AnkraDocs
Console

API reference · Networking

Load balancers

18 operations of the Ankra Cloud API: Managed load balancers and their certificates.

List load balancers#

GET/v1/load-balancers
Operation
list_load_balancers
Credentials
API token, Portal session
Requires
Permission read

Without nodes, frontends and backends; get one for those.

Parameters

Parameters
NameInTypeDescription
labelqueryarray of stringkey=value; repeat to require several labels. Only load balancers carrying every label are listed.

Responses

200Every load balancer that matches (next_cursor is always null).application/json

200 response fields
FieldTypeDescription
itemsrequiredarray of LoadBalancer
idrequiredstring
zonerequiredstring
regionstringThe region of the load balancer's zone.
namerequiredstring
network_idrequiredstring
staterequiredstringOne of creating, running, error, deleting
labelsrequiredLabelsKeys of 1-63 letters, digits, ., _, / or -, starting and ending with a letter or digit; values of at most 255 printable characters.
high_availabilityrequiredbooleanTwo VMs on different compute nodes (true) or one (false). A load balancer created without high_availability in a zone that lacks the load_balancer_ha capability (one compute node, see get_zone_capabilities) runs on a single VM; asking for a pair there is refused with 409.
public_ipv4requiredstring | nullThe floating IPv4 frontend address (the add-on); null without the add-on or until allocated.
public_ipv6requiredstring | nullThe IPv6 frontend address to publish: the first VM's own address (the first of its public /64). On a pair it does not fail over to the second VM; publish public_ipv6_addresses for that. Null until the VM's /64 is allocated.
public_ipv6_addressesrequiredarray of stringEvery VM's IPv6 frontend address, in VM order; each VM serves every frontend on its own.
addressrequiredstring | nullThe public IPv4 address, the same as public_ipv4 (kept for older clients); null without the IPv4 add-on or until allocated.
configuration_generationrequiredinteger
is_configuration_appliedrequiredboolean
nodesrequiredarray of object
idrequiredstring
namerequiredstring
staterequiredstring
is_activerequiredbooleanThe VM that holds the load balancer's address (the active member of the pair's failover), as its guest last reported.
is_healthyrequiredboolean
health_detailrequiredstring
is_configuration_appliedrequiredboolean
frontendsrequiredarray of LoadBalancerFrontend
idrequiredstring
namerequiredstring
portrequiredinteger
moderequiredstringThe mode of its backend.One of tcp, http
backend_idrequiredstring
tlsrequiredbooleanTerminates TLS with its certificates.
certificate_idsrequiredarray of stringThe first answers clients that send no server name; the others are chosen by SNI.
redirect_to_httpsrequiredbooleanAnswers every request with a 301 to https on the same host.
backendsrequiredarray of LoadBalancerBackend
idrequiredstring
namerequiredstring
moderequiredstringOne of tcp, http
balancerequiredstringOne of roundrobin, leastconn, source
health_check_pathrequiredstringThe http check's path, empty for other checks. Kept for older clients; read health_check.
health_checkrequiredLoadBalancerHealthCheck
typerequiredstringtcp connects to the member; http sends GET <path>; none never checks.One of tcp, http, none
pathrequiredstringFor http checks.
expected_statusrequiredstringFor http checks: 200, or a range such as 200-399.
interval_secondsrequiredinteger
riserequiredintegerSuccesses that bring a member back.
fallrequiredintegerFailures that take a member out.
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
active_operationrequiredOperation | null
idrequiredstring
kindrequiredstringOne of server.create, server.metadata, server.start, server.stop, server.restart, server.delete, server.force_release, server.change_plan, server.rebuild, server.renumber_ipv6, server.attach_network, server.detach_network, server.firewall, storage.create, storage.attach, storage.detach, storage.resize, storage.delete, storage.backup, backup.restore, backup.delete, template.create, template.copy, template.delete, snapshot.create, snapshot.delete, router.sync, floating_ip.sync, network.sync, public_pool.sync, server.move, server.migrate, server.recover, server.settle_migration, node.cordon, node.uncordon, node.drain, node.fence, node.maintenance, node.agent_upgrade, node.provision, load_balancer.create, load_balancer.delete, database.create, database.delete, database.restore, edge.sync, edge.delete, storage.move, storage.rebalance_policy, storage.drain_host, object_storage.migrate, kubernetes_cluster.create, kubernetes_cluster.delete, kubernetes_cluster.upgrade, kubernetes_cluster.snapshot, kubernetes_cluster.restore, node_pool.sync, node_pool.delete, kubernetes_host.bootstrap, kubernetes_cluster.platform_register, kubernetes_cluster.platform_deregister, control_plane.expand, control_plane.shrink, backup.verify
server_idrequiredstring | null
storage_idrequiredstring | null
backup_idrequiredstring | null
template_idrequiredstring | null
router_idrequiredstring | null
floating_ip_idrequiredstring | null
node_idstringSet on node maintenance operations (operator only); absent otherwise.
load_balancer_idstring | nullSet on the operations that create and delete a load balancer.
database_idstring | nullSet on the operations that create and delete a managed database.
edge_idstring | nullSet on the operations that sync and delete a network edge.
snapshot_idstring | nullSet on the operations that create and delete a snapshot, and on a storage.create that clones one.
kubernetes_cluster_idstring | nullSet on the operations of a managed Kubernetes cluster.
node_pool_idstring | nullSet on the operations of a Kubernetes node pool.
kubernetes_host_idstringSet on a regional host cluster bootstrap (operator only); absent otherwise.
statusrequiredstringOne of pending, running, succeeded, failed, cancelled
steprequiredstringMachine name of the current step, e.g. create_disk or transfer_cross_zone.
step_indexrequiredinteger
step_countrequiredinteger
errorrequiredstringEmpty unless the operation failed.
created_atrequiredstring (date-time)
started_atrequiredstring (date-time) | null
finished_atrequiredstring (date-time) | null
deadline_atrequiredstring (date-time)
actorstringWho asked for the operation: user:<id>, token:<name>, operator, system:<component>; empty on older operations.
progressMigrationProgressPresent on GET /v1/operations/{id} while a server.migrate drives a live transfer.
staterequiredstringOne of reserved, detached, preparing, sending, switched, aborting
source_node_idrequiredstring
target_node_idrequiredstring
phaserequiredstringHow far the nodes report the current attempt.One of , preparing, transferring, completed, failed
attemptrequiredintegerWhich send this is under the convergence policy, from 1.
iterationrequiredintegerMemory passes so far in the current attempt.
transferred_bytesrequiredinteger
total_bytesrequiredinteger0 when the hypervisor does not report it.
dirty_bytes_per_secondrequiredinteger
downtime_millisecondsrequiredintegerThe pause the guest took at handover, once completed.
detailrequiredstring
reported_atrequiredstring (date-time) | nullThe reporting node's clock.
eventsarray of OperationEventPresent on GET /v1/operations/{id}; the newest 100 entries of the operation's log, oldest first.
atrequiredstring (date-time)
kindrequiredstringFor example target_chosen, send_started, handed_over, undoing, cold_fallback, move_cancelled, recovery_started, succeeded, failed.
messagerequiredstring
datarequiredobject
created_atrequiredstring (date-time)
next_cursorrequirednull
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/load-balancers' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Create a load balancer on a private network#

