Circleci Schema
graph LR
CircleCIContext -- HAS_ENV_VAR --> CircleCIContextEnvVar
CircleCIContext -- RESTRICTED_TO --> CircleCIProject
CircleCIOrganization -- RESOURCE --> CircleCIComponent
CircleCIOrganization -- RESOURCE --> CircleCIContext
CircleCIOrganization -- RESOURCE --> CircleCIContextEnvVar
CircleCIOrganization -- RESOURCE --> CircleCIEnvironment
CircleCIOrganization -- RESOURCE --> CircleCIGroup
CircleCIOrganization -- RESOURCE --> CircleCIOidcConfig
CircleCIOrganization -- RESOURCE --> CircleCIPolicy
CircleCIOrganization -- RESOURCE --> CircleCIProject
CircleCIPipeline -- HAS_TRIGGER --> CircleCITrigger
CircleCIProject -- HAS_COMPONENT --> CircleCIComponent
CircleCIProject -- RESOURCE --> CircleCICheckoutKey
CircleCIProject -- RESOURCE --> CircleCIPipeline
CircleCIProject -- RESOURCE --> CircleCIProjectEnvVar
CircleCIProject -- RESOURCE --> CircleCIProjectOidcConfig
CircleCIProject -- RESOURCE --> CircleCITrigger
CircleCIProject -- RESOURCE --> CircleCIWebhookCircleCICheckoutKey
A public checkout or deploy key for a CircleCI project.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | Synthesized CircleCI checkout key ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| created_at | Checkout key creation timestamp. | |
| fingerprint | Yes | Checkout key fingerprint. |
| preferred | Whether this is the preferred checkout key. | |
| project_slug | Slug of the owning CircleCI project. | |
| public_key | SSH public key. | |
| type | Checkout key type. |
Relationships
(:CircleCIProject)-[:RESOURCE]->(:CircleCICheckoutKey): The CircleCI project contains the checkout key.
CircleCIComponent
A deploy component in a CircleCI organization.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI component ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| created_at | Component creation timestamp. | |
| labels | Labels assigned to the component. | |
| name | Yes | Component name. |
| project_id | ID of the associated CircleCI project. | |
| release_count | Number of component releases. | |
| updated_at | Component update timestamp. |
Relationships
(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIComponent): The CircleCI organization contains the deploy component.(:CircleCIProject)-[:HAS_COMPONENT]->(:CircleCIComponent): The CircleCI project has the deploy component.
CircleCIContext
A CircleCI context containing shared environment variables.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI context ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| created_at | Context creation timestamp. | |
| name | Yes | Context name. |
Relationships
(:CircleCIContext)-[:HAS_ENV_VAR]->(:CircleCIContextEnvVar): The CircleCI context has the environment variable.(:CircleCIContext)-[:RESTRICTED_TO]->(:CircleCIProject): The context is restricted to the allowed CircleCI projects.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIContext): The CircleCI organization contains the context.
CircleCIContextEnvVar
A named environment variable in a CircleCI context.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | Synthesized context environment variable ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| context_id | ID of the owning context. | |
| created_at | Variable creation timestamp. | |
| updated_at | Variable update timestamp. | |
| variable | Yes | Environment variable name. |
Relationships
(:CircleCIContext)-[:HAS_ENV_VAR]->(:CircleCIContextEnvVar): The CircleCI context has the environment variable.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIContextEnvVar): The CircleCI organization contains the context environment variable.
CircleCIEnvironment
A deploy environment in a CircleCI organization.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI environment ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| created_at | Environment creation timestamp. | |
| description | Environment description. | |
| labels | Labels assigned to the environment. | |
| name | Yes | Environment name. |
| updated_at | Environment update timestamp. |
Relationships
(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIEnvironment): The CircleCI organization contains the deploy environment.
CircleCIGroup
A CircleCI organization group with the canonical UserGroup label.
Ontology Mapping: This node uses the ontology label
UserGroup.
Properties
Ontology-generated fields are shown in italics.
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI group ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| description | Group description. | |
| name | Yes | Group name. |
| _ont_description | Normalized field sourced from description. |
|
| _ont_name | Yes | Normalized field sourced from name. |
| _ont_source | Module that populated this node's ontology fields. |
Relationships
(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIGroup): The CircleCI organization contains the user group.
