmjs.com/package/glob-parent)                                                                   | 6.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [glob-to-regexp](https://www.npmjs.com/package/glob-to-regexp)                                                             | 0.4.1        | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [glob](https://www.npmjs.com/package/glob)                                                                                 | 7.2.3        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [globals](https://www.npmjs.com/package/globals)                                                                           | 11.12.0      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [globby](https://www.npmjs.com/package/globby)                                                                             | 10.0.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [globby](https://www.npmjs.com/package/globby)                                                                             | 13.2.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [got](https://www.npmjs.com/package/got)                                                                                   | 7.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [got](https://www.npmjs.com/package/got)                                                                                   | 8.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [graceful-fs](https://www.npmjs.com/package/graceful-fs)                                                                   | 4.2.11       | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [has-flag](https://www.npmjs.com/package/has-flag)                                                                         | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [has-symbol-support-x](https://www.npmjs.com/package/has-symbol-support-x)                                                 | 1.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [has-to-string-tag-x](https://www.npmjs.com/package/has-to-string-tag-x)                                                   | 1.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [hasown](https://www.npmjs.com/package/hasown)                                                                             | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [hoist-non-react-statics](https://www.npmjs.com/package/hoist-non-react-statics)                                           | 3.3.2        | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [http-cache-semantics](https://www.npmjs.com/package/http-cache-semantics)                                                 | 3.8.1        | [See license](/catalyx-blockchain-manager/canton-network/version-2.0/support-and-resources/open-source-licenses) |
| [human-signals](https://www.npmjs.com/package/human-signals)                                                               | 1.1.1        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [human-signals](https://www.npmjs.com/package/human-signals)                                                               | 2.1.0        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [ieee754](https://www.npmjs.com/package/ieee754)                                                                           | 1.2.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [ignore](https://www.npmjs.com/package/ignore)                                                                             | 5.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [image-webpack-loader](https://www.npmjs.com/package/image-webpack-loader)                                                 | 8.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin-gifsicle](https://www.npmjs.com/package/imagemin-gifsicle)                                                       | 7.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin-mozjpeg](https://www.npmjs.com/package/imagemin-mozjpeg)                                                         | 9.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin-optipng](https://www.npmjs.com/package/imagemin-optipng)                                                         | 8.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin-pngquant](https://www.npmjs.com/package/imagemin-pngquant)                                                       | 9.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin-svgo](https://www.npmjs.com/package/imagemin-svgo)                                                               | 9.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin-webp](https://www.npmjs.com/package/imagemin-webp)                                                               | 7.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [imagemin](https://www.npmjs.com/package/imagemin)                                                                         | 7.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [immer](https://www.npmjs.com/package/immer)                                                                               | 9.0.21       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [immutable](https://www.npmjs.com/package/immutable)                                                                       | 5.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [import-fresh](https://www.npmjs.com/package/import-fresh)                                                                 | 3.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [import-lazy](https://www.npmjs.com/package/import-lazy)                                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [inflight](https://www.npmjs.com/package/inflight)                                                                         | 1.0.6        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [inherits](https://www.npmjs.com/package/inherits)                                                                         | 2.0.4        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [ini](https://www.npmjs.com/package/ini)                                                                                   | 1.3.8        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [into-stream](https://www.npmjs.com/package/into-stream)                                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-arrayish](https://www.npmjs.com/package/is-arrayish)                                                                   | 0.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-core-module](https://www.npmjs.com/package/is-core-module)                                                             | 2.16.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-cwebp-readable](https://www.npmjs.com/package/is-cwebp-readable)                                                       | 3.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [is-extglob](https://www.npmjs.com/package/is-extglob)                                                                     | 2.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-gif](https://www.npmjs.com/package/is-gif)                                                                             | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-glob](https://www.npmjs.com/package/is-glob)                                                                           | 4.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-jpg](https://www.npmjs.com/package/is-jpg)                                                                             | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-natural-number](https://www.npmjs.com/package/is-natural-number)                                                       | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-number](https://www.npmjs.com/package/is-number)                                                                       | 7.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-object](https://www.npmjs.com/package/is-object)                                                                       | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-plain-obj](https://www.npmjs.com/package/is-plain-obj)                                                                 | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-png](https://www.npmjs.com/package/is-png)                                                                             | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-retry-allowed](https://www.npmjs.com/package/is-retry-allowed)                                                         | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-stream](https://www.npmjs.com/package/is-stream)                                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-stream](https://www.npmjs.com/package/is-stream)                                                                       | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [is-svg](https://www.npmjs.com/package/is-svg)                                                                             | 4.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [isarray](https://www.npmjs.com/package/isarray)                                                                           | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [isexe](https://www.npmjs.com/package/isexe)                                                                               | 2.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [isurl](https://www.npmjs.com/package/isurl)                                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [jest-worker](https://www.npmjs.com/package/jest-worker)                                                                   | 27.5.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [jose](https://www.npmjs.com/package/jose)                                                                                 | 4.15.9       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [js-tokens](https://www.npmjs.com/package/js-tokens)                                                                       | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [jsesc](https://www.npmjs.com/package/jsesc)                                                                               | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [json-buffer](https://www.npmjs.com/package/json-buffer)                                                                   | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [json-parse-even-better-errors](https://www.npmjs.com/package/json-parse-even-better-errors)                               | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [json-schema-traverse](https://www.npmjs.com/package/json-schema-traverse)                                                 | 0.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [json-schema-traverse](https://www.npmjs.com/package/json-schema-traverse)                                                 | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [json5](https://www.npmjs.com/package/json5)                                                                               | 2.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [junk](https://www.npmjs.com/package/junk)                                                                                 | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [jwt-decode](https://www.npmjs.com/package/jwt-decode)                                                                     | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [keyv](https://www.npmjs.com/package/keyv)                                                                                 | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lines-and-columns](https://www.npmjs.com/package/lines-and-columns)                                                       | 1.2.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [loader-runner](https://www.npmjs.com/package/loader-runner)                                                               | 4.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [loader-utils](https://www.npmjs.com/package/loader-utils)                                                                 | 2.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lodash-es](https://www.npmjs.com/package/lodash-es)                                                                       | 4.17.21      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lodash.curry](https://www.npmjs.com/package/lodash.curry)                                                                 | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lodash.flow](https://www.npmjs.com/package/lodash.flow)                                                                   | 3.5.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lodash.get](https://www.npmjs.com/package/lodash.get)                                                                     | 4.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lodash.isequal](https://www.npmjs.com/package/lodash.isequal)                                                             | 4.5.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lodash](https://www.npmjs.com/package/lodash)                                                                             | 4.17.21      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [loose-envify](https://www.npmjs.com/package/loose-envify)                                                                 | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lowercase-keys](https://www.npmjs.com/package/lowercase-keys)                                                             | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lowercase-keys](https://www.npmjs.com/package/lowercase-keys)                                                             | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [lru-cache](https://www.npmjs.com/package/lru-cache)                                                                       | 4.1.5        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [magic-string](https://www.npmjs.com/package/magic-string)                                                                 | 0.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [make-dir](https://www.npmjs.com/package/make-dir)                                                                         | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [make-dir](https://www.npmjs.com/package/make-dir)                                                                         | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [mdn-data](https://www.npmjs.com/package/mdn-data)                                                                         | 2.0.14       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                    |
| [mdn-data](https://www.npmjs.com/package/mdn-data)                                                                         | 2.0.28       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                    |
| [mdn-data](https://www.npmjs.com/package/mdn-data)                                                                         | 2.0.30       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                    |
| [memoize-one](https://www.npmjs.com/package/memoize-one)                                                                   | 6.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [merge-stream](https://www.npmjs.com/package/merge-stream)                                                                 | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [merge2](https://www.npmjs.com/package/merge2)                                                                             | 1.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [micromatch](https://www.npmjs.com/package/micromatch)                                                                     | 4.0.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [mime-db](https://www.npmjs.com/package/mime-db)                                                                           | 1.52.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [mime-db](https://www.npmjs.com/package/mime-db)                                                                           | 1.54.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [mime-types](https://www.npmjs.com/package/mime-types)                                                                     | 2.1.35       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [mimic-fn](https://www.npmjs.com/package/mimic-fn)                                                                         | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [mimic-response](https://www.npmjs.com/package/mimic-response)                                                             | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [minimatch](https://www.npmjs.com/package/minimatch)                                                                       | 3.1.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [mozjpeg](https://www.npmjs.com/package/mozjpeg)                                                                           | 7.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ms](https://www.npmjs.com/package/ms)                                                                                     | 2.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [neo-async](https://www.npmjs.com/package/neo-async)                                                                       | 2.6.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [nice-try](https://www.npmjs.com/package/nice-try)                                                                         | 1.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [node-fetch](https://www.npmjs.com/package/node-fetch)                                                                     | 2.7.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [node-releases](https://www.npmjs.com/package/node-releases)                                                               | 2.0.19       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [normalize-path](https://www.npmjs.com/package/normalize-path)                                                             | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [normalize-url](https://www.npmjs.com/package/normalize-url)                                                               | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [normalize.css](https://www.npmjs.com/package/normalize.css)                                                               | 8.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [npm-conf](https://www.npmjs.com/package/npm-conf)                                                                         | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [npm-run-path](https://www.npmjs.com/package/npm-run-path)                                                                 | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [npm-run-path](https://www.npmjs.com/package/npm-run-path)                                                                 | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [nth-check](https://www.npmjs.com/package/nth-check)                                                                       | 2.1.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [object-assign](https://www.npmjs.com/package/object-assign)                                                               | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [oidc-client-ts](https://www.npmjs.com/package/oidc-client-ts)                                                             | 3.2.0        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [oidc-client](https://www.npmjs.com/package/oidc-client)                                                                   | 1.11.5       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [once](https://www.npmjs.com/package/once)                                                                                 | 1.4.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [onetime](https://www.npmjs.com/package/onetime)                                                                           | 5.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [optipng-bin](https://www.npmjs.com/package/optipng-bin)                                                                   | 7.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [os-filter-obj](https://www.npmjs.com/package/os-filter-obj)                                                               | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [ow](https://www.npmjs.com/package/ow)                                                                                     | 0.17.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-cancelable](https://www.npmjs.com/package/p-cancelable)                                                                 | 0.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-cancelable](https://www.npmjs.com/package/p-cancelable)                                                                 | 0.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-event](https://www.npmjs.com/package/p-event)                                                                           | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-event](https://www.npmjs.com/package/p-event)                                                                           | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-finally](https://www.npmjs.com/package/p-finally)                                                                       | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-is-promise](https://www.npmjs.com/package/p-is-promise)                                                                 | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-map-series](https://www.npmjs.com/package/p-map-series)                                                                 | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-pipe](https://www.npmjs.com/package/p-pipe)                                                                             | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-reduce](https://www.npmjs.com/package/p-reduce)                                                                         | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-timeout](https://www.npmjs.com/package/p-timeout)                                                                       | 1.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [p-timeout](https://www.npmjs.com/package/p-timeout)                                                                       | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [parent-module](https://www.npmjs.com/package/parent-module)                                                               | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [parse-json](https://www.npmjs.com/package/parse-json)                                                                     | 5.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [path-is-absolute](https://www.npmjs.com/package/path-is-absolute)                                                         | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [path-key](https://www.npmjs.com/package/path-key)                                                                         | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [path-key](https://www.npmjs.com/package/path-key)                                                                         | 3.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [path-parse](https://www.npmjs.com/package/path-parse)                                                                     | 1.0.7        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [path-type](https://www.npmjs.com/package/path-type)                                                                       | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pend](https://www.npmjs.com/package/pend)                                                                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [picocolors](https://www.npmjs.com/package/picocolors)                                                                     | 1.1.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [picomatch](https://www.npmjs.com/package/picomatch)                                                                       | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pify](https://www.npmjs.com/package/pify)                                                                                 | 2.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pify](https://www.npmjs.com/package/pify)                                                                                 | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pify](https://www.npmjs.com/package/pify)                                                                                 | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pinkie-promise](https://www.npmjs.com/package/pinkie-promise)                                                             | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pinkie](https://www.npmjs.com/package/pinkie)                                                                             | 2.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pngquant-bin](https://www.npmjs.com/package/pngquant-bin)                                                                 | 6.0.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [prepend-http](https://www.npmjs.com/package/prepend-http)                                                                 | 1.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [prepend-http](https://www.npmjs.com/package/prepend-http)                                                                 | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [process-nextick-args](https://www.npmjs.com/package/process-nextick-args)                                                 | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [promise](https://www.npmjs.com/package/promise)                                                                           | 7.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [prop-types](https://www.npmjs.com/package/prop-types)                                                                     | 15.8.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [property-expr](https://www.npmjs.com/package/property-expr)                                                               | 2.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [proto-list](https://www.npmjs.com/package/proto-list)                                                                     | 1.2.4        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [pseudomap](https://www.npmjs.com/package/pseudomap)                                                                       | 1.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [pump](https://www.npmjs.com/package/pump)                                                                                 | 3.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [punycode](https://www.npmjs.com/package/punycode)                                                                         | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [pure-color](https://www.npmjs.com/package/pure-color)                                                                     | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [query-string](https://www.npmjs.com/package/query-string)                                                                 | 5.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [queue-microtask](https://www.npmjs.com/package/queue-microtask)                                                           | 1.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [randombytes](https://www.npmjs.com/package/randombytes)                                                                   | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [rc-pagination](https://www.npmjs.com/package/rc-pagination)                                                               | 5.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [rc-util](https://www.npmjs.com/package/rc-util)                                                                           | 5.44.4       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-ace](https://www.npmjs.com/package/react-ace)                                                                       | 10.1.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-base16-styling](https://www.npmjs.com/package/react-base16-styling)                                                 | 0.6.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-clientside-effect](https://www.npmjs.com/package/react-clientside-effect)                                           | 1.2.7        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-dom](https://www.npmjs.com/package/react-dom)                                                                       | 19.2.4       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-fast-compare](https://www.npmjs.com/package/react-fast-compare)                                                     | 2.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-fast-compare](https://www.npmjs.com/package/react-fast-compare)                                                     | 3.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-focus-lock](https://www.npmjs.com/package/react-focus-lock)                                                         | 2.13.6       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-hook-form](https://www.npmjs.com/package/react-hook-form)                                                           | 7.54.2       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-is](https://www.npmjs.com/package/react-is)                                                                         | 16.13.1      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-is](https://www.npmjs.com/package/react-is)                                                                         | 18.3.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-json-view](https://www.npmjs.com/package/react-json-view)                                                           | 1.21.3       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-lifecycles-compat](https://www.npmjs.com/package/react-lifecycles-compat)                                           | 3.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-oidc-context](https://www.npmjs.com/package/react-oidc-context)                                                     | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-oidc](https://www.npmjs.com/package/react-oidc)                                                                     | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-popper](https://www.npmjs.com/package/react-popper)                                                                 | 2.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-router-dom](https://www.npmjs.com/package/react-router-dom)                                                         | 6.30.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-router](https://www.npmjs.com/package/react-router)                                                                 | 6.30.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-select](https://www.npmjs.com/package/react-select)                                                                 | 5.10.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-tabs](https://www.npmjs.com/package/react-tabs)                                                                     | 6.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-textarea-autosize](https://www.npmjs.com/package/react-textarea-autosize)                                           | 8.5.9        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-toastify](https://www.npmjs.com/package/react-toastify)                                                             | 11.0.5       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [react-transition-group](https://www.npmjs.com/package/react-transition-group)                                             | 4.4.5        | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                     |
| [react](https://www.npmjs.com/package/react)                                                                               | 19.2.4       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [reactstrap](https://www.npmjs.com/package/reactstrap)                                                                     | 9.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [readable-stream](https://www.npmjs.com/package/readable-stream)                                                           | 2.3.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [regenerator-runtime](https://www.npmjs.com/package/regenerator-runtime)                                                   | 0.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [replace-ext](https://www.npmjs.com/package/replace-ext)                                                                   | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [require-from-string](https://www.npmjs.com/package/require-from-string)                                                   | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [resolve-from](https://www.npmjs.com/package/resolve-from)                                                                 | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [resolve](https://www.npmjs.com/package/resolve)                                                                           | 1.22.10      | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [responselike](https://www.npmjs.com/package/responselike)                                                                 | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [reusify](https://www.npmjs.com/package/reusify)                                                                           | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [rimraf](https://www.npmjs.com/package/rimraf)                                                                             | 2.7.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [rollup-plugin-inject](https://www.npmjs.com/package/rollup-plugin-inject)                                                 | 3.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [rollup-plugin-node-polyfills](https://www.npmjs.com/package/rollup-plugin-node-polyfills)                                 | 0.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [rollup-pluginutils](https://www.npmjs.com/package/rollup-pluginutils)                                                     | 2.8.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [run-parallel](https://www.npmjs.com/package/run-parallel)                                                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [rxjs](https://www.npmjs.com/package/rxjs)                                                                                 | 7.8.2        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [safe-buffer](https://www.npmjs.com/package/safe-buffer)                                                                   | 5.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [safe-buffer](https://www.npmjs.com/package/safe-buffer)                                                                   | 5.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sass-embedded-darwin-arm64](https://www.npmjs.com/package/sass-embedded-darwin-arm64)                                     | 1.86.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sass-embedded](https://www.npmjs.com/package/sass-embedded)                                                               | 1.86.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [scheduler](https://www.npmjs.com/package/scheduler)                                                                       | 0.27.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [schema-utils](https://www.npmjs.com/package/schema-utils)                                                                 | 2.7.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [schema-utils](https://www.npmjs.com/package/schema-utils)                                                                 | 4.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [seek-bzip](https://www.npmjs.com/package/seek-bzip)                                                                       | 1.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [semver-regex](https://www.npmjs.com/package/semver-regex)                                                                 | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [semver-truncate](https://www.npmjs.com/package/semver-truncate)                                                           | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [semver](https://www.npmjs.com/package/semver)                                                                             | 5.7.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [semver](https://www.npmjs.com/package/semver)                                                                             | 6.3.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [serialize-javascript](https://www.npmjs.com/package/serialize-javascript)                                                 | 4.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [serialize-javascript](https://www.npmjs.com/package/serialize-javascript)                                                 | 6.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [setimmediate](https://www.npmjs.com/package/setimmediate)                                                                 | 1.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [shebang-command](https://www.npmjs.com/package/shebang-command)                                                           | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [shebang-command](https://www.npmjs.com/package/shebang-command)                                                           | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [shebang-regex](https://www.npmjs.com/package/shebang-regex)                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [shebang-regex](https://www.npmjs.com/package/shebang-regex)                                                               | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [signal-exit](https://www.npmjs.com/package/signal-exit)                                                                   | 3.0.7        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [slash](https://www.npmjs.com/package/slash)                                                                               | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [slash](https://www.npmjs.com/package/slash)                                                                               | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sort-keys-length](https://www.npmjs.com/package/sort-keys-length)                                                         | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sort-keys](https://www.npmjs.com/package/sort-keys)                                                                       | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sort-keys](https://www.npmjs.com/package/sort-keys)                                                                       | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [source-map-js](https://www.npmjs.com/package/source-map-js)                                                               | 1.2.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [source-map-support](https://www.npmjs.com/package/source-map-support)                                                     | 0.5.21       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [source-map](https://www.npmjs.com/package/source-map)                                                                     | 0.5.7        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [source-map](https://www.npmjs.com/package/source-map)                                                                     | 0.6.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [sourcemap-codec](https://www.npmjs.com/package/sourcemap-codec)                                                           | 1.4.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [stable](https://www.npmjs.com/package/stable)                                                                             | 0.1.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [strict-uri-encode](https://www.npmjs.com/package/strict-uri-encode)                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [string\_decoder](https://www.npmjs.com/package/string_decoder)                                                            | 1.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [strip-dirs](https://www.npmjs.com/package/strip-dirs)                                                                     | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [strip-eof](https://www.npmjs.com/package/strip-eof)                                                                       | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [strip-final-newline](https://www.npmjs.com/package/strip-final-newline)                                                   | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [strip-outer](https://www.npmjs.com/package/strip-outer)                                                                   | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [strnum](https://www.npmjs.com/package/strnum)                                                                             | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [stylis](https://www.npmjs.com/package/stylis)                                                                             | 4.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [supports-color](https://www.npmjs.com/package/supports-color)                                                             | 8.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [supports-preserve-symlinks-flag](https://www.npmjs.com/package/supports-preserve-symlinks-flag)                           | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [svgo-loader](https://www.npmjs.com/package/svgo-loader)                                                                   | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [svgo](https://www.npmjs.com/package/svgo)                                                                                 | 2.8.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [svgo](https://www.npmjs.com/package/svgo)                                                                                 | 3.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sync-child-process](https://www.npmjs.com/package/sync-child-process)                                                     | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [sync-message-port](https://www.npmjs.com/package/sync-message-port)                                                       | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tapable](https://www.npmjs.com/package/tapable)                                                                           | 2.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tar-stream](https://www.npmjs.com/package/tar-stream)                                                                     | 1.6.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [temp-dir](https://www.npmjs.com/package/temp-dir)                                                                         | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tempfile](https://www.npmjs.com/package/tempfile)                                                                         | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [terser-webpack-plugin](https://www.npmjs.com/package/terser-webpack-plugin)                                               | 5.3.14       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [terser](https://www.npmjs.com/package/terser)                                                                             | 5.39.0       | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [through](https://www.npmjs.com/package/through)                                                                           | 2.3.8        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [timed-out](https://www.npmjs.com/package/timed-out)                                                                       | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tiny-case](https://www.npmjs.com/package/tiny-case)                                                                       | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tiny-warning](https://www.npmjs.com/package/tiny-warning)                                                                 | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [to-buffer](https://www.npmjs.com/package/to-buffer)                                                                       | 1.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [to-regex-range](https://www.npmjs.com/package/to-regex-range)                                                             | 5.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [toposort](https://www.npmjs.com/package/toposort)                                                                         | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tr46](https://www.npmjs.com/package/tr46)                                                                                 | 0.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [trim-repeated](https://www.npmjs.com/package/trim-repeated)                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [tslib](https://www.npmjs.com/package/tslib)                                                                               | 2.8.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [tunnel-agent](https://www.npmjs.com/package/tunnel-agent)                                                                 | 0.6.0        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [type-fest](https://www.npmjs.com/package/type-fest)                                                                       | 0.11.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [type-fest](https://www.npmjs.com/package/type-fest)                                                                       | 2.19.0       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                    |
| [typescript](https://www.npmjs.com/package/typescript)                                                                     | 2.9.2        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [ua-parser-js](https://www.npmjs.com/package/ua-parser-js)                                                                 | 1.0.40       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [unbzip2-stream](https://www.npmjs.com/package/unbzip2-stream)                                                             | 1.4.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [undici-types](https://www.npmjs.com/package/undici-types)                                                                 | 6.20.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [update-browserslist-db](https://www.npmjs.com/package/update-browserslist-db)                                             | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [uri-js](https://www.npmjs.com/package/uri-js)                                                                             | 4.4.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [url-parse-lax](https://www.npmjs.com/package/url-parse-lax)                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [url-parse-lax](https://www.npmjs.com/package/url-parse-lax)                                                               | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [url-to-options](https://www.npmjs.com/package/url-to-options)                                                             | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-callback-ref](https://www.npmjs.com/package/use-callback-ref)                                                         | 1.3.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-composed-ref](https://www.npmjs.com/package/use-composed-ref)                                                         | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-isomorphic-layout-effect](https://www.npmjs.com/package/use-isomorphic-layout-effect)                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-isomorphic-layout-effect](https://www.npmjs.com/package/use-isomorphic-layout-effect)                                 | 1.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-latest](https://www.npmjs.com/package/use-latest)                                                                     | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-sidecar](https://www.npmjs.com/package/use-sidecar)                                                                   | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [use-sync-external-store](https://www.npmjs.com/package/use-sync-external-store)                                           | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [util-deprecate](https://www.npmjs.com/package/util-deprecate)                                                             | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [uuid](https://www.npmjs.com/package/uuid)                                                                                 | 3.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [varint](https://www.npmjs.com/package/varint)                                                                             | 6.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [warning](https://www.npmjs.com/package/warning)                                                                           | 4.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [watchpack](https://www.npmjs.com/package/watchpack)                                                                       | 2.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [web-vitals](https://www.npmjs.com/package/web-vitals)                                                                     | 2.1.4        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                        |
| [webidl-conversions](https://www.npmjs.com/package/webidl-conversions)                                                     | 3.0.1        | [BSD-2-Clause](https://opensource.org/licenses/BSD-2-Clause)                                                     |
| [webpack-sources](https://www.npmjs.com/package/webpack-sources)                                                           | 3.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [webpack](https://www.npmjs.com/package/webpack)                                                                           | 5.98.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [whatwg-url](https://www.npmjs.com/package/whatwg-url)                                                                     | 5.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [which](https://www.npmjs.com/package/which)                                                                               | 1.3.1        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [which](https://www.npmjs.com/package/which)                                                                               | 2.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [wrappy](https://www.npmjs.com/package/wrappy)                                                                             | 1.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [xtend](https://www.npmjs.com/package/xtend)                                                                               | 4.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [yallist](https://www.npmjs.com/package/yallist)                                                                           | 2.1.2        | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [yaml](https://www.npmjs.com/package/yaml)                                                                                 | 1.10.2       | [ISC](https://opensource.org/licenses/ISC)                                                                       |
| [yauzl](https://www.npmjs.com/package/yauzl)                                                                               | 2.10.0       | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [yup](https://www.npmjs.com/package/yup)                                                                                   | 1.6.1        | [MIT](https://opensource.org/licenses/MIT)                                                                       |
| [zustand](https://www.npmjs.com/package/zustand)                                                                           | 4.5.6        | [MIT](https://opensource.org/licenses/MIT)                                                                       |


# Version 1.11


# Getting Started

This section covers the Canton Network integration of CatalyX Blockchain Manager (CAT-BM).

The Canton integration of CatalyX Blockchain Manager enables organisations to deploy, manage, and scale Canton Network infrastructure, validator nodes, and synchronizers as a turnkey, enterprise-grade platform. CAT-BM is a Kubernetes-native solution that provides high availability, enterprise security, GitOps-driven operations, and full lifecycle automation for Canton components.

\
IntellectEU has been providing node infrastructure on Canton since the public network's inception in July 2024, currently operating 2 Supervalidators (including the GSF multi-tenant Supervalidator) and approximately 15% of the network's Validators. IntellectEU sits on the Global Synchronizer Foundation Board and on its Technical, Legal, and Tokenomics Committees.

## Documentation Overview

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-hexagon-nodes">:hexagon-nodes:</i></td><td><strong>Introduction to Canton Network</strong></td><td>Learn more about Canton Network.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/introduction-to-canton-network">Introduction to Canton Network</a></td></tr><tr><td><i class="fa-circle-arrow-down">:circle-arrow-down:</i></td><td><strong>Installation Instructions</strong></td><td>Set up and installations instructions.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton">Installation Instructions</a></td></tr><tr><td><i class="fa-desktop-arrow-down">:desktop-arrow-down:</i></td><td><strong>Network &#x26; Node Management</strong></td><td>Domain and node management.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management">Network &amp; Node Management</a></td></tr><tr><td><i class="fa-tachograph-digital">:tachograph-digital:</i></td><td><strong>Validator Management</strong></td><td>Core functionality and validator operations.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/validator-management">Validator Management</a></td></tr><tr><td><i class="fa-gear-complex-code">:gear-complex-code:</i></td><td><strong>Technical Documentation</strong></td><td>Architecture and system design overview.</td><td></td></tr><tr><td><i class="fa-memo">:memo:</i></td><td><strong>Release Notes</strong></td><td>Latest product updates and release notes.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/release-notes">Release Notes</a></td></tr><tr><td><i class="fa-square-info">:square-info:</i></td><td><strong>Support &#x26; Resources</strong></td><td>Additional support and resources.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources">Support &amp; Resources</a></td></tr><tr><td><i class="fa-comments-question">:comments-question:</i></td><td><strong>FAQ</strong></td><td>Frequently Asked Questions.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/faq">FAQ</a></td></tr><tr><td><i class="fa-gear-complex-api">:gear-complex-api:</i></td><td><strong>API Reference</strong></td><td>API endpoint URLs per environment.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/api-reference">API Reference</a></td></tr><tr><td><i class="fa-creative-commons-share">:creative-commons-share:</i></td><td><strong>Open Source Licenses</strong></td><td>Licenses used for the CAT-BM platform.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses">Open Source Licenses</a></td></tr></tbody></table>

***


# Introduction to Canton Network

This section covers the introduction to the Canton Network, including its core components, architecture, and key concepts relevant to operating nodes with CatalyX Blockchain Manager.

## Canton Network Overview

The [Canton Network](https://www.canton.network/) is the first privacy-enabled interoperable blockchain network, designed for regulated, real-world assets. Blockchain applications in the Canton Network can use the Global Synchronizer to enable atomic transactions across sovereign blockchains, without sacrificing privacy or control.

The Canton network is composed of nodes known as **Validators** that achieve consensus through **Synchronizers**. Validator nodes are responsible for storing contract data and executing smart contract code. The synchronizers, in turn, distribute encrypted messages and facilitate transaction coordination.

Transaction data is only distributed on a **need-to-know basis** to maintain confidentiality. This is the key delta to other chains: In most other chains, all state and transactions get replicated to all nodes/validators. In Canton, state and transactions get distributed only to nodes/validators that are specified in the smart contracts.

## Core Components of the Canton Network

<details>

<summary>The Global Synchronizer</summary>

The [Global Synchronizer](https://www.canton.network/global-synchronizer) is a decentralized and transparently governed interoperability service for the Canton Network.

The Global Synchronizer is a decentrally operated service, using a 2/3 majority Byzantine Fault Tolerant ([BFT](https://docs.sync.global/glossary.html#term-BFT)) consensus protocol for message ordering and confirmation, and BFT majority voting on governance changes.

Its infrastructure is operated by independently acting organizations, called Super Validators, that run components of the decentralized infrastructure, and coordinate activities via an on-chain governance application. Its open source code is maintained in [Splice](https://github.com/hyperledger-labs/splice).

The [Global Synchronizer Foundation (“GSF”)](https://sync.global/) has been created in partnership with the Linux Foundation to coordinate the governance of the Global Synchronizer and lead efforts to grow the Global Synchronizer ecosystem. The GSF provides transparency into Super Validator governance and operations. The GSF also operates a Super Validator node, and takes part in governance votes on behalf of its members.

</details>

<details>

<summary>Synchronizers (previously Domains)</summary>

Canton is a network composed of multiple [synchronizers](https://docs.digitalasset.com/overview/3.4/explanations/canton/synchronizers.html), each operating under its own rules, governance, and set of participants. Each synchronizer functions as an independent sub-network that participates in the wider Canton Network.

In a composed solution, each synchronizer is a sub-network. A [Validator Node](https://docs.sync.global/validator_operator/index.html) (previously Participant nodes) connects to one or more synchronizers, enabling transactions that span domains.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-7d8fd36a0df45341369bd440cbcb87cf0d66f11e%2Fimage%20(16).png?alt=media" alt=""><figcaption></figcaption></figure>

A Canton Domain consists of three entities: Sequencers, Mediators, and a Topology Manager. These are collectively called the **domain entities**.

![Canton Domain Entities Diagram](https://docs.daml.com/_images/canton-domain-diagram.svg)

In general, every domain entity can run in a separate trust domain (i.e., can be operated by an independent organization). In practice, all domain entities are typically run by a single organization. Each participant node runs in its own trust domain.

The generic term **member** refers to either a domain entity or a participant node.

</details>

<details>

<summary>Super Validators</summary>

[Super Validators](https://www.canton.network/blog/what-is-a-validator-on-the-canton-network) form the backbone of the [Global Synchronizer](https://www.canton.network/global-synchronizer)’s decentralized interoperability and synchronization infrastructure. They ensure the integrity, security, and operational reliability of the Global Synchronizer by:

* Running the core infrastructure of the Global Synchronizer
* Sequencing transactions across the network
* Validating Canton Coin transactions
* Participating in network governance and decision-making

</details>

<details>

<summary>Validators (previously Participants)</summary>

[Validators](https://docs.sync.global/validator_operator/index.html) work within the broader Canton Network—a “network of networks” where each node stores only the data it needs, and interacts with other Validators via [synchronizers](https://docs.digitalasset.com/overview/3.4/explanations/canton/synchronizers.html). Validators typically connect to one or more synchronizers (which might be run as centralized or decentralized services) to receive and confirm encrypted messages.

The primary roles of a Validator in the Global Synchronizer ecosystem are to:

* Validate transactions
* Record activity
* Facilitate network connectivity for users and applications
* Coordinate upgrades and migrations

</details>

<details>

<summary>Parties</summary>

In Canton, [parties](https://docs.digitalasset.com/integrate/devnet/canton-network-overview/index.html#parties) are the core on-ledger identities, and are the wallet addresses, similar to an address or Externally Owned Account (EOA) on other blockchains. They are central to how permissions and privacy are managed within the network.

Parties come in two forms, internal and external. An [internal party](https://docs.digitalasset.com/overview/3.4/explanations/canton/external-party.html) is created on the validator node, it gives a validator node submission rights and therefore holds its key on the validator node. Transactions are signed using the Validators own internal keys for signing (and thereby the validator operator has full control of everything that happens on the party).

[External parties](https://docs.digitalasset.com/overview/3.4/explanations/canton/external-party.html) are similar to how node interactions happens on other networks and therefore Externally Owned Accounts. In this case the signing key can be held externally and a signature is required alongside the transaction to authorize the action.

</details>

<details>

<summary>Canton Coin</summary>

Canton Network’s native token, [Canton Coin](https://www.digitalasset.com/hubfs/Canton%20Network%20Files/Documents%20\(whitepapers%2c%20etc...\)/Canton%20Coin_%20A%20Canton-Network-native%20payment%20application.pdf), is a utility token launched as part of the Global Synchronizer. It facilitate the transfer of value, provide incentives, and serve as payment for infrastructure costs.

The Canton Coin application employs a burn-mint equilibrium mechanism, aiming to stabilize the conversion rate of Canton Coin around the intrinsic value it provides to network users:

* Fee Burning: Users pay fees (denominated in USD but paid by burning Canton Coin) when they initiate Canton Coin transfers or when they create a traffic balance. Instead of paying these fees to a central authority, the coins are burned—i.e., removed from circulation.
* Minting Rewards: Validators (as well as Super Validators and application providers) can mint new Canton Coins in return for their “utility” contributions:
  * Infrastructure Operation: Super Validators operating synchronizer nodes earn minting rights by contributing to the synchronization service.
  * Application Services: Application providers can earn rewards any time they facilitate a transaction.
  * Usage: When a Validator uses the network, that Validator earns “minting rights” proportional to the fees they burn, which the network treats as a proxy for the activity generated by that node.
  * Liveness Incentives: Validators are rewarded for uptime and for being ready to serve transaction traffic. If a Validator does not use all its minting allowance via direct activity, a portion is allocated as a “liveness” bonus.
* Dynamic Equilibrium: The system is designed so that, over the long term, the total amount of coins burned (which reflects actual network utility) roughly balances the coins minted (subject to a predetermined maximum allowed minting curve). When usage is high, more coins are burned, tending to increase the token’s conversion rate; when usage is lower, supply increases until balance is restored.

</details>

Please refer to [Digital Assets' documentation](https://docs.digitalasset.com/overview/3.5/overview/index.html) to learn more about the core elements of the Canton Network.

***

## Concepts & Glossary

This section defines the key business and technical terms used throughout the CatalyX Blockchain Manager and Canton integration. Use it as the first reference when encountering unfamiliar terminology.

<details>

<summary>Business Concepts</summary>

| **Term**                        | **Definition**                                                                                                                                         |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Canton Network**              | A privacy-first blockchain network built on Daml, designed for regulated financial applications.                                                       |
| **Participant**                 | An organisation connected to the Canton network that can host parties and submit transactions.                                                         |
| **Domain**                      | The synchronisation layer of Canton — mediates transactions between participants.                                                                      |
| **Sync Domain**                 | Coordinates transaction sequencing. A **Private Sync Domain** is isolated within an organisation; the **Global Sync Domain** is publicly reachable.    |
| **Party**                       | A logical entity within Canton that can own contracts and be a signatory or observer.                                                                  |
| **DAR file**                    | Daml Archive — a compiled package of Daml smart contract code, uploaded to a participant.                                                              |
| **Validator**                   | A Canton node that validates and sequences transactions. A **Bridge Validator** is connected to both a private sync domain and the global sync domain. |
| **Super Validator**             | A special Canton participant node that participates in network governance, permissioning, and topology management on the global sync domain.           |
| **Splice**                      | The open-source governance and reward infrastructure for the Canton Network.                                                                           |
| **CatalyX**                     | IntellectEU's suite of blockchain infrastructure products built on Canton and other protocols.                                                         |
| **CAT-BM**                      | CatalyX Blockchain Manager, IntellectEU’s platform for deploying and operating Canton and other DLT infrastructure.                                    |
| **CPM**                         | CatalyX Package Manager, the application registry ("Canton App Store") for discovering, publishing, and downloading Canton applications.               |
| **GSF /** **Canton Foundation** | Global Synchronizer Foundation that governs the Global Sync Domain on Canton.                                                                          |

</details>

<details>

<summary>Technical Concepts</summary>

| **Term**                             | **Definition**                                                                                                   |
| ------------------------------------ | ---------------------------------------------------------------------------------------------------------------- |
| **Ledger API**                       | The gRPC API exposed by Canton participant nodes for submitting and reading transactions.                        |
| **Admin API**                        | The API for managing participant configuration, parties, and packages.                                           |
| **Topology**                         | The configuration of domains, participants, and their relationships on the network.                              |
| **PQS (Participant Query Store)**    | A queryable off-ledger store for Canton contract data.                                                           |
| **KMS driver**                       | Canton integration module that delegates key operations to external KMS/HSM (AWS KMS, GCP KMS, HashiCorp Vault). |
| **WaaS**                             | Wallet-as-a-Service (e.g. Dfns), external key custody and signing service supported by CAT-BM.                   |
| **ArgoCD**                           | GitOps continuous-delivery tool used to synchronise desired state from Git into the Kubernetes cluster.          |
| **Helm chart**                       | Kubernetes packaging format used to deploy Canton components.                                                    |
| **CRD (Custom Resource Definition)** | Kubernetes extension used by the CAT-BM Canton Operator to manage node lifecycle.                                |
| **CAT-BM Canton Operator**           | Custom Kubernetes Operator that watches CRDs and reconciles Canton component state.                              |
| **Round**                            | 10-minute cycle on Canton Network governing minting and distribution of Canton Coins.                            |

</details>

***

## Learn more about Canton Network <a href="#learn-more-about-canton" id="learn-more-about-canton"></a>

| **Resource**                                                                                                    | **Purpose**                                              |
| --------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
| [Canton Network](https://canton.network/)                                                                       | Official Canton Network site                             |
| [Canton Network Whitepaper](https://www.digitalasset.com/hubfs/Canton/Canton%20Network%20-%20White%20Paper.pdf) | Official Canton Network Whitepaper                       |
| [Global Synchronizer Foundation](https://sync.global/)                                                          | GSF governance, committees, and network information      |
| [Digital Asset docs](https://docs.digitalasset.com/)                                                            | Canton / Daml technical documentation from Digital Asset |
| [Daml documentation](https://docs.daml.com/)                                                                    | Daml language and SDK reference                          |
| [Splice on GitHub](https://github.com/hyperledger-labs/splice)                                                  | Open-source Splice repository                            |
| [CIPs](https://github.com/canton-foundation/cips)                                                               | Canton Improvement Proposals                             |

***


# Installation Instructions

This section provides an overview of the steps necessary to launch CAT-BM for the Canton Network.

## Installation Instructions Overview

{% stepper %}
{% step %}
**Prerequisites**

{% content-ref url="/pages/yhlhY7K0tXIMkZgEdUvU" %}
[Prerequisites](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/prerequisites)
{% endcontent-ref %}
{% endstep %}

{% step %}
**Setup**

{% content-ref url="/pages/G7ey5zeAvPIAdBfWtOZ6" %}
[Setup](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/set-up)
{% endcontent-ref %}
{% endstep %}

{% step %}
**CAT-BM Canton Service Installation**

{% content-ref url="/pages/McIbiyvFWD8xpqCFdphN" %}
[CAT-BM Canton Service Installation](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/cat-bm-canton-service-installation)
{% endcontent-ref %}
{% endstep %}

{% step %}
**External Identity Provider Configuration (optional)**

{% content-ref url="/pages/u0ylfiYfGRM6KXWYoz7z" %}
[External Identity Provider Configuration (optional)](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/external-identity-provider-configuration-optional)
{% endcontent-ref %}
{% endstep %}
{% endstepper %}


# Prerequisites

System, infrastructure, and access requirements to prepare for a CatalyX Blockchain Manager installation on Canton Network.

{% stepper %}
{% step %}
**Setup Kubernetes or OpenShift cluster**

{% hint style="info" %}
Supported version of **Kubernetes**: 1.21 and later.\
\
We recommend AWS (EKS) or Google Cloud (GKE), but you can install it on a standalone cluster as well.
{% endhint %}

**Define your cluster size considering the following minimum requirements and your business needs:**<br>

1. Minimal requirements for the Catalyst Blockchain Manager Canton service for 1 instance with:<br>

* 2 core CPU
* 4GB RAM
* 10GB disk space<br>

2. Each node (Domain, participant, or application) that will be deployed consumes additional resources. Minimal requirements for one node:

| Node        | CPUe | Memory, Gi | Storage, Gi |
| ----------- | ---- | ---------- | ----------- |
| Domain      | 1    | 1          | 1           |
| Participant | 1    | 1          | 1           |
| Application | 1    | 1          | 1           |

{% hint style="info" %}
Deciding on the size of the cluster, please consider the expected load of the nodes and increase these values accordingly.
{% endhint %}
{% endstep %}

{% step %}
**Install Helm to your workstation**

Helm can be installed either from source, or from pre-built binary releases.

**Follow the installation manual below:**

{% embed url="<https://helm.sh/docs/intro/install/>" %}

{% hint style="info" %}
Supported version of **Helm**: 3.X.\
\
No customisation is needed.
{% endhint %}
{% endstep %}

{% step %}
**Install Traefik ingress**

The ingress-controller is needed for traffic routing to expose nodes (domains & applications).\
\
The Catalyst Blockchain Manager Canton service creates a CRD resource (IngressRoute in case of using Traefik), that is automatically started and deleted along with each application (and on demand for domains).

**Follow the installation manual below:**

{% embed url="<https://github.com/traefik/traefik-helm-chart>" %}

{% hint style="info" %}
Supported version of **Traefik**: 2.3.<br>

No customisation is needed, the default port ( :443 ) for HTTPS traffic will be used.<br>

We recommend installing Traefik to a separate namespace from the application (creation of a namespace for the CatalyX Blockchain Manager Canton service is described in step 6).
{% endhint %}
{% endstep %}

{% step %}
**Install cert-manager to create TLS certificate**

TLS certificate is needed for secured communication between a User and the СatalyX Blockchain Manager Canton service components.

**Follow the installation manual below:**

{% embed url="<https://cert-manager.io/docs/installation/helm/>" %}

We recommend using the last release of the official helm chart.

{% hint style="info" %}
You can skip this step and specify your TLS certificate and key as a Kubernetes secret in Helm chart values instead later (Helm chart values are described in the Setup section).\
You can find the manual on how to create a Kubernetes secret here:

[kubernetes.io/docs/concepts/configuration/secret/#tls-secrets](https://kubernetes.io/docs/concepts/configuration/secret/#tls-secrets)
{% endhint %}
{% endstep %}

{% step %}
**Create an A-record in a zone in your domain’s DNS management panel and assign it to the load balancer created upon Traefik or OpenShift installation**

CatalyX Blockchain Manager Canton service needs a wildcard record *`*.<domain>`* to expose nodes. All created nodes (domains, participants, applications) will have a *`<NodeName>.<domainName>`* address.

**For example, in case you are using AWS, follow these steps:**

1. Go to the Route53 service.
2. Create a new domain or choose the existing domain.
3. Create an A record.
4. Switch “alias” to ON.
5. In the “Route traffic to” field select “Alias to application and classic load balancer.”
6. Select your region (where the cluster is installed).
7. Select an ELB balancer from the drop-down list.\*

{% hint style="warning" %}
Choose the ELB balancer, which was automatically configured upon the Traefik chart installation as described in step 3 (or upon OpenShift installation in case of using OpenShift).\
You can check the ELB by the following command:

```bash
kubectl get svc -n ${ingress-namespace}
```

* where:
  * *`${ingress-namespace}`* is the name of the namespace, where the ingress was installed.
  * ELB is displayed in the *`EXTERNAL-IP`* field.
    {% endhint %}
    {% endstep %}

{% step %}
**Create a namespace for the CatalyX Blockchain Manager Canton service application**

```bash
kubectl create ns ${ns_name}
```

where *`${ns_name}`* — name of namespace (can be any).
{% endstep %}

{% step %}
**Get the credentials to the Helm repository in the JFrog artifactory provided by the IntellectEU admin team**

Add the repo to Helm with the username and password provided:

```bash
helm repo add catbp <https://intellecteu.jfrog.io/artifactory/catbp-helm> --username ${ARTIFACTORY_USERNAME} --password ${ARTIFACTORY_PASSWORD}
```

As a result: *`"catbp" has been added to your repositories`*
{% endstep %}

{% step %}
**Create an ImagePullSecret to access the Catalyst Blockchain Manager Canton service deployable images**

For example, create this Secret, naming it *`intellecteu-jfrog-access:`*

```bash
kubectl create secret intellecteu-jfrog-access regcred --docker-server=intellecteu-catbp-docker.jfrog.io --docker-username=${your-name} --docker-password=${your-password} --docker-email=${your-email} -n ${ns_name}
```

where:

* `${your-name}+` — your Docker username.
* `${your-password}` — your Docker password.
* `${your-email}` — your Docker email.
* `${ns_name}` — the namespace created for the Catalyst Blockchain Manager Canton service on the previous step.

{% hint style="warning" %}
In case you want to use a readiness check and use a private repository for the image, you should create a “secret” file with your credentials in Kubernetes for further specifying it in the Helm chart upon Catalyst Blockchain Manager installation.\
\
Please refer to the official Kubernetes documentation: [kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/](https://kubernetes.io/docs/tasks/configure-pod-container/pull-image-private-registry/)\
\
Helm chart configuration instructions you will find [here.](#helmChartVals)
{% endhint %}
{% endstep %}

{% step %}
**Setup Keycloak realm or Auth0 tenant**

**For Keycloak**

Download [the realm.json](https://docs.catalyx.solutions/canton/_attachments/realm-v1.8.json) file and import it to create necessary clients, scopes & users in your keycloak realm.

{% hint style="info" %}
User roles `canton_viewer` & `canton_writer` will be evaluated by the Catalyst Blockchain Manager Canton service
{% endhint %}

{% hint style="info" %}
After creating realm, set url and realm name in [helm values.](#helmChartVals)
{% endhint %}

#### Role-Based Access Control (RBAC)

{% hint style="info" %}
Console UI enforcement of these roles was added in **v1.11.15**. In earlier versions the roles existed on the backend but the Console UI did not adapt to them.
{% endhint %}

Two roles are supported:

* **`canton_viewer`** — can view all resources (domains, participants, applications, validators), but cannot create, edit, or delete anything.
* **`canton_writer`** — can create, edit, and delete any resource, in addition to viewing.

Enforcement is gated by the `AUTH_ROLES` flag, which must be set **consistently on both the API and the UI**:

{% code title="helm-values.yaml" %}

```yaml
api:
  extraEnv:
    AUTH_ROLES: "true"

ui:
  extraEnv:
    AUTH_ROLES: "true"
```

{% endcode %}

{% hint style="warning" %}
If `AUTH_ROLES` differs between the `api` and `ui` sections, a viewer can end up seeing create/edit/delete controls that the backend then rejects with HTTP 403 — the API is the source of truth for enforcement, but the UI must match it to hide those controls in the first place. Set the same value in both places.
{% endhint %}

**For Keycloak Auth0 tenant**

If you want to enable Auth0 as an option for ledger authentication, set up a tenant.

{% hint style="info" %}
After creating tenant, make sure set 'enabled', domain, api id, client id and client secret in [helm values.](#helmChartVals)
{% endhint %}
{% endstep %}

{% step %}
**(Optional) Setup Monitoring & Dashboard**

The installation of the CatalyX Blockchain Manager Canton service includes templates to assist monitoring. If you use Graphana, to observe the metrics of all nodes, install the [kube-prometheus-stack](https://github.com/prometheus-community/helm-charts/tree/main/charts/kube-prometheus-stack) on your cluster.

Once installed, configure Keycloak OAuth2 authentication on Grafana following the detailed steps provided in the [Grafana documentation](https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/keycloak/)

[This file](https://docs.catalyx.solutions/canton/_attachments/dashboard-v1.5.json) is a default dashboard that can be [imported in Grafana](https://grafana.com/docs/grafana/latest/dashboards/build-dashboards/import-dashboards/).

{% hint style="info" %}
After configuring Grafana, make sure set 'url' & 'clusterDashboard' in the Grafana section in [helm values.](#helmChartVals)
{% endhint %}
{% endstep %}

{% step %}
**Enter License Key**

Request a license key and set it in [helm values.](#helmChartVals)
{% endstep %}
{% endstepper %}


# Setup

Full Helm chart values reference for configuring the CatalyX Blockchain Manager Canton service prior to installation.

Before installing the CatalyX Blockchain Manager Canton Service, you must configure the Helm chart values file. This page documents every available configuration option and explains how to prepare your `values.yaml` file for deployment.

{% hint style="info" %}
You will need values from the previous steps, including your domain name, identity provider credentials, JFrog credentials, and license key, before filling in this file.
{% endhint %}

### Required Configuration

At a minimum, the following fields must be set before installation:

| Field                       | Description                                                                                                               |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------- |
| `domainName`                | The domain where CAT-BM will be hosted (wildcard DNS must be configured).                                                 |
| `auth.keycloakUrl`          | The base URL of your Keycloak instance. **Only required when using integrated Keycloak** (`auth.keycloak.enabled: true`). |
| `auth.keycloakRealm`        | The name of the Keycloak realm created in the prerequisites step. **Only required when using integrated Keycloak.**       |
| `api.licenseKey.key`        | Your CAT-BM license key (or configure via Kubernetes secret — see below).                                                 |
| `api.imagePullSecrets`      | The name of the `ImagePullSecret` created in the prerequisites step.                                                      |
| `operator.imagePullSecrets` | Same `ImagePullSecret` for the operator component.                                                                        |

{% hint style="info" %}
If you are using an external Identity Provider (Okta, Microsoft Entra ID, Auth0, or other OIDC-compatible provider) instead of integrated Keycloak, set `auth.keycloak.enabled: false` and configure `auth.url`, `auth.client.idApiOperator`, `auth.client.idUI`, and `auth.client.secret` instead. See the [External Identity Provider Configuration](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/external-identity-provider-configuration-optional) page for full setup instructions.
{% endhint %}

### Configure helm chart values

```yaml
# -- address where application will be hosted.
domainName: ""

auth:
  enabled: true
  ## -- Keycloak is enabled by default. Set keycloakUrl and keycloakRealm when using integrated Keycloak.
  ## -- To use an external IdP (Okta, Entra ID, Auth0, etc.), set keycloak.enabled=false and configure auth.url and auth.client below instead.
  keycloak:
    enabled: true
  keycloakUrl: ""
  keycloakRealm: ""
  ## -- Configure values below when keycloak.enabled=false (external IdP)
  ## -- OpenID provider endpoint for obtaining an access token
  url: ""
  ## - OpenID client IDs and secret
  client:
    idApiOperator: "" # client_id for api and operator components
    idUI: "" #client_id for ui component
    secret: ""
    externalSecret:
      enabled: false # If enabled, will be used instead of 'secret' field
      remoteSecretRef: "" # Name of the remote secret
      secretStoreRef:
        name: "" # SecretStore Name
        kind: "SecretStore" # Type of SecretStore ("SecretStore" or "ClusterSecretStore")

rbac:
  # -- Whether to create RBAC Resourses (Role, SA, RoleBinding)
  enabled: true
  # -- Service Account Name to use for api, ui, operator
  serviceAccountName: canton-console
  # -- Automount API credentials for a Service Account.
  automountServiceAccountToken: false
# operator component values
operator:
  # -- number of operator pods to run
  replicaCount: 1
  # -- operator image settings
  image:
    repository: intellecteu-catbp-docker.jfrog.io/catbp/canton/canton-operator
    pullPolicy: IfNotPresent
    # defaults to appVersion
    tag: ""
  # -- operator image pull secrets
  imagePullSecrets: []
  #   - name: ""

  # -- extra env variables for operator pods
  extraEnv: {}
  # -- labels for operator pods
  labels: {}
  # -- annotations for operator pods
  podAnnotations: {}
  # -- Automount API credentials for a Service Account.
  automountServiceAccountToken: true
  # -- security context on a pod level
  podSecurityContext:
    # runAsNonRoot: true
    # runAsUser: 4444
    # runAsGroup: 5555
    # fsGroup: 4444
  # -- security context on a container level
  securityContext: {}
  # Define update strategy for Operator pods
  updateStrategy: {}
  # -- CPU and Memory requests and limits
  # TO TEST
  resources: {}
    # requests:
    #   cpu: "200m"
    #   memory: "500Mi"
    # limits:
    #   cpu: "500m"
    #   memory: "700Mi"
  # -- Specify Node Labels to place operator pods on
  nodeSelector: {}
  # -- https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/
  tolerations: []
  # -- https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
  affinity: {}
  # -- keycloak client secret is used to get token from keycloak
  # -- Can be fetched from ExternalSecret or provided directly in the 'secret' field
  keycloakClient:
    secret: "" # Keycloak client secret
    externalSecret:
      enabled: false # If enabled, will be used instead of 'secret' field
      remoteSecretRef: "" # Name of the remote secret
      secretStoreRef:
        name: "" # SecretStore Name
        kind: "SecretStore" # Type of SecretStore ("SecretStore" or "ClusterSecretStore")
  ## Readiness and Liveness probes for Operator component
  ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/
  probes:
    # -- Enable Kubernetes Liveness and Readiness probes
    enabled: true
    # --  Liveness probe for Operator container
    livenessProbe:
      # -- Number of seconds after the container has started before probe is initiated
      initialDelaySeconds: 60
      # -- How often (in seconds) to perform the probe
      periodSeconds: 10
      # -- Number of seconds after which the probe times out
      timeoutSeconds: 1
      # -- Minimum consecutive successes for the probe to be considered successful after having failed
      successThreshold: 1
      # -- Minimum consecutive failures for the probe to be considered failed after having succeeded
      failureThreshold: 3
    # --  Readiness probe for Operator container
    readinessProbe:
      # -- Number of seconds after the container has started before probe is initiated
      initialDelaySeconds: 40
      # -- How often (in seconds) to perform the probe
      periodSeconds: 10
      # -- Number of seconds after which the probe times out
      timeoutSeconds: 1
      # -- Minimum consecutive successes for the probe to be considered successful after having failed
      successThreshold: 1
      # -- Minimum consecutive failures for the probe to be considered failed after having succeeded
      failureThreshold: 5

# API component values
api:
  # -- the persistence volume claim for DARs
  darsPvc:
    enabled: true
    size: 5Gi
    mountPath: /dars-storage
    # If defined, storageClassName: <storageClass>
    # If undefined, no storageClassName spec is set, choosing the default provisioner.  (gp2 on AWS, standard on GKE, AWS & OpenStack)
    storageClass: ""
    # Annotations for darsPvc
    # Example:
    # annotations:
    #   example.io/disk-volume-type: SSD
    annotations: {}
  # -- environment for api pods
  environment: "dev"
  # -- gateway configuration for channel subscription gateway
  gateway:
    events:
      heartbeat:
        enabled: false
        interval: 60 # interval in seconds
  # -- number of api pods to run
  replicaCount: 1
  # -- api image settings
  image:
    repository: intellecteu-catbp-docker.jfrog.io/catbp/canton/canton-console
    pullPolicy: IfNotPresent
    # defaults to appVersion
    tag: ""
  # -- api image pull secrets
  imagePullSecrets: []
  #   - name: ""

  # -- extra env variables for api pods
  extraEnv: {}
  # -- labels for api pods
  labels: {}
  # -- api service port and name
  service:
    port: 8080
    portName: http
  # -- annotations for api pods
  podAnnotations: {}
  # -- Automount API credentials for a Service Account.
  automountServiceAccountToken: true
  # -- securtiry context on a pod level
  podSecurityContext:
    # runAsNonRoot: true
    # runAsUser: 4444
    # runAsGroup: 5555
    # fsGroup: 4444
  # -- security context on a container level
  securityContext: {}
  # Define update strategy for API pods
  updateStrategy: {}
    # type: RollingUpdate
    # rollingUpdate:
    #   maxUnavailable: 0
    #   maxSurge: 1
  # -- CPU and Memory requests and limits
  # TO TEST
  resources: {}
    # requests:
    #   cpu: "200m"
    #   memory: "900Mi"
    # limits:
    #   cpu: "500m"
    #   memory: "1000Mi"
  # -- Specify Node Labels to place api pods on
  nodeSelector: {}
  # -- https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/
  tolerations: []
  # -- https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
  affinity: {}
  # -- keycloak client secret is used to get token from keycloak
  # -- Can be fetched from ExternalSecret or provided directly in the 'secret' field
  keycloakClient:
    secret: "" # Keycloak client secret
    externalSecret:
      enabled: false # If enabled, will be used instead of 'secret' field
      remoteSecretRef: "" # Name of the external secret
      secretStoreRef:
        name: "" # SecretStore Name
        kind: "SecretStore" # Type of SecretStore ("SecretStore" or "ClusterSecretStore")
  ## Readiness and Liveness probes for API component
  ## Ref: https://kubernetes.io/docs/tasks/configure-pod-container/configure-liveness-readiness-probes/
  probes:
    # -- Enable Kubernetes Liveness and Readiness probes
    enabled: true
    # --  Liveness probe for API container
    livenessProbe:
      # -- Number of seconds after the container has started before probe is initiated
      initialDelaySeconds: 90
      # -- How often (in seconds) to perform the probe
      periodSeconds: 10
      # -- Number of seconds after which the probe times out
      timeoutSeconds: 3
      # -- Minimum consecutive successes for the probe to be considered successful after having failed
      successThreshold: 1
      # -- Minimum consecutive failures for the probe to be considered failed after having succeeded
      failureThreshold: 3
    # --  Readiness probe for API container
    readinessProbe:
      # -- Number of seconds after the container has started before probe is initiated
      initialDelaySeconds: 60
      # -- How often (in seconds) to perform the probe
      periodSeconds: 10
      # -- Number of seconds after which the probe times out
      timeoutSeconds: 10
      # -- Minimum consecutive successes for the probe to be considered successful after having failed
      successThreshold: 1
      # -- Minimum consecutive failures for the probe to be considered failed after having succeeded
      failureThreshold: 5
  # -- License Key for canton console
  licenseKey:
    key: ""  # Set licenseKey if NOT using a Kubernetes secret
    secret:
      enabled: false  # Set to 'true' to use a Kubernetes Secret
      name: ""        # Name of the Kubernetes secret
      key: ""         # Key inside the secret that contains licenseKey
  # -- Auth providers configuration for ledger
  ledgerAuth:
    auth0:
      enabled: false
      domain: ""
      apiIdentifier: ""
      clientId: ""
      clientSecret: ""
# UI component values
ui:
  # -- gateway configuration for channel subscription gateway
  gateway:
    events:
      heartbeat:
        enabled: false
        interval: 60 # interval in seconds
  # -- ui autoscaling settings
  autoscaling:
    enabled: false
    minReplicas: 1
    maxReplicas: 5
    targetCPUUtilizationPercentage: 80
    # targetMemoryUtilizationPercentage: 80
  # -- number of ui pods to run
  replicaCount: 1
  # -- api image settings
  image:
    repository: intellecteu-catbp-docker.jfrog.io/catbp/canton/canton-console-ui
    pullPolicy: IfNotPresent
    # defaults to appVersion
    tag: ""
  # -- api image pull secrets
  imagePullSecrets: []
  #   - name: ""

  # -- extra env variables for ui pods
  extraEnv: {}
  # -- labels for ui pods
  labels: {}
  # -- api service port and name
  service:
    port: 80
    portName: http
  # -- annotations for api pods
  podAnnotations: {}
  # -- Automount API credentials for a Service Account.
  automountServiceAccountToken: true
  # -- securtiry context on a pod level
  podSecurityContext:
  #   runAsNonRoot: true
  #   runAsUser: 4444
  #   runAsGroup: 5555
  #   fsGroup: 4444
  # -- security context on a container level
  securityContext: {}
  # Define update strategy for UI pods
  updateStrategy: {}
  # -- CPU and Memory requests and limits
  # TO TEST
  resources: {}
  #   requests:
  #     cpu: "100m"
  #     memory: "50Mi"
  #   limits:
  #     cpu: "200m"
  #   memory: "200Mi"
  # -- Specify Node Labels to place api pods on
  nodeSelector: {}
  # -- https://kubernetes.io/docs/concepts/scheduling-eviction/taint-and-toleration/
  tolerations: []
  # -- https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/#node-affinity
  affinity: {}
  # -- metrics server and Prometheus Operator configuration
  # -- keycloak client secret is used to get token from keycloak (set in env-specific values)
  keycloakClient:
    id: ""

# -- Ingress for any ingress controller.
ingressConfig:
  provider:
    # -- #Currently supported: [traefik, traefikCRD]
    name: traefikCRD
    traefik:
      ingressClass: ""
    traefikCRD:
      tlsStore:
        enabled: false
        name: default
  # -- specify whether to create Ingres resources for API and UI
  enabled: false
  tls:
    enabled: false
    # -- Certificate and Issuer will be created with Cert-Manager. Names will be autogenerated.
    # if `certManager.enabled` `ingressConfig.tls.secretName` will be ignored
    certManager:
      enabled: false
      email: ""
      server: "https://acme-staging-v02.api.letsencrypt.org/directory"
    # -- secret name with own tls certificate to use with ingress
    secretName: ""
  # Strip Application prefix middleware configuration
  stripApplicationPrefix:
    enabled: true
    regex:
      - "/.*(/api)?/"

# -- Whether to parse and send logs to centralised storage
# FluentD Output Configuration. Fluentd aggregates and parses logs
# FluentD is a part of Logging Operator. CRs `Output` and `Flow`s will be created
logOutput:
  # Configuration specific to ElasticSearch logging
  elasticSearch:
    enabled: false
    # -- The hostname of your Elasticsearch node
    host: ""
    # -- The port number of your Elasticsearch node
    port: 443
    # -- The index name to write events
    index_name: ""
    # -- Data stream configuration
    data_stream:
      enabled: false
      name: ""
      data_stream_template_name: ""
    # -- The login username to connect to the Elasticsearch node
    user: ""
    # -- Specify secure password with Kubernetes secret
    secret:
      create: false
      password: ""
      annotations: {}
    # Buffer configuration for handling logs
    buffer:
      chunk_limit_size: 4M
      total_limit_size: 512MB
      flush_mode: interval
      flush_interval: 10s
      flush_thread_count: 2
      overflow_action: block
  # Configuration specific to Loki logging
  loki:
    enabled: false
    # URL of the Loki instance to send logs to
    url: ""
    # Labels to attach to log streams sent to Loki
    # Format: label_name: log_field_name
    labels: {}
    # Format to use when flattening the record to a log line: key_value, json
    line_format: ""
    # Buffer configuration for handling logs
    buffer:
      chunk_limit_size: 4m
      timekey: 1m
      timekey_wait: 30s
      timekey_use_utc: true
  # Configuration specific to Logz.io logging
  logzIo:
    enabled: false
    # Logz.io endpoint configuration
    endpoint:
      url: ""
      port: 8071
    # Logz.io secret configuration
    secret:
      create: false
      token: ""
      annotations: {}
    # Include tags in the log output
    output_include_tags: true
    # Include timestamp in the log output
    output_include_time: true
    # Buffer configuration for handling logs
    buffer:
      type: file
      flush_mode: interval
      flush_thread_count: 4
      flush_interval: 5s
      chunk_limit_size: 16m
      queue_limit_length: 4096

monitoring:
  # -- Enable integration with a prometheus-operator. The module fetches metrics from the canton nodes in the system.
  # Prometheus operator and grafana need to be installed beforehand
  enabled: false
  url:
  # -- Configuration for ServiceMonitor resource
  serviceMonitor:
    # -- How often to pull metrics from resources
    interval: 30s
  # -- Configuration for prometheusRules resource
  prometheusRules:
    enabled: false
    # Additional prometheusRules labels
    labels: {}
  grafana:
    enabled: false
    # -- grafana default admin username and email. Grafana is authenticated through default API authentication automatically.
    # -- grafana normal URL
    url: ""
    user: admin
    email: admin@domain.com
    # -- grafana default path to dashboard
    clusterDashboard: ""
    # -- grafana service and port for ingress
    service:
      name: grafana
      namespace: monitoring
      port: 80
```


# CAT-BM Canton Service Installation

Instructions for deploying the CatalyX Blockchain Manager Canton Service using Helm.

## Install the Catalyst Blockchain Manager Canton Service

Use the following command:

```bash
helm upgrade --install ${canton_release_name} catbp/canton-console --values values.yaml -n ${ns_name}
```

where:

* ${`canton_release_name`} — name of the Catalyst Blockchain Manager Canton service release.\
  You can choose any name/alias.\
  It is used to address for updating, deleting the Helm chart.
* *`catbp/canton-console`* — chart name, where “catbp” is a repository name, “canton-console” is the chart name.
* *`values.yaml`* — a values file.
* ${`ns_name`} — name of the namespace you’ve created before

You can check the status of the installation by using these commands:

* *`helm ls`* — check the "status" field of the installed chart.

{% hint style="info" %}
Status “deployed” should be shown.
{% endhint %}

* *`kubectl get pods`* — get the status of applications separately.

{% hint style="info" %}
All pods statuses must be “running.”
{% endhint %}

* *`kubectl describe pod $pod_name`* — get detailed information about pods.


# External Identity Provider Configuration (optional)

This section outlines the requirements for configuring an external Identity Provider (IdP) instead of the default integrated Keycloak.

When using an external IdP, CatalyX does not create users or OAuth clients for you; all required OIDC clients and users must be set up in your IdP before creating a validator, in accordance with the Canton Validator OIDC requirements.

{% hint style="info" %}
This page covers the technical configuration requirements for external identity providers, including external IDP setup guides. For more details on the supported identity providers, see the Security & Privacy Implementation page.
{% endhint %}

{% content-ref url="/pages/bvHLoRkGDY6yVqcoe4i9" %}
[Broken mention](broken://pages/bvHLoRkGDY6yVqcoe4i9)
{% endcontent-ref %}

The Identity Provider must be configured before launching a Canton Validator Node. This section provides a brief overview of configuring Clients and Users in your Identity Provider before setting up the Validator. For a full description of requirements, consult the Canton Validator OICD Requirements:

{% embed url="<https://docs.dev.sync.global/validator_operator/validator_helm.html#oidc-provider-requirements>" %}

## 1. Identity Requirements

In this section, we describe the Identity requirements for the Catalyst platform and Canton Validator.

### 1.1. Catalyst Blockchain Manager

Catalyst integrates seamlessly with any OICD OAuth provider. The following information is expected from the Identity Provider:

* OICD Discovery
* Authorize Endpoint
* Token Endpoint
* Refresh Token endpoint
* JWKS endpoint

#### 1.1.1. Clients

The clients required to set up a Canton validator with an IdP are explained below.