POST/v1/load-balancers
Operation
create_load_balancer
Credentials
API token, Portal session
Requires
Permission operate

HAProxy on the account's private network. high_availability true is two VMs on different compute nodes that move a floating IPv4 address between them with VRRP; false is one VM. Without the field a zone with two or more compute nodes gets a pair and a zone with one gets a single VM; asking for a pair where the zone lacks the load_balancer_ha capability (one compute node, see get_zone_capabilities) is a 409 that says so.

IPv6 is always on: every VM serves the frontends on the first address of its own public /64 (public_ipv6, all of them in public_ipv6_addresses). On a pair that address is the first VM's and does not move to the second when the first fails: VRRP carries the IPv4 address only, so publish every entry of public_ipv6_addresses (for example as several AAAA records or Service ingress IPs) for IPv6 failover. public_ipv4 (default true) adds a floating IPv4 frontend address, the paid add-on.

Price per month: €4.50 per VM plus €3 for the IPv4 add-on, so €12 for a pair with IPv4 (as before), €9 for a pair without, €7.50 for one VM with IPv4 and €4.50 for one VM without. An account may hold 5.

Request bodyapplication/json

Request body fields
FieldTypeDescription
zonerequiredstring
namerequiredstring
network_idrequiredstring
labelsLabelsKeys of 1-63 letters, digits, ., _, / or -, starting and ending with a letter or digit; values of at most 255 printable characters.
high_availabilitybooleanTwo VMs on different compute nodes (true) or one (false). Defaults to true where the zone has two compute nodes, false where it has one.
public_ipv4booleanThe floating IPv4 frontend address, the paid add-on. IPv6 is always on.
zone_redundantbooleanA VM pair in each of two or more zones of the zone's region. Validated against the region (400 in a region with one zone), then answered 501 until zone-redundant placement lands.