CircleCIOidcConfig
An organization-level CircleCI OIDC custom-claims configuration.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | Owning organization ID used as the configuration ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| audience | Trusted OIDC token audiences. | |
| audience_updated_at | Timestamp of the last audience change. | |
| org_id | Owning organization ID. | |
| project_id | Owning project ID when present. | |
| scope | OIDC configuration scope. | |
| ttl | OIDC token time to live. | |
| ttl_updated_at | Timestamp of the last token TTL change. |
Relationships
(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIOidcConfig): The CircleCI organization contains its OIDC configuration.
CircleCIOrganization
A CircleCI organization with the canonical Tenant label.
Ontology Mapping: This node uses the ontology label
Tenant.
Properties
Ontology-generated fields are shown in italics.
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI organization ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| avatar_url | URL of the organization avatar. | |
| name | Organization display name. | |
| slug | Yes | CircleCI organization slug. |
| vcs_login | GitHub organization login derived from the CircleCI slug. | |
| vcs_type | Version control system type. | |
| _ont_name | Yes | Normalized field sourced from name. |
| _ont_source | Module that populated this node's ontology fields. |
Relationships
(:CircleCIOrganization)-[:ASSOCIATED_WITH]->(:GitHubOrganization): The CircleCI organization is associated with a matching GitHub organization.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIComponent): The CircleCI organization contains the deploy component.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIContext): The CircleCI organization contains the context.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIContextEnvVar): The CircleCI organization contains the context environment variable.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIEnvironment): The CircleCI organization contains the deploy environment.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIGroup): The CircleCI organization contains the user group.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIOidcConfig): The CircleCI organization contains its OIDC configuration.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIPolicy): The CircleCI organization contains the configuration policy.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIProject): The CircleCI organization contains the project.
CircleCIPipeline
A CircleCI pipeline definition with the canonical CICDPipeline label.
Ontology Mapping: This node uses the ontology label
CICDPipeline.
Properties
Ontology-generated fields are shown in italics.
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI pipeline ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| checkout_source_provider | Pipeline checkout provider. | |
| checkout_source_repo_external_id | External ID of the checkout repository. | |
| checkout_source_repo_full_name | Full name of the checkout repository. | |
| config_source_file_path | Path to the pipeline configuration file. | |
| config_source_provider | Pipeline configuration provider. | |
| config_source_repo_external_id | External ID of the configuration repository. | |
| config_source_repo_full_name | Full name of the configuration repository. | |
| created_at | Pipeline creation timestamp. | |
| description | Pipeline description. | |
| name | Yes | Pipeline name. |
| _ont_name | Yes | Normalized field sourced from name. |
| _ont_source | Module that populated this node's ontology fields. | |
| _ont_type | Yes | Property generated by the ontology mapping. |
Relationships
(:CircleCIPipeline)-[:HAS_TRIGGER]->(:CircleCITrigger): The CircleCI pipeline has the trigger.(:CircleCIProject)-[:RESOURCE]->(:CircleCIPipeline): The CircleCI project contains the pipeline definition.
CircleCIPolicy
A CircleCI configuration policy in an organization policy bundle.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | Synthesized CircleCI policy ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| content | Policy source in Rego. | |
| context | CircleCI policy context. | |
| created_at | Policy creation timestamp. | |
| created_by | Identity that created the policy. | |
| decision_enabled | Whether policy decisions are enabled for the context. | |
| name | Yes | Policy name. |
Relationships
(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIPolicy): The CircleCI organization contains the configuration policy.