**CNS Client ID (Public)**

The requirements for the client are:

* Client ID.
* The client needs to support authorization code flow + token refresh.
* Configure redirect URIs based on the environment. Please request them from your Catalyst admin.

**Client Catalyst API (Private)**

This client is used by the Catalyst API. The main requirements are:

* Client ID.
* Client secret.
* The client needs to support authorization code flow + token refresh
* The requirement for an authorization code depends on the IdP and will be verified during the integration test.
* This client is used only for server-to-server interactions and does not require redirect URIs.

#### 1.1.2. Users

To start using Catalyst, you must create a user for the administrator of the instance.

### 1.2. Canton Validator

The requirements for the OICD Provider are explained through the following docs:

{% embed url="<https://docs.dev.sync.global/validator_operator/validator_helm.html#oidc-provider-requirements>" %}

#### 1.2.1. Clients

Based on the documentation, the required clients for the Canton Validator are:

* **CNS Client**
  * Client ID
  * Redirect URI: Please request them from your Catalyst Admin.
* **Wallet Client**
  * Client ID
  * Redirect URI: Please request them from your Catalyst Admin.
* **Ledger Client**
  * Client ID
  * Ledger Client Secret
  * Ledger API User: The token needs a sub field. In most of the IdPs, the Client ID is the sub, but in others, it is required to create a service account logic to fill in this field correctly.

#### 1.2.2. Users

The validator requires a wallet user account. This user is required to log in to the wallet application.

## 2. Canton JWT Requirements

From a security perspective, the components that comprise the Validator node must be able to authenticate with one another and with external UI and API users. Canton uses JTW access tokens for authentication and expects them to be issued by an external OpenID Connect (OIDC) provider.

Canton follows the OAuth 2.0 Authorization Framework, as defined in RFC 6749 and RFC 6750.

The Ledger API enforces some JWT dependencies that are described in the following documentation:

{% embed url="<https://docs.digitalasset.com/operate/3.5/howtos/secure/apis/jwt.html#configure-leeway-parameters-for-jwt-authorization>" %}

Based on our experience, the changes should be the following:

* The configuration time-to-live for the client JWT tokens should be set to > 5 minutes.
* JWT Header Claim
* The typ claim should be “JWT”.
* JWT Payload Mandatory fields
* iss
* sub
* aud
* exp
* iat
* Scope: should be a list of strings separated by one space.

***


# Okta Setup Guide

CatalyX Blockchain Manager supports Okta as an external Identity Provider. This section walks through the steps required to configure Okta before creating a validator in CAT-BM.

### Catalyst Client Setup

Two clients must be created in Okta under **Applications → Applications**.

**UI Client**

The UI client is used by the CAT-BM console. When creating it, select the following options:

* Sign-in method: **OIDC - OpenID Connect**
* Application type: **Single-Page Application**
* Grant type: **Authorization Code** and **Refresh Token**

Once created, navigate to **LOGIN → Sign-in redirect URIs** and add the following URLs:

* `<UI url>`
* `<UI url>/domains`
* `<UI url>/participants`

Add the same URLs to the **Sign-out redirect URIs**.

**API Client**

This client is used by the CAT-BM API and other backend components. When creating it, select:

* Sign-in method: **OIDC - OpenID Connect**
* Application type: **Web Application**
* Grant type: **Client Credentials**, **Authorization Code**, and **Refresh Token**

| Client | Sign-in Method        | Application Type        | Grant Types                                           | Has Client Secret |
| ------ | --------------------- | ----------------------- | ----------------------------------------------------- | ----------------- |
| UI     | OIDC - OpenID Connect | Single-Page Application | Authorization Code; Refresh Token                     | No                |
| API    | OIDC - OpenID Connect | Web Application         | Client Credentials; Authorization Code; Refresh Token | Yes               |

### User Access Setup

CAT-BM enforces role-based access using two roles: `canton_viewer` (read-only) and `canton_writer` (full operational access). These roles must be added to the Okta token.

**Step 1 — Add the roles attribute to the user profile:**

Go to **Profile Editor → User (default)**:

* Select **Add Attribute** and choose **String Array**
* Set Display name to `roles`
* Set Variable name to `roles`

**Step 2 — Add the roles claim to the token:**

Go to **Security → API → \[your auth server] → Claims** and select **Add Claim**:

* Name: `roles` (must be this exact name)
* Include in token type: **Access Token**
* Value: `user.roles` (or `appuser.roles` if added to the application user profile)

Repeat with **Include in token type** set to **ID Token**.

{% hint style="info" %}
You can verify the token in **Security → API → Token Preview**. The token should contain a `roles` claim with `canton_viewer` and `canton_writer` values in both the `id_token` and `token`.
{% endhint %}

### Helm Chart Configuration

{% hint style="info" %}
**GitOps transition note:** CatalyX Blockchain Manager is moving toward a GitOps-driven deployment model using Helm charts managed via ArgoCD. The Helm chart field references below reflect the current configuration approach. These may change as the GitOps model matures — confirm with the engineering team for the latest guidance on your deployment.
{% endhint %}

Fill in the following fields in your Helm chart values:

```yaml
auth:
  url: “”
  client:
    idApiOperator: “”
    idUI: “”
    secret: “”
```

* **auth.url** — The Issuer URI from **Security → API → \[your auth server]** (the Issuer URI field on the default server)
* **auth.client.idApiOperator** — Client ID of the API client, found under **Applications → Applications**
* **auth.client.idUI** — Client ID of the UI client, found under **Applications → Applications**
* **auth.client.secret** — Client Secret of the API client, found on the client's page

### Validator Client Setup

Before creating a validator in CAT-BM, three additional clients must be created in Okta.

**CNS and Wallet Clients**

Create two separate clients with the following options:

* Sign-in method: **OIDC - OpenID Connect**
* Application type: **Single-Page Application**
* Grant type: **Authorization Code** and **Refresh Token**

After creating the validator, retrieve the Wallet URL from the Wallet page and add it to **LOGIN → Sign-in redirect URIs** on the Wallet client.

**Ledger Client**

* Sign-in method: **API Services**

#### Adding the `daml_ledger_api` Scope

After creating the Ledger client, you need to define and assign the `daml_ledger_api` scope so the client can request it in token exchanges.

**Step 1 — Add the scope to your authorization server:**

Go to **Security → API → \[your auth server] → Scopes** and select **Add Scope**:

* Name: `daml_ledger_api`
* Display phrase: `Daml Ledger API` (or any descriptive label)
* Default scope: unchecked (unless required by your setup)

**Step 2 — Grant the scope to the Ledger client:**

Go to **Applications → Applications → Ledger client → Okta API Scopes**, locate `daml_ledger_api`, and click **Grant**.

**Step 3 — Verify the scope is returned in tokens:**

Go to **Security → API → Token Preview**, select the Ledger client and **Client Credentials** grant type, then confirm `daml_ledger_api` appears in the `scp` claim of the resulting access token.

| Client | Sign-in Method        | Application Type        | Grant Types                       | Has Client Secret |
| ------ | --------------------- | ----------------------- | --------------------------------- | ----------------- |
| Wallet | OIDC - OpenID Connect | Single-Page Application | Authorization Code; Refresh Token | No                |
| CNS    | OIDC - OpenID Connect | Single-Page Application | Authorization Code; Refresh Token | No                |
| Ledger | API Services          | —                       | —                                 | Yes               |

Assign at least one user to both the Wallet and CNS clients — this will be the main wallet user when creating the validator.

### Obtaining Fields for Validator Creation

When creating a validator in CAT-BM with Okta as the IdP, the following fields are required:

| Field                    | Where to find it in Okta                                         |
| ------------------------ | ---------------------------------------------------------------- |
| CNS Client ID            | Applications → Applications → CNS client → Client ID             |
| Wallet Client ID         | Applications → Applications → Wallet client → Client ID          |
| Ledger API Client ID     | Applications → Applications → Ledger client → Client ID          |
| Ledger API Client Secret | Applications → Applications → Ledger client → Client Secrets tab |
| Ledger API User          | Same as the Ledger API Client ID by default in Okta              |
| Wallet User              | Username of the main wallet user account                         |
| Audience                 | Security → API → \[your auth server] → Audience field            |


# Microsoft EntraID Setup Guide

CatalyX Blockchain Manager supports Microsoft Entra ID (formerly Azure Active Directory) as an external Identity Provider.

## 1 — Catalyst Client Setup

### 1.1 — UI Client

Create a new App Registration for the UI:

* **Name:** `canton-ui`
* **Supported account types:** Single tenant (My organization only)
* **Platform:** Single-Page Application (SPA)

After creation, go to **Authentication → Add Redirect URI** and add the following URLs:

* `<UI url>`
* `<UI url>/domains`
* `<UI url>/participants`
* `<UI url>/validators`

**CORS origins:**

* `<UI url>`

**Front-channel logout URL:**

* `<UI url>`

{% hint style="info" %}
Redirect URIs, CORS origins, and the logout URL will be known after installation on a fresh environment.
{% endhint %}

### 1.2 — API Client

Create a second App Registration for the API:

* **Name:** `catalyst-api`
* **Supported account types:** Single tenant

After creation:

{% stepper %}
{% step %}

#### Create a Client Secret

Go to **Certificates & Secrets → New client secret** and save the secret **value** immediately — it will not be shown again. Do not save the secret ID.
{% endstep %}

{% step %}

#### Expose an API

Go to **Expose an API → Add** next to Application ID URI and accept the default value `api://<client-id>`.
{% endstep %}

{% step %}

#### Add a Scope

Click **Add a scope** and fill in:

* **Scope name:** `access`
* **Who can consent:** Admins and users
* **Admin consent display name:** `Catalyst API access`
* **Admin consent description:** `Catalyst API access`
  {% endstep %}

{% step %}

#### Grant API Permissions

Go to the **UI App Registration → API permissions → Add a permission → My APIs → catalyst-api**, select the `access` scope, and click **Add permissions**.

Then click **Grant admin consent for \[tenant]**.
{% endstep %}
{% endstepper %}

| Client               | Platform Type           | Grant Types                                             | Has Client Secret |
| -------------------- | ----------------------- | ------------------------------------------------------- | ----------------- |
| UI (`canton-ui`)     | Single-Page Application | Authorization Code (PKCE) + Refresh Token               | No                |
| API (`catalyst-api`) | Web                     | Client Credentials + Authorization Code + Refresh Token | Yes               |

### 1.3 — User Setup

Create a new user in **Entra ID → Users → New user → Create new user**:

* **Username:** e.g. `canton-admin@<tenant>.onmicrosoft.com`
* **Display name:** e.g. `Canton Admin`
* **Password:** set a temporary password — the user will be prompted to change it on first login

Assign the user to both Enterprise Applications:

* **Entra ID → Enterprise Applications → `canton-ui` → Users and Groups → Add user/group**
* **Entra ID → Enterprise Applications → `catalyst-api` → Users and Groups → Add user/group**

### 1.4 — Fields Required by IntellectEU

After completing the Entra ID setup, provide the following values to IntellectEU:

| Field             | Where to find it                                                                          |
| ----------------- | ----------------------------------------------------------------------------------------- |
| UI Client ID      | App Registrations → `canton-ui` → Overview → Application (client) ID                      |
| API Client ID     | App Registrations → `catalyst-api` → Overview → Application (client) ID                   |
| API Client Secret | App Registrations → `catalyst-api` → Certificates & Secrets → value saved during creation |
| Tenant ID         | Entra ID → Overview → Tenant ID                                                           |
| Auth URL          | `https://login.microsoftonline.com/<tenant-id>/v2.0`                                      |
| User Username     | Entra ID → Users → \[user] → User principal name                                          |
| User Password     | Set during user creation in step 1.3                                                      |


# Auth0 Setup Guide

## Configuring Auth0 for CatalyX

### 1. CatalyX API (Resource Server)

Navigate to **Applications → APIs → Create API** and configure:

* **Name:** CatalyX
* **Identifier (Audience):** `<audience>`

### 2. UI Client

Create a new application with type **Single Page Application** and configure:

* **Grant types:** Authorization Code, Refresh Token
* **Allowed Callback URLs:** `<UI url>`, `<UI url>/domains`, `<UI url>/participants`
* **Allowed Logout URLs:** same three URLs as above

The UI client requests the `<audience>` on login.

### 3. API Client

Create a new application with type **Regular Web Application** and configure:

* **Grant types:** Client Credentials, Authorization Code, Refresh Token

### 4. Connect Both Clients to the CatalyX API

Go to **APIs → CatalyX → Machine to Machine Applications**, enable both the UI and API clients, and grant their respective scopes.

| Client | Application Type        | Grant Types                                           | Has Client Secret |
| ------ | ----------------------- | ----------------------------------------------------- | ----------------- |
| UI     | Single Page Application | Authorization Code; Refresh Token                     | No                |
| API    | Regular Web Application | Client Credentials; Authorization Code; Refresh Token | Yes               |

### Example Helm Value Overrides

{% code title="helm-values.yaml" %}

```yaml
api:
  extraEnv:
    AUTH_ROLES: "false"
    AUTH_AUDIENCE: "<audience>" # Comes from identifier of Auth0 API

ui:
  extraEnv:
    AUTH_ROLES: "false"
    AUTH_AUDIENCE: "<audience>" # Comes from identifier of Auth0 API

auth:
  enabled: true
  keycloak:
    enabled: false
  url: "https://dev-2bsf8p5hbjadzwh4.us.auth0.com/" # Example URL
  client:
    idApiOperator: "<API Client ID>"
    idUI: "<UI client ID>"
    secret: "<API secret>"
```

{% endcode %}

{% hint style="info" %}
`AUTH_ROLES` must be set to the same value under both `api.extraEnv` and `ui.extraEnv` — see [Role-Based Access Control (RBAC)](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/prerequisites#role-based-access-control-rbac) for what `canton_viewer`/`canton_writer` enforcement does when this flag is `"true"`.
{% endhint %}

## Configuring Auth0 for Validator

To configure Auth0 resources for a validator, follow the [Kubernetes Validator Deployment](https://docs.canton.network) guide. Resources should be created under the CatalyX API.

{% hint style="info" %}
Callback URLs and Logout URLs can be added after CatalyX deploys Wallet and CNS resources and generates the URLs.
{% endhint %}


# Network & Node Management


# Domains

This page introduces Domains (or Synchronizers) in Canton and explains how they are created and configured in Catalyst. Canton is a network composed of multiple domains, each operating under its own rules, governance, and set of participants. Each domain functions as an independent sub-network that participates in the wider Canton Network.

### What is a Domain/ Synchronizer?

In a composed solution, each domain is a sub-network. A Participant Node connects to one or more Domains, enabling transactions that span Domains.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-7d8fd36a0df45341369bd440cbcb87cf0d66f11e%2Fimage%20(16).png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
For more information about Participant nodes, see [Participants](broken://pages/27a5b9a93b16fb5fe81a9e6ff2aa908021e0156b).
{% endhint %}

### How Do I Create a Domain?

To create a Domain, go to the **Domains** tab and click the **Create** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-838226eb09dce4eb8c8419bd6626e7f920a587ad%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Provide a Domain name**

Enter a unique Domain name (required).
{% endstep %}

{% step %}
**Fill in the main settings**

{% hint style="info" %}
Using a predefined image is recommended for compatibility. However, you can select your own image if needed. If you want to use an image from a private repository, specify an `imagePullSecret`. You can create an `imagePullSecret` in your Kubernetes cluster and reference it by name here.
{% endhint %}

* Choose domain image
* Enable **Daemon** if required
* Enable **Ingress** if required
* **Resources allocation:**
  * **Requested CPU** — Guaranteed CPU resources that will be allocated
  * **CPU limit** — Maximum CPU resources that will be allocated
  * **Requested memory (MB)** — Guaranteed amount of RAM that will be allocated
  * **Memory limit (MB)** — Maximum amount of RAM that can be allocated
  * **Storage size**
* You can add custom environment variables if needed
  {% endstep %}

{% step %}
**Fill in Topology**

* Enable **Embedded Topology** if needed
* **Topology:**
  * Choose between form or raw view topology
  * Choose **Admin Port**
  * Choose **Public port**
  * Choose **Storage type:**

{% tabs %}
{% tab title="Memory" %}
No additional configuration required.
{% endtab %}

{% tab title="PostgreSQL" %}
A PostgreSQL database will be provisioned in the cluster.

* Choose User
* Choose Password
* Choose Storage size

{% hint style="info" %}
When selecting PostgreSQL as storage type, a postgres database will be provisioned in the cluster.
{% endhint %}

{% hint style="info" %}
For production deployments, consider using the **External** option below instead. See [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery#use-an-external-database-for-production) for recommendations on database hosting and safe pod operations.
{% endhint %}
{% endtab %}

{% tab title="External" %}
A database is expected to be hosted at the given hostname and port, with the same name as the domain and a user with the provided credentials.

* Choose User
* Choose Password
* Choose Hostname
* Choose Port
  {% endtab %}
  {% endtabs %}
  {% endstep %}

{% step %}
**Bootstrap (optional)**

Provide bootstrap commands if needed.
{% endstep %}
{% endstepper %}

***


# Participants

This page introduces Participants in Canton and explains how they are created, configured, and managed using Catalyst. In Canton's execution model, each application party is hosted on a Participant Node, which maintains the party's private state and history and synchronizes with other participants using the Canton protocol via domains.

### What is a Participant?

Each party of the application is hosted on a **Participant Node**. The Participant Node stores the party's unique projection and history of the shared system of record. Participant Nodes synchronize by running a consensus protocol (the Canton Protocol) between them, sending encrypted messages through Domains that provide guaranteed delivery and order consistency.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-1006ae8784552623fc8cfdb7d5794acce70b29b6%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
For more information about Domains, see [Domains](broken://pages/df6fa4e1fbdb4023b904163cd1981d66ba03e3e1).
{% endhint %}

### How Do I Create a Participant?

To create a Participant, go to the **Participants** tab and click the **Create** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-5da6be03d5a80abc0e6957146ce4bfdba6f7ed99%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Provide a Participant name**

Enter a unique Participant name (required).
{% endstep %}

{% step %}
**Fill in the main settings**

{% hint style="info" %}
Using a predefined image is recommended for compatibility. If you want to use an image from a private repository, specify an `imagePullSecret`.
{% endhint %}

* Choose participant image
* Choose DAR files to upload
* Enable **Navigator** if required
* Enable **Daemon** if required
* **Resources allocation:**
  * **Requested CPU** — Guaranteed CPU resources that will be allocated
  * **CPU limit** — Maximum CPU resources that will be allocated
  * **Requested memory (MB)** — Guaranteed amount of RAM that will be allocated
  * **Memory limit (MB)** — Maximum amount of RAM that can be allocated
  * **Storage size**
* You can add custom environment variables if needed

{% hint style="info" %}
To prevent pod evictions, you can choose to disable CPU limits for the resource allocation.
{% endhint %}
{% endstep %}

{% step %}
**Fill in Topology**

* Enable **Embedded Topology** if needed
* **Topology:**
  * Choose between form or raw view topology
  * Choose **Admin Port**
  * Choose **Public port**
  * Choose **Storage type:**

{% tabs %}
{% tab title="Memory" %}
No additional configuration required.
{% endtab %}

{% tab title="PostgreSQL" %}
A postgres database will be provisioned in the cluster.

* Choose User
* Choose Password
* Choose Storage size

{% hint style="info" %}
For production deployments, consider using the **External** option below instead. See [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery#use-an-external-database-for-production) for recommendations on database hosting and safe pod operations.
{% endhint %}
{% endtab %}

{% tab title="External" %}
A database is expected to be hosted at the given hostname and port with the same name as the participant and a user with the provided credentials.

* Choose User

* Choose Password

* Choose Hostname

* Choose Port
  {% endtab %}
  {% endtabs %}

* Enable **Authorization Service** if needed
  {% endstep %}

{% step %}
**Bootstrap (optional)**

Provide bootstrap commands if needed.
{% endstep %}
{% endstepper %}

### How Do I Connect a Participant to a Domain?

After the participant is created, click the **Connect to domain** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-3d775b8d306f9b9b3b46a1ad9919500014af6b89%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Select either a domain available in this Catalyst Canton console, or connect to any external domain by providing the full domain URL.
{% endhint %}

### How Do I Upload DAR Files to a Participant?

After the participant is created, click the **Upload DAR** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-db1431cf26d96ed22fc9bad2bcef89618dfb1779%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Select one or multiple DAR files to upload to the participant. DAR files can be added to the console through the [Collections](broken://pages/70b986760b8e86303857f0b72acf6a4f5adf5e8d) tab.
{% endhint %}

### Parties & Users

A party represents an entity capable of creating and interacting with contracts on the ledger. Each party is hosted on one or more Participant Nodes.

A Party is created by default once a Participant is connected to a Domain. However, Catalyst Blockchain Manager allows users to add additional parties on a participant node.

#### Local Parties vs. Parties

The Participant Details page includes the following tabs: **Local Parties**, **Parties**, **Users**, **Dar Files**, and **Logs**.

* **Local Parties** — Allows users to trigger an explicit fetch of all parties registered to this participant on the ledger.
* **Parties** — Shows parties across the entire ledger (the full network), not just those local to this participant.

{% hint style="info" %}
If you create a party outside of Catalyst, it will not appear in the list automatically. Click **Fetch Local Parties** again to pick up that change.
{% endhint %}

{% hint style="info" %}
The Local Parties tab is only shown for validator participants. It does not appear for standalone participants (non-validator nodes).
{% endhint %}

{% hint style="warning" %}
For networks with a large number of parties (e.g., MainNet with \~500,000 parties), the fetch process can take a considerable amount of time.
{% endhint %}

For detailed Party and User Management, head to the Parties and Users section:

{% content-ref url="/pages/f15e7603f08b261b9e85b489ea62cbaefac624f8" %}
[Parties & Users](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/parties-and-users)
{% endcontent-ref %}


# Parties & Users

## Overview

This section explains how to:

* View and manage parties on a participant.
* Create a User in Keycloak.
* Create a User in CatalyX.
* Assign user permissions and roles.
* Link a User to a Party.
* Access the Wallet UI.

This process is commonly used when onboarding a new customer, validator user, or application participant.

## Prerequisites

Before starting, ensure you have:

* Access to CatalyX Blockchain Manager
* Access to the Keycloak Admin Console
* Permissions to manage Participants and Users
* A deployed validator or participant

***

## Part 1 — View and Manage Parties

### What is a Party?

A Party represents an entity capable of creating contracts, interacting with contracts, and participating on the ledger. Each Party is hosted on one or more Participant Nodes.

### The Parties Tab

The **Parties** tab on the Participant details page allows you to look up any party — local or remote — by ID prefix. Enter at least two characters of a party ID to search. This tab is suitable for looking up a specific known party.

{% hint style="info" %}
The Parties tab does not load all parties automatically. In production environments a participant may be aware of hundreds of thousands of parties (the Canton Network MainNet has \~500,000+), making a full listing impractical.
{% endhint %}

### The Local Parties Tab

The **Local Parties** tab shows parties that are hosted on this participant node. Unlike the Parties tab, local parties can be fetched in bulk.

Local parties are **not** loaded automatically on page load. To retrieve them, click **Fetch Local Parties**. While fetching is in progress, the existing list continues to be displayed and the fetch button is disabled. Once complete, the list updates to show all local parties.

{% hint style="info" %}
Only parties created through CatalyX are guaranteed to appear in the local parties list. Parties created directly via the Ledger API or gRPC may not be included.
{% endhint %}

### Create a Party

To allocate a new party on this participant, open the **Parties** tab and click **Add Party**. Provide a party name and any optional display information, then click **Save**.

After creation, the party becomes available on the ledger. Example party identifier:

```
alice::participant1::domain
```

***

## Part 2 — Create a User in Keycloak

{% stepper %}
{% step %}
**Open Keycloak**

Log in to the **Keycloak Admin Console** and select the appropriate Realm.
{% endstep %}

{% step %}
**Create a User**

Navigate to **Users** and click **Add User**. Enter a username.

{% hint style="info" %}
Recommended naming convention: `cpm-${client}`
{% endhint %}
{% endstep %}

{% step %}
**Configure Credentials**

Open the **Credentials** tab, set a password, and save your changes.
{% endstep %}
{% endstepper %}

***

## Part 3 — Create a User in CatalyX

{% stepper %}
{% step %}
**Open Participant Users**

Navigate to **Participants**, open the target Participant, open the **Users** tab, and click **Create User**.
{% endstep %}

{% step %}
**Configure the User**

Provide a username.

{% hint style="warning" %}
The username must match the Keycloak username exactly. Example: `cpm-client`
{% endhint %}
{% endstep %}

{% step %}
**Assign the Primary Party**

Paste the full party ID of the party created in Part 1 directly into the **Primary Party** field. Do not use a party name — the field requires the full party address.

{% hint style="info" %}
You can copy the full party ID from the **Local Parties** or **Parties** tab on the Participant details page.
{% endhint %}

{% hint style="warning" %}
If the party ID entered does not exist on this participant, CatalyX will display an error. Verify the party ID is correct and that the party is hosted on this participant before proceeding.
{% endhint %}
{% endstep %}
{% endstepper %}

***

## Part 4 — Grant User Rights and Roles

### Available Rights

{% tabs %}
{% tab title="CanActAs" %}
Allows the user to act on behalf of the Party, submit transactions, and interact with contracts.

**Recommended for:** operational users, wallet users, application users.
{% endtab %}

{% tab title="CanReadAs" %}
Allows the user to view ledger data and read contracts. Does **not** allow submitting transactions or acting on behalf of the Party.

**Recommended for:** auditors, monitoring users, read-only access.
{% endtab %}

{% tab title="ParticipantAdmin" %}
Provides administrative access to the Participant. Use carefully.

**Recommended only for:** platform administrators, DevOps operators.
{% endtab %}
{% endtabs %}

### Recommended Rights by User Type

| User Type   | Recommended Rights |
| ----------- | ------------------ |
| Wallet user | CanActAs           |
| Auditor     | CanReadAs          |
| Admin       | ParticipantAdmin   |

### Assign Rights

Under **User Rights**, choose the appropriate role and select the target Party, then click **Save**.

{% hint style="info" %}
Grant the minimum required permissions. Avoid assigning `ParticipantAdmin` unless necessary.
{% endhint %}

***

## Part 5 — Access the Wallet UI

{% stepper %}
{% step %}
**Open the Wallet UI**

Open the Wallet UI URL for your validator. Example: `https://wallet-${validator-name}.${domain}`
{% endstep %}

{% step %}
**Log in**

Log in using the Keycloak credentials created in Part 2.
{% endstep %}
{% endstepper %}

After login, verify that the wallet opens successfully, balances are visible, and Party permissions work correctly.

{% hint style="warning" %}
Use an incognito browser window to avoid Keycloak session conflicts.
{% endhint %}

***

## Validation Checklist

| Validation            | Expected Result                |
| --------------------- | ------------------------------ |
| Party created         | Party visible in CatalyX       |
| Keycloak user created | User can authenticate          |
| CatalyX user created  | User visible under Participant |
| Rights assigned       | User has correct access        |
| Wallet login works    | User can access wallet         |

## Troubleshooting

| Issue                                    | Cause                                                                | Resolution                                                                           |
| ---------------------------------------- | -------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| User cannot log in                       | Incorrect Keycloak credentials                                       | Reset password                                                                       |
| Wallet access denied                     | Missing CanActAs role                                                | Grant correct rights                                                                 |
| User not linked to Party                 | Primary Party not assigned                                           | Update user configuration                                                            |
| Primary Party field shows an error       | Party ID does not exist on this participant                          | Verify the full party ID from the Local Parties tab                                  |
| User visible in Keycloak but not CatalyX | CatalyX user not created                                             | Create user in Participant Users tab                                                 |
| Session conflicts during login           | Existing Keycloak session                                            | Use incognito browser                                                                |
| Local Parties list is empty after fetch  | No parties created through CatalyX yet, or startup fetch is disabled | Click Fetch Local Parties manually; check `CANTON_CONSOLE_PARTIES_FETCH_ALL` setting |

## Best Practices

* Use consistent naming conventions across Keycloak and CatalyX
* Match Keycloak and CatalyX usernames exactly
* Copy party IDs directly from the Local Parties tab to avoid typos
* Grant minimum required permissions
* Avoid assigning `ParticipantAdmin` unless necessary
* Use separate users for admin and operational activities


# Applications

This page explains how custom applications can be deployed and managed in Catalyst through the Applications tab. Applications can be backend or frontend types, including DAML-based applications.

### How Do I Create an Application?

To create an application, go to the **Applications** tab and click the **Create** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-5d1b4af0921b3b5b35aad2d05415b80e04a19d9e%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Provide an Application name**

Enter a unique Application name (required).
{% endstep %}

{% step %}
**Fill in the main settings**

Applications can have a **UI** or **Backend** type.

{% tabs %}
{% tab title="UI Application" %}
When deploying a UI application, choose between providing an image for the application or selecting one of the previously uploaded UI files (uploaded through the [Collections](broken://pages/70b986760b8e86303857f0b72acf6a4f5adf5e8d) tab).

{% hint style="info" %}
When selecting a UI file to deploy, the image field will be ignored. The UI application will be served by a nginx server.
{% endhint %}
{% endtab %}

{% tab title="Backend Application" %}
Provide a Docker image for the backend application.
{% endtab %}
{% endtabs %}

* Choose **Application Type**
* Choose **application image** (or file if UI app and not using an image)
* Choose **Port**
* Choose **Subdomain:**
  * Select subdomain from existing participants
  * Choose custom subdomain
* **Resources allocation:**
  * **Requested CPU** — Guaranteed CPU resources that will be allocated
  * **CPU limit** — Maximum CPU resources that will be allocated
  * **Requested memory (MB)** — Guaranteed amount of RAM that will be allocated
  * **Memory limit (MB)** — Maximum amount of RAM that can be allocated
* You can add custom environment variables if needed
  {% endstep %}
  {% endstepper %}

***


# Collections

This page explains how Collections in Catalyst are used to manage reusable artifacts such as DAML archive (DAR) packages and UI packages. Items uploaded to Collections can later be uploaded to participants or deployed as applications.

{% hint style="info" %}
For a step-by-step guide on uploading DAR files — including direct participant uploads, application-specific deployments (CPM, billing, Tradecraft), and Canton console commands — see [Upload DARs](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/dar-management).
{% endhint %}

### My Collection

In the **My Collection** tab, DAR packages and UI packages can be uploaded to the console. These can then be uploaded to participants or deployed as applications respectively.

#### DAR Collections

When a Daml project is compiled, the compiler produces a Daml archive. These are platform-independent packages of compiled Daml code that can be uploaded to a Daml ledger or imported in other Daml projects. Daml archives have a `.dar` file ending.

{% hint style="info" %}
DAR files can be uploaded from the user's local computer, or obtained from the Catalyst Package Manager (CPM).

To read about CPM, see the [Canton Package Manager](/catalyx-package-manager) section of this guide.
{% endhint %}

**Upload a DAR file**

To upload a DAR file, go to the **Collections** tab and click **Upload DAR File** to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-17d63b77421c0629a558c4c35c7e8f62e7712124%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

#### UI Collections

The UI Collections feature of Catalyst allows you to provide a frontend for your app by publishing files exposed by HTTPS over a ledger-specific subdomain.

{% hint style="warning" %}
UI Collections must be uploaded to the console and deployed in the form of `.zip` files. The `.zip` should contain a single root directory, and the contents of that directory should contain an `index.html` along with the rest of the resources for your UI.
{% endhint %}

To upload a UI file, go to the **Collections** tab and click **Upload UI File** to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-66b85e03a4f5d7582dbd94df855be4fc7b01a812%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

***


# Networking

This page describes how network communication works in Catalyst for participants, domains, and applications. Components running inside the cluster communicate using Kubernetes internal DNS names, while selected services and APIs can also be exposed externally through ingress routes.

### Participants

For every participant running on Catalyst, the following (internal) endpoints are available:

| Endpoint                     | Address                                                                |
| ---------------------------- | ---------------------------------------------------------------------- |
| **Ledger API**               | `<canton-participant-name>.<namespace>.svc.cluster.local:5011`         |
| **Admin API**                | `<canton-participant-name>.<namespace>.svc.cluster.local:5019`         |
| **HTTP JSON API (internal)** | `jsonapi-<canton-participant-name>.<namespace>.svc.cluster.local:7011` |
| **HTTP JSON API (external)** | `http(s)://<canton-participant-name>.<your-domain>`                    |

{% hint style="info" %}
Default ports are shown above. If you set custom ports when creating a participant, the values will differ.
{% endhint %}

### Domains

For every domain running on Catalyst, the following (internal) endpoints are available:

| Endpoint                 | Address                                                   |
| ------------------------ | --------------------------------------------------------- |
| **Public API**           | `<canton-domain-name>.<namespace>.svc.cluster.local:5018` |
| **Admin API**            | `<canton-domain-name>.<namespace>.svc.cluster.local:5019` |
| **Ingress (if enabled)** | `http(s)://<canton-domain-name>.<your-domain>`            |

{% hint style="info" %}
Default ports are shown above. If you set custom ports when creating a domain, the values will differ.
{% endhint %}

### Applications

For every application running on Catalyst, the following endpoints are available:

| Type             | Address                                                      |
| ---------------- | ------------------------------------------------------------ |
| **Internal**     | `<application-name>.<namespace>.svc.cluster.local:80`        |
| **Backend app**  | `http(s)://<subdomain>.<your-domain>/<application-name>/api` |
| **Frontend app** | `http(s)://<subdomain>.<your-domain>/<application-name>`     |

{% hint style="info" %}
The default port (80) is used above. If you set a custom port when creating an application, the value will differ.
{% endhint %}

***


# Validator Management


# Validator Management with Integrated Keycloak

This page explains how to use Catalyst to create and deploy Validators on the Canton network with Integrated Keycloak. In this mode, Catalyst provisions and configures Keycloak automatically as part of the validator deployment, you don't need to bring or manage your own identity provider.

Keycloak is a login and user-management system: it verifies who you are, lets you sign in securely, and controls what you're allowed to access. When you create a validator with integrated Keycloak, Catalyst uses Keycloak as the security gate for all validator services, automatically creating the required users and connecting components such as the Wallet UI and APIs.

{% hint style="info" %}
This guide is for the **Default** authentication option with integrated Keycloak. To set up a validator with a custom identity provider, see [Create Validator with Custom Identity Provider](broken://pages/1d459ba5d7a4cfbd01fe511c1d03b5a8a26223cd).
{% endhint %}

### Validator Management

Validators can be deployed on Catalyst and seamlessly connected to the Canton Network.

#### Set Up a Validator

To set up a Validator, go to the **Validators** tab and click the **Set up validator** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-f708491149ce1eb68f93592f014e924b78aba185%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Main Settings Configuration**

Provide the following information:

* Sponsor SV Name
* Name
* Onboard secret
* Image tag
* Image repo
* Image pull secret
* Scan address
* SV sponsor address
* Party hint
* Migration id

<details>

<summary>More info about these fields</summary>

| Field                  | Description                                                                                                                                         |
| ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Sponsor SV Name**    | The name of the Super Validator that sponsored you to join the network                                                                              |
| **Name**               | The identifier or label for the validator node                                                                                                      |
| **Onboard secret**     | Passphrase obtained from the super validator in order to join the network                                                                           |
| **Image tag**          | The specific version or tag of the container image to be used                                                                                       |
| **Image repo**         | The repository where the container image is stored                                                                                                  |
| **Image pull secret**  | Credentials required to pull the container image from a private registry (`secret docker-registry`)                                                 |
| **Scan address**       | The address used for scanning and retrieving validator-related data                                                                                 |
| **SV Sponsor Address** | URL of the SV app of the super validator sponsoring you. Typically starts with `https://sv.sv-N`                                                    |
| **Party hint**         | Used as a prefix for the Party ID of your validator's administrator. Format: `<organization>-<function>-<enumerator>`, e.g., `myCompany-myWallet-1` |
| **Migration id**       | Used to track database migrations. Starts at `0` for the initial deployment and increments by 1 with each migration                                 |

</details>

{% hint style="info" %}
An onboarding secret should be requested from your sponsoring SV in order to join the network.
{% endhint %}

{% hint style="warning" %}
Only turn on the **Restore participant identities** toggle if you want to restore a validator from an Identity Dump.
{% endhint %}
{% endstep %}

{% step %}
**Cluster Configuration**

Provide the following information:

**2.1 — Enable or disable:**

* Disable wallet
* Fail on app version mismatch
* Disable probes

**2.2 — Fill in the remaining fields:**

* Default JVM Options
* Top up:
  * Enable
  * Min Top up interval
  * Target throughput
  * Contact point

<details>

<summary>More info about these fields</summary>

| Field                            | Description                                                                                                        |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| **Disable wallet**               | Turn on to not deploy a wallet UI with your validator                                                              |
| **Fail on app version mismatch** | If enabled, the deployment will fail if there is a mismatch between the validator and network application versions |
| **Disable probes**               | Probes test the health of a deployment. It is recommended to not disable them in standard scenarios                |
| **Default JVM Options**          | Default configuration options for the Java Virtual Machine (JVM) running the validator                             |
| **Top up**                       | Enables or disables the validator's automatic traffic purchase mechanism                                           |
| **Min Top up interval**          | Minimum amount of time that must pass between two automatic top-ups                                                |
| **Target throughput**            | Desired average traffic rate in bytes per second                                                                   |
| **Contact point**                | Where the validator can be reached for operational or administrative communication                                 |

</details>

{% hint style="danger" %}
Do **not** set the Custom Authentication flag on — these instructions are for integrated Keycloak configuration. To use a custom identity provider instead, see [Create Validator with Custom Identity Provider](broken://pages/1d459ba5d7a4cfbd01fe511c1d03b5a8a26223cd).
{% endhint %}
{% endstep %}

{% step %}
**Cluster Participant Configuration**

Provide the following information:

* Node Identifier
* Enable or disable:
  * Expose Ledger API
  * Private JSON API
* Default JVM Options

<details>

<summary>More info about these fields</summary>

| Field                   | Description                                                     |
| ----------------------- | --------------------------------------------------------------- |
| **Node identifier**     | A unique identifier for the validator node within the network   |
| **Expose ledger API**   | Opens up GRPC Ledger API to the outside                         |
| **Private JSON API**    | Closes JSON Ledger API (open by default)                        |
| **Default JVM Options** | Default configuration options for the JVM running the validator |

</details>

**3.1 — Database Type**

{% tabs %}
{% tab title="PostgreSQL" %}
A PostgreSQL database will be created automatically.

* Database User
* Database Password
  {% endtab %}

{% tab title="External Database" %}
Connect to an external database of your choice.

* Database User
* Database Password
* Host/IP address
* Port number
  {% endtab %}
  {% endtabs %}
  {% endstep %}

{% step %}
**Configure Resources**

Configure the necessary resources:

* Requested CPU
* CPU limit
* Requested memory
* Memory limit
* Replicas

<details>

<summary>More info about these fields</summary>

| Field                | Description                                                          |
| -------------------- | -------------------------------------------------------------------- |
| **Requested CPU**    | Minimum amount of CPU resources requested for the validator node     |
| **CPU limit**        | Maximum amount of CPU resources the validator node is allowed to use |
| **Requested memory** | Minimum amount of memory requested for the validator node            |
| **Memory limit**     | Maximum amount of memory the validator node is allowed to use        |
| **Replicas**         | Number of instances of the validator node to run                     |

</details>

{% hint style="info" %}
The pre-filled figures for resource configuration are a standard recommendation. Please adapt to your unique scenario if needed.
{% endhint %}
{% endstep %}

{% step %}
**Configure Environment Variables**

Override the values of the environment variables for the following components:

* Participant node
* Validator backend
* Canton Name Service UI
* Wallet UI

<details>

<summary>More info about these components</summary>

| Component                  | Description                                                                   |
| -------------------------- | ----------------------------------------------------------------------------- |
| **Participant node**       | The node that interacts with the Canton ledger on behalf of participants      |
| **Validator backend**      | The backend service responsible for validating and processing transactions    |
| **Canton Name Service UI** | The UI for managing and viewing Canton network names and identifiers          |
| **Wallet UI**              | User interface for interacting with the wallet associated with your validator |

</details>

{% hint style="danger" %}
This is a very specific configuration. If you are not sure about this step, please contact IntellectEU.
{% endhint %}
{% endstep %}

{% step %}
**Summary**

Review your Validator configuration. Once you have confirmed the settings, click the **Confirm** button to finalize and proceed with the deployment.
{% endstep %}

{% step %}
**Create a Permanent Password in Keycloak**

To access the wallet UI, you must first define a new password in Keycloak.

1. Save the credentials displayed in the pop-up window.
2. Once your node is up and running, click on the last link containing the text `wallet-web-ui`, then click the link at the top left part of the screen.
3. A pop-up will ask you to re-authenticate. Close your session by clicking the **Log out** button.
4. Insert the temporary credentials saved in the previous step to authenticate yourself.
5. Define a new password and click **Submit**. You will be forwarded to the wallet UI console of your new Validator.
   {% endstep %}
   {% endstepper %}

***

### Identity and Access Management

As part of the validator provisioning process, Keycloak is set as the identity provider for authentication and authorization across the validator infrastructure. Each validator is assigned a dedicated user (`$VALIDATOR_NAME_walletuser`) within a specific realm (`validator`) for secure access to services.

{% hint style="danger" %}
We strongly recommend updating the password for this user after the initial setup to maintain security and reduce risks associated with default credentials.
{% endhint %}

#### Resetting the Wallet User Password in Keycloak

{% stepper %}
{% step %}
**Log in to the Keycloak admin console**

* **URL:** `https://<your-keycloak-domain>/auth/admin/`
* Use an account with administrative access.
  {% endstep %}

{% step %}
**Navigate to the validator realm**

From the top-left dropdown menu, select **validator**.
{% endstep %}

{% step %}
**Locate the wallet user**

In the left sidebar, click on **Users** and use the search field to find `$VALIDATOR_NAME_walletuser`.
{% endstep %}

{% step %}
**Access the user's credentials**

Click on the user to open their settings, then navigate to the **Credentials** tab.
{% endstep %}

{% step %}
**Reset the password**

* Enter a new password and confirm it.
* Toggle **Temporary** to **OFF** if you do not want the user to be forced to reset the password upon next login.
* Click **Reset Password**.
  {% endstep %}

{% step %}
**Verify the changes**

Test the new password by authenticating the service or using the Keycloak test login page (if enabled).

{% hint style="warning" %}
Make sure to store the new password securely and update any dependent services or configuration files if needed.
{% endhint %}
{% endstep %}
{% endstepper %}

<details>

<summary>Additional Keycloak documentation resources</summary>

* [Keycloak Documentation – Managing Users](https://www.keycloak.org/docs/latest/server_admin/#admin-cli)
* [Keycloak Admin Console Guide](https://www.keycloak.org/docs/latest/server_admin/#admin-console)
* [Resetting Passwords via Admin Console](https://www.keycloak.org/docs/latest/server_admin/#resetting-passwords)

</details>

***


# Validator Management with Custom Identity Provider

This page explains how to create a Canton Validator using an external Identity Provider (IdP) instead of Catalyst's integrated Keycloak. In this mode, Catalyst does not create users or OAuth clients for you — all required OIDC clients and users must be set up in your IdP before creating the validator.

{% hint style="info" %}
The alternative to this approach is using an Integrated Keycloak that automates the process, as detailed in [Create Validator with Integrated Keycloak](broken://pages/09ab7fd8546b1d9c108768741af3810b3c02d11f).
{% endhint %}

### Prerequisites: Configure Your Identity Provider

Below you can find a brief overview of how to set up Clients and Users in your Identity Provider before setting up the Validator. For a full description of requirements, consult the [Canton Validator OIDC requirements](https://network.canton.global/validator_operator/validator_helm.html#oidc-provider-requirements) and navigate to the [External Identity Provider Configuration](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/external-identity-provider-configuration-optional) page in the installation instructions:

{% content-ref url="/pages/u0ylfiYfGRM6KXWYoz7z" %}
[External Identity Provider Configuration (optional)](/catalyx-blockchain-manager/canton-network/version-1.11/installation-instructions-canton/external-identity-provider-configuration-optional)
{% endcontent-ref %}

{% hint style="info" %}
The sections on secrets and other Kubernetes configuration can be ignored — Catalyst creates them. You only need to set up clients and users beforehand.
{% endhint %}

#### Setting up Clients and Users in your Identity Provider

The following clients are used by a Validator node and must be configured with the proper flows in your Identity Provider:

| Validator Component | OpenID Flow              | Fields required by Catalyst |
| ------------------- | ------------------------ | --------------------------- |
| Validator           | Client Credentials Grant | Client Id, Client secret    |
| Canton Name Service | Authorization Code       | Client Id                   |
| Wallet              | Authorization Code       | Client Id                   |

{% hint style="warning" %}
It is recommended to allow all audiences for the clients during validator creation. These can be restricted later, once Catalyst has generated the required URLs.
{% endhint %}

Before setting up the validator, create a user in your Identity Provider and ensure this user has permission to use the OIDC clients created for the validator.

{% hint style="info" %}
This user will be mapped to the main Validator party and will receive rewards, which can be viewed from the Wallet.
{% endhint %}

<details>

<summary>Microsoft Entra ID — Creating Clients and Users for a New Validator</summary>

**Wallet Client**

Create an App Registration for the Wallet:

* **Platform:** Single-Page Application
* No client secret needed

After creating the validator, obtain the Wallet URL and add it to the Wallet App Registration under **Authentication**:

* **Redirect URI:** `https://wallet-validator-<name>.<domain>`
* **CORS origin:** `https://wallet-validator-<name>.<domain>`
* **Front-channel logout URL:** `https://wallet-validator-<name>.<domain>`

Under **Expose an API**:

* Accept the default Application ID URI: `api://<client-id>`
* Add a scope named `access`, who can consent: Admins and users

{% hint style="info" %}
Redirect URIs, CORS origins, and the logout URL must be added after validator creation — the URLs are only known at that point.
{% endhint %}

**Ledger Client**

Create an App Registration for the ledger:

* **Name:** e.g. `canton-ledger`
* No platform or redirect URI needed
* Go to **Certificates & Secrets → New client secret** — save the value immediately
* Go to **Expose an API → Add** Application ID URI — accept the default `api://<client-id>`
* Click **Add a scope**:
  * **Scope name:** `access`
  * **Who can consent:** Admins and users
  * **Admin consent display name:** `Ledger API access`
  * **Admin consent description:** `Ledger API access`

Then grant the Wallet registration access to the Ledger API:

**Wallet App Registration → API permissions → Add a permission → My APIs → \[ledger app] → access → Add permissions → Grant admin consent**

| Client | Platform Type                  | Grant Types                        | Has Client Secret |
| ------ | ------------------------------ | ---------------------------------- | ----------------- |
| Wallet | Single-Page Application        | Authorization Code + Refresh Token | No                |
| Ledger | None (Client Credentials only) | Client Credentials                 | Yes               |

**User Setup**

Create a new user in **Entra ID → Users → New user → Create new user**.

Assign the user to both the Wallet and CNS Enterprise Applications via **Enterprise Applications → \[app] → Users and Groups → Add user/group**.

**Fields Required by IntellectEU**

After completing the setup, provide the following values to IntellectEU:

| Field                        | Where to find it                                                                           |
| ---------------------------- | ------------------------------------------------------------------------------------------ |
| Ledger Client Application ID | App Registrations → `canton-ledger` → Overview → Application (client) ID                   |
| Ledger Client Object ID      | App Registrations → `canton-ledger` → Overview → Object ID                                 |
| Ledger Client Secret         | App Registrations → `canton-ledger` → Certificates & Secrets → value saved during creation |
| Wallet UI Client ID          | App Registrations → \[wallet app] → Overview → Application (client) ID                     |
| Wallet User Username         | Entra ID → Users → \[wallet user] → User principal name                                    |
| Wallet User Password         | Set during user creation above                                                             |

</details>

***

### Set Up a Validator

To set up a Validator, go to the **Validators** tab and click the **Set up validator** button.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-f708491149ce1eb68f93592f014e924b78aba185%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Main Settings Configuration**

Provide the following information:

* Sponsor SV Name
* Name
* Onboard secret
* Image tag
* Image repo
* Image pull secret
* Scan address
* SV sponsor address
* Party hint
* Migration id

<details>

<summary>More info about these fields</summary>

| Field                  | Description                                                                                                       |
| ---------------------- | ----------------------------------------------------------------------------------------------------------------- |
| **Sponsor SV Name**    | The name of the Super Validator that sponsored you to join the network                                            |
| **Name**               | The identifier or label for the validator node                                                                    |
| **Onboard secret**     | Passphrase obtained from the super validator in order to join the network                                         |
| **Image tag**          | The specific version or tag of the container image to be used                                                     |
| **Image repo**         | The repository where the container image is stored                                                                |
| **Image pull secret**  | Credentials required to pull the container image from a private registry                                          |
| **Scan address**       | The address used for scanning and retrieving validator-related data                                               |
| **SV Sponsor Address** | URL of the SV app of the super validator sponsoring you (starts with `https://sv.sv-N`)                           |
| **Party hint**         | Used as a prefix for the Party ID. Format: `<organization>-<function>-<enumerator>`, e.g., `myCompany-myWallet-1` |
| **Migration id**       | Used to track database migrations. Starts at `0` and increments by 1 with each migration                          |

</details>

{% hint style="info" %}
An onboarding secret should be requested from your sponsoring SV in order to join the network.
{% endhint %}

{% hint style="warning" %}
Only turn on the **Restore participant identities** toggle if you want to restore a validator from an Identity Dump.
{% endhint %}
{% endstep %}

{% step %}
**Cluster Configuration**

**2.1 — Enable or disable:**

* Disable wallet
* Fail on app version mismatch
* Disable probes

**2.2 — Fill in the fields:**

* Default JVM Options
* Top up: Enable, Min Top up interval, Target throughput, Contact point

{% hint style="danger" %}
Make sure to set the **Custom Authentication** flag **ON**.
{% endhint %}

**2.3 — Fill in the custom authentication fields:**

* CNS Client Id
* Wallet Client Id
* Ledger API Client Id
* Ledger API Client Secret
* Ledger API User
* Wallet User
* Audience

<details>

<summary>More info about custom authentication fields</summary>

| Field                        | Description                                                               |
| ---------------------------- | ------------------------------------------------------------------------- |
| **CNS Client Id**            | Client for the Canton Name Service                                        |
| **Wallet Client Id**         | Client for the Wallet application                                         |
| **Ledger API Client Id**     | Client for the Validator                                                  |
| **Ledger API Client Secret** | Secret part of the Client Credentials Grant Flow for the Validator client |
| **Ledger API User**          | User of the components described above                                    |
| **Wallet User**              | User that will access the wallet application and receive rewards          |
| **Audience**                 | Audience claim expected by the clients                                    |

</details>
{% endstep %}

{% step %}
**Cluster Participant Configuration**

Provide the following information:

* Node Identifier
* Enable or disable: Expose Ledger API, Private JSON API
* Default JVM Options

**3.1 — Database Type**

{% tabs %}
{% tab title="PostgreSQL" %}
A PostgreSQL database will be created automatically.

* Database User
* Database Password
  {% endtab %}

{% tab title="External Database" %}
Connect to an external database.

* Database User
* Database Password
* Host/IP address
* Port number
  {% endtab %}
  {% endtabs %}
  {% endstep %}

{% step %}
**Configure Resources**

* Requested CPU
* CPU limit
* Requested memory
* Memory limit
* Replicas

{% hint style="info" %}
The pre-filled figures for resource configuration are a standard recommendation. Please adapt to your unique scenario if needed.
{% endhint %}
{% endstep %}

{% step %}
**Configure Environment Variables**

Override the values of the environment variables for:

* Participant node
* Validator backend
* Canton Name Service UI
* Wallet UI

{% hint style="danger" %}
This is a very specific configuration. If you are not sure about this step, please contact IntellectEU.
{% endhint %}
{% endstep %}

{% step %}
**Summary**

Review your Validator configuration. Once confirmed, click the **Confirm** button to finalize and proceed with the deployment.
{% endstep %}
{% endstepper %}

***

### Identity and Access Management

In deployments where an external Identity Provider is used, your organization is responsible for managing user credentials and access controls for the validator infrastructure.

{% hint style="danger" %}
We strongly recommend updating the password for this user account after the initial setup to ensure that access remains secure and unique.
{% endhint %}

#### Resetting the Wallet User Password in Your Identity Provider

To change the password for the wallet user, refer to the official documentation for your IdP. Typical steps include:

1. Log into your Identity Provider's admin portal.
2. Locate the user account associated with the validator (e.g., `$VALIDATOR_NAME_walletuser`).
3. Initiate a password reset or manual update from the user management section.
4. Disable any temporary password flags if you want to use the new password directly.
5. Update any validator configuration files or services that use this credential.

{% hint style="danger" %}
Always ensure that the new credentials are stored securely and are reflected across all dependent components.
{% endhint %}

{% hint style="warning" %}
If your IdP integrates with federation or SSO, ensure that policies and password propagation are correctly applied.
{% endhint %}

<details>

<summary>Common IdP documentation resources</summary>

* [Azure AD User Management](https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/)
* [Okta Admin Guide](https://help.okta.com/)
* [Auth0 Password Reset](https://auth0.com/docs/authenticate/login/password-reset)

</details>

***


# Validator Backups and Identity Dumps

How to configure scheduled backups and identity dumps for validator nodes in CatalyX Blockchain Manager.

## Overview

This guide explains how to configure scheduled backups and identity dumps for validator nodes in CatalyX Blockchain Manager.

Scheduled backups help ensure:

* Faster recovery after failures
* Protection against data loss
* Disaster recovery readiness
* Validator identity preservation

This document covers: validator database backups, validator identity dumps (IDDumps), restore procedures, and backup strategy recommendations.

***

## Backup Types Overview

| Backup Type   | Includes                                           | Does NOT Include                                        | Recommended Usage                           |
| ------------- | -------------------------------------------------- | ------------------------------------------------------- | ------------------------------------------- |
| IDDump        | Cryptographic keys and validator identity material | Database contents, ledger state, transaction history    | Identity recovery and validator restoration |
| PVC/PV Backup | Validator and participant database state           | Cryptographic keys and secrets                          | Stateful workload recovery                  |
| S3 Backup     | Database dumps and snapshots stored externally     | Runtime state and identities unless explicitly exported | Long-term disaster recovery                 |

{% hint style="warning" %}
IDDumps alone cannot restore ledger/database state. Database backups alone cannot restore validator identity. Full disaster recovery requires **both** backup types.
{% endhint %}

***

## Part 1 — Schedule Validator Backups

### Prerequisites

Before enabling scheduled backups:

* Ensure sufficient cluster storage is available
* Verify backup retention requirements
* Confirm the validator is operational

{% hint style="info" %}
If IntellectEU manages the cluster, backup snapshotting may already be enabled. Verify available resources before configuring additional scheduled backups.
{% endhint %}

### Create a Backup Schedule

{% stepper %}
{% step %}

#### Open Validator Backups

Navigate to the **Validators** page, open the target validator, locate the **Backups** section, and click **Schedule**.
{% endstep %}

{% step %}

#### Configure the Schedule

Provide the following settings:

**Cron Expression** — defines how often backups run using standard Unix cron syntax.

| Schedule              | Cron          |
| --------------------- | ------------- |
| Every day at midnight | `0 0 * * *`   |
| Every 6 hours         | `0 */6 * * *` |
| Every Sunday at 02:00 | `0 2 * * 0`   |

**Max Backup Number** — defines how many backups are retained. When the limit is exceeded, older backups are automatically deleted.

* Development: 3–5 backups
* Production: 7–30 backups
  {% endstep %}

{% step %}

#### Confirm the Schedule

Click **Confirm** to activate the backup schedule. Once configured, backups will run automatically and the retention policy will be enforced.
{% endstep %}
{% endstepper %}

### View Existing Backups

To view backup history, navigate to **Validators → Backups → Show history**. The history page displays backup timestamps, status, and available restore actions.

***

## 1.1 Restore Validator from Backup

{% stepper %}
{% step %}

#### Open Backup History

Navigate to **Validators → Backups → Show history**.
{% endstep %}

{% step %}

#### Start the Restore

Open the **Actions** menu for the desired backup and select **Restore**. A restore status indicator will appear showing start time, current progress, and restore status.
{% endstep %}

{% step %}

#### Wait for Completion

When complete, the restore status changes to **Completed**.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
Restoring from a database backup restores database state only. Validator identities and cryptographic material are **not** restored by database backups.
{% endhint %}

***

## Part 2 — Schedule Validator Identity Dumps (IDDumps)

### What is an Identity Dump?

An Identity Dump (IDDump) contains the validator's cryptographic keys, identity material, and validator access credentials.

IDDumps are required to recover validator ownership, restore wallet access, rejoin the network after failures, and recover balances. They do **not** contain database contents, transaction history, or ledger state.

### Configure an Identity Dump Schedule

{% stepper %}
{% step %}

#### Open Identity Backup Settings

Navigate to the **Validator details** page, open the **Management** section, locate **Identity dumps**, and click **Schedule**.
{% endstep %}

{% step %}

#### Configure the Schedule

**Cron Expression** — defines how frequently IDDumps are created. Recommended: daily for production validators, weekly for development environments.

**Max Dump Number** — defines how many IDDumps are retained. Older dumps are automatically removed after reaching the configured limit.

* Production: minimum 14 dumps
* Critical infrastructure: 30+ dumps
  {% endstep %}

{% step %}

#### Activate the Schedule

Click **Confirm**. After configuration, the next scheduled execution time is displayed along with schedule management options.
{% endstep %}
{% endstepper %}

### View Existing Identity Dumps

To list available IDDumps, open **Validator details → Identity Backups → Show list**. The list displays dump names, creation timestamps, and available actions.

***

## 2.1 Restore Validator from Identity Dump

### Important Notes

When restoring a validator:

* Reuse the same validator configuration values
* Keep Keycloak users and clients
* Preserve onboarding secrets
* Use the same party hint and node identifier

The restored validator receives a new participant hash, reuses existing cryptographic keys, and regains access to balances and network identity.

### Restore Procedure

{% stepper %}
{% step %}

#### Create an Identity Dump

Create an IDDump from the existing validator before deletion.
{% endstep %}

{% step %}

#### Delete the Validator Resource

Delete the validator resource only. Do **not** remove Keycloak users, Keycloak clients, or Kubernetes secrets.
{% endstep %}

{% step %}

#### Recreate the Validator

Create the validator again using the same onboarding secret, party hint, node identifier, and migration configuration. Include the following restore configuration:

```json
"participantIdentitiesDumpImport": {
    "identitiesSecretName": "<iddump-secret-name>",
    "newParticipantIdentifier": "<new-identifier>"
},
"migrateValidatorParty": true
```

{% hint style="warning" %}
Disable auto-init during restore and choose a new participant identifier.
{% endhint %}
{% endstep %}
{% endstepper %}

### Verify Successful Restore

After restore, open the validator wallet UI and log in using the existing Keycloak wallet user. Confirm that wallet access works, balances are visible, and the validator is operational.

{% hint style="info" %}
Use an incognito browser session to avoid Keycloak session conflicts with the CatalyX UI.
{% endhint %}

***

## Best Practices

Use **both** scheduled database backups and scheduled identity dumps to ensure complete disaster recovery coverage.

### Recommended Backup Frequency

| Environment | Database Backup | IDDump |
| ----------- | --------------- | ------ |
| Development | Daily           | Weekly |
| Staging     | Every 12h       | Daily  |
| Production  | Every 6h        | Daily  |

### Storage Recommendations

As of **v1.11.7**, backup volume sizing is automatic. The CAT-BM Operator calculates the required backup volume size using the formula:

```
backup volume size = number of backups × database storage size
```

The volume is automatically resized on the next scheduled backup run when the database storage size increases. Note that Kubernetes PVCs can only increase in size — reducing the **Max Backup Number** setting does not shrink the backup volume.

{% hint style="info" %}
If IntellectEU manages your cluster, snapshot-based backup may already be enabled. Verify available storage capacity before configuring additional scheduled backups alongside existing snapshots.
{% endhint %}

Additional recommendations:

* Backup retention should align with your compliance requirements
* Configure off-cluster backup export for disaster recovery
* For production environments, allocate headroom beyond the calculated minimum to account for database growth between backup runs

### Never Force-Delete a Database Pod

Domain, participant, and validator databases run as stateful Kubernetes workloads, each backed by its own storage. Deleting a database pod is sometimes necessary — for maintenance, node draining, or troubleshooting — but how it's done matters.

{% hint style="danger" %}
Never force-delete a database pod (`kubectl delete pod --force --grace-period=0`). A force-delete does not wait for the pod to fully terminate, and a replacement can be scheduled while the original is still shutting down — leaving two processes writing to the same database storage at once. This can corrupt the database, and the damage isn't always visible right away: it can go undetected until the affected data is read.
{% endhint %}

If a pod needs to be removed, delete it normally and allow it to terminate gracefully. If a pod is stuck terminating, contact CatalyX support before forcing removal.

{% content-ref url="/pages/n4QmocInDV7pxmDuH8fz" %}
[Support Center](/support-center)
{% endcontent-ref %}

***

### Reduce Restart-Related Corruption Risk (v1.11.17+)

As of **v1.11.17**, validator, participant, and domain databases can additionally run in a way that guards against the failure mode described above, preventing data corruption during pod restarts or configuration changes — even when a pod isn't cleanly terminated.

This is gated by the `CANTON_OPERATOR_POSTGRES_USESTATEFULSET` environment variable, set under `spec.envVars` (see [Environment Variables](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/validator-custom-resource-definition#environment-variables)).

{% hint style="warning" %}
Enabling this variable triggers a database server restart, incurring roughly 1 minute of downtime.
{% endhint %}

***

### Use an External Database for Production

For production domains, participants, and validators, we recommend configuring an **External** database (see the storage type options on the [Domains](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/domains) and [Participants](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/participants) pages) instead of the in-cluster provisioned PostgreSQL option. An externally managed database service (e.g. AWS RDS) moves durability, backup, and failover responsibility to a managed service, reducing the operational risk of running the database as an in-cluster workload.

***

## Troubleshooting

| Issue                                     | Cause                                                                               | Resolution                                                                                                                                                                                                           |
| ----------------------------------------- | ----------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Restore completes but wallet inaccessible | Missing IDDump                                                                      | Restore identities separately                                                                                                                                                                                        |
| Validator cannot rejoin network           | Wrong participant identifier                                                        | Use correct migration settings                                                                                                                                                                                       |
| Login fails after restore                 | Keycloak users removed                                                              | Preserve original users and clients                                                                                                                                                                                  |
| Backup creation fails                     | Insufficient storage on initial setup, or automatic volume resize not yet triggered | On v1.11.7+, the Operator resizes the backup volume automatically on the next scheduled run. If the issue persists on first setup, ensure sufficient cluster storage is available for the initial volume allocation. |
| Database pod stuck terminating            | Pod not fully released before a replacement is scheduled                            | Do not force-delete (`--force --grace-period=0`) — this risks two processes writing to the same storage. Wait for graceful termination, or contact CatalyX support.                                                  |


# Data Retention & Pruning Policy

How CatalyX Blockchain Manager handles data retention, ledger pruning, and backup strategy for validator and participant infrastructure.

## Overview

CatalyX Blockchain Manager provides automated backup, recovery, data retention, and pruning capabilities to help organizations protect their blockchain infrastructure, optimize storage usage, and meet operational and regulatory requirements.

These capabilities are designed to:

* Protect validator and participant data through scheduled backups
* Preserve validator identities and cryptographic material
* Enable disaster recovery
* Optimize storage by removing obsolete data
* Maintain security and audit logs
* Support enterprise data lifecycle management

Although these concepts are closely related, they serve different purposes:

| Feature            | Purpose                                                                |
| ------------------ | ---------------------------------------------------------------------- |
| **Data Retention** | Defines how long operational logs and audit information are preserved. |
| **Backups**        | Protect validator and ledger data for recovery.                        |
| **Identity Dumps** | Preserve validator identities and cryptographic material.              |
| **Pruning**        | Removes obsolete ledger data that is no longer required.               |

{% hint style="warning" %}
A complete disaster recovery strategy requires **both** scheduled database backups and scheduled Identity Dumps (IDDumps). These backup types protect different components of a validator and cannot replace one another.
{% endhint %}

***

## Data Retention

### Security and Audit Logging

CatalyX Blockchain Manager centralizes security and operational logs using Azure Log Analytics.

Default log retention periods:

| Environment          | Log Retention |
| -------------------- | ------------- |
| Mainnet (Production) | 30 days       |
| Devnet / Testnet     | 7 days        |

These logs support:

* Security investigations
* Operational troubleshooting
* Compliance audits
* Incident response
* Infrastructure monitoring

The centralized logging solution includes:

* Azure Activity Logs
* Kubernetes audit logs
* Kubernetes API server logs
* PostgreSQL audit logs (pgaudit)
* Network flow logs
* Microsoft Sentinel integration
* Microsoft Defender integration

### Infrastructure Audit Trail

CatalyX Blockchain Manager maintains an audit trail for infrastructure and operational activities, including:

* Resource creation and deletion
* Infrastructure configuration changes
* Azure role assignments
* Policy modifications
* Kubernetes API activity
* Database authentication
* Database query execution

This information supports operational monitoring, forensic investigations, and compliance reporting.

***

## Backup Strategy

Scheduled backups and Identity Dumps are the foundation of CatalyX's disaster recovery approach for validator infrastructure.

| Backup Type                                             | Includes                                                             | Does Not Include                                        | Recommended Usage           |
| ------------------------------------------------------- | -------------------------------------------------------------------- | ------------------------------------------------------- | --------------------------- |
| Identity Dump (IDDump)                                  | Validator cryptographic keys, validator identity, wallet credentials | Database contents, ledger state, transaction history    | Validator identity recovery |
| Database Backup (PVC/PV Backup)                         | Validator database, participant database, ledger state               | Validator identities and cryptographic keys             | Operational recovery        |
| External Storage Backup (S3 or other supported storage) | Database dumps and snapshots                                         | Runtime state and identities unless explicitly exported | Long-term disaster recovery |

{% hint style="info" %}
For scheduling database backups and Identity Dumps, viewing backup history, and restoring a validator, see [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery). That page covers the full configuration and restore workflow — this page focuses on retention strategy, pruning, and compliance considerations.
{% endhint %}

### Recommended Backup Schedule

| Environment | Database Backup | Identity Dump |
| ----------- | --------------- | ------------- |
| Development | Daily           | Weekly        |
| Staging     | Every 12 hours  | Daily         |
| Production  | Every 6 hours   | Daily         |

Recommended retention values are documented in [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery#best-practices). Organizations should ultimately configure retention according to their own operational and compliance requirements.

***

## Pruning

### What is Pruning?

Pruning permanently removes obsolete ledger data that is no longer required for normal ledger operation.

Unlike backups, pruning is intended to optimize storage rather than provide recovery.

