AnkraDocs
Console

API reference · Compute

SSH keys, init scripts and server groups

15 operations of the Ankra Cloud API: SSH keys, init scripts and server groups.

List init scripts#

GET/v1/init-scripts
Operation
list_init_scripts
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
cursorquerystringThe next_cursor of the previous page.
limitqueryintegerPage size; the server applies its default and maximum.

Responses

200A page of init scripts, newest first.application/json · InitScriptList

200 response fields
FieldTypeDescription
itemsrequiredarray of InitScript
idrequiredstring
namerequiredstring
contentrequiredstring
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
next_cursorrequiredstring | nullPass as ?cursor= for the next page; null on the last page.
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/init-scripts' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Add an init script#

POST/v1/init-scripts
Operation
create_init_script
Credentials
API token, Portal session
Requires
Permission operate

Content up to 32 KiB; at most 100 scripts per account.

Request bodyapplication/json · InitScriptRequest

Request body fields
FieldTypeDescription
namestring
contentstring

Responses

201Created.application/json

201 response fields
FieldTypeDescription
init_scriptrequiredInitScript
idrequiredstring
namerequiredstring
contentrequiredstring
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 409The resource's state does not allow this now.
  • 422The account would exceed a quota; detail names the limit.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/init-scripts' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "content": "string"
}'

Get an init script#

GET/v1/init-scripts/{id}
Operation
get_init_script
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

200Found.application/json

200 response fields
FieldTypeDescription
init_scriptrequiredInitScript
idrequiredstring
namerequiredstring
contentrequiredstring
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/init-scripts/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Change an init script#

PATCH/v1/init-scripts/{id}
Operation
update_init_script
Credentials
API token, Portal session
Requires
Permission operate

Servers keep the user data they booted with.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Request bodyapplication/json · InitScriptRequest

Request body fields
FieldTypeDescription
namestring
contentstring

Responses

200Updated.application/json

200 response fields
FieldTypeDescription
init_scriptrequiredInitScript
idrequiredstring
namerequiredstring
contentrequiredstring
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PATCH 'https://cloud.ankra.app/v1/init-scripts/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "content": "string"
}'

Delete an init script#

DELETE/v1/init-scripts/{id}
Operation
delete_init_script
Credentials
API token, Portal session
Requires
Permission operate

Servers keep the user data they booted with.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

204Deleted.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/init-scripts/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

List server groups#

GET/v1/server-groups
Operation
list_server_groups
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
cursorquerystringThe next_cursor of the previous page.
limitqueryintegerPage size; the server applies its default and maximum.

Responses

200A page of server groups, newest first.application/json · ServerGroupList

200 response fields
FieldTypeDescription
itemsrequiredarray of ServerGroup
idrequiredstring
zonerequiredstring | nullNull for a zone-spread group, whose members live in several zones of region.
regionrequiredstring
namerequiredstring
spreadrequiredstringThe failure domain members are kept apart in. host: different compute nodes, preferring different racks; rack: different racks of the zone; zone: different zones of the region (and different nodes inside each).One of host, rack, zone
strictrequiredbooleanPlacement fails with a clear error rather than share a failure domain.
policyrequiredstringThe same as strict (strict: true), kept for older clients.One of strict, soft
member_countrequiredinteger
membersarray of stringServer identifiers, oldest first; only on the single-group read.
created_atrequiredstring (date-time)
next_cursorrequiredstring | nullPass as ?cursor= for the next page; null on the last page.
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/server-groups' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Add a server group#

POST/v1/server-groups
Operation
create_server_group
Credentials
API token, Portal session
Requires
Permission operate

An empty anti-affinity group in a zone; at most 100 groups per account.

Request bodyapplication/json · CreateServerGroupRequest

Request body fields
FieldTypeDescription
zonestringRequired for host and rack spread; for zone spread it names a zone of the region instead of region.
regionstringThe region of a zone-spread group (or give zone).
namerequiredstring
spreadstringOne of host, rack, zone
strictboolean
policystringOlder spelling of strict; send one of the two.One of strict, soft

Responses

201Created.application/json

201 response fields
FieldTypeDescription
server_grouprequiredServerGroup
idrequiredstring
zonerequiredstring | nullNull for a zone-spread group, whose members live in several zones of region.
regionrequiredstring
namerequiredstring
spreadrequiredstringThe failure domain members are kept apart in. host: different compute nodes, preferring different racks; rack: different racks of the zone; zone: different zones of the region (and different nodes inside each).One of host, rack, zone
strictrequiredbooleanPlacement fails with a clear error rather than share a failure domain.
policyrequiredstringThe same as strict (strict: true), kept for older clients.One of strict, soft
member_countrequiredinteger
membersarray of stringServer identifiers, oldest first; only on the single-group read.
created_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 409The resource's state does not allow this now.
  • 422The account would exceed a quota; detail names the limit.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/server-groups' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string"
}'

Get a server group#

GET/v1/server-groups/{id}
Operation
get_server_group
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