CircleCIProject
A CircleCI project linked to its external source repository.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI project ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| default_branch | Default repository branch. | |
| name | Project name. | |
| organization_id | Owning organization ID. | |
| organization_name | Owning organization name. | |
| organization_slug | Owning organization slug. | |
| slug | Yes | CircleCI project slug. |
| vcs_provider | Version control provider. | |
| vcs_url | Version control repository URL. |
Relationships
(:CircleCIContext)-[:RESTRICTED_TO]->(:CircleCIProject): The context is restricted to the allowed CircleCI projects.(:CircleCIOrganization)-[:RESOURCE]->(:CircleCIProject): The CircleCI organization contains the project.(:CircleCIProject)-[:BUILDS]->(:GitHubRepository): The CircleCI project builds a matching GitHub repository.(:CircleCIProject)-[:BUILDS]->(:GitLabProject): The CircleCI project builds a matching GitLab project.(:CircleCIProject)-[:HAS_COMPONENT]->(:CircleCIComponent): The CircleCI project has the deploy component.(:CircleCIProject)-[:RESOURCE]->(:CircleCICheckoutKey): The CircleCI project contains the checkout key.(:CircleCIProject)-[:RESOURCE]->(:CircleCIPipeline): The CircleCI project contains the pipeline definition.(:CircleCIProject)-[:RESOURCE]->(:CircleCIProjectEnvVar): The CircleCI project contains the environment variable.(:CircleCIProject)-[:RESOURCE]->(:CircleCIProjectOidcConfig): The CircleCI project contains its OIDC configuration.(:CircleCIProject)-[:RESOURCE]->(:CircleCITrigger): The CircleCI project contains the trigger.(:CircleCIProject)-[:RESOURCE]->(:CircleCIWebhook): The CircleCI project contains the outbound webhook.(:Image)-[:PACKAGED_BY]->(:CircleCIProject): MatchLink for the building project: (Image)-[:PACKAGED_BY]->(CircleCIProject).
Emitted where a rung identifies the building CircleCI project (the /pipeline feed run reliably carries project_slug). Analogous to the GitHub ImagePackagedByWorkflowMatchLink; the PACKAGED_FROM edge to the repo follows either the matcher's own repo edge or the project's existing CircleCIProject-[:BUILDS]->repo hop.
Properties:
Field Description match_method Value sourced from match_method.
CircleCIProjectEnvVar
A project-level CircleCI environment variable with a masked value.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | Synthesized project environment variable ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| name | Yes | Environment variable name. |
| project_slug | Slug of the owning CircleCI project. | |
| value | Masked environment variable value. |
Relationships
(:CircleCIProject)-[:RESOURCE]->(:CircleCIProjectEnvVar): The CircleCI project contains the environment variable.
CircleCIProjectOidcConfig
A project-level CircleCI OIDC custom-claims configuration.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | Owning project ID used as the configuration ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| audience | Trusted OIDC token audiences. | |
| audience_updated_at | Timestamp of the last audience change. | |
| org_id | Owning organization ID. | |
| project_id | Owning project ID. | |
| scope | OIDC configuration scope. | |
| ttl | OIDC token time to live. | |
| ttl_updated_at | Timestamp of the last token TTL change. |
Relationships
(:CircleCIProject)-[:RESOURCE]->(:CircleCIProjectOidcConfig): The CircleCI project contains its OIDC configuration.
CircleCITrigger
An event or schedule trigger attached to a CircleCI pipeline.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI trigger ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| checkout_ref | Version control reference to check out. | |
| config_ref | Version control reference containing the config. | |
| cron_expression | Cron expression for a scheduled trigger. | |
| description | Trigger description. | |
| disabled | Whether the trigger is disabled. | |
| event_name | Yes | Event that activates the trigger. |
| event_preset | Configured event preset. | |
| event_source_provider | Provider that supplies trigger events. | |
| pipeline_id | ID of the owning CircleCI pipeline. |
Relationships
(:CircleCIPipeline)-[:HAS_TRIGGER]->(:CircleCITrigger): The CircleCI pipeline has the trigger.(:CircleCIProject)-[:RESOURCE]->(:CircleCITrigger): The CircleCI project contains the trigger.
CircleCIWebhook
An outbound webhook configured for a CircleCI project.
Properties
| Field | Index | Description |
|---|---|---|
| id | Yes | CircleCI webhook ID. |
| firstseen | Timestamp when a sync job first created this node. | |
| lastupdated | Yes | Timestamp of the last sync that observed this node. |
| events | Webhook event subscriptions. | |
| has_signing_secret | Whether the webhook has a signing secret configured. | |
| name | Yes | Webhook name. |
| url | Webhook destination URL. | |
| verify_tls | Whether the webhook verifies TLS certificates. |
Relationships
(:CircleCIProject)-[:RESOURCE]->(:CircleCIWebhook): The CircleCI project contains the outbound webhook.