Pruning helps:

* Reduce database size
* Improve storage efficiency
* Remove obsolete ledger history
* Support organizational data lifecycle policies
* Assist with regulatory requirements such as GDPR "right to erasure," where applicable

{% hint style="info" %}
Pruning does not affect active ledger state.
{% endhint %}

### Supported Pruning Types

CatalyX Blockchain Manager supports scheduled pruning for:

* Domain nodes
* Participant nodes

{% hint style="warning" %}
Pruning is supported only for Enterprise deployments using PostgreSQL.
{% endhint %}

### Configuring Pruning

Pruning schedules are configured directly from the **Domain** or **Participant** management pages (see [Domains](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/domains) and [Participants](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/participants)).

| Parameter        | Description                                                              |
| ---------------- | ------------------------------------------------------------------------ |
| Cron Expression  | Defines how frequently pruning is executed                               |
| Retention Time   | Specifies how long data is retained before becoming eligible for pruning |
| Maximum Duration | Maximum execution time allowed for a pruning operation                   |

Example configuration (for demonstration purposes only — production environments should set retention according to operational and regulatory requirements):

| Setting          | Example Value |
| ---------------- | ------------- |
| Cron Expression  | `*/1 * * * *` |
| Retention Time   | `1 second`    |
| Maximum Duration | `20 seconds`  |

The same schedule can also be set at the CRD level. See [Validator CRD User Guide](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/validator-crd-user-guide) for the `scheduledPrune` spec fields.

### Monitoring Pruning

After configuring a pruning schedule:

1. Wait for the scheduled execution.
2. Refresh the Pruning Schedule page.
3. Verify that pruning completed successfully.

The UI displays:

* Last execution
* Pruning status
* Pruned records

### Backup Pruning vs. Ledger Pruning

These are different operations and should not be confused.

| Backup Pruning                         | Ledger Pruning                   |
| -------------------------------------- | -------------------------------- |
| Removes old backup files               | Removes obsolete ledger data     |
| Controlled by backup retention setting | Controlled by pruning schedule   |
| Frees backup storage                   | Reduces database size            |
| Does not affect ledger state           | Does not affect active contracts |

***

## Best Practices

For production deployments, IntellectEU recommends:

* Schedule regular automated database backups.
* Schedule regular Identity Dumps.
* Store backups in external storage whenever possible.
* Periodically validate restore procedures.
* Configure pruning only after defining a suitable retention policy.
* Monitor scheduled backup and pruning jobs.
* Review backup retention periodically to balance recovery objectives and storage utilization.

***

## Compliance Considerations

CatalyX Blockchain Manager provides capabilities that support organizational compliance requirements through:

* Configurable backup retention
* Scheduled pruning
* Security logging
* Infrastructure audit trails
* Validator identity preservation
* Disaster recovery mechanisms

{% hint style="warning" %}
Organizations remain responsible for defining retention policies that satisfy their own regulatory and business requirements.
{% endhint %}

***

## Frequently Asked Questions

<details>

<summary>What is the difference between a Database Backup and an Identity Dump?</summary>

A Database Backup protects the validator database and ledger state. An Identity Dump protects validator identity, cryptographic keys, and wallet credentials. Both are required for complete disaster recovery.

</details>

<details>

<summary>How long are security logs retained?</summary>

Mainnet (Production): 30 days. Devnet/Testnet: 7 days.

</details>

<details>

<summary>Can I configure pruning schedules?</summary>

Yes. Pruning schedules allow administrators to define the execution schedule, retention period, and maximum execution duration, either from the Domain/Participant management pages or via the CRD.

</details>

<details>

<summary>Does pruning delete active ledger data?</summary>

No. Pruning removes only obsolete ledger data that is no longer required for normal ledger operation.

</details>

<details>

<summary>Does pruning affect backups?</summary>

No. Ledger pruning and backup retention are independent features.

</details>

<details>

<summary>Can I restore a validator using only an Identity Dump, or only a database backup?</summary>

No, in either case. Identity Dumps restore validator identity only — database state must be restored separately. Database backups restore ledger state but do not restore validator identity, cryptographic keys, or wallet credentials. See [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery) for the full restore procedure.

</details>

<details>

<summary>Does pruning require downtime?</summary>

Pruning is designed as a scheduled maintenance operation and does not require planned validator downtime under normal operating conditions.

</details>


# DAR management

How to upload and deploy DAR files in CatalyX Blockchain Manager.

## Overview

DAR (DAML Archive) files contain compiled DAML application packages. They must be uploaded to a participant before any DAML templates or ledger workflows from that package can be used.

DAR files are required to:

* deploy DAML applications
* enable ledger workflows
* install application templates on participants
* support CPM, billing, Tradecraft, and other Canton applications

DAR files use the `.dar` extension. Examples: `cpm-<version>.dar`, `ieu-billing-<version>.dar`, `canton-swap-<version>.dar`.

***

## Upload Flow Overview

Uploading a DAR in CatalyX is typically a two-step process:

| Step       | Description                                      |
| ---------- | ------------------------------------------------ |
| **Step 1** | Upload the DAR to Collections                    |
| **Step 2** | Deploy the DAR from Collections to a Participant |

Storing DARs in Collections first allows packages to be reused across multiple participants and environments without re-uploading the source file each time.

{% hint style="info" %}
You can also upload a DAR directly to a participant without going through Collections. See [Part 2](#part-2--upload-dar-directly-to-a-participant) below.
{% endhint %}

***

## Part 1 — Upload DAR to Collections

Collections are reusable artifact repositories inside CatalyX. They support both DAR packages and UI packages. Once uploaded, a DAR in Collections can be deployed to any participant or referenced by applications.

{% hint style="info" %}
For a full overview of Collections, see the [Collections](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/collections) page.
{% endhint %}

{% stepper %}
{% step %}
**Navigate to Collections**

Open CatalyX Blockchain Manager and navigate to **Collections** from the left navigation menu. The page contains two sections: **DAR Collections** and **UI Collections**.
{% endstep %}

{% step %}
**Open the Upload Dialog**

In the **DAR Collections** section, click **Upload DAR File**.
{% endstep %}

{% step %}
**Select the DAR File**

Choose the `.dar` file from your local machine (e.g. `cpm-0.2.1.dar`, `ieu-billing-1.0.0.dar`).
{% endstep %}

{% step %}
**Confirm the Upload**

After upload, the DAR appears in the DAR Collections table with the following details:

* Package name
* File size
* Available actions: **Deploy**, **Download**, **Remove**

The package is now available for deployment to any participant.
{% endstep %}
{% endstepper %}

***

## Part 2 — Upload DAR to a Participant

{% stepper %}
{% step %}
**Navigate to the Participant**

Open **Participants** from the left navigation and select the target participant.
{% endstep %}

{% step %}
**Open the DARs Tab**

Inside the participant details page, open the **DARs** tab and click **Upload DAR**.
{% endstep %}

{% step %}
**Select DAR Files**

Choose one or multiple `.dar` files. Multi-file upload is supported.

After upload:

* The package appears in the participant DARs list
* The package hash becomes visible
* DAML templates from the package become available on the ledger
  {% endstep %}
  {% endstepper %}

***

## UI Package Uploads

UI packages provide frontend applications exposed through HTTPS. They are uploaded to **Collections → UI Collections** separately from DAR files.

UI packages must:

* be uploaded as `.zip` files
* contain a single root directory
* include an `index.html` at the root

{% stepper %}
{% step %}
**Navigate to UI Collections**

Go to **Collections → UI Collections**.
{% endstep %}

{% step %}
**Upload the UI File**

Click **Upload UI File** and select the `.zip` package.

After upload, the package appears in UI Collections and becomes available for deployment.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
For a full overview of UI Collections and how to deploy UI packages as applications, see the [Collections](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/collections) page.
{% endhint %}

***

## Application-Specific DAR Deployments

### CPM

{% stepper %}
{% step %}
Download `cpm-${version}.dar`
{% endstep %}

{% step %}
Upload the DAR to the target participant
{% endstep %}

{% step %}
Verify the DAR is visible in the participant DAR list
{% endstep %}
{% endstepper %}

### Billing Subscriber

{% stepper %}
{% step %}
Download `ieu-billing-${version}.dar`
{% endstep %}

{% step %}
Upload the DAR to the target participant
{% endstep %}

{% step %}
Confirm deployment completed successfully
{% endstep %}
{% endstepper %}

### Tradecraft (CantonSwap)

{% stepper %}
{% step %}
Download `canton-swap-${version}.dar`
{% endstep %}

{% step %}
Upload the DAR to the participant
{% endstep %}

{% step %}
Verify the package is visible in the DAR list
{% endstep %}
{% endstepper %}

***

## Verification Checklist

| Validation                      | Expected Result                          |
| ------------------------------- | ---------------------------------------- |
| DAR visible in Collections      | Package appears in DAR Collections table |
| DAR uploaded to participant     | Package visible under Participant DARs   |
| Package hash generated          | Hash visible in DAR list                 |
| Application templates available | DAML workflows accessible on the ledger  |
| No upload errors                | Upload completed without errors          |

***

## Troubleshooting

| Issue                              | Cause                                                           | Resolution                                                     |
| ---------------------------------- | --------------------------------------------------------------- | -------------------------------------------------------------- |
| DAR upload fails                   | Invalid file format                                             | Verify the file uses the `.dar` extension                      |
| DAR not visible on participant     | Upload incomplete or failed                                     | Re-upload the package                                          |
| Templates unavailable after upload | Package uploaded to Collections but not deployed to participant | Upload the DAR to the participant (Part 2)                     |
| UI deployment fails                | Invalid ZIP structure                                           | Ensure the ZIP contains a single root folder with `index.html` |
| Upload button disabled             | Insufficient permissions                                        | Verify your user has the required access rights                |

***

## Best Practices

* Store reusable DARs in Collections so they can be deployed to multiple participants without re-uploading
* Use versioned naming conventions (e.g. `cpm-0.2.1.dar`) to distinguish package versions
* Keep older package versions in Collections for rollback purposes
* Verify package hashes after deployment
* Upload all required DARs before deploying dependent applications
* Keep production and development packages separate


# Validator Custom Resource Definition

This page provides an overview of the Validator Custom Resource Definition (CRD) used by Catalyst Blockchain Manager to deploy and manage Canton validators using Kubernetes. It describes the structure of the CRD and explains how each validator component is defined and configured.

{% hint style="info" %}
A Custom Resource Definition (CRD) in Kubernetes is a way to extend the Kubernetes API by defining new, custom object types, allowing you to manage application-specific data.
{% endhint %}

### Structure of the Specification

The CRD specification defines each validator component separately.

| Component            | CRD Location                            |
| -------------------- | --------------------------------------- |
| **Validator** (core) | Top level of the specification          |
| **ANS/CNS UI**       | `spec.applicationCantonNameServer.spec` |
| **Wallet UI**        | `spec.walletUI.spec`                    |
| **Participant Node** | `spec.participant.spec`                 |

#### Provisioned Postgres Database

The PostgreSQL database provisioned for the validator is not explicitly represented in the CRD specification. To increase the database storage size (decreases are ignored), use:

```
spec.storageSize
```

### Modifying Component Specifications

#### Environment Variables

For all components, environment variables are defined under `spec.envVars`. They follow the same structure and format used in Kubernetes Pods and Deployments.

#### Resources

Each component has a resource specification:

```yaml
resources:
    cpuLimit: '2'
    cpuRequested: '1'
    imagePullSecret: intellecteu-gitlab-access
    memoryLimit: 2Gi
    memoryRequested: 1Gi
    replicas: 1
```

| Field             | Description                                    |
| ----------------- | ---------------------------------------------- |
| `cpuLimit`        | Maximum CPU allocation                         |
| `cpuRequested`    | Minimum CPU allocation                         |
| `memoryLimit`     | Maximum memory allocation                      |
| `memoryRequested` | Minimum memory allocation                      |
| `replicas`        | Number of instances (can be set to `0` or `1`) |

To scale down a validator, set the `replicas` field to `0` for all components.

### Example CRD

<details>

<summary>Full example Validator CRD YAML</summary>

```yaml
apiVersion: catalyst.manager.canton/v1
kind: Validator
metadata:
  name: validator1st
  namespace: canton-dev
spec:
  application:
    spec:
      domain: participant-validator1st
      resources:
        cpuLimit: '2'
        cpuRequested: '1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 2Gi
        memoryRequested: 1Gi
        replicas: 1
      type: backend
      validatorParent: validator1st
  applicationCantonNameServer:
    spec:
      domain: cns-validator1st
      image: >-
        digitalasset-canton-network-docker.jfrog.io/digitalasset/ans-web-ui:0.3.15
      resources:
        cpuLimit: '1'
        cpuRequested: '0.1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 1536Mi
        memoryRequested: 240Mi
        replicas: 1
      type: ui
  applicationWallet:
    spec:
      domain: wallet-validator1st
      image: >-
        digitalasset-canton-network-docker.jfrog.io/digitalasset/wallet-web-ui:0.3.15
      resources:
        cpuLimit: '1'
        cpuRequested: '0.1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 1536Mi
        memoryRequested: 240Mi
        replicas: 1
      type: ui
  customAuth: false
  disabledWallet: false
  enableKms: false            # master flag for KMS; the KMS fields live under participant.spec
  image: digitalasset-canton-network-docker.jfrog.io/digitalasset/validator-app:0.3.15
  imageRepo: digitalasset-canton-network-docker.jfrog.io/digitalasset
  imageTag: 0.3.15
  migrationId: '0'
  migrationMigrating: false
  participant:
    spec:
      adminPort: '5002'
      auth: true
      authProvider: keycloak
      image: >-
        digitalasset-canton-network-docker.jfrog.io/digitalasset/canton-participant:0.3.15
      jsonapi: false
      ledgerPort: '5001'
      # --- KMS (only applied when spec.enableKms is true) ---
      serviceAccount: catbm-aws-kms          # AWS/GCP: K8s ServiceAccount (IRSA / workload identity)
      kmsValue: '{ type = "aws", region = "eu-west-1", audit-logging = true }'   # HOCON provider config
      kmsAzureVaultSecretName: ''            # Azure only: K8s Secret with tenant-id, client-id, client-secret
      overrideImage: ''                      # Azure only: Azure-KMS driver participant image (matches splice image)
      logLevel: INFO
      resources:
        cpuLimit: '2'
        cpuRequested: '1'
        imagePullSecret: intellecteu-gitlab-access   # Azure KMS: set to pull secret for the override (driver) image
        memoryLimit: 2Gi
        memoryRequested: 1Gi
        replicas: 1
      storageType: Shared Postgres
  resources:
    cpuLimit: '2'
    cpuRequested: '1'
    imagePullSecret: intellecteu-gitlab-access
    memoryLimit: 2Gi
    memoryRequested: 1Gi
    replicas: 1
  storageSize: 20Gi
```

</details>

### KMS Fields

The following fields control KMS for a validator. `enableKms` is immutable after creation; all other KMS fields are also immutable **except `overrideImage`**, which remains editable.

| Field                                        | Location                          | Notes                                                                  |
| -------------------------------------------- | --------------------------------- | ---------------------------------------------------------------------- |
| `enableKms`                                  | `spec`                            | Master flag; immutable after creation                                  |
| `participant.spec.kmsValue`                  | `spec.participant.spec`           | HOCON provider config (AWS / GCP / Azure)                              |
| `participant.spec.serviceAccount`            | `spec.participant.spec`           | AWS/GCP ServiceAccount; not used for Azure                             |
| `participant.spec.kmsAzureVaultSecretName`   | `spec.participant.spec`           | Azure only; Secret with `tenant-id` / `client-id` / `client-secret`    |
| `participant.spec.overrideImage`             | `spec.participant.spec`           | Azure driver image; the only KMS-adjacent field editable post-creation |
| `participant.spec.resources.imagePullSecret` | `spec.participant.spec.resources` | Azure only; pull secret for the override (driver) image                |

When `enableKms` is `true`: `kmsValue` is required, plus either `serviceAccount` (AWS/GCP) or `kmsAzureVaultSecretName` (Azure).

***


# Validator CRD User Guide

Catalyst uses the operator pattern with Custom Resource Definitions. The same operations available in the Catalyst GUI can also be performed directly on Kubernetes with access to the cluster.

### Creating a Validator

<details>

<summary>Full creation example (Kubernetes YAML)</summary>

```yaml
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: database-validator-dev-foo
data:
  user: "YWRtaW4="
  password: "YWRtaW4="
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-onboarding-validator
data:
  secret: "<onboarding-secret-base64>"
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-cns-ui-auth
data:
  url: "<keycloak-url-base64>"
  clientId: "<cns-client-id-base64>"
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-wallet-ui-auth
data:
  url: "<keycloak-url-base64>"
  clientId: "<wallet-client-id-base64>"
  username: "<wallet-username-base64>"
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-ledger-api-auth
data:
  client-id: "<client-id-base64>"
  client-secret: "<client-secret-base64>"
  ledger-api-user: "<ledger-api-user-base64>"
  url: "<token-url-base64>"
---
apiVersion: catalyst.manager.canton/v1
kind: Validator
metadata:
  name: validator-dev-foo
  namespace: canton-dev
spec:
  config:
    scanAddress: "https://scan.sv-1.dev.global.canton.network.sync.global"
    svSponsorAddress: "https://sv.sv-1.dev.global.canton.network.sync.global"
    defaultJvmOptions: "-Xms1152M -Xmx1152M -Dscala.concurrent.context.minThreads=4"
    partyHint: ieu-foo-001
    failOnAppVersionMismatch: true
    database:
      port: 5432
      pwdField: password
      schema: validator
      secretName: database-validator-dev-foo
      userField: user
    participant:
      nodeIdentifier: IEUDevFoo001
  customAuth: true
  imageRepo: ghcr.io/digital-asset/decentralized-canton-sync/docker
  imageTag: 0.4.16
  migrationId: "0"
  migrationMigrating: false
  onboardingSecretName: cn-app-validator-dev-foo-onboarding-validator
  storageSize: 20Gi
```

</details>

{% hint style="info" %}
**Key notes when creating a validator:**

* The onboarding secret is one-time use.
* The validator name, participant identifier, and party hint should be changed when deploying a new validator.
* Secrets (names and fields) are referenced inside the Validator definition itself — keep them in-sync.
* Some data is provided as part of the reference itself (e.g., `port`, `schema`), not as a secret field.
  {% endhint %}

### Validator Operations

#### Migration

The following fields are used in migration:

```yaml
spec:
  migrationId: "2"
  migrationMigrating: false
```

To migrate, set the values as follows:

```yaml
spec:
  migrationId: "new mig id"
  migrationMigrating: true
```

Once the migration is complete, set `migrationMigrating` back to `false`.

#### Recovery from Identity Dump

To recover Canton Coin balances using an Identities Backup, create a Kubernetes secret in the following format:

```yaml
apiVersion: v1
data:
  content: <Identity Backup>
kind: Secret
metadata:
  labels:
    validator: <validator crd name>
  name: id-backup-secret-example
  namespace: namespace-of-val
type: Opaque
```

Then create a validator (removing the old one if on the same cluster) with the following fields added to `spec`:

```yaml
spec:
  config:
    partyHint: "oldParty"
    participant:
      nodeIdentifier: "validator-foooooooo"
    identitiesImport:
      newParticipantIdentifier: "validator-foooooooo"
      secretName: "secret-with-identity-dump-party"
    isMigrateValidatorParty: true
```

{% hint style="warning" %}
The participant should have the same node identifier as the `newParticipantIdentifier` field, which must differ from the previous validator.
{% endhint %}

### Configuring the Validator

#### Environment Variable Overrides

To add extra environment variables:

```yaml
spec:
  config:
    validatorOverrides:
      - name: OVERRIDE_EXAMPLE
        value: "5432"
    participantOverrides: []
    walletOverrides:
      - name: OVERRIDE_WITH_SECRET
        valueFrom:
          secretKeyRef:
            key: password
            name: secret
    cnsOverrides: []
```

{% hint style="info" %}
These overrides will **override** any variables generated by the `spec.config`. In older versions, environment variables were defined directly in `application.spec.envVars`, `applicationWallet.spec.envVars`, etc. On upgrade to v1.10, a script generates the `spec.config` fields from these. The `<app>.spec.envVars` format will be removed in a future release.
{% endhint %}

#### Resource Customization

```yaml
spec:
  application:
    spec:
      resources:
        cpuLimit: "4"
        cpuRequested: "2"
        memoryLimit: 8Gi
        memoryRequested: 4Gi
        replicas: 1
  applicationCantonNameServer:
    spec:
      resources:
        cpuLimit: "2"
        cpuRequested: "0.5"
        memoryLimit: 2Gi
        memoryRequested: 512Mi
        replicas: 1
  applicationWallet:
    spec:
      resources:
        cpuLimit: "2"
        cpuRequested: "0.5"
        memoryLimit: 2Gi
        memoryRequested: 512Mi
        replicas: 1
  participant:
    spec:
      resources:
        cpuLimit: "4"
        cpuRequested: "2"
        memoryLimit: 8Gi
        memoryRequested: 4Gi
        replicas: 1
  storageSize: 50Gi
```

#### Other Configuration Examples

<details>

<summary>Enable top-up</summary>

```yaml
spec:
  config:
    topUp:
      enabled: true
      minInterval: 2m
      targetThroughput: 80000
```

</details>

<details>

<summary>Enable scheduled pruning</summary>

```yaml
spec:
  config:
    scheduledPrune:
      retention: "2m"
      cron: "* * * * *"
      maxDuration: "30d"
```

</details>

<details>

<summary>Provide additional config</summary>

```yaml
spec:
  config:
    additionalConfigOther: |
      canton.validator-apps.validator_backend.participant-bootstrapping-dump {
        type = file
        file = /participant-bootstrapping-dump/content
        new-participant-identifier = "validator-fooooooo"
      }
```

</details>

<details>

<summary>Set contact point</summary>

```yaml
spec:
  config:
    contactPoint: "mycompany@mail.com"
```

</details>

***

## KMS

KMS is set at creation via `spec.enableKms` plus fields on the participant spec. It cannot be toggled on or off after creation.

### AWS / GCP

{% tabs %}
{% tab title="AWS" %}

```yaml
spec:
  enableKms: true
  participant:
    spec:
      serviceAccount: catbm-aws-kms
      kmsValue: '{ type = "aws", region = "eu-west-1", audit-logging = true }'
```

{% endtab %}

{% tab title="GCP" %}

```yaml
spec:
  enableKms: true
  participant:
    spec:
      serviceAccount: catbm-gcp-kms
      kmsValue: '{ type = "gcp", project-id = "my-project" }'
```

{% endtab %}
{% endtabs %}

### Azure

```yaml
spec:
  enableKms: true
  participant:
    spec:
      overrideImage: <azure-kms-driver participant image, matching the splice image>
      resources:
        imagePullSecret: azure-kms-registry-credentials
      kmsValue: '{ type = driver, name = "azure-kms", config { vault-url = "...", credential { type = environment } } }'
      kmsAzureVaultSecretName: azure-kms-credentials
```

The secret named by `kmsAzureVaultSecretName` must contain: `tenant-id`, `client-id`, `client-secret`.

### API-to-CRD field mapping

The REST API nests these under `clusterParticipantConfig`:

| API field                               | CRD path                                          |
| --------------------------------------- | ------------------------------------------------- |
| `enableKms`                             | `spec.enableKms`                                  |
| `kmsValue`                              | `spec.participant.spec.kmsValue`                  |
| `kmsServiceAccount`                     | `spec.participant.spec.serviceAccount`            |
| `kmsAzureVaultSecretName`               | `spec.participant.spec.kmsAzureVaultSecretName`   |
| `overrideImage`                         | `spec.participant.spec.overrideImage`             |
| `participant.resources.imagePullSecret` | `spec.participant.spec.resources.imagePullSecret` |

***


# Key Management Service (KMS)

How to enable KMS-backed key management for Canton Validator Participant nodes using IRSA (IAM Roles for Service Accounts).

CatalyX Blockchain Manager supports External Key Management Services (KMS) for storing Canton Validator Participant cryptographic keys. When KMS is enabled, participant keys are stored and managed in an external KMS rather than locally on the node, improving key security and enabling compliance with enterprise key management policies.

For background on why KMS matters, the two Canton key storage modes (encrypted vs. external), and the broader key management and wallet strategy for CAT-BM, see the Security & Privacy Implementation page:

{% content-ref url="/pages/bvHLoRkGDY6yVqcoe4i9" %}
[Broken mention](broken://pages/bvHLoRkGDY6yVqcoe4i9)
{% endcontent-ref %}

{% hint style="info" %}
KMS integration was introduced in **v1.11.8** as a Phase 1, environment-level toggle. As of **v1.11.11**, KMS is configured **per validator** — each validator can be created with its own KMS provider configuration and ServiceAccount, independently of other validators in the same environment. The Azure KMS driver was added in **v1.11.13**, and Azure authentication via AKS Workload Identity (cross-tenant) was added in **v1.11.15**.
{% endhint %}

{% hint style="warning" %}
KMS is now selected at **validator creation time** in the console (or via the API). It cannot be toggled on or off for an existing validator through the edit wizard. The environment-level Operator settings still exist, but they are no longer a master switch — they now only support migration of pre-v1.11.11 validators. See [Operator Settings (Legacy Migration Only)](#operator-settings-legacy-migration-only) below.
{% endhint %}

***

## What Changed in v1.11.11

| Aspect              | Phase 1 (v1.11.8)                                              | Per-validator (v1.11.11)                                                                                                                  |
| ------------------- | -------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| Scope               | Environment-wide — applied to **all** newly created validators | **Per validator** — chosen individually at creation time                                                                                  |
| How it is enabled   | `CANTON_TOPOLOGY_KMS_ENABLED=true` on the Operator             | `enableKms` flag in the validator create request / console create flow                                                                    |
| KMS provider config | Single global `CANTON_TOPOLOGY_KMS_VALUE` for everyone         | Per-validator `kmsValue` (falls back to the Operator default if omitted)                                                                  |
| ServiceAccount      | Single global `CANTON_TOPOLOGY_KMS_SERVICE_ACCOUNT`            | Per-validator `kmsServiceAccount` (falls back to the Operator default if omitted)                                                         |
| Changing the toggle | Required redeploying the Operator                              | No redeploy — set per validator at create time                                                                                            |
| Existing validators | Retained their original config                                 | Legacy KMS validators are auto-migrated on first reconcile (see [Backward Compatibility](#backward-compatibility-with-legacy-validators)) |

The Phase 1 global auto-enable flag (`CANTON_TOPOLOGY_KMS_ENABLED`) has been **retired**. KMS is no longer turned on by an environment variable; it is driven entirely by the per-validator request.

***

## How It Works

When a validator is created with KMS enabled, the CAT-BM Operator injects additional Canton crypto configuration into that validator's Participant pod at provisioning time. The Participant authenticates with the external KMS using IRSA — an IAM Role is associated with a Kubernetes ServiceAccount, and that ServiceAccount is assigned to the Participant pod.

The ServiceAccount is **externally managed**. It must be created and maintained outside of CAT-BM, and its name is provided per validator (or via the Operator default).

Each validator carries its own KMS settings on its spec:

* `enableKms` — whether this validator uses KMS
* `kmsValue` — the Canton KMS provider configuration fragment for this validator
* `kmsServiceAccount` — the externally managed ServiceAccount this validator's Participant pod runs under

Validators created without KMS are unaffected and continue to run under the `default` ServiceAccount with no KMS crypto config injected.

***

## Prerequisites

Before enabling KMS for a validator, ensure the following are in place:

* An external KMS key created in the appropriate region/project (e.g. AWS KMS, GCP KMS)
* An IAM Role configured with permissions to use the KMS key
* A Kubernetes ServiceAccount created in the validator namespace with the IAM Role ARN annotated via IRSA:

```yaml
apiVersion: v1
kind: ServiceAccount
metadata:
  name: catalyst-canton-kms
  namespace: <validator-namespace>
  annotations:
    eks.amazonaws.com/role-arn: <iam-role-arn>
```

* The ServiceAccount name and the KMS provider configuration available to supply in the create request

***

## Enabling KMS for a Validator

KMS is enabled per validator at creation time. In the **Create Validator** flow, the participant configuration accepts three fields:

| Field               | Description                                                                                                       |
| ------------------- | ----------------------------------------------------------------------------------------------------------------- |
| `enableKms`         | Set to `true` to store this validator's participant keys in an external KMS. Default: `false`.                    |
| `kmsValue`          | The KMS provider configuration in Canton config format (see below). Required when `enableKms` is true.            |
| `kmsServiceAccount` | The externally managed Kubernetes ServiceAccount used for IRSA authentication. Required when `enableKms` is true. |

### Request body (API)

These fields live under `clusterParticipantConfig` in the create-validator request. There are two modes, distinguished by which field you supply:

* **AWS / GCP** — use `kmsServiceAccount`
* **Azure (vault secret)** — use `kmsAzureVaultSecretName` (plus `overrideImage`)
* **Azure (AKS Workload Identity, cross-tenant)** — use `kmsAzureWorkloadIdentity: true` with `kmsServiceAccount` instead of a vault secret (see [AKS Workload Identity (Cross-Tenant)](#aks-workload-identity-cross-tenant) below)

`clusterParticipantConfig` KMS fields:

| Field                      | Type    | Description                                                                           |
| -------------------------- | ------- | ------------------------------------------------------------------------------------- |
| `enableKms`                | boolean | Master flag — turns KMS on for this validator                                         |
| `kmsValue`                 | string  | HOCON provider config (see Provider Examples below)                                   |
| `kmsServiceAccount`        | string  | K8s ServiceAccount — for AWS/GCP IRSA, or for Azure when using Workload Identity      |
| `kmsAzureVaultSecretName`  | string  | K8s Secret holding Azure credentials (Azure vault-secret mode only)                   |
| `kmsAzureWorkloadIdentity` | boolean | Use AKS Workload Identity instead of a vault secret for Azure KMS auth (cross-tenant) |
| `overrideImage`            | string  | Participant image override (required for Azure driver image)                          |

Azure also needs a pull secret for `overrideImage`, set elsewhere in the request body:

| Field                                   | Description                                     |
| --------------------------------------- | ----------------------------------------------- |
| `participant.resources.imagePullSecret` | Pull secret for the override image (Azure only) |

AWS example:

```json
{
  "clusterParticipantConfig": {
    "nodeIdentifier": "my-validator-01",
    "enableKms": true,
    "kmsValue": "{ type = \"aws\", region = \"eu-west-1\", audit-logging = true }",
    "kmsServiceAccount": "catalyst-canton-kms"
  }
}
```

### `kmsValue` format

`kmsValue` takes a Canton configuration fragment. Because it is passed through verbatim, any Canton-supported KMS provider can be used.

AWS KMS:

```
{ type = "aws", region = "eu-west-1", audit-logging = true }
```

GCP KMS:

```
{ type = "gcp", project-id = "my-project" }
```

Azure KMS (driver-based):

```
{ type = driver, name = "azure-kms", config { vault-url = "https://<your-vault>.vault.azure.net", credential { type = environment } } }
```

Azure additionally requires:

* `kmsAzureVaultSecretName`: a K8s Secret containing fields `tenant-id`, `client-id`, `client-secret`
* `overrideImage`: an Azure-KMS-enabled participant image that matches the splice image used by the validator's other apps
* A pull secret for that image, set under `participant.resources.imagePullSecret`

Azure example request:

```json
{
  "clusterParticipantConfig": {
    "nodeIdentifier": "my-validator-01",
    "enableKms": true,
    "kmsValue": "{ type = driver, name = \"azure-kms\", config { vault-url = \"https://my-vault.vault.azure.net\", credential { type = environment } } }",
    "kmsAzureVaultSecretName": "azure-kms-credentials",
    "overrideImage": "registry.gitlab.com/.../canton-azure-kms-driver:latest"
  },
  "participant": {
    "resources": {
      "imagePullSecret": "azure-kms-registry-credentials"
    }
  }
}
```

Adjust the provider settings to match your KMS key. For AWS, set `audit-logging = true` to enable KMS API audit logs (recommended for production).

### AKS Workload Identity (Cross-Tenant)

{% hint style="info" %}
Introduced in **v1.11.15**. This is an alternative to the vault-secret Azure flow above — it removes the need for a `client-secret` stored in a Kubernetes Secret.
{% endhint %}

AKS supports [cross-tenant Workload Identity](https://learn.microsoft.com/en-us/azure/aks/workload-identity-cross-tenant), which lets a validator authenticate to an Azure Key Vault that lives in a **different tenant** than the AKS cluster:

* The AKS cluster runs in **Tenant A** (the CAT-BM cluster).
* The Azure Key Vault and managed identity live in **Tenant B** (the customer's tenant).
* A Kubernetes `ServiceAccount` annotated with `azure.workload.identity/client-id` binds the Participant pod to a managed identity in Tenant B via a federated OIDC credential — no `client-secret` required.
* The Participant pod (not the Deployment) must carry the label `azure.workload.identity/use: "true"` so the AKS Workload Identity mutating webhook fires.
* The webhook automatically injects `AZURE_CLIENT_ID`, `AZURE_TENANT_ID`, `AZURE_FEDERATED_TOKEN_FILE`, and `AZURE_AUTHORITY_HOST` into the pod from the ServiceAccount's annotations.
* The Azure KMS driver picks these up automatically via `credential { type = default }` (`DefaultAzureCredential`) — no driver changes are needed.

To use this mode, set `kmsAzureWorkloadIdentity: true` and supply `kmsServiceAccount` (the externally managed ServiceAccount bound to the Tenant B identity) instead of `kmsAzureVaultSecretName`:

```json
{
  "clusterParticipantConfig": {
    "nodeIdentifier": "my-validator-01",
    "enableKms": true,
    "kmsValue": "{ type = driver, name = \"azure-kms\", config { vault-url = \"https://my-vault.vault.azure.net\", credential { type = default } } }",
    "kmsAzureWorkloadIdentity": true,
    "kmsServiceAccount": "catalyst-azure-workload-identity",
    "overrideImage": "registry.gitlab.com/.../canton-azure-kms-driver:latest"
  },
  "participant": {
    "resources": {
      "imagePullSecret": "azure-kms-registry-credentials"
    }
  }
}
```

Note the `credential` type in `kmsValue` changes from `environment` (vault-secret mode) to `default` (Workload Identity mode).

The existing vault-secret-based Azure KMS flow continues to work unchanged — `kmsAzureWorkloadIdentity` and `kmsAzureVaultSecretName` are mutually exclusive ways of authenticating the same Azure KMS driver.

### Validation

When `enableKms` is `true`, `kmsValue` must be non-blank, and at least one of `kmsServiceAccount` (AWS/GCP, or Azure Workload Identity), or `kmsAzureVaultSecretName` (Azure vault-secret mode) must be non-blank. Creating an Azure KMS validator without providing either a vault secret or a Workload Identity ServiceAccount is rejected. If a required field is missing, empty, or whitespace-only, the API rejects the request with **HTTP 400** and a `fieldErrors` map identifying the offending field(s):

```json
{
  "fieldErrors": {
    "clusterParticipantConfig.kmsValue": "kmsValue must not be empty when enableKms is true",
    "clusterParticipantConfig.kmsServiceAccount": "kmsServiceAccount must not be empty when enableKms is true"
  },
  "globalErrors": {}
}
```

When `enableKms` is `false`, these fields are ignored and no validation is applied.

***

## Operator Settings (Legacy Migration Only)

The Operator still reads two environment-level KMS settings, but in v1.11.11 they are **not** a general-purpose configuration knob. Because the API requires both `kmsValue` and `kmsServiceAccount` whenever `enableKms=true` (see [Validation](#validation)), every validator created through the CAT-BM API or console already carries explicit values — so the Operator defaults are **never consulted for new validators**.

If `enableKms=true` but a per-validator KMS field is left blank, the Operator falls back to its configured defaults. This happens both as a one-time backfill onto pre-v1.11.11 validators on first reconcile, and at render time for any validator.

| Variable                                      | Role in v1.11.11                                                                               |
| --------------------------------------------- | ---------------------------------------------------------------------------------------------- |
| `CANTON_TOPOLOGY_KMS_ENABLED`                 | **Retired** — no longer used to auto-enable KMS. KMS is enabled per validator via `enableKms`. |
| `CANTON_TOPOLOGY_KMS_VALUE`                   | Default fallback for `kmsValue` when blank.                                                    |
| `CANTON_TOPOLOGY_KMS_SERVICE_ACCOUNT`         | Default fallback for `kmsServiceAccount` when blank.                                           |
| `CANTON_TOPOLOGY_KMS_AZURE_IMAGE`             | Default fallback for `overrideImage` (Azure) when blank.                                       |
| `CANTON_TOPOLOGY_KMS_AZURE_IMAGE_PULL_SECRET` | Default fallback for `participant.resources.imagePullSecret` (Azure) when blank.               |
| `CANTON_TOPOLOGY_KMS_AZURE_VAULT_SECRET`      | Default fallback for `kmsAzureVaultSecretName` (Azure) when blank.                             |

{% hint style="warning" %}
To prevent a validator with blank KMS fields from silently inheriting these defaults, set the relevant variables to `""` on the Operator.
{% endhint %}

{% hint style="info" %}
If your environment has no legacy (pre-v1.11.11) KMS validators, these Operator settings have no effect and can be ignored. They only matter while un-migrated Phase 1 validators still exist — see [Backward Compatibility](#backward-compatibility-with-legacy-validators).
{% endhint %}

***

## What the Operator Configures

When a validator is provisioned with KMS enabled, the Operator makes the following changes to that validator's Participant pod:

**ServiceAccount reference** — the resolved ServiceAccount (per-validator value, or the Operator default) is set on the Participant/Canton spec:

```yaml
spec:
  serviceAccountName: catalyst-canton-kms
```

**KMS crypto config injection** — the following environment variable is injected into the Participant pod, built from the resolved `kmsValue`:

```
ADDITIONAL_CONFIG_SPLICE_PARTICIPANT_CRYPTO_KMS =
  "canton.participants.participant.crypto.provider = kms
   canton.participants.participant.crypto.kms { type = "aws", region = "eu-west-1", audit-logging = true }"
```

***

## Backward Compatibility with Legacy Validators

Validators that were created under the Phase 1 environment-level model (with `enableKms=true` but no per-validator `kmsValue` / `kmsServiceAccount` on their spec) are automatically migrated. On the next reconcile, the Operator **backfills** the global topology values (`CANTON_TOPOLOGY_KMS_VALUE` / `CANTON_TOPOLOGY_KMS_SERVICE_ACCOUNT`) onto the validator CR.

This makes the validator's KMS configuration fully explicit on its own spec, so that API reads (GET) and Operator writes (reconcile) share a single source of truth. The backfill:

* Runs only for validators that already have `enableKms=true`.
* Only fills fields that are currently **blank** — it never overwrites an explicit per-validator value.
* Runs regardless of the `disableUserEdit` flag, because it is a system migration rather than a user edit (it executes before the user-edit guard in the reconcile loop).
* Is **idempotent and self-terminating** — once both `kmsValue` and `kmsServiceAccount` are populated, it short-circuits and patches nothing on subsequent reconciles. After this one-time migration the validator no longer depends on the global Operator defaults.

{% hint style="warning" %}
For the legacy backfill to work, the Operator's `CANTON_TOPOLOGY_KMS_VALUE` and `CANTON_TOPOLOGY_KMS_SERVICE_ACCOUNT` defaults must still match what those validators were originally provisioned with, **until every legacy validator has reconciled at least once**. Removing them before legacy validators have been migrated would leave those validators without a resolvable KMS configuration.
{% endhint %}

***

## Verifying KMS Is Active

After provisioning a validator with KMS enabled, verify that:

1. The API echoes the KMS fields back on the participant — a GET on the participant returns `enableKms=true` and the `kmsValue` / `kmsServiceAccount` you submitted.
2. The Participant pod references the correct ServiceAccount — check with `kubectl get pod <participant-pod> -o yaml | grep serviceAccountName`
3. The `ADDITIONAL_CONFIG_SPLICE_PARTICIPANT_CRYPTO_KMS` environment variable is present on the Participant pod
4. The Participant starts successfully and reaches a Ready state — check the [Status](https://gitlab.com/intellecteu/products/catalyst/cat-bp/catbp-docu/catalyx-gitbook/-/blob/staging/catalyx-blockchain-manager/canton-network/version-2.0/console-guide-canton/validator-detail/status.md) page in the console

{% hint style="info" %}
KMS key usage will appear in your provider's audit log (e.g. AWS CloudTrail) if audit logging is enabled on your KMS key. This can be used to confirm the Participant is actively using KMS for cryptographic operations.
{% endhint %}

***

## Scope and Limitations

| Capability                                         | v1.11.11                                                                                                                                                                              |
| -------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Per-validator KMS toggle (at create time)          | ✅ Supported                                                                                                                                                                           |
| Per-validator KMS provider config & ServiceAccount | ✅ Supported                                                                                                                                                                           |
| Multiple KMS providers (AWS, GCP, …)               | ✅ Supported via the `kmsValue` Canton config fragment                                                                                                                                 |
| Azure KMS via AKS Workload Identity (cross-tenant) | ✅ Supported since **v1.11.15** — `kmsAzureWorkloadIdentity` as an alternative to `kmsAzureVaultSecretName`                                                                            |
| Legacy validator migration                         | ✅ Supported — Operator KMS settings backfilled onto the CR on reconcile                                                                                                               |
| Environment-level KMS defaults for new validators  | ❌ Not applicable — validation requires explicit values, so Operator defaults are never used for new validators                                                                        |
| Toggling KMS on an existing validator (edit)       | ❌ Not supported — KMS is fixed at creation time; the edit wizard guards these fields. All KMS fields are immutable after creation **except `overrideImage`**, which remains editable. |
| Retroactive KMS enablement for non-KMS validators  | ❌ Not supported — only validators created with `enableKms=true` use KMS                                                                                                               |
| Operator-managed ServiceAccount lifecycle          | ❌ Not yet supported — SA must be externally managed                                                                                                                                   |
| KMS key rotation                                   | ❌ Not yet supported                                                                                                                                                                   |


# Logging

This page explains how Catalyst provides access to logs for all running participant and validator components directly from the user interface. Logs are retrieved from the Kubernetes API and displayed per component, with each entry including a Kubernetes-provided timestamp.

### Component Logs

Catalyst displays logs for all running components on the Participant or Validator detail page. Logs are fetched from the Kubernetes API.

### Navigating Logs

Scroll up and down through the log output. Scroll **down** to see newer entries, scroll **up** to see older ones.

### Log Formatting

Your logs can use any format. However, to enable level filtering, format your logs as JSON with a `level` field:

```json
{"level": "error", "message": "Connection failed"}
{"level": "info", "message": "Service started"}
```

When your logs follow this format, you can filter by severity level (info, warning, error, etc.).

### Searching Logs

Use the search field to find specific text within your loaded logs. The search works on logs currently displayed in your view. To search older logs, scroll up to load them first.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-d5ef54e2f3d6badd877d1936db0ee9d68fbbcdd1%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

***


# Wallet Sweeps

This page explains how to configure wallet sweeps on a validator. A wallet sweep monitors the balance of a specific party (the sender). When the sender's balance exceeds a configured maximum threshold, the validator automatically initiates a transfer to another party (the receiver), ensuring only a defined minimum balance remains.

### Configure a Wallet Sweep

{% stepper %}
{% step %}
**Navigate to the Sweep section**

Go to the Validator's details page and locate the **Sweep** section.
{% endstep %}

{% step %}
**Add a new sweep**

Click the **+** icon to configure a new sweep.
{% endstep %}

{% step %}
**Provide sweep configuration**

Fill in the following information:

* **Primary party ID (sender)**
* **Secondary party ID (receiver)**
* **Maximum balance threshold (USD)**
* **Minimum balance to retain (USD)**
* **Toggle on/off: Use Transfer Preapproval**

<details>

<summary>More info about these fields</summary>

| Field                               | Description                                                          |
| ----------------------------------- | -------------------------------------------------------------------- |
| **Primary party ID (sender)**       | The hosted party whose wallet balance will be monitored and swept    |
| **Secondary party ID (receiver)**   | The party that will receive the swept funds                          |
| **Maximum balance threshold (USD)** | When the sender's balance exceeds this amount, the sweep is executed |
| **Minimum balance to retain (USD)** | The amount that will remain in the sender's wallet after the sweep   |
| **Use Transfer Preapproval**        | See below                                                            |

</details>
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
**Use Transfer Preapproval toggle behavior:**

* **Enabled (true):** Performs a direct automatic transfer. No acceptance by the receiver is required.
* **Disabled (false):** Creates a transfer offer that must be accepted by the receiver (manually or via auto-accept).
  {% endhint %}

### Alternative Sweep Configuration Method

Wallet sweeps can also be configured during:

* Initial validator setup
* Editing an existing validator setup

This is done through the standard validator configuration flow.

***


# Expose Ledger API

How to expose and access the Ledger API for a participant or validator in CatalyX Blockchain Manager.

## Overview

This guide explains how to:

* expose the Ledger API for a participant or validator
* configure authentication and authorization
* configure Keycloak integration
* access the JSON Ledger API and gRPC Ledger API
* validate access tokens
* troubleshoot common Ledger API access issues

The Ledger API allows external applications to submit commands, query contracts, consume ledger events, and integrate with Canton applications.

{% hint style="info" %}
Enabling the Ledger API exposes the participant API externally but does **not** cause ledger downtime or interrupt validator operations.
{% endhint %}

## What is the Ledger API?

The Ledger API exposes services that allow applications to interact with the Canton ledger. It supports command submission, transaction streaming, active contract queries, and event subscriptions.

There are two primary API types:

| API Type        | Purpose                                    |
| --------------- | ------------------------------------------ |
| gRPC Ledger API | Native high-performance Canton integration |
| JSON Ledger API | REST/WebSocket-based integration           |

### Architecture

The Ledger API uses OpenID Connect (OIDC), JWT access tokens, Keycloak authentication, and Canton authorization checks. Authorization is performed for every request.

Required token claims:

* `aud` — audience
* `sub` — subject
* `scope` — must include `daml_ledger_api`

***

## Part 1 — Enable Ledger API Exposure

{% stepper %}
{% step %}

#### Open Validator Details

Navigate to **Validators**, select the target validator, and open **Edit configuration**.
{% endstep %}

{% step %}

#### Enable Ledger API Exposure

Locate the **Ledger API** or **API Exposure** settings and enable:

* JSON Ledger API exposure
* External API access

Save the configuration. After deployment, the participant exposes Ledger API endpoints externally.
{% endstep %}

{% step %}

#### Access the Ledger API URL

After enabling the API, the Ledger API URL becomes visible in the validator details page. Typical URL formats:

```
https://participant-${validator-name}.${domain}
```

```
https://json-api-${validator-name}.${domain}
```

Credentials are authenticated using Keycloak.
{% endstep %}
{% endstepper %}

***

## Part 2 — Configure Keycloak Authentication

Keycloak acts as the Identity Provider (IdP), OAuth Provider, and token issuer. Applications authenticate against Keycloak and receive JWT access tokens used by Canton.

### Create a Realm

{% stepper %}
{% step %}

#### Open Keycloak

Log in to the Keycloak Admin Console and click **Add Realm**.
{% endstep %}

{% step %}

#### Configure the Realm

Provide a **Realm Name** and **Display Name**, then click **Create**.

Use separate realms per environment, for example: `sandbox`, `production`.
{% endstep %}
{% endstepper %}

### Create an OpenID Client

{% stepper %}
{% step %}

#### Open Clients

Navigate to **Clients → Create**.
{% endstep %}

{% step %}

#### Configure the Client

Provide:

* **Client ID** — recommended: `canton-participants`
* **Protocol** — `openid-connect`
  {% endstep %}

{% step %}

#### Configure Access Type

Set **Access Type** to `confidential` and enable:

* Standard Flow
* Direct Access Grants
* Service Accounts

Save the configuration.
{% endstep %}

{% step %}

#### Configure Redirect URLs

Add the participant JSON API URL:

```
https://json-api-${participant}.${domain}/*
```

Save changes.
{% endstep %}
{% endstepper %}

### Create the `daml_ledger_api` Scope

{% stepper %}
{% step %}

#### Open Client Scopes

Navigate to **Client Scopes → Create**.
{% endstep %}

{% step %}

#### Configure the Scope

Create a scope named `daml_ledger_api`, enable **Include In Token Scope**, and save.
{% endstep %}

{% step %}

#### Assign the Scope to the Client

Navigate to **Client → Client Scopes** and add `daml_ledger_api` to **Assigned Default Client Scopes**.
{% endstep %}
{% endstepper %}

### Configure the Audience Mapper

The Ledger API validates the token audience against the participant identifier. Navigate to **Client Scopes → daml\_ledger\_api → Mappers** and create a mapper:

| Field                    | Value                         |
| ------------------------ | ----------------------------- |
| Name                     | `audience-participant-mapper` |
| Mapper Type              | Audience                      |
| Included Custom Audience | participant ID                |

Enable **Add to ID token** and **Add to access token**.

Example audience value:

```
sandbox::12205d66c5f04ee07...
```

***

## Part 3 — Configure Roles and Users

Navigate to **Client → Roles → Add Role** and create the required roles. Recommended roles:

* `Participant_Admin`
* `Party`
* `Broker`
* `Borrower`
* `Lender`

To create a user, navigate to **Users → Add User**, provide a username, email, and password, then navigate to **User → Role Mappings** and assign the appropriate client role (e.g. `Participant_Admin`).

***

## Part 4 — Configure Canton Authorization

Configure the participant to validate JWT tokens against Keycloak:

```
ledger-api {
    address = localhost
    port = 6865
    auth-services = [{
        type = jwt-rs-256-jwks
        url = "http://localhost:8080/auth/realms/company/protocol/openid-connect/certs"
    }]
}
```

***

## Part 5 — Generate an Access Token

Request a token from Keycloak:

```bash
curl -X POST \
  https://${keycloak}/auth/realms/${realm}/protocol/openid-connect/token \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password" \
  -d "client_id=canton-participants" \
  -d "client_secret=${CLIENT_SECRET}" \
  -d "scope=daml_ledger_api" \
  -d "username=participant_admin" \
  -d "password=${PASSWORD}"
```

The response contains an access token, expiration, and token type.

### Validate the JWT Token

The JWT token must contain:

```json
{
  "aud": "participantId",
  "sub": "userId",
  "scope": "daml_ledger_api",
  "exp": 1300819380
}
```

* The `aud` audience must match the participant ID
* The `scope` must include `daml_ledger_api`

***

## Part 6 — Access the Ledger API

### JSON Ledger API

Used for REST integrations, WebSocket event streaming, frontend applications, and lightweight integrations. Include the JWT token in every request:

```
Authorization: Bearer <access_token>
```

Common endpoints:

| Endpoint            | Purpose                 |
| ------------------- | ----------------------- |
| `/v2/updates/flats` | Flat event stream       |
| `/v2/updates/trees` | Transaction tree stream |
| `/docs/openapi`     | OpenAPI documentation   |
| `/docs/asyncapi`    | AsyncAPI documentation  |

### gRPC Ledger API

Used for backend services, high-performance integrations, and native Canton clients. Main services: Command Submission Service, Command Completion Service, Command Service.

### Ledger Events

The Ledger API emits the following event types:

* Created Events
* Exercised Events
* Archived Events
* Transaction Tree Events

Applications consume events asynchronously.

***

## Troubleshooting

### Common Issues

| Issue                          | Cause                          | Resolution                           |
| ------------------------------ | ------------------------------ | ------------------------------------ |
| Unauthorized client            | Incorrect client configuration | Verify confidential client settings  |
| Invalid audience               | Wrong participant audience     | Update audience mapper               |
| Missing scope                  | `daml_ledger_api` not assigned | Add default client scope             |
| 401 Unauthorized               | Invalid token                  | Regenerate token                     |
| Ledger API inaccessible        | API not exposed                | Enable Ledger API exposure           |
| Create Party button greyed out | Parties not yet loaded         | Wait for synchronization to complete |

### Validation Checklist

| Check                              | Expected Result             |
| ---------------------------------- | --------------------------- |
| Ledger API enabled                 | External endpoint available |
| Keycloak client created            | OAuth authentication works  |
| `daml_ledger_api` scope configured | Tokens include scope        |
| Audience mapper configured         | Token audience valid        |
| User roles assigned                | API access granted          |
| JWT token valid                    | Requests authorized         |

***

## Best Practices

* Use confidential clients in production
* Separate environments by realm
* Use short-lived access tokens
* Restrict `Participant_Admin` role usage
* Always validate token scopes
* Use HTTPS-only endpoints
* Configure CORS for JSON API access

***

## Additional References

* [JSON Ledger API](https://docs.digitalasset.com/build/3.4/explanations/json-api/index.html)
* [Ledger API Services](https://docs.digitalasset.com/build/3.4/explanations/ledger-api-services.html)
* [Ledger API Proto Docs](https://docs.digitalasset.com/build/3.4/reference/lapi-proto-docs.html)
* [JSON API Reference](https://docs.digitalasset.com/build/3.4/reference/json-api/json-api.html)


# Disaster Recovery from a Failure on Global Synchronizer

This flow is adapted from the [Canton official guide](https://dev.network.canton.global/validator_operator/validator_backups.html#disaster-recovery-from-loss-of-the-cometbft-storage-layer-of-the-global-synchronizer), with additional instructions for Catalyst validator installations.

{% hint style="warning" %}
Follow these steps only when instructed to by your super validator sponsor or the IntellectEU team during a network recovery event.
{% endhint %}

{% stepper %}
{% step %}
**Set environment variables**

```bash
export NAME=<name of the validator>
export PASSWORD=<password for wallet>
export KEYCLOAK_URL=<keycloak url>
export REALM=<keycloak realm for catalyst>
```

{% endstep %}

{% step %}
**Log in to Keycloak and obtain a token**

```bash
curl --location "${KEYCLOAK_URL}/auth/realms/${REALM}/protocol/openid-connect/token" \
  --header "Content-Type: application/x-www-form-urlencoded" \
  --data-urlencode "grant_type=password" \
  --data-urlencode "client_id=${NAME}-wallet-ui" \
  --data-urlencode "username=${NAME}_walletuser" \
  --data-urlencode "password=${PASSWORD}" > token.json
```

{% endstep %}

{% step %}
**Extract the access token**

```bash
export TOKEN=$(jq -r .access_token token.json)
```

{% endstep %}

{% step %}
**Obtain the snapshot from the wallet**

{% hint style="info" %}

* The wallet URL can be obtained from the UI page of the wallet application.
* The super validators on network recovery will provide the timestamp in the `#validators-ops` channel.
* The timestamp format is the same as the logs for the validator.
  {% endhint %}

```bash
export WALLET_URL=<url of the validator wallet application>
export TIMESTAMP=<timestamp on the same format as the logs>

curl -sSLf "${WALLET_URL}/api/validator/v0/admin/domain/data-snapshot?timestamp=${TIMESTAMP}&force=true" \
  -X GET \
  -H "authorization: Bearer ${TOKEN}" \
  -H "Content-Type: application/json" > dump_response.json
```

{% endstep %}

{% step %}
**Extract the data snapshot**

```bash
jq '.data_snapshot' dump_response.json > data_snapshot.json
```

{% endstep %}

{% step %}
**Copy the snapshot to the validator pod**

{% hint style="info" %}
The validator pod will have the name of the validator plus suffixes added by Kubernetes.
{% endhint %}

```bash
export NAMESPACE=<namespace of the validator>
export PODNAME=<pod of validator>

kubectl cp data_snapshot.json ${NAMESPACE}/${PODNAME}:/domain-upgrade-dump/domain_migration_dump.json
```

{% endstep %}

{% step %}
**Verify the file integrity (MD5 checksum)**

```bash
export LOCAL_DUMP_MD5SUM=$(md5sum data_snapshot.json)
export PODS_DUMP_MD5SUM=$(kubectl -n "${NAMESPACE}" exec -it ${PODNAME} -- md5sum /domain-upgrade-dump/domain_migration_dump.json)

if [ "$(echo $LOCAL_DUMP_MD5SUM | awk '{print $1}')" = "$(echo $PODS_DUMP_MD5SUM | awk '{print $1}')" ]; then
  echo 'MD5SUM checksums are equal.'
else
  echo 'MD5SUM checksums are not equal! Check the file copied is correct.'
fi
```

{% endstep %}

{% step %}
**Trigger the migration**

In the Catalyst UI validator page, **edit the validator**, set `migrationID` to a new migration ID, and toggle **migrating** to `true`.

Confirm and wait for the update to complete.
{% endstep %}
{% endstepper %}

***


# Validator Upgrade Policy and Release Schedule

CatalyX's policy and process for validator node upgrades, release validation, and version compatibility on the Canton Network.

## Overview

CatalyX follows the official Canton Foundation release lifecycle for validator upgrades. New Canton releases are continuously monitored, evaluated, and validated by IntellectEU before being recommended for customer environments.

The objective of the upgrade process is to maintain compatibility with the Canton Network while minimizing operational risk and service disruption.

{% hint style="info" %}
CatalyX does not automatically upgrade validator nodes. Upgrades are performed in a controlled manner following internal validation, customer communication, and agreed maintenance windows where applicable.
{% endhint %}

***

## Upgrade Policy

Validator upgrades are performed according to the release schedule published by the Canton Foundation.

When a new supported version becomes available, IntellectEU:

* Reviews the Canton Foundation release notes.
* Evaluates compatibility with supported CatalyX components.
* Performs internal validation and testing.
* Reviews migration requirements and known issues.
* Updates internal and customer documentation where necessary.
* Recommends the validated release to customers.
* Assists customers with upgrade planning and execution.

This process ensures that validator nodes remain compatible with the Canton Network while reducing the risk of introducing regressions into production environments.

***

## Release Validation Process

Before a validator version is recommended for customer use, IntellectEU follows an internal release validation process:

1. Reviewing the new Canton Foundation release.
2. Validating compatibility with supported CatalyX services.
3. Testing validator deployment and upgrade procedures.
4. Verifying database migrations (if applicable).
5. Validating package compatibility.
6. Reviewing known issues and workarounds.
7. Updating operational documentation.
8. Recommending the validated release for customer deployment.

{% hint style="info" %}
Only validated releases are recommended for production environments.
{% endhint %}

***

## Release Schedule

CatalyX does not maintain its own fixed release calendar for Canton validator versions. Validator upgrades follow the availability of new Canton Foundation releases.

Customers can monitor upcoming and released versions through:

* Canton Foundation release announcements
* CatalyX Blockchain Manager [Release Notes](/catalyx-blockchain-manager/canton-network/version-1.11/release-notes)
* CatalyX Product Roadmap

After a new Canton release becomes available, IntellectEU performs validation before recommending customer upgrades.

***

## Typical Upgrade Process

A validator upgrade generally consists of four stages.

{% stepper %}
{% step %}

#### Preparation

Before performing an upgrade, it is recommended to:

* Schedule an appropriate maintenance window.
* Review the release notes for the target version.
* Verify that recent database backups are available.
* Verify that a recent Validator Identity Dump (IDDump) exists.
* Review any migration requirements.

{% hint style="info" %}
See [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery) for how to schedule and verify backups and IDDumps.
{% endhint %}
{% endstep %}

{% step %}

#### Upgrade the Validator Version

The validator application version is upgraded by updating the validator image.

Using the CatalyX UI:

* Open the validator.
* Edit the validator configuration.
* Select the new Image Tag.
* Save the configuration.

Using the [Validator CRD](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/validator-custom-resource-definition):

```yaml
spec:
  imageTag: 0.6.x
```

The operator deploys the updated validator version.
{% endstep %}

{% step %}

#### Execute Migration (When Required)

Some validator releases require an application or data migration.

When migration is required:

1. Increment the Migration ID.
2. Set **Migrating** to **true**.
3. Wait for the migration to complete.
4. Set **Migrating** back to **false**.

Example:

```yaml
spec:
  migrationId: "3"
  migrationMigrating: true
```

After successful completion:

```yaml
spec:
  migrationMigrating: false
```

{% hint style="warning" %}
Migration should only be executed once for each required upgrade.
{% endhint %}
{% endstep %}

{% step %}

#### Post-Upgrade Validation

After the upgrade completes, verify that the validator is operating normally:

* Validator status is **Running**.
* Participant successfully joins and synchronizes with the network.
* Wallet login succeeds.
* Applications start successfully.
* No startup errors are present in the logs.
* Scan API responds successfully.
* Health status is normal.
  {% endstep %}
  {% endstepper %}

***

## Backup Recommendations Before Upgrading

Before every upgrade, IntellectEU recommends creating both a database backup and a Validator Identity Dump (IDDump). See [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery) for scheduling and restore procedures.

| Backup Type            | Preserves                                                                     | Does Not Preserve                                    |
| ---------------------- | ----------------------------------------------------------------------------- | ---------------------------------------------------- |
| Database Backup        | Validator database, participant database, ledger state, transaction history   | Validator identities and cryptographic keys          |
| Identity Dump (IDDump) | Validator identity, cryptographic keys, wallet identity, participant identity | Database contents, ledger state, transaction history |

{% hint style="warning" %}
For complete disaster recovery, both database backups and Identity Dumps should be available before performing an upgrade.
{% endhint %}

***

## Upgrade Best Practices

To minimize operational risk, IntellectEU recommends:

* Test upgrades in DevNet or TestNet before Production.
* Create a database backup.
* Create an Identity Dump.
* Review release notes.
* Perform upgrades during planned maintenance windows.
* Verify validator health immediately after the upgrade.
* Monitor logs until validator initialization completes successfully.

***

## Version Compatibility

Validator nodes should remain on a supported Canton version validated by IntellectEU.

Although older versions may continue operating for a period of time, remaining significantly behind the supported version increases operational risk and may eventually lead to incompatibility with newer network components.

Customers are encouraged to upgrade after IntellectEU validates and recommends a new release.

### Consequences of Running an Outdated Validator

If a validator remains on an older version after the Canton Network has moved forward, the following issues may occur:

* Application initialization failures.
* Package compatibility conflicts.
* Migration failures.
* Validator remaining in **Pending** state.
* Failure to join or synchronize with the network.
* Inability to deploy newer applications or packages.
* Reduced compatibility with newer Canton protocol features.
* Unsupported configuration for future incident resolution.

{% hint style="danger" %}
In some cases, the validator must be upgraded before normal operation can resume.
{% endhint %}

***

## Customer Communication Process

When a new supported validator version becomes available, IntellectEU typically follows this process:

1. Review the official Canton Foundation release.
2. Perform internal compatibility testing.
3. Validate upgrade and migration procedures.
4. Update operational documentation if required.
5. Notify customers of the recommended upgrade.
6. Schedule or assist with the upgrade.
7. Verify validator health after deployment.

***

## Frequently Asked Questions

<details>

<summary>How often should validator nodes be upgraded?</summary>

Validator nodes should be upgraded after IntellectEU has validated and recommended the corresponding Canton Foundation release. There is no fixed calendar for upgrades, as they depend on the Canton Foundation release schedule and the validation process performed by IntellectEU.

</details>

<details>

<summary>Does every upgrade require a migration?</summary>

No. Some releases only require updating the validator application version, while others introduce schema or application changes that require a migration. Migration requirements are documented as part of each supported release.

</details>

<details>

<summary>Can upgrades be rolled back?</summary>

Application versions can generally be reverted if necessary. However, migrations may introduce irreversible data changes. Always create a database backup and Identity Dump before upgrading to ensure recovery options are available.

</details>

<details>

<summary>How long does an upgrade take?</summary>

Upgrade duration depends on validator size, database size, whether migrations are required, and infrastructure performance. Most routine upgrades complete within a planned maintenance window.

</details>


# Release Notes

## Version 1.11

**What's New**

* **Validator Backup and restore** — Configure a database backups schedule through Catalyst and restore validators.
* **Identity backups scheduling** — Configure the identity backup flow through a schedule; these backups are now also visible in the Catalyst UI.
* **Configure External DB** — Create Validators configured for an external Database service (e.g. RDS).
* **User roles added to match new DAML versions** — Added Roles for Participant users in the new DAML versions on the Edit User UI.

**Patches Summary**

| Patch    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| v1.11.1  | Validator deployment fix: resolved an error thrown when deploying Validators without a wallet configured.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| v1.11.2  | Validator wallet configuration fix: resolved a bug where wallet username configuration was missing for some Validators.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| v1.11.3  | Client heap dump & parties cache: added client heap dump support and an initial attempt at parties cache improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| v1.11.6  | Disabled party cache.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| v1.11.7  | Local parties tab & dynamic backup sizing: added a local parties view on the participant details page, improved party fetching performance, and introduced automatic backup volume sizing based on database size and retention settings.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| v1.11.8  | **I**ntroduced environment-level AWS KMS support for Canton Validator Participant key management via IRSA (IAM Roles for Service Accounts). When enabled, participant keys are stored in KMS rather than locally. Configured via `CANTON_TOPOLOGY_KMS_ENABLED`, `CANTON_TOPOLOGY_KMS_VALUE`, and `CANTON_TOPOLOGY_KMS_SERVICE_ACCOUNT` environment variables. Existing validators are not affected when KMS is enabled at the environment level.                                                                                                                                                                                                                                                                                                                                                           |
| v1.11.9  | KMS integration patch                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| v1.11.10 | Added support for Microsoft EntraID as an external Identity Provider. EntraID requires explicit OAuth scope logic on Ledger API and Validator API requests (`<ledger_client_id>/.default` and `api://<ledger_client_id>/.default` respectively). All previously supported IdP configurations remain unaffected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| v1.11.11 | Support was introduced for per-participant KMS configuration, allowing validators to be deployed with individual KMS settings that override the global default. The release also addresses several frontend bugs around session handling and form behavior, fixes a validator identity-dump CronJob failure, and includes several security upgrades.                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| v1.11.12 | Fixed a JVM race condition on Operator startup where the Postgres JDBC driver was not reliably registered with `DriverManager`, intermittently causing "No suitable driver found" errors when checking validator/participant database availability and suspending deployment as a result.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| v1.11.13 | Added support for the Azure KMS driver alongside AWS/GCP, including a participant image override (`overrideImage`) that can be changed and updated independently of other validator components, and an `imagePullSecret` field for the override image. Validator components can now be scaled to 0 replicas. Also fixes env-var validation on the validator edit dialog, a broken Canton Helm chart version, incorrect `targetThroughtput`/`kmsValue` config when disabled/set, the Azure KMS create-wizard's required-field gating, the KMS Value display on validator/participant details pages, the Validator API route being unavailable when the wallet is disabled, validator creation incorrectly rejecting `replicas=0`, and adds HOCON format validation for the Azure KMS value field in the UI. |
| v1.11.14 | Security fixes: bumped the base Docker images used across cat-bm-canton components.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| v1.11.15 | Added role-based access control to the Console UI — `canton_viewer` and `canton_writer` roles now determine which create/edit/delete controls a user sees, gated by the `AUTH_ROLES` flag on both the API and UI. Added support for configuring Azure KMS authentication via AKS Workload Identity (cross-tenant), letting a validator authenticate to an Azure Key Vault in another tenant via a federated ServiceAccount instead of a vault secret. Also fixes a mismatch between the UI and backend `AUTH_ROLES` defaults that let viewers see write controls the backend would reject, removes a stray health-dump "Create a file" control from the viewer role, and fixes a `POST /api/files` 400 error that was blocking DAR/package uploads.                                                        |
| v1.11.16 | Reworked the Console UI **Dashboard** page, now renamed **Monitoring**. Grafana is no longer embedded in the UI — the Monitoring page now links out to the configured Grafana dashboard, opening it in a new tab. Added a Noves section linking to the Noves Data App; when Noves is not configured, clicking the button opens a message prompting the user to install it or contact CatalyX support. Set the `CLUSTER_NOVES_URL` variable on the UI to configure the link. Also includes security fixes for critical dependency and Dockerfile vulnerabilities.                                                                                                                                                                                                                                           |
| v1.11.17 | Improved database reliability: validator, participant, and domain databases now run in a way that prevents a rare failure mode that could corrupt data during pod restarts or configuration changes. This is gated by the `CANTON_OPERATOR_POSTGRES_USESTATEFULSET` environment variable; enabling it triggers a database server restart, incurring roughly 1 minute of downtime.                                                                                                                                                                                                                                                                                                                                                                                                                          |

***

<details>

<summary>Version 1.10</summary>

**What’s new**

* **Custom Resource Definition changes for Git Ops** - Changes to the main Validator CRD specification to make Git Ops integration easier
* **Custom Annotations for On-Prem Deployments** - Introduced custom Kubernetes annotations for services and deployments, targeted at on-premises customers.
* **Participant Communication API Upgrade** - CatalyX now uses the V2 API for participant communication.
* **Ledger API Egress Support** - Added the ability to configure Ledger API egress.
* **Validator Creation Prefill** - Validator provisioning now automatically queries the network to prefill configuration values, reducing manual input and setup errors.
* **Security Enhancements** - Upgraded dependencies to address known vulnerabilities.
* **Multi-DAR Upload** - Users can now upload multiple DAR files in a single operation.