Responses

202The load balancer and its load_balancer.create operation.application/json

202 response fields
FieldTypeDescription
load_balancerrequiredLoadBalancer
idrequiredstring
zonerequiredstring
regionstringThe region of the load balancer's zone.
namerequiredstring
network_idrequiredstring
staterequiredstringOne of creating, running, error, deleting
labelsrequiredLabelsKeys of 1-63 letters, digits, ., _, / or -, starting and ending with a letter or digit; values of at most 255 printable characters.
high_availabilityrequiredbooleanTwo VMs on different compute nodes (true) or one (false). A load balancer created without high_availability in a zone that lacks the load_balancer_ha capability (one compute node, see get_zone_capabilities) runs on a single VM; asking for a pair there is refused with 409.
public_ipv4requiredstring | nullThe floating IPv4 frontend address (the add-on); null without the add-on or until allocated.
public_ipv6requiredstring | nullThe IPv6 frontend address to publish: the first VM's own address (the first of its public /64). On a pair it does not fail over to the second VM; publish public_ipv6_addresses for that. Null until the VM's /64 is allocated.
public_ipv6_addressesrequiredarray of stringEvery VM's IPv6 frontend address, in VM order; each VM serves every frontend on its own.
addressrequiredstring | nullThe public IPv4 address, the same as public_ipv4 (kept for older clients); null without the IPv4 add-on or until allocated.
configuration_generationrequiredinteger
is_configuration_appliedrequiredboolean
nodesrequiredarray of object
idrequiredstring
namerequiredstring
staterequiredstring
is_activerequiredbooleanThe VM that holds the load balancer's address (the active member of the pair's failover), as its guest last reported.
is_healthyrequiredboolean
health_detailrequiredstring
is_configuration_appliedrequiredboolean
frontendsrequiredarray of LoadBalancerFrontend
idrequiredstring
namerequiredstring
portrequiredinteger
moderequiredstringThe mode of its backend.One of tcp, http
backend_idrequiredstring
tlsrequiredbooleanTerminates TLS with its certificates.
certificate_idsrequiredarray of stringThe first answers clients that send no server name; the others are chosen by SNI.
redirect_to_httpsrequiredbooleanAnswers every request with a 301 to https on the same host.
backendsrequiredarray of LoadBalancerBackend
idrequiredstring
namerequiredstring
moderequiredstringOne of tcp, http
balancerequiredstringOne of roundrobin, leastconn, source
health_check_pathrequiredstringThe http check's path, empty for other checks. Kept for older clients; read health_check.
health_checkrequiredLoadBalancerHealthCheck
typerequiredstringtcp connects to the member; http sends GET <path>; none never checks.One of tcp, http, none
pathrequiredstringFor http checks.
expected_statusrequiredstringFor http checks: 200, or a range such as 200-399.
interval_secondsrequiredinteger
riserequiredintegerSuccesses that bring a member back.
fallrequiredintegerFailures that take a member out.
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
active_operationrequiredOperation | null
idrequiredstring
kindrequiredstringOne of server.create, server.metadata, server.start, server.stop, server.restart, server.delete, server.force_release, server.change_plan, server.rebuild, server.renumber_ipv6, server.attach_network, server.detach_network, server.firewall, storage.create, storage.attach, storage.detach, storage.resize, storage.delete, storage.backup, backup.restore, backup.delete, template.create, template.copy, template.delete, snapshot.create, snapshot.delete, router.sync, floating_ip.sync, network.sync, public_pool.sync, server.move, server.migrate, server.recover, server.settle_migration, node.cordon, node.uncordon, node.drain, node.fence, node.maintenance, node.agent_upgrade, node.provision, load_balancer.create, load_balancer.delete, database.create, database.delete, database.restore, edge.sync, edge.delete, storage.move, storage.rebalance_policy, storage.drain_host, object_storage.migrate, kubernetes_cluster.create, kubernetes_cluster.delete, kubernetes_cluster.upgrade, kubernetes_cluster.snapshot, kubernetes_cluster.restore, node_pool.sync, node_pool.delete, kubernetes_host.bootstrap, kubernetes_cluster.platform_register, kubernetes_cluster.platform_deregister, control_plane.expand, control_plane.shrink, backup.verify
server_idrequiredstring | null
storage_idrequiredstring | null
backup_idrequiredstring | null
template_idrequiredstring | null
router_idrequiredstring | null
floating_ip_idrequiredstring | null
node_idstringSet on node maintenance operations (operator only); absent otherwise.
load_balancer_idstring | nullSet on the operations that create and delete a load balancer.
database_idstring | nullSet on the operations that create and delete a managed database.
edge_idstring | nullSet on the operations that sync and delete a network edge.
snapshot_idstring | nullSet on the operations that create and delete a snapshot, and on a storage.create that clones one.
kubernetes_cluster_idstring | nullSet on the operations of a managed Kubernetes cluster.
node_pool_idstring | nullSet on the operations of a Kubernetes node pool.
kubernetes_host_idstringSet on a regional host cluster bootstrap (operator only); absent otherwise.
statusrequiredstringOne of pending, running, succeeded, failed, cancelled
steprequiredstringMachine name of the current step, e.g. create_disk or transfer_cross_zone.
step_indexrequiredinteger
step_countrequiredinteger
errorrequiredstringEmpty unless the operation failed.
created_atrequiredstring (date-time)
started_atrequiredstring (date-time) | null
finished_atrequiredstring (date-time) | null
deadline_atrequiredstring (date-time)
actorstringWho asked for the operation: user:<id>, token:<name>, operator, system:<component>; empty on older operations.
progressMigrationProgressPresent on GET /v1/operations/{id} while a server.migrate drives a live transfer.
staterequiredstringOne of reserved, detached, preparing, sending, switched, aborting
source_node_idrequiredstring
target_node_idrequiredstring
phaserequiredstringHow far the nodes report the current attempt.One of , preparing, transferring, completed, failed
attemptrequiredintegerWhich send this is under the convergence policy, from 1.
iterationrequiredintegerMemory passes so far in the current attempt.
transferred_bytesrequiredinteger
total_bytesrequiredinteger0 when the hypervisor does not report it.
dirty_bytes_per_secondrequiredinteger
downtime_millisecondsrequiredintegerThe pause the guest took at handover, once completed.
detailrequiredstring
reported_atrequiredstring (date-time) | nullThe reporting node's clock.
eventsarray of OperationEventPresent on GET /v1/operations/{id}; the newest 100 entries of the operation's log, oldest first.
atrequiredstring (date-time)
kindrequiredstringFor example target_chosen, send_started, handed_over, undoing, cold_fallback, move_cancelled, recovery_started, succeeded, failed.
messagerequiredstring
datarequiredobject
created_atrequiredstring (date-time)
operationrequiredOperation
idrequiredstring
kindrequiredstringOne of server.create, server.metadata, server.start, server.stop, server.restart, server.delete, server.force_release, server.change_plan, server.rebuild, server.renumber_ipv6, server.attach_network, server.detach_network, server.firewall, storage.create, storage.attach, storage.detach, storage.resize, storage.delete, storage.backup, backup.restore, backup.delete, template.create, template.copy, template.delete, snapshot.create, snapshot.delete, router.sync, floating_ip.sync, network.sync, public_pool.sync, server.move, server.migrate, server.recover, server.settle_migration, node.cordon, node.uncordon, node.drain, node.fence, node.maintenance, node.agent_upgrade, node.provision, load_balancer.create, load_balancer.delete, database.create, database.delete, database.restore, edge.sync, edge.delete, storage.move, storage.rebalance_policy, storage.drain_host, object_storage.migrate, kubernetes_cluster.create, kubernetes_cluster.delete, kubernetes_cluster.upgrade, kubernetes_cluster.snapshot, kubernetes_cluster.restore, node_pool.sync, node_pool.delete, kubernetes_host.bootstrap, kubernetes_cluster.platform_register, kubernetes_cluster.platform_deregister, control_plane.expand, control_plane.shrink, backup.verify
server_idrequiredstring | null
storage_idrequiredstring | null
backup_idrequiredstring | null
template_idrequiredstring | null
router_idrequiredstring | null
floating_ip_idrequiredstring | null
node_idstringSet on node maintenance operations (operator only); absent otherwise.
load_balancer_idstring | nullSet on the operations that create and delete a load balancer.
database_idstring | nullSet on the operations that create and delete a managed database.
edge_idstring | nullSet on the operations that sync and delete a network edge.
snapshot_idstring | nullSet on the operations that create and delete a snapshot, and on a storage.create that clones one.
kubernetes_cluster_idstring | nullSet on the operations of a managed Kubernetes cluster.
node_pool_idstring | nullSet on the operations of a Kubernetes node pool.
kubernetes_host_idstringSet on a regional host cluster bootstrap (operator only); absent otherwise.
statusrequiredstringOne of pending, running, succeeded, failed, cancelled
steprequiredstringMachine name of the current step, e.g. create_disk or transfer_cross_zone.
step_indexrequiredinteger
step_countrequiredinteger
errorrequiredstringEmpty unless the operation failed.
created_atrequiredstring (date-time)
started_atrequiredstring (date-time) | null
finished_atrequiredstring (date-time) | null
deadline_atrequiredstring (date-time)
actorstringWho asked for the operation: user:<id>, token:<name>, operator, system:<component>; empty on older operations.
progressMigrationProgressPresent on GET /v1/operations/{id} while a server.migrate drives a live transfer.
staterequiredstringOne of reserved, detached, preparing, sending, switched, aborting
source_node_idrequiredstring
target_node_idrequiredstring
phaserequiredstringHow far the nodes report the current attempt.One of , preparing, transferring, completed, failed
attemptrequiredintegerWhich send this is under the convergence policy, from 1.
iterationrequiredintegerMemory passes so far in the current attempt.
transferred_bytesrequiredinteger
total_bytesrequiredinteger0 when the hypervisor does not report it.
dirty_bytes_per_secondrequiredinteger
downtime_millisecondsrequiredintegerThe pause the guest took at handover, once completed.
detailrequiredstring
reported_atrequiredstring (date-time) | nullThe reporting node's clock.
eventsarray of OperationEventPresent on GET /v1/operations/{id}; the newest 100 entries of the operation's log, oldest first.
atrequiredstring (date-time)
kindrequiredstringFor example target_chosen, send_started, handed_over, undoing, cold_fallback, move_cancelled, recovery_started, succeeded, failed.
messagerequiredstring
datarequiredobject
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 402The account may not create billable resources. reason is payment_method_required while it has neither a default payment method nor a live credit (add one through POST /v1/account/billing/setup-session or redeem a coupon), or account_suspended while an invoice is overdue past the grace period (pay it; nothing already running is stopped) or Ankra staff suspended the account (contact support). GET /v1/account/billing reports the same standing.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • 422The account would exceed a quota; detail names the limit.
  • 503No capacity or address is free, or a host did not answer; try again later.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/load-balancers' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "zone": "string",
  "name": "string",
  "network_id": "string"
}'