200Found.application/json

200 response fields
FieldTypeDescription
server_grouprequiredServerGroup
idrequiredstring
zonerequiredstring | nullNull for a zone-spread group, whose members live in several zones of region.
regionrequiredstring
namerequiredstring
spreadrequiredstringThe failure domain members are kept apart in. host: different compute nodes, preferring different racks; rack: different racks of the zone; zone: different zones of the region (and different nodes inside each).One of host, rack, zone
strictrequiredbooleanPlacement fails with a clear error rather than share a failure domain.
policyrequiredstringThe same as strict (strict: true), kept for older clients.One of strict, soft
member_countrequiredinteger
membersarray of stringServer identifiers, oldest first; only on the single-group read.
created_atrequiredstring (date-time)
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/server-groups/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Change a server group#

PATCH/v1/server-groups/{id}
Operation
update_server_group
Credentials
API token, Portal session
Requires
Permission operate

Only the name changes.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Request bodyapplication/json · RenameRequest

Request body fields
FieldTypeDescription
namerequiredstring

Responses

200Updated.application/json

200 response fields
FieldTypeDescription
server_grouprequiredServerGroup
idrequiredstring
zonerequiredstring | nullNull for a zone-spread group, whose members live in several zones of region.
regionrequiredstring
namerequiredstring
spreadrequiredstringThe failure domain members are kept apart in. host: different compute nodes, preferring different racks; rack: different racks of the zone; zone: different zones of the region (and different nodes inside each).One of host, rack, zone
strictrequiredbooleanPlacement fails with a clear error rather than share a failure domain.
policyrequiredstringThe same as strict (strict: true), kept for older clients.One of strict, soft
member_countrequiredinteger
membersarray of stringServer identifiers, oldest first; only on the single-group read.
created_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PATCH 'https://cloud.ankra.app/v1/server-groups/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string"
}'

Delete a server group#

DELETE/v1/server-groups/{id}
Operation
delete_server_group
Credentials
API token, Portal session
Requires
Permission operate

409 while the group has servers.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

204Deleted.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/server-groups/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

List SSH keys#

GET/v1/ssh-keys
Operation
list_ssh_keys
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
cursorquerystringThe next_cursor of the previous page.
limitqueryintegerPage size; the server applies its default and maximum.

Responses

200A page of SSH keys, newest first.application/json · SSHKeyList

200 response fields
FieldTypeDescription
itemsrequiredarray of SSHKey
idrequiredstring
namerequiredstring
public_keyrequiredstring
fingerprintrequiredstringSHA256 fingerprint, as ssh-keygen -l prints it.
created_atrequiredstring (date-time)
next_cursorrequiredstring | nullPass as ?cursor= for the next page; null on the last page.
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/ssh-keys' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Add an SSH key#

POST/v1/ssh-keys
Operation
create_ssh_key
Credentials
API token, Portal session
Requires
Permission operate

409 when the account already holds the name or the key; at most 100 keys per account.

Request bodyapplication/json · CreateSSHKeyRequest

Request body fields
FieldTypeDescription
namerequiredstring
public_keyrequiredstringOne OpenSSH public key line.

Responses

201Created.application/json

201 response fields
FieldTypeDescription
ssh_keyrequiredSSHKey
idrequiredstring
namerequiredstring
public_keyrequiredstring
fingerprintrequiredstringSHA256 fingerprint, as ssh-keygen -l prints it.
created_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 409The resource's state does not allow this now.
  • 422The account would exceed a quota; detail names the limit.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/ssh-keys' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "public_key": "string"
}'

Get an SSH key#

GET/v1/ssh-keys/{id}
Operation
get_ssh_key
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

200Found.application/json

200 response fields
FieldTypeDescription
ssh_keyrequiredSSHKey
idrequiredstring
namerequiredstring
public_keyrequiredstring
fingerprintrequiredstringSHA256 fingerprint, as ssh-keygen -l prints it.
created_atrequiredstring (date-time)
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/ssh-keys/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Change an SSH key#

PATCH/v1/ssh-keys/{id}
Operation
update_ssh_key
Credentials
API token, Portal session
Requires
Permission operate

Only the name changes; add a new key and delete the old one to replace a key.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Request bodyapplication/json · RenameRequest

Request body fields
FieldTypeDescription
namerequiredstring

Responses

200Updated.application/json

200 response fields
FieldTypeDescription
ssh_keyrequiredSSHKey
idrequiredstring
namerequiredstring
public_keyrequiredstring
fingerprintrequiredstringSHA256 fingerprint, as ssh-keygen -l prints it.
created_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PATCH 'https://cloud.ankra.app/v1/ssh-keys/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string"
}'

Delete an SSH key#

DELETE/v1/ssh-keys/{id}
Operation
delete_ssh_key
Credentials
API token, Portal session
Requires
Permission operate

Servers keep the keys they were created with.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

204Deleted.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/ssh-keys/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"