Access: FC ports and initiators
The Access view in one JSON document: every FC target port, the LUN table (identical on every port), and the initiator registry joined with live login state. Access is hard-deny: a WWPN that is not registered is refused at the kernel. Registry changes are applied to the live target configuration immediately, without touching other initiators’ sessions.
WWPNs are accepted in any of three forms (naa. prefixed, colon
separated, or bare 16 hex digits) and are stored and returned in the
naa. form.
GET /api/targets
Returns the whole access picture.
curl -sk https://appliance:8443/api/targets -H "Authorization: Bearer $OVTL_KEY"
{
"fc": {
"ports": [
{"host": "host12", "wwpn": "naa.2100000000000a01", "state": "Online", "speed": "8 Gbit", "serving": true, "built": true},
{"host": "host13", "wwpn": "naa.2100000000000a02", "state": "Linkdown", "speed": "unknown", "serving": true, "built": true}
],
"no_hba": false
},
"luns": [
{"lun": 0, "backstore": "changer10", "device": "/dev/sg3", "library": 10},
{"lun": 1, "backstore": "drive11", "device": "/dev/sg4", "library": 10},
{"lun": 2, "backstore": "drive12", "device": "/dev/sg5", "library": 10}
],
"libraries": [10],
"initiators": [
{"wwpn": "naa.10000000c9000001", "alias": "IBMI-PROD-P1", "fabric": "fc", "ports": "", "libraries": "", "created_at": "2026-08-31T00:02:11Z", "logged_in": true, "port_state": "Online", "applied": true}
]
}
| Field | Meaning |
|---|---|
fc.ports[].serving |
The port is included in the served set. built means its target configuration exists in the kernel right now. |
fc.no_hba |
No FC host port exists. Idle is the healthy state on a box without an HBA. |
luns[] |
The port-identical LUN table: one changer plus one LUN per drive, per library. |
initiators[].ports / libraries |
Scope, comma-joined. Empty string means all; - means none. |
initiators[].applied |
The ACL exists everywhere its scope says it should. |
unmanaged |
Present only if the kernel holds ACLs the registry does not know. They are reported, never deleted. |
error |
Present only if the LUN table or a live apply could not be computed. The registry change is still recorded. |
POST /api/targets/acls
Registers an initiator and applies it live. Default scope is all ports, all libraries.
| Body field | Type | Notes |
|---|---|---|
wwpn |
string | Required. Any of the three accepted forms. |
alias |
string | Optional display name. |
ports |
string[] | Optional. Omit for all ports. An empty list means no ports. |
libraries |
int[] | Optional library ids. Omit for all. An empty list means no libraries. |
curl -sk -X POST https://appliance:8443/api/targets/acls \
-H "Authorization: Bearer $OVTL_KEY" -H 'Content-Type: application/json' \
-d '{"wwpn":"10:00:00:00:c9:00:00:01","alias":"IBMI-PROD-P1","libraries":[10]}'
Returns the refreshed GET /api/targets view. 400 if the WWPN is
malformed or already registered. If the host is already logged into the
fabric, its session comes up the moment the ACL exists.
PUT /api/targets/acls/{wwpn}
Renames or rescopes a registered initiator and applies the change. The
scope rules are the same as on create. Changing the LUN map of a
logged-in initiator recreates its ACL, which bounces that host’s session
briefly. 404 for an unknown initiator.
curl -sk -X PUT https://appliance:8443/api/targets/acls/naa.10000000c9000001 \
-H "Authorization: Bearer $OVTL_KEY" -H 'Content-Type: application/json' \
-d '{"alias":"IBMI-PROD-P1","ports":["naa.2100000000000a01"],"libraries":[10]}'
DELETE /api/targets/acls/{wwpn}
Deregisters an initiator and applies. Refused with 400 while that
initiator has a live session, because removal drops the host mid-flight.
Pass ?force=1 to remove it anyway. 404 for an unknown initiator.
curl -sk -X DELETE "https://appliance:8443/api/targets/acls/naa.10000000c9000001?force=1" \
-H "Authorization: Bearer $OVTL_KEY"
PUT /api/targets/ports
Includes or excludes one FC port from serving. Disabling a port drops
every session on it. The exclusion list is persisted as the
fc.disabled_ports setting.
| Body field | Type | Notes |
|---|---|---|
wwn |
string | Required, naa. form only. |
serving |
bool | Required. |
curl -sk -X PUT https://appliance:8443/api/targets/ports \
-H "Authorization: Bearer $OVTL_KEY" -H 'Content-Type: application/json' \
-d '{"wwn":"naa.2100000000000a02","serving":false}'
Returns the refreshed GET /api/targets view.