Get a load balancer with its VMs, frontends and backends#

GET/v1/load-balancers/{id}
Operation
get_load_balancer
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

200The load balancer.application/json

200 response fields
FieldTypeDescription
load_balancerrequiredLoadBalancer
idrequiredstring
zonerequiredstring
regionstringThe region of the load balancer's zone.
namerequiredstring
network_idrequiredstring
staterequiredstringOne of creating, running, error, deleting
labelsrequiredLabelsKeys of 1-63 letters, digits, ., _, / or -, starting and ending with a letter or digit; values of at most 255 printable characters.
high_availabilityrequiredbooleanTwo VMs on different compute nodes (true) or one (false). A load balancer created without high_availability in a zone that lacks the load_balancer_ha capability (one compute node, see get_zone_capabilities) runs on a single VM; asking for a pair there is refused with 409.
public_ipv4requiredstring | nullThe floating IPv4 frontend address (the add-on); null without the add-on or until allocated.
public_ipv6requiredstring | nullThe IPv6 frontend address to publish: the first VM's own address (the first of its public /64). On a pair it does not fail over to the second VM; publish public_ipv6_addresses for that. Null until the VM's /64 is allocated.
public_ipv6_addressesrequiredarray of stringEvery VM's IPv6 frontend address, in VM order; each VM serves every frontend on its own.
addressrequiredstring | nullThe public IPv4 address, the same as public_ipv4 (kept for older clients); null without the IPv4 add-on or until allocated.
configuration_generationrequiredinteger
is_configuration_appliedrequiredboolean
nodesrequiredarray of object
idrequiredstring
namerequiredstring
staterequiredstring
is_activerequiredbooleanThe VM that holds the load balancer's address (the active member of the pair's failover), as its guest last reported.
is_healthyrequiredboolean
health_detailrequiredstring
is_configuration_appliedrequiredboolean
frontendsrequiredarray of LoadBalancerFrontend
idrequiredstring
namerequiredstring
portrequiredinteger
moderequiredstringThe mode of its backend.One of tcp, http
backend_idrequiredstring
tlsrequiredbooleanTerminates TLS with its certificates.
certificate_idsrequiredarray of stringThe first answers clients that send no server name; the others are chosen by SNI.
redirect_to_httpsrequiredbooleanAnswers every request with a 301 to https on the same host.
backendsrequiredarray of LoadBalancerBackend
idrequiredstring
namerequiredstring
moderequiredstringOne of tcp, http
balancerequiredstringOne of roundrobin, leastconn, source
health_check_pathrequiredstringThe http check's path, empty for other checks. Kept for older clients; read health_check.
health_checkrequiredLoadBalancerHealthCheck
typerequiredstringtcp connects to the member; http sends GET <path>; none never checks.One of tcp, http, none
pathrequiredstringFor http checks.
expected_statusrequiredstringFor http checks: 200, or a range such as 200-399.
interval_secondsrequiredinteger
riserequiredintegerSuccesses that bring a member back.
fallrequiredintegerFailures that take a member out.
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
active_operationrequiredOperation | null
idrequiredstring
kindrequiredstringOne of server.create, server.metadata, server.start, server.stop, server.restart, server.delete, server.force_release, server.change_plan, server.rebuild, server.renumber_ipv6, server.attach_network, server.detach_network, server.firewall, storage.create, storage.attach, storage.detach, storage.resize, storage.delete, storage.backup, backup.restore, backup.delete, template.create, template.copy, template.delete, snapshot.create, snapshot.delete, router.sync, floating_ip.sync, network.sync, public_pool.sync, server.move, server.migrate, server.recover, server.settle_migration, node.cordon, node.uncordon, node.drain, node.fence, node.maintenance, node.agent_upgrade, node.provision, load_balancer.create, load_balancer.delete, database.create, database.delete, database.restore, edge.sync, edge.delete, storage.move, storage.rebalance_policy, storage.drain_host, object_storage.migrate, kubernetes_cluster.create, kubernetes_cluster.delete, kubernetes_cluster.upgrade, kubernetes_cluster.snapshot, kubernetes_cluster.restore, node_pool.sync, node_pool.delete, kubernetes_host.bootstrap, kubernetes_cluster.platform_register, kubernetes_cluster.platform_deregister, control_plane.expand, control_plane.shrink, backup.verify
server_idrequiredstring | null
storage_idrequiredstring | null
backup_idrequiredstring | null
template_idrequiredstring | null
router_idrequiredstring | null
floating_ip_idrequiredstring | null
node_idstringSet on node maintenance operations (operator only); absent otherwise.
load_balancer_idstring | nullSet on the operations that create and delete a load balancer.
database_idstring | nullSet on the operations that create and delete a managed database.
edge_idstring | nullSet on the operations that sync and delete a network edge.
snapshot_idstring | nullSet on the operations that create and delete a snapshot, and on a storage.create that clones one.
kubernetes_cluster_idstring | nullSet on the operations of a managed Kubernetes cluster.
node_pool_idstring | nullSet on the operations of a Kubernetes node pool.
kubernetes_host_idstringSet on a regional host cluster bootstrap (operator only); absent otherwise.
statusrequiredstringOne of pending, running, succeeded, failed, cancelled
steprequiredstringMachine name of the current step, e.g. create_disk or transfer_cross_zone.
step_indexrequiredinteger
step_countrequiredinteger
errorrequiredstringEmpty unless the operation failed.
created_atrequiredstring (date-time)
started_atrequiredstring (date-time) | null
finished_atrequiredstring (date-time) | null
deadline_atrequiredstring (date-time)
actorstringWho asked for the operation: user:<id>, token:<name>, operator, system:<component>; empty on older operations.
progressMigrationProgressPresent on GET /v1/operations/{id} while a server.migrate drives a live transfer.
staterequiredstringOne of reserved, detached, preparing, sending, switched, aborting
source_node_idrequiredstring
target_node_idrequiredstring
phaserequiredstringHow far the nodes report the current attempt.One of , preparing, transferring, completed, failed
attemptrequiredintegerWhich send this is under the convergence policy, from 1.
iterationrequiredintegerMemory passes so far in the current attempt.
transferred_bytesrequiredinteger
total_bytesrequiredinteger0 when the hypervisor does not report it.
dirty_bytes_per_secondrequiredinteger
downtime_millisecondsrequiredintegerThe pause the guest took at handover, once completed.
detailrequiredstring
reported_atrequiredstring (date-time) | nullThe reporting node's clock.
eventsarray of OperationEventPresent on GET /v1/operations/{id}; the newest 100 entries of the operation's log, oldest first.
atrequiredstring (date-time)
kindrequiredstringFor example target_chosen, send_started, handed_over, undoing, cold_fallback, move_cancelled, recovery_started, succeeded, failed.
messagerequiredstring
datarequiredobject
created_atrequiredstring (date-time)
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/load-balancers/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Rename a load balancer or replace its labels#