{% hint style="warning" %}
**Breaking change:** API endpoint /api/files now expects 'files' param instead of 'file'
{% endhint %}

**Bug Fixes**

* **Optimized the validator listing call** - reducing cold start times reported at >1 minute for some customers.
* **Resolved Liveness Probe Creation Issue** - Solved limitations when being created for certain components.
* **Resolved a logging issue** - some runtime logs were not visible in the UI.

**Patches Summary**

* **v1.10.1** - Fixed bug where logs could be truncated - json formatted logs are now returned fully instead of only returning the message field
* **v1.10.2** - Fixed scan API forwarding regression errors in cross environment Identity Dump recovery introduced in 1.10
* **v1.10.3** - Fixed to handle change on validator images where the default user was changed
* **v1.10.4** - Fixed logs formatted in json, so they could get truncated in CatalyX UI
* **v1.10.5** - Changed DAR upload through CatalyX to match the new DAML Ledger API

</details>

<details>

<summary>Version 1.9</summary>

**What’s new**

* **Secure JSON API Communication** – CatalyX now establishes direct HTTPS connections with the DAML JSON API, removing the prior reliance on Traefik HTTP-to-HTTPS redirection. This improves compatibility with different cluster environments
* **Dedicated Metrics Port Exposure** – Participants and validators now expose an explicit metrics port, enhancing observability and integration with monitoring tools.
* **Client-Focused Enhancements** – Participants and validators now expose a dedicated Prometheus-compatible metrics port, enabling tighter integration with observability stacks and more granular performance monitoring.
  * **UI Redesign** – Modernized frontend for improved UX and streamlined workflows.
  * **Flexible Deployment Options** – Additional deployment flags and configurations to support heterogeneous client environments and infrastructure.
  * **Stability Improvements** – Multiple backend fixes and improvements to ensure more consistent runtime behavior.

**Patches Summary**

* **v1.9.0 / v1.9.1-** Internal-only builds for penetration testing and internal QA cycles.
* **v1.9.2-** Major client release featuring UI overhaul and modular deployment support for varied infrastructure requirements.
* **v1.9.3-** Resolved an issue introduced in v1.9 where validator pods failed to restart correctly during migration operations
* **…​**
* **v1.9.5-** Introduced dedicated metrics port bindings for both participants and validators.
* **v1.9.6-** Modified CatalyX’s DAML JSON API integration to initiate direct HTTPS requests, eliminating dependency on Traefik-level HTTPS redirection.
* **v1.9.7-** Added the ability to disable wallet creation during validator provisioning. Improved identity dump behavior by removing wallet password requirements and avoiding field duplication.

</details>

<details>

<summary>Version 1.8</summary>

**What’s new**

* **Extended Identity Provider Integration** - CatalyX now supports integration with additional identity providers beyond Keycloak, enabling broader compatibility with enterprise authentication systems such as Auth0 and Okta.
* **Custom Authorization Controls** - Introduced a configurable authorization mechanism that allows manual definition of clients and users to enhance flexibility for custom access control and tighter security policies.

**Improvements**

* **Validator Provisioning Flow Enhancements** - Streamlined the creation and configuration process for validators with improved component orchestration and resource management, reducing setup time and potential misconfigurations.
* **Bug Fixes.** - Includes various UI and backend corrections to improve stability and consistency.

**Patches**

* **v1.8.1 -** Fixed application creation issue with custom Identity Providers.
* **v1.8.2 -** Resolved volume sizing bug affecting Operator stability.
* **v1.8.3 -** Updated Helm charts and removed deprecated replicated labels; internal CI/CD improvements.
* **v1.8.4 -** Enabled license key injection via Kubernetes secrets.
* **v1.8.5 -** Fixed port conflict in validator UI Docker images for versions >0.3.15.
* **v1.8.6 -** Corrected Canton Name Server image reference from `cns-web-ui` to `ans-web-ui` for version 0.3.17.
* **v1.8.7 -** Added option to disable Role-Based Access Control and use a single Admin role.
* **…​**
* **v1.8.10 -** Resolved a regression introduced in build v1.8.7.
* **v1.8.11 -** Introduced ability to define default images (e.g., Postgres, NGINX).
* **v1.8.12 -** Added configuration option to disable `typ` header verification.
* **v1.8.13 -** Enabled Postgres deployment customization via the Validator CRD.
* **v1.8.14 -** Updated Postgres deployment strategy to support rolling updates.

{% hint style="warning" %}
Since **v1.8.4** the license key can be passed as a secret, please update your values.yaml with the respective values.
{% endhint %}

```yaml
 licenseKey:
    key: ""  # Set licenseKey if NOT using a Kubernetes secret
    secret:
      enabled: false  # Set to 'true' to use a Kubernetes Secret
      name: ""        # Name of the Kubernetes secret
      key: ""         # Key inside the secret that contains licenseKey

```

</details>

<details>

<summary>Version 1.7</summary>

**What’s new**

* **Validator Identity Dump Management** - CatalyX now allows users to generate identity dumps for validator nodes directly from the UI. These dumps are stored as Kubernetes secrets within the cluster, enabling secure and persistent identity management.
* **Validator Recreation from Identity Dumps** - Validators can now be safely deleted and later recreated using their previously stored identity dumps, preserving node identity across lifecycle operations and reducing redeployment overhead.

**Improvements**

* **Stability & Maintenance Fixes** - Includes minor backend and UI fixes to enhance system reliability and user experience.<br>

</details>

<details>

<summary>Version 1.6</summary>

**What’s new**

* **Validator Lifecycle Management** - CatalyX now supports the deployment and operational management of Canton validator nodes directly from the UI, enabling users to provision, monitor, and maintain validator infrastructure with minimal manual intervention.
* **Wallet Operations Interface** - Introduced a dedicated interface for Canton wallet management, allowing users to operate their wallets more securely and efficiently.

**Improvements**

* **One-Click Health Data Export** - Users can now generate and download comprehensive health dumps for both participants and domains in a single action, simplifying diagnostics and support workflows.
* **Stability & Usability Enhancements** - Includes various minor fixes and refinements to improve overall stability and user experience.

</details>

<details>

<summary>Version 1.5</summary>

**What’s new**

* **Scheduled Backup Support** CatalyX now enables automated scheduling of backups for both domains and participants. This ensures regular state snapshots and enhances disaster recovery readiness with minimal manual oversight.
* **Embedded Cluster Monitoring Dashboard** A built-in dashboard has been introduced for real-time observability of cluster health. This provides a consolidated view of node status, resource usage, and system metrics directly within the CatalyX interface.
* **Direct Node Health Dump Downloads** Users can now download health dump files directly from individual nodes, streamlining diagnostics and enabling faster support workflows.

**Improvements**

* **Runtime Log Level Management** It is now possible to dynamically adjust the log level of running nodes without requiring restarts, providing enhanced control during debugging or incident analysis.
* **Topology Update API** A new API has been added to allow live updates to node topology configurations, simplifying the process of managing participant and domain relationships at runtime.

<br>

</details>

<details>

<summary>Version 1.4</summary>

**What’s new**

* Support for Auth0 as ledger authentication provider

**Improvements**

* Minor security improvements
* Minor UX improvements

</details>

<details>

<summary>Version 1.3</summary>

**What’s new**

* Full remote administration of participant and domain nodes

**Improvements**

* See when the next run of the pruning schedule will take place
* Improved node health feedback

</details>

<details>

<summary>Version 1.2</summary>

**What’s new**

* Option to enable a PostgreSQL backend for the HTTP JSON API server, for more efficient data caching and improved query performance
* IAM integration for parties created outside of CAT-BM

**Improvements**

* Improved feedback for pruning schedule: Status of last runs, including number of pruned records
* Increased configurability for already running nodes
* UI/UX improvements on Collections and input validation

</details>

<details>

<summary>Version 1.1</summary>

**What’s new**

* Role-based access control
* A Web UI for the Daml REPL console
* Pruning: CatalyX now supports pruning leveraging the Canton protocol

**Improvements**

* Improvements for Dars/package management

</details>

<details>

<summary>Version 1.0</summary>

**What’s new**

* Intuitive UI for Canton/DAML deployment & operations
* Simplified Canton nodes configuration & bootstrap
* Integrated off-ledger Identity Access Management
* Party & User management
* DAR package management
* Query active contract
* Deploy DAML client applications

</details>

***


# Support & Resources

Contact our Support Center or explore the additional resources below to answer any questions you may have about CatalyX Blockchain Manager.

<p align="right"><button type="button" class="button secondary" data-action="search" data-icon="magnifying-glass">Search...</button><a href="https://docs.catalyx.solutions/general/support" class="button primary">Go to Support Center</a></p>

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><i class="fa-message-question">:message-question:</i></td><td><strong>FAQ</strong></td><td>Frequently Asked Questions.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/faq">FAQ</a></td></tr><tr><td><i class="fa-gear-complex-api">:gear-complex-api:</i></td><td><strong>API Reference</strong></td><td>API endpoint URLs per environment.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/api-reference">API Reference</a></td></tr><tr><td><i class="fa-creative-commons-share">:creative-commons-share:</i></td><td><strong>Open Source Licenses</strong></td><td>Licenses used for the CAT-BM platform.</td><td><a href="/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses">Open Source Licenses</a></td></tr></tbody></table>

***


# FAQ

This section covers answers to frequently asked questions about CatalyX Blockchain Manager and Canton Network operations.

{% hint style="info" %}
This page is a work in progress. More questions will be added over time.
{% endhint %}

## Backups, Identity Dumps & Retention

<details>

<summary>What's the difference between a database backup and an Identity Dump (IDDump)?</summary>

Database backups protect ledger and database state. Identity Dumps (IDDumps) protect validator identity and cryptographic keys. Both are required for full disaster recovery — neither can substitute for the other.

Learn more: [Validator Backups and Identity Dumps](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/identity-backup-and-recovery)

</details>

<details>

<summary>How long are security and audit logs retained?</summary>

30 days on Mainnet (Production), and 7 days on Devnet/Testnet.

Learn more: [Data Retention & Pruning Policy](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/data-retention-and-pruning-policy)

</details>

<details>

<summary>Does ledger pruning delete active data, and does it require downtime?</summary>

No to both. Pruning only removes obsolete ledger data that's no longer required for normal operation, and it runs as a scheduled maintenance task without requiring planned validator downtime.

Learn more: [Data Retention & Pruning Policy](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/data-retention-and-pruning-policy)

</details>

## Validator Upgrades

<details>

<summary>How often should I upgrade my validator, and does CatalyX auto-upgrade it?</summary>

CatalyX does not automatically upgrade validator nodes. Upgrades follow IntellectEU's validation of each Canton Foundation release before it's recommended for customer environments.

Learn more: [Validator Upgrade Policy and Release Schedule](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/validator-upgrade-policy-and-release-schedule)

</details>

<details>

<summary>Does every upgrade require a migration?</summary>

No. Only releases that introduce schema or application changes require a migration; others only update the validator application version.

Learn more: [Validator Upgrade Policy and Release Schedule](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/validator-upgrade-policy-and-release-schedule)

</details>

## KMS & Security

<details>

<summary>Can I use an external KMS (AWS, GCP, Azure) instead of storing validator keys directly?</summary>

Yes. Per-validator KMS is supported for storing participant keys with an external key management service.

Learn more: [KMS Integration](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/kms-integration)

</details>

## Networking & API

<details>

<summary>How do I expose the Ledger API for a validator?</summary>

Covers enabling gRPC vs. JSON Ledger API access and configuring Keycloak-based token authentication.

Learn more: [Expose Ledger API](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/expose-ledger-api)

</details>

<details>

<summary>Is there a REST API for triggering backups, restores, or pruning instead of using the UI?</summary>

Yes. 128 documented endpoints are available, including validator backup, restore, and prune operations.

Learn more: [API Reference](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/api-reference)

</details>

## Troubleshooting

<details>

<summary>Why can't I log into the wallet UI, or why is the Primary Party field showing an error?</summary>

See the troubleshooting table for common causes and resolutions.

Learn more: [Parties & Users](/catalyx-blockchain-manager/canton-network/version-1.11/network-and-node-management/parties-and-users)

</details>

<details>

<summary>Why did my DAR upload fail, or why don't templates appear after upload?</summary>

See the troubleshooting table for common causes and resolutions.

Learn more: [Upload DARs](/catalyx-blockchain-manager/canton-network/version-1.11/validator-management/dar-management)

</details>


# API Reference

REST API reference for the CatalyX Blockchain Manager Canton Console v1.11, covering all 128 endpoints across validators, participants, domains, and more.

## List validators

> Returns Splice validators visible to this CBM, optionally filtered by name substring and/or lifecycle phase, paginated via \`from\` (offset) and \`limit\`. The response also includes the total count of matching validators.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-controller","description":"Create, list, edit and remove Splice validator deployments, and read their configuration and status."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorFilterResponseDto":{"type":"object","description":"Paginated list of `ValidatorResponseDto` entries plus the total count of validators matching the filter.","properties":{"validators":{"type":"array","items":{"$ref":"#/components/schemas/ValidatorResponseDto"}},"totalCount":{"type":"integer","format":"int64"}}},"ValidatorResponseDto":{"type":"object","description":"Full validator details returned by GET / list endpoints: cluster and participant configuration, app info for validator / wallet / CNS, contact point and optional Keycloak credentials created on first provisioning.","properties":{"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"application":{"type":"string"},"applicationCantonNameServer":{"type":"string"},"applicationWallet":{"type":"string"},"contactPoint":{"type":"string"},"createdUser":{"$ref":"#/components/schemas/CreatedUserDto"},"customAuth":{"type":"boolean"},"databaseStorage":{"type":"string"},"disabledWallet":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"exposeLedgerApi":{"type":"boolean"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"immutable":{"type":"boolean"},"jsonApiAddress":{"type":"string"},"ledgerApiAddress":{"type":"string"},"validatorApiAddress":{"type":"string"},"migrationId":{"type":"string"},"migrationMigrating":{"type":"boolean"},"name":{"type":"string"},"onboardingSecretName":{"type":"string"},"participant":{"type":"string"},"participantIdentitiesDumpSecretName":{"type":"string"},"participantInfo":{"$ref":"#/components/schemas/AppInfoDto"},"partyId":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"privateJsonApi":{"type":"boolean"},"scanAddress":{"type":"string"},"storageSize":{"type":"string"},"disableProbes":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"CreatedUserDto":{"type":"object","properties":{"id":{"type":"string"},"temporaryPassword":{"type":"string"},"username":{"type":"string"}}},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}},"paths":{"/validators":{"get":{"tags":["validator-controller"],"summary":"List validators","description":"Returns Splice validators visible to this CBM, optionally filtered by name substring and/or lifecycle phase, paginated via `from` (offset) and `limit`. The response also includes the total count of matching validators.","operationId":"listValidators","parameters":[{"name":"from","in":"query","description":"Zero-based offset of the first result to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"status","in":"query","description":"Filter by validator lifecycle phase.","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}},{"name":"limit","in":"query","description":"Maximum number of results to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Substring matched against the validator name.","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorFilterResponseDto"}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create validator

> Provisions a new Splice validator (participant, validator app, wallet, CNS) and optionally creates the associated Keycloak user when custom auth is not used. The returned payload includes the initial Keycloak credentials for non-custom-auth validators.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-controller","description":"Create, list, edit and remove Splice validator deployments, and read their configuration and status."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorDto":{"type":"object","description":"Splice validator definition: cluster and participant configuration, container image, auth and database settings used to provision a new validator deployment and convert it to the underlying CRD.","properties":{"auth":{"$ref":"#/components/schemas/ValidatorAuthDto"},"clusterConfig":{"$ref":"#/components/schemas/ClusterConfigDto"},"clusterParticipantConfig":{"$ref":"#/components/schemas/ClusterParticipantConfigDto"},"customAuth":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"imageRepo":{"type":"string","minLength":1},"imageTag":{"type":"string","minLength":1},"name":{"type":"string","maxLength":33,"minLength":1},"onboardingSecret":{"type":"string"},"participant":{"$ref":"#/components/schemas/AppInfoDto"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"}},"required":["clusterConfig","clusterParticipantConfig","imageRepo","imageTag","name","participant"]},"ValidatorAuthDto":{"type":"object","description":"Auth configuration for a Splice validator: per-application OIDC client ids / secrets and the OAuth2 issuer / audience to use.","properties":{"cnsClientId":{"type":"string","description":"Client for the Canton Name Service","minLength":1},"walletClientId":{"type":"string","description":"Client for Wallet application","minLength":1},"ledgerApiClientId":{"type":"string","description":"Client for Validator","minLength":1},"ledgerApiClientSecret":{"type":"string","description":"Secret part of Client Credentials Grant Flow for the Validator client","minLength":1},"walletUser":{"type":"string","description":"User that will access the wallet application and receive rewards","minLength":1},"ledgerApiUser":{"type":"string","description":"Subject of the Validator client","minLength":1},"audience":{"type":"string","description":"Audience claim expected by the clients\n","minLength":1},"oidcAuthorityUrl":{"type":"string"},"oidcConfigUrl":{"type":"string"},"jwksUrl":{"type":"string"}},"required":["audience","cnsClientId","ledgerApiClientId","ledgerApiClientSecret","ledgerApiUser","walletClientId","walletUser"]},"ClusterConfigDto":{"type":"object","description":"Cluster-wide Splice / Canton configuration for a validator: shared DARs, application metadata for validator / wallet / CNS, decentralized synchronizer URL, dev-net flags and JVM options.","properties":{"additionalConfigOther":{"type":"string"},"additionalUsersEnvVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"appDars":{"type":"string"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"contactPoint":{"type":"string"},"decentralizedSynchronizerUrl":{"type":"string"},"defaultJvmOptions":{"type":"string","minLength":1},"devNet":{"type":"boolean"},"disabledWallet":{"type":"boolean"},"extraDomains":{"type":"array","items":{"$ref":"#/components/schemas/ExtraDomainDto"}},"failOnAppVersionMismatch":{"type":"boolean"},"fixedTokens":{"type":"boolean"},"metrics":{"$ref":"#/components/schemas/MetricsDto"},"migrateValidatorParty":{"type":"boolean"},"migration":{"$ref":"#/components/schemas/MigrationDto"},"participantIdentitiesDumpBackup":{"$ref":"#/components/schemas/IdentitiesDumpPeriodicBackupDto"},"participantIdentitiesDumpImport":{"$ref":"#/components/schemas/ParticipantIdentitiesImportDto"},"partyHint":{"type":"string","minLength":1},"pvcVolumeStorageClass":{"type":"string"},"scanAddress":{"type":"string","minLength":1},"svSponsorAddress":{"type":"string","minLength":1},"svValidator":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"useSequencerConnectionsFromScan":{"type":"boolean"},"walletUserName":{"type":"string"},"scheduledPrune":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"},"disableProbes":{"type":"boolean"}},"required":["appInfoCantonNameService","appInfoValidator","defaultJvmOptions","migration","partyHint","scanAddress","svSponsorAddress"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"ExtraDomainDto":{"type":"object","properties":{"alias":{"type":"string"},"url":{"type":"string"}}},"MetricsDto":{"type":"object","properties":{"enable":{"type":"boolean"},"interval":{"type":"string"},"release":{"type":"string"}}},"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]},"IdentitiesDumpPeriodicBackupDto":{"type":"object","properties":{"backupInterval":{"type":"string","minLength":1},"locationBucketName":{"type":"string","minLength":1},"locationBucketProjectId":{"type":"string","minLength":1},"locationBucketSecretName":{"type":"string","minLength":1},"locationPrefix":{"type":"string"}},"required":["backupInterval","locationBucketName","locationBucketProjectId","locationBucketSecretName","locationPrefix"]},"ParticipantIdentitiesImportDto":{"type":"object","properties":{"identitiesSecretName":{"type":"string","description":"The name of the secret participant identities backup file dump.","minLength":1},"newParticipantIdentifier":{"type":"string","minLength":1}},"required":["identitiesSecretName","newParticipantIdentifier"]},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]},"ClusterParticipantConfigDto":{"type":"object","description":"Participant-side cluster configuration: JVM options, KMS settings, exposure of the ledger / JSON API and node identifier.","properties":{"defaultJvmOptions":{"type":"string","deprecated":true},"enableHealthProbes":{"type":"boolean","deprecated":true},"nodeIdentifier":{"type":"string"},"exposeLedgerApi":{"type":"boolean"},"privateJsonApi":{"type":"boolean"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}}},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}},"ValidatorResponseDto":{"type":"object","description":"Full validator details returned by GET / list endpoints: cluster and participant configuration, app info for validator / wallet / CNS, contact point and optional Keycloak credentials created on first provisioning.","properties":{"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"application":{"type":"string"},"applicationCantonNameServer":{"type":"string"},"applicationWallet":{"type":"string"},"contactPoint":{"type":"string"},"createdUser":{"$ref":"#/components/schemas/CreatedUserDto"},"customAuth":{"type":"boolean"},"databaseStorage":{"type":"string"},"disabledWallet":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"exposeLedgerApi":{"type":"boolean"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"immutable":{"type":"boolean"},"jsonApiAddress":{"type":"string"},"ledgerApiAddress":{"type":"string"},"validatorApiAddress":{"type":"string"},"migrationId":{"type":"string"},"migrationMigrating":{"type":"boolean"},"name":{"type":"string"},"onboardingSecretName":{"type":"string"},"participant":{"type":"string"},"participantIdentitiesDumpSecretName":{"type":"string"},"participantInfo":{"$ref":"#/components/schemas/AppInfoDto"},"partyId":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"privateJsonApi":{"type":"boolean"},"scanAddress":{"type":"string"},"storageSize":{"type":"string"},"disableProbes":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}}},"CreatedUserDto":{"type":"object","properties":{"id":{"type":"string"},"temporaryPassword":{"type":"string"},"username":{"type":"string"}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}},"paths":{"/validators":{"post":{"tags":["validator-controller"],"summary":"Create validator","description":"Provisions a new Splice validator (participant, validator app, wallet, CNS) and optionally creates the associated Keycloak user when custom auth is not used. The returned payload includes the initial Keycloak credentials for non-custom-auth validators.","operationId":"createValidator","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorResponseDto"}}}},"400":{"description":"Validator payload is invalid or references unknown resources.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A validator with the same name already exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorResponseDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update validator

> Applies an in-place edit to an existing validator (image, env vars, overrides, database/wallet settings, etc.). Immutable fields cannot be changed and validators marked as \`disableUserEdit\` reject updates.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-controller","description":"Create, list, edit and remove Splice validator deployments, and read their configuration and status."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorEditDto":{"type":"object","description":"Partial update payload for a Splice validator. Non-null fields replace the corresponding section of the existing validator; null fields are left unchanged. Includes a `cleanRestoreData` flag and toggles for ledger-API exposure.","properties":{"clusterConfig":{"$ref":"#/components/schemas/ClusterConfigEditDto"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"name":{"type":"string"},"databaseStorage":{"type":"string"},"participant":{"$ref":"#/components/schemas/AppInfoEditDto"},"cleanRestoreData":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"privateJsonApi":{"type":"boolean"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"}}},"ClusterConfigEditDto":{"type":"object","properties":{"scanAddress":{"type":"string"},"contactPoint":{"type":"string"},"migration":{"$ref":"#/components/schemas/MigrationDto"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoEditDto"},"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoEditDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoEditDto"},"disableProbes":{"type":"boolean"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}},"required":["migration"]},"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"AppInfoEditDto":{"type":"object","description":"Partial update payload for an application component's deployment metadata; non-null fields replace the existing values and `envVarsDelete` removes specific variables.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"envVarsDelete":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}}}},"paths":{"/validators":{"put":{"tags":["validator-controller"],"summary":"Update validator","description":"Applies an in-place edit to an existing validator (image, env vars, overrides, database/wallet settings, etc.). Immutable fields cannot be changed and validators marked as `disableUserEdit` reject updates.","operationId":"updateValidator","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorEditDto"}}},"required":true},"responses":{"200":{"description":"OK"},"400":{"description":"The validator edit payload is invalid or attempts to change immutable fields.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the name referenced in the payload."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get validator pruning schedule

> Returns the validator's current pruning configuration (cron, retention, max duration) and the computed next run timestamp. Returns an empty DTO when no schedule is set.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-prune-controller","description":"Run pruning on a validator and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]}}},"paths":{"/validators/{name}/prune":{"get":{"tags":["validator-prune-controller"],"summary":"Get validator pruning schedule","description":"Returns the validator's current pruning configuration (cron, retention, max duration) and the computed next run timestamp. Returns an empty DTO when no schedule is set.","operationId":"getValidatorPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"}}}},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create validator pruning schedule

> Enables a cron-based ledger pruning schedule on the validator. Fails if a pruning schedule is already configured; use PUT to modify an existing one.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-prune-controller","description":"Run pruning on a validator and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]}}},"paths":{"/validators/{name}/prune":{"post":{"tags":["validator-prune-controller"],"summary":"Create validator pruning schedule","description":"Enables a cron-based ledger pruning schedule on the validator. Fails if a pruning schedule is already configured; use PUT to modify an existing one.","operationId":"createValidatorPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"The pruning schedule payload is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name."},"409":{"description":"A pruning schedule already exists for this validator."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update validator pruning schedule

> Replaces the cron expression, retention and max-duration of the validator's existing pruning schedule. Fails if no schedule has been configured yet.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-prune-controller","description":"Run pruning on a validator and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]}}},"paths":{"/validators/{name}/prune":{"put":{"tags":["validator-prune-controller"],"summary":"Update validator pruning schedule","description":"Replaces the cron expression, retention and max-duration of the validator's existing pruning schedule. Fails if no schedule has been configured yet.","operationId":"updateValidatorPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"}}},"required":true},"responses":{"204":{"description":"No Content"},"400":{"description":"The pruning schedule payload is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"The validator does not exist or has no pruning schedule configured."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete validator pruning schedule

> Removes the configured pruning schedule from the validator. Idempotent: succeeds with no-op if no schedule is currently set.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-prune-controller","description":"Run pruning on a validator and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/validators/{name}/prune":{"delete":{"tags":["validator-prune-controller"],"summary":"Delete validator pruning schedule","description":"Removes the configured pruning schedule from the validator. Idempotent: succeeds with no-op if no schedule is currently set.","operationId":"deleteValidatorPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create validator backup schedule

