Publishing Images and Marketplace Demos
The Publish Access Record Lifecycle
A publish access record moves through a set of statuses (the PAR_STATUS type alias
in air_sdk.types). The PENDING_* states are awaiting reviewer action:
Requester Flow
The requester actions are the same five on both Image and MarketplaceDemo:
request_publish, request_public, request_allowlist_change, request_unpublish,
and cancel_publish_access_record. Each returns the updated resource, whose
publish_access_record_id points at the PAR the request created.
1. Request to Publish
Submit a resource for review. justification is required. Set prefer_public=False
to ask for restricted (allow-list) access, and describe the desired orgs in
allowed_orgs_request_text.
2. Request a Visibility Change
For an already-published resource, request a switch between public and restricted
(request_public), or update the allow-list on a restricted resource
(request_allowlist_change).
3. Request to Unpublish, or Cancel a Pending Request
request_unpublish queues removal for review; cancel_publish_access_record
withdraws whatever request is currently pending so you can resubmit.
Reviewer Flow
Reviewers (community managers) act on the publish access records themselves. The PAR
endpoints — api.image_publish_access_records and
api.marketplace_demo_publish_access_records — expose the same interface: list,
get, approve, deny, and set_visibility.
1. Find Records Awaiting Review
List by status to triage the queue. Both endpoints accept the same filters
(status, publicly_published, requested_by_email, requesting_org_display_name,
requesting_org_ngc_org_name, plus the resource id).
2. Approve
Approve as public (publicly_published=True) or restricted (publicly_published=False
with allowed_orgs). When omitted, publicly_published defaults to the record’s
prefer_public.
3. Deny
Reject a pending request, optionally with a denial_reason that is surfaced back to
the requester.
4. Set Visibility Directly
On an already-approved record, a reviewer can change visibility immediately without a
new request. When restricting, allowed_orgs is the full replacement allow-list.
Privileged Immediate Publish / Unpublish
Privileged callers can publish or unpublish directly, auto-approving the underlying
record and skipping the request/review cycle. Use allowed_orgs (org UUIDs) here —
the authoritative allow-list, distinct from the free-text allowed_orgs_request_text
hint used by the gated request_* actions.
Resource-Specific Differences
The flows are otherwise identical; a few extras exist only on demos:
tags—marketplace_demos.request_publishaccepts atagslist to assign tag names as part of the request (omit to leave tags unchanged,[]to clear).publish_images— demo publish/visibility requests can cascade to the images the demo references, publishing org-owned images so they reach the demo’s audience. WhenFalse(default), a request that needs image publishing is rejected with 400.- Return types — image publish/unpublish return the updated
Image; the demo equivalents returnNone. - 409 conflicts — while a demo’s images are still cascading,
publish,unpublish, andprovisionmay return 409; retry once the cascade settles.