PATCH/v1/load-balancers/{id}
Operation
update_load_balancer
Credentials
API token, Portal session
Requires
Permission operate

labels replaces the labels whole ({} removes them all); an absent field is left unchanged. Neither reaches HAProxy, so the configuration generation stays. 409 when the name is taken or the load balancer is being deleted.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
namestring
labelsLabelsKeys of 1-63 letters, digits, ., _, / or -, starting and ending with a letter or digit; values of at most 255 printable characters.

Responses

200The load balancer, described in full.application/json

200 response fields
FieldTypeDescription
load_balancerrequiredLoadBalancer
idrequiredstring
zonerequiredstring
regionstringThe region of the load balancer's zone.
namerequiredstring
network_idrequiredstring
staterequiredstringOne of creating, running, error, deleting
labelsrequiredLabelsKeys of 1-63 letters, digits, ., _, / or -, starting and ending with a letter or digit; values of at most 255 printable characters.
high_availabilityrequiredbooleanTwo VMs on different compute nodes (true) or one (false). A load balancer created without high_availability in a zone that lacks the load_balancer_ha capability (one compute node, see get_zone_capabilities) runs on a single VM; asking for a pair there is refused with 409.
public_ipv4requiredstring | nullThe floating IPv4 frontend address (the add-on); null without the add-on or until allocated.
public_ipv6requiredstring | nullThe IPv6 frontend address to publish: the first VM's own address (the first of its public /64). On a pair it does not fail over to the second VM; publish public_ipv6_addresses for that. Null until the VM's /64 is allocated.
public_ipv6_addressesrequiredarray of stringEvery VM's IPv6 frontend address, in VM order; each VM serves every frontend on its own.
addressrequiredstring | nullThe public IPv4 address, the same as public_ipv4 (kept for older clients); null without the IPv4 add-on or until allocated.
configuration_generationrequiredinteger
is_configuration_appliedrequiredboolean
nodesrequiredarray of object
idrequiredstring
namerequiredstring
staterequiredstring
is_activerequiredbooleanThe VM that holds the load balancer's address (the active member of the pair's failover), as its guest last reported.
is_healthyrequiredboolean
health_detailrequiredstring
is_configuration_appliedrequiredboolean
frontendsrequiredarray of LoadBalancerFrontend
idrequiredstring
namerequiredstring
portrequiredinteger
moderequiredstringThe mode of its backend.One of tcp, http
backend_idrequiredstring
tlsrequiredbooleanTerminates TLS with its certificates.
certificate_idsrequiredarray of stringThe first answers clients that send no server name; the others are chosen by SNI.
redirect_to_httpsrequiredbooleanAnswers every request with a 301 to https on the same host.
backendsrequiredarray of LoadBalancerBackend
idrequiredstring
namerequiredstring
moderequiredstringOne of tcp, http
balancerequiredstringOne of roundrobin, leastconn, source
health_check_pathrequiredstringThe http check's path, empty for other checks. Kept for older clients; read health_check.
health_checkrequiredLoadBalancerHealthCheck
typerequiredstringtcp connects to the member; http sends GET <path>; none never checks.One of tcp, http, none
pathrequiredstringFor http checks.
expected_statusrequiredstringFor http checks: 200, or a range such as 200-399.
interval_secondsrequiredinteger
riserequiredintegerSuccesses that bring a member back.
fallrequiredintegerFailures that take a member out.
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
active_operationrequiredOperation | null
idrequiredstring
kindrequiredstringOne of server.create, server.metadata, server.start, server.stop, server.restart, server.delete, server.force_release, server.change_plan, server.rebuild, server.renumber_ipv6, server.attach_network, server.detach_network, server.firewall, storage.create, storage.attach, storage.detach, storage.resize, storage.delete, storage.backup, backup.restore, backup.delete, template.create, template.copy, template.delete, snapshot.create, snapshot.delete, router.sync, floating_ip.sync, network.sync, public_pool.sync, server.move, server.migrate, server.recover, server.settle_migration, node.cordon, node.uncordon, node.drain, node.fence, node.maintenance, node.agent_upgrade, node.provision, load_balancer.create, load_balancer.delete, database.create, database.delete, database.restore, edge.sync, edge.delete, storage.move, storage.rebalance_policy, storage.drain_host, object_storage.migrate, kubernetes_cluster.create, kubernetes_cluster.delete, kubernetes_cluster.upgrade, kubernetes_cluster.snapshot, kubernetes_cluster.restore, node_pool.sync, node_pool.delete, kubernetes_host.bootstrap, kubernetes_cluster.platform_register, kubernetes_cluster.platform_deregister, control_plane.expand, control_plane.shrink, backup.verify
server_idrequiredstring | null
storage_idrequiredstring | null
backup_idrequiredstring | null
template_idrequiredstring | null
router_idrequiredstring | null
floating_ip_idrequiredstring | null
node_idstringSet on node maintenance operations (operator only); absent otherwise.
load_balancer_idstring | nullSet on the operations that create and delete a load balancer.
database_idstring | nullSet on the operations that create and delete a managed database.
edge_idstring | nullSet on the operations that sync and delete a network edge.
snapshot_idstring | nullSet on the operations that create and delete a snapshot, and on a storage.create that clones one.
kubernetes_cluster_idstring | nullSet on the operations of a managed Kubernetes cluster.
node_pool_idstring | nullSet on the operations of a Kubernetes node pool.
kubernetes_host_idstringSet on a regional host cluster bootstrap (operator only); absent otherwise.
statusrequiredstringOne of pending, running, succeeded, failed, cancelled
steprequiredstringMachine name of the current step, e.g. create_disk or transfer_cross_zone.
step_indexrequiredinteger
step_countrequiredinteger
errorrequiredstringEmpty unless the operation failed.
created_atrequiredstring (date-time)
started_atrequiredstring (date-time) | null
finished_atrequiredstring (date-time) | null
deadline_atrequiredstring (date-time)
actorstringWho asked for the operation: user:<id>, token:<name>, operator, system:<component>; empty on older operations.
progressMigrationProgressPresent on GET /v1/operations/{id} while a server.migrate drives a live transfer.
staterequiredstringOne of reserved, detached, preparing, sending, switched, aborting
source_node_idrequiredstring
target_node_idrequiredstring
phaserequiredstringHow far the nodes report the current attempt.One of , preparing, transferring, completed, failed
attemptrequiredintegerWhich send this is under the convergence policy, from 1.
iterationrequiredintegerMemory passes so far in the current attempt.
transferred_bytesrequiredinteger
total_bytesrequiredinteger0 when the hypervisor does not report it.
dirty_bytes_per_secondrequiredinteger
downtime_millisecondsrequiredintegerThe pause the guest took at handover, once completed.
detailrequiredstring
reported_atrequiredstring (date-time) | nullThe reporting node's clock.
eventsarray of OperationEventPresent on GET /v1/operations/{id}; the newest 100 entries of the operation's log, oldest first.
atrequiredstring (date-time)
kindrequiredstringFor example target_chosen, send_started, handed_over, undoing, cold_fallback, move_cancelled, recovery_started, succeeded, failed.
messagerequiredstring
datarequiredobject
created_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PATCH 'https://cloud.ankra.app/v1/load-balancers/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "labels": {}
}'