> Creates a scheduled (cron-based) database backup job for the validator's internal Postgres. Reactivates the schedule if it was previously soft-deleted. Not supported for validators backed by an external database.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-backup-controller","description":"Trigger validator backups, browse backup history and manage scheduled validator backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorBackupDto":{"type":"object","description":"Request body to trigger or schedule a Splice validator backup: cron expression and retention limit.","properties":{"cron":{"type":"string"},"maxBackups":{"type":"integer","format":"int32","maximum":84,"minimum":2}},"required":["maxBackups"]},"ScheduledValidatorBackupDto":{"type":"object","description":"Persisted backup schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/validators/{name}/backup":{"post":{"tags":["validator-backup-controller"],"summary":"Create validator backup schedule","description":"Creates a scheduled (cron-based) database backup job for the validator's internal Postgres. Reactivates the schedule if it was previously soft-deleted. Not supported for validators backed by an external database.","operationId":"createBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorBackupDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}},"400":{"description":"The backup schedule payload is invalid or the validator uses an external database.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}},"503":{"description":"Validator database is not running so a backup cannot be scheduled.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}}}}}}}
```

## Get validator backup schedule

> Returns the current backup schedule for the validator, including the cron expression and the computed unix timestamp of the next planned run.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-backup-controller","description":"Trigger validator backups, browse backup history and manage scheduled validator backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledValidatorBackupDto":{"type":"object","description":"Persisted backup schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/validators/{name}/backup":{"get":{"tags":["validator-backup-controller"],"summary":"Get validator backup schedule","description":"Returns the current backup schedule for the validator, including the cron expression and the computed unix timestamp of the next planned run.","operationId":"getBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator or backup schedule exists for the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update validator backup schedule

> Replaces the cron expression and retention settings on the validator's backup schedule. Also clears the soft-deleted flag, effectively reactivating a paused schedule.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-backup-controller","description":"Trigger validator backups, browse backup history and manage scheduled validator backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorBackupDto":{"type":"object","description":"Request body to trigger or schedule a Splice validator backup: cron expression and retention limit.","properties":{"cron":{"type":"string"},"maxBackups":{"type":"integer","format":"int32","maximum":84,"minimum":2}},"required":["maxBackups"]},"ScheduledValidatorBackupDto":{"type":"object","description":"Persisted backup schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/validators/{name}/backup":{"put":{"tags":["validator-backup-controller"],"summary":"Update validator backup schedule","description":"Replaces the cron expression and retention settings on the validator's backup schedule. Also clears the soft-deleted flag, effectively reactivating a paused schedule.","operationId":"updateBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorBackupDto"}}},"required":true},"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}},"400":{"description":"The backup schedule payload is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No backup schedule exists for the given validator.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete validator backup schedule

> Soft-deletes the validator's backup schedule so that no further backups run. The schedule resource is retained and can be reactivated by re-issuing a POST.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-backup-controller","description":"Trigger validator backups, browse backup history and manage scheduled validator backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/validators/{name}/backup":{"delete":{"tags":["validator-backup-controller"],"summary":"Delete validator backup schedule","description":"Soft-deletes the validator's backup schedule so that no further backups run. The schedule resource is retained and can be reactivated by re-issuing a POST.","operationId":"deleteBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No backup schedule exists for the given validator."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List remote participants with filters

> Returns a paginated list of CBM-side remote participant registrations, optionally filtered by health status, lifecycle phase, or name substring. The result also includes the total count of registrations matching the filters.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-controller","description":"Register and manage externally-hosted Canton participants reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteParticipantFilterResponseDto":{"type":"object","description":"Paginated list of `RemoteParticipantDto` entries plus the total count.","properties":{"participants":{"type":"array","items":{"$ref":"#/components/schemas/RemoteParticipantDto"}},"totalCount":{"type":"integer","format":"int64"}}},"RemoteParticipantDto":{"type":"object","description":"Externally-hosted Canton participant registered in CBM: admin / ledger / JSON-API endpoints, auth provider and identifying metadata.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonApiUrl":{"type":"string","minLength":1},"ledgerAddress":{"type":"string","minLength":1},"ledgerId":{"type":"string","minLength":1},"ledgerPort":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"v3":{"type":"boolean"}},"required":["adminAddress","adminPort","authProvider","image","jsonApiUrl","ledgerAddress","ledgerId","ledgerPort","name"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-participants":{"get":{"tags":["remote-participant-controller"],"summary":"List remote participants with filters","description":"Returns a paginated list of CBM-side remote participant registrations, optionally filtered by health status, lifecycle phase, or name substring. The result also includes the total count of registrations matching the filters.","operationId":"listRemoteParticipants","parameters":[{"name":"healthStatus","in":"query","description":"If set, only return participants whose last known health check matches this value.","required":false,"schema":{"type":"boolean"}},{"name":"from","in":"query","description":"Zero-based index of the first registration to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"status","in":"query","description":"Lifecycle phase to filter by (e.g. RUNNING, FAILED).","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}},{"name":"limit","in":"query","description":"Maximum number of registrations to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Case-sensitive substring matched against the registration name.","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteParticipantFilterResponseDto"}}}},"400":{"description":"Pagination or filter parameters are invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Register a remote participant

> Creates a CBM-side registration for a Canton participant node that runs outside the cluster. Only configuration metadata (endpoints, auth provider, resources) is stored; the remote workload itself is not provisioned by CBM.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-controller","description":"Register and manage externally-hosted Canton participants reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteParticipantDto":{"type":"object","description":"Externally-hosted Canton participant registered in CBM: admin / ledger / JSON-API endpoints, auth provider and identifying metadata.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonApiUrl":{"type":"string","minLength":1},"ledgerAddress":{"type":"string","minLength":1},"ledgerId":{"type":"string","minLength":1},"ledgerPort":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"v3":{"type":"boolean"}},"required":["adminAddress","adminPort","authProvider","image","jsonApiUrl","ledgerAddress","ledgerId","ledgerPort","name"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-participants":{"post":{"tags":["remote-participant-controller"],"summary":"Register a remote participant","description":"Creates a CBM-side registration for a Canton participant node that runs outside the cluster. Only configuration metadata (endpoints, auth provider, resources) is stored; the remote workload itself is not provisioned by CBM.","operationId":"createRemoteParticipant","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RemoteParticipantDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteParticipantDto"}}}},"400":{"description":"The request payload failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A remote participant with the same name is already registered in CBM.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteParticipantDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update a remote participant registration

> Updates the CBM-side configuration (endpoints, auth provider, resources) for an existing remote participant. The remote Canton node is not reconfigured by this call.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-controller","description":"Register and manage externally-hosted Canton participants reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteParticipantDto":{"type":"object","description":"Externally-hosted Canton participant registered in CBM: admin / ledger / JSON-API endpoints, auth provider and identifying metadata.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonApiUrl":{"type":"string","minLength":1},"ledgerAddress":{"type":"string","minLength":1},"ledgerId":{"type":"string","minLength":1},"ledgerPort":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"v3":{"type":"boolean"}},"required":["adminAddress","adminPort","authProvider","image","jsonApiUrl","ledgerAddress","ledgerId","ledgerPort","name"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-participants":{"put":{"tags":["remote-participant-controller"],"summary":"Update a remote participant registration","description":"Updates the CBM-side configuration (endpoints, auth provider, resources) for an existing remote participant. The remote Canton node is not reconfigured by this call.","operationId":"updateRemoteParticipant","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RemoteParticipantDto"}}},"required":true},"responses":{"200":{"description":"OK"},"400":{"description":"The request payload failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Connects/Disconnects an already registered domain to a participant

> Proxies an admin-API call to the remote participant to toggle the connection state of a previously registered domain. Use the connect query flag to choose between connect and disconnect.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-connection-controller","description":"Configure, register, connect and disconnect a remote Canton participant against one of its sync domains."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/connections/{domainAlias}":{"put":{"tags":["remote-participant-connection-controller"],"summary":"Connects/Disconnects an already registered domain to a participant","description":"Proxies an admin-API call to the remote participant to toggle the connection state of a previously registered domain. Use the connect query flag to choose between connect and disconnect.","operationId":"updateRemoteParticipantConnection","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"domainAlias","in":"path","description":"Alias of the domain connection already registered on the participant.","required":true,"schema":{"type":"string"}},{"name":"connect","in":"query","description":"true to connect, false to disconnect","required":true,"schema":{"type":"boolean","description":"true to connect, false to disconnect"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The participant name or domain alias is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Either the participant is not registered in CBM or the domain alias is unknown on the remote node."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List remote domains with filtering and pagination

> Returns the CBM-registered remote domains, optionally filtered by health status, lifecycle phase or name. Pagination is controlled via the from/limit query parameters. This call reads local registration metadata and does not query the remote nodes.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-controller","description":"Register and manage externally-hosted Canton sync domains reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteDomainFilterResponseDto":{"type":"object","description":"Paginated list of `RemoteDomainDto` entries plus the total count.","properties":{"domains":{"type":"array","items":{"$ref":"#/components/schemas/RemoteDomainDto"}},"totalCount":{"type":"integer","format":"int64"}}},"RemoteDomainDto":{"type":"object","description":"Externally-hosted sync domain registered in CBM: admin / public endpoints, image metadata and lifecycle phase.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string","minLength":1},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["adminAddress","adminPort","image","name","publicAddress","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-domains":{"get":{"tags":["remote-domain-controller"],"summary":"List remote domains with filtering and pagination","description":"Returns the CBM-registered remote domains, optionally filtered by health status, lifecycle phase or name. Pagination is controlled via the from/limit query parameters. This call reads local registration metadata and does not query the remote nodes.","operationId":"listRemoteDomains","parameters":[{"name":"healthStatus","in":"query","description":"If set, returns only remote domains whose last observed health matches this value.","required":false,"schema":{"type":"boolean"}},{"name":"from","in":"query","description":"Zero-based offset of the first remote domain to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"status","in":"query","description":"Lifecycle phase to filter by (e.g. running, failed).","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}},{"name":"limit","in":"query","description":"Maximum number of remote domains to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Case-insensitive substring filter on the remote domain registration name.","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteDomainFilterResponseDto"}}}},"400":{"description":"One of the query parameters has an invalid value.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Register a remote domain

> Stores CBM-side registration metadata for a Canton sync domain that runs outside this cluster. The remote domain workload itself is not created here; CBM only tracks the connection details so subsequent operations can be proxied to it.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-controller","description":"Register and manage externally-hosted Canton sync domains reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteDomainDto":{"type":"object","description":"Externally-hosted sync domain registered in CBM: admin / public endpoints, image metadata and lifecycle phase.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string","minLength":1},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["adminAddress","adminPort","image","name","publicAddress","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-domains":{"post":{"tags":["remote-domain-controller"],"summary":"Register a remote domain","description":"Stores CBM-side registration metadata for a Canton sync domain that runs outside this cluster. The remote domain workload itself is not created here; CBM only tracks the connection details so subsequent operations can be proxied to it.","operationId":"createRemoteDomain","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RemoteDomainDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteDomainDto"}}}},"400":{"description":"Invalid registration payload.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A node with the same name is already registered or running in the cluster.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteDomainDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update a remote domain registration

> Updates the CBM-side connection metadata (addresses, ports, image, resources) for a previously registered remote domain. The remote node itself is not modified by this call.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-controller","description":"Register and manage externally-hosted Canton sync domains reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteDomainDto":{"type":"object","description":"Externally-hosted sync domain registered in CBM: admin / public endpoints, image metadata and lifecycle phase.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string","minLength":1},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["adminAddress","adminPort","image","name","publicAddress","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-domains":{"put":{"tags":["remote-domain-controller"],"summary":"Update a remote domain registration","description":"Updates the CBM-side connection metadata (addresses, ports, image, resources) for a previously registered remote domain. The remote node itself is not modified by this call.","operationId":"updateRemoteDomain","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RemoteDomainDto"}}},"required":true},"responses":{"200":{"description":"OK"},"400":{"description":"Invalid update payload.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List participants

> Returns the paginated list of participants matching the given filters along with the total count of matches (ignoring pagination). All filter parameters are optional and combined with AND semantics.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-controller","description":"Create, list, edit and remove Canton participant deployments, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ParticipantFilterResponseDto":{"type":"object","description":"Paginated list of `ParticipantDto` entries plus the total count of participants matching the filter.","properties":{"participants":{"type":"array","items":{"$ref":"#/components/schemas/ParticipantDto"}},"totalCount":{"type":"integer","format":"int64"}}},"ParticipantDto":{"type":"object","description":"Canton participant definition: container image, admin / ledger endpoints, authentication, postgres storage and Canton-specific settings used to provision a new participant deployment.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"auth":{"type":"boolean"},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"authorization":{"$ref":"#/components/schemas/AuthorizationDto"},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonapi":{"type":"boolean"},"jsonapiImage":{"type":"string"},"privateJsonapi":{"type":"boolean"},"jsonapiQueryStore":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"ledgerAddress":{"type":"string"},"ledgerPort":{"type":"string","minLength":1},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"navigator":{"type":"boolean"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"},"validatorParent":{"type":"string"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}},"required":["adminPort","authProvider","image","ledgerPort","name"]},"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/participants":{"get":{"tags":["participant-controller"],"summary":"List participants","description":"Returns the paginated list of participants matching the given filters along with the total count of matches (ignoring pagination). All filter parameters are optional and combined with AND semantics.","operationId":"listParticipants","parameters":[{"name":"healthStatus","in":"query","description":"If true, returns only participants reported as healthy; if false, only unhealthy ones.","required":false,"schema":{"type":"boolean"}},{"name":"from","in":"query","description":"Zero-based offset of the first participant to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"status","in":"query","description":"Lifecycle phase to filter by (e.g. RUNNING, PENDING, FAILED).","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}},{"name":"limit","in":"query","description":"Maximum number of participants to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Substring match on the participant Kubernetes resource name.","required":false,"schema":{"type":"string"}},{"name":"storageType","in":"query","description":"Storage backend to filter by (e.g. POSTGRES, EXTERNAL, MEMORY).","required":false,"schema":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantFilterResponseDto"}}}},"400":{"description":"One or more query parameters failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create participant

> Provisions a new Canton participant in this CBM by creating the underlying Kubernetes Custom Resource. When the storage type is EXTERNAL or POSTGRES, a database secret is recreated with the provided credentials. The operation is asynchronous: a 201 response means the resource has been accepted; lifecycle status must be polled via the GET endpoint.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-controller","description":"Create, list, edit and remove Canton participant deployments, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ParticipantDto":{"type":"object","description":"Canton participant definition: container image, admin / ledger endpoints, authentication, postgres storage and Canton-specific settings used to provision a new participant deployment.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"auth":{"type":"boolean"},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"authorization":{"$ref":"#/components/schemas/AuthorizationDto"},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonapi":{"type":"boolean"},"jsonapiImage":{"type":"string"},"privateJsonapi":{"type":"boolean"},"jsonapiQueryStore":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"ledgerAddress":{"type":"string"},"ledgerPort":{"type":"string","minLength":1},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"navigator":{"type":"boolean"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"},"validatorParent":{"type":"string"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}},"required":["adminPort","authProvider","image","ledgerPort","name"]},"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/participants":{"post":{"tags":["participant-controller"],"summary":"Create participant","description":"Provisions a new Canton participant in this CBM by creating the underlying Kubernetes Custom Resource. When the storage type is EXTERNAL or POSTGRES, a database secret is recreated with the provided credentials. The operation is asynchronous: a 201 response means the resource has been accepted; lifecycle status must be polled via the GET endpoint.","operationId":"createParticipant","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ParticipantDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantDto"}}}},"400":{"description":"The participant payload failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A participant or backing workload with the same name already exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update participant

> Applies the supplied configuration to the existing participant Custom Resource. The participant is identified by the name field of the body. The operator picks up the change and rolls the workload asynchronously; this endpoint only acknowledges that the CR has been updated.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-controller","description":"Create, list, edit and remove Canton participant deployments, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ParticipantDto":{"type":"object","description":"Canton participant definition: container image, admin / ledger endpoints, authentication, postgres storage and Canton-specific settings used to provision a new participant deployment.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"auth":{"type":"boolean"},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"authorization":{"$ref":"#/components/schemas/AuthorizationDto"},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonapi":{"type":"boolean"},"jsonapiImage":{"type":"string"},"privateJsonapi":{"type":"boolean"},"jsonapiQueryStore":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"ledgerAddress":{"type":"string"},"ledgerPort":{"type":"string","minLength":1},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"navigator":{"type":"boolean"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"},"validatorParent":{"type":"string"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}},"required":["adminPort","authProvider","image","ledgerPort","name"]},"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/participants":{"put":{"tags":["participant-controller"],"summary":"Update participant","description":"Applies the supplied configuration to the existing participant Custom Resource. The participant is identified by the name field of the body. The operator picks up the change and rolls the workload asynchronously; this endpoint only acknowledges that the CR has been updated.","operationId":"updateParticipant","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ParticipantDto"}}},"required":true},"responses":{"200":{"description":"OK"},"400":{"description":"The participant payload failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Connects/Disconnects an already registered domain to a participant

> Toggles the connection state of an existing sync-domain registration on the participant. The domain must already be registered via POST; this endpoint does not modify the connection configuration, only its connected/disconnected state.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"connection-controller","description":"Configure, register, connect and disconnect a Canton participant against one of its sync domains."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/connections/{domainAlias}":{"put":{"tags":["connection-controller"],"summary":"Connects/Disconnects an already registered domain to a participant","description":"Toggles the connection state of an existing sync-domain registration on the participant. The domain must already be registered via POST; this endpoint does not modify the connection configuration, only its connected/disconnected state.","operationId":"updateParticipantConnection","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant holding the connection.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"domainAlias","in":"path","description":"Alias of the previously registered sync domain to (dis)connect.","required":true,"schema":{"type":"string"}},{"name":"connect","in":"query","description":"true to connect, false to disconnect","required":true,"schema":{"type":"boolean","description":"true to connect, false to disconnect"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The participant name, domain alias or port failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No such participant exists or the domain alias is not registered."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Set the runtime log level for a node

> Adjusts the log level used by the Canton node at runtime without restarting the pod. Takes effect immediately for subsequent log output.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"log-controller","description":"Stream pod logs and adjust log levels at runtime for the managed workloads."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/logs/{name}/{level}":{"put":{"tags":["log-controller"],"summary":"Set the runtime log level for a node","description":"Adjusts the log level used by the Canton node at runtime without restarting the pod. Takes effect immediately for subsequent log output.","operationId":"updateLogLevel","parameters":[{"name":"name","in":"path","description":"Name of the Canton node whose log level should be updated","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"level","in":"path","description":"New log level to apply","required":true,"schema":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]}}],"responses":{"200":{"description":"OK"},"400":{"description":"Invalid node name or log level","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node or its pod not found"},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get identity dump schedule

> Returns the current identity dump schedule for the validator along with the computed unix timestamp of the next planned run.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledValidatorIdDumpDto":{"type":"object","description":"Persisted identity-dump schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"validatorName":{"type":"string"},"cron":{"type":"string"},"nextRun":{"type":"string"},"maxDumps":{"type":"integer","format":"int32"}}}}},"paths":{"/id-dumps/{validatorName}/schedule":{"get":{"tags":["validator-id-dumps-controller"],"summary":"Get identity dump schedule","description":"Returns the current identity dump schedule for the validator along with the computed unix timestamp of the next planned run.","operationId":"getSchedule","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorIdDumpDto"}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator or identity dump schedule exists for the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorIdDumpDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create identity dump schedule

> Creates a cron-based schedule that periodically produces identity dumps for the validator, retaining at most \`maxDumps\` of them. Reactivates a soft-deleted schedule if one exists.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorIdDumpScheduleDto":{"type":"object","description":"Request body to schedule recurring identity dumps for a Splice validator (cron expression plus retention limit); converts to the underlying CRD.","properties":{"cron":{"type":"string"},"maxDumps":{"type":"integer","format":"int32","minimum":1}}},"ScheduledValidatorIdDumpDto":{"type":"object","description":"Persisted identity-dump schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"validatorName":{"type":"string"},"cron":{"type":"string"},"nextRun":{"type":"string"},"maxDumps":{"type":"integer","format":"int32"}}}}},"paths":{"/id-dumps/{validatorName}/schedule":{"post":{"tags":["validator-id-dumps-controller"],"summary":"Create identity dump schedule","description":"Creates a cron-based schedule that periodically produces identity dumps for the validator, retaining at most `maxDumps` of them. Reactivates a soft-deleted schedule if one exists.","operationId":"createSchedule","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorIdDumpScheduleDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorIdDumpDto"}}}},"400":{"description":"The schedule payload is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorIdDumpDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update identity dump schedule

> Replaces the cron expression and retention (\`maxDumps\`) of the validator's identity dump schedule. Also clears the soft-deleted flag, reactivating a paused schedule.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorIdDumpScheduleDto":{"type":"object","description":"Request body to schedule recurring identity dumps for a Splice validator (cron expression plus retention limit); converts to the underlying CRD.","properties":{"cron":{"type":"string"},"maxDumps":{"type":"integer","format":"int32","minimum":1}}},"ScheduledValidatorIdDumpDto":{"type":"object","description":"Persisted identity-dump schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"validatorName":{"type":"string"},"cron":{"type":"string"},"nextRun":{"type":"string"},"maxDumps":{"type":"integer","format":"int32"}}}}},"paths":{"/id-dumps/{validatorName}/schedule":{"put":{"tags":["validator-id-dumps-controller"],"summary":"Update identity dump schedule","description":"Replaces the cron expression and retention (`maxDumps`) of the validator's identity dump schedule. Also clears the soft-deleted flag, reactivating a paused schedule.","operationId":"updateSchedule","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorIdDumpScheduleDto"}}},"required":true},"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorIdDumpDto"}}}},"400":{"description":"The schedule payload is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No identity dump schedule exists for the given validator.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledValidatorIdDumpDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete identity dump schedule

> Soft-deletes the validator's identity dump schedule so that no further dumps run. The resource is preserved and can be reactivated via POST.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/id-dumps/{validatorName}/schedule":{"delete":{"tags":["validator-id-dumps-controller"],"summary":"Delete identity dump schedule","description":"Soft-deletes the validator's identity dump schedule so that no further dumps run. The resource is preserved and can be reactivated via POST.","operationId":"deleteSchedule","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No identity dump schedule exists for the given validator."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List sync domains with filtering

> Returns a paginated list of sync domains matching the supplied filters together with the total count of matches. All filter parameters are optional and combined with AND.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-controller","description":"Create, list, edit and remove Canton sync domains, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainFilterResponseDto":{"type":"object","description":"Paginated list of `DomainDto` entries plus the total count of sync domains matching the filter.","properties":{"domains":{"type":"array","items":{"$ref":"#/components/schemas/DomainDto"}},"totalCount":{"type":"integer","format":"int64"}}},"DomainDto":{"type":"object","description":"Canton sync domain definition: name, container image, log level, admin / public endpoints and Canton-specific bootstrap settings used to provision a single-replica sync domain.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"ingress":{"type":"boolean"},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string"},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"}},"required":["adminPort","image","name","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/domains":{"get":{"tags":["domain-controller"],"summary":"List sync domains with filtering","description":"Returns a paginated list of sync domains matching the supplied filters together with the total count of matches. All filter parameters are optional and combined with AND.","operationId":"listDomains","parameters":[{"name":"healthStatus","in":"query","description":"Filter by health status; true returns only healthy domains, false only unhealthy.","required":false,"schema":{"type":"boolean"}},{"name":"from","in":"query","description":"Zero-based index of the first domain to return for pagination.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"status","in":"query","description":"Filter by the lifecycle phase of the domain.","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}},{"name":"limit","in":"query","description":"Maximum number of domains to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Filter by domain name (substring match).","required":false,"schema":{"type":"string"}},{"name":"storageType","in":"query","description":"Filter by the configured storage type of the domain.","required":false,"schema":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainFilterResponseDto"}}}},"400":{"description":"One or more query parameters are invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create a new sync domain

> Provisions a new Canton sync domain as a Kubernetes resource. For external or Postgres storage, the database credentials are stored in a dedicated secret and injected as environment variables. The created domain is returned in its initial state.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-controller","description":"Create, list, edit and remove Canton sync domains, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainDto":{"type":"object","description":"Canton sync domain definition: name, container image, log level, admin / public endpoints and Canton-specific bootstrap settings used to provision a single-replica sync domain.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"ingress":{"type":"boolean"},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string"},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"}},"required":["adminPort","image","name","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/domains":{"post":{"tags":["domain-controller"],"summary":"Create a new sync domain","description":"Provisions a new Canton sync domain as a Kubernetes resource. For external or Postgres storage, the database credentials are stored in a dedicated secret and injected as environment variables. The created domain is returned in its initial state.","operationId":"createDomain","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DomainDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainDto"}}}},"400":{"description":"The request payload is invalid or fails validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A domain with the same name already exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update an existing sync domain

> Applies the supplied spec changes to the existing sync domain resource. The domain is identified by the name field in the request body.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-controller","description":"Create, list, edit and remove Canton sync domains, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainDto":{"type":"object","description":"Canton sync domain definition: name, container image, log level, admin / public endpoints and Canton-specific bootstrap settings used to provision a single-replica sync domain.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"ingress":{"type":"boolean"},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string"},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"}},"required":["adminPort","image","name","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/domains":{"put":{"tags":["domain-controller"],"summary":"Update an existing sync domain","description":"Applies the supplied spec changes to the existing sync domain resource. The domain is identified by the name field in the request body.","operationId":"updateDomain","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DomainDto"}}},"required":true},"responses":{"200":{"description":"OK"},"400":{"description":"The request payload is invalid or fails validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List HA sync domains with filtering

> Returns a paginated list of HA sync domains matching the supplied filters together with the total count. All filter parameters are optional.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-ha-controller","description":"Configure and inspect high-availability settings of a Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainHAResponseDto":{"type":"object","description":"Paginated list of HA sync domain entries plus the total count.","properties":{"domainHAs":{"type":"array","items":{"$ref":"#/components/schemas/DomainHAEntry"}},"totalCount":{"type":"integer","format":"int64"}}},"DomainHAEntry":{"type":"object","properties":{"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"status":{"$ref":"#/components/schemas/DomainHAStatusDto"}},"required":["name","status"]},"DomainHAStatusDto":{"type":"object","description":"Runtime status of an HA sync domain split per component (mediator, topology manager, sequencer, in-cluster database, bootstrap).","properties":{"mediator":{"$ref":"#/components/schemas/MediatorStatusDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerStatusDto"},"sequencer":{"$ref":"#/components/schemas/SequencerStatusDto"},"inClusterDatabase":{"$ref":"#/components/schemas/InClusterDatabaseStatusDto"},"bootstrap":{"$ref":"#/components/schemas/BootstrapStatusDto"}}},"MediatorStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"TopologyManagerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"SequencerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"InClusterDatabaseStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"BootstrapStatusDto":{"type":"object","properties":{"started":{"type":"boolean"},"completed":{"type":"boolean"},"error":{"type":"string"},"ready":{"type":"boolean"}}}}},"paths":{"/domainha":{"get":{"tags":["domain-ha-controller"],"summary":"List HA sync domains with filtering","description":"Returns a paginated list of HA sync domains matching the supplied filters together with the total count. All filter parameters are optional.","operationId":"list","parameters":[{"name":"from","in":"query","description":"Zero-based index of the first HA domain to return for pagination.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"limit","in":"query","description":"Maximum number of HA domains to return.","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Filter by HA domain name (substring match).","required":false,"schema":{"type":"string"}},{"name":"phase","in":"query","description":"Filter by the lifecycle phase of the HA domain.","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHAResponseDto"}}}},"400":{"description":"One or more query parameters are invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create a highly available sync domain

> Provisions a new sync domain with replicated mediator and sequencer components to support failover. Fails if a HA domain with the same name already exists.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-ha-controller","description":"Configure and inspect high-availability settings of a Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainHADto":{"type":"object","description":"High-availability sync domain definition: per-component (sequencer, mediator, topology manager) specifications plus in-cluster or external storage settings.","properties":{"name":{"type":"string","maxLength":15,"minLength":2},"defaults":{"$ref":"#/components/schemas/DefaultsDto"},"sequencer":{"$ref":"#/components/schemas/SequencerSpecDto"},"mediator":{"$ref":"#/components/schemas/MediatorSpecDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerSpecDto"},"externalStorage":{"$ref":"#/components/schemas/ExternalStorageSpecDto"},"inClusterStorage":{"$ref":"#/components/schemas/InClusterStorageSpecDto"},"validStorage":{"type":"boolean"}},"required":["defaults","mediator","name","sequencer","topologyManager"]},"DefaultsDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"SequencerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"ingress":{"$ref":"#/components/schemas/SequencerIngressConfigDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"SequencerIngressConfigDto":{"type":"object","description":"Per-sequencer ingress flags toggling exposure of the admin and public APIs.","properties":{"adminAPIEnabled":{"type":"boolean"},"publicAPIEnabled":{"type":"boolean"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}},"MediatorSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"TopologyManagerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ExternalStorageSpecDto":{"type":"object","properties":{"hostname":{"type":"string","minLength":1},"port":{"type":"integer","format":"int32"},"adminUsername":{"type":"string","minLength":1},"adminPassword":{"type":"string","minLength":1},"ssl":{"type":"boolean"},"maxConnections":{"type":"integer","format":"int32"},"schemaName":{"type":"string"}},"required":["adminPassword","adminUsername","hostname","port"]},"InClusterStorageSpecDto":{"type":"object","properties":{"storageSize":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"validStorageSize":{"type":"boolean"}},"required":["resources","storageSize"]}}},"paths":{"/domainha":{"post":{"tags":["domain-ha-controller"],"summary":"Create a highly available sync domain","description":"Provisions a new sync domain with replicated mediator and sequencer components to support failover. Fails if a HA domain with the same name already exists.","operationId":"create","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}}},"400":{"description":"The request payload is invalid or fails validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A HA sync domain with the same name already exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update an existing HA sync domain

> Applies the supplied editable changes to the HA sync domain resource and returns the updated DTO. The HA domain is identified by the name in the request body.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-ha-controller","description":"Configure and inspect high-availability settings of a Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainHAEditDto":{"type":"object","description":"Partial update payload for an HA sync domain; non-null sections replace the corresponding configuration on the existing deployment.","properties":{"name":{"type":"string"},"defaults":{"$ref":"#/components/schemas/DefaultsEditDto"},"sequencer":{"$ref":"#/components/schemas/SequencerEditDto"},"mediator":{"$ref":"#/components/schemas/MediatorEditDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerEditDto"},"inClusterStorage":{"$ref":"#/components/schemas/InClusterStorageEditDto"}},"required":["defaults","mediator","name","sequencer","topologyManager"]},"DefaultsEditDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"SequencerEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"MediatorEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"TopologyManagerEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"InClusterStorageEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"storageSize":{"type":"string"},"validStorageSize":{"type":"boolean"}},"required":["resources"]},"DomainHADto":{"type":"object","description":"High-availability sync domain definition: per-component (sequencer, mediator, topology manager) specifications plus in-cluster or external storage settings.","properties":{"name":{"type":"string","maxLength":15,"minLength":2},"defaults":{"$ref":"#/components/schemas/DefaultsDto"},"sequencer":{"$ref":"#/components/schemas/SequencerSpecDto"},"mediator":{"$ref":"#/components/schemas/MediatorSpecDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerSpecDto"},"externalStorage":{"$ref":"#/components/schemas/ExternalStorageSpecDto"},"inClusterStorage":{"$ref":"#/components/schemas/InClusterStorageSpecDto"},"validStorage":{"type":"boolean"}},"required":["defaults","mediator","name","sequencer","topologyManager"]},"DefaultsDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"SequencerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"ingress":{"$ref":"#/components/schemas/SequencerIngressConfigDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"SequencerIngressConfigDto":{"type":"object","description":"Per-sequencer ingress flags toggling exposure of the admin and public APIs.","properties":{"adminAPIEnabled":{"type":"boolean"},"publicAPIEnabled":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}},"MediatorSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"TopologyManagerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ExternalStorageSpecDto":{"type":"object","properties":{"hostname":{"type":"string","minLength":1},"port":{"type":"integer","format":"int32"},"adminUsername":{"type":"string","minLength":1},"adminPassword":{"type":"string","minLength":1},"ssl":{"type":"boolean"},"maxConnections":{"type":"integer","format":"int32"},"schemaName":{"type":"string"}},"required":["adminPassword","adminUsername","hostname","port"]},"InClusterStorageSpecDto":{"type":"object","properties":{"storageSize":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"validStorageSize":{"type":"boolean"}},"required":["resources","storageSize"]}}},"paths":{"/domainha":{"put":{"tags":["domain-ha-controller"],"summary":"Update an existing HA sync domain","description":"Applies the supplied editable changes to the HA sync domain resource and returns the updated DTO. The HA domain is identified by the name in the request body.","operationId":"update","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/DomainHAEditDto"}}},"required":true},"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}}},"400":{"description":"The request payload is invalid or fails validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No HA sync domain exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List applications with filtering and pagination

> Returns a page of deployed applications optionally filtered by status, name and type. Supports offset/limit pagination via the from and limit query parameters.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"application-controller","description":"Manage generic CBM-deployed applications and their lifecycle."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ApplicationFilterResponseDto":{"type":"object","description":"Paginated list of `ApplicationDto` entries plus the total count of applications matching the filter.","properties":{"applications":{"type":"array","items":{"$ref":"#/components/schemas/ApplicationDto"}},"totalCount":{"type":"integer","format":"int64"}}},"ApplicationDto":{"type":"object","description":"Generic CBM-deployed application: name, container image, port, package, parent validator and Kubernetes resource requirements; used both as a request and a response body on the applications endpoints.","properties":{"domain":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string"},"name":{"type":"string","minLength":1},"packageName":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"port":{"type":"integer","format":"int32"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"type":{"type":"string","enum":["BACKEND","UI"]},"validatorParent":{"type":"string"}},"required":["domain","name","type"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/applications":{"get":{"tags":["application-controller"],"summary":"List applications with filtering and pagination","description":"Returns a page of deployed applications optionally filtered by status, name and type. Supports offset/limit pagination via the from and limit query parameters.","operationId":"listApplications","parameters":[{"name":"from","in":"query","description":"Zero-based index of the first application to return","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"status","in":"query","description":"Filter by current lifecycle phase of the application","required":false,"schema":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]}},{"name":"limit","in":"query","description":"Maximum number of applications to return","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Filter by application name (substring match)","required":false,"schema":{"type":"string"}},{"name":"type","in":"query","description":"Filter by application type","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ApplicationFilterResponseDto"}}}},"400":{"description":"Invalid filter or pagination parameters","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create a new application

> Deploys a new CBM application CRD onto the Kubernetes cluster. When the target participant uses an OIDC auth provider (e.g. Keycloak), the corresponding auth client and environment variables are provisioned automatically. Fails if a resource with the same name already exists.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"application-controller","description":"Manage generic CBM-deployed applications and their lifecycle."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ApplicationDto":{"type":"object","description":"Generic CBM-deployed application: name, container image, port, package, parent validator and Kubernetes resource requirements; used both as a request and a response body on the applications endpoints.","properties":{"domain":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string"},"name":{"type":"string","minLength":1},"packageName":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"port":{"type":"integer","format":"int32"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"type":{"type":"string","enum":["BACKEND","UI"]},"validatorParent":{"type":"string"}},"required":["domain","name","type"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/applications":{"post":{"tags":["application-controller"],"summary":"Create a new application","description":"Deploys a new CBM application CRD onto the Kubernetes cluster. When the target participant uses an OIDC auth provider (e.g. Keycloak), the corresponding auth client and environment variables are provisioned automatically. Fails if a resource with the same name already exists.","operationId":"createApplication","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApplicationDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ApplicationDto"}}}},"400":{"description":"Invalid application payload","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"An application or resource with the same name already exists","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ApplicationDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Update an existing application

> Applies the provided application spec to the existing CRD, updating image, env vars, resources and other mutable fields.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"application-controller","description":"Manage generic CBM-deployed applications and their lifecycle."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ApplicationDto":{"type":"object","description":"Generic CBM-deployed application: name, container image, port, package, parent validator and Kubernetes resource requirements; used both as a request and a response body on the applications endpoints.","properties":{"domain":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string"},"name":{"type":"string","minLength":1},"packageName":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"port":{"type":"integer","format":"int32"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"type":{"type":"string","enum":["BACKEND","UI"]},"validatorParent":{"type":"string"}},"required":["domain","name","type"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/applications":{"put":{"tags":["application-controller"],"summary":"Update an existing application","description":"Applies the provided application spec to the existing CRD, updating image, env vars, resources and other mutable fields.","operationId":"updateApplication","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApplicationDto"}}},"required":true},"responses":{"200":{"description":"OK"},"400":{"description":"Invalid application payload","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Application not found"},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get validator restore job

> Returns the current status and metadata of the validator's most recent restore job. Use this to poll the progress of a previously triggered restore.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-restore-controller","description":"Restore a Splice validator from a previously created backup (database, identity, wallet)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorRestoreResponseDto":{"type":"object","description":"Single entry in the validator restore history: filenames restored from, overall status and capture timestamp.","properties":{"filenames":{"type":"array","items":{"type":"string"},"maxItems":2,"minItems":2},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/validators/{name}/restore":{"get":{"tags":["validator-restore-controller"],"summary":"Get validator restore job","description":"Returns the current status and metadata of the validator's most recent restore job. Use this to poll the progress of a previously triggered restore.","operationId":"getRestoreJob","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorRestoreResponseDto"}}}},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No restore job exists for the given validator.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorRestoreResponseDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Trigger validator restore

> Starts a long-running restore job that recreates the validator's state from the referenced backup files. Returns immediately with the created job descriptor; poll the GET endpoint for status. Any previous completed restore job for this validator is deleted first.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-restore-controller","description":"Restore a Splice validator from a previously created backup (database, identity, wallet)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorRestoreDto":{"type":"object","description":"Request body to start a Splice validator restore from one or more previously captured backup files.","properties":{"filenames":{"type":"array","items":{"type":"string"},"maxItems":2,"minItems":2}}},"ValidatorRestoreResponseDto":{"type":"object","description":"Single entry in the validator restore history: filenames restored from, overall status and capture timestamp.","properties":{"filenames":{"type":"array","items":{"type":"string"},"maxItems":2,"minItems":2},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/validators/{name}/restore":{"post":{"tags":["validator-restore-controller"],"summary":"Trigger validator restore","description":"Starts a long-running restore job that recreates the validator's state from the referenced backup files. Returns immediately with the created job descriptor; poll the GET endpoint for status. Any previous completed restore job for this validator is deleted first.","operationId":"createRestoreJob","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator to restore.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ValidatorRestoreDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorRestoreResponseDto"}}}},"400":{"description":"The restore payload references missing or invalid backup files.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorRestoreResponseDto"}}}},"409":{"description":"A restore job is already running for this validator.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorRestoreResponseDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Check sponsor scan quorum

> Verifies that the supplied sponsor scan address can reach a quorum of Super Validators on the network. Used as a pre-flight check before launching a prefill.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-prefill-controller","description":"Prefill a Splice validator, check quorum status and perform top-up operations."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"CheckQuorumRequest":{"type":"object","description":"Request body for the Splice prefill quorum check; references the sponsor scan address used during validator on-boarding.","properties":{"sponsorScanAddress":{"type":"string"}}}}},"paths":{"/validators/prefill/check-quorum":{"post":{"tags":["validator-prefill-controller"],"summary":"Check sponsor scan quorum","description":"Verifies that the supplied sponsor scan address can reach a quorum of Super Validators on the network. Used as a pre-flight check before launching a prefill.","operationId":"checkQuorum","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CheckQuorumRequest"}}},"required":true},"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"boolean"}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get the pruning schedule of a participant

> Reads the current pruning schedule from the remote enterprise participant and enriches it with the Unix timestamp of the next scheduled cron run, computed in CBM.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-prune-controller","description":"Run pruning on a remote participant and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/remote-participants/{name}/prune":{"get":{"tags":["remote-participant-prune-controller"],"summary":"Get the pruning schedule of a participant","description":"Reads the current pruning schedule from the remote enterprise participant and enriches it with the Unix timestamp of the next scheduled cron run, computed in CBM.","operationId":"getRemoteParticipantPruningSchedule","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"400":{"description":"The supplied participant name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name or no schedule is configured.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create a pruning schedule on a participant

> Validates the cron expression and sends it to the remote enterprise participant's admin API, which will then prune old ledger data on the configured cadence.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-prune-controller","description":"Run pruning on a remote participant and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/remote-participants/{name}/prune":{"post":{"tags":["remote-participant-prune-controller"],"summary":"Create a pruning schedule on a participant","description":"Validates the cron expression and sends it to the remote enterprise participant's admin API, which will then prune old ledger data on the configured cadence.","operationId":"createRemoteParticipantPruningSchedule","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"The participant name, cron expression, or retention payload is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Clear the pruning schedule on a participant

> Proxies a clear-schedule call to the remote enterprise participant so that no further automatic pruning runs are triggered. Previously pruned data is not restored.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-prune-controller","description":"Run pruning on a remote participant and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/prune":{"delete":{"tags":["remote-participant-prune-controller"],"summary":"Clear the pruning schedule on a participant","description":"Proxies a clear-schedule call to the remote enterprise participant so that no further automatic pruning runs are triggered. Previously pruned data is not restored.","operationId":"deleteRemoteParticipantPruningSchedule","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied participant name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy a GET request to the participant JSON Ledger API

> Forwards the incoming GET request (path beyond /jsonapi, query string, headers) to the configured JSON Ledger API endpoint of the remote participant and streams the response back.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-json-api-controller","description":"Proxy requests to the JSON Ledger API of a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/jsonapi/**":{"get":{"tags":["remote-participant-json-api-controller"],"summary":"Proxy a GET request to the participant JSON Ledger API","description":"Forwards the incoming GET request (path beyond /jsonapi, query string, headers) to the configured JSON Ledger API endpoint of the remote participant and streams the response back.","operationId":"getRemoteParticipantRequest","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy a POST request to the participant JSON Ledger API

> Forwards the incoming POST request body and path/query to the configured JSON Ledger API endpoint of the remote participant. Used for command submission and similar mutating ledger operations.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-json-api-controller","description":"Proxy requests to the JSON Ledger API of a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/jsonapi/**":{"post":{"tags":["remote-participant-json-api-controller"],"summary":"Proxy a POST request to the participant JSON Ledger API","description":"Forwards the incoming POST request body and path/query to the configured JSON Ledger API endpoint of the remote participant. Used for command submission and similar mutating ledger operations.","operationId":"postRemoteParticipantRequest","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"The remote JSON Ledger API rejected the request due to a state conflict (e.g. duplicate command id).","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy a DELETE request to the participant JSON Ledger API

> Forwards the incoming DELETE request to the configured JSON Ledger API endpoint of the remote participant, typically used to cancel or release ledger resources.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-json-api-controller","description":"Proxy requests to the JSON Ledger API of a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/jsonapi/**":{"delete":{"tags":["remote-participant-json-api-controller"],"summary":"Proxy a DELETE request to the participant JSON Ledger API","description":"Forwards the incoming DELETE request to the configured JSON Ledger API endpoint of the remote participant, typically used to cancel or release ledger resources.","operationId":"deleteRemoteParticipantRequest","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Lists all configured dars of a participant

> Queries the remote participant's admin API and returns the DARs currently installed on the node, including their hashes and package metadata.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-dar-controller","description":"List, upload and remove DAR packages on a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DarDto":{"type":"object","description":"Reference to a DAR package uploaded to a Canton participant: identifying hash, package name and version.","properties":{"hash":{"type":"string"},"name":{"type":"string"},"version":{"type":"string"}}}}},"paths":{"/remote-participants/{name}/dars":{"get":{"tags":["remote-participant-dar-controller"],"summary":"Lists all configured dars of a participant","description":"Queries the remote participant's admin API and returns the DARs currently installed on the node, including their hashes and package metadata.","operationId":"listRemoteParticipantDars","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/DarDto"}}}}},"400":{"description":"The supplied participant name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/DarDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Upload dar file to a participant

> Reads each requested DAR from CBM file storage and uploads it to the remote participant via its admin API. Between 1 and 15 DAR names may be uploaded in a single call.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-dar-controller","description":"List, upload and remove DAR packages on a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/dars":{"post":{"tags":["remote-participant-dar-controller"],"summary":"Upload dar file to a participant","description":"Reads each requested DAR from CBM file storage and uploads it to the remote participant via its admin API. Between 1 and 15 DAR names may be uploaded in a single call.","operationId":"uploadRemoteParticipantDar","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"darName","in":"query","description":"Names of DAR files (already stored in CBM file storage) to upload to the participant.","required":true,"schema":{"type":"array","items":{"type":"string"},"maxItems":15,"minItems":1}}],"responses":{"200":{"description":"OK"},"400":{"description":"The participant name or the supplied list of DAR names is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"The participant is not registered in CBM or a referenced DAR is missing from CBM file storage."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Remove a dar from a participant

> Proxies an admin-API call to the remote participant to uninstall the DAR identified by its hash. The DAR is only removed from the remote node; CBM file storage is untouched.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-dar-controller","description":"List, upload and remove DAR packages on a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}/dars":{"delete":{"tags":["remote-participant-dar-controller"],"summary":"Remove a dar from a participant","description":"Proxies an admin-API call to the remote participant to uninstall the DAR identified by its hash. The DAR is only removed from the remote node; CBM file storage is untouched.","operationId":"removeRemoteParticipantDar","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"darHash","in":"query","description":"Hash of the DAR to remove, as reported by the participant.","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK"},"400":{"description":"The participant name or DAR hash is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Either the participant is not registered in CBM or the DAR hash is unknown on the remote node."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Lists all configured domain connections of a participant

> Calls the remote participant's admin API to retrieve every domain connection it has been configured with, regardless of current connectivity state.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-connection-controller","description":"Configure, register, connect and disconnect a remote Canton participant against one of its sync domains."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ConnectionDto":{"type":"object","description":"The DTO representing a connection to a domain.","properties":{"connected":{"type":"boolean","description":"It represents the connection status. It is true when the connection is established, false otherwise."},"custom":{"type":"boolean","description":"It represents a custom domain.  When it is true the domainUrl should be used, use domainName and port otherwise "},"domainAlias":{"type":"string","description":"This is the alias of the domain to connect to. It does not have to be the same as the actual domain name.","minLength":1},"domainName":{"type":"string","description":"This is name of the domain to connect to. "},"isHADomain":{"type":"boolean","description":"Defines whether the domain name belongs to the HA Domain entity"},"domainUrl":{"type":"string","description":"This is the URL of the domain to connect to. It must be accessible from the participant node. Usage: https://<domain-name>.<namespace>.svc.cluster.local:<public-port>"},"publicPort":{"type":"string","description":"This is public port of the domain to connect to. "}},"required":["domainAlias"]}}},"paths":{"/remote-participants/{name}/connections":{"get":{"tags":["remote-participant-connection-controller"],"summary":"Lists all configured domain connections of a participant","description":"Calls the remote participant's admin API to retrieve every domain connection it has been configured with, regardless of current connectivity state.","operationId":"listRemoteParticipantConnections","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/ConnectionDto"}}}}},"400":{"description":"The supplied participant name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/ConnectionDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Configures, registers and connects a domain to a participant

> Proxies an admin-API call to the remote participant to register a new domain connection and immediately connect it. The exact RPC is selected based on the remote node's Canton major version (V0 vs V3).

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-connection-controller","description":"Configure, register, connect and disconnect a remote Canton participant against one of its sync domains."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ConnectionDto":{"type":"object","description":"The DTO representing a connection to a domain.","properties":{"connected":{"type":"boolean","description":"It represents the connection status. It is true when the connection is established, false otherwise."},"custom":{"type":"boolean","description":"It represents a custom domain.  When it is true the domainUrl should be used, use domainName and port otherwise "},"domainAlias":{"type":"string","description":"This is the alias of the domain to connect to. It does not have to be the same as the actual domain name.","minLength":1},"domainName":{"type":"string","description":"This is name of the domain to connect to. "},"isHADomain":{"type":"boolean","description":"Defines whether the domain name belongs to the HA Domain entity"},"domainUrl":{"type":"string","description":"This is the URL of the domain to connect to. It must be accessible from the participant node. Usage: https://<domain-name>.<namespace>.svc.cluster.local:<public-port>"},"publicPort":{"type":"string","description":"This is public port of the domain to connect to. "}},"required":["domainAlias"]}}},"paths":{"/remote-participants/{name}/connections":{"post":{"tags":["remote-participant-connection-controller"],"summary":"Configures, registers and connects a domain to a participant","description":"Proxies an admin-API call to the remote participant to register a new domain connection and immediately connect it. The exact RPC is selected based on the remote node's Canton major version (V0 vs V3).","operationId":"createRemoteParticipantConnection","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConnectionDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"The connection payload or participant name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name."},"409":{"description":"A domain connection with the same alias is already registered on the remote participant."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get the current pruning schedule of a remote domain component

> Fetches the cron-based pruning schedule currently configured on the mediator or sequencer of the remote sync domain, together with the next computed run timestamp. The schedule is read from the remote node via its admin API.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-prune-controller","description":"Run pruning on a remote sync domain and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/remote-domains/{name}/prune":{"get":{"tags":["remote-domain-prune-controller"],"summary":"Get the current pruning schedule of a remote domain component","description":"Fetches the cron-based pruning schedule currently configured on the mediator or sequencer of the remote sync domain, together with the next computed run timestamp. The schedule is read from the remote node via its admin API.","operationId":"getRemoteDomainPruningSchedule","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the target remote domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"component","in":"query","description":"Remote domain component to inspect (mediator or sequencer).","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"400":{"description":"Invalid component value.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name, or no schedule is configured.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create a pruning schedule on a remote domain component

> Sends a pruning schedule (cron-based ledger data retention) to the mediator or sequencer of a remote sync domain. The schedule is applied on the remote node via its admin API; CBM only resolves the connection details from its local registration.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-prune-controller","description":"Run pruning on a remote sync domain and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/remote-domains/{name}/prune":{"post":{"tags":["remote-domain-prune-controller"],"summary":"Create a pruning schedule on a remote domain component","description":"Sends a pruning schedule (cron-based ledger data retention) to the mediator or sequencer of a remote sync domain. The schedule is applied on the remote node via its admin API; CBM only resolves the connection details from its local registration.","operationId":"createRemoteDomainPruningSchedule","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the target remote domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"component","in":"query","description":"Remote domain component the schedule applies to (mediator or sequencer).","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"Invalid cron expression, component, or schedule payload.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Clear the pruning schedule on a remote domain component

> Instructs the mediator or sequencer of the remote sync domain to drop its current pruning schedule. The clear command is proxied to the remote node's admin API.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-prune-controller","description":"Run pruning on a remote sync domain and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-domains/{name}/prune":{"delete":{"tags":["remote-domain-prune-controller"],"summary":"Clear the pruning schedule on a remote domain component","description":"Instructs the mediator or sequencer of the remote sync domain to drop its current pruning schedule. The clear command is proxied to the remote node's admin API.","operationId":"deleteRemoteDomainPruningSchedule","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the target remote domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"component","in":"query","description":"Remote domain component whose schedule should be cleared (mediator or sequencer).","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"Invalid component value.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name, or no schedule exists to clear."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get participant restore job

> Returns the descriptor of the current restore job for the participant, including the source backup file and the job's runtime status. Used to poll the progress of a long-running restore initiated via POST.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-restore-controller","description":"Restore a Canton participant from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RestoreDto":{"type":"object","description":"Request body to start a participant or domain restore from a previously captured backup file.","properties":{"fileName":{"type":"string","minLength":1}},"required":["fileName"]}}},"paths":{"/participants/{name}/restore":{"get":{"tags":["participant-restore-controller"],"summary":"Get participant restore job","description":"Returns the descriptor of the current restore job for the participant, including the source backup file and the job's runtime status. Used to poll the progress of a long-running restore initiated via POST.","operationId":"getParticipantRestoreSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose restore job to fetch.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No restore job exists for the given participant.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create participant restore job

> Launches a one-shot restore job that recreates the participant's storage from the specified backup file. Any previous restore job for this participant is removed first. This is a long-running operation: the response is a job descriptor whose progress can be polled via the GET endpoint.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-restore-controller","description":"Restore a Canton participant from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RestoreDto":{"type":"object","description":"Request body to start a participant or domain restore from a previously captured backup file.","properties":{"fileName":{"type":"string","minLength":1}},"required":["fileName"]}}},"paths":{"/participants/{name}/restore":{"post":{"tags":["participant-restore-controller"],"summary":"Create participant restore job","description":"Launches a one-shot restore job that recreates the participant's storage from the specified backup file. Any previous restore job for this participant is removed first. This is a long-running operation: the response is a job descriptor whose progress can be polled via the GET endpoint.","operationId":"createParticipantRestoreSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to restore.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"400":{"description":"The body, participant name, or backup file failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists or the referenced backup file is missing.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete participant restore job

> Removes the restore job descriptor for the participant. If a restore is currently running it will be cancelled. Restored data already written to the participant's storage is not rolled back.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-restore-controller","description":"Restore a Canton participant from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/restore":{"delete":{"tags":["participant-restore-controller"],"summary":"Delete participant restore job","description":"Removes the restore job descriptor for the participant. If a restore is currently running it will be cancelled. Restored data already written to the participant's storage is not rolled back.","operationId":"deleteParticipantRestoreSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose restore job should be removed.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No restore job exists for the given participant."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get participant pruning schedule

> Returns the current pruning schedule configured on the participant, including the cron expression, retention and the predicted Unix timestamp of the next run.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-prune-controller","description":"Run pruning on a participant and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/participants/{name}/prune":{"get":{"tags":["participant-prune-controller"],"summary":"Get participant pruning schedule","description":"Returns the current pruning schedule configured on the participant, including the cron expression, retention and the predicted Unix timestamp of the next run.","operationId":"getParticipantPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose pruning schedule to fetch.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"400":{"description":"The participant name or port failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create participant pruning schedule

> Configures a recurring pruning schedule on the participant via its admin API. Pruning deletes ledger data older than the configured retention. This endpoint is only supported on enterprise participants; a 400 is returned otherwise.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-prune-controller","description":"Run pruning on a participant and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/participants/{name}/prune":{"post":{"tags":["participant-prune-controller"],"summary":"Create participant pruning schedule","description":"Configures a recurring pruning schedule on the participant via its admin API. Pruning deletes ledger data older than the configured retention. This endpoint is only supported on enterprise participants; a 400 is returned otherwise.","operationId":"createParticipantPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the enterprise participant to schedule pruning on.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"The body, cron expression, or participant is non-enterprise.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete participant pruning schedule

> Clears the pruning schedule on the participant via its admin API. Already pruned ledger data cannot be recovered; this only stops future scheduled runs.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-prune-controller","description":"Run pruning on a participant and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/prune":{"delete":{"tags":["participant-prune-controller"],"summary":"Delete participant pruning schedule","description":"Clears the pruning schedule on the participant via its admin API. Already pruned ledger data cannot be recovered; this only stops future scheduled runs.","operationId":"deleteParticipantPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose pruning schedule to clear.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The participant name or port failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Refresh and list local parties

> Triggers an asynchronous refresh of the cached local-parties view from the participant's ledger API and immediately returns the current view together with the refresh status. Subsequent calls to the GET endpoint will reflect the refreshed data once the background fetch completes.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"local-party-controller","description":"Fetch and synchronise local parties hosted on a Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"LocalPartyListingDTO":{"type":"object","description":"Local-party listing for a participant: the in-progress fetch flag and the currently-known list of party identifiers.","properties":{"fetching":{"type":"boolean"},"parties":{"type":"array","items":{"type":"string"}}}}}},"paths":{"/participants/{name}/parties/local/fetch":{"post":{"tags":["local-party-controller"],"summary":"Refresh and list local parties","description":"Triggers an asynchronous refresh of the cached local-parties view from the participant's ledger API and immediately returns the current view together with the refresh status. Subsequent calls to the GET endpoint will reflect the refreshed data once the background fetch completes.","operationId":"fetchParties","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose local parties to refresh.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/LocalPartyListingDTO"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy GET to participant JSON Ledger API

> Forwards a GET request to the participant's JSON Ledger API endpoint, preserving the path suffix, query string and body. CBM authenticates the request with a freshly minted ledger token chosen according to the participant's auth provider (Keycloak, Auth0 or validator).

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"json-api-controller","description":"Proxy requests to the JSON Ledger API of a local Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/jsonapi/**":{"get":{"tags":["json-api-controller"],"summary":"Proxy GET to participant JSON Ledger API","description":"Forwards a GET request to the participant's JSON Ledger API endpoint, preserving the path suffix, query string and body. CBM authenticates the request with a freshly minted ledger token chosen according to the participant's auth provider (Keycloak, Auth0 or validator).","operationId":"getParticipantRequest","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to proxy the call to.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy POST to participant JSON Ledger API

> Forwards a POST request (JSON or octet-stream) to the participant's JSON Ledger API. When the call is a party-allocation request (POST /v2/parties) and succeeds, the newly allocated party is added to CBM's local-party cache for the participant.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"json-api-controller","description":"Proxy requests to the JSON Ledger API of a local Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/jsonapi/**":{"post":{"tags":["json-api-controller"],"summary":"Proxy POST to participant JSON Ledger API","description":"Forwards a POST request (JSON or octet-stream) to the participant's JSON Ledger API. When the call is a party-allocation request (POST /v2/parties) and succeeds, the newly allocated party is added to CBM's local-party cache for the participant.","operationId":"postParticipantRequest","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to proxy the call to.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"The participant rejected the request as conflicting (for example party already exists).","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy DELETE to participant JSON Ledger API

> Forwards a DELETE request to the participant's JSON Ledger API. The path suffix and query string after /jsonapi are passed through unchanged.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"json-api-controller","description":"Proxy requests to the JSON Ledger API of a local Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/jsonapi/**":{"delete":{"tags":["json-api-controller"],"summary":"Proxy DELETE to participant JSON Ledger API","description":"Forwards a DELETE request to the participant's JSON Ledger API. The path suffix and query string after /jsonapi are passed through unchanged.","operationId":"deleteParticipantRequest","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to proxy the call to.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy PATCH to participant JSON Ledger API

> Forwards a PATCH request (JSON or octet-stream) to the participant's JSON Ledger API, preserving path, query string and body.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"json-api-controller","description":"Proxy requests to the JSON Ledger API of a local Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/jsonapi/**":{"patch":{"tags":["json-api-controller"],"summary":"Proxy PATCH to participant JSON Ledger API","description":"Forwards a PATCH request (JSON or octet-stream) to the participant's JSON Ledger API, preserving path, query string and body.","operationId":"patchParticipantRequest","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to proxy the call to.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"The participant rejected the request as conflicting.","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Lists all configured dars of a participant

> Returns the list of Daml Archive (DAR) packages currently uploaded to the given participant by calling its admin API. The package service is dispatched based on the participant's Canton/validator version.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-dar-controller","description":"List, upload and remove DAR packages on a Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DarDto":{"type":"object","description":"Reference to a DAR package uploaded to a Canton participant: identifying hash, package name and version.","properties":{"hash":{"type":"string"},"name":{"type":"string"},"version":{"type":"string"}}}}},"paths":{"/participants/{name}/dars":{"get":{"tags":["participant-dar-controller"],"summary":"Lists all configured dars of a participant","description":"Returns the list of Daml Archive (DAR) packages currently uploaded to the given participant by calling its admin API. The package service is dispatched based on the participant's Canton/validator version.","operationId":"listParticipantDars","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the target participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/DarDto"}}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/DarDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Upload dar file to a participant

> Uploads one or more DAR packages already stored in the CBM file store to the target participant. Between 1 and 15 DAR names can be uploaded in a single request; uploads are performed in order and the call returns when all are accepted by the admin API.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-dar-controller","description":"List, upload and remove DAR packages on a Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/dars":{"post":{"tags":["participant-dar-controller"],"summary":"Upload dar file to a participant","description":"Uploads one or more DAR packages already stored in the CBM file store to the target participant. Between 1 and 15 DAR names can be uploaded in a single request; uploads are performed in order and the call returns when all are accepted by the admin API.","operationId":"uploadParticipantDar","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the target participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"darName","in":"query","description":"Names of DAR files in the CBM file store to upload (1 to 15 entries).","required":true,"schema":{"type":"array","items":{"type":"string"},"maxItems":15,"minItems":1}}],"responses":{"200":{"description":"OK"},"400":{"description":"Validation failed (participant name, DAR list size, or unknown DAR).","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Remove a dar from a participant

> Unregisters the DAR identified by its content hash from the given participant. The package contents themselves are not deleted from the ledger; only the registration is removed. The operation is idempotent on success.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-dar-controller","description":"List, upload and remove DAR packages on a Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/dars":{"delete":{"tags":["participant-dar-controller"],"summary":"Remove a dar from a participant","description":"Unregisters the DAR identified by its content hash from the given participant. The package contents themselves are not deleted from the ledger; only the registration is removed. The operation is idempotent on success.","operationId":"removeParticipantDar","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the target participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"darHash","in":"query","description":"Content hash of the DAR to remove, as reported by the list endpoint.","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK"},"400":{"description":"The participant name or DAR hash failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists or the DAR is not registered."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Lists all configured domain connections of a participant

> Returns the list of sync-domain connections registered on the participant, including each domain's alias, URL, parameters and current connection state.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"connection-controller","description":"Configure, register, connect and disconnect a Canton participant against one of its sync domains."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ConnectionDto":{"type":"object","description":"The DTO representing a connection to a domain.","properties":{"connected":{"type":"boolean","description":"It represents the connection status. It is true when the connection is established, false otherwise."},"custom":{"type":"boolean","description":"It represents a custom domain.  When it is true the domainUrl should be used, use domainName and port otherwise "},"domainAlias":{"type":"string","description":"This is the alias of the domain to connect to. It does not have to be the same as the actual domain name.","minLength":1},"domainName":{"type":"string","description":"This is name of the domain to connect to. "},"isHADomain":{"type":"boolean","description":"Defines whether the domain name belongs to the HA Domain entity"},"domainUrl":{"type":"string","description":"This is the URL of the domain to connect to. It must be accessible from the participant node. Usage: https://<domain-name>.<namespace>.svc.cluster.local:<public-port>"},"publicPort":{"type":"string","description":"This is public port of the domain to connect to. "}},"required":["domainAlias"]}}},"paths":{"/participants/{name}/connections":{"get":{"tags":["connection-controller"],"summary":"Lists all configured domain connections of a participant","description":"Returns the list of sync-domain connections registered on the participant, including each domain's alias, URL, parameters and current connection state.","operationId":"listParticipantConnections","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose connections to list.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/ConnectionDto"}}}}},"400":{"description":"The participant name or port failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/ConnectionDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Configures, registers and connects a domain to a participant

> Registers a new sync-domain connection on the participant and immediately connects to it via the participant's admin API. The combination of domain alias and URL must be unique for the participant; a 409 is returned if the participant is already connected to another incompatible domain.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"connection-controller","description":"Configure, register, connect and disconnect a Canton participant against one of its sync domains."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ConnectionDto":{"type":"object","description":"The DTO representing a connection to a domain.","properties":{"connected":{"type":"boolean","description":"It represents the connection status. It is true when the connection is established, false otherwise."},"custom":{"type":"boolean","description":"It represents a custom domain.  When it is true the domainUrl should be used, use domainName and port otherwise "},"domainAlias":{"type":"string","description":"This is the alias of the domain to connect to. It does not have to be the same as the actual domain name.","minLength":1},"domainName":{"type":"string","description":"This is name of the domain to connect to. "},"isHADomain":{"type":"boolean","description":"Defines whether the domain name belongs to the HA Domain entity"},"domainUrl":{"type":"string","description":"This is the URL of the domain to connect to. It must be accessible from the participant node. Usage: https://<domain-name>.<namespace>.svc.cluster.local:<public-port>"},"publicPort":{"type":"string","description":"This is public port of the domain to connect to. "}},"required":["domainAlias"]}}},"paths":{"/participants/{name}/connections":{"post":{"tags":["connection-controller"],"summary":"Configures, registers and connects a domain to a participant","description":"Registers a new sync-domain connection on the participant and immediately connects to it via the participant's admin API. The combination of domain alias and URL must be unique for the participant; a 409 is returned if the participant is already connected to another incompatible domain.","operationId":"createParticipantConnection","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant on which to register the connection.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ConnectionDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"The connection payload or participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists."},"409":{"description":"The participant is already connected to another incompatible domain."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get participant backup schedule

> Returns the current scheduled backup configuration for the participant, including the cron expression and the predicted Unix timestamp of the next run.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-backup-controller","description":"Trigger participant backups, browse backup history and manage scheduled participant backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledBackupDto":{"type":"object","description":"Persisted backup schedule for a Canton workload: cron expression, retention limit and the resolved next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/participants/{name}/backup":{"get":{"tags":["participant-backup-controller"],"summary":"Get participant backup schedule","description":"Returns the current scheduled backup configuration for the participant, including the cron expression and the predicted Unix timestamp of the next run.","operationId":"getParticipantBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose schedule to fetch.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No backup schedule exists for the given participant.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create participant backup schedule

> Creates a recurring backup schedule (Kubernetes CronJob owned by the participant) that periodically dumps the participant's storage to the configured backup location. The cron expression is validated against the platform's non-enterprise allowed schedule.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-backup-controller","description":"Trigger participant backups, browse backup history and manage scheduled participant backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BackupDto":{"type":"object","description":"Schedule definition used to configure a recurring backup job on a Canton workload (participant or domain). Carries the cron expression that drives the schedule and the maximum number of backups to retain.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32","minimum":1}},"required":["cron","maxBackups"]},"ScheduledBackupDto":{"type":"object","description":"Persisted backup schedule for a Canton workload: cron expression, retention limit and the resolved next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/participants/{name}/backup":{"post":{"tags":["participant-backup-controller"],"summary":"Create participant backup schedule","description":"Creates a recurring backup schedule (Kubernetes CronJob owned by the participant) that periodically dumps the participant's storage to the configured backup location. The cron expression is validated against the platform's non-enterprise allowed schedule.","operationId":"createParticipantBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to back up.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BackupDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"400":{"description":"The body, cron expression, or participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete participant backup schedule

> Removes the scheduled backup CronJob for the participant. Existing backup files already produced in the backup location are not deleted.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-backup-controller","description":"Trigger participant backups, browse backup history and manage scheduled participant backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}/backup":{"delete":{"tags":["participant-backup-controller"],"summary":"Delete participant backup schedule","description":"Removes the scheduled backup CronJob for the participant. Existing backup files already produced in the backup location are not deleted.","operationId":"deleteParticipantBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose schedule should be removed.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No backup schedule exists for the given participant."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List validator identity dumps

> Returns the identity dump secrets currently stored for a single validator, ordered by creation time.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"IdDumpDto":{"type":"object","description":"Identity-dump artifact metadata: name of the Kubernetes secret holding the dump, the owning validator name and the timestamp at which it was captured.","properties":{"secretName":{"type":"string"},"validatorName":{"type":"string"},"timestamp":{"type":"integer","format":"int64"},"createdAt":{"type":"string"}}}}},"paths":{"/id-dumps/{validatorName}":{"get":{"tags":["validator-id-dumps-controller"],"summary":"List validator identity dumps","description":"Returns the identity dump secrets currently stored for a single validator, ordered by creation time.","operationId":"listParticipantIdentityDumps","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/IdDumpDto"}}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create validator identity dump

> Synchronously requests an identity dump from the validator's wallet and stores it as a Kubernetes secret. The dump can later be used to recover or transfer the validator's identity.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"IdDumpDto":{"type":"object","description":"Identity-dump artifact metadata: name of the Kubernetes secret holding the dump, the owning validator name and the timestamp at which it was captured.","properties":{"secretName":{"type":"string"},"validatorName":{"type":"string"},"timestamp":{"type":"integer","format":"int64"},"createdAt":{"type":"string"}}}}},"paths":{"/id-dumps/{validatorName}":{"post":{"tags":["validator-id-dumps-controller"],"summary":"Create validator identity dump","description":"Synchronously requests an identity dump from the validator's wallet and stores it as a Kubernetes secret. The dump can later be used to recover or transfer the validator's identity.","operationId":"createIdentityDump","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/IdDumpDto"}}}},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/IdDumpDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Proxy an HTTP request to an internal service

> Forwards the provided HTTP method, URL, headers and body to an internal Canton or Splice service that is not directly exposed outside the cluster, and returns the upstream response. Timestamps in the URL are normalized to ISO-8601 with millisecond precision and a 'Z' suffix.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"proxy-controller","description":"HTTP proxy endpoints used to forward requests to internal Canton / Splice services (including validator API access-token retrieval)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ProxyRequestDto":{"type":"object","description":"Generic HTTP proxy request: target URL, method, custom headers and body forwarded by the proxy controller.","properties":{"url":{"type":"string"},"method":{"type":"string"},"headers":{"type":"object","additionalProperties":{"type":"string"}},"body":{"type":"string"}}}}},"paths":{"/http-proxy":{"post":{"tags":["proxy-controller"],"summary":"Proxy an HTTP request to an internal service","description":"Forwards the provided HTTP method, URL, headers and body to an internal Canton or Splice service that is not directly exposed outside the cluster, and returns the upstream response. Timestamps in the URL are normalized to ISO-8601 with millisecond precision and a 'Z' suffix.","operationId":"proxyRequest","requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ProxyRequestDto"}}},"required":true},"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"object"}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Retrieve an access token for the validator API

> Performs an OAuth login against the validator wallet using stored credentials combined with the supplied password, and returns a bearer token usable for validator API calls.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"proxy-controller","description":"HTTP proxy endpoints used to forward requests to internal Canton / Splice services (including validator API access-token retrieval)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"PasswordDto":{"type":"object","description":"Wrapper around a single password value; used by endpoints that update credentials in isolation.","properties":{"password":{"type":"string","minLength":1}},"required":["password"]},"OauthLoginResponse":{"type":"object","description":"Token response returned by the OAuth2 login flow (access token).","properties":{"access_token":{"type":"string"}}}}},"paths":{"/http-proxy/validator-api-access-token":{"post":{"tags":["proxy-controller"],"summary":"Retrieve an access token for the validator API","description":"Performs an OAuth login against the validator wallet using stored credentials combined with the supplied password, and returns a bearer token usable for validator API calls.","operationId":"getValidatorApiAccessToken","parameters":[{"name":"validator","in":"query","description":"Name of the validator whose wallet credentials should be used","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/PasswordDto"}}},"required":true},"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/OauthLoginResponse"}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List stored files with filtering and pagination

> Returns a page of files in the CBM file storage, optionally filtered by type and name. Supports offset/limit pagination via the from and limit query parameters.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"file-storage-controller","description":"Upload, list and remove files used by validators, participants and domains (DAR packages, identity dumps, configuration archives, …)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"FileFilterResponseDto":{"type":"object","description":"Paginated list of `FileDto` entries plus the total count of stored files matching the filter.","properties":{"files":{"type":"array","items":{"$ref":"#/components/schemas/FileDto"}},"totalCount":{"type":"integer","format":"int64"}}},"FileDto":{"type":"object","description":"File DTO","properties":{"name":{"type":"string","description":"Name of the file"},"sizeInBytes":{"type":"integer","format":"int64","description":"Size of the file in bytes"}}}}},"paths":{"/files":{"get":{"tags":["file-storage-controller"],"summary":"List stored files with filtering and pagination","description":"Returns a page of files in the CBM file storage, optionally filtered by type and name. Supports offset/limit pagination via the from and limit query parameters.","operationId":"listFiles","parameters":[{"name":"fileType","in":"query","description":"Filter by file type/category","required":false,"schema":{"type":"string","enum":["DAR","UI_PACKAGE"]}},{"name":"from","in":"query","description":"Zero-based index of the first file to return","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"limit","in":"query","description":"Maximum number of files to return","required":false,"schema":{"type":"integer","format":"int32"}},{"name":"name","in":"query","description":"Filter by file name (substring match)","required":false,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/FileFilterResponseDto"}}}},"400":{"description":"Invalid filter or pagination parameters","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Upload files to server-side storage

> Uploads one or more files of the given type (DAR, identity dump, config, etc.) into the CBM-managed file storage so they can later be consumed by Canton workloads. File extensions are validated against the declared file type.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"file-storage-controller","description":"Upload, list and remove files used by validators, participants and domains (DAR packages, identity dumps, configuration archives, …)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/files":{"post":{"tags":["file-storage-controller"],"summary":"Upload files to server-side storage","description":"Uploads one or more files of the given type (DAR, identity dump, config, etc.) into the CBM-managed file storage so they can later be consumed by Canton workloads. File extensions are validated against the declared file type.","operationId":"createFile","parameters":[{"name":"fileType","in":"query","description":"Type/category of the uploaded files (controls allowed extension and storage location)","required":true,"schema":{"type":"string","enum":["DAR","UI_PACKAGE"]}}],"requestBody":{"content":{"multipart/form-data":{"schema":{"type":"object","properties":{"files":{"type":"array","description":"Multipart files to upload","items":{"type":"string","format":"binary"}}},"required":["files"]}}}},"responses":{"201":{"description":"Created"},"400":{"description":"Invalid file or extension does not match the declared file type","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"409":{"description":"A file with the same name already exists"},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get the current domain restore job

> Returns the restore job descriptor for the sync domain, including its current status. Use this endpoint to poll the progress of an in-flight restore.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-restore-controller","description":"Restore a Canton sync domain from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RestoreDto":{"type":"object","description":"Request body to start a participant or domain restore from a previously captured backup file.","properties":{"fileName":{"type":"string","minLength":1}},"required":["fileName"]}}},"paths":{"/domains/{name}/restore":{"get":{"tags":["domain-restore-controller"],"summary":"Get the current domain restore job","description":"Returns the restore job descriptor for the sync domain, including its current status. Use this endpoint to poll the progress of an in-flight restore.","operationId":"getDomainRestoreSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose restore job should be returned.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"400":{"description":"The supplied domain name is invalid or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No restore job exists for the given domain.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Trigger a domain restore job

> Starts an asynchronous restore of the sync domain from a previously produced backup file. Any existing restore job for the domain is replaced; progress can be polled via the corresponding GET endpoint.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-restore-controller","description":"Restore a Canton sync domain from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RestoreDto":{"type":"object","description":"Request body to start a participant or domain restore from a previously captured backup file.","properties":{"fileName":{"type":"string","minLength":1}},"required":["fileName"]}}},"paths":{"/domains/{name}/restore":{"post":{"tags":["domain-restore-controller"],"summary":"Trigger a domain restore job","description":"Starts an asynchronous restore of the sync domain from a previously produced backup file. Any existing restore job for the domain is replaced; progress can be polled via the corresponding GET endpoint.","operationId":"createDomainRestoreSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain to restore into.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"400":{"description":"The request payload is invalid or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"The sync domain or referenced backup file does not exist.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RestoreDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete the domain restore job

> Removes the restore job for the sync domain. Any in-progress restore work is cancelled as the underlying Kubernetes job is deleted.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-restore-controller","description":"Restore a Canton sync domain from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/domains/{name}/restore":{"delete":{"tags":["domain-restore-controller"],"summary":"Delete the domain restore job","description":"Removes the restore job for the sync domain. Any in-progress restore work is cancelled as the underlying Kubernetes job is deleted.","operationId":"deleteDomainRestoreSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose restore job should be removed.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied domain name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No restore job exists for the given domain."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get the domain pruning schedule

> Returns the active pruning schedule for the targeted component (mediator or sequencer), including the cron expression and a computed Unix timestamp for the next run.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-prune-controller","description":"Run pruning on a sync domain and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/domains/{name}/prune":{"get":{"tags":["domain-prune-controller"],"summary":"Get the domain pruning schedule","description":"Returns the active pruning schedule for the targeted component (mediator or sequencer), including the cron expression and a computed Unix timestamp for the next run.","operationId":"getDomainPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose schedule should be returned.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port of the domain to call; defaults to the standard admin port.","required":false,"schema":{"type":"integer","format":"int32","default":5019}},{"name":"component","in":"query","description":"Domain component to read the pruning schedule from; either MEDIATOR or SEQUENCER.","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"400":{"description":"The supplied domain name or component is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create a domain pruning schedule

> Schedules recurring pruning of old ledger data for the targeted component (mediator or sequencer) of an enterprise sync domain. Pruning is only available on enterprise nodes; the schedule is enforced by the node itself.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-prune-controller","description":"Run pruning on a sync domain and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}},"paths":{"/domains/{name}/prune":{"post":{"tags":["domain-prune-controller"],"summary":"Create a domain pruning schedule","description":"Schedules recurring pruning of old ledger data for the targeted component (mediator or sequencer) of an enterprise sync domain. Pruning is only available on enterprise nodes; the schedule is enforced by the node itself.","operationId":"createDomainPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain to prune.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port of the domain to call; defaults to the standard admin port.","required":false,"schema":{"type":"integer","format":"int32","default":5019}},{"name":"component","in":"query","description":"Domain component to prune; either MEDIATOR or SEQUENCER.","required":true,"schema":{"type":"string"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/ScheduledPruneDto"}}},"required":true},"responses":{"201":{"description":"Created"},"400":{"description":"The cron expression, payload or component is invalid, or the domain is not enterprise.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete the domain pruning schedule

> Clears the pruning schedule on the targeted component (mediator or sequencer) of the sync domain. Already pruned data is not affected.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-prune-controller","description":"Run pruning on a sync domain and manage its pruning schedule."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/domains/{name}/prune":{"delete":{"tags":["domain-prune-controller"],"summary":"Delete the domain pruning schedule","description":"Clears the pruning schedule on the targeted component (mediator or sequencer) of the sync domain. Already pruned data is not affected.","operationId":"deleteDomainPruningSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose schedule should be cleared.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port of the domain to call; defaults to the standard admin port.","required":false,"schema":{"type":"integer","format":"int32","default":5019}},{"name":"component","in":"query","description":"Domain component to clear the pruning schedule from; either MEDIATOR or SEQUENCER.","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied domain name or component is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get the domain backup schedule

> Returns the current backup schedule for the sync domain, including the cron expression and a calculated Unix timestamp for the next planned run.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-backup-controller","description":"Trigger domain backups, browse backup history and manage scheduled domain backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ScheduledBackupDto":{"type":"object","description":"Persisted backup schedule for a Canton workload: cron expression, retention limit and the resolved next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/domains/{name}/backup":{"get":{"tags":["domain-backup-controller"],"summary":"Get the domain backup schedule","description":"Returns the current backup schedule for the sync domain, including the cron expression and a calculated Unix timestamp for the next planned run.","operationId":"getDomainBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose schedule should be returned.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"400":{"description":"The supplied domain name is invalid or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No backup schedule exists for the given domain.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Create or replace a domain backup schedule

> Provisions a recurring backup job for the sync domain using the supplied cron expression. The created schedule is owned by the domain resource and produces backup artifacts asynchronously on each cron tick.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-backup-controller","description":"Trigger domain backups, browse backup history and manage scheduled domain backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BackupDto":{"type":"object","description":"Schedule definition used to configure a recurring backup job on a Canton workload (participant or domain). Carries the cron expression that drives the schedule and the maximum number of backups to retain.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32","minimum":1}},"required":["cron","maxBackups"]},"ScheduledBackupDto":{"type":"object","description":"Persisted backup schedule for a Canton workload: cron expression, retention limit and the resolved next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}},"paths":{"/domains/{name}/backup":{"post":{"tags":["domain-backup-controller"],"summary":"Create or replace a domain backup schedule","description":"Provisions a recurring backup job for the sync domain using the supplied cron expression. The created schedule is owned by the domain resource and produces backup artifacts asynchronously on each cron tick.","operationId":"createDomainBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain to back up.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/BackupDto"}}},"required":true},"responses":{"201":{"description":"Created","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"400":{"description":"The cron expression or payload is invalid, or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ScheduledBackupDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete the domain backup schedule

> Removes the recurring backup job associated with the sync domain. Existing backup artifacts already produced are not affected.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-backup-controller","description":"Trigger domain backups, browse backup history and manage scheduled domain backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/domains/{name}/backup":{"delete":{"tags":["domain-backup-controller"],"summary":"Delete the domain backup schedule","description":"Removes the recurring backup job associated with the sync domain. Existing backup artifacts already produced are not affected.","operationId":"deleteDomainBackupSchedule","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose schedule should be removed.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied domain name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No backup schedule exists for the given domain."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Execute a Canton console command

> Runs an ad-hoc Canton console script against the target participant or domain node identified by name. The command is executed synchronously and produces no response body.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"command-controller","description":"Execute and manage ad-hoc Canton console commands against a participant or domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"CommandDto":{"type":"object","description":"Canton console script to be executed as a one-shot command against a participant or domain.","properties":{"script":{"type":"string","minLength":1}},"required":["script"]}}},"paths":{"/commands/{name}":{"post":{"tags":["command-controller"],"summary":"Execute a Canton console command","description":"Runs an ad-hoc Canton console script against the target participant or domain node identified by name. The command is executed synchronously and produces no response body.","operationId":"executeCommand","parameters":[{"name":"name","in":"path","description":"Name of the Canton node (participant or domain) to execute the command against","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"requestBody":{"content":{"application/json":{"schema":{"$ref":"#/components/schemas/CommandDto"}}},"required":true},"responses":{"204":{"description":"No Content"},"400":{"description":"Invalid node name or command payload","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Target node not found"},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get validator

> Returns the full details of a single Splice validator, including its applications, participant, database and wallet configuration, and the resolved validator party id.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-controller","description":"Create, list, edit and remove Splice validator deployments, and read their configuration and status."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorResponseDto":{"type":"object","description":"Full validator details returned by GET / list endpoints: cluster and participant configuration, app info for validator / wallet / CNS, contact point and optional Keycloak credentials created on first provisioning.","properties":{"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"application":{"type":"string"},"applicationCantonNameServer":{"type":"string"},"applicationWallet":{"type":"string"},"contactPoint":{"type":"string"},"createdUser":{"$ref":"#/components/schemas/CreatedUserDto"},"customAuth":{"type":"boolean"},"databaseStorage":{"type":"string"},"disabledWallet":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"exposeLedgerApi":{"type":"boolean"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"immutable":{"type":"boolean"},"jsonApiAddress":{"type":"string"},"ledgerApiAddress":{"type":"string"},"validatorApiAddress":{"type":"string"},"migrationId":{"type":"string"},"migrationMigrating":{"type":"boolean"},"name":{"type":"string"},"onboardingSecretName":{"type":"string"},"participant":{"type":"string"},"participantIdentitiesDumpSecretName":{"type":"string"},"participantInfo":{"$ref":"#/components/schemas/AppInfoDto"},"partyId":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"privateJsonApi":{"type":"boolean"},"scanAddress":{"type":"string"},"storageSize":{"type":"string"},"disableProbes":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"CreatedUserDto":{"type":"object","properties":{"id":{"type":"string"},"temporaryPassword":{"type":"string"},"username":{"type":"string"}}},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}},"paths":{"/validators/{name}":{"get":{"tags":["validator-controller"],"summary":"Get validator","description":"Returns the full details of a single Splice validator, including its applications, participant, database and wallet configuration, and the resolved validator party id.","operationId":"getValidator","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorResponseDto"}}}},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorResponseDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete validator

> Deletes the validator CRD and, when \`deleteResources\` is true, cleans up associated identity dumps, wallet/CNS/ledger-auth/onboarding secrets and Keycloak resources. Always removes the participant entry from the local party finder cache.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-controller","description":"Create, list, edit and remove Splice validator deployments, and read their configuration and status."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/validators/{name}":{"delete":{"tags":["validator-controller"],"summary":"Delete validator","description":"Deletes the validator CRD and, when `deleteResources` is true, cleans up associated identity dumps, wallet/CNS/ledger-auth/onboarding secrets and Keycloak resources. Always removes the participant entry from the local party finder cache.","operationId":"deleteValidator","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"deleteResources","in":"query","description":"Whether to also remove related secrets, identity dumps and Keycloak resources.","required":false,"schema":{"type":"boolean","default":true}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get validator backup history

> Returns the list of recorded backup runs (and their status / artifacts) produced by the validator's scheduled backup job.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-backup-controller","description":"Trigger validator backups, browse backup history and manage scheduled validator backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ValidatorBackupHistoryDto":{"type":"object","description":"Validator backup history: ordered list of previously captured backups with their files and statuses.","properties":{"backupList":{"type":"array","items":{"$ref":"#/components/schemas/ValidatorBackupPropertiesDto"}}}},"ValidatorBackupPropertiesDto":{"type":"object","description":"Single validator backup entry: list of captured backup files, overall status and capture timestamp.","properties":{"files":{"type":"array","items":{"$ref":"#/components/schemas/FilePropertiesDto"}},"status":{"type":"string"},"timestamp":{"type":"string"}}},"FilePropertiesDto":{"type":"object","description":"File metadata: filename, size and timestamp (split into separate date and time fields).","properties":{"date":{"type":"string"},"filename":{"type":"string"},"size":{"type":"integer","format":"int32"},"time":{"type":"string"}}}}},"paths":{"/validators/{name}/backup/history":{"get":{"tags":["validator-backup-controller"],"summary":"Get validator backup history","description":"Returns the list of recorded backup runs (and their status / artifacts) produced by the validator's scheduled backup job.","operationId":"getBackupHistory","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorBackupHistoryDto"}}}},"400":{"description":"The supplied validator name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator or backup schedule exists for the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ValidatorBackupHistoryDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get prefill network info

> Returns network metadata used by the validator prefill / top-up flow, such as the discovered sponsor scan addresses and migration parameters. Read-only.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-prefill-controller","description":"Prefill a Splice validator, check quorum status and perform top-up operations."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"NetworkInfoDto":{"type":"object","description":"Splice network endpoints split by environment: devnet, testnet and mainnet.","properties":{"devnet":{"$ref":"#/components/schemas/NetworkInfoDetails"},"testnet":{"$ref":"#/components/schemas/NetworkInfoDetails"},"mainnet":{"$ref":"#/components/schemas/NetworkInfoDetails"}}},"NetworkInfoDetails":{"type":"object","properties":{"version":{"type":"string"},"migrationId":{"type":"integer","format":"int32"},"svDetailsList":{"type":"array","items":{"$ref":"#/components/schemas/SVDetails"}}}},"SVDetails":{"type":"object","properties":{"name":{"type":"string"},"sponsorAddress":{"type":"string"},"scanAddress":{"type":"string"}}}}},"paths":{"/validators/prefill/network-info":{"get":{"tags":["validator-prefill-controller"],"summary":"Get prefill network info","description":"Returns network metadata used by the validator prefill / top-up flow, such as the discovered sponsor scan addresses and migration parameters. Read-only.","operationId":"getNetworkInfo","responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/NetworkInfoDto"}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List image pull secret names

> Returns the names of all Kubernetes image pull secrets available in the CBM namespace that can be referenced by Canton or Splice workloads.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"secrets-controller","description":"Manage Kubernetes secrets consumed by Canton / Splice workloads."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/secrets":{"get":{"tags":["secrets-controller"],"summary":"List image pull secret names","description":"Returns the names of all Kubernetes image pull secrets available in the CBM namespace that can be referenced by Canton or Splice workloads.","operationId":"getSecrets","responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"type":"string"}}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get a remote participant registration

> Returns the local CBM registration data (endpoints, auth provider, resources, phase) for the remote participant identified by name. No call is made to the remote node.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-controller","description":"Register and manage externally-hosted Canton participants reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteParticipantDto":{"type":"object","description":"Externally-hosted Canton participant registered in CBM: admin / ledger / JSON-API endpoints, auth provider and identifying metadata.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonApiUrl":{"type":"string","minLength":1},"ledgerAddress":{"type":"string","minLength":1},"ledgerId":{"type":"string","minLength":1},"ledgerPort":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"v3":{"type":"boolean"}},"required":["adminAddress","adminPort","authProvider","image","jsonApiUrl","ledgerAddress","ledgerId","ledgerPort","name"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-participants/{name}":{"get":{"tags":["remote-participant-controller"],"summary":"Get a remote participant registration","description":"Returns the local CBM registration data (endpoints, auth provider, resources, phase) for the remote participant identified by name. No call is made to the remote node.","operationId":"getRemoteParticipant","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteParticipantDto"}}}},"400":{"description":"The supplied name does not satisfy node-name constraints.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteParticipantDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete a remote participant registration

> Removes the CBM-side registration of the remote participant. The remote Canton node itself is not stopped or modified; only the local configuration entry is deleted.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-controller","description":"Register and manage externally-hosted Canton participants reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-participants/{name}":{"delete":{"tags":["remote-participant-controller"],"summary":"Delete a remote participant registration","description":"Removes the CBM-side registration of the remote participant. The remote Canton node itself is not stopped or modified; only the local configuration entry is deleted.","operationId":"deleteRemoteParticipant","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied name does not satisfy node-name constraints.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Check status of a participant

> Queries the admin API of the remote Canton participant and returns its current status (identity, active/connected domains, version). CBM proxies the call to the remote node's admin address using the version-appropriate client.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-participant-status-controller","description":"Inspect the runtime status of a remote Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ParticipantStatusDto":{"type":"object","description":"Runtime status of a Canton participant: active flag, id, uptime and the lists of currently connected and unhealthy sync domains.","properties":{"active":{"type":"boolean"},"connectedDomains":{"type":"array","items":{"type":"string"}},"id":{"type":"string"},"unhealthyDomains":{"type":"array","items":{"type":"string"}},"uptime":{"type":"integer","format":"int64"}}}}},"paths":{"/remote-participants/{name}/status":{"get":{"tags":["remote-participant-status-controller"],"summary":"Check status of a participant","description":"Queries the admin API of the remote Canton participant and returns its current status (identity, active/connected domains, version). CBM proxies the call to the remote node's admin address using the version-appropriate client.","operationId":"getRemoteParticipantHealthStatus","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote participant.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantStatusDto"}}}},"400":{"description":"The supplied name does not satisfy node-name constraints.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote participant is registered under the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantStatusDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get a single remote domain registration

> Returns CBM-side registration metadata for the remote domain identified by name. This call reads local state only and does not contact the remote node.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-controller","description":"Register and manage externally-hosted Canton sync domains reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RemoteDomainDto":{"type":"object","description":"Externally-hosted sync domain registered in CBM: admin / public endpoints, image metadata and lifecycle phase.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string","minLength":1},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["adminAddress","adminPort","image","name","publicAddress","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/remote-domains/{name}":{"get":{"tags":["remote-domain-controller"],"summary":"Get a single remote domain registration","description":"Returns CBM-side registration metadata for the remote domain identified by name. This call reads local state only and does not contact the remote node.","operationId":"getRemoteDomain","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteDomainDto"}}}},"400":{"description":"The supplied name is not a valid node identifier.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/RemoteDomainDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Deregister a remote domain

> Removes the CBM-side registration of the remote domain. The remote node itself is not stopped or deleted; only its local registration metadata is dropped.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-controller","description":"Register and manage externally-hosted Canton sync domains reachable from this CBM instance."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/remote-domains/{name}":{"delete":{"tags":["remote-domain-controller"],"summary":"Deregister a remote domain","description":"Removes the CBM-side registration of the remote domain. The remote node itself is not stopped or deleted; only its local registration metadata is dropped.","operationId":"deleteRemoteDomain","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied name is not a valid node identifier.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Check status of a remote domain

> Looks up the CBM-side registration for the given remote domain and proxies a status probe to its admin endpoint. Returns the health information reported by the remote node.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"remote-domain-status-controller","description":"Inspect the runtime status of a remote Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainStatusDto":{"type":"object","description":"Runtime status of a single-replica sync domain: active flag, id, uptime, sequencer state and the list of currently connected participants.","properties":{"active":{"type":"boolean"},"connectedParticipants":{"type":"array","items":{"type":"string"}},"id":{"type":"string"},"sequencer":{"$ref":"#/components/schemas/SequencerDto"},"uptime":{"type":"integer","format":"int64"}}},"SequencerDto":{"type":"object","description":"Compact status of a Canton sequencer: active flag and free-form details string.","properties":{"active":{"type":"boolean"},"details":{"type":"string"}}}}},"paths":{"/remote-domains/{name}/status":{"get":{"tags":["remote-domain-status-controller"],"summary":"Check status of a remote domain","description":"Looks up the CBM-side registration for the given remote domain and proxies a status probe to its admin endpoint. Returns the health information reported by the remote node.","operationId":"getRemoteDomainHealthStatus","parameters":[{"name":"name","in":"path","description":"CBM-side registration name of the remote domain to probe.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainStatusDto"}}}},"400":{"description":"The supplied name is not a valid node identifier.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No remote domain is registered under the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainStatusDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get participant

> Returns the configuration and current lifecycle phase of a single participant, including storage, ports, ledger/admin addresses, authorization and resource settings.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-controller","description":"Create, list, edit and remove Canton participant deployments, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ParticipantDto":{"type":"object","description":"Canton participant definition: container image, admin / ledger endpoints, authentication, postgres storage and Canton-specific settings used to provision a new participant deployment.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"auth":{"type":"boolean"},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"authorization":{"$ref":"#/components/schemas/AuthorizationDto"},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonapi":{"type":"boolean"},"jsonapiImage":{"type":"string"},"privateJsonapi":{"type":"boolean"},"jsonapiQueryStore":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"ledgerAddress":{"type":"string"},"ledgerPort":{"type":"string","minLength":1},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"navigator":{"type":"boolean"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"},"validatorParent":{"type":"string"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}},"required":["adminPort","authProvider","image","ledgerPort","name"]},"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/participants/{name}":{"get":{"tags":["participant-controller"],"summary":"Get participant","description":"Returns the configuration and current lifecycle phase of a single participant, including storage, ports, ledger/admin addresses, authorization and resource settings.","operationId":"getParticipant","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to fetch.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantDto"}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete participant

> Removes the participant Custom Resource together with its database secret, Keycloak client scopes and any cached local-party state. The underlying Kubernetes workload is torn down asynchronously by the operator.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-controller","description":"Create, list, edit and remove Canton participant deployments, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/participants/{name}":{"delete":{"tags":["participant-controller"],"summary":"Delete participant","description":"Removes the participant Custom Resource together with its database secret, Keycloak client scopes and any cached local-party state. The underlying Kubernetes workload is torn down asynchronously by the operator.","operationId":"deleteParticipant","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to delete.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Check status of a participant

> Queries the participant's admin API and returns its live runtime status, including whether it is initialized, active and connected to its sync domains. The participant is selected dynamically depending on whether it is a Canton or validator-backed participant.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-status-controller","description":"Inspect the runtime status of a Canton participant (health, sync state, connected domains)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ParticipantStatusDto":{"type":"object","description":"Runtime status of a Canton participant: active flag, id, uptime and the lists of currently connected and unhealthy sync domains.","properties":{"active":{"type":"boolean"},"connectedDomains":{"type":"array","items":{"type":"string"}},"id":{"type":"string"},"unhealthyDomains":{"type":"array","items":{"type":"string"}},"uptime":{"type":"integer","format":"int64"}}}}},"paths":{"/participants/{name}/status":{"get":{"tags":["participant-status-controller"],"summary":"Check status of a participant","description":"Queries the participant's admin API and returns its live runtime status, including whether it is initialized, active and connected to its sync domains. The participant is selected dynamically depending on whether it is a Canton or validator-backed participant.","operationId":"getParticipantHealthStatus","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant to query.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port on which to contact the participant.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantStatusDto"}}}},"400":{"description":"The participant name or port failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ParticipantStatusDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List backup files available for restore

> Lists the backup files in the participant's backup location that can be used as the source for a restore. Names returned here can be passed to the create restore endpoint.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-restore-controller","description":"Restore a Canton participant from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BackupHistoryDto":{"type":"object","description":"Entry in the backup history of a Canton workload describing a single backup artifact: file name, size in bytes, status of the backup operation and the timestamp at which it was produced.","properties":{"filename":{"type":"string"},"size":{"type":"integer","format":"int32","description":"File size in bytes"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/participants/{name}/restore/listFiles":{"get":{"tags":["participant-restore-controller"],"summary":"List backup files available for restore","description":"Lists the backup files in the participant's backup location that can be used as the source for a restore. Names returned here can be passed to the create restore endpoint.","operationId":"getParticipantRestoreFiles","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose available backup files to list.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get participant restore history

> Returns the history of restore operations previously executed for the participant, including their source backup file, completion time and final status.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-restore-controller","description":"Restore a Canton participant from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RestoreHistoryDto":{"type":"object","description":"Single entry in a restore history: filename, status, timestamp and any log captured during the restore.","properties":{"filename":{"type":"string"},"log":{"type":"string"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/participants/{name}/restore/history":{"get":{"tags":["participant-restore-controller"],"summary":"Get participant restore history","description":"Returns the history of restore operations previously executed for the participant, including their source backup file, completion time and final status.","operationId":"getParticipantRestoreHistory","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose restore history to fetch.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/RestoreHistoryDto"}}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/RestoreHistoryDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List local parties

> Returns the cached view of parties hosted on the given participant, along with the status of the latest background refresh. The data is served from CBM's in-memory cache and may lag the ledger; use the fetch endpoint to force a refresh.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"local-party-controller","description":"Fetch and synchronise local parties hosted on a Canton participant."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"LocalPartyListingDTO":{"type":"object","description":"Local-party listing for a participant: the in-progress fetch flag and the currently-known list of party identifiers.","properties":{"fetching":{"type":"boolean"},"parties":{"type":"array","items":{"type":"string"}}}}}},"paths":{"/participants/{name}/parties/local":{"get":{"tags":["local-party-controller"],"summary":"List local parties","description":"Returns the cached view of parties hosted on the given participant, along with the status of the latest background refresh. The data is served from CBM's in-memory cache and may lag the ledger; use the fetch endpoint to force a refresh.","operationId":"getLocalParties","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose local parties to list.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/LocalPartyListingDTO"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get participant backup history

> Returns the list of previously produced backup files for the participant, as reported by the backup CronJob's history, including their filenames and creation timestamps.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"participant-backup-controller","description":"Trigger participant backups, browse backup history and manage scheduled participant backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BackupHistoryDto":{"type":"object","description":"Entry in the backup history of a Canton workload describing a single backup artifact: file name, size in bytes, status of the backup operation and the timestamp at which it was produced.","properties":{"filename":{"type":"string"},"size":{"type":"integer","format":"int32","description":"File size in bytes"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/participants/{name}/backup/history":{"get":{"tags":["participant-backup-controller"],"summary":"Get participant backup history","description":"Returns the list of previously produced backup files for the participant, as reported by the backup CronJob's history, including their filenames and creation timestamps.","operationId":"getParticipantBackupHistory","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the participant whose backup history to fetch.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"400":{"description":"The participant name failed validation.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No participant with the given name exists.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get cluster observability information

> Returns information about the cluster-level observability stack, in particular the URL of the cluster dashboard used to inspect metrics and health of managed workloads.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"observability-controller","description":"Expose observability data such as metrics endpoints for the managed workloads."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ClusterInformationDto":{"type":"object","description":"Connection metadata describing the Canton / Splice cluster CBM is attached to (URL of the cluster control plane).","properties":{"url":{"type":"string"}}}}},"paths":{"/observability/cluster":{"get":{"tags":["observability-controller"],"summary":"Get cluster observability information","description":"Returns information about the cluster-level observability stack, in particular the URL of the cluster dashboard used to inspect metrics and health of managed workloads.","operationId":"getCluster","responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ClusterInformationDto"}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Fetch a window of log lines for a node

> Returns up to numLogs parsed log lines around the given reference timestamp, filtered by minimum log level and a free-text filter. Use prevLogs to fetch lines older than the reference timestamp.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"log-controller","description":"Stream pod logs and adjust log levels at runtime for the managed workloads."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"LogLineDto":{"type":"object","description":"Single Canton-formatted log line: parsed timestamp, log level and message content.","properties":{"content":{"type":"string"},"level":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"timeStamp":{"type":"string"}}}}},"paths":{"/logs/{name}":{"get":{"tags":["log-controller"],"summary":"Fetch a window of log lines for a node","description":"Returns up to numLogs parsed log lines around the given reference timestamp, filtered by minimum log level and a free-text filter. Use prevLogs to fetch lines older than the reference timestamp.","operationId":"printLogs","parameters":[{"name":"name","in":"path","description":"Name of the Canton node whose logs should be returned","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"referenceTimestamp","in":"query","description":"Reference timestamp (ISO-8601) used as the anchor of the log window","required":true,"schema":{"type":"string"}},{"name":"prevLogs","in":"query","description":"If true, fetch lines older than the reference timestamp; otherwise newer","required":true,"schema":{"type":"boolean"}},{"name":"numLogs","in":"query","description":"Number of log lines to return (between 20 and 100)","required":true,"schema":{"type":"integer","format":"int32","maximum":100,"minimum":20}},{"name":"level","in":"query","description":"Minimum log level to include","required":true,"schema":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]}},{"name":"filter","in":"query","description":"Free-text substring filter applied to log messages","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/LogLineDto"}}}}},"400":{"description":"Invalid node name or query parameters","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node or its pod not found","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/LogLineDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Download node logs as a streamed file

> Streams up to tailLines most recent log lines from the node's pod as a plain text attachment. When previous=true, logs are pulled from the previously terminated container instance. The response uses a streaming body so the connection remains open while logs are written.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"log-controller","description":"Stream pod logs and adjust log levels at runtime for the managed workloads."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"StreamingResponseBody":{}}},"paths":{"/logs/{name}/download":{"get":{"tags":["log-controller"],"summary":"Download node logs as a streamed file","description":"Streams up to tailLines most recent log lines from the node's pod as a plain text attachment. When previous=true, logs are pulled from the previously terminated container instance. The response uses a streaming body so the connection remains open while logs are written.","operationId":"downloadLogs","parameters":[{"name":"name","in":"path","description":"Name of the Canton node whose logs should be downloaded","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"tailLines","in":"query","description":"Number of most recent log lines to include (100-100000, default 10000)","required":false,"schema":{"type":"integer","format":"int32","default":10000,"maximum":100000,"minimum":100}},{"name":"previous","in":"query","description":"If true, fetch logs from the previous (terminated) container instance","required":false,"schema":{"type":"boolean","default":false}}],"responses":{"400":{"description":"Invalid node name or query parameters","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node, pod or previous container instance not found","content":{"*/*":{"schema":{"$ref":"#/components/schemas/StreamingResponseBody"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List all identity dumps

> Returns identity dump secrets for every validator managed by this CBM, across all validators.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"IdDumpDto":{"type":"object","description":"Identity-dump artifact metadata: name of the Kubernetes secret holding the dump, the owning validator name and the timestamp at which it was captured.","properties":{"secretName":{"type":"string"},"validatorName":{"type":"string"},"timestamp":{"type":"integer","format":"int64"},"createdAt":{"type":"string"}}}}},"paths":{"/id-dumps":{"get":{"tags":["validator-id-dumps-controller"],"summary":"List all identity dumps","description":"Returns identity dump secrets for every validator managed by this CBM, across all validators.","operationId":"listAllParticipantIdentityDumps","responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/IdDumpDto"}}}}},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List available health dump files on a node

> Returns the names of health dump files that currently exist on the target node and can be downloaded via the download endpoint.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"health-dump-controller","description":"Trigger and download Canton health dumps for diagnostic purposes."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/health-dumps/{name}":{"get":{"tags":["health-dump-controller"],"summary":"List available health dump files on a node","description":"Returns the names of health dump files that currently exist on the target node and can be downloaded via the download endpoint.","operationId":"listHealthDumpFiles","parameters":[{"name":"name","in":"path","description":"Name of the Canton node whose health dump files should be listed","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"type":"string"}}}}},"400":{"description":"Invalid node name","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node not found","content":{"*/*":{"schema":{"type":"array","items":{"type":"string"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Generate and download a node health dump

> Triggers the Canton health dump command on the target node and returns the resulting diagnostics file as an application/octet-stream attachment. The version of the health dump API used depends on whether the node is a validator (V3) or a classic Canton node (V0).

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"health-dump-controller","description":"Trigger and download Canton health dumps for diagnostic purposes."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/health-dumps/{name}/execute":{"get":{"tags":["health-dump-controller"],"summary":"Generate and download a node health dump","description":"Triggers the Canton health dump command on the target node and returns the resulting diagnostics file as an application/octet-stream attachment. The version of the health dump API used depends on whether the node is a validator (V3) or a classic Canton node (V0).","operationId":"executeHealthDump","parameters":[{"name":"name","in":"path","description":"Name of the Canton node to generate a health dump for","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"string","format":"binary"}}}},"400":{"description":"Invalid node name","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node not found","content":{"*/*":{"schema":{"type":"string","format":"binary"}}}},"500":{"description":"Internal server error while creating or writing health dump file","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Download an existing health dump file

> Streams a previously generated health dump file from the target node by its path as an application/octet-stream attachment.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"health-dump-controller","description":"Trigger and download Canton health dumps for diagnostic purposes."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/health-dumps/{name}/download":{"get":{"tags":["health-dump-controller"],"summary":"Download an existing health dump file","description":"Streams a previously generated health dump file from the target node by its path as an application/octet-stream attachment.","operationId":"getHealthDumpFile","parameters":[{"name":"name","in":"path","description":"Name of the Canton node that owns the health dump file","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"filePath","in":"query","description":"Path of the health dump file on the node to download","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"400":{"description":"Invalid node name or file path","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node or health dump file not found","content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Download a stored file

> Returns the raw binary contents of a previously uploaded file of the given type as an application/octet-stream response.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"file-storage-controller","description":"Upload, list and remove files used by validators, participants and domains (DAR packages, identity dumps, configuration archives, …)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/files/{name}":{"get":{"tags":["file-storage-controller"],"summary":"Download a stored file","description":"Returns the raw binary contents of a previously uploaded file of the given type as an application/octet-stream response.","operationId":"getFile","parameters":[{"name":"name","in":"path","description":"Name of the file to download","required":true,"schema":{"type":"string"}},{"name":"fileType","in":"query","description":"Type/category of the file to download","required":true,"schema":{"type":"string","enum":["DAR","UI_PACKAGE"]}}],"responses":{"200":{"description":"OK","content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"400":{"description":"Invalid file name or type","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"File not found in storage","content":{"application/octet-stream":{"schema":{"type":"string","format":"binary"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete a stored file

> Removes a previously uploaded file of the given type from server-side storage.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"file-storage-controller","description":"Upload, list and remove files used by validators, participants and domains (DAR packages, identity dumps, configuration archives, …)."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/files/{name}":{"delete":{"tags":["file-storage-controller"],"summary":"Delete a stored file","description":"Removes a previously uploaded file of the given type from server-side storage.","operationId":"deleteFile","parameters":[{"name":"name","in":"path","description":"Name of the file to delete","required":true,"schema":{"type":"string"}},{"name":"fileType","in":"query","description":"Type/category of the file to delete","required":true,"schema":{"type":"string","enum":["DAR","UI_PACKAGE"]}}],"responses":{"204":{"description":"No Content"},"400":{"description":"Invalid file name or type","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"File not found in storage"},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get a sync domain by name

> Returns the full DTO of a single sync domain, including its current phase, storage configuration, resources, and topology.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-controller","description":"Create, list, edit and remove Canton sync domains, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainDto":{"type":"object","description":"Canton sync domain definition: name, container image, log level, admin / public endpoints and Canton-specific bootstrap settings used to provision a single-replica sync domain.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"ingress":{"type":"boolean"},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string"},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"}},"required":["adminPort","image","name","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}},"paths":{"/domains/{name}":{"get":{"tags":["domain-controller"],"summary":"Get a sync domain by name","description":"Returns the full DTO of a single sync domain, including its current phase, storage configuration, resources, and topology.","operationId":"getDomain","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainDto"}}}},"400":{"description":"The supplied domain name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete a sync domain

> Removes the sync domain Kubernetes resource and its associated database secret. The underlying resources are cleaned up asynchronously by the operator.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-controller","description":"Create, list, edit and remove Canton sync domains, and read their configuration."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/domains/{name}":{"delete":{"tags":["domain-controller"],"summary":"Delete a sync domain","description":"Removes the sync domain Kubernetes resource and its associated database secret. The underlying resources are cleaned up asynchronously by the operator.","operationId":"deleteDomain","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain to delete.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied domain name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Check status of a domain

> Queries the live admin API of the sync domain and returns its current health and runtime status. The domain pod must be reachable for the call to succeed.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-status-controller","description":"Inspect the runtime status of a Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainStatusDto":{"type":"object","description":"Runtime status of a single-replica sync domain: active flag, id, uptime, sequencer state and the list of currently connected participants.","properties":{"active":{"type":"boolean"},"connectedParticipants":{"type":"array","items":{"type":"string"}},"id":{"type":"string"},"sequencer":{"$ref":"#/components/schemas/SequencerDto"},"uptime":{"type":"integer","format":"int64"}}},"SequencerDto":{"type":"object","description":"Compact status of a Canton sequencer: active flag and free-form details string.","properties":{"active":{"type":"boolean"},"details":{"type":"string"}}}}},"paths":{"/domains/{name}/status":{"get":{"tags":["domain-status-controller"],"summary":"Check status of a domain","description":"Queries the live admin API of the sync domain and returns its current health and runtime status. The domain pod must be reachable for the call to succeed.","operationId":"getDomainHealthStatus","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"port","in":"query","description":"Admin gRPC port of the domain to query; defaults to the standard admin port.","required":false,"schema":{"type":"integer","format":"int32","default":5019}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainStatusDto"}}}},"400":{"description":"The supplied domain name or port is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainStatusDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## List available backup files for restore

> Returns the list of backup artifacts currently available on the domain's backup storage. Any returned file name can be used as the source of a restore job.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-restore-controller","description":"Restore a Canton sync domain from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BackupHistoryDto":{"type":"object","description":"Entry in the backup history of a Canton workload describing a single backup artifact: file name, size in bytes, status of the backup operation and the timestamp at which it was produced.","properties":{"filename":{"type":"string"},"size":{"type":"integer","format":"int32","description":"File size in bytes"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/domains/{name}/restore/listFiles":{"get":{"tags":["domain-restore-controller"],"summary":"List available backup files for restore","description":"Returns the list of backup artifacts currently available on the domain's backup storage. Any returned file name can be used as the source of a restore job.","operationId":"getDomainRestoreFiles","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain whose backup files should be listed.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"400":{"description":"The supplied domain name is invalid or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get domain restore history

> Returns the history of past restore runs for the sync domain, including the status and metadata of each completed or failed attempt.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-restore-controller","description":"Restore a Canton sync domain from a previously created backup."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"RestoreHistoryDto":{"type":"object","description":"Single entry in a restore history: filename, status, timestamp and any log captured during the restore.","properties":{"filename":{"type":"string"},"log":{"type":"string"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/domains/{name}/restore/history":{"get":{"tags":["domain-restore-controller"],"summary":"Get domain restore history","description":"Returns the history of past restore runs for the sync domain, including the status and metadata of each completed or failed attempt.","operationId":"getDomainRestoreHistory","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain to query history for.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/RestoreHistoryDto"}}}}},"400":{"description":"The supplied domain name is invalid or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/RestoreHistoryDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get domain backup history

> Returns the history of past backup runs for the sync domain, including status and metadata for each produced artifact.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-backup-controller","description":"Trigger domain backups, browse backup history and manage scheduled domain backups."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"BackupHistoryDto":{"type":"object","description":"Entry in the backup history of a Canton workload describing a single backup artifact: file name, size in bytes, status of the backup operation and the timestamp at which it was produced.","properties":{"filename":{"type":"string"},"size":{"type":"integer","format":"int32","description":"File size in bytes"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}},"paths":{"/domains/{name}/backup/history":{"get":{"tags":["domain-backup-controller"],"summary":"Get domain backup history","description":"Returns the history of past backup runs for the sync domain, including status and metadata for each produced artifact.","operationId":"getDomainBackupHistory","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the sync domain to query history for.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"400":{"description":"The supplied domain name is invalid or backup is not supported.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No sync domain exists with the given name.","content":{"*/*":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/BackupHistoryDto"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get a HA sync domain by name

> Returns the full DTO of a single HA sync domain, including replication configuration and the current phase.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-ha-controller","description":"Configure and inspect high-availability settings of a Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"DomainHADto":{"type":"object","description":"High-availability sync domain definition: per-component (sequencer, mediator, topology manager) specifications plus in-cluster or external storage settings.","properties":{"name":{"type":"string","maxLength":15,"minLength":2},"defaults":{"$ref":"#/components/schemas/DefaultsDto"},"sequencer":{"$ref":"#/components/schemas/SequencerSpecDto"},"mediator":{"$ref":"#/components/schemas/MediatorSpecDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerSpecDto"},"externalStorage":{"$ref":"#/components/schemas/ExternalStorageSpecDto"},"inClusterStorage":{"$ref":"#/components/schemas/InClusterStorageSpecDto"},"validStorage":{"type":"boolean"}},"required":["defaults","mediator","name","sequencer","topologyManager"]},"DefaultsDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"SequencerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"ingress":{"$ref":"#/components/schemas/SequencerIngressConfigDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"SequencerIngressConfigDto":{"type":"object","description":"Per-sequencer ingress flags toggling exposure of the admin and public APIs.","properties":{"adminAPIEnabled":{"type":"boolean"},"publicAPIEnabled":{"type":"boolean"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}},"MediatorSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"TopologyManagerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ExternalStorageSpecDto":{"type":"object","properties":{"hostname":{"type":"string","minLength":1},"port":{"type":"integer","format":"int32"},"adminUsername":{"type":"string","minLength":1},"adminPassword":{"type":"string","minLength":1},"ssl":{"type":"boolean"},"maxConnections":{"type":"integer","format":"int32"},"schemaName":{"type":"string"}},"required":["adminPassword","adminUsername","hostname","port"]},"InClusterStorageSpecDto":{"type":"object","properties":{"storageSize":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"validStorageSize":{"type":"boolean"}},"required":["resources","storageSize"]}}},"paths":{"/domainha/{name}":{"get":{"tags":["domain-ha-controller"],"summary":"Get a HA sync domain by name","description":"Returns the full DTO of a single HA sync domain, including replication configuration and the current phase.","operationId":"get","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the HA sync domain.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}}},"400":{"description":"The supplied HA domain name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No HA sync domain exists with the given name.","content":{"*/*":{"schema":{"$ref":"#/components/schemas/DomainHADto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete a HA sync domain

> Removes the HA sync domain Kubernetes resource. The replicated components are torn down asynchronously by the operator.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"domain-ha-controller","description":"Configure and inspect high-availability settings of a Canton sync domain."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/domainha/{name}":{"delete":{"tags":["domain-ha-controller"],"summary":"Delete a HA sync domain","description":"Removes the HA sync domain Kubernetes resource. The replicated components are torn down asynchronously by the operator.","operationId":"delete","parameters":[{"name":"name","in":"path","description":"Kubernetes resource name of the HA sync domain to delete.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"The supplied HA domain name is invalid.","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No HA sync domain exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get Canton console output for a node

> Returns the buffered Canton console (stdout) output collected from the pod backing the given node, useful for inspecting results of previously executed commands.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"log-controller","description":"Stream pod logs and adjust log levels at runtime for the managed workloads."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/console/{name}":{"get":{"tags":["log-controller"],"summary":"Get Canton console output for a node","description":"Returns the buffered Canton console (stdout) output collected from the pod backing the given node, useful for inspecting results of previously executed commands.","operationId":"printConsoleOutput","parameters":[{"name":"name","in":"path","description":"Name of the Canton node whose console output should be returned","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"type":"array","items":{"type":"string"}}}}},"400":{"description":"Invalid node name","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Node or its pod not found","content":{"*/*":{"schema":{"type":"array","items":{"type":"string"}}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Get an application by name

> Returns the current spec and status of the application identified by the given name.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"application-controller","description":"Manage generic CBM-deployed applications and their lifecycle."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}},"schemas":{"ApplicationDto":{"type":"object","description":"Generic CBM-deployed application: name, container image, port, package, parent validator and Kubernetes resource requirements; used both as a request and a response body on the applications endpoints.","properties":{"domain":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string"},"name":{"type":"string","minLength":1},"packageName":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"port":{"type":"integer","format":"int32"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"type":{"type":"string","enum":["BACKEND","UI"]},"validatorParent":{"type":"string"}},"required":["domain","name","type"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}},"paths":{"/applications/{name}":{"get":{"tags":["application-controller"],"summary":"Get an application by name","description":"Returns the current spec and status of the application identified by the given name.","operationId":"getApplication","parameters":[{"name":"name","in":"path","description":"Name of the application to retrieve","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"OK","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ApplicationDto"}}}},"400":{"description":"Invalid application name","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Application not found","content":{"*/*":{"schema":{"$ref":"#/components/schemas/ApplicationDto"}}}},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete an application

> Removes the application CRD identified by name and cleans up any associated auth provider clients (e.g. Keycloak) that were created for it.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"application-controller","description":"Manage generic CBM-deployed applications and their lifecycle."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/applications/{name}":{"delete":{"tags":["application-controller"],"summary":"Delete an application","description":"Removes the application CRD identified by name and cleans up any associated auth provider clients (e.g. Keycloak) that were created for it.","operationId":"deleteApplication","parameters":[{"name":"name","in":"path","description":"Name of the application to delete","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"Invalid application name","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"Application not found"},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete all identity dumps

> Removes every identity dump secret currently stored for the validator. The schedule (if any) is not affected.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/id-dumps/{validatorName}/dumps":{"delete":{"tags":["validator-id-dumps-controller"],"summary":"Delete all identity dumps","description":"Removes every identity dump secret currently stored for the validator. The schedule (if any) is not affected.","operationId":"deleteAllIdentityDumps","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator exists with the given name."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## Delete a single identity dump

> Removes a single identity dump secret belonging to the validator, identified by the secret's name. Other dumps and the schedule are left untouched.

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"tags":[{"name":"validator-id-dumps-controller","description":"Trigger and schedule validator identity dump jobs and download their artifacts."}],"servers":[{"url":"http://localhost:8080/api","description":"Generated server url"}],"security":[{"bearerAuth":[]}],"components":{"securitySchemes":{"bearerAuth":{"type":"http","description":"Bearer JWT issued by the configured OAuth2 / OIDC provider (typically Keycloak or Auth0). Pass as `Authorization: Bearer <access_token>`.","name":"bearerAuth","scheme":"bearer","bearerFormat":"JWT"}}},"paths":{"/id-dumps/{validatorName}/dumps/{secretName}":{"delete":{"tags":["validator-id-dumps-controller"],"summary":"Delete a single identity dump","description":"Removes a single identity dump secret belonging to the validator, identified by the secret's name. Other dumps and the schedule are left untouched.","operationId":"deleteIdentityDump","parameters":[{"name":"validatorName","in":"path","description":"Kubernetes resource name of the validator.","required":true,"schema":{"type":"string","maxLength":47,"minLength":1,"pattern":"[a-z]([-a-z0-9]*[a-z0-9])?([a-z0-9]([-a-z0-9]*[a-z0-9])?)*"}},{"name":"secretName","in":"path","description":"Name of the Kubernetes secret holding the identity dump to delete.","required":true,"schema":{"type":"string"}}],"responses":{"204":{"description":"No Content"},"400":{"description":"Bad Request","content":{"*/*":{"schema":{"type":"object","additionalProperties":{"type":"string"}}}}},"401":{"description":"Unauthorized","content":{"*/*":{"schema":{"type":"object"}}}},"404":{"description":"No validator or identity dump secret matches the given names."},"500":{"description":"Internal Server Error","content":{"*/*":{"schema":{"type":"object"}}}}}}}}}
```