Delete a load balancer, its VMs and its address#

DELETE/v1/load-balancers/{id}
Operation
delete_load_balancer
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Responses

202Accepted; poll the operation.application/json · OperationEnvelope

202 response fields
FieldTypeDescription
operationrequiredOperation
idrequiredstring
kindrequiredstringOne of server.create, server.metadata, server.start, server.stop, server.restart, server.delete, server.force_release, server.change_plan, server.rebuild, server.renumber_ipv6, server.attach_network, server.detach_network, server.firewall, storage.create, storage.attach, storage.detach, storage.resize, storage.delete, storage.backup, backup.restore, backup.delete, template.create, template.copy, template.delete, snapshot.create, snapshot.delete, router.sync, floating_ip.sync, network.sync, public_pool.sync, server.move, server.migrate, server.recover, server.settle_migration, node.cordon, node.uncordon, node.drain, node.fence, node.maintenance, node.agent_upgrade, node.provision, load_balancer.create, load_balancer.delete, database.create, database.delete, database.restore, edge.sync, edge.delete, storage.move, storage.rebalance_policy, storage.drain_host, object_storage.migrate, kubernetes_cluster.create, kubernetes_cluster.delete, kubernetes_cluster.upgrade, kubernetes_cluster.snapshot, kubernetes_cluster.restore, node_pool.sync, node_pool.delete, kubernetes_host.bootstrap, kubernetes_cluster.platform_register, kubernetes_cluster.platform_deregister, control_plane.expand, control_plane.shrink, backup.verify
server_idrequiredstring | null
storage_idrequiredstring | null
backup_idrequiredstring | null
template_idrequiredstring | null
router_idrequiredstring | null
floating_ip_idrequiredstring | null
node_idstringSet on node maintenance operations (operator only); absent otherwise.
load_balancer_idstring | nullSet on the operations that create and delete a load balancer.
database_idstring | nullSet on the operations that create and delete a managed database.
edge_idstring | nullSet on the operations that sync and delete a network edge.
snapshot_idstring | nullSet on the operations that create and delete a snapshot, and on a storage.create that clones one.
kubernetes_cluster_idstring | nullSet on the operations of a managed Kubernetes cluster.
node_pool_idstring | nullSet on the operations of a Kubernetes node pool.
kubernetes_host_idstringSet on a regional host cluster bootstrap (operator only); absent otherwise.
statusrequiredstringOne of pending, running, succeeded, failed, cancelled
steprequiredstringMachine name of the current step, e.g. create_disk or transfer_cross_zone.
step_indexrequiredinteger
step_countrequiredinteger
errorrequiredstringEmpty unless the operation failed.
created_atrequiredstring (date-time)
started_atrequiredstring (date-time) | null
finished_atrequiredstring (date-time) | null
deadline_atrequiredstring (date-time)
actorstringWho asked for the operation: user:<id>, token:<name>, operator, system:<component>; empty on older operations.
progressMigrationProgressPresent on GET /v1/operations/{id} while a server.migrate drives a live transfer.
staterequiredstringOne of reserved, detached, preparing, sending, switched, aborting
source_node_idrequiredstring
target_node_idrequiredstring
phaserequiredstringHow far the nodes report the current attempt.One of , preparing, transferring, completed, failed
attemptrequiredintegerWhich send this is under the convergence policy, from 1.
iterationrequiredintegerMemory passes so far in the current attempt.
transferred_bytesrequiredinteger
total_bytesrequiredinteger0 when the hypervisor does not report it.
dirty_bytes_per_secondrequiredinteger
downtime_millisecondsrequiredintegerThe pause the guest took at handover, once completed.
detailrequiredstring
reported_atrequiredstring (date-time) | nullThe reporting node's clock.
eventsarray of OperationEventPresent on GET /v1/operations/{id}; the newest 100 entries of the operation's log, oldest first.
atrequiredstring (date-time)
kindrequiredstringFor example target_chosen, send_started, handed_over, undoing, cold_fallback, move_cancelled, recovery_started, succeeded, failed.
messagerequiredstring
datarequiredobject
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/load-balancers/<id>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Add a backend#

POST/v1/load-balancers/{id}/backends
Operation
create_load_balancer_backend
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
namerequiredstring
moderequiredstringOne of tcp, http
balancestringOne of roundrobin, leastconn, source
health_check_pathstringOlder form of an http health check of this path.
health_checkLoadBalancerHealthCheckInputFields left out keep their value (on creation, the default of a TCP check every 2 s, rise 2, fall 3, path /, expected 200-399).
typestringOne of tcp, http, none
pathstring
expected_statusstring
interval_secondsinteger
riseinteger
fallinteger

Responses

201The backend.application/json

201 response fields
FieldTypeDescription
backendrequiredLoadBalancerBackend
idrequiredstring
namerequiredstring
moderequiredstringOne of tcp, http
balancerequiredstringOne of roundrobin, leastconn, source
health_check_pathrequiredstringThe http check's path, empty for other checks. Kept for older clients; read health_check.
health_checkrequiredLoadBalancerHealthCheck
typerequiredstringtcp connects to the member; http sends GET <path>; none never checks.One of tcp, http, none
pathrequiredstringFor http checks.
expected_statusrequiredstringFor http checks: 200, or a range such as 200-399.
interval_secondsrequiredinteger
riserequiredintegerSuccesses that bring a member back.
fallrequiredintegerFailures that take a member out.
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/load-balancers/<id>/backends' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "mode": "tcp"
}'

Change how a backend balances and checks its members#

PATCH/v1/load-balancers/{id}/backends/{backend}
Operation
update_load_balancer_backend
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
backendrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
balancestringOne of roundrobin, leastconn, source
health_checkLoadBalancerHealthCheckInputFields left out keep their value (on creation, the default of a TCP check every 2 s, rise 2, fall 3, path /, expected 200-399).
typestringOne of tcp, http, none
pathstring
expected_statusstring
interval_secondsinteger
riseinteger
fallinteger

Responses

200The backend.application/json

200 response fields
FieldTypeDescription
backendrequiredLoadBalancerBackend
idrequiredstring
namerequiredstring
moderequiredstringOne of tcp, http
balancerequiredstringOne of roundrobin, leastconn, source
health_check_pathrequiredstringThe http check's path, empty for other checks. Kept for older clients; read health_check.
health_checkrequiredLoadBalancerHealthCheck
typerequiredstringtcp connects to the member; http sends GET <path>; none never checks.One of tcp, http, none
pathrequiredstringFor http checks.
expected_statusrequiredstringFor http checks: 200, or a range such as 200-399.
interval_secondsrequiredinteger
riserequiredintegerSuccesses that bring a member back.
fallrequiredintegerFailures that take a member out.
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PATCH 'https://cloud.ankra.app/v1/load-balancers/<id>/backends/<backend>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "balance": "roundrobin",
  "health_check": {
    "type": "tcp",
    "path": "string",
    "expected_status": "string",
    "interval_seconds": 1,
    "rise": 1,
    "fall": 1
  }
}'

Remove a backend and its members#

DELETE/v1/load-balancers/{id}/backends/{backend}
Operation
delete_load_balancer_backend
Credentials
API token, Portal session
Requires
Permission operate

409 while a frontend forwards to it.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
backendrequiredpathstring

Responses

204Removed.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/load-balancers/<id>/backends/<backend>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Replace a backend's whole member list at once#

PUT/v1/load-balancers/{id}/backends/{backend}/members
Operation
replace_load_balancer_members
Credentials
API token, Portal session
Requires
Permission operate

The list becomes the backend's members in one configuration change (one configuration generation), so HAProxy never serves a half-replaced backend: members missing from it leave, new ones join, and a member named again keeps its id and takes the new address, port, weight and state. An empty list empties the backend; a list equal to the current one changes nothing. Members follow the add-member rules (IPv4 host of the network, its ULA /64 or a global IPv6 address); names are unique within the list; at most 256 members.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
backendrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
membersrequiredarray of object
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightinteger
enabledboolean

Responses

200The backend's members after the replacement.application/json

200 response fields
FieldTypeDescription
membersrequiredarray of LoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PUT 'https://cloud.ankra.app/v1/load-balancers/<id>/backends/<backend>/members' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "members": [
    {
      "name": "string",
      "address": "10.0.0.20",
      "port": 1
    }
  ]
}'

Add a member to a backend#

POST/v1/load-balancers/{id}/backends/{backend}/members
Operation
create_load_balancer_member
Credentials
API token, Portal session
Requires
Permission operate

A member is IPv4 or IPv6: an IPv4 host of the load balancer's private network, an address of that network's ULA /64 (a server's leg address6) or a global IPv6 address (a server's public_ipv6). 400 for anything else.

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
backendrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightinteger
enabledboolean

Responses

201The member.application/json

201 response fields
FieldTypeDescription
memberrequiredLoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/load-balancers/<id>/backends/<backend>/members' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "address": "10.0.0.20",
  "port": 1
}'

Change a member's weight or take it out of rotation#

PATCH/v1/load-balancers/{id}/backends/{backend}/members/{member}
Operation
update_load_balancer_member
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
backendrequiredpathstring
memberrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
weightinteger
enabledboolean

Responses

200The member.application/json

200 response fields
FieldTypeDescription
memberrequiredLoadBalancerMember
idrequiredstring
backend_idrequiredstring
namerequiredstring
addressrequiredstringAn IPv4 or IPv6 address.
portrequiredinteger
weightrequiredinteger
enabledrequiredboolean
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X PATCH 'https://cloud.ankra.app/v1/load-balancers/<id>/backends/<backend>/members/<member>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "weight": 0,
  "enabled": false
}'

Remove a member from its backend#

DELETE/v1/load-balancers/{id}/backends/{backend}/members/{member}
Operation
delete_load_balancer_member
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
backendrequiredpathstring
memberrequiredpathstring

Responses

204Removed.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/load-balancers/<id>/backends/<backend>/members/<member>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Listen on a port and forward to a backend#

POST/v1/load-balancers/{id}/frontends
Operation
create_load_balancer_frontend
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring

Request bodyapplication/json

Request body fields
FieldTypeDescription
namerequiredstring
portrequiredinteger
backend_idrequiredstring
tlsbooleanTerminate TLS; needs certificate_ids.
certificate_idsarray of stringCertificates of the account; the first answers clients without SNI. A load balancer uses at most 16.
redirect_to_httpsbooleanOnly on a plain frontend of an http backend.

Responses

201The frontend.application/json

201 response fields
FieldTypeDescription
frontendrequiredLoadBalancerFrontend
idrequiredstring
namerequiredstring
portrequiredinteger
moderequiredstringThe mode of its backend.One of tcp, http
backend_idrequiredstring
tlsrequiredbooleanTerminates TLS with its certificates.
certificate_idsrequiredarray of stringThe first answers clients that send no server name; the others are chosen by SNI.
redirect_to_httpsrequiredbooleanAnswers every request with a 301 to https on the same host.
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/load-balancers/<id>/frontends' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "port": 1,
  "backend_id": "string"
}'

Stop listening on a frontend's port#

DELETE/v1/load-balancers/{id}/frontends/{frontend}
Operation
delete_load_balancer_frontend
Credentials
API token, Portal session
Requires
Permission operate

Parameters

Parameters
NameInTypeDescription
idrequiredpathstring
frontendrequiredpathstring

Responses

204Removed.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/load-balancers/<id>/frontends/<frontend>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

List the account's load balancer certificates#

GET/v1/load-balancers/certificates
Operation
list_load_balancer_certificates
Credentials
API token, Portal session
Requires
Permission read

Responses

200Every certificate, newest first (next_cursor is always null).application/json

200 response fields
FieldTypeDescription
itemsrequiredarray of LoadBalancerCertificate
idrequiredstring
namerequiredstring
common_namerequiredstring
dns_namesrequiredarray of string
not_beforerequiredstring (date-time)
not_afterrequiredstring (date-time)
fingerprint_sha256requiredstringLowercase hex SHA-256 of the leaf certificate.
frontend_countrequiredintegerFrontends that terminate TLS with it.
created_atrequiredstring (date-time)
next_cursorrequirednull
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/load-balancers/certificates' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Upload a certificate chain and its private key#

POST/v1/load-balancers/certificates
Operation
create_load_balancer_certificate
Credentials
API token, Portal session
Requires
Permission operate

The chain (leaf first) and an unencrypted private key (PKCS #8, PKCS #1 or SEC 1; RSA of at least 2048 bits, ECDSA or Ed25519), both PEM. The key must belong to the leaf. It is sealed with the control plane's secret key and only ever leaves it inside a configuration pushed to a load balancer VM. 503 when the control plane has no secret key; an account holds at most 100 certificates.

Request bodyapplication/json

Request body fields
FieldTypeDescription
namerequiredstring
certificaterequiredstring
private_keyrequiredstring

Responses

201The certificate, without its key.application/json

201 response fields
FieldTypeDescription
certificaterequiredLoadBalancerCertificateA certificate chain the account's load balancers terminate TLS with. Its private key is sealed at rest and never returned.
idrequiredstring
namerequiredstring
common_namerequiredstring
dns_namesrequiredarray of string
not_beforerequiredstring (date-time)
not_afterrequiredstring (date-time)
fingerprint_sha256requiredstringLowercase hex SHA-256 of the leaf certificate.
frontend_countrequiredintegerFrontends that terminate TLS with it.
created_atrequiredstring (date-time)
  • 400The request is invalid; detail says why.
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 409The resource's state does not allow this now.
  • 422The account would exceed a quota; detail names the limit.
  • 503No capacity or address is free, or a host did not answer; try again later.
  • defaultAny other error, usually 500.

Example

bash
curl -X POST 'https://cloud.ankra.app/v1/load-balancers/certificates' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN" \
  -H 'Content-Type: application/json' \
  -d '{
  "name": "string",
  "certificate": "string",
  "private_key": "string"
}'

Get a certificate#

GET/v1/load-balancers/certificates/{certificate}
Operation
get_load_balancer_certificate
Credentials
API token, Portal session
Requires
Permission read

Parameters

Parameters
NameInTypeDescription
certificaterequiredpathstring

Responses

200The certificate, without its key.application/json

200 response fields
FieldTypeDescription
certificaterequiredLoadBalancerCertificateA certificate chain the account's load balancers terminate TLS with. Its private key is sealed at rest and never returned.
idrequiredstring
namerequiredstring
common_namerequiredstring
dns_namesrequiredarray of string
not_beforerequiredstring (date-time)
not_afterrequiredstring (date-time)
fingerprint_sha256requiredstringLowercase hex SHA-256 of the leaf certificate.
frontend_countrequiredintegerFrontends that terminate TLS with it.
created_atrequiredstring (date-time)
  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • defaultAny other error, usually 500.

Example

bash
curl 'https://cloud.ankra.app/v1/load-balancers/certificates/<certificate>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"

Delete a certificate and its sealed key#

DELETE/v1/load-balancers/certificates/{certificate}
Operation
delete_load_balancer_certificate
Credentials
API token, Portal session
Requires
Permission operate

409 while a frontend terminates TLS with it.

Parameters

Parameters
NameInTypeDescription
certificaterequiredpathstring

Responses

204Deleted.

  • 401Not signed in, or the credential is invalid or expired.
  • 403The role lacks the permission, the token is read-only (a read-only token also gets reason: read_only_token_cannot_read_credentials on every credential read), the CSRF header is missing, a support session may not do this, or the route needs a verified email address and the caller's is not (reason: email_unverified).
  • 404No such resource in the caller's account.
  • 409The resource's state does not allow this now.
  • defaultAny other error, usually 500.

Example

bash
curl -X DELETE 'https://cloud.ankra.app/v1/load-balancers/certificates/<certificate>' \
  -H "Authorization: Bearer $ANKRA_CLOUD_TOKEN"