## The AppInfoEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"AppInfoEditDto":{"type":"object","description":"Partial update payload for an application component's deployment metadata; non-null fields replace the existing values and `envVarsDelete` removes specific variables.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"envVarsDelete":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The ClusterConfigEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ClusterConfigEditDto":{"type":"object","properties":{"scanAddress":{"type":"string"},"contactPoint":{"type":"string"},"migration":{"$ref":"#/components/schemas/MigrationDto"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoEditDto"},"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoEditDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoEditDto"},"disableProbes":{"type":"boolean"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}},"required":["migration"]},"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"AppInfoEditDto":{"type":"object","description":"Partial update payload for an application component's deployment metadata; non-null fields replace the existing values and `envVarsDelete` removes specific variables.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"envVarsDelete":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}}}
```

## The ConfigMapVolumeSource object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}}}}}
```

## The EmptyDirVolumeSource object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}}}}}
```

## The EnvVar object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}}}}}
```

## The EnvVarSource object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}}}}}
```

## The HostPathVolumeSource object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}}}}}
```

## The KeyToPath object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}}}}}
```

## The MigrationDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]}}}}
```

## The PersistentVolumeClaimVolumeSource object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}}}}}
```

## The PostgresConfigDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}}}}}
```

## The Quantity object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}}}}}
```

## The ResourcesDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The SecretKeySelector object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}}}}}
```

## The SecretVolumeSource object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}}}}}
```

## The TopUpDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}}}}}
```

## The ValidatorDbConfigDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}}}}}
```

## The ValidatorEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorEditDto":{"type":"object","description":"Partial update payload for a Splice validator. Non-null fields replace the corresponding section of the existing validator; null fields are left unchanged. Includes a `cleanRestoreData` flag and toggles for ledger-API exposure.","properties":{"clusterConfig":{"$ref":"#/components/schemas/ClusterConfigEditDto"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"name":{"type":"string"},"databaseStorage":{"type":"string"},"participant":{"$ref":"#/components/schemas/AppInfoEditDto"},"cleanRestoreData":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"privateJsonApi":{"type":"boolean"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"}}},"ClusterConfigEditDto":{"type":"object","properties":{"scanAddress":{"type":"string"},"contactPoint":{"type":"string"},"migration":{"$ref":"#/components/schemas/MigrationDto"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoEditDto"},"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoEditDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoEditDto"},"disableProbes":{"type":"boolean"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}},"required":["migration"]},"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"AppInfoEditDto":{"type":"object","description":"Partial update payload for an application component's deployment metadata; non-null fields replace the existing values and `envVarsDelete` removes specific variables.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"envVarsDelete":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}}}}}
```

## The Volume object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}}}}}
```

## The VolumeMount object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}}}}}
```

## The WalletSweepDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}}}
```

## The ScheduledValidatorPruneDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]}}}}
```

## The ValidatorBackupDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorBackupDto":{"type":"object","description":"Request body to trigger or schedule a Splice validator backup: cron expression and retention limit.","properties":{"cron":{"type":"string"},"maxBackups":{"type":"integer","format":"int32","maximum":84,"minimum":2}},"required":["maxBackups"]}}}}
```

## The ScheduledValidatorBackupDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ScheduledValidatorBackupDto":{"type":"object","description":"Persisted backup schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}}}
```

## The RemoteParticipantDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"RemoteParticipantDto":{"type":"object","description":"Externally-hosted Canton participant registered in CBM: admin / ledger / JSON-API endpoints, auth provider and identifying metadata.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonApiUrl":{"type":"string","minLength":1},"ledgerAddress":{"type":"string","minLength":1},"ledgerId":{"type":"string","minLength":1},"ledgerPort":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"v3":{"type":"boolean"}},"required":["adminAddress","adminPort","authProvider","image","jsonApiUrl","ledgerAddress","ledgerId","ledgerPort","name"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The RemoteDomainDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"RemoteDomainDto":{"type":"object","description":"Externally-hosted sync domain registered in CBM: admin / public endpoints, image metadata and lifecycle phase.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string","minLength":1},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["adminAddress","adminPort","image","name","publicAddress","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The AuthorizationDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}}}}}
```

## The ParticipantDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ParticipantDto":{"type":"object","description":"Canton participant definition: container image, admin / ledger endpoints, authentication, postgres storage and Canton-specific settings used to provision a new participant deployment.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"auth":{"type":"boolean"},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"authorization":{"$ref":"#/components/schemas/AuthorizationDto"},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonapi":{"type":"boolean"},"jsonapiImage":{"type":"string"},"privateJsonapi":{"type":"boolean"},"jsonapiQueryStore":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"ledgerAddress":{"type":"string"},"ledgerPort":{"type":"string","minLength":1},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"navigator":{"type":"boolean"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"},"validatorParent":{"type":"string"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}},"required":["adminPort","authProvider","image","ledgerPort","name"]},"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}}}
```

## The StorageDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}}}
```

## The ValidatorIdDumpScheduleDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorIdDumpScheduleDto":{"type":"object","description":"Request body to schedule recurring identity dumps for a Splice validator (cron expression plus retention limit); converts to the underlying CRD.","properties":{"cron":{"type":"string"},"maxDumps":{"type":"integer","format":"int32","minimum":1}}}}}}
```

## The ScheduledValidatorIdDumpDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ScheduledValidatorIdDumpDto":{"type":"object","description":"Persisted identity-dump schedule for a Splice validator: cron expression, retention limit and next-run timestamp.","properties":{"validatorName":{"type":"string"},"cron":{"type":"string"},"nextRun":{"type":"string"},"maxDumps":{"type":"integer","format":"int32"}}}}}}
```

## The DomainDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainDto":{"type":"object","description":"Canton sync domain definition: name, container image, log level, admin / public endpoints and Canton-specific bootstrap settings used to provision a single-replica sync domain.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"ingress":{"type":"boolean"},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string"},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"}},"required":["adminPort","image","name","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}}}
```

## The CantonFlagsDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}}}}}
```

## The ContainerResourcesDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]}}}}
```

## The DefaultsEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DefaultsEditDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}}}}}
```

## The DomainHAEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainHAEditDto":{"type":"object","description":"Partial update payload for an HA sync domain; non-null sections replace the corresponding configuration on the existing deployment.","properties":{"name":{"type":"string"},"defaults":{"$ref":"#/components/schemas/DefaultsEditDto"},"sequencer":{"$ref":"#/components/schemas/SequencerEditDto"},"mediator":{"$ref":"#/components/schemas/MediatorEditDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerEditDto"},"inClusterStorage":{"$ref":"#/components/schemas/InClusterStorageEditDto"}},"required":["defaults","mediator","name","sequencer","topologyManager"]},"DefaultsEditDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"SequencerEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"MediatorEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"TopologyManagerEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"InClusterStorageEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"storageSize":{"type":"string"},"validStorageSize":{"type":"boolean"}},"required":["resources"]}}}}
```

## The ImageDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]}}}}
```

## The InClusterStorageEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"InClusterStorageEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"storageSize":{"type":"string"},"validStorageSize":{"type":"boolean"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]}}}}
```

## The MediatorEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"MediatorEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}}}}}
```

## The ResourceRequirementsDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]}}}}
```

## The SequencerEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SequencerEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}}}}}
```

## The TopologyManagerEditDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"TopologyManagerEditDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}}}}}
```

## The DefaultsDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DefaultsDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}}}}}
```

## The DomainHADto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainHADto":{"type":"object","description":"High-availability sync domain definition: per-component (sequencer, mediator, topology manager) specifications plus in-cluster or external storage settings.","properties":{"name":{"type":"string","maxLength":15,"minLength":2},"defaults":{"$ref":"#/components/schemas/DefaultsDto"},"sequencer":{"$ref":"#/components/schemas/SequencerSpecDto"},"mediator":{"$ref":"#/components/schemas/MediatorSpecDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerSpecDto"},"externalStorage":{"$ref":"#/components/schemas/ExternalStorageSpecDto"},"inClusterStorage":{"$ref":"#/components/schemas/InClusterStorageSpecDto"},"validStorage":{"type":"boolean"}},"required":["defaults","mediator","name","sequencer","topologyManager"]},"DefaultsDto":{"type":"object","properties":{"image":{"$ref":"#/components/schemas/ImageDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"}},"required":["image"]},"ImageDto":{"type":"object","description":"Container image reference: registry, repository, tag and the Kubernetes pull secret used to fetch it.","properties":{"registry":{"type":"string","minLength":1},"repository":{"type":"string","minLength":1},"tag":{"type":"string","minLength":1},"pullSecretName":{"type":"string"}},"required":["registry","repository","tag"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"SequencerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"ingress":{"$ref":"#/components/schemas/SequencerIngressConfigDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"SequencerIngressConfigDto":{"type":"object","description":"Per-sequencer ingress flags toggling exposure of the admin and public APIs.","properties":{"adminAPIEnabled":{"type":"boolean"},"publicAPIEnabled":{"type":"boolean"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}},"MediatorSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"TopologyManagerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ExternalStorageSpecDto":{"type":"object","properties":{"hostname":{"type":"string","minLength":1},"port":{"type":"integer","format":"int32"},"adminUsername":{"type":"string","minLength":1},"adminPassword":{"type":"string","minLength":1},"ssl":{"type":"boolean"},"maxConnections":{"type":"integer","format":"int32"},"schemaName":{"type":"string"}},"required":["adminPassword","adminUsername","hostname","port"]},"InClusterStorageSpecDto":{"type":"object","properties":{"storageSize":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"validStorageSize":{"type":"boolean"}},"required":["resources","storageSize"]}}}}
```

## The ExternalStorageOverridesDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}}}}}
```

## The ExternalStorageSpecDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ExternalStorageSpecDto":{"type":"object","properties":{"hostname":{"type":"string","minLength":1},"port":{"type":"integer","format":"int32"},"adminUsername":{"type":"string","minLength":1},"adminPassword":{"type":"string","minLength":1},"ssl":{"type":"boolean"},"maxConnections":{"type":"integer","format":"int32"},"schemaName":{"type":"string"}},"required":["adminPassword","adminUsername","hostname","port"]}}}}
```

## The InClusterStorageSpecDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"InClusterStorageSpecDto":{"type":"object","properties":{"storageSize":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"validStorageSize":{"type":"boolean"}},"required":["resources","storageSize"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]}}}}
```

## The MediatorSpecDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"MediatorSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}}}}}
```

## The SequencerIngressConfigDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SequencerIngressConfigDto":{"type":"object","description":"Per-sequencer ingress flags toggling exposure of the admin and public APIs.","properties":{"adminAPIEnabled":{"type":"boolean"},"publicAPIEnabled":{"type":"boolean"}}}}}}
```

## The SequencerSpecDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SequencerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"ingress":{"$ref":"#/components/schemas/SequencerIngressConfigDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"SequencerIngressConfigDto":{"type":"object","description":"Per-sequencer ingress flags toggling exposure of the admin and public APIs.","properties":{"adminAPIEnabled":{"type":"boolean"},"publicAPIEnabled":{"type":"boolean"}}},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}}}}}
```

## The TopologyManagerSpecDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"TopologyManagerSpecDto":{"type":"object","properties":{"resources":{"$ref":"#/components/schemas/ResourceRequirementsDto"},"cantonFlags":{"$ref":"#/components/schemas/CantonFlagsDto"},"env":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"storageOverrides":{"$ref":"#/components/schemas/ExternalStorageOverridesDto"}},"required":["resources"]},"ResourceRequirementsDto":{"type":"object","description":"Kubernetes container resource requirements: limits and requests, each composed of CPU and memory values.","properties":{"limits":{"$ref":"#/components/schemas/ContainerResourcesDto"},"requests":{"$ref":"#/components/schemas/ContainerResourcesDto"}},"required":["limits","requests"]},"ContainerResourcesDto":{"type":"object","description":"Kubernetes container CPU and memory values (used as either limits or requests).","properties":{"cpu":{"type":"string","minLength":1},"memory":{"type":"string","minLength":1}},"required":["cpu","memory"]},"CantonFlagsDto":{"type":"object","description":"Runtime log-level flags for a Canton workload (root, Canton-specific and stdout log levels).","properties":{"logLevelRoot":{"type":"string"},"logLevelCanton":{"type":"string"},"logLevelStdout":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ExternalStorageOverridesDto":{"type":"object","properties":{"schemaName":{"type":"string"},"dbName":{"type":"string"},"userUsername":{"type":"string"},"userPassword":{"type":"string"}}}}}}
```

## The ApplicationDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ApplicationDto":{"type":"object","description":"Generic CBM-deployed application: name, container image, port, package, parent validator and Kubernetes resource requirements; used both as a request and a response body on the applications endpoints.","properties":{"domain":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string"},"name":{"type":"string","minLength":1},"packageName":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"port":{"type":"integer","format":"int32"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"type":{"type":"string","enum":["BACKEND","UI"]},"validatorParent":{"type":"string"}},"required":["domain","name","type"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The AppInfoDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The ClusterConfigDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ClusterConfigDto":{"type":"object","description":"Cluster-wide Splice / Canton configuration for a validator: shared DARs, application metadata for validator / wallet / CNS, decentralized synchronizer URL, dev-net flags and JVM options.","properties":{"additionalConfigOther":{"type":"string"},"additionalUsersEnvVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"appDars":{"type":"string"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"contactPoint":{"type":"string"},"decentralizedSynchronizerUrl":{"type":"string"},"defaultJvmOptions":{"type":"string","minLength":1},"devNet":{"type":"boolean"},"disabledWallet":{"type":"boolean"},"extraDomains":{"type":"array","items":{"$ref":"#/components/schemas/ExtraDomainDto"}},"failOnAppVersionMismatch":{"type":"boolean"},"fixedTokens":{"type":"boolean"},"metrics":{"$ref":"#/components/schemas/MetricsDto"},"migrateValidatorParty":{"type":"boolean"},"migration":{"$ref":"#/components/schemas/MigrationDto"},"participantIdentitiesDumpBackup":{"$ref":"#/components/schemas/IdentitiesDumpPeriodicBackupDto"},"participantIdentitiesDumpImport":{"$ref":"#/components/schemas/ParticipantIdentitiesImportDto"},"partyHint":{"type":"string","minLength":1},"pvcVolumeStorageClass":{"type":"string"},"scanAddress":{"type":"string","minLength":1},"svSponsorAddress":{"type":"string","minLength":1},"svValidator":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"useSequencerConnectionsFromScan":{"type":"boolean"},"walletUserName":{"type":"string"},"scheduledPrune":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"},"disableProbes":{"type":"boolean"}},"required":["appInfoCantonNameService","appInfoValidator","defaultJvmOptions","migration","partyHint","scanAddress","svSponsorAddress"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"ExtraDomainDto":{"type":"object","properties":{"alias":{"type":"string"},"url":{"type":"string"}}},"MetricsDto":{"type":"object","properties":{"enable":{"type":"boolean"},"interval":{"type":"string"},"release":{"type":"string"}}},"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]},"IdentitiesDumpPeriodicBackupDto":{"type":"object","properties":{"backupInterval":{"type":"string","minLength":1},"locationBucketName":{"type":"string","minLength":1},"locationBucketProjectId":{"type":"string","minLength":1},"locationBucketSecretName":{"type":"string","minLength":1},"locationPrefix":{"type":"string"}},"required":["backupInterval","locationBucketName","locationBucketProjectId","locationBucketSecretName","locationPrefix"]},"ParticipantIdentitiesImportDto":{"type":"object","properties":{"identitiesSecretName":{"type":"string","description":"The name of the secret participant identities backup file dump.","minLength":1},"newParticipantIdentifier":{"type":"string","minLength":1}},"required":["identitiesSecretName","newParticipantIdentifier"]},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]}}}}
```

## The ClusterParticipantConfigDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ClusterParticipantConfigDto":{"type":"object","description":"Participant-side cluster configuration: JVM options, KMS settings, exposure of the ledger / JSON API and node identifier.","properties":{"defaultJvmOptions":{"type":"string","deprecated":true},"enableHealthProbes":{"type":"boolean","deprecated":true},"nodeIdentifier":{"type":"string"},"exposeLedgerApi":{"type":"boolean"},"privateJsonApi":{"type":"boolean"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}}}}}}
```

## The ExtraDomainDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ExtraDomainDto":{"type":"object","properties":{"alias":{"type":"string"},"url":{"type":"string"}}}}}}
```

## The IdentitiesDumpPeriodicBackupDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"IdentitiesDumpPeriodicBackupDto":{"type":"object","properties":{"backupInterval":{"type":"string","minLength":1},"locationBucketName":{"type":"string","minLength":1},"locationBucketProjectId":{"type":"string","minLength":1},"locationBucketSecretName":{"type":"string","minLength":1},"locationPrefix":{"type":"string"}},"required":["backupInterval","locationBucketName","locationBucketProjectId","locationBucketSecretName","locationPrefix"]}}}}
```

## The MetricsDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"MetricsDto":{"type":"object","properties":{"enable":{"type":"boolean"},"interval":{"type":"string"},"release":{"type":"string"}}}}}}
```

## The ParticipantIdentitiesImportDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ParticipantIdentitiesImportDto":{"type":"object","properties":{"identitiesSecretName":{"type":"string","description":"The name of the secret participant identities backup file dump.","minLength":1},"newParticipantIdentifier":{"type":"string","minLength":1}},"required":["identitiesSecretName","newParticipantIdentifier"]}}}}
```

## The ValidatorAuthDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorAuthDto":{"type":"object","description":"Auth configuration for a Splice validator: per-application OIDC client ids / secrets and the OAuth2 issuer / audience to use.","properties":{"cnsClientId":{"type":"string","description":"Client for the Canton Name Service","minLength":1},"walletClientId":{"type":"string","description":"Client for Wallet application","minLength":1},"ledgerApiClientId":{"type":"string","description":"Client for Validator","minLength":1},"ledgerApiClientSecret":{"type":"string","description":"Secret part of Client Credentials Grant Flow for the Validator client","minLength":1},"walletUser":{"type":"string","description":"User that will access the wallet application and receive rewards","minLength":1},"ledgerApiUser":{"type":"string","description":"Subject of the Validator client","minLength":1},"audience":{"type":"string","description":"Audience claim expected by the clients\n","minLength":1},"oidcAuthorityUrl":{"type":"string"},"oidcConfigUrl":{"type":"string"},"jwksUrl":{"type":"string"}},"required":["audience","cnsClientId","ledgerApiClientId","ledgerApiClientSecret","ledgerApiUser","walletClientId","walletUser"]}}}}
```

## The ValidatorDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorDto":{"type":"object","description":"Splice validator definition: cluster and participant configuration, container image, auth and database settings used to provision a new validator deployment and convert it to the underlying CRD.","properties":{"auth":{"$ref":"#/components/schemas/ValidatorAuthDto"},"clusterConfig":{"$ref":"#/components/schemas/ClusterConfigDto"},"clusterParticipantConfig":{"$ref":"#/components/schemas/ClusterParticipantConfigDto"},"customAuth":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"imageRepo":{"type":"string","minLength":1},"imageTag":{"type":"string","minLength":1},"name":{"type":"string","maxLength":33,"minLength":1},"onboardingSecret":{"type":"string"},"participant":{"$ref":"#/components/schemas/AppInfoDto"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"}},"required":["clusterConfig","clusterParticipantConfig","imageRepo","imageTag","name","participant"]},"ValidatorAuthDto":{"type":"object","description":"Auth configuration for a Splice validator: per-application OIDC client ids / secrets and the OAuth2 issuer / audience to use.","properties":{"cnsClientId":{"type":"string","description":"Client for the Canton Name Service","minLength":1},"walletClientId":{"type":"string","description":"Client for Wallet application","minLength":1},"ledgerApiClientId":{"type":"string","description":"Client for Validator","minLength":1},"ledgerApiClientSecret":{"type":"string","description":"Secret part of Client Credentials Grant Flow for the Validator client","minLength":1},"walletUser":{"type":"string","description":"User that will access the wallet application and receive rewards","minLength":1},"ledgerApiUser":{"type":"string","description":"Subject of the Validator client","minLength":1},"audience":{"type":"string","description":"Audience claim expected by the clients\n","minLength":1},"oidcAuthorityUrl":{"type":"string"},"oidcConfigUrl":{"type":"string"},"jwksUrl":{"type":"string"}},"required":["audience","cnsClientId","ledgerApiClientId","ledgerApiClientSecret","ledgerApiUser","walletClientId","walletUser"]},"ClusterConfigDto":{"type":"object","description":"Cluster-wide Splice / Canton configuration for a validator: shared DARs, application metadata for validator / wallet / CNS, decentralized synchronizer URL, dev-net flags and JVM options.","properties":{"additionalConfigOther":{"type":"string"},"additionalUsersEnvVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"appDars":{"type":"string"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"contactPoint":{"type":"string"},"decentralizedSynchronizerUrl":{"type":"string"},"defaultJvmOptions":{"type":"string","minLength":1},"devNet":{"type":"boolean"},"disabledWallet":{"type":"boolean"},"extraDomains":{"type":"array","items":{"$ref":"#/components/schemas/ExtraDomainDto"}},"failOnAppVersionMismatch":{"type":"boolean"},"fixedTokens":{"type":"boolean"},"metrics":{"$ref":"#/components/schemas/MetricsDto"},"migrateValidatorParty":{"type":"boolean"},"migration":{"$ref":"#/components/schemas/MigrationDto"},"participantIdentitiesDumpBackup":{"$ref":"#/components/schemas/IdentitiesDumpPeriodicBackupDto"},"participantIdentitiesDumpImport":{"$ref":"#/components/schemas/ParticipantIdentitiesImportDto"},"partyHint":{"type":"string","minLength":1},"pvcVolumeStorageClass":{"type":"string"},"scanAddress":{"type":"string","minLength":1},"svSponsorAddress":{"type":"string","minLength":1},"svValidator":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"useSequencerConnectionsFromScan":{"type":"boolean"},"walletUserName":{"type":"string"},"scheduledPrune":{"$ref":"#/components/schemas/ScheduledValidatorPruneDto"},"disableProbes":{"type":"boolean"}},"required":["appInfoCantonNameService","appInfoValidator","defaultJvmOptions","migration","partyHint","scanAddress","svSponsorAddress"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"ExtraDomainDto":{"type":"object","properties":{"alias":{"type":"string"},"url":{"type":"string"}}},"MetricsDto":{"type":"object","properties":{"enable":{"type":"boolean"},"interval":{"type":"string"},"release":{"type":"string"}}},"MigrationDto":{"type":"object","properties":{"id":{"type":"integer","format":"int32","minimum":0},"migrating":{"type":"boolean"}},"required":["id"]},"IdentitiesDumpPeriodicBackupDto":{"type":"object","properties":{"backupInterval":{"type":"string","minLength":1},"locationBucketName":{"type":"string","minLength":1},"locationBucketProjectId":{"type":"string","minLength":1},"locationBucketSecretName":{"type":"string","minLength":1},"locationPrefix":{"type":"string"}},"required":["backupInterval","locationBucketName","locationBucketProjectId","locationBucketSecretName","locationPrefix"]},"ParticipantIdentitiesImportDto":{"type":"object","properties":{"identitiesSecretName":{"type":"string","description":"The name of the secret participant identities backup file dump.","minLength":1},"newParticipantIdentifier":{"type":"string","minLength":1}},"required":["identitiesSecretName","newParticipantIdentifier"]},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ScheduledValidatorPruneDto":{"type":"object","properties":{"cron":{"type":"string"},"maxDuration":{"type":"string"},"retention":{"type":"string"},"nextRun":{"type":"string"}},"required":["cron","maxDuration","retention"]},"ClusterParticipantConfigDto":{"type":"object","description":"Participant-side cluster configuration: JVM options, KMS settings, exposure of the ledger / JSON API and node identifier.","properties":{"defaultJvmOptions":{"type":"string","deprecated":true},"enableHealthProbes":{"type":"boolean","deprecated":true},"nodeIdentifier":{"type":"string"},"exposeLedgerApi":{"type":"boolean"},"privateJsonApi":{"type":"boolean"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}}},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}}}}}
```

## The CreatedUserDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"CreatedUserDto":{"type":"object","properties":{"id":{"type":"string"},"temporaryPassword":{"type":"string"},"username":{"type":"string"}}}}}}
```

## The ValidatorResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorResponseDto":{"type":"object","description":"Full validator details returned by GET / list endpoints: cluster and participant configuration, app info for validator / wallet / CNS, contact point and optional Keycloak credentials created on first provisioning.","properties":{"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"application":{"type":"string"},"applicationCantonNameServer":{"type":"string"},"applicationWallet":{"type":"string"},"contactPoint":{"type":"string"},"createdUser":{"$ref":"#/components/schemas/CreatedUserDto"},"customAuth":{"type":"boolean"},"databaseStorage":{"type":"string"},"disabledWallet":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"exposeLedgerApi":{"type":"boolean"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"immutable":{"type":"boolean"},"jsonApiAddress":{"type":"string"},"ledgerApiAddress":{"type":"string"},"validatorApiAddress":{"type":"string"},"migrationId":{"type":"string"},"migrationMigrating":{"type":"boolean"},"name":{"type":"string"},"onboardingSecretName":{"type":"string"},"participant":{"type":"string"},"participantIdentitiesDumpSecretName":{"type":"string"},"participantInfo":{"$ref":"#/components/schemas/AppInfoDto"},"partyId":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"privateJsonApi":{"type":"boolean"},"scanAddress":{"type":"string"},"storageSize":{"type":"string"},"disableProbes":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"CreatedUserDto":{"type":"object","properties":{"id":{"type":"string"},"temporaryPassword":{"type":"string"},"username":{"type":"string"}}},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}}}
```

## The ValidatorRestoreDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorRestoreDto":{"type":"object","description":"Request body to start a Splice validator restore from one or more previously captured backup files.","properties":{"filenames":{"type":"array","items":{"type":"string"},"maxItems":2,"minItems":2}}}}}}
```

## The ValidatorRestoreResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorRestoreResponseDto":{"type":"object","description":"Single entry in the validator restore history: filenames restored from, overall status and capture timestamp.","properties":{"filenames":{"type":"array","items":{"type":"string"},"maxItems":2,"minItems":2},"status":{"type":"string"},"timestamp":{"type":"string"}}}}}}
```

## The CheckQuorumRequest object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"CheckQuorumRequest":{"type":"object","description":"Request body for the Splice prefill quorum check; references the sponsor scan address used during validator on-boarding.","properties":{"sponsorScanAddress":{"type":"string"}}}}}}
```

## The ScheduledPruneDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ScheduledPruneDto":{"type":"object","description":"Persisted pruning schedule for a Canton workload: cron expression, retention window, max duration and next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxDurationInSec":{"type":"integer","format":"int64","minimum":1},"nextRun":{"type":"string"},"retentionInSec":{"type":"integer","format":"int64","minimum":1}},"required":["cron","maxDurationInSec","retentionInSec"]}}}}
```

## The ConnectionDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ConnectionDto":{"type":"object","description":"The DTO representing a connection to a domain.","properties":{"connected":{"type":"boolean","description":"It represents the connection status. It is true when the connection is established, false otherwise."},"custom":{"type":"boolean","description":"It represents a custom domain.  When it is true the domainUrl should be used, use domainName and port otherwise "},"domainAlias":{"type":"string","description":"This is the alias of the domain to connect to. It does not have to be the same as the actual domain name.","minLength":1},"domainName":{"type":"string","description":"This is name of the domain to connect to. "},"isHADomain":{"type":"boolean","description":"Defines whether the domain name belongs to the HA Domain entity"},"domainUrl":{"type":"string","description":"This is the URL of the domain to connect to. It must be accessible from the participant node. Usage: https://<domain-name>.<namespace>.svc.cluster.local:<public-port>"},"publicPort":{"type":"string","description":"This is public port of the domain to connect to. "}},"required":["domainAlias"]}}}}
```

## The RestoreDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"RestoreDto":{"type":"object","description":"Request body to start a participant or domain restore from a previously captured backup file.","properties":{"fileName":{"type":"string","minLength":1}},"required":["fileName"]}}}}
```

## The LocalPartyListingDTO object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"LocalPartyListingDTO":{"type":"object","description":"Local-party listing for a participant: the in-progress fetch flag and the currently-known list of party identifiers.","properties":{"fetching":{"type":"boolean"},"parties":{"type":"array","items":{"type":"string"}}}}}}}
```

## The BackupDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"BackupDto":{"type":"object","description":"Schedule definition used to configure a recurring backup job on a Canton workload (participant or domain). Carries the cron expression that drives the schedule and the maximum number of backups to retain.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32","minimum":1}},"required":["cron","maxBackups"]}}}}
```

## The ScheduledBackupDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ScheduledBackupDto":{"type":"object","description":"Persisted backup schedule for a Canton workload: cron expression, retention limit and the resolved next-run timestamp.","properties":{"cron":{"type":"string","minLength":1},"maxBackups":{"type":"integer","format":"int32"},"nextRun":{"type":"string"}},"required":["cron"]}}}}
```

## The IdDumpDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"IdDumpDto":{"type":"object","description":"Identity-dump artifact metadata: name of the Kubernetes secret holding the dump, the owning validator name and the timestamp at which it was captured.","properties":{"secretName":{"type":"string"},"validatorName":{"type":"string"},"timestamp":{"type":"integer","format":"int64"},"createdAt":{"type":"string"}}}}}}
```

## The ProxyRequestDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ProxyRequestDto":{"type":"object","description":"Generic HTTP proxy request: target URL, method, custom headers and body forwarded by the proxy controller.","properties":{"url":{"type":"string"},"method":{"type":"string"},"headers":{"type":"object","additionalProperties":{"type":"string"}},"body":{"type":"string"}}}}}}
```

## The PasswordDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"PasswordDto":{"type":"object","description":"Wrapper around a single password value; used by endpoints that update credentials in isolation.","properties":{"password":{"type":"string","minLength":1}},"required":["password"]}}}}
```

## The OauthLoginResponse object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"OauthLoginResponse":{"type":"object","description":"Token response returned by the OAuth2 login flow (access token).","properties":{"access_token":{"type":"string"}}}}}}
```

## The CommandDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"CommandDto":{"type":"object","description":"Canton console script to be executed as a one-shot command against a participant or domain.","properties":{"script":{"type":"string","minLength":1}},"required":["script"]}}}}
```

## The ValidatorFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorFilterResponseDto":{"type":"object","description":"Paginated list of `ValidatorResponseDto` entries plus the total count of validators matching the filter.","properties":{"validators":{"type":"array","items":{"$ref":"#/components/schemas/ValidatorResponseDto"}},"totalCount":{"type":"integer","format":"int64"}}},"ValidatorResponseDto":{"type":"object","description":"Full validator details returned by GET / list endpoints: cluster and participant configuration, app info for validator / wallet / CNS, contact point and optional Keycloak credentials created on first provisioning.","properties":{"appInfoCantonNameService":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoValidator":{"$ref":"#/components/schemas/AppInfoDto"},"appInfoWallet":{"$ref":"#/components/schemas/AppInfoDto"},"application":{"type":"string"},"applicationCantonNameServer":{"type":"string"},"applicationWallet":{"type":"string"},"contactPoint":{"type":"string"},"createdUser":{"$ref":"#/components/schemas/CreatedUserDto"},"customAuth":{"type":"boolean"},"databaseStorage":{"type":"string"},"disabledWallet":{"type":"boolean"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"exposeLedgerApi":{"type":"boolean"},"imageRepo":{"type":"string"},"imageTag":{"type":"string"},"immutable":{"type":"boolean"},"jsonApiAddress":{"type":"string"},"ledgerApiAddress":{"type":"string"},"validatorApiAddress":{"type":"string"},"migrationId":{"type":"string"},"migrationMigrating":{"type":"boolean"},"name":{"type":"string"},"onboardingSecretName":{"type":"string"},"participant":{"type":"string"},"participantIdentitiesDumpSecretName":{"type":"string"},"participantInfo":{"$ref":"#/components/schemas/AppInfoDto"},"partyId":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"postgresPassword":{"type":"string","deprecated":true},"postgresUser":{"type":"string","deprecated":true},"privateJsonApi":{"type":"boolean"},"scanAddress":{"type":"string"},"storageSize":{"type":"string"},"disableProbes":{"type":"boolean"},"topUp":{"$ref":"#/components/schemas/TopUpDto"},"databaseConfig":{"$ref":"#/components/schemas/ValidatorDbConfigDto"},"postgresConfig":{"$ref":"#/components/schemas/PostgresConfigDto"},"walletSweeps":{"type":"array","items":{"$ref":"#/components/schemas/WalletSweepDto"}}}},"AppInfoDto":{"type":"object","description":"Application deployment metadata: container environment variables and resource requirements declared for an individual Canton/Splice application component.","properties":{"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["envVars"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"CreatedUserDto":{"type":"object","properties":{"id":{"type":"string"},"temporaryPassword":{"type":"string"},"username":{"type":"string"}}},"TopUpDto":{"type":"object","properties":{"enable":{"type":"boolean"},"minTopupInterval":{"type":"string"},"targetThroughput":{"type":"integer","format":"int32"}}},"ValidatorDbConfigDto":{"type":"object","description":"Database configuration for a Splice validator: whether an external Postgres is used and, if so, its connection credentials.","properties":{"external":{"type":"boolean"},"username":{"type":"string"},"password":{"type":"string"},"hostname":{"type":"string"},"port":{"type":"string"}}},"PostgresConfigDto":{"type":"object","description":"Postgres deployment configuration consumed by a participant or domain: container image, JVM args, resources and any extra volumes / volume mounts.","properties":{"args":{"type":"array","items":{"type":"string"}},"image":{"type":"string"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"volumes":{"type":"array","items":{"$ref":"#/components/schemas/Volume"}},"volumeMounts":{"type":"array","items":{"$ref":"#/components/schemas/VolumeMount"}}}},"Volume":{"type":"object","properties":{"name":{"type":"string"},"emptyDir":{"$ref":"#/components/schemas/EmptyDirVolumeSource"},"configMap":{"$ref":"#/components/schemas/ConfigMapVolumeSource"},"persistentVolumeClaim":{"$ref":"#/components/schemas/PersistentVolumeClaimVolumeSource"},"secret":{"$ref":"#/components/schemas/SecretVolumeSource"},"hostPath":{"$ref":"#/components/schemas/HostPathVolumeSource"}}},"EmptyDirVolumeSource":{"type":"object","properties":{"medium":{"type":"string"},"sizeLimit":{"$ref":"#/components/schemas/Quantity"}}},"Quantity":{"type":"object","properties":{"amount":{"type":"string"},"format":{"type":"string"}}},"ConfigMapVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"name":{"type":"string"},"optional":{"type":"boolean"}}},"KeyToPath":{"type":"object","properties":{"key":{"type":"string"},"mode":{"type":"integer","format":"int32"},"path":{"type":"string"}}},"PersistentVolumeClaimVolumeSource":{"type":"object","properties":{"claimName":{"type":"string"},"readOnly":{"type":"boolean"}}},"SecretVolumeSource":{"type":"object","properties":{"defaultMode":{"type":"integer","format":"int32"},"items":{"type":"array","items":{"$ref":"#/components/schemas/KeyToPath"}},"optional":{"type":"boolean"},"secretName":{"type":"string"}}},"HostPathVolumeSource":{"type":"object","properties":{"path":{"type":"string"},"type":{"type":"string"}}},"VolumeMount":{"type":"object","properties":{"name":{"type":"string"},"path":{"type":"string"},"subPath":{"type":"string"},"readOnly":{"type":"boolean"}}},"WalletSweepDto":{"type":"object","properties":{"senderPartyId":{"type":"string","minLength":1},"receiverPartyId":{"type":"string","minLength":1},"maxBalanceUSD":{"type":"string","minLength":1},"minBalanceUSD":{"type":"string","minLength":1},"useTransferPreapproval":{"type":"boolean"}},"required":["maxBalanceUSD","minBalanceUSD","receiverPartyId","senderPartyId","useTransferPreapproval"]}}}}
```

## The FilePropertiesDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"FilePropertiesDto":{"type":"object","description":"File metadata: filename, size and timestamp (split into separate date and time fields).","properties":{"date":{"type":"string"},"filename":{"type":"string"},"size":{"type":"integer","format":"int32"},"time":{"type":"string"}}}}}}
```

## The ValidatorBackupHistoryDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorBackupHistoryDto":{"type":"object","description":"Validator backup history: ordered list of previously captured backups with their files and statuses.","properties":{"backupList":{"type":"array","items":{"$ref":"#/components/schemas/ValidatorBackupPropertiesDto"}}}},"ValidatorBackupPropertiesDto":{"type":"object","description":"Single validator backup entry: list of captured backup files, overall status and capture timestamp.","properties":{"files":{"type":"array","items":{"$ref":"#/components/schemas/FilePropertiesDto"}},"status":{"type":"string"},"timestamp":{"type":"string"}}},"FilePropertiesDto":{"type":"object","description":"File metadata: filename, size and timestamp (split into separate date and time fields).","properties":{"date":{"type":"string"},"filename":{"type":"string"},"size":{"type":"integer","format":"int32"},"time":{"type":"string"}}}}}}
```

## The ValidatorBackupPropertiesDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ValidatorBackupPropertiesDto":{"type":"object","description":"Single validator backup entry: list of captured backup files, overall status and capture timestamp.","properties":{"files":{"type":"array","items":{"$ref":"#/components/schemas/FilePropertiesDto"}},"status":{"type":"string"},"timestamp":{"type":"string"}}},"FilePropertiesDto":{"type":"object","description":"File metadata: filename, size and timestamp (split into separate date and time fields).","properties":{"date":{"type":"string"},"filename":{"type":"string"},"size":{"type":"integer","format":"int32"},"time":{"type":"string"}}}}}}
```

## The NetworkInfoDetails object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"NetworkInfoDetails":{"type":"object","properties":{"version":{"type":"string"},"migrationId":{"type":"integer","format":"int32"},"svDetailsList":{"type":"array","items":{"$ref":"#/components/schemas/SVDetails"}}}},"SVDetails":{"type":"object","properties":{"name":{"type":"string"},"sponsorAddress":{"type":"string"},"scanAddress":{"type":"string"}}}}}}
```

## The NetworkInfoDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"NetworkInfoDto":{"type":"object","description":"Splice network endpoints split by environment: devnet, testnet and mainnet.","properties":{"devnet":{"$ref":"#/components/schemas/NetworkInfoDetails"},"testnet":{"$ref":"#/components/schemas/NetworkInfoDetails"},"mainnet":{"$ref":"#/components/schemas/NetworkInfoDetails"}}},"NetworkInfoDetails":{"type":"object","properties":{"version":{"type":"string"},"migrationId":{"type":"integer","format":"int32"},"svDetailsList":{"type":"array","items":{"$ref":"#/components/schemas/SVDetails"}}}},"SVDetails":{"type":"object","properties":{"name":{"type":"string"},"sponsorAddress":{"type":"string"},"scanAddress":{"type":"string"}}}}}}
```

## The SVDetails object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SVDetails":{"type":"object","properties":{"name":{"type":"string"},"sponsorAddress":{"type":"string"},"scanAddress":{"type":"string"}}}}}}
```

## The RemoteParticipantFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"RemoteParticipantFilterResponseDto":{"type":"object","description":"Paginated list of `RemoteParticipantDto` entries plus the total count.","properties":{"participants":{"type":"array","items":{"$ref":"#/components/schemas/RemoteParticipantDto"}},"totalCount":{"type":"integer","format":"int64"}}},"RemoteParticipantDto":{"type":"object","description":"Externally-hosted Canton participant registered in CBM: admin / ledger / JSON-API endpoints, auth provider and identifying metadata.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonApiUrl":{"type":"string","minLength":1},"ledgerAddress":{"type":"string","minLength":1},"ledgerId":{"type":"string","minLength":1},"ledgerPort":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"v3":{"type":"boolean"}},"required":["adminAddress","adminPort","authProvider","image","jsonApiUrl","ledgerAddress","ledgerId","ledgerPort","name"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The ParticipantStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ParticipantStatusDto":{"type":"object","description":"Runtime status of a Canton participant: active flag, id, uptime and the lists of currently connected and unhealthy sync domains.","properties":{"active":{"type":"boolean"},"connectedDomains":{"type":"array","items":{"type":"string"}},"id":{"type":"string"},"unhealthyDomains":{"type":"array","items":{"type":"string"}},"uptime":{"type":"integer","format":"int64"}}}}}}
```

## The DarDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DarDto":{"type":"object","description":"Reference to a DAR package uploaded to a Canton participant: identifying hash, package name and version.","properties":{"hash":{"type":"string"},"name":{"type":"string"},"version":{"type":"string"}}}}}}
```

## The RemoteDomainFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"RemoteDomainFilterResponseDto":{"type":"object","description":"Paginated list of `RemoteDomainDto` entries plus the total count.","properties":{"domains":{"type":"array","items":{"$ref":"#/components/schemas/RemoteDomainDto"}},"totalCount":{"type":"integer","format":"int64"}}},"RemoteDomainDto":{"type":"object","description":"Externally-hosted sync domain registered in CBM: admin / public endpoints, image metadata and lifecycle phase.","properties":{"adminAddress":{"type":"string","minLength":1},"adminPort":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string","minLength":1},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"}},"required":["adminAddress","adminPort","image","name","publicAddress","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```

## The DomainStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainStatusDto":{"type":"object","description":"Runtime status of a single-replica sync domain: active flag, id, uptime, sequencer state and the list of currently connected participants.","properties":{"active":{"type":"boolean"},"connectedParticipants":{"type":"array","items":{"type":"string"}},"id":{"type":"string"},"sequencer":{"$ref":"#/components/schemas/SequencerDto"},"uptime":{"type":"integer","format":"int64"}}},"SequencerDto":{"type":"object","description":"Compact status of a Canton sequencer: active flag and free-form details string.","properties":{"active":{"type":"boolean"},"details":{"type":"string"}}}}}}
```

## The SequencerDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SequencerDto":{"type":"object","description":"Compact status of a Canton sequencer: active flag and free-form details string.","properties":{"active":{"type":"boolean"},"details":{"type":"string"}}}}}}
```

## The ParticipantFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ParticipantFilterResponseDto":{"type":"object","description":"Paginated list of `ParticipantDto` entries plus the total count of participants matching the filter.","properties":{"participants":{"type":"array","items":{"$ref":"#/components/schemas/ParticipantDto"}},"totalCount":{"type":"integer","format":"int64"}}},"ParticipantDto":{"type":"object","description":"Canton participant definition: container image, admin / ledger endpoints, authentication, postgres storage and Canton-specific settings used to provision a new participant deployment.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"auth":{"type":"boolean"},"authProvider":{"type":"string","enum":["keycloak","auth0","custom"]},"authorization":{"$ref":"#/components/schemas/AuthorizationDto"},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"jsonapi":{"type":"boolean"},"jsonapiImage":{"type":"string"},"privateJsonapi":{"type":"boolean"},"jsonapiQueryStore":{"type":"boolean"},"exposeLedgerApi":{"type":"boolean"},"ledgerAddress":{"type":"string"},"ledgerPort":{"type":"string","minLength":1},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"navigator":{"type":"boolean"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"},"validatorParent":{"type":"string"},"enableKms":{"type":"boolean"},"kmsValue":{"type":"string"},"kmsServiceAccount":{"type":"string"}},"required":["adminPort","authProvider","image","ledgerPort","name"]},"AuthorizationDto":{"type":"object","description":"Credential and OIDC client descriptor used to obtain tokens for a Canton participant: client id / secret, username / password and JWKS URL.","properties":{"clientId":{"type":"string"},"clientSecret":{"type":"string"},"jwksUrl":{"type":"string"},"password":{"type":"string"},"username":{"type":"string"},"audience":{"type":"string"}}},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}}}
```

## The BackupHistoryDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"BackupHistoryDto":{"type":"object","description":"Entry in the backup history of a Canton workload describing a single backup artifact: file name, size in bytes, status of the backup operation and the timestamp at which it was produced.","properties":{"filename":{"type":"string"},"size":{"type":"integer","format":"int32","description":"File size in bytes"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}}}
```

## The RestoreHistoryDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"RestoreHistoryDto":{"type":"object","description":"Single entry in a restore history: filename, status, timestamp and any log captured during the restore.","properties":{"filename":{"type":"string"},"log":{"type":"string"},"status":{"type":"string"},"timestamp":{"type":"string"}}}}}}
```

## The ClusterInformationDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ClusterInformationDto":{"type":"object","description":"Connection metadata describing the Canton / Splice cluster CBM is attached to (URL of the cluster control plane).","properties":{"url":{"type":"string"}}}}}}
```

## The LogLineDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"LogLineDto":{"type":"object","description":"Single Canton-formatted log line: parsed timestamp, log level and message content.","properties":{"content":{"type":"string"},"level":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"timeStamp":{"type":"string"}}}}}}
```

## The StreamingResponseBody object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"StreamingResponseBody":{}}}}
```

## The FileDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"FileDto":{"type":"object","description":"File DTO","properties":{"name":{"type":"string","description":"Name of the file"},"sizeInBytes":{"type":"integer","format":"int64","description":"Size of the file in bytes"}}}}}}
```

## The FileFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"FileFilterResponseDto":{"type":"object","description":"Paginated list of `FileDto` entries plus the total count of stored files matching the filter.","properties":{"files":{"type":"array","items":{"$ref":"#/components/schemas/FileDto"}},"totalCount":{"type":"integer","format":"int64"}}},"FileDto":{"type":"object","description":"File DTO","properties":{"name":{"type":"string","description":"Name of the file"},"sizeInBytes":{"type":"integer","format":"int64","description":"Size of the file in bytes"}}}}}}
```

## The DomainFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainFilterResponseDto":{"type":"object","description":"Paginated list of `DomainDto` entries plus the total count of sync domains matching the filter.","properties":{"domains":{"type":"array","items":{"$ref":"#/components/schemas/DomainDto"}},"totalCount":{"type":"integer","format":"int64"}}},"DomainDto":{"type":"object","description":"Canton sync domain definition: name, container image, log level, admin / public endpoints and Canton-specific bootstrap settings used to provision a single-replica sync domain.","properties":{"adminAddress":{"type":"string"},"adminPort":{"type":"string","minLength":1},"bootstrap":{"type":"string"},"daemon":{"type":"boolean"},"enterprise":{"type":"boolean","description":"Whether the canton image is enterprise or not"},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string","minLength":1},"ingress":{"type":"boolean"},"logLevel":{"type":"string","enum":["TRACE","DEBUG","INFO","WARN","ERROR"]},"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"publicAddress":{"type":"string"},"publicPort":{"type":"string","minLength":1},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"storage":{"$ref":"#/components/schemas/StorageDto"},"topology":{"type":"string"}},"required":["adminPort","image","name","publicPort"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}},"StorageDto":{"type":"object","description":"Persistent storage configuration: type (in-cluster or external Postgres), size, backup size and connection credentials when external.","properties":{"backupSize":{"type":"string"},"hostname":{"type":"string"},"password":{"type":"string"},"port":{"type":"string"},"size":{"type":"string"},"type":{"type":"string","enum":["Memory","Postgres","Shared Postgres","External"]},"user":{"type":"string"}}}}}}
```

## The BootstrapStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"BootstrapStatusDto":{"type":"object","properties":{"started":{"type":"boolean"},"completed":{"type":"boolean"},"error":{"type":"string"},"ready":{"type":"boolean"}}}}}}
```

## The DomainHAEntry object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainHAEntry":{"type":"object","properties":{"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"status":{"$ref":"#/components/schemas/DomainHAStatusDto"}},"required":["name","status"]},"DomainHAStatusDto":{"type":"object","description":"Runtime status of an HA sync domain split per component (mediator, topology manager, sequencer, in-cluster database, bootstrap).","properties":{"mediator":{"$ref":"#/components/schemas/MediatorStatusDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerStatusDto"},"sequencer":{"$ref":"#/components/schemas/SequencerStatusDto"},"inClusterDatabase":{"$ref":"#/components/schemas/InClusterDatabaseStatusDto"},"bootstrap":{"$ref":"#/components/schemas/BootstrapStatusDto"}}},"MediatorStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"TopologyManagerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"SequencerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"InClusterDatabaseStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"BootstrapStatusDto":{"type":"object","properties":{"started":{"type":"boolean"},"completed":{"type":"boolean"},"error":{"type":"string"},"ready":{"type":"boolean"}}}}}}
```

## The DomainHAResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainHAResponseDto":{"type":"object","description":"Paginated list of HA sync domain entries plus the total count.","properties":{"domainHAs":{"type":"array","items":{"$ref":"#/components/schemas/DomainHAEntry"}},"totalCount":{"type":"integer","format":"int64"}}},"DomainHAEntry":{"type":"object","properties":{"name":{"type":"string","minLength":1},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"status":{"$ref":"#/components/schemas/DomainHAStatusDto"}},"required":["name","status"]},"DomainHAStatusDto":{"type":"object","description":"Runtime status of an HA sync domain split per component (mediator, topology manager, sequencer, in-cluster database, bootstrap).","properties":{"mediator":{"$ref":"#/components/schemas/MediatorStatusDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerStatusDto"},"sequencer":{"$ref":"#/components/schemas/SequencerStatusDto"},"inClusterDatabase":{"$ref":"#/components/schemas/InClusterDatabaseStatusDto"},"bootstrap":{"$ref":"#/components/schemas/BootstrapStatusDto"}}},"MediatorStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"TopologyManagerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"SequencerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"InClusterDatabaseStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"BootstrapStatusDto":{"type":"object","properties":{"started":{"type":"boolean"},"completed":{"type":"boolean"},"error":{"type":"string"},"ready":{"type":"boolean"}}}}}}
```

## The DomainHAStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"DomainHAStatusDto":{"type":"object","description":"Runtime status of an HA sync domain split per component (mediator, topology manager, sequencer, in-cluster database, bootstrap).","properties":{"mediator":{"$ref":"#/components/schemas/MediatorStatusDto"},"topologyManager":{"$ref":"#/components/schemas/TopologyManagerStatusDto"},"sequencer":{"$ref":"#/components/schemas/SequencerStatusDto"},"inClusterDatabase":{"$ref":"#/components/schemas/InClusterDatabaseStatusDto"},"bootstrap":{"$ref":"#/components/schemas/BootstrapStatusDto"}}},"MediatorStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"TopologyManagerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"SequencerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"InClusterDatabaseStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}},"BootstrapStatusDto":{"type":"object","properties":{"started":{"type":"boolean"},"completed":{"type":"boolean"},"error":{"type":"string"},"ready":{"type":"boolean"}}}}}}
```

## The InClusterDatabaseStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"InClusterDatabaseStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}}}}}
```

## The MediatorStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"MediatorStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}}}}}
```

## The SequencerStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"SequencerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}}}}}
```

## The TopologyManagerStatusDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"TopologyManagerStatusDto":{"type":"object","properties":{"ready":{"type":"boolean"}}}}}}
```

## The ApplicationFilterResponseDto object

```json
{"openapi":"3.1.0","info":{"title":"Catalyst Blockchain Manager: Canton Console API","version":"1.0.0-local"},"components":{"schemas":{"ApplicationFilterResponseDto":{"type":"object","description":"Paginated list of `ApplicationDto` entries plus the total count of applications matching the filter.","properties":{"applications":{"type":"array","items":{"$ref":"#/components/schemas/ApplicationDto"}},"totalCount":{"type":"integer","format":"int64"}}},"ApplicationDto":{"type":"object","description":"Generic CBM-deployed application: name, container image, port, package, parent validator and Kubernetes resource requirements; used both as a request and a response body on the applications endpoints.","properties":{"domain":{"type":"string","minLength":1},"envVars":{"type":"array","items":{"$ref":"#/components/schemas/EnvVar"}},"image":{"type":"string"},"name":{"type":"string","minLength":1},"packageName":{"type":"string"},"phase":{"type":"string","enum":["COMPLETED","PENDING","RUNNING"]},"port":{"type":"integer","format":"int32"},"resources":{"$ref":"#/components/schemas/ResourcesDto"},"type":{"type":"string","enum":["BACKEND","UI"]},"validatorParent":{"type":"string"}},"required":["domain","name","type"]},"EnvVar":{"type":"object","properties":{"name":{"type":"string"},"value":{"type":"string"},"valueFrom":{"$ref":"#/components/schemas/EnvVarSource"}}},"EnvVarSource":{"type":"object","properties":{"secretKeyRef":{"$ref":"#/components/schemas/SecretKeySelector"}}},"SecretKeySelector":{"type":"object","properties":{"key":{"type":"string"},"name":{"type":"string"},"optional":{"type":"boolean"}}},"ResourcesDto":{"type":"object","description":"Container/Pod related fields.","properties":{"cpuLimit":{"type":"string","description":"The maximum amount of CPU allowed for a container. The value is a string with a suffix of milliCPU, e.g. 500m. The value can also be given in CPU units, e.g. 0.5. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-cpu"},"cpuRequested":{"type":"string","description":"The requested amount of CPU for a container. See cpuLimit for details."},"imagePullSecret":{"type":"string","description":"The name of the image pull secret to use for the container. The secret must be present in the same namespace as the pod."},"memoryLimit":{"type":"string","description":"The maximum amount of memory allowed for a container. The value is a string with a quantity suffix, e.g. 123Mi. The value can also be given in bytes, e.g. 128974848. See: https://kubernetes.io/docs/concepts/configuration/manage-resources-containers/#meaning-of-memory"},"memoryRequested":{"type":"string","description":"The requested amount of memory for a container. See memoryLimit for details."},"replicas":{"type":"integer","format":"int32","description":"The requested replicas for a container."}}}}}}
```


# Open Source Licenses

In this page we list all the software/components/libraries and their licenses used for CatalyX Blockchain Manager v1.11

## API

| Package                                                                                                                                                                               | Version                                   | License(s)                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| [ch.qos.logback:logback-classic](https://mvnrepository.com/artifact/ch.qos.logback/logback-classic)                                                                                   | 1.5.32                                    | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html)                                                                                                                                                                                                        |
| [ch.qos.logback:logback-core](https://mvnrepository.com/artifact/ch.qos.logback/logback-core)                                                                                         | 1.5.32                                    | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [LGPL-2.1](https://www.gnu.org/licenses/old-licenses/lgpl-2.1.html)                                                                                                                                                                                                        |
| [com.auth0:auth0](https://mvnrepository.com/artifact/com.auth0/auth0)                                                                                                                 | 2.10.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [com.auth0:java-jwt](https://mvnrepository.com/artifact/com.auth0/java-jwt)                                                                                                           | 4.4.0                                     | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [com.cronutils:cron-utils](https://mvnrepository.com/artifact/com.cronutils/cron-utils)                                                                                               | 9.2.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.daml:bindings-java](https://mvnrepository.com/artifact/com.daml/bindings-java)                                                                                                   | 3.2.0-adhoc.20241030.13394.0.v3e6a4a6c    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml:classmate](https://mvnrepository.com/artifact/com.fasterxml/classmate)                                                                                                 | 1.7.3                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson:jackson-bom](https://mvnrepository.com/artifact/com.fasterxml.jackson/jackson-bom)                                                                             | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-annotations)                                                   | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-core](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-core)                                                                 | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-databind](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind)                                                         | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://mvnrepository.com/artifact/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml)                               | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jdk8](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jdk8)                                       | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jsr310](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jsr310)                                   | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-base](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base)                               | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-json-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider)             | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-yaml-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-yaml-provider)             | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations) | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-parameter-names](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-parameter-names)                         | 2.18.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.github.ben-manes.caffeine:caffeine](https://mvnrepository.com/artifact/com.github.ben-manes.caffeine/caffeine)                                                                   | 3.2.3                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.github.java-json-tools:json-patch](https://mvnrepository.com/artifact/com.github.java-json-tools/json-patch)                                                                     | 1.13                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [LGPL-3.0](https://www.gnu.org/licenses/lgpl-3.0.html)                                                                                                                                                                                                                                |
| [com.github.stephenc.jcip:jcip-annotations](https://mvnrepository.com/artifact/com.github.stephenc.jcip/jcip-annotations)                                                             | 1.0-1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.android:annotations](https://mvnrepository.com/artifact/com.google.android/annotations)                                                                                   | 4.1.1.4                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.api.grpc:proto-google-common-protos](https://mvnrepository.com/artifact/com.google.api.grpc/proto-google-common-protos)                                                   | 2.41.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.findbugs:jsr305](https://mvnrepository.com/artifact/com.google.code.findbugs/jsr305)                                                                                 | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.gson:gson](https://mvnrepository.com/artifact/com.google.code.gson/gson)                                                                                             | 2.13.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.errorprone:error\_prone\_annotations](https://mvnrepository.com/artifact/com.google.errorprone/error_prone_annotations)                                                   | 2.43.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:failureaccess](https://mvnrepository.com/artifact/com.google.guava/failureaccess)                                                                                   | 1.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:guava](https://mvnrepository.com/artifact/com.google.guava/guava)                                                                                                   | 33.3.0-jre                                | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:listenablefuture](https://mvnrepository.com/artifact/com.google.guava/listenablefuture)                                                                             | 9999.0-empty-to-avoid-conflict-with-guava | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.protobuf:protobuf-java](https://mvnrepository.com/artifact/com.google.protobuf/protobuf-java)                                                                             | 3.25.5                                    | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [com.google.protobuf:protobuf-javalite](https://mvnrepository.com/artifact/com.google.protobuf/protobuf-javalite)                                                                     | 3.25.5                                    | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [com.ibm.async:asyncutil](https://mvnrepository.com/artifact/com.ibm.async/asyncutil)                                                                                                 | 0.1.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.javax0.license3j:license3j](https://mvnrepository.com/artifact/com.javax0.license3j/license3j)                                                                                   | 3.2.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:content-type](https://mvnrepository.com/artifact/com.nimbusds/content-type)                                                                                             | 2.2                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:lang-tag](https://mvnrepository.com/artifact/com.nimbusds/lang-tag)                                                                                                     | 1.7                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:nimbus-jose-jwt](https://mvnrepository.com/artifact/com.nimbusds/nimbus-jose-jwt)                                                                                       | 9.37.4                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:oauth2-oidc-sdk](https://mvnrepository.com/artifact/com.nimbusds/oauth2-oidc-sdk)                                                                                       | 9.43.6                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okhttp3:logging-interceptor](https://mvnrepository.com/artifact/com.squareup.okhttp3/logging-interceptor)                                                               | 4.12.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okhttp3:okhttp](https://mvnrepository.com/artifact/com.squareup.okhttp3/okhttp)                                                                                         | 4.12.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio](https://mvnrepository.com/artifact/com.squareup.okio/okio)                                                                                                   | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio-jvm](https://mvnrepository.com/artifact/com.squareup.okio/okio-jvm)                                                                                           | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.sun.istack:istack-commons-runtime](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-runtime)                                                                     | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.istack:istack-commons-tools](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-tools)                                                                         | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:relaxng-datatype](https://mvnrepository.com/artifact/com.sun.xml.bind.external/relaxng-datatype)                                                           | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:rngom](https://mvnrepository.com/artifact/com.sun.xml.bind.external/rngom)                                                                                 | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.typesafe:config](https://mvnrepository.com/artifact/com.typesafe/config)                                                                                                         | 1.4.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-codec:commons-codec](https://mvnrepository.com/artifact/commons-codec/commons-codec)                                                                                         | 1.15                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-io:commons-io](https://mvnrepository.com/artifact/commons-io/commons-io)                                                                                                     | 2.14.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-logging:commons-logging](https://mvnrepository.com/artifact/commons-logging/commons-logging)                                                                                 | 1.2                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client)                                                                                       | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client-api](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client-api)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-httpclient-okhttp](https://mvnrepository.com/artifact/io.fabric8/kubernetes-httpclient-okhttp)                                                                 | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-admissionregistration](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-admissionregistration)                                             | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apiextensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apiextensions)                                                             | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apps](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apps)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-autoscaling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-autoscaling)                                                                 | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-batch](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-batch)                                                                             | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-certificates](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-certificates)                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-common](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-common)                                                                           | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-coordination](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-coordination)                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-core](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-core)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-discovery](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-discovery)                                                                     | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-events](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-events)                                                                           | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-extensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-extensions)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-flowcontrol](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-flowcontrol)                                                                 | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-gatewayapi](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-gatewayapi)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-metrics](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-metrics)                                                                         | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-networking](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-networking)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-node](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-node)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-policy](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-policy)                                                                           | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-rbac](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-rbac)                                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-resource](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-resource)                                                                       | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-scheduling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-scheduling)                                                                   | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-storageclass](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-storageclass)                                                               | 6.13.5                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:zjsonpatch](https://mvnrepository.com/artifact/io.fabric8/zjsonpatch)                                                                                                     | 0.3.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-api](https://mvnrepository.com/artifact/io.grpc/grpc-api)                                                                                                               | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-context](https://mvnrepository.com/artifact/io.grpc/grpc-context)                                                                                                       | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-core](https://mvnrepository.com/artifact/io.grpc/grpc-core)                                                                                                             | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-netty](https://mvnrepository.com/artifact/io.grpc/grpc-netty)                                                                                                           | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf)                                                                                                     | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf-lite](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf-lite)                                                                                           | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-stub](https://mvnrepository.com/artifact/io.grpc/grpc-stub)                                                                                                             | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-util](https://mvnrepository.com/artifact/io.grpc/grpc-util)                                                                                                             | 1.67.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-commons](https://mvnrepository.com/artifact/io.micrometer/micrometer-commons)                                                                               | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-core](https://mvnrepository.com/artifact/io.micrometer/micrometer-core)                                                                                     | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-jakarta9](https://mvnrepository.com/artifact/io.micrometer/micrometer-jakarta9)                                                                             | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-observation](https://mvnrepository.com/artifact/io.micrometer/micrometer-observation)                                                                       | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-all](https://mvnrepository.com/artifact/io.netty/netty-all)                                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-buffer](https://mvnrepository.com/artifact/io.netty/netty-buffer)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec](https://mvnrepository.com/artifact/io.netty/netty-codec)                                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-dns](https://mvnrepository.com/artifact/io.netty/netty-codec-dns)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-haproxy](https://mvnrepository.com/artifact/io.netty/netty-codec-haproxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http](https://mvnrepository.com/artifact/io.netty/netty-codec-http)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http2](https://mvnrepository.com/artifact/io.netty/netty-codec-http2)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-memcache](https://mvnrepository.com/artifact/io.netty/netty-codec-memcache)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-mqtt](https://mvnrepository.com/artifact/io.netty/netty-codec-mqtt)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-redis](https://mvnrepository.com/artifact/io.netty/netty-codec-redis)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-smtp](https://mvnrepository.com/artifact/io.netty/netty-codec-smtp)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-socks](https://mvnrepository.com/artifact/io.netty/netty-codec-socks)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-stomp](https://mvnrepository.com/artifact/io.netty/netty-codec-stomp)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-xml](https://mvnrepository.com/artifact/io.netty/netty-codec-xml)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-common](https://mvnrepository.com/artifact/io.netty/netty-common)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler](https://mvnrepository.com/artifact/io.netty/netty-handler)                                                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-proxy](https://mvnrepository.com/artifact/io.netty/netty-handler-proxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-ssl-ocsp](https://mvnrepository.com/artifact/io.netty/netty-handler-ssl-ocsp)                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver](https://mvnrepository.com/artifact/io.netty/netty-resolver)                                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns)                                                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-classes-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-classes-macos)                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-native-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-native-macos)                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport](https://mvnrepository.com/artifact/io.netty/netty-transport)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-epoll)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-kqueue)                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-native-epoll)                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-native-kqueue)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-unix-common](https://mvnrepository.com/artifact/io.netty/netty-transport-native-unix-common)                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-rxtx](https://mvnrepository.com/artifact/io.netty/netty-transport-rxtx)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-sctp](https://mvnrepository.com/artifact/io.netty/netty-transport-sctp)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-udt](https://mvnrepository.com/artifact/io.netty/netty-transport-udt)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.perfmark:perfmark-api](https://mvnrepository.com/artifact/io.perfmark/perfmark-api)                                                                                               | 0.27.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor:reactor-core](https://mvnrepository.com/artifact/io.projectreactor/reactor-core)                                                                                   | 3.7.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-core](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-core)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-http](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-http)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.sentry:sentry](https://mvnrepository.com/artifact/io.sentry/sentry)                                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-reactor](https://mvnrepository.com/artifact/io.sentry/sentry-reactor)                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-jakarta)                                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-starter-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-starter-jakarta)                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-jakarta)                                                                                 | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.swagger.core.v3:swagger-annotations-jakarta](https://mvnrepository.com/artifact/io.swagger.core.v3/swagger-annotations-jakarta)                                                   | 2.2.47                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.swagger.core.v3:swagger-core-jakarta](https://mvnrepository.com/artifact/io.swagger.core.v3/swagger-core-jakarta)                                                                 | 2.2.47                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.swagger.core.v3:swagger-models-jakarta](https://mvnrepository.com/artifact/io.swagger.core.v3/swagger-models-jakarta)                                                             | 2.2.47                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [jakarta.activation:jakarta.activation-api](https://mvnrepository.com/artifact/jakarta.activation/jakarta.activation-api)                                                             | 2.1.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [jakarta.annotation:jakarta.annotation-api](https://mvnrepository.com/artifact/jakarta.annotation/jakarta.annotation-api)                                                             | 2.1.1                                     | [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html)                                                               |
| [jakarta.mail:jakarta.mail-api](https://mvnrepository.com/artifact/jakarta.mail/jakarta.mail-api)                                                                                     | 2.1.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [jakarta.validation:jakarta.validation-api](https://mvnrepository.com/artifact/jakarta.validation/jakarta.validation-api)                                                             | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                         |
| [jakarta.ws.rs:jakarta.ws.rs-api](https://mvnrepository.com/artifact/jakarta.ws.rs/jakarta.ws.rs-api)                                                                                 | 3.1.0                                     | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                                                                                    |
| [jakarta.xml.bind:jakarta.xml.bind-api](https://mvnrepository.com/artifact/jakarta.xml.bind/jakarta.xml.bind-api)                                                                     | 4.0.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [javax.annotation:javax.annotation-api](https://mvnrepository.com/artifact/javax.annotation/javax.annotation-api)                                                                     | 1.3.2                                     | [CDDL-1.0](https://opensource.org/licenses/CDDL-1.0)                                                                                                                                                                                                                                                                                             |
| [net.jodah:failsafe](https://mvnrepository.com/artifact/net.jodah/failsafe)                                                                                                           | 2.4.4                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:accessors-smart](https://mvnrepository.com/artifact/net.minidev/accessors-smart)                                                                                         | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:json-smart](https://mvnrepository.com/artifact/net.minidev/json-smart)                                                                                                   | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.commons:commons-compress](https://mvnrepository.com/artifact/org.apache.commons/commons-compress)                                                                         | 1.27.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.commons:commons-lang3](https://mvnrepository.com/artifact/org.apache.commons/commons-lang3)                                                                               | 3.18.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpclient](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpclient)                                                                       | 4.5.14                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpcore](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpcore)                                                                           | 4.4.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-core](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core)                                                                         | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-dom](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-dom)                                                                           | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-storage](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-storage)                                                                   | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-api](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-api)                                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-to-slf4j](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-to-slf4j)                                                                 | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-core](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-core)                                                             | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-el](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-el)                                                                 | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-websocket](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-websocket)                                                   | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.bouncycastle:bcprov-jdk18on](https://mvnrepository.com/artifact/org.bouncycastle/bcprov-jdk18on)                                                                                 | 1.83                                      | [Bouncy Castle](https://www.bouncycastle.org/licence.html)                                                                                                                                                                                                                                                                                       |
| [org.checkerframework:checker-qual](https://mvnrepository.com/artifact/org.checkerframework/checker-qual)                                                                             | 3.43.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.codehaus.mojo:animal-sniffer-annotations](https://mvnrepository.com/artifact/org.codehaus.mojo/animal-sniffer-annotations)                                                       | 1.24                                      | [MIT](https://opensource.org/licenses/MIT), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                            |
| [org.eclipse.angus:angus-activation](https://mvnrepository.com/artifact/org.eclipse.angus/angus-activation)                                                                           | 2.0.3                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.eclipse.angus:angus-mail](https://mvnrepository.com/artifact/org.eclipse.angus/angus-mail)                                                                                       | 2.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [org.eclipse.microprofile.openapi:microprofile-openapi-api](https://mvnrepository.com/artifact/org.eclipse.microprofile.openapi/microprofile-openapi-api)                             | 4.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.glassfish:jakarta.el](https://mvnrepository.com/artifact/org.glassfish/jakarta.el)                                                                                               | 3.0.4                                     | [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html)                                                               |
| [org.glassfish.jaxb:codemodel](https://mvnrepository.com/artifact/org.glassfish.jaxb/codemodel)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-core](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-core)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-jxc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-jxc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-runtime](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-runtime)                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-xjc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-xjc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:txw2](https://mvnrepository.com/artifact/org.glassfish.jaxb/txw2)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:xsom](https://mvnrepository.com/artifact/org.glassfish.jaxb/xsom)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.hdrhistogram:HdrHistogram](https://mvnrepository.com/artifact/org.hdrhistogram/HdrHistogram)                                                                                     | 2.2.2                                     | [BSD-2-Clause](https://opensource.org/licenses/BSD-2-Clause), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                            |
| [org.hibernate.validator:hibernate-validator](https://mvnrepository.com/artifact/org.hibernate.validator/hibernate-validator)                                                         | 8.0.3.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.honton.chas.hocon:jackson-dataformat-hocon](https://mvnrepository.com/artifact/org.honton.chas.hocon/jackson-dataformat-hocon)                                                   | 1.1.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss:jandex](https://mvnrepository.com/artifact/org.jboss/jandex)                                                                                                               | 2.4.5.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:commons-logging-jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/commons-logging-jboss-logging)                                                 | 1.0.0.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/jboss-logging)                                                                                 | 3.6.3.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client)                                                                           | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client-api](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client-api)                                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core)                                                                               | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core-spi](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core-spi)                                                                       | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jackson2-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jackson2-provider)                                                     | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jaxb-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jaxb-provider)                                                             | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-multipart-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-multipart-provider)                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains:annotations](https://mvnrepository.com/artifact/org.jetbrains/annotations)                                                                                             | 13.0                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib)                                                                           | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-common](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-common)                                                             | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk7](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk7)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk8](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk8)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jspecify:jspecify](https://mvnrepository.com/artifact/org.jspecify/jspecify)                                                                                                     | 1.0.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.keycloak:keycloak-admin-client](https://mvnrepository.com/artifact/org.keycloak/keycloak-admin-client)                                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.keycloak:keycloak-client-common-synced](https://mvnrepository.com/artifact/org.keycloak/keycloak-client-common-synced)                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.latencyutils:LatencyUtils](https://mvnrepository.com/artifact/org.latencyutils/LatencyUtils)                                                                                     | 2.0.3                                     | [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                                                                                          |
| [org.ow2.asm:asm](https://mvnrepository.com/artifact/org.ow2.asm/asm)                                                                                                                 | 9.7.1                                     | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                          |
| [org.reactivestreams:reactive-streams](https://mvnrepository.com/artifact/org.reactivestreams/reactive-streams)                                                                       | 1.0.4                                     | [MIT-0](https://spdx.org/licenses/MIT-0.html)                                                                                                                                                                                                                                                                                                    |
| [org.slf4j:jul-to-slf4j](https://mvnrepository.com/artifact/org.slf4j/jul-to-slf4j)                                                                                                   | 2.0.17                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.slf4j:slf4j-api](https://mvnrepository.com/artifact/org.slf4j/slf4j-api)                                                                                                         | 2.0.17                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.snakeyaml:snakeyaml-engine](https://mvnrepository.com/artifact/org.snakeyaml/snakeyaml-engine)                                                                                   | 2.7                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springdoc:springdoc-openapi-starter-common](https://mvnrepository.com/artifact/org.springdoc/springdoc-openapi-starter-common)                                                   | 2.8.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springdoc:springdoc-openapi-starter-webmvc-api](https://mvnrepository.com/artifact/org.springdoc/springdoc-openapi-starter-webmvc-api)                                           | 2.8.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://mvnrepository.com/artifact/org.springdoc/springdoc-openapi-starter-webmvc-ui)                                             | 2.8.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-aop](https://mvnrepository.com/artifact/org.springframework/spring-aop)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-beans](https://mvnrepository.com/artifact/org.springframework/spring-beans)                                                                               | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-context](https://mvnrepository.com/artifact/org.springframework/spring-context)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-context-support](https://mvnrepository.com/artifact/org.springframework/spring-context-support)                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-core](https://mvnrepository.com/artifact/org.springframework/spring-core)                                                                                 | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-expression](https://mvnrepository.com/artifact/org.springframework/spring-expression)                                                                     | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-jcl](https://mvnrepository.com/artifact/org.springframework/spring-jcl)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-web](https://mvnrepository.com/artifact/org.springframework/spring-web)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webflux](https://mvnrepository.com/artifact/org.springframework/spring-webflux)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webmvc](https://mvnrepository.com/artifact/org.springframework/spring-webmvc)                                                                             | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot)                                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-actuator](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-actuator)                                                     | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-actuator-autoconfigure](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-actuator-autoconfigure)                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-autoconfigure](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-autoconfigure)                                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter)                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-actuator](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-actuator)                                     | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-cache](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-cache)                                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-json](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-json)                                             | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-logging](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-logging)                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-oauth2-client](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-oauth2-client)                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-oauth2-resource-server](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-oauth2-resource-server)         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-reactor-netty](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-reactor-netty)                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-security](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-security)                                     | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-tomcat](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-tomcat)                                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-validation](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-validation)                                 | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-web](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web)                                               | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-webflux](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-webflux)                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.cloud:spring-cloud-gateway-mvc](https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-gateway-mvc)                                           | 4.0.4                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-config](https://mvnrepository.com/artifact/org.springframework.security/spring-security-config)                                         | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-core](https://mvnrepository.com/artifact/org.springframework.security/spring-security-core)                                             | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-crypto](https://mvnrepository.com/artifact/org.springframework.security/spring-security-crypto)                                         | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-client](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-client)                           | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-core](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-core)                               | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-jose](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-jose)                               | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-oauth2-resource-server](https://mvnrepository.com/artifact/org.springframework.security/spring-security-oauth2-resource-server)         | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.security:spring-security-web](https://mvnrepository.com/artifact/org.springframework.security/spring-security-web)                                               | 6.5.9                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.webjars:swagger-ui](https://mvnrepository.com/artifact/org.webjars/swagger-ui)                                                                                                   | 5.32.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.webjars:webjars-locator-lite](https://mvnrepository.com/artifact/org.webjars/webjars-locator-lite)                                                                               | 1.1.3                                     | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.yaml:snakeyaml](https://mvnrepository.com/artifact/org.yaml/snakeyaml)                                                                                                           | 2.4                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |

## Operator

| Package                                                                                                                                                                               | Version                                   | License(s)                                                                                                                                                                                                                                                                                                                                       |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| [com.daml:bindings-java](https://mvnrepository.com/artifact/com.daml/bindings-java)                                                                                                   | 2.8.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson:jackson-bom](https://mvnrepository.com/artifact/com.fasterxml.jackson/jackson-bom)                                                                             | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-annotations)                                                   | 2.21                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-core](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-core)                                                                 | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.core:jackson-databind](https://mvnrepository.com/artifact/com.fasterxml.jackson.core/jackson-databind)                                                         | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://mvnrepository.com/artifact/com.fasterxml.jackson.dataformat/jackson-dataformat-yaml)                               | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jdk8](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jdk8)                                       | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.datatype:jackson-datatype-jsr310](https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jsr310)                                   | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-base](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-base)                               | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-json-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-json-provider)             | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-yaml-provider](https://mvnrepository.com/artifact/com.fasterxml.jackson.jakarta.rs/jackson-jakarta-rs-yaml-provider)             | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-jakarta-xmlbind-annotations) | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.fasterxml.jackson.module:jackson-module-parameter-names](https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-parameter-names)                         | 2.21.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.github.java-json-tools:json-patch](https://mvnrepository.com/artifact/com.github.java-json-tools/json-patch)                                                                     | 1.13                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [LGPL-3.0](https://www.gnu.org/licenses/lgpl-3.0.html)                                                                                                                                                                                                                                |
| [com.github.stephenc.jcip:jcip-annotations](https://mvnrepository.com/artifact/com.github.stephenc.jcip/jcip-annotations)                                                             | 1.0-1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.android:annotations](https://mvnrepository.com/artifact/com.google.android/annotations)                                                                                   | 4.1.1.4                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.api.grpc:proto-google-common-protos](https://mvnrepository.com/artifact/com.google.api.grpc/proto-google-common-protos)                                                   | 2.22.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.findbugs:jsr305](https://mvnrepository.com/artifact/com.google.code.findbugs/jsr305)                                                                                 | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.code.gson:gson](https://mvnrepository.com/artifact/com.google.code.gson/gson)                                                                                             | 2.13.2                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.errorprone:error\_prone\_annotations](https://mvnrepository.com/artifact/com.google.errorprone/error_prone_annotations)                                                   | 2.41.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:failureaccess](https://mvnrepository.com/artifact/com.google.guava/failureaccess)                                                                                   | 1.0.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:guava](https://mvnrepository.com/artifact/com.google.guava/guava)                                                                                                   | 32.0.1-android                            | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.guava:listenablefuture](https://mvnrepository.com/artifact/com.google.guava/listenablefuture)                                                                             | 9999.0-empty-to-avoid-conflict-with-guava | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.j2objc:j2objc-annotations](https://mvnrepository.com/artifact/com.google.j2objc/j2objc-annotations)                                                                       | 2.8                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.google.protobuf:protobuf-java](https://mvnrepository.com/artifact/com.google.protobuf/protobuf-java)                                                                             | 3.25.5                                    | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [com.ibm.async:asyncutil](https://mvnrepository.com/artifact/com.ibm.async/asyncutil)                                                                                                 | 0.1.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:content-type](https://mvnrepository.com/artifact/com.nimbusds/content-type)                                                                                             | 2.3                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:lang-tag](https://mvnrepository.com/artifact/com.nimbusds/lang-tag)                                                                                                     | 1.7                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:nimbus-jose-jwt](https://mvnrepository.com/artifact/com.nimbusds/nimbus-jose-jwt)                                                                                       | 10.0.1                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.nimbusds:oauth2-oidc-sdk](https://mvnrepository.com/artifact/com.nimbusds/oauth2-oidc-sdk)                                                                                       | 11.21.3                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup:javapoet](https://mvnrepository.com/artifact/com.squareup/javapoet)                                                                                                     | 1.13.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okhttp3:okhttp](https://mvnrepository.com/artifact/com.squareup.okhttp3/okhttp)                                                                                         | 4.12.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio](https://mvnrepository.com/artifact/com.squareup.okio/okio)                                                                                                   | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.squareup.okio:okio-jvm](https://mvnrepository.com/artifact/com.squareup.okio/okio-jvm)                                                                                           | 3.4.0                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.sun.istack:istack-commons-runtime](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-runtime)                                                                     | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.istack:istack-commons-tools](https://mvnrepository.com/artifact/com.sun.istack/istack-commons-tools)                                                                         | 4.1.2                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:relaxng-datatype](https://mvnrepository.com/artifact/com.sun.xml.bind.external/relaxng-datatype)                                                           | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.sun.xml.bind.external:rngom](https://mvnrepository.com/artifact/com.sun.xml.bind.external/rngom)                                                                                 | 4.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [com.typesafe:config](https://mvnrepository.com/artifact/com.typesafe/config)                                                                                                         | 1.4.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [com.zaxxer:HikariCP](https://mvnrepository.com/artifact/com.zaxxer/HikariCP)                                                                                                         | 5.0.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-codec:commons-codec](https://mvnrepository.com/artifact/commons-codec/commons-codec)                                                                                         | 1.18.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-io:commons-io](https://mvnrepository.com/artifact/commons-io/commons-io)                                                                                                     | 2.14.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [commons-logging:commons-logging](https://mvnrepository.com/artifact/commons-logging/commons-logging)                                                                                 | 1.2                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client)                                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-client-api](https://mvnrepository.com/artifact/io.fabric8/kubernetes-client-api)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-httpclient-jdk](https://mvnrepository.com/artifact/io.fabric8/kubernetes-httpclient-jdk)                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-httpclient-vertx](https://mvnrepository.com/artifact/io.fabric8/kubernetes-httpclient-vertx)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-admissionregistration](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-admissionregistration)                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apiextensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apiextensions)                                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-apps](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-apps)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-autoscaling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-autoscaling)                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-batch](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-batch)                                                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-certificates](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-certificates)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-common](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-common)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-coordination](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-coordination)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-core](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-core)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-discovery](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-discovery)                                                                     | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-events](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-events)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-extensions](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-extensions)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-flowcontrol](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-flowcontrol)                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-gatewayapi](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-gatewayapi)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-metrics](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-metrics)                                                                         | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-networking](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-networking)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-node](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-node)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-policy](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-policy)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-rbac](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-rbac)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-resource](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-resource)                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-scheduling](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-scheduling)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:kubernetes-model-storageclass](https://mvnrepository.com/artifact/io.fabric8/kubernetes-model-storageclass)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-client](https://mvnrepository.com/artifact/io.fabric8/openshift-client)                                                                                         | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-client-api](https://mvnrepository.com/artifact/io.fabric8/openshift-client-api)                                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model](https://mvnrepository.com/artifact/io.fabric8/openshift-model)                                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-autoscaling](https://mvnrepository.com/artifact/io.fabric8/openshift-model-autoscaling)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-config](https://mvnrepository.com/artifact/io.fabric8/openshift-model-config)                                                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-console](https://mvnrepository.com/artifact/io.fabric8/openshift-model-console)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-hive](https://mvnrepository.com/artifact/io.fabric8/openshift-model-hive)                                                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-installer](https://mvnrepository.com/artifact/io.fabric8/openshift-model-installer)                                                                       | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-machine](https://mvnrepository.com/artifact/io.fabric8/openshift-model-machine)                                                                           | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-machineconfiguration](https://mvnrepository.com/artifact/io.fabric8/openshift-model-machineconfiguration)                                                 | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-miscellaneous](https://mvnrepository.com/artifact/io.fabric8/openshift-model-miscellaneous)                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-monitoring](https://mvnrepository.com/artifact/io.fabric8/openshift-model-monitoring)                                                                     | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-operator](https://mvnrepository.com/artifact/io.fabric8/openshift-model-operator)                                                                         | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-operatorhub](https://mvnrepository.com/artifact/io.fabric8/openshift-model-operatorhub)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-storageversionmigrator](https://mvnrepository.com/artifact/io.fabric8/openshift-model-storageversionmigrator)                                             | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-tuned](https://mvnrepository.com/artifact/io.fabric8/openshift-model-tuned)                                                                               | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:openshift-model-whereabouts](https://mvnrepository.com/artifact/io.fabric8/openshift-model-whereabouts)                                                                   | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.fabric8:zjsonpatch](https://mvnrepository.com/artifact/io.fabric8/zjsonpatch)                                                                                                     | 7.3.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.github.java-diff-utils:java-diff-utils](https://mvnrepository.com/artifact/io.github.java-diff-utils/java-diff-utils)                                                             | 4.16                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-api](https://mvnrepository.com/artifact/io.grpc/grpc-api)                                                                                                               | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-context](https://mvnrepository.com/artifact/io.grpc/grpc-context)                                                                                                       | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-core](https://mvnrepository.com/artifact/io.grpc/grpc-core)                                                                                                             | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-netty](https://mvnrepository.com/artifact/io.grpc/grpc-netty)                                                                                                           | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf)                                                                                                     | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-protobuf-lite](https://mvnrepository.com/artifact/io.grpc/grpc-protobuf-lite)                                                                                           | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-stub](https://mvnrepository.com/artifact/io.grpc/grpc-stub)                                                                                                             | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.grpc:grpc-util](https://mvnrepository.com/artifact/io.grpc/grpc-util)                                                                                                             | 1.59.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.javaoperatorsdk:operator-framework](https://mvnrepository.com/artifact/io.javaoperatorsdk/operator-framework)                                                                     | 5.1.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.javaoperatorsdk:operator-framework-core](https://mvnrepository.com/artifact/io.javaoperatorsdk/operator-framework-core)                                                           | 5.1.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.javaoperatorsdk:operator-framework-spring-boot-starter](https://mvnrepository.com/artifact/io.javaoperatorsdk/operator-framework-spring-boot-starter)                             | 6.1.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-commons](https://mvnrepository.com/artifact/io.micrometer/micrometer-commons)                                                                               | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.micrometer:micrometer-observation](https://mvnrepository.com/artifact/io.micrometer/micrometer-observation)                                                                       | 1.15.10                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-all](https://mvnrepository.com/artifact/io.netty/netty-all)                                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-buffer](https://mvnrepository.com/artifact/io.netty/netty-buffer)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec](https://mvnrepository.com/artifact/io.netty/netty-codec)                                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-dns](https://mvnrepository.com/artifact/io.netty/netty-codec-dns)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-haproxy](https://mvnrepository.com/artifact/io.netty/netty-codec-haproxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http](https://mvnrepository.com/artifact/io.netty/netty-codec-http)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-http2](https://mvnrepository.com/artifact/io.netty/netty-codec-http2)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-memcache](https://mvnrepository.com/artifact/io.netty/netty-codec-memcache)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-mqtt](https://mvnrepository.com/artifact/io.netty/netty-codec-mqtt)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-redis](https://mvnrepository.com/artifact/io.netty/netty-codec-redis)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-smtp](https://mvnrepository.com/artifact/io.netty/netty-codec-smtp)                                                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-socks](https://mvnrepository.com/artifact/io.netty/netty-codec-socks)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-stomp](https://mvnrepository.com/artifact/io.netty/netty-codec-stomp)                                                                                           | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-codec-xml](https://mvnrepository.com/artifact/io.netty/netty-codec-xml)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-common](https://mvnrepository.com/artifact/io.netty/netty-common)                                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler](https://mvnrepository.com/artifact/io.netty/netty-handler)                                                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-proxy](https://mvnrepository.com/artifact/io.netty/netty-handler-proxy)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-handler-ssl-ocsp](https://mvnrepository.com/artifact/io.netty/netty-handler-ssl-ocsp)                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver](https://mvnrepository.com/artifact/io.netty/netty-resolver)                                                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns)                                                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-classes-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-classes-macos)                                                             | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-resolver-dns-native-macos](https://mvnrepository.com/artifact/io.netty/netty-resolver-dns-native-macos)                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport](https://mvnrepository.com/artifact/io.netty/netty-transport)                                                                                               | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-epoll)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-classes-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-classes-kqueue)                                                                 | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-epoll](https://mvnrepository.com/artifact/io.netty/netty-transport-native-epoll)                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-kqueue](https://mvnrepository.com/artifact/io.netty/netty-transport-native-kqueue)                                                                   | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-native-unix-common](https://mvnrepository.com/artifact/io.netty/netty-transport-native-unix-common)                                                         | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-rxtx](https://mvnrepository.com/artifact/io.netty/netty-transport-rxtx)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-sctp](https://mvnrepository.com/artifact/io.netty/netty-transport-sctp)                                                                                     | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.netty:netty-transport-udt](https://mvnrepository.com/artifact/io.netty/netty-transport-udt)                                                                                       | 4.1.132.Final                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.pebbletemplates:pebble](https://mvnrepository.com/artifact/io.pebbletemplates/pebble)                                                                                             | 3.2.0                                     | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                                                                                                                                                                                                                                                     |
| [io.perfmark:perfmark-api](https://mvnrepository.com/artifact/io.perfmark/perfmark-api)                                                                                               | 0.26.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor:reactor-core](https://mvnrepository.com/artifact/io.projectreactor/reactor-core)                                                                                   | 3.7.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-core](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-core)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.projectreactor.netty:reactor-netty-http](https://mvnrepository.com/artifact/io.projectreactor.netty/reactor-netty-http)                                                           | 1.2.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [io.sentry:sentry](https://mvnrepository.com/artifact/io.sentry/sentry)                                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-reactor](https://mvnrepository.com/artifact/io.sentry/sentry-reactor)                                                                                               | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-jakarta)                                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-boot-starter-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-boot-starter-jakarta)                                                       | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.sentry:sentry-spring-jakarta](https://mvnrepository.com/artifact/io.sentry/sentry-spring-jakarta)                                                                                 | 8.13.2                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [io.vertx:vertx-auth-common](https://mvnrepository.com/artifact/io.vertx/vertx-auth-common)                                                                                           | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                 |
| [io.vertx:vertx-core](https://mvnrepository.com/artifact/io.vertx/vertx-core)                                                                                                         | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                           |
| [io.vertx:vertx-web-client](https://mvnrepository.com/artifact/io.vertx/vertx-web-client)                                                                                             | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                 |
| [io.vertx:vertx-web-common](https://mvnrepository.com/artifact/io.vertx/vertx-web-common)                                                                                             | 4.5.14                                    | [EPL-1.0](https://www.eclipse.org/legal/epl-v10.html), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                 |
| [jakarta.activation:jakarta.activation-api](https://mvnrepository.com/artifact/jakarta.activation/jakarta.activation-api)                                                             | 2.1.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [jakarta.annotation:jakarta.annotation-api](https://mvnrepository.com/artifact/jakarta.annotation/jakarta.annotation-api)                                                             | 2.1.1                                     | [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html)                                                               |
| [jakarta.mail:jakarta.mail-api](https://mvnrepository.com/artifact/jakarta.mail/jakarta.mail-api)                                                                                     | 2.1.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [jakarta.validation:jakarta.validation-api](https://mvnrepository.com/artifact/jakarta.validation/jakarta.validation-api)                                                             | 3.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                         |
| [jakarta.ws.rs:jakarta.ws.rs-api](https://mvnrepository.com/artifact/jakarta.ws.rs/jakarta.ws.rs-api)                                                                                 | 3.1.0                                     | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                                                                                    |
| [jakarta.xml.bind:jakarta.xml.bind-api](https://mvnrepository.com/artifact/jakarta.xml.bind/jakarta.xml.bind-api)                                                                     | 4.0.4                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [javax.annotation:javax.annotation-api](https://mvnrepository.com/artifact/javax.annotation/javax.annotation-api)                                                                     | 1.3.2                                     | [CDDL-1.0](https://opensource.org/licenses/CDDL-1.0)                                                                                                                                                                                                                                                                                             |
| [net.bytebuddy:byte-buddy](https://mvnrepository.com/artifact/net.bytebuddy/byte-buddy)                                                                                               | 1.17.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.bytebuddy:byte-buddy-agent](https://mvnrepository.com/artifact/net.bytebuddy/byte-buddy-agent)                                                                                   | 1.17.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:accessors-smart](https://mvnrepository.com/artifact/net.minidev/accessors-smart)                                                                                         | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [net.minidev:json-smart](https://mvnrepository.com/artifact/net.minidev/json-smart)                                                                                                   | 2.5.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.commons:commons-lang3](https://mvnrepository.com/artifact/org.apache.commons/commons-lang3)                                                                               | 3.18.0                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpclient](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpclient)                                                                       | 4.5.14                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.httpcomponents:httpcore](https://mvnrepository.com/artifact/org.apache.httpcomponents/httpcore)                                                                           | 4.4.16                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-core](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-core)                                                                         | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-dom](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-dom)                                                                           | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.james:apache-mime4j-storage](https://mvnrepository.com/artifact/org.apache.james/apache-mime4j-storage)                                                                   | 0.8.12                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-api](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-api)                                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-core](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core)                                                                         | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-jul](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-jul)                                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.logging.log4j:log4j-slf4j2-impl](https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-slf4j2-impl)                                                           | 2.24.3                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-core](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-core)                                                             | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-el](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-el)                                                                 | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.apache.tomcat.embed:tomcat-embed-websocket](https://mvnrepository.com/artifact/org.apache.tomcat.embed/tomcat-embed-websocket)                                                   | 10.1.54                                   | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.aspectj:aspectjrt](https://mvnrepository.com/artifact/org.aspectj/aspectjrt)                                                                                                     | 1.9.21                                    | [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt)                                                                                                                                                                                                                                                                             |
| [org.bouncycastle:bcprov-jdk18on](https://mvnrepository.com/artifact/org.bouncycastle/bcprov-jdk18on)                                                                                 | 1.83                                      | [Bouncy Castle](https://www.bouncycastle.org/licence.html)                                                                                                                                                                                                                                                                                       |
| [org.checkerframework:checker-qual](https://mvnrepository.com/artifact/org.checkerframework/checker-qual)                                                                             | 3.33.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.codehaus.mojo:animal-sniffer-annotations](https://mvnrepository.com/artifact/org.codehaus.mojo/animal-sniffer-annotations)                                                       | 1.23                                      | [MIT](https://opensource.org/licenses/MIT), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                            |
| [org.eclipse.angus:angus-activation](https://mvnrepository.com/artifact/org.eclipse.angus/angus-activation)                                                                           | 2.0.3                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.eclipse.angus:angus-mail](https://mvnrepository.com/artifact/org.eclipse.angus/angus-mail)                                                                                       | 2.0.5                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL 2.0](http://www.eclipse.org/legal/epl-2.0), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html), [GPL2 w/ CPE](https://www.gnu.org/software/classpath/license.html) |
| [org.eclipse.microprofile.openapi:microprofile-openapi-api](https://mvnrepository.com/artifact/org.eclipse.microprofile.openapi/microprofile-openapi-api)                             | 4.0.2                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.glassfish.jaxb:codemodel](https://mvnrepository.com/artifact/org.glassfish.jaxb/codemodel)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-core](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-core)                                                                                       | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-jxc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-jxc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-runtime](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-runtime)                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:jaxb-xjc](https://mvnrepository.com/artifact/org.glassfish.jaxb/jaxb-xjc)                                                                                         | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:txw2](https://mvnrepository.com/artifact/org.glassfish.jaxb/txw2)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.glassfish.jaxb:xsom](https://mvnrepository.com/artifact/org.glassfish.jaxb/xsom)                                                                                                 | 4.0.6                                     | [EDL-1.0](https://www.eclipse.org/org/documents/edl-v10.php), [EPL-2.0](https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt), [GPL-2.0-with-classpath-exception](https://www.gnu.org/software/classpath/license.html)                                                                                                                      |
| [org.honton.chas.hocon:jackson-dataformat-hocon](https://mvnrepository.com/artifact/org.honton.chas.hocon/jackson-dataformat-hocon)                                                   | 1.1.1                                     | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss:jandex](https://mvnrepository.com/artifact/org.jboss/jandex)                                                                                                               | 2.4.5.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:commons-logging-jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/commons-logging-jboss-logging)                                                 | 1.0.0.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.jboss.logging:jboss-logging](https://mvnrepository.com/artifact/org.jboss.logging/jboss-logging)                                                                                 | 3.6.3.Final                               | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client)                                                                           | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-client-api](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-client-api)                                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core)                                                                               | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-core-spi](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-core-spi)                                                                       | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jackson2-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jackson2-provider)                                                     | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-jaxb-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-jaxb-provider)                                                             | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jboss.resteasy:resteasy-multipart-provider](https://mvnrepository.com/artifact/org.jboss.resteasy/resteasy-multipart-provider)                                                   | 6.2.12.Final                              | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains:annotations](https://mvnrepository.com/artifact/org.jetbrains/annotations)                                                                                             | 13.0                                      | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib)                                                                           | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-common](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-common)                                                             | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk7](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk7)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.jetbrains.kotlin:kotlin-stdlib-jdk8](https://mvnrepository.com/artifact/org.jetbrains.kotlin/kotlin-stdlib-jdk8)                                                                 | 1.9.25                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.keycloak:keycloak-admin-client](https://mvnrepository.com/artifact/org.keycloak/keycloak-admin-client)                                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.keycloak:keycloak-client-common-synced](https://mvnrepository.com/artifact/org.keycloak/keycloak-client-common-synced)                                                           | 26.0.8                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0), [Public Domain / CC0](http://repository.jboss.org/licenses/cc0-1.0.txt)                                                                                                                                                                                                               |
| [org.mockito:mockito-core](https://mvnrepository.com/artifact/org.mockito/mockito-core)                                                                                               | 5.17.0                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.objenesis:objenesis](https://mvnrepository.com/artifact/org.objenesis/objenesis)                                                                                                 | 3.3                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.ow2.asm:asm](https://mvnrepository.com/artifact/org.ow2.asm/asm)                                                                                                                 | 9.7.1                                     | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause), [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                          |
| [org.postgresql:postgresql](https://mvnrepository.com/artifact/org.postgresql/postgresql)                                                                                             | 42.3.9                                    | [BSD-2-Clause](https://opensource.org/licenses/BSD-2-Clause)                                                                                                                                                                                                                                                                                     |
| [org.reactivestreams:reactive-streams](https://mvnrepository.com/artifact/org.reactivestreams/reactive-streams)                                                                       | 1.0.4                                     | [MIT-0](https://spdx.org/licenses/MIT-0.html)                                                                                                                                                                                                                                                                                                    |
| [org.slf4j:slf4j-api](https://mvnrepository.com/artifact/org.slf4j/slf4j-api)                                                                                                         | 2.0.17                                    | [MIT](https://opensource.org/licenses/MIT)                                                                                                                                                                                                                                                                                                       |
| [org.snakeyaml:snakeyaml-engine](https://mvnrepository.com/artifact/org.snakeyaml/snakeyaml-engine)                                                                                   | 2.9                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-aop](https://mvnrepository.com/artifact/org.springframework/spring-aop)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-beans](https://mvnrepository.com/artifact/org.springframework/spring-beans)                                                                               | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-context](https://mvnrepository.com/artifact/org.springframework/spring-context)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-core](https://mvnrepository.com/artifact/org.springframework/spring-core)                                                                                 | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-expression](https://mvnrepository.com/artifact/org.springframework/spring-expression)                                                                     | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-jcl](https://mvnrepository.com/artifact/org.springframework/spring-jcl)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-web](https://mvnrepository.com/artifact/org.springframework/spring-web)                                                                                   | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webflux](https://mvnrepository.com/artifact/org.springframework/spring-webflux)                                                                           | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework:spring-webmvc](https://mvnrepository.com/artifact/org.springframework/spring-webmvc)                                                                             | 6.2.17                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot)                                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-autoconfigure](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-autoconfigure)                                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter)                                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-json](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-json)                                             | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-log4j2](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-log4j2)                                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-reactor-netty](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-reactor-netty)                           | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-tomcat](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-tomcat)                                         | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-web](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web)                                               | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.springframework.boot:spring-boot-starter-webflux](https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-webflux)                                       | 3.5.13                                    | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.unbescape:unbescape](https://mvnrepository.com/artifact/org.unbescape/unbescape)                                                                                                 | 1.1.6.RELEASE                             | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |
| [org.yaml:snakeyaml](https://mvnrepository.com/artifact/org.yaml/snakeyaml)                                                                                                           | 2.4                                       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                                                                                                                                                                                                                                                        |

## UI

| Package                                                                                                                    | Version      | License(s)                                                                                                        |
| -------------------------------------------------------------------------------------------------------------------------- | ------------ | ----------------------------------------------------------------------------------------------------------------- |
| [@babel/code-frame](https://www.npmjs.com/package/@babel/code-frame)                                                       | 7.26.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/generator](https://www.npmjs.com/package/@babel/generator)                                                         | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/helper-module-imports](https://www.npmjs.com/package/@babel/helper-module-imports)                                 | 7.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/helper-string-parser](https://www.npmjs.com/package/@babel/helper-string-parser)                                   | 7.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/helper-validator-identifier](https://www.npmjs.com/package/@babel/helper-validator-identifier)                     | 7.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/parser](https://www.npmjs.com/package/@babel/parser)                                                               | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/runtime](https://www.npmjs.com/package/@babel/runtime)                                                             | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/runtime](https://www.npmjs.com/package/@babel/runtime)                                                             | 7.27.6       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/runtime](https://www.npmjs.com/package/@babel/runtime)                                                             | 7.28.4       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/template](https://www.npmjs.com/package/@babel/template)                                                           | 7.26.9       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/traverse](https://www.npmjs.com/package/@babel/traverse)                                                           | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@babel/types](https://www.npmjs.com/package/@babel/types)                                                                 | 7.26.10      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@bufbuild/protobuf](https://www.npmjs.com/package/@bufbuild/protobuf)                                                     | 2.2.4        | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [@emotion/babel-plugin](https://www.npmjs.com/package/@emotion/babel-plugin)                                               | 11.13.5      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/cache](https://www.npmjs.com/package/@emotion/cache)                                                             | 11.14.0      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/hash](https://www.npmjs.com/package/@emotion/hash)                                                               | 0.9.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/memoize](https://www.npmjs.com/package/@emotion/memoize)                                                         | 0.9.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/react](https://www.npmjs.com/package/@emotion/react)                                                             | 11.14.0      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/serialize](https://www.npmjs.com/package/@emotion/serialize)                                                     | 1.3.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/sheet](https://www.npmjs.com/package/@emotion/sheet)                                                             | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/unitless](https://www.npmjs.com/package/@emotion/unitless)                                                       | 0.10.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/use-insertion-effect-with-fallbacks](https://www.npmjs.com/package/@emotion/use-insertion-effect-with-fallbacks) | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/utils](https://www.npmjs.com/package/@emotion/utils)                                                             | 1.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@emotion/weak-memoize](https://www.npmjs.com/package/@emotion/weak-memoize)                                               | 0.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@esbuild-plugins/node-modules-polyfill](https://www.npmjs.com/package/@esbuild-plugins/node-modules-polyfill)             | 0.2.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [@esbuild/darwin-arm64](https://www.npmjs.com/package/@esbuild/darwin-arm64)                                               | 0.18.20      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@floating-ui/core](https://www.npmjs.com/package/@floating-ui/core)                                                       | 1.6.9        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@floating-ui/dom](https://www.npmjs.com/package/@floating-ui/dom)                                                         | 1.6.13       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@floating-ui/utils](https://www.npmjs.com/package/@floating-ui/utils)                                                     | 0.2.9        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@intellecteu/common-ui](https://www.npmjs.com/package/@intellecteu/common-ui)                                             | 0.1.51       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@jridgewell/gen-mapping](https://www.npmjs.com/package/@jridgewell/gen-mapping)                                           | 0.3.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@jridgewell/resolve-uri](https://www.npmjs.com/package/@jridgewell/resolve-uri)                                           | 3.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@jridgewell/set-array](https://www.npmjs.com/package/@jridgewell/set-array)                                               | 1.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@jridgewell/source-map](https://www.npmjs.com/package/@jridgewell/source-map)                                             | 0.3.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@jridgewell/sourcemap-codec](https://www.npmjs.com/package/@jridgewell/sourcemap-codec)                                   | 1.5.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@jridgewell/trace-mapping](https://www.npmjs.com/package/@jridgewell/trace-mapping)                                       | 0.3.25       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@loadable/component](https://www.npmjs.com/package/@loadable/component)                                                   | 5.16.4       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@nodelib/fs.scandir](https://www.npmjs.com/package/@nodelib/fs.scandir)                                                   | 2.1.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@nodelib/fs.stat](https://www.npmjs.com/package/@nodelib/fs.stat)                                                         | 2.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@nodelib/fs.walk](https://www.npmjs.com/package/@nodelib/fs.walk)                                                         | 1.2.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@popperjs/core](https://www.npmjs.com/package/@popperjs/core)                                                             | 2.11.8       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@remix-run/router](https://www.npmjs.com/package/@remix-run/router)                                                       | 1.23.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@sindresorhus/is](https://www.npmjs.com/package/@sindresorhus/is)                                                         | 0.7.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@tanstack/query-core](https://www.npmjs.com/package/@tanstack/query-core)                                                 | 4.36.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@tanstack/react-query](https://www.npmjs.com/package/@tanstack/react-query)                                               | 4.36.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@tanstack/react-table](https://www.npmjs.com/package/@tanstack/react-table)                                               | 8.21.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@tanstack/table-core](https://www.npmjs.com/package/@tanstack/table-core)                                                 | 8.21.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@trysound/sax](https://www.npmjs.com/package/@trysound/sax)                                                               | 0.2.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [@types/eslint-scope](https://www.npmjs.com/package/@types/eslint-scope)                                                   | 3.7.7        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/eslint](https://www.npmjs.com/package/@types/eslint)                                                               | 9.6.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/estree](https://www.npmjs.com/package/@types/estree)                                                               | 1.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/glob](https://www.npmjs.com/package/@types/glob)                                                                   | 7.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/hoist-non-react-statics](https://www.npmjs.com/package/@types/hoist-non-react-statics)                             | 3.3.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/json-schema](https://www.npmjs.com/package/@types/json-schema)                                                     | 7.0.15       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/minimatch](https://www.npmjs.com/package/@types/minimatch)                                                         | 5.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/node](https://www.npmjs.com/package/@types/node)                                                                   | 22.13.10     | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/parse-json](https://www.npmjs.com/package/@types/parse-json)                                                       | 4.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/react-transition-group](https://www.npmjs.com/package/@types/react-transition-group)                               | 4.4.12       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@types/react](https://www.npmjs.com/package/@types/react)                                                                 | 19.0.11      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/ast](https://www.npmjs.com/package/@webassemblyjs/ast)                                                     | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/floating-point-hex-parser](https://www.npmjs.com/package/@webassemblyjs/floating-point-hex-parser)         | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/helper-api-error](https://www.npmjs.com/package/@webassemblyjs/helper-api-error)                           | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/helper-buffer](https://www.npmjs.com/package/@webassemblyjs/helper-buffer)                                 | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/helper-numbers](https://www.npmjs.com/package/@webassemblyjs/helper-numbers)                               | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/helper-wasm-bytecode](https://www.npmjs.com/package/@webassemblyjs/helper-wasm-bytecode)                   | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/helper-wasm-section](https://www.npmjs.com/package/@webassemblyjs/helper-wasm-section)                     | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/ieee754](https://www.npmjs.com/package/@webassemblyjs/ieee754)                                             | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/leb128](https://www.npmjs.com/package/@webassemblyjs/leb128)                                               | 1.13.2       | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [@webassemblyjs/utf8](https://www.npmjs.com/package/@webassemblyjs/utf8)                                                   | 1.13.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/wasm-edit](https://www.npmjs.com/package/@webassemblyjs/wasm-edit)                                         | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/wasm-gen](https://www.npmjs.com/package/@webassemblyjs/wasm-gen)                                           | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/wasm-opt](https://www.npmjs.com/package/@webassemblyjs/wasm-opt)                                           | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/wasm-parser](https://www.npmjs.com/package/@webassemblyjs/wasm-parser)                                     | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@webassemblyjs/wast-printer](https://www.npmjs.com/package/@webassemblyjs/wast-printer)                                   | 1.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [@xtuc/ieee754](https://www.npmjs.com/package/@xtuc/ieee754)                                                               | 1.2.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [@xtuc/long](https://www.npmjs.com/package/@xtuc/long)                                                                     | 4.2.2        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [ace-builds](https://www.npmjs.com/package/ace-builds)                                                                     | 1.39.0       | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [acorn](https://www.npmjs.com/package/acorn)                                                                               | 7.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [acorn](https://www.npmjs.com/package/acorn)                                                                               | 8.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ajv-formats](https://www.npmjs.com/package/ajv-formats)                                                                   | 2.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ajv-keywords](https://www.npmjs.com/package/ajv-keywords)                                                                 | 3.5.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ajv-keywords](https://www.npmjs.com/package/ajv-keywords)                                                                 | 5.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ajv](https://www.npmjs.com/package/ajv)                                                                                   | 6.12.6       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ajv](https://www.npmjs.com/package/ajv)                                                                                   | 8.17.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [arch](https://www.npmjs.com/package/arch)                                                                                 | 2.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [archive-type](https://www.npmjs.com/package/archive-type)                                                                 | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [array-union](https://www.npmjs.com/package/array-union)                                                                   | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [asap](https://www.npmjs.com/package/asap)                                                                                 | 2.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [babel-plugin-macros](https://www.npmjs.com/package/babel-plugin-macros)                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [balanced-match](https://www.npmjs.com/package/balanced-match)                                                             | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [base16](https://www.npmjs.com/package/base16)                                                                             | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [base64-js](https://www.npmjs.com/package/base64-js)                                                                       | 1.5.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [big.js](https://www.npmjs.com/package/big.js)                                                                             | 5.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [bin-build](https://www.npmjs.com/package/bin-build)                                                                       | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [bin-check](https://www.npmjs.com/package/bin-check)                                                                       | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [bin-version-check](https://www.npmjs.com/package/bin-version-check)                                                       | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [bin-version](https://www.npmjs.com/package/bin-version)                                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [bin-wrapper](https://www.npmjs.com/package/bin-wrapper)                                                                   | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [bl](https://www.npmjs.com/package/bl)                                                                                     | 1.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [body-scroll-lock](https://www.npmjs.com/package/body-scroll-lock)                                                         | 4.0.0-beta.0 | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [boolbase](https://www.npmjs.com/package/boolbase)                                                                         | 1.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [brace-expansion](https://www.npmjs.com/package/brace-expansion)                                                           | 1.1.11       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [braces](https://www.npmjs.com/package/braces)                                                                             | 3.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [browserslist](https://www.npmjs.com/package/browserslist)                                                                 | 4.24.4       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer-alloc-unsafe](https://www.npmjs.com/package/buffer-alloc-unsafe)                                                   | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer-alloc](https://www.npmjs.com/package/buffer-alloc)                                                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer-builder](https://www.npmjs.com/package/buffer-builder)                                                             | 0.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer-crc32](https://www.npmjs.com/package/buffer-crc32)                                                                 | 0.2.13       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer-fill](https://www.npmjs.com/package/buffer-fill)                                                                   | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer-from](https://www.npmjs.com/package/buffer-from)                                                                   | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer](https://www.npmjs.com/package/buffer)                                                                             | 5.7.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [buffer](https://www.npmjs.com/package/buffer)                                                                             | 6.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cacheable-request](https://www.npmjs.com/package/cacheable-request)                                                       | 2.1.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [callsites](https://www.npmjs.com/package/callsites)                                                                       | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [caniuse-lite](https://www.npmjs.com/package/caniuse-lite)                                                                 | 1.0.30001706 | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [caw](https://www.npmjs.com/package/caw)                                                                                   | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [chrome-trace-event](https://www.npmjs.com/package/chrome-trace-event)                                                     | 1.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [classnames](https://www.npmjs.com/package/classnames)                                                                     | 2.5.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [clone-response](https://www.npmjs.com/package/clone-response)                                                             | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [clsx](https://www.npmjs.com/package/clsx)                                                                                 | 2.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [colorjs.io](https://www.npmjs.com/package/colorjs.io)                                                                     | 0.5.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [commander](https://www.npmjs.com/package/commander)                                                                       | 2.20.3       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [commander](https://www.npmjs.com/package/commander)                                                                       | 7.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [concat-map](https://www.npmjs.com/package/concat-map)                                                                     | 0.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [config-chain](https://www.npmjs.com/package/config-chain)                                                                 | 1.1.13       | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [content-disposition](https://www.npmjs.com/package/content-disposition)                                                   | 0.5.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [convert-source-map](https://www.npmjs.com/package/convert-source-map)                                                     | 1.9.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [copy-webpack-plugin](https://www.npmjs.com/package/copy-webpack-plugin)                                                   | 11.0.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [core-js](https://www.npmjs.com/package/core-js)                                                                           | 3.41.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [core-util-is](https://www.npmjs.com/package/core-util-is)                                                                 | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cosmiconfig](https://www.npmjs.com/package/cosmiconfig)                                                                   | 7.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cron-validate](https://www.npmjs.com/package/cron-validate)                                                               | 1.5.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cross-fetch](https://www.npmjs.com/package/cross-fetch)                                                                   | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cross-spawn](https://www.npmjs.com/package/cross-spawn)                                                                   | 5.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cross-spawn](https://www.npmjs.com/package/cross-spawn)                                                                   | 6.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cross-spawn](https://www.npmjs.com/package/cross-spawn)                                                                   | 7.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [crypto-js](https://www.npmjs.com/package/crypto-js)                                                                       | 4.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [css-select](https://www.npmjs.com/package/css-select)                                                                     | 4.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [css-select](https://www.npmjs.com/package/css-select)                                                                     | 5.1.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [css-tree](https://www.npmjs.com/package/css-tree)                                                                         | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [css-tree](https://www.npmjs.com/package/css-tree)                                                                         | 2.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [css-tree](https://www.npmjs.com/package/css-tree)                                                                         | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [css-what](https://www.npmjs.com/package/css-what)                                                                         | 6.1.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [csso](https://www.npmjs.com/package/csso)                                                                                 | 4.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [csso](https://www.npmjs.com/package/csso)                                                                                 | 5.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [csstype](https://www.npmjs.com/package/csstype)                                                                           | 3.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [cwebp-bin](https://www.npmjs.com/package/cwebp-bin)                                                                       | 7.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [debug](https://www.npmjs.com/package/debug)                                                                               | 4.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decode-uri-component](https://www.npmjs.com/package/decode-uri-component)                                                 | 0.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decompress-response](https://www.npmjs.com/package/decompress-response)                                                   | 3.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decompress-tar](https://www.npmjs.com/package/decompress-tar)                                                             | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decompress-tarbz2](https://www.npmjs.com/package/decompress-tarbz2)                                                       | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decompress-targz](https://www.npmjs.com/package/decompress-targz)                                                         | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decompress-unzip](https://www.npmjs.com/package/decompress-unzip)                                                         | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [decompress](https://www.npmjs.com/package/decompress)                                                                     | 4.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [deepmerge](https://www.npmjs.com/package/deepmerge)                                                                       | 2.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [detect-node-es](https://www.npmjs.com/package/detect-node-es)                                                             | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [diff-match-patch](https://www.npmjs.com/package/diff-match-patch)                                                         | 1.0.5        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [dir-glob](https://www.npmjs.com/package/dir-glob)                                                                         | 3.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [dom-helpers](https://www.npmjs.com/package/dom-helpers)                                                                   | 5.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [dom-serializer](https://www.npmjs.com/package/dom-serializer)                                                             | 1.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [dom-serializer](https://www.npmjs.com/package/dom-serializer)                                                             | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [domelementtype](https://www.npmjs.com/package/domelementtype)                                                             | 2.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [domhandler](https://www.npmjs.com/package/domhandler)                                                                     | 4.3.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [domhandler](https://www.npmjs.com/package/domhandler)                                                                     | 5.0.3        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [domutils](https://www.npmjs.com/package/domutils)                                                                         | 2.8.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [domutils](https://www.npmjs.com/package/domutils)                                                                         | 3.2.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [download](https://www.npmjs.com/package/download)                                                                         | 6.2.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [download](https://www.npmjs.com/package/download)                                                                         | 7.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [duplexer3](https://www.npmjs.com/package/duplexer3)                                                                       | 0.1.5        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [electron-to-chromium](https://www.npmjs.com/package/electron-to-chromium)                                                 | 1.5.120      | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [emojis-list](https://www.npmjs.com/package/emojis-list)                                                                   | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [end-of-stream](https://www.npmjs.com/package/end-of-stream)                                                               | 1.4.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [enhanced-resolve](https://www.npmjs.com/package/enhanced-resolve)                                                         | 5.18.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [entities](https://www.npmjs.com/package/entities)                                                                         | 2.2.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [entities](https://www.npmjs.com/package/entities)                                                                         | 4.5.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [error-ex](https://www.npmjs.com/package/error-ex)                                                                         | 1.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [es-module-lexer](https://www.npmjs.com/package/es-module-lexer)                                                           | 1.6.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [esbuild](https://www.npmjs.com/package/esbuild)                                                                           | 0.18.20      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [escalade](https://www.npmjs.com/package/escalade)                                                                         | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [escape-string-regexp](https://www.npmjs.com/package/escape-string-regexp)                                                 | 1.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [escape-string-regexp](https://www.npmjs.com/package/escape-string-regexp)                                                 | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [eslint-scope](https://www.npmjs.com/package/eslint-scope)                                                                 | 5.1.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [esrecurse](https://www.npmjs.com/package/esrecurse)                                                                       | 4.3.0        | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [estraverse](https://www.npmjs.com/package/estraverse)                                                                     | 4.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [estraverse](https://www.npmjs.com/package/estraverse)                                                                     | 5.3.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [estree-walker](https://www.npmjs.com/package/estree-walker)                                                               | 0.6.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [events](https://www.npmjs.com/package/events)                                                                             | 3.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [eventsource](https://www.npmjs.com/package/eventsource)                                                                   | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [exec-buffer](https://www.npmjs.com/package/exec-buffer)                                                                   | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 0.7.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [execa](https://www.npmjs.com/package/execa)                                                                               | 5.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [executable](https://www.npmjs.com/package/executable)                                                                     | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ext-list](https://www.npmjs.com/package/ext-list)                                                                         | 2.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ext-name](https://www.npmjs.com/package/ext-name)                                                                         | 5.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fast-deep-equal](https://www.npmjs.com/package/fast-deep-equal)                                                           | 3.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fast-glob](https://www.npmjs.com/package/fast-glob)                                                                       | 3.3.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fast-json-stable-stringify](https://www.npmjs.com/package/fast-json-stable-stringify)                                     | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fast-uri](https://www.npmjs.com/package/fast-uri)                                                                         | 3.0.6        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [fast-xml-parser](https://www.npmjs.com/package/fast-xml-parser)                                                           | 4.5.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fastq](https://www.npmjs.com/package/fastq)                                                                               | 1.19.1       | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [fbemitter](https://www.npmjs.com/package/fbemitter)                                                                       | 3.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [fbjs-css-vars](https://www.npmjs.com/package/fbjs-css-vars)                                                               | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fbjs](https://www.npmjs.com/package/fbjs)                                                                                 | 3.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fd-slicer](https://www.npmjs.com/package/fd-slicer)                                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 10.11.0      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 12.4.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 3.9.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 4.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 5.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 6.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [file-type](https://www.npmjs.com/package/file-type)                                                                       | 8.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [filename-reserved-regex](https://www.npmjs.com/package/filename-reserved-regex)                                           | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [filenamify](https://www.npmjs.com/package/filenamify)                                                                     | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fill-range](https://www.npmjs.com/package/fill-range)                                                                     | 7.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [find-root](https://www.npmjs.com/package/find-root)                                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [find-versions](https://www.npmjs.com/package/find-versions)                                                               | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [flux](https://www.npmjs.com/package/flux)                                                                                 | 4.0.4        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [focus-lock](https://www.npmjs.com/package/focus-lock)                                                                     | 1.3.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [formik](https://www.npmjs.com/package/formik)                                                                             | 2.4.6        | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [from2](https://www.npmjs.com/package/from2)                                                                               | 2.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fs-constants](https://www.npmjs.com/package/fs-constants)                                                                 | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [fs.realpath](https://www.npmjs.com/package/fs.realpath)                                                                   | 1.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [function-bind](https://www.npmjs.com/package/function-bind)                                                               | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [get-proxy](https://www.npmjs.com/package/get-proxy)                                                                       | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 4.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 5.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [get-stream](https://www.npmjs.com/package/get-stream)                                                                     | 6.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [gifsicle](https://www.npmjs.com/package/gifsicle)                                                                         | 5.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [glob-parent](https://www.npmjs.com/package/glob-parent)                                                                   | 5.1.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [glob-parent](https://www.npmjs.com/package/glob-parent)                                                                   | 6.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [glob-to-regexp](https://www.npmjs.com/package/glob-to-regexp)                                                             | 0.4.1        | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [glob](https://www.npmjs.com/package/glob)                                                                                 | 7.2.3        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [globals](https://www.npmjs.com/package/globals)                                                                           | 11.12.0      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [globby](https://www.npmjs.com/package/globby)                                                                             | 10.0.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [globby](https://www.npmjs.com/package/globby)                                                                             | 13.2.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [got](https://www.npmjs.com/package/got)                                                                                   | 7.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [got](https://www.npmjs.com/package/got)                                                                                   | 8.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [graceful-fs](https://www.npmjs.com/package/graceful-fs)                                                                   | 4.2.11       | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [has-flag](https://www.npmjs.com/package/has-flag)                                                                         | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [has-symbol-support-x](https://www.npmjs.com/package/has-symbol-support-x)                                                 | 1.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [has-to-string-tag-x](https://www.npmjs.com/package/has-to-string-tag-x)                                                   | 1.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [hasown](https://www.npmjs.com/package/hasown)                                                                             | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [hoist-non-react-statics](https://www.npmjs.com/package/hoist-non-react-statics)                                           | 3.3.2        | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [http-cache-semantics](https://www.npmjs.com/package/http-cache-semantics)                                                 | 3.8.1        | [See license](/catalyx-blockchain-manager/canton-network/version-1.11/support-and-resources/open-source-licenses) |
| [human-signals](https://www.npmjs.com/package/human-signals)                                                               | 1.1.1        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [human-signals](https://www.npmjs.com/package/human-signals)                                                               | 2.1.0        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [ieee754](https://www.npmjs.com/package/ieee754)                                                                           | 1.2.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [ignore](https://www.npmjs.com/package/ignore)                                                                             | 5.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [image-webpack-loader](https://www.npmjs.com/package/image-webpack-loader)                                                 | 8.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin-gifsicle](https://www.npmjs.com/package/imagemin-gifsicle)                                                       | 7.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin-mozjpeg](https://www.npmjs.com/package/imagemin-mozjpeg)                                                         | 9.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin-optipng](https://www.npmjs.com/package/imagemin-optipng)                                                         | 8.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin-pngquant](https://www.npmjs.com/package/imagemin-pngquant)                                                       | 9.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin-svgo](https://www.npmjs.com/package/imagemin-svgo)                                                               | 9.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin-webp](https://www.npmjs.com/package/imagemin-webp)                                                               | 7.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [imagemin](https://www.npmjs.com/package/imagemin)                                                                         | 7.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [immer](https://www.npmjs.com/package/immer)                                                                               | 9.0.21       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [immutable](https://www.npmjs.com/package/immutable)                                                                       | 5.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [import-fresh](https://www.npmjs.com/package/import-fresh)                                                                 | 3.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [import-lazy](https://www.npmjs.com/package/import-lazy)                                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [inflight](https://www.npmjs.com/package/inflight)                                                                         | 1.0.6        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [inherits](https://www.npmjs.com/package/inherits)                                                                         | 2.0.4        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [ini](https://www.npmjs.com/package/ini)                                                                                   | 1.3.8        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [into-stream](https://www.npmjs.com/package/into-stream)                                                                   | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-arrayish](https://www.npmjs.com/package/is-arrayish)                                                                   | 0.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-core-module](https://www.npmjs.com/package/is-core-module)                                                             | 2.16.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-cwebp-readable](https://www.npmjs.com/package/is-cwebp-readable)                                                       | 3.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [is-extglob](https://www.npmjs.com/package/is-extglob)                                                                     | 2.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-gif](https://www.npmjs.com/package/is-gif)                                                                             | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-glob](https://www.npmjs.com/package/is-glob)                                                                           | 4.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-jpg](https://www.npmjs.com/package/is-jpg)                                                                             | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-natural-number](https://www.npmjs.com/package/is-natural-number)                                                       | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-number](https://www.npmjs.com/package/is-number)                                                                       | 7.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-object](https://www.npmjs.com/package/is-object)                                                                       | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-plain-obj](https://www.npmjs.com/package/is-plain-obj)                                                                 | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-png](https://www.npmjs.com/package/is-png)                                                                             | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-retry-allowed](https://www.npmjs.com/package/is-retry-allowed)                                                         | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-stream](https://www.npmjs.com/package/is-stream)                                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-stream](https://www.npmjs.com/package/is-stream)                                                                       | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [is-svg](https://www.npmjs.com/package/is-svg)                                                                             | 4.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [isarray](https://www.npmjs.com/package/isarray)                                                                           | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [isexe](https://www.npmjs.com/package/isexe)                                                                               | 2.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [isurl](https://www.npmjs.com/package/isurl)                                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [jest-worker](https://www.npmjs.com/package/jest-worker)                                                                   | 27.5.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [jose](https://www.npmjs.com/package/jose)                                                                                 | 4.15.9       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [js-tokens](https://www.npmjs.com/package/js-tokens)                                                                       | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [jsesc](https://www.npmjs.com/package/jsesc)                                                                               | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [json-buffer](https://www.npmjs.com/package/json-buffer)                                                                   | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [json-parse-even-better-errors](https://www.npmjs.com/package/json-parse-even-better-errors)                               | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [json-schema-traverse](https://www.npmjs.com/package/json-schema-traverse)                                                 | 0.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [json-schema-traverse](https://www.npmjs.com/package/json-schema-traverse)                                                 | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [json5](https://www.npmjs.com/package/json5)                                                                               | 2.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [junk](https://www.npmjs.com/package/junk)                                                                                 | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [jwt-decode](https://www.npmjs.com/package/jwt-decode)                                                                     | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [keyv](https://www.npmjs.com/package/keyv)                                                                                 | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lines-and-columns](https://www.npmjs.com/package/lines-and-columns)                                                       | 1.2.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [loader-runner](https://www.npmjs.com/package/loader-runner)                                                               | 4.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [loader-utils](https://www.npmjs.com/package/loader-utils)                                                                 | 2.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lodash-es](https://www.npmjs.com/package/lodash-es)                                                                       | 4.17.21      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lodash.curry](https://www.npmjs.com/package/lodash.curry)                                                                 | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lodash.flow](https://www.npmjs.com/package/lodash.flow)                                                                   | 3.5.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lodash.get](https://www.npmjs.com/package/lodash.get)                                                                     | 4.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lodash.isequal](https://www.npmjs.com/package/lodash.isequal)                                                             | 4.5.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lodash](https://www.npmjs.com/package/lodash)                                                                             | 4.17.21      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [loose-envify](https://www.npmjs.com/package/loose-envify)                                                                 | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lowercase-keys](https://www.npmjs.com/package/lowercase-keys)                                                             | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lowercase-keys](https://www.npmjs.com/package/lowercase-keys)                                                             | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [lru-cache](https://www.npmjs.com/package/lru-cache)                                                                       | 4.1.5        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [magic-string](https://www.npmjs.com/package/magic-string)                                                                 | 0.25.9       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [make-dir](https://www.npmjs.com/package/make-dir)                                                                         | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [make-dir](https://www.npmjs.com/package/make-dir)                                                                         | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [mdn-data](https://www.npmjs.com/package/mdn-data)                                                                         | 2.0.14       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                     |
| [mdn-data](https://www.npmjs.com/package/mdn-data)                                                                         | 2.0.28       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                     |
| [mdn-data](https://www.npmjs.com/package/mdn-data)                                                                         | 2.0.30       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                     |
| [memoize-one](https://www.npmjs.com/package/memoize-one)                                                                   | 6.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [merge-stream](https://www.npmjs.com/package/merge-stream)                                                                 | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [merge2](https://www.npmjs.com/package/merge2)                                                                             | 1.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [micromatch](https://www.npmjs.com/package/micromatch)                                                                     | 4.0.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [mime-db](https://www.npmjs.com/package/mime-db)                                                                           | 1.52.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [mime-db](https://www.npmjs.com/package/mime-db)                                                                           | 1.54.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [mime-types](https://www.npmjs.com/package/mime-types)                                                                     | 2.1.35       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [mimic-fn](https://www.npmjs.com/package/mimic-fn)                                                                         | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [mimic-response](https://www.npmjs.com/package/mimic-response)                                                             | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [minimatch](https://www.npmjs.com/package/minimatch)                                                                       | 3.1.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [mozjpeg](https://www.npmjs.com/package/mozjpeg)                                                                           | 7.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ms](https://www.npmjs.com/package/ms)                                                                                     | 2.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [neo-async](https://www.npmjs.com/package/neo-async)                                                                       | 2.6.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [nice-try](https://www.npmjs.com/package/nice-try)                                                                         | 1.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [node-fetch](https://www.npmjs.com/package/node-fetch)                                                                     | 2.7.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [node-releases](https://www.npmjs.com/package/node-releases)                                                               | 2.0.19       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [normalize-path](https://www.npmjs.com/package/normalize-path)                                                             | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [normalize-url](https://www.npmjs.com/package/normalize-url)                                                               | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [normalize.css](https://www.npmjs.com/package/normalize.css)                                                               | 8.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [npm-conf](https://www.npmjs.com/package/npm-conf)                                                                         | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [npm-run-path](https://www.npmjs.com/package/npm-run-path)                                                                 | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [npm-run-path](https://www.npmjs.com/package/npm-run-path)                                                                 | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [nth-check](https://www.npmjs.com/package/nth-check)                                                                       | 2.1.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [object-assign](https://www.npmjs.com/package/object-assign)                                                               | 4.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [oidc-client-ts](https://www.npmjs.com/package/oidc-client-ts)                                                             | 3.2.0        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [oidc-client](https://www.npmjs.com/package/oidc-client)                                                                   | 1.11.5       | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [once](https://www.npmjs.com/package/once)                                                                                 | 1.4.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [onetime](https://www.npmjs.com/package/onetime)                                                                           | 5.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [optipng-bin](https://www.npmjs.com/package/optipng-bin)                                                                   | 7.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [os-filter-obj](https://www.npmjs.com/package/os-filter-obj)                                                               | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [ow](https://www.npmjs.com/package/ow)                                                                                     | 0.17.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-cancelable](https://www.npmjs.com/package/p-cancelable)                                                                 | 0.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-cancelable](https://www.npmjs.com/package/p-cancelable)                                                                 | 0.4.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-event](https://www.npmjs.com/package/p-event)                                                                           | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-event](https://www.npmjs.com/package/p-event)                                                                           | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-finally](https://www.npmjs.com/package/p-finally)                                                                       | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-is-promise](https://www.npmjs.com/package/p-is-promise)                                                                 | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-map-series](https://www.npmjs.com/package/p-map-series)                                                                 | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-pipe](https://www.npmjs.com/package/p-pipe)                                                                             | 3.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-reduce](https://www.npmjs.com/package/p-reduce)                                                                         | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-timeout](https://www.npmjs.com/package/p-timeout)                                                                       | 1.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [p-timeout](https://www.npmjs.com/package/p-timeout)                                                                       | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [parent-module](https://www.npmjs.com/package/parent-module)                                                               | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [parse-json](https://www.npmjs.com/package/parse-json)                                                                     | 5.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [path-is-absolute](https://www.npmjs.com/package/path-is-absolute)                                                         | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [path-key](https://www.npmjs.com/package/path-key)                                                                         | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [path-key](https://www.npmjs.com/package/path-key)                                                                         | 3.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [path-parse](https://www.npmjs.com/package/path-parse)                                                                     | 1.0.7        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [path-type](https://www.npmjs.com/package/path-type)                                                                       | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pend](https://www.npmjs.com/package/pend)                                                                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [picocolors](https://www.npmjs.com/package/picocolors)                                                                     | 1.1.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [picomatch](https://www.npmjs.com/package/picomatch)                                                                       | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pify](https://www.npmjs.com/package/pify)                                                                                 | 2.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pify](https://www.npmjs.com/package/pify)                                                                                 | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pify](https://www.npmjs.com/package/pify)                                                                                 | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pinkie-promise](https://www.npmjs.com/package/pinkie-promise)                                                             | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pinkie](https://www.npmjs.com/package/pinkie)                                                                             | 2.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pngquant-bin](https://www.npmjs.com/package/pngquant-bin)                                                                 | 6.0.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [prepend-http](https://www.npmjs.com/package/prepend-http)                                                                 | 1.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [prepend-http](https://www.npmjs.com/package/prepend-http)                                                                 | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [process-nextick-args](https://www.npmjs.com/package/process-nextick-args)                                                 | 2.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [promise](https://www.npmjs.com/package/promise)                                                                           | 7.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [prop-types](https://www.npmjs.com/package/prop-types)                                                                     | 15.8.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [property-expr](https://www.npmjs.com/package/property-expr)                                                               | 2.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [proto-list](https://www.npmjs.com/package/proto-list)                                                                     | 1.2.4        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [pseudomap](https://www.npmjs.com/package/pseudomap)                                                                       | 1.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [pump](https://www.npmjs.com/package/pump)                                                                                 | 3.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [punycode](https://www.npmjs.com/package/punycode)                                                                         | 2.3.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [pure-color](https://www.npmjs.com/package/pure-color)                                                                     | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [query-string](https://www.npmjs.com/package/query-string)                                                                 | 5.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [queue-microtask](https://www.npmjs.com/package/queue-microtask)                                                           | 1.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [randombytes](https://www.npmjs.com/package/randombytes)                                                                   | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [rc-pagination](https://www.npmjs.com/package/rc-pagination)                                                               | 5.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [rc-util](https://www.npmjs.com/package/rc-util)                                                                           | 5.44.4       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-ace](https://www.npmjs.com/package/react-ace)                                                                       | 10.1.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-base16-styling](https://www.npmjs.com/package/react-base16-styling)                                                 | 0.6.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-clientside-effect](https://www.npmjs.com/package/react-clientside-effect)                                           | 1.2.7        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-dom](https://www.npmjs.com/package/react-dom)                                                                       | 19.2.4       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-fast-compare](https://www.npmjs.com/package/react-fast-compare)                                                     | 2.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-fast-compare](https://www.npmjs.com/package/react-fast-compare)                                                     | 3.2.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-focus-lock](https://www.npmjs.com/package/react-focus-lock)                                                         | 2.13.6       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-hook-form](https://www.npmjs.com/package/react-hook-form)                                                           | 7.54.2       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-is](https://www.npmjs.com/package/react-is)                                                                         | 16.13.1      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-is](https://www.npmjs.com/package/react-is)                                                                         | 18.3.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-json-view](https://www.npmjs.com/package/react-json-view)                                                           | 1.21.3       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-lifecycles-compat](https://www.npmjs.com/package/react-lifecycles-compat)                                           | 3.0.4        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-oidc-context](https://www.npmjs.com/package/react-oidc-context)                                                     | 3.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-oidc](https://www.npmjs.com/package/react-oidc)                                                                     | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-popper](https://www.npmjs.com/package/react-popper)                                                                 | 2.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-router-dom](https://www.npmjs.com/package/react-router-dom)                                                         | 6.30.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-router](https://www.npmjs.com/package/react-router)                                                                 | 6.30.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-select](https://www.npmjs.com/package/react-select)                                                                 | 5.10.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-tabs](https://www.npmjs.com/package/react-tabs)                                                                     | 6.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-textarea-autosize](https://www.npmjs.com/package/react-textarea-autosize)                                           | 8.5.9        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-toastify](https://www.npmjs.com/package/react-toastify)                                                             | 11.0.5       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [react-transition-group](https://www.npmjs.com/package/react-transition-group)                                             | 4.4.5        | [BSD-3-Clause](https://opensource.org/licenses/BSD-3-Clause)                                                      |
| [react](https://www.npmjs.com/package/react)                                                                               | 19.2.4       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [reactstrap](https://www.npmjs.com/package/reactstrap)                                                                     | 9.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [readable-stream](https://www.npmjs.com/package/readable-stream)                                                           | 2.3.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [regenerator-runtime](https://www.npmjs.com/package/regenerator-runtime)                                                   | 0.14.1       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [replace-ext](https://www.npmjs.com/package/replace-ext)                                                                   | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [require-from-string](https://www.npmjs.com/package/require-from-string)                                                   | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [resolve-from](https://www.npmjs.com/package/resolve-from)                                                                 | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [resolve](https://www.npmjs.com/package/resolve)                                                                           | 1.22.10      | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [responselike](https://www.npmjs.com/package/responselike)                                                                 | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [reusify](https://www.npmjs.com/package/reusify)                                                                           | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [rimraf](https://www.npmjs.com/package/rimraf)                                                                             | 2.7.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [rollup-plugin-inject](https://www.npmjs.com/package/rollup-plugin-inject)                                                 | 3.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [rollup-plugin-node-polyfills](https://www.npmjs.com/package/rollup-plugin-node-polyfills)                                 | 0.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [rollup-pluginutils](https://www.npmjs.com/package/rollup-pluginutils)                                                     | 2.8.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [run-parallel](https://www.npmjs.com/package/run-parallel)                                                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [rxjs](https://www.npmjs.com/package/rxjs)                                                                                 | 7.8.2        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [safe-buffer](https://www.npmjs.com/package/safe-buffer)                                                                   | 5.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [safe-buffer](https://www.npmjs.com/package/safe-buffer)                                                                   | 5.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sass-embedded-darwin-arm64](https://www.npmjs.com/package/sass-embedded-darwin-arm64)                                     | 1.86.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sass-embedded](https://www.npmjs.com/package/sass-embedded)                                                               | 1.86.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [scheduler](https://www.npmjs.com/package/scheduler)                                                                       | 0.27.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [schema-utils](https://www.npmjs.com/package/schema-utils)                                                                 | 2.7.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [schema-utils](https://www.npmjs.com/package/schema-utils)                                                                 | 4.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [seek-bzip](https://www.npmjs.com/package/seek-bzip)                                                                       | 1.0.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [semver-regex](https://www.npmjs.com/package/semver-regex)                                                                 | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [semver-truncate](https://www.npmjs.com/package/semver-truncate)                                                           | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [semver](https://www.npmjs.com/package/semver)                                                                             | 5.7.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [semver](https://www.npmjs.com/package/semver)                                                                             | 6.3.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [serialize-javascript](https://www.npmjs.com/package/serialize-javascript)                                                 | 4.0.0        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [serialize-javascript](https://www.npmjs.com/package/serialize-javascript)                                                 | 6.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [setimmediate](https://www.npmjs.com/package/setimmediate)                                                                 | 1.0.5        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [shebang-command](https://www.npmjs.com/package/shebang-command)                                                           | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [shebang-command](https://www.npmjs.com/package/shebang-command)                                                           | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [shebang-regex](https://www.npmjs.com/package/shebang-regex)                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [shebang-regex](https://www.npmjs.com/package/shebang-regex)                                                               | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [signal-exit](https://www.npmjs.com/package/signal-exit)                                                                   | 3.0.7        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [slash](https://www.npmjs.com/package/slash)                                                                               | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [slash](https://www.npmjs.com/package/slash)                                                                               | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sort-keys-length](https://www.npmjs.com/package/sort-keys-length)                                                         | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sort-keys](https://www.npmjs.com/package/sort-keys)                                                                       | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sort-keys](https://www.npmjs.com/package/sort-keys)                                                                       | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [source-map-js](https://www.npmjs.com/package/source-map-js)                                                               | 1.2.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [source-map-support](https://www.npmjs.com/package/source-map-support)                                                     | 0.5.21       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [source-map](https://www.npmjs.com/package/source-map)                                                                     | 0.5.7        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [source-map](https://www.npmjs.com/package/source-map)                                                                     | 0.6.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [sourcemap-codec](https://www.npmjs.com/package/sourcemap-codec)                                                           | 1.4.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [stable](https://www.npmjs.com/package/stable)                                                                             | 0.1.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [strict-uri-encode](https://www.npmjs.com/package/strict-uri-encode)                                                       | 1.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [string\_decoder](https://www.npmjs.com/package/string_decoder)                                                            | 1.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [strip-dirs](https://www.npmjs.com/package/strip-dirs)                                                                     | 2.1.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [strip-eof](https://www.npmjs.com/package/strip-eof)                                                                       | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [strip-final-newline](https://www.npmjs.com/package/strip-final-newline)                                                   | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [strip-outer](https://www.npmjs.com/package/strip-outer)                                                                   | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [strnum](https://www.npmjs.com/package/strnum)                                                                             | 1.1.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [stylis](https://www.npmjs.com/package/stylis)                                                                             | 4.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [supports-color](https://www.npmjs.com/package/supports-color)                                                             | 8.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [supports-preserve-symlinks-flag](https://www.npmjs.com/package/supports-preserve-symlinks-flag)                           | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [svgo-loader](https://www.npmjs.com/package/svgo-loader)                                                                   | 4.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [svgo](https://www.npmjs.com/package/svgo)                                                                                 | 2.8.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [svgo](https://www.npmjs.com/package/svgo)                                                                                 | 3.3.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sync-child-process](https://www.npmjs.com/package/sync-child-process)                                                     | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [sync-message-port](https://www.npmjs.com/package/sync-message-port)                                                       | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tapable](https://www.npmjs.com/package/tapable)                                                                           | 2.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tar-stream](https://www.npmjs.com/package/tar-stream)                                                                     | 1.6.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [temp-dir](https://www.npmjs.com/package/temp-dir)                                                                         | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tempfile](https://www.npmjs.com/package/tempfile)                                                                         | 2.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [terser-webpack-plugin](https://www.npmjs.com/package/terser-webpack-plugin)                                               | 5.3.14       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [terser](https://www.npmjs.com/package/terser)                                                                             | 5.39.0       | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [through](https://www.npmjs.com/package/through)                                                                           | 2.3.8        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [timed-out](https://www.npmjs.com/package/timed-out)                                                                       | 4.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tiny-case](https://www.npmjs.com/package/tiny-case)                                                                       | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tiny-warning](https://www.npmjs.com/package/tiny-warning)                                                                 | 1.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [to-buffer](https://www.npmjs.com/package/to-buffer)                                                                       | 1.1.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [to-regex-range](https://www.npmjs.com/package/to-regex-range)                                                             | 5.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [toposort](https://www.npmjs.com/package/toposort)                                                                         | 2.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tr46](https://www.npmjs.com/package/tr46)                                                                                 | 0.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [trim-repeated](https://www.npmjs.com/package/trim-repeated)                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [tslib](https://www.npmjs.com/package/tslib)                                                                               | 2.8.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [tunnel-agent](https://www.npmjs.com/package/tunnel-agent)                                                                 | 0.6.0        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [type-fest](https://www.npmjs.com/package/type-fest)                                                                       | 0.11.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [type-fest](https://www.npmjs.com/package/type-fest)                                                                       | 2.19.0       | [CC0-1.0](https://creativecommons.org/publicdomain/zero/1.0/)                                                     |
| [typescript](https://www.npmjs.com/package/typescript)                                                                     | 2.9.2        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [ua-parser-js](https://www.npmjs.com/package/ua-parser-js)                                                                 | 1.0.40       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [unbzip2-stream](https://www.npmjs.com/package/unbzip2-stream)                                                             | 1.4.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [undici-types](https://www.npmjs.com/package/undici-types)                                                                 | 6.20.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [update-browserslist-db](https://www.npmjs.com/package/update-browserslist-db)                                             | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [uri-js](https://www.npmjs.com/package/uri-js)                                                                             | 4.4.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [url-parse-lax](https://www.npmjs.com/package/url-parse-lax)                                                               | 1.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [url-parse-lax](https://www.npmjs.com/package/url-parse-lax)                                                               | 3.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [url-to-options](https://www.npmjs.com/package/url-to-options)                                                             | 1.0.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-callback-ref](https://www.npmjs.com/package/use-callback-ref)                                                         | 1.3.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-composed-ref](https://www.npmjs.com/package/use-composed-ref)                                                         | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-isomorphic-layout-effect](https://www.npmjs.com/package/use-isomorphic-layout-effect)                                 | 1.2.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-isomorphic-layout-effect](https://www.npmjs.com/package/use-isomorphic-layout-effect)                                 | 1.2.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-latest](https://www.npmjs.com/package/use-latest)                                                                     | 1.3.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-sidecar](https://www.npmjs.com/package/use-sidecar)                                                                   | 1.1.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [use-sync-external-store](https://www.npmjs.com/package/use-sync-external-store)                                           | 1.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [util-deprecate](https://www.npmjs.com/package/util-deprecate)                                                             | 1.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [uuid](https://www.npmjs.com/package/uuid)                                                                                 | 3.4.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [varint](https://www.npmjs.com/package/varint)                                                                             | 6.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [warning](https://www.npmjs.com/package/warning)                                                                           | 4.0.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [watchpack](https://www.npmjs.com/package/watchpack)                                                                       | 2.4.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [web-vitals](https://www.npmjs.com/package/web-vitals)                                                                     | 2.1.4        | [Apache-2.0](https://www.apache.org/licenses/LICENSE-2.0)                                                         |
| [webidl-conversions](https://www.npmjs.com/package/webidl-conversions)                                                     | 3.0.1        | [BSD-2-Clause](https://opensource.org/licenses/BSD-2-Clause)                                                      |
| [webpack-sources](https://www.npmjs.com/package/webpack-sources)                                                           | 3.2.3        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [webpack](https://www.npmjs.com/package/webpack)                                                                           | 5.98.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [whatwg-url](https://www.npmjs.com/package/whatwg-url)                                                                     | 5.0.0        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [which](https://www.npmjs.com/package/which)                                                                               | 1.3.1        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [which](https://www.npmjs.com/package/which)                                                                               | 2.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [wrappy](https://www.npmjs.com/package/wrappy)                                                                             | 1.0.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [xtend](https://www.npmjs.com/package/xtend)                                                                               | 4.0.2        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [yallist](https://www.npmjs.com/package/yallist)                                                                           | 2.1.2        | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [yaml](https://www.npmjs.com/package/yaml)                                                                                 | 1.10.2       | [ISC](https://opensource.org/licenses/ISC)                                                                        |
| [yauzl](https://www.npmjs.com/package/yauzl)                                                                               | 2.10.0       | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [yup](https://www.npmjs.com/package/yup)                                                                                   | 1.6.1        | [MIT](https://opensource.org/licenses/MIT)                                                                        |
| [zustand](https://www.npmjs.com/package/zustand)                                                                           | 4.5.6        | [MIT](https://opensource.org/licenses/MIT)                                                                        |


# Version 1.10


# Getting Started


# Canton Network Introduction

## What is Canton?

Canton is a Daml ledger interoperability protocol. Parties hosted on different participant nodes can transact using smart contracts written in Daml and the Canton protocol.

The Canton protocol allows connecting different Daml ledgers into a single virtual global ledger. Daml, as the smart contract language, defines who is entitled to see and who is authorized to change any given contract.

The Canton synchronization protocol enforces these visibility and authorization rules, and ensures that data is shared reliably with very high levels of privacy, even in the presence of malicious actors. The Canton network can be extended without friction with new parties, ledgers, and applications building on other applications. Extensions require neither a central managing entity nor consensus within the global network.

## Benefits of Canton Network

### Distributed Apps from Scratch

Building distributed applications from scratch offers numerous advantages, including improved workflow automation, reduced errors, enhanced security, and effective auditing in regulated industries.

To build an application that automates a cross-organization workflow, one must devise and correctly implement a set of rules for exchanging data (i.e., a communication protocol). Today's standards help with transporting data (e.g., REST, gRPC) and describing its shape (e.g., XML schemas, session types), as well as handling authentication (e.g., X.509, TLS). But implementing the protocol logic remains a non-trivial task. For example, an estimated 10% of the trade volume in stock markets is subject to manual intervention (reconciliation), due to mismatches and mistakes in interpreting the exchanged data.

A smart contract platform solves the problem of diverging implementations by providing a shared data encoding and execution logic for the protocol. The security of cross-organization distributed applications critically depends on proper authorization, and Canton's design addresses this from the ground up.

### Integrating Applications

Business workflows often need to be composed into higher-level workflows, but their software implementations typically do not easily achieve the desired properties. For instance, in a travel agency workflow that combines booking a flight and a hotel, it is crucial to ensure atomicity of distributed transactions — the flight and hotel should be booked together or not at all.

This atomicity is only possible if both the airline and the hotel systems build in specific and compatible support for it. Standards such as X/Open XA exist, but they have to be correctly implemented by all involved subsystems, including their off-the-shelf components. Canton provides this coordination natively.

### Scalability

Platforms relying on proof-of-work blockchains sacrifice scalability: their throughput is typically limited to tens of transactions per second, and the historic data required to use the platform securely often grows unboundedly with time.

Canton avoids replicating a global shared state at all participants. State changes are only shared with the participants who need to see them, which removes the global throughput cap and enables horizontal scaling.

### Privacy

A global shared state is also a privacy leak that is unacceptable for use cases such as handling trade secrets, financial data, or healthcare. It also clashes with the data minimization requirements of the EU General Data Protection Regulation (GDPR).

Canton enforces that each participant only receives the subset of data it is entitled to see, with no encrypted copies of other parties' data stored locally. This subtransaction-level privacy model makes Canton suitable for regulated industries without requiring expensive cryptographic techniques.

{% hint style="info" %}
For more information, see the [Daml official documentation](https://docs.daml.com/).
{% endhint %}


# Canton Component Overview

## Domains

A Canton domain consists of three entities: Sequencers, Mediators, and a Topology Manager. These are collectively called the **domain entities**.

![Canton Domain Entities Diagram](https://docs.daml.com/_images/canton-domain-diagram.svg)

In general, every domain entity can run in a separate trust domain (i.e., can be operated by an independent organization). In practice, all domain entities are typically run by a single organization. Each participant node runs in its own trust domain.

The generic term **member** refers to either a domain entity or a participant node.

### Sequencer

#### Ordering

The sequencer provides a global total-order multicast where messages are uniquely time-stamped and the global ordering is derived from the timestamps. Instead of delivering a single message, the sequencer provides message batching — a list of individual messages are submitted, and all messages in a batch receive the same timestamp. Each message may have a different set of recipients.

#### Evidence

The sequencer provides recipients with a cryptographic proof of authenticity for every message batch it delivers, including evidence on the order of batches.

#### Sender and Recipient Privacy

Recipients do not learn the identity of the submitting participant. A recipient only learns the identities of recipients on a particular message from a batch if it is itself a recipient of that message.

### Mediator

The mediator computes the final result for a confirmation request and distributes it to participants, ensuring that transactions are atomically committed across participants while preserving privacy. At a high level, the mediator:

1. Collects confirmation responses from participants
2. Validates them according to the Canton protocol
3. Computes the conclusions (approve / reject / timed out) according to the confirmation policy
4. Sends the result message

Additionally, for auditability, the mediator persists every received message in long-term storage.

### Topology Manager

The topology manager allows participants to join and leave the Canton domain, and to register, revoke, and rotate public keys. It tracks the parties **hosted** by a given participant and defines the **trust level** of each participant (ordinary or VIP).

## Participant-Internal Canton Components

Canton uses the Daml-on-X architecture to promote code reuse. The participant node is broken down into a set of services, with the Canton-specific service being the Ledger Synchronization Service (LSS).

![Participant-internal Canton Components](https://docs.daml.com/_images/canton-participant-components.svg)

### Transactions

This is the central component of LSS within Canton.

**Submission and Segregation:** Each recipient obtains only the subtransaction (projection) it is entitled to see; other parts of the transaction are never shared with the participant, not even in encrypted form. The submitter also informs the mediator about the informees and confirmers of the transaction.

**Validity and Confirmation Responses:** Each informee of a requested transaction performs local checks on the validity of its visible subtransaction, confirming that it conforms to Daml semantics and the ledger authorization model.

**Confirmation Result Processing:** Based on the result message from the mediator, the transaction component commits or aborts the requested transaction.

### Sequencer Client

The sequencer client handles the connection to the sequencer, ensures in-order delivery, and stores the cryptographic proofs of authenticity for messages from the sequencer.

### Identity Client

The identity client handles messages coming from the domain topology manager and verifies the validity of received identity information changes.

## Applications

A DAML application is an application developed using the DAML programming language. DAML applications treat every action as an asynchronous operation, and contention is considered a natural and expected occurrence. Key design considerations include:

* Bundling or batching business logic to increase transaction throughput
* Maximizing parallelism through sharding
* Avoiding large sets of observers that can hinder parallelism
* Splitting contracts across natural lines to reduce contention

The diagram below shows the components often used in a DAML deployment. High availability is achieved via active-active (HTTP JSON API Service, sequencer) or active-passive (participant node, mediator) clustering.

![DAML components](https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-356de63516963abb970426028403aa97357fbf1d%2Fcreate%20apps%20intro.png?alt=media)

## Collections

A collection is a workspace area within Catalyst where files containing Daml models, triggers, automation, and UI assets can be uploaded and managed. Collections act as a centralized repository, making it convenient to deploy and redeploy these files across multiple ledgers.

## Validators

A validator in the Canton network is a specialized node responsible for validating transactions. Validators operate as part of a broader network that may include both standard validators and super validators. Super validators have additional responsibilities, such as dictating network policies and approving the addition of new validators.

As a participant in the network, validators can earn Canton coins as rewards for their services. These tokens can be used to pay for network services, transfer within the network, or manage traffic costs via the integrated wallet. Validators can also register custom names using the Canton Name Server (CNS) or Amulet Name Server (ANS).


# Network & Node Management


# Domains

## What is a Domain?

In a composed solution, each domain is a sub-network. A Participant Node connects to one or more Domains, enabling transactions that span Domains.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-7d8fd36a0df45341369bd440cbcb87cf0d66f11e%2Fimage%20(16).png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
For more information about Participants, see [Participants](broken://pages/f453801a9ef8c6d071dc979a0a384cc648c8fdd5).
{% endhint %}

## How Do I Create a Domain?

To create a Domain, go to the **Domains** tab and click the **Create** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-838226eb09dce4eb8c8419bd6626e7f920a587ad%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Provide a Domain name**

Enter a unique Domain name (required).
{% endstep %}

{% step %}
**Fill in the main settings**

{% hint style="info" %}
Using a predefined image is recommended for compatibility. If you want to use an image from a private repository, specify an `imagePullSecret`. You can create an `imagePullSecret` in your Kubernetes cluster and reference it by name here.
{% endhint %}

* Choose domain image
* Enable **Daemon** if required
* Enable **Ingress** if required
* **Resources allocation:**
  * **Requested CPU** — Guaranteed CPU resources that will be allocated
  * **CPU limit** — Maximum CPU resources that will be allocated
  * **Requested memory (MB)** — Guaranteed amount of RAM that will be allocated
  * **Memory limit (MB)** — Maximum amount of RAM that can be allocated
  * **Storage size**
* You can add custom environment variables if needed
  {% endstep %}

{% step %}
**Fill in Topology**

* Enable **Embedded Topology** if needed
* **Topology:**
  * Choose between form or raw view topology
  * Choose **Admin Port**
  * Choose **Public port**
  * Choose **Storage type:**

{% tabs %}
{% tab title="Memory" %}
No additional configuration required.
{% endtab %}

{% tab title="PostgreSQL" %}
A PostgreSQL database will be provisioned in the cluster.

* Choose User
* Choose Password
* Choose Storage size

{% hint style="info" %}
When selecting PostgreSQL, a postgres database will be provisioned in the cluster.
{% endhint %}
{% endtab %}

{% tab title="External" %}
A database is expected to be hosted at the given hostname and port, with the same name as the domain and a user with the provided credentials.

* Choose User
* Choose Password
* Choose Hostname
* Choose Port
  {% endtab %}
  {% endtabs %}
  {% endstep %}

{% step %}
**Bootstrap (optional)**

Provide bootstrap commands if needed.
{% endstep %}
{% endstepper %}


# Participants

## What is a Participant?

Each party of the application is hosted on a **Participant Node**. The Participant Node stores the party's unique projection and history of the shared system of record. Participant Nodes synchronize by running a consensus protocol (the Canton Protocol) between them, sending encrypted messages through Domains that provide guaranteed delivery and order consistency.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-1006ae8784552623fc8cfdb7d5794acce70b29b6%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
For more information about Domains, see [Domains](broken://pages/f7e3c63a81a45de7413b96ef8af9d441e59cf30a).
{% endhint %}

## How Do I Create a Participant?

To create a Participant, go to the **Participants** tab and click the **Create** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-5da6be03d5a80abc0e6957146ce4bfdba6f7ed99%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Provide a Participant name**

Enter a unique Participant name (required).
{% endstep %}

{% step %}
**Fill in the main settings**

{% hint style="info" %}
Using a predefined image is recommended for compatibility. If you want to use an image from a private repository, specify an `imagePullSecret`.
{% endhint %}

* Choose participant image
* Choose DAR files to upload
* Enable **Navigator** if required
* Enable **Daemon** if required
* **Resources allocation:**
  * **Requested CPU** — Guaranteed CPU resources that will be allocated
  * **CPU limit** — Maximum CPU resources that will be allocated
  * **Requested memory (MB)** — Guaranteed amount of RAM that will be allocated
  * **Memory limit (MB)** — Maximum amount of RAM that can be allocated
  * **Storage size**
* You can add custom environment variables if needed
  {% endstep %}

{% step %}
**Fill in Topology**

* Enable **Embedded Topology** if needed
* **Topology:**
  * Choose between form or raw view topology
  * Choose **Admin Port**
  * Choose **Public port**
  * Choose **Storage type:**

{% tabs %}
{% tab title="Memory" %}
No additional configuration required.
{% endtab %}

{% tab title="PostgreSQL" %}
A postgres database will be provisioned in the cluster.

* Choose User
* Choose Password
* Choose Storage size
  {% endtab %}

{% tab title="External" %}
A database is expected to be hosted at the given hostname and port with the same name as the participant and a user with the provided credentials.

* Choose User

* Choose Password

* Choose Hostname

* Choose Port
  {% endtab %}
  {% endtabs %}

* Enable **Authorization Service** if needed
  {% endstep %}

{% step %}
**Bootstrap (optional)**

Provide bootstrap commands if needed.
{% endstep %}
{% endstepper %}

## How Do I Connect a Participant to a Domain?

After the participant is created, click the **Connect to domain** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-3d775b8d306f9b9b3b46a1ad9919500014af6b89%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Select either a domain available in this Catalyst Canton console, or connect to any external domain by providing the full domain URL.
{% endhint %}

## How Do I Upload DAR Files to a Participant?

After the participant is created, click the **Upload DAR** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-db1431cf26d96ed22fc9bad2bcef89618dfb1779%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Select one or multiple DAR files to upload to the participant. DAR files can be added to the console through the [Collections](broken://pages/c3e32623075cd946e177c2021c1dada1b8ba346f) tab.
{% endhint %}

## Parties

A Party is created by default once a Participant is connected to a Domain. However, Catalyst Blockchain Manager allows you to add additional parties on a participant node.

### Add Party

In the Participants menu, under the **Parties** section, click **Add party**, set the name, and click **Save**.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-490e40cf7dee1b750a510333de58f80605787d6f%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

## User Management

Catalyst Blockchain Manager allows you to manage the user accounts that interact as part of a Party.

### Create a User

In the Participants menu, under the **Users** section, click **Create user** and select the Primary Party this new user belongs to.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-77b7023d2d2cb2ebb4d451f273d40a3d1c586ee0%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

If the new User has admin rights, select the **ParticipantAdmin** checkbox. Otherwise, select the type of right for which party:

* **CanActAs** — The User can interact as the selected Party
* **CanReadAs** — The User has read-only rights but cannot interact on behalf of the Party

### Manage Users

Navigate to the Participants menu, under the **Users** section, and select the action to perform from the right-hand menu column.


# Applications

Custom applications can be deployed through the Applications tab. This can be any backend or frontend process, including DAML apps.

## How Do I Create an Application?

To create an application, go to the **Applications** tab and click the **Create** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-5d1b4af0921b3b5b35aad2d05415b80e04a19d9e%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Provide an Application name**

Enter a unique Application name (required).
{% endstep %}

{% step %}
**Fill in the main settings**

Applications can have a **UI** or **Backend** type.

{% tabs %}
{% tab title="UI Application" %}
When deploying a UI application, choose between providing an image for the application or selecting one of the previously uploaded UI files (uploaded through the [Collections](broken://pages/c3e32623075cd946e177c2021c1dada1b8ba346f) tab).

{% hint style="info" %}
When selecting a UI file to deploy, the image field will be ignored. The UI application will be served by a nginx server.
{% endhint %}
{% endtab %}

{% tab title="Backend Application" %}
Provide a Docker image for the backend application.
{% endtab %}
{% endtabs %}

* Choose **Application Type**
* Choose **application image** (or file if UI app and not using an image)
* Choose **Port**
* Choose **Subdomain:**
  * Select subdomain from existing participants
  * Choose custom subdomain
* **Resources allocation:**
  * **Requested CPU** — Guaranteed CPU resources that will be allocated
  * **CPU limit** — Maximum CPU resources that will be allocated
  * **Requested memory (MB)** — Guaranteed amount of RAM that will be allocated
  * **Memory limit (MB)** — Maximum amount of RAM that can be allocated
* You can add custom environment variables if needed
  {% endstep %}
  {% endstepper %}


# Collections

## My Collection

In the **My Collection** tab, DAR packages and UI packages can be uploaded to the console. These can then be uploaded to participants or deployed as applications respectively.

### DAR Collections

When a Daml project is compiled, the compiler produces a Daml archive. These are platform-independent packages of compiled Daml code that can be uploaded to a Daml ledger or imported in other Daml projects. Daml archives have a `.dar` file ending.

{% hint style="info" %}
DAR files can be uploaded from the user's local computer, or obtained from the Canton Package Manager (CPM).

To read about CPM interaction, see the Canton Package Manager section of this guide.
{% endhint %}

#### Upload a DAR file

To upload a DAR file, go to the **Collections** tab and click **Upload DAR File** to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-2c73f3eee4e975da6492b80c7cdaf4842bc94502%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

### UI Collections

The UI Collections feature of Catalyst allows you to provide a frontend for your app by publishing files exposed by HTTPS over a ledger-specific subdomain.

{% hint style="warning" %}
UI Collections must be uploaded to the console and deployed in the form of `.zip` files. The `.zip` should contain a single root directory, and the contents of that directory should contain an `index.html` along with the rest of the resources for your UI.
{% endhint %}

To upload a UI file, go to the **Collections** tab and click **Upload UI File** to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-66b85e03a4f5d7582dbd94df855be4fc7b01a812%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>


# Rest API

Please consult the following link for the full REST API reference documentation:

[REST API Reference (v1.10)](attachment:api-docv1.10.html)

{% hint style="info" %}
The REST API documentation is provided as an attached HTML file. Contact IntellectEU if you need access to the latest version.
{% endhint %}


# Networking

In Catalyst, processes can communicate in multiple ways. In-cluster communication is facilitated by Kubernetes internal DNS names. Certain services or endpoints are also exposed through ingress routes.

## Participants

For every participant running on Catalyst, the following internal endpoints are available:

| Endpoint                     | Address                                                                |
| ---------------------------- | ---------------------------------------------------------------------- |
| **Ledger API**               | `<canton-participant-name>.<namespace>.svc.cluster.local:5011`         |
| **Admin API**                | `<canton-participant-name>.<namespace>.svc.cluster.local:5019`         |
| **HTTP JSON API (internal)** | `jsonapi-<canton-participant-name>.<namespace>.svc.cluster.local:7011` |
| **HTTP JSON API (external)** | `http(s)://<canton-participant-name>.<your-domain>`                    |

{% hint style="info" %}
Default ports are shown above. If you set custom ports when creating a participant, the values will differ.
{% endhint %}

## Domains

For every domain running on Catalyst, the following internal endpoints are available:

| Endpoint                 | Address                                                   |
| ------------------------ | --------------------------------------------------------- |
| **Public API**           | `<canton-domain-name>.<namespace>.svc.cluster.local:5018` |
| **Admin API**            | `<canton-domain-name>.<namespace>.svc.cluster.local:5019` |
| **Ingress (if enabled)** | `http(s)://<canton-domain-name>.<your-domain>`            |

{% hint style="info" %}
Default ports are shown above. If you set custom ports when creating a domain, the values will differ.
{% endhint %}

## Applications

For every application running on Catalyst, the following endpoints are available:

| Type             | Address                                                      |
| ---------------- | ------------------------------------------------------------ |
| **Internal**     | `<application-name>.<namespace>.svc.cluster.local:80`        |
| **Backend app**  | `http(s)://<subdomain>.<your-domain>/<application-name>/api` |
| **Frontend app** | `http(s)://<subdomain>.<your-domain>/<application-name>`     |

{% hint style="info" %}
The default port (80) is used above. If you set a custom port when creating an application, the value will differ.
{% endhint %}


# Validator Management


# Create Validator with Integrated Keycloak

{% hint style="info" %}
This guide is for the **Default** authentication option with integrated Keycloak. To set up a validator with a custom identity provider, see [Create Validator with Custom Identity Provider](broken://pages/9844ff1963d140a1f9c290677670d71bb72d16d0).
{% endhint %}

## Validator Management

Validators can be deployed on Catalyst and seamlessly connected to the Canton Network.

### Set Up a Validator

To set up a Validator, go to the **Validators** tab and click the **Set up validator** button to open a side window.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-f708491149ce1eb68f93592f014e924b78aba185%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
For further details, expand the collapsible **"More Info"** sections on each step.
{% endhint %}

{% stepper %}
{% step %}
**Main Settings Configuration**

Provide the following information:

* Name
* Onboard secret
* Image tag
* Image repo
* Image pull secret
* Postgres user
* Postgres password

<details>

<summary>More info about these fields</summary>

| Field                 | Description                                                                                         |
| --------------------- | --------------------------------------------------------------------------------------------------- |
| **Name**              | The identifier or label for the validator node                                                      |
| **Onboard secret**    | Passphrase obtained from the super validator in order to join the network                           |
| **Image tag**         | The specific version or tag of the container image to be used                                       |
| **Image repo**        | The repository where the container image is stored                                                  |
| **Image pull secret** | Credentials required to pull the container image from a private registry (`secret docker-registry`) |
| **Postgres user**     | Username for the Postgres database used by the validator                                            |
| **Postgres password** | Password for the Postgres database user                                                             |

</details>

{% hint style="info" %}
An onboarding secret should be requested from your sponsoring SV in order to join the network.
{% endhint %}

{% hint style="danger" %}
Do **not** set the Custom Authentication flag on — these instructions are for integrated Keycloak configuration. To use a custom identity provider, see [Create Validator with Custom Identity Provider](broken://pages/9844ff1963d140a1f9c290677670d71bb72d16d0).
{% endhint %}
{% endstep %}

{% step %}
**Cluster Configuration**

**2.1 — Enable or disable:**

* Enable wallet
* Fail on app version mismatch
* Use sequencer connections from scan

**2.2 — Fill in the remaining fields:**

* Cluster URL
* Disable wallet
* Fail on app version mismatch
* Scan address
* SV Sponsor Address
* Party hint
* Default JVM Options
* Migration: Id
* Top up: Enable, Top up min interval, Target throughput

**2.3 — Enable or disable:**

* Participant identities dump import
* Participant identities dump periodic backup

<details>

<summary>More info about these fields</summary>

| Field                            | Description                                                                                                         |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------- |
| **Cluster URL**                  | URL of the Kubernetes cluster where the validator is deployed. Used for looking up directory entries in the scan UI |
| **Disable wallet**               | Turn on to not deploy a wallet UI with your validator                                                               |
| **Fail on app version mismatch** | If enabled, deployment fails on validator/network version mismatch                                                  |
| **Scan address**                 | Address used for scanning and retrieving validator-related data                                                     |
| **SV Sponsor Address**           | URL of the SV app of the super validator sponsoring you (starts with `https://sv.sv-N`)                             |
| **Party hint**                   | Prefix for the Party ID. Format: `<organization>-<function>-<enumerator>`, e.g., `myCompany-myWallet-1`             |
| **Default JVM Options**          | Default JVM configuration options for the validator                                                                 |
| **Migration Id**                 | Starts at `0` for initial deployment, increments by 1 with each migration                                           |
| **Attach PVC**                   | Attach a Persistent Volume Claim for data persistence during migration (recommended)                                |
| **Migrating**                    | Set to `true` when upgrading to trigger the migration process                                                       |

</details>
{% endstep %}

{% step %}
**Cluster Participant Configuration**

* Insert your default JVM configurations
* Enable or disable: **Enable health probes**
* Insert your **Node Identifier**

<details>

<summary>More info about these fields</summary>

| Field                    | Description                                                   |
| ------------------------ | ------------------------------------------------------------- |
| **Node identifier**      | A unique identifier for the validator node within the network |
| **Enable health probes** | Turns on health checks to monitor the validator's status      |
| **Default JVM Options**  | Default JVM configuration options for the validator           |

</details>
{% endstep %}

{% step %}
**Configure Resources**

* Requested CPU
* CPU limit
* Requested memory
* Memory limit
* Replicas

<details>

<summary>More info about these fields</summary>

| Field                | Description                     |
| -------------------- | ------------------------------- |
| **Requested CPU**    | Minimum CPU resources requested |
| **CPU limit**        | Maximum CPU resources allowed   |
| **Requested memory** | Minimum memory requested        |
| **Memory limit**     | Maximum memory allowed          |
| **Replicas**         | Number of instances to run      |

</details>
{% endstep %}

{% step %}
**Configure Environment Variables**

Override environment variables for:

* Participant node
* Validator backend
* Canton Name Service UI
* Wallet UI

{% hint style="danger" %}
This is a very specific configuration. If you are not sure about this step, please contact IntellectEU.
{% endhint %}
{% endstep %}

{% step %}
**Summary**

Review your Validator configuration. Click **Confirm** to finalize and proceed with the deployment.
{% endstep %}

{% step %}
**Create a Permanent Password in Keycloak**

To access the wallet UI, you must first define a new password in Keycloak.

{% stepper %}
{% step %}
Save the credentials displayed in the pop-up window.
{% endstep %}

{% step %}
Once your node is up and running, click on the last link containing `wallet-web-ui`, then click the link at the top left of the screen.
{% endstep %}

{% step %}
A pop-up will ask you to re-authenticate. Close your session by clicking **Log out**.
{% endstep %}

{% step %}
Insert the temporary credentials saved in the previous step.
{% endstep %}

{% step %}
Define a new password and click **Submit**. You will be forwarded to the wallet UI console of your new Validator.
{% endstep %}
{% endstepper %}
{% endstep %}
{% endstepper %}

***

## Identity and Access Management

As part of the validator provisioning process, Keycloak is set as the identity provider. Each validator is assigned a dedicated user (`$VALIDATOR_NAME_walletuser`) within the `validator` realm.

{% hint style="danger" %}
We strongly recommend updating the password for this user after the initial setup to maintain security.
{% endhint %}

### Resetting the Wallet User Password in Keycloak

{% stepper %}
{% step %}
**Log in to the Keycloak admin console**

* **URL:** `https://<your-keycloak-domain>/auth/admin/`
* Use an account with administrative access.
  {% endstep %}

{% step %}
**Navigate to the validator realm**

From the top-left dropdown, select **validator**, then find `$VALIDATOR_NAME_walletuser` under **Users**.
{% endstep %}

{% step %}
**Reset the password**

Navigate to the **Credentials** tab, enter a new password, toggle **Temporary** to **OFF**, and click **Reset Password**.

{% hint style="warning" %}
Store the new password securely and update any dependent services or configuration files if needed.
{% endhint %}
{% endstep %}
{% endstepper %}

<details>

<summary>Additional Keycloak documentation resources</summary>

* [Keycloak Documentation – Managing Users](https://www.keycloak.org/docs/latest/server_admin/#admin-cli)
* [Keycloak Admin Console Guide](https://www.keycloak.org/docs/latest/server_admin/#admin-console)
* [Resetting Passwords via Admin Console](https://www.keycloak.org/docs/latest/server_admin/#resetting-passwords)

</details>


# Create Validator with Custom Identity Provider

{% hint style="info" %}
The alternative to this approach is using Integrated Keycloak, which automates the process as detailed in [Create Validator with Integrated Keycloak](broken://pages/f103cefdb6247b38919caf1c1aae134da2406c0c).
{% endhint %}

When installing Catalyst, it is configured with an Identity Provider used to authenticate Catalyst and the validators deployed through it.

This is a brief overview of how to set up Clients and Users in your Identity Provider before setting up the Validator. For a full description of requirements, consult the [Canton Validator OIDC requirements](https://network.canton.global/validator_operator/validator_helm.html#oidc-provider-requirements).

{% hint style="info" %}
The sections on secrets and other Kubernetes configuration can be ignored — Catalyst creates them. Clients and users need to be set up beforehand.
{% endhint %}

## Prerequisites: Configure Your Identity Provider

### Clients

The following clients are used by a Validator node and must be configured with the proper flows in your Identity Provider:

{% hint style="warning" %}
It is recommended to allow all audiences for the clients when creating the validator. These can be restricted later once Catalyst generates the URLs.
{% endhint %}

| Validator Component | OpenID Flow              | Fields required by Catalyst |
| ------------------- | ------------------------ | --------------------------- |
| Validator           | Client Credentials Grant | Client Id, Client secret    |
| Canton Name Service | Authorization Code       | Client Id                   |
| Wallet              | Authorization Code       | Client Id                   |

### Users

A single user needs to be created beforehand with access to the clients created.

{% hint style="info" %}
This user will be mapped to the main Validator party and will receive rewards, which can be viewed from the Wallet.
{% endhint %}

***

## Set Up a Validator

{% stepper %}
{% step %}

#### Main Settings Configuration

Provide the following information:

* Name, Onboard secret, Image tag, Image repo, Image pull secret
* Postgres user, Postgres password
* Requested CPU, CPU limit, Requested memory, Memory limit, Replicas

<details>

<summary>More info about these fields</summary>

| Field                 | Description                                                              |
| --------------------- | ------------------------------------------------------------------------ |
| **Name**              | The identifier or label for the validator node                           |
| **Onboard secret**    | Passphrase obtained from the super validator                             |
| **Image tag**         | The specific version or tag of the container image                       |
| **Image repo**        | The repository where the container image is stored                       |
| **Image pull secret** | Credentials required to pull the container image from a private registry |
| **Postgres user**     | Username for the Postgres database                                       |
| **Postgres password** | Password for the Postgres database user                                  |
| **Requested CPU**     | Minimum CPU resources requested                                          |
| **CPU limit**         | Maximum CPU resources allowed                                            |
| **Requested memory**  | Minimum memory requested                                                 |
| **Memory limit**      | Maximum memory allowed                                                   |
| **Replicas**          | Number of instances to run                                               |

</details>

{% hint style="info" %}
An onboarding secret should be requested from your sponsoring SV in order to join the network.
{% endhint %}

{% hint style="danger" %}
Make sure to set the **Custom Authentication** flag **ON**.
{% endhint %}

Now set the custom authentication fields:

* CNS Client Id
* Wallet Client Id
* Ledger API Client Id
* Ledger API Client Secret
* Ledger API User
* Wallet User
* Audience

<details>

<summary>More info about custom authentication fields</summary>

| Field                        | Description                                                               |
| ---------------------------- | ------------------------------------------------------------------------- |
| **CNS Client Id**            | Client for the Canton Name Service                                        |
| **Wallet Client Id**         | Client for the Wallet application                                         |
| **Ledger API Client Id**     | Client for the Validator                                                  |
| **Ledger API Client Secret** | Secret part of the Client Credentials Grant Flow for the Validator client |
| **Ledger API User**          | User of the components described above                                    |
| **Wallet User**              | User that will access the wallet application and receive rewards          |
| **Audience**                 | Audience claim expected by the clients                                    |

</details>

{% hint style="info" %}
The value for **Ledger API User** and **Wallet User** depends on the Identity Provider — use what the IdP puts as the `subject` field in the JWT token.
{% endhint %}
{% endstep %}

{% step %}

#### Cluster Configuration

**2.1 — Enable or disable:**

* Enable wallet
* Fail on app version mismatch
* Use sequencer connections from scan

**2.2 — Fill in the remaining fields:**

* Cluster URL, Disable wallet, Scan address, SV Sponsor Address, Party hint, Default JVM Options
* Migration: Id, Migrating
* Top up: Enable, Top up min interval, Target throughput

**2.3 — Enable or disable:**

* Participant identities dump import
* Participant identities dump periodic backup

<details>

<summary>More info about these fields</summary>

| Field                            | Description                                                      |
| -------------------------------- | ---------------------------------------------------------------- |
| **Cluster URL**                  | URL of the Kubernetes cluster where the validator is deployed    |
| **Disable wallet**               | Turn on to not deploy a wallet UI with your validator            |
| **Fail on app version mismatch** | Deployment fails on version mismatch if enabled                  |
| **Scan address**                 | Address used for scanning and retrieving validator-related data  |
| **SV Sponsor Address**           | URL of the SV app sponsoring you (starts with `https://sv.sv-N`) |
| **Party hint**                   | Prefix for the Party ID. Format: `<org>-<function>-<enumerator>` |
| **Default JVM Options**          | Default JVM configuration options                                |
| **Migrating**                    | Set to `true` when upgrading to trigger the migration process    |

</details>
{% endstep %}

{% step %}

#### Cluster Participant Configuration

* Insert your default JVM configurations
* Enable or disable: **Enable health probes**
* Insert your **Node Identifier**
  {% endstep %}

{% step %}

#### Configure Resources

* Requested CPU, CPU limit, Requested memory, Memory limit, Replicas
  {% endstep %}

{% step %}

#### Configure Environment Variables

Override environment variables for: Participant node, Validator backend, Canton Name Service UI, Wallet UI.

{% hint style="danger" %}
This is a very specific configuration. If you are not sure about this step, please contact IntellectEU.
{% endhint %}
{% endstep %}

{% step %}

#### Summary

Review your Validator configuration. Click **Confirm** to finalize and proceed with the deployment.
{% endstep %}
{% endstepper %}

***

## Identity and Access Management

In deployments where an external Identity Provider is used, your organization is responsible for managing user credentials and access controls.

{% hint style="danger" %}
We strongly recommend updating the password for the wallet user after the initial setup.
{% endhint %}

### Resetting the Wallet User Password

Refer to the official documentation for your IdP. Typical steps:

1. Log into your Identity Provider's admin portal.
2. Locate the user account associated with the validator (e.g., `$VALIDATOR_NAME_walletuser`).
3. Initiate a password reset or manual update from the user management section.
4. Disable any temporary password flags if you want to use the new password directly.
5. Update any validator configuration files or services that use this credential.

{% hint style="warning" %}
If your IdP integrates with federation or SSO, ensure policies and password propagation are correctly applied.
{% endhint %}

<details>

<summary>Common IdP documentation resources</summary>

* [Azure AD User Management](https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/)
* [Okta Admin Guide](https://help.okta.com/)
* [Auth0 Password Reset](https://auth0.com/docs/authenticate/login/password-reset)

</details>


# Backup and Recovery

This page explains how to back up the Parties of your Validator and how to restore from them. This prevents your Canton Coins from being lost.

## How to Create a New Identity Dump

{% hint style="danger" %}
When deleting the old deployment, make sure to set **Delete all resources** to **false** as displayed below.
{% endhint %}

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-2ef0e163e1ec383ac5ced8a51919ac1a3a7aecec%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>

{% stepper %}
{% step %}
**Go to the Validators tab**

Navigate to the **Validators** tab to see all your Validators.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-009d7f3a4ba5008d65e368be3472bbfd8ff1f6fd%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Click the dump icon**

Click on the dump icon of the validator you want to back up.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-5875c0a49598c5b3bfb3cea53edbe822a2198feb%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Provide your wallet user password**

A pop-up will appear asking you to provide your Validator wallet user password (stored when creating your validator).

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-43fc5cd43d75f343cc27d3b94a7d404892e178fc%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}

***

## How to Restore a Validator from an Identity Dump

{% stepper %}
{% step %}
**Click "Set up validator"**

From your Validators menu, click the **Set up validator** button.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-f708491149ce1eb68f93592f014e924b78aba185%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Enable "Restore participant identities"**

Enable the option to **Restore participant identities**.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-5bab6861395427456718fe99a464c73506fc0351%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Select your Identity Dump**

Select your Identity Dump and provide a new ID following the naming rules.
{% endstep %}

{% step %}
**Proceed as a new validator**

Proceed to create your validator as you would for a new one.

{% hint style="danger" %}
The fields used to configure the network access must be **identical** to the ones used on the Validator you are trying to restore.
{% endhint %}

{% hint style="info" %}
Check the [Validator Management](broken://pages/f103cefdb6247b38919caf1c1aae134da2406c0c) section for more details on how to set up a new validator.
{% endhint %}
{% endstep %}
{% endstepper %}


# Validator Custom Resource Definition

This document provides an overview of the **Validator Custom Resource Definition (CRD)** in the Catalyst Blockchain Manager Canton system. It outlines the structure of the CRD and the components it deploys.

## Structure of the Spec

The spec specifies every component needed to deploy a validator separately.

| Component            | CRD Location                            |
| -------------------- | --------------------------------------- |
| **Validator** (core) | Top level of the spec                   |
| **ANS/CNS UI**       | `spec.applicationCantonNameServer.spec` |
| **Wallet UI**        | `spec.walletUI.spec`                    |
| **Participant Node** | `spec.participant.spec`                 |

### Provisioned Postgres Database

The database that is created is not represented in the spec. To increase the volume size (decreases are ignored), use:

```yaml
spec.storageSize
```

## Changing Component Specifications

### Environment Variables

For all components, environment variables are present under `spec.envVars`. These can have the same format as in Pods and Deployments.

### Resources

All components have a resource specification:

```yaml
resources:
    cpuLimit: '2'
    cpuRequested: '1'
    imagePullSecret: intellecteu-gitlab-access
    memoryLimit: 2Gi
    memoryRequested: 1Gi
    replicas: 1
```

| Field             | Description                                    |
| ----------------- | ---------------------------------------------- |
| `cpuLimit`        | Maximum CPU allocation                         |
| `cpuRequested`    | Minimum CPU allocation                         |
| `memoryLimit`     | Maximum memory allocation                      |
| `memoryRequested` | Minimum memory allocation                      |
| `replicas`        | Number of instances (can be set to `0` or `1`) |

To scale down the validator, set every `replicas` field to `0`.

## Example CRD

<details>

<summary>Full example Validator CRD YAML</summary>

```yaml
apiVersion: catalyst.manager.canton/v1
kind: Validator
metadata:
  name: validator1st
  namespace: canton-dev
spec:
  application:
    spec:
      domain: participant-validator1st
      resources:
        cpuLimit: '2'
        cpuRequested: '1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 2Gi
        memoryRequested: 1Gi
        replicas: 1
      type: backend
      validatorParent: validator1st
  applicationCantonNameServer:
    spec:
      domain: cns-validator1st
      image: >-
        digitalasset-canton-network-docker.jfrog.io/digitalasset/ans-web-ui:0.3.15
      resources:
        cpuLimit: '1'
        cpuRequested: '0.1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 1536Mi
        memoryRequested: 240Mi
        replicas: 1
      type: ui
  applicationWallet:
    spec:
      domain: wallet-validator1st
      image: >-
        digitalasset-canton-network-docker.jfrog.io/digitalasset/wallet-web-ui:0.3.15
      resources:
        cpuLimit: '1'
        cpuRequested: '0.1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 1536Mi
        memoryRequested: 240Mi
        replicas: 1
      type: ui
  customAuth: false
  disableAutoInit: false
  image: digitalasset-canton-network-docker.jfrog.io/digitalasset/validator-app:0.3.15
  imageRepo: digitalasset-canton-network-docker.jfrog.io/digitalasset
  imageTag: 0.3.15
  migrationAttachPVC: 'false'
  migrationId: '0'
  migrationMigrating: false
  participant:
    spec:
      adminPort: '5002'
      auth: true
      authProvider: keycloak
      daemon: false
      enterprise: true
      ha: false
      image: >-
        digitalasset-canton-network-docker.jfrog.io/digitalasset/canton-participant:0.3.15
      jsonapi: false
      ledgerPort: '5001'
      logLevel: INFO
      navigator: false
      resources:
        cpuLimit: '2'
        cpuRequested: '1'
        imagePullSecret: intellecteu-gitlab-access
        memoryLimit: 2Gi
        memoryRequested: 1Gi
        replicas: 1
      storageType: Shared Postgres
  resources:
    cpuLimit: '2'
    cpuRequested: '1'
    imagePullSecret: intellecteu-gitlab-access
    memoryLimit: 2Gi
    memoryRequested: 1Gi
    replicas: 1
  storageSize: 20Gi
  walletEnabled: true
```

</details>


# Validator CRD User Guide

Catalyst uses the operator pattern with Custom Resource Definitions. The same operations available in the Catalyst GUI can also be performed directly on Kubernetes with cluster access.

## Creating a Validator

<details>

<summary>Full creation example (Kubernetes YAML)</summary>

```yaml
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: database-validator-dev-foo
data:
  user: "YWRtaW4="
  password: "YWRtaW4="
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-onboarding-validator
data:
  secret: "<onboarding-secret-base64>"
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-cns-ui-auth
data:
  url: "<keycloak-url-base64>"
  clientId: "<cns-client-id-base64>"
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-wallet-ui-auth
data:
  url: "<keycloak-url-base64>"
  clientId: "<wallet-client-id-base64>"
  username: "<wallet-username-base64>"
---
apiVersion: v1
kind: Secret
metadata:
  namespace: canton-dev
  name: cn-app-validator-dev-foo-ledger-api-auth
data:
  client-id: "<client-id-base64>"
  client-secret: "<client-secret-base64>"
  ledger-api-user: "<ledger-api-user-base64>"
  url: "<token-url-base64>"
---
apiVersion: catalyst.manager.canton/v1
kind: Validator
metadata:
  name: validator-dev-foo
  namespace: canton-dev
spec:
  config:
    scanAddress: "https://scan.sv-1.dev.global.canton.network.sync.global"
    svSponsorAddress: "https://sv.sv-1.dev.global.canton.network.sync.global"
    defaultJvmOptions: "-Xms1152M -Xmx1152M -Dscala.concurrent.context.minThreads=4"
    partyHint: ieu-foo-001
    failOnAppVersionMismatch: true
    database:
      port: 5432
      pwdField: password
      schema: validator
      secretName: database-validator-dev-foo
      userField: user
    participant:
      nodeIdentifier: IEUDevFoo001
  customAuth: true
  imageRepo: ghcr.io/digital-asset/decentralized-canton-sync/docker
  imageTag: 0.4.16
  migrationId: "0"
  migrationMigrating: false
  onboardingSecretName: cn-app-validator-dev-foo-onboarding-validator
  storageSize: 20Gi
```

</details>

{% hint style="info" %}
**Key notes:**

* The onboarding secret is one-time use.
* The validator name, participant identifier, and party hint should be changed for each new validator.
* Secrets are referenced inside the Validator definition — keep names in sync.
* Some values (e.g., `port`, `schema`) are set directly in the spec, not as secret references.
  {% endhint %}

## Validator Operations

### Migration

```yaml
spec:
  migrationId: "2"
  migrationMigrating: false
```

To migrate:

```yaml
spec:
  migrationId: "new mig id"
  migrationMigrating: true
```

Once migration is complete, set `migrationMigrating` back to `false`.

### Recovery from Identity Dump

Create a Kubernetes secret:

```yaml
apiVersion: v1
data:
  content: <Identity Backup>
kind: Secret
metadata:
  labels:
    validator: <validator crd name>
  name: id-backup-secret-example
  namespace: namespace-of-val
type: Opaque
```

Then create a validator with these additional fields:

```yaml
spec:
  particpant:
    nodeIdentifier: "validator-foooooooo"
  config:
    partyHint: "oldParty"
    identitiesImport:
      newParticipantIdentifier: "validator-foooooooo"
      secretName: "secret-with-identity-dump-party"
    isMigrateValidatorParty: true
```

{% hint style="warning" %}
The participant should have the same node identifier as `newParticipantIdentifier`, which must differ from the previous validator.
{% endhint %}

## Configuring the Validator

### Environment Variable Overrides

```yaml
spec:
  config:
    validatorOverrides:
      - name: OVERRIDE_EXAMPLE
        value: "5432"
    participantOverrides: []
    walletOverrides:
      - name: OVERRIDE_WITH_SECRET
        valueFrom:
          secretKeyRef:
            key: password
            name: secret
    cnsOverrides: []
```

{% hint style="info" %}
These overrides will **override** any variables generated by `spec.config`.

On upgrade to v1.10, a script generates `spec.config` fields from older `<app>.spec.envVars` format. The `<app>.spec.envVars` format will be removed in a future release.
{% endhint %}

### Resource Customization

```yaml
spec:
  application:
    spec:
      resources:
        cpuLimit: "4"
        cpuRequested: "2"
        memoryLimit: 8Gi
        memoryRequested: 4Gi
        replicas: 1
  applicationCantonNameServer:
    spec:
      resources:
        cpuLimit: "2"
        cpuRequested: "0.5"
        memoryLimit: 2Gi
        memoryRequested: 512Mi
        replicas: 1
  applicationWallet:
    spec:
      resources:
        cpuLimit: "2"
        cpuRequested: "0.5"
        memoryLimit: 2Gi
        memoryRequested: 512Mi
        replicas: 1
  participant:
    spec:
      resources:
        cpuLimit: "4"
        cpuRequested: "2"
        memoryLimit: 8Gi
        memoryRequested: 4Gi
        replicas: 1
  storageSize: 50Gi
```

### Other Configuration Examples

<details>

<summary>Enable top-up</summary>

```yaml
spec:
  config:
    topUp:
      enabled: true
      minInterval: 2m
      targetThroughput: 80000
```

</details>

<details>

<summary>Enable scheduled pruning</summary>

```yaml
spec:
  config:
    scheduledPrune:
      retention: "2m"
      cron: "* * * * *"
      maxDuration: "30d"
```

</details>

<details>

<summary>Provide additional config</summary>

```yaml
spec:
  config:
    additionalConfigOther: |
      canton.validator-apps.validator_backend.participant-bootstrapping-dump {
        type = file
        file = /participant-bootstrapping-dump/content
        new-participant-identifier = "validator-fooooooo"
      }
```

</details>

<details>

<summary>Set contact point</summary>

```yaml
spec:
  config:
    contactPoint: "mycompany@mail.com"
```

</details>


# Logging

## Component Logs

Catalyst displays logs for all running components on their main page. Logs are fetched from the Kubernetes API.

## How Logs Work

When you view a component, you see its log output. Each log entry includes a timestamp from the Kubernetes API.

## Navigating Logs

Scroll up and down through the log output. Scroll **down** to see newer entries, scroll **up** to see older ones.

## Log Formatting

Your logs can use any format. However, to enable level filtering, format your logs as JSON with a `level` field:

```json
{"level": "error", "message": "Connection failed"}
{"level": "info", "message": "Service started"}
```

When your logs follow this format, you can filter by severity level (info, warning, error, etc.).

## Searching Logs

Use the search field to find specific text within your loaded logs. The search works on logs currently displayed in your view. To search older logs, scroll up to load them first.

<figure><img src="https://2680825251-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FsUGPGTcyMu8FXsdY8XQY%2Fuploads%2Fgit-blob-d5ef54e2f3d6badd877d1936db0ee9d68fbbcdd1%2Fimage.png?alt=media" alt=""><figcaption></figcaption></figure>




---

[Next Page](/llms-full.txt